AI Act, Colombia and ISO 42001: the 2026 AI regulatory map
Since August 2, 2026 the EU AI Act applies in general, but the AI Omnibus pushed high-risk rules to 2027 and 2028. Colombia still has no AI law, yet Law 1581 and the SIC already set the rules for personal data. Here is the map, with dates and a 10-step plan for companies working in both markets.
The EU AI Act has applied in general since August 2, 2026. The AI Omnibus (Regulation (EU) 2026/1744, in force since July 27, 2026) moved high-risk obligations to December 2027 and August 2028, softened AI literacy and bans, from December 2, 2026, systems that create non-consensual intimate images or child sexual abuse material. The Act reaches a Colombian company whenever its AI output is used in the EU.
Colombia has no AI law, but Law 1581 of 2012 and SIC Circular Externa 002 de 2024 already require authorization, impact studies and demonstrable accountability. Our advice: one governance system for both regimes, built on ISO/IEC 42001. This article is general information, not legal advice.
The AI Act calendar after the Omnibus
The AI Act has been in force since August 1, 2024 and applies in stages. The Omnibus, approved by Parliament (June 16, 2026, 423 votes to 57) and the Council (June 29), rewrote several dates.
| Date | What applies |
|---|---|
| Feb 2, 2025 | Prohibited practices (Art. 5), AI literacy (Art. 4) |
| Aug 2, 2025 | General-purpose AI (GPAI) models, governance, penalties |
| Jul 27, 2026 | Omnibus in force; amended Art. 4 |
| Aug 2, 2026 | General application, including Art. 50 transparency |
| Dec 2, 2026 | New bans; Art. 50(2) marking for generators already on the market |
| Aug 2, 2027 | GPAI models marketed before Aug 2, 2025 |
| Dec 2, 2027 | High-risk rules for Annex III (hiring, credit, education) |
| Aug 2, 2028 | High-risk rules for Annex I (AI in regulated products) |
The AI Act Service Desk still shows the 2024 text: for amended provisions, read Regulation (EU) 2026/1744 on EUR-Lex.
Who is in scope: roles, reach and risk tiers
Roles. The provider develops an AI system or model and markets it under its own name; the deployer uses it under its authority. Putting your brand on a high-risk system, modifying it substantially or changing its purpose makes you its provider (Article 25(1)).
Reach. The Act covers providers placing AI on the EU market wherever they are established (Article 2(1)(a)), and third-country providers and deployers whose system output is used in the Union (Article 2(1)(c)). A Bogotá team running a chatbot for a French retailer, or ranking candidates for a Madrid employer, is in scope. Non-EU providers of high-risk systems or GPAI models need an EU authorised representative (Articles 22 and 54).
| Tier | Examples | Date |
|---|---|---|
| Prohibited (Art. 5) | Social scoring, emotion recognition at work or school, untargeted scraping of facial images | Feb 2, 2025 |
| Prohibited (new) | Nudifier apps, child sexual abuse material | Dec 2, 2026 |
| High-risk (Annex III) | CV screening, credit scoring, exam grading | Dec 2, 2027 |
| High-risk (Annex I) | AI safety components of regulated products, such as medical devices | Aug 2, 2028 |
| Transparency (Art. 50) | Chatbots, voice agents, content generators, deepfakes | Aug 2, 2026 |
An Annex III system limited to a narrow procedural or preparatory task is not high-risk unless it profiles people (Article 6(3)); document and register that assessment. From December 2, 2027, deployers of high-risk systems must ensure human oversight, keep logs for at least six months and inform workers' representatives (Article 26).
What already applies: GPAI, AI literacy, Article 50
GPAI models. Since August 2, 2025, their providers must document them, inform downstream providers, respect text-and-data-mining opt-outs and publish a training-content summary (Article 53(1)). Their Code of Practice (July 2025) had 21 full signatories on July 31, 2026, including Anthropic, Google, Microsoft and OpenAI; Meta declined. If you use these models through an API, these duties are the vendor's: ask for its documentation.
AI literacy. Since July 27, 2026, Article 4 asks providers and deployers to “take measures to support the development of AI literacy” of the people operating AI, without guaranteeing any specific level. It is not in the Article 99(4) fine list: sanctions depend on national law. A documented, role-based training plan is the best evidence.
Transparency. Since August 2, 2026, providers must make chatbots disclose they are AI unless it is obvious (Article 50(1)) and mark generated content in a machine-readable way (50(2)). Deployers must disclose deepfakes and AI-generated public-interest text published without editorial review (50(4)). Details in rights and provenance of AI content.
Fines (Article 99). Up to €35 million or 7% of worldwide turnover for prohibited practices, and up to €15 million or 3% for breaching operator duties, Article 50 included. SMEs and start-ups face the lower of the two amounts.
GDPR and AI: EDPB, CNIL and the courts
The GDPR usually applies first. EDPB Opinion 28/2024 (December 17, 2024) holds that a model trained on personal data is not always anonymous, that legitimate interest can support development and deployment if it passes the three-step test, and that unlawful training can affect the lawfulness of deployment unless the model was duly anonymised.
On automated decisions, the CJEU holds that a credit score can itself be an Article 22 decision (SCHUFA, 2023) and that people may demand an explanation of “the procedure and principles actually applied” (Dun & Bradstreet Austria, February 27, 2025). GDPR fines reach €20 million or 4%.
In France, the CNIL finalised its AI recommendations on July 22, 2025 (13 practical sheets). It presumes a DPIA for AI Act high-risk systems that process personal data and, in most cases, for general-purpose systems; recruitment, with attention to AI, is a 2026 inspection priority. The GDPR reform in the Digital Omnibus, which would add a legitimate-interest route for AI, had no Council mandate as of September 21, 2026.
Colombia: no AI law yet, strict data rules already
Policy and bills. CONPES 4144 (February 14, 2025) sets the national AI policy: six axes and 106 actions to 2030, with about COP 479,273 million of indicative investment. The government bill (PL 043/2025 Senado, 324/2025 Cámara) was archived at the end of the 2025-2026 legislature without a first-debate vote. PL 025 de 2026 Cámara, filed on July 21, 2026, proposes risk tiers, MinCiencias as authority and a data-sovereignty clause. Semana reports a debate over whether MinCiencias or the SIC should be the authority.
Already binding. Law 2502 of 2025 raises the fine for impersonation by up to one third when AI is used. Law 1581 of 2012 covers any AI processing of personal data; citing ruling T-323 de 2024, the SIC stresses that it is technology-neutral.
| Duty | Basis | In practice |
|---|---|---|
| Prior, informed, provable authorization | Law 1581, Art. 9 | Consent in chatbots and agents |
| Explicit authorization for sensitive data | Law 1581, Arts. 5 and 6 | Biometrics and health |
| International transfers | Law 1581, Art. 26 | Adequate country or express authorization |
| Contract with foreign processors | Decree 1074 of 2015, Art. 2.2.2.25.5.2 | One per AI vendor |
| Privacy impact study | SIC Circular 002 de 2024 | Before designing high-risk AI |
| Demonstrable accountability | Decree 1074, Art. 2.2.2.25.6.1 | Evidence for the SIC |
The Circular adds a four-part test (suitability, necessity, reasonableness, strict proportionality) and warns that personal data found online is not public data: collecting private, semi-private or sensitive data from the web for AI requires prior, express and informed authorization. SIC fines reach 2,000 monthly minimum wages (Article 23).
Latin America and the United States
Status on September 26, 2026; we make no forecasts.
| Where | Instrument | Status |
|---|---|---|
| Brazil | PL 2338/2023 | Passed the Senate (Dec 10, 2024); in a Chamber special committee |
| Chile | Boletín 16821-19 | Passed the Chamber (sent to the Senate Oct 13, 2025); in the Senate |
| Peru | Law 31814, DS 115-2025-PCM | Regulation in force; private-sector phase-in of 1 to 4 years |
| Mexico | Federal initiatives | Not confirmed on official portals: check locally |
| US federal | EO 14179, 14365, 14409 | Deregulation and pressure on state laws |
| Colorado | SB26-189 | Duties for consequential decisions from Jan 1, 2027 |
| California | SB 53 | Frontier developers: safety frameworks, incident reports |
| Texas | TRAIGA (HB 149) | In force since Jan 1, 2026 |
In the ILIA 2025 index (CEPAL and CENIA), Colombia ranks 4th of 19 countries with 55.84 points, behind Chile, Brazil and Uruguay and ahead of Peru (51.93) and Mexico (47.03). Peru's regulation already classifies uses as prohibited, high-risk or acceptable and requires advance transparency for high-risk systems (Article 25).
In the US, EO 14409 (June 2, 2026) sets up voluntary government testing of frontier models with advanced cyber capabilities, with no licensing. EO 14365 set up a task force to challenge state AI laws, yet states keep legislating: if you sell HR, lending or insurance software there, plan for Colorado in 2027 (notice, explanation of adverse outcomes, human review).
A 10-step plan, with ISO/IEC 42001 as the skeleton
Standards. ISO/IEC 42001:2023 is the certifiable AI management system; ISO/IEC 42005:2025 covers impact assessment and ISO/IEC 42006:2025 the certification bodies. NIST's AI RMF (2023) remains the US reference, though it is under revision. CEN-CENELEC is preparing the AI Act's harmonised standards: prEN 18286 on quality management reached public enquiry on October 30, 2025.
Procurement. You will mostly see vendors' 42001 certificates, from Anthropic, AWS or Microsoft: they cover the vendor's management system, not your use case. Our rule: use 42001 as the skeleton, map the AI Act and Law 1581 onto it, and certify when a client or tender asks. Here is the order we recommend for a mid-size company:
| # | Step | Legal anchor | When |
|---|---|---|---|
| 1 | Inventory AI systems and models, and your role in each | AI Act Arts. 2 and 25 | Now |
| 2 | Rule out prohibited uses; safeguard image and video generators | Art. 5 | Now; Dec 2, 2026 |
| 3 | Classify risk; document Article 6(3) exemptions | Art. 6, Annex III | Before Dec 2, 2027 |
| 4 | Disclose chatbots, mark outputs, label deepfakes | Art. 50 | Already due |
| 5 | Documented, role-based AI training | Art. 4 | Ongoing |
| 6 | DPIA for the EU, privacy impact study for Colombia | GDPR Art. 35; SIC Circular 002 | Before each project |
| 7 | Settle the legal basis: legitimate interest or authorization | EDPB 28/2024; Law 1581 | Before processing |
| 8 | Processor, transmission and supplier contracts; vendor documentation | GDPR Art. 28; Decree 1074; AI Act Art. 53 | Before go-live |
| 9 | Human review of automated decisions; keep logs | GDPR Art. 22; AI Act Art. 26 | Now; Art. 26 in Dec 2027 |
| 10 | EU representatives if needed; RNBD if assets exceed 100,000 UVT; quarterly review | AI Act Arts. 22 and 54; GDPR Art. 27; Decree 1074 | Now |
Start with steps 1, 4 and 8: the inventory shows where you stand, transparency is already enforceable and contracts take time. Our AI consulting team can help you set priorities.
Key takeaways
- The AI Act has applied since August 2, 2026, and Article 50 transparency is already enforceable.
- The Omnibus moved high-risk rules to December 2027 and August 2028 and adds new bans from December 2, 2026.
- A Colombian company is in scope when its AI output is used in the EU (Article 2(1)(c)).
- Colombia has no AI law yet, but Law 1581 and SIC Circular 002 de 2024 already require authorization, impact studies and accountability.
- One governance system on ISO/IEC 42001; start with inventory, transparency and contracts.
Sources
- Regulation (EU) 2026/1744 (Digital Omnibus on AI)
- AI Omnibus enters into force
- AI Act, Article 2: Scope
- The General-Purpose AI Code of Practice (signatories)
- Opinion 28/2024 on data protection aspects of AI models
- Les fiches pratiques IA
- Circular Externa 002 de 2024: tratamiento de datos personales en sistemas de inteligencia artificial
- Ley Estatutaria 1581 de 2012
- Proyecto de Ley 025 de 2026 Cámara (inteligencia artificial)
- Documento CONPES 4144: Política Nacional de Inteligencia Artificial
- Executive Order 14409: Promoting Advanced Artificial Intelligence Innovation and Security
- ISO/IEC 42001:2023 Artificial intelligence: Management system
Editorial note: this analysis reflects the public information available on the review date. Models, prices and rules change fast; every third-party figure links to its source, and our opinions are labeled as such. Spotted an error? Write to contact@slash-digital.io.
The questions we hear often
Does the EU AI Act apply to a company based in Colombia?
Yes, when it places AI systems or models on the EU market, or when the output of its AI system is used in the EU (Article 2(1)(a) and (c)). Non-EU providers of high-risk systems or GPAI models also need an EU authorised representative, and the GDPR may require a representative too (Article 27).
What did the AI Omnibus change?
Regulation (EU) 2026/1744, in force since July 27, 2026, moved high-risk obligations to December 2, 2027 (Annex III) and August 2, 2028 (Annex I), softened the AI literacy duty, added bans on non-consensual intimate imagery and child sexual abuse material from December 2, 2026, and gave generators already on the market until that date to mark outputs. Article 50 was not postponed.
Does Colombia have an AI law?
Not as of September 26, 2026. The government bill was archived and PL 025 de 2026 Cámara is still a bill. Law 1581 of 2012, SIC Circular Externa 002 de 2024 and Law 2502 of 2025 already apply to AI projects.
Is AI literacy training mandatory?
Article 4 requires providers and deployers to take measures to support the AI literacy of the people operating AI for them, without guaranteeing a specific level. It is not in the Article 99(4) fine list, so sanctions depend on national law; documented training is still the simplest evidence.
Do we need ISO/IEC 42001 certification?
Neither the AI Act nor Colombian law requires it. It is a voluntary, certifiable management system that organises inventory, risk and controls, and large vendors already hold it. Use it as a framework; certify when clients or tenders ask.
More analysis to read next
Rights and provenance of AI content
Who owns AI output? Lawsuits and settlements, vendor indemnities, likeness and voice, AI Act Article 50, C2PA, SynthID and a practical policy for brand teams.
Local AI and open weightsUncensored models: what they are and what they risk
What removing a model's safeguards really means, why the ecosystem exists, what it breaks, what the law bans in 2026 and what to use instead.
ModelsClaude Opus 5.5: what changes for businesses
Launched September 22, 2026: cheaper than Opus 5, Fable 5.1-level results per Anthropic. Pricing, benchmarks, breaking changes and when to use it.
Let's put it in production
Tell us your challenge. We reply within 24 business hours with an honest first read: if we can help, we'll say how; if not, we'll say who can.
I reply personally. No endless forms, no canned replies.