AI LAW RADAR · Daily Last verified 21 Aug 2026

Jurisdiction dossier

Kyrgyzstan: AI regulation & deadlines

Kyrgyzstan legislated on AI before either of its neighbours and commenced after both. Chapter 23 of the Digital Code (Code No. 178 of 31 July 2025, «Эркин-Тоо» No. 59 of 8 August 2025) was adopted five months before Kazakhstan's AI Law was published, but commencement Law No. 179 delayed it by six months from 5 August 2025, so arts. 191-197 bind only from 6 February 2026 - after Kazakhstan (18 January 2026) and Uzbekistan (21 January 2026). It is also the deepest of the three. Art. 193 subjects EVERY AI system applied in the country to an owner-run danger assessment at design, before first use and on any unplanned change, and requires the result AND the methodology to be published on the owner's site and as open data. Systems that the assessment classifies as «повышенной опасности» - high danger, judged comparatively against alternative means, with an express carve-out for purely auxiliary use - then carry the art. 194(5) owner duties (conformity, life-cycle risk management, technical documentation, log retention, remediation, suspension on official demand), the art. 195 gate of a publicly posted declaration of conformity signed with a qualified digital signature before first application, and the art. 196 user duties including a free explanation right for anyone whose rights a decision touches. Art. 126 classifies digital-wellbeing AI as high-danger by statute. Art. 197 applies at any danger level: tell consumers they are dealing with an AI, tell people they are being emotion-recognised or biometrically classified, label deepfakes, and publish AI-use information both on the user's site and on the sectoral regulator's. Unlike Kazakhstan's deferred marking standard, the implementing layer is finished - Cabinet of Ministers Resolution No. 770 of 2 December 2025 approved five annexes under arts. 193 and 194, and Order No. 1181-т of 31 December 2025 approved the declaration content. Enforcement is the thin part: the only AI offence is art. 228-10 of the Code of Offences, inserted by Law No. 180, and it reaches solely the art. 192(2) ban on designing, developing or applying AI to cause targeted and knowingly unlawful harm - 200 расчетных показателей for natural persons and 650 for legal persons, at 100 som per показатель, i.e. 20,000 and 65,000 som. Nothing penalises a missing danger assessment, a missing declaration or an unlabelled deepfake; the real sanctions are regulator-ordered suspension and civil liability. 3 obligations tracked — 3 in force.

Binding — Binding sectoral Flagship law: Digital Code Chapter 23 (arts. 191-197)

Kyrgyzstan legislated on AI before either of its neighbours and commenced after both. Chapter 23 of the Digital Code (Code No. 178 of 31 July 2025, «Эркин-Тоо» No. 59 of 8 August 2025) was adopted five months before Kazakhstan's AI Law was published, but commencement Law No. 179 delayed it by six months from 5 August 2025, so arts. 191-197 bind only from 6 February 2026 - after Kazakhstan (18 January 2026) and Uzbekistan (21 January 2026). It is also the deepest of the three. Art. 193 subjects EVERY AI system applied in the country to an owner-run danger assessment at design, before first use and on any unplanned change, and requires the result AND the methodology to be published on the owner's site and as open data. Systems that the assessment classifies as «повышенной опасности» - high danger, judged comparatively against alternative means, with an express carve-out for purely auxiliary use - then carry the art. 194(5) owner duties (conformity, life-cycle risk management, technical documentation, log retention, remediation, suspension on official demand), the art. 195 gate of a publicly posted declaration of conformity signed with a qualified digital signature before first application, and the art. 196 user duties including a free explanation right for anyone whose rights a decision touches. Art. 126 classifies digital-wellbeing AI as high-danger by statute. Art. 197 applies at any danger level: tell consumers they are dealing with an AI, tell people they are being emotion-recognised or biometrically classified, label deepfakes, and publish AI-use information both on the user's site and on the sectoral regulator's. Unlike Kazakhstan's deferred marking standard, the implementing layer is finished - Cabinet of Ministers Resolution No. 770 of 2 December 2025 approved five annexes under arts. 193 and 194, and Order No. 1181-т of 31 December 2025 approved the declaration content. Enforcement is the thin part: the only AI offence is art. 228-10 of the Code of Offences, inserted by Law No. 180, and it reaches solely the art. 192(2) ban on designing, developing or applying AI to cause targeted and knowingly unlawful harm - 200 расчетных показателей for natural persons and 650 for legal persons, at 100 som per показатель, i.e. 20,000 and 65,000 som. Nothing penalises a missing danger assessment, a missing declaration or an unlabelled deepfake; the real sanctions are regulator-ordered suspension and civil liability.

checked 21 Aug 2026 primary source ↗

The Register

3 obligations
Kyrgyzstan Binding

Digital Code arts. 191-193 - every AI system used in the country must be danger-assessed, and both the method and the result must be published

Binds Владельцы систем искусственного интеллекта - the owners of AI systems applied in the Kyrgyz Republic, with the art. 192(3) risk-minimisation duty extending to users as well. Resolution No. 770 para. 2 spells the scope out: owners of AI systems applied in Kyrgyzstan 'irrespective of organisational-legal form, departmental (sectoral) affiliation and form of ownership'. There is no turnover, headcount, sector or nationality threshold anywhere in Chapter 23, so a sole trader running one model and a state body running a national platform owe the same assessment and the same publication.. Chapter 23 of the Digital Code of the Kyrgyz Republic (Code No. 178 of 31 July 2025), arts. 191 to 193, is the base layer of Kyrgyzstan's AI regime and it is unusual in applying to every AI system without a risk gate. Art. 191(1) starts from permission: AI systems are designed, developed and applied without restriction except where this Code says otherwise. Art. 191(2) then fixes seven sectoral principles that owners must build to - risk reduction, openness, explainability, human controllability, accuracy, reliability and security - and art. 191(3) makes them the basis on which every requirement for AI systems is set and read. Art. 192(1) limits what those requirements may protect to six enumerated goods (life and health, human and civil rights and freedoms, the environment, defence capability, national security, public order), art. 192(2) prohibits outright the design, development or application of AI systems for the targeted and knowingly unlawful causing of harm to those goods, and art. 192(3) puts a general duty on owners and users of AI systems irrespective of danger level to take all reasonable and necessary measures to minimise the risk of such harm. Art. 193 is the operative obligation: ALL AI systems applied in Kyrgyzstan are subject to a danger assessment, carried out by the system's owner at the design stage, again on completion of development and before application, and again on any unplanned change to the system or its environment of use that could alter the result. The owner writes the methodology itself, but under requirements set by the Cabinet of Ministers, and art. 193(4) requires BOTH the assessment result AND the methodology to be posted on the owner's website in a form simple and intelligible to natural persons and additionally as open data, state secrets excepted. Those Cabinet requirements exist: Resolution No. 770 of 2 December 2025 approved a Requirements-for-the-danger-assessment-methodology annex, so this is a filled slot and not a deferred one.

In force since 6 February 2026. The Code was enacted by a separate commencement statute. Law No. 179 of 31 July 2025 «О введении в действие Цифрового кодекса Кыргызской Республики», art. 1, brings the Code into effect «по истечении шести месяцев со дня официального опубликования настоящего Закона», with no article and no chapter carved out. Law No. 179 was published in the official state newspaper «Эркин-Тоо» No. 58 (3714) of 5 August 2025; the six months expire at the end of 5 February 2026, and the ЦБД record card for Law No. 179 states dateOfEntry 6 February 2026. Chapter 23 therefore binds from 6 February 2026. The companion Law No. 180 of the same date, which inserted the administrative offence, carries the identical six-month clause in its art. 8 and commenced on the same day. The implementing act is Cabinet of Ministers Resolution No. 770 of 2 December 2025, published in «Эркин-Тоо» No. 96 (3753) of 5 December 2025, which approves five annexes under arts. 193 and 194 - the danger-assessment methodology requirements, and requirements for risk management, for system characteristics, for digital data quality and for technical documentation. Its para. 4 commences it 'fifteen days after the entry into force of the Digital Code', which computed from 6 February 2026 puts it at 21 February 2026; the ЦБД record card carries no dateOfEntry for the Resolution, so that single date is arithmetic from the Resolution's own text rather than a stated date. The Resolution's status in ЦБД is «Действует».

Stated maximum penalty — Nothing. There is no administrative offence for failing to run the danger assessment, for using a methodology that does not meet the Resolution No. 770 requirements, or for not publishing the result and the methodology. The only AI-specific offence Kyrgyzstan created is art. 228-10 of the Code of Offences (Code No. 128 of 28 October 2021, article inserted by Law No. 180 of 31 July 2025), and it reaches only the art. 192(2) prohibition: design, development or application of AI systems for the targeted and knowingly unlawful causing of harm to the protected goods, fined at 200 расчетных показателей for natural persons and 650 for legal persons. The расчетный показатель has been 100 som since 1 January 2006 (Law No. 13 of 27 January 2006 art. 2; Jogorku Kenesh Resolution No. 1115-III of 15 June 2006, still «Действует»), so the ceiling is 20,000 som for a natural person and 65,000 som for a legal person - roughly 230 and 745 US dollars. This is the same enforcement gap Kazakhstan has: a fully drafted duty layer sitting on a single narrow offence.

In force · 6 Feb 2026 checked 21 Aug 2026 KG Digital Code arts. 191-193 ↗ high confidence
Kyrgyzstan Binding

Digital Code arts. 194-196 - self-classified high-danger AI needs a signed public declaration of conformity before first use

Binds Владельцы (owners) and пользователи (users) of AI systems that the owner's own danger assessment classifies as high-danger, plus, by art. 126, every provider of a digital wellbeing service that uses AI within the service, without any assessment step. Duties split by role: arts. 194 and 195 fall on the owner, art. 196 on the user, and art. 196(3) moves the owner's set onto a rebrander, repurposer or substantial modifier. No size or sector threshold; Resolution No. 770 para. 2 restates the scope as all owners irrespective of legal form, sectoral affiliation or ownership.. Where the art. 193 danger assessment returns a system whose use raises the risk of harm to the protected goods to a level requiring risk management, art. 194(1) makes it a «система искусственного интеллекта повышенной опасности» - a high-danger AI system - and the Digital Code's substantive regime attaches for the whole life cycle. The classification is comparative and self-executed rather than annex-driven: it asks whether the system raises risk relative to alternative ways of doing the same thing, and art. 194(3) expressly excludes systems whose role in the decision or action is purely auxiliary and does not raise risk. Art. 194(4) hands the Cabinet of Ministers the four requirement families - risk management, system characteristics (openness, explainability, controllability, accuracy, reliability, digital resilience), digital data quality, and technical documentation - and all four now exist as annexes to Resolution No. 770. Art. 194(5) lists seven owner duties: conform to the mandatory requirements; implement and maintain a risk-management system across the whole life cycle; produce proper technical documentation; preserve the system logs while the system is under its control; confirm conformity before first application; remedy identified non-conformities; and, on demand of the competent state body, suspend - and on a final court act terminate - design and development carried on in breach. Art. 195 is the gate: before a high-danger system may be applied, its owner must adopt a declaration of conformity in the form and content approved by the Cabinet of Ministers, cast as a digital document, signed with a qualified digital signature, and posted on the owner's website as a publicly accessible digital record. Art. 196 then binds the user (deployer): operate per the manual, keep the processed data relevant, maintain effective supervision with named responsible persons and allocated resources, notify the owner and suspend use the moment there is ground to believe the manual-compliant use could cause harm, preserve logs, and suspend or terminate on official demand or court act. Art. 196(2) adds an explanation right where the output feeds a decision capable of infringing rights: general information about the system's characteristics and operating principles must be published on the site for consumer-facing systems and supplied in accessible form otherwise, and anyone whose interests the decision touches may demand, free of charge, information letting them understand and check how the result about them was arrived at. Art. 196(3) transfers the owner's duties to whoever puts the system into service under their own name or mark, changes its purpose, makes substantial modifications, or turns it into a high-danger system - the EU AI Act art. 25 pattern - and art. 196(4) releases the original owner in the latter two cases. Art. 196(5) exempts purely personal or family use from most duties, but makes that user and whoever gave them access jointly and severally liable where third-party rights are infringed. One sector is classified by statute rather than by assessment: art. 126 declares AI systems used to deliver digital wellbeing services to be high-danger systems as a matter of law.

In force since 6 February 2026. The Code was enacted by a separate commencement statute. Law No. 179 of 31 July 2025 «О введении в действие Цифрового кодекса Кыргызской Республики», art. 1, brings the Code into effect «по истечении шести месяцев со дня официального опубликования настоящего Закона», with no article and no chapter carved out. Law No. 179 was published in the official state newspaper «Эркин-Тоо» No. 58 (3714) of 5 August 2025; the six months expire at the end of 5 February 2026, and the ЦБД record card for Law No. 179 states dateOfEntry 6 February 2026. Chapter 23 therefore binds from 6 February 2026. The companion Law No. 180 of the same date, which inserted the administrative offence, carries the identical six-month clause in its art. 8 and commenced on the same day. The regime is operable rather than pending: Cabinet of Ministers Resolution No. 770 of 2 December 2025 («Эркин-Тоо» No. 96 (3753) of 5 December 2025) supplies all four art. 194(4) requirement families as annexes 2 to 5, and the art. 195 declaration was completed separately by Cabinet of Ministers Order No. 1181-т of 31 December 2025, which approved the Requirements for the content of the declaration of conformity of high-danger AI systems. Both are «Действует» in ЦБД. Resolution No. 770 commences fifteen days after the Code, i.e. 21 February 2026 on the arithmetic of its own para. 4; the ЦБД card states no dateOfEntry for it.

Stated maximum penalty — Nothing, in administrative terms. The Code of Offences contains no article penalising application of a high-danger AI system without a declaration, non-conformity with the Resolution No. 770 requirements, absence of a risk-management system, loss of logs, or refusal of the art. 196(2) explanation. Art. 228-10, the only AI-specific offence, is confined to the art. 192(2) targeted-unlawful-harm prohibition (200 расчетных показателей for natural persons, 650 for legal persons; the расчетный показатель is 100 som, so 20,000 and 65,000 som). What does bite is non-monetary and, for an operating business, heavier: art. 194(5)(7) and art. 196(1)(7) let the competent state body order suspension of design, development or application on demand, with termination on a final court act. Civil exposure is the other real channel - art. 192(3) makes owners and users liable for harm caused, and for digital wellbeing services art. 127(2) lets the consumer elect a statutory compensation of 100 to 400 расчетных показателей (10,000 to 40,000 som) in place of proving damages, with the burden on the provider to disprove causation.

In force · 6 Feb 2026 checked 21 Aug 2026 KG Digital Code arts. 194-196 ↗ high confidence
Kyrgyzstan Binding

Digital Code art. 197 - tell consumers they are talking to an AI, tell people they are being emotion- or biometrically classified, and label deepfakes

Binds Owners and users of AI systems that interact with natural persons as consumers (part 1); users of emotion-recognition and biometric-classification systems (part 2); users of AI systems for deepfakes (part 4). Danger tier is irrelevant here - a minimal-danger chatbot owes part 1 - and there is no size, sector or nationality threshold. Part 1's register limb additionally reaches the sectoral regulator of the national ecosystem, which must publish the same information on its own site.. Art. 197 is Kyrgyzstan's transparency article and, unlike the rest of Chapter 23, it applies to AI systems at any danger level. Part 1 obliges owners and users who design, develop or apply AI systems in order to interact with natural persons as consumers to inform those consumers of the fact that they are interacting with an AI system, except where it is obvious from the circumstances; it further declares information about the use of AI systems within digital-environment legal relations to be publicly accessible information, which must be posted in accessible and intelligible form both on the sites of the users of those systems and on the site of the sectoral regulator of the national ecosystem - a disclosure register duty that goes beyond the EU AI Act art. 50 equivalent. Part 2 requires users of systems intended for emotion recognition or for the classification of natural persons by biometric characteristics to inform the persons concerned that such a system is being applied to them; Kyrgyzstan regulates these by notification rather than banning them in workplaces and education as the EU does. Part 4 requires users of AI systems for deepfakes to disclose the artificial origin or alteration of the material. Part 3 disapplies parts 1 and 2 - not part 4 - for functions where informing would frustrate lawful use for defence, national security, or public order in the detection, prevention and investigation of crime and criminal prosecution; part 5 disapplies part 4 for lawful use protecting those same goods or in exercise of the freedom of scientific, technical and artistic creativity, teaching and learning, which is a notably wide carve-out from deepfake labelling. Part 6 conditions every one of those exceptions on necessary measures having been taken to protect the affected human and civil rights and freedoms.

In force since 6 February 2026. The Code was enacted by a separate commencement statute. Law No. 179 of 31 July 2025 «О введении в действие Цифрового кодекса Кыргызской Республики», art. 1, brings the Code into effect «по истечении шести месяцев со дня официального опубликования настоящего Закона», with no article and no chapter carved out. Law No. 179 was published in the official state newspaper «Эркин-Тоо» No. 58 (3714) of 5 August 2025; the six months expire at the end of 5 February 2026, and the ЦБД record card for Law No. 179 states dateOfEntry 6 February 2026. Chapter 23 therefore binds from 6 February 2026. The companion Law No. 180 of the same date, which inserted the administrative offence, carries the identical six-month clause in its art. 8 and commenced on the same day. Art. 197 needs no implementing act and none has been issued: the duties are self-executing on the text, and neither Resolution No. 770 nor Order No. 1181-т touches transparency. What has NOT been located is any published register on the site of the sectoral regulator of the national ecosystem under part 1, which the article requires; that is recorded as an open follow-up rather than asserted either way.

Stated maximum penalty — Nothing. There is no administrative offence for failing to disclose AI interaction, for applying emotion recognition or biometric classification without notifying the person, or for publishing an unlabelled deepfake. Art. 228-10 of the Code of Offences, the only AI-specific offence, covers the art. 192(2) targeted-unlawful-harm prohibition alone (200 расчетных показателей for natural persons, 650 for legal persons, at 100 som per показатель). Kyrgyzstan therefore sits at the opposite end from Kazakhstan on this one point: Kazakhstan's KoAP art. 641-1 does penalise failure to inform users about misleading synthetic outputs, at 15 to 100 MRP, while Kyrgyzstan's identical duty carries no fine at all.

In force · 6 Feb 2026 checked 21 Aug 2026 KG Digital Code art. 197 ↗ high confidence

Questions & answers

From the data

When does Digital Code Chapter 23 (arts. 191-197) take effect in Kyrgyzstan?

Digital Code Chapter 23 (arts. 191-197) is already in force, with obligations live since February 6, 2026. Kyrgyzstan legislated on AI before either of its neighbours and commenced after both. Chapter 23 of the Digital Code (Code No. 178 of 31 July 2025, «Эркин-Тоо» No. 59 of 8 August 2025) was adopted five months before Kazakhstan's AI Law was published, but commencement Law No. 179 delayed it by six months from 5 August 2025, so arts. 191-197 bind only from 6 February 2026 - after Kazakhstan (18 January 2026) and Uzbekistan (21 January 2026). It is also the deepest of the three. Art. 193 subjects EVERY AI system applied in the country to an owner-run danger assessment at design, before first use and on any unplanned change, and requires the result AND the methodology to be published on the owner's site and as open data. Systems that the assessment classifies as «повышенной опасности» - high danger, judged comparatively against alternative means, with an express carve-out for purely auxiliary use - then carry the art. 194(5) owner duties (conformity, life-cycle risk management, technical documentation, log retention, remediation, suspension on official demand), the art. 195 gate of a publicly posted declaration of conformity signed with a qualified digital signature before first application, and the art. 196 user duties including a free explanation right for anyone whose rights a decision touches. Art. 126 classifies digital-wellbeing AI as high-danger by statute. Art. 197 applies at any danger level: tell consumers they are dealing with an AI, tell people they are being emotion-recognised or biometrically classified, label deepfakes, and publish AI-use information both on the user's site and on the sectoral regulator's. Unlike Kazakhstan's deferred marking standard, the implementing layer is finished - Cabinet of Ministers Resolution No. 770 of 2 December 2025 approved five annexes under arts. 193 and 194, and Order No. 1181-т of 31 December 2025 approved the declaration content. Enforcement is the thin part: the only AI offence is art. 228-10 of the Code of Offences, inserted by Law No. 180, and it reaches solely the art. 192(2) ban on designing, developing or applying AI to cause targeted and knowingly unlawful harm - 200 расчетных показателей for natural persons and 650 for legal persons, at 100 som per показатель, i.e. 20,000 and 65,000 som. Nothing penalises a missing danger assessment, a missing declaration or an unlabelled deepfake; the real sanctions are regulator-ordered suspension and civil liability.

Who must comply with AI rules in Kyrgyzstan?

Current obligations bind, among others, Владельцы систем искусственного интеллекта - the owners of AI systems applied in the Kyrgyz Republic, with the art. 192(3) risk-minimisation duty extending to users as well. Resolution No. 770 para. 2 spells the scope out: owners of AI systems applied in Kyrgyzstan 'irrespective of organisational-legal form, departmental (sectoral) affiliation and form of ownership'. There is no turnover, headcount, sector or nationality threshold anywhere in Chapter 23, so a sole trader running one model and a state body running a national platform owe the same assessment and the same publication.; Владельцы (owners) and пользователи (users) of AI systems that the owner's own danger assessment classifies as high-danger, plus, by art. 126, every provider of a digital wellbeing service that uses AI within the service, without any assessment step. Duties split by role: arts. 194 and 195 fall on the owner, art. 196 on the user, and art. 196(3) moves the owner's set onto a rebrander, repurposer or substantial modifier. No size or sector threshold; Resolution No. 770 para. 2 restates the scope as all owners irrespective of legal form, sectoral affiliation or ownership.. Scope and thresholds vary per instrument — see each row's source for the legal text.

What are the penalties for AI non-compliance in Kyrgyzstan?

Stated statutory maxima include: KG Digital Code arts. 191-193 — Nothing. There is no administrative offence for failing to run the danger assessment, for using a methodology that does not meet the Resolution No. 770 requirements, or for not publishing the result and the methodology. The only AI-specific offence Kyrgyzstan created is art. 228-10 of the Code of Offences (Code No. 128 of 28 October 2021, article inserted by Law No. 180 of 31 July 2025), and it reaches only the art. 192(2) prohibition: design, development or application of AI systems for the targeted and knowingly unlawful causing of harm to the protected goods, fined at 200 расчетных показателей for natural persons and 650 for legal persons. The расчетный показатель has been 100 som since 1 January 2006 (Law No. 13 of 27 January 2006 art. 2; Jogorku Kenesh Resolution No. 1115-III of 15 June 2006, still «Действует»), so the ceiling is 20,000 som for a natural person and 65,000 som for a legal person - roughly 230 and 745 US dollars. This is the same enforcement gap Kazakhstan has: a fully drafted duty layer sitting on a single narrow offence.; KG Digital Code arts. 194-196 — Nothing, in administrative terms. The Code of Offences contains no article penalising application of a high-danger AI system without a declaration, non-conformity with the Resolution No. 770 requirements, absence of a risk-management system, loss of logs, or refusal of the art. 196(2) explanation. Art. 228-10, the only AI-specific offence, is confined to the art. 192(2) targeted-unlawful-harm prohibition (200 расчетных показателей for natural persons, 650 for legal persons; the расчетный показатель is 100 som, so 20,000 and 65,000 som). What does bite is non-monetary and, for an operating business, heavier: art. 194(5)(7) and art. 196(1)(7) let the competent state body order suspension of design, development or application on demand, with termination on a final court act. Civil exposure is the other real channel - art. 192(3) makes owners and users liable for harm caused, and for digital wellbeing services art. 127(2) lets the consumer elect a statutory compensation of 100 to 400 расчетных показателей (10,000 to 40,000 som) in place of proving damages, with the burden on the provider to disprove causation.. These are the maximum amounts in the instruments; actual enforcement is at the regulator's discretion.