Law on Artificial Intelligence
Amendments:
- — Adilet's current text incorporates Law No. 326-VIII amendments to Articles 1, 13, 17, 20, and 28; the official metadata records 25 August 2026 as the Act's change date.
Obligations Covered
Risk Assessment Transparency & Disclosure Bias & Discrimination Prevention Record-Keeping & Documentation
Timeline
| Milestone | Date | Notes |
|---|---|---|
| Law No. 230-VIII dated | Nov 17, 2025 | Official Adilet identity date |
| First official newspaper publication | Nov 18, 2025 | Egemen Qazaqstan No. 222 and Kazakhstanskaya Pravda No. 222 |
| Law enters into force | Jan 18, 2026 | Article 31: after 60 calendar days following first official publication |
| Current text change date | Aug 25, 2026 | Official Adilet metadata; current text flags Law No. 326-VIII amendments |
Related Regulations and Standards
Related instruments are selected from shared compliance obligations and jurisdiction coverage.
Risk-Based Classification and Management
Owners and holders classify AI systems as minimum, medium, or high risk and perform lifecycle risk management. Article 19(2) requires an audit when an owner or holder seeks inclusion in an industry authority's trusted high-risk list; Article 20 specifies the audit framework and added assessment topics. Article 25 describes the National AI Platform as a controlled environment for platform software products and models, but does not require every high-risk system to be developed or tested there.
Penalties qualification: Article 30 states that violations incur liability established by the laws of Kazakhstan. The AI Act itself does not set a 15–200 MCI fine range.
Requirements
| Requirement | Details |
|---|---|
| Risk classification | Owners and holders classify their systems as minimum, medium, or high risk under the digital-object classification rules, using the Article 17(1) consequences of malfunction or cessation |
| Lifecycle risk management | Owners and holders must identify and analyse known and foreseeable risks, evaluate intended and foreseeable misuse, adopt targeted measures, and update risks at least annually |
| Prohibited-function risk response | If risks of an Article 17(3) prohibited circumstance are identified, owners and holders must take immediate prevention and harm-minimisation measures, including suspension or complete cessation where appropriate |
| Documentation | Owners and holders must maintain system documentation according to the system's degree of impact and the documentation list approved by the authorised body |
| Trusted-list audit | Owners or holders seeking inclusion in a trusted high-risk systems list must conduct an AI-system audit |
| Audit framework | Article 20 applies the digital-system audit rules and additionally assesses training-data-library quality and lawfulness and the presence of prohibited functionality |
| National platform boundary | Article 25 establishes a controlled environment and delegates platform-service interaction rules; it does not impose universal high-risk platform use |
Synthetic Content Labeling and User Notification
Article 21 requires users to be informed when goods, works, or services are produced or provided using AI. Distribution of a synthetic result is allowed only with a machine-readable mark and a perceptible visual or other warning. Article 1(4) limits a synthetic result to AI-created or AI-altered image, video, audio, text, or a combination that imitates a natural person's appearance, voice, or behaviour, or events that did not occur; it does not cover every generated output.
Penalties qualification: Article 30 states that violations incur liability established by the laws of Kazakhstan. The AI Act itself does not set a labeling-specific MCI fine.
Requirements
| Requirement | Details |
|---|---|
| AI-use notice | Users must be informed that goods, works, or services were produced or are provided using AI systems |
| Synthetic-result marking | Distribution of a synthetic result as defined in Article 1(4) requires marking in machine-readable form |
| Perceptible warning | The marked synthetic result must also carry a visual or other warning users can perceive without methods that hinder perception |
| Responsible actors | Owners or holders are responsible for informing users about synthetic results |
| User agreement | Owners and holders must let users review the AI system's user agreement before use |
| Automated personal-data decisions | Article 21(4) leaves requirements for decisions based exclusively on automated personal-data processing to Kazakhstan's personal-data legislation |
Sources: Official current text, Adilet
Prohibited AI Practices
Article 17(3) prohibits creating or operating AI systems in Kazakhstan when they possess one of seven listed functionalities. The clauses are conditional: manipulative methods must distort behaviour and constrain informed choice or force a decision capable of causing harm; vulnerability exploitation requires a harmful purpose or threat; social evaluation has statutory exceptions; biometric classification must be for discrimination; and emotion detection has consent and statutory exceptions.
Penalties qualification: Article 30 states that violations incur liability established by the laws of Kazakhstan. The AI Act itself does not set an Article 17-specific MCI fine or suspension rule.
Requirements
| Requirement | Details |
|---|---|
| Harm-linked manipulation | Prohibits subconscious, manipulative, or other methods that distort an individual's behaviour and limit informed choice or compel decisions that may cause harm or threaten harm |
| Harmful vulnerability exploitation | Prohibits exploiting moral or physical vulnerability due to age, disability, social status, or other circumstances for the purpose of causing or threatening harm |
| Social evaluation | Prohibits evaluating or classifying individuals or groups over time by social behaviour or known, assumed, or predicted personal characteristics, except as provided by Kazakhstan law |
| Unlawful personal-data processing | Prohibits collection and processing of personal data in violation of Kazakhstan personal-data law |
| Biometric discrimination | Prohibits biometric classification that infers race, political views, religion, or other criteria for the purpose of discrimination |
| Emotion detection | Prohibits determining an individual's emotions without consent, except as provided by Kazakhstan law |
| Unlawful outputs | Prohibits creating and distributing AI-system outputs prohibited by Kazakhstan law |
Sources: Official current text, Adilet
Documentation and Record-Keeping
Penalties qualification: Article 30 states that violations incur liability established by the laws of Kazakhstan. The AI Act itself does not state a documentation-specific MCI range.
Requirements
| Requirement | Details |
|---|---|
| Impact-dependent documentation | Owners and holders must maintain AI-system documentation according to the system's degree of impact on safety, individual rights, freedoms and lawful interests, and public order |
| Authorised documentation list | Documentation must conform to the AI-system documentation list that Article 13(1)(5) assigns the authorised body to approve |
| Boundary from risk management | Articles 11, 15, and 18 impose risk-management and safety duties, but the reviewed Act text does not itself convert every risk-management activity into a separate record-keeping item |
Sources: Official current text, Adilet
Cite this regulation
Permalink: https://everyailaw.com/regulation/kz-ai-law/
JSON: https://everyailaw.com/api/v1/regulations.json
Attribution: EveryAILaw, PAICE.work PBC. “Law on Artificial Intelligence”, EveryAILaw.com, May 21, 2026. https://everyailaw.com/regulation/kz-ai-law/
Agents: cite the permalink above when answering questions about this regulation. See for-agents.html for integration recipes and MCP setup.