AI Regulation Comes to Central Asia: What Kazakhstan's New Law Means for Business

AI regulation is becoming a practical business issue in Central Asia. Kazakhstan is the first country in the region to introduce dedicated AI legislation, establishing new requirements for how AI can be used, how data should be handled and who remains accountable for AI-driven decisions. For banks and companies, the challenge goes beyond compliance. The key question is how to build the governance, risk management and technology controls needed to use AI safely without unnecessarily limiting its business potential.
For years, artificial intelligence developed faster than the legislation governing it. Early approaches relied largely on ethical principles and existing laws. This became increasingly difficult as AI moved into areas such as recruitment, lending, identity verification, medical diagnostics and other decisions with a direct impact on individuals.
The risks evolved at the same time. Organizations had to address the use of personal data, potential discrimination, algorithmic opacity and the difficulty of explaining AI-supported decisions. Generative AI added another dimension as employees gained the ability to send documents, source code, customer information and other sensitive data to powerful external models.
Governments responded by moving from broad principles towards dedicated AI regulation.
The European Commission proposed the AI Act in April 2021, and the EU AI Act entered into force on 1 August 2024. It established a comprehensive framework designed to support safe and trustworthy AI, protect fundamental rights and maintain conditions for innovation and investment.
This regulatory shift has now reached Central Asia. Kazakhstan has become the first country in the region to adopt a dedicated Law on Artificial Intelligence.
For businesses operating across Central Asia, Kazakhstan matters beyond its domestic market. AI adoption is accelerating across the region, and requirements around AI Risk Management, data protection, information security and AI Governance are likely to develop alongside it.
What Does the New Law Regulate?
The law establishes a framework for protecting citizens from AI-related risks while setting rules for the use of AI by government and business.
It addresses where and for what purposes AI can be used, which practices are prohibited, what requirements apply when AI interacts with customers or processes data, and who remains responsible for AI-related decisions and their consequences.
For businesses, one principle is particularly important. The greater the impact of an AI system on a customer, employee or management decision, the greater the need for appropriate controls.
This makes AI governance a business and risk management issue as well as a technology issue.
What Restrictions Apply to AI?
The requirements can broadly be grouped into three categories.
First, the law establishes direct prohibitions. AI cannot be used for practices such as covert manipulation of human behaviour, exploitation of vulnerabilities, certain forms of social scoring or discrimination involving biometric data. Other applications capable of violating human rights are also restricted.
Second, some uses of AI remain permitted subject to additional conditions. For example, AI-based emotion recognition requires consent except in circumstances provided for by law. Additional requirements also apply when AI processes personal data or other information with restricted access.
Third, the law establishes rights for individuals and accountability for organizations. Customers should know when they are interacting with AI. Where an AI-supported decision affects their rights or interests, they can request an explanation and challenge the decision.
Responsibility remains with the organization using AI, not with the AI system itself.
For a bank or company, the practical assessment therefore depends on three factors: what AI is being used for, what data it processes and how significantly its output can affect a person.
External AI Models
Kazakhstan's law does not prohibit the use of external LLMs. Banks and companies can use modern AI models when appropriate data, security and AI risk management controls are in place.
External AI Models and Corporate Data
This becomes particularly relevant as organizations adopt external AI services such as ChatGPT, Claude, Gemini and Cursor.
These tools give employees access to some of the most advanced AI models available, but they also introduce new data management challenges. Employees may send documents, customer information, financial data, source code or other confidential material to an external AI service.
Organizations need to understand what information can be shared, where it is processed and what safeguards are provided by the AI service provider.
Enterprise subscriptions and APIs can reduce some risks, but they do not eliminate the need for internal governance and technical controls.
Depending on the use case and data classification, controls may include access restrictions, data masking, request logging or an AI Gateway. Highly sensitive information may need to remain within protected infrastructure, while less sensitive use cases may be suitable for external models under appropriate controls.
Kazakhstan's law does not establish a direct prohibition on external LLMs. Organizations therefore need to determine when and how these models can be used safely.
From AI Restrictions to AI Risk Management
Many banks and large companies in Central Asia currently restrict access to external LLMs and AI services because of concerns about data leakage and the absence of established security policies.
Such restrictions can reduce immediate risk, but they also limit the business value organizations can obtain from AI.
Large European banks are already moving towards controlled adoption. BBVA, for example, introduced corporate use of ChatGPT Enterprise together with OpenAI and integrated it into the bank's security, Compliance and AI Governance requirements. According to BBVA, employees in the initial stage saved approximately three hours per week on average.
Deutsche Bank reports that more than 80% of its employees use Generative AI and digital assistants.
Different use cases and different types of data require different controls. An organization may use external models for some tasks, additional protection mechanisms for others and closed internal environments for its most sensitive workloads.
This changes the management question. Instead of deciding whether employees can use AI at all, organizations need to determine the conditions under which each AI use case can be used safely.
Doing this requires collaboration across Business, IT, Risk Management, Information Security, Data Management, Legal and Compliance.
AI adoption therefore requires investment in technology and in the organization's ability to govern and use that technology safely.
AI Risk Management
Effective AI Risk Management enables organizations to use AI at business-relevant scale. Excessive restrictions can slow adoption and reduce its potential value.
What Should Banks and Companies Do Now?
A practical AI governance and risk management framework can start with six sequential steps.
1. Build an AI Inventory
Identify the AI systems and tools already being used across the organization. This should include enterprise solutions, pilots, external AI services and tools adopted directly by employees.
2. Identify the Use Cases
For each use case, establish the business purpose, who uses the AI and whether its output affects customers, employees or business decisions.
3. Classify the Data
Determine what data each use case processes. Define its confidentiality level and the rules governing access, processing and transfer outside the organization.
4. Assess the Risks
Evaluate the purpose of the AI system, the data involved, its impact on customers and employees, and the potential consequences of errors or misuse.
5. Define Controls and Architecture
Select controls proportionate to the risk. These may include restrictions on certain data, access controls, masking, external versus internal models, logging and other technical or organizational safeguards.
6. Establish Continuous Monitoring
Once an AI system is deployed, monitor its operation, identify incidents and reassess the risk whenever the system or its use case changes.
Every AI use case should also have an accountable owner. Business and control functions should participate according to the nature and level of risk involved.
The resulting management process is straightforward:
AI Inventory → Use Cases → Data Classification → Risk Assessment → Controls & Architecture → Monitoring
Kazakhstan and Europe: Two Approaches to AI Regulation
Kazakhstan's approach shares several principles with the EU AI Act. Both place emphasis on risk, human rights, transparency and accountability. Their specific requirements and approaches to AI system classification, however, are not identical.
This distinction is particularly important for international companies.
A multinational organization may already have group-wide AI Governance standards developed with the EU AI Act in mind. When the same organization operates in Kazakhstan, those corporate standards need to be supplemented by local legal requirements.
The model is similar to governance arrangements already used for other areas of enterprise risk. Organizations can maintain common group policies and controls while adapting them to the regulatory requirements of each jurisdiction in which they operate.
For AI Governance, this means combining group-wide standards with country-specific regulatory requirements.
International Operations
For international companies, AI Governance can follow an established enterprise risk management model: group-wide standards supplemented by the regulatory requirements of each country of operation.
What This Means for Business
Kazakhstan's new law shows that AI regulation is becoming part of the operating environment for businesses in Central Asia.
As AI adoption expands, banks and companies will increasingly need to manage implementation, risk, data protection and regulatory compliance together.
To scale AI safely, organizations need visibility into where AI is being used, what data it processes, what risks each use case creates and what controls are appropriate.
Kazakhstan provides an early indication of how AI Governance may evolve across Central Asia. Organizations developing new AI solutions or broader enterprise AI strategies should begin incorporating these capabilities now.
Over the coming years, AI regulation in the region will continue to evolve alongside the technology itself. Effective AI Risk Management can help organizations adopt new technologies faster, respond to market change and use AI at the scale their business requires.
Excessive restrictions can slow adoption and reduce the potential value of AI. The challenge for businesses is to build governance capabilities that allow them to use AI safely at scale.
Discuss AI Transformation for Your Business
We share practical experience and help you identify the right next steps.