Digital Code, Chapter 23: AI system design and risk-management obligations
Digital Code, Law No. 178 (18 June 2025), in force 6 February 2026, Chapter 23, Arts. 191-196
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
In force 7 months, effective 6 February 2026.
An AI risk obligations rule binding public and private bodies.
As of 7 September 2026.
What it requires
- An app that designs, develops or applies an AI system in Kyrgyzstan may do so without restriction beyond what the Digital Code sets, and should follow the Code's principles of risk reduction, openness, explainability, human oversight, accuracy, reliability and security.
- An app whose AI system a hazard assessment finds poses increased danger to life, health, rights, the environment, defense, national security or public order must have its owner reassess that hazard at each design, development, deployment and material-change stage, and publish the assessment and its methodology on the owner's own website as open data.
- An owner of such a heightened-risk system must meet the Cabinet of Ministers' risk-management, transparency, accuracy, reliability, data-quality and technical-documentation requirements, keep operating logs, and declare conformity in a signed digital document published on the owner's site before the system is deployed.
- A user of such a heightened-risk system must operate it per its instructions, keep the data it processes relevant, maintain effective human oversight and resourcing, suspend use and notify the owner on signs of harm, keep operating logs, and comply with a regulator's suspension order or a final court order to stop using the system.
- Where such a system's output feeds a decision that could affect a person's rights, the user must publish or otherwise supply plain-language information about the system and, on request from an affected person, explain free of charge how that person's result was reached.
What it reaches
Obligation class
DPIA, Governance
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
Arts. 191-196, read in full, establish Kyrgyzstan's AI governance framework: Art. 191 sets non-binding design principles (risk reduction, openness, explainability, human oversight, accuracy, reliability, security) that any later binding requirement must implement, and Arts. 192-196 attach binding duties once an owner's own hazard assessment finds a system poses increased danger to a protected interest.
An owner of such a system must reassess and republish the hazard assessment at each life-cycle stage, meet Cabinet of Ministers risk-management and documentation requirements, keep operating logs, and declare conformity by a published, digitally signed document before deployment.
A user of such a system must operate it per its instructions, maintain effective human oversight, suspend use and notify the owner on signs of harm, keep logs, comply with a suspension or final court order, and, where the system's output feeds a rights-affecting decision, explain that result to an affected person on request free of charge; a person using the system solely for personal or family needs is excused most of these duties.
When LexLint raises it
high_risk_decisions
Read the law
text of Chapter 23 (Systems of Artificial Intelligence)
Articles 191 through 196, of the Digital Code of the Kyrgyz Republic, Law No. 178 of 31 July 2025, reproduced by ИС Континент (continent-online.com), a commercial CIS legal-database mirror