Presidencia del Consejo de Ministros, Secretaría de Gobierno y Transformación Digital (SGTD) · PE · 4 provisions encoded · verified against the official source as of 2026-10-02.
Informational data, not legal advice. Summaries and rules have not been reviewed by a lawyer: always verify official law text for decisions. A suggested guard is intended to address each rule; adding it is not a statement of compliance to that law.
Sources last verified 3 Oct 2026; each provision states how.
Data release
Data release 2026.10.03.3, data as of 3 Oct 2026, schema 0.3.9.
Legal review
None of the 4 provisions has been reviewed by a lawyer; no TwinEthos rule has been legally reviewed yet. Treat each as research to check against the official text; it is not legal advice. Open questions for counsel on them: 4.
Audit standard
4 of 4 provisions audit-grade. The audit standard is TwinEthos's own quality bar for provenance, dates, applicability, detectors, fixtures, remediation and licences; it is not a legal review.
Detectors
5 detectors, all experimental: written from the rule's text and not yet measured for precision on real code, so treat a hit as a lead to verify. Each provision lists its detectors' known limits.
Changes
2026.10.03.3 (3 Oct 2026): 4 provisions added
Each data release records which provisions changed; the full list is on Changes.
Binding law — in force
Explain high-risk AI decisions that affect human rights, with the key criteria and factors, in accessible language (Peru, Regulation of Law 31814 Art. 25.3)
Regulation of Law 31814, Art. 25.3 (explanation of results of decisions affecting human rights) · official text · In force: applies since 10 Sep 2026; a further phase applies from 10 Sep 2027, 10 Sep 2028, 10 Sep 2029 · PE
Peru's Regulation of Law 31814 Art. 25.3 requires that, where a high-risk AI system takes decisions affecting human rights, the explanation of its results be guaranteed to the affected users through mechanisms that let them understand the criteria and key factors used in the automated decision, in language accessible to the user. For private developers and implementers it applies in phases by sector from 2026-09-10. Detect a model-driven adverse decision with no stored criteria or key factors.
Trust and provenancenot reviewed by a lawyer · audit-grade · source verified 3 Oct 2026 · release 2026.10.03.3
Lane
Binding law — in force In force: applies since 10 Sep 2026; a further phase applies from 10 Sep 2027, 10 Sep 2028, 10 Sep 2029
Quoted text found word for word in the captured official document (3 Oct 2026). Source last verified 3 Oct 2026: checked against the captured official document; not in the weekly watcher's list; checked against the captured document.
Data release
Data release 2026.10.03.3, data as of 3 Oct 2026, schema 0.3.9.
Legal review
Not reviewed by a lawyer. TwinEthos derived this rule from the official text it cites: treat it as research to check against that text; it is not legal advice. No TwinEthos rule has been legally reviewed yet. Open questions for counsel on this rule: 1.
Audit standard
Audit-grade: meets all 10 checks of the TwinEthos audit standard that apply to it. The audit standard is TwinEthos's own quality bar for provenance, dates, applicability, detectors, fixtures, remediation and licences; it is not a legal review.
Detectors
1 detector (code pattern), experimental: written from the rule's text and not yet measured for precision on real code, so treat a hit as a lead to verify.
Known limits:
Adverse outcomes as numeric codes
Decision set in a different file from the model call
The explanation may be produced by a separate letters module; follow the decision path before reporting.
Who it applies to
Duty falls on: developer, deployer
Systems covered: high risk, automated decision
Sectors: healthcare, education, employment, lending, public services, essential services
Developers and implementers in Peru of high-risk AI systems (Art. 24.1) whose decisions affect human rights. Same private-sector phase-in as Art. 25.1 (2026-09-10 to 2029-09-10). Which decisions 'impact human rights' is a question for counsel (review flag).
Not covered:
Use of AI systems for personal purposes (Art. 4(a))
Use of AI systems for defence and national security, provided the principles of Art. 7 are met (Art. 4(b))
Whether it applies depends on facts outside the code; a person has to decide.
The guard to add
Send each adverse AI-assisted decision with its main reasons and the AI's role, plus a way to correct data and appeal to a human who can change the outcome.
Where model output becomes an adverse status (denied, declined, rejected, ineligible), the decision service stores reason codes or principal reasons, the model id and version, and an input snapshot or hash with the decision. The notice to the person (letter, email, portal response) says AI was involved and what role it played, lists the main factors, and links to data correction and to an appeal that creates a human-review task with authority to change the outcome. An explanation endpoint returns the stored record on request, so the deployer can explain a decision long after the model has changed.
Where it goes: 2 data models, 9 AI output handling, 14 user-facing text.
What this provision adds:
Explain the result to the affected user with the criteria and key factors used, in language accessible to them.
Example (Python + OpenAI SDK + Pydantic), before:
resp = client.chat.completions.create(model=MODEL, messages=msgs)
if 'deny' in resp.choices[0].message.content.lower():
application.status = 'denied'
send_email(applicant.email, 'Your application was declined.')
After:
a = Assessment.model_validate_json(resp.choices[0].message.content) # decision, reason_codes
if a.decision == 'deny':
decisions.insert(app_id=application.id, status='denied', reason_codes=a.reason_codes,
model=resp.model, input_hash=hashlib.sha256(payload).hexdigest())
send_email(applicant.email, render('adverse_action_notice.txt',
reasons=a.reason_codes,
role_of_ai='An AI model assessed your application; a reviewer can change the outcome.',
correct_data_url='/profile/data', appeal_url=f'/appeals/new?decision={application.id}'))
UnitedHealth nH Predict claim-denial litigation (2023-11; alleged (not proven)). A class action filed in November 2023 alleges that UnitedHealth's nH Predict model had a 90% error rate, measured by denials reversed on appeal, while only about 0.2% of members appealed. UnitedHealth disputes the allegations; the litigation is ongoing. Source: STAT News · evidence grade: primary · cited by Explain adverse AI-assisted decisions and offer a way to contest them — everywhere
Rule id pe-ai-regulation.high-risk-decision-explanation · review status: primary source derived
Binding law — in force
Tell users in advance what a high-risk AI system is for, what it does and what decisions it can take (Peru, Regulation of Law 31814 Art. 25.1-25.2)
Regulation of Law 31814, Art. 25.1-25.2 (algorithmic transparency: prior, clear information to users; visible labelling) · official text · In force: applies since 10 Sep 2026; a further phase applies from 10 Sep 2027, 10 Sep 2028, 10 Sep 2029 · PE
Peru's Regulation of Law 31814 Art. 25.1 requires the developer or implementer of a high-risk AI system to establish mechanisms for algorithmic transparency that inform the user in advance, clearly and simply, of the system's purpose or use, its main functions and the type of decisions it can take; Art. 25.2 adds that these may include visible labelling informing users beforehand that the product, service or content operates on AI, with its main capabilities and limitations, except for internal administrative support with no direct impact on decisions affecting rights or services. For private developers and implementers the duty applies in phases by sector from 2026-09-10. Detect a model used in hiring, credit, health or admission decisions with no prior AI notice in the flow.
Trust and provenancenot reviewed by a lawyer · audit-grade · source verified 3 Oct 2026 · release 2026.10.03.3
Lane
Binding law — in force In force: applies since 10 Sep 2026; a further phase applies from 10 Sep 2027, 10 Sep 2028, 10 Sep 2029
Quoted text found word for word in the captured official document (3 Oct 2026). Source last verified 3 Oct 2026: checked against the captured official document; not in the weekly watcher's list; checked against the captured document.
Data release
Data release 2026.10.03.3, data as of 3 Oct 2026, schema 0.3.9.
Legal review
Not reviewed by a lawyer. TwinEthos derived this rule from the official text it cites: treat it as research to check against that text; it is not legal advice. No TwinEthos rule has been legally reviewed yet. Open questions for counsel on this rule: 1.
Audit standard
Audit-grade: meets all 10 checks of the TwinEthos audit standard that apply to it. The audit standard is TwinEthos's own quality bar for provenance, dates, applicability, detectors, fixtures, remediation and licences; it is not a legal review.
Detectors
1 detector (code pattern), experimental: written from the rule's text and not yet measured for precision on real code, so treat a hit as a lead to verify.
Known limits:
Notices shown by a separate UI layer
High-risk uses named in other words
The notice may be rendered by the front end; confirm the user sees it before the AI is used.
Who it applies to
Duty falls on: developer, deployer
Systems covered: high risk, consequential decision
Developers and implementers in Peru of AI systems in high-risk uses listed in Art. 24.1: management of critical national assets supporting essential services; evaluation of children and adolescents in education; selection, evaluation, hiring and dismissal of workers; access to social programmes; credit evaluation (fraud detection excepted); access to health services; screening, diagnosis or prognosis affecting health, emergency prioritisation and processing of sensitive data in electronic health records; emotion inference at work or in education (medical or safety reasons excepted); and other uses risking life, safety, rights, freedom or dignity with high risk of discrimination or high complexity for human supervision. Private developers and implementers apply Art. 25 in phases (Primera DCF): from 2026-09-10 for health, education, justice, security, economy and finance; 2027-09-10 for transport, commerce and labour and for small enterprises; 2028-09-10 for production, agriculture, energy and mining and for micro-enterprises; 2029-09-10 for all other uses. Which sector a use belongs to, and whether a use is high-risk, are questions for counsel (review flag; the SGTD answers consultations, Art. 24.2).
Not covered:
Use of AI systems for personal purposes (Art. 4(a))
Use of AI systems for defence and national security, provided the principles of Art. 7 are met (Art. 4(b))
Visible labelling is not needed where AI supports internal administrative processes with no direct impact on decisions affecting rights or services (Art. 25.2)
Whether it applies depends on facts outside the code; a person has to decide.
The guard to add
Send the person an AI-use notice on the decision path, before or when an AI system makes or substantially factors a consequential decision about them, and record its delivery.
A notice step in the decision workflow itself (application intake, underwriting, eligibility, applicant or employee scoring, diagnostic support) that runs before the model call, e.g. send_admt_notice(consumer) ahead of underwrite(), or a notice block rendered on the intake page the person submits from. The notice says that AI is used in the decision, for what, and how to get more information or ask for review, and its delivery is stored with the decision (notice id, channel, timestamp). The template lives in the repo so its content is reviewable; a privacy-policy paragraph alone is not on the decision path.
Where it goes: 1 application source code, 9 AI output handling, 14 user-facing text.
What this provision adds:
Before the user interacts, tell them clearly and simply the system's purpose, main functions and the type of decisions it can take.
Where relevant to the decision or the interaction, label the product, service or content as operating on AI, with its main capabilities and limitations.
Rule id pe-ai-regulation.high-risk-prior-information-and-label · review status: primary source derived
Binding law — in force
Keep a record of how a high-risk AI system works and people able to stop, correct or invalidate its decisions (Peru, Regulation of Law 31814 Art. 31.1, 31.4)
Regulation of Law 31814, Art. 31.4 (human oversight able to stop, correct or invalidate high-risk decisions) · official text · In force: applies since 10 Sep 2026; a further phase applies from 10 Sep 2027, 10 Sep 2028, 10 Sep 2029 · PE
Peru's Regulation of Law 31814 Art. 31 requires developers and implementers of high-risk AI systems to keep an up-to-date, accessible, preventive record of the system's operating principles, data sources, algorithmic logic and expected social and ethical impacts (31.1), and to implement human oversight in decisions with significant impact in health, education, justice, finance and access to basic programmes and services, with staff trained not to be biased by the system's results and able to stop, correct or invalidate its decisions (31.4). For private developers and implementers it applies in phases by sector from 2026-09-10. Detect a model whose output sets a decision status with no review, override or stop path.
Trust and provenancenot reviewed by a lawyer · audit-grade · source verified 3 Oct 2026 · release 2026.10.03.3
Lane
Binding law — in force In force: applies since 10 Sep 2026; a further phase applies from 10 Sep 2027, 10 Sep 2028, 10 Sep 2029
Quoted text found word for word in the captured official document (3 Oct 2026). Source last verified 3 Oct 2026: checked against the captured official document; not in the weekly watcher's list; checked against the captured document.
Data release
Data release 2026.10.03.3, data as of 3 Oct 2026, schema 0.3.9.
Legal review
Not reviewed by a lawyer. TwinEthos derived this rule from the official text it cites: treat it as research to check against that text; it is not legal advice. No TwinEthos rule has been legally reviewed yet. Open questions for counsel on this rule: 1.
Audit standard
Audit-grade: meets all 10 checks of the TwinEthos audit standard that apply to it. The audit standard is TwinEthos's own quality bar for provenance, dates, applicability, detectors, fixtures, remediation and licences; it is not a legal review.
Detectors
2 detectors (code pattern, missing artifact), experimental: written from the rule's text and not yet measured for precision on real code, so treat a hit as a lead to verify.
Known limits:
Status set in a different file from the model call
Oversight implemented as a feature flag
The oversight step may be enforced downstream (a case-management system); follow the decision path before reporting.
Who it applies to
Duty falls on: developer, deployer
Systems covered: high risk, consequential decision
Sectors: healthcare, education, employment, lending, public services, essential services
Developers and implementers in Peru of high-risk AI systems (Art. 24.1); human oversight for decisions with significant impact in health, education, justice, finance and access to basic programmes and services. Same private-sector phase-in as Art. 25 (Chapter II of Title VI, 2026-09-10 to 2029-09-10). Whether the record of 31.1 must be published or only kept accessible, and what training 31.4 requires, are questions for counsel (review flag).
Not covered:
Use of AI systems for personal purposes (Art. 4(a))
Use of AI systems for defence and national security, provided the principles of Art. 7 are met (Art. 4(b))
Whether it applies depends on facts outside the code; a person has to decide.
The guard to add
Put human supervision and a per-decision explanation record between high-impact model output and the action it triggers, backed by a documented risk-management plan.
On the high-impact path (credit, hiring, healthcare, essential services), model output becomes a pending decision rather than an action: a person can approve, override, or stop it (review queue with override, LangGraph interrupt, a kill switch checked before acting). Each decision stores the final result, the main criteria or reason codes, the model version, and the reviewer, and an explanation endpoint returns that record to the affected user. Alongside the code, keep the risk-management plan, user-protection measures, an overview of the training data used for explanations, and documentation of these measures in the repository.
Where it goes: 9 AI output handling, 15 agent action surface, 2 data models, 12 repository artifacts.
What this provision adds:
Keep an up-to-date, accessible record of the system's operating principles, data sources, algorithmic logic and expected social and ethical impacts.
Give trained staff the ability to stop, correct or invalidate the system's decisions before they take effect in health, education, justice, finance and access to basic services.
Example (Python + scikit-learn), before:
score = model.predict_proba([features])[0][1]
status = 'approved' if score > 0.7 else 'denied'
applications.save(app_id, status=status)
After:
if settings.HIGH_IMPACT_AI_PAUSED: # kill switch
raise ServiceUnavailable('automated scoring paused')
score = model.predict_proba([features])[0][1]
proposed = 'approved' if score > 0.7 else 'denied'
decisions.insert(app_id=app_id, proposed=proposed, score=score,
reason_codes=top_reason_codes(features, k=3), model_version=MODEL_VERSION,
status='pending_review')
# applications.save runs from the reviewer's approve/override handler
Rule id pe-ai-regulation.high-risk-record-and-human-oversight · review status: primary source derived
Binding law — in force
Do not use AI to infer race, political opinions, union membership, religion or sex life from biometric data (Peru, Regulation of Law 31814 Art. 23.1(d))
Regulation of Law 31814, Art. 23.1(d) (prohibited: inferring sensitive traits from biometric data; discriminatory classification) · official text · In force: applies since 22 Jan 2026 · PE
Peru's Regulation of Law 31814 (Supreme Decree 115-2025-PCM) Art. 23.1(d) prohibits, as improper use, AI systems intended to analyse, classify or infer people's sensitive data from their biometric data to deduce or infer racial or ethnic origin, political opinions, trade union membership, religious or philosophical beliefs, sex life or sexual orientation, and to evaluate or classify people or groups where that causes or contributes to discriminatory or disproportionate results that violate fundamental rights. Detect a face or voice pipeline that computes a race, religion, sexual-orientation or political label.
Trust and provenancenot reviewed by a lawyer · audit-grade · source verified 3 Oct 2026 · release 2026.10.03.3
Lane
Binding law — in force In force: applies since 22 Jan 2026
Quoted text found word for word in the captured official document (3 Oct 2026). Source last verified 3 Oct 2026: checked against the captured official document; not in the weekly watcher's list; checked against the captured document.
Data release
Data release 2026.10.03.3, data as of 3 Oct 2026, schema 0.3.9.
Legal review
Not reviewed by a lawyer. TwinEthos derived this rule from the official text it cites: treat it as research to check against that text; it is not legal advice. No TwinEthos rule has been legally reviewed yet. Open questions for counsel on this rule: 1.
Audit standard
Audit-grade: meets all 10 checks of the TwinEthos audit standard that apply to it. The audit standard is TwinEthos's own quality bar for provenance, dates, applicability, detectors, fixtures, remediation and licences; it is not a legal review.
Detectors
1 detector (code pattern), experimental: written from the rule's text and not yet measured for precision on real code, so treat a hit as a lead to verify.
Known limits:
Labels held in a model's config or class list outside the file
Proxies for sensitive traits
Self-declared survey fields next to unrelated face code can match; confirm the label is computed from biometric data.
Who it applies to
Duty falls on: developer, deployer
Systems covered: prohibited
Developers and implementers (Art. 6(b), (d)) of AI systems in Peru, public or private, intended to infer sensitive traits from biometric data, or to evaluate or classify people with discriminatory or disproportionate results. Applies with the Regulation's entry into force, computed as 2026-01-22 (90 business days after publication on 2025-09-09). The business-day count and whether the private-sector phase-in of the Primera DCF (which names only Art. 25 and Chapter II of Title VI) also delays Art. 23 are questions for counsel (review flag).
Not covered:
Use of AI systems for personal purposes (Art. 4(a))
Use of AI systems for defence and national security, provided the principles of Art. 7 are met (Art. 4(b))
Whether it applies depends on facts outside the code; a person has to decide.
The guard to add
Remove any model, prompt, or label set that infers race, political opinion, union membership, religion or beliefs, sex life, or sexual orientation from biometric data.
In biometric pipelines (face, voice, gait, iris), the code computes only the attributes the feature needs and never a sensitive-trait category: no classifier heads or labels for race or ethnicity, political opinion, trade-union membership, religious or philosophical belief, sex life, or sexual orientation, and no attribute API used for those traits (for example DeepFace.analyze with the 'race' action). Prompts that send a person's photo or voice to a multimodal model instruct it not to guess these traits, and an output check strips any such inference. The data model has no columns for these traits derived from biometric input.
Where it goes: 1 application source code, 2 data models, 7 prompt construction, 9 AI output handling.
What this provision adds:
Do not compute or store racial or ethnic origin, political opinions, union membership, religious or philosophical beliefs, sex life or sexual orientation from face, voice or other biometric data.
Example (Python DeepFace), before:
result = DeepFace.analyze(img_path=photo, actions=['age', 'gender', 'race'])
profile.update(age=result[0]['age'], ethnicity=result[0]['dominant_race'])
After:
result = DeepFace.analyze(img_path=photo, actions=['age']) # no 'race' action
profile.update(age=result[0]['age'])
Rule id pe-ai-regulation.no-sensitive-trait-inference-from-biometrics · review status: primary source derived
Informational data, not legal advice. Summaries are TwinEthos's own words and rules have not been reviewed by a lawyer: check the official text before relying on any of it. A guard addresses an item; adding it is not a statement that your code meets any law.