26 August 2026

AI regulation in Chile and Costa Rica: what it means if you want a chatbot

Chile has an AI bill in the Senate with fines up to 20,000 UTM. Costa Rica has a strategy and no law. Neither stops you, but both change how you should go about it.

Every week we get the same question: can I put an AI chatbot in my company, or will I get into trouble?

The short answer is yes, and that in neither country is there a law today stopping you. The long answer is more useful.

Chile: there is a bill, and it is serious

Chile leads AI regulation in the region. The bill was introduced by presidential message in May 2024, the Chamber of Deputies approved it in detail on October 13, 2025, and it has been in the Senate since, in its second constitutional stage.

It follows the European model: it classifies uses by risk level.

  • Unacceptable risk: prohibited.
  • High risk: allowed with strong requirements for transparency, human oversight and documentation.
  • Limited risk: transparency obligations, essentially disclosing that someone is interacting with an AI.
  • No evident risk: no specific obligations.

Proposed fines reach 20,000 UTM, alongside a civil liability regime and confidentiality duties.

In parallel, in July 2026 the Chamber approved a separate bill targeting deepfakes. Different initiatives, same direction.

Costa Rica: a strategy, not yet a law

Costa Rica adopted a National Artificial Intelligence Strategy 2024-2027, developed with European Union support and aligned with OECD principles and the Hiroshima AI Process. It has six pillars: ethics and governance, infrastructure, education and talent, innovation, international leadership and public sector transformation.

A strategy is not a law: it creates no enforceable obligations. The legislative discussion exists and revolves mainly around data protection, where Costa Rica has an acknowledged gap: Law 8968 dates from 2011 and the country holds no EU adequacy recognition.

What to do today, law or no law

The practical part does not depend on what gets passed. If you are going to use AI in your business, these four hold in both scenarios.

Disclose that it is an AI

It is the most likely obligation in any regulation that passes, and it works better anyway: people forgive a mistake from an identified bot, and do not forgive feeling deceived.

Choose carefully where you put it

An assistant answering questions about hours and prices is low risk under any classification. One that decides who gets credit, who gets hired or how a medical case is prioritized is exactly what the Chilean bill would treat as high risk.

Make it answer from your documents, not from memory

An unconstrained model invents. The technique used to prevent this is RAG: the model answers citing your actual documents instead of generating from its training. Beyond reducing errors, it leaves a trail of why it answered what it answered — which is precisely what an audit asks for.

That is how we build our AI agents and chatbots: they answer with the company's information, not with what the model remembers.

Watch the data you feed it

This is the part most often missed. If your chatbot processes customer data, personal data law already applies — in Chile that is Law 21.719, effective December 1, 2026. AI regulation is still being debated; data regulation already has a date.

In short

Do not wait for the law to use AI. Start with low-risk cases, disclose that it is a bot, make it answer from your documents, and treat data as if the law were already in force — because when it comes to personal data in Chile, it practically is.


At egobytes we build AI agents and chatbots that answer with your business's real information. Let's talk.

Sources: Chilean Senate — bill status · MinCiencia — AI systems bill · Costa Rica National AI Strategy (MICITT)

If you can imagine it, we can build it.

Tell us what you need. We'll get back with a clear proposal, no jargon.