CiberLATAMbywhalemate

Mexico: 200 AI Bills, No Federal Law

Mexico has nearly 200 state-level AI proposals, but no federal general law or corporate cybersecurity framework yet.

Whalemate Labs · AI-assisted researchAug 10, 202638 min read

Mexico entered the second half of 2026 with a visible regulatory contradiction: local legislatures are holding about 200 AI-related proposals, and 39 have already been approved, while the country still has no General Artificial Intelligence Law published in the Official Gazette of the Federation. The count, presented by Manuel Haces-Aviña in a Check Point panel and cited by El Economista, also shows that Chiapas is the only state where no AI bill was identified, and that only two states have written an explicit definition of AI into local law. The message in that map is clear, the response has been fragmented, uneven and, in several cases, more punitive than technical.

Executive Summary

The hardest number in the material is also the most revealing for understanding Mexico’s current regulatory moment: roughly 200 state-level initiatives tied to artificial intelligence have been introduced in local congresses, and 39 have already been approved, while the country still has no General Artificial Intelligence Law published in the Official Gazette of the Federation. The tally, attributed to Manuel Haces-Aviña and circulated by El Economista, places Mexico in a cluttered regulatory environment. There is legislative movement, but no unified framework. States are active, but there is no federal architecture capable of aligning criteria, defining concepts, setting risk standards, and stabilizing obligations for companies and public entities.

The fragmentation is not minor. The same El Economista report says only two states have incorporated an explicit definition of artificial intelligence into their local rules. At the other extreme, Chiapas is the only state where no AI-related initiative was identified. That contrast does not point to a mature public policy, but to an uneven patchwork, with rules moving at different speeds and with approaches that change depending on the state, the subject matter, and each local legislature’s political incentives. Within that patchwork, Yucatán chose a criminal-law response, with prison terms and fines of up to 234,000 pesos for anyone who uses AI to generate or alter fake images, videos or audio to harm third parties. San Luis Potosí, by contrast, moved in the opposite direction and its Justice Committee voted to repeal criminal provisions that regulated AI use, aiming to remove sanctions tied to the technology. Between those two ends, the country shows a lack of conceptual and punitive consistency.

At the federal level, the debate is no longer just declarative. On July 24, 2026, a bill was introduced in the Chamber of Deputies to enact the Federal Law for the Ethical, Sovereign and Inclusive Development of Artificial Intelligence. That text proposes a National Artificial Intelligence Council as a decentralized public body, a National Algorithmic Audit Platform to assess and issue technical opinions on data, models and AI systems, and a risk traffic-light system to distinguish uses by their level of danger. In parallel, Gabriela Jiménez Godoy, the deputy coordinator for Morena in the Chamber of Deputies, promoted a constitutional reform to Article 73 to explicitly authorize Congress to legislate on artificial intelligence systems. Even with those initiatives, the material agrees that in 2026 Mexico still has no approved or published general law, and the proposals remain under committee review or in process.

The AI regulatory gap sits alongside a more advanced state response in public cybersecurity than in corporate cybersecurity. The National Cybersecurity Plan 2025-2030, presented in late 2025 by the ATDT with support from the IDB, lays out a phased roadmap that runs from Foundation in 2025 to Transformation in 2030. The plan includes a National Cybersecurity Operations Center, a national incident response center for the federal public administration, a critical infrastructure inventory, vulnerability assessment programs, simulation exercises, training, and the strengthening of the regulatory framework through future specific legislation. The General Cybersecurity Policy for the Federal Public Administration and the National Cybersecurity Council reinforce that institutional approach, but they do not replace a general law that applies uniformly to the entire corporate chain.

The regional picture helps measure the distance. Peru already has a specific AI law and its implementing regulation, Chile is moving ahead with a risk-based bill and also has more consolidated data and cybersecurity frameworks, Uruguay regulated state cybersecurity obligations and created a National Artificial Intelligence Center, and Paraguay still has no AI law but is facing growing pressure from incidents and sector-specific reforms. In Mexico, the debate has entered the political, technical and budgetary phases, but the result is still an incomplete architecture, with scattered rules, uneven definitions and sanctions that vary from one state to another.

México, IA y ciberseguridad, 2025 a 2026Cronología de hitos regulatorios y legislativos en México2025National PlanforCybersecuritypresentedJul 2026Federal AI lawintroducedJul 2026National debateabout minors andplatformsAug 2026200 initiativesstate reportedAug 2026Constitutionalreform inprogress
Mexico, AI, and cybersecurity, 2025 to 2026 — Sequence of regulatory and legislative milestones in Mexico, with 2026 as the turning point.

Context and Background

Mexico’s artificial intelligence file can no longer be read as a sequence of isolated legislative projects. The material shows layered rules piling up and, at times, overlapping or even contradicting one another. At the federal level, the debate revolves around two fronts. The first is the absence of a General Artificial Intelligence Law. The second is the lack of a general corporate cybersecurity law that would impose uniform minimum standards on all companies, beyond the obligations that already exist by sector or through public supply chains.

On AI, several specialized sources agree that Mexico does not have an approved and published general law. ITSitio México says so for 2026; Ecosistema Startup reinforces that in July 2026 there is still no single general law published in the Official Gazette of the Federation; Noticias PV Nayarit adds that the ordinary session ended without a committee opinion on the bills under review. At the same time, Academia de IA describes the framework as reactive regulation, built on sector-specific patches, especially in labor, copyright, education and personal data. That description fits both the volume of initiatives and the weakness of the final legal closure.

The most visible sectoral block in Mexico is tied to labor and copyright. México Prioridad reported that the May 14, 2026 reforms to the Federal Labor Law and the Federal Copyright Law aim to protect artists’ image and voice from cloning through artificial intelligence. Expansión adds that among the proposals under discussion is the idea of registering voice and image as biometric data to prove ownership of those recordings when they are cloned or reused through AI. The debate is therefore not limited to productivity or automation. It also touches identity, exploitation of personal attributes, traceability and proof of authorship.

At the same time, the issue of children and digital platforms has started to take on greater political weight. Infobae México reported that on July 20, 2026, the Government of Mexico, the SEP, UNESCO and academic specialists announced a national debate to build a legislative proposal on the use of digital platforms, artificial intelligence and social media among minors. El Financiero, days earlier, had reported President Claudia Sheinbaum’s announcement of a national debate after the World Cup. The timing matters: while the federal initiative seeks to organize a broad discussion, concrete bills continue to move slowly in Congress.

Cybersecurity follows a different institutional logic. The National Cybersecurity Plan 2025-2030 was presented by the ATDT with support from the IDB and is described as the country’s first specialized cybersecurity policy. Indusecc presents it as a phased roadmap, from Foundation to Transformation. Hub.ind.br adds that the plan includes a National Cybersecurity Operations Center, an incident response center for the federal public administration, a critical infrastructure inventory, simulation exercises and the promise of future specific legislation. Debate adds that the General Cybersecurity Policy for the Federal Public Administration led to the creation of the National Cybersecurity Council, chaired by the SSPC and made up of nine agencies, including SEDENA, SEMAR and the FGR.

That setup matters because it organizes the state, but it does not solve private-sector exposure. OneSecMX and DySE Consultores, with the caveats of their formats, describe current obligations as concentrated in federal agencies and passed indirectly to vendors and supply chains. In other words, the state sets rules for itself and pushes requirements downstream, but it has not closed the gap left by the absence of a general law that establishes uniform obligations for all companies. That is exactly the kind of gap the material returns to most often.

Key Facts Table

Date Fact Source Confidence
2026-08-06 El Economista reported around 200 state-level AI initiatives and 39 approvals in Mexico El Economista Confirmed
2026-08-06 Chiapas was identified as the only state with no known state-level AI initiative El Economista Confirmed
2026-08-06 Only two states incorporated an explicit AI definition into local rules El Economista Confirmed
2026-08-06 Mexico’s general AI law remains pending El Economista Confirmed
2026-07-24 A bill to create the Federal Law for the Ethical, Sovereign and Inclusive Development of AI was introduced in the Chamber of Deputies ITSitio México Confirmed
2026-07-24 The bill proposes a National AI Council ITSitio México Confirmed
2026-07-24 The bill proposes a National Algorithmic Audit Platform ITSitio México Confirmed
2026-07-24 The bill includes a risk traffic-light system ITSitio México Confirmed
2026-08-04 The Budget Committee approved impact opinions, including one on ethical AI use Hoja de Ruta Digital Confirmed
2026-08-04 The ethical AI use bill estimated an impact of 286,949,153 pesos in 2026 Hoja de Ruta Digital Confirmed
2026-07-28 San Luis Potosí moved to repeal sanctions for AI use Heraldo de México Confirmed
2026-08-08 México Prioridad reported that Yucatán reformed its Penal Code to punish AI deepfakes México Prioridad Confirmed
2025-12 The National Cybersecurity Plan 2025-2030 was presented Indusecc Confirmed
2026-07-14 The plan includes a CNSOC and a national incident response center hub.ind.br Confirmed
2026-08-06 The federal framework was reinforced with a National Cybersecurity Council Debate Confirmed
2026-07-31 In Peru, the PCM said there is no legal authorization to use AI in administrative sanctions Infobae Perú Confirmed
2026-07-29 Chile has a risk-based AI bill in legislative process Ecija Confirmed
2026-07-15 Uruguay launched its National Artificial Intelligence Center Búsqueda Confirmed

Operation Timeline

Date Event Actor/vector Verified source
2026-07-10 President Claudia Sheinbaum announced a national debate on AI and digital platform regulation Federal executive branch El Financiero
2026-07-20 The Government of Mexico, SEP, UNESCO and specialists announced a national debate on minors, AI and social media Public sector and academia Infobae México
2026-07-22 The Chamber of Deputies Science, Technology and Innovation Committee advanced AI bill proposals focused on children Federal legislature La Crónica de Hoy
2026-07-24 The Federal Law for the Ethical, Sovereign and Inclusive Development of AI was introduced Chamber of Deputies ITSitio México
2026-07-24 The AI bill was estimated to have a budget impact in 2026 Budget Committee Hoja de Ruta Digital
2026-07-25 Noticias PV Nayarit reported the ordinary session closed without a general AI law Federal Congress Noticias PV Nayarit
2026-07-28 Ecosistema Startup reported 85 federal AI-related initiatives, 67 still pending Ecosistema Startup, Universidad Anáhuac Ecosistema Startup
2026-08-03 ITSitio reiterated that Mexico has no approved and published general AI law Specialized sector ITSitio México
2026-08-04 Hoja de Ruta Digital reported a budget impact opinion of 286,949,153 pesos Budget Committee Hoja de Ruta Digital
2026-08-06 El Economista reported about 200 state initiatives and 39 approvals Local legislatures El Economista
2026-08-07 Gabriela Jiménez Godoy introduced a constitutional reform to Article 73 Congress of the Union El Economista
2026-08-08 México Prioridad reported Yucatán reforms to punish deepfakes Local legislature México Prioridad
Comparativo regional de madurezLínea comparativa de hitos regionales en IA y ciberseguridadPeru 2023AI Lawenacted andregulatedChile 2026Bill based onrisk levelsUruguay 2026National centerCentro nacionalof AI anddecrees MCUMexico 2026200initiativeswithout lawgeneral
Regional maturity comparison — Peru, Chile, Uruguay, and Mexico show different levels of regulatory closure in AI and cybersecurity.

Attack Chain and TTPs

The material does not describe an intrusion campaign, a single malicious operation or a discrete technical incident. There are no published IOCs, no hashes, no domains, no IP addresses, no attributed malware and no concrete exploitation vectors. For that reason, a classic attack-chain reconstruction would not be honest. What the research does allow is a different reading, one focused on a chain of regulatory and operational exposure that leaves companies, states and citizens with uneven coverage against AI and cybersecurity risks.

That chain starts with the lack of a general framework. In Mexico, the absence of a General Artificial Intelligence Law leaves each state to produce its own response, often in the form of criminal-law initiatives or incomplete definitions. At the federal level, the lack of a general corporate cybersecurity law means obligations are concentrated in the state and then cascade to contractors, suppliers and sectors regulated by other rules. The result is a compliance surface that is hard to map, with different criteria across jurisdictions and gray areas in the value chain.

In that context, the relevant TTPs are not malware-based but policy- and compliance-based. The most visible risk technique is regulatory fragmentation. Yucatán criminalizes AI uses that generate or manipulate fake content, while San Luis Potosí is moving to unwind sanctions. The state-by-state count shows that only two states explicitly defined what they mean by AI. That means the same system can be treated very differently depending on the jurisdiction. For a company operating in several states, the problem is not only legal. It is also operational, because internal policies on AI use, evidence retention, traceability and incident response can be subject to uneven local rules.

The second exposure layer is opacity around in-house and third-party systems. El Economista says that, without a general law, companies operate under sector-specific obligations with limited oversight over the AI systems they use. That points to a concrete weakness. Many organizations consume third-party tools, models embedded in cloud services, or automations integrated into enterprise software without a robust inventory of models, data, purposes and risks. Without a general standard, the definition of minimum controls gets scattered across privacy, labor, copyright, consumer issues and supplier contracts.

The third layer is the asymmetry between innovation and supervision. ITSitio and Expansión point to a federal architecture that proposes a National AI Council, an algorithmic audit platform and a risk traffic-light system. That suggests an attempt to move away from a purely reactive model toward one based on classification and technical oversight. But the material does not yet show the legal translation of that proposal. It also does not show a consolidated operating authority, audit procedures or published rules for interoperability with states, companies and sectors.

Normative TTP Matrix

TTP Description Source
Regulatory fragmentation Multiple state initiatives without a unified federal framework El Economista
Inconsistent definition Only two states reportedly incorporated an explicit AI definition El Economista
Selective criminalization Yucatán sanctions deepfakes and content manipulation México Prioridad
Partial decriminalization San Luis Potosí moves to repeal sanctions tied to AI use Heraldo de México
Proposed algorithmic audit National council and platform for technical opinions ITSitio México
State cybersecurity management 2025-2030 plan and General Policy for public administration Indusecc, Debate
No uniform corporate framework No general cybersecurity law for the private sector Debate, OneSecMX
Matriz TTPs normativasMatriz de tácticas normativas observadas en el materialFragmentation200 initiativesstateSelective sanctioningYucatán penalizesdeepfakesDecriminalizationSan Luis Potosírepeals sanctionsGovernanceGuidance andAI auditingPublic cybersecurity2025-2030 Plan, CNSOC, incident response, future regulatory framework
Normative TTP Matrix — The main observable tactics are fragmentation, decriminalization, proposed auditing, and state control.

Regional Impact

Regional Overview

The regional comparison shows that Mexico’s problem is not a total lack of activity, but the absence of a regulatory closeout. Peru already deployed a specific AI law and a regulation that took effect in January 2026, with concrete obligations for high-risk systems and explicit prohibitions on mass surveillance without legal basis, individual crime prediction and autonomous lethal systems. Chile is processing a risk-based AI bill and pairs it with Personal Data Law 21.719, which governs automated decisions and profiling. Uruguay combined reforms on state cybersecurity, a national AI center and specific rules for automated systems in delivery and transport platforms. Mexico, by contrast, is still debating the core framework while continuing to accumulate state and sector-specific initiatives.

The cybersecurity contrast is similar. Uruguay requires public bodies to file annual reports on their cybersecurity status and send them to Agesic, in addition to complying with the Uruguayan Cybersecurity Framework. Chile, based on the available material, appears as a more integrated jurisdiction across data, cybersecurity and incident response. Mexico, meanwhile, is building a cybersecurity policy for its federal public administration, with future specific legislation still under development. That leaves companies in an intermediate position, with indirect obligations if they supply the state, but without a comparable general framework for all sectors.

Mexico

Mexico concentrates the largest volume of material and also the greatest regulatory dispersion. The figure of nearly 200 state initiatives, with 39 approved, reflects intense political activity but also a lack of convergence. Some states are advancing through criminal law, others are trying out definitions, others are repealing sanctions, and several have no recorded proposals at all. Yucatán chose to punish the generation or manipulation of fake images, videos or audio through AI with prison and fines of up to 234,000 pesos. San Luis Potosí moved toward repealing criminal sanctions linked to the technology. The result is a map with diverging rules for very similar uses.

At the federal level, the legislative sequence is not trivial. On July 24, the bill for the Federal Law for the Ethical, Sovereign and Inclusive Development of AI was introduced. The same text seeks a National Artificial Intelligence Council, a National Algorithmic Audit Platform and a risk traffic-light system. Days later, Gabriela Jiménez Godoy introduced a constitutional reform to Article 73 to give Congress explicit authority in the area. But the operational fact remains the same, there is no general law approved or published. In addition, the specialized publication ecosystem, including Academia de IA, Ecosistema Startup and ITSitio México, agrees that the debate is still in process.

Federal cybersecurity is moving at a different speed. The National Cybersecurity Plan 2025-2030 and the General Cybersecurity Policy for the Federal Public Administration create a clearer institutional setup for the state. There is an annual roadmap, an operations center, an incident response center, a critical infrastructure inventory and a provision for future legislation. However, the material also makes a gap visible. There is no general corporate cybersecurity law that unifies requirements for companies outside the state perimeter, nor a general AI framework that orders audits, risk classification and responsibilities on a national scale.

Esquema mexicano de regulaciónFlujo de regulación estatal y federal en MéxicoStates~200 initiatives39 approvedFederal CongressGeneral law pending2 bills in SenateCybersecurity2025-2030 planGeneral APF policyOperational impactheterogeneous local rules, sector-specific obligations, and indirect burden for providersno single framework for companies or for AI as its own category
Mexican regulatory framework — Mexican action is split between state and federal levels, with AI and cybersecurity measures moving in parallel.

Peru

Peru is the clearest benchmark in the material for comparing regulatory speed. Law No. 31814 was enacted in July 2023 and strengthened with a regulation approved in September 2025 and effective since January 2026. According to the sources, the rule classifies systems by risk level, prohibits certain high-impact practices and requires human oversight for high-risk uses. In health, education, justice, security, the economy and finance, enhanced obligations begin to apply on September 10, 2026. There is also a staggered timetable for other sectors and for certain public actors.

The combination of law, regulation and deadlines makes Peru look like a more closed regulatory governance model than Mexico. The material also shows limits, because Infobae Perú reported that there is no legal authorization to use AI in administrative sanctioning. In other words, the country is not opening the door to automating sanctions without an explicit legal basis. AI can improve public services and streamline internal processes, but it cannot simply replace the legal framework in administrative punishment.

Chile

Chile still does not have an approved specific AI law, but it does have a bill in process with a risk-based approach. Ecija describes four categories, unacceptable risk, high risk, limited risk and no evident risk. Nodo.build adds that Personal Data Law 21.719, which it says has been in force since December 2024, regulates automated profiling, algorithmic decisions and recognizes a right to object to decisions based on AI. The country shows a more coherent structure between data and future AI controls, although the material also includes claims from sources that are not fully confirmed about Chile’s regional leadership in cybersecurity.

For comparative analysis, Chile works as an intermediate model, but one more structured than Mexico. It has a risk-language AI bill, a personal data law that addresses automated decisions and an incident response infrastructure recognized by LACNIC. That does not mean regulation is complete, but it does mean the baseline looks more integrated.

Paraguay

Paraguay combines regulatory lag with operational activity in cybersecurity. It does not have a promulgated AI law or an approved national strategy, although MITIC and CONACYT are developing the topic. MuchoTexto says there is no approved document, no budget allocation and no designated AI authority. At the same time, the country is seeing real incident pressure, with 8,309 reports and 4,109 cybersecurity incidents handled by CERT-PY between January 2023 and July 2026. So far in 2026, nearly half of attacks affected the private sector and more than a third hit the public sector.

The material also shows sector-specific responses. Paraguay has an electronic trust services law, a personal data protection law aligned with GDPR, and debates over e-commerce reform that seek to incorporate AI, strengthen cybersecurity and eliminate gray areas in sales over WhatsApp. Public policy exists, but it still has not turned into an integrated AI framework. That is why the country appears behind in the ILIA index and at the same time active in partial measures.

Uruguay

Uruguay shows a more mature institutional cybersecurity structure and an AI agenda focused on development. Decree 66/025 requires covered entities to comply with the Uruguayan Cybersecurity Framework, while the 2026 accountability process requires annual reports on each public agency’s cybersecurity status. On the AI side, the government launched the National Artificial Intelligence Center, with public-academic leadership and IDB funding. The country also maintains specific rules for automated systems in delivery and transport platforms, with information duties, algorithmic explanations and risk assessments.

Uruguay does not appear in the material as having a closed general AI law, but it does stand out as a country where the state has already institutionalized important parts of the issue, especially in the relationship between algorithms, labor, information security and national research capacity. That combination places it, in the material, ahead of Mexico in cybersecurity organization and closer to a structured public policy on automation.

United States

The United States still does not have a federal AI law equivalent to the European one. RecMedia describes an active debate between the federal government and the states, while Talla Política emphasizes a sectoral and competitive approach, supported by executive orders and by existing agencies such as antitrust, commerce and civil rights. In the context of the US-Mexico-Canada Agreement, Buzos characterizes the U.S. position as zero regulation, although that source stays in the opinion space of the material. For Mexico, the point matters because of trade weight and because it helps explain pressure to avoid overly rigid frameworks.

Countries without consolidated coverage in the material

There are no additional verifiable facts in the research for Argentina, Bolivia or Colombia.

Technical Indicators

No technical IOCs were published in the compiled material. There are no hashes, domains, IP addresses, exploit paths, malware signatures or forensic samples tied to a specific incident. The available input is regulatory, institutional and comparative, not forensic or operational.

Analysis for Security Teams

For security teams, the Mexican case is more about mapping legal obligations than about hunting threats. The priority is not just technical controls, but also identifying which duties apply in each state, which sectors were affected by labor or copyright reforms, and which AI or cybersecurity clauses are already being pushed down to government suppliers. A company operating across several Mexican jurisdictions cannot assume that one state’s local rule covers the whole country. Yucatán, San Luis Potosí and other local congresses can impose or remove sanctions, change definitions, or leave interpretive gaps. That requires building compliance matrices by territory, by data type and by use case.

At the same time, it is worth separating three layers that the public debate keeps mixing together: generative AI, algorithmic automation and corporate cybersecurity. Mexico’s legislative reaction is focused on deepfakes, voice and image cloning, automated decisions and AI use with minors. The technical response cannot be reduced to a single privacy control. It needs a model inventory, risk assessment by use case, input traceability, controls over vendors and human review procedures where employment, education, service access or administrative processes may be affected.

The cybersecurity front has its own urgency. The 2025-2030 National Plan and the General Policy for the Federal Public Administration create direct requirements for federal agencies and indirect ones for contractors. Companies working with government need to review contract terms, business continuity, incident reporting, ISO/IEC 27001 controls and response programs. In practice, the regulatory perimeter does not stop at the public agency portal. It extends to vendors, integrators, platforms and outsourced services. If there is no general corporate cybersecurity law, the real standard will be the one imposed by public customers and sensitive supply chains.

For organizations with regional exposure, the comparative map also matters. Peru already imposes obligations by risk level and specific deadlines. Chile is moving in the same direction, with risk categories and automated decisions under the umbrella of data protection. Uruguay already requires annual cybersecurity reporting and is expanding national AI capabilities. Paraguay, despite lacking an AI law, faces enough cybersecurity incidents to push reforms in e-commerce, digital identity and response capacity. These are not equivalent countries, and treating them as if they were creates compliance mistakes.

Flujo de cumplimiento empresarialProceso de cumplimiento frente a reglas fragmentadas de IA y ciberseguridadLocal inputsYucatán, SLP, othersAI inventorymodels, data, vendorsRisk assessmenttraffic lights and audit trailControlsTTPs, clauses, evidenceOutcomecompliance by jurisdiction, not a uniform countrywide rule
Enterprise compliance flow — From local fragmentation to indirect pressure through public contracts and supply chains.

Material Limitations

The file does not include the full text of the Mexican bills, their committee opinions, or consolidated versions of the local reforms. For that reason, it is not possible to reconstruct each state initiative article by article or confirm whether all the budget impact figures have already been turned into operational approvals.

There is also no isolated technical incident that would allow for a campaign narrative with verifiable IOCs. The available material is regulatory and public-policy oriented. As a result, the attack-chain section was limited to a chain of regulatory and operational exposure, not a forensic intrusion.

Several claims in the research are marked by the source itself as uncertain. In particular, some regional comparisons about cybersecurity leadership, or mentions of state attribution in Paraguayan incidents, should be read cautiously. That uncertainty has been preserved in the body of the report.

There is also a timing mismatch. Some sources come from different days in July and August 2026, while others are institutional references without a precise date or with their own internal chronology. The report prioritized confirmed facts and placed less weight on assertions that were not corroborated by more than one source or that were framed as editorial opinion.

Sources

View all