Mexico - Criminal Code Reform on AI (2025)
Bill amending Criminal Code and Copyright law re: generative AI
Iniciativa que reforma diversas disposiciones del Código Penal Federal y de la Ley Federal del Derecho de Autor en materia de IA generativa
Mexico
RAI-MX-NA-IQRDDXX-2025Proposed federal initiative (presented April 30, 2025) would add new criminal offenses addressing misuse of generative AI (deepfakes, non-consensual biometric use, deceptive manipulation) to the Código Penal Federal and amend the Ley Federal del Derecho de Autor to (i) recognize works assisted by AI, (ii) exclude autonomous AI-generated works from copyright protection, and (iii) require transparency about AI-assisted creation. The bill establishes sanctions including imprisonment and fines and sets a framework for protecting identity, authorship transparency, and copyright integrity.
Summary
This initiative, submitted to the Chamber of Deputies on April 30, 2025 by Deputy Víctor Manuel Pérez Díaz (PAN), proposes coordinated reforms to the Mexican Código Penal Federal and the Ley Federal del Derecho de Autor to address risks posed by generative artificial intelligence (AI). The criminal-law portion creates a new chapter and three new articles (211 Bis 8, 211 Bis 9 and 211 Bis 10) that (a) define "tools based on generative artificial intelligence," (b) define "improper use" of those tools in a closed list (manipulative deepfakes intended to deceive, non-consensual exploitation of facial images and biometric data, dissemination of confidential/reserved information, and misrepresenting AI-generated works as human-authored to gain registration or commercial advantage), and (c) set a penal range of six months to four years imprisonment and 100 to 600 days of fines for the prohibited conduct. The copyright amendment adds a new classification of works "according to the technology used for their creation," creating a category for "AI-assisted" works while excluding from protection "contents and systems created by generative AI that violate existing rights, are generated autonomously, do not identify sources/technology/authors, or lack authorization for incorporated elements." The bill also clarifies that computer programs may include systems created with the assistance of AI, except where excluded.
Substantively, the initiative balances two interrelated policy goals: (1) criminalize and deter malicious uses of generative AI that harm identity, privacy, reputation, democratic decision-making or infringe third-party rights; and (2) modernize copyright law to reflect degrees of human creative contribution in works involving AI. The bill draws on international regulatory thinking (risk-based approaches exemplified by the EU AI Act and international guidance from WIPO/UNESCO/OECD) and is intended to close enforcement gaps (deepfakes, non-consensual biometric uses, registration of autonomous AI outputs as human works) while protecting human authorship and incentivizing transparent use of AI in creative processes.
If adopted, the reforms will require public bodies (prosecutors, copyright registration agency) and private actors (AI developers, platform operators, publishers, rights managers) to adapt practices: law-enforcement will need capacity to investigate AI-enabled fraud and privacy invasions; the Instituto Nacional del Derecho de Autor (INDAUTOR) will need to update registration and disclosure rules; platforms may have to implement takedown and notice procedures and require provenance/attribution; and creators and commercial users of AI outputs will have new obligations to disclose AI assistance and to secure authorizations for training data where required. The criminal sanctions are relatively specific and aim to deter a discrete set of harmful behaviours, while the copyright text introduces a technology-based taxonomy and an exclusion for autonomous AI outputs that fail to meet transparency and authorization thresholds. The measure remains a proposal: it was published in the Gaceta Parlamentaria (April 30, 2025) and was received by commissions in late May 2025. The initiative is connected to broader policy debates in Mexico about identity, privacy, cultural industries and international regulatory alignment on AI.
Full article
Read full text ↗Overview
The initiative "Que reforma y adiciona diversas disposiciones del Código Penal Federal y de la Ley Federal del Derecho de Autor, en materia de inteligencia artificial generativa" was filed in the Cámara de Diputados on April 30, 2025 by Deputy Víctor Manuel Pérez Díaz (PAN). It introduces a dedicated chapter in the Código Penal Federal to criminalize the "improper use" of generative AI tools (including deepfakes, unauthorized biometric extraction/use, dissemination of illicitly obtained private/confidential material, and fraudulent registration/presentation of AI autonomous outputs as human creations). Parallel amendments to the Ley Federal del Derecho de Autor would create a new classification of works "according to the technology used for their creation," explicitly recognizing "AI-assisted" creations while excluding from protection autonomous AI outputs that (i) infringe pre-existing rights, (ii) were generated without authorization for incorporated materials, or (iii) fail to transparently identify sources, the technology used, and human authors. The text of the initiative is publicly available in the Gaceta Parlamentaria: Gaceta Parlamentaria, 30 April 2025.
Definitions
The bill provides operational definitions that are central to enforcement. It defines "tools based on generative artificial intelligence" as systems that, with broad autonomy and without substantial and decisive human intervention, create content (text, images, audio, video, software code) using deep-learning models in response to commands. "Improper use" is defined via a closed list including: (a) deliberate, deceptive manipulation of audiovisual content intended to cause harm or mislead decision-making; (b) exploitation of facial recognition data or remote biometric identification sourced non-selectively from the internet or CCTV; (c) dissemination of confidential/reserved information or media illegally obtained; and (d) presenting AI-generated works as human-authored to obtain registration or commercialization while concealing sources or violation of third-party rights. These definitions aim for legal precision to distinguish permissible AI-assisted creativity from harms and frauds.
Governance and Institutional Framework
Implementation and enforcement would engage multiple institutions. Criminal provisions will be prosecuted through Mexico's ordinary justice system and require capacity-building among Ministerio Público and forensic units to investigate AI-enabled fabrications and biometric misuse. The copyright amendments implicate the Instituto Nacional del Derecho de Autor (INDAUTOR), the administrative body that maintains the public registry of copyright and issues certificates; INDAUTOR would need to update registration rules and administrative forms to require disclosure of AI assistance and sources. The initiative references international instruments and proposes an alignment-oriented approach similar to risk-based models (for example the EU's AI regulatory approach); further institutional coordination with the Secretaría de Cultura, Secretaría de Gobernación, and data protection authority (INAI) would be expected. The initiative text is published in the legislature's Gaceta: Gaceta Parlamentaria, and would require administrative guidance from INDAUTOR (Instituto Nacional del Derecho de Autor) for registration practice adjustments.
Key Focus Areas
The initiative targets a constellation of policy priorities: (1) Protecting identity, privacy and dignity by criminalizing non-consensual generation and dissemination of deepfakes and biometric misuse; (2) Safeguarding copyright and market integrity by preventing fraudulent registration or commercialization of autonomous AI outputs that use protected material without authorization; (3) Promoting transparency and authorship attribution by requiring creators to disclose AI assistance and sources; (4) Establishing enforceable sanctions (prison and fines) to deter harmful uses; and (5) Promoting alignment with international standards and best practices—its risk-awareness echoes the EU risk-based model and international guidance from institutions like WIPO/UNESCO and the OECD. The bill is deliberately narrow in scope for criminalization (targeting manipulative and harmful conduct rather than broad bans on technology), while the copyright provisions create a technology-based taxonomy ("AI-assisted" vs "autonomous generative AI") to calibrate protection and incentives for human creativity.
Implementation Framework
Operationalizing the reforms would require: (a) legislative adoption and publication in the Diario Oficial; (b) rulemaking and administrative guidance from INDAUTOR on registration forms, disclosure requirements and evidentiary standards for AI assistance; (c) capacity-building for prosecutors, courts and forensic labs in AI provenance, media forensics and biometric data tracing; (d) coordination protocols between INAI (National Institute for Transparency, Access to Information and Protection of Personal Data), INDAUTOR and law enforcement for cases implicating data protection or privacy breaches; and (e) engagement with platforms and intermediaries to establish notice-and-takedown, content labelling, and provenance metadata practices. For international comparators see the EU AI Act overview: AI Act documents and the Council press release Council (21 May 2024).
Monitoring and Evaluation
Monitoring will require qualitative and quantitative indicators: number and outcome of prosecutions under the new Penal provisions; INDAUTOR statistics on registrations flagged as AI-assisted or refused under the exclusion; platform takedown metrics; incidence of reported non-consensual deepfakes and biometric abuses; and case law developments. Periodic evaluation could be mandated (e.g., annual public reports by INDAUTOR and the Attorney General's Office on enforcement and trends). Independent oversight and stakeholder consultations (creators, rights organizations, civil-society privacy groups, tech providers) would be essential to refine definitions and minimize chilling effects on legitimate AI-assisted creativity. International guidance from UNESCO and OECD is relevant for evaluation frameworks: UNESCO guidance on generative AI in education and research is available via UNESCO, and OECD AI Principles via OECD.
Penalties, Liability, and Appeals
The initiative sets criminal penalties for prohibited conduct: imprisonment from six months to four years and fines of 100 to 600 days (as drafted in Article 211 Bis 10). The copyright changes include substantive exclusions from protection but do not create new civil remedies in the draft; standard civil claims (infringement, unfair competition, moral damage) would remain available. Defendants would retain criminal procedural rights and appeals through the ordinary judicial system; administrative review mechanisms would apply to registration denials by INDAUTOR. Penalties are framed to deter manipulative, deceptive commercial or reputational harms rather than to penalize ordinary creative assistance. Prosecutorial discretion and proportionality will determine how broadly the criminal provisions are applied in practice.
Relationship to Other Instruments
The initiative complements and intersects with existing national laws and international standards. It amends the Código Penal Federal and the Ley Federal del Derecho de Autor, and will interact with Mexico's data-protection framework (Federal Law on Protection of Personal Data Held by Private Parties and INAI oversight), telecommunications and intermediary liability regimes, and sectoral rules (e.g., electoral law, Penal provisions covering defamation or sexual offences). It references international regulatory developments (EU AI Act) and guidance from WIPO and UNESCO. Where conflicts or overlaps occur (for example between evidence rules for registration and data-protection constraints), inter-agency guidance and judicial interpretation will be necessary to reconcile obligations. The initiative also invites updates to administrative practice by INDAUTOR and potential secondary regulations to operationalize disclosure and registration rules.
International Alignment
The bill explicitly cites and aligns with international trends favoring risk-based regulation for AI and strengthened protections against identity-based harms. It references the EU model of risk-tiered obligations for AI, as well as WIPO and UNESCO analyses on AI and copyright. Its approach—criminalizing harmful manipulative uses while clarifying copyright treatment for AI-assisted versus autonomous outputs—mirrors debates in other jurisdictions (United States Copyright Office guidance, EU AI Act obligations for transparency and high-risk categories, and Beijing/China court rulings on AI-generated images). For context: see EU AI Act documentation (AI Act documents), WIPO analyses on AI and copyright, and INDAUTOR materials on copyright registration (INDAUTOR).
Implementation Timeline
| Milestone | Date |
|---|---|
| Initiative published in Gaceta Parlamentaria | 2025-04-30 |
| Turned to relevant committees (Commissions) | 2025-05-27 |
| Legislative debate and committee review (expected; illustrative) | 6–12 months after referral (dependent on legislative calendar) |
| Potential enactment and publication in Diario Oficial (if approved) | Variable — post-approval |
Sources and References
Requirements for a company
What an organisation has to do under Mexico - Criminal Code Reform on AI (2025), at a glance. Not legal advice — the table below gives the provision and deadline for each item.
Not yet in force (Under Review). These requirements apply once the instrument takes effect and may change before then.
Must do
11- Do not deliberately manipulate audiovisual content using AI to cause harm or mislead.Any person using generative AI tools.
- Do not exploit facial recognition or biometric data obtained non-consensually using generative AI.Any person using generative AI tools.
- Do not disseminate confidential or private information illegally obtained using generative AI.Any person using generative AI tools.
- Do not present autonomous AI-generated works as human-authored for fraudulent registration or commercialization.Creators and publishers of AI-generated works.
- Ensure autonomous AI outputs do not infringe pre-existing intellectual property rights.Creators of autonomous AI outputs.
- Obtain authorization for all incorporated materials used in autonomous AI-generated works.Creators of autonomous AI outputs.
- +5 more in the table below
Must not do
0Nothing in this category.
Should do
3- Document the provenance of training data used for generative AI models.AI developers and providers.
- Implement opt-out or consent mechanisms for biometric data use in generative AI systems.AI developers and providers.
- Prepare transparency statements regarding AI autonomy and human intervention in generative AI systems.AI developers and providers.
Should not do
0Nothing in this category.
Who must do what
The obligations under Mexico - Criminal Code Reform on AI (2025), most serious first. Not legal advice — verify against the official text before relying on it.
| # | Who | Requirement | By when | Where | Severity |
|---|---|---|---|---|---|
| 1 | Any person using generative AI tools. | Do not deliberately manipulate audiovisual content using AI to cause harm or mislead. “deliberate, deceptive manipulation of audiovisual content intended to cause harm or mislead decision-making” | — | Código Penal Federal | Critical |
| 2 | Any person using generative AI tools. | Do not exploit facial recognition or biometric data obtained non-consensually using generative AI. “exploitation of facial recognition data or remote biometric identification sourced non-selectively from the internet or CCTV” | — | Código Penal Federal | Critical |
| 3 | Any person using generative AI tools. | Do not disseminate confidential or private information illegally obtained using generative AI. “dissemination of confidential/reserved information or media illegally obtained” | — | Código Penal Federal | Critical |
| 4 | Creators and publishers of AI-generated works. | Do not present autonomous AI-generated works as human-authored for fraudulent registration or commercialization. “presenting AI-generated works as human-authored to obtain registration or commercialization while concealing sources or violation of third-party rights.” | — | Código Penal Federal, Ley Federal del Derecho de Autor | Critical |
| 5 | Creators of autonomous AI outputs. | Ensure autonomous AI outputs do not infringe pre-existing intellectual property rights. “excluding from protection autonomous AI outputs that (i) infringe pre-existing rights” | — | Ley Federal del Derecho de Autor | Important |
| 6 | Creators of autonomous AI outputs. | Obtain authorization for all incorporated materials used in autonomous AI-generated works. “excluding from protection autonomous AI outputs that... (ii) were generated without authorization for incorporated materials” | — | Ley Federal del Derecho de Autor | Important |
| 7 | Creators of autonomous AI outputs. | Transparently identify sources, technology used, and human authors for autonomous AI outputs. “excluding from protection autonomous AI outputs that... (iii) fail to transparently identify sources, the technology used, and human authors.” | — | Ley Federal del Derecho de Autor | Important |
| 8 | Creators and publishers of AI-assisted works. | Disclose AI assistance when creating or publishing works. “requiring creators to disclose AI assistance and sources” | — | Ley Federal del Derecho de Autor | Important |
| 9 | Platform operators. | Establish procedures for handling notices of unlawful deepfakes and enable rapid takedown. “establish procedures for notices of unlawful deepfakes, enable rapid takedown” | — | — | Important |
| 10 | Platform operators. | Require provenance metadata for uploaded AI-generated content. “require provenance metadata for uploaded AI-generated content” | — | — | Important |
| 11 | Platform operators. | Cooperate with prosecutors in investigations related to generative AI misuse. “cooperate with prosecutors” | — | — | Important |
| 12 | AI developers and providers. | Document the provenance of training data used for generative AI models. “Document training data provenance” | — | — | Recommended |
| 13 | AI developers and providers. | Implement opt-out or consent mechanisms for biometric data use in generative AI systems. “implement opt-out/consent mechanisms for biometric data” | — | — | Recommended |
| 14 | AI developers and providers. | Prepare transparency statements regarding AI autonomy and human intervention in generative AI systems. “prepare transparency statements about AI autonomy and human intervention” | — | — | Recommended |
Related Regulations
Iniciativa que adiciona el artículo 199 Octies al Código Penal Federal para sancionar la creación de contenido íntimo sexual con IA sin consentimiento (Bill adding criminal sanction for AI‑generated intimate content without consent)
Mexico93% similar
Federal Artificial Intelligence legislative initiatives and Senate commission proposal (2023–2025)
Mexico91% similar
Iniciativa que adiciona disposiciones para el uso de Inteligencia Artificial por unidades de seguridad pública (Bill authorizing/setting rules for AI use in public security investigations)
Mexico91% similar
Proyecto de decreto que reforma la Ley Federal de Cinematografía, la Ley Federal del Derecho de Autor y la Ley Federal del Trabajo para proteger a actores de doblaje frente al uso de IA (Bill to protect dubbing actors from AI use)
Mexico91% similar
Proyecto de decreto que regula tecnologías emergentes, disruptivas e inteligencia artificial (Bill to regulate emerging/disruptive technologies and AI)
Mexico90% similar
© Regulations.AI · updated on 13-Jun-2026