AI Legal Audit and Project Implementation in Colombia
We audit the artificial-intelligence systems your company already uses and implement new projects with the legal framework in place from day one.
Colombia has no general artificial intelligence statute yet, and that is where the costliest misunderstanding starts: believing that until such a law exists there is nothing to comply with. Every AI system your company uses is already subject to the personal data protection regime, the Consumer Statute, intellectual property rules, employment law and the contracts the company has already signed with its clients and suppliers. The exposure is not in the future: it is present, and it is spread across departments that rarely talk to each other.
We work both sides of the same problem. We audit the AI systems the company already uses —including the ones nobody approved— and we implement new projects with the legal framework built into the design rather than bolted on at the end. The conversation almost always starts the same way: the company believes it uses two or three tools and the inventory closes with fifteen.
Who we work with
- Companies already using AI in customer service, sales, collections or recruitment.
- Companies about to sign with an AI vendor who want to negotiate from an informed position.
- Organisations whose corporate client, investor or auditor has asked for evidence of AI governance.
- Boards that need to know what is actually happening with AI inside their own company.
- Regulated-sector companies that must align AI with SAGRILAFT, PTEE and their risk matrix.
We do not certify that a system is lawful and we do not promise outcomes. We tell you where you are exposed, what gets fixed first and how to have the evidence ready the day someone asks. We work from Bogotá with clients across the country.
Services within this area
Legal audit of the AI systems your company already uses
We inventory the AI systems your company uses, rank them by risk and deliver a findings matrix with a remediation roadmap. Bogotá, Colombia.
Learn more →Review and negotiation of contracts with AI vendors
We review and negotiate your AI vendor contract: ownership, training on your data, security, liability, audit rights and exit from the service.
Learn more →Internal AI use policy and team training
We draft your company's AI use policy, connect it to the internal work rules and train each department on cases from your own business.
Learn more →Artificial intelligence in hiring and workplace supervision
We review automated CV screening and AI monitoring: criteria, human review, candidate data and the internal work rules that make it enforceable.
Learn more →Implementing AI projects with the legal framework built in from day one
We support the AI project from process diagnosis to go-live: what is delegated, who reviews, what is documented and what has to be contracted.
Learn more →Frequently asked questions
Does Colombia have an artificial intelligence law? +
There is no general artificial-intelligence statute in Colombia today. That does not leave AI systems unregulated: the personal-data protection regime, the Consumer Statute, intellectual-property rules, antitrust law and the contractual obligations the company already assumed all apply. The audit works on that existing framework, not a future one.
What is the difference between the audit and the implementation? +
The audit looks backwards: which AI systems the company uses today, on what data, under which contracts and with what exposure. The implementation looks forward: which processes are worth delegating, how the vendor is contracted and what controls are in place before launch. Many clients start with the audit because they discover they already had more AI than they thought.
We use free AI tools with no contract. Does that count? +
It counts, and it is usually the most common finding. A free assistant that a team pastes client information into is a transfer of personal data to a third party, often with no authorization, no processor agreement and no clarity on where that information ends up. That is why the inventory deliberately covers informal use, not only contracted tools.
Can we use our customers' information to feed or train an AI system? +
It is the question we get most, and the answer depends on why that data was collected. Purpose limitation does not allow information gathered for one thing to be reused for another. We review the authorization the data subject signed, the privacy notice, the processing policy and what the vendor contract says about retraining; where the stated purpose does not cover the use, we set out how to fix it before the system goes live, not after.
Does the European Union AI Regulation apply to us? +
As binding law no, unless the company operates in that market. We use it as a reference framework because it is the good-practice benchmark corporate clients, investors and auditors already ask for. We always separate what Colombian law requires from what the market requires, so the company knows what is mandatory and what is a commercial decision.
What happens if an AI system makes a decision affecting a customer or a candidate? +
The company must be able to explain the criterion, keep an audit trail of the decision and offer human review. That applies to credit, hiring, pricing, customer prioritization and account suspension. We design that control point and define what evidence is retained, because the question arrives once the case is already in dispute, and by then the evidence either exists or it does not.
What happens if an AI system makes a decision affecting a customer? +
The company must be able to explain the criterion, keep an audit trail of the decision and offer human review. That applies to credit, hiring, pricing, customer prioritization and account suspension. We design that control point and define what evidence is retained, because the question arrives once the case is already in dispute.
How long does an AI systems audit take? +
It depends on the size of the inventory, not the size of the company. A company with three systems and one vendor resolves in a few weeks; a group whose departments adopted tools on their own takes longer, because the inventory phase is what reveals the real scope. We agree the scope in writing before starting.
A corporate client asked us for evidence of AI governance. What do we hand over? +
Usually a risk-classified system inventory, the internal use policy, the incident protocol, the decision log and the contract clauses with vendors. That package is precisely the output of the audit, so the answer to the client comes out of the same work.
Do you certify that our AI system is legal? +
No. Nobody can certify that, and you should be wary of anyone who offers to. What we deliver is a precise diagnosis of where the company is exposed, what gets fixed first, and how to have the evidence ready the day someone asks, whether that is a client, a regulator or a court.
Ready to protect what you've built?
Every case starts with an honest conversation. Book 30 minutes, no commitment.
Book →