Skip to content
Ceci est une traduction de commodite. La version anglaise est la version officielle et juridiquement contraignante. Voir la version anglaise
Latin AmericaMEDIUM coverage

Colombia — AI Framework under Habeas Data (SIC): AI Compliance Requirements

Colombia's SIC (Superintendencia de Industria y Comercio) Circular Externa 002 of 2024 (21 Aug 2024) addresses processing of personal data in AI systems and automated decision-making under Law 1581 of 2012. Database registration with SIC is required for organizations processing Colombian resident data. Colombia is developing its national AI strategy under Conpes 4023.

Summary of publicly-available regulatory text as of 2026-08-22. Verify against current official sources before relying on this for compliance decisions. Not legal advice.

Key Facts

Effective Date

January 1, 2024

Maximum Penalty

Up to 2,000 times the monthly legal minimum wage (SMLMV) — an inflation-indexed formula, approximately COP 3.5 billion (~$830,000 USD) at 2026's SMLMV, not a fixed sum — plus suspension of data-processing activities for up to 6 months, temporary closure of operations for up to 6 months for material breaches, or permanent closure for persistent non-compliance; criminal liability may attach separately for unauthorized processing.

What Your Business Must Do

1 compliance requirement identified. Critical requirements carry the highest risk of enforcement action.

Register AI Databases with Colombia SIC

Medium Priority

Organizations processing Colombian resident personal data must register databases — including AI training datasets — with the SIC's National Database Registry (RNBD) under Law 1581.

Law 1581 of 2012 (Colombia), as elaborated for AI by SIC Circular Externa 002 of 21 August 2024

Who Does This Apply To?

Applies to: any data controller or processor that processes the personal data of Colombian residents under Law 1581 of 2012, as elaborated for AI and automated decision-making by the Superintendencia de Industria y Comercio (SIC) Circular Externa 002 of 21 August 2024. Organisations processing Colombian personal data must register their databases in the National Database Registry (RNBD) with the SIC; the registration duty is generally tied to the entity's legal form and asset thresholds, while the substantive data-protection duties apply regardless of size. For AI: controllers must have a lawful basis and prior, informed consent, honour data-subject rights (including in relation to automated decisions and profiling), and apply the SIC's demonstrated-accountability (responsabilidad demostrada) expectations to AI systems — privacy-by-design, impact assessments for high-risk processing, and human oversight. Colombia's national AI policy is being developed under the CONPES framework. Enforced by the SIC; administrative fines reach up to 2,000 times the monthly legal minimum wage (SMLMV) — roughly COP 3.5 billion / ~$830,000 USD at 2026's rate, an inflation-indexed figure, not a fixed sum.

Recent Regulatory Guidance

guidance2024-08-21

SIC Circular Externa 002 of 2024 — Personal-data processing in AI systems

Colombia's SIC Circular Externa 002 of 21 Aug 2024 sets guidelines for processing personal data in AI systems under Habeas Data Law 1581/2012: processing must satisfy suitability, necessity, reasonableness and proportionality (strict sense); only strictly necessary data may be collected; information security must be guaranteed; and data subjects retain the rights to know, access, update and delete their data. The SIC stressed that using algorithms or automated decisions does not remove legal accountability — the deploying organisation remains responsible. (Conpes 4023, Colombia's National AI policy, complements this with responsible-AI governance expectations.)

Frequently Asked Questions

Does Colombia — AI Framework under Habeas Data (SIC) apply to my business?

Colombia's SIC (Superintendencia de Industria y Comercio) Circular Externa 002 of 2024 (21 Aug 2024) addresses processing of personal data in AI systems and automated decision-making under Law 1581 of 2012. Database registration with SIC is required… Use Aegis Firma's free scanner to get a personalized assessment in under 5 minutes.

What is the penalty for non-compliance?

The maximum penalty under Colombia — AI Framework under Habeas Data (SIC) is: Up to 2,000 times the monthly legal minimum wage (SMLMV) — an inflation-indexed formula, approximately COP 3.5 billion (~$830,000 USD) at 2026's SMLMV, not a fixed sum — plus suspension of data-processing activities for up to 6 months, temporary closure of operations for up to 6 months for material breaches, or permanent closure for persistent non-compliance; criminal liability may attach separately for unauthorized processing.. Fines are typically scaled by company size, severity of violation, and whether violations were willful or accidental.

How do I comply with Colombia — AI Framework under Habeas Data (SIC)?

The 1 requirements above cover the core obligations. The fastest path to compliance is: (1) conduct an AI risk assessment, (2) document your AI systems, (3) implement transparency disclosures where required. Aegis Firma generates all required documents automatically.

Official Source

https://www.sic.gov.co/inteligencia-artificial

Last updated: 2026-08-22 — verify at source before relying on this information.

Don't leave compliance to chance

Aegis Firma scans your AI tools, tells you exactly which regulations apply, and generates all required documents — in 30 minutes.

Start your free compliance scan