No Central Asian jurisdiction currently has a bespoke “AI-native law firm” regime. The applicable framework is layered: AI law, data protection, information security, civil liability, legal-profession rules, contracts and sector regulation.
| Jurisdiction | Status | Core signal for law firms |
|---|---|---|
| Kazakhstan | AI statute | Transparency, accountability, human autonomy, data protection and AI risk management are express statutory principles. |
| Kyrgyzstan | Digital Code | Risk-based treatment includes heightened requirements and declarations for high-risk AI systems. |
| Uzbekistan | AI amendments | Sole reliance on AI conclusions for legally significant decisions affecting rights and freedoms is prohibited. |
| Tajikistan | General law | Personal-data and information-security duties are currently the primary operational controls. |
| Turkmenistan | Framework announced | AI-specific rules and responsibility allocation were announced for development in January 2026; current controls remain general. |
| AIFC | Special jurisdiction | Legal-services ethics and data-protection rules operate together; official AI/data-protection guidance is available. |
Kazakhstan
The Law “On Artificial Intelligence” of 17 November 2025 establishes principles including transparency and explainability, responsibility and accountability, human welfare and freedom of will, data protection, privacy, safety and security. It requires owners and holders to manage AI risks and informs users when goods, works or services are produced using AI systems. For a law firm, this makes AI governance more than a voluntary best practice.
Kyrgyzstan
The Digital Code of 31 July 2025 provides a broader digital-law architecture and distinguishes AI systems of increased danger. A December 2025 Cabinet measure approved declaration requirements for conformity with mandatory Digital Code requirements. The practical question is whether a legal workflow falls into a high-risk category because of its purpose or impact—not merely because it is used by lawyers.
Uzbekistan
Law No. O‘RQ–1115 of 21 January 2026 amended the informatization framework, defined AI and established principles for its use. The clearest rule for AI-native legal services is that legally significant decisions connected with human rights and freedoms may not rely solely on AI-system conclusions. Illegal AI-enabled personal-data processing can also trigger administrative consequences.
Tajikistan and Turkmenistan
The absence of a dedicated AI statute is not a compliance vacuum. Tajikistan's personal-data legislation covers processing, confidentiality, operators and cross-border transfers. Turkmenistan's law on private-life information regulates collection, processing and protection, while its information-security legislation requires prevention and detection of unauthorised access. Turkmenistan officially announced development of an AI legal framework in January 2026.
AIFC
The AIFC Legal Services Code requires registered legal advisers to protect confidence in the profession and operates alongside the AIFC data-protection framework. The AIFC also issued specific regulatory guidance on data protection and AI. This combination makes the AIFC a useful regional laboratory for professional AI governance.
Primary sources
- Kazakhstan: Law On Artificial Intelligence
- Kazakhstan: Personal Data and Protection
- Kyrgyz Republic: Digital Code
- Kyrgyz Republic: high-risk AI declaration requirements
- Uzbekistan: official summary of Law O‘RQ–1115
- Tajikistan: Personal Data Act
- Turkmenistan: official AI framework announcement
- AIFC Legal Services Code
- AIFC Guidance on Data Protection and AI