Law on Artificial Intelligence

Jurisdiction:
Kazakhstan
enforcing
Effective:
Jan 18, 2026
Authority:
Ministry of Artificial Intelligence and Digital Development
Official text
Amendments:
  • — Adilet's current text incorporates Law No. 326-VIII amendments to Articles 1, 13, 17, 20, and 28; the official metadata records 25 August 2026 as the Act's change date.

Obligations Covered

Risk Assessment Transparency & Disclosure Bias & Discrimination Prevention Record-Keeping & Documentation

Timeline

MilestoneDateNotes
Law No. 230-VIII datedNov 17, 2025Official Adilet identity date
First official newspaper publicationNov 18, 2025Egemen Qazaqstan No. 222 and Kazakhstanskaya Pravda No. 222
Law enters into forceJan 18, 2026Article 31: after 60 calendar days following first official publication
Current text change dateAug 25, 2026Official Adilet metadata; current text flags Law No. 326-VIII amendments

Related Regulations and Standards

Related instruments are selected from shared compliance obligations and jurisdiction coverage.

Risk-Based Classification and Management

Copy link to this provision

Obligation:
Risk Assessment
enforcing
Effective:
Jan 18, 2026
Risk tier:
all (tiered obligations)
Scope:
Owners and holders of AI systems; the audit duty in Article 19(2) is limited to systems seeking inclusion in a trusted high-risk list
high-impact
Owners and holders classify AI systems as minimum, medium, or high risk and perform lifecycle risk management. Article 19(2) requires an audit when an owner or holder seeks inclusion in an industry authority's trusted high-risk list; Article 20 specifies the audit framework and added assessment topics. Article 25 describes the National AI Platform as a controlled environment for platform software products and models, but does not require every high-risk system to be developed or tested there. Penalties qualification: Article 30 states that violations incur liability established by the laws of Kazakhstan. The AI Act itself does not set a 15–200 MCI fine range.

Requirements

RequirementDetails
Risk classificationOwners and holders classify their systems as minimum, medium, or high risk under the digital-object classification rules, using the Article 17(1) consequences of malfunction or cessation
Lifecycle risk managementOwners and holders must identify and analyse known and foreseeable risks, evaluate intended and foreseeable misuse, adopt targeted measures, and update risks at least annually
Prohibited-function risk responseIf risks of an Article 17(3) prohibited circumstance are identified, owners and holders must take immediate prevention and harm-minimisation measures, including suspension or complete cessation where appropriate
DocumentationOwners and holders must maintain system documentation according to the system's degree of impact and the documentation list approved by the authorised body
Trusted-list auditOwners or holders seeking inclusion in a trusted high-risk systems list must conduct an AI-system audit
Audit frameworkArticle 20 applies the digital-system audit rules and additionally assesses training-data-library quality and lawfulness and the presence of prohibited functionality
National platform boundaryArticle 25 establishes a controlled environment and delegates platform-service interaction rules; it does not impose universal high-risk platform use

Synthetic Content Labeling and User Notification

Copy link to this provision

Obligation:
Transparency
enforcing
Effective:
Jan 18, 2026
Risk tier:
all
Scope:
Article 21(3) assigns synthetic-result information responsibility to owners and holders, and Article 15(2)(5) assigns user-agreement access to them; Article 21(1) states the user information duty without naming a responsible actor
high-impact
Article 21 requires users to be informed when goods, works, or services are produced or provided using AI. Distribution of a synthetic result is allowed only with a machine-readable mark and a perceptible visual or other warning. Article 1(4) limits a synthetic result to AI-created or AI-altered image, video, audio, text, or a combination that imitates a natural person's appearance, voice, or behaviour, or events that did not occur; it does not cover every generated output. Penalties qualification: Article 30 states that violations incur liability established by the laws of Kazakhstan. The AI Act itself does not set a labeling-specific MCI fine.

Requirements

RequirementDetails
AI-use noticeUsers must be informed that goods, works, or services were produced or are provided using AI systems
Synthetic-result markingDistribution of a synthetic result as defined in Article 1(4) requires marking in machine-readable form
Perceptible warningThe marked synthetic result must also carry a visual or other warning users can perceive without methods that hinder perception
Responsible actorsOwners or holders are responsible for informing users about synthetic results
User agreementOwners and holders must let users review the AI system's user agreement before use
Automated personal-data decisionsArticle 21(4) leaves requirements for decisions based exclusively on automated personal-data processing to Kazakhstan's personal-data legislation

Prohibited AI Practices

Copy link to this provision

Obligation:
Bias Prevention
enforcing
Effective:
Jan 18, 2026
Risk tier:
all
Scope:
Creation and operation in Kazakhstan of AI systems possessing a listed Article 17(3) functionality, subject to each paragraph's harm, purpose, consent, or statutory-exception condition
high-impact
Article 17(3) prohibits creating or operating AI systems in Kazakhstan when they possess one of seven listed functionalities. The clauses are conditional: manipulative methods must distort behaviour and constrain informed choice or force a decision capable of causing harm; vulnerability exploitation requires a harmful purpose or threat; social evaluation has statutory exceptions; biometric classification must be for discrimination; and emotion detection has consent and statutory exceptions. Penalties qualification: Article 30 states that violations incur liability established by the laws of Kazakhstan. The AI Act itself does not set an Article 17-specific MCI fine or suspension rule.

Requirements

RequirementDetails
Harm-linked manipulationProhibits subconscious, manipulative, or other methods that distort an individual's behaviour and limit informed choice or compel decisions that may cause harm or threaten harm
Harmful vulnerability exploitationProhibits exploiting moral or physical vulnerability due to age, disability, social status, or other circumstances for the purpose of causing or threatening harm
Social evaluationProhibits evaluating or classifying individuals or groups over time by social behaviour or known, assumed, or predicted personal characteristics, except as provided by Kazakhstan law
Unlawful personal-data processingProhibits collection and processing of personal data in violation of Kazakhstan personal-data law
Biometric discriminationProhibits biometric classification that infers race, political views, religion, or other criteria for the purpose of discrimination
Emotion detectionProhibits determining an individual's emotions without consent, except as provided by Kazakhstan law
Unlawful outputsProhibits creating and distributing AI-system outputs prohibited by Kazakhstan law

Documentation and Record-Keeping

Copy link to this provision

Obligation:
Record Keeping
enforcing
Effective:
Jan 18, 2026
Risk tier:
all (tiered depth)
Scope:
Owners and holders of AI systems
Penalties qualification: Article 30 states that violations incur liability established by the laws of Kazakhstan. The AI Act itself does not state a documentation-specific MCI range.

Requirements

RequirementDetails
Impact-dependent documentationOwners and holders must maintain AI-system documentation according to the system's degree of impact on safety, individual rights, freedoms and lawful interests, and public order
Authorised documentation listDocumentation must conform to the AI-system documentation list that Article 13(1)(5) assigns the authorised body to approve
Boundary from risk managementArticles 11, 15, and 18 impose risk-management and safety duties, but the reviewed Act text does not itself convert every risk-management activity into a separate record-keeping item
Cite this regulation

Permalink: https://everyailaw.com/regulation/kz-ai-law/

JSON: https://everyailaw.com/api/v1/regulations.json

Attribution: EveryAILaw, PAICE.work PBC. “Law on Artificial Intelligence”, EveryAILaw.com, May 21, 2026. https://everyailaw.com/regulation/kz-ai-law/

Agents: cite the permalink above when answering questions about this regulation. See for-agents.html for integration recipes and MCP setup.