Ali Zuweid's Political Programme
Proposed bill · Digital State, Data, Artificial Intelligence and Cybersecurity
Artificial Intelligence Governance, Algorithmic Accountability and High-Risk Systems Law
A risk-based legal framework governing the AI system lifecycle, limiting unacceptable practices and giving individuals notification, explanation and human review rights, while protecting innovation and building coherent national governance.
Executive Summary
Iraq has entered a new regulatory phase for artificial intelligence, but its legal architecture is still developing. The Iraqi National Centre for Artificial Intelligence states that the national strategy extending to 2050 remains under preparation. Its readiness assessment found that only 19 of 64 institutions had clear readiness improvement plans, while the official website places strategy completion at 40%.[2] On 26 April 2026, the Ministry of Planning discussed refining the strategy's objectives, computing infrastructure and the concept of a sovereign national language model.[3]
On 23 September 2026, the Communications and Media Commission released the ‘Draft Regulation for Artificial Intelligence Services in the Republic of Iraq’ for thirty days of public consultation, aiming to regulate services, protect users and data, and promote security, transparency and investment.[4] The draft contains important elements, including risk classification, licensing requirements, transparency, human oversight and data governance. However, AI regulation inherently extends beyond telecommunications and information technology to justice, health, education, employment, banking, social protection and infrastructure. Iraq therefore needs a horizontal law enacted by the legislature defining rights, limits and powers, beneath which sectoral regulations operate.[5]
The bill proposes a risk-based model instead of licensing every AI use identically. It prohibits a narrow set of unacceptable practices, imposes strong duties on high-risk systems, grants direct rights to affected persons, and regulates general-purpose models, generative AI and agents capable of external actions. It draws on recent international experience from the EU AI Act, UNESCO Recommendation, OECD Principles, Council of Europe framework, NIST risk management framework and international AI management standards, adapted to Iraq's state structure and present capacity.[7][8][9][10][11][13]
The central institutional principle is to avoid a new parallel authority when Iraq already has a higher committee, national centre and sectoral bodies. The law fixes their roles: the higher committee coordinates policy; the national centre provides the technical secretariat, register and assessment; sectoral bodies supervise within their sectors; and the Communications and Media Commission remains responsible for services within telecommunications and information technology. This separation prevents a single body from regulating health, justice, banking and employment simply because the tool used is AI.
First — Constitutional and Legal Context
AI regulation begins with the Constitution rather than technology. Article (14) establishes equality before the law; Article (15) protects life, security and liberty; Article (17), personal privacy; Article (19), fair trials and procedures; Article (38), expression, journalism and publication; and Article (40), electronic communications confidentiality, prohibiting monitoring or disclosure except for legal and security necessity and by judicial order.[1] Any state algorithmic system for biometric identification, prediction, prioritisation or decision-making must therefore meet legality, necessity, proportionality and human review standards.
AI also intersects with personal data and privacy protection, electronic transactions, cybersecurity, digital crime, telecommunications, banking, health, education, labour, consumer protection, criminal procedure, public procurement and competition laws. A comprehensive law should not replace these, but add horizontal safeguards and responsibilities where AI introduces additional risk or opaque or large-scale decisions.
Second — Iraq's Legislative Gap
Iraqi institutions are already moving towards use and regulation. The national strategy is developing, the national centre exists, the Communications and Media Commission has released a regulatory draft, and a published study by the Parliamentary Research and Studies Department recommended AI legislation alongside strategy, infrastructure and skills.[2][4][6] The issue is not inactivity, but absence of a horizontal law clearly answering questions a sectoral regulation alone cannot settle: which uses are prohibited? When is a system high-risk? Who may object? When is biometric identification permissible? How is liability divided between model developers and deployers? What limits apply to automated decisions in justice, employment or credit?
AI does not always need a ‘service licence’ to affect citizens. It may simply be embedded in human resources software, a hospital programme, bank assessment, traffic camera or judicial assistance system. The bill therefore regulates use by risk, rather than whether a product is sold directly to the public.
Third — Proposed Legislative Policy
| Category | Rule | Examples |
|---|---|---|
| Unacceptable practices | Specific statutory prohibition | General social scoring, disproportionate mass biometric identification, individual criminal prediction based solely on traits |
| High-risk systems | Impact assessment, documentation, registration, human oversight, testing and post-deployment monitoring | Justice, law enforcement, credit, education, employment, health, public services and critical infrastructure |
| General-purpose models | Documentation, safety and transparency according to capability and scale | Language and multimodal models integrable into different applications |
| Generative content and automated interaction | Disclosure and readable labelling where needed to prevent deception | Conversational assistants and synthetic images, audio and video |
| Limited risks | Light or voluntary obligations | General productivity tools that do not make decisions affecting rights |
The bill also adopts ‘responsibility according to control’: model developers are responsible for design, documentation and updates under their control; deployers for context, data, use and human oversight; and sectoral authorities for domain-specific additional requirements. This prevents shifting the entire burden to the weakest link in the value chain.
Fourth — Text of the Bill
Chapter One — General Provisions and Definitions
Article (1) — Title and nature of the Law
This Law is called the ‘Artificial Intelligence Governance, Algorithmic Accountability and High-Risk Systems Law’ and establishes a horizontal AI governance framework in the Republic of Iraq. Sectoral laws and data protection, cybersecurity, consumer protection and civil and criminal liability rules remain applicable where no specific provision exists, interpreted consistently with this Law's safeguards.
Article (2) — Objectives
This Law aims to enable safe, responsible AI development and use; protect rights, freedoms and human dignity; prevent discrimination and serious harm; ensure transparency, accountability and reviewability; regulate high-risk and general-purpose systems; support innovation, investment and scientific research; and establish coherent national governance adaptable to technological development.
Article (3) — Governing principles
Governance shall rest on legality, necessity and proportionality; human primacy and effective human oversight; safety, security and robustness; privacy and data protection; non-discrimination and equal opportunities; context-appropriate transparency and explainability; traceability and accountability; competition and innovation; protection of children and groups at risk; and effective objection and remedy.
Article (4) — Personal and material scope
This Law applies to every public or private natural or legal person developing, providing, importing, distributing, deploying or using AI in Iraq; placing systems or outputs on the Iraqi market; or directing outputs to persons in Iraq or producing substantial legal or material effects on them.
Article (5) — Extraterritorial application
Foreign providers are subject to relevant obligations where they provide systems or services to users in Iraq, target its market, process data of persons in Iraq or generate substantial effects in Iraq. Foreign providers required to register shall appoint an Iraqi legal representative, without relieving the original provider of liability.
Article (6) — Limited exceptions
Commercial registration and prior assessment requirements do not apply to research and development not placed into service or on the market, or non-professional personal use. Prohibited-practice, rights, data and security provisions remain applicable where others are harmed. Purely military combat systems follow a special regime; this exception does not cover administration, recruitment, surveillance, investigation or public service systems merely because a security or military body uses them.
Article (7) — Core definitions
An ‘AI system’ is a machine-based system designed to operate with varying autonomy, which may adapt after deployment and infer from inputs how to generate predictions, content, recommendations or decisions influencing physical or virtual environments. ‘Provider’ means one who develops a system or places it on the market or into service under their name. ‘Deployer’ means one using it under their professional authority. ‘Affected person’ means someone whose rights, interests, opportunities or legal position are affected.
Article (8) — Risk and general-purpose model definitions
A ‘high-risk system’ falls within this Law's fields or criteria and, on failure or misuse, presents a significant likelihood of affecting health, safety, rights, livelihoods or access to essential services. A ‘general-purpose AI model’ can perform a broad range of tasks and be integrated into multiple systems. A ‘model with systemic risk’ is a general-purpose model whose capabilities, deployment scale or potential effects warrant additional safety measures.
Chapter Two — Risk Classification and Prohibited Practices
Article (9) — Risk-based approach
AI systems shall be classified by actual use, context, capability and potential harm into prohibited practices, high-risk systems, systems with specific transparency duties, and low- or limited-risk systems. Classification shall not be raised or lowered solely by the provider's trade name or technical claims.
Article (10) — Risk criteria
Classification shall consider autonomy, affected population size, reversibility of harm, data sensitivity, vulnerable groups, reliance on outputs in decisions, difficulty detecting error, potential large-scale spread, connection to infrastructure, money or physical safety, and reasonably foreseeable misuse.
Article (11) — Harmful manipulation and exploitation prohibited
Placing or using systems employing covert or deceptive techniques or deliberately exploiting age, disability or economic or psychological vulnerability is prohibited where they materially impair informed decision-making and cause or are likely to cause serious physical, psychological, financial or legal harm.
Article (12) — General social scoring prohibited
Public bodies and private entities performing public functions shall not establish or use general social scoring that evaluates or classifies people by social behaviour or predicted characteristics outside the data collection context, where this causes detrimental or disproportionate treatment or denial of rights, services or opportunities.
Article (13) — Inference of highly sensitive traits prohibited
Biometric or behavioural characteristics shall not be used to infer race, ethnicity, religion, sect, political opinion, sexual orientation or other highly sensitive traits for classification or treatment, unless specific legislation authorises necessary, defined processing for a legitimate protective purpose with strict safeguards against discrimination or general profiling databases.
Article (14) — Facial recognition databases from untargeted collection prohibited
Creating or expanding facial or biometric recognition databases through large-scale untargeted collection of images or recordings from the internet, surveillance cameras or public sources is prohibited without a specific, proportionate legal basis.
Article (15) — Remote biometric identification in public places
Public authorities shall not use real-time remote biometric identification in publicly accessible places for law enforcement except to search for missing persons, prevent imminent danger to life or investigate a specified serious felony, under a prior judicial order defining location, duration, purpose and comparison database, documenting false results and destroying unnecessary data. It shall not be used for general surveillance or tracking lawful protests, political activity or journalism.
Article (16) — Criminal prediction based solely on traits prohibited
Decisions to investigate, detain, search or classify someone as likely to offend shall not rely exclusively or decisively on algorithmic predictions based on personality, traits, past behaviour or social connections without current, objectively verifiable facts connected to a specific offence.
Article (17) — Emotion inference in work and education prohibited
Systems inferring emotional or psychological states shall not be used in workplaces or educational institutions for recruitment, evaluation, discipline, admission or dismissal decisions, except defined medical or safety uses managed by competent bodies with consent and appropriate legal safeguards.
Article (18) — Sole automated decisions on liberty or fundamental rights prohibited
AI shall not be the sole final decision-maker in deprivation of liberty, judicial judgments, withdrawal of civil rights, serious administrative penalties or termination of essential subsistence benefits. A competent person must decide, with genuine power to depart from the system's recommendation after reviewing its grounds and relevant data.
Chapter Three — High-Risk System Obligations
Article (19) — High-risk fields
Subject to this Law, high-risk systems include those used for biometric identification; critical infrastructure and services; educational admission and assessment; recruitment and worker management; credit, insurance and essential financial services; public benefits and services; healthcare affecting diagnosis or treatment; law enforcement, borders and migration; justice and dispute resolution assistance; elections and democratic administration; road safety and transport; and allocating resources or services whose denial affects rights or livelihoods.
Article (20) — Amending the high-risk list
On the Higher Committee for AI Governance's recommendation and after public consultation, the Council of Ministers may add or amend uses where evidence shows harm comparable in severity and likelihood. A category expressly established by law may be removed only by law.
Article (21) — Risk management system
High-risk providers shall maintain continuous lifecycle risk management covering known and foreseeable risks, intended use and reasonably foreseeable misuse testing, affected groups, mitigation controls, post-deployment verification and documentation of key technical and organisational decisions.
Article (22) — Training and testing data governance
Training, validation and testing data shall be relevant, appropriately high-quality, representative as far as possible of intended populations and contexts, subject to error and known-bias detection, and accompanied by provenance and legal and technical limitations. This does not authorise collection of personal data without a lawful basis.
Article (23) — Technical documentation
Before release, providers shall prepare technical files describing intended purpose, general architecture, performance limits, data, accuracy metrics, known risks, security controls, evaluation methods, human oversight, material change records and safe-use instructions sufficiently for competent authority audit without requiring unnecessary trade secret disclosure.
Article (24) — Automatic logging
High-risk systems shall generate and retain sufficient operational logs to trace decisions and significant events, detect failures and investigate incidents, with proportionate retention, restricted access and tamper protection. Logging requirements shall not become unlawful surveillance of users or affected persons.
Article (25) — Instructions and transparency for deployers
Providers shall clearly explain capabilities and limitations, accuracy and reliability, populations or conditions of weaker performance, data requirements, over-automation risks, error indicators, security measures and how to disable systems or revert to alternatives when necessary.
Article (26) — Effective human oversight
High-risk design and operation shall allow qualified people to understand tasks, monitor outputs, suspect errors, reject or modify recommendations and stop systems when danger arises. Oversight is not effective if staff are practically obliged to follow outputs or lack time, information or authority to review them.
Article (27) — Accuracy, robustness and cybersecurity
Providers and deployers, within their responsibilities, shall ensure appropriate, demonstrated accuracy, robustness, continuity and cybersecurity, test resistance to input manipulation, poisoning, leakage and model attacks, and establish recovery, secure update and vulnerability management plans.
Article (28) — Bias and discrimination testing
Before and after operation, high-risk systems shall undergo reasonable testing for unjustified differences in error rates or outcomes between legally protected groups. Material disparities unexplained by legitimate, proportionate purposes require suspension or restriction of consequential use until corrected.
Article (29) — AI impact assessment
Before first high-risk use, deployers shall assess purpose, less intrusive alternatives, affected persons and groups, relevant data and rights, error, discrimination and security risks, human oversight, complaints, performance indicators and shutdown plans. Public bodies shall publish an assessment summary unless security or investigation confidentiality requires withholding a specified part.
Article (30) — Fundamental rights impact assessment
Where public authorities, essential service providers, large employers or financial, health or educational institutions use systems for consequential decisions, assessment must independently analyse potential effects on equality, privacy, expression, fair trials, children's and disability rights, and work, education and health rights according to context.
Article (31) — Conformity assessment before use
High-risk systems shall not enter service before required technical and rights assessments, demonstration of binding-standard compliance and registration where applicable. Regulations shall require independent assessment for the most sensitive uses, including biometrics, law enforcement, justice and critical infrastructure.
Article (32) — Post-deployment monitoring
Providers and deployers shall collect performance, incident, complaint and significant error indicators after deployment and review changes in context, data or audience that increase risk. Material model, purpose, data-source or autonomy changes require reassessment.
Article (33) — Serious incident reporting
Providers or deployers shall notify the sector regulator and Iraqi National Centre for Artificial Intelligence of serious incidents or failures causing death, serious injury, widespread rights violations, critical service disruption, significant leakage or collective discrimination without undue delay and within seventy-two hours of initial awareness, completing technical investigation later.
Article (34) — Change management
Material changes include changes to purpose, user groups, major data sources, model architecture, agent capabilities, autonomy or decision thresholds affecting risk. They require reassessment, documentation and potentially renewed conformity assessment before deployment.
Article (35) — Suppliers and the value chain
Each value-chain participant shall provide downstream parties with technical information necessary for compliance within its responsibility. Primary providers shall not contractually prevent deployers from meeting legal duties or reporting risks. Open-source component developers are not liable for uses they neither marketed nor controlled except within this Law's limits.
Article (36) — Public procurement of high-risk systems
Government high-risk procurement requires auditable safety, rights, security and data and log portability requirements; state testing and auditing rights; supplier exit and avoidance of technology lock-in; and clear data ownership and processing location consistent with data protection and digital sovereignty laws.
Chapter Four — Individual Rights and Algorithmic Accountability
Article (37) — Notice of AI use
People shall receive clear notice when directly interacting with AI where they might reasonably believe they are dealing with a human, and when automation materially assesses applications, eligibility, opportunities or legal status, unless use is inherently obvious or temporary non-disclosure is legally required for a specific investigation.
Article (38) — Right to understand consequential decisions
Anyone substantially affected by an AI-based decision may receive an understandable account of principal outcome factors, relevant data sources, known limitations and human involvement sufficient to understand and challenge it, without requiring unnecessary source code or trade secret disclosure.
Article (39) — Human review
People may request meaningful human review of high-impact decisions made automatically or decisively reliant on AI. Reviewers must have authority to change or revoke decisions, examine objections and necessary information, and not simply reconfirm automated outputs.
Article (40) — Objections and grievances
Deployers shall provide an easy, free channel to object to consequential algorithmic decisions and give reasoned responses within reasonable time. Objection does not bar existing administrative or judicial grievance and appeal routes.
Article (41) — Non-discrimination
Developing or using systems producing legally prohibited direct or indirect discrimination is forbidden. Lack of knowledge of a protected characteristic does not remove liability where proxies foreseeably produce discriminatory outcomes that reasonable measures could detect or mitigate.
Article (42) — Accessibility
Interfaces, notices and objections shall accommodate disability needs. Reliance on voice, images, movement or biometrics shall not create unjustified exclusion. Suitable alternatives shall be available where particular groups cannot use a system.
Article (43) — Child protection
Children's best interests shall govern systems designed for them or likely to be widely used by them. Excessive commercial behavioural or psychological exploitation is prohibited. Educational, care and biometric systems for children require stricter necessity, data minimisation and human oversight.
Article (44) — No covert high-impact experimentation
Public bodies and essential service providers shall not covertly test systems potentially affecting rights, eligibility, prices or essential service access without a legal basis, risk plan and monitoring. Individuals shall not be subjects of high-impact decision experiments without appropriate safeguards.
Article (45) — Public register of government systems
The Iraqi National Centre for Artificial Intelligence shall publish a register of public-sector high-risk systems, identifying the body, purpose, provider, risk category, basis of use, assessment date, human review and objection channel. Specified details may be withheld where publication threatens national security, investigation integrity or cybersecurity, with reasons given as far as possible.
Article (46) — Whistleblower and researcher protection
Good-faith employees, contractors or security researchers shall not face retaliation for reporting serious risks, violations or vulnerabilities to competent authorities under responsible disclosure procedures. Protection excludes unlawful data appropriation or disclosure beyond what reporting requires.
Article (47) — Evidence preservation and auditability
In disputes or incidents, providers and deployers shall retain relevant logs and technical documents long enough for investigation or adjudication, protecting confidentiality. Courts may order necessary material made available to independent experts with safeguards for trade secrets and personal data.
Article (48) — Remedy and compensation
This Law does not affect rights to seek cessation of processing, correction of decisions, removal of unlawful effects or compensation under general liability rules. Courts may consider failure to retain legally required logs when assessing evidential burdens and presumptions.
Chapter Five — General-Purpose Models and Generative AI
Article (49) — General-purpose provider obligations
General-purpose model providers shall document capabilities, limitations and integration requirements, provide downstream developers with compliance information, follow a lawful intellectual property and data-source policy, and publish a meaningful summary of principal training data types and sources without disclosing secrets or personal data.
Article (50) — Identifying models with systemic risk
Implementing regulations shall set flexible criteria based on capabilities, reach, autonomy, agentic ability, potential critical infrastructure, cybersecurity or vital-domain use, safety test results and potential harm. No single computational criterion shall be exclusive.
Article (51) — Assessing models with systemic risk
Providers of models with systemic risk shall periodically evaluate capabilities and risks, conduct appropriate adversarial and red-team testing, manage security vulnerabilities, assess large-scale misuse, document serious incidents and mitigate before and after release.
Article (52) — Reporting systemic risks and incidents
Such providers shall notify the Centre and competent sectoral authority upon discovering capabilities, behaviour or incidents reasonably capable of widespread harm, serious loss of control, major compromise or direct facilitation of extremely dangerous unlawful activity, and submit corrective plans without undue delay.
Article (53) — Generative content transparency
Providers generating text, audio, images or video shall take reasonable technical measures enabling detection of automated generation or modification where practicable, including provenance metadata or machine-readable labels, respecting open standards and interoperability.
Article (54) — Synthetic content imitating real people
Public publishers of synthetic or substantially altered content imitating a real person's speech or actions in potentially deceptive ways must clearly disclose generation or alteration, unless artistic, satirical or educational context makes this obvious to reasonable viewers. Labelling does not remove liability for defamation, fraud, privacy or other rights violations.
Article (55) — Interaction with agents and autonomous systems
Where systems can independently execute external actions, such as money transfers, commands, system modifications or transactions, providers and deployers must define authority limits, appropriate authentication, human approval for sensitive operations, shutdown capability, traceable logs and prevention of unauthorised privilege escalation.
Article (56) — Open source
Open development shall be respected. Publishing a free open-source model or component alone does not impose commercial-provider obligations unless it is marketed, offered as a service or classified as a systemic-risk model under this Law. Data security and anti-circumvention duties remain applicable.
Article (57) — Intellectual property and data sources
This Law creates no new copyright or intellectual property exception. Model providers shall maintain documented policies respecting applicable rights and reasonable mechanisms for rights-holder requests. Trade secrecy shall not conceal proven unlawful data collection or use.
Article (58) — Environmental and computing impact
Regulations shall impose proportionate disclosure of large models' training and operating energy and resource consumption where reliably measurable. Efficient technology shall be encouraged without numerical restrictions unsupported by national data.
Chapter Six — Government Use and Sensitive Sectors
Article (59) — Public-sector use
Public bodies shall not operate high-risk systems before identifying administrative responsibility, completing impact assessment and registration, training users, defining a human alternative and testing data quality and local context. Use must be reviewable by oversight and judicial bodies.
Article (60) — Judiciary and public prosecution
AI may assist legal research, case management and analysis but shall not replace judges in forming convictions, weighing evidence or determining liability or sentence. Material use in evidence analysis or judicial recommendations must be disclosed in the case file so parties can challenge methodology where necessary.
Article (61) — Law enforcement
Criminal analysis, biometric identification and risk assessment systems require written internal authorisation and judicial safeguards according to the intervention. Automated output alone is insufficient for arrest, search or accusation. Facial, voice and fingerprint models shall be accuracy-tested across relevant populations.
Article (62) — Health
Systems affecting diagnosis, treatment or patient prioritisation shall meet medical safety and sectoral requirements in addition to this Law. Clinicians must understand limitations and recommendation sources. Necessary care shall not be denied through unreviewable automated decisions.
Article (63) — Education
Admission, assessment, academic monitoring and dropout prediction systems shall undergo fairness, accuracy and accessibility testing, with human review where admission, achievement or discipline is affected. Unnecessary inference of emotional or health states through continuous student surveillance is prohibited.
Article (64) — Recruitment and employment
Candidate screening, appraisal, promotion or dismissal systems require notice to workers or candidates, discrimination testing, human review and identification of relied-on data. Excessive biometric or behavioural collection merely to improve assessment ‘efficiency’ is prohibited.
Article (65) — Credit, insurance and financial services
Financial and insurance institutions using high-risk credit, pricing or fraud systems must retain understandable outcome reasons, prohibit discriminatory proxies and allow human objections review. The Central Bank of Iraq may impose stricter technical requirements within its powers.
Article (66) — Social protection and essential services
When systems determine eligibility or priority for benefits, support, housing or essential services, automated error shall not trigger immediate interruption without notice, an opportunity to correct and human review. A manual emergency route must exist for system failure.
Article (67) — Critical infrastructure and services
Systems controlling or assisting control of electricity, water, telecommunications, transport, health and critical financial systems shall meet joint AI and cybersecurity law requirements, including safe isolation, pre-update testing, business continuity, manual or alternative operation and supplier management.
Article (68) — Elections and democratic life
Electoral systems for voter registration or verification, polling centre allocation, result counting or eligibility decisions are high-risk. Core decisions must permit audit, recount or independent verification. Public authorities shall not use individual political profiling to restrict lawful participation.
Article (69) — Borders and migration
Biometric verification and border or migration risk assessment require human review and safeguards against discrimination and collective error. Entry, rights or protection applications shall not be refused solely on unverifiable behavioural, emotional or algorithmic prediction.
Article (70) — Media, platforms and content
The Communications and Media Commission shall regulate AI services within its telecommunications, information technology and platform remit consistently with this Law. Transparency or safety requirements shall not become general prior censorship of opinions, news or lawful content.
Article (71) — Security and defence
Security and defence bodies shall establish confidential internal safety, traceability, accountability, human oversight and cybersecurity standards for systems outside public registration. Any use affecting civilians, procedural rights or public services remains subject to constitutional, statutory and special-law safeguards. System secrecy shall not prevent competent judicial oversight.
Chapter Seven — Institutional Governance and Coordination
Article (72) — Higher Committee for AI Governance
The existing Higher Committee for Artificial Intelligence shall continue as a national policy and coordination committee. Within ninety days of entry into force, a Council of Ministers decision shall reorganise its powers to ensure regulatory, rights, economic, security and scientific representation without an unnecessary parallel apparatus.
Article (73) — Higher Committee responsibilities
The Committee shall propose national regulatory policy; approve risk classifications and common standards; coordinate sectoral bodies; propose regulations and instructions; review trends and emerging risks; approve research and capacity priorities; supervise the national register; propose agreements and international cooperation; and publish an annual report on AI governance in Iraq.
Article (74) — Iraqi National Centre for Artificial Intelligence
The Centre shall provide the Committee's technical secretariat, operate the national high-risk register, develop assessment and testing guidance, collect incident reports, manage regulatory sandboxes and coordinate technical testing. It shall not replace legally competent sectoral licensing or sanctioning authorities.
Article (75) — Sector regulators
The Central Bank of Iraq, Communications and Media Commission and health, education, transport, financial, security and other authorities shall exercise existing powers over systems in their sectors, applying this Law as a common minimum. Its higher safeguards prevail over conflicting sectoral instructions.
Article (76) — Communications and Media Commission role
The Commission shall continue regulating AI in telecommunications, information technology, platforms and digital services within its statutory remit, aligning regulations with this Law's classification, rights and procedures. A sectoral regulation alone shall not extend to medical, judicial, banking or employment decisions outside its competence.
Article (77) — Coordination and jurisdictional conflicts
For systems under multiple regulators, the Higher Committee shall designate a coordinating lead while preserving other bodies' powers. Unnecessary duplicate registration or auditing shall be prevented; a single assessment may be recognised if it meets all bodies' legal requirements.
Article (78) — Multi-stakeholder advisory council
The Higher Committee shall form an advisory council of independent university, private sector, professional association, civil society, human rights and cybersecurity experts, persons with disabilities and startup representatives. Its role is advisory; recommendations and members' interests shall be disclosed to avoid conflicts.
Article (79) — Technical standards
Competent bodies shall, where possible, adopt interoperable international or national AI risk management, assessment, audit and security standards adapted to Iraq. Essential rights-affecting obligations shall not be delegated entirely to closed commercial standards whose legal substance the public or courts cannot understand.
Article (80) — Accreditation of assessors and auditors
Regulations shall specify laboratory and independent auditor accreditation for systems requiring third-party assessment, including competence, independence, data confidentiality and conflicts prevention. Accreditation does not prevent regulators' own examinations.
Article (81) — National high-risk systems register
The Centre shall establish a unified electronic register of high-risk systems marketed or used in Iraq, covering providers, representatives, purposes, risk categories, conformity status, serious incidents and corrective measures. Narrow rules shall identify non-public data protecting security and trade secrets.
Article (82) — International cooperation
Competent bodies shall exchange expertise, technical information and dangerous-system alerts under agreements and law, seeking standards alignment that reduces Iraqi companies' compliance costs and enables mutual recognition of assessments without weakening rights protection.
Chapter Eight — Supervision, Compliance and Sanctions
Article (83) — Supervisory powers
Within its remit, a regulator may request documents and logs, conduct or commission tests, summon provider or deployer representatives, examine complaints and incidents, order correction, restrict or temporarily suspend use for serious risk, and withdraw systems where less restrictive measures cannot mitigate risk.
Article (84) — Risk-based auditing
Supervision shall prioritise highest-risk and widest-impact systems. Low-risk systems shall not face burdensome routine audit without reason. Sectoral coordination shall avoid duplication and provide simplified small-business compliance unless use is high-risk.
Article (85) — Urgent corrective orders
For imminent serious threats to life, safety, rights or critical infrastructure, competent bodies may temporarily suspend a specified function, deployment or update for up to thirty days, renewable once by reasoned decision. Addressees shall have grievance rights and urgent judicial review.
Article (86) — Administrative violations
Administrative violations include operating high-risk systems without required registration or assessment, withholding mandatory information, failing to report serious incidents, obstructing audits, breaching transparency or failing to implement final corrective orders. Prohibited practices and deliberately falsified information are serious violations.
Article (87) — Graduated administrative sanctions
Sanctions shall consider severity, duration, repetition, affected numbers, establishment size, cooperation and remediation. They include notice, binding corrective plans, warnings, suspension of functions or services, withdrawal of registration, temporary bans on specified systems and fines within this Law's limits.
Article (88) — Administrative fine limits
Ordinary violations shall attract no more than two hundred and fifty million Iraqi dinars or one per cent of annual Iraqi revenue, whichever is lower. Prohibited practices or deliberate concealment of serious incidents shall attract no more than one billion dinars or two per cent of annual Iraqi revenue, whichever is lower. Regulations may set lower bands reflecting small enterprises without exceeding these limits.
Article (89) — Procedural safeguards
Final sanctions require notice of facts and legal grounds, access to non-confidential evidence and reasonable response time. Decisions must be written, reasoned and proportionate, except urgent temporary orders under Article (85).
Article (90) — Grievance and appeal
Regulatory decisions may be challenged within thirty days before the body designated by law or sectoral regulation, without barring competent court appeal. Courts may suspend enforcement where irreparable harm is likely and suspension does not threaten a weightier public interest.
Article (91) — Civil liability allocation
Liability follows actual control over harm: providers answer for design, information or update defects under their control; deployers for misuse contrary to instructions, changed purposes or neglected oversight. Shared causes may lead to apportioned liability under general rules.
Article (92) — No implied new crimes
Administrative violations shall not be interpreted as criminal offences unless expressly established by law. Existing criminal provisions apply where AI is used to commit an offence; mere possession of a multipurpose tool or model is not punishable.
Article (93) — Data protection and cybersecurity cooperation
Where supervision reveals personal data breaches, cyber incidents or crime, necessary information shall be referred to the data protection authority, National Cybersecurity Centre or investigative body according to law, avoiding unnecessary duplicate provider requests.
Chapter Nine — Innovation, Research and Capacity Building
Article (94) — Regulatory sandboxes
The Centre and sectoral bodies shall establish sandboxes for companies, universities and public bodies to test innovative systems within defined time, geographical and numerical limits, with clear data, security, oversight and stopping conditions. Sandboxes cannot exempt prohibited practices or waive fundamental rights.
Article (95) — Scientific research
The state shall encourage independent research on AI safety, fairness, explainability, security, Arabic and Kurdish languages and the Iraqi context. Public bodies may provide anonymised or synthetic research data under data protection and confidentiality laws. Mere academic research not marketed requires no prior licence under this Law.
Article (96) — Startups and small enterprises
Regulators shall prepare simplified compliance guides, templates and advisory services for startups and small enterprises and reduce unnecessary registration and audit burdens, without relaxing essential requirements for high-risk decisions.
Article (97) — Literacy and skills
Public bodies and institutions deploying high-risk systems shall adopt suitable AI literacy programmes for staff and users, covering capabilities, limitations, bias, security, privacy and output verification, with specialised training by sector and role.
Article (98) — Languages and local context
Systems widely used in public or essential services must be tested in Arabic and, as needed, Kurdish and constitutionally recognised languages and relevant local contexts. Strong foreign-language performance is insufficient evidence of suitability in Iraq.
Article (99) — Competition and portability
Government system and public service contracts shall provide for export of non-confidential data, logs and configurations, open interfaces and standards where practicable, and avoidance of terms unjustifiably preventing supplier changes. Monopoly or technological lock-in practices shall be referred to competition authorities.
Article (100) — Pilot procurement
Public bodies may procure or trial innovative systems on a limited scale with defined success metrics, risks, duration, alternative trial arrangements and exit plans. Pilots shall not automatically become national deployments or long-term contracts without independent assessment of results, risks and costs.
Chapter Ten — Transitional and Final Provisions
Article (101) — Regulations and instructions
The Council of Ministers and sectoral bodies shall issue implementing regulations and instructions within their powers within one hundred and eighty days of publication. Instructions shall not add prohibited practices, sanctions or fundamental-rights interference without a basis in the Law.
Article (102) — Aligning AI services regulation
Within one hundred and twenty days of entry into force, the Communications and Media Commission shall review any existing or draft AI services regulation and align its scope, classification, registration, data and sanction requirements with this framework and other sectoral laws.
Article (103) — Government systems inventory
Within one hundred and eighty days, every public body shall inventory algorithmic and AI systems it uses or procures, classify them provisionally and send high-risk data to the Centre for registration and priority review.
Article (104) — Existing-system compliance transition
Existing high-risk systems shall have twelve months to complete registration, assessment and documentation. Prohibited practices shall stop under shorter timetables not exceeding ninety days, unless temporary continuation is necessary to prevent greater danger under reasoned decision and competent supervision.
Article (105) — General-purpose model transition
Providers of general-purpose models available in Iraq before entry into force shall have twelve months for documentation and transparency compliance; systemic-risk models shall have nine months for required safety assessments.
Article (106) — Relationship with data protection law
Personal data protection rules apply throughout AI lifecycles. Compliance with this Law is not an independent processing basis. Assessments needing sensitive or personal data must identify lawful grounds, minimise data and ensure security under the relevant law.
Article (107) — Relationship with cybersecurity law
Cybersecurity and critical information infrastructure protection requirements apply additionally to covered systems. Incident reporting shall be coordinated to avoid duplication; stricter security standards prevail for critical infrastructure or vital services.
Article (108) — Relationship with sectoral laws
Health, education, labour, banking, telecommunications, consumer protection, intellectual property, competition, criminal procedure and other laws remain effective. Registration or conformity assessment does not authorise activities requiring separate professional or sectoral licences.
Article (109) — Judiciary and rights preserved
No provision shall diminish judicial independence, defence rights, expression, journalism, scientific research, communications confidentiality, privacy, equality or constitutional safeguards. Rights restrictions must be prescribed by law, necessary, proportionate and challengeable.
Article (110) — Periodic review
Every two years, the Higher Committee shall submit to the Council of Ministers and Council of Representatives a public report on implementation, technology, incidents, costs, innovation and regulatory effects on rights and markets, proposing amendments as needed. Periodic review does not replace Parliament's authority to amend prohibitions or fundamental rights.
Article (111) — Repeal and conflict
Expressly conflicting provisions are repealed to the extent of conflict, and existing instructions and regulations amended under Article (102). This does not abolish existing sectoral powers unless irreconcilable with this Law.
Article (112) — Entry into force
This Law takes effect ninety days after publication in the Official Gazette, subject to its specific transitional periods.
Fifth — Statement of Reasons
This Law is enacted to establish a national legal framework keeping pace with rapid AI use in government, the economy and society; protect constitutional rights from automated decisions, discrimination and disproportionate surveillance; regulate high-risk systems, general-purpose models and generative content; define responsibilities of developers, providers, deployers and supervisors; and provide a clear environment for innovation, investment and scientific research.
Sixth — Explanatory Memorandum
1. Why a horizontal law rather than only a service regulation?
The Communications and Media Commission draft is an important sectoral step, but AI affects decisions outside ‘telecommunications services’ in the sectoral sense. The law therefore establishes a parliamentary horizontal foundation while allowing the Commission, Central Bank, ministries and others to specify technical requirements within their powers. This better respects statutory competence and prevents regulatory conflict.
2. Why no new authority?
Iraq already has a higher committee, an adviser's office and a national AI centre, alongside sector regulators. The ongoing national strategy indicates that coordination and capacity, rather than another administrative apparatus, are the present challenge.[2] The bill therefore assigns technical secretariat, registration and sandbox functions to the Centre while leaving licensing and sanctions to competent sectoral bodies.
3. Rights do not require source code disclosure
The explanation right gives people enough information to understand and challenge a decision, not to force companies to publish code or trade secrets. Courts or independent auditors may examine deeper information under confidentiality safeguards where needed. This balances defence rights and innovation protection.
4. Public-sector AI
The bill sets a higher standard for the state because its decisions can affect rights, liberty or essential benefits. It requires assessment, registration and human oversight and prevents AI alone deciding deprivation of liberty, judgments or termination of subsistence benefits. This aligns with international human-centred governance and effective human oversight trends.[8][9][12]
5. General-purpose and generative AI
Regulating only the ‘final application’ is no longer sufficient: one general model may enter thousands of applications. The bill requires basic provider documentation and escalates requirements where capability or reach creates systemic risk. This reflects modern governance frameworks' inclusion of general-purpose models.[7][9][11]
6. Applicability in Iraq
The bill avoids requirements difficult for an emerging market, such as a large new agency, third-party certification for every system or a rigid statutory compute threshold. It strengthens requirements where harm is substantial. This graduated approach matters where national and international data show institutional readiness and supporting AI infrastructure still developing.[2][14]
Seventh — Alignment with Existing Legislation and Regulations
| Area | Alignment rule |
|---|---|
| Personal data protection | AI law compliance is not an independent data-processing basis; lawfulness, rights, transfer and retention remain governed by data protection law. |
| Cybersecurity | Model and system security complements critical information infrastructure and incident-reporting requirements. |
| Communications and Media Commission | Sectoral telecommunications and information technology regulations continue, but scope, licensing and sanctions must align with this horizontal law. |
| Banking and financial services | The Central Bank may impose stricter credit, fraud and financial system standards within its remit. |
| Health, education, employment and justice | Professional and sectoral rules remain effective; this Law adds algorithmic risk, transparency and human oversight duties. |
| Intellectual property | No new copyright or intellectual property exceptions are created; appropriate compliance policies and data-source documentation are required. |
Eighth — Transitional Provisions and Implementation Requirements
Implementation needs regulatory capacity more than new buildings. It begins with a government inventory, national register, common impact assessment method, sectoral team training, an initial high-risk list and alignment of the Commission's regulation. Existing systems receive longer than prohibited practices: continuing an older low-risk system does not warrant the same treatment as a system denying rights or enabling extensive biometric surveillance.
| Period after entry into force | Principal obligation |
|---|---|
| 90 days | Reorganise Higher Committee powers and begin identifying sectoral leads. |
| 120 days | Review Communications and Media Commission AI regulations. |
| 180 days | Issue core regulations and complete government system inventories. |
| 9 months | Bring systemic-risk general-purpose models into compliance. |
| 12 months | Bring other existing high-risk systems and general-purpose models into compliance. |
Ninth — Financial and Implementation Impact
The bill creates no new independent authority, avoiding a complete regulatory apparatus's establishment costs. Costs centre on the register and platform, assessment and audit teams within the Centre and sectoral bodies, training, laboratories, testing tools and accreditation. Reliable public data do not currently support a precise national cost. The law therefore requires a detailed executive financial estimate before central systems launch, reusing existing infrastructure and staff where possible.
The unified framework should reduce regulatory uncertainty costs for companies, limit duplicate registration and reduce government procurement risks involving unauditable systems or long-term technology lock-in.
Tenth — Useful International Comparison
| Framework | Useful concept | Iraqi adaptation |
|---|---|---|
| European Union — AI Act | Risk classification, specified prohibitions, high-risk systems and general-purpose model rules | Use the structure without literally copying European accreditation machinery, market arrangements or institutional thresholds. |
| UNESCO | Dignity, rights, fairness, transparency, accountability and ethical impact assessment | Turn principles into applicable statutory rights and procedures. |
| OECD | Trustworthy, innovative AI, transparency, robustness, accountability and interoperability | Technology-neutral definitions and flexible classification updates. |
| Council of Europe | Link the AI lifecycle with human rights, democracy and rule of law | Strengthen judicial review and procedural rights in government use. |
| NIST AI RMF | Practical, adaptable risk management and continuous testing | Use as a technical reference for bodies and laboratories, not law binding in itself. |
| ISO/IEC 42001, 23894 and 42005 | Management systems and institutional risk and impact assessment | Adopt standards for assessment and accreditation without delegating fundamental rights to closed standards. |
| United Nations — Global Digital Compact | Safe, trustworthy, human-centred governance, human oversight and international cooperation | National alignment supporting capacity and preventing isolation of Iraq's market from global standards. |
The EU AI Act entered its general application phase on 2 August 2026, with transitions for certain high-risk systems under the current consolidated text. European experience is therefore an important practical source, but not a model to copy wholesale.[7] The Council of Europe Framework Convention opened for signature in 2024 as the first legally binding international treaty in this field. Its entry-into-force and ratification status remain separate from drawing on its principles.[10]
Eleventh — Sources and References
- Iraqi Council of Representatives — Constitution of the Republic of Iraq, 2005. Articles 14, 15, 17, 19, 38 and 40 directly concern equality, liberty, privacy, fair procedures, expression and communications. Official source.
- Iraqi National Centre for Artificial Intelligence — National AI strategy preparation stages. Strategy status, participating bodies, readiness assessment of 64 institutions and the 2026 completion indicator. Official source.
- Iraqi Ministry of Planning, 26 April 2026 — Ministry discusses AI strategy. Discussion of measurable objectives, computing infrastructure and a sovereign national language model. Official source.
- Communications and Media Commission, September 2026 — AI services draft regulation released for public consultation. Consultation announcement.
- Communications and Media Commission — Draft Regulation for Artificial Intelligence Services in the Republic of Iraq. The 2026 consultation draft covers scope, risk classification, registration, transparency, governance and sanctions. Published text.
- Iraqi Council of Representatives — Parliamentary Research and Studies Department, 2025. ‘Artificial Intelligence Technologies and Their Role in Developing the Industrial Sector’, recommending a national strategy and legislation regulating use. Study.
- European Union — Regulation (EU) 2024/1689 (Artificial Intelligence Act), consolidated text. Risk framework, prohibitions, high-risk systems, general-purpose models and application stages. EUR-Lex.
- UNESCO — Recommendation on the Ethics of Artificial Intelligence, 2021. Global standard for ethics, rights, transparency and accountability. Source.
- OECD — AI Principles, updated in 2024. Principles of trustworthy AI, innovation, transparency, robustness, accountability and international cooperation. Source.
- Council of Europe — Framework Convention on Artificial Intelligence and Human Rights, Democracy and the Rule of Law, CETS No. 225. Text and explanation; Signature and ratification status.
- NIST — Artificial Intelligence Risk Management Framework (AI RMF 1.0) and Generative AI Profile. A practical lifecycle risk management framework. Source.
- United Nations — Global Digital Compact, 2024. Safe, trustworthy, human-centred governance, human oversight and international cooperation. Adopted text.
- ISO/IEC 42001:2023, ISO/IEC 23894:2023 and ISO/IEC 42005:2025. AI management systems, risk management and system impact assessment. ISO/IEC 42001; ISO/IEC 23894.
- World Bank — Digital Progress and Trends Report 2025: Strengthening AI Foundations, published 2026. Describes readiness, infrastructure and capacity gaps in low- and middle-income countries, including Iraq as a low-readiness example. Source.
- UNDP Regional Bureau for Arab States, 16 September 2026. A regional workshop translating human-rights-based AI governance principles into practical applications in Arab countries. Source.
A proposed legislative document within Ali Zuweid's Political Programme · POL-90