evidoria

← Back to browse

Good practice Imported

Peru's National AI Law Regulation — Education Named a High-Risk Sector Requiring Human Oversight

Peru · Lima · See the Peru profile · See the Lima profile

Evidence: Descriptive / self-reported Top 82% 33/100 · Ask Evidence Copilot about this practice

Peru's 2025 AI-law regulation names education a 'high-risk' sector, mandating algorithmic transparency, human oversight and data-protection-by-design for school evaluation systems by September 2026 — though rights groups flag ambiguous rules and voluntary private-sector audits.

1 of 15 seats
Oversight committee civil-society representation
1 year
Education-sector compliance deadline after regulation approval (September 2026)
4 years
Maximum phased private-sector compliance period
Peru's National AI Law Regulation — Education Named a High-Risk Sector Requiring Human Oversight

Details

Promoter
Presidencia del Consejo de Ministros (PCM) / Secretaría de Gobierno y Transformación Digital (SGTD), with MINEDU
Period
2023 (Law N.º 31814 enacted) – regulation approved September 2025 – education-sector compliance deadline September 2026 – ongoing
Keywords
AI regulation, algorithmic transparency, human oversight, data protection by design, education-sector risk classification

Context

Peru's Law No. 31814 (2023) promotes the use of artificial intelligence for the country's economic and social development. Its implementing regulation, Decreto Supremo No. 115-2025-PCM, was approved on 9 September 2025 by the Secretaría de Gobierno y Transformación Digital (SGTD) under the Presidencia del Consejo de Ministros, and explicitly classifies 'educational evaluation systems' as high-risk AI alongside health, justice, security and finance.

Objectives

The regulation aims to protect fundamental rights against AI-driven harms in high-risk sectors, requiring clear prior information to users, comprehensible explanations of automated results, security audits, and data protection by design (minimisation, anonymisation) for systems like automated school evaluation.

Activities

High-risk systems must have trained staff able to stop, correct or invalidate automated decisions before they affect students, and SGTD must coordinate with the Ministry of Education to promote responsible AI use under the National Basic Education Curriculum. Complaints can be filed through INDECOPI, the Cybercrime Investigation Division, the national data-protection authority (ANPDP), and a public complaints portal.

Results

Public-sector obligations begin in January 2026, with the education sector facing a compliance deadline of September 2026 — one year after the regulation's approval — and private-sector compliance phased over up to four years. As the September 2026 deadline had not yet passed at the time of this research, no implementation outcomes for schools are yet documented.

Conclusions

Independent reviewers have flagged weaknesses: Access Now calls the regulation's risk definitions 'too ambiguous' and notes that fundamental-rights impact assessments are mandatory only for government entities (optional for the private companies that build most EdTech tools), while Hiperderecho finds the 15-member oversight committee has only one civil-society seat and has remained largely inactive — so this is a binding legal mandate with real requirements on paper, but still untested and imperfectly overseen in practice.

Implementation

Indicative cost
Medium (€50k–€500k) — No budget figures disclosed; implementation requires audits, staff training and a public complaints portal across public and (eventually) private education-sector actors.
Time to results
Long (> 3 years) — Law enacted 2023; implementing regulation approved September 2025; public-sector obligations from January 2026; education-sector compliance deadline September 2026; private-sector compliance phased over up to four years.
Staffing & skills
Secretaría de Gobierno y Transformación Digital (SGTD), coordinating with the Ministry of Education (MINEDU); trained staff required within regulated entities to oversee/override automated decisions

Conditions for success

  • Public-sector obligations starting January 2026 to build institutional practice ahead of the wider September 2026 education-sector deadline
  • Named complaint channels (INDECOPI, Cybercrime Investigation Division, ANPDP, gob.pe/iaperu portal)

Common failure modes

  • Ambiguous risk-trigger definitions (e.g. manipulative-AI prohibitions triggering only on 'substantial' behavioural change), per Access Now
  • Fundamental-rights impact assessments mandatory only for government entities, optional for private EdTech vendors
  • 15-member oversight High-Level Committee has only one civil-society seat and is described by Hiperderecho as largely inactive

Where it fits

Governance type
national government regulation
Scale
national
Income level
upper-middle-income (Peru)

Commonly funded by

National / regional programmes

Indicative funding routes for practices of this type — always check each programme's current calls and eligibility rules.

Do you run this practice? Claim it — verified implementers get a public contact pathway and can propose corrections.

Data sources

Where this practice's information was retrieved from, and when.

Attachments

Similar practices you may find useful