Peru is emerging as one of Latin America’s leading jurisdictions for artificial intelligence regulation. With Law No. 31814, which promotes the use of artificial intelligence for the country’s economic and social development, and its implementing Regulation approved through Supreme Decree No. 115-2025-PCM, Peru has established a comprehensive framework for the responsible development and use of AI. The Regulation was approved on September 9, 2025.
For businesses operating in Peru, the framework goes beyond encouraging innovation. It establishes expectations around AI risk classification, transparency, human oversight, protection of fundamental rights, and responsible use of AI systems.
As AI increasingly influences healthcare, finance, education, public services, employment, and business operations, understanding Peru’s AI regulations is becoming an important part of technology governance, regulatory compliance, and risk management.
What Does Peru’s AI Regulation Require?
Peru’s AI framework establishes a risk-based approach to artificial intelligence and seeks to ensure that AI is developed and used safely, ethically, transparently, sustainably, and inclusively while respecting fundamental rights. The Secretariat of Government and Digital Transformation (SGTD) plays a central role in coordinating the country’s AI governance framework and providing technical and regulatory guidance.
For businesses, this means AI governance can no longer be treated solely as an IT or innovation issue. Organizations using AI should consider how systems are selected, documented, monitored, deployed, and overseen throughout their lifecycle.
Peru’s AI Risk Classification: What Businesses Need to Know
The Regulation classifies AI systems and uses according to the risks they may create. This approach is designed to protect fundamental rights while allowing organizations to continue developing and adopting beneficial AI technologies.
Prohibited or Improper Uses
Certain uses of AI are not permitted because of their potential to manipulate individuals, undermine fundamental rights, or create unacceptable risks.
Examples include:
- AI systems that manipulate or deceive individuals in ways that influence decision-making without adequate awareness
- Autonomous lethal weapons that operate without human supervision
- Mass surveillance without an appropriate legal basis or where it disproportionately affects fundamental rights
- Certain biometric systems used to infer sensitive characteristics or identify individuals in real time in public spaces, subject to specific legal exceptions
These restrictions demonstrate that Peru’s AI framework is focused not only on technological performance but also on protecting individual rights and preventing harmful applications of artificial intelligence.
High-Risk AI Systems
Higher-risk applications require stronger governance, safeguards, and oversight. Areas addressed by the framework include applications involving sectors and decisions where AI can have significant effects on individuals or society.
Examples include:
- Education and access to educational opportunities
- Healthcare and other sensitive services
- Employment and workforce-related decision-making
- Financial services and credit-related decisions
- Social programs and public services
- Critical infrastructure and other sensitive environments
Organizations using higher-risk AI systems should be prepared to address requirements related to transparency, documentation, human oversight, risk management, and accountability.
What Does the Peru AI Act Mean for Businesses?
Companies operating in Peru should treat AI compliance as part of their broader corporate governance and regulatory risk framework.
Key priorities include:
- AI inventory: Identify the AI systems, tools, vendors, and applications used across the organization.
- Risk classification: Determine which AI applications may create elevated regulatory, operational, or rights-related risks.
- Governance policies: Establish clear internal rules governing the acquisition, development, deployment, monitoring, and retirement of AI systems.
- Human oversight: Define who is responsible for reviewing AI-supported decisions and intervening when necessary.
- Documentation: Maintain records demonstrating how AI systems are evaluated, implemented, monitored, and governed.
- Transparency: Establish processes for communicating when and how AI is being used, particularly where individuals may be affected by AI-generated decisions or outputs.
- Vendor oversight: Evaluate third-party AI providers and incorporate appropriate compliance, security, transparency, and accountability requirements into contracts.
- Regulatory monitoring: Track changes to Peru’s AI framework and related technical standards as implementation continues.
The framework provides organizations with time to adapt, but companies should not interpret transitional periods as a reason to postpone governance. Building an AI compliance framework early can reduce regulatory risk and create a stronger foundation for responsible AI adoption.
Why AI Governance Can Become a Competitive Advantage in Peru
AI regulation does not have to be viewed solely as a compliance burden. Organizations that establish effective AI governance can use it to strengthen trust with customers, employees, business partners, investors, and regulators.
A structured AI governance program can also help companies:
- Identify AI-related risks before they become compliance or reputational problems
- Create consistent standards across business units and jurisdictions
- Improve accountability for AI-supported decisions
- Demonstrate responsible technology practices to customers and partners
- Align local operations with international AI governance principles
- Build a scalable foundation for future AI adoption
For multinational companies, Peru’s framework is particularly relevant because AI governance increasingly intersects with data protection, cybersecurity, employment, consumer protection, corporate governance, and cross-border compliance.
What Should Companies Do Now?
Organizations using or planning to deploy AI in Peru should begin by establishing a clear understanding of their current AI footprint.
A practical starting point includes:
- Identify AI use cases across departments, subsidiaries, and business functions.
- Map AI vendors and systems and determine what data and decisions each system affects.
- Classify potential risks based on the purpose and impact of each AI application.
- Document governance responsibilities so ownership of AI compliance is clearly established.
- Review contracts and vendor controls for transparency, data protection, security, and accountability requirements.
- Establish monitoring and review processes for higher-risk AI systems.
- Track regulatory developments as Peru continues implementing and refining its AI governance framework.
Taking these steps early can help businesses move from reactive compliance to proactive AI governance.
How Corpiya Helps Companies Navigate Peru’s AI Framework
Corpiya supports organizations entering or operating in Peru by helping them understand and operationalize emerging AI governance requirements.
Our support can include:
- Assessing AI risk classifications and applicable obligations
- Developing internal AI governance and compliance policies
- Establishing documentation and oversight processes
- Supporting impact and risk assessments for higher-risk AI systems
- Reviewing third-party AI and technology arrangements
- Coordinating compliance requirements across multiple entities and jurisdictions
- Monitoring regulatory developments affecting AI and corporate operations
Navigating Peru’s AI framework can involve complex compliance requirements, documentation, and coordination across business units and legal entities. Corpiya combines regulatory and operational expertise with technology-enabled entity management to help organizations maintain visibility over their corporate structures, obligations, documentation, and compliance deadlines.
Corpiya’s AI-driven Entity Management System centralizes entity data, automates workflows, tracks deadlines, and supports ongoing compliance management across jurisdictions. This integrated approach helps organizations establish stronger governance infrastructure while continuing to pursue responsible AI adoption.
The Future of AI Governance in Latin America
Peru’s AI framework represents an important development in the region’s approach to artificial intelligence regulation. By establishing rules around responsible AI use, risk, transparency, and protection of fundamental rights, Peru is helping shape the direction of AI governance in Latin America.
For companies operating in Peru, the priority is no longer simply understanding what AI can do. It is understanding how AI should be governed, documented, monitored, and deployed responsibly.
Organizations that build AI governance into their operating model now will be better positioned to manage regulatory change, protect stakeholder trust, and scale AI responsibly as the regulatory landscape continues to evolve.
For more information or tailored support, including how our AI-driven Entity Management System can streamline compliance and entity governance, fill out the form below or contact us at info@corpiya.com.
Put These Insights Into Action
Talk to our team about how this applies to your operations — wherever your business takes you, Corpiya is ready to support your next move.


