Chapter 02

The Regulatory Map

The same AI workflow can face materially different legal treatment across the region.

Primary-source comparisonCurrent as of 4 August 2026

No Central Asian jurisdiction currently has a bespoke “AI-native law firm” regime. The applicable framework is layered: AI law, data protection, information security, civil liability, legal-profession rules, contracts and sector regulation.

JurisdictionStatusCore signal for law firms
KazakhstanAI statuteTransparency, accountability, human autonomy, data protection and AI risk management are express statutory principles.
KyrgyzstanDigital CodeRisk-based treatment includes heightened requirements and declarations for high-risk AI systems.
UzbekistanAI amendmentsSole reliance on AI conclusions for legally significant decisions affecting rights and freedoms is prohibited.
TajikistanGeneral lawPersonal-data and information-security duties are currently the primary operational controls.
TurkmenistanFramework announcedAI-specific rules and responsibility allocation were announced for development in January 2026; current controls remain general.
AIFCSpecial jurisdictionLegal-services ethics and data-protection rules operate together; official AI/data-protection guidance is available.

Kazakhstan

The Law “On Artificial Intelligence” of 17 November 2025 establishes principles including transparency and explainability, responsibility and accountability, human welfare and freedom of will, data protection, privacy, safety and security. It requires owners and holders to manage AI risks and informs users when goods, works or services are produced using AI systems. For a law firm, this makes AI governance more than a voluntary best practice.

Kyrgyzstan

The Digital Code of 31 July 2025 provides a broader digital-law architecture and distinguishes AI systems of increased danger. A December 2025 Cabinet measure approved declaration requirements for conformity with mandatory Digital Code requirements. The practical question is whether a legal workflow falls into a high-risk category because of its purpose or impact—not merely because it is used by lawyers.

Uzbekistan

Law No. O‘RQ–1115 of 21 January 2026 amended the informatization framework, defined AI and established principles for its use. The clearest rule for AI-native legal services is that legally significant decisions connected with human rights and freedoms may not rely solely on AI-system conclusions. Illegal AI-enabled personal-data processing can also trigger administrative consequences.

Tajikistan and Turkmenistan

The absence of a dedicated AI statute is not a compliance vacuum. Tajikistan's personal-data legislation covers processing, confidentiality, operators and cross-border transfers. Turkmenistan's law on private-life information regulates collection, processing and protection, while its information-security legislation requires prevention and detection of unauthorised access. Turkmenistan officially announced development of an AI legal framework in January 2026.

AIFC

The AIFC Legal Services Code requires registered legal advisers to protect confidence in the profession and operates alongside the AIFC data-protection framework. The AIFC also issued specific regulatory guidance on data protection and AI. This combination makes the AIFC a useful regional laboratory for professional AI governance.