Information Technology 2026

CHILE Law and Practice Contributed by: Carolina Cabrera, LawTech

and public-sector decision-making are likely to receive closer attention. Authorities such as the Data Protec - tion Agency, the National Cybersecurity Agency, the CMF, SUBTEL, consumer authorities and digital gov - ernment bodies may each play a role. Third, private compliance and contracting will con - tinue to develop before the statutory framework is fully settled. Companies are already addressing AI through procurement policies, acceptable use rules, ven - dor due diligence, governance committees, impact assessments, model risk controls, cybersecurity requirements and clauses on training data, outputs, confidentiality, IP, auditability, explainability, liability and incidents. Overall, Chile’s AI regulation is expected to become more formal, but not through one instrument alone. The likely model is a combination of a general AI law, regulatory guidance, sector enforcement, data pro - tection, cybersecurity and increasingly sophisticated contractual governance. 8.2 Standards in Contract Drafting Technology contract drafting in Chile has become more modular, operational and focused on risk allo - cation. Rather than relying on a single services agree - ment, sophisticated projects are commonly structured through a master agreement supported by statements of work, data processing agreements, security sched - ules, SLAs, cloud or SaaS addenda, continuity provi - sions and, increasingly, AI-specific clauses. A clear development is the greater importance of data protection and cybersecurity drafting. Contracts now include more detailed clauses on controller/processor roles, transfers, subprocessors, data location, breach notification, security measures, audit rights, encryp - tion, access controls, vulnerability management, inci - dent response, forensic support, continuity, disaster recovery and secure deletion or return. Cloud and SaaS contracts have changed negotia - tion dynamics. Global providers often resist changes to standard terms, so negotiation focuses on order forms, service descriptions, support terms, DPAs, security documentation, service credits, termination assistance and regulatory requirements.

Liability clauses have also become more granular, with differentiated caps or carve-outs for confidentiality, personal data, cybersecurity, IP infringement, fraud, wilful misconduct, gross negligence, supplier-caused regulatory fines, payment obligations and audit or compliance duties. AI is an emerging drafting area. Clauses now address permitted use of AI tools, training data, prompts, out - puts, model improvement, confidentiality, IP owner - ship, third-party rights, hallucinations, bias, explain - ability, auditability, human review, prohibited uses and responsibility for AI-generated content. Pricing has also become more flexible, combining fixed price, time-and-materials, subscriptions, consump - tion, capacity-based teams, minimum commitments, true-ups, service credits and milestones. 8.3 Hyperscalers Hyperscalers such as Microsoft, AWS and Google have significantly changed technology contract nego - tiations in Chile. Their influence has reduced the scope for bespoke negotiation of core cloud terms, while increasing the importance of due diligence, regula - tory alignment, technical architecture, security docu - mentation, exit planning and risk allocation across the cloud supply chain. In most cases, hyperscalers operate on standard glob - al terms and are reluctant to amend core documents. Negotiation therefore shifts away from the main terms and into order forms, service descriptions, support plans, data processing addenda, security documenta - tion, SLAs, enterprise agreements and the customer’s cloud architecture. This has made pre-contractual review more impor - tant. Customers focus on where data is stored and accessed, subprocessors, certifications, audit reports, incident notification, continuity commitments, service credits, export/deletion at termination and support obligations. For regulated customers, especially in financial servic - es, the challenge is reconciling global cloud terms with local requirements on outsourcing, cybersecurity, data protection, continuity, auditability, regulatory access, incident reporting and supplier risk management. This

26 CHAMBERS.COM

Powered by