South Korea's Privacy Regulator Helps Unwind the National AI Digital Textbook Rollout
South Korea
South Korea's $850m national AI-textbook rollout was found in May 2025 by privacy regulator PIPC to have two data-protection violations. …
Peru · Lima · See the Peru profile
Peru's 2025 AI-law regulation names education a 'high-risk' sector, mandating algorithmic transparency, human oversight and data-protection-by-design for school evaluation systems by September 2026 — though rights groups flag ambiguous rules and voluntary private-sector audits.
Peru's Law N.º 31814 (2023), which promotes the use of artificial intelligence for the country's economic and social development, gained its implementing regulation on 9 September 2025: Decreto Supremo N.º 115-2025-PCM, approved by the Secretaría de Gobierno y Transformación Digital (SGTD) under the Presidencia del Consejo de Ministros. The regulation explicitly classifies "educational evaluation systems" as high-risk AI, alongside health, justice, security and finance. High-risk systems affecting fundamental rights must give users clear prior information, provide comprehensible explanations of automated results, undergo security audits, and embed data protection by design (minimization, anonymization). SGTD must coordinate with the Ministry of Education (MINEDU) to promote responsible, ethical, transparent and inclusive AI use in developing student competencies under the National Basic Education Curriculum.
Mandatory human oversight requires trained staff able to "stop, correct or invalidate" automated decisions before they affect students. Complaints can be filed with INDECOPI (consumer protection), Peru's Cybercrime Investigation Division, and the national data-protection authority (ANPDP), backed by a public complaints portal (gob.pe/iaperu). Per the digital-rights organisation Hiperderecho, education is among the sectors facing the first hard compliance deadline — September 2026, a year after the regulation's approval — with public-sector obligations starting January 2026 and private-sector compliance phased over up to four years.
Independent reviewers have raised concrete concerns. Access Now called the regulation's risk definitions "too ambiguous" (manipulative-AI prohibitions trigger only on "substantial" behavioural change) and noted that fundamental-rights impact assessments are mandatory only for government entities, optional for the private companies that build most EdTech tools. Hiperderecho found the 15-member oversight High-Level Committee has only one civil-society seat and, in its analysis, remained "evidently inactive." Because the education-sector compliance deadline (September 2026) had not yet passed at the time of this research, no implementation outcomes for schools are yet available — this is a binding legal mandate with real teeth on paper, but still untested in practice.
Read the full analysis: https://hiperderecho.org/2025/09/nuevo-reglamento-de-ia-en-el-peru-y-nuevas-garantias-frente-a-malos-usos/
Implementation detail (cost, timeline, staffing, conditions for success) is not yet available for this practice.
Where this practice's information was retrieved from, and when.
South Korea
South Korea's $850m national AI-textbook rollout was found in May 2025 by privacy regulator PIPC to have two data-protection violations. …
United Kingdom
The UK government's June 2025 position on generative AI in schools and colleges: embrace the opportunity, but with human oversight, …
Belgium
The EU AI Act classifies AI for admissions, grading, steering learning and exam monitoring as 'high-risk' — mandating risk management, …
Finland
Finland's education ministry and Opetushallitus published national AI recommendations (31 March 2025) after consulting 172 organisations and youth 'Digiraati' councils, …
Open full copilot Grounded in cited practices — always check the sources.