Yasmin Rashidova
Senior Associate

Yasmin Rashidova is a Senior Associate at the Banking and Finance Department.

She advises international and Kazakhstani clients on cross-border financing, debt transactions and regulatory matters, with particular experience advising international financial institutions and commercial banks on financing and infrastructure projects in Kazakhstan and Central Asia. Her experience includes syndicated and unsecured financings, project and infrastructure finance, and transactions involving IFC, EBRD, ADB, AIIB, MIGA and other international financial institutions. She has also advised on financing transactions in the microfinance, transportation, mining, energy and aviation sectors, as well as capital markets matters.

Sakzhan Kanafin
Associate

Sakzhan Kanafin is an Associate at the Banking and Finance Department.

He advises Kazakhstani and international clients on financing and corporate matters, with a focus on cross-border transactions, debt financing and regulatory issues. His experience includes advising IFC, AIIB, EBRD and other international financial institutions, as well as international investors, on financing and infrastructure projects in Kazakhstan and Central Asia. Sakzhan has also assisted with multiple cross-border financing transactions involving leading Kazakhstani microfinance organisations, including the review of financing documentation and advice on Kazakh law requirements.

Zhan Jumaliyev
Junior Associate

Zhan Jumaliyev is a Junior Associate at the Banking and Finance Department.

He advises international financial institutions, investors and financial sector clients on financing transactions and regulatory matters. His experience includes advising EBRD and international investment funds on cross-border financing transactions involving Kazakhstani financial institutions and microfinance organisations. Zhan assists with the review and negotiation of financing and security documentation, corporate approvals, and provides advice on Kazakhs law requirements and legal opinions.

KAZAKHSTAN – A PIONEER IN ARTIFICIAL INTELLIGENCE REGULATION: BALANCING FINTECH DEVELOPMENT AND CONSUMER RIGHTS PROTECTION

  1. KAZAKHSTAN 2026: AI AS A NEW REGULATORY IMPERATIVE FOR THE BANKING SECTOR

Kazakhstan entered 2026 with unprecedented regulatory and political momentum in the field of digital technologies.

On 6 January 2026, the President of the Republic of Kazakhstan, Kassym-Jomart Tokayev, signed a Decree declaring 2026 the “Year of Digitalisation and Artificial Intelligence”. According to the President of the Republic, artificial intelligence (“AI”) “has created a kind of dividing line between those countries that will manage to enter the future and those that will remain in the past”. It is for this reason that AI and digital technologies have been designated as priority areas for the country’s development.

In June 2026, the President of the Republic of Kazakhstan approved by Decree the Nationwide Strategy “Digital Qazaqstan” through 2029. The strategy marks Kazakhstan’s transition from fragmented automation to an integrated digital-state model in which AI becomes a fundamental tool for managing the economy, the social sphere and public administration.

Kazakhstan has recently taken a number of systemic measures in this area. A dedicated Ministry of AI and Digital Development has been established, the national AI center alem.ai has commenced operations, and AI technologies are being actively deployed in the provision of public services.

Kazakhstan’s banking sector is more advanced in terms of digitalisation than most neighbouring markets. AI has been integrated into banks’ key operational processes, including credit scoring, fraud prevention (anti-fraud), service personalisation, KYC identification and AML monitoring.

  1. LEGISLATIVE BREAKTHROUGH: LAW “ON ARTIFICIAL INTELLIGENCE”

2.1. Background to Adoption and Place in the Legislative Framework

The development of the legal framework governing AI in Kazakhstan began well before the adoption of the AI Law.

Despite the evident maturity of the market and the regulators’ position, no comprehensive legislative act existed until autumn 2025. The AI Law became the first specialised legislative act of the Republic of Kazakhstan dedicated to AI.

2.2. Three-Tier Classification of AI Systems

The conceptual core of the AI Law is a risk-based approach implemented through a three-tier classification of AI systems according to the degree of their impact on the safety of users, society and the state:

Minimal-risk systems – systems whose malfunction or cessation of operation would have a minimal impact on their users;

  • Medium-risk systems – systems whose malfunction or cessation of operation may reduce the efficiency of users’ activities, cause non-pecuniary harm or result in material damage;
  • High-risk systems – systems whose malfunction or cessation of operation may result in a social and/or technological emergency and/or significant adverse consequences for the defence, security, economy or infrastructure of the Republic of Kazakhstan or the vital activities of individuals.

The classification of a particular system into a specific risk category is carried out by its owner and/or holder in accordance with the rules for classification of informatisation objects. High-risk AI systems classified as critical information and communications infrastructure facilities, as well as those intended for the formation of state electronic information resources, are treated as state systems for the purposes of compliance with information security requirements.

In addition to classification by risk level, the AI Law provides for classification of AI systems according to their degree of autonomy: low-autonomy systems (where a decision is made by a human), medium-autonomy systems (autonomous decisions that may be adjusted by a human) and high-autonomy systems (where human adjustment is completely excluded or technically impossible).

2.3. High-Risk AI Systems in the Financial Sector

For the banking and fintech sectors, the key issue is which AI systems automatically fall within the high-risk category. Nevertheless, based on the functional definition of high-risk systems, a number of financial applications of AI are highly likely to fall within this category:

  • Credit scoring systems (creditworthiness assessment algorithms that make or materially determine lending decisions): their malfunction or systematic bias may cause significant material damage to users and destabilise the credit market;
  • AML/financial monitoring: anti-money laundering systems that make autonomous decisions to block accounts or suspend transactions affect citizens’ constitutional rights to dispose of their property and may have significant adverse consequences for the economy;
  • Biometric identification systems (online KYC) used for account opening and customer verification: failures or discriminatory patterns may result in widespread denial of access to financial services;
  • Highly autonomous anti-fraud systems: automatic blocking of transactions as a result of false positives causes direct material damage to bona fide customers.

For high-risk systems, the AI Law establishes the following set of obligations:

  1. the owner and/or holder shall implement a continuous risk management process throughout the entire lifecycle of the AI system, including: identification and analysis of known and foreseeable risks associated with intended use; assessment of risks arising from reasonably foreseeable misuse; implementation of measures to prevent and eliminate identified risks; and regular updating of the risk assessment, at least once a year. Where risks associated with prohibited functionalities are identified, the holder shall immediately take appropriate measures, up to and including suspension or complete termination of the system’s operation.
  2. mandatory audit of AI systems for holders seeking to have their systems included in the “list of trusted high-risk AI systems”.
  3. sector-specific state authorities establish and publish on their websites lists of trusted high-risk AI systems.
  4. owners and holders shall maintain documentation for an AI system “depending on the degree of its impact on the safety, rights, freedoms and legitimate interests of individuals and on public order”, in accordance with the list of documentation approved by the authorised body.
  5. users shall be informed that goods, works and services are produced or provided using AI systems.

2.4. Rights and Obligations of Participants in the Financial Sector

The AI Law regulates relations between owners and holders of AI systems (banks and fintech companies), users (customers), and authorised state bodies. In the financial sector, the following key user rights should be highlighted:

  • the right to review the user agreement of an AI system;
  • the right to protection of personal data and confidential information processed by an AI system;
  • the right to receive explanations concerning the outputs of an AI system affecting the user’s rights and legitimate interests;
  • the right to request information regarding the data on the basis of which the AI system made a decision;
  • the right to refuse to interact with an AI system unless such interaction is mandatory under the legislation of the Republic of Kazakhstan.

In relation to fully automated lending decisions, the latter right raises significant practical issues regarding the possibility of reviewing an automated refusal by referring the loan application to an authorised bank employee for consideration. The AI Law expressly provides that requirements applicable to decisions based solely on automated processing of personal data are established by the legislation on personal data.

As regards owners and holders of AI systems , the AI Law imposes, inter alia, the following obligations:

  • to manage risks associated with AI systems;
  • to take measures to ensure the security and reliability of AI systems, including protection against unauthorised access and failures;
  • to maintain documentation for AI systems;
  • to provide user support in relation to the operation of AI systems;

to provide users with an opportunity to review the user agreement before commencing use of an AI system).

The Agency of the Republic of Kazakhstan for Regulation and Development of the Financial Market (the “ARDFM”) adopted Resolution No. 1Gumar N.A. “The Impact of AI and Voice Technologies on the Efficiency of Banking Operations in Kazakhstan” // Statistics, Accounting and Audit. 2025. Vol. 1“The AI Law in Kazakhstan: What You Need to Know” // Informburo.kz. 24 February 2026. URL: https://informburo. kz/cards/zakon-ob-ii-v-kazaxstane-cto-vazno-znat-vsemkazaxstancam- o-pravilax-i-strafax-v-2026-godu. No. 99. Pp. 167–179. DOI: 10.51579/1563-2415.2025.-4.12. URL: https://sua.aesa.kz/main/ article/view/398.[/mfn]8, effective from 2“AI Law Enters into Force in Kazakhstan” // Gov.kz (Ministry of Digital Development, Innovations and Aerospace Industry). 18 January 2026. URL: https://www.gov.kz/memleket/entities/maidd/ press/news/details/1143060?lang=ru. November 2025, which supplemented these obligations with cybersecurity requirements applicable to financial institutions, including mandatory biometric authentication and two-factor authentication for customer-facing services.

  1. DIGITAL CONSTITUTION OF KAZAKHSTAN

The Digital Code entered into force on 9 January 2026, the first comprehensive law of its kind, one that changes, once and for all, our relationship with gadgets, data and the state.

3.1. The Concept of Fully Automated Decisions in Banking

The Digital Code introduces into Kazakh law the concept of Fully Automated Decisions (“FAD”) decisions made entirely without direct human involvement. This category is borrowed from European regulation.

In the banking context, FAD manifests most clearly in credit-scoring systems. Modern second-tier banks widely apply machine-learning models to assess borrowers’ creditworthiness.

3.2. The Requirement of Human Involvement

The central element of the FAD legal regime in the Digital Code is the citizen’s mandatory right to human review.

First and foremost, the Digital Code establishes an obligation for a financial organisation to inform the borrower of the fact that a decision was made through FAD. The notification shall be given in an understandable form, contain the main factors that influenced the decision, and explain the right to challenge it.

If AI scoring denies a loan, the borrower is entitled to demand that the decision be reviewed with the involvement of an authorised bank employee. The Digital Code establishes essential requirements for such a review: the specialist shall carry out an independent assessment rather than simply confirm the algorithmic conclusion. Thus, “human involvement” within the meaning of the Digital Code is not a formal procedure but a substantive check.

3.3. Algorithmic Transparency and Explainability Requirements

The Digital Code introduces requirements for the explainability of algorithmic systems, which in the financial sector are implemented through several mechanisms. First, banks shall maintain registries of the FAD systems they use and disclose key parameters of their operation to the regulator. Second, when reviewing complaints about automated denials, the bank shall provide the borrower with information about exactly which factors had a decisive influence on the scoring outcome.

3.4. Protecting the Rights of Financial-Services Consumers

In addition to the right to challenge a decision, the Digital Code establishes an expanded set of consumer rights in relations with financial organisations that use FAD systems.

A key protective tool is the prohibition on discriminatory algorithms. The Digital Code directly establishes that FAD systems in the financial sphere may not make decisions based on data directly related to protected characteristics (nationality, sex, religious beliefs, etc.) or serving as proxies for them.

  1. KEY RISKS

4.1. Data Localisation

The central legal barrier to the direct use of foreign cloud platforms and large language models such as ChatGPT (OpenAI) or Claude (Anthropic) is the national data localisation regime.

First, the Personal Data Law establishes the mandatory requirement that personal data shall be stored by the owner and/or operator, as well as by third parties, in a database located within the territory of the Republic of Kazakhstan. The Personal Data Law defines personal data as “data, including biometric data, relating to a specific or identifiable data subject, recorded on electronic, paper and/or other tangible media”. Therefore, by direct operation of law, the localisation requirement extends to all information falling within this definition.

Moreover, this definition is formulated extremely broadly and includes any information allowing identification of the data subject: from surname, first name and individual identification number to information on their property status, transactions and contractual obligations.

Second, for the financial sector, this regime is significantly tightened by Article 69.2 of the Banking Law. Under this provision, banks guarantee the confidentiality of their clients’ transactions, accounts and other information, the disclosure of which could harm the client.

Thus, the direct transmission of raw client data to foreign public clouds via standard APIs becomes legally impossible. The servers of foreign AI providers lie outside the legal framework and jurisdiction of the Republic of Kazakhstan, meaning that any transfer to them of information enabling client identification or revealing the content of their banking transactions qualifies as a direct violation of both personal data legislation and banking secrecy laws.

The practical response to this conflict has been the implementation of so-called Sovereign Data Gateways. These function as an intelligent insulating buffer at the boundary between a financial institution’s internal perimeter and external Large Language Models (the “LLM”) providers. The gateway’s operating principle involves three sequential operations performed in real time before the request is sent outside the Kazakhstani perimeter:

  • First, masking and depersonalisation: the gateway algorithms automatically detect personal data within the request text (IIN, names, payment card numbers, etc.) and replace them with synthetic equivalents that prevent reconstruction of the original identity.
  • Second, tokenisation: all sensitive financial indicators are replaced with unique tokens, with the mapping table required for reverse depersonalisation stored exclusively on the bank’s local server within Kazakhstan.
  • Third, context anonymisation: the original prompt is reformulated so that the external model can solve a mathematical or logical task without being able to identify either the specific data subject or the specific financial institution.

The implementation of such gateways formally ensures compliance, yet simultaneously significantly complicates the IT architecture of financial organisations. Nevertheless, within a stringent regulatory environment, it is precisely such multi-layered isolation that becomes the only legal means of combining the cognitive potential of advanced LLMs with the requirements of Kazakh law.

4.2. Mandatory Labelling of Synthetic Content

The intensive integration of artificial intelligence technologies into Kazakhstan’s banking activities transforms transparency in algorithm-consumer interaction from a mere ethical aspiration into a strict legal imperative. The AI Law stipulates that consumers shall be informed that goods, works and services are produced or provided using artificial intelligence systems.

The problem of unlabeled AI use in financial communications has both formal-legal and substantive dimensions. The deliberate concealment of algorithmic involvement constitutes a violation of the imperative of Article 3“The Year of Digitalisation and AI in Kazakhstan: How the New AI Law and Financial Regulation Are Changing the Game for Banks and Big Tech” // Toppress.kz. 15 February 2026. URL: https:// toppress.kz/article/god-cifrovizacii-i-iskusstvennogo-intellektav- kazahstane-kak-novii-zakon-ob-ii-i-finregulirovanie-menyayutigru- dlya-bankov-i-bigtech.1 of the AI Law, but at a deeper level it undermines the very notion of informed consumer choice.

Non-compliance with the above requirements constitutes an administrative offence and attracts penalties. Upon a repeat violation, the competent authority is empowered to suspend or completely prohibit the operation of the AI system.

  1. CONCLUSION

In conclusion, it can be stated that by 2026 Kazakhstan had developed a distinct model for regulating artificial intelligence in the financial sector, based on the principle of technological neutrality. The National Bank and ARDFM do not seek to impose administrative restrictions on the choice of specific architectural solutions. Instead, the regulators primarily focus on overseeing the outcomes of technology deployment and ensuring non-discriminatory access of market participants to infrastructure.

The central constraining and guiding instrument in this framework is the Digital Code of the Republic of Kazakhstan, together with the specialised AI Law and personal data legislation. These legislative acts establish a robust framework for the protection of consumer rights, comprising three fundamental elements: unconditional data sovereignty, preventing the uncontrolled transfer of bank secrecy outside the national jurisdiction, the prohibition of discriminatory practices, ranging from social scoring to biometric classification, and the right to transparency, implemented through mandatory labelling of synthetic content. Accordingly, the protection of citizens’ interests does not impede technological development, but rather establishes clear legal boundaries within which such development may take place.

Kazakhstan’s approach demonstrates that consistent risk-based regulation, supported by meaningful sanctions for non-compliance, can move the market from a stage of fragmented experimentation towards the deliberate development of reliable and accountable AI systems

SOURCES

  1. “AI Law Enters into Force in Kazakhstan” // Gov.kz (Ministry of Digital Development, Innovations and Aerospace Industry). 18 January 2026. URL: https://www.gov.kz/memleket/entities/maidd/ press/news/details/1143060?lang=ru.
  2. “The Year of Digitalisation and AI in Kazakhstan: How the New AI Law and Financial Regulation Are Changing the Game for Banks and Big Tech” // Toppress.kz. 15 February 2026. URL: https:// toppress.kz/article/god-cifrovizacii-i-iskusstvennogo-intellekta-v-kazahstane-kak-novii-zakon-ob-ii-i-finregulirovanie-menyayut-igru-dlya-bankov-i-bigtech.
  3. Gumar N.A. “The Impact of AI and Voice Technologies on the Efficiency of Banking Operations in Kazakhstan” // Statistics, Accounting and Audit. 2025. Vol. 4. No. 99. Pp. 167–179. DOI: 10.51579/1563-2415.2025.-4.12. URL: https://sua.aesa.kz/main/ article/view/398.
  4. “The AI Law in Kazakhstan: What You Need to Know” // Informburo.kz. 24 February 2026. URL: https://informburo. kz/cards/zakon-ob-ii-v-kazaxstane-cto-vazno-znat-vsem-kazaxstancam-o-pravilax-i-strafax-v-2026-godu.
  5. Law of the Republic of Kazakhstan dated 21 May 2013 No. 94-V “On Personal Data and Their Protection” // Adilet Legal Information System. URL: https://adilet.zan.kz/rus/docs/ Z1300000094/z13094.htm.
  6. Law of the Republic of Kazakhstan dated 17 November 2025 No. 230-VIII “On Artificial Intelligence” // Adilet Legal Information System. URL: https://adilet.zan.kz/rus/docs/Z2500000230.
  7. Law of the Republic of Kazakhstan dated 16 January 2026 No. 258- VIII “On Banks and Banking Activity in the Republic of Kazakhstan” // Adilet Legal Information System. URL: https://adilet.zan.kz/rus/ docs/Z2600000258.
  8. National Payment Corporation of the National Bank of the Republic of Kazakhstan. Report “Artificial Intelligence in Kazakhstan’s Financial Market: Current State, Prospects and Analysis of Regulatory Approaches”. April 2024. URL: https://prg. kz/document/?doc_id=33467322.
  9. “How the ARDFM Will Regulate the Adoption of AI in Banks” // Prodengi.kz. URL: https://prodengi.kz/post/kak-arrfr-budet-regulirovat-vnedrenie-ii-v-bankax.
  10. Code of the Republic of Kazakhstan dated 5 July 2014 No. 235-V “On Administrative Offences” // Adilet Legal Information System. URL: https://adilet.zan.kz/rus/docs/K1400000235 .
  11. Oralbayev Ch. “Key Aspects of the Law of the Republic of Kazakhstan ‘On Artificial Intelligence’ No. 230-VIII” // Paragraf Information System. 18 January 2026. URL: https://prg.kz/ document/?doc_id=33297881.
  12. Resolution of the ARDFM Board dated 20 August 2025 No. 38 (on banking sector policy and AI risks).
  13. Decree of the President of the Republic of Kazakhstan “On Approval of the Nationwide Strategy for Large-Scale Digitalisation and Comprehensive Implementation of Artificial Intelligence Technologies ‘Digital Qazaqstan’ through 2029” // Kazpravda.kz. URL: https://kazpravda.kz/n/ukaz-prezidenta-respubliki-kazahstan-02-jw/.
  14. Decree of the President of the Republic of Kazakhstan dated 6 January 2026 “On Declaring 2026 the Year of Digitalisation and Artificial Intelligence” // Akorda.kz. URL: https://www. akorda.kz/ru/ob-obyavlenii-goda-cifrovizacii-i-iskusstvennogo-intellekta-601222.
  15. Digital Code of the Republic of Kazakhstan dated 9 January 2026 No. 255-VIII // Adilet Legal Information System. URL: https://adilet. zan.kz/rus/docs/K2600000255.
  16. “What Are Depersonalisation, Masking and Tokenisation – Is There a Difference Between These Terms?” // Cisoclub.ru. URL: https://cisoclub.ru/chto-takoe-obezlichivanie-maskirovanie-i-tokenizacija-est-li-raznica-v-jetih-terminah/.
  17. “What Is a Gateway? An Easy-to-Understand Explanation” // Alotceriot.com. URL: https://www.alotceriot. com/what-is-a-gatewayalotcer-gatewaygateway-definitiongateway-definitionindustrial-automationpeer-to-peer-communicatiorouting-functionsdata-forwardingprotocol-gatewayapplication-gatewaysecurity/.
  18. “What Are Security Gateways and What Functions Do They Perform” // Dtu.kz. URL: https://www.dtu.kz/blog-post/chto-takoe-shlyuzy-bezopasnosti-i-kakie-funkczii-oni-vypolnyayut/.
  19. Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation). 27 April 2016. URL: https:// eur-lex.europa.eu/eli/reg/2016/679/oj/eng.