AI Law and Digital Governance in Mexico

Introduction

Mexico does not yet have a comprehensive artificial intelligence law, but a growing regulatory framework governs AI-related activities through data protection, cybersecurity, and digital governance instruments. The Federal Law on the Protection of Personal Data Held by Private Parties (LFPDPPP) of 2010, the General Law of Transparency and Access to Public Information, and emerging digital government policies form the backbone of AI regulation. Mexico has adopted the OECD AI Principles and participates in international efforts toward ethical AI governance.

Data Protection Framework

The LFPDPPP governs the processing of personal data by private entities, including AI systems that use personal data for training or inference. Key principles include consent, purpose limitation, proportionality, and data quality. The National Institute for Transparency, Access to Information and Personal Data Protection (INAI) enforces data protection obligations and may impose fines for non-compliance. Automated decision-making that produces legal effects requires specific disclosure and the right to challenge such decisions.

Digital Governance and Cybersecurity

The Digital Transformation and Technology Strategy of the federal government promotes digital government services, open data, and interoperability standards. The National Cybersecurity Strategy coordinates responses to cyber threats affecting AI systems. The Federal Law on Cybersecurity (recently enacted at the time of writing) establishes baseline security requirements for critical infrastructure, incident reporting obligations, and criminal penalties for cyberattacks.

AI Ethics and Regulation

Mexico has issued non-binding ethical guidelines for AI development and use, emphasizing transparency, accountability, and non-discrimination. The AI Ethics Committee within the Ministry of Economy promotes responsible AI innovation. Sector-specific regulations apply to AI in healthcare (COFEPRIS approvals for AI-based medical devices), finance (CNBV guidelines for algorithmic trading and credit scoring), and criminal justice (prohibition on automated sentencing).

International Cooperation

Mexico participates in the Global Partnership on AI (GPAI), the OECD AI Policy Observatory, and UNESCO’s recommendations on AI ethics. The USMCA (United States-Mexico-Canada Agreement) includes provisions on digital trade and cross-border data flows relevant to AI development. Bilateral cooperation with the United States and the European Union addresses AI governance, research collaboration, and regulatory convergence.

Conclusion

Mexican AI law is evolving from existing data protection and cybersecurity frameworks toward comprehensive regulation. The current patchwork approach provides baseline protections while allowing flexibility for innovation. Future legislative efforts are expected to address algorithmic accountability, AI liability, and sector-specific regulation.