Publications

Law of the Republic of Azerbaijan "On the Regulation of Artificial Intelligence"

PREAMBLE

References: the Constitution; Presidential Decree No. 530 of 19.03.2025 and the 2025–2028 Strategy; Decree No. 3378 (Strategy for Socio-Economic Development 2022–2026); Decree No. 4060 (Cybersecurity Strategy 2023–2027); Council of Europe Framework Convention on AI; commitments under ISO/IEC, etc.
This image was generated using AI
July 28, 2026

CHAPTER I. GENERAL PROVISIONS

Art. 1. Subject matter and objectives
Art. 2. Scope of application
Art. 3. Exclusions (defence and national security)
Art. 4. Key definitions
Art. 5. Principles (can be drawn from the Strategy + international instruments)
Art. 6. Relationship with other laws
Art. 7. Azerbaijani language and digital sovereignty (aligns with the Strategy)

CHAPTER II. CLASSIFICATION OF AI SYSTEMS BY RISK LEVEL

Art. 8. Approach to risk classification.
Art. 9. Prohibited practices (social scoring by public authorities, manipulative systems exploiting vulnerabilities, indiscriminate biometric scraping, emotion recognition in the workplace and in education, predictive policing based solely on profiling, socio-demographic scoring of natural persons by the State beyond purposes established by law)
Art. 10. High-risk AI systems (general definition + list in Annex I)
Art. 11. Priority sectors (referral mechanism: the list is approved by the Cabinet of Ministers in accordance with the Strategy)
Art. 12. Limited-risk systems (transparency obligations)
Art. 13. Minimal-risk systems (voluntary codes of practice)

CHAPTER III. REQUIREMENTS FOR HIGH-RISK AI SYSTEMS

Art. 14. Risk management system
Art. 15. Data quality and data governance (link to the Strategy)
Art. 16. Technical documentation
Art. 17. Automatic record-keeping (logging)
Art. 18. Transparency and provision of information to deployer organisations
Art. 19. Human oversight
Art. 20. Accuracy, robustness and cybersecurity (link to the Strategy and the Cybersecurity Strategy)
Art. 21. Quality management system (ISO/IEC 42001)
Art. 22. Conformity assessment procedure
Art. 23. “AZ-AI” conformity mark and national registration

CHAPTER IV. OBLIGATIONS OF ACTORS

Art. 24. Obligations of providers
Art. 25. Obligations of deployers
Art. 26. Obligations of importers
Art. 27. Obligations of distributors
Art. 28. Authorised representatives of foreign providers
Art. 29. Responsibility along the value chain (change of roles upon substantial modification)
Art. 30. National register of AI systems.

CHAPTER V. GENERAL-PURPOSE AI MODELS (GPAI)

Absent from the Strategy, but in my view critical for the development of AI (open to discussion)
Art. 31. Definition of GPAI and criteria (compute + qualitative)
Art. 32. Baseline obligations: technical documentation, information for downstream providers
Art. 33. Copyright compliance policy
Art. 34. Summary of training data (including special requirements for Azerbaijani-language data)
Art. 35. GPAI with systemic risk: red-teaming, incident reporting, enhanced cybersecurity
Art. 36. Regime for open-source GPAI: partial exemptions subject to conditions

CHAPTER VI. TRANSPARENCY AND COUNTERING DISINFORMATION

A direct response to the threats named in Section 3 of the Strategy: “deepfakes, disinformation attacks, etc.”
Art. 37. Disclosure of interaction with AI
Art. 38. Labelling of synthetic content and deepfakes (visible + embedded metadata, modelled on the Chinese Measures 2025 with a human-rights adjustment)
Art. 39. Notification in cases of emotion recognition and biometric categorisation
Art. 40. Special regime during electoral periods and in respect of public figures
Art. 41. Interaction with the protection of honour, dignity and business reputation

CHAPTER VII. AI IN THE PUBLIC SECTOR

Art. 42. Mandatory algorithmic impact assessment (AIA) prior to deployment
Art. 43. Public register of AI systems of state bodies
Art. 44. Rules for AI procurement (link to the Law “On Public Procurement”)
Art. 45. Heightened requirements for systems making decisions about citizens (social benefits, taxation, migration, justice, law enforcement)
Art. 46. Integration with “E-Government” and “G-Cloud”
Art. 47. Special regime for the systems of DTX, XRİTDX, defence and intelligence

CHAPTER VIII. RIGHTS OF PERSONS AFFECTED BY AI SYSTEMS

Art. 48. Right to information
Art. 49. Right to an explanation of an automated decision
Art. 50. Right to human review
Art. 51. Right to lodge a complaint with the competent authority
Art. 52. Right to an effective remedy
Art. 53. Collective actions (corresponds to the Civil Procedure Code)

CHAPTER IX. INSTITUTIONAL FRAMEWORK

Art. 54. AI Coordination Council under the Cabinet of Ministers
Art. 55. Ministry of Digital Development and Transport
Art. 56. Sectoral competent authorities
Art. 57. Powers of XRİTDX in the field of information security of AI in state bodies
Art. 58. Powers of DTX on national security aspects (reflecting the Strategy on threats)
Art. 59. Standardisation and market surveillance in the consumer sphere (in line with the Strategy)
Art. 60. Notified conformity assessment bodies
Art. 61. Monitoring and evaluation functions
Art. 62. Scientific advisory panel under the Coordination Council
Art. 63. Representation of the Republic of Azerbaijan in international AI bodies

CHAPTER X. SUPPORT FOR INNOVATION AND THE ECOSYSTEM

Art. 64. Regulatory sandboxes
Art. 65. Testing in real-world conditions
Art. 66. Special regime for SMEs and start-ups (link to the Strategy – preferential loans)
Art. 67. Legal status of the AI Academy (institutionalisation of the Strategy)
Art. 68. Open government data for training AI
Art. 69. Azerbaijani-language NLP infrastructure
Art. 70. Incentives for residents of technology parks and SEZs

CHAPTER XI. STANDARDISATION

Art. 71. National AI standards
Art. 72. Presumption of conformity where harmonised standards are applied
Art. 73. Recognition of international standards (ISO/IEC 42001, 23894, 22989, 23053, etc.)

CHAPTER XII. MARKET SURVEILLANCE AND ADMINISTRATIVE LIABILITY

Art. 74. Market surveillance powers
Art. 75. Investigative powers
Art. 76. Corrective measures (recall, suspension, withdrawal)
Art. 77. Administrative penalties, scale: up to 7% of annual turnover for breach of the prohibitions (Art. 9); up to 3% for breach of high-risk requirements; up to 1.5% for GPAI and transparency; reduced caps for SMEs, in manats
Art. 78. Corresponding amendments to the Code of Administrative Offences

CHAPTER XIII. CIVIL LIABILITY

Art. 79. Civil liability for harm caused by an AI system
Art. 80. Burden of proof and eased presumptions in favour of the claimant
Art. 81. Relationship with producer’s liability
Art. 82. Disclosure of evidence in court

CHAPTER XIV. INTERNATIONAL COOPERATION

Art. 83. Implementation of Conventions (need to search for the ratified instruments)
Art. 84. Mutual recognition of conformity assessments
Art. 85. Cross-border cooperation with market surveillance authorities
Art. 86. Regional cooperation

CHAPTER XV. TRANSITIONAL AND FINAL PROVISIONS

Art. 87. Phased entry into force (synchronised with the Strategy):

  • General provisions, prohibitions, principles – after 6 months.
  • Transparency, GPAI, citizens’ rights – after 12 months.
  • Requirements for high-risk systems, conformity assessment – after 24 months.
  • Mandatory registration and penalties – after 30 months.
  • Full implementation – by the end of 2028 (conclusion of the Strategy).
Art. 88. Regime for systems already put into service (grandfathering)
Art. 89. Amendments to related laws (package of amendments)
Art. 90. Review of the law every 3 years
Art. 91. Subordinate acts of the Cabinet of Ministers

ANNEXES

I. List of areas of use of high-risk AI systems (with an updating mechanism by the Cabinet of Ministers)
II. Requirements for technical documentation
III. Conformity assessment procedures (A, B, C)
IV. Criteria for determining systemic risk for GPAI
V. Structure and content of the algorithmic impact assessment (AIA)
VI. Criteria for determining priority sectors (per the Strategy)
VII. Requirements for Azerbaijani-language support