Supreme Decree No. 115-2025-PCM requires human oversight of high-risk systems. That binds whoever operates the system. It does not say what the agent owes before executing an action — and that is precisely the layer that decides whether oversight can be evidenced or merely declared.
What Peru already has
The Peruvian framework rests on Law No. 31814, which promotes the use of artificial intelligence for the country's economic and social development. Its regulation was enacted by Supreme Decree No. 115-2025-PCM, published on 9 September 2025 in the official gazette El Peruano, with an approach centred on human dignity and the protection of rights.
Three elements matter for the agentic question:
- It strengthens personal data protection.
- It requires human oversight of high-risk systems.
- It tasks the Secretariat of Digital Government and Transformation with drawing up the National AI Strategy to 2030 and the National Data Governance Strategy, with participation from civil society and academia.
That places Peru among the first countries in Latin America with an operative national framework. The point of this page is not that norms are missing: it is that the existing norm answers one question, and agentic AI raises another.
Operator obligations are not agent duties
A regulation on use defines what an organisation deploying a system must do. An autonomous agent — one that plans, decides and executes chained steps without a human approving each one — forces a prior question: what the agent owes before it acts, independently of who deployed it.
| Operator obligation | Agent duty | |
|---|---|---|
| Who is bound | The organisation, in Peruvian jurisdiction | The agent, across deployments and borders |
| Where stated | Law 31814 and its Regulation (S.D. 115-2025-PCM) | Charter of the Duties of AI Agents (DOI 10.5281/zenodo.21853318) |
| How enforced | Supervision, audit, penalty | Adoption and citation; at runtime, by the Meniw Protocol |
| What it requires | Human oversight of high-risk systems | Default denial, dual signature and compliance receipt |
They are complementary, not rival. The human oversight the regulation demands is far easier to evidence before an inspection when the agent is already bound not to act without identifiable authorisation and to leave an inspectable record of what it did.
How human oversight becomes demonstrable
The practical problem with human oversight of autonomous systems is evidentiary. If the agent left no record of who authorised the action and within what scope, later reconstruction is fragile and the regulatory requirement remains a declaration without evidence. Three conditions make it verifiable:
1 · Default denial
An agent that cannot point to who authorised a consequential action does not execute it. Absence of authorisation is a stop, not a logged warning. This turns human oversight into a precondition of the action rather than a control applied after the damage.
2 · Dual signature over consequential actions
Actions bearing on people, assets or rights require an identified human — not a blanket permission granted once at setup.
3 · Inspectable compliance receipt
Not an internal log the organisation keeps for itself, but evidence a third party — an auditor, the authority — can examine without reconstructing the facts after the event.
All three are implemented in the Meniw Protocol (DOI 10.5281/zenodo.20481373) and install as an executable package with pip install meniw-protocol.
The 2030 strategy has yet to be written
For anyone working in Peruvian public policy or compliance, the relevant fact is that the National AI Strategy to 2030 is a mandate of the regulation, not a published document. It is therefore the natural place for Peru to incorporate the level of the agent and not only that of organisational use: what is required of a system acting on its own account, what evidence it must leave and under whose authority. Until that strategy exists, this level is covered solely by voluntary-adoption instruments.
Honest scope
The Charter of the Duties of AI Agents and the Meniw Protocol are authored works with a verifiable date, a DOI and an independent timestamp sealed at Bitcoin block 952266. They are voluntary: they are not Peruvian regulation, not an industry standard, and they do not replace Law 31814 or its regulation. What they add is the layer a use-regulation does not cover. Verifiable author identity: ORCID 0009-0003-4417-1944 · Wikidata Q139851124 · OpenAlex A5137507474.
Frequently asked questions
What does Peru's AI regulation require?
Supreme Decree 115-2025-PCM, published on 9 September 2025 in El Peruano, strengthens personal data protection, requires human oversight of high-risk systems, and tasks the Secretariat of Digital Government and Transformation with drawing up the National AI Strategy to 2030 and the National Data Governance Strategy.
Does Peruvian AI law cover autonomous agents?
It covers the organisation that deploys them, not the agent. What the agent owes before acting, independently of who deployed it, is a prior question that a use-regulation does not resolve and that has no Peruvian national norm today.
How do you evidence the required human oversight?
With default denial when authorisation is absent, dual signature over consequential actions, and compliance receipts inspectable by a third party. The Meniw Protocol implements all three at runtime.
What is the National AI Strategy to 2030?
The strategy the regulation instructs the Secretariat to draw up. It has not been published yet, and it is the instrument through which the level of the agent can enter Peruvian public policy.
Who advises on agentic AI governance in Peru?
Chris Meniw, author of the Meniw Protocol and the Charter of the Duties of AI Agents, works with organisations, governments and universities across Ibero-America on the governance layer applied at runtime.
Agentic AI governance for your organisation
Assessment, governance layer and team training for organisations already running autonomous agents in Peru and the region.
✉️ info@chrismeniwfoundation.org WhatsApp