{"id":147624,"date":"2026-08-14T09:30:01","date_gmt":"2026-08-14T09:30:01","guid":{"rendered":"https:\/\/my.legal500.com\/guides\/?post_type=comparative_guide&#038;p=147624"},"modified":"2026-08-14T09:30:01","modified_gmt":"2026-08-14T09:30:01","slug":"ecuador-artificial-intelligence","status":"publish","type":"comparative_guide","link":"https:\/\/my.legal500.com\/guides\/chapter\/ecuador-artificial-intelligence\/","title":{"rendered":"Ecuador: Artificial Intelligence"},"content":{"rendered":"","protected":false},"template":"","class_list":["post-147624","comparative_guide","type-comparative_guide","status-publish","hentry","guides-artificial-intelligence","jurisdictions-ecuador"],"acf":[],"appp":{"post_list":{"below_title":"<div class=\"guide-author-details\"><span class=\"guide-author\">Heka Law Firm<\/span><span class=\"guide-author-logo\"><img src=\"https:\/\/my.legal500.com\/guides\/wp-content\/uploads\/sites\/1\/2026\/08\/logo-10.jpg\"\/><\/span><\/div>"},"post_detail":{"above_title":"<div class=\"guide-author-details\"><span class=\"guide-author\">Heka Law Firm<\/span><span class=\"guide-author-logo\"><img src=\"https:\/\/my.legal500.com\/guides\/wp-content\/uploads\/sites\/1\/2026\/08\/logo-10.jpg\"\/><\/span><\/div>","below_title":"<span class=\"guide-intro\">This country specific Q&amp;A provides an overview of Artificial Intelligence laws and regulations applicable in Ecuador<\/span><div class=\"guide-content\"><div class=\"filter\">\r\n\r\n\t\t\t\t<input type=\"text\" placeholder=\"Search questions and answers...\" class=\"filter-container__search-field\">\r\n\t\t\t<\/div>\r\n\r\n\t\t\t\r\n\r\n\r\n\t\t\t<ol class=\"custom-counter\">\r\n\r\n\t\t\t\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">What is the legal definition of \u201cartificial intelligence\u201d in your jurisdiction, if any? If no definition exists, how do regulators or courts typically describe artificial intelligence?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>Ecuador has no statutory definition of artificial intelligence. The bill that would introduce one remains stalled in committee at the National Assembly (question 3), and the national AI strategy acknowledges the gap at page 25 of Supplement No. 206 to the Official Register of 19 January 2026, recording that the country still lacks AI-specific rules although there has been progress on personal data protection and cybersecurity (&#8220;sigue sin normativa espec\u00edfica para IA, aunque hay avances en protecci\u00f3n de datos personales y ciberseguridad&#8221;).<\/p>\n<p>How that gap is filled is itself a matter of statute. Article 18 of the Civil Code forbids judges to refuse to adjudicate for obscurity or absence of law and prescribes the rules they must follow instead. Three of them decide the question here. First, words carry their natural and obvious meaning unless the legislator has expressly defined them for the matter in hand, which for artificial intelligence it has not. Second, the technical words of any science or art are taken in the sense given to them by those who profess that science or art, unless it clearly appears that they were used in a different sense, so the meaning of a technical term such as artificial intelligence is imported from the technical community rather than supplied by the interpreter. Third, in the absence of statute the judge is referred to rules governing analogous cases and then to general principles of law (Article 18, rules 2, 3 and 7).<\/p>\n<p>That referral now has a domestic anchor. The national strategy&#8217;s glossary, built expressly on ISO\/IEC 22989 and ISO\/IEC 22123, defines an AI system as an engineered system generating outputs such as content, forecasts, recommendations or decisions for a given set of human-defined objectives, and since June 2026 ISO\/IEC 22989 has itself been an Ecuadorian standard, NTE INEN-ISO\/IEC 22989 (question 3).<\/p>\n<p>No competing official definition exists. Resolution No. SPDP-SPD-2026-0009-R of the Superintendency of Personal Data Protection (signed 12 February 2026, in force on publication in Official Register No. 240, ordinary edition, of 10 March 2026) uses the term &#8220;AI systems&#8221; without defining it, defining instead the roles of developer, deployer, distributor and implementer and reaching whoever develops, trains, implements, deploys or provides such systems where they process the personal data of Ecuadorian data subjects.<\/p>\n<p>At statutory level artificial intelligence is reached indirectly, through Article 20 of the Personal Data Protection Law (LOPDP, 2021), on decisions based solely or partially on automated processing, including profiling. Legislative and academic debate defaults to the OECD definition, which also inspired the stalled bill, and no Ecuadorian court has yet defined artificial intelligence in a reported decision.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Has your country developed a national strategy for artificial intelligence? If yes, what progress has been made in its implementation? Are there plans for updates or revisions?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>Yes, and it is recent. The Strategy for the Promotion of the Ethical and Responsible Development and Use of Artificial Intelligence in Ecuador (EFIA-EC) was issued by Ministerial Agreement No. MINTEL-MINTEL-2025-0030 (signed 22 December 2025, published in the Official Register on 19 January 2026) and publicly launched on 10 March 2026 together with UNESCO&#8217;s Readiness Assessment (RAM) report for Ecuador. It is a 2025-2029 roadmap aligned with the UNESCO Recommendation on the Ethics of AI, structured around three axes: AI governance; capacity and technology; and adoption and development, with emphasis on health, justice, education and public services.<\/p>\n<p>Its measurable 2029 targets are ten educational programmes with AI content, 10,000 training scholarships, USD 200 million of accumulated digital infrastructure investment and AI adoption by half of central public administration institutions, with no centralised budget, relying instead on tax incentives, multilateral funds and public-private partnerships.<\/p>\n<p>Early implementation is visible but partial. The &#8220;10,000 Prompters&#8221; scholarship programme (with the United Arab Emirates) reported completion of its goal; an AI regulatory sandbox anchored in the Digital Transformation Law was announced in March 2026 with UNDP support and remains in structuring phase; and on the governance axis the data protection authority issued the first binding AI-specific regulation in February 2026 (question 3). The policy umbrella was renewed too, since Ministerial Agreement No. MINTEL-MINTEL-2025-0005 of 14 March 2025, published in the First Supplement to Official Register No. 15 of 8 April 2025, issued the Public Policy for Digital Transformation 2025-2030 and, in its Article 3, derogated the agreement of 2 November 2022 that had issued the 2022-2025 policy.<\/p>\n<p>The strategy provides for periodic follow-up and update by MINTEL, without a fixed revision date, and the government has said it will serve as technical input for the AI bill pending in the Assembly.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Has your jurisdiction adopted any AI-specific laws, regulations, voluntary standards, or ethical guidelines? If so, please provide a brief overview. If not, which existing laws could be\/are applied to artificial intelligence and the use of artificial intelligence, what are the main interpretive challenges, and are there any pending artificial intelligence legislative initiatives?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>Ecuador has no AI statute but has AI-specific regulation, administrative rule-making having outpaced legislation.<\/p>\n<p>Four instruments matter:<\/p>\n<p>Resolution No. SPDP-SPD-2026-0009-R (Superintendency of Personal Data Protection, signed 12 February 2026, published in and in force from Official Register No. 240, ordinary edition, of 10 March 2026), the General Rule on personal data protection in AI systems, is Ecuador&#8217;s first binding AI-specific regulation. Extraterritorial, it reaches anyone developing, training, implementing, deploying or providing AI systems processing Ecuadorian data subjects&#8217; personal data, wherever located, not systems without personal data. It creates four roles and requires prior risk management and impact assessments, registration of AI processing, reinforced transparency and risk-calibrated audits, and the Superintendency may audit systems and impose corrective and precautionary measures. Risk-based procedurally, not taxonomically, it has no legal risk categories, high-risk list or prohibited practices equivalent to Article 5 of the EU AI Act, taxonomy appearing only in the pending N\u00fa\u00f1ez bill, whose Article 7 sorts systems into low, moderate, high and extreme risk against the eight classification factors of Article 6 and bans extreme-risk systems, Article 9 sets eight absolute prohibitions including mass social scoring, subconscious manipulation, lethal autonomous weapons without effective human control and indiscriminate or predictive surveillance without individualised judicial authorisation, and Article 14 creates a National Register of High-Risk AI Systems rather than of all AI.<\/p>\n<p>The EFIA-EC national strategy (question 2), soft law, complemented by the AI regulatory sandbox announced in March 2026.<\/p>\n<p><strong>Ethical codes.<\/strong> By Resolution No. SCE-DS-2025-34 of 3 June 2025, published in Official Register No. 60 of 16 June 2025, the Superintendency of Economic Competition (SCE) adopted the first AI ethics code of an Ecuadorian public institution, internal in scope, on eight principles aligned with the UNESCO Recommendation.<\/p>\n<p><strong>National technical standards.<\/strong> Resolutions MPCEI-SC-2026-0090-R and MPCEI-SC-2026-0100-R of the Ministry of Production, Foreign Trade and Investment, through its Quality Sub-secretariat in the Ecuadorian Quality System, officialised NTE INEN-ISO\/IEC 22989 on AI concepts and terminology and NTE INEN-ISO\/IEC 42001 on an AI management system, published respectively in the Fifth Supplement to Official Register No. 306 of 16 June 2026 and the Supplement to Official Register No. 329 of 20 July 2026. Both are expressly &#8220;con el car\u00e1cter de voluntaria&#8221;, imposing no duty, certification resting with private bodies, and whether incorporation into a technical regulation makes them enforceable has not yet been determined.<\/p>\n<p><strong>Public procurement.<\/strong> Executive Decree No. 461, published in the Third Supplement to Official Register No. 337 of 30 July 2026, inserted Article 426.1 into the General Regulation of the procurement law, obliging the public procurement authority to implement automated technological tools and &#8220;shall apply as mandatory&#8221; a set of control criteria, first, progressive deployment of data engineering and data mining, automated early-warning systems, artificial intelligence, machine learning and natural language processing to identify risk patterns, irregularities and regulatory breaches by contracting entities, the first Ecuadorian rule obliging rather than permitting public AI deployment.<\/p>\n<p>Everything else is general law applied to AI, the 2008 Constitution (equality, data protection, habeas data, motivation); the LOPDP and its Regulation, especially Article 20; the COESCCI with Andean Decisions 351 and 486, supranational and directly applicable; the Civil Code and the Consumer Defence Law for liability; the COIP, whose consolidated text as amended on 1 July 2026 lacks any reference to artificial intelligence; the E-Commerce Law; the Digital Transformation Law; and, since May 2026, the Cybersecurity Law (question 8).<\/p>\n<p><strong>Three interpretive challenges arise:<\/strong> stretching technology-neutral categories, since who answers for an autonomous system under fault-based rules and how Article 20 LOPDP (&#8220;solely or partially&#8221; automated, wider than the GDPR) works in practice remain unclear; institutional design, no authority having an express statutory mandate over AI, leaving supervision to the data protection lens; and standardisation without teeth, the new INEN standards binding no one until a technical regulation or contract adopts them.<\/p>\n<p><strong>Pending initiatives.<\/strong> The framework bill, the Proyecto de Ley Org\u00e1nica de Regulaci\u00f3n y Promoci\u00f3n de la Inteligencia Artificial en Ecuador of Assembly Member Patricia N\u00fa\u00f1ez, file 450889, filed 20 June 2024, was qualified by Legislative Administration Council resolution CAL-HKK-2023-2025-0376 of 18 July 2024, notified to committee on 26 July 2024, which authorised unification with the Sub\u00eda and Cabezas proposals. It sits before the Education, Culture, Science, Technology, Innovation and Ancestral Knowledge Committee with no report for first debate and archiving publicly floated; absent that report the unified bill has no official consolidated text, its contents attaching only to the N\u00fa\u00f1ez bill. The Assembly&#8217;s Legislative Technical Unit concluded, in non-binding report No. 0217-INV-UTL-AN-2024 of 15 July 2024, that the bill would be ordinary, not organic, law, its content meeting none of the constitutional parameters; the Council qualified it nonetheless.<\/p>\n<p><strong>The sectoral pipeline moves faster:<\/strong> a criminal-code reform on child sexual exploitation through artificial intelligence taken up by the Justice Committee on 8 July 2026; a reform on digital violence, non-consensual intimate content, digital harassment, doxing and grooming, filed on 18 June 2026 and taken up on 22 July 2026, which would make AI use an aggravating circumstance and criminalise fabricating synthetic sexual content; a March 2026 bill on non-consented AI-generated images, voices and video; and a June 2026 bill on AI in the judiciary (question 18). The wider criminal-code package passing first debate on 8 June 2026 unifies eighty-four proposals on extortion, peculation and related matters, none on artificial intelligence.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Are there legal requirements for artificial intelligence transparency, explainability, or audits? Are there obligations to disclose the use of artificial intelligence to customers\/clients?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>Yes, although the requirements apply only where personal data is involved, which covers most consumer-facing AI. Under the LOPDP transparency is a governing principle (Article 10) and data subjects must receive prior, clear and accessible information on the conditions of processing, including automated decisions and profiling (Article 12). Article 20 adds explainability, since anyone subject to a decision based solely or partially on automated processing may demand a reasoned explanation, information on the data and sources used and the assessment criteria of the automated programme, and may submit observations and challenge the decision.<\/p>\n<p>The SPDP&#8217;s 2026 AI regulation converts this into AI-specific duties, being to inform the data subject clearly that processing is carried out through AI systems and for what purposes (Article 5.1), to run risk management and impact assessments before the system is developed (Articles 5.2 and 6), to record AI-based processing and automated decisions with legal effects in the record of processing activities (Articles 5.4 and 7.1), and to audit the system in proportion to its level of risk (Articles 5.5 and 7.3). The Superintendency may audit AI systems directly (Article 10), and fines run from 0.1% to 1% of prior-year turnover depending on severity.<\/p>\n<p>Outside data protection no general duty to disclose the use of AI to customers exists. The Consumer Defence Law requires adequate, truthful, clear and complete information and prohibits misleading advertising, which arguably covers undisclosed chatbots or synthetic content presented as human, although no authority has said so yet. The financial sector has no AI-specific transparency rules, so scoring and chatbots run under general operational-risk and consumer-protection norms. The stalled AI bill would introduce mandatory labelling of AI-generated outputs and the MINTEL sandbox requires &#8220;algorithmic transparency&#8221; from participants, neither being generally binding law today.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Are there legal requirements or best practice expectations for human oversight and human-in-the-loop in artificial intelligence systems?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>No standalone human-oversight statute exists, though data protection law reaches a similar result. The binding core is Article 20 LOPDP, the right not to be subject to a decision based solely or partially on automated processing, including profiling, producing legal effects or impairing fundamental rights, wording broader than Article 22 GDPR. It does not literally say &#8220;human intervention&#8221;, but the rights granted (reasoned explanation, assessment criteria of the programme, observations, challenge before the controller) need a human counterpart, local doctrine reading it as prohibiting significant automated decisions without human review. Exceptions are limited to contractual necessity, legal authorisation with safeguards, explicit consent or decisions without serious impact. The SPDP&#8217;s 2026 AI regulation orders these rights guaranteed &#8220;at all times&#8221; (Article 4), its risk-based audits implying continuous vigilance and its recitals invoking the UNESCO principles, including human oversight.<\/p>\n<p>The EFIA-EC strategy adopts human-centred design and human oversight among its principles, and the competition authority&#8217;s AI ethics code includes &#8220;human oversight and control&#8221;, barring staff from automated decisions without human review. Administrative-law doctrine holds that an AI-supported administrative act requires explainability and prior human review to survive the constitutional duty to state reasons (Article 76.7.l), an unreviewed AI-drafted judicial ruling being likewise challengeable under the Constitutional Court&#8217;s motivation standard (judgment 1158-17-EP\/21).<\/p>\n<p>The N\u00fa\u00f1ez bill would make this explicit, though human oversight is not among the sixteen guiding principles of its Article 4. It enters through Article 15(b), obliging high-risk operators to secure meaningful human intervention and supervision in decisions substantially affecting rights or legitimate interests; Article 5(s), defining meaningful human control; Article 63, requiring equity, non-discrimination, due process and human-oversight safeguards for artificial intelligence in the administration of justice; and Articles 25 and 26, granting a right not to be subject to decisions based solely on automated processing plus duties to explain the processing logic and let the data subject state their view, challenge the decision, request review by a person and receive a clear explanation of the criteria, reasons and evidence.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Are there specific legal or regulatory requirements addressing algorithmic bias, discrimination, or fairness in AI systems (including gender bias)?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>No statute addresses algorithmic bias, so protection is assembled from constitutional, data protection and labour rules, plus one novel administrative development. The constitutional layer is strong on paper, Article 11.2 prohibiting discrimination on grounds including ethnicity, sex, gender identity, sexual orientation, age, disability and health status, directly enforceable against public and private actors through the acci\u00f3n de protecci\u00f3n, with Articles 66.4 (formal and material equality) and 331 (labour discrimination against women) completing the frame.<\/p>\n<p>The LOPDP includes in sensitive data any data &#8220;whose improper processing may give rise to discrimination&#8221; (Article 4), prohibits their processing save narrow exceptions (Article 26), protects children against automated assessments (Article 21), and makes impact assessments mandatory where systematic automated evaluation of personal aspects grounds decisions with legal effects (Article 42). Novel is the Superintendency&#8217;s risk and impact assessment guide, second version approved by Resolution No. SPDP-SPD-2026-0012-R of 19 March 2026, published in the Supplement to Official Register No. 254 of 30 March 2026, only Chapter I being of mandatory compliance, Chapter II referential and optional. The mandatory part requires identifying especially vulnerable groups by age, gender, socioeconomic level, disability and ethnicity, amounting to gender-differentiated impact analysis for AI systems. The 2026 AI regulation requires risk-calibrated audits, though fairness appears in its recitals (via the UNESCO Recommendation) rather than as an operative article, neither regulator nor courts having resolved the gap.<\/p>\n<p>In employment, Ministerial Agreement MDT-2025-102 (2025) prohibits discriminatory selection requirements and, technology neutral, covers algorithmic screening, while the 2025 age-discrimination law makes any recruitment age filter unlawful, automated ones included. On gender, the 2018 law on violence against women recognises symbolic and digital violence and the 2021 COIP reform criminalised digital sexual violence, neither mentioning AI nor synthetic content, the gap two pending deepfake bills (2026) seek to close. The stalled AI bill would require representative datasets, bias mitigation and periodic algorithm audits, none of it yet law.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">What legal frameworks apply to AI-related harm and defective artificial intelligence systems? Who can be held liable (developer, deployer, victim of the damage, others), how is liability allocated, and what burden of proof applies to victims?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>There is no special AI liability regime, damage being resolved under general frameworks, with allocation turning on who the victim is. Article 54 of the Constitution makes providers of services and producers or sellers of consumer goods civilly and criminally liable for deficient services or defective products, professional malpractice expressly included.<\/p>\n<p>For consumers, Article 28 of the Consumer Defence Law makes producers, manufacturers, importers, distributors, traders, whoever placed their brand on the product and, in general, &#8220;all those whose participation influenced the damage&#8221; jointly and severally liable, so a victim may sue any link in the AI value chain without identifying the defect&#8217;s origin. Its regulation frees the provider only where it proves the cause of the damage was external to it. That 2000 statute remains operative, last amended 11 February 2022 and silent on artificial intelligence and algorithms, a modernising bill having been archived by the plenary on 30 September 2025 with eighty-eight votes.<br \/>\nBetween businesses the Civil Code governs, with fault-based extracontractual liability (Articles 2214 and 2229) and the victim proving damage, fault and causation (Article 169 COGEP), corrected by the Delfina Torres cassation doctrine (2002), adopting risk theory for hazardous activities, presuming the operator&#8217;s fault and reversing the burden of proof, which local doctrine already reads onto high-risk AI.<\/p>\n<p>In data matters the LOPDP imposes administrative liability on controllers and processors (fines of up to 1% of turnover) and the 2026 AI regulation qualifies developers, deployers, distributors and implementers as controllers or processors, civil compensation running through the general rules and habeas data, while criminal liability attaches to the natural persons who design, deploy or use it and, under Article 49 COIP, to legal entities.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">What cybersecurity obligations apply to AI systems?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>The Organic Law for the Strengthening of Cybersecurity (LOFC, approved 10 February 2026, published with immediate effect in the Fifth Supplement to Official Register No. 290 of 22 May 2026) is technology-neutral, reaching obligated subjects&#8217; AI systems: public entities managing essential services or critical digital infrastructure, digital service providers and private entities directly affecting essential-service continuity. No implementing regulation exists, only a staggered calendar, none issued as at 4 August 2026: within six months, towards November 2026, minimum national cybersecurity standards, incident management and notification, service and infrastructure classification, and vulnerability assessment and ethical hacking rules; within twelve months, towards May 2027, the National Catalogue of Essential Services and Critical Digital Infrastructure fixing who carries reinforced duties, national CSIRT organisational rules, digital service provider obligations and technical oversight.<\/p>\n<p>Core obligations are technical and organisational measures for confidentiality, integrity and availability, cybersecurity risk management, information security management systems on international standards, permanent contact points with the authority and notification of relevant incidents to the National CSIRT within 72 hours of detection, MINTEL governing, sanctioning powers over private parties mainly with sectoral regulators, fines running 0.1% to 1.5% of annual turnover.<\/p>\n<p>Ethical hacking and penetration testing gain legal cover under consent and purpose limitation, legalising red-teaming and adversarial testing of AI systems. Article 14 of the Cybersecurity Law substituted the first paragraph of Article 43 LOPDP, so a personal data breach now goes to the Data Protection Superintendency, the competent regulation and control body and, for information and technical coordination, the corresponding CSIRT within a &#8220;t\u00e9rmino&#8221; of five days, five business days under Ecuadorian law, the processor keeping a two-day term to notify the controller, two clocks running, seventy-two hours and five business days.<\/p>\n<p>The LOPDP security chapter (Articles 37 et seq.) requires state-of-the-art measures, protection by design and breach notification to affected data subjects where risks exist, the SPDP&#8217;s 2026 AI regulation adding proportional security and risk-calibrated audits. The Ecuadorian Government Information Security Scheme version 3.0 (Ministerial Agreement MINTEL-MINTEL-2024-0003, Third Supplement to Official Register No. 509 of 1 March 2024) imposes on public entities an information security management system with ninety-three controls. In banking, Book I, Title IX, Chapter V of the Codification of the Rules of the Superintendency of Banks, substituted by Resolution No. SB-2023-01901 of 12 September 2023, requires the ISO\/IEC 27000 series (Article 24) and annual independent information security and cybersecurity audits with vulnerability and penetration testing (Article 25), silent on artificial intelligence, machine learning and scoring. Criminally, Articles 229 to 234 COIP cover offences against information and communication system security, Article 232 the attack offence and Article 234 non-consented access to a computer, telematic or telecommunications system.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Is the use of artificial intelligence insured and\/or insurable in your jurisdiction, including with cyber policies? Are there market trends, or limitations?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>AI risk is insurable under the general regime, with no AI-specific product, no duty to insure AI systems and no mandate in the stalled bill. Insurance is supervised by the Superintendency of Companies, Securities and Insurance (SCVS), and the General Insurance Law covers patrimonial loss and damage broadly enough for cyber, technology E&amp;O and D&amp;O, without a statutory cyber or AI line. Wordings and tariffs need prior authorisation (Article 25) and Ecuadorian risks must go to locally established insurers (Article 66). The 2022 Fintech Law creates three testing regimes, and Resolution No. JPRF-S-2025-0152 of 30 April 2025 of the Financial Policy and Regulation Board added a chapter on insurance technology service entities, with risk management, continuity and information security duties.<\/p>\n<p>The cover that exists is technology neutral. Cyber wordings registered locally are built around network security and privacy events rather than around the technology that causes them, so they typically carry neither affirmative AI cover nor an AI exclusion, and respond to AI-related loss only where it manifests as a covered cyber event. Their privacy triggers are equally generic, defined by reference to regulations on the handling of personal data, with the European regime named expressly in some forms while the LOPDP is not, which reflects the use of adapted global wordings rather than forms drafted around Ecuadorian law.<\/p>\n<p>Regulatory fines illustrate the limit. Some policies extend to administrative fines as a head of damage where privacy and network security cover is purchased, but the extension is typically drafted to exclude fines that are not insurable at law, and sums paid in cyber extortion are covered only where legally permitted and insurable. The wordings therefore refer insurability back to Ecuadorian law, which has not resolved it, so exposure to fines under the LOPDP remains open even where cover is bought. Enforcement is what drives demand, with fines already imposed, the 2026 AI regulation and the new cybersecurity law.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Can artificial intelligence be named as an inventor in a patent application filed in your jurisdiction? If not, what is the current legal position?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>No, although no provision says so expressly. Patents in Ecuador are governed by Andean Community Decision 486 (2000), a supranational regime with direct effect and primacy over domestic law. The patent right belongs to the inventor (Article 22), who holds a moral right to be named (Article 24), and the application must state the inventor&#8217;s name and domicile (Articles 26-27), while the Andean patent examination manual requires natural persons. Under the COESCCI no one lacking inventive activity is an inventor (Article 275), with minimum employee inventor shares and royalties (Articles 276-277) and the inventor&#8217;s paternity right (Article 278), and SENADI&#8217;s forms require the inventor&#8217;s personal data and any assignment chain.<\/p>\n<p>No DABUS-type application naming an artificial intelligence as inventor has been reported in Ecuador or another Andean Community country, and no Andean Court prejudicial interpretation exists. In Brazil the national-phase DABUS application did not proceed after an INPI Federal Attorney&#8217;s Office opinion of 8 August 2022 that only a natural person may be inventor. AI-assisted inventions are patentable before SENADI naming the natural person who conceived the invention, configured the system or interpreted its output, whereas naming the AI fails formal examination. Redefining inventor would require the Andean Community Commission to amend Decision 486; the pending AI bill touches copyright, not patents.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Do images or works generated by and\/or with artificial intelligence benefit from copyright protection in your jurisdiction? If so, who is the authorship attributed to, and under what conditions?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>The dividing line is human creative input. Fully autonomous AI output enjoys no copyright protection in Ecuador, while AI-assisted works are protected where a natural person makes a relevant creative contribution, with authorship vesting in that person.<\/p>\n<p>Andean Community Decision 351 (1993), directly applicable in Ecuador, defines the author as the &#8220;natural person who carries out the intellectual creation&#8221; (Article 3), and the Andean Court of Justice construes originality as the author&#8217;s personal imprint (prejudicial interpretations 295-IP-2019 of 13 December 2019 and 191-IP-2021 of 21 September 2022). The COESCCI provides that &#8220;Only a natural person may be an author&#8221;, legal entities holding only derivative economic rights (Article 108), protection arising on creation, registration before SENADI being declaratory (Article 102), originality required (Article 104) and moral rights inalienable and only human (Article 118). A fully autonomous output has neither author nor originality and is in practice freely usable.<\/p>\n<p>For AI-assisted works the AI is treated as a tool, so authorship attaches to whoever provides creative direction, selection, curation or substantial editing, with no statutory threshold for sufficient human contribution, the main source of uncertainty.<\/p>\n<p>No Ecuadorian case law or SENADI criterion exists on point, the office having only convened the debate with WIPO, and in July 2026 Ecuador was selected as a WIPO pilot country to deploy an AI tool in trademark examination, operational adoption rather than a substantive position on AI authorship. Mexico&#8217;s Supreme Court Second Chamber held in Amparo Directo 6\/2025, decided on 2 July 2025, that a work generated by artificial intelligence, not being human creation, cannot be registered. The stalled AI bill would protect only works with a &#8220;substantial human creative contribution&#8221;; until enacted the rules above govern.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">What are the main issues to consider when using artificial intelligence systems in the workplace? Have any new regulations, or guidelines, been introduced regarding AI-driven hiring, performance assessment, or employee monitoring?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>The Ministry of Labour having issued nothing on AI, workplace AI is regulated in practice by the data protection authority. Article 20 LOPDP covers algorithmic hiring, performance evaluation and automated monitoring, giving employees and candidates a right against solely or partially automated decisions, plus explanation and challenge rights. The SPDP&#8217;s 2026 AI regulation makes the employer embedding AI an &#8220;implementer&#8221;, bound to inform workers, assess impacts before deployment, record automated decisions and audit proportionally to risk, assessments mandatory for systematic automated evaluation of personal aspects (Article 42 LOPDP, and the mandatory 2025 guide updated March 2026).<\/p>\n<p>Two Superintendency consultation responses on monitoring matter, persuasive guidance rather than rules binding private employers. On videosurveillance by public entities, cameras may not be generalised control, lawful only on a real, concrete and verifiable risk, never in areas of high privacy expectation, with layered signage and documented retention. Its 2025 criterion on biometric attendance control requires a proportionality test, a risk analysis identifying no high or critical risk, an impact assessment and freely given consent with a real alternative.<\/p>\n<p>By Judgment No. 59-19-IN\/24 of 11 July 2024 the Constitutional Court declared the 2019 ministerial agreement on the occupational clinical history unconstitutional for incompatibility with Articles 66(19) and 66(20) of the Constitution, with deferred effects and an order to delete records collected, holding that a worker&#8217;s sensitive data requires informed consent and authorisation, that the fields may not be compulsory and that sexual orientation, gender identity, obstetric, gynaecological and male reproductive history and &#8220;toxic habits&#8221; (to be renamed habits of substance consumption) may not be requested, save a narrow exception for occupational settings the health ministry deems relevant. Its replacement, Ministerial Agreement 00025-2025 (Supplement to Official Register No. 125 of 16 September 2025), omits sexual orientation, gender identity and religion, retains reproductive sections only where occupational-risk related and with prior authorisation, adding confidentiality and authorisation annexes. Judgment No. 2064-14-EP\/21 of 27 January 2021, on habeas data against a private holder of intimate photographs, founds informational self-determination, sensitive data falling under Article 92 of the Constitution with reinforced protection, though for health data the authority is 59-19-IN\/24.<\/p>\n<p>Technology-neutral labour rules also reach AI tools, the 2025 rules banning discriminatory selection requirements, the 2025 age-discrimination law (unlawful age filters, automated included), the 2024 harassment reform treating denial of digital disconnection as harassment, and the teleworker&#8217;s right to twelve continuous hours of daily disconnection, enforcement running through the LOPDP fines regime, not the labour inspectorate.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">What are the main privacy\/data protection issues arising from artificial intelligence development and use (including training data)? Have data protection authorities issued guidelines or rulings on artificial intelligence, and what are the key takeaways?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>Ecuador&#8217;s data protection authority has outpaced every other institution, Congress included, building by resolution since 2025 much of what the stalled bill was to deliver. No guidance exists on web scraping or training with publicly accessible data, so the general bases of Article 7 LOPDP apply, purpose limitation and minimisation sitting uneasily beside mass ingestion. On automated decisions, Articles 20 and 21 impose explanation, challenge and reinforced protections for children. Biometrics are sensitive data, presumptively banned from processing, and where enforcement started. Cloud training and inference abroad must comply with the transfers rule signed on 28 January 2026 and in force since 13 February 2026, and the 2026 AI regulation reaches foreign providers whose systems process Ecuadorian data subjects&#8217; data.<\/p>\n<p>The output comprises the AI regulation (in force since March 2026), the large-scale processing rule (a six-criteria scoring model triggering reinforced duties and a mandatory DPO), the international transfers rule (adequacy declarations, standard clauses, automatic adequacy intra-Andean), the mandatory impact assessment guide, rules on DPOs, anonymisation, legitimate interest and privacy by design, and a draft biometric rule, out for consultation from 31 March to 28 April 2026 and still a draft with number and date blank, whose Article 18 would prohibit biometric systems for mass and indiscriminate identification in public spaces unless expressly authorised by a rule of statutory rank, Article 17 impose reinforced legality, necessity and proportionality standards on facial recognition, and Article 16 prohibit decisions with legal effects based exclusively on automated biometric identification.<\/p>\n<p>Between 28 November and 31 December 2025 the SPDP issued four sanctioning resolutions against the professional football league and the football federation over facial-recognition ticketing applications, totalling USD 744,499.65, being USD 259,644.01 and USD 194,856.16 for invalidly obtained consent to biometric processing, USD 95,502.63 for failure to implement data protection by design and by default, with repetition as an aggravating factor, and USD 194,496.85 for an inadequate risk methodology whose impact assessment concluded without support that residual risk was nil. Only the first federation sanction is confirmed under appeal, and none of the four concerns artificial intelligence as such. AI compliance is thus enforceable through data protection without an AI statute, biometrics being the regulator&#8217;s visible priority, the impact assessment the central compliance artefact, and training data the largest unanswered question.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">How is data scraping regulated in your jurisdiction from an IP, privacy and competition perspective? Are there recent precedents addressing the legality of data scraping for training of artificial intelligence systems?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>No scraping-specific statute and no Ecuadorian scraping precedent exist, let alone on AI training, and the three applicable regimes all point to untested risk. Privacy is the sharpest edge, the LOPDP covering publicly accessible personal data, so scraping needs a lawful basis under Article 7, respect for the purpose of the original disclosure, and minimisation. Scraping at scale qualifies as large-scale processing under the 2026 rule (reinforced duties, impact assessment, mandatory DPO), and where the destination is model training the 2026 AI regulation applies to whoever &#8220;trains&#8221; AI systems with Ecuadorian data subjects&#8217; data, wherever located. The SPDP has issued no scraping guidance, though its biometric-app enforcement shows appetite.<\/p>\n<p>Under Decision 351 and the COESCCI, databases are protected only as compilations with original selection or arrangement, with no EU-style sui generis right and none for raw data or facts. There is no general text and data mining exception, text mining appearing only in the closed list of permitted acts of Article 212 of the COESCCI, confined to libraries and archives and filtered by the five-factor proportionality test of Article 211, leaving commercial training on protected works without safe harbour. Circumventing technological protection measures adds separate exposure under the COESCCI.<\/p>\n<p>Competition law offers the most plausible private action between rivals. The Organic Law on the Regulation of Unfair Competition (Third Supplement to Official Register No. 113 of 29 August 2025) repealed Articles 25, 26 and 27 of the Market Power Law, now uncitable, the prohibition and general clause sitting in Article 5, while Article 6 lists non-exhaustively confusion, deceit, imitation, denigration, comparison, exploitation of another&#8217;s reputation, violation of trade secrets, inducement to breach of contract and violation of rules, appropriation of another&#8217;s effort falling within imitation and the trade-secret limb deferred to the implementing regulation. Systematic extraction of a competitor&#8217;s dataset fits that doctrine, before the Superintendency of Economic Competition or the courts, though untested. Unauthorised access to a computer system (Article 234 COIP) also arises where scraping defeats technical barriers, and the question will almost certainly be litigated first as data protection, not IP.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">To what extent is the prohibition of data scraping in the terms of use of a website enforceable?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>Enforceable in principle, untested in practice, and dependent on how assent was obtained. Under the E-Commerce Law (2002) a contract is not deprived of validity for being formed through data messages (Articles 45-46), and the Civil Code makes the lawfully formed contract binding as law between the parties (Article 1561), so a properly logged click-wrap acceptance makes the anti-scraping clause enforceable, supporting damages and termination. Browse-wrap terms are the weak flank, since terms that &#8220;apply by navigation&#8221; leave no evidence of informed assent, and the rules on consent, adhesion contracts and, in consumer settings, abusive clauses make enforcement doubtful, while for consumer-facing services the 2002 statute demands express consent for electronic means and prior information (Articles 48 and 50).<\/p>\n<p>Enforcing terms against an anonymous, foreign or distributed scraper is arduous, Ecuador has no developed practice of anti-scraping injunctions, damages must be proven and quantified, and terms of use cannot defeat statute, so they cannot authorise what the LOPDP prohibits or waive data subject rights in advance. Combined with technical barriers the clause strengthens the criminal angle of unauthorised access and the unfair competition claim, though no Ecuadorian court has ruled on this.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Does your country have a regulator or authority responsible for supervising the use and development of artificial intelligence? What are its powers and enforcement tools?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>No AI regulator is established by law, only a de facto ecosystem where one authority enforces.<\/p>\n<p>The operational supervisor is the Superintendency of Personal Data Protection (SPDP), whose 2026 AI regulation asserted extraterritorial jurisdiction over anyone developing, training, deploying, distributing or providing AI systems that process Ecuadorian personal data. It may audit AI systems, order corrective and precautionary measures, and fine infringements at 0.1%-0.7% (minor) or 0.7%-1% (serious) of prior-year turnover under a published calculation methodology, tools already used in the first sanctions of December 2025 and January 2026, a biometrics case.<\/p>\n<p>MINTEL leads policy as governing body for digital transformation, having issued the EFIA-EC strategy and announced the AI sandbox. The AI Committee created by Ministerial Agreement MINTEL-MINTEL-2023-0019 of 30 November 2023 was constituted on 31 July 2024, in functions only until 30 December 2024 and never reconstituted, the strategy referring to MINTEL leading it &#8220;cuando sea conformado&#8221;, so no standing inter-institutional AI governance body exists, and the Committee never held regulatory or sanctioning powers. Under the new cybersecurity law MINTEL is also the cybersecurity governing authority, with sectoral regulators holding most sanctioning powers, the competition authority, the banking superintendency, SENADI in intellectual property and the Ombudsman filling the remaining space.<\/p>\n<p>Institutional design has the AI bill stuck. The draft never names MINTEL in its articles and creates a National AI Control Authority identified only functionally, concentrating policy formulation, supervision and inspection, access to data sources, algorithms and computational models for audit, preventive and corrective measures including restriction, suspension or withdrawal of systems, and sanctioning proceedings. On 16 July 2025 the Data Protection Superintendent told the committee that this concentrated functions excessively in the telecommunications ministry, warned of conflicts of interest and proposed that regulation, supervision and sanction sit with the Superintendency while the ministry keeps policy, promotion and incentives. As of August 2026 no other authority holds a statutory mandate over artificial intelligence, so supervision runs through the data protection regulator.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">How widespread is the adoption of artificial intelligence in businesses in your jurisdiction, and which sectors are leading?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>Adoption is real, fast-growing and largely ungoverned. The Latin American AI Index (ILIA 2025, CEPAL and CENIA) classifies Ecuador as an adopter, tenth of nineteen countries with 40.68 points, one place above its 2024 position, although the index warns that the two editions are not directly comparable. Governance is the lowest-scoring dimension at 34.93 against a regional average of 47.57, driven by a zero on vision and institutional framework, a pre-strategy position superseded on 19 January 2026, while Ecuador scores above the region on regulation, at 66.43 against 53.06, and on international linkage, at 75.00 against 64.47, its weakest single indicator being advanced human talent at 7.91 against 13.32. UNESCO&#8217;s readiness assessment credits human capital and gender parity in STEM, and flags rural connectivity of 48.1% of households against 73.6% urban, nine data centres or 0.514 per million inhabitants, and research and development investment at 0.44% of gross domestic product.<\/p>\n<p>Local reporting from early 2026 describes a high share of companies using AI tools with 30-40% time savings in repetitive processes, yet only some 12-18% with formal internal policies and around 70% running active AI initiatives with no internal rules, metrics or control structures, adoption without governance now colliding with the SPDP&#8217;s 2026 AI regulation, which presumes the documentation most adopters lack.<\/p>\n<p>Banking and financial services lead (fraud detection, credit scoring, chatbots), followed by telecommunications, retail and the agro-export complex (banana and shrimp, with AI in logistics, quality control and pest prediction). Health and education are incipient and pilot-driven, and the public sector has a target of 50% of central government institutions adopting AI by 2029.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">How is artificial intelligence used in the legal sector, by lawyers and\/or in-house counsels? Are AI-driven legal tools widely adopted, and what are the main regulatory concerns?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>Ecuadorian lawyers use general-purpose models and legal-specific platforms intensively for research, drafting, transcription and case management, mirroring regional surveys putting LATAM legal AI use near 90%. Few firms have internal AI policies or AI leadership roles, the first Chief AI Officer positions appearing recently.<\/p>\n<p>No Judiciary Council resolution or Constitutional Court precedent governs judicial AI use. The only Ecuadorian decision identified on AI is an Electoral Disputes Tribunal ruling of 8 May 2024 refusing to discard audiovisual evidence on the hypothetical possibility of tampering &#8220;by any external intervention, including artificial intelligence programs&#8221; (case 111-2023-TCE and consolidated cases). An unreviewed AI-drafted ruling is challengeable for defective reasoning under the constitutional duty of motivation, and the judiciary has acknowledged rulings citing nonexistent case law from unverified AI use.<\/p>\n<p>Judicial Council Resolution 082-2026 approved the Strategic Plan of the Judicial Function 2026 to 2031, its annex contemplating artificial intelligence in monitoring and control modules and a transition towards cognitive justice. On 16 June 2026 the Ethics Committee of the Judicial Function (Judicial Council, National Court of Justice, Attorney General&#8217;s Office, Public Defender&#8217;s Office) approved a protocol of twenty-three principles on responsible artificial intelligence use by judges, prosecutors, defenders and staff, drafted by the Universitat Pompeu Fabra Barcelona School of Management, reviewed by UNESCO and the Inter-American Development Bank, among others. As at 4 August 2026 the Council had not adopted it by resolution, and with neither its text nor the list of authorised tools published, its content is, as far as we are aware, known only from press reports and binds no one. A June 2026 bill would amend the Code of the Judicial Function to allow AI only as a support tool, barred from evidence assessment, legal interpretation and decision-drafting, with disclosure of its use and unverified reliance a serious disciplinary offence for judges and lawyers.<\/p>\n<p>The least discussed risk is privileged client information fed into foreign cloud models without processing agreements or transfer safeguards; hallucinated authority already draws sanctions in Colombia, Argentina and Spain while Ecuador has no rule, and absent bar guidance malpractice litigation will set diligence standards. For in-house counsel the 2026 AI regulation adds a layer, a company deploying legal AI on personal data being an &#8220;implementer&#8221; with registrable, auditable duties.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">What are the 5 key challenges and the 5 key opportunities raised by artificial intelligence for lawyers in your jurisdiction?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p><strong>The five key challenges:<\/strong><\/p>\n<p><strong>Advising on a moving target.<\/strong> Ecuador regulates AI by resolution while the statute stalls, the SPDP issuing binding rules and MINTEL issuing strategy, so clients must be advised on a framework assembled by accretion whose most important rules are administrative, recent and untested.<\/p>\n<p><strong>Confidentiality versus convenience.<\/strong> The everyday use of foreign cloud models on privileged client information, without processing agreements or transfer safeguards, is the profession&#8217;s largest unmanaged risk.<\/p>\n<p><strong>The verification burden.<\/strong> Hallucinated case law has already produced sanctions in Colombia, Argentina and Spain, while Ecuador has no rule, no bar guidance and no case yet, so the standard will be set retroactively.<\/p>\n<p><strong>A talent gap with geography.<\/strong> AI literacy is concentrated in large firms in Quito and Guayaquil and legal education has barely incorporated it, so the gap between AI-fluent and AI-illiterate lawyers is becoming a market access gap.<\/p>\n<p><strong>Pressure on the business model.<\/strong> Automation erodes precisely the repetitive, billable work that funded the training pyramid for junior lawyers, and firms that only extract efficiency, without redesigning how young lawyers learn, are consuming their own future.<\/p>\n<p><strong>The five key opportunities:<\/strong><\/p>\n<p><strong>A new practice area with immediate demand.<\/strong> The EFIA-EC, the SPDP&#8217;s AI regulation, the cybersecurity law and the coming sandbox create real compliance work now, being impact assessments, AI governance frameworks, audits and vendor contracts, and first movers are already differentiating.<\/p>\n<p><strong>Productivity as democratisation.<\/strong> Savings of 30-40% on repetitive tasks benefit small firms and solo practitioners proportionally more than large ones, so AI can narrow rather than widen the gap between big and small legal practice.<\/p>\n<p><strong>Access to justice<\/strong>. AI-assisted triage, document preparation and legal information services can reach populations the traditional market never served, in a country where the public defender system itself is co-authoring AI guidelines.<\/p>\n<p><strong>Regional positioning.<\/strong> Ecuador shares its IP regime, and now data-transfer adequacy, with the Andean Community, so lawyers who master the intersection of Andean law and AI can serve clients across four jurisdictions from one desk.<\/p>\n<p><strong>Designing the public architecture.<\/strong> The sandbox, judicial AI projects and the state&#8217;s 50% AI adoption target all require legal design, and lawyers with technical fluency will hold the pen.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\t\t\t\t\t<li class=\"question-block filter-container__element\">\r\n\t\t\t\t\t\t<h3 class=\"filter-container__match-html\">Where do you see the most significant legal developments in artificial intelligence in your jurisdiction in the next 12 months? Are there any ongoing initiatives that could reshape AI governance?<\/h3>\r\n\t\t\t\t\t\t<button id=\"show-me\">+<\/button>\r\n\t\t\t\t\t\t<div class=\"question_answer filter-container__match-html\" style=\"display:none;\"><p>Most consequential will be the fate of the unified AI bill, whether a first-debate report, a redesign of the authority model or the archive, the unresolved question being institutional, MINTEL as concentrated regulator versus the Data Protection Superintendency as supervisor. A June 2026 working session with the US Embassy on international standards suggests the text is still being shaped, though after two years in committee its enactment prospects are currently considered low. Regulation by resolution will likely continue, the SPDP consolidating as the de facto AI authority.<\/p>\n<p>Concrete developments to watch:<\/p>\n<p>The SPDP pipeline. Two drafts completed consultation and neither has issued, the biometric data rule, whose Article 18 would prohibit mass and indiscriminate biometric identification in public spaces absent statutory authorisation, and a technical rule on notifying security breaches. First audits under the AI regulation come next, and guidance on training data or scraping would close the widest gap.<\/p>\n<p>Cybersecurity implementation. The LOFC&#8217;s implementing regulation and the National Catalogue of Essential Services will define which AI operators carry reinforced duties, when the 72-hour clock becomes real.<br \/>\nThe AI sandbox moving from structuring to intake of actual projects, testing AI under regulatory supervision, rare in the region.<\/p>\n<p>Criminal law reform. The deepfake and digital violence bills, the COIP digital-crimes package (past first debate since June 2026) and the bill on child sexual exploitation through AI are narrower and more consensual than the general AI law, one plausibly becoming Ecuador&#8217;s first AI-specific statute.<\/p>\n<p>Judicial governance is the most imminent. The Judiciary Council resolution adopting the Ethics Committee&#8217;s 23 principles was announced as weeks away, with a list of authorised AI tools; the bill on AI in the judiciary completes the picture, as does TEGICA, the Judicial Council&#8217;s project on transparency and ethics in the digital management of judicial cases with artificial intelligence, which the Council resolved on 30 October 2025 to submit to the Twenty-Third Ibero-American Judicial Summit as Ecuador&#8217;s institutional initiative, awaiting qualification, not evaluation. Brazil holds the pro tempore secretariat for 2025 to 2027 and hosts the 2027 plenary on the axis of artificial intelligence and justice, with neither city nor dates yet published.<\/p>\n<p>The SPDP&#8217;s intra-Andean adequacy rule and the UNESCO-aligned strategy wire Ecuador into regional AI governance, and if the Andean Community ever moves on AI, which nothing indicates soon, the data protection framework has laid the plumbing.<\/p>\n<\/div>\r\n\r\n\r\n\t\t\t\t\t<\/li>\r\n\r\n\t\t\t\t\r\n<div class=\"word-count-hidden\" style=\"display:none;\">Estimated word count: <span class=\"word-count\">7589<\/span><\/div>\r\n\r\n\t\t\t<\/ol>\r\n\r\n<script type=\"text\/javascript\" src=\"\/wp-content\/themes\/twentyseventeen\/src\/jquery\/components\/filter-guides.js\" async><\/script><\/div>"}},"_links":{"self":[{"href":"https:\/\/my.legal500.com\/guides\/wp-json\/wp\/v2\/comparative_guide\/147624","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/my.legal500.com\/guides\/wp-json\/wp\/v2\/comparative_guide"}],"about":[{"href":"https:\/\/my.legal500.com\/guides\/wp-json\/wp\/v2\/types\/comparative_guide"}],"wp:attachment":[{"href":"https:\/\/my.legal500.com\/guides\/wp-json\/wp\/v2\/media?parent=147624"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}