AI Governance for Latin America
Attorney, Chief AI Officer and AI Solutions Architect. I govern what I design. I design what I govern.
Chief AI Officer and Senior AI Counsel at HEKA Law · fAIr LAC Fellow at IDB Lab. I design and deliver functional AI systems for legal teams and companies across Latin America, and establish the ISO 42001 and ISO 38507 frameworks that govern them.
Services
Two complementary capabilities rarely offered together in the region.
Strategic governance
- ISO 42001 and ISO 38507 framework implementation
- Corporate AI usage policies
- Compliance with EU AI Act and emerging Latin American regulations
- Audits of AI systems in production
- Executive and board advisory on algorithmic risk
Custom AI solutions
- Corporate legal automation with generative AI
- Agents and workflows for in-house legal teams
- Document analysis and multi-source cross-referencing tools
- Functional prototypes that replace costly manual processes
- Direct implementation with operational deliverables, not just recommendations
I understand artificial intelligence because I use it every day. I govern it because I am an attorney with specific international certifications. That combination is rare in Latin America and it is what my clients hire.
Delivered solutions
Five operational systems built for clients across four distinct sectors. Without names for confidentiality; with results for transparency of method.
Each of these systems is operational today. Each was designed, built, implemented and delivered by the same professional who signs this site.
About
An attorney from Universidad de los Hemisferios with a postgraduate specialization in Procedural Law from Universidad Andina Simón Bolívar. Before turning fully to artificial intelligence, he practiced corporate, administrative and labor law, structured cross-border operations for a foreign engineering firm operating in Ecuador, managed public procurement in the electric utility sector, and led commercial projects and partnerships as general manager of a benefit and collective-interest corporation. That multi-sector path gave him something rare in the AI ecosystem: genuine legal judgment combined with hands-on operational management.
Today he is Chief AI Officer and Senior AI Counsel at HEKA Law, a Fellow of the IDB Lab fAIr LAC program, and runs an independent AI solutions practice. He holds ISO 42001 (AI Management Leader), ISO 38507 (AI Governance Leader) and CAIO-CP certifications, is a CAIDP Graduate, and serves as GCRAI Global Ambassador for Ecuador. He designs and delivers functional AI systems for legal teams and companies, establishes the frameworks that govern them, and trains legal and executive teams at universities and companies across Ecuador and the region. He governs what he designs; he designs what he governs.
Featured Publications
Quién decide cuando decide la máquina
China graded AI agents' decision authority into three levels, in force since 15 July 2026; no Latin American rule yet governs agents.
What you pasted into the chat
What each AI provider does with your conversations depending on the plan: training, retention, legal discoverability and the first rulings.
AI regulation in Ecuador (living page, in Spanish)
The status of every AI rule in Ecuador, checked against official sources. It updates the Ecuador chapter of The Legal 500 written with Andrés Terán.
Artificial affection now has a regulator
China regulates emotional AI companions; the UN links chatbot sycophancy to documented deaths.
The obedience factory
1,333 court decisions contaminated by AI hallucinations; education rewards obedience, not verification.
Cuatro días, ochenta y cinco cuentas
An agent system hit an Asian government in four days: 85 credentials cracked and 2,564 records taken.
Frequently asked questions
Who is Oscar Obando Chaves?
Oscar Obando Chaves is an Ecuadorian attorney and AI lawyer, Chief AI Officer and Senior AI Counsel at HEKA Law (Quito, Ecuador), and an AI Solutions Architect. He is a Fellow of the first cohort of the fAIr LAC · AudacIA program by IDB Lab, Global Ambassador of the Global Council for Responsible AI (GCRAI) for Ecuador, ISO 42001 AI Management Leader, ISO 38507 AI Governance Leader, CAIO-CP and CAIDP Graduate. He publishes freely distributable documents on AI every week at oscarobando.ai/es/publicaciones/. He co-authored, with Andrés Terán, the Ecuador chapter of The Legal 500 Artificial Intelligence Comparative Guide 2026, and is the instructor of the Executive Program on Artificial Intelligence at Universidad Espíritu Santo (UEES).
What services does Oscar Obando offer?
He offers two complementary layers: strategic AI governance (ISO 42001 and ISO 38507 implementation, corporate AI usage policies, EU AI Act compliance and audits of AI systems in production), delivered through HEKA Law; and custom solutions built with generative AI (legal automation, agents, multi-source document analysis) as an independent practice, for legal teams and companies across Latin America.
What is the real state of AI regulation in Ecuador?
Ecuador still has no artificial intelligence law, but it already has binding AI regulation. The Personal Data Protection Superintendency issued Resolution SPDP-SPD-2026-0009-R, the first binding AI-specific rule of general application, in force since 10 March 2026: it applies to controllers and processors that develop, train, implement, deploy or provide AI systems processing personal data of Ecuadorian data subjects, regardless of where the system or the provider is located. On 9 September 2026 the Superintendency signed an amendment to that rule and a rule on biometric data, which will take effect upon publication in the Official Register; as of 17 September 2026 neither had been published. The Organic Law for the Strengthening of Cybersecurity has been in force since 22 May 2026 and requires public entities and critical digital infrastructure operators to report incidents within 72 hours. The EFIA-EC national strategy is public policy and NTE INEN-ISO/IEC 42001 is voluntary. At the National Assembly, the Education Committee recommended on 31 August 2026 that the AI bill filed in 2024 be archived. The plenary archived it on 15 September 2026, with 88 votes. The status of each rule, checked against official sources, is at oscarobando.ai/es/regulacion-ia-ecuador/ (in Spanish), a living page that updates the Ecuador chapter of The Legal 500 Artificial Intelligence Comparative Guide 2026, written by Oscar Obando Chaves and Andrés Terán.
What common mistakes do Latin American companies make when adopting AI?
The three most frequent mistakes are: adopting AI tools without an acceptable use policy, which creates uncontrolled Shadow AI; importing governance frameworks designed for North American or European contexts without adapting them to local institutional reality; and treating AI governance as an IT project when it is a board-level decision.
What is Shadow AI and why is it a risk?
Shadow AI refers to the unauthorized, uncontrolled use of AI tools in organizations. Employees adopt ChatGPT, Copilot, or other tools without IT oversight, creating data leakage risks, compliance violations, and security vulnerabilities. The solution is a clear acceptable use policy and continuous monitoring.
What is ISO 42001 and why should my company implement it?
ISO/IEC 42001 is the international standard for AI management systems. It provides a framework for governance, risk management, and responsible AI implementation. Implementing it demonstrates commitment to responsible AI, reduces compliance risks, and positions your organization as a leader in AI governance.
What is the difference between ISO 42001 and ISO 38507?
ISO 42001 focuses on AI management systems and governance. ISO 38507 focuses on IT governance and board-level oversight. Both are complementary: 42001 is operational, 38507 is strategic. Together they create comprehensive AI governance.
What does a Chief AI Officer (CAIO) do?
A Chief AI Officer is responsible for an organization's AI strategy, governance, and oversight. They define acceptable-use policies, manage risks, coordinate responsible adoption across business units, and report AI maturity and compliance to the board. Oscar Obando serves in this role as Chief AI Officer at HEKA Law, advising organizations across Latin America.
Where does Oscar Obando publish his AI documents?
Oscar Obando publishes freely distributable documents every week at oscarobando.ai/es/publicaciones/, with analysis in Spanish on artificial intelligence and its impact on work, the economy and the law. They can be read on the site and downloaded as PDFs, with no sign-up. He previously published the El Futuro es hoy newsletter on LinkedIn, whose 107 editions remain available there.