---
title: "Uzbekistan AI Regulation 2026: Law ZRU-1115 Explained"
description: "Understand Uzbekistan’s AI Regulation 2026 (Law ZRU-1115), ethical rules, and key compliance requirements for businesses."
canonical: "https://axipro.co/uzbekistan-ai-regulation/"
language: "en-US"
modified: "2026-09-27T04:26:27+00:00"
generator: "WordPress 7.1.2"
---

[Home](https://axipro.co)

/ [AI Security](https://axipro.co/category/ai-security/)

/ Uzbekistan AI Regulation 2026: Law ZRU-1115 Explained

# Uzbekistan AI Regulation 2026: Law ZRU-1115 Explained

![Picture of Pedro Dias](https://axipro.co/wp-content/uploads/2026/05/pedro-passport-picture-scaled.jpg)

- Pedro Dias
- September 27, 2026

Copy Link

Uzbekistan regulates artificial intelligence through two documents. The first is **Law ZRU-1115**, signed on 21 January 2026. It amends existing legislation to define AI, stops anyone from basing decisions about people’s rights on AI output alone, and fines companies that process personal data unlawfully with AI. The second is the set of **Ethical Rules approved by Order No. 3787**, in force since 17 June 2026, which spell out what developers, implementers, and users actually have to do.

Uzbekistan hasn’t passed a standalone AI act, and its rules don’t sort systems into risk tiers or require conformity assessments. The framework is short and blunt, and it’s already enforceable. Below we walk through what each document requires, who it applies to, how it stacks up against the EU AI Act, and what a company using AI in Uzbekistan should do next.

## **Uzbekistan AI Regulation at a Glance (TL;DR)**

| Instrument | Date | What it does | Who it binds |
| --- | --- | --- | --- |
| Law ZRU-1115 | Signed 21 January 2026 | Defines AI in law, sets general rules for AI-built information resources and systems, bans legally significant decisions based only on AI, adds fines for unlawful AI processing of personal data | State bodies, organizations, website owners, anyone processing personal data with AI |
| Order No. 3787 (Ethical Rules) | Registered 14 March 2026, in force 17 June 2026 | Sets eight mandatory ethical principles and lists rights and obligations for developers, implementers, and users | Individuals and companies developing, implementing, or using AI in Uzbekistan |
| Law No. 1125 (Personal Data amendments) | Adopted 26 March 2026 | Limits data localization to biometric, genetic, and local telecom user data, and allows cross-border transfers under conditions | Personal data operators, including AI providers |
| AI Strategy until 2030 (RP-358) | 14 October 2024 | Sets national targets for AI adoption, infrastructure, and skills | Government bodies |

## **What Is Law ZRU-1115?**

The law’s official title is a mouthful: *“On making additions and changes to certain legislative acts of the Republic of Uzbekistan in connection with the regulation of relations arising from the use of artificial intelligence.”* Put simply, it’s an amending law. Instead of creating a new AI code, it writes AI into laws that were already on the books.

### When It Was Signed and When It Took Effect

The Legislative Chamber of the Oliy Majlis adopted the bill on 12 August 2025, and the Senate approved it on 1 November 2025. President Shavkat Mirziyoyev signed it on 21 January 2026. You can read the official text in [Lex.uz, Uzbekistan’s national legislation database](https://lex.uz/en/docs/8011930).

The law set out the principles and the penalties. The day-to-day detail arrived later with the Ethical Rules, which came into force on 17 June 2026. For compliance planning, treat mid-June 2026 as the point when the whole framework started applying.

### Why Uzbekistan Amended Existing Laws Instead of Passing a Standalone AI Act

Uzbekistan wants more AI, not less. Its national strategy sets numeric targets for adoption, investment, and local computing capacity, and a heavy EU-style act would have worked against them.

So lawmakers kept it light. They defined AI, drew two hard lines (human control over decisions that affect people’s rights, and protection of personal data), and left the Ministry of Digital Technologies to fill in the rest through secondary rules. Businesses get less legal certainty, and the government gets to move faster.

### Which Laws ZRU-1115 Changes

For businesses, two amendments matter most.

The **Law “On Informatization” (ZRU-560-II, 2003)** now contains a legal definition of AI, a new article on using AI in information resources and systems, duties for website owners, and updated powers for the ministry in charge.

The **Code on Administrative Liability** now includes an offense for processing and spreading personal data unlawfully using AI.

Let Axipro help you build a business continuity plan that's practical, compliant, and audit-ready.

Schedule Your Free Assessment Today

[Schedule a consultation](https://axipro.co/free-assessment/)

## **The Legal Definition of Artificial Intelligence in Uzbekistan**

Under the amended Law “On Informatization,” AI is a set of technological solutions that imitate human cognitive functions, including learning on their own and solving problems, and that produce results on specific tasks comparable to what a person could do.

That’s deliberately broad. It covers generative AI, machine learning classifiers, recommendation engines, and most agentic systems. The Ethical Rules add a narrower term, the **AI system**: software built on AI that can find, collect, store, analyze, process, evaluate, and use data, and make decisions on its own based on that data. If your product makes a decision from data, or shapes one, assume it counts.

## **Key Rules Introduced by Law ZRU-1115**

General Principles for Using AI in Information Systems and Resources

The new article in the Law “On Informatization” starts from harm. Information resources created with AI, and information systems running on AI, must not harm people’s life, health, freedom, honor, or dignity, or violate their other inalienable rights.

The standard is short and open-ended. It gives regulators something to enforce against without saying in advance what counts as harm. Principle-based rules like this deserve to be taken seriously precisely because the edges are undefined.

Human Oversight: No Decisions on Rights and Freedoms Based Solely on AI

Most coverage leads with this provision, and it’s easy to see why. When someone makes a legally significant decision that affects human rights and freedoms, **they can’t rely only on conclusions produced by AI systems or AI-built information resources**.

AI can feed into the decision, but a person has to make it. That applies to loan denials, benefit eligibility, hiring rejections, licensing outcomes, and disciplinary action. In each case, someone needs to look at the AI output and own the final call.

**Insider Note:** In AI governance engagements, teams rarely struggle to show that a review step exists. What they struggle to show is that the reviewer could disagree, and sometimes did. If a human clicks “approve” on every AI recommendation and nobody ever records an override, auditors will see automation with a signature on top. Build the override path and log when people use it, starting on day one.

Powers of the Authorized State Body (Ministry of Digital Technologies)

ZRU-1115 makes the [Ministry of Digital Technologies](https://www.digital.gov.uz/en/activity_page/sun-iy-intellekt) the authorized state body for AI. Among its new jobs, it’s responsible for attracting investment into AI, building data-processing infrastructure for government bodies, and organizing training for AI specialists.

The ministry also writes the secondary rules. The Ethical Rules are the first big one, and more standards are on the way.

## **AI and Personal Data: New Administrative Liability**

### What Counts as Unlawful Processing of Personal Data Using AI

ZRU-1115 goes after two things: processing personal data unlawfully with AI, and spreading that data through mass media, telecom networks, or the internet. The second part is what stands out. If you scrape someone’s profile photo into a face-matching tool, that’s one violation. If you then publish what the tool produced, that’s another.

Website owners get a duty of their own, and the law names bloggers specifically. They have to stop the public content on their sites from being used to process personal data unlawfully with AI. For any platform that hosts user profiles, that means anti-scraping controls and terms of use that say so clearly.

### Fines and Confiscation Under the Code on Administrative Liability

The penalty is an administrative fine of **50 to 100 base calculation units (BCU)**, or roughly $1,700 to $3,400 at 2026 values. Authorities can also **confiscate whatever was used to commit the offense**.

Next to EU fines, that’s little money. The confiscation clause is a different story. Depending on how enforcers read “instruments,” it could cover servers, devices, or the accounts used for the processing. For most companies, losing those would hurt far more than paying the fine.

### How ZRU-1115 Interacts With the Law “On Personal Data”

ZRU-1115 sits on top of Uzbekistan’s personal data law rather than replacing it. Whether your processing is lawful in the first place (consent, legal basis, purpose limits) is still decided under the Law “On Personal Data.” ZRU-1115 just adds an AI-specific way to punish violations.

The personal data law itself changed this year. **Law No. 1125**, adopted on 26 March 2026, scaled back mandatory localization. Biometric data, genetic data, and data about users of local telecom services still have to be stored in Uzbekistan. Everything else can go abroad as long as one of three conditions holds: the destination country is recognized as adequate, the operator uses approved standard contractual clauses or binding corporate rules, or it follows approved international standards.

**Important:** As of mid-2026, the Cabinet of Ministers hadn’t published its list of adequate countries. Until it does, sending Uzbek personal data abroad for AI processing will in practice rely on contractual clauses or approved standards. And any AI feature built on face or voice data, which counts as biometric, still needs storage inside Uzbekistan.

## **The New Ethical Rules: Ministry of Digital Technologies Order No. 3787**

The Ministry of Justice registered the Ethical Rules for the Development, Implementation and Use of AI-Based Solutions as number 3787 on 14 March 2026, and they took effect on 17 June 2026. The word “ethics” is a little misleading. The rules read as requirements: everyone covered must strictly comply, and nobody should treat an AI decision as final.

### Core Ethical Principles (Transparency, Fairness, Accountability, Safety)

There are eight mandatory principles: lawfulness; putting the interests of the individual, society, the state, and the environment first; transparency and intelligibility; accountability, responsibility for outcomes, and oversight; fairness and non-discrimination; openness and transparency; information security; and reliability and safety.

Most of the practical work comes from three of them. **Intelligibility** means you have to be able to explain how the system works, the main criteria its algorithm uses, how it reaches decisions, and where its data comes from. **Accountability** means every decision made with AI stays under human control and open to human review, and a person makes the final call. **Reliability and safety** mean the system has to run consistently and accurately, and the data fed into it has to be stored securely.

The rules also stretch the human-oversight requirement past ZRU-1115. You can’t rely solely on AI conclusions in **healthcare decisions** either, which covers diagnosis, choosing treatment, analyzing medical images, and managing patient data.

### Obligations for AI Developers

Developers and implementers share a single list of duties. They have to keep algorithms transparent and understandable, prevent bias, and protect personal data and restricted information. They also have to explain clearly what the system can do, where it falls short, and what risks it carries, and they have to guarantee that a human can review its outputs and make the final decision.

On top of that, they must write and publish user guidelines for each AI system, and they can’t use AI for anything that breaks Uzbek law or could harm individuals, society, the state, or the environment. In return, the rules confirm their ownership and IP rights and let them propose changes to the rules.

### Obligations for AI Owners and Operators

If you deploy someone else’s model, you’re an implementer, and the full list above applies to you. Buying a model from a vendor doesn’t hand off your duty to explain it, check it for bias, or keep a person in charge of what it produces.

End users have responsibilities too. They have to follow the system’s terms, use it properly, protect personal data and restricted information, respect other people’s copyright, and avoid causing harm. In exchange, they have the right to know how the system may be used, to get an explanation of how its algorithms work, and to report problems to the developer.

### Labelling and Disclosure of AI-Generated Content

What the Ethical Rules ask for is disclosure. Developers and implementers have to tell users the rules for using the AI system, what it can and can’t be used for, and that its outputs aren’t always accurate and are meant as advice or information.

They don’t explicitly require you to watermark or tag synthetic content, which Article 50 of the EU AI Act does. In practice, a clear in-product notice that users are dealing with AI, along with a published user guide that sets out the system’s limits, meets the Uzbek requirement. Plenty of teams will label outputs anyway, since it’s cheap and satisfies both regimes.

## **Who Must Comply?**

### Government Bodies and State Organizations

State bodies were the original target of the human-oversight rule in ZRU-1115, and they’re still the most exposed. Any ministry, agency, or state-owned company that uses AI for permits, benefits, tax assessments, or citizen services has to keep a human decision-maker involved and be able to prove it.

### Private Companies Operating in Uzbekistan

The Ethical Rules apply to every individual and company that develops, implements, or uses AI in Uzbekistan. That includes banks scoring credit, employers screening candidates, telecoms and e-commerce platforms personalizing offers, and clinics using diagnostic tools. The personal data fines apply to any company processing personal data with AI, whatever sector it’s in.

### Foreign Companies Offering AI Products to Uzbek Users

Neither document has an extraterritorial test like the EU AI Act’s, and the Ethical Rules talk about activity within Uzbekistan. Even so, a foreign SaaS or AI provider that processes personal data of people in Uzbekistan falls under the personal data law. That brings in the localization rules for biometric data and, with them, the AI-specific fines. Local resellers and enterprise customers will also pass the Ethical Rules’ disclosure and oversight duties down to vendors through their contracts. If you sell AI into Uzbekistan, assume the rules apply to you.

## **Where ZRU-1115 Fits in Uzbekistan’s AI Strategy Until 2030**

ZRU-1115 is the legal piece of a larger economic plan. Presidential Resolution RP-358 of 14 October 2024 approved the [Strategy for the Development of AI Technologies until 2030](https://lex.uz/en/docs/7159258). It came with an action plan for 2024 to 2026, targets for AI-based products and services, and a list of big data sets from the social and economic sectors that the government wants opened up for AI projects.

Decree PF-141, signed on 24 July 2026, took this a step further. It added AI to the Digital Uzbekistan 2030 Strategy and told state bodies to build out the legal framework for AI, write ethics rules, and draft state standards, reporting progress every quarter. Its duties fall on government rather than industry, but it makes it pretty clear that more detailed rules are coming.

## **How Uzbekistan’s Approach Compares to the EU AI Act**

Both regimes insist on human control, and that’s about where the overlap ends. The [EU AI Act](https://en.wikipedia.org/wiki/Artificial_Intelligence_Act) is a product-safety regulation organized around risk tiers. Uzbekistan’s framework is a set of principles spread across amendments to older laws.

| Dimension | Uzbekistan (ZRU-1115 + Order No. 3787) | EU AI Act |
| --- | --- | --- |
| Legal form | Amendments to existing laws plus ministerial rules | Standalone regulation |
| Risk classification | None | Four tiers, from prohibited to minimal risk |
| Human oversight | Mandatory for rights-affecting and healthcare decisions | Mandatory for high-risk systems |
| Transparency | Disclose purposes, limits, and potential inaccuracy of AI | Article 50 disclosure and labelling of AI-generated content, applying from 2 August 2026 |
| Conformity assessment | None | Required for high-risk systems |
| Maximum penalty | 50 to 100 BCU plus confiscation (personal data offense) | Up to €35 million or 7% of global turnover |
| Territorial scope | Activity in Uzbekistan, plus personal data rules | Explicitly extraterritorial |

In practice, a company already working toward EU AI Act compliance will cover most of Uzbekistan’s requirements along the way. It doesn’t work in the other direction. Axipro’s overview of [AI regulatory compliance trends](https://axipro.co/ai-regulatory-compliance-trends/) compares these models with the Gulf approach, and our piece on [EU AI Act rules for recruitment tools](https://axipro.co/eu-ai-act-recruitment-tools/) shows how much further the EU’s high-risk regime reaches than Uzbekistan’s single oversight rule.

## **Common Misunderstandings About Uzbekistan’s AI Law**

**“Uzbekistan has no AI law.”** It has no standalone AI act, but it does have binding AI rules in the Law “On Informatization,” a dedicated administrative offense, and mandatory Ethical Rules. Assuming that no single code means no regulation is the costliest mistake here.

**“The Ethical Rules are voluntary guidance.”** The rules say participants must strictly comply. They don’t come with their own penalty schedule, since the fines live in the Code on Administrative Liability and target personal data offenses. Ignoring the ethics duties can still come back to bite you in procurement, licensing, or a contract dispute.

**“Only government AI is regulated.”** The oversight rule started with state bodies, but private companies are covered by the Ethical Rules and the personal data offense as well.

**“An ISO 42001 certificate equals compliance.”** A certificate is strong evidence that you govern AI well. It won’t make your processing of Uzbek personal data lawful, and it won’t satisfy the localization rules for biometric data.

Reach SOC 2 Compliance in 6 Weeks or Less

Schedule Your Free SOC 2 Assessment Today

[Schedule](https://axipro.co/free-assessment/)

## **What’s Still Missing: Sector-Specific Rules on the Horizon**

The rules are thinnest exactly where AI can do the most damage. The Labour Code says nothing about algorithmic hiring, monitoring, or dismissal, and Uzbek academics have already pointed this out in studies comparing it with the EU. Financial services have no AI-specific model risk rules. Healthcare gets the oversight requirement, but no validation standard or incident reporting.

Without risk classification, a chatbot answering questions about store hours sits under the same principles as a model triaging patients. PF-141’s instruction to draft state standards suggests sector rules and technical standards will follow. Companies that set up governance now will find those rules much easier to absorb than companies that wait.

## **Practical Compliance Checklist for Businesses Using AI in Uzbekistan**

### Map Your AI Systems and Personal Data Flows

Start by listing every AI system you build, buy, or embed, and include the AI features hidden inside SaaS tools your teams already use. For each one, note whose personal data it touches, where that data lives, and whether any of it is biometric or genetic. That single inventory tells you which systems fall under the Ethical Rules and which data flows trigger localization or cross-border transfer rules under Law No. 1125.

### Put Human Review Into High-Impact Decisions

Find every decision that affects someone’s rights, freedoms, or health, and redesign it so a named person makes the final call. Give reviewers enough information to disagree with the AI, a real way to override it, and a log that records when they do. That log is what you’ll show a regulator or a customer who asks.

### Disclose AI Use and Its Limits to Users

For each AI system, publish a user guide that explains what it’s for, what it shouldn’t be used for, and that its outputs can be wrong and are only advisory. Add an in-product notice anywhere users interact with AI. If you also have EU users, label AI-generated content now and you’ll cover both regimes with one control.

### Document Governance Using ISO/IEC 42001

Uzbekistan’s rules tell you what outcomes you need, not how to run the program that gets you there. [ISO/IEC 42001](https://www.iso.org/standard/81230.html), the certifiable standard for AI management systems, covers the how. Its requirements for AI policy, impact assessments, lifecycle controls, data governance, and third-party oversight line up closely with the Ethical Rules’ demands on transparency, bias prevention, and human oversight.

A scoped [ISO 42001 gap analysis and risk assessment](https://axipro.co/iso-42001-gap-analysis-and-risk-assessment/) usually takes one to three weeks and shows how far your current controls are from both the standard and the Uzbek rules. If you already hold ISO 27001, you can reuse a lot of your management system, and our comparison of [ISO 42001 vs ISO 27001](https://axipro.co/iso-42001-vs-iso-27001/) explains what carries over. Axipro’s [ISO 42001 certification services](https://axipro.co/iso-42001/) take the program from gap analysis through to guaranteed certification on the Achievement Plan.

### Pro Tip: Build one control set instead of three.

Build one control set instead of three. Write your AI impact assessment to ISO 42001, then give it a section for Uzbekistan’s oversight and disclosure duties and another for the EU AI Act. Each new market you enter adds a section, not a whole new program.

## **The Bottom Line**

Uzbekistan picked speed over structure. Law ZRU-1115 writes AI into existing laws, bans decisions about people’s rights that rest only on AI, and fines unlawful AI processing of personal data. Order No. 3787 adds mandatory principles, disclosure duties, and a rule that a human stays in charge, including in healthcare. The fines are modest, but confiscation is a real risk, and more detailed rules are on the way. If you inventory your AI, keep people in control of high-impact decisions, tell users honestly what your systems can and can’t do, and run the program on ISO 42001, you’ll be compliant now and in good shape for whatever comes next.

## Frequently Asked Questions

Does Uzbekistan have a specific AI law?

Not a standalone one. Uzbekistan regulates AI through Law ZRU-1115, which amends the Law “On Informatization” and the Code on Administrative Liability, and through the Ethical Rules approved by Order No. 3787. Both are binding.

Can AI make fully autonomous decisions about people’s rights in Uzbekistan?

No. A legally significant decision that affects someone’s rights and freedoms can’t rest on AI conclusions alone, and the Ethical Rules apply the same rule to healthcare. A person has to review the output and make the final decision.

What are the fines for misusing personal data with AI?

Processing or spreading personal data unlawfully with AI can bring a fine of 50 to 100 base calculation units, roughly $1,700 to $3,400. Authorities can also confiscate whatever was used to commit the offense, which is usually the bigger worry for a business.

Do the rules apply to foreign companies?

The Ethical Rules cover AI activity in Uzbekistan, and the personal data law covers anyone processing personal data of people there. A foreign AI provider with Uzbek users should assume both apply, especially if it handles biometric data, which has to be stored in the country.

Is AI-generated content required to be labelled?

Not explicitly. Developers and implementers have to tell users the rules, purposes, and limits of their AI systems and warn them that outputs may be inaccurate. Labelling synthetic content is still good practice, and the EU AI Act requires it.

Axipro Author

![Picture of Pedro Dias](https://axipro.co/wp-content/uploads/2026/05/pedro-passport-picture-scaled.jpg)

### Pedro Dias

Pedro has been writing online for over 10 years. With experience in all things programming, cyber security, and compliance, he is our editor-in-chief at Axipro.

- September 27, 2026
- [AI Security](https://axipro.co/category/ai-security/)

Copy Link

## Blog Highlights

## Explore More Articles

[Read More Blogs](https://axipro.co/blog/)

- [AI Security](https://axipro.co/category/ai-security/)

- September 27, 2026

#### [Uzbekistan AI Regulation 2026: Law ZRU-1115 Explained](https://axipro.co/uzbekistan-ai-regulation/)

Uzbekistan regulates artificial intelligence through two documents. The first is Law ZRU-1115, signed on 21 January 2026. It amends existing legislation to define AI, stops anyone from basing decisions about people’s rights on AI output alone, and fines companies that process personal data unlawfully with AI. The second is the set of Ethical Rules approved by Order No. 3787, in force since 17 June 2026, which spell out what developers, implementers, and users actually have to do. Uzbekistan hasn’t passed a standalone AI act, and its rules don’t sort systems into risk tiers or require conformity assessments. The framework is short and blunt, and it’s already enforceable. Below we walk through what each document requires, who it applies to, how it stacks up against the EU AI Act, and what a company using AI in Uzbekistan should do next. Uzbekistan AI Regulation at a Glance (TL;DR) Instrument Date What it does Who it binds Law ZRU-1115 Signed 21 January 2026 Defines AI in law, sets general rules for AI-built information resources and systems, bans legally significant decisions based only on AI, adds fines for unlawful AI processing of personal data State bodies, organizations, website owners, anyone processing personal data with AI Order No. 3787 (Ethical Rules) Registered 14 March 2026, in force 17 June 2026 Sets eight mandatory ethical principles and lists rights and obligations for developers, implementers, and users Individuals and companies developing, implementing, or using AI in Uzbekistan Law No. 1125 (Personal Data amendments) Adopted 26 March 2026 Limits data localization to biometric, genetic, and local telecom user data, and allows cross-border transfers under conditions Personal data operators, including AI providers AI Strategy until 2030 (RP-358) 14 October 2024 Sets national targets for AI adoption, infrastructure, and skills Government bodies What Is Law ZRU-1115? The law’s official title is a mouthful: “On making additions and changes to certain legislative acts of the Republic of Uzbekistan in connection with the regulation of relations arising from the use of artificial intelligence.” Put simply, it’s an amending law. Instead of creating a new AI code, it writes AI into laws that were already on the books. When It Was Signed and When It Took Effect The Legislative Chamber of the Oliy Majlis adopted the bill on 12 August 2025, and the Senate approved it on 1 November 2025. President Shavkat Mirziyoyev signed it on 21 January 2026. You can read the official text in Lex.uz, Uzbekistan’s national legislation database. The law set out the principles and the penalties. The day-to-day detail arrived later with the Ethical Rules, which came into force on 17 June 2026. For compliance planning, treat mid-June 2026 as the point when the whole framework started applying. Why Uzbekistan Amended Existing Laws Instead of Passing a Standalone AI Act Uzbekistan wants more AI, not less. Its national strategy sets numeric targets for adoption, investment, and local computing capacity, and a heavy EU-style act would have worked against them. So lawmakers kept it light. They defined AI, drew two hard lines (human control over decisions that affect people’s rights, and protection of personal data), and left the Ministry of Digital Technologies to fill in the rest through secondary rules. Businesses get less legal certainty, and the government gets to move faster. Which Laws ZRU-1115 Changes For businesses, two amendments matter most. The Law “On Informatization” (ZRU-560-II, 2003) now contains a legal definition of AI, a new article on using AI in information resources and systems, duties for website owners, and updated powers for the ministry in charge. The Code on Administrative Liability now includes an offense for processing and spreading personal data unlawfully using AI. The Legal Definition of Artificial Intelligence in Uzbekistan Under the amended Law “On Informatization,” AI is a set of technological solutions that imitate human cognitive functions, including learning on their own and solving problems, and that produce results on specific tasks comparable to what a person could do. That’s deliberately broad. It covers generative AI, machine learning classifiers, recommendation engines, and most agentic systems. The Ethical Rules add a narrower term, the AI system: software built on AI that can find, collect, store, analyze, process, evaluate, and use data, and make decisions on its own based on that data. If your product makes a decision from data, or shapes one, assume it counts. Key Rules Introduced by Law ZRU-1115 General Principles for Using AI in Information Systems and Resources The new article in the Law “On Informatization” starts from harm. Information resources created with AI, and information systems running on AI, must not harm people’s life, health, freedom, honor, or dignity, or violate their other inalienable rights. The standard is short and open-ended. It gives regulators something to enforce against without saying in advance what counts as harm. Principle-based rules like this deserve to be taken seriously precisely because the edges are undefined. Human Oversight: No Decisions on Rights and Freedoms Based Solely on AI Most coverage leads with this provision, and it’s easy to see why. When someone makes a legally significant decision that affects human rights and freedoms, they can’t rely only on conclusions produced by AI systems or AI-built information resources. AI can feed into the decision, but a person has to make it. That applies to loan denials, benefit eligibility, hiring rejections, licensing outcomes, and disciplinary action. In each case, someone needs to look at the AI output and own the final call. Insider Note: In AI governance engagements, teams rarely struggle to show that a review step exists. What they struggle to show is that the reviewer could disagree, and sometimes did. If a human clicks “approve” on every AI recommendation and nobody ever records an override, auditors will see automation with a signature on top. Build the override path and log when people use it, starting on day one. Powers of the Authorized State Body (Ministry of Digital Technologies) ZRU-1115 makes the Ministry of Digital Technologies the authorized state body for AI. Among its new jobs, it’s

[Read more](https://axipro.co/uzbekistan-ai-regulation/)

- [SOC-2](https://axipro.co/category/soc-2-2/)

- September 24, 2026

#### [The SaaS Founder’s 6-Week SOC 2 Readiness Plan (Free Template)](https://axipro.co/soc-2-readiness-plan/)

You can get a SaaS company ready for a SOC 2 audit in six weeks, but you’ll feel every one of them. Most published timelines say three to six months. For a company with no project owner, no identity provider, and nothing written down, that’s about right. A cloud-native startup that already has the basics in place and can protect some time is a different story, and it can fit the work into six hard weeks. This plan walks through that route one week at a time. Each week has an owner, an hour estimate, and a clear test for when it’s finished. The free Google Sheet version turns the plan into a tracker you can hand out to owners and update in your weekly standup. Before you start, know what you’re signing up for. At the end of week 6 you’ll be audit-ready, which isn’t the same as holding a Type II report. Nobody can get you a Type II in six weeks. This is also the do-it-yourself route, and it takes a lot of hours. We’ll show you where those hours go and what the faster option looks like. Is Six Weeks Realistic for Your Company? Six weeks works when most of the plumbing already exists and your job is to formalize it, fill the gaps, and prove it all works. It falls apart when you’re building the foundations and documenting them at the same time. Go through this table honestly before you promise a customer a date. Six weeks is realistic if… Plan for 10 to 16 weeks if… Your product runs on a major cloud provider You host on-premise or across several data centers You already use an identity provider with SSO Every tool has its own login and password You have fewer than about 50 employees You have multiple offices, subsidiaries, or products in scope One named person owns the project with 10 to 15 hours a week Compliance is “everyone’s job,” so in practice nobody owns it An engineer can give you 15 to 20 hours in weeks 3 and 4 Engineering is fully committed to a launch You only need the Security criteria You need Availability, Confidentiality, or Privacy on day one Landing mostly in the right-hand column doesn’t mean you should throw the plan out. Give each week two weeks instead of one and follow the same order. What “SOC 2 Ready” Means at the End of Week 6 SOC 2 doesn’t give you a certificate. An independent CPA firm examines your controls against the AICPA Trust Services Criteria and writes a report, and which of the two report types you go for decides what you can show a buyer after week 6. A Type I report checks whether your controls are designed properly on a single date. Once you’re ready, a Type I audit can start almost right away. A Type II report checks whether those controls kept working over an observation period of at least three months, and usually six to twelve. Most enterprise procurement teams want Type II in the end. Being “ready” at the end of this plan means your in-scope controls are in place, you can pull evidence for any of them on request, and your auditor is booked. From there you either start a Type I audit or open your Type II observation window. Plenty of buyers will sign with a Type I report plus a letter from your auditor saying the Type II period is underway. Important: The Type II clock doesn’t start until your controls are running. If readiness slips by a week, your Type II report slips by a week too. Founders who tell a prospect “we’ll have SOC 2 in Q3” often forget this and end up renegotiating the deal. Before Week 1: Four Decisions to Make First Settle these before the clock starts. If you change any of them halfway through, you’ll redo work. Scope. Decide which systems, teams, and data the report covers. For most SaaS companies that’s the production environment, the code repository, the identity provider, customer data stores, and any support tools that touch customer data. Corporate systems that never see customer data can usually stay out. Trust Services Criteria. Security (also called the Common Criteria) is mandatory. Availability, Confidentiality, Processing Integrity, and Privacy are optional. Report type. Pick Type I if a deal is blocked right now and the buyer will accept it. If there’s no deadline, go straight to Type II. You’ll need it eventually, and skipping Type I saves you an audit fee. Owner and tooling. Name one person who’s accountable for the plan, and decide where your controls and evidence will live. The tooling choice gets its own section below. Pro Tip: Adding Criteria Only add optional criteria when a customer contract or security questionnaire asks for them. Each one brings more controls to set up and more evidence to collect, and you can widen the scope in next year’s audit. Spreadsheet or Compliance Software: Choosing Your Tracking Tool Every SOC 2 program needs a system of record, meaning one place where each control, its owner, its status, and its evidence live. You can run it yourself in a spreadsheet or a GRC platform, or have a consultant implement it for you. The right choice depends mostly on which report you’re after and how much of your team’s time you can spare. A spreadsheet is free and familiar. It also makes you understand your own environment before you automate any of it. For a Type I, or for a small team with a tight scope, a well-built spreadsheet can take you all the way to the audit. Axipro’s free GRC workbook for SOC 2 and ISO 27001 covers all 33 SOC 2 Common Criteria plus the optional criteria, with evidence, risk, policy, and gap trackers built in. It has no macros and opens straight in Google Sheets or Excel. A GRC platform connects to your cloud, identity provider, code repository, and HR system.

[Read more](https://axipro.co/soc-2-readiness-plan/)

- [All Blog](https://axipro.co/category/blog/), [Customer Stories](https://axipro.co/category/stories/), [ISO 42001](https://axipro.co/category/iso-42001/), [ISO-27001](https://axipro.co/category/iso-27001/)

- September 23, 2026

#### [How MetisJean Went From Startup to ISO 27001 and ISO 27701 Certified in Five Months](https://axipro.co/metisjean-iso-27001-27701-42001/)

MetisJean, a technology startup with no governance framework, earned ISO/IEC 27001 and ISO/IEC 27701 certification and implemented ISO/IEC 42001 with Axipro in five months.

[Read more](https://axipro.co/metisjean-iso-27001-27701-42001/)

WhatsApp us
