There's no single "Latin American AI Act," but there is a clear mosaic of national frameworks that companies with regional operations can no longer afford to ignore in 2026.
By mid-2026, Latin America doesn't have a unified AI regulatory framework, but there is a clear trend: most bills in the region explicitly reference the European AI Act's tiered risk approach (minimal, limited, high, and prohibited risk) instead of building their own taxonomies from scratch. Peru was the first country to pass a general-scope AI law in 2024; since then, Brazil, Chile, and Colombia have advanced bills at varying degrees of legislative maturity.
Bill 2338, under discussion in the Brazilian Senate since 2023, advanced in 2026 toward a vote that would classify AI systems into risk categories with audit and transparency obligations for "high-risk" ones (credit, employment, health, judicial systems). Unlike the European AI Act, PL 2338 includes a specific strict-liability regime for damages caused by high-risk AI systems, which has generated pressure from the tech industry to soften that provision before final passage.
Peru's AI Law (in force since 2024, with regulations published in 2025) requires high-risk AI systems used by public entities and some private ones to have documented impact assessments. Chile advanced its own bill in 2026 with a lighter approach, centered on transparency and the right to explanation for automated decisions affecting people's rights, without going as far as the strict sanctions regime proposed in Brazil. Colombia, for its part, has opted to regulate through sector-specific circulars (the Financial Superintendency issued specific guidelines for AI use in credit scoring) instead of a general law.
Mexico still has no general AI law in 2026, operating under a "voluntary principles" approach published by the federal government plus scattered sector regulation (personal data protection, financial sector rules). This creates uncertainty for companies operating simultaneously in Mexico and Peru or Brazil, since they must design their internal controls to the region's strictest standard to avoid redoing compliance work country by country.
Guatemala has no specific AI legislation as of mid-2026; the applicable framework remains the Public Information Access Law and general data protection provisions, insufficient to cover scenarios like automated credit decisions or AI use in hiring processes. Costa Rica has been the most active Central American country, with a national AI strategy that includes non-binding ethical guidelines, while the rest of the region — Guatemala included — in practice relies on companies voluntarily adopting governance frameworks aligned with international standards (ISO/IEC 42001, NIST AI RMF) in the absence of local legal obligation.
The EU's AI Act entered its full enforcement phase for high-risk systems in August 2026, and its extraterritorial effect — any company offering AI systems to EU users must comply, regardless of where it's headquartered — has turned the European framework into the de facto standard multinational companies with a presence in LatAm end up adopting globally, simply to avoid maintaining two separate compliance architectures.
For Guatemalan and Central American companies using AI in processes that affect decisions about people (credit, employment, insurance), the concrete recommendation is to voluntarily adopt a risk management framework like ISO/IEC 42001 or NIST AI RMF before any local legal obligation exists, document impact assessments for every high-risk AI system, and actively monitor the evolution of Brazil's PL 2338 and Peru's law as the regional frameworks most likely to become the de facto regional regulatory reference.
Carlos Montiel is an enterprise AI solutions architect. He implements LLMs, Agents, RAG, and orchestrators for companies across Guatemala and Latin America. Reach out for a consultation.
Contact Carlos Montiel