Strategy and regulation · September 2026

AI Act, Colombia and ISO 42001: the 2026 AI regulatory map

Since August 2, 2026 the EU AI Act applies in general, but the AI Omnibus pushed high-risk rules to 2027 and 2028. Colombia still has no AI law, yet Law 1581 and the SIC already set the rules for personal data. Here is the map, with dates and a 10-step plan for companies working in both markets.

Aug 2, 2026 Article 50 transparency appliesDec 2, 2027 Annex III high-risk rules€35M or 7% top AI Act fine
In short

The EU AI Act has applied in general since August 2, 2026. The AI Omnibus (Regulation (EU) 2026/1744, in force since July 27, 2026) moved high-risk obligations to December 2027 and August 2028, softened AI literacy and bans, from December 2, 2026, systems that create non-consensual intimate images or child sexual abuse material. The Act reaches a Colombian company whenever its AI output is used in the EU.

Colombia has no AI law, but Law 1581 of 2012 and SIC Circular Externa 002 de 2024 already require authorization, impact studies and demonstrable accountability. Our advice: one governance system for both regimes, built on ISO/IEC 42001. This article is general information, not legal advice.

The AI Act calendar after the Omnibus

The AI Act has been in force since August 1, 2024 and applies in stages. The Omnibus, approved by Parliament (June 16, 2026, 423 votes to 57) and the Council (June 29), rewrote several dates.

Dates under Regulation (EU) 2026/1744, checked on EUR-Lex on September 26, 2026.
DateWhat applies
Feb 2, 2025Prohibited practices (Art. 5), AI literacy (Art. 4)
Aug 2, 2025General-purpose AI (GPAI) models, governance, penalties
Jul 27, 2026Omnibus in force; amended Art. 4
Aug 2, 2026General application, including Art. 50 transparency
Dec 2, 2026New bans; Art. 50(2) marking for generators already on the market
Aug 2, 2027GPAI models marketed before Aug 2, 2025
Dec 2, 2027High-risk rules for Annex III (hiring, credit, education)
Aug 2, 2028High-risk rules for Annex I (AI in regulated products)
Read the right text

The AI Act Service Desk still shows the 2024 text: for amended provisions, read Regulation (EU) 2026/1744 on EUR-Lex.

Who is in scope: roles, reach and risk tiers

Roles. The provider develops an AI system or model and markets it under its own name; the deployer uses it under its authority. Putting your brand on a high-risk system, modifying it substantially or changing its purpose makes you its provider (Article 25(1)).

Reach. The Act covers providers placing AI on the EU market wherever they are established (Article 2(1)(a)), and third-country providers and deployers whose system output is used in the Union (Article 2(1)(c)). A Bogotá team running a chatbot for a French retailer, or ranking candidates for a Madrid employer, is in scope. Non-EU providers of high-risk systems or GPAI models need an EU authorised representative (Articles 22 and 54).

Risk tiers and examples.
TierExamplesDate
Prohibited (Art. 5)Social scoring, emotion recognition at work or school, untargeted scraping of facial imagesFeb 2, 2025
Prohibited (new)Nudifier apps, child sexual abuse materialDec 2, 2026
High-risk (Annex III)CV screening, credit scoring, exam gradingDec 2, 2027
High-risk (Annex I)AI safety components of regulated products, such as medical devicesAug 2, 2028
Transparency (Art. 50)Chatbots, voice agents, content generators, deepfakesAug 2, 2026

An Annex III system limited to a narrow procedural or preparatory task is not high-risk unless it profiles people (Article 6(3)); document and register that assessment. From December 2, 2027, deployers of high-risk systems must ensure human oversight, keep logs for at least six months and inform workers' representatives (Article 26).

What already applies: GPAI, AI literacy, Article 50

GPAI models. Since August 2, 2025, their providers must document them, inform downstream providers, respect text-and-data-mining opt-outs and publish a training-content summary (Article 53(1)). Their Code of Practice (July 2025) had 21 full signatories on July 31, 2026, including Anthropic, Google, Microsoft and OpenAI; Meta declined. If you use these models through an API, these duties are the vendor's: ask for its documentation.

AI literacy. Since July 27, 2026, Article 4 asks providers and deployers to “take measures to support the development of AI literacy” of the people operating AI, without guaranteeing any specific level. It is not in the Article 99(4) fine list: sanctions depend on national law. A documented, role-based training plan is the best evidence.

Transparency. Since August 2, 2026, providers must make chatbots disclose they are AI unless it is obvious (Article 50(1)) and mark generated content in a machine-readable way (50(2)). Deployers must disclose deepfakes and AI-generated public-interest text published without editorial review (50(4)). Details in rights and provenance of AI content.

Fines (Article 99). Up to €35 million or 7% of worldwide turnover for prohibited practices, and up to €15 million or 3% for breaching operator duties, Article 50 included. SMEs and start-ups face the lower of the two amounts.

GDPR and AI: EDPB, CNIL and the courts

The GDPR usually applies first. EDPB Opinion 28/2024 (December 17, 2024) holds that a model trained on personal data is not always anonymous, that legitimate interest can support development and deployment if it passes the three-step test, and that unlawful training can affect the lawfulness of deployment unless the model was duly anonymised.

On automated decisions, the CJEU holds that a credit score can itself be an Article 22 decision (SCHUFA, 2023) and that people may demand an explanation of “the procedure and principles actually applied” (Dun & Bradstreet Austria, February 27, 2025). GDPR fines reach €20 million or 4%.

In France, the CNIL finalised its AI recommendations on July 22, 2025 (13 practical sheets). It presumes a DPIA for AI Act high-risk systems that process personal data and, in most cases, for general-purpose systems; recruitment, with attention to AI, is a 2026 inspection priority. The GDPR reform in the Digital Omnibus, which would add a legitimate-interest route for AI, had no Council mandate as of September 21, 2026.

Colombia: no AI law yet, strict data rules already

Policy and bills. CONPES 4144 (February 14, 2025) sets the national AI policy: six axes and 106 actions to 2030, with about COP 479,273 million of indicative investment. The government bill (PL 043/2025 Senado, 324/2025 Cámara) was archived at the end of the 2025-2026 legislature without a first-debate vote. PL 025 de 2026 Cámara, filed on July 21, 2026, proposes risk tiers, MinCiencias as authority and a data-sovereignty clause. Semana reports a debate over whether MinCiencias or the SIC should be the authority.

Already binding. Law 2502 of 2025 raises the fine for impersonation by up to one third when AI is used. Law 1581 of 2012 covers any AI processing of personal data; citing ruling T-323 de 2024, the SIC stresses that it is technology-neutral.

Personal-data duties for an AI project.
DutyBasisIn practice
Prior, informed, provable authorizationLaw 1581, Art. 9Consent in chatbots and agents
Explicit authorization for sensitive dataLaw 1581, Arts. 5 and 6Biometrics and health
International transfersLaw 1581, Art. 26Adequate country or express authorization
Contract with foreign processorsDecree 1074 of 2015, Art. 2.2.2.25.5.2One per AI vendor
Privacy impact studySIC Circular 002 de 2024Before designing high-risk AI
Demonstrable accountabilityDecree 1074, Art. 2.2.2.25.6.1Evidence for the SIC

The Circular adds a four-part test (suitability, necessity, reasonableness, strict proportionality) and warns that personal data found online is not public data: collecting private, semi-private or sensitive data from the web for AI requires prior, express and informed authorization. SIC fines reach 2,000 monthly minimum wages (Article 23).

Latin America and the United States

Status on September 26, 2026; we make no forecasts.

From official legislative and government sources.
WhereInstrumentStatus
BrazilPL 2338/2023Passed the Senate (Dec 10, 2024); in a Chamber special committee
ChileBoletín 16821-19Passed the Chamber (sent to the Senate Oct 13, 2025); in the Senate
PeruLaw 31814, DS 115-2025-PCMRegulation in force; private-sector phase-in of 1 to 4 years
MexicoFederal initiativesNot confirmed on official portals: check locally
US federalEO 14179, 14365, 14409Deregulation and pressure on state laws
ColoradoSB26-189Duties for consequential decisions from Jan 1, 2027
CaliforniaSB 53Frontier developers: safety frameworks, incident reports
TexasTRAIGA (HB 149)In force since Jan 1, 2026

In the ILIA 2025 index (CEPAL and CENIA), Colombia ranks 4th of 19 countries with 55.84 points, behind Chile, Brazil and Uruguay and ahead of Peru (51.93) and Mexico (47.03). Peru's regulation already classifies uses as prohibited, high-risk or acceptable and requires advance transparency for high-risk systems (Article 25).

In the US, EO 14409 (June 2, 2026) sets up voluntary government testing of frontier models with advanced cyber capabilities, with no licensing. EO 14365 set up a task force to challenge state AI laws, yet states keep legislating: if you sell HR, lending or insurance software there, plan for Colorado in 2027 (notice, explanation of adverse outcomes, human review).

A 10-step plan, with ISO/IEC 42001 as the skeleton

Standards. ISO/IEC 42001:2023 is the certifiable AI management system; ISO/IEC 42005:2025 covers impact assessment and ISO/IEC 42006:2025 the certification bodies. NIST's AI RMF (2023) remains the US reference, though it is under revision. CEN-CENELEC is preparing the AI Act's harmonised standards: prEN 18286 on quality management reached public enquiry on October 30, 2025.

Procurement. You will mostly see vendors' 42001 certificates, from Anthropic, AWS or Microsoft: they cover the vendor's management system, not your use case. Our rule: use 42001 as the skeleton, map the AI Act and Law 1581 onto it, and certify when a client or tender asks. Here is the order we recommend for a mid-size company:

Status on September 26, 2026.
#StepLegal anchorWhen
1Inventory AI systems and models, and your role in eachAI Act Arts. 2 and 25Now
2Rule out prohibited uses; safeguard image and video generatorsArt. 5Now; Dec 2, 2026
3Classify risk; document Article 6(3) exemptionsArt. 6, Annex IIIBefore Dec 2, 2027
4Disclose chatbots, mark outputs, label deepfakesArt. 50Already due
5Documented, role-based AI trainingArt. 4Ongoing
6DPIA for the EU, privacy impact study for ColombiaGDPR Art. 35; SIC Circular 002Before each project
7Settle the legal basis: legitimate interest or authorizationEDPB 28/2024; Law 1581Before processing
8Processor, transmission and supplier contracts; vendor documentationGDPR Art. 28; Decree 1074; AI Act Art. 53Before go-live
9Human review of automated decisions; keep logsGDPR Art. 22; AI Act Art. 26Now; Art. 26 in Dec 2027
10EU representatives if needed; RNBD if assets exceed 100,000 UVT; quarterly reviewAI Act Arts. 22 and 54; GDPR Art. 27; Decree 1074Now
Our rule of thumb

Start with steps 1, 4 and 8: the inventory shows where you stand, transparency is already enforceable and contracts take time. Our AI consulting team can help you set priorities.

Key takeaways

  • The AI Act has applied since August 2, 2026, and Article 50 transparency is already enforceable.
  • The Omnibus moved high-risk rules to December 2027 and August 2028 and adds new bans from December 2, 2026.
  • A Colombian company is in scope when its AI output is used in the EU (Article 2(1)(c)).
  • Colombia has no AI law yet, but Law 1581 and SIC Circular 002 de 2024 already require authorization, impact studies and accountability.
  • One governance system on ISO/IEC 42001; start with inventory, transparency and contracts.

Sources

  1. Regulation (EU) 2026/1744 (Digital Omnibus on AI) · EUR-Lex, 2026-07-24
  2. AI Omnibus enters into force · European Commission, 2026-07-27
  3. AI Act, Article 2: Scope · AI Act Service Desk, European Commission, 2024-06-13
  4. The General-Purpose AI Code of Practice (signatories) · European Commission, 2026-07-31
  5. Opinion 28/2024 on data protection aspects of AI models · EDPB, 2024-12-17
  6. Les fiches pratiques IA · CNIL, 2025-07-22
  7. Circular Externa 002 de 2024: tratamiento de datos personales en sistemas de inteligencia artificial · Superintendencia de Industria y Comercio, 2024-08-21
  8. Ley Estatutaria 1581 de 2012 · Secretaría General del Senado, 2012
  9. Proyecto de Ley 025 de 2026 Cámara (inteligencia artificial) · Cámara de Representantes de Colombia, 2026-07-21
  10. Documento CONPES 4144: Política Nacional de Inteligencia Artificial · DNP, 2025-02-14
  11. Executive Order 14409: Promoting Advanced Artificial Intelligence Innovation and Security · Federal Register, 2026-06-05
  12. ISO/IEC 42001:2023 Artificial intelligence: Management system · ISO, 2023-12

Editorial note: this analysis reflects the public information available on the review date. Models, prices and rules change fast; every third-party figure links to its source, and our opinions are labeled as such. Spotted an error? Write to contact@slash-digital.io.

Frequently asked questions

The questions we hear often

Does the EU AI Act apply to a company based in Colombia?

Yes, when it places AI systems or models on the EU market, or when the output of its AI system is used in the EU (Article 2(1)(a) and (c)). Non-EU providers of high-risk systems or GPAI models also need an EU authorised representative, and the GDPR may require a representative too (Article 27).

What did the AI Omnibus change?

Regulation (EU) 2026/1744, in force since July 27, 2026, moved high-risk obligations to December 2, 2027 (Annex III) and August 2, 2028 (Annex I), softened the AI literacy duty, added bans on non-consensual intimate imagery and child sexual abuse material from December 2, 2026, and gave generators already on the market until that date to mark outputs. Article 50 was not postponed.

Does Colombia have an AI law?

Not as of September 26, 2026. The government bill was archived and PL 025 de 2026 Cámara is still a bill. Law 1581 of 2012, SIC Circular Externa 002 de 2024 and Law 2502 of 2025 already apply to AI projects.

Is AI literacy training mandatory?

Article 4 requires providers and deployers to take measures to support the AI literacy of the people operating AI for them, without guaranteeing a specific level. It is not in the Article 99(4) fine list, so sanctions depend on national law; documented training is still the simplest evidence.

Do we need ISO/IEC 42001 certification?

Neither the AI Act nor Colombian law requires it. It is a voluntary, certifiable management system that organises inventory, risk and controls, and large vendors already hold it. Use it as a framework; certify when clients or tenders ask.

Talk to Slash

Let's put it in production

Tell us your challenge. We reply within 24 business hours with an honest first read: if we can help, we'll say how; if not, we'll say who can.

I reply personally. No endless forms, no canned replies.

Message Esteban