South America's financial sector is in the middle of an AI transformation that few regions can match in speed or ambition. From Brazil's massive Open Finance ecosystem -- now exceeding 128 million active consents across more than 200 participating institutions -- to Colombia's mandatory Open Finance decree, Argentina's booming fintech scene with over 800 startups, and Chile's phased Open Finance rollout, the continent is deploying AI-driven credit scoring, fraud detection, robo-advisory, and algorithmic underwriting at scale. Yet the regulatory frameworks governing these deployments are neither uniform nor static. For CTOs, CISOs, and compliance officers at Latin American financial institutions, fintechs, and banks, mapping the compliance landscape across multiple jurisdictions is now a strategic imperative -- not an optional exercise.
This guide provides a pan-regional overview of the data protection laws, financial supervisory expectations, Open Finance mandates, and emerging AI-specific regulations that shape how financial services companies across South America can lawfully build, deploy, and govern artificial intelligence. Each section includes a compliance checklist your team can act on regardless of which country -- or how many countries -- you operate in.
The South American Regulatory Landscape
Unlike the European Union, which harmonized data protection through GDPR, South America regulates AI and personal data through a patchwork of national laws, sector-specific financial supervisory guidance, and emerging regional agreements. Brazil's LGPD sets the tone, but Colombia, Argentina, Chile, Peru, and Uruguay each impose distinct obligations. Financial institutions operating across borders must comply with every jurisdiction where they collect data, serve customers, or process transactions -- and several of these laws now carry extraterritorial reach.
- The Lei Geral de Protecao de Dados (LGPD) is South America's most comprehensive data protection law and the primary framework governing AI deployments in Brazil's financial sector. The ANPD (Autoridade Nacional de Protecao de Dados) has been actively enforcing LGPD against financial institutions and technology companies, with investigations into Meta and Worldcoin for biometric data processing signaling increased scrutiny of AI-driven identity verification. LGPD
- LGPD Article 20 grants data subjects the right to request review of automated decisions that affect their interests, including credit scoring, insurance underwriting, and fraud flagging. Financial institutions must be able to provide meaningful explanations of how their AI models reached a decision -- black-box models that cannot produce human-interpretable rationale create direct compliance exposure. LGPD
- The ANPD's AI regulatory sandbox, running through December 2026, allows qualified financial institutions and fintechs to test AI applications under supervised conditions. Participation provides regulatory safe harbor during the testing period, but institutions must document outcomes, risk assessments, and data protection impact analyses (DPIAs) as a condition of enrollment. Evaluate whether your AI use cases qualify. LGPD
- LGPD requires a lawful basis for processing personal data in AI systems. For financial services, legitimate interest and contract performance are the most common bases, but both require a balancing test documented in a Legitimate Interest Assessment (LIA). Consent-based processing for AI model training introduces withdrawal risk -- if a customer revokes consent, you must be able to retrain or adjust the model without that individual's data.
- Brazil's Open Finance ecosystem, regulated by the Banco Central do Brasil, is the largest in the region with over 128 million active consents and 200+ participating institutions. Since February 2026, credit portability via Open Finance allows customers to transfer their credit history between institutions -- AI models that ingest this data must comply with Banco Central's data-sharing standards and consent management protocols. OPEN FINANCE
- Colombia's Decree 0368/2026 establishes mandatory Open Finance participation beginning April 2026, supervised by the Superintendencia Financiera de Colombia (SFC). The decree introduces a dual-consent architecture: customers must consent both to the data-sharing arrangement and to each specific use of their data. AI systems consuming Open Finance data in Colombia must enforce this two-layer consent model and maintain granular audit trails of consent status per data element. OPEN FINANCE
- Argentina's Banco Central (BCRA) announced its open finance framework in October 2025, designed to integrate with the country's 800+ fintech ecosystem. Chile's CMF has mapped a phased Open Finance rollout from 2027 through 2029 under Law 21.521. Institutions building AI platforms for cross-border deployment should design consent management and data ingestion layers that can accommodate the distinct consent models each country will require. OPEN FINANCE
- When AI models are trained on Open Finance data, the training itself is a form of data processing that requires explicit authorization. Institutions must ensure their consent flows distinguish between using shared data for the immediate service request (e.g., a credit application) and using it for model training, feature engineering, or analytics -- conflating these purposes violates purpose limitation principles across all regional frameworks. OPEN FINANCE LGPD
- Colombia's Law 1581/2012, enforced by the Superintendencia de Industria y Comercio (SIC), requires explicit and informed consent for personal data processing. The SIC has demonstrated willingness to penalize large-scale AI deployments: Mercado Libre was fined for processing biometric data without adequate authorization, setting a precedent for any financial institution using AI-driven facial recognition, liveness detection, or biometric KYC. REGIONAL
- Argentina's Personal Data Protection Act (PDPA, Law 25.326) holds EU adequacy status, meaning it aligns closely with GDPR standards. For AI in financial services, this means Argentine data subjects have the right to access the logic involved in automated processing that affects them. The BCRA's integration of open finance with Argentina's 800+ fintechs will intensify the need for AI explainability and data minimization in credit and payments use cases. REGIONAL
- Chile's new Personal Data Protection Law (PDPL), enacted in 2024, introduces extraterritorial scope -- it applies to any entity processing Chilean residents' data regardless of where the entity is domiciled. The law establishes a data protection authority with enforcement powers and aligns Chile's framework more closely with GDPR. Financial institutions deploying AI that processes Chilean customer data from servers outside Chile are now subject to PDPL obligations. REGIONAL
- Peru's Law No. 29733 imposes strict breach notification timelines and requires data controllers to register their databases with the national authority. Uruguay holds EU adequacy status and became the first Latin American signatory to the Council of Europe's Framework Convention on Artificial Intelligence in September 2025, signaling that Uruguayan regulators will align AI governance expectations with European standards. Financial institutions operating in Uruguay should anticipate AI-specific compliance requirements drawing from this convention. REGIONAL
- Across South America, data subjects hold ARCO rights -- Access, Rectification, Cancellation (or Deletion), and Objection. These rights apply directly to AI systems: a customer denied credit by an AI model has the right to access the data used, request correction of inaccurate inputs, object to the automated processing, and in some jurisdictions demand that the decision be reviewed by a human. Your AI pipeline must support all four rights operationally, not just as policy statements. REGIONAL
- The right to rectification creates a technical requirement for AI systems: if a customer corrects their personal data, the institution must evaluate whether the corrected data changes the AI model's output. For credit scoring and risk assessment models, this means maintaining the ability to re-run decisions with updated inputs and communicate revised outcomes within regulatory timeframes. LGPD REGIONAL
- The right to object to automated processing is particularly consequential for financial AI. Under Brazil's LGPD Article 20 and analogous provisions in Colombia and Argentina, data subjects can challenge decisions made solely by automated means. Institutions must implement fallback processes -- human review pathways for credit decisions, fraud determinations, and account actions -- that can be activated when a customer exercises this right.
- Cancellation and deletion requests affect AI training data. When a customer exercises their right to deletion, institutions must determine whether that individual's data was used in model training and, if so, whether the model must be retrained. Establish a data lineage framework that tracks which personal data contributed to which models, enabling compliant responses to deletion requests without destabilizing production AI systems.
- Financial institutions training AI models on data from multiple South American countries face complex cross-border transfer rules. Brazil's LGPD permits transfers to countries with adequate data protection levels or under Standard Contractual Clauses (SCCs). Argentina and Uruguay, holding EU adequacy status, follow GDPR-aligned transfer mechanisms including SCCs and Binding Corporate Rules (BCRs). LGPD REGIONAL
- The Ibero-American Data Protection Network has developed model contractual clauses specifically designed for transfers within the region. These clauses provide a standardized mechanism for institutions that need to move personal data between South American jurisdictions for AI processing, centralized model training, or consolidated analytics. Evaluate whether your current transfer agreements align with these model clauses. REGIONAL
- Cloud-hosted AI infrastructure introduces transfer considerations by default. If your AI models run on cloud platforms with data centers outside the originating country, the data movement to those servers constitutes a cross-border transfer subject to each country's export rules. Document where your model training data is stored, where inference occurs, and whether any personal data transits through servers in non-adequate jurisdictions.
- For institutions centralizing AI model training across multiple South American markets, consider establishing a regional data processing hub in a jurisdiction with EU adequacy status (Argentina or Uruguay) to simplify the transfer compliance matrix. This does not eliminate per-country consent and processing requirements, but it reduces the number of distinct transfer mechanisms you must maintain.
- Beyond data protection laws, financial regulators across South America are setting AI governance expectations through supervisory guidance. Brazil's Banco Central requires that AI models used in credit decisions comply with Resolution 4.893 on cybersecurity and Resolution 4.658 on cloud computing and data processing. The CMN (Conselho Monetario Nacional) imposes model risk management standards that parallel the OCC's SR 11-7 framework for banks operating in Brazil. REGIONAL
- Colombia's Superintendencia Financiera (SFC) supervises AI deployments within the financial sector and has the authority to require algorithmic impact assessments for high-risk AI use cases. The SFC's oversight of Colombia's Open Finance decree means that AI systems consuming shared financial data will face direct supervisory scrutiny on model governance, bias testing, and consumer protection. OPEN FINANCE
- Chile's Comision para el Mercado Financiero (CMF) regulates fintechs under Law 21.521 and has signaled that AI governance will be integral to its Open Finance supervision framework as the rollout progresses from 2027 through 2029. Institutions planning to participate in Chile's Open Finance ecosystem should build AI model documentation and validation processes now, before supervisory expectations are codified into binding requirements. REGIONAL
- Board-level AI governance is an emerging supervisory expectation across the region. Financial regulators in Brazil, Colombia, and Chile increasingly expect that boards of directors are informed about AI deployments, associated risks, and the institution's approach to algorithmic fairness. Document board briefings and establish an AI risk committee or designate AI oversight responsibilities within an existing risk governance structure.
- South American regulators are moving from guidance to enforcement. Colombia's SIC fined Mercado Libre for collecting and processing biometric data without proper authorization -- a case directly relevant to any financial institution using AI-powered facial recognition for customer onboarding, identity verification, or transaction authentication. The ruling established that biometric data processed by AI systems requires heightened consent and security measures. REGIONAL
- Brazil's ANPD has investigated TikTok for data processing practices affecting minors and scrutinized Worldcoin's iris-scanning biometric collection program. While these are not financial services companies, the enforcement rationale applies directly to fintechs and banks deploying AI-based biometric authentication: the ANPD treats biometric data as sensitive personal data under LGPD, triggering heightened processing requirements. LGPD
- The Meta enforcement action in Brazil, targeting the company's use of personal data for AI training without adequate informed consent, signals that regulators will not accept broad privacy policy language as a substitute for specific, granular consent for AI model training. Financial institutions that train proprietary models on customer transaction data, behavioral patterns, or communication records should review whether their consent mechanisms would withstand similar scrutiny. LGPD
- Penalty structures vary across jurisdictions but are escalating. LGPD fines can reach 2% of a company's revenue in Brazil, capped at BRL 50 million per infraction. Colombia's SIC can impose fines up to 2,000 minimum wages. Chile's new PDPL introduces administrative fines modeled on GDPR proportionality. Treat compliance budgets as risk investments calibrated to these penalty ceilings, not as discretionary expenses. REGIONAL
- Build a centralized AI model inventory that maps each model to the jurisdictions where it operates, the personal data it processes, its lawful basis in each country, and its risk classification. Update it quarterly at minimum and include models deployed by third-party vendors on your behalf. LGPD REGIONAL
- Conduct Data Protection Impact Assessments (DPIAs) for every AI system that processes personal data at scale. Brazil's LGPD, Chile's PDPL, and Colombia's Law 1581 all require or strongly recommend impact assessments for high-risk automated processing. Use a single DPIA template adapted per jurisdiction to avoid duplication while ensuring each country's specific requirements are met. LGPD REGIONAL
- Implement ARCO rights fulfillment workflows that connect to your AI systems. When a customer requests access, rectification, deletion, or objects to automated processing, your response must include the ability to explain AI-driven decisions, correct inputs and re-evaluate outcomes, delete data from training sets, and escalate to human review. REGIONAL
- Design Open Finance consent management to enforce dual-consent models where required (Colombia) and purpose-limited consent everywhere. AI systems that consume Open Finance data must distinguish between using data for immediate service delivery and using it for model training, analytics, or profiling. OPEN FINANCE
- Map all cross-border data flows involving AI model training and inference. For each flow, document the legal transfer mechanism (SCCs, BCRs, adequacy, Ibero-American model clauses), the data categories transferred, and the destination country's adequacy status. Maintain this mapping as a living document reviewed at least semi-annually. LGPD REGIONAL
- Establish AI explainability standards that satisfy the most stringent jurisdiction in your operating footprint. Brazil's LGPD Article 20 right to review of automated decisions, Argentina's PDPA logic-access rights, and Colombia's consent framework all demand that AI models produce human-interpretable explanations. Build explainability into model design rather than retrofitting it. LGPD REGIONAL
- Review AI vendor and cloud provider contracts for compliance with each jurisdiction's data localization and transfer rules. Assess whether your AI infrastructure provider can demonstrate compliance with LGPD, Chile's PDPL extraterritorial requirements, and Colombia's SFC supervisory expectations. Include contractual provisions for audit rights, sub-processor notifications, and breach response timelines. REGIONAL
- Develop an AI incident response playbook tailored to South American regulatory timelines. Peru's Law 29733 imposes strict breach notification windows. Brazil's ANPD requires notification of security incidents that may cause significant risk or harm. Colombia's SIC expects prompt disclosure. Your playbook should map each country's notification authority, required timelines, and mandatory content for breach notifications involving AI systems. LGPD REGIONAL
Looking Ahead: 2026-2028 Regional Outlook
The regulatory trajectory across South America points toward convergence with global AI governance standards, but through distinct national paths. Uruguay's signing of the Council of Europe's AI Convention in September 2025 marks the first formal alignment of a Latin American country with Europe's AI governance framework -- other nations are likely to follow with their own adaptations. Brazil's AI regulatory sandbox running through December 2026 will generate supervisory learnings that will shape permanent AI regulation. Colombia's Open Finance mandate, Chile's phased rollout, and Argentina's fintech integration will each generate new compliance requirements as regulators observe how AI interacts with open data ecosystems.
For CTOs and CISOs at financial institutions operating across the region, the strategic calculus is straightforward: build compliance infrastructure for the most demanding jurisdiction you operate in, design consent and data governance layers that can accommodate country-specific requirements without re-architecting, and treat ARCO rights fulfillment as a core system capability rather than a manual process. The institutions that invest in pan-regional AI governance frameworks now will be positioned to scale confidently as new regulations emerge, while those that take a country-by-country reactive approach will find themselves perpetually catching up.
South America's AI regulatory landscape is complex, but it follows recognizable principles: protect personal data, explain automated decisions, honor individual rights, and govern cross-border flows. The financial institutions that build these principles into their AI architecture -- rather than layering compliance on top of it -- will move faster, serve customers better, and face regulators with confidence.
Need Help Navigating AI Compliance Across South America?
Our team advises financial institutions on pan-regional AI governance, data protection compliance, Open Finance readiness, and cross-border data transfer frameworks across Brazil, Colombia, Argentina, Chile, Peru, and Uruguay. We help you build a unified compliance architecture before regulators ask the questions.
Book a Consultation