Audience: Colombian AI developers and government agencies, LATAM enterprises subject to CONPES obligations, Andean Community technology companies, compliance teams managing multi-jurisdiction Latin American deployments, and organizations aligning with OECD AI Principles.
National AI policy adopted with $116M investment. Four-tier risk classification active. Colombia adopted CONPES 4144 on February 14, 2025, establishing the National Artificial Intelligence Policy. The policy organizes action around six strategic axes with 106 concrete actions through 2030 and a multi-year investment of COP 479 billion (approximately USD 116 million). Led by the Department of National Planning and MinTIC, the framework uses a four-tier risk classification: prohibited, high-risk, limited-risk (transparency obligations), and low/minimal risk. A draft bill submitted July 2025 proposes a binding legal framework with Ministry of Science-led governance.
Contents
1. Colombia AI Regulatory Landscape 2. Key Policy Instruments 3. Six Strategic Axes 4. Risk Classification System 5. Obligation-to-Procedure Mapping 6. SWT3 Procedure Cards 7. Quick Reference 8. Quick Start 9. References1. Colombia AI Regulatory Landscape
Colombia is Latin America's fourth-largest economy and a regional leader in digital government transformation. The country's AI ecosystem spans financial services (Bancolombia, Nequi), government digital services (GOV.CO platform), healthcare, agriculture, and a growing startup sector concentrated in Bogota and Medellin. Colombia is an OECD member since 2020 and has committed to implementing the OECD AI Principles.
CONPES 4144 represents the most detailed national AI policy in the Andean Community. Unlike Brazil's AI Act (a binding law) or Peru's AI regulatory framework, Colombia's approach combines a comprehensive policy document with concrete investment commitments and a phased implementation timeline through 2030. The policy is coordinated across 14 government entities, with the Department of National Planning (DNP) and the Ministry of Information and Communications Technology (MinTIC) as lead agencies.
Colombia's regulatory trajectory is moving from policy to legislation. A draft AI bill submitted in July 2025 proposes binding obligations including a national AI registry, algorithmic impact assessments for high-risk systems, and a governance structure led by the Ministry of Science, Technology, and Innovation. Organizations operating in Colombia should treat CONPES 4144 as the current compliance baseline and the draft bill as the near-term binding framework.
2. Key Policy Instruments
| Instrument | Scope | Status |
|---|---|---|
| CONPES 4144 (Feb 2025) | National AI Policy: six strategic axes, 106 actions, four-tier risk classification, COP 479B investment through 2030. | Adopted |
| Draft AI Bill (Jul 2025) | Proposed binding law: national AI registry, algorithmic impact assessments, Ministry of Science governance, penalties. | Draft / Legislative review |
| Law 1581 of 2012 (Habeas Data) | Personal data protection, consent, data subject rights, Superintendencia de Industria y Comercio (SIC) enforcement. | In force |
| OECD AI Principles (2019) | Transparency, accountability, fairness, robustness, human oversight. Colombia committed as OECD member. | Binding commitment |
| Decreto 1078 of 2015 (Digital Government) | Digital services framework, GOV.CO platform requirements, public sector AI adoption guidelines. | In force |
3. Six Strategic Axes
CONPES 4144 organizes its 106 actions across six strategic axes. Each axis creates distinct evidence obligations for AI systems operating in Colombia.
Axis 1: AI Governance and Ethics
Establishes the risk classification system, ethical guidelines, and institutional governance structures. Requires organizations deploying high-risk AI to implement governance frameworks with clear accountability chains and oversight mechanisms.
Axis 2: Data Infrastructure and Interoperability
Mandates data quality standards, interoperability frameworks, and open data initiatives for AI development. Organizations must demonstrate data provenance and quality controls for training data used in systems deployed in Colombia.
Axis 3: Talent and Capacity Building
Invests in AI education and workforce development. While primarily government-facing, organizations deploying AI in regulated sectors must demonstrate staff competency and training records for AI system operators.
Axis 4: Innovation and Productive Development
Creates sandboxes, innovation hubs, and incentives for responsible AI adoption. Organizations participating in regulatory sandboxes must maintain evidence of compliance with sandbox conditions.
Axis 5: Adoption in Public Administration
Requires government agencies adopting AI to implement transparency, accountability, and impact assessment requirements. Government contractors and vendors must meet these obligations as a condition of public procurement.
Axis 6: International Cooperation and Standards
Aligns Colombia with OECD AI Principles, UNESCO Recommendation on the Ethics of AI, and regional frameworks. Multi-jurisdiction deployments benefit from demonstrating alignment with international standards Colombia has adopted.
4. Risk Classification System
CONPES 4144 introduces a four-tier risk classification aligned with international best practices. The classification determines the depth and frequency of evidence obligations.
| Tier | Definition | Evidence Depth |
|---|---|---|
| Prohibited | AI applications that violate fundamental rights, social scoring by government, subliminal manipulation. | Not deployable. No evidence path. |
| High-Risk | AI in healthcare, financial services, criminal justice, education, employment, critical infrastructure, biometric identification. | Full: governance, impact assessment, continuous monitoring, human oversight, transparency. |
| Limited-Risk | AI systems with transparency obligations: chatbots, content generation, emotion recognition. | Transparency disclosures, user notification, content labeling. |
| Low/Minimal Risk | AI applications with minimal impact: spam filters, content recommendation, internal tools. | Voluntary best practices. Recommended: basic inference logging. |
5. Obligation-to-Procedure Mapping
| CONPES Obligation | Evidence Needed | SWT3 Procedure |
|---|---|---|
| Risk classification and impact assessment (Axis 1) | Risk tier documentation, algorithmic impact assessment records, classification rationale | AI-RISK.1, AI-IMPACT.1 |
| AI governance framework (Axis 1) | Governance structure, accountability assignments, oversight procedures, ethics review records | AI-GOV.1 |
| Transparency and disclosure (Axis 1, 5) | User notification records, AI system identification, decision explanation, content labeling | AI-TRANS.1, AI-EXPL.1 |
| Data quality and provenance (Axis 2) | Training data documentation, data source records, quality metrics, provenance chain | AI-DATA.1 |
| Human oversight for high-risk systems (Axis 1) | Human reviewer records, override capability, review latency, escalation procedures | AI-HITL.1 |
| Fairness and non-discrimination (Axis 1) | Bias evaluation records, demographic analysis, fairness metrics, remediation actions | AI-FAIR.1 |
| Inference record-keeping (Axis 1, 5) | Inference provenance, model identity, input/output hashes, decision timestamps | AI-INF.1, AI-LOG.1 |
| Personal data protection (Law 1581) | Consent records, purpose limitation, data subject access, SIC compliance documentation | AI-CONSENT.1, AI-DATA.1 |
| Model robustness and safety (Axis 1) | Testing records, adversarial evaluation, performance monitoring, drift detection | AI-ROBUST.1, AI-DRIFT.1 |
| Continuous monitoring (Axis 1, 5) | Ongoing performance metrics, drift thresholds, alert records, remediation actions | AI-DRIFT.1, AI-PERF.1 |
| Audit trail and accountability (Axis 1) | Complete decision chain, responsible party identification, audit log integrity | AI-AUDIT.1, AI-LOG.1 |
| OECD AI Principles alignment (Axis 6) | Cross-framework evidence, international standard compliance records | AI-GOV.1, AI-FAIR.1, AI-TRANS.1 |
6. SWT3 Procedure Cards
Algorithmic Impact Assessment
Colombia context: CONPES 4144 Axis 1 requires impact assessments for high-risk AI systems. The draft AI bill proposes mandatory algorithmic impact assessments (AIAs) for systems affecting healthcare, financial services, employment, and public administration. Colombia's SIC (Superintendencia de Industria y Comercio) is expected to review impact assessments for systems processing personal data under Law 1581.
SWT3 evidence: AI-IMPACT.1 anchors record the impact assessment was conducted, assessment methodology, risk categories evaluated, affected populations identified, and mitigation measures documented. Each assessment produces a tamper-evident fingerprint that regulators can independently verify.
For financial AI (credit scoring, fraud detection), verify the impact assessment addresses Colombia's banked and unbanked populations separately. Nequi and Daviplata serve millions of previously unbanked Colombians -- impact assessments must account for financial inclusion effects.
AI Governance Framework
Colombia context: CONPES 4144 assigns governance responsibilities across 14 government entities and expects private sector organizations deploying high-risk AI to establish comparable governance structures. The draft bill proposes that the Ministry of Science, Technology, and Innovation serve as the national AI governance authority. Organizations must demonstrate clear accountability chains from AI system operation to responsible individuals.
SWT3 evidence: AI-GOV.1 anchors record governance structure, responsible parties, oversight meeting records, and policy update history. The anchor chain provides a verifiable timeline of governance activities that survives personnel changes and organizational restructuring.
Verify governance records identify named individuals (not just roles) with accountability for AI system decisions. For public sector AI, confirm alignment with Decreto 1078 digital government requirements and GOV.CO platform standards.
Transparency Disclosure
Colombia context: Both CONPES 4144 and the draft bill require transparency disclosures when AI systems interact with individuals or affect their decisions. For public administration AI (Axis 5), transparency is a constitutional obligation. Limited-risk systems such as chatbots must clearly identify themselves as AI. Colombia's multilingual context -- Spanish is official, but indigenous languages are protected under the 1991 Constitution -- may require disclosure accessibility considerations.
SWT3 evidence: AI-TRANS.1 anchors record that disclosures were delivered, the disclosure method, language, content, and timestamp. Combined with AI-EXPL.1, organizations demonstrate both notification and the capacity for meaningful explanation.
For government-facing AI systems, verify transparency disclosures comply with GOV.CO accessibility standards. For consumer-facing AI, confirm disclosures are in Spanish and accessible to the target population. Rural deployments may require consideration of literacy and connectivity constraints.
Data Provenance and Quality
Colombia context: CONPES 4144 Axis 2 establishes data infrastructure and interoperability requirements. AI systems must demonstrate data quality controls, source documentation, and compliance with Law 1581 (Habeas Data) when processing personal information. The SIC enforces data protection obligations and has authority to investigate data practices underlying AI systems.
SWT3 evidence: AI-DATA.1 anchors record data source identification, quality metrics, collection methodology, and consent basis. The evidence chain connects training data provenance to the deployed model, creating an auditable path from data origin to inference output.
Verify data provenance records distinguish between Colombian-sourced data and imported datasets. For AI systems trained on international data and deployed in Colombia, confirm the training data reflects Colombian population characteristics and that cross-border data transfer requirements under Law 1581 are satisfied.
Continuous Monitoring and Drift Detection
Colombia context: CONPES 4144 requires ongoing monitoring of high-risk AI systems, not just pre-deployment assessment. The policy recognizes that AI system behavior can degrade over time due to data drift, concept drift, or environmental changes. For financial services AI, the Superintendencia Financiera de Colombia (SFC) expects continuous risk monitoring aligned with existing prudential supervision requirements.
SWT3 evidence: AI-DRIFT.1 anchors record monitoring infrastructure is active, drift thresholds are configured, and alerts are generated when performance degrades. Combined with AI-PERF.1, organizations demonstrate both detection capability and response procedures.
For financial AI under SFC supervision, verify drift thresholds align with existing model risk management requirements. Check that drift detection covers both statistical drift (data distribution) and outcome drift (decision quality). Verify anchor continuity -- gaps in the monitoring chain indicate periods without oversight.
Fairness Evaluation
Colombia context: Colombia's 1991 Constitution guarantees equality and prohibits discrimination. CONPES 4144 extends these protections to AI systems, requiring fairness evaluation across relevant demographic dimensions. Colombia's population includes significant Afro-Colombian (approximately 10%), indigenous (approximately 4%), and internally displaced populations -- AI fairness evaluations must address locally relevant dimensions rather than imported demographic categories.
SWT3 evidence: AI-FAIR.1 anchors record evaluation methodology, demographic dimensions tested, metrics applied, and results. The evidence is produced at evaluation time, not reconstructed for audit, ensuring assessment integrity.
Verify fairness evaluation includes Colombian-specific dimensions: geographic region (urban/rural, conflict-affected areas), ethnic group, displacement status, and socioeconomic stratum (estratos 1-6). Standard North American or European demographic categories are not sufficient for Colombian compliance.
7. Quick Reference
| Regulator Question | Where to Look |
|---|---|
| Has an algorithmic impact assessment been conducted? | AI-IMPACT.1 anchors with assessment methodology, risk categories, affected populations, and mitigation measures. |
| What risk tier is this system classified under? | AI-RISK.1 anchors with classification rationale. High-risk: healthcare, finance, employment, public administration, biometrics. |
| Is there a governance framework with named accountability? | AI-GOV.1 anchors with governance structure, responsible individuals, oversight records, policy update history. |
| Are users informed when AI affects their decisions? | AI-TRANS.1 anchors with disclosure method, language, and delivery confirmation. Verify Spanish accessibility. |
| Is the system monitored for performance drift? | AI-DRIFT.1 and AI-PERF.1 anchors showing continuous monitoring and threshold configuration. |
| Has the system been evaluated for bias? | AI-FAIR.1 anchors with Colombian-relevant demographic dimensions (region, estrato, ethnicity, displacement). |
| Is personal data processing compliant with Law 1581? | AI-CONSENT.1 and AI-DATA.1 anchors with consent basis, purpose limitation, SIC alignment. |
| Are inference decisions recorded for high-risk systems? | AI-INF.1 and AI-LOG.1 anchors with decision provenance. Verify no gaps in anchor timeline. |
| Does the system meet OECD AI Principles? | Cross-reference AI-GOV.1, AI-FAIR.1, AI-TRANS.1, AI-ROBUST.1 anchor coverage against five OECD principles. |
8. Quick Start
# Install the SDK
pip install swt3-ai
from swt3_ai import WitnessClient
client = WitnessClient(
tenant_id="your-tenant-id",
api_key="axm_live_..."
)
# Record algorithmic impact assessment for financial AI
client.witness_impact_assessment(
model_id="credito-scoring-v2",
assessment_method="algorithmic_impact_assessment",
risk_tier="high",
affected_populations=["unbanked", "rural", "displaced"],
jurisdiction="CO"
)
# Record transparency disclosure
client.witness_transparency(
model_id="credito-scoring-v2",
disclosure_method="web_notification",
disclosure_language="es",
content_type="credit_decision_explanation",
jurisdiction="CO"
)
# Record fairness evaluation with Colombian-specific dimensions
client.witness_fairness_evaluation(
model_id="credito-scoring-v2",
evaluation_method="disparate_impact_analysis",
demographic_groups=["gender", "region", "estrato", "ethnicity"],
pass_threshold=0.8,
result="pass",
jurisdiction="CO"
)
# Run the demo
python -m swt3_ai.demo
SDK Documentation | Create a free account
9. References
- CONPES 4144: Politica Nacional de Inteligencia Artificial (February 2025) -- Departamento Nacional de Planeacion
- Draft AI Bill (July 2025) -- Congreso de la Republica de Colombia
- Law 1581 of 2012 (Habeas Data) -- Republica de Colombia
- Decreto 1078 of 2015 -- Digital Government Framework
- OECD AI Principles (2019) -- Organisation for Economic Co-operation and Development
- Superintendencia de Industria y Comercio (SIC) -- sic.gov.co
- Superintendencia Financiera de Colombia (SFC) -- superfinanciera.gov.co
- Brazil AI Act Crosswalk (SWT3 Protocol)
- Peru AI Law Crosswalk (SWT3 Protocol)
- SWT3 SDK Documentation
- Create a free account