The Development of AI Legislation in Morocco
As the European Union implements its AI Act and France adapts its own sectoral regulations, Morocco has opted for a methodical approach to constructing its own legislative framework for artificial intelligence (AI). This framework is being developed gradually, with a focus on creating robust guidelines that will govern the use of AI technologies, which are already being utilized in various sectors such as banking, public administration, and businesses. The Moroccan market for technology has reached a pivotal moment, as AI becomes increasingly integrated into operational processes, especially with initiatives like the "Morocco IA 2030" roadmap set to launch in January 2026. This roadmap is not an isolated effort but is part of a broader strategy that began with the "Morocco Digital" initiative, which was introduced in a royal speech by His Majesty Mohammed VI in 2016. For legal professionals, understanding how to secure corporate assets in this evolving landscape is becoming paramount, as they must navigate the existing legal framework while anticipating future regulations that are still taking shape.
Current Legal Framework and Future Directions
The current legal landscape in Morocco does not provide a specific law dedicated to AI; however, practitioners are not operating in a legal vacuum. Instead, they rely on a combination of existing laws and regulations that indirectly apply to AI technologies. The foundation of this legal structure includes laws that govern electronic data exchange, data protection, and cybersecurity. For instance, Law No. 53-05, enacted in 2007, affirms the legal validity of electronic signatures and documents, providing a basis for contracts negotiated with AI assistance. Additionally, Law No. 07-03, introduced in 2003, criminalizes unauthorized access to automated data processing systems, thus serving as a legal tool against potential intrusions into AI systems. More recently, Law No. 43-20, which came into effect in 2020, has updated the legal framework surrounding electronic transactions and trust services, thereby strengthening the basis for future regulations concerning AI.
Furthermore, there are four key pillars that currently shape the risk matrix for AI practitioners in Morocco: data protection, cybersecurity, contractual liability, and intellectual property. The National Commission for the Protection of Personal Data (CNDP) strictly enforces data protection laws, requiring compliance from any AI systems that process personal data. In terms of cybersecurity, any AI solutions integrated by public administrations or vital operators must adhere to guidelines set forth by the General Directorate for Information System Security (DGSSI). In the absence of a specific liability regime for AI, general contractual laws apply, necessitating careful drafting of contracts to delineate responsibilities and liabilities related to AI deployment. Lastly, while existing intellectual property laws protect human-created works, the status of AI-generated content remains ambiguous; therefore, contracts must clearly specify the rights concerning such outputs.
Looking ahead, Morocco is working on establishing a dedicated legal framework for AI, with the Ministry of Digital Transition and Administration Reform collaborating with various stakeholders to draft a comprehensive legal framework. This framework, referred to as "Digital X.0," aims to enhance data governance and establish a digital identity that ensures interoperability and consent tracking between public and private sectors. As Morocco seeks to solidify its position in the realm of AI governance, it is vital for legal practitioners to remain proactive in understanding and adapting to these developments.
As reported by village-justice.com.