AI risk obligations
Digital Code, Chapter 23: AI system design and risk-management obligations
Digital Code, Law No. 178 (18 June 2025), in force 6 February 2026, Chapter 23, Arts. 191-196text of Chapter 23 (Systems of Artificial Intelligence)
In force 8 months, effective 6 February 2026. Binds public and private bodies.
What this law does
Arts. 191-196, read in full, establish Kyrgyzstan's AI governance framework: Art. 191 sets non-binding design principles (risk reduction, openness, explainability, human oversight, accuracy, reliability, security) that any later binding requirement must implement, and Arts. 192-196 attach binding duties once an owner's own hazard assessment finds a system poses increased danger to a protected interest.
An owner of such a system must reassess and republish the hazard assessment at each life-cycle stage, meet Cabinet of Ministers risk-management and documentation requirements, keep operating logs, and declare conformity by a published, digitally signed document before deployment.
A user of such a system must operate it per its instructions, maintain effective human oversight, immediately suspend use and notify the owner once it has grounds to believe use could cause harm, keep logs, comply with a suspension or final court order, and, where the system's output feeds a rights-affecting decision, explain that result to an affected person on request free of charge; a person using the system solely for personal or family needs is excused most of these duties.
Chapter 23 states no duty for an owner or a user to notify the authorized state body of a suspension or of grounds to believe a system may cause harm: that body's role under Arts. 194(5)(7) and 196(1)(7) is to demand a suspension the owner or user must then carry out, enforceable by a final court act ordering the system's use to stop.
What it requires