Skip to main content

Kazakhstan AI Law

Law of the Republic of Kazakhstan on Artificial Intelligence (Law No. 230-VIII)

First comprehensive AI law in Central Asia. Establishes risk-based classification (low/medium/high-risk), mandatory AI content labeling, and explicit prohibitions on manipulation, social scoring, and non-consensual emotion detection. Requires annual risk assessments for high-risk systems.

Jurisdiction

Kazakhstan

KZ

Enacted

Nov 17, 2025

Effective

Jan 18, 2026

Enforcement

Ministry of Artificial Intelligence and Digital Development

Signed November 17, 2025; effective January 18, 2026

Who Must Comply

This law applies to:

  • AI system developers
  • AI system owners/operators
  • Users of AI systems in Kazakhstan

Who bears obligations:

This regulation places direct obligations on deployers (organizations using AI systems).

Safety Provisions

  • Prohibited: AI using manipulative techniques affecting subconscious or distorting behavior
  • Prohibited: AI exploiting vulnerabilities (age, disability) to cause harm
  • Prohibited: Social scoring based on social behavior or personal characteristics
  • Prohibited: Emotion detection without subject consent (except legal cases)
  • Prohibited: Biometric classification for discrimination (race, political views, etc.)
  • Mandatory labeling: All synthetic content (image, video, audio, text) must carry machine-readable marker and user disclosure
  • Continuous lifecycle risk management required; systems must be suspended if threatening rights
  • User right to understand AI operation and data basis for decisions
  • Right to refuse AI interaction unless required by law

Compliance Timeline

Jan 18, 2026

All provisions take effect

Enforcement

Enforced by

Ministry of Artificial Intelligence and Digital Development

Penalties

Administrative liability for violations including failure to inform users about synthetic content and failure to manage high-risk AI risks

Quick Facts

Binding
Yes
Mental Health Focus
Yes
Child Safety Focus
Yes
Algorithmic Scope
Yes

Why It Matters

Prohibitions on manipulation and emotion detection without consent directly align with NOPE's harmful AI behavior detection. Mandatory content labeling creates transparency requirements.

Recent Developments

First Central Asian country to enact comprehensive AI legislation. Law closely mirrors EU AI Act prohibited practices.

What You Need to Comply

Developers must conduct continuous lifecycle risk management with annual reviews. High-risk systems require enhanced information security controls. All synthetic content must be labeled with machine-readable markers.

NOPE can help

Cite This

APA

Kazakhstan. (2025). Law of the Republic of Kazakhstan on Artificial Intelligence (Law No. 230-VIII). Retrieved from https://nope.net/regs/kz-ai-law

BibTeX

@misc{kz_ai_law,
  title = {Law of the Republic of Kazakhstan on Artificial Intelligence (Law No. 230-VIII)},
  author = {Kazakhstan},
  year = {2025},
  url = {https://nope.net/regs/kz-ai-law}
}

Related Regulations

Enacted VN AI Safety

Vietnam AI Law

First comprehensive AI law in Southeast Asia. Risk-management oriented framework with high-risk AI list updated by Prime Minister. Applies extraterritorially to foreign organizations whose AI systems impact Vietnamese users.

In Effect CN AI Safety

China GenAI Labeling Rules

Mandatory labeling of AI-generated content (implicit for all, explicit where applicable). Released by State Administration for Market Regulation and Standardization Administration of China. Complements existing GenAI interim measures with three national standards for AI security and governance.

Enacted UZ AI Safety

Uzbekistan AI Law

Uzbekistan's AI governance framework via amendments to Law on Informatization. Mandates AI content labeling, prohibits AI decisions affecting rights without human oversight, and establishes protections against AI harms to life, health, and dignity. Responds to 3x increase in AI-related violations (1,129 in 2023 to 3,553 in 2024).

In Effect MY Online Safety

Malaysia OSA

Requires licensed platforms to implement content moderation systems, child-specific safeguards, and submit Online Safety Plans. Nine categories of harmful content regulated.

In Effect RU Online Safety

Blogger Registration Law

Requires bloggers with audiences exceeding 10,000 users to register with Roskomnadzor and restricts content reposting and advertising on unregistered pages.

In Effect SG Sector-Specific

SG MAS AI Governance

First mandatory AI governance requirements in Singapore, shifting from voluntary Model AI Governance Framework to binding obligations for financial sector. Establishes three mandatory focus areas: oversight and governance, risk management systems, and development/validation/deployment protocols.