
Governments worldwide are racing to regulate AI. Europe has the EU AI Act, the US has executive orders and state laws, and China has comprehensive AI content rules. Mexico and Latin America are building their frameworks now — and businesses that prepare early will have a significant compliance advantage.
Mexico's Current AI Landscape
Mexico does not yet have a specific AI law as of mid-2026. The government published a National AI Strategy in 2018 and has updated it since, but binding regulation remains in development. However, existing laws already apply to AI systems, and businesses ignoring them face real risk.
The Mexican Congress has introduced AI-related bills, and regulatory action is expected in 2027. The trajectory is clear: waiting is not a strategy.
LFPDPPP: Mexico's Data Privacy Law and AI
The Ley Federal de Protección de Datos Personales en Posesión de los Particulares (LFPDPPP)is Mexico's main data privacy law. It applies to any AI system that processes personal data of Mexican residents — which means virtually any customer-facing AI application.
Key requirements under LFPDPPP for AI systems:
- —Explicit consent before collecting and processing personal data through AI interfaces
- —Privacy notice (aviso de privacidad) must describe AI processing activities
- —Purpose limitation: data collected for one AI purpose cannot be used for another without additional consent
- —Data subject rights: users can request access, correction, deletion, or processing restrictions
- —Security measures proportional to the sensitivity of data processed
- —Data breach notification requirements (INAI must be notified of significant breaches)
AI Risk Classification
| Risk Level | Examples | Required Action |
|---|---|---|
| Low Risk | FAQ chatbots, content recommendations, scheduling AI | Privacy notice + consent |
| Medium Risk | Credit scoring aids, HR screening tools, customer profiling | Impact assessment + documentation |
| High Risk | Hiring decisions, medical diagnosis, law enforcement | Strict compliance, human oversight, audits |
| Prohibited | Social scoring by government, manipulation of behavior | Cannot deploy |
EU AI Act: Indirect Impact on Mexican Businesses
Even if you operate only in Mexico, the EU AI Act affects you if: (1) you sell products or services to EU customers, (2) you use AI tools developed by EU companies that build in compliance requirements, or (3) your supply chain includes EU-based partners with AI governance requirements. Many global AI providers — Anthropic, OpenAI, Google — are building EU AI Act compliance into their enterprise offerings, which cascades to their business customers.
Your 3-Step Action Plan
Step 1 — AI Inventory: Document every AI system your business uses or plans to use. Categorize by the type of data processed and decisions made. This inventory is the foundation of any compliance framework.
Step 2 — Privacy Audit: Review your privacy notice and consent mechanisms for all AI-powered touchpoints. Ensure data processing activities are described, consent is specific, and data subject rights are honored.
Step 3 — Governance Design: Designate an AI governance owner, establish a review process for new AI deployments, and create transparency mechanisms so users know when AI is making decisions that affect them.
HEA Consulting builds compliance-first AI systems. Every client implementation includes privacy architecture review and LFPDPPP alignment from day one — not retrofitted after the fact.