-
What is the legal definition of “artificial intelligence” in your jurisdiction, if any? If no definition exists, how do regulators or courts typically describe artificial intelligence?
Mexico lacks a federal legal definition of Artificial Intelligence (AI). Some state-level definitions exist. The National Alliance for Artificial Intelligence (ANIA) advised the Mexican Senate and issued a Roadmap and Agenda Proposal 2024-2030, and incorporated the ODCE definition.
Several bills in Congress have proposed AI definitions, but these show regulatory and technical limitations. Definitions are often overly broad or too vague for effective implementation.
A recent bill defined it as “an information, algorithmic, or physical system designed to imitate human capabilities such as learning, reasoning, perception, or decision-making, which can operate autonomously or with assistance, and whose outcomes have an impact on individuals, processes, or environments, whether physical or digital”.
Also, recently, Mexico’s Supreme Court of Justice (SCJN) agreed to a Sinaloa State Criminal Code AI definition as “the applications, programs or technology that allow automatic alterations or modifications on photographs, audio or video”, in the context of the sexual intimacy crime. Afterwards, the Supreme Court also accepted a definition in the Quintana Roo State Criminal Code, as “the capacity of technological, computer, software, or application systems of a machine to simulate human capabilities such as reasoning, learning, creativity, the ability to plan, and process data for the performance of specific and autonomous tasks”.
In a recent case ruling detailed below, AI cannot be owners or authors, the SCJN defined AI as an algorithmic system simulating human reasoning, processing data, making predictions, and performing actions based on patterns, but lacking human experience, perception, feelings, and self-awareness.
However, to prevent definitions from becoming obsolete and evolve alongside the fast-paced growth of AI, a more accurate definition and approach is needed. Below, please find the key elements that an AI definition for a regulatory framework should include:
- Defining AI as a capability of a software-based system. Defining AI as a software system per se, is too expansive and could unintentionally include non-AI systems (e.g., simple rule-based or deterministic software).
- Clarifying that it can receive explicit or implicit objectives.
- Outlining the process of analyzing, interpreting, or inferring from input to generate outputs.
- Considering different types of outputs, by listing possible results from the use of AI including predictions, content, recommendations, and decisions, it covers a broad range of AI applications. Most definition approaches focus mainly on generative AI.
- Impact: considering that AI can influence both physical and virtual environments.
- Acknowledgment of AI’s autonomy and adaptation capabilities to technological evolution.
-
Has your country developed a national strategy for artificial intelligence? If yes, what progress has been made in its implementation? Are there plans for updates or revisions?
Mexico developed a national AI strategy, first announced in 2018. Titled “Towards an AI Strategy in Mexico: Harnessing the AI Revolution,” it outlined six thematic areas: governance, government and public services, research and development, capacity/skills/education, data infrastructure, and ethics/regulation.
More recently, on May 15, 2024, a group of experts (ANIA) proposed a National AI Agenda (2024-2030) to the Senate. This agenda suggests public policy and governance recommendations for ethical AI development, including a risk-based regulatory approach, data privacy, IP protection, regulatory sandboxes, and comprehensive AI/cybersecurity frameworks.
While not formally adopted, the 2025-2030 National Development Plan includes a commitment to optimize public services and improve policy design using analytical tools like AI, a priority also highlighted by President Claudia Sheinbaum, who has stated that science and technology are a priority on the Government’s agenda. The new Digital Transformation and Telecommunications Agency (ATDT) is also expected to issue relevant regulations and standards.
As of July 2026, no updates or revisions have been proposed or implemented.
-
Has your jurisdiction adopted any AI-specific laws, regulations, voluntary standards, or ethical guidelines? If so, please provide a brief overview. If not, which existing laws could be/are applied to artificial intelligence and the use of artificial intelligence, what are the main interpretive challenges, and are there any pending artificial intelligence legislative initiatives?
As of July 2026, Mexico lacks centralized, comprehensive, and specific AI regulation, despite over 100 AI-related bills introduced in Congress since 2020. However, this is expected to change, with key legislative proposals anticipated for discussion in the upcoming September session. President Claudia Sheinbaum recently stated that public consultations will be organized on the regulation of social media and AI, focusing on AI’s risks and benefits, as well as the impact of social media on children’s and adolescents’ mental health and digital addiction.
Given the absence of specific AI legislation, existing laws are being considered for their potential applicability, though their interpretation for AI presents significant challenges:
- Copyright Law: The Federal Copyright Law (LFDA) was amended on May 14, 2026 in order to grant performing artists rights against unauthorized AI use of their voice, image, and performances. Voice is now an explicitly protected asset, any AI-generated “clone” or “identifiable simulation” requires prior written consent and specific remuneration; consent is revocable for good cause; and AI programs used to violate LFDA rights lose their own copyright protection. Exceptions exist only for parody, satire, or creative imitation that does not substitute the artist professionally.
- Privacy Law: The Federal Law on Protection of Personal Data Held by Private Parties (LFPDPPP), though not designed for AI, applies its principles (transparency, consent, purpose) to automated profiling and decision-making, including biometric recognition. This law expands the definition of personal data, broadens legal bases for processing, and enhances individual rights over automated processing. Challenges arise from AI’s extensive data processing without clear human oversight, and the law lacks AI-specific rules for legal certainty. A new LFPDPPP is currently being drafted by the data protection authority, the Ministry of Anticorruption and Good Government. This new law is set to include enhanced data protection rights, similar to GDPR, and to include AI-related provisions.
- Consumer Protection: May apply where AI tools are used in advertising, pricing, or automated customer interactions lead to misleading information, deceit or discriminatory outcomes affecting consumers, or defective products/services causing consumer harm.
- Criminal Code: Relevant for misuse of AI (e.g., identity theft, fraud, cybercrime). Its strict interpretation makes direct application to AI difficult, prompting legislative proposals to criminalize specific AI-related offenses like deepfakes and identity theft. State-level codes (Sinaloa, Tabasco, Tamaulipas, Morelos, San Luis Potosí, Colima and Aguascalientes) have already increased penalties or criminalized AI use in certain contexts.
- Commercial Code: Some of its provisions on e-commerce, consent, and contractual validity may apply to AI-generated acts.
- Federal and local Civil Code: Provide general rules on contracts, torts, civil liability, damages, and negligence, applicable on a case-by-case basis.
- Labor Law: The Federal Labor Law (LFT) was amended on May 14, 2026, alongside the LFDA, expanding coverage beyond actors and musicians to dubbing actors, voice-over artists, and narrators. New Article 305 Bis mandates that all employment contracts with performers must expressly specify conditions and remuneration for any AI or technology-based use of their voice or image. This matter is also indirectly relevant as AI impacts employment (e.g., as an employee tool, or regarding job displacement).
- Sector-Specific Regulations (Health, Banking): AI use in these highly regulated fields may infringe existing laws that currently lack AI-specific provisions.
- USMCA 19.17: provides safe harbors for intermediaries, though not drafted for AI, could be relevant. Current treaty renegotiations could include AI-related matters.
- IP: The Federal Intellectual Property Protection Law (LFPPI) was amended in April 2026, to provide that prohibited acts remain subject to the same sanctions when committed through the use of AI. We have not identified any publicly reported cases in which this provision has been enforced.
-
Are there legal requirements for artificial intelligence transparency, explainability, or audits? Are there obligations to disclose the use of artificial intelligence to customers/clients?
Overall, there is no comprehensive AI regulation in Mexico. However, recent legislative amendments have introduced algorithmic transparency requirements, and a notable judicial ruling has addressed the use of AI in courts.
Amendments to the Federal Labor Law
The amendments to the LFT concerning digital platform workers enshrine the principle of algorithmic transparency. The law provides that the rules governing the allocation of services or tasks through algorithms must be transparent, clear, and available to workers. Additionally, the amendments establish a proactive social transparency mechanism requiring platforms to prepare an algorithmic work management policy document.
These policies must clearly and accessibly explain the consequences of compliance with instructions, the impact of third-party ratings, incentives and penalties, the existence of categories influencing task assignment, and other relevant criteria. This document must be incorporated into the employment contract and disclosed to workers at the commencement of the employment relationship or upon any subsequent modification. Furthermore, the law provides that algorithms must be reasonable, must not endanger the health or physical integrity of the worker, and must not result in discrimination.
The LFT further establishes an appeal and accountability mechanism for workers, which must be administered by a natural person rather than an automated system.
Alternative Dispute Resolution Mechanisms
On January 26, 2024, the General Law on Alternative Dispute Resolution Mechanisms (LGMASC) was published in the Official Gazette of the Federation (DOF). This law broadly regulates all forms of legal dispute resolution other than litigation, including, for example, arbitration and conciliation. The statute includes a chapter on online dispute resolution that incorporates definitions of automated systems and algorithmic transparency.
The law’s definition of “automated systems” functions as an umbrella term intended to encompass all forms of AI. This includes machine learning systems, any system performing data processing, natural language processing, algorithms, and artificial neural networks.
The legislation also offers an initial articulation of the concept of algorithmic transparency, defining it as the set of practices designed to ensure that algorithms employed by automated systems are visible, comprehensible, and auditable. The law does not define the concepts of “visibility”, “comprehensibility”, and “auditability,” leaving the applicable standard unclear. Moreover, meaningful algorithmic transparency requires the establishment of an independent authority with the competence to evaluate and oversee the deployment of such systems, which is a development that would represent a significant step toward strengthening the regulatory framework in the future.
Judicial Case Law
Beginning with Case 212/2025/ Tesis II.2o.C.8 K (11a.) (detailed below), which clarified the use of AI for the Judiciary activities, required that any AI used in legal proceedings cannot be a “black box.” Algorithms must be fully explainable and replicable by the affected parties. Judicial systems using AI (such as Queretaro State SonIA system), are legally required to disclose using AI to guarantee transparency and fair trials.
-
Are there legal requirements or best practice expectations for human oversight and human-in-the-loop in artificial intelligence systems?
Mexico lacks specific legislation mandating human oversight in AI systems. However, binding case law from January 2026 establishes human supervision and decision-making as a minimum element for the ethical use of AI in judicial proceedings, ensuring that AI operates as an auxiliary tool and not as a substitute for the judicial function.
Court rulings, as mentioned, have explicitly required that the use of AI by courts and judges must not only be disclosed and explained, but ensure there is sufficient human intervention/human-in-the-loop, particularly regarding the ruling and decisions that impact citizens’ rights only for technical, administrative, or mathematical tasks. Crucially, the case law establishes that AI cannot replace judicial discretion or human legal analysis. It explicitly mandates “human oversight” as a guiding principle, making a human-in-the-loop a structural legal requirement for any automated judicial decision.
Following these court rulings, the Federal Council of the Judiciary institutionalized this case law by issuing Circular 1/2026 as the first formal regulatory document binding federal courts. It sets forth the principles of transparency and mandatory human oversight, and legally prohibits judges from executing unverified or fully automated AI tasks, solidifying “human-in-the-loop” from a loose best practice into an internal administrative law. Mexico has already seen a case of a judge that was sanctioned for using Gen-AI for drafting rulings and court resolutions without transparency or human intervention.
For lawyers specifically, the BMA Code of Professional Ethics (Articles 10.2, 13.1 and 13.2) requires attorneys to act personally or under their responsibility and to diligently supervise the work of collaborators, an obligation extending to AI-generated output. The BMA Guidelines (October 2025) reinforce this through the principle of exclusive professional responsibility, prohibiting delegation of professional judgment to AI systems. Best practices include mandatory human review of all AI-generated work products, firm-level AI use policies, and senior lawyer supervision of AI-assisted work by junior staff with the same scrutiny applied to human-authored work.
-
Are there specific legal or regulatory requirements addressing algorithmic bias, discrimination, or fairness in AI systems (including gender bias)?
No. As previously mentioned, Mexico does not currently have AI-specific regulation, nor any other regulation related to algorithmic bias, discrimination, or fairness in AI systems. As a basis, the Mexican Constitution prohibits discrimination based on, among other grounds, gender, ethnicity, disability, age, religion, health conditions, or sexual orientation. These principles are set forth in the Federal Law to Prevent and Eliminate Discrimination, which applies regardless of whether discriminatory outcomes result from human or automated decision-making. We are not aware of any public cases where this law serves as a basis for any bias, discrimination or fairness in the use of AI.
In addition, the Ministry of Science and Technology and the ATDT issued the “Declaration of Ethics and Good Practices for the Use and Development” also known as the “Principles of Chapultepec,” which is non-binding. Among these principles, transparency, rights expansion, and fairness are promoted across the AI lifecycle, calling for prior impact assessments and human accountability in AI decisions, but carry no enforcement mechanism.
Finally, the LFPDPPP does not specifically regulate algorithmic bias, but it requires personal data processing to comply with principles such as lawfulness, fairness, non-discrimination, proportionality, and accountability. In addition, several AI bills in Congress seek to introduce obligations relating to transparency, human oversight, risk management, and the prevention of discriminatory or bias, including gender bias. However, these proposals have not yet been enacted.
-
What legal frameworks apply to AI-related harm and defective artificial intelligence systems? Who can be held liable (developer, deployer, victim of the damage, others), how is liability allocated, and what burden of proof applies to victims?
This is certainly an area for future conflict and legal evolution: while some bills of law have tried to address who should be liable in certain scenarios, or even try to make the AI developer liable for any and all damages and mistakes, those bills have not advanced. Mexico’s current system uses a mix of strict (objective) liability, subjective liability (negligence), product liability and consumer protection, as well as criminal liability and other sectorial protections. Because AI does not have legal personality in Mexico, courts treat it strictly as a tool; only humans or corporations can bear legal liability. Responsibility is allocated based on control and role in the lifecycle, between the developer/manufacturer, the deployer/operator, an user, or sometimes even the victim, in cases of gross negligence, intentional misuse, or unpredictable behavior. Most recently, baseline general AI models could be considered as liable in certain cases.
The main issue is that the current framework was not designed for AI, and is mostly inoperative in AI scenarios. Burden of proof mostly is impossible for victims, as well as finding a causal link. AI black box, whenever it exists, makes it hard to prove who and why a result was provided. AI is not a dangerous machine, under strict liability, and multi-purpose AI systems make it more complex. And defining a “mistake” on AI, under consumer protection rules, is not the same as a traditional software mistake, as AI is essentially probabilistic and not linear.
Thus, we are likely to see an evolving case law where judges will try to apply or adapt traditional liability rules for new cases, with more or less success and friction. However, criminal liability, due its strict rules, may not work and require legislative update.
-
What cybersecurity obligations apply to AI systems?
Currently, Mexico does not have any specific, dedicated regulations or comprehensive laws enacted either for AI systems or for cybersecurity. Instead, the legal framework relies entirely on existing statutes to govern these technological deployments.
The primary and most enforceable regulation that applies to AI systems is the LFPDPPP. Under this framework, any AI system that processes personal data must strictly comply with established data protection principles, requiring the implementation of administrative, physical, and technical security measures to safeguard data pipelines, while ensuring transparency and honoring data subjects’ rights regarding automated decision-making. Since legislators are aware that AI can be used for cyber crimes, there is a lot of interest in updating the federal and local criminal codes to explicitly include AI as a means of criminal action. Additionally, specialized sectors, such as telco, banking and fintech, must comply with strict cybersecurity guidelines issued by the regulators, which directly impact AI deployments in those industries.
-
Is the use of artificial intelligence insured and/or insurable in your jurisdiction, including with cyber policies? Are there market trends, or limitations?
While Mexico lacks specific AI insurance policies or regulations, AI use is theoretically insurable under the Law on Insurance and Bonding Institutions. This law allows coverage for new risks if lawful and based on a defined insurable interest. Thus, AI risk is not inherently uninsurable due to lack of specific regulation. However, regulatory ambiguity and ‘silent AI’ make insurers cautious, particularly regarding external infrastructure or unclear liability.
A practical limit is the territorial scope of contracts, typically requiring risks within Mexico. Cross-border AI infrastructure (e.g., cloud) may challenge this. Mexican AI systems could theoretically be covered by civil liability policies if risks are lawful and defined. Yet, no known specific AI liability policies exist in Mexico; lack of precedent and AI risk uncertainty deter providers.
As AI legal treatment matures, insurers may reconsider limits, especially for high-risk sectors. Meanwhile, companies deploying AI should use traditional liability frameworks and ensure risk allocation via internal controls and contractual protections.
-
Can artificial intelligence be named as an inventor in a patent application filed in your jurisdiction? If not, what is the current legal position?
No. The LFPPI states that an invention is a human creation that transforms matter or energy existing in nature, for its use by humans to satisfy specific needs. In that sense, only human beings can be considered inventors.
As for the patent owner(s), while a legal entity can be named as the patent owner (e.g., through an assignment from an employee-inventor or other contractual agreements), AI systems lack legal personality and capacity to enter into such agreements or hold rights. Note, importantly, that software is not patentable in Mexico; but it can be registered as copyright.
Moreover, in connection with this topic, the SCJN recently issued a decision (to be analyzed in more detail below) confirming that only human beings can create works, hence, only humans can be authors. The outputs of AI are considered products, not works of authorship.
-
Do images or works generated by and/or with artificial intelligence benefit from copyright protection in your jurisdiction? If so, who is the authorship attributed to, and under what conditions?
No, images generated entirely by or primarily with AI do not currently benefit from copyright protection in Mexico. The Mexican legal framework, specifically the LFDA, establishes that an “author” is the natural person who creates a literary and artistic work. Consequently, the authorship of content generated by AI, absent significant human creative input, is not attributed to anyone.
This interpretation was recently affirmed by the SCJN in Amparo Directo 6/2025, following INDAUTOR’s denial of copyright registration for an AI-generated avatar created using Leonardo AI. The Supreme Court confirmed that the LFDA recognizes only natural persons as authors, reasoning that AI merely executes algorithms and processes human-provided information. The final ruling classified AI outputs as “products” rather than copyrightable “works,” while noting that AI software itself remains copyrightable. A preliminary draft had addressed the potential public domain status of AI outputs, but this aspect was ultimately excluded from the final decision, leaving ownership partially unresolved.
-
What are the main issues to consider when using artificial intelligence systems in the workplace? Have any new regulations, or guidelines, been introduced regarding AI-driven hiring, performance assessment, or employee monitoring?
There are no new AI regulations regarding labour-related topics. However, using AI systems in the workplace presents employers with significant legal, operational, and ethical risks.
When deploying AI systems in the workplace, employers must carefully consider a range of legal, operational, and ethical risks. This includes navigating compliance with existing laws, managing the practical challenges of implementation and integration, and addressing the ethical implications for employees and the organizational culture. A primary concern is protecting confidential and strategic information. Many AI tools risk data leakage or unauthorized use. Employers must use vetted tools and implement policies prohibiting uploading sensitive data to unsecured platforms.
Another critical issue is the ownership and legal status of AI-generated outputs. Mexico’s law requires human authorship, creating uncertainty over employer ownership of content created by AI tools, particularly when third-party providers or external datasets are involved.
AI systems demand extreme caution in human resources. While useful, they often lack transparency and can reinforce bias, leading to unfair outcomes without human oversight. Mexico lacks specific AI regulations for hiring or monitoring, but existing labor and privacy laws prohibit discrimination and require monitoring to be proportionate.
Legislative proposals classify AI-driven employment decisions as high-risk, following international trends, often prohibiting automated decisions without meaningful human involvement.
In the interim, employers should proactively adopt internal governance frameworks for AI use. This includes defining permitted tools and use cases, classifying AI systems by risk level, ensuring human review for sensitive decisions, safeguarding data protection, and establishing internal AI codes of conduct or ethics committees. Such measures mitigate legal exposure and build a foundation for future regulatory compliance.
-
What are the main privacy/data protection issues arising from artificial intelligence development and use (including training data)? Have data protection authorities issued guidelines or rulings on artificial intelligence, and what are the key takeaways?
AI development and use raise significant privacy concerns, primarily due to their reliance on vast volumes of personal data for training and tuning. In Mexico, the former National Institute of Transparency (INAI) published non-binding Recommendations for processing personal data when using AI, offering guidance on responsible AI use, privacy by design, and compliance with data privacy principles such as transparency, consent, and purpose limitation.
Mexico’s data privacy environment is undergoing a significant transition. INAI was dissolved in 2024 and replaced by the Anticorruption and Good Governance Ministry in May 2025. Additionally, the LFPDPPP, enacted in March 2025 with its Regulations still pending, significantly strengthens data subject rights and increases obligations for data controllers and processors. While it does not introduce AI-specific regulations, its enhanced provisions on automated decision-making (including the right to object to decisions made without human intervention that produce adverse legal effect) and increased requirements for transparency and explicability are highly relevant to AI systems. A new LFPDPPP is currently being drafted by the data protection authority, set to include enhanced data protection rights and AI-related provisions.
Training AI models often involves automated profiling, biometric recognition, and algorithmic assessments. These activities are regulated under the LFPDPPP, which requires transparency and explicability for automated decisions, addressing bias and discrimination risks. However, achieving this transparency remains challenging given the “black-box” nature inherent in many AI systems.
Without a comprehensive AI framework, determining which AI systems trigger specific regulatory obligations remains challenging. Implementing robust security measures and internal controls, including comprehensive privacy policies and Data Processing Agreements (DPAs), is crucial. DPAs are particularly relevant when sharing large datasets, such as in Retrieval Augmented Generation (RAG), and should specify conditions for AI system use, security measures, data breach protocols, data retention terms, periodic audits, and parties’ obligations for non-compliance.
-
How is data scraping regulated in your jurisdiction from an IP, privacy and competition perspective? Are there recent precedents addressing the legality of data scraping for training of artificial intelligence systems?
Data scraping in Mexico is not subject to a specific, overarching regulation. Instead, its legality is assessed under existing legal frameworks, particularly those governing intellectual property (IP), privacy, and competition.
From an IP perspective: The LFDA grants owners exclusive control over reproduction and public communication of their works, including original databases based on creative selection or arrangement. Copying substantial portions of a site’s curated structure without a license infringes copyright and the ToS. Mexico lacks broad “fair use” or specific TDM exceptions, so unauthorized scrapping of copyrighted material for AI training is likely infringement. The LFDA (amended 2020) includes anti-circumvention prohibitions against bypassing TPMs, making such actions potentially illegal (with exceptions). If scraped data includes confidential business information meeting the trade secret definition, its unauthorized acquisition and use could constitute misappropriation.
From a privacy perspective: The LFPDPPP requires scrapers collecting personal data to provide notice, transparency, purpose-limitation, and secure consent and honour user’s rights. The prior regulator, INAI, joined international regulators in emphasizing that publicly available personal information remains subject to data protection laws. The SCJN recently clarified that website ToS prohibiting scraping are only binding when a user’s assent is explicit (e.g., via a clickwrap agreement), not through passive “browsewrap” terms, making clear permissions essential for contractual enforceability.
From an antitrust perspective: Preventing third parties from scraping publicly available data or content could be seen as an abuse of dominance if the information owner holds a dominant market position. This interpretation suggests restricting access to data might threaten competition if the data is considered an “essential input.” This interpretation suggests restricting access to data might threaten competition if the data is considered an “essential input.” While Mexico lacks direct precedents like the US case hiQ Labs, Inc v LinkedIn Corp (where blocking a startup from scraping LinkedIn data was challenged), similar arguments of “refusal to deal” could arise. Similar arguments of “refusal to deal” amounting to abuse of dominance could be made, as this interpretation has apparently gained traction given the growing role of data as an essential competitive tool. In a broader context, the Mexican antitrust authority’s blocking of Walmart/Cornershop (2019) partly due to the strategic use of competitors’ data highlights how data access can be viewed as an essential competitive tool.
Regarding precedents for AI training: As mentioned, the SCJN ruling on website terms is relevant. While no specific precedents directly address the legality of data scraping for AI training in Mexico, the general principles of IP, privacy, and competition law, as outlined above, would apply. The SCJN’s stance on explicit consent for terms of use is particularly important for any large-scale data collection.
-
To what extent is the prohibition of data scraping in the terms of use of a website enforceable?
While Mexico has few public cases indicating established precedent to indicate established case law or an emerging trend, the enforceability of a website’s terms of use (ToS) generally depends on how consent was obtained. Under Mexican civil law, a contractual relationship is formed when consent is given. However, recent rulings by SCJN, particularly in January and June 2025, clarify that explicit consent, such as through a “clickwrap” agreement (where users actively click an ‘Accept’ button), is generally required to bind users to the ToS. Conversely, “browsewrap” agreements (where terms are merely posted via a link, and assent is implied by continued use) are increasingly difficult to enforce, as courts emphasize the need for conspicuous notice and unambiguous user acceptance.
Therefore, the prohibition of data scraping within ToS is primarily enforceable through a breach of contract claim before civil courts, but its success hinges on proving valid consent to those specific terms. Beyond contract law, data scraping can also violate provisions of the LFDA (particularly the anti-circumvention prohibitions), the LFPDPPP, and the Federal Criminal Code, providing multiple legal grounds for a claim.
The primary challenge lies in proving: (i) that a contract was validly formed, and (ii) that scraping actually occurred. Both points typically require specialized forensic evidence, which can be difficult and costly, especially if offshore elements are involved. Given the evolving Mexican judicial system, the level of expertise in resolving these matters is still uncertain. Consequently, most companies affected by scraping prefer to initiate extrajudicial steps, such as cease-and-desist letters, before resorting to litigation.
-
Does your country have a regulator or authority responsible for supervising the use and development of artificial intelligence? What are its powers and enforcement tools?
As of July 2026, Mexico does not yet have a specific authority directly regulating or overseeing AI. However, this is expected to change soon with potential legislative developments.
Several legislative proposals have been presented in Congress advocating for creating a dedicated AI regulatory authority and adopting a risk-based governance framework. Some suggest the creation of a new regulator, or creating a council of regulatory bodies to oversee AI. However, as of the date hereof, none of these proposals have been enacted, and Mexico does not yet have a specific authority responsible for AI regulation.
Sectorial regulators still apply, including the Anticorruption Ministry for privacy, Profeco for consumer protection, IMPI and INDAUTOR for copyright, the new national competition agency for antitrust CNA, and sector-specific regulators for health, finance, education and other sectors.Separately, the Telecommunications and Broadcasting Law (LFTR), issued in 2025, replaced previous legislation and dissolved the Federal Institute of Telecommunications. Its regulatory authority has been assumed by the ATDT, reporting to the President. This Agency now oversees telecommunications, broadcasting, and digital platforms.
Although the ATDT has no express powers specifically granted for AI, it holds authority to issue regulations concerning information and communication technologies, telecommunications, and software development, which could encompass AI in the future. Furthermore, the LFTR introduced a new regulatory framework for digital platforms, broadly defined as any digital service provided by intermediaries over the Internet that offers, commercializes, or intermediates goods, services, applications, products, or content. The breadth of this definition will necessitate a case-by-case assessment to determine its applicability to various technology companies, potentially including those utilizing AI.
-
How widespread is the adoption of artificial intelligence in businesses in your jurisdiction, and which sectors are leading?
The use of AI by businesses in Mexico is growing but remains uneven across sectors. While adoption is not yet widespread, there is a clear upward trend, particularly among large companies and multinationals seeking operational efficiency, automation, and data-driven decision-making.
The sectors showing the most rapid adoption of AI technologies include:
- Financial services, where AI is being used primarily for fraud detection, transaction monitoring, chatbots, risk assessment and process automation.
- E-commerce and logistics, leveraging AI for inventory management, personalized marketing, route optimization and enhanced customer experiences.
- Media and entertainment, particularly in content generation, recommendation algorithms, and audience analytics.
- Legal and professional services, where AI tools support document review, research, and internal knowledge management.
- Manufacturing, for supply chain optimization and predictive maintenance.
Among SMEs, adoption is more limited but growing, with 64% reported to have integrated AI solutions . Many rely on free or open-access AI tools for basic tasks such as content creation, customer engagement, or internal productivity. However, concerns around data protection, cost, a lack of skilled personnel and challenges with data quality often limit more advanced or large-scale deployment.
-
How is artificial intelligence used in the legal sector, by lawyers and/or in-house counsels? Are AI-driven legal tools widely adopted, and what are the main regulatory concerns?
AI tools are increasingly being used in the legal sector in Mexico. Law firms and in-house legal departments are adopting them as support tools for tasks like contract drafting, legal research, due diligence, and litigation analysis. These tools are particularly useful for efficiently processing large information volumes, extracting key document insights, and assisting in drafting standard clauses or internal reports.
Applications span areas like M&A, litigation, regulatory compliance and transactional work. While no Mexican law firm has developed its own AI solution, some collaborate with technology providers to curate databases or fine-tune legal models for local legal sources and practices.
A key regulatory concern is ensuring AI tools use remains consistent with professional confidentiality obligations. As many AI tools are cloud-based, lawyers must verify that appropriate safeguards protect sensitive information and maintain attorney-client privilege. This encourages a thoughtful approach, focusing on secure platforms, clear internal policies, and understanding data processing and storage.
As with any emerging technology, human oversight remains essential. Lawyers are ultimately responsible for the legal work, even with AI assistance. While Mexican regulators have not yet issued specific guidance, the profession is expected to apply existing ethical standards to new tools.
AI is gradually transforming legal work, offering greater efficiency and support across tasks.
-
What are the 5 key challenges and the 5 key opportunities raised by artificial intelligence for lawyers in your jurisdiction?
Key challenges:
a. Data confidentiality, privilege and cybersecurity. AI tools often operate on external servers, raising concerns about how client information is processed, stored or reused. Lawyers must ensure that the platforms they use preserve confidentiality and respect attorney-client privilege, and hold cybersecurity best standards.
b. Protection of know-how and internal knowledge. A growing concern is whether the use of AI tools may result in the firm’s internal know-how, such as templates, analysis, or legal strategies, being absorbed into external systems. Lawyers must take steps to ensure that proprietary content is not used to train tools accessible for third parties or even competitors.
c. Cost efficiency and client perception. AI streamlines legal work, but clients may expect lower fees. High costs for advanced AI and integration challenges can hinder smaller firms. Law firms must demonstrate AI’s value and secure ROI while transparently showing how AI enhances, rather than replaces, expertise.
d. Ethical dilemmas and professional responsibility. Lawyers remain responsible for the legal accuracy of work produced with AI assistance, and there is a risk of overreliance on tools without proper review or understanding of their limitations, which can lead to issues with competence, confidentiality, and supervision when using AI-generated output or advice.
e. Regulatory uncertainty and compliance: The lack of a comprehensive AI-specific legal framework in Mexico creates ambiguity regarding liability, data governance, and ethical use. Lawyers must navigate existing fragmented laws (privacy, IP, competition) while anticipating rapid legislative changes.
Key opportunities:
a. Increased productivity and efficiency. AI can automate repetitive tasks such as due diligence, document review, contract comparison, or legal research, allowing lawyers to focus on higher-value activities.
b. Cost reduction and increased accessibility: By streamlining processes, AI can lower operational costs, potentially making legal services more affordable and accessible to a broader segment of the population.
c. Improved accuracy and risk management: AI can reduce human error in due diligence, compliance checks, and legal document generation, leading to better outcomes and reduced risks for clients.
d. Internal knowledge and competitive differentiation. AI improves access to internal knowledge by structuring and retrieving prior work. This aids junior lawyers and consistency. AI analyzes legal data to identify trends, predict outcomes, and inform strategies, providing a competitive advantage.
e. Innovation and new service offerings: AI enables the development of new legal tech solutions and service models (e.g., AI-powered chatbots for initial client intake or legal guidance, online dispute resolution tools), creating new revenue streams and specialized niches for law firms.
-
Where do you see the most significant legal developments in artificial intelligence in your jurisdiction in the next 12 months? Are there any ongoing initiatives that could reshape AI governance?
In the next 12 months, the most significant legal developments in Mexico are expected to come from legislative activity in Congress. Several AI-related initiatives have been presented, aiming to regulate the development, deployment, and use of AI systems across sectors. These proposals advocate for principles of transparency, accountability, non-discrimination, and human oversight, particularly for high-risk systems in employment, health, finance, and public services. President Claudia Sheinbaum as well as the Senate’s commission on AI have already stated that regulation is coming soon, particularly related to its use by minors.
A recurring theme in these initiatives is the creation of a national AI agency and the adoption of a risk-based regulatory model, similar to the EU’s AI Act. While these proposals remain under discussion, they signal growing momentum toward a structured governance framework.
In parallel, ongoing debates around AI-generated content, data sovereignty, and algorithmic bias are gaining relevance. Recent efforts to reform the LFDA, driven in part by actors and performers seeking protection against unauthorized AI-generated uses of their image and voice, have further shaped the regulatory landscape. The SCJN’s ruling in Amparo Directo 6/2025 confirmed that AI cannot be an author and established a key precedent on AI-generated outputs. Additional pending cases on technology and copyright may further influence future legislation.
Taken together, these developments suggest that Mexico is moving toward a more proactive stance on AI regulation. While no binding framework has been enacted yet, companies using or developing AI systems should begin aligning with international standards and strengthening internal policies to anticipate emerging obligations.
Mexico: Artificial Intelligence
This country-specific Q&A provides an overview of Artificial Intelligence laws and regulations applicable in Mexico.
-
What is the legal definition of “artificial intelligence” in your jurisdiction, if any? If no definition exists, how do regulators or courts typically describe artificial intelligence?
-
Has your country developed a national strategy for artificial intelligence? If yes, what progress has been made in its implementation? Are there plans for updates or revisions?
-
Has your jurisdiction adopted any AI-specific laws, regulations, voluntary standards, or ethical guidelines? If so, please provide a brief overview. If not, which existing laws could be/are applied to artificial intelligence and the use of artificial intelligence, what are the main interpretive challenges, and are there any pending artificial intelligence legislative initiatives?
-
Are there legal requirements for artificial intelligence transparency, explainability, or audits? Are there obligations to disclose the use of artificial intelligence to customers/clients?
-
Are there legal requirements or best practice expectations for human oversight and human-in-the-loop in artificial intelligence systems?
-
Are there specific legal or regulatory requirements addressing algorithmic bias, discrimination, or fairness in AI systems (including gender bias)?
-
What legal frameworks apply to AI-related harm and defective artificial intelligence systems? Who can be held liable (developer, deployer, victim of the damage, others), how is liability allocated, and what burden of proof applies to victims?
-
What cybersecurity obligations apply to AI systems?
-
Is the use of artificial intelligence insured and/or insurable in your jurisdiction, including with cyber policies? Are there market trends, or limitations?
-
Can artificial intelligence be named as an inventor in a patent application filed in your jurisdiction? If not, what is the current legal position?
-
Do images or works generated by and/or with artificial intelligence benefit from copyright protection in your jurisdiction? If so, who is the authorship attributed to, and under what conditions?
-
What are the main issues to consider when using artificial intelligence systems in the workplace? Have any new regulations, or guidelines, been introduced regarding AI-driven hiring, performance assessment, or employee monitoring?
-
What are the main privacy/data protection issues arising from artificial intelligence development and use (including training data)? Have data protection authorities issued guidelines or rulings on artificial intelligence, and what are the key takeaways?
-
How is data scraping regulated in your jurisdiction from an IP, privacy and competition perspective? Are there recent precedents addressing the legality of data scraping for training of artificial intelligence systems?
-
To what extent is the prohibition of data scraping in the terms of use of a website enforceable?
-
Does your country have a regulator or authority responsible for supervising the use and development of artificial intelligence? What are its powers and enforcement tools?
-
How widespread is the adoption of artificial intelligence in businesses in your jurisdiction, and which sectors are leading?
-
How is artificial intelligence used in the legal sector, by lawyers and/or in-house counsels? Are AI-driven legal tools widely adopted, and what are the main regulatory concerns?
-
What are the 5 key challenges and the 5 key opportunities raised by artificial intelligence for lawyers in your jurisdiction?
-
Where do you see the most significant legal developments in artificial intelligence in your jurisdiction in the next 12 months? Are there any ongoing initiatives that could reshape AI governance?