Mexico - AI Use in Public Security (2025)
Bill authorizing/setting rules for AI use in public security investigations
Iniciativa que adiciona disposiciones para el uso de Inteligencia Artificial por unidades de seguridad pública
Mexico
RAI-MX-NA-IQADPXX-2025Proposed amendment (presented 4 March 2025) to add an Article 8 Bis to the Federal Law Against Organized Crime authorizing public security units to use artificial intelligence (AI) for investigation, identification and analysis of organized crime. The initiative defines permitted AI uses (predictive analytics, communications and financial monitoring, biometric recognition, risk evaluation, inter-agency data integration) and requires adherence to principles of legality, proportionality, effectiveness and respect for human rights, with supervision by the Secretaría de Seguridad y Protección Ciudadana.
Summary
Full article
Read full text ↗Overview
The initiative presented on 4 March 2025 proposes to add Article 8 Bis to the Ley Federal contra la Delincuencia Organizada to expressly permit and frame the use of Artificial Intelligence (AI) by public security units for activities related to the investigation, identification and analysis of organized crime. The published text sets out illustrative applications—predictive analytics, communications and financial network monitoring, facial recognition and other biometric systems, suspicious-transaction risk assessment, workflow automation, machine-learning tools for identifying modus operandi, and AI-optimized inter-institutional databases. The legislative text and accompanying exposition of motives are available in the official publication: Gaceta Parlamentaria, 4 Mar 2025. The initiative is also listed in the Chamber of Deputies' information system: SITL initiatives index. The overview explains the policy rationale (strengthening intelligence and investigative capabilities to combat organized crime) and highlights the stated commitment to observe principles such as legality, proportionality, opportunity, progressivity, efficacy and full respect for human rights.
Definitions
The initiative's operative proposal is concise: it authorizes "the unit and the institutions in charge of public security" to use AI for defined investigative purposes. While the draft lists application domains, it includes no comprehensive statutory definitions for technical terms such as "artificial intelligence", "automated decision", "biometric processing", "high-risk system" or "human-in-the-loop". Implementers will need to rely on cross-references to other instruments and internationally accepted definitions (e.g., OECD and IEEE references) or on secondary regulations to ensure a shared interpretive framework between security agencies, data-protection bodies and courts.
Governance and Institutional Framework
The proposal names the Secretaría de Seguridad y Protección Ciudadana (SSPC) as the supervising authority for the implementation and operation of AI uses in public security. However, the text does not create a new independent oversight body or establish procedural safeguards such as mandatory prior authorizations, inter-institutional oversight committees, independent audits or parliamentary review. The initiative must therefore be read alongside existing institutions: the Federal Executive through SSPC, the Cámara de Diputados (via Commission of Justice during parliamentary processing), and autonomous agencies such as the Instituto Nacional de Transparencia, Acceso a la Información y Protección de Datos Personales (INAI) which enforces transparency and data-protection norms for public-sector processing. For coherent governance, the law should define roles and coordination mechanisms between SSPC, INAI, the Fiscalía General de la República (FGR) for prosecution-related uses, and the courts for judicial oversight.
Key Focus Areas
Detailed policy and technical focus areas required to operationalize the initiative include: (1) Legal basis and individual rights safeguards — ensuring that any intrusive use (e.g., biometric recognition) has express legal basis, temporal limits, judicial authorization where liberty is affected, and accessible remedies; (2) Data protection and minimization — application of the Ley General de Protección de Datos Personales en Posesión de Sujetos Obligados to limit collection, retention and secondary uses; (3) Algorithmic risk management — mandatory AI impact assessments (privacy, nondiscrimination, accuracy), bias testing, and acceptance thresholds for deployment in law-enforcement contexts; (4) Transparency and documentation — maintaining auditable model cards, training-data provenance, decision-logs and change-control records; (5) Cybersecurity and model security — baseline controls for model integrity, provenance and access controls to avoid tampering or exfiltration; (6) Vendor and procurement standards — contractual clauses for audit rights, explainability, liability allocation and data-handling obligations; and (7) Human oversight — clear human-in-the-loop requirements for actions that materially affect individual rights. These areas are necessary because the initiative as drafted provides authorization but not the procedural or technical guardrails needed to mitigate documented harms (false positives, discriminatory outcomes, mission creep, and mass surveillance).
Implementation Framework
To translate the statutory authorization into lawful practice, an implementation framework would typically include: (a) secondary regulations or technical guidelines issued by SSPC in coordination with INAI and the Attorney General's Office; (b) mandatory risk-classification of AI systems (low, medium, high risk) with higher scrutiny for intrusive categories (biometrics, predictive policing); (c) pre-deployment AI impact assessments that must be reviewed by an independent auditor or oversight unit; (d) registration or inventory of AI systems used by public security units and a public summary registry of non-sensitive features; (e) standardized procurement and contracting templates requiring vendor transparency and security warranties; (f) operator training, certification, and recordkeeping obligations; and (g) judicial or administrative authorization procedures for system use in specific cases (e.g., bulk biometric searches). International technical norms (ISO/IEC) and regional guidance (OECD, Council of Europe) should inform these instruments.
Monitoring and Evaluation
Monitoring should include continuous performance evaluation, bias audits, periodic independent reviews, and public reporting. Key measurable indicators would be false-positive/false-negative rates for biometric systems, accuracy of predictive models, incident reports of misuse, number and outcome of automated-based operational actions (stops, arrests), and data-breach incidents. An independent oversight mechanism (audit unit within SSPC with public reporting obligations and INAI coordination) would help provide accountability. These monitoring outputs should be available in anonymized form to civil-society reviewers and to specialized parliamentary committees, balancing operational secrecy with rights-protective transparency.
Penalties, Liability, and Appeals
The initiative as published does not detail penalties or remediation mechanisms. For responsible implementation, the legal package should include administrative sanctions (fines, suspension of systems, revocation of procurement contracts) for non-compliance with data-protection and auditing obligations, disciplinary measures for public servants who misuse systems, and criminal liability in cases of willful abuse leading to rights violations. It should also guarantee individual remedies: judicial review, expedited appeals, data-correction and deletion rights, and clear processes for contesting automated decisions impacting liberty or legal status.
Relationship to Other Instruments
The proposed amendment intersects with multiple existing and recent instruments: the Ley General de Protección de Datos Personales en Posesión de Sujetos Obligados (public-sector data protection), the Ley del Sistema Nacional de Investigación e Inteligencia en Materia de Seguridad Pública (published July 2025), the Ley de Seguridad Nacional (classification of intelligence information), applicable provisions of the Código Penal Federal concerning illegal access and misuse of systems, and administrative procurement and contracting rules. Coherence and hierarchy must be clarified — notably how confidentiality regimes for intelligence reconcile with transparency and data-protection obligations and how judicial oversight applies to AI-enabled investigative actions.
International Alignment
The initiative should be aligned with evolving international norms: the Council of Europe and EU guidance on biometric mass surveillance, the OECD Principles on AI, and recommendations by human-rights bodies. Alignment requires adopting internationally accepted risk-assessment methodologies, model-evaluation standards, and vendor due-diligence practices. Cross-border data flows (e.g., cloud hosting or third-party models trained abroad) create additional legal and security considerations to be addressed via contractual safeguards and export-control-like measures for specialized AI systems.
Implementation Timeline
| Milestone | Target Date | Notes |
|---|---|---|
| Initiative formally presented (Gaceta Parlamentaria) | 2025-03-04 | Gaceta Parlamentaria (4 Mar 2025) |
| Turned to Commission of Justice | 2025-03-04 | SITL - initiatives listing |
| Commission review, hearings & technical consultations | 3–6 months after referral | Expected stakeholder hearings with SSPC, INAI, civil society, academia |
| Draft secondary regulations / technical standards | 6–12 months after approval | Need coordination with INAI and procurement authorities |
| Pre-deployment audits & registration | Concurrent with regulations | High-risk systems must complete AI impact assessment before use |
Sources and References
Requirements for a company
What an organisation has to do under Mexico - AI Use in Public Security (2025), at a glance. Not legal advice — the table below gives the provision and deadline for each item.
Not yet in force (Proposed). These requirements apply once the instrument takes effect and may change before then.
Must do
6- Ensure AI use fully respects human rights.Public security units using AI.
- Ensure AI use adheres to the principle of legality.Public security units using AI.
- Ensure AI use adheres to the principle of proportionality.Public security units using AI.
- Use AI systems solely for investigation, identification, and analysis of organized crime.Public security units using AI.
- Operate AI systems under the supervision of the Secretaría de Seguridad y Protección Ciudadana (SSPC).Public security units using AI.
- Ensure AI use adheres to the principle of effectiveness.Public security units using AI.
Must not do
0Nothing in this category.
Should do
0Nothing in this category.
Should not do
0Nothing in this category.
Who must do what
The obligations under Mexico - AI Use in Public Security (2025), most serious first. Not legal advice — verify against the official text before relying on it.
| # | Who | Requirement | By when | Where | Severity |
|---|---|---|---|---|---|
| 1 | Public security units using AI. | Ensure AI use fully respects human rights. “requires adherence to principles of legality, proportionality, effectiveness and respect for human rights” | Before deployment | Article 8 Bis (proposed) | Critical |
| 2 | Public security units using AI. | Ensure AI use adheres to the principle of legality. “requires adherence to principles of legality, proportionality, effectiveness and respect for human rights” | Before deployment | Article 8 Bis (proposed) | Critical |
| 3 | Public security units using AI. | Ensure AI use adheres to the principle of proportionality. “requires adherence to principles of legality, proportionality, effectiveness and respect for human rights” | Before deployment | Article 8 Bis (proposed) | Critical |
| 4 | Public security units using AI. | Use AI systems solely for investigation, identification, and analysis of organized crime. “authorizing public security units to use artificial intelligence (AI) for investigation, identification and analysis of organized crime.” | Before deployment | Article 8 Bis (proposed) | Critical |
| 5 | Public security units using AI. | Operate AI systems under the supervision of the Secretaría de Seguridad y Protección Ciudadana (SSPC). “with supervision by the Secretaría de Seguridad y Protección Ciudadana.” | Before deployment | Article 8 Bis (proposed) | Important |
| 6 | Public security units using AI. | Ensure AI use adheres to the principle of effectiveness. “requires adherence to principles of legality, proportionality, effectiveness and respect for human rights” | Before deployment | Article 8 Bis (proposed) | Important |
Related Regulations
Federal Artificial Intelligence legislative initiatives and Senate commission proposal (2023–2025)
Mexico93% similar
Iniciativa para reformar la fracción XVII del artículo 73 de la Constitución en materia de Inteligencia Artificial (Constitutional reform to grant Congress power to legislate on AI)
Mexico92% similar
Iniciativa que reforma diversas disposiciones del Código Penal Federal y de la Ley Federal del Derecho de Autor en materia de IA generativa (Bill amending Criminal Code and Copyright law re: generative AI)
Mexico91% similar
Proyecto de decreto que regula tecnologías emergentes, disruptivas e inteligencia artificial (Bill to regulate emerging/disruptive technologies and AI)
Mexico91% similar
Iniciativa que adiciona el artículo 199 Octies al Código Penal Federal para sancionar la creación de contenido íntimo sexual con IA sin consentimiento (Bill adding criminal sanction for AI‑generated intimate content without consent)
Mexico91% similar
© Regulations.AI · updated on 13-Jun-2026