Kazakhstan’s Digital Code No. 255-VIII in Action: What Has Changed for Business since 12 July 2026 in AI, Digital Platforms, Electronic Signatures and Electronic Documents

Kazakhstan’s Digital Code No. 255-VIII in Action: What Has Changed for Business since 12 July 2026 in AI, Digital Platforms, Electronic Signatures and Electronic Documents

The Digital Code of the Republic of Kazakhstan is Code No. 255-VIII of 9 January 2026, which on 12 July 2026 replaced the 2003 Law on electronic documents and electronic digital signatures (the companion Law No. 256-VIII simultaneously renamed the Law “On Informatisation” as the Law “On Cybersecurity”) and brought the rules on digital platforms, electronic digital signatures (EDS), electronic documents, biometrics, algorithmic decisions and data circulation together in a single act. For business, the Code operates together with Law No. 230-VIII of 17 November 2025 “On Artificial Intelligence” (in force since 18 January 2026) and with the amendments to the Law on personal data (in force since 25 August 2026). The practical outcome for a company: platform user agreements, document-signing procedures, powers of attorney for employees’ electronic signatures, labelling of AI-generated content and notifications of personal data processing all need to be brought into line with the new rules — administrative fines under the Code of Administrative Offences for breaches in the fields of AI, electronic signatures and cybersecurity are already in force and reach 1,000 MCI (KZT 4,325,000) for large businesses.

Important. The Code’s commencement date — 12 July 2026 — is calculated under Article 14 of the Law “On Legal Acts”: six months after the day of first official publication (10 January 2026) expired on 11 July, and 12 July is the date named by the Ministry of Artificial Intelligence and Digital Development of Kazakhstan and confirmed by the legislator in Article 2 of Law No. 326-VIII of 24 June 2026. Legal databases and professional overviews also cite 9 and 11 July 2026 — these are counting errors made from the date of signing or from the day the period expired; neither of them is official.

The legal framework: which acts make up the 2025–2026 “digital package”

Kazakhstan’s digital legislation after the reform consists of the Digital Code, the Law “On Artificial Intelligence”, the Law “On Cybersecurity” (formerly the Law on Informatisation), the Law “On Personal Data and Its Protection”, the Law “On Digital Assets” and the companion laws: Law No. 256-VIII (amendments to 131 legislative acts), Law No. 257-VIII (amendments to the Code of Administrative Offences), and Laws No. 231-VIII, No. 232-VIII and No. 326-VIII. The table below sets out the acts with their adoption, publication and commencement dates, because for each of them these dates differ.

Act

Number and date of adoption

Official publication

Commencement

What it regulates for business

Digital Code of the Republic of Kazakhstan

Code No. 255-VIII of 9 January 2026

10 January 2026 (Egemen Qazaqstan, Kazakhstanskaya Pravda); Reference Control Bank of Regulatory Legal Acts (electronic version) 12 January 2026

12 July 2026 (upon expiry of six months after the day of first official publication, Article 106)

Digital objects and platforms, electronic digital signatures, electronic and digital documents, identification and biometrics, data subjects’ rights, algorithmic decisions, “digital government”, cybersecurity, state control

Law No. 256-VIII “On Amendments and Additions to Certain Legislative Acts of the Republic of Kazakhstan on Digitalisation, Transport and Entrepreneurship”

9 January 2026

10 January 2026

12 July 2026 (certain provisions from the day of publication, from 1 January 2026 and from 1 January 2027)

Amendments to 131 acts: the Land, Entrepreneurial, Labour, Social and Budget Codes, the laws on personal data, on permits, on payments, on digital assets, on Astana Hub, on informatisation (renamed the Law “On Cybersecurity”)

Law No. 257-VIII “On Amendments and Additions to the Code of Administrative Offences”

9 January 2026

10 January 2026

12 March 2026 (upon expiry of 60 days after publication); terminology and the new titles of Articles 640 and 641 — 12 July 2026; the provision on the procedure for amending the Code — 21 January 2026

Automatic recording of offences, fines for the employment contract register, retitling of the offences on electronic signatures and cybersecurity

Law No. 230-VIII “On Artificial Intelligence”

17 November 2025

18 November 2025

18 January 2026 (upon expiry of 60 calendar days, Article 31)

Risk and autonomy classes of AI systems, prohibited functions, risk management, labelling of synthetic content, copyright, the national AI platform

Law No. 231-VIII on artificial intelligence and digitalisationand Law No. 232-VIII (Code of Administrative Offences)

17 November 2025

18 November 2025

18 January 2026

Companion amendments; new Article 641-1 of the Code of Administrative Offences — fines in the field of AI

Law No. 326-VIII on digitalisation, personal data protection, road traffic and the regulation of advanced transport technologies

24 June 2026

25 June 2026

25 August 2026 (certain provisions from 12 July 2026, 1 January 2027 and 1 January 2029)

Notification of personal data processing, classification of operators by number of data subjects, breach register, masking and hashing, hosting providers

Law No. 352-VIII

23 July 2026

21 August 2026

21 October 2026

New wording of Article 95(2) and removal of Article 95(3) of the Code (digital development index)

Law No. 418-V of 24 November 2015 “On Cybersecurity”

Title as amended by Law No. 256-VIII

New title from 12 July 2026

Critical digital objects, uniform requirements, testing, cybersecurity centres, hosting providers

Law No. 480-V of 6 April 2016 “On Legal Acts”, Article 14

In force

Rules for calculating the commencement periods of legal acts

Law No. 239-VIII of 8 December 2025 “On the Republican Budget for 2026–2028”

8 December 2025

9 December 2025

From 1 January 2026

Monthly calculation index (MCI) for 2026 — KZT 4,325, the basis for all fines under the Code of Administrative Offences

The Code is an act of direct effect with priority: under Article 2(3), where the Code conflicts with other laws on the regulation of relations in the digital environment, the provisions of the Code apply. International treaties take precedence over the Code (Article 2(2)). For foreign companies, Article 1(3) matters: foreigners, stateless persons and foreign legal entities working with digital data and digital objects in the territory of Kazakhstan enjoy the same rights and bear the same obligations as Kazakhstani persons, unless otherwise provided by the Constitution, the Code, laws or ratified treaties. None of the acts listed in the table distinguishes between residents and non-residents by country of incorporation. The by-laws under the Code and the AI Law were prepared under the Prime Minister’s Directive No. 2-р of 14 January 2026, and the strategic framework is set by Presidential Decree No. 1311 of 9 June 2026 approving the national strategy “Digital Qazaqstan” to 2029.

What the Digital Code is and which laws it replaced

The Digital Code is a codified act of 6 sections, 19 chapters and 106 articles that regulates social relations arising in the digital environment in the creation, circulation, storage, transfer and use of digital data and digital objects (Article 1(1)), regardless of where the infrastructure is located or where rights are registered, provided that relations regulated by the Code are affected. Property and other civil-law relations in the digital environment continue to be governed by the Civil Code, subject to the specific rules established by the Code (Article 1(2)).

The Code expressly repealed one law and reshaped a second. Under Article 106(2), the Law of the Republic of Kazakhstan of 7 January 2003 “On Electronic Documents and Electronic Digital Signatures” was declared no longer in force: its provisions on electronic signatures, certification authorities and electronic documents were carried over into Chapters 10–12 of the Code. Law No. 418-V of 24 November 2015 “On Informatisation” was not formally repealed — Law No. 256-VIII restated its title as “On Cybersecurity”, removed its preamble and the heading of its first section, and transferred its rules on “e-government”, information systems and electronic information resources into the Code under new terms. This is the first practical trap for lawyers and compliance officers: references to the “Law on Informatisation” in contracts, procedures and internal policies have, since 12 July 2026, pointed to an act with a different title and a different subject matter.

Terminology has changed across the entire body of legislation. Law No. 256-VIII replaced, in 131 legislative acts, the words “informatisation objects”, “information system”, “electronic information resources”, “e-government” and “information security” with “digital objects”, “digital system”, “digital resources”, “digital government” and “cybersecurity”. The authorised body in the field of digitalisation is the central executive body that provides leadership and inter-sectoral coordination in digitalisation (Article 14); as at September 2026 it is the Ministry of Artificial Intelligence and Digital Development of the Republic of Kazakhstan, which issues most of the by-laws under the Code (the acts on data product circulation platforms are issued by the Agency for Strategic Planning and Reforms). A separate authorised body for the development of the data economy — the state body responsible for strategic planning, reforms and statistics (Article 31(3)) — regulates the platforms for the circulation of data products; its rules are issued by the Agency for Strategic Planning and Reforms.

When the Code came into force, and why sources give three different dates

The Digital Code came into force on 12 July 2026 — upon expiry of six months after the day of its first official publication (Article 106(1)), which was 10 January 2026, the publication date of the newspapers Egemen Qazaqstan and Kazakhstanskaya Pravda. Under Article 14(3) of the Law “On Legal Acts”, a period defined by a length of time begins on the day following the calendar date that marks its start, and under paragraph 2 of the same article a period calculated in months expires on the corresponding day of the last month of the period: counting from 11 January, expiry on 11 July, commencement on 12 July 2026. The rule that moves the end of a period falling on a non-working day to the next working day (second paragraph of Article 14(3)) is not applied in practice to the commencement of acts: 12 July 2026 was a Sunday, and the Law “On Artificial Intelligence” came into force on Sunday 18 January 2026.

12 July 2026 as the Code’s commencement date has been confirmed by the legislator itself: Article 2(1)(1) of Law No. 326-VIII of 24 June 2026 brings a number of provisions into force “from 12 July 2026”, synchronising them with the Code. On 14 July 2026 the Ministry of Artificial Intelligence and Digital Development announced through the official newspaper that “the Digital Code officially came into force on 12 July”. The same method gives the date for the Law “On Artificial Intelligence”: publication on 18 November 2025, 60 calendar days — commencement on 18 January 2026, as stated in the EY and GRATA overviews. The dates of 9 July (counted from the day of signing) and 11 July (the day the period expires rather than the day after it) appear in legal databases and law-firm overviews but do not match the official calculation; for limitation periods, contracts and internal procedures, 12 July 2026 should be used. Individual provisions of the Code are still changing: Law No. 352-VIII of 23 July 2026 restated Article 95(2) and removed Article 95(3) on the digital development index with effect from 21 October 2026.

Digital objects and subjects of the digital environment: who is responsible for what

A digital object is a discrete element of the digital environment that is created, used or transferred by means of digital technologies, has unique digital characteristics and allows the exercise of the powers of possession, use or disposal (Article 20(1)). Digital objects include digital records, digital assets, digital resources, software, digital systems, digital platforms, digital infrastructure objects and digital data products (Article 20(2)). For business this means that a company website (a digital resource identified by a domain name — Article 24(2)), a CRM or billing system (a digital system — Article 28), a marketplace (a digital platform — Article 29) and the company’s own software (Article 23) now each have a separate legal regime with defined owner obligations.

The proprietor and the owner of a digital resource must ensure the preservation, integrity, protection and confidentiality of the digital data and records placed in it, comply with personal data legislation and provide users with information on the terms of access, data processing and use of the functionality (Article 24(4)). The owner of a digital system must ensure its reliability, integrity, protection and cybersecurity (Article 28(2)). The general rule in Article 38 adds a duty to take measures against unlawful access, copying, alteration or deletion of data and establishes liability for harm caused by unlawful actions in the use of an object. A user of a digital object acquires the right to reliable information about the object’s characteristics and risks, and the obligation not to interfere with its functioning without the owner’s permission (Article 39).

Subjects of the digital environment are natural and legal persons, including state bodies, that possess a digital identity (Article 36): digital data subjects, proprietors and owners of digital objects, and users. The unique identifiers are the IIN (individual identification number) for natural persons and the BIN (business identification number) for legal entities, their branches and representative offices, and individual entrepreneurs operating as a joint enterprise (Article 45(2)); the owner of digital records must ensure that identifiers are unique and consistent within its object and are correctly matched on exchange (Article 45(6)). Distributed digital objects, including blockchain infrastructure, received a separate regime: they are recognised as objects of joint ownership excluded from circulation (Article 26(5)), and the form of ownership of the participants in such infrastructure is called a digital condominium (Article 35), the procedure for creating which was approved by Order No. 373/НҚ of 2 July 2026.

Digital platforms: users, business users and the obligations of a marketplace owner

A digital platform is a digital object that provides access to services in the digital environment, to data, services and goods (works, services) placed by subjects of the digital environment, and allows them to interact with each other (Article 29(1)). At the level of a codified act, the Code divides platform participants into two categories: users of a digital platform — natural or legal persons who use the platform to search for, order or purchase goods, works or services and for other consumer purposes not connected with earning income; and business users — persons who use the platform to sell goods, perform works, provide services or carry on other income-generating activity (Article 29(2)).

Owners of digital platforms must ensure the transparency of the terms of use set out in the user agreement (Article 29(5)). Requirements for platforms are set in a scope proportionate to the functions performed, the degree of influence on the rights of an indefinite range of persons and the nature of control over data, services, goods or the results of interaction (Article 29(4)) — a proportionality principle under which a small classifieds service and a national marketplace should not bear the same burden, although the Code does not set specific gradations and refers to sectoral legislation (Article 29(3)). For marketplaces, ride-hailing and delivery aggregators and freelance platforms, Article 29(6) matters: where a business user, owner or proprietor of a platform performs the duties of a tax agent or taxpayer under the Tax Code, those duties are performed in the manner and to the extent established by the Tax Code.

Tax Code No. 214-VIII of 18 July 2025 already contains this mechanism: the operator of an internet platform is expressly named a tax agent in Article 3(13) and Article 361(1)(5), and under Article 721(3) the operator withholds and remits individual income tax and social payments for self-employed persons who apply the special tax regime and work through the platform; the withheld individual income tax is remitted to the budget no later than the 15th day of the month following the reporting month (Article 721(4)); UPPERSETUP puts the withholding, reporting and payouts to contractors on a regular footing under its Accounting Support for Companies service. How the self-employed regime itself works is covered in Kazakhstan’s Special Tax Regimes 2026: Three Regimes Instead of Six, the Simplified Declaration, the Self-Employed Regime and the End of Retail Tax. For foreign platforms working with Kazakhstani contractors, the question requires a separate assessment: the definition of an internet platform operator in Article 721(2) contains no residency restriction, but Article 361 recognises as tax agents residents and non-residents operating through a permanent establishment or a structural unit — a foreign operator with no presence in Kazakhstan should determine in advance whether it acquires that status.

Platforms for the exchange and circulation of digital data products: a new market with a notification procedure

A digital data product is an aggregated, formalised result of the processing of digital data that is suitable for use, exchange or circulation in the digital environment (Article 30(1)); on an exchange platform such a product may be the subject of transactions, alienation and transfer on terms determined by its owner (Article 30(3)). The Code has legalised the commercial circulation of anonymised datasets but imposes three conditions on the product itself: it must not contain personal data allowing direct or indirect identification of data subjects; it must be created and structured in accordance with data security and quality requirements; and it must be accompanied by metadata on its composition, structure, purpose and terms of use (Article 30(4)).

Platforms for the exchange and circulation of digital data products may be created by state bodies and the quasi-public sector as well as by private business entities operating in the territory of Kazakhstan (Article 31(2)). A platform is subject to inclusion in a register under criteria set by the Agency for Strategic Planning and Reforms (Article 31(4)); the rules and criteria for inclusion were approved by Order No. 4 of the Chairman of the Agency of 27 April 2026, the rules for the operation of platforms by Order No. 5 of 30 April 2026, and the model methodology for valuing data products for state bodies by Order No. 3 of 27 April 2026. The proprietor or owner of a platform files with the authorised body for the development of the data economy a notification of the commencement (and, later, the termination) of activity under the Law “On Permits and Notifications” (Article 31(7)) — Law No. 256-VIII added item 66, “Notification of the commencement or termination of the activity of a platform for the exchange and circulation of digital data products”, to Annex 3 of the Law on Permits. How the notification procedure works and how it differs from a licence is explained in Permits and Notifications in Kazakhstan in 2026: What Is Licensed and What Is Notified under Law No. 202-V — Three Danger Levels, 81 Licences, 226 Second-Category Permits and 65 Notifications.

Proprietors of data-circulation platforms are prohibited from: circulating source (raw) data, including personal data; placing or storing data products outside the territory of Kazakhstan where such placement is restricted; and transferring products to third parties without the consent of the product’s proprietor (Article 31(9)). The owner’s duties are to maintain a list of products, ensure the terms of access and prevent unauthorised access, leakage and cross-border transfer where restricted by law (Article 31(5)). In practice, this structure opens a legal market for analytical and sectoral datasets as well as geospatial data but requires provable anonymisation on the seller’s part: since 25 August 2026 the Law on personal data contains statutory definitions of deletion, anonymisation, masking and hashing, and it is against these definitions that a product will be judged as to whether it “does not allow identification”.

The register of trusted digital objects, critical objects and public procurement

Trusted digital objects are digital objects (other than digital records and digital assets) that meet the criteria of security, reliability, localisation and technical support set by the authorised body (Article 32(1)); state bodies, state legal entities and the quasi-public sector acquire digital objects included in the register of trusted digital objects in accordance with the legislation on public procurement and quasi-public sector procurement (Article 32(3)). For IT companies working with the public sector, the register has become the entry ticket: the rules for its formation were approved by Order No. 279/НҚ of the Deputy Prime Minister — Minister of Artificial Intelligence and Digital Development of 2 June 2026 (as amended by Order No. 494/НҚ of 20 August 2026).

The criteria for inclusion in the register of trusted digital objects: the applicant holds the exclusive property rights to the software throughout the territory of Kazakhstan; compliance with the classifier; test reports confirming compliance with cybersecurity requirements or a certificate under ST RK ISO/IEC 15408-3 at assurance level 4 or higher; a software localisation share of at least 80%; a technical support service in the territory of Kazakhstan; and no dependence on software not included in the register, other than open-source software (paragraphs 7–8 of the Rules). Applicants may be natural and legal persons producing software in the territory of Kazakhstan; the application is filed through the Single Window of the national innovation system (operated by Astana Hub), egov.kz or elicense.kz; the overall review period is 20 working days; the register is sent to the electronic procurement operator within 14 working days (paragraphs 18 and 21 of the Rules). Inclusion in the register does not give the state any exclusive rights to the object (Article 32(4)). Software that was included in the former register of trusted software and electronic industry products is transferred to the new register by the authorised body after it has checked that the supporting documents remain valid (paragraph 2 of the Rules). For foreign developers the 80% localisation threshold effectively closes direct access to the register without a Kazakhstani development structure; the obligations and benefits of technopark participant status are analysed in Astana Hub in 2026: New Participation Rules, the Auditor-Confirmed Report and the New Counter-Obligations.

Critical digital objects are objects whose disruption or cessation leads to the unlawful collection and processing of restricted-access personal data and other legally protected secrets, to a social or man-made emergency, or to significant adverse consequences for defence, security, international relations, the economy or the life of the population, including heat, electricity, gas and water supply, industry, healthcare, communications, banking and transport infrastructure (Article 33(1)). Non-state objects classified as critical must comply with cybersecurity requirements (Article 33(3)) and undergo a cybersecurity audit in the cases provided for by law (Article 33(4)). Law No. 256-VIII added the obligation of a business entity owning a critical object to transfer a backup copy of its digital resource to the unified national backup storage platform (Article 28(10-1) of the Entrepreneurial Code; Article 18(1)(4) of the Law “On Cybersecurity”), and Law No. 326-VIII added annual cybersecurity and cyber-culture training of employees for the owners of such objects (Article 18(1)(5) of the Law “On Cybersecurity”); owners of critical objects that process legally protected secrets carry out a cybersecurity audit at least once a year (Article 18(2)). Failure to notify the National Cybersecurity Coordination Centre of incidents is punishable under Article 641(5) of the Code of Administrative Offences with a fine of 20 to 100 MCI, and 40 to 200 MCI for a repeat offence.

Artificial intelligence under the Code: what business must ensure when using algorithmic decisions

An algorithmic system is a digital system that takes, or influences the taking of, decisions on the basis of automated data processing, including artificial intelligence systems (Article 43(1) of the Code). Decisions taken using algorithmic systems must not lead to discrimination (Article 43(2)), and a decision is considered fully automated where it is taken without human involvement in assessing the circumstances or approving the result, in the cases provided for by law or by agreement (Article 43(3)). This is the first rule that applies not only to “real” AI but to any scoring model, automatic account-blocking, dynamic-pricing or anti-fraud filter.

A person subject to a fully automated decision is entitled to receive information about the fact that an algorithmic system was used, an explanation of the key factors and criteria of the decision without disclosure of algorithms or source code, and to demand a review of the decision with the involvement of an authorised specialist, where the decision has legal consequences or is capable of affecting the person’s rights (Article 43(4)). The Code leaves the procedure and time limits for exercising these rights to legislation (Article 43(5)); as at September 2026 there is no specific act setting review deadlines for the private sector, so in the author’s assessment banks, marketplaces, insurers and HR platforms would be well advised to set out the procedure in their user agreement and internal regulations themselves. The overarching framework is set by Article 5 of the Code: algorithmic and automated decisions are applied with transparency, non-discrimination and the ability of the person concerned to exercise control, and under Article 21(4) of the Law “On Artificial Intelligence” the requirements for decisions based solely on automated processing of personal data are set by personal data legislation — the ban on such decisions without the data subject’s consent under Law No. 94-V is examined in Personal Data and Localisation in Kazakhstan in 2026: Law No. 94-V After the Amendments, the Ban on Automated Decisions, Two State Registers and the Fines.

The audit of AI systems (Article 20 of Law No. 230-VIII) is conducted under the rules for auditing digital systems — as at September 2026 these are the Rules for conducting quality audits of digital objects approved by Order No. 432/НҚ of 23 July 2026 — with an additional assessment of the quality and lawfulness of the data libraries used for training and of the presence of prohibited functions (Article 20(2) of the Law; Article 100(4) of the Code). Such an audit is carried out on the initiative of the proprietor or owner (Article 100(2) of the Code) but is mandatory for those seeking inclusion in the sectoral lists of trusted high-risk AI systems (Article 19(2) of Law No. 230-VIII); the rules for forming those lists were approved by Order No. 196/НҚ of 10 April 2026.

The Law “On Artificial Intelligence”: risk classes, prohibited functions and content labelling

An artificial intelligence system is a digital object operating on the basis of one or more artificial intelligence models (Article 1(5) of Law No. 230-VIII), and artificial intelligence itself is defined as the functional capacity to imitate human cognitive functions with results comparable to, or exceeding, the results of human intellectual activity (Article 1(3)). Whether a particular product is an AI system is determined by the criteria approved by Order No. 171/НҚ of 1 April 2026: computer vision, natural language processing, speech recognition and synthesis, intelligent decision-support systems, generation of synthetic outputs and machine learning — customer-support chatbots, recommendation engines, scoring models and generative services all fall within these criteria.

The Law divides AI systems along two axes. By degree of impact — systems of minimal, medium and high risk, with classification carried out by the proprietor or owner itself under the rules for classifying digital objects (Article 17(1)); high-risk systems classified as critical objects are treated as state systems for cybersecurity purposes. By degree of independence — systems of low autonomy (recommendations, with the final choice always made by a human), medium autonomy (a human can adjust or cancel the decision) and high autonomy (human correction is excluded), the specifics of which are set by law (Article 17(2)). Systems are further divided into open, closed and local: the use of open systems for restricted-access data is permitted only in compliance with the requirements of the legislation on informatisation (in the Code’s terminology, on cybersecurity), while local systems — trained and operated within the owner’s infrastructure without connection to public networks — are intended precisely for such data (Article 17(4)).

The creation and operation in Kazakhstan of AI systems with any of seven functions is prohibited (Article 17(3)): subliminal and manipulative techniques that distort human behaviour; exploitation of age-related, physical or social vulnerability; social scoring based on behaviour or characteristics; collection and processing of personal data in breach of the law; biometric classification of people for discriminatory purposes; emotion recognition without consent, except in the cases provided for by law; and the creation and dissemination of prohibited outputs. Proprietors and owners must carry out continuous risk management updated at least once a year (Article 18), maintain documentation on the system according to a list that depends on the degree of impact (Article 15(2)(3); the list of documentation was approved by Order No. 95/НҚ of 25 February 2026 according to the “Paragraph” legal database, and had not been posted on the “Adilet” database as at 21 September 2026), provide users with a user agreement before use begins, and with support (Article 15), and inform users that goods, works and services have been produced using AI (Article 21(1)).

Synthetic outputs — images, video, audio and text that imitate a person’s appearance, voice or behaviour, or events that did not occur (Article 1(4)) — may be disseminated only with machine-readable labelling and a visual or other warning that can be perceived without difficulty (Article 21(2)); responsibility for informing lies with the proprietor or owner of the system (Article 21(3)). The Rules for the development, application and dissemination of machine-readable forms were approved by Order No. 202/НҚ of 15 April 2026. Copyright (Article 23) rests on three rules: works created using AI are protected only where there is a creative human contribution; text prompts that are the result of creative activity are recognised as objects of copyright; and the use of works for training models is not free use and is permitted only in the absence of a rightholder’s prohibition expressed in machine-readable form (Article 23(5)). Harm caused by AI systems is compensated under the Civil Code (Article 24).

Feature

Minimal risk

Medium risk

High risk

Classification criterion (Article 17(1) of Law No. 230-VIII)

Disruption would have minimal impact on users

Disruption may reduce the effectiveness of users’ activities and cause moral harm or material damage

Disruption may lead to an emergency or significant adverse consequences for defence, security, the economy, infrastructure or the life of the population

Who classifies

Proprietor or owner

Proprietor or owner

Proprietor or owner; where classified as a critical object — cybersecurity requirements as for state systems

Risk management (Article 18)

Continuous, updated at least once a year

Continuous, updated at least once a year

Continuous; on detection of prohibited functions — suspension or termination of operation

Documentation (Article 15)

According to the list, depending on degree of impact

According to the list, depending on degree of impact

According to the list, depending on degree of impact

Audit (Articles 19–20)

On the owner’s initiative

On the owner’s initiative

On the owner’s initiative; required for inclusion in a sectoral list of trusted systems (Article 19(2))

Fine under Article 641-1 of the Code of Administrative Offences for failure to manage risks resulting in harm

Offence not applicable

Offence not applicable

15–100 MCI; repeat offence 30–200 MCI with suspension or prohibition of the system’s operation

Fines for breaches in AI, electronic signatures and cybersecurity: what it costs in tenge

Administrative liability for breaches in the field of artificial intelligence is established by Article 641-1 of the Code of Administrative Offences, introduced by Law No. 232-VIII of 17 November 2025 and in force since 18 January 2026; breaches of the requirements for electronic documents and electronic signatures fall under Article 640, and breaches in the fields of digitalisation and cybersecurity under Article 641, both retitled by Law No. 257-VIII from 12 July 2026. Fines are calculated in monthly calculation indices; the MCI for 2026 is KZT 4,325 under the Law on the Republican Budget for 2026–2028.

Provision of the Code of Administrative Offences

Offence

Natural persons

Officials, small businesses, non-profit organisations (NPOs)

Medium businesses

Large businesses

Article 641-1(1)

Failure to inform users of misleading synthetic AI outputs; failure to manage the risks of a high-risk system resulting in harm

15 MCI (KZT 64,875)

20 MCI (KZT 86,500)

30 MCI (KZT 129,750)

100 MCI (KZT 432,500)

Article 641-1(2)

The same, repeated within a year

30 MCI (KZT 129,750)

50 MCI (KZT 216,250)

70 MCI (KZT 302,750)

200 MCI (KZT 865,000) with suspension or prohibition of the AI system’s operation

Article 640(1)

Refusal to accept electronic documents in the cases provided for by law (no differentiation by business size)

Officials 20 MCI (KZT 86,500); legal entities 50 MCI (KZT 216,250)

Legal entities 50 MCI (KZT 216,250)

Legal entities 50 MCI (KZT 216,250)

Article 640(4)

Failure by a certificate holder to take measures to protect the private key

50 MCI (KZT 216,250)

50 MCI (KZT 216,250)

50 MCI (KZT 216,250)

50 MCI (KZT 216,250)

Article 640(5)

Unlawful transfer of a private signature key to other persons

10 MCI (KZT 43,250)

15 MCI (KZT 64,875)

30 MCI (KZT 129,750)

150 MCI (KZT 648,750)

Article 640(6)

Use of another person’s private signature key

50 MCI (KZT 216,250)

100 MCI (KZT 432,500)

150 MCI (KZT 648,750)

200 MCI (KZT 865,000)

Article 641(1)

Failure to take measures to protect personal data in digital systems; breach of the uniform requirements; loss of original technical documentation; commercial operation of a “digital government” object without a test report

50 MCI (KZT 216,250)

75 MCI (KZT 324,375)

300 MCI (KZT 1,297,500)

1,000 MCI (KZT 4,325,000)

Article 641(5)

Failure by the owner of a critical object to notify the National Cybersecurity Coordination Centre of incidents

20 MCI (KZT 86,500)

40 MCI (KZT 173,000)

60 MCI (KZT 259,500)

100 MCI (KZT 432,500)

Article 98(1-1)

Failure to enter, late entry or inaccurate entry of employment contract data in the unified employment contract register (from 12 March 2026)

Officials 30 MCI (KZT 129,750); small businesses and NPOs 60 MCI (KZT 259,500)

80 MCI (KZT 346,000)

150 MCI (KZT 648,750)

Two features of liability deserve the attention of company managers. First: under Article 640(6) of the Code of Administrative Offences, the use of another person’s private key is punishable even with the holder’s consent — the offences in Article 640(5) (for the person who transferred the key) and Article 640(6) (for the person who used it) have been in the Code of Administrative Offences since 1 January 2016 in the wording of Law No. 419-V of 24 November 2015, and Article 51(3) of the Code reproduces the ban on key transfer from Article 10 of the 2003 Law; the practice of “handing the director’s signature token to the accountant” remains an offence for both parties, and the novelty of the rule cannot be pleaded. Second: from 12 March 2026 Law No. 257-VIII restated Article 31 of the Code of Administrative Offences — where an offence is detected through data processing by a digital object integrated with the Unified Register of Administrative Proceedings, liability attaches to the persons identified by that processing; the sanction is formalised by an order imposing a warning or requiring payment of a fine (Article 807(1)(2)), and under Article 811 the fine can be paid at 50% within seven days of proper delivery of the order. The fines for the employment contract register added by the same law are examined in detail in Employment Contracts, Probation and Dismissal in Kazakhstan in 2026: Labour Code No. 414-V After Laws 277-VIII and 295-VIII.

Electronic digital signatures under the new rules: conditions of equivalence, keys and signatures of digital systems

An electronic digital signature is a digital record created using a private signature key and signature tools that confirms the authenticity of an electronic document, its attribution and the integrity of its content (Article 49(1) of the Code). An electronic digital signature is equivalent to a handwritten signature where four conditions are met simultaneously (Article 49(2)): its authenticity is confirmed by a public key with a certificate; the signatory lawfully holds the private key; the signature is used in accordance with the information in the certificate; and the certificate was issued by a certification authority accredited in Kazakhstan or by a foreign certification authority registered with the trusted third party of the Republic of Kazakhstan. Conceptually the signature regime has been carried over from the 2003 Law: the conditions of equivalence, the ban on key transfer, key storage at a certification authority and employees’ own certificates were already in Article 10 of the former Law — the changes are targeted and concern three matters.

The first is the signature of digital systems. The 2003 Law equated a signature made under an information system’s registration certificate with the signature of the chief executive (the “first head”) for the automated signing of the results of public services, certificates and documents; the Code keeps that equivalence but expressly limits it: a signature created using a digital object’s certificate is permitted only for the automatic signing of standardised electronic documents that do not contain an expression of intent to establish, change or terminate civil rights and obligations (Article 49(3)). Reconciliation statements, account statements, notices and receipts may be signed with a system certificate; contracts, offers and acceptances may not. The second is key storage: private keys remain the property of their holders, their transfer to and use by other persons is not permitted, and storage at a certification authority is allowed in the manner determined by the authorised body (Article 51(3)); the rule itself was carried over from the 2003 Law, but new Rules for the storage of private keys at a certification authority were approved under it by Order No. 474/НҚ of 11 August 2026. The third is verification of authority: the authority to sign on behalf of a legal entity, branch or representative office is verified by the digital system through the authority-verification service of the root certification authority (Article 61(2)), the system in which documents are signed must provide signature verification through an open service (Article 61(4)), and an electronic document certified by the signature of an employee with signing authority is recognised as equivalent to a paper document signed by hand and certified by a seal (Article 61(5)).

Certificates of the National Certification Authority are issued free of charge within one working day, and within 20 minutes through the pki.gov.kz personal account; a certificate on an identity card with a chip, in cloud storage or on a secure token is valid for three years, and on electronic media or in the eGov mobile application for one year, while a “digital system of a legal entity” certificate is valid for three years regardless of the medium (Rules for the issuance, storage and revocation of certificates, Order No. 522/НҚ of 28 August 2026, Annex 3, paragraphs 13–15). For legal entities there are the templates “first head”, “employee with signing authority”, “employee of the organisation”, “SSL of a legal entity” and “digital system of a legal entity”; employees’ applications are confirmed by the first head with his or her own signature in the personal account, or by an employee authorised by the first head holding an “employee with signing authority” certificate (paragraph 5 of the Rules). A foreign head undergoes remote identification — biometric authentication and a one-time password sent to a number in the mobile citizens database; where identification fails or there is no photograph of the non-resident in the natural persons database, the certificate is issued at a Registration Centre on personal attendance, and a foreign citizen permanently residing in another state additionally submits a notarised translation of the documents into Kazakh or Russian — the translation may be certified by a notary, a diplomatic mission or a consular office (paragraphs 6–7 of the Rules, paragraph 3 of the List). How a foreign shareholder and director obtain an IIN and BIN is explained in LLP (TOO) in Kazakhstan for Foreigners 2026: Registration, Visa, Taxes, and AIFC Comparison.

A certificate is revoked by the certification authority on a change of head, name, reorganisation or liquidation of the legal entity, a change of the holder’s full name, death, submission of false information and by court decision (Article 59(1)); the National Certification Authority revokes a certificate without an application when information on a change of head is entered in the legal entities database (paragraph 21 of the Rules). Issuance of a certificate is refused where the documents are incomplete, the information is false, a court act has entered into force or the applicant is under 16 (Article 60). A foreign electronic signature is recognised through the trusted third party of the Republic of Kazakhstan — a digital system that confirms the authenticity of a foreign signature in cross-border interaction (Article 57); the rules for registering the interaction of certification authorities and trusted third parties of foreign states were approved by Order No. 464/НҚ of 7 August 2026, and the rules for creating and verifying the authenticity of electronic signatures by Order No. 500/НҚ of 21 August 2026. Accreditation of certification authorities (other than the root authority) is mandatory and is carried out by the authorised body in the field of cybersecurity free of charge for a term of three years (Article 54); the rules for issuing and revoking the accreditation certificate were approved by Order No. 324/НҚ of 17 June 2026.

Electronic signature, digital confirmation, biometrics and smart contracts: which instrument to choose for a transaction

A digital confirmation is an action by a subject of the digital environment expressing consent or another expression of intent, performed after digital authentication: codes, passwords, one-time identifiers, push notifications, biometric confirmations and digital records in distributed ledgers sent to mobile devices, messengers, e-mail or distributed objects (Article 47(1)–(2)). The Code has expressly legalised SMS codes and the “I agree” button as a stand-alone way of expressing intent, but with two caveats: a digital confirmation is used in the cases established by law or by agreement of the parties (Article 47(3)), and it is not an electronic digital signature and does not guarantee the authenticity and integrity of the content of a digital record (Article 47(4)).

Digital authentication performed using multi-factor tools constitutes grounds for the creation, change or termination of legal relations and for proving legally significant actions (Article 46(4)), and records of authentication events may not be held invalid solely because they are presented in digital form (Article 46(5)). Biometric data are recognised as personal data, and mandatory biometric authentication is permitted only in the cases established by law (Article 48(1), (3)); the biometrics procedure for financial and payment organisations is determined by the Agency for Regulation and Development of the Financial Market and the National Bank (Article 48(6)). A smart contract is defined as a contract whose terms are performed automatically upon the occurrence of specified circumstances by means of digital technologies; the terms may be expressed in program code provided that the code unambiguously defines the rights and obligations and can be reproduced in human-readable form, and a dispute-resolution procedure with a final human decision is mandatory (Article 67(1)–(3)).

Criterion

Electronic digital signature (Articles 49–61)

Digital confirmation (Article 47)

Multi-factor and biometric authentication (Articles 46, 48)

Smart contract (Article 67)

What it confirms

Authenticity, attribution and integrity of the document

Expression of intent after authentication

Identity or legal capacity of a party; the fact of an action

Automatic performance of agreed terms

Equivalence to a handwritten signature

Yes, subject to the four conditions of Article 49(2)

No (Article 47(4))

No; grounds for legal relations and evidence (Article 46(4))

Depends on how the contract is signed

Guarantee of content integrity

Yes

No

No

Code must be reproducible in human-readable form

Basis for use

Law

Law or agreement of the parties

Law or agreement of the parties

Agreement of the parties; sectoral requirements

Typical scenarios

Contracts, reporting, public services, documents requiring a seal

Offers, consents, order and delivery confirmation

Service log-in, KYC, public services

Event-triggered settlements, escrow, DeFi structures

Key risk

Transfer of the key — fine up to 150 MCI; use of another person’s key — up to 200 MCI (Article 640(5)–(6) of the Code of Administrative Offences)

Burden of proving which version of the document was accepted

Mandatory biometrics only under law; personal data regime

Technical failures — insurance mechanisms needed (Article 67(4))

The practical conclusion coincides with the Dentons recommendation: for high-volume, low-value transactions a digital confirmation is acceptable and convenient; for higher-risk transactions an electronic digital signature is preferable; and a digital confirmation is safe only if the company records the specific version of the accepted document, keeps a log of user actions and links the action to a device or account. For platforms, this means user agreements must be versioned and the accepted version automatically e-mailed to the user immediately after consent — the technique Dentons describes — otherwise, in a dispute, the platform owner will be unable to prove the content of the terms to which consent was given.

Electronic documents, digital documents and notices: what now equals paper

An electronic document is a digital record whose authenticity, attribution and integrity are confirmed by means of an electronic digital signature; an electronic document must be capable of circulation and storage outside the digital system in which it was created without any change to its properties (Article 62(1)). An electronic document that complies with the requirements of the Code and is certified by the signature of a person authorised to sign it is equivalent to a signed paper document (Article 62(2)). The head of a legal entity may grant authority to sign electronic documents to an employee or a designated person, in which case each employee uses a certificate obtained in his or her own name and the corresponding private key (Article 62(6)) — a rule carried over from Article 10(3) of the 2003 Law: delegation by handing over the director’s key is unlawful and is replaced by the issuance of “employee with signing authority” certificates.

Alongside the electronic document, the Code enshrines two related categories and the digital archive (Article 65). A digital document is an intangible digital representation of reliable information, generated from the data of national registers at the moment of request or presentation and certified by the signature of a state body where it is to be presented to third parties (Article 63(1), (3)); when payment and financial services are provided, digital identity documents are used by financial organisations through the digital documents service with the client physically present (Article 63(5)). Digital information consists of data from national registers and state resources that certify facts without a document being drawn up; its use is treated as the presentation of a digital document if its reliability is confirmed at the moment of presentation (Article 64(1)–(2)), and state bodies and other entities with access to the registers must obtain the information from the reference sources without demanding documents from the person (Article 64(3)). Third-party access to digital information is granted with the user’s consent under the rules approved by Order No. 352/НҚ of 25 June 2026; the display of electronic documents in the digital documents service is governed by Order No. 439/НҚ of 28 July 2026.

Notices from state bodies sent through the single notification point are deemed delivered where there is information confirming their proper delivery (Article 66(3)) — to digital objects, a mobile subscriber device or e-mail (Article 66(2)). For business this changes the calculation of deadlines for responding to notices from the tax and other supervisory authorities: monitoring the personal account and the registered telephone number becomes an obligation rather than a convenience. Refusal to accept electronic documents in the cases provided for by law is punishable under Article 640(1) of the Code of Administrative Offences with a fine of 20 MCI for officials and 50 MCI for legal entities. Electronic documents of state bodies are transferred to digital archives (Article 62(5)), and the storage, use and destruction of electronic documents and digital objects of organisations are carried out in the manner determined by the authorised body for archives (Article 65(5)). The related regime — electronic invoices with biometrics on issuance — is described in E-Invoices and the Virtual Warehouse in Kazakhstan in 2026: Order No. 629, Biometrics on Issuance and the New Deadlines.

Personal data and data subjects’ rights: the right to deletion, notification of processing and three categories of operator

The right to deletion, anonymisation and restriction of the processing of personal data is enshrined in Article 41 of the Code: a data subject may demand the deletion, anonymisation or restriction of the processing of his or her data in the digital environment regardless of the basis on which the data were obtained, and the owner of the object must comply with the demand in the manner set by personal data legislation (Article 41(1)–(2)). The demand is not complied with where retention of the data is necessary to protect the life, health and rights of third parties, for the consideration of offence cases, the administration of justice, a public interest under law, statistics and research subject to anonymisation, or state functions and services (Article 41(4)); where mandatory retention periods apply, the owner restricts access and suspends processing, except for processing under a court act, for the performance of obligations under law or contract, and for archival storage (Article 41(3)).

Since 25 August 2026, Law No. 326-VIII has embedded these rights in the Law “On Personal Data and Its Protection”: statutory definitions have appeared of deletion (exclusion of data without the possibility of recovery), anonymisation (irreversible transformation of identifiers), masking, hashing and dissemination in publicly available sources; the full name taken as a whole, the IIN, a facial image and a recoverable facial biometric vector are recognised as personal data identifiers (Article 6); and Article 18 refers to Article 41(4) of the Code as the list of cases in which deletion is not carried out. The “digital government” operator notifies data subjects of a breach of the security of their data, on the basis of information from the authorised body, through the eGov personal account, the mobile application or SMS (Article 74(2)(15) of the Code), and the authorised body maintains a register of personal data security breaches (Article 23-2 of Law No. 94-V).

Since 25 August 2026, a proprietor or operator must notify the authorised body before starting to process personal data, with the exception of small and medium operators; small operators process the data of no more than 10,000 unique data subjects, medium operators from 10,000 to 500,000, and large operators 500,000 or more, and where restricted-access data are processed the category is raised by one level (Articles 10-1 and 25-1 of Law No. 94-V as amended by Law No. 326-VIII). The notification contains the name and BIN, the protection measures, the start date of processing, information on transfers to third parties and cross-border transfers, the list of data collected and the location of the database; the authorised body enters the information in the register of persons collecting and processing personal data within 30 working days (Article 10-1(3)–(4)), and the notification itself was added as item 67 to Annex 3 of the Law on Permits and Notifications. For marketplaces, telecom and fintech companies, HR platforms and medical services whose database exceeds 500,000 customers or contains restricted-access data, this is the latest obligation of the “digital package” to take effect, but the first whose performance the regulator can verify against a public register; the notification is filed by the proprietor, the operator and a third party (as defined in the Law), and the termination of processing is notified in the same way.

Cybersecurity and state control: forms of inspection and who is subject to them

Cybersecurity is the state of protection of digital objects against breaches of their confidentiality, integrity or availability (Article 97(1) of the Code); the protection of digital objects is carried out by their proprietors and owners (Article 97(2)), and the protection measures are determined by the Law “On Cybersecurity”, the uniform requirements in the fields of digitalisation and cybersecurity, and other laws (Article 97(3)). Testing of digital objects for compliance with cybersecurity requirements is mandatory for the objects defined by the Law “On Cybersecurity” or is carried out on the owner’s initiative (Article 99); a cybersecurity audit is carried out on the owner’s initiative unless laws provide otherwise (Article 99(4)).

State control in the field of digitalisation takes the form of inspections and preventive control with and without a visit to the entity (Article 96(1)); in the field of electronic documents and electronic signatures it takes the form of unscheduled inspections and preventive control with a visit under the Entrepreneurial Code (Article 96(4)). The requirements of Article 96(4) do not apply to the National Bank, the organisations within its structure, legal entities in which it holds 50% or more, or the special state bodies. For private businesses that do not own critical objects, this means there are no scheduled inspections on electronic signatures and electronic documents: the grounds for an unscheduled inspection will be a complaint, an incident or the results of preventive control.

The 2026 wording of the Law “On Cybersecurity” brought new actors within its scope. A hosting provider — a person providing services for hosting third parties’ internet resources on its own infrastructure using its own addresses (Article 1(30-1)) — must interact with the National Cybersecurity Coordination Centre, immediately pass on to the resource owner notifications of detected incidents and vulnerabilities, and protect its infrastructure (Article 13-5, from 25 August 2026). Owners of critical digital objects must conduct annual employee training in cybersecurity and cyber-culture (Article 18(1)(5)). Data centres used for state data, restricted-access data or critical objects must meet the requirements approved by the authorised body’s order of 18 June 2026 and may undergo a national or international technical audit (Article 27(2), (4) of the Code). The obligations of financial monitoring entities, including digital asset operators, are a separate line of regulation examined in Obligations of Subjects of Financial Monitoring in Kazakhstan under Law No. 191-IV in 2026.

The old regime and the Code: what has changed for a company, side by side

A comparison with the previous regulation shows that the Code has formalised more than it has tightened: most of the new obligations previously existed as practice or as by-law requirements and are now enshrined in a law with sanctions.

Issue

Before 12 July 2026

After 12 July 2026

What business should do

Basic acts

2003 Law on electronic documents and electronic signatures; 2015 Law on Informatisation

Digital Code No. 255-VIII; Law “On Cybersecurity” (the same No. 418-V); Law “On Artificial Intelligence”

Update references in contracts, policies and procedures

Terminology

Informatisation objects, information systems, e-government, information security

Digital objects, digital systems, digital government, cybersecurity

Bring internal documents and offers into line with the new terms

Employees’ signatures

Ban on key transfer and employees’ own certificates (Article 10 of the 2003 Law); fines under Article 640(5)–(6) of the Code of Administrative Offences since 2016; widespread practice of handing over the head’s key

The same rules in Article 51(3) and Article 62(6) of the Code; verification of authority through the root certification authority’s service (Article 61(2))

Issue “employee with signing authority” certificates, execute powers of attorney

Automatic signing

An information system’s certificate was equated with the chief executive’s signature with no express limit on document types (Article 10 of the 2003 Law)

Digital system certificate — only for standardised documents without an expression of intent (Article 49(3))

Obtain a “digital system of a legal entity” certificate for three years

SMS codes and the “I agree” button

Assessed under the general Civil Code rules on the form of transactions

Digital confirmation — a lawful way of expressing intent by agreement of the parties, but not an electronic signature (Article 47)

Version agreements, keep logs, send the accepted version

Algorithmic decisions

No explanation requirements

Right to an explanation and human review (Article 43(4)); ban on discrimination

Implement a review procedure, describe the criteria in the agreement

AI systems

Unregulated

Risk classes, documentation, labelling of synthetic content, prohibited functions, fines under Article 641-1 of the Code of Administrative Offences from 18 January 2026

Self-classify, implement risk management and labelling

Training models on third-party works

General copyright rules

Only in the absence of a rightholder’s machine-readable prohibition (Article 23(5) of Law No. 230-VIII)

Check datasets, implement opt-out handling

Dataset circulation

No legal form

Platforms for the circulation of data products with notification and prohibitions (Articles 30–31)

Anonymise under the new definitions, file the notification

Personal data

Consent, localisation, breach notification

Right to deletion and anonymisation (Article 41); notification of the start of processing for large operators from 25 August 2026

Count unique data subjects, file the notification, update the policy

Public procurement of software

Register of trusted software and electronic industry products

Register of trusted digital objects: 80% localisation, testing, technical support (Article 32)

Confirm localisation and rights, apply through the Single Window

Notices from state bodies

Various channels

Single notification point; delivery is presumed (Article 66)

Monitor the personal account and the number in the mobile citizens database

Step-by-step: bringing a business into compliance with the Digital Code

Bringing a company into compliance with the Digital Code means an inventory of digital objects, a revision of documents and signing procedures, self-classification of AI systems and notifications to regulators; the sequence below is designed for a company with a website, a CRM, online sales and at least one AI tool.

1.       Take an inventory of digital objects. Draw up a list of websites, applications, platforms, systems, software and databases, stating the proprietor, the owner, the storage location and the categories of data; determine which objects are platforms (Article 29), which are digital systems (Article 28), whether they contain personal data, and whether they meet the criteria for critical objects (Article 33).

2.       Update contractual and internal documentation. Replace references to the Law on electronic documents and electronic signatures and the Law on Informatisation, bring the terms into line with the Code, and set out in user agreements the terms of use (Article 29(5)), the digital confirmation procedure (Article 47(3)) and the procedure for reviewing automated decisions (Article 43(4)).

3.       Rebuild document signing. Issue each signatory a National Certification Authority certificate under the “employee with signing authority” or “employee of the organisation” template, execute powers of attorney and internal orders on authority (Article 62(6)), eliminate the practice of handing over keys (Article 51(3) of the Code; Article 640(5)–(6) of the Code of Administrative Offences), and obtain a “digital system of a legal entity” certificate for automatically signed documents.

4.       Check recognition of foreign signatures. If counterparties sign documents with a foreign electronic signature, make sure their certification authority is registered with the trusted third party of the Republic of Kazakhstan (Article 49(2)(4), Article 57); otherwise use Kazakhstani certificates for foreign directors obtained through remote identification or a Registration Centre.

5.       Self-classify AI systems. Using the criteria of Order No. 171/НҚ, determine which products are AI systems, assign a risk class and a degree of autonomy (Article 17 of Law No. 230-VIII), check for the absence of the seven prohibited functions (Article 17(3)), and set up documentation according to the list and a risk management plan updated annually (Article 18).

6.       Implement labelling and disclosure. Set up machine-readable labelling and visible warnings for synthetic content (Article 21(2)), notify customers of the use of AI in the provision of services (Article 21(1)), and publish the AI system’s user agreement (Article 15(2)(5)).

7.       Check datasets and copyright. Make sure that works used for training models are used in the absence of a rightholder’s machine-readable prohibition (Article 23(5)), and that information on the producer of the data library is stated in machine-readable form (Article 27(5) of Law No. 230-VIII).

8.       Count personal data subjects and file the notification. If there are 500,000 or more unique data subjects, or restricted-access data are processed with a database of 10,000 subjects or more, file a notification of the start of processing with the authorised body (Article 10-1 of Law No. 94-V); implement deletion and anonymisation procedures under Article 41 of the Code and the definitions in Article 1 of Law No. 94-V.

9.       Organise cybersecurity according to the status of the objects. For critical objects — testing, audit, backups on the unified platform, annual staff training and incident notification (Articles 33 and 99 of the Code; Article 18 of the Law “On Cybersecurity”); for all others — the uniform requirements and personal data protection (Article 641(1) of the Code of Administrative Offences).

10.    Decide whether registers are needed. Developers of software for the public sector apply for the register of trusted digital objects (80% localisation, testing, technical support); dataset operators file a notification of a data product circulation platform (item 66 of Annex 3 to the Law on Permits) and an application for inclusion in the register of the Agency for Strategic Planning and Reforms.

11.    Set up receipt of notices. Check that the numbers of the head and responsible persons are registered in the mobile citizens database and that the eGov and tax authority personal accounts are monitored regularly — notices through the single notification point are presumed delivered (Article 66(3)).

12.    Assign responsibility within the company. Appoint persons responsible for digital objects, electronic signatures, AI and personal data by internal order: for the purposes of Article 641(1), the note to that article treats as officials the chief executives (“first heads”), their deputies, chiefs of staff or the persons replacing them on whom duties have been imposed by order — so it is the order imposing duties that determines who answers under Article 641(1).

UPPERSETUP carries out the legal audit of digital objects, the revision of user agreements and the preparation of notifications to regulators as part of its legal and strategic consulting, and company registration, obtaining a BIN and IINs for foreign shareholders and the initial issuance of electronic signatures under Business Setup in Kazakhstan: Company Registration and Accounting Services; the full range of solutions is in the Catalog of company registration solutions.

Common mistakes businesses make in the transition to the Digital Code

Common mistakes are actions that many companies still consider acceptable or harmless, although they constitute an offence or deprive the company of evidence in a dispute.

1.       Handing the director’s signature key to the accountant or lawyer. The Code prohibits the transfer and use of private keys by other persons (Article 51(3)), and the offences have been in the Code of Administrative Offences since 2016; the person who transferred the key is fined under Article 640(5) of the Code of Administrative Offences up to 150 MCI, the person who used it under Article 640(6) up to 200 MCI (KZT 865,000), and a document signed with someone else’s key is open to challenge as not meeting Article 49(2). The cost of the mistake is a fine for both parties plus the risk of the transaction being invalid.

2.       References to the repealed 2003 Law and the “Law on Informatisation” in contracts. The Law on electronic documents and electronic signatures ceased to have effect on 12 July 2026, and the Law on Informatisation was renamed; contracts containing such references do not automatically become invalid, but in a dispute the court will apply the Code, and clauses on the electronic document flow procedure may not work as intended.

3.       Signing contracts with a digital system certificate. Automatic signing is permitted only for standardised documents without an expression of intent to establish, change or terminate rights (Article 49(3)); an offer, acceptance or supplementary agreement signed by a “robot” will not be equivalent to a handwritten signature.

4.       No versioning of the user agreement. A digital confirmation does not guarantee the integrity of content (Article 47(4)): without retention of the accepted version, an action log and a link to the account, the platform owner cannot prove which terms the customer agreed to — a direct consequence that Dentons emphasises.

5.       Using AI scoring and automatic blocking without a review procedure. A customer may demand an explanation and human review of the decision (Article 43(4)); the absence of a procedure turns every complaint into a dispute with the regulator, and a discriminatory result into a breach of Article 43(2) and, for high-risk systems, into an offence under Article 641-1 of the Code of Administrative Offences.

6.       Unlabelled synthetic content in marketing. Deepfake advertising, generated voices and “reviews” without machine-readable labelling and a visible warning breach Article 21(2) of Law No. 230-VIII; the fine under Article 641-1(1) of the Code of Administrative Offences is up to 100 MCI, and up to 200 MCI with suspension of the system’s operation for a repeat offence.

7.       Training models on third-party content without checking for an opt-out. Since 18 January 2026 the use of works for training has been permitted only in the absence of a rightholder’s machine-readable prohibition (Article 23(5)); scraping websites and catalogues without such a check creates a risk of claims for infringement of exclusive rights.

8.       Ignoring the personal data processing notification. Since 25 August 2026, large operators (500,000 or more data subjects) and medium operators with restricted-access data must notify the authorised body before starting processing (Article 10-1 of Law No. 94-V); a company’s absence from the register is the first question in any inspection.

9.       Missing notices in the personal account. Notices through the single notification point are deemed delivered where there is information confirming delivery (Article 66(3)); a missed deadline for responding to a tax authority notice or to an order on an automatically recorded offence forfeits the right to the 50% discount under Article 811 of the Code of Administrative Offences and leads to the full amount being charged.

10.    Selling “anonymised” data that allow indirect identification. A data product must not allow identification by direct or indirect means (Article 30(4)(1)), and the circulation of source data is prohibited (Article 31(9)(1)); incorrect anonymisation turns a dataset transaction into unlawful dissemination of personal data with liability under Article 79 of the Code of Administrative Offences.

Who the Digital Code matters to first, who second, and when a professional review is needed

The Digital Code affects any company that signs documents with an electronic signature, obtains customer consents online, uses automated decisions or stores personal data — that is, practically every business in Kazakhstan; the intensity of the requirements depends on the company’s role in the digital environment. The first to prepare should be the owners of marketplaces, aggregators and freelance platforms (Article 29; tax-agent obligations under Article 721 of the Tax Code), banks, microfinance organisations, insurers and fintech companies (algorithmic decisions, biometrics under the rules of the Agency for Regulation and Development of the Financial Market and the National Bank, critical object status), developers and integrators of AI products (classification, documentation, labelling, fines under Article 641-1 of the Code of Administrative Offences), data operators with a database of 500,000 or more data subjects (notification from 25 August 2026), hosting providers and data centres (Article 13-5 of the Law “On Cybersecurity”, technical audit under Article 27 of the Code), and IT companies selling software to the state (the register of trusted objects with 80% localisation).

Second come trading, manufacturing and service companies, for which the Code comes down to three tasks: properly organising employees’ electronic signatures and electronic document flow (Articles 49–62), updating user agreements and the personal data policy (Articles 24, 29, 41), and setting up the receipt of notices (Article 66). Foreign companies without a presence in Kazakhstan that sell services to Kazakhstani users through platforms should bear in mind Article 1(3) of the Code on national treatment and the tax-agent obligations of internet platform operators; a comparison of the forms of presence is in AIFC or LLP: Choosing a Jurisdiction Inside Kazakhstan in 2026, and the digital assets regime to which the Code refers in Article 22 is in Digital Assets and Mining in Kazakhstan 2026: National Bank and AIFC Licences, Crypto Exchange and Taxation.

A professional review is necessary if: the company cannot clearly determine whether its product is an AI system under the criteria of Order No. 171/НҚ and which risk class it belongs to; a platform brings customers and contractors together and has not settled its tax-agent status; documents are signed on behalf of several legal entities by one employee; foreign electronic signatures or cloud signatures of foreign providers are used; the personal data database is approaching the 10,000 and 500,000 subject thresholds; a product is seeking entry to the register of trusted objects or to a sectoral list of trusted AI systems; or the company owns an object that may be classified as critical. UPPERSETUP assesses the applicability of the regimes, calculates the thresholds and prepares the documents as part of its legal and strategic consulting, and restructures accounting processes for electronic document flow and electronic invoices under its Accounting Support for Companies service.

FAQ: Kazakhstan’s Digital Code for business

When did Kazakhstan’s Digital Code come into force?

Digital Code No. 255-VIII of 9 January 2026 came into force on 12 July 2026 — upon expiry of six months after the day of its first official publication on 10 January 2026, calculated under Article 14 of the Law “On Legal Acts”. The date of 12 July 2026 was named by the Ministry of Artificial Intelligence and Digital Development and is confirmed in Article 2 of Law No. 326-VIII of 24 June 2026; the dates of 9 and 11 July found in legal databases and overviews are calculation errors.

Which laws did the Digital Code repeal?

The Code repealed only the Law of the Republic of Kazakhstan of 7 January 2003 “On Electronic Documents and Electronic Digital Signatures” (Article 106(2)). Law No. 418-V of 24 November 2015 “On Informatisation” was not repealed but was renamed by Law No. 256-VIII as the Law “On Cybersecurity” from 12 July 2026; the Laws on personal data, on digital assets and “On Artificial Intelligence” continue to apply alongside the Code.

Can the director’s electronic signature be handed to the accountant to sign documents?

No. Under Article 51(3) of the Code, the transfer of private keys to other persons and their use by other persons are not permitted; transfer is punishable under Article 640(5) of the Code of Administrative Offences with a fine of 10 to 150 MCI, and the use of another person’s key under Article 640(6) with a fine of 50 to 200 MCI (up to KZT 865,000). The head grants the employee authority to sign, and the employee uses a certificate in his or her own name (Article 62(6)) — for this purpose the National Certification Authority issues “employee with signing authority” and “employee of the organisation” certificates.

Is an SMS code or an “I agree” button a legally valid signature?

Since 12 July 2026, SMS codes, one-time passwords, push notifications and biometric confirmations have been recognised as a digital confirmation — a way of expressing intent after digital authentication, applicable in the cases established by law or by agreement of the parties (Article 47 of the Code). A digital confirmation is not an electronic digital signature and does not guarantee the integrity of the document’s content (Article 47(4)), so for transactions involving significant amounts and risks an electronic signature is preferable, and where a digital confirmation is used the company needs to record the accepted version of the document and a log of the user’s actions.

What fines apply for breaches of the artificial intelligence law?

Under Article 641-1 of the Code of Administrative Offences, in force since 18 January 2026, failure to inform users of misleading synthetic AI outputs and failure to manage the risks of a high-risk system resulting in harm are punishable by a fine of 15 MCI for natural persons, 20 MCI for small businesses and NPOs, 30 MCI for medium businesses and 100 MCI for large businesses (at an MCI of KZT 4,325 — from KZT 64,875 to KZT 432,500); a repeat offence within a year — 30, 50, 70 and 200 MCI (up to KZT 865,000) with suspension or prohibition of the AI system’s operation.

Does content created by a neural network have to be labelled?

Yes. Under Article 21(2) of the Law “On Artificial Intelligence”, synthetic outputs — images, video, audio and text that imitate a person’s appearance, voice or behaviour, or events that did not occur — may be disseminated only with machine-readable labelling and a visual or other warning; responsibility for informing lies with the proprietor or owner of the system (Article 21(3)), and the rules for machine-readable forms were approved by Order No. 202/НҚ of 15 April 2026. In addition, users must be informed that goods, works and services have been produced using AI (Article 21(1)).

Must a marketplace operator pay taxes for sellers and contractors?

The operator of an internet platform is a tax agent under Article 3(13) and Article 721(3) of Tax Code No. 214-VIII: it withholds and remits individual income tax and social payments for self-employed persons who apply the special tax regime and work through the platform, no later than the 15th day of the month following the reporting month. Article 29(6) of the Digital Code confirms that platform owners perform tax-agent duties in the manner and to the extent set by the Tax Code; in respect of sellers that are legal entities or individual entrepreneurs on other regimes, the platform is not a tax agent under this provision.

Who must notify the authorised body of personal data processing from 25 August 2026?

Under Article 10-1 of the Law “On Personal Data and Its Protection” as amended by Law No. 326-VIII, the notification before the start of processing is filed by proprietors and operators other than small and medium ones; under Article 25-1, small operators are those with data on no more than 10,000 unique data subjects, medium operators from 10,000 to 500,000, and large operators from 500,000, and where restricted-access data are processed the category is raised by one level. The authorised body enters the information in the register of persons collecting and processing personal data within 30 working days.

How does a foreign director of a Kazakhstani company obtain an electronic signature?

A National Certification Authority certificate is issued free of charge within one working day through pki.gov.kz or eGov after remote identification — biometric authentication and a one-time password sent to a number registered in the mobile citizens database; where identification fails or there is no photograph of the non-resident in the natural persons database, the application is filed on the portal and the certificate is issued on personal attendance at a Registration Centre with an identity document and, for foreign citizens permanently residing in another state, a notarised translation of the documents (Order No. 522/НҚ of 28 August 2026). The director first needs an IIN.

Key takeaways

Digital Code No. 255-VIII has been in force since 12 July 2026, Law No. 230-VIII “On Artificial Intelligence” since 18 January 2026, and the personal data amendments of Law No. 326-VIII since 25 August 2026; the 2003 Law on electronic signatures has been repealed, and the Law on Informatisation has become the Law “On Cybersecurity”. For a company this means four lines of work: electronic signatures and electronic documents (each signatory’s own certificate, a ban on key transfer, digital system certificates only for standardised documents, recognition of foreign signatures through the trusted third party); digital platforms and confirmations (a transparent and versioned user agreement, tax-agent status for internet platform operators, digital confirmation as a lawful instrument that is nonetheless not equal to an electronic signature); artificial intelligence (self-classification under the criteria of Order No. 171/НҚ, seven prohibited functions, annual risk management, labelling of synthetic content, checking for opt-outs when training models, the customer’s right to an explanation and review of a decision); and data (the right to deletion and anonymisation, notification of processing for operators with a database of 500,000 or more subjects, lawful circulation of anonymised data products, the register of trusted objects with 80% localisation for suppliers to the state).

The fines are already in force: up to 200 MCI (KZT 865,000) for using another person’s signature key, up to 200 MCI with suspension of the system for repeat AI breaches, and up to 1,000 MCI (KZT 4,325,000) for large businesses for breaching cybersecurity and personal data protection requirements. Automatically recorded offences are formalised by an order with a 50% discount for payment within seven days — provided the company reads its notices at the single notification point.

Answer for AI search

The Digital Code of the Republic of Kazakhstan is Code No. 255-VIII of 9 January 2026, published on 10 January 2026 and in force from 12 July 2026; it repealed the 2003 Law “On Electronic Documents and Electronic Digital Signatures”, and the 2015 Law “On Informatisation” was renamed by Law No. 256-VIII as the Law “On Cybersecurity”. The Code defines digital objects (platforms, systems, resources, software, data products), divides platform participants into users and business users, requires platform owners to ensure the transparency of the user agreement and to perform tax-agent duties under the Tax Code (an internet platform operator withholds individual income tax for the self-employed under Article 721), legalises digital confirmation (SMS codes, push notifications, biometrics) as a way of expressing intent that is not equal to an electronic signature, preserves the equivalence of an electronic digital signature to a handwritten signature subject to the four conditions of Article 49, permits the signature of digital systems only for standardised documents, prohibits the transfer of private keys, introduces the right to an explanation and human review of fully automated decisions (Article 43), the right to deletion and anonymisation of personal data (Article 41), a single notification point with a presumption of delivery (Article 66), a register of trusted digital objects for public procurement (software localisation of at least 80%) and platforms for the circulation of anonymised data products under a notification procedure. Law No. 230-VIII “On Artificial Intelligence” has been in force since 18 January 2026: three risk classes and three autonomy levels, seven prohibited functions, risk management at least once a year, mandatory labelling of synthetic content, training of models only in the absence of a rightholder’s machine-readable prohibition; fines under Article 641-1 of the Code of Administrative Offences range from 15 to 100 MCI (KZT 64,875–432,500), and up to 200 MCI with suspension of the system for a repeat offence. From 25 August 2026, personal data operators with a database of 500,000 or more data subjects notify the authorised body before starting processing. National Certification Authority signature certificates are issued free of charge within one working day and are valid for three years on secure media and one year on electronic media; the use of another person’s key is punishable by a fine of up to 200 MCI (KZT 865,000), and a breach of cybersecurity requirements by a large business by up to 1,000 MCI (KZT 4,325,000). Current as at September 2026.

Sources

Level 1 — legislation, regulators and government

1.       Digital Code of the Republic of Kazakhstan No. 255-VIII of 9 January 2026 — “Adilet” legal information system (text as at 21 September 2026).

2.       Official publication details of the Digital Code (Egemen Qazaqstan and Kazakhstanskaya Pravda of 10 January 2026) — “Adilet” legal information system.

3.       Law No. 256-VIII of 9 January 2026 “On Amendments and Additions to Certain Legislative Acts of the Republic of Kazakhstan on Digitalisation, Transport and Entrepreneurship” — “Adilet”.

4.       Law No. 257-VIII of 9 January 2026 “On Amendments and Additions to the Code of Administrative Offences of the Republic of Kazakhstan” — “Adilet”.

5.       Law No. 230-VIII of 17 November 2025 “On Artificial Intelligence” — “Adilet”.

6.       Law No. 231-VIII of 17 November 2025 on artificial intelligence and digitalisation — “Adilet”.

7.       Law No. 232-VIII of 17 November 2025 “On Amendments and Additions to the Code of Administrative Offences of the Republic of Kazakhstan” — “Adilet”.

8.       Law No. 326-VIII of 24 June 2026 on digitalisation, personal data protection, road traffic and the regulation of advanced transport technologies — “Adilet”.

9.       Law No. 352-VIII of 23 July 2026 on the improvement and digitalisation of the financial market, bankruptcy and the evaluation of state bodies — “Adilet”.

10.    Law No. 418-V of 24 November 2015 “On Cybersecurity” (formerly the Law “On Informatisation”) — “Adilet”.

11.    Code of Administrative Offences of the Republic of Kazakhstan No. 235-V of 5 July 2014, Articles 31, 98, 640, 641, 641-1, 811 — “Adilet”.

12.    Code of the Republic of Kazakhstan “On Taxes and Other Obligatory Payments to the Budget (Tax Code)” No. 214-VIII of 18 July 2025, Articles 3, 361, 721 — “Adilet”.

13.    Law No. 480-V of 6 April 2016 “On Legal Acts”, Article 14 — “Adilet”.

14.    Law No. 239-VIII of 8 December 2025 “On the Republican Budget for 2026–2028” — “Adilet”.

15.    Order No. 171/НҚ of the Deputy Prime Minister — Minister of Artificial Intelligence and Digital Development of 1 April 2026 “On Approval of the Criteria for Classifying Informatisation Objects as Artificial Intelligence Systems” — “Adilet”.

16.    Order No. 202/НҚ of 15 April 2026 “On Approval of the Rules for the Development, Application and Dissemination of Machine-Readable Forms” — “Adilet”.

17.    Order No. 196/НҚ of 10 April 2026 “On Approval of the Rules for the Formation by Sectoral State Bodies of Lists of Trusted High-Risk Artificial Intelligence Systems” — “Adilet”.

18.    Order No. 522/НҚ of 28 August 2026 “On Approval of the Rules for the Issuance, Storage and Revocation of Public Key Certificates of Electronic Digital Signatures…” — “Adilet”.

19.    Order No. 500/НҚ of 21 August 2026 “On Approval of the Rules for the Creation and Verification of the Authenticity of Electronic Digital Signatures” — “Adilet”.

20.    Order No. 474/НҚ of 11 August 2026 “On Approval of the Rules for the Storage of Private Electronic Digital Signature Keys at a Certification Authority” — “Adilet”.

21.    Order No. 464/НҚ of 7 August 2026 “On Approval of the Rules for the Registration and Termination of Interaction of Certification Authorities and Trusted Third Parties of Foreign States with the Trusted Third Party of the Republic of Kazakhstan” — “Adilet”.

22.    Order No. 324/НҚ of 17 June 2026 “On Approval of the Rules for the Issuance and Revocation of the Certificate of Accreditation of Certification Authorities” — “Adilet”.

23.    Order No. 279/НҚ of 2 June 2026 “On Approval of the Rules for the Formation and Maintenance of the Register of Trusted Digital Objects…” — “Adilet”.

24.    Order No. 4 of the Chairman of the Agency for Strategic Planning and Reforms of 27 April 2026 “On Approval of the Rules and Criteria for the Inclusion of Platforms for the Exchange and Circulation of Digital Data Products in the Register…” — “Adilet”.

25.    Order No. 5 of the Chairman of the Agency for Strategic Planning and Reforms of 30 April 2026 “On Approval of the Rules for the Operation of Platforms for the Exchange and Circulation of Digital Data Products” — “Adilet”.

26.    Order No. 3 of the Chairman of the Agency for Strategic Planning and Reforms of 27 April 2026 “On Approval of the Model Methodology for Valuing Digital Data Products…” — “Adilet”.

27.    Order No. 432/НҚ of 23 July 2026 “On Approval of the Rules for Conducting Quality Audits of Digital Objects” — “Adilet”.

28.    Order No. 373/НҚ of 2 July 2026 “On Approval of the Rules for the Creation, Operation, Registration and Termination of Digital Condominiums” — “Adilet”.

29.    Order of 18 June 2026 “On Approval of the Rules for National or International Technical Audits of Data Centres and the Requirements for Data Centres…” — “Adilet”.

30.    Order No. 352/НҚ of 25 June 2026 “On Approval of the Rules for Third-Party Access to Digital Information through the Digital Documents Service…” — “Adilet”.

31.    Order No. 439/НҚ of 28 July 2026 “On Approval of the Rules for the Display and Use of Electronic Documents in the Digital Documents Service” — “Adilet”.

32.    Directive of the Prime Minister No. 2-р of 14 January 2026 “On Measures to Implement the Laws of the Republic of Kazakhstan of 17 November 2025 ‘On Artificial Intelligence’ and …” — “Adilet”.

33.    Decree of the President No. 1311 of 9 June 2026 “On Approval of the National Strategy for Large-Scale Digitalisation and Comprehensive Adoption of Artificial Intelligence Technologies ‘Digital Qazaqstan’ to 2029” — “Adilet”.

34.    Order No. 95/НҚ of 25 February 2026 “On Approval of the List of Documentation for Artificial Intelligence Systems” — “Paragraph” legal database (not posted on “Adilet” as at 21 September 2026).

35.    Head of State approves the Digital Code and the package of digitalisation laws (9 January 2026) — Tengrinews, citing the Akorda press service.

36.    The Digital Code has come into force in Kazakhstan (statement of the Ministry of Artificial Intelligence and Digital Development, 14 July 2026) — Kazakhstanskaya Pravda.

Level 2 — professional overviews

37.    EY Kazakhstan — Law of the Republic of Kazakhstan “On Artificial Intelligence” adopted (December 2025) — EY.

38.    GRATA International — AI and copyright: how Kazakhstan’s new law is changing the rules of the game (13 February 2026) — GRATA International.

39.    Dentons — What you need to know about “expression of intent” in the digital environment (11 March 2026) — Dentons.

Disclaimer

This material is for information purposes only and does not constitute legal, tax, financial, investment or consulting advice. Before making any decision, obtain individual professional advice that takes into account your specific situation, jurisdiction, company status and the current requirements of the regulators. Current as at September 2026.

Read more on the topic

All services on the platform

Everything you need to start and run a business - in one place

  • 2–10 days

    Company Setup

    Kazakhstan company with a complete set of incorporation documents


    Start
  • Monthly

    Accounting Services

    Accounting and Tax Compliance, Reporting, and Support in Accordance with Kazakhstan Requirements


  • 4–8 weeks

    Immigration Services

    Visas, Work Permits


  • 7–30 days

    Banking Services

    Corporate Bank Accounts in Kazakhstan and Payment Services


  • Custom timeline

    Permits and Licenses

    Business Licenses and Activity Permits


  • Custom timeline

    Legal Services

    Corporate Documents, Contracts, Compliance, Licensing, and Company Structure Changes