Mexico - Criminal Code Reform on AI (2025)

Bill amending Criminal Code and Copyright law re: generative AI

Iniciativa que reforma diversas disposiciones del Código Penal Federal y de la Ley Federal del Derecho de Autor en materia de IA generativa

Mexico

RAI-MX-NA-IQRDDXX-2025
Under Review(Under Review)
BillEnforcement and PenaltiesTransparency and DisclosureData Protection and Privacy
Export PDF

Proposed federal initiative (presented April 30, 2025) would add new criminal offenses addressing misuse of generative AI (deepfakes, non-consensual biometric use, deceptive manipulation) to the Código Penal Federal and amend the Ley Federal del Derecho de Autor to (i) recognize works assisted by AI, (ii) exclude autonomous AI-generated works from copyright protection, and (iii) require transparency about AI-assisted creation. The bill establishes sanctions including imprisonment and fines and sets a framework for protecting identity, authorship transparency, and copyright integrity.

Summary

This initiative, submitted to the Chamber of Deputies on April 30, 2025 by Deputy Víctor Manuel Pérez Díaz (PAN), proposes coordinated reforms to the Mexican Código Penal Federal and the Ley Federal del Derecho de Autor to address risks posed by generative artificial intelligence (AI). The criminal-law portion creates a new chapter and three new articles (211 Bis 8, 211 Bis 9 and 211 Bis 10) that (a) define "tools based on generative artificial intelligence," (b) define "improper use" of those tools in a closed list (manipulative deepfakes intended to deceive, non-consensual exploitation of facial images and biometric data, dissemination of confidential/reserved information, and misrepresenting AI-generated works as human-authored to gain registration or commercial advantage), and (c) set a penal range of six months to four years imprisonment and 100 to 600 days of fines for the prohibited conduct. The copyright amendment adds a new classification of works "according to the technology used for their creation," creating a category for "AI-assisted" works while excluding from protection "contents and systems created by generative AI that violate existing rights, are generated autonomously, do not identify sources/technology/authors, or lack authorization for incorporated elements." The bill also clarifies that computer programs may include systems created with the assistance of AI, except where excluded.

Substantively, the initiative balances two interrelated policy goals: (1) criminalize and deter malicious uses of generative AI that harm identity, privacy, reputation, democratic decision-making or infringe third-party rights; and (2) modernize copyright law to reflect degrees of human creative contribution in works involving AI. The bill draws on international regulatory thinking (risk-based approaches exemplified by the EU AI Act and international guidance from WIPO/UNESCO/OECD) and is intended to close enforcement gaps (deepfakes, non-consensual biometric uses, registration of autonomous AI outputs as human works) while protecting human authorship and incentivizing transparent use of AI in creative processes.

If adopted, the reforms will require public bodies (prosecutors, copyright registration agency) and private actors (AI developers, platform operators, publishers, rights managers) to adapt practices: law-enforcement will need capacity to investigate AI-enabled fraud and privacy invasions; the Instituto Nacional del Derecho de Autor (INDAUTOR) will need to update registration and disclosure rules; platforms may have to implement takedown and notice procedures and require provenance/attribution; and creators and commercial users of AI outputs will have new obligations to disclose AI assistance and to secure authorizations for training data where required. The criminal sanctions are relatively specific and aim to deter a discrete set of harmful behaviours, while the copyright text introduces a technology-based taxonomy and an exclusion for autonomous AI outputs that fail to meet transparency and authorization thresholds. The measure remains a proposal: it was published in the Gaceta Parlamentaria (April 30, 2025) and was received by commissions in late May 2025. The initiative is connected to broader policy debates in Mexico about identity, privacy, cultural industries and international regulatory alignment on AI.

Full article

Read full text ↗

Overview

The initiative "Que reforma y adiciona diversas disposiciones del Código Penal Federal y de la Ley Federal del Derecho de Autor, en materia de inteligencia artificial generativa" was filed in the Cámara de Diputados on April 30, 2025 by Deputy Víctor Manuel Pérez Díaz (PAN). It introduces a dedicated chapter in the Código Penal Federal to criminalize the "improper use" of generative AI tools (including deepfakes, unauthorized biometric extraction/use, dissemination of illicitly obtained private/confidential material, and fraudulent registration/presentation of AI autonomous outputs as human creations). Parallel amendments to the Ley Federal del Derecho de Autor would create a new classification of works "according to the technology used for their creation," explicitly recognizing "AI-assisted" creations while excluding from protection autonomous AI outputs that (i) infringe pre-existing rights, (ii) were generated without authorization for incorporated materials, or (iii) fail to transparently identify sources, the technology used, and human authors. The text of the initiative is publicly available in the Gaceta Parlamentaria: Gaceta Parlamentaria, 30 April 2025.

Definitions

The bill provides operational definitions that are central to enforcement. It defines "tools based on generative artificial intelligence" as systems that, with broad autonomy and without substantial and decisive human intervention, create content (text, images, audio, video, software code) using deep-learning models in response to commands. "Improper use" is defined via a closed list including: (a) deliberate, deceptive manipulation of audiovisual content intended to cause harm or mislead decision-making; (b) exploitation of facial recognition data or remote biometric identification sourced non-selectively from the internet or CCTV; (c) dissemination of confidential/reserved information or media illegally obtained; and (d) presenting AI-generated works as human-authored to obtain registration or commercialization while concealing sources or violation of third-party rights. These definitions aim for legal precision to distinguish permissible AI-assisted creativity from harms and frauds.

Governance and Institutional Framework

Implementation and enforcement would engage multiple institutions. Criminal provisions will be prosecuted through Mexico's ordinary justice system and require capacity-building among Ministerio Público and forensic units to investigate AI-enabled fabrications and biometric misuse. The copyright amendments implicate the Instituto Nacional del Derecho de Autor (INDAUTOR), the administrative body that maintains the public registry of copyright and issues certificates; INDAUTOR would need to update registration rules and administrative forms to require disclosure of AI assistance and sources. The initiative references international instruments and proposes an alignment-oriented approach similar to risk-based models (for example the EU's AI regulatory approach); further institutional coordination with the Secretaría de Cultura, Secretaría de Gobernación, and data protection authority (INAI) would be expected. The initiative text is published in the legislature's Gaceta: Gaceta Parlamentaria, and would require administrative guidance from INDAUTOR (Instituto Nacional del Derecho de Autor) for registration practice adjustments.

Key Focus Areas

The initiative targets a constellation of policy priorities: (1) Protecting identity, privacy and dignity by criminalizing non-consensual generation and dissemination of deepfakes and biometric misuse; (2) Safeguarding copyright and market integrity by preventing fraudulent registration or commercialization of autonomous AI outputs that use protected material without authorization; (3) Promoting transparency and authorship attribution by requiring creators to disclose AI assistance and sources; (4) Establishing enforceable sanctions (prison and fines) to deter harmful uses; and (5) Promoting alignment with international standards and best practices—its risk-awareness echoes the EU risk-based model and international guidance from institutions like WIPO/UNESCO and the OECD. The bill is deliberately narrow in scope for criminalization (targeting manipulative and harmful conduct rather than broad bans on technology), while the copyright provisions create a technology-based taxonomy ("AI-assisted" vs "autonomous generative AI") to calibrate protection and incentives for human creativity.

Implementation Framework

Operationalizing the reforms would require: (a) legislative adoption and publication in the Diario Oficial; (b) rulemaking and administrative guidance from INDAUTOR on registration forms, disclosure requirements and evidentiary standards for AI assistance; (c) capacity-building for prosecutors, courts and forensic labs in AI provenance, media forensics and biometric data tracing; (d) coordination protocols between INAI (National Institute for Transparency, Access to Information and Protection of Personal Data), INDAUTOR and law enforcement for cases implicating data protection or privacy breaches; and (e) engagement with platforms and intermediaries to establish notice-and-takedown, content labelling, and provenance metadata practices. For international comparators see the EU AI Act overview: AI Act documents and the Council press release Council (21 May 2024).

Monitoring and Evaluation

Monitoring will require qualitative and quantitative indicators: number and outcome of prosecutions under the new Penal provisions; INDAUTOR statistics on registrations flagged as AI-assisted or refused under the exclusion; platform takedown metrics; incidence of reported non-consensual deepfakes and biometric abuses; and case law developments. Periodic evaluation could be mandated (e.g., annual public reports by INDAUTOR and the Attorney General's Office on enforcement and trends). Independent oversight and stakeholder consultations (creators, rights organizations, civil-society privacy groups, tech providers) would be essential to refine definitions and minimize chilling effects on legitimate AI-assisted creativity. International guidance from UNESCO and OECD is relevant for evaluation frameworks: UNESCO guidance on generative AI in education and research is available via UNESCO, and OECD AI Principles via OECD.

Penalties, Liability, and Appeals

The initiative sets criminal penalties for prohibited conduct: imprisonment from six months to four years and fines of 100 to 600 days (as drafted in Article 211 Bis 10). The copyright changes include substantive exclusions from protection but do not create new civil remedies in the draft; standard civil claims (infringement, unfair competition, moral damage) would remain available. Defendants would retain criminal procedural rights and appeals through the ordinary judicial system; administrative review mechanisms would apply to registration denials by INDAUTOR. Penalties are framed to deter manipulative, deceptive commercial or reputational harms rather than to penalize ordinary creative assistance. Prosecutorial discretion and proportionality will determine how broadly the criminal provisions are applied in practice.

Relationship to Other Instruments

The initiative complements and intersects with existing national laws and international standards. It amends the Código Penal Federal and the Ley Federal del Derecho de Autor, and will interact with Mexico's data-protection framework (Federal Law on Protection of Personal Data Held by Private Parties and INAI oversight), telecommunications and intermediary liability regimes, and sectoral rules (e.g., electoral law, Penal provisions covering defamation or sexual offences). It references international regulatory developments (EU AI Act) and guidance from WIPO and UNESCO. Where conflicts or overlaps occur (for example between evidence rules for registration and data-protection constraints), inter-agency guidance and judicial interpretation will be necessary to reconcile obligations. The initiative also invites updates to administrative practice by INDAUTOR and potential secondary regulations to operationalize disclosure and registration rules.

International Alignment

The bill explicitly cites and aligns with international trends favoring risk-based regulation for AI and strengthened protections against identity-based harms. It references the EU model of risk-tiered obligations for AI, as well as WIPO and UNESCO analyses on AI and copyright. Its approach—criminalizing harmful manipulative uses while clarifying copyright treatment for AI-assisted versus autonomous outputs—mirrors debates in other jurisdictions (United States Copyright Office guidance, EU AI Act obligations for transparency and high-risk categories, and Beijing/China court rulings on AI-generated images). For context: see EU AI Act documentation (AI Act documents), WIPO analyses on AI and copyright, and INDAUTOR materials on copyright registration (INDAUTOR).

Implementation Timeline

MilestoneDate
Initiative published in Gaceta Parlamentaria2025-04-30
Turned to relevant committees (Commissions)2025-05-27
Legislative debate and committee review (expected; illustrative)6–12 months after referral (dependent on legislative calendar)
Potential enactment and publication in Diario Oficial (if approved)Variable — post-approval

Sources and References

SourceType
Gaceta Parlamentaria: Iniciativa que reforma y adiciona diversas disposiciones del Código Penal Federal y de la Ley Federal de Derecho de Autor (30 April 2025)Primary Source
Instituto Nacional del Derecho de Autor (INDAUTOR) — institutional role and servicesPrimary Source (agency)
AI Act — documents and background (EU)Secondary/Context
UNESCO: Guidance for Generative AI in Education and ResearchContext
OECD AI PrinciplesContext

Requirements for a company

What an organisation has to do under Mexico - Criminal Code Reform on AI (2025), at a glance. Not legal advice — the table below gives the provision and deadline for each item.

Not yet in force (Under Review). These requirements apply once the instrument takes effect and may change before then.

Must do

11
  • Do not deliberately manipulate audiovisual content using AI to cause harm or mislead.Any person using generative AI tools.
  • Do not exploit facial recognition or biometric data obtained non-consensually using generative AI.Any person using generative AI tools.
  • Do not disseminate confidential or private information illegally obtained using generative AI.Any person using generative AI tools.
  • Do not present autonomous AI-generated works as human-authored for fraudulent registration or commercialization.Creators and publishers of AI-generated works.
  • Ensure autonomous AI outputs do not infringe pre-existing intellectual property rights.Creators of autonomous AI outputs.
  • Obtain authorization for all incorporated materials used in autonomous AI-generated works.Creators of autonomous AI outputs.
  • +5 more in the table below

Must not do

0

Nothing in this category.

Should do

3
  • Document the provenance of training data used for generative AI models.AI developers and providers.
  • Implement opt-out or consent mechanisms for biometric data use in generative AI systems.AI developers and providers.
  • Prepare transparency statements regarding AI autonomy and human intervention in generative AI systems.AI developers and providers.

Should not do

0

Nothing in this category.

Who must do what

The obligations under Mexico - Criminal Code Reform on AI (2025), most serious first. Not legal advice — verify against the official text before relying on it.

#WhoRequirementBy whenWhereSeverity
1Any person using generative AI tools.Do not deliberately manipulate audiovisual content using AI to cause harm or mislead.
deliberate, deceptive manipulation of audiovisual content intended to cause harm or mislead decision-making
Código Penal FederalCritical
2Any person using generative AI tools.Do not exploit facial recognition or biometric data obtained non-consensually using generative AI.
exploitation of facial recognition data or remote biometric identification sourced non-selectively from the internet or CCTV
Código Penal FederalCritical
3Any person using generative AI tools.Do not disseminate confidential or private information illegally obtained using generative AI.
dissemination of confidential/reserved information or media illegally obtained
Código Penal FederalCritical
4Creators and publishers of AI-generated works.Do not present autonomous AI-generated works as human-authored for fraudulent registration or commercialization.
presenting AI-generated works as human-authored to obtain registration or commercialization while concealing sources or violation of third-party rights.
Código Penal Federal, Ley Federal del Derecho de AutorCritical
5Creators of autonomous AI outputs.Ensure autonomous AI outputs do not infringe pre-existing intellectual property rights.
excluding from protection autonomous AI outputs that (i) infringe pre-existing rights
Ley Federal del Derecho de AutorImportant
6Creators of autonomous AI outputs.Obtain authorization for all incorporated materials used in autonomous AI-generated works.
excluding from protection autonomous AI outputs that... (ii) were generated without authorization for incorporated materials
Ley Federal del Derecho de AutorImportant
7Creators of autonomous AI outputs.Transparently identify sources, technology used, and human authors for autonomous AI outputs.
excluding from protection autonomous AI outputs that... (iii) fail to transparently identify sources, the technology used, and human authors.
Ley Federal del Derecho de AutorImportant
8Creators and publishers of AI-assisted works.Disclose AI assistance when creating or publishing works.
requiring creators to disclose AI assistance and sources
Ley Federal del Derecho de AutorImportant
9Platform operators.Establish procedures for handling notices of unlawful deepfakes and enable rapid takedown.
establish procedures for notices of unlawful deepfakes, enable rapid takedown
Important
10Platform operators.Require provenance metadata for uploaded AI-generated content.
require provenance metadata for uploaded AI-generated content
Important
11Platform operators.Cooperate with prosecutors in investigations related to generative AI misuse.
cooperate with prosecutors
Important
12AI developers and providers.Document the provenance of training data used for generative AI models.
Document training data provenance
Recommended
13AI developers and providers.Implement opt-out or consent mechanisms for biometric data use in generative AI systems.
implement opt-out/consent mechanisms for biometric data
Recommended
14AI developers and providers.Prepare transparency statements regarding AI autonomy and human intervention in generative AI systems.
prepare transparency statements about AI autonomy and human intervention
Recommended

© Regulations.AI · updated on 13-Jun-2026