Colombia Sets Child-Safety Duties for Accessible AI Systems
Colombia’s Decree 769 of 2026 is in force. It applies a child online-safety framework to specified digital-service actors, expressly including AI systems accessible to children and adolescents in Colombia. It is not a general Colombian AI Act.
Status: Decree 769 was issued on 16 July 2026 and the published legal record lists 18 July 2026 as its effective date.
Who is in scope: The decree expressly includes developers and providers of applications, videogames, AI systems and digital platforms whose products are accessible to children and adolescents in Colombia. Applicability remains conditioned by the service, interaction with children, and capacity to affect online-risk management.
What covered firms must do: The text requires security and privacy by design and by default, reasonable due diligence to address children’s online risks, and a semiannual report to MinTIC on protection measures and safe-design implementation.
- Authority
- Government of Colombia; Title 31 identifies the Ministry of Information and Communications Technologies (MinTIC) in its implementation framework.
- Instrument
- Decree 769 of 2026, adding Title 31 to Decree 1078 of 2015.
- Status
- In force. The published legal record lists an effective date of 18 July 2026.
- Primary sources
- Published legal text; Colombian Presidency release.
What changed?
Decree 769 regulates Law 2489 of 2025 through a framework for healthy and safe digital environments for children and adolescents. Its general scope includes public entities, private firms, nonprofit and community organizations, educational institutions, and the public. For private firms, the text says enforceable obligations expressly fall on telecom-network and service providers, platform and digital-service providers, and other actors with a material role in shaping the digital environment.
That does not make every technology firm subject to every provision. The decree says the identification of obligated parties depends on the nature of the actor and service, its level of interaction with children and adolescents, and its capacity to affect online-risk management. It also excludes editorially controlled content providers from the relevant industry chapter under the Title’s terms.
Where do AI systems fit?
Article 2.2.31.3.4 provides the direct AI link. It says the industry duty to contribute to safe digital environments includes developers and providers of applications, videogames, artificial-intelligence systems and digital platforms whose products are accessible to children and adolescents in Colombia.
The source supports this conclusion. A provider should assess whether its product is accessible to children and adolescents in Colombia, then assess the decree’s scope conditions and exclusions. The source does not support describing this as universal coverage of all AI providers, a stand-alone AI licensing regime, or a dedicated AI regulator.
What are the operative duties?
The decree requires digital-service providers and software-industry participants to implement security and privacy standards by design and by default. It also requires reasonable due-diligence measures to identify, prevent and mitigate risks that can affect children’s rights in the design, operation and provision of digital services.
Article 2.2.31.3.5 requires obligated subjects to send MinTIC a semiannual report covering progress on protection measures and compliance with safe-design guidelines. The report must include an analysis of risks associated with implementation. The text says application is differentiated by risk level, the service’s nature, the degree of interaction with children and adolescents, and the obligated party’s technical and operational capacity.
| Question | What the decree supports |
|---|---|
| Is the decree in force? | Yes. The published legal record lists 18 July 2026 as the effective date, and the decree says it applies from the day after publication in the Diario Oficial. |
| Does it expressly mention AI systems? | Yes. The industry-scope provision includes AI systems accessible to children and adolescents in Colombia. |
| Are all AI providers automatically covered? | No. Scope depends on the product’s accessibility to children and adolescents and the decree’s other actor and service conditions. |
| Does the text prescribe an age-assurance method or a technical AI standard in the cited provisions? | No such method or standard is specified in the cited provisions. |
What remains to come?
Some implementation detail remains prospective. The decree says MinTIC will establish technical and operational definitions by resolution within 12 months of the Title taking effect. It also directs MinTIC to issue technical guidelines for the security-and-privacy provision. Those future materials may clarify implementation, but they should not be presented as existing requirements before they are issued.
The decree’s reporting obligation does not itself establish a specific reporting calendar in the cited provision. It requires semiannual reporting, but this update does not infer a first due date, reporting format, penalty, or technical submission system.
What should product and compliance teams do now?
Teams responsible for products accessible to children and adolescents in Colombia can begin by documenting the service’s audience, child-access pathways, and role in online-risk management. They can map current safety and privacy-by-design controls to the decree’s language and identify who would own the required risk analysis and semiannual reporting record.
This is a readiness step, not legal advice or proof that a particular firm is covered. A source-specific review of the decree, the firm’s service, and later MinTIC materials is needed before making jurisdiction-specific implementation decisions.
Colombia’s Decree 769 is an in-force child online-safety measure that expressly reaches certain AI systems accessible to children and adolescents. Keep the characterization exact: it imposes scoped digital-safety, risk-analysis and reporting duties. It is not a general AI Act, a universal AI-provider rule, or a published technical standard.
Decree 769 legal-text record, Bogotá Legal Secretariat; Presidency release. Verify Articles 2.2.31.1.2, 2.2.31.2.8, 2.2.31.3.4, 2.2.31.3.5 and the decree’s effectiveness clause.
FAQ
Is Decree 769 a Colombian AI Act?
No. It is a cross-sector child online-safety decree. It expressly includes certain AI systems among the covered industry actors, but it is not framed as a general AI Act.
Which AI systems does the decree mention?
The industry-scope provision includes AI systems whose products are accessible to children and adolescents in Colombia. Applicability also depends on the decree’s actor, service and risk-management conditions.
What does the semiannual report cover?
For obligated subjects, it covers progress on protection measures and compliance with safe-design guidelines, including risk analysis associated with implementation. The cited provision does not specify a particular reporting date or format.
Has MinTIC issued all technical detail?
No. The decree says MinTIC will set technical and operational definitions by resolution within 12 months and will issue technical guidelines for the security-and-privacy provision.