AI in action: use cases, risks and governance in Colombia

Tuesday 6 October 2026

Sergio Michelsen
Brigard Urrutia, Bogotá, Colombia
smichelsen@bu.com.co

Companies in Colombia are increasingly adopting artificial intelligence (AI) tools in their daily operations, which raises significant legal challenges that must be carefully examined. These challenges can be addressed through three main pillars: (i) the general framework on AI and the regulatory landscape in Colombia, as well some foreign legal frameworks that serve as reference; (ii) specific legal risks in business practices; and (iii) corporate governance recommendations for responsible AI implementation.

Defining AI and the regulatory landscape

Understanding AI begins with its conceptual foundations. The EU AI Act[1] defines AI as a machine-based system designed to operate with varying levels of autonomy, capable of adaptation after deployment and which infers from input data how to generate outputs such as predictions, content, recommendations or decisions. Colombia’s CONPES 3975 describes it as a field of computer science dedicated to solving cognitive problems commonly associated with human intelligence. It is important to emphasise that AI is not a one-size-fits-all solution: it entails costs, implementation timelines and requires careful evaluation of whether it genuinely improves processes.

Regarding the regulatory panorama, three jurisdictions merit mention: the EU (where the AI Act is already in force), the US (with a more sector-specific approach) and Colombia, where a patchwork of instruments coexists, including CONPES 3975, the Superintendence of Industry and Commerce’s (SIC) guidelines on data protection and consumer law, pending legislative bills, resolutions by the National Copyright Directorate (DNDA) and the Ministry of ICT’s ethical guide for public entities.

Legal risks in business practices

The analysis of specific legal risks begins with a foundational premise: when using third-party AI tools, the primary risk lies not only in the outputs generated, but also in the information introduced in the prompts. Organisations must assume that using these tools may constitute disclosure of information to a third party. Three risk axes can be identified: (i) personal data, requiring verification of data subject authorisation and provider security guarantees; (ii) confidential information, where using AI tools may breach confidentiality agreements absent proper authorisation; and (iii) copyright, as input information may be used to train the model, generating unauthorised uses.

On the output side, one cannot assume AI-generated content may be used without restrictions. Many providers include contractual limitations on the use of results. Furthermore, the authorship question must be addressed: if an output is generated entirely by a machine without substantial human creative intervention, there is an ongoing debate about whether it qualifies for copyright protection, with the practical consequence that third parties could use it without authorisation. The need for human review must be emphasised as a quality and risk control measure, with references to cases such as Mata v Avianca,[2] where lawyers were sanctioned for citing AI-fabricated cases. A proportional human-in-the-loop protocol is recommended depending on the risk level of each use case.

Multiple specific use cases illustrate these risks. In personalised experiences (social media feeds, streaming), the massive use of personal data raises concerns about whether companies rely on their own data or web scraping techniques. In human resources, AI-driven selection parameters can generate discrimination by sex, age or other characteristics, warranting data anonymisation and human supervision. For customer service chatbots, the risk lies in what the chatbot says when it deviates from its script and what it learns from users, as illustrated by cases involving major platforms. Defining guardrails is recommended, including AI interaction disclaimers and maintaining human escalation mechanisms.

Additional use cases include inventory management and logistics (where AI optimises demand forecasting, supplier management, anomaly detection and distribution route optimisation, with challenges around commercially sensitive information and data sharing among competitors); CCTV surveillance (where facial recognition and biometric surveillance must meet strict criteria of legality, necessity and proportionality, as established in international precedent); and dynamic pricing (where a recent Maryland law restricting personal data-based dynamic pricing illustrates the risks of consumer protection violations and anticompetitive practices). In AI-generated marketing images, data protection and copyright risks arise from advertising with AI-generated person likenesses, making indemnity clauses and thorough review of tool terms of service advisable.

Governance recommendations

From the developers’ perspective, AI developers face risks stemming from lack of governance and control over development, use of low-quality or biased data, non-compliance with data protection and human rights regulations, absence of adequate pre-deployment testing and failure to incorporate privacy and security by design principles.

Practical governance recommendations applicable to both AI users and developers/providers include (i) identifying the real need for AI and establishing clear usage policies; (ii) conducting due diligence in vendor selection and ensuring contracts serve as the first line of defence against AI risks, with provisions addressing intellectual property ownership, data processing roles, indemnification, service levels and audit rights; (iii) implementing a continuous AI risk management system proportional to potential harms; (iv) conducting privacy impact assessments before deployment when high risks to data subjects are foreseeable; (v) ensuring transparency and user information about AI interactions; (vi) guaranteeing human oversight of AI systems, particularly for high-risk decisions; (vii) applying privacy by design and by default principles; (viii) ensuring data quality, accuracy and integrity; (ix) adopting robust cybersecurity measures; (x) establishing clear responsibilities across the AI value chain; and (xi) guaranteeing the rights of data subjects and users affected by AI-driven decisions.

Conclusion

AI is already transforming critical business decisions, and understanding its risks is not optional; it is part of the work of any management team seeking to adopt AI strategically, safely and sustainably. Companies operating in Colombia must navigate a complex regulatory environment that, while lacking a comprehensive AI-specific statute, draws on existing data protection, consumer law and copyright frameworks to impose meaningful obligations on AI users and developers alike. The practical recommendations outlined above provide a roadmap for organisations to implement AI responsibly while managing legal, reputational and operational risks.


[1] Regulation (EU) 2024/1689 laying down harmonised rules on artificial intelligence (EU Artificial Intelligence Act) [2024] OJ L2024/1689.

[2] Mata v Avianca Inc 678 F Supp 3d 443 (SDNY 2023).