Mexico is the second-largest economy in Latin America and one of the most active markets for AI deployment in the region. It has no enacted federal AI statute. That absence does not mean a compliance vacuum, but nor does it mean the ground is stable. Between December 2024 and July 2025 Mexico dissolved and rebuilt the institutions that an AI operator would have dealt with: the data protection authority, the competition authority and the telecommunications regulator were all extinguished and their functions moved inside the federal executive, and the private-sector data protection statute was replaced. This guide sets out what verifiably exists now, and is explicit about what could not be read at source.

Key takeaways

  • Mexico has no enacted federal AI statute. The Orden Jurídico Nacional index of federal laws maintained by the Secretaría de Gobernación lists 302 federal laws and none is an AI law. The nearest federal instrument is a voluntary declaration, the Principios de Chapultepec, issued on 29 January 2026 by SECIHTI and the Agencia de Transformación Digital y Telecomunicaciones.
  • Private-sector data protection is now supervised inside the federal executive. The Secretaría Anticorrupción y Buen Gobierno states on its own site that the protection of personal data is now one of its attributions. INAI was provided for extinction by the constitutional reform published on 20 December 2024.
  • The governing statute is the Ley Federal de Protección de Datos Personales en Posesión de los Particulares expedited by decree published in the Diario Oficial de la Federación on 20 March 2025. It replaced the 2010 law of the same name, so article numbers and penalty figures drawn from the older statute no longer hold.
  • The competition and telecommunications regulators were replaced in July 2025. Competition enforcement sits with the Comisión Nacional Antimonopolio and telecommunications regulation with the Comisión Reguladora de Telecomunicaciones inside the Agencia de Transformación Digital y Telecomunicaciones.
  • Mexican companies supplying AI products or services into EU markets face EU AI Act extraterritorial reach under Regulation (EU) 2024/1689. Mexico has no bilateral agreement with the EU that incorporates AI Act obligations, so this exposure must be assessed separately from domestic Mexican compliance.

The 2024 constitutional reform and what it moved

The starting point for any assessment of Mexican AI compliance in 2026 is not a data protection statute but a constitutional amendment. On 20 December 2024 the Diario Oficial de la Federación published the Decreto por el que se reforman, adicionan y derogan diversas disposiciones de la Constitución Política de los Estados Unidos Mexicanos, en materia de simplificación orgánica. It amended articles 3, 6, 26, 27, 28, 41, 76, 78, 89, 105, 113, 116, 123 and 134.

Two of its transitional articles dissolved the regulators that a foreign AI operator would previously have dealt with. The eleventh transitional article provides that the Comisión Federal de Competencia Económica and the Instituto Federal de Telecomunicaciones are extinguished on the entry into force of the decree. The fifth transitional article provides that a set of public bodies, including the Instituto Nacional de Transparencia, Acceso a la Información y Protección de Datos Personales, are to be understood as extinguished once the implementing legislation referred to in the second transitional article enters into force.

For personal data held by private parties, the reform states that the law referred to in article 90 of the Constitution, which is the statute governing the organisation of the federal public administration, will determine the competence to hear proceedings on protection, verification and the imposition of sanctions. In plain terms, supervision moved from an autonomous constitutional body to a ministry.

The 2025 data protection statute

The implementing legislation arrived three months later. On 20 March 2025 the Diario Oficial de la Federación published, in its evening edition, the Decreto por el que se expiden la Ley General de Transparencia y Acceso a la Información Pública; la Ley General de Protección de Datos Personales en Posesión de Sujetos Obligados; la Ley Federal de Protección de Datos Personales en Posesión de los Particulares; y se reforma el artículo 37, fracción XV, de la Ley Orgánica de la Administración Pública Federal.

The consequence for AI operators is straightforward and easy to get wrong. The private-sector data protection law in force in Mexico is a 2025 statute, not the 2010 statute of the same name. The Orden Jurídico Nacional index maintained by the Secretaría de Gobernación records it with a publication date of 20 March 2025 and no subsequent reform. Compliance programmes, privacy notices and internal policies that cite article numbers, consent categories, ARCO procedures or fine ranges taken from the 2010 law are citing a lapsed instrument, and the same is true of any advice memorandum written before spring 2025.

This guide does not reproduce the article numbering of the 2025 statute. Its operative text could not be read at source. The Diario Oficial serves the decree as a single record that carries three complete statutes and runs past the length our reading tools accept, and the Cámara de Diputados legal library at diputados.gob.mx, which is the usual clean source for consolidated federal law, refused connection throughout. Rather than restate the 2010 numbering and present it as current, we have removed it. Operators should take article references, the definition of sensitive personal data, the treatment of automated processing and the penalty schedule from the published text of the 2025 law itself. The 2011 Reglamento of the 2010 law is still listed in the Orden Jurídico Nacional index with a publication date of 21 December 2011 and no reform, and its standing under the new statute is a question for Mexican counsel rather than something this guide can settle from the public record.

Who supervises now

The Secretaría Anticorrupción y Buen Gobierno is the federal ministry that took the function. Its own site carries the statement, in a banner on the front page, that the protection of personal data is now an attribution of the Secretaría, and it routes data protection matters to a dedicated portal. The decree of 20 March 2025 amending article 37, fracción XV, of the Ley Orgánica de la Administración Pública Federal is the mechanism: article 37 is the article that sets out that Secretaría's powers.

Practically, this changes the counterparty rather than the substance of a data protection posture. An operator that had built a programme around consent, purpose limitation, proportionality, privacy notices and the ARCO rights is not starting again. But the body that receives complaints, opens verification proceedings and imposes sanctions is now a ministry inside the executive rather than an autonomous institute, and the published resolution record that operators used to read for interpretive guidance stopped with the institute that produced it. There is, as at August 2026, no comparable body of published decisions under the new arrangement that we were able to locate.

We make no claim here about the fine range. The figures that circulate in secondary commentary, expressed as multiples of the daily minimum wage, come from the 2010 statute. Whether the 2025 law carries the same schedule, converts it to the Unidad de Medida y Actualización, or sets different bands, is not something we could establish from a source we could read.

No AI-specific penalty regime. Mexico's penalty exposure for AI operators derives from the federal data protection statute, sector-specific regulation, and general competition law. There is no AI-specific penalty regime, no AI risk classification system, and no mandatory pre-deployment notification requirement of the kind created by Regulation (EU) 2024/1689. Compliance exposure in Mexico is calibrated to the data and market conduct dimensions of AI deployment rather than to the AI system as such. For contrast, Article 99 of the EU AI Act sets fines of EUR 35 million or 7 per cent of worldwide annual turnover for the prohibited practices in Article 5, EUR 15 million or 3 per cent for other operator obligations, and EUR 7.5 million or 1 per cent for supplying incorrect information, whichever is higher, enforced by national market surveillance authorities. Mexico has nothing structurally equivalent.

What exists instead of a statute

The Orden Jurídico Nacional, the national legal compilation maintained by the Secretaría de Gobernación, indexes 302 federal laws and 135 federal regulations. None of them is an artificial intelligence statute. That index is the cleanest official list of federal ordinances we could open, and it is the basis for the statement that Mexico has no enacted AI law. One caution belongs with it: the most recent publication date it carried when we read it on 17 August 2026 was March 2025, so it lags. We were not able to run a keyword search of the Diario Oficial itself, because the gazette's advanced search has moved to a form that does not accept a query in the URL.

What does exist at federal level is a voluntary instrument. On 29 January 2026 the Secretaría de Ciencia, Humanidades, Tecnología e Innovación and the Agencia de Transformación Digital y Telecomunicaciones published the Principios de Chapultepec, a Declaración de ética y buenas prácticas para el uso y desarrollo de la Inteligencia Artificial. It is a declaration. It creates no duty, no register, no supervisory power and no sanction, and nothing in it is enforceable against an operator. Its significance is directional: it tells you which two bodies are holding the pen on Mexican AI policy, and it is the document a future statute would most plausibly be built on top of.

This guide previously described a Senate Punto de Acuerdo of 2023 calling for a national AI strategy, and a comprehensive AI framework proposal under review in the Chamber of Deputies. Neither could be confirmed. senado.gob.mx returned 403 to every request and diputados.gob.mx refused connection, so the parliamentary record was closed to us. Rather than describe legislative activity we could not see, we have removed those passages. Operators who need the current state of the Mexican legislative pipeline should have Mexican counsel pull it from the Sistema de Información Legislativa directly.

The practical implication is unchanged and worth stating plainly: AI-specific statutory obligations do not exist in Mexico today, and a governance programme built for the Mexican market has to be built out of data protection, sector regulation and competition law. For the nearest regional comparison, Brazil's PL 2338, introduced by Senator Rodrigo Pacheco with Senator Eduardo Gomes as rapporteur, see the Brazil AI Bill PL 2338 operators guide published on this site.

Sector regulators with AI-relevant authority

In the absence of a horizontal AI statute, sector regulators carry the primary compliance burden for AI applications in regulated industries. Two of the four names an operator would have used in 2024 are gone.

The Comisión Nacional Bancaria y de Valores supervises banks, brokerage firms, investment funds and other financial intermediaries, and it survived the reform intact. This guide previously attributed AI-relevant technology risk obligations to a CNBV instrument identified as Circular 4/2019. That instrument does not appear on any CNBV page we were able to open, and cnbv.gob.mx presented an invalid certificate chain to every direct request, so the claim has been withdrawn rather than reworded. Financial institutions using AI for credit scoring, fraud detection, algorithmic trading or customer segmentation should establish their technology risk obligations from the disposiciones de carácter general applicable to their own institution type, published in the Diario Oficial de la Federación, and not from any circular number cited in secondary commentary, this guide's earlier version included.

The Comisión Federal para la Protección contra Riesgos Sanitarios also survived. It regulates medicines, vaccines, medical devices, food, cosmetics, supplements, pesticides and health service establishments. AI applications used in diagnostic support, drug development, clinical decision support or health data analysis engage its authorisation and surveillance regime. We found no COFEPRIS instrument specific to artificial intelligence or to software as a medical device on its own pages, so operators in this space are working with general device and health service rules applied to a new object.

The Instituto Federal de Telecomunicaciones no longer exists. The eleventh transitional article of the constitutional reform of 20 December 2024 extinguished it. On 16 July 2025 the Diario Oficial published the Decreto por el que se expide la Ley en Materia de Telecomunicaciones y Radiodifusión y se abroga la Ley Federal de Telecomunicaciones y Radiodifusión. The new regulator is the Comisión Reguladora de Telecomunicaciones, which article 7 of that law establishes as an órgano administrativo desconcentrado of the Agencia de Transformación Digital y Telecomunicaciones with technical, operational and management independence, and article 8 charges with the regulation, promotion and supervision of the use of the radio spectrum. Telecommunications operators running AI in network management, recommendation or subscriber profiling now answer to that commission, under a statute published in 2025, not to the IFT under the 2014 law.

Competition law exposure after the antimonopoly reform

The Comisión Federal de Competencia Económica no longer exists either. The same eleventh transitional article extinguished it, and on 16 July 2025 the Diario Oficial published the Decreto por el que se reforman, adicionan y derogan diversas disposiciones de la Ley Federal de Competencia Económica y de la Ley Federal de las Entidades Paraestatales. The statute retains its name; the enforcer does not. Article 3, fracción V, of the reformed law defines the Comisión as the Comisión Nacional Antimonopolio, and article 10 establishes it as an organismo público descentralizado of the federal public administration with technical autonomy.

The substantive exposure for AI operators is unchanged in kind. Concerted practices analysis under the Ley Federal de Competencia Económica applies to conduct, and pricing conduct produced by an algorithm is still conduct. Operators using AI in pricing, supply chain optimisation or market-facing recommendation should treat the absence of an express agreement as no defence where the system's behaviour has the object or effect of restricting competition, and should look separately at AI systems that ingest competitor pricing, volume or customer information obtained through a shared platform.

What this guide can no longer offer is a specific Mexican authority publication on algorithmic collusion. An earlier version cited a Cofece opinion on algorithmic collusion and digital markets dated 2022. We could not read cofece.mx, which presented an invalid certificate chain, and we could not verify that document anywhere on an official domain. It has been removed. Operators should ask Mexican competition counsel what enforcement guidance, if any, the new commission has adopted or inherited, because the institutional discontinuity means old guidance cannot be assumed to carry forward.

USMCA Chapter 19: digital trade and cross-border data flows

The United States-Mexico-Canada Agreement, which entered into force in July 2020, contains a Digital Trade chapter, Chapter 19, that is directly relevant to AI operators moving data across the three member states. Its provisions are separate and should not be conflated. Article 19.12, Location of Computing Facilities, provides that no Party shall require a covered person to use or locate computing facilities in that Party's territory as a condition for conducting business in that territory. Article 19.11, Cross-Border Transfer of Information by Electronic Means, provides that no Party shall prohibit or restrict the cross-border transfer of information, including personal information, by electronic means where the activity is for the conduct of the business of a covered person. Article 19.4 covers non-discriminatory treatment of digital products, and Article 19.8 covers the protection of personal information.

Neither discipline is absolute. Paragraph 2 of Article 19.11 preserves a Party's ability to adopt or maintain a measure inconsistent with paragraph 1 where it is necessary to achieve a legitimate public policy objective, provided the measure is not applied as arbitrary or unjustifiable discrimination or a disguised restriction on trade and does not restrict transfers more than is necessary to achieve the objective. An operator that reads Chapter 19 as an unconditional guarantee that Mexican data can always leave Mexico has read it too generously.

For practical compliance, operators moving AI-processed personal data from Mexico to the United States or Canada satisfy two sets of conditions at once. Chapter 19 constrains what Mexico may impose on them. The international transfer provisions of the 2025 federal data protection statute constrain what the operator itself must do before transferring. These do not conflict, and each has to be satisfied on its own terms. We have deliberately not cited article numbers for the Mexican transfer regime here, because the operative text of the 2025 statute could not be read at source and the numbering of the 2010 law cannot be assumed to carry over.

Mexico has no adequacy decision, bilateral AI agreement, or equivalence mechanism with the European Union. Operators transferring AI-processed personal data from Mexico to EU-based processors must comply with the Mexican international transfer provisions on one side and the Chapter V transfer restrictions of the GDPR on the other, without the benefit of an equivalence bridge. For the EU regulatory context on cross-border AI data flows, the EU AI Act's extraterritorial reach guide on agentliability.eu covers the EU side of this equation in full.

EU AI Act extraterritorial exposure for Mexican operators

Article 2(1)(c) of Regulation (EU) 2024/1689 applies the EU AI Act to providers and deployers of AI systems established outside the Union where the output of those systems is used in the Union. A Mexican company that develops or deploys an AI system whose outputs are used by EU-based operators, consumers, or institutions is within the scope of the EU AI Act for those outputs. This applies regardless of whether the Mexican operator has any physical establishment or legal entity in the EU.

Mexican AI companies with EU market exposure should therefore conduct a dual-track compliance assessment: domestic Mexican compliance under the 2025 data protection statute and the sector frameworks, and EU AI Act compliance under Regulation (EU) 2024/1689 for the EU-facing dimension of their operations. The two frameworks do not conflict, but they are not equivalent. The EU AI Act's prohibited practices in Article 5, high-risk classification under Annex III, conformity assessment under Articles 43 and 44, technical documentation under Article 11 and Annex IV, and its market surveillance mechanisms create obligations that have no direct analogue in Mexico's current domestic framework.

The EU timetable has moved and it moves in the operator's favour. The Digital Omnibus entered into force on 27 July 2026 as Regulation (EU) 2026/1744. The Annex III high-risk obligations now apply from 2 December 2027 and the Annex I obligations from 2 August 2028. The Article 5 prohibitions, the Article 50 transparency duties, the general purpose AI obligations and the Article 4 AI literacy duty were not deferred and have applied since 2 August 2026. A Mexican provider whose outputs reach the Union is therefore already inside the prohibitions and the transparency duties, whatever its Annex III timetable turns out to be.

For an overview of the global comparative picture, including how US, EU, and UK frameworks interact for operators with multi-jurisdictional exposure, see the resources section of this site and the frameworks reference for a structured comparison of the major AI regulatory instruments.

Practical compliance checklist for operators in Mexico

The following steps reflect the current compliance environment for AI operators active in the Mexican market. They are not a substitute for legal advice specific to an operator's use case and sector.

First, re-base the whole programme on the 2025 statute. Obtain the published text of the Ley Federal de Protección de Datos Personales en Posesión de los Particulares as expedited on 20 March 2025, and check every article reference in your privacy notices, contracts, data processing records and internal policies against it. Anything citing the 2010 law is citing an instrument that no longer governs. Then map the obligations across all AI systems processing personal data of individuals in Mexico, including systems operated elsewhere whose outputs produce effects on people in Mexico.

Second, treat the INAI material as legacy rather than live. Resolutions and guidance published by the institute before its extinction still show how the older statutory principles were applied to automated processing, and that reasoning is the best available indication of how a successor may approach the same questions. It is not current regulator guidance and nobody should cite it as though it were. Whether the Secretaría Anticorrupción y Buen Gobierno adopts, replaces or ignores that body of interpretation is the single most useful thing for a Mexican operator to watch.

Third, for AI systems in financial services, obtain the technology and operational risk provisions of the disposiciones de carácter general that apply to your own institution type, as published in the Diario Oficial de la Federación, and work from those. Do not build a control set from a circular number found in a compliance article, this guide's earlier version included. If your AI governance documentation was prepared for EU AI Act purposes it will cover much of the substance, but reporting formats and supervisory notification requirements are national and need separate adaptation.

Fourth, evaluate competition exposure for AI systems involved in pricing, market recommendations, or the processing of commercially sensitive competitor data, and have it reviewed by counsel who is working with the Comisión Nacional Antimonopolio rather than with Cofece precedent alone. The assessment should cover algorithmic coordination and information exchange separately.

Fifth, establish a monitoring protocol. A statute is not imminent, but implementing regulations under the 2025 data protection law, the first enforcement practice of the new data protection supervisor, the first decisions of the Comisión Nacional Antimonopolio and the Comisión Reguladora de Telecomunicaciones, and any move from the Principios de Chapultepec towards binding rules, will all move faster than primary legislation. The standing workflow should watch the Diario Oficial de la Federación, the Secretaría Anticorrupción y Buen Gobierno, and the Agencia de Transformación Digital y Telecomunicaciones. It should not watch INAI, Cofece or the IFT, none of which still exists.

Sixth, conduct a Chapter 19 analysis for any AI system that moves personal data across the Mexico to United States or Mexico to Canada border. Confirm the position under Article 19.12 on computing facilities and Article 19.11 on cross-border transfers, including the legitimate public policy exception in its second paragraph, alongside the international transfer conditions of the Mexican statute. Document the analysis for both domestic regulatory purposes and potential cross-border enforcement scenarios.

Frequently asked questions

Does Mexico have a federal AI law in 2026?

No. The index of federal laws maintained by the Secretaría de Gobernación lists 302 federal laws and none of them is an AI statute. The nearest federal instrument is the Principios de Chapultepec, a declaration of ethics and good practice for the use and development of artificial intelligence issued jointly by SECIHTI and the Agencia de Transformación Digital y Telecomunicaciones on 29 January 2026. It is voluntary and creates no obligation.

Which data protection law applies to AI systems in Mexico, and which body supervises it?

The Ley Federal de Protección de Datos Personales en Posesión de los Particulares expedited by decree published in the Diario Oficial de la Federación on 20 March 2025, which replaced the 2010 law of the same name. Supervision no longer sits with an autonomous institute. The Secretaría Anticorrupción y Buen Gobierno states on its own site that the protection of personal data is now one of its attributions.

Which sector regulators in Mexico have AI-relevant authority?

The Comisión Nacional Bancaria y de Valores for financial services and the Comisión Federal para la Protección contra Riesgos Sanitarios for medicines, medical devices and health services both continue. The Instituto Federal de Telecomunicaciones and the Comisión Federal de Competencia Económica were extinguished by the constitutional reform published on 20 December 2024, and were replaced in July 2025 by the Comisión Reguladora de Telecomunicaciones, inside the Agencia de Transformación Digital y Telecomunicaciones, and the Comisión Nacional Antimonopolio.

How do the digital trade rules in Chapter 19 of the USMCA interact with AI data flows between Mexico and the United States?

Article 19.12 addresses the location of computing facilities and Article 19.11 addresses cross-border transfers of information, subject to a legitimate public policy exception in its second paragraph. Non-discriminatory treatment of digital products is Article 19.4 and the protection of personal information is Article 19.8. Operators must satisfy the Chapter 19 disciplines and the Mexican international transfer conditions independently.

What penalties apply under Mexican data protection law for AI systems?

This guide does not state a figure. The penalty schedule of the 2010 statute lapsed with that statute, and the operative text of the 2025 law could not be read at source: the Diario Oficial serves it as a single record longer than our reading tools accept, and diputados.gob.mx refused connection. Take the range, the numbering and the criminal referral route from the published 2025 text, not from figures carried over from 2010.

References

  1. Decreto por el que se reforman, adicionan y derogan diversas disposiciones de la Constitución Política de los Estados Unidos Mexicanos, en materia de simplificación orgánica. Diario Oficial de la Federación, 20 December 2024. Record 5745905.
  2. Decreto por el que se expiden la Ley General de Transparencia y Acceso a la Información Pública; la Ley General de Protección de Datos Personales en Posesión de Sujetos Obligados; la Ley Federal de Protección de Datos Personales en Posesión de los Particulares; y se reforma el artículo 37, fracción XV, de la Ley Orgánica de la Administración Pública Federal. Diario Oficial de la Federación, edición vespertina, 20 March 2025. Record 5752569.
  3. Secretaría de Gobernación, Orden Jurídico Nacional. Index of federal laws and regulations, consulted 17 August 2026. Entry for the Ley Federal de Protección de Datos Personales en Posesión de los Particulares, published 20 March 2025, sin reforma; entry for the Reglamento of 21 December 2011.
  4. Secretaría Anticorrupción y Buen Gobierno. Institutional site at gob.mx, consulted 17 August 2026: "La Protección de Datos Personales es ahora atribución de la Secretaría Anticorrupción y Buen Gobierno."
  5. Decreto por el que se expide la Ley en Materia de Telecomunicaciones y Radiodifusión y se abroga la Ley Federal de Telecomunicaciones y Radiodifusión. Diario Oficial de la Federación, 16 July 2025. Record 5763167. Comisión Reguladora de Telecomunicaciones, articles 3, 7 and 8.
  6. Decreto por el que se reforman, adicionan y derogan diversas disposiciones de la Ley Federal de Competencia Económica y de la Ley Federal de las Entidades Paraestatales. Diario Oficial de la Federación, 16 July 2025. Record 5763164. Comisión Nacional Antimonopolio, articles 3, fracción V, and 10.
  7. Secretaría de Ciencia, Humanidades, Tecnología e Innovación and Agencia de Transformación Digital y Telecomunicaciones. Principios de Chapultepec. Declaración de ética y buenas prácticas para el uso y desarrollo de la Inteligencia Artificial, 29 January 2026.
  8. United States-Mexico-Canada Agreement, Chapter 19: Digital Trade. Entered into force 1 July 2020. Articles 19.4, 19.8, 19.11 and 19.12, consulted in the Government of Canada text at international.gc.ca.
  9. Regulation (EU) 2024/1689 of the European Parliament and of the Council (EU AI Act), OJ L, 12 July 2024, Articles 2, 5, 11, 43, 44, 50, 99, Annex III, Annex IV.
  10. Regulation (EU) 2026/1744 (Digital Omnibus), in force 27 July 2026.
  11. OECD Recommendation on Artificial Intelligence, OECD/LEGAL/0449, adopted May 2019, revised 3 May 2024.
  12. Council of Europe Framework Convention on Artificial Intelligence and Human Rights, Democracy and the Rule of Law, CETS No. 225, opened for signature at Vilnius on 5 September 2024. Not yet in force. This guide makes no claim about Mexican signature or ratification.