CiberLATAMbywhalemate

Chile Approves Deepfake Regulation Bill

Chile’s lower house approved a bill regulating AI-generated content and deepfakes. Data protection fines could reach 4% of annual revenue.

Whalemate Labs · AI-assisted researchPublished:Updated 4 min read

Chile’s Chamber of Deputies approved a bill in general terms that regulates content generated with artificial intelligence and specifically sanctions deepfakes, with 128 votes in favor, 2 against and 5 abstentions. After the vote, the initiative returned to committee to continue its legislative process.

Update August 27, 2026: The review adds details on the sanctioning regime in the Personal Data Protection Law, which now provides initial fines of between 5,000 and 20,000 UTM. According to Radio Universidad de Chile, repeat offenses and aggravating factors could push penalties as high as 4% of annual revenue.

Chile’s Chamber of Deputies approved, in general terms, a bill that regulates content generated with artificial intelligence and specifically sanctions deepfakes. The vote passed 128 to 2, with 5 abstentions. Afterward, the measure returned to the Commission on Future, Science, Technology, Knowledge and Innovation to continue its legislative path.

What does the anti-deepfake bill establish?

The bill creates a right to digital integrity to protect a person’s image, body and voice. It targets AI-generated content that could be used without authorization. It also applies to individuals, companies and social networks, except private messaging.

According to The Standard CIO, the proposal would also require platforms to label AI-generated content, remove reported material within 72 hours and maintain a legal representative in Chile. The measure is part of a broader legislative push aimed at addressing the spread of synthetic material and its abusive uses.

How does it intersect with other digital laws in Chile?

Chile is also weighing three other regulatory efforts tied to data, AI and digital violence. Bill 16821-19, titled "Regulate Artificial Intelligence Systems," was introduced in 2024, remains under review and is moving forward with a risk-based approach, although its effective date has not yet been set.

Cercai warns that the text could still change, so the final obligations for companies on AI and compliance remain subject to parliamentary debate. On another track, since 2020 lawmakers have been considering a bill that defines digital violence and amends the Penal Code. It is now in its second constitutional review in the Senate.

That digital violence bill seeks to add crimes linked to the nonconsensual spread of intimate material and other forms of abuse carried out through information technologies. It also adds a specific aggravating factor in the sexual sphere under Article 161-E, which punishes anyone who, without authorization, displays or distributes false but realistic digital content created with artificial intelligence in order to harm a person.

What happens with Personal Data Protection Law 21.719?

Personal Data Protection Law No. 21.719 was passed by Congress in 2024 and is now set to enter into full force on December 1, 2026, with new obligations for companies and public agencies in how they handle personal data.

The law creates the Personal Data Protection Agency as an autonomous body with oversight and sanctioning powers, and it establishes a new infringement regime with meaningful financial penalties for organizations that fail to comply with data-processing obligations.

Specialized Chilean outlets say the law will take effect on December 1, 2026, and that each personal data point processed must have a justified purpose, a defined retention period and controls over who can access the information. Other business media describe it as difficult to implement for public services and companies, with fines that can reach 4% of annual revenue from sales and services in cases of aggravated violations.

At the same time, the government is negotiating with lawmakers a possible delay until December 1, 2027, while keeping the agency’s launch slated for late 2026. That option is still under review and is not confirmed as binding law. In the meantime, business and technology outlets are treating it as a countdown for companies, which will need to adapt their data governance, privacy and information security models to meet the new standards.

Sources

View all