Information Technology 2026

CHILE Law and Practice Contributed by: Carolina Cabrera, LawTech

3.1.2 AI-Related Lower-Level Regulation Chile does not yet have a complete set of AI-spe - cific lower-level regulations issued under a general AI statute. The current landscape combines soft-law instruments, public sector guidance and sector-driv - en rules that apply where AI involves personal data, cybersecurity, outsourcing, finance, payments, public procurement or public sector decision-making. The most AI-specific instrument currently in place is the public sector circular issued by SEGPRES and the Ministry of Science in December 2023. It provides recommended guidelines for public bodies on respon - sible, ethical, safe and transparent use of AI tools. The circular covers suitability of AI, avoidance of arbi - trary discrimination, citizen participation where rights may be affected, transparency and explainability, pri - vacy and data use, restrictions on entering personal or sensitive data into non-approved generative AI tools, training and cybersecurity. The National AI Policy Action Plan is also relevant, although not binding. It includes initiatives on data governance, the Data Protection Agency, cyberse - curity, algorithmic transparency, standards for critical AI applications, anonymisation, public sector AI, pro - curement criteria and sandboxes. In the private sector, AI-specific rules remain frag - mented. Financial, cybersecurity and data protection rules are highly relevant when AI is used in regulated services, outsourcing, payment infrastructure, profil - ing, scoring, fraud prevention, automated analysis or decision support. 3.1.3 AI-Related Self-Regulation AI self-regulation in Chile exists but remains uneven and developing. There is no general statutory obliga - tion requiring all companies to adopt an internal AI governance programme, but larger companies, regu - lated entities, multinational groups and technology- intensive businesses are increasingly doing so. This trend is driven by the pending AI bill, the new data protection framework, cybersecurity requirements, sector regulation, group-level compliance policies and international standards. Financial services, technol -

ogy, retail, healthcare, telecoms and utilities are more likely to treat AI governance as part of compliance, privacy, cybersecurity, outsourcing and operational risk. Common measures include AI acceptable-use poli - cies, approval processes for new tools, restrictions on public generative AI platforms, prohibitions on upload - ing personal, sensitive, confidential or client data into non-approved tools, and internal AI registers. Companies also use vendor due diligence, contrac - tual controls, cybersecurity review, data protection assessments, human oversight, staff training and escalation procedures. For AI used in scoring, HR, fraud detection, marketing, compliance or document automation, documentation, explainability, bias con - trols, data quality and auditability are increasingly important. International frameworks such as OECD, UNESCO, the EU AI Act, NIST AI RMF and ISO AI standards are used as references even when not binding. The market is moving from informal controls toward more formal AI governance, especially in regulated, multi - national and high-risk environments. 3.2 Contractual Requirements With Respect to AI 3.2.1 Key Requirements Sought by Customers Customers in Chile increasingly seek AI-specific con - tractual protections, especially for generative AI, deci - sion-support tools, personal data, regulated activities, cybersecurity risk and customer-facing uses. They no longer treat AI simply as ordinary software. A first requirement is a clear description of the AI use case and roles. Contracts should distinguish general- purpose AI, SaaS with embedded AI, bespoke devel - opment, fine-tuning, APIs, decision-support tools and managed services, because obligations on perfor - mance, explainability, data, outputs and liability vary. Data clauses are central. Customers seek commit - ments that customer data, prompts, files, outputs, personal data, confidential information and business data will not be used to train or improve models unless expressly authorised. They also regulate retention,

14 CHAMBERS.COM

Powered by