Skip to content
POL-90

This is a proposal for discussion, not an enacted law.

Ali Zuweid's Political Programme

Proposed bill · Digital State, Data, Artificial Intelligence and Cybersecurity

Artificial Intelligence Governance, Algorithmic Accountability and High-Risk Systems Law

A risk-based legal framework governing the AI system lifecycle, limiting unacceptable practices and giving individuals notification, explanation and human review rights, while protecting innovation and building coherent national governance.

Document number
POL-90
Version
1.0
Publication/last update date
7 October 2026
Scope
Republic of Iraq

Executive Summary

Iraq has entered a new regulatory phase for artificial intelligence, but its legal architecture is still developing. The Iraqi National Centre for Artificial Intelligence states that the national strategy extending to 2050 remains under preparation. Its readiness assessment found that only 19 of 64 institutions had clear readiness improvement plans, while the official website places strategy completion at 40%.[2] On 26 April 2026, the Ministry of Planning discussed refining the strategy's objectives, computing infrastructure and the concept of a sovereign national language model.[3]

On 23 September 2026, the Communications and Media Commission released the ‘Draft Regulation for Artificial Intelligence Services in the Republic of Iraq’ for thirty days of public consultation, aiming to regulate services, protect users and data, and promote security, transparency and investment.[4] The draft contains important elements, including risk classification, licensing requirements, transparency, human oversight and data governance. However, AI regulation inherently extends beyond telecommunications and information technology to justice, health, education, employment, banking, social protection and infrastructure. Iraq therefore needs a horizontal law enacted by the legislature defining rights, limits and powers, beneath which sectoral regulations operate.[5]

The bill proposes a risk-based model instead of licensing every AI use identically. It prohibits a narrow set of unacceptable practices, imposes strong duties on high-risk systems, grants direct rights to affected persons, and regulates general-purpose models, generative AI and agents capable of external actions. It draws on recent international experience from the EU AI Act, UNESCO Recommendation, OECD Principles, Council of Europe framework, NIST risk management framework and international AI management standards, adapted to Iraq's state structure and present capacity.[7][8][9][10][11][13]

The central institutional principle is to avoid a new parallel authority when Iraq already has a higher committee, national centre and sectoral bodies. The law fixes their roles: the higher committee coordinates policy; the national centre provides the technical secretariat, register and assessment; sectoral bodies supervise within their sectors; and the Communications and Media Commission remains responsible for services within telecommunications and information technology. This separation prevents a single body from regulating health, justice, banking and employment simply because the tool used is AI.

Second — Iraq's Legislative Gap

Iraqi institutions are already moving towards use and regulation. The national strategy is developing, the national centre exists, the Communications and Media Commission has released a regulatory draft, and a published study by the Parliamentary Research and Studies Department recommended AI legislation alongside strategy, infrastructure and skills.[2][4][6] The issue is not inactivity, but absence of a horizontal law clearly answering questions a sectoral regulation alone cannot settle: which uses are prohibited? When is a system high-risk? Who may object? When is biometric identification permissible? How is liability divided between model developers and deployers? What limits apply to automated decisions in justice, employment or credit?

AI does not always need a ‘service licence’ to affect citizens. It may simply be embedded in human resources software, a hospital programme, bank assessment, traffic camera or judicial assistance system. The bill therefore regulates use by risk, rather than whether a product is sold directly to the public.

Third — Proposed Legislative Policy

Proposed regulatory structure
CategoryRuleExamples
Unacceptable practicesSpecific statutory prohibitionGeneral social scoring, disproportionate mass biometric identification, individual criminal prediction based solely on traits
High-risk systemsImpact assessment, documentation, registration, human oversight, testing and post-deployment monitoringJustice, law enforcement, credit, education, employment, health, public services and critical infrastructure
General-purpose modelsDocumentation, safety and transparency according to capability and scaleLanguage and multimodal models integrable into different applications
Generative content and automated interactionDisclosure and readable labelling where needed to prevent deceptionConversational assistants and synthetic images, audio and video
Limited risksLight or voluntary obligationsGeneral productivity tools that do not make decisions affecting rights

The bill also adopts ‘responsibility according to control’: model developers are responsible for design, documentation and updates under their control; deployers for context, data, use and human oversight; and sectoral authorities for domain-specific additional requirements. This prevents shifting the entire burden to the weakest link in the value chain.

Fourth — Text of the Bill

Fifth — Statement of Reasons

This Law is enacted to establish a national legal framework keeping pace with rapid AI use in government, the economy and society; protect constitutional rights from automated decisions, discrimination and disproportionate surveillance; regulate high-risk systems, general-purpose models and generative content; define responsibilities of developers, providers, deployers and supervisors; and provide a clear environment for innovation, investment and scientific research.

Sixth — Explanatory Memorandum

1. Why a horizontal law rather than only a service regulation?

The Communications and Media Commission draft is an important sectoral step, but AI affects decisions outside ‘telecommunications services’ in the sectoral sense. The law therefore establishes a parliamentary horizontal foundation while allowing the Commission, Central Bank, ministries and others to specify technical requirements within their powers. This better respects statutory competence and prevents regulatory conflict.

2. Why no new authority?

Iraq already has a higher committee, an adviser's office and a national AI centre, alongside sector regulators. The ongoing national strategy indicates that coordination and capacity, rather than another administrative apparatus, are the present challenge.[2] The bill therefore assigns technical secretariat, registration and sandbox functions to the Centre while leaving licensing and sanctions to competent sectoral bodies.

3. Rights do not require source code disclosure

The explanation right gives people enough information to understand and challenge a decision, not to force companies to publish code or trade secrets. Courts or independent auditors may examine deeper information under confidentiality safeguards where needed. This balances defence rights and innovation protection.

4. Public-sector AI

The bill sets a higher standard for the state because its decisions can affect rights, liberty or essential benefits. It requires assessment, registration and human oversight and prevents AI alone deciding deprivation of liberty, judgments or termination of subsistence benefits. This aligns with international human-centred governance and effective human oversight trends.[8][9][12]

5. General-purpose and generative AI

Regulating only the ‘final application’ is no longer sufficient: one general model may enter thousands of applications. The bill requires basic provider documentation and escalates requirements where capability or reach creates systemic risk. This reflects modern governance frameworks' inclusion of general-purpose models.[7][9][11]

6. Applicability in Iraq

The bill avoids requirements difficult for an emerging market, such as a large new agency, third-party certification for every system or a rigid statutory compute threshold. It strengthens requirements where harm is substantial. This graduated approach matters where national and international data show institutional readiness and supporting AI infrastructure still developing.[2][14]

Seventh — Alignment with Existing Legislation and Regulations

Intersecting legislation and policy areas
AreaAlignment rule
Personal data protectionAI law compliance is not an independent data-processing basis; lawfulness, rights, transfer and retention remain governed by data protection law.
CybersecurityModel and system security complements critical information infrastructure and incident-reporting requirements.
Communications and Media CommissionSectoral telecommunications and information technology regulations continue, but scope, licensing and sanctions must align with this horizontal law.
Banking and financial servicesThe Central Bank may impose stricter credit, fraud and financial system standards within its remit.
Health, education, employment and justiceProfessional and sectoral rules remain effective; this Law adds algorithmic risk, transparency and human oversight duties.
Intellectual propertyNo new copyright or intellectual property exceptions are created; appropriate compliance policies and data-source documentation are required.

Eighth — Transitional Provisions and Implementation Requirements

Implementation needs regulatory capacity more than new buildings. It begins with a government inventory, national register, common impact assessment method, sectoral team training, an initial high-risk list and alignment of the Commission's regulation. Existing systems receive longer than prohibited practices: continuing an older low-risk system does not warrant the same treatment as a system denying rights or enabling extensive biometric surveillance.

Implementation stages
Period after entry into forcePrincipal obligation
90 daysReorganise Higher Committee powers and begin identifying sectoral leads.
120 daysReview Communications and Media Commission AI regulations.
180 daysIssue core regulations and complete government system inventories.
9 monthsBring systemic-risk general-purpose models into compliance.
12 monthsBring other existing high-risk systems and general-purpose models into compliance.

Ninth — Financial and Implementation Impact

The bill creates no new independent authority, avoiding a complete regulatory apparatus's establishment costs. Costs centre on the register and platform, assessment and audit teams within the Centre and sectoral bodies, training, laboratories, testing tools and accreditation. Reliable public data do not currently support a precise national cost. The law therefore requires a detailed executive financial estimate before central systems launch, reusing existing infrastructure and staff where possible.

The unified framework should reduce regulatory uncertainty costs for companies, limit duplicate registration and reduce government procurement risks involving unauditable systems or long-term technology lock-in.

Tenth — Useful International Comparison

Comparative instruments and adaptation to Iraq
FrameworkUseful conceptIraqi adaptation
European Union — AI ActRisk classification, specified prohibitions, high-risk systems and general-purpose model rulesUse the structure without literally copying European accreditation machinery, market arrangements or institutional thresholds.
UNESCODignity, rights, fairness, transparency, accountability and ethical impact assessmentTurn principles into applicable statutory rights and procedures.
OECDTrustworthy, innovative AI, transparency, robustness, accountability and interoperabilityTechnology-neutral definitions and flexible classification updates.
Council of EuropeLink the AI lifecycle with human rights, democracy and rule of lawStrengthen judicial review and procedural rights in government use.
NIST AI RMFPractical, adaptable risk management and continuous testingUse as a technical reference for bodies and laboratories, not law binding in itself.
ISO/IEC 42001, 23894 and 42005Management systems and institutional risk and impact assessmentAdopt standards for assessment and accreditation without delegating fundamental rights to closed standards.
United Nations — Global Digital CompactSafe, trustworthy, human-centred governance, human oversight and international cooperationNational alignment supporting capacity and preventing isolation of Iraq's market from global standards.

The EU AI Act entered its general application phase on 2 August 2026, with transitions for certain high-risk systems under the current consolidated text. European experience is therefore an important practical source, but not a model to copy wholesale.[7] The Council of Europe Framework Convention opened for signature in 2024 as the first legally binding international treaty in this field. Its entry-into-force and ratification status remain separate from drawing on its principles.[10]

Eleventh — Sources and References

  1. Iraqi Council of Representatives — Constitution of the Republic of Iraq, 2005. Articles 14, 15, 17, 19, 38 and 40 directly concern equality, liberty, privacy, fair procedures, expression and communications. Official source.
  2. Iraqi National Centre for Artificial Intelligence — National AI strategy preparation stages. Strategy status, participating bodies, readiness assessment of 64 institutions and the 2026 completion indicator. Official source.
  3. Iraqi Ministry of Planning, 26 April 2026 — Ministry discusses AI strategy. Discussion of measurable objectives, computing infrastructure and a sovereign national language model. Official source.
  4. Communications and Media Commission, September 2026 — AI services draft regulation released for public consultation. Consultation announcement.
  5. Communications and Media Commission — Draft Regulation for Artificial Intelligence Services in the Republic of Iraq. The 2026 consultation draft covers scope, risk classification, registration, transparency, governance and sanctions. Published text.
  6. Iraqi Council of Representatives — Parliamentary Research and Studies Department, 2025. ‘Artificial Intelligence Technologies and Their Role in Developing the Industrial Sector’, recommending a national strategy and legislation regulating use. Study.
  7. European Union — Regulation (EU) 2024/1689 (Artificial Intelligence Act), consolidated text. Risk framework, prohibitions, high-risk systems, general-purpose models and application stages. EUR-Lex.
  8. UNESCO — Recommendation on the Ethics of Artificial Intelligence, 2021. Global standard for ethics, rights, transparency and accountability. Source.
  9. OECD — AI Principles, updated in 2024. Principles of trustworthy AI, innovation, transparency, robustness, accountability and international cooperation. Source.
  10. Council of Europe — Framework Convention on Artificial Intelligence and Human Rights, Democracy and the Rule of Law, CETS No. 225. Text and explanation; Signature and ratification status.
  11. NIST — Artificial Intelligence Risk Management Framework (AI RMF 1.0) and Generative AI Profile. A practical lifecycle risk management framework. Source.
  12. United Nations — Global Digital Compact, 2024. Safe, trustworthy, human-centred governance, human oversight and international cooperation. Adopted text.
  13. ISO/IEC 42001:2023, ISO/IEC 23894:2023 and ISO/IEC 42005:2025. AI management systems, risk management and system impact assessment. ISO/IEC 42001; ISO/IEC 23894.
  14. World Bank — Digital Progress and Trends Report 2025: Strengthening AI Foundations, published 2026. Describes readiness, infrastructure and capacity gaps in low- and middle-income countries, including Iraq as a low-readiness example. Source.
  15. UNDP Regional Bureau for Arab States, 16 September 2026. A regional workshop translating human-rights-based AI governance principles into practical applications in Arab countries. Source.

A proposed legislative document within Ali Zuweid's Political Programme · POL-90

What are you looking for?

Search content published on the website.