AI compliance in Mexico: regulatory frameworks and what already applies to your company

Mexican regulation of artificial intelligence is not a future topic: it is a conversation that already touches your company if you process personal data, automate decisions about people, or sell to European clients.

In 2026 three levels of obligation coexist: the active Mexican framework (LFPDPPP and its regulations), the sector regulations (financial, health, telecommunications), and the demands of international clients who request voluntary certifications.

What DOES already apply in Mexico

The Ley Federal de Protección de Datos Personales en Posesión de los Particulares (LFPDPPP) applies to any AI system that processes personal data of Mexican customers. The operational consequence is concrete: if an AI agent decides on credit, segments customers, or evaluates résumés, you must explain how it does so, with what data, and let the user opt out.

The Instituto Nacional de Transparencia (INAI) has specific inspection powers over automated decisions. Its criterion is that any decision with legal effects on a person must be reviewable and explainable.

For regulated sectors: the CNBV requires traceability of AI models in credit decisions, COFEPRIS applies to AI in health, and the IFT has published criteria on AI in telecommunications services.

What does NOT apply directly (but does arrive)

The European Union AI Act is not Mexican law. If you have no European clients and no EU data, it does not bind you directly. But if you sell to European corporations, they require it contractually down the chain, so it ends up applying via a commercial clause.

The same dynamic occurs with NIST AI RMF and ISO/IEC 42001:2023: these are voluntary frameworks, but clients and partners request them as a procurement condition.

The voluntary framework that is worth adopting

ISO/IEC 42001:2023 is the first international AI management system standard. It defines governance, risk, compliance, and life cycle. Adopting it is not mandatory, but it gives you a common language with auditors, clients, and providers.

A typical implementation takes 6–12 months: inventory of AI systems, risk assessment, policy definition, technical documentation, and internal audit before seeking certification.

Four concrete actions to start with

  1. Inventory: list every AI system in production, not just the obvious ones. Include agents, scoring, OCR, classification, and text generation.
  2. Risk classification: separate the systems according to their potential impact (high if they affect rights, low if they are internal operations).
  3. Documented policy: a short document that explains what AI you use, with what data, who decides about them, and how they are audited.
  4. Human-review channel: any person affected by an automated decision must be able to request a human review. Under the LFPDPPP this is not optional.

Regulatory framework applying to personal data

In addition to the LFPDPPP there are sector guidelines that apply: the Ley Federal del Trabajo and NOM-035 for AI in HR, the CNBV rules for credit scoring, and the INAI criteria for automated decisions with legal effects.

Bottom line: there is no single “AI law in Mexico,” but there is a mosaic of obligations that are already in force and apply without any new law being needed.


Sources

[1] Cámara de Diputados — Ley Federal de Protección de Datos Personales en Posesión de los Particulares — https://www.diputados.gob.mx/LeyesBiblio/pdf/LFPDPPP.pdf

[2] ISO/IEC 42001:2023 — Information technology — Artificial intelligence — Management system — https://www.iso.org/standard/81230.html

[3] NIST AI Risk Management Framework (AI RMF 1.0) — https://www.nist.gov/itl/ai-risk-management-framework

[4] INAI México — Criteria on automated decisions — https://gob.mx/inai

[5] European Commission — AI Act overview (comparative reference) — https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai

Also in Digital World

← Back to categories