October 1, 2026 | By Martha Villalobos and Hector Noriega
This article is featured in the 4th edition of IR Global’s The Visionaries – A Roadmap for Resilience.

How can businesses in your jurisdiction adopt AI and automation responsibly, and what guidance are you offering to ensure regulatory compliance?
Like other nations, Mexico faces enormous challenges in achieving ethical AI development. Mexico is characterised by having a legal framework that protects due process rights with a human rights perspective, which is undoubtedly applicable to issues and problems arising from AI. However, there is no specific legislation for AI. Certain provisions within the existing legislation are applicable to AI, even if not explicitly stated. Among the norms with indirect impact on AI regulation are:
- The principles of equality and non discrimination established in the Political Constitution of the United Mexican States and various other laws.
- The Federal Law on Protection of Personal Data Held by Private Parties, which sets principles and norms for the protection of personal data, also applicable to data used in AI systems.
- The Federal Law to Prevent and Eliminate Discrimination, which establishes non-discrimination principles applicable to AI.
- International human rights instruments, which form part of the normative framework applicable in Mexico under Article 133 of the Constitution, also play a role. According to the Supreme Court of Justice of the Nation, international treaties are part of the legal framework and take precedence over federal and local laws. Instruments like the Universal Declaration of Human Rights protect privacy and personal image, prohibit arbitrary interference in private life, family, home, and correspondence, and prevent attacks on honour and reputation.
Although there is no specific AI regulatory authority, various public entities have powers to influence AI governance, such as the Federal Telecommunications Institute (IFT) and the Secretariat for Anti-Corruption and Good Governance.
In matters of privacy, data transparency, and access to information, Mexico has a coordinated normative and institutional framework led by the Secretariat for Anti-Corruption and Good Governance, constitutionally tasked with guaranteeing two fundamental rights: access to public information and protection of personal data. This ensures that any federal authority, autonomous bodies, political parties, trusts, public funds, and unions, or any individual or entity receiving and using public resources or performing acts of authority, must provide the public information requested. Standards of open data and open government must also be adopted. It guarantees the protection and proper use of personal data, as well as the exercise and safeguarding of the rights of access, rectification, cancellation, and opposition that everyone has concerning their data.
Responsible adoption of AI and automation by businesses in Mexico then requires a careful analysis of the potential impact of the AI to be adopted, considering the general legislation in effect. While the lack of express legislation may be perceived as an advantage by businesses, the reality is that such circumstance requires businesses to reinterpret existing, well known laws, in sought of their potential applicability to AI.
What are the key risks of implementing AI, from data privacy to ethical concerns, and how can you help businesses in your jurisdiction navigate these complexities?
While tools and applications based on AI abound in our environment, helping us obtain information, make decisions, pay taxes, and even secure loans and jobs, in its current form, AI replicates and amplifies many of the social challenges we face. Around one-third of the global population still lacks adequate internet access. Additionally, the AI industry is highly concentrated in just two countries, United States and China, and only a dozen companies encompass a significant portion of the sector. This concentration can only lead to greater inequality of outcomes, including gender disparities. Non-diverse AI teams, unrepresentative data, and opaque or biased algorithms can cause harm, especially to populations already vulnerable. Therefore, key risks are liabilities or conflict derived from AI’s unwanted outcomes leading to discrimination, gender disparities, unethical use and unwanted disclosure of private information, among others.
Are you seeing any trends in AI-driven disputes or liability concerns? How can firms assist clients in addressing potential AI-related litigation or regulatory scrutiny?
Since the various AI applications currently available are relatively new, no specific trends regarding litigation on this topic have yet been observed in Mexico. Over a decade ago, the implementation of regulations on the use and processing of personal data had a positive impact on protecting individuals’ rights and, naturally, led to disputes and the imposition of sanctions. Similarly, as the use of AI progresses and becomes more
prevalent, potential liabilities arising from its use will become more visible, inevitably leading to conflict. Given the current lack of judicial or regulatory precedents related to AI use, preventive measures such as analysis and monitoring are of utmost importance to safeguard businesses seeking to adopt automation and AI mechanisms.
KEY TAKEAWAYS
- Since the various AI applications currently available are relatively new, no specific trends regarding litigation on this topic have yet been observed in Mexico. Over a decade ago, the implementation of regulations on the use and processing of personal data had a positive impact on protecting individuals’ rights and, naturally, led to disputes and the imposition of sanctions. Similarly, as the use of AI progresses and becomes more prevalent, potential liabilities arising from its use will become more visible, inevitably leading to conflict. Given the current lack of judicial or regulatory precedents related to AI use, preventive measures such as analysis and monitoring are of utmost importance to safeguard businesses seeking to adopt automation and AI mechanisms.
- AI systems may perpetuate existing inequalities or infringe on data privacy. Without clear oversight, businesses risk ethical violations and reputational harm. Licensing agreements should address bias, restrict data misuse, and clearly assign liability. Continuous monitoring is essential.
- While AI-specific disputes in Mexico are still nascent, parallels with past data protection enforcement suggest that AI use will eventually lead to regulatory and legal scrutiny. Proactive risk assessments, compliance reviews, and contractual protections offer the best defence.