Kazakhstan AI Law
Law of the Republic of Kazakhstan on Artificial Intelligence (Law No. 230-VIII)
First comprehensive AI law in Central Asia. Establishes risk-based classification (low/medium/high-risk), mandatory AI content labeling, and explicit prohibitions on manipulation, social scoring, and non-consensual emotion detection. Requires annual risk assessments for high-risk systems.
Jurisdiction
Kazakhstan
KZ
Enacted
Nov 17, 2025
Effective
Jan 18, 2026
Enforcement
Ministry of Artificial Intelligence and Digital Development
Signed November 17, 2025; effective January 18, 2026
What It Requires
Who Must Comply
Safety Provisions
- • Prohibited: AI using manipulative techniques affecting subconscious or distorting behavior
- • Prohibited: AI exploiting vulnerabilities (age, disability) to cause harm
- • Prohibited: Social scoring based on social behavior or personal characteristics
- • Prohibited: Emotion detection without subject consent (except legal cases)
- • Prohibited: Biometric classification for discrimination (race, political views, etc.)
- • Mandatory labeling: All synthetic content (image, video, audio, text) must carry machine-readable marker and user disclosure
- • Continuous lifecycle risk management required; systems must be suspended if threatening rights
- • User right to understand AI operation and data basis for decisions
- • Right to refuse AI interaction unless required by law
Compliance Timeline
Jan 18, 2026
All provisions take effect
Enforcement
Enforced by
Ministry of Artificial Intelligence and Digital Development
Penalties
Administrative liability for violations including failure to inform users about synthetic content and failure to manage high-risk AI risks
Quick Facts
- Binding
- Yes
- Mental Health Focus
- Yes
- Child Safety Focus
- Yes
- Algorithmic Scope
- Yes
Why It Matters
Prohibitions on manipulation and emotion detection without consent directly align with NOPE's harmful AI behavior detection. Mandatory content labeling creates transparency requirements.
Recent Developments
First Central Asian country to enact comprehensive AI legislation. Law closely mirrors EU AI Act prohibited practices.
What You Need to Comply
Developers must conduct continuous lifecycle risk management with annual reviews. High-risk systems require enhanced information security controls. All synthetic content must be labeled with machine-readable markers.
NOPE can helpCite This
APA
Kazakhstan. (2025). Law of the Republic of Kazakhstan on Artificial Intelligence (Law No. 230-VIII). Retrieved from https://nope.net/regs/kz-ai-law
BibTeX
@misc{kz_ai_law,
title = {Law of the Republic of Kazakhstan on Artificial Intelligence (Law No. 230-VIII)},
author = {Kazakhstan},
year = {2025},
url = {https://nope.net/regs/kz-ai-law}
} Related Regulations
Vietnam AI Law
First comprehensive AI law in Southeast Asia. Risk-management oriented framework with high-risk AI list updated by Prime Minister. Applies extraterritorially to foreign organizations whose AI systems impact Vietnamese users.
China GenAI Labeling Rules
Mandatory labeling of AI-generated content (implicit for all, explicit where applicable). Released by State Administration for Market Regulation and Standardization Administration of China. Complements existing GenAI interim measures with three national standards for AI security and governance.
Uzbekistan AI Law
Uzbekistan's AI governance framework via amendments to Law on Informatization. Mandates AI content labeling, prohibits AI decisions affecting rights without human oversight, and establishes protections against AI harms to life, health, and dignity. Responds to 3x increase in AI-related violations (1,129 in 2023 to 3,553 in 2024).
Malaysia OSA
Requires licensed platforms to implement content moderation systems, child-specific safeguards, and submit Online Safety Plans. Nine categories of harmful content regulated.
Blogger Registration Law
Requires bloggers with audiences exceeding 10,000 users to register with Roskomnadzor and restricts content reposting and advertising on unregistered pages.
SG MAS AI Governance
First mandatory AI governance requirements in Singapore, shifting from voluntary Model AI Governance Framework to binding obligations for financial sector. Establishes three mandatory focus areas: oversight and governance, risk management systems, and development/validation/deployment protocols.