CHILE Trends and Developments Contributed by: Carolina Cabrera, LawTech
This evolution is encouraging the development of shared accountability models. Rather than assigning responsibility entirely to one party, organisations and providers are increasingly recognising that effective AI governance requires collaboration throughout the technology life cycle. Providers may be expected to explain system limita - tions, disclose relevant information and support moni - toring activities. Clients, meanwhile, continue to play a critical role in ensuring that AI systems are deployed appropriately and in accordance with legal, ethical and business requirements. Cybersecurity and Operational Resilience Cybersecurity is increasingly regarded as one of the defining regulatory issues of the digital economy. Chile’s Cybercrime Law has modernised the legal framework applicable to offences affecting informa - tion systems, data integrity and digital services. By aligning Chile with the standards established under the Budapest Convention, the legislation reflects growing recognition that cyber incidents are not merely tech - nical events but also legal, operational and business risks capable of generating significant consequences for organisations and their service providers. Together, the Cybercrime Law and the Cybersecurity Framework Law signal a clear regulatory expecta - tion that organisations should adopt more mature approaches to cybersecurity governance, incident management and operational resilience. This expec - tation increasingly extends beyond internal operations and encompasses the management of risks arising throughout technology supply chains and outsourced service arrangements. For organisations undertaking digital transformation initiatives, cybersecurity is increasingly viewed as a matter of governance, regulatory compliance and risk management rather than solely a technical issue. Clients increasingly expect providers to demonstrate that appropriate security measures are embedded within their services. Common requirements include: • incident detection and response capabilities;
• vulnerability management programmes; • business continuity arrangements; • disaster recovery planning; • employee security awareness training; and • regular testing and security assessments.
Consequently, cybersecurity considerations are becoming more prominent not only in technology design but also in procurement strategies, contractual negotiations and vendor management programmes. The Evolution of Technology Contracting The cumulative effect of these regulatory develop - ments is transforming the way technology contracts are negotiated and structured. For organisations procuring complex technology solu - tions, contractual negotiations increasingly serve as a mechanism for addressing regulatory and operational risks rather than merely defining commercial terms. Market practice suggests that discussions concerning cybersecurity governance, data protection account - ability, supplier oversight, operational resilience and AI-related responsibilities are becoming increasingly important components of technology contracting dis - cussions. Historically, technology agreements focused primarily on commercial and operational matters. Key areas of negotiation included pricing, service levels, intellec - tual property rights and implementation obligations. Whilst these topics remain important, regulatory con - siderations now occupy a more prominent role within contractual discussions. Modern technology agreements increasingly address issues such as: • privacy and data protection obligations; • cybersecurity requirements; • incident management procedures; • AI governance responsibilities;
• audit and oversight rights; • subcontractor management; • operational resilience measures; and • regulatory co-operation obligations.
33 CHAMBERS.COM
Powered by FlippingBook