Mexico has no comprehensive federal AI law, though at least three competing bills and a constitutional-reform proposal are pending in Congress. The bigger recent change is institutional: INAI, the body that long handled data protection, was dissolved in 2025, its functions split between the Secretaria Anticorrupcion y Buen Gobierno and a new transparency body. Concrete, binding AI-specific rules already exist in narrower places, platform-worker algorithmic transparency, AI voice and image cloning consent, and bank biometric authentication, and the first real AI-related sanction landed in July 2026. This page sets out the instruments, the dates, and which ones are binding versus proposed, with links to the primary sources.
Last reviewed: 23 July 2026 · A factual snapshot; AI policy is evolving, so confirm against the primary sources linked below
Mexico has not enacted a general AI statute. A Senate committee is consolidating at least eight prior bills into a single Ley General de Inteligencia Artificial, a separate Senate bill proposes a new AI regulatory agency, a Chamber of Deputies bill proposes a traffic-light risk system, and a constitutional-reform bill would give Congress explicit authority to legislate on AI. None has cleared committee, and the Chamber of Deputies has named AI a priority for the session opening 1 September 2026 without yet presenting definitive text.
What has changed concretely is the data-protection landscape. INAI, Mexico's long-standing transparency and data-protection institute, was dissolved by a December 2024 constitutional reform; a new federal data-protection law took effect in March 2025 without adding any AI-specific provisions; and INAI's functions were formally handed over in May 2025 to the Secretaria Anticorrupcion y Buen Gobierno (data protection) and a new body, Transparencia para el Pueblo (transparency). That successor agency issued Mexico's first significant AI-related sanction in July 2026, a roughly 42.8 million peso fine against the Mexican Football Federation over a facial-recognition stadium system, in a case that originated as an INAI investigation.
A "Simplificacion Organica" constitutional reform published in the Diario Oficial de la Federacion (DOF) eliminated seven autonomous bodies, including INAI, the national transparency and data-protection institute, transferring their functions to federal executive-branch agencies.
A decree added a new chapter to the Ley Federal del Trabajo (LFT) recognising delivery riders and drivers as "personas trabajadoras de plataformas digitales," a distinct labour category, entering into force six months later on 22 June 2025.
A new Ley Federal de Proteccion de Datos Personales en Posesion de los Particulares (LFPDPPP) took effect, the date INAI ceased to exist in law. Legal commentary confirms the new law adds no AI-specific provisions, leaving only general principles to apply to AI data processing by default.
INAI completed its institutional handover: personal-data-protection oversight passed directly to the Secretaria Anticorrupcion y Buen Gobierno (SABG), while transparency and access-to-information functions passed to a new body, Transparencia para el Pueblo, operating under SABG.
New Article 291-J LFT requires that rules for algorithmic task assignment be transparent and known to workers, obliging platforms to produce a plain-language "algorithmic management policy document" and to have complaints about algorithmic decisions resolved by a human, not an automated system.
IMSS ran a mandatory-participation pilot requiring platforms to register qualifying workers in the social-security system, extending medical care, work-risk insurance and INFONAVIT housing-credit access; the pilot's rules remain in force pending a planned reform of the Ley del Seguro Social.
A reform to the Federal Labour Law and the Federal Copyright Law took effect requiring express consent and pre-agreed remuneration before any AI-generated reproduction of a performer's voice, image or performance, and requiring artist contracts to specify AI-use terms, the most concrete enacted AI-specific rule found for 2026.
The CNBV published a resolution requiring at least a 90 percent facial-biometric match against official identity records for bank client authentication, restricting sharing of biometric data between banks, and empowering the CNBV to suspend a bank's biometric use for serious non-compliance, framed partly as a response to AI-enabled fraud.
The Secretaria Anticorrupcion y Buen Gobierno fined the Mexican Football Federation (FMF) roughly 42.8 million pesos over its "Fan ID" facial-recognition stadium-registration system, an investigation opened by INAI before its dissolution and concluded by its successor. The FMF has said it will challenge the fine.
The president of the Chamber of Deputies' Junta de Coordinacion Politica named an AI legal framework as one of five priority reforms for the ordinary session opening 1 September 2026, though no definitive bill text had yet been presented and several competing AI bills remain pending across both chambers.
With no general AI statute in force, what binds AI in Mexico today is a set of narrower rules, in data protection, labour, and specific sectors, plus state-level criminal law. The table below sorts the main instruments by whether they carry legal force now or remain proposed.
| Instrument | Status | Applies to / owner |
|---|---|---|
| LFPDPPP, federal data-protection law (2025) | Binding, no AI-specific rules | Any organisation processing personal data; oversight now with the SABG |
| LFT Article 291-J, algorithmic-management transparency | Binding | Digital platforms assigning work via algorithm (delivery, rideshare) |
| LFT and LFDA reform on AI voice/image cloning (May 2026) | Binding | Producers of AI-generated content using a performer's voice, image or likeness |
| CNBV facial-biometric resolution (2026) | Binding | Banks and credit institutions using biometric client authentication |
| State deepfake criminal statutes (Sinaloa, Mexico City and others) | Binding (state level) | Individuals generating non-consensual AI sexual deepfakes |
| Ley General/Nacional de Inteligencia Artificial and Article 73 reform | Proposed, not enacted | Would create a comprehensive federal AI framework and possibly a dedicated regulator |
| INAI's 2022 AI and personal-data recommendations | Voluntary, not updated since INAI's dissolution | Public- and private-sector AI developers processing personal data |
For the wider picture across jurisdictions, see our AI regulation by country comparison and the Spain and Canada references, which also lack a comprehensive AI Act.
There is no comprehensive AI-specific compliance regime to align to yet, but organisations should not read that as an absence of risk. Data protection now runs through the Secretaria Anticorrupcion y Buen Gobierno, which has already shown it will fine AI-adjacent biometric processing; platforms using algorithmic task assignment carry a specific disclosure duty; and producers of AI-generated voice or image content need performer consent under the 2026 reform.
The practical watch item is Congress: a general AI law is a named legislative priority for September 2026, though its content and timeline remain unsettled. Our AI GRC guide covers how those pieces fit together, and a short governance assessment benchmarks where an organisation stands against a structured model.
Not yet. As of July 2026, at least three federal AI bills are pending, a general AI law backed by a Senate committee, a national-use AI law from the Senate, and an ethical/sovereign AI law from the Chamber of Deputies, alongside a separate proposal to amend Article 73 of the Constitution to give Congress explicit authority to legislate on AI. None has been reported out of committee or enacted. The Chamber of Deputies has named an AI framework a priority for the session opening 1 September 2026, but no definitive bill text has been presented.
No. INAI was dissolved under a constitutional reform published 20 December 2024, and a new federal data-protection law took effect 20 to 21 March 2025, the date INAI ceased to exist in law. Its functions were formally handed over on 9 May 2025: personal-data-protection oversight now sits directly with the Secretaria Anticorrupcion y Buen Gobierno (SABG), while transparency and access-to-information duties went to a new body, Transparencia para el Pueblo, operating under SABG. Sources describing INAI as active are out of date.
Yes. The SABG fined the Mexican Football Federation roughly 42.8 million pesos in July 2026 over its Fan ID facial-recognition stadium-registration system, finding it failed to properly disclose that the biometric data collected was sensitive personal data and relied on a website checkbox rather than express written consent. The investigation began under INAI before its dissolution and was concluded by its successor agency; the Federation has said it will challenge the fine.
Since 22 June 2025, Article 291-J of the Federal Labour Law requires digital platforms to disclose, in a plain-language policy document, the criteria their algorithms use for task assignment, ratings, incentives, penalties and disconnection, and requires that complaints about algorithm-driven decisions be resolved by a human rather than an automated system. A parallel mandatory pilot brought qualifying platform workers into the IMSS social-security system from July 2025.
There is no single comprehensive federal deepfake law yet, but binding rules already exist at several levels: a May 2026 federal reform requires consent and payment before an AI system reproduces a performer's voice or image; state criminal statutes, upheld by the Supreme Court for Sinaloa and separately enacted in Mexico City, criminalise non-consensual AI-generated sexual images, audio or video; and federal reforms extending similar criminal liability nationwide have passed the Chamber of Deputies but remain before the Senate.
A federal appellate ruling in August 2025, believed to be Mexico's first judicial guidance on the question, held that tools such as ChatGPT, Grok and Gemini may be used as an auxiliary tool for narrow, numerical tasks such as calculating a bond amount, but may not replace judicial decision-making, and that any such use must be traceable, verifiable and disclosed in the ruling itself.
There is no single enacted national AI strategy yet. President Claudia Sheinbaum announced that the federal government would open a public debate and consultation process on AI and social-media regulation once 2026 World Cup activities concluded, aiming eventually to send a legislative initiative to Congress. In the meantime, sector regulators including the CNBV and Banco de Mexico are issuing their own AI-relevant rules and guidance independently of any national framework.
A short, free assessment benchmarks where your organisation stands against a structured AI governance model, a practical first step even where the AI-specific regulatory picture is still forming.
This page is general information describing the state of Mexico AI policy as at 23 July 2026, not legal or compliance advice. Several federal AI bills are moving through Congress and the picture may change quickly; always confirm the current position against the primary sources linked above and obtain advice from your own qualified counsel before relying on it.