Bangladesh's Draft AI Policy: Risk Tiers, No Law Yet | TLY

AI Regulation Tracker  /  Draft policy

Bangladesh's AI Policy Is Still a Draft, and the Draft Is Worth Reading

The ICT Division published Draft v2 of a National AI Policy 2026-2030 on February 9, 2026, and ran a public consultation that closed February 8, 2026. It proposes a four-tier risk taxonomy, a named regulator and a statute by 2028. None of it binds anyone today.

The short version

Bottom line. This is a draft policy, not a rule. The Information and Communication Technology Division published Bangladesh National AI Policy 2026-2030, Draft v2, dated February 9, 2026, on a dedicated government consultation portal. The portal states that the AI Policy Committee is reviewing consultation responses for integration into a final draft, and adoption is still pending. No adopted version was identified in the government sources reviewed as of August 3, 2026.

Who this affects. Nobody yet, in the sense of a present legal duty. On its own terms the draft is aimed at public authorities deploying AI in Bangladesh, private deployers of high-risk AI in law enforcement, biometric identification, creditworthiness, welfare allocation, employment and essential public services, generative AI chatbot providers including what it calls both domestic and foreign AI products and companies, and firms processing children's data.

Effective date. None. The draft carries no commencement date because it has not been adopted. Its own internal milestones point to 2028: a comprehensive Artificial Intelligence Act to be drafted by 2028, comprehensive AI liability legislation by 2028, and a Mid-Term Comprehensive Review in 2028.

What changed. A detailed national AI policy text is now on the table and has been through a public consultation. Draft v1.1 appeared as an ICT Division notice in January 2026, the online public consultation ran from January 26 to February 8, 2026, and Draft v2 followed on February 9, 2026.

Anthony's analysis. Read this as a signal of direction, not as compliance work. What makes it worth twenty minutes is how closely the proposed architecture tracks the EU model: four risk tiers, a single coordinating regulator, certification of high-risk systems, and mandatory impact assessments. If it survives adoption in roughly this shape, the vocabulary a US firm already uses for the EU AI Act will largely transfer.

Primary sources. Bangladesh National AI Policy 2026-2030, Draft v2, published by the ICT Division.

Key facts

At a glance
Jurisdiction
Bangladesh
Instrument
Bangladesh National AI Policy 2026-2030, Draft v2, dated February 9, 2026
Publisher
Information and Communication Technology Division, Ministry of Posts, Telecommunications and Information Technology
Status
Draft. Under review by the AI Policy Committee; adoption pending
Consultation
Online public consultation opened January 26, 2026; feedback period concluded February 8, 2026
Proposed regulator
National Data Governance Authority (NDGA), as central coordinating and regulatory body, per the draft text
Proposed statute
Ministry of Law, Justice and Parliamentary Affairs to initiate drafting a comprehensive Artificial Intelligence Act by 2028
Earlier version
Draft v1.1, published as an ICT Division notice; the two government sources are not consistent on its date, so treat the v2 cover date as the anchor

Regulatory briefing

Instrument
Bangladesh National AI Policy 2026-2030, Draft v2 (February 9, 2026); earlier Draft v1.1 published as an ICT Division notice
Authority
Information and Communication Technology Division, Ministry of Posts, Telecommunications and Information Technology, drafted under the National AI Policy Steering Committee
Jurisdiction
Bangladesh
Status
Draft, in public consultation review. Not adopted as of August 3, 2026
Bindingness
Not binding. Draft policy text, creating no present legal obligation
Effective date
None. The draft has not been adopted and appoints no commencement date
Primary source
Bangladesh National AI Policy 2026-2030, Draft v2

What was published, and what it is not

On February 9, 2026 the Information and Communication Technology Division put a document on a government consultation portal titled Bangladesh National AI Policy 2026-2030, Draft v2. An earlier Draft v1.1 had gone out as an ICT Division notice in January. The consultation portal records an online public consultation opening on January 26, 2026 and a public feedback period concluding on February 8, 2026, and states that the AI Policy Committee is reviewing the submitted responses so that recommendations can be integrated into the final policy draft.

That last sentence is the one that governs everything else on this page. The committee is reviewing. Adoption is pending. No adopted or gazetted version was identified in the government sources reviewed as of August 3, 2026. So every provision described below is proposed text in an unadopted draft. It does not require anything of you, it does not prohibit anything, and it creates no liability. I am going to keep saying that, because policy drafts of this quality get summarised in the trade press as though they were already in force, and a compliance officer who acts on that summary will have spent budget on a document that a committee can still rewrite.

One housekeeping note on dates. The two government sources are not consistent about when Draft v1.1 was published, and the ICT Division notice page also carries an archive date. Rather than pick a winner, use what is unambiguous: the cover page of the v2 PDF reads Draft v2, February 9, 2026, and that is the version being tracked here.

It is also worth saying what this draft is procedurally. It is a policy instrument produced by an executive division, not a bill before Parliament. Even in its own account of itself it is a waypoint: it directs that a statute be drafted later. Policy of this kind can shape procurement, ministerial guidance and agency behaviour long before any statute exists, which is exactly why it is worth reading early, but it is not the same species of thing as a law.

The proposed architecture: four tiers and one regulator

The substantive core of the draft is section 4.1, and it will look immediately familiar to anyone who has worked through the EU AI Act:

To ensure proportional and effective regulation, the government shall adopt a risk-based classification framework for AI systems. AI applications shall be categorized into prohibited (unacceptable risk), high-risk, limited-risk, and low-risk systems, with regulatory obligations calibrated to the level of risk posed to individuals, society, and the State.Bangladesh National AI Policy 2026-2030, Draft v2, s.4.1, February 9, 2026

Four tiers, calibrated obligations, and a high-risk list that the draft populates with law enforcement, biometric identification, creditworthiness, welfare allocation, employment and access to essential public services. The proposed safeguards for that tier are data quality requirements, risk management measures, human oversight and transparency obligations. That is the European vocabulary, adopted more or less wholesale.

The draft then does something many national AI strategies avoid, which is to name a body:

The government shall designate the National Data Governance Authority (NDGA) as the central coordinating and regulatory body for AI governance across government. In addition to its role in data governance and interoperability, NDGA shall be empowered to issue technical standards, certify compliance for high-risk AI systems, oversee Algorithmic Impact Assessments, and coordinate AI policy implementation across ministries, regulators, and public agencies.Bangladesh National AI Policy 2026-2030, Draft v2, s.4.1, February 9, 2026

Note the verb tense. The government shall designate. The NDGA is not, on the strength of this document, currently regulating AI in Bangladesh; the designation is a proposal sitting inside a draft. But the choice is informative. Putting standard setting, high-risk certification and oversight of impact assessments in one authority, rather than scattering them across sectoral regulators, is a design decision with consequences for how quickly guidance appears and how consistent it is. It is also the design that gives an outside firm a single door to knock on, which is worth more in practice than most people admit.

Alongside the tiers, the draft proposes Algorithmic Impact Assessments for all significant public-authority AI and for private high-risk AI, with what it calls regulatory enforcement measures for deployment without one. It also proposes regulatory sandboxes with one-year renewable waivers. Again: proposed. There is no sandbox you can apply to on the basis of this text.

Liability, prohibitions and the 2028 legislative pathway

The liability section is the part I would watch most closely, because it is where a policy document is at its weakest and its intentions are at their clearest. The draft sets out a strict-liability approach for certain harms and is candid that this is an interim regime operating under existing tort and administrative law principles, with comprehensive AI liability legislation due by 2028.

Read that carefully. It is an acknowledgement that the drafters do not yet have a statutory hook for the liability rule they want, so they are proposing to route it through general law until one exists. Whether that survives contact with Bangladesh's courts is not something a policy document can settle, and I would not build a risk model on it.

The prohibition list is the other headline item. The draft would bar AI-enabled social scoring, indiscriminate biometric mass surveillance without lawful authorization, manipulative or deceptive AI, AI-driven election interference and deepfakes, collection of data on under-16s without parental or legal guardian consent, and the use of children's data to train AI models. That last pair is the one I would flag to a US product team, because if it survives adoption in that form it reaches backwards into how a model was built rather than forwards into how it is deployed, and training-data provenance is the hardest thing to retrofit.

On the statute itself, the draft is explicit:

To transition from policy guidance to a comprehensive statutory framework, the Ministry of Law, Justice, and Parliamentary Affairs shall initiate the drafting of a comprehensive Artificial Intelligence Act by 2028.Bangladesh National AI Policy 2026-2030, Draft v2, s.7.5 Legislative Pathway, February 9, 2026

Initiate the drafting by 2028. Not enact by 2028, and not introduce now. This document is a direction to a ministry to start work, and no Artificial Intelligence Act was identified in the government sources reviewed as of August 3, 2026. The draft also states that Bangladesh shall ratify the Council of Europe AI Framework Convention at section 4.10, which is a statement of intent inside an unadopted policy, not a ratification.

A Mid-Term Comprehensive Review is scheduled for 2028 under section 7.2. Put those three 2028 markers together and you get the honest timeline: this is a document about the second half of the decade, published early enough that industry can argue with it.

Who the draft says it would reach

The scope language matters for readers outside Bangladesh. On chatbot and generative AI provisions the draft refers expressly to both domestic and foreign AI products and companies. So the drafters are not writing a domestic-firms-only instrument, and a US company shipping a consumer-facing model into that market should assume it is inside the intended perimeter of whatever eventually gets adopted.

The draft also leans on other instruments it describes as already in force, naming a Personal Data Protection Ordinance 2025, a National Data Governance Ordinance 2025 and a Cyber Safety Ordinance 2025. I am reporting that those are referenced inside this draft. I have not verified their status against their own official sources, and neither should you take a policy document's characterisation of adjacent legislation as authority for it. If any of those instruments matters to your exposure, go read the instrument.

The practical exposure question for a US business is therefore narrower than the draft's ambition suggests. Today there is nothing here to comply with. What exists is a reasonably detailed public statement of where an executive division intends to take AI regulation, published with a consultation record attached, which is enough to plan against even though it is not enough to owe anything under.

There is a second reason the scope language repays attention. Extraterritorial reach in a draft is cheap to write and expensive to operate. Saying an instrument covers foreign products and companies is a sentence; building the supervisory capacity to inspect a foreign model, certify it as high-risk compliant, and act on a complaint about it is an institutional project. Between now and adoption, the questions worth asking of the final text are the boring administrative ones. Who serves notice on a foreign provider. Whether a local representative or establishment is required. What the certification pathway for a high-risk system actually looks like in steps and documents, as opposed to in principle. Draft v2 answers those at the level of policy intent, which is the right level for a policy, but it means the operational answer is still open.

What to do with this on Monday

First, file it correctly. In a regulatory register this belongs in the watch column, with status Draft and effective date None. Anyone who logs it as an obligation has created work that does not exist and, worse, has trained the register's readers to distrust it.

Second, if you have real revenue or user exposure in Bangladesh, do the cheap mapping now rather than later. The draft's high-risk list is specific: law enforcement, biometric identification, creditworthiness, welfare allocation, employment, essential public services. If one of your products lands in one of those categories, note it and move on. That is a fifteen-minute exercise today and a large one after a statute exists.

Third, the children's data provisions are the ones with the longest lead time. A prohibition on training with children's data, and a consent requirement for under-16 collection, cannot be satisfied retroactively by a policy document. If your training pipelines cannot currently answer the question of whose data is in them, that is a gap worth closing on its own merits, in every market, regardless of what Bangladesh eventually adopts.

Fourth, watch for the adopted text rather than for commentary about it. The single most useful monitoring action is a periodic check of the consultation portal and the ICT Division's policies index for a version that drops the word Draft from its cover page. Until that appears, the correct professional answer to the question of what Bangladesh requires of AI systems is that its national policy is in draft and its statutory framework is proposed for later this decade.

My own read, offered as opinion rather than fact: the EU-shaped architecture here looks like a deliberate bet that convergence is cheaper than invention. Borrowing a taxonomy imports a body of interpretation along with the vocabulary, and it lets a firm that has already done the EU work reuse most of it. The offsetting risk is the familiar one. A four-tier taxonomy, a certification function and an impact-assessment review process need staff, technical capacity and a complaints procedure, and none of that arrives with the drafting. Watch for how the final text resources the NDGA, not just for what it empowers the NDGA to do.

Bangladesh National AI Policy 2026-2030, Draft v2: what is proposed and what its status is
ElementWhat the draft proposesStatus
Risk classificationProhibited, high-risk, limited-risk and low-risk tiers with calibrated obligations (s.4.1)Proposed, not in force
RegulatorNDGA as central coordinating and regulatory body, empowered to issue standards and certify high-risk systems (s.4.1)Proposed designation, not in force
Algorithmic Impact AssessmentsMandatory for significant public-authority AI and private high-risk AIProposed, not enforceable
SandboxesRegulatory sandboxes with one-year renewable waiversProposed, none open on this text
LiabilityStrict liability for certain harms, described as an interim regime under existing tort and administrative lawProposed; comprehensive legislation due by 2028
StatuteMinistry of Law to initiate drafting a comprehensive Artificial Intelligence Act (s.7.5)By 2028; no Act identified in sources reviewed
CoE Framework ConventionDraft states Bangladesh shall ratify (s.4.10)Statement of intent in a draft
ReviewMid-Term Comprehensive Review (s.7.2)Scheduled for 2028
Key compliance takeaway

Bangladesh's ICT Division has published a detailed draft National AI Policy for 2026-2030 and run a public consultation on it, and the AI Policy Committee is reviewing the responses. The draft proposes an EU-style four-tier risk taxonomy, the NDGA as a single AI regulator with standard-setting and high-risk certification powers, mandatory algorithmic impact assessments, and a comprehensive Artificial Intelligence Act to be drafted by 2028. None of it is in force. Log it as a watch item, map any product that would land in the proposed high-risk categories, and check the portal for a version whose cover page no longer says Draft.

Source File
Primary source
Bangladesh National AI Policy 2026-2030, Draft v2, February 9, 2026, published by the Information and Communication Technology Division, for the risk classification and NDGA designation at s.4.1 and the legislative pathway at s.7.5.
Corroborating
The government consultation portal at aipolicy.gov.bd for the consultation dates and review status, and the ICT Division notice page for National AI Policy Bangladesh 2026-2030 (Draft v1.1).
How to verify
Open the PDF and read the cover page: it reads Bangladesh, National AI Policy, 2026-2030, Draft v2, February 9, 2026. Then read section 4.1 for the four-tier classification and the NDGA designation, and section 7.5 for the direction to initiate drafting an Artificial Intelligence Act by 2028. Finally open aipolicy.gov.bd and read the consultation status, which records the feedback period concluding February 8, 2026 and the AI Policy Committee reviewing responses.

Last verified: August 3, 2026 against the primary sources listed above.

Frequently asked

Has Bangladesh adopted a national AI policy?

Not on the sources reviewed. The Information and Communication Technology Division published Bangladesh National AI Policy 2026-2030 as Draft v2, dated February 9, 2026, and ran a public consultation whose feedback period concluded February 8, 2026. The consultation portal states that the AI Policy Committee is reviewing submitted responses for integration into the final policy draft. No adopted version was identified in the government sources reviewed as of August 3, 2026.

Does the draft create obligations for my company today?

No. It is draft policy text. It does not require an algorithmic impact assessment, does not prohibit any deployment, and does not create liability. Its provisions describe what the government proposes to do, using the formula that the government shall adopt or shall designate. Treat it as a signal of direction and a planning input, not as a compliance obligation.

Is the NDGA regulating AI in Bangladesh?

The draft proposes designating the National Data Governance Authority as the central coordinating and regulatory body for AI governance across government, empowered to issue technical standards, certify compliance for high-risk AI systems and oversee Algorithmic Impact Assessments. That designation is a proposal inside an unadopted draft, not a description of a current supervisory arrangement.

Is there an Artificial Intelligence Act in Bangladesh?

None was identified in the government sources reviewed as of August 3, 2026, and this document does not itself create one. Section 7.5 of the draft directs the Ministry of Law, Justice and Parliamentary Affairs to initiate the drafting of a comprehensive Artificial Intelligence Act by 2028. The draft separately anticipates comprehensive AI liability legislation by 2028 and a Mid-Term Comprehensive Review in the same year.