Mexico - AI Use in Public Security (2025)

Bill authorizing/setting rules for AI use in public security investigations

Iniciativa que adiciona disposiciones para el uso de Inteligencia Artificial por unidades de seguridad pública

Mexico

RAI-MX-NA-IQADPXX-2025
Proposed(Officially filed for action)
BillGovernance and OversightData Protection and Privacy
Export PDF

Proposed amendment (presented 4 March 2025) to add an Article 8 Bis to the Federal Law Against Organized Crime authorizing public security units to use artificial intelligence (AI) for investigation, identification and analysis of organized crime. The initiative defines permitted AI uses (predictive analytics, communications and financial monitoring, biometric recognition, risk evaluation, inter-agency data integration) and requires adherence to principles of legality, proportionality, effectiveness and respect for human rights, with supervision by the Secretaría de Seguridad y Protección Ciudadana.

Summary

This proposed initiative, presented to the Chamber of Deputies on 4 March 2025 by Deputy Ricardo Sóstenes Mejía Berdeja (PT), seeks to add an Article 8 Bis to the Ley Federal contra la Delincuencia Organizada (Federal Law Against Organized Crime) to expressly permit and define use of Artificial Intelligence (AI) tools by public security units. The amendment lists illustrative areas of application—predictive analysis of crime patterns using historical data; real-time monitoring and analysis of communications and financial networks linked to criminal groups; deployment of facial recognition and biometric systems in high-incidence zones; risk assessment in suspicious financial operations; automation and optimization of investigative processes; the use of machine learning to identify modus operandi; and the construction of optimized inter-institutional AI-enabled databases to improve prevention and operational response. Context: The initiative arises against a background of Mexico's national security strategy that emphasizes strengthening intelligence and investigative capacities. Proponents argue AI offers efficiency and precision gains for complex investigations of organized crime. The text frames AI adoption as a tool to modernize enforcement, improve interagency coordination, and reduce impunity, while stating the need to observe principles such as legality, proportionality, opportunity, progressivity, efficacy and efficiency, and to ensure full respect for human rights. Governance and supervision: The draft assigns supervisory responsibility to the Secretaría de Seguridad y Protección Ciudadana (SSPC) for implementation and operation, and envisages protocols securing the processing of information and AI-generated products to prevent misuse and privacy breaches. However, the initiative as published is concise and primarily declaratory: it authorizes AI use and lists areas of use and high-level principles but does not set out detailed procedural safeguards, mandatory impact assessments, auditing regimes, or specific redress mechanisms. Consequently, major governance questions remain open: Who conducts algorithmic impact assessments? What standards apply to biometric systems (accuracy, bias testing, false positive controls)? How is inter-jurisdictional data sharing governed? What transparency and documentation are required for automated decisions affecting liberty or rights? Legal interactions and risks: The initiative must be read alongside Mexico's data protection regimes (notably the Ley General de Protección de Datos Personales en Posesión de Sujetos Obligados for public sector data and the Ley Federal de Protección de Datos Personales en Posesión de los Particulares for private-sector datasets), the newly published Ley del Sistema Nacional de Investigación e Inteligencia en Materia de Seguridad Pública (which creates confidentiality/reservation classifications for intelligence products), and human-rights obligations under the Constitution and international treaties. Risks include biometric mass surveillance, discriminatory policing via biased models, opaque automated decision-making, mission creep in scope of surveillance, security of sensitive databases, misuse of inter-agency databases, and insufficient judicial or administrative oversight. Implementation considerations: To operationalize the intent while protecting rights, the bill would need implementing regulations and operational standards: clear definitions, risk-based categorization of AI applications, mandatory algorithmic impact assessments for high-risk uses (especially biometric recognition and predictive policing), independent auditing and documentation requirements, retention and minimization rules, cybersecurity baseline requirements, procurement and vendor accountability clauses, training for operators on human-rights compliant use, mechanisms for individual redress and oversight by autonomous data-protection and transparency authorities, and public reporting requirements. Stakeholder reaction: Human-rights and privacy advocates are likely to request explicit prohibitions on indiscriminate facial recognition, mandatory human-in-the-loop safeguards, transparent impact assessments, and judicial oversight for intrusive uses. Security agencies and proponents will emphasize operational benefits in disrupting organized networks. Judicial and legislative committees will need to reconcile national security confidentiality with transparency and redress obligations to ensure constitutional compliance. Conclusion: The March 4, 2025 initiative marks a clear legislative push to authorize AI in public security work in Mexico. As drafted it provides high-level authorisation and principles but leaves material details to subsequent regulation or implementing decrees. To reduce legal and rights-based risk, complementary instruments (regulations, technical standards, oversight mechanisms, civil-society participation) are recommended before large-scale deployment of high-risk AI systems in policing and intelligence contexts. Primary source: Gaceta Parlamentaria (4 Mar 2025) and legislative information system records at SITL - Chamber of Deputies initiatives listing.

Full article

Read full text ↗

Overview

The initiative presented on 4 March 2025 proposes to add Article 8 Bis to the Ley Federal contra la Delincuencia Organizada to expressly permit and frame the use of Artificial Intelligence (AI) by public security units for activities related to the investigation, identification and analysis of organized crime. The published text sets out illustrative applications—predictive analytics, communications and financial network monitoring, facial recognition and other biometric systems, suspicious-transaction risk assessment, workflow automation, machine-learning tools for identifying modus operandi, and AI-optimized inter-institutional databases. The legislative text and accompanying exposition of motives are available in the official publication: Gaceta Parlamentaria, 4 Mar 2025. The initiative is also listed in the Chamber of Deputies' information system: SITL initiatives index. The overview explains the policy rationale (strengthening intelligence and investigative capabilities to combat organized crime) and highlights the stated commitment to observe principles such as legality, proportionality, opportunity, progressivity, efficacy and full respect for human rights.

Definitions

The initiative's operative proposal is concise: it authorizes "the unit and the institutions in charge of public security" to use AI for defined investigative purposes. While the draft lists application domains, it includes no comprehensive statutory definitions for technical terms such as "artificial intelligence", "automated decision", "biometric processing", "high-risk system" or "human-in-the-loop". Implementers will need to rely on cross-references to other instruments and internationally accepted definitions (e.g., OECD and IEEE references) or on secondary regulations to ensure a shared interpretive framework between security agencies, data-protection bodies and courts.

Governance and Institutional Framework

The proposal names the Secretaría de Seguridad y Protección Ciudadana (SSPC) as the supervising authority for the implementation and operation of AI uses in public security. However, the text does not create a new independent oversight body or establish procedural safeguards such as mandatory prior authorizations, inter-institutional oversight committees, independent audits or parliamentary review. The initiative must therefore be read alongside existing institutions: the Federal Executive through SSPC, the Cámara de Diputados (via Commission of Justice during parliamentary processing), and autonomous agencies such as the Instituto Nacional de Transparencia, Acceso a la Información y Protección de Datos Personales (INAI) which enforces transparency and data-protection norms for public-sector processing. For coherent governance, the law should define roles and coordination mechanisms between SSPC, INAI, the Fiscalía General de la República (FGR) for prosecution-related uses, and the courts for judicial oversight.

Key Focus Areas

Detailed policy and technical focus areas required to operationalize the initiative include: (1) Legal basis and individual rights safeguards — ensuring that any intrusive use (e.g., biometric recognition) has express legal basis, temporal limits, judicial authorization where liberty is affected, and accessible remedies; (2) Data protection and minimization — application of the Ley General de Protección de Datos Personales en Posesión de Sujetos Obligados to limit collection, retention and secondary uses; (3) Algorithmic risk management — mandatory AI impact assessments (privacy, nondiscrimination, accuracy), bias testing, and acceptance thresholds for deployment in law-enforcement contexts; (4) Transparency and documentation — maintaining auditable model cards, training-data provenance, decision-logs and change-control records; (5) Cybersecurity and model security — baseline controls for model integrity, provenance and access controls to avoid tampering or exfiltration; (6) Vendor and procurement standards — contractual clauses for audit rights, explainability, liability allocation and data-handling obligations; and (7) Human oversight — clear human-in-the-loop requirements for actions that materially affect individual rights. These areas are necessary because the initiative as drafted provides authorization but not the procedural or technical guardrails needed to mitigate documented harms (false positives, discriminatory outcomes, mission creep, and mass surveillance).

Implementation Framework

To translate the statutory authorization into lawful practice, an implementation framework would typically include: (a) secondary regulations or technical guidelines issued by SSPC in coordination with INAI and the Attorney General's Office; (b) mandatory risk-classification of AI systems (low, medium, high risk) with higher scrutiny for intrusive categories (biometrics, predictive policing); (c) pre-deployment AI impact assessments that must be reviewed by an independent auditor or oversight unit; (d) registration or inventory of AI systems used by public security units and a public summary registry of non-sensitive features; (e) standardized procurement and contracting templates requiring vendor transparency and security warranties; (f) operator training, certification, and recordkeeping obligations; and (g) judicial or administrative authorization procedures for system use in specific cases (e.g., bulk biometric searches). International technical norms (ISO/IEC) and regional guidance (OECD, Council of Europe) should inform these instruments.

Monitoring and Evaluation

Monitoring should include continuous performance evaluation, bias audits, periodic independent reviews, and public reporting. Key measurable indicators would be false-positive/false-negative rates for biometric systems, accuracy of predictive models, incident reports of misuse, number and outcome of automated-based operational actions (stops, arrests), and data-breach incidents. An independent oversight mechanism (audit unit within SSPC with public reporting obligations and INAI coordination) would help provide accountability. These monitoring outputs should be available in anonymized form to civil-society reviewers and to specialized parliamentary committees, balancing operational secrecy with rights-protective transparency.

Penalties, Liability, and Appeals

The initiative as published does not detail penalties or remediation mechanisms. For responsible implementation, the legal package should include administrative sanctions (fines, suspension of systems, revocation of procurement contracts) for non-compliance with data-protection and auditing obligations, disciplinary measures for public servants who misuse systems, and criminal liability in cases of willful abuse leading to rights violations. It should also guarantee individual remedies: judicial review, expedited appeals, data-correction and deletion rights, and clear processes for contesting automated decisions impacting liberty or legal status.

Relationship to Other Instruments

The proposed amendment intersects with multiple existing and recent instruments: the Ley General de Protección de Datos Personales en Posesión de Sujetos Obligados (public-sector data protection), the Ley del Sistema Nacional de Investigación e Inteligencia en Materia de Seguridad Pública (published July 2025), the Ley de Seguridad Nacional (classification of intelligence information), applicable provisions of the Código Penal Federal concerning illegal access and misuse of systems, and administrative procurement and contracting rules. Coherence and hierarchy must be clarified — notably how confidentiality regimes for intelligence reconcile with transparency and data-protection obligations and how judicial oversight applies to AI-enabled investigative actions.

International Alignment

The initiative should be aligned with evolving international norms: the Council of Europe and EU guidance on biometric mass surveillance, the OECD Principles on AI, and recommendations by human-rights bodies. Alignment requires adopting internationally accepted risk-assessment methodologies, model-evaluation standards, and vendor due-diligence practices. Cross-border data flows (e.g., cloud hosting or third-party models trained abroad) create additional legal and security considerations to be addressed via contractual safeguards and export-control-like measures for specialized AI systems.

Implementation Timeline

MilestoneTarget DateNotes
Initiative formally presented (Gaceta Parlamentaria)2025-03-04Gaceta Parlamentaria (4 Mar 2025)
Turned to Commission of Justice2025-03-04SITL - initiatives listing
Commission review, hearings & technical consultations3–6 months after referralExpected stakeholder hearings with SSPC, INAI, civil society, academia
Draft secondary regulations / technical standards6–12 months after approvalNeed coordination with INAI and procurement authorities
Pre-deployment audits & registrationConcurrent with regulationsHigh-risk systems must complete AI impact assessment before use

Sources and References

SourceType
Gaceta Parlamentaria — Iniciativa que adiciona el artículo 8 Bis a la Ley Federal contra la Delincuencia Organizada (4 Mar 2025)Primary Source
SITL — Chamber of Deputies initiatives listing (entry for Mejía Berdeja, 4 Mar 2025)Primary Source

Requirements for a company

What an organisation has to do under Mexico - AI Use in Public Security (2025), at a glance. Not legal advice — the table below gives the provision and deadline for each item.

Not yet in force (Proposed). These requirements apply once the instrument takes effect and may change before then.

Must do

6
  • Ensure AI use fully respects human rights.Public security units using AI.
  • Ensure AI use adheres to the principle of legality.Public security units using AI.
  • Ensure AI use adheres to the principle of proportionality.Public security units using AI.
  • Use AI systems solely for investigation, identification, and analysis of organized crime.Public security units using AI.
  • Operate AI systems under the supervision of the Secretaría de Seguridad y Protección Ciudadana (SSPC).Public security units using AI.
  • Ensure AI use adheres to the principle of effectiveness.Public security units using AI.

Must not do

0

Nothing in this category.

Should do

0

Nothing in this category.

Should not do

0

Nothing in this category.

Who must do what

The obligations under Mexico - AI Use in Public Security (2025), most serious first. Not legal advice — verify against the official text before relying on it.

#WhoRequirementBy whenWhereSeverity
1Public security units using AI.Ensure AI use fully respects human rights.
requires adherence to principles of legality, proportionality, effectiveness and respect for human rights
Before deploymentArticle 8 Bis (proposed)Critical
2Public security units using AI.Ensure AI use adheres to the principle of legality.
requires adherence to principles of legality, proportionality, effectiveness and respect for human rights
Before deploymentArticle 8 Bis (proposed)Critical
3Public security units using AI.Ensure AI use adheres to the principle of proportionality.
requires adherence to principles of legality, proportionality, effectiveness and respect for human rights
Before deploymentArticle 8 Bis (proposed)Critical
4Public security units using AI.Use AI systems solely for investigation, identification, and analysis of organized crime.
authorizing public security units to use artificial intelligence (AI) for investigation, identification and analysis of organized crime.
Before deploymentArticle 8 Bis (proposed)Critical
5Public security units using AI.Operate AI systems under the supervision of the Secretaría de Seguridad y Protección Ciudadana (SSPC).
with supervision by the Secretaría de Seguridad y Protección Ciudadana.
Before deploymentArticle 8 Bis (proposed)Important
6Public security units using AI.Ensure AI use adheres to the principle of effectiveness.
requires adherence to principles of legality, proportionality, effectiveness and respect for human rights
Before deploymentArticle 8 Bis (proposed)Important

© Regulations.AI · updated on 13-Jun-2026