Uruguay Decreto 276/025: AI Testing & Data Spaces Framework | TLY

Uruguay's Decreto 276/025 sets a governance framework for AI testing environments and data spaces under Ley 20.212

By Anthony Guerriero, Founder and Publisher, The Leveraged Years. Montevideo dateline, December 10, 2025. Last verified: 2026-07-25.

Most of Latin America is still debating whether to pass a broad AI law. Uruguay did something narrower and more concrete. It wrote the operating rules for a single, bounded mechanism: supervised testing environments where innovative data and AI projects can run with limited regulatory exceptions, under supervision, with a fixed exit date. On December 2, 2025 the President, acting in Council of Ministers, signed Decreto N° 276/025, published in the Diario Oficial on December 10. Read the decree's own heading and the scope is unmistakable: it is the reglamentación of articles 74 and 75 of Ley N° 20.212, the statute that promotes innovative projects, in particular those using data and artificial intelligence. Per the primary text at IMPO, the decree sets a minimum governance scheme for what Uruguayan law calls entornos controlados de prueba (controlled testing environments, the local term for regulatory sandboxes) and espacios de datos (data spaces).

So this is not a horizontal AI statute and does not pretend to be one. It creates no risk tiers, no across-the-board duties on AI systems, and no fines. It stands up one governance framework for one thing: how a sandbox or a data space gets proposed, approved, run, and closed. There is a committee, an application checklist, a clock, and a public register. For anyone tracking how a small jurisdiction actually builds a piece of AI governance rather than announcing an ambition, this narrow decree is a clean primary source.

What the decree actually creates

Article 1 states the objective plainly: to establish a minimum governance scheme for the creation and management of controlled testing environments and data spaces, aimed at innovative projects, especially in the use of data and artificial intelligence, that need regulatory exceptions, special authorizations, or sponsorship from public entities. Every such environment must respect the decree's stated principles, which it lists as equity, non-discrimination, responsibility, accountability, transparency, audit, and safe innovation, alongside personal-data protection principles.

Article 2 supplies the definitions that make the framework operable. A controlled testing environment is a temporary experimentation space opened in a specific field, aimed at a defined audience, and supervised by the competent public entity that grants the applicable regulatory exceptions or special authorizations. A regulatory exception is a temporary, extraordinary, reasoned, and documented relaxation of a normative requirement. The decree also fixes a working definition of an AI system, borrowing the now-standard international phrasing:

"Sistema de inteligencia artificial: sistema basado en máquinas que, con objetivos explícitos o implícitos, infiere, a partir de la entrada que recibe, salidas tales como predicciones, contenidos, recomendaciones o decisiones que pueden influir en entornos físicos o virtuales."

English gloss: "Artificial intelligence system: a machine-based system that, with explicit or implicit objectives, infers from the input it receives outputs such as predictions, content, recommendations, or decisions that can influence physical or virtual environments." (Art. 2)

How the AI and data sandbox actually works

The machinery runs through one body. Article 3 creates the Comité Técnico de Evaluación de Entornos Controlados, a technical evaluation committee chaired by AGESIC, Uruguay's e-government and information-society agency, with seats for the data protection regulator (Unidad Reguladora y de Control de Datos Personales, URCDP), the Ministry of Industry, Energy and Mining (MIEM), and the national research and innovation agency (ANII). The committee has 120 days from publication to draft its internal rules and, under Article 6, to publish the minimum-content documents and participation protocols that later applicants will have to meet.

Creating a sandbox is a documented approval flow, not a press release. Under Article 7, one or more public entities propose an environment to the committee. The proposal must contain, at minimum: an analysis of the existing legal framework; the technical specifications; the requirements future participants must meet, including transparency and accountability minimums; the operating period; the evaluation criteria; and, where a private, academic, or civil-society actor suggested it, their identity. Intellectual-property questions have to be settled before the environment is created. The committee then issues a technical report within 60 business days, extendable by 30, and AGESIC approves by reasoned resolution. AGESIC cannot approve without a favorable committee report and, where a regulatory exception is involved, without the granting resolution from the competent public entity.

Two limits give the regime its spine. The operating period is capped hard:

"El plazo por el que se entenderá operativo el entorno controlado de prueba, que no podrá exceder en ningún caso de 2 (dos) años." (Art. 7, lit. d)

English gloss: "The period for which the controlled testing environment is deemed operative, which may in no case exceed two (2) years."

And Article 9 forbids exceptions that break existing legal or constitutional provisions or that conflict with human-rights obligations under international law. An exception can never outlast the environment that houses it. Article 8 adds a public-register duty: AGESIC must publish on its website a list of every initiative the committee has assessed, past and present, including its objective, scope, the competent public entities, and eventual results. Chapter III, Article 14, extends the same logic to data spaces, infrastructures for reusing information held by the State and other actors, and requires the URCDP's favorable opinion whenever personal data is in play.

Who is covered

The sandbox is open to more than government. Article 7 lets public entities promote an environment, and Article 12 lets private entities, civil-society organizations, and academia present participants to the competent public entity. Individuals and private actors can even propose the creation of an environment, with the committee seeking the backing of the relevant public bodies. What every participant owes is disclosure. Article 12 requires each project to state its specific term, the people affected and any geographic scope, a data protection impact assessment under Decreto N° 64/020 where applicable, an estimate of potential harm to affected subjects with remedies and guarantees, and, where a public-interest benefit is claimed, a description of it. Projects must be fully public, with only the narrow exceptions of Uruguay's access-to-information law, Ley N° 18.381.

How Uruguay compares with peer sandbox regimes

The two-year statutory cap and the four-agency committee are what make Decreto 276/025 citable next to larger regimes. The table below sets it beside other AI or data sandboxes for orientation only. Details for other jurisdictions come from their own public frameworks and are summarized at a high level.

JurisdictionInstrumentLegal statusGoverning bodyTime limit in the rule
UruguayDecreto N° 276/025 (under Ley 20.212)Enacted decree, Dec 2025Comité Técnico chaired by AGESIC, with URCDP, MIEM, ANIIHard cap: 2 years per environment (Art. 7d)
European UnionAI Act, Art. 57 (AI regulatory sandboxes)In force; each member state must set up at least oneNational competent authoritiesDuration set per sandbox plan, no fixed statutory cap in the article
BrazilANPD regulatory sandbox on AI and data protectionRegulator-run pilot programAutoridade Nacional de Proteção de Dados (ANPD)Set by program cycle, not a general statute
ColombiaSIC data protection sandboxRegulator-run initiativeSuperintendencia de Industria y Comercio (SIC)Defined per participant plan

The pattern worth noticing: the EU delegates duration to each sandbox plan, while Uruguay writes the ceiling into the decree itself. For a company weighing where to run a supervised trial, a fixed exit date is a feature, because it bounds the legal exposure of every party from day one.

Practical steps if you want into a Uruguayan sandbox

  1. Watch AGESIC's public register and the committee's minimum-content documents, which Article 6 requires within 120 days of publication. Those documents define what a compliant application looks like.
  2. Find your competent public entity. A sandbox needs a public sponsor that can grant the regulatory exception or special authorization; identify which body governs your use case before drafting anything.
  3. Build the Article 12 file early. Term, affected subjects, geographic scope, a Decreto 64/020 data protection impact assessment, a harm estimate with remedies, and any public-interest justification.
  4. Settle intellectual property up front. Article 7 requires IP questions to be resolved before the environment is created, not during it.
  5. Plan for the two-year clock and for full publicity. Assume your project is public under Ley 18.381 and design the trial to reach a defensible result inside the cap.

What it does NOT do

Key Facts

Instrument
Decreto N° 276/025, regulating arts. 74 and 75 of Ley N° 20.212 (Uruguay).
Issuer
President of the Republic acting in Council of Ministers; reglamentation proposed by AGESIC.
Dates
Promulgated December 2, 2025; published in the Diario Oficial December 10, 2025.
Who is covered
Public entities, plus private entities, civil society, and academia that propose or join a controlled testing environment or data space.
Key limit
Any sandbox may operate for no more than two years (Art. 7d); no fines are created.
Status
In force; committee has 120 days from publication to issue its rules and minimum-content documents.

Sources

Related on The Leveraged Years