Mexico - AI Development Guidelines (2018)
General principles and impact‑assessment guide for AI in the Federal Public Administration
Principios generales y guía de análisis de impacto para el desarrollo y uso de sistemas con elementos de inteligencia artificial en la Administración Pública Federal
Mexico
RAI-MX-NA-PGYGDXX-2018A non‑binding policy framework published in 2018 by Mexico's Coordinación de la Estrategia Digital Nacional to provide general principles and an impact‑assessment guide for AI systems used across the Federal Public Administration. The document promotes human‑centred design, transparency, accountability and rights‑respecting deployment, and asks agencies to perform impact analyses and apply risk‑based safeguards before deploying AI‑enabled systems.
Summary
In 2018 the Coordinación de la Estrategia Digital Nacional (part of Mexico’s federal digital strategy apparatus) published a guidance framework titled “Principios generales y guía de análisis de impacto para el desarrollo y uso de sistemas con elementos de inteligencia artificial en la Administración Pública Federal.” The publication is a policy‑level, non‑binding framework intended to guide federal agencies in Mexico on the responsible development, procurement and use of systems that incorporate elements of artificial intelligence (AI). The document situates AI use within broader government digital transformation goals while foregrounding ethical, legal and rights‑based considerations.
The guidance establishes a set of core principles—centred on respect for human rights, transparency and explainability, fairness and non‑discrimination, privacy and data protection, security and robustness, and human oversight—and pairs them with an operational Impact Assessment Guide that public agencies are encouraged to adopt when planning, acquiring, developing or deploying AI systems. The Impact Assessment Guide is structured to help public servants identify the intended purpose of an AI system, map affected populations and stakeholders, evaluate potential harms and benefits, document data sources and governance, assess algorithmic biases and discrimination risks, plan for testing and validation, and design monitoring and remediation processes. It advocates multidisciplinary teams, documentation of design decisions, and engagement with affected groups.
While the guidance itself does not create new statutory penalties or an independent enforcement agency, it connects to existing legal regimes (notably data protection laws and administrative accountability mechanisms) and recommends institutional roles and internal governance (e.g., appointing responsible officers or AI stewards, establishing review committees, and maintaining audit trails). It also references international instruments and good practices (for example, the OECD AI Principles and global ethics recommendations) as alignment benchmarks.
Practically, the framework functions as an early national effort to operationalize trustworthy AI for the Mexican federal administration: it is intended to reduce the risk of discriminatory, opaque or unsafe AI decision‑making in public services and to increase public trust in algorithmic systems. The document served as a starting point for subsequent policy conversations, working groups and multi‑stakeholder initiatives in Mexico (including the emergence of coalitions and national strategy workstreams). Sources that reference the framework include official government portals and legislative analyses; the primary public posting and related materials were made available via the InnovaMx/gob.mx platform and were discussed in subsequent parliamentary and policy documents. Because the publication is a guidance tool rather than a law, obligations and enforcement are implemented via agency practice, administrative rules, and existing sectoral laws rather than penalties contained in the guidance itself.
Full article
Read full text ↗Overview
The 2018 document produced by Mexico's Coordinación de la Estrategia Digital Nacional sets out high‑level principles and a practical impact‑assessment guide for systems containing elements of artificial intelligence intended for use in the Federal Public Administration (APF). It is presented as advisory guidance to strengthen ethical and rights‑respecting adoption of AI across federal agencies. The guidance frames AI as a tool to improve public service delivery while cautioning that public deployments must be evaluated for privacy, fairness, transparency and human dignity risks. The public posting and summary information were published on the government’s innovation/digital platform; see the official posting on InnovaMx for the announcement and access information: Principles and Impact Assessment Guide (InnovaMx). The guide complements Mexico’s broader 2017–2018 digital strategy efforts and aligns with international instruments such as the OECD AI Principles and UNESCO’s Recommendation on the Ethics of Artificial Intelligence.
Definitions
The guidance uses practical, operational definitions rather than attempting exhaustive technical taxonomy. Key terms include: "AI system" or "systems with elements of AI" (systems that perform data‑driven inference, prediction or decision‑support using models or algorithmic processes capable of learning or adapting); "impact analysis" (a structured assessment of the potential effects on rights, equity, security and public value); "affected people" (citizens, beneficiaries, employees or any stakeholder materially impacted by an AI system’s outcomes); and "human oversight" (mechanisms enabling human review, intervention and final decision‑making where appropriate). Definitions are intentionally broad to capture diverse algorithmic components used across government services, procurement and analytics.
Governance and Institutional Framework
The document recommends that each federal agency adopt internal governance arrangements for AI initiatives. Suggested elements include appointing an AI project owner or steward, defining roles for legal and privacy officers, creating multidisciplinary development teams (technical, legal, ethics, subject‑matter experts), and establishing internal review committees to sign off on impact assessments prior to deployment. While the guidance does not create a new external regulator, it encourages coordination with existing accountability bodies and alignment with the national digital strategy. For more context on the institutional placement and the public announcement, see InnovaMx / CEDN posting. Agencies are also advised to publish non‑sensitive documentation to enable public scrutiny and to maintain internal registries of deployed systems to support oversight and audits.
Key Focus Areas
The guide organizes analysis around several programmatic risk and value areas: (1) Rights and equality — identifying risks to civil‑political rights and vulnerable groups, and designing mitigation for bias and discrimination; (2) Transparency and explainability — documenting system purpose, data sources and decision logic in accessible form for those affected; (3) Data governance and privacy — mapping personal data flows, ensuring lawful bases, and applying minimization and retention limits under Mexico’s data protection regime; (4) Security and robustness — specifying resilience, testing, and secure development practices; (5) Accountability and redress — specifying responsible parties, complaint channels and remedial processes for harms; and (6) Operational fit and public value — verifying that AI is proportionate to the problem and that non‑AI alternatives were considered. For each area the guide provides checklists and recommended evidence to collect, including test results, fairness evaluations, audit logs and user‑facing notices. These focus areas mirror international best practices such as the OECD AI Principles and the UNESCO recommendation referenced earlier.
Implementation Framework
The recommended implementation approach is lifecycle‑oriented: from problem definition and requirements, through data collection and model development, to testing, deployment, monitoring and decommissioning. The guide emphasizes the need for: (a) clear documentation at each phase (design rationale, data provenance, model versions); (b) risk‑based classification of systems (higher scrutiny for high‑impact decisions affecting rights and entitlements); (c) staged testing including pilot deployments and controlled rollouts; (d) maintenance and update policies; and (e) citizen‑centred communication strategies. It advises agencies to conduct formal Impact Analyses before procurement or in‑house development and to retain evidence demonstrating due diligence. The guide also recommends stakeholder engagement and external consultations when systems touch large or vulnerable populations.
Monitoring and Evaluation
Monitoring recommendations require agencies to establish performance metrics, fairness indicators, error‑rate tracking and mechanisms for periodic re‑assessment as data distributions shift. Suggested operational controls include automated alerts for performance degradation, scheduled audits (technical and ethical), and change‑control procedures for model updates. The guide portrays monitoring as continuous rather than a one‑time approval event; agencies must report outcomes internally and be prepared to pause, roll back or refine systems when adverse impacts are detected. Where appropriate, agencies should make non‑sensitive monitoring summaries publicly available to support transparency and trust.
Penalties, Liability, and Appeals
Because the product is an advisory framework rather than statute, it does not itself prescribe criminal or administrative penalties. Instead the guide points agencies to applicable laws (data protection, administrative responsibility and public sector accountability frameworks) for enforcement and redress. It recommends that agencies implement internal grievance and appeals channels, maintain audit trails to support investigations, and coordinate with existing accountability bodies if systemic harm occurs. In practice, disciplinary or corrective actions for failures to follow internal rules would flow from agency internal controls and Mexico’s administrative responsibility mechanisms.
Relationship to Other Instruments
The guidance is designed to complement Mexico’s broader digital strategy materials and to be consistent with international norms. It specifically references alignment with international policy tools and situates itself as an operational adjunct to national digital transformation initiatives. Agencies are recommended to map AI projects against sectoral regulation (health, social services, finance) and to engage sector regulators when AI use intersects regulated functions. The guide also informed later policy debate and legislative proposals related to AI governance in Mexico; see parliamentary analyses and references on national legislative portals where the guide is cited as an antecedent to subsequent initiatives.
International Alignment
The document frames Mexican public‑sector AI governance in an international context, encouraging adoption of globally recognised principles and tools. It explicitly points readers toward OECD guidance on AI governance and to UNESCO’s ethics recommendation as widely accepted normative benchmarks. Agencies are urged to consult international standards and participate in multilateral fora to align procurement, testing and interoperability practices—particularly for cross‑border data flows and models trained on international data. Relevant references include the OECD AI Principles and the UNESCO Recommendation on the Ethics of AI.
Implementation Timeline
| Phase | Suggested Timing | Key Activities |
|---|---|---|
| Preparation | 0–3 months | Inventory existing systems; designate AI steward; train core team; adopt template Impact Assessment. |
| Assessment & design | 1–4 months | Conduct impact analysis; stakeholder mapping; define metrics and mitigation measures. |
| Pilot & testing | 2–6 months | Technical validation, bias/fairness testing, privacy impact tests, controlled pilot with monitoring. |
| Deployment | 1–3 months | Rollout with monitoring, publish non‑sensitive documentation, open complaint channels. |
| Operational monitoring | Ongoing | Periodic audits, retraining/updates, incident response and public reporting. |
Sources and References
| Source | Type |
|---|---|
| Principios y Guía de Análisis de Impacto (InnovaMx / Coordinación de la Estrategia Digital Nacional) | Primary Source |
| UNESCO – Recommendation on the Ethics of Artificial Intelligence (2021) | Primary/International Standard |
| OECD – AI Principles (2019) | Primary/International Standard |
Requirements for a company
What an organisation has to do under Mexico - AI Development Guidelines (2018), at a glance. Not legal advice — the table below gives the provision and deadline for each item.
Must do
11- Conduct a formal impact analysis for AI systems.Federal Public Administration agencies.
- Adopt internal governance arrangements for AI initiatives.Each federal agency.
- Establish internal review committees to approve impact assessments.Federal agencies deploying AI systems.
- Identify and mitigate risks to rights, equality, and vulnerable groups.Federal agencies developing or using AI.
- Document system purpose, data sources, and decision logic in accessible form.Federal agencies deploying AI systems.
- Map personal data flows, ensure lawful bases, and apply data protection limits.Federal agencies using AI with personal data.
- +5 more in the table below
Must not do
0Nothing in this category.
Should do
3- Appoint an AI project owner or steward.Federal agencies adopting AI.
- Maintain internal registries of deployed AI systems.Federal agencies using AI.
- Publish non-sensitive documentation to enable public scrutiny.Federal agencies deploying AI systems.
Should not do
0Nothing in this category.
Who must do what
The obligations under Mexico - AI Development Guidelines (2018), most serious first. Not legal advice — verify against the official text before relying on it.
| # | Who | Requirement | By when | Where | Severity |
|---|---|---|---|---|---|
| 1 | Federal Public Administration agencies. | Conduct a formal impact analysis for AI systems. “advises agencies to conduct formal Impact Analyses before procurement or in-house development” | Before procurement or in-house development | Overview, Implementation Framework | Important |
| 2 | Each federal agency. | Adopt internal governance arrangements for AI initiatives. “recommends that each federal agency adopt internal governance arrangements for AI initiatives.” | — | Governance and Institutional Framework | Important |
| 3 | Federal agencies deploying AI systems. | Establish internal review committees to approve impact assessments. “establishing internal review committees to sign off on impact assessments prior to deployment.” | Before deployment | Governance and Institutional Framework | Important |
| 4 | Federal agencies developing or using AI. | Identify and mitigate risks to rights, equality, and vulnerable groups. “identifying risks to civil-political rights and vulnerable groups, and designing mitigation for bias and discrimination” | Before deployment | Key Focus Areas | Important |
| 5 | Federal agencies deploying AI systems. | Document system purpose, data sources, and decision logic in accessible form. “documenting system purpose, data sources and decision logic in accessible form for those affected” | Before deployment | Key Focus Areas | Important |
| 6 | Federal agencies using AI with personal data. | Map personal data flows, ensure lawful bases, and apply data protection limits. “mapping personal data flows, ensuring lawful bases, and applying minimization and retention limits under Mexico’s data protection regime” | Before deployment | Key Focus Areas | Important |
| 7 | Federal agencies operating AI systems. | Establish performance metrics, fairness indicators, and error-rate tracking. “require agencies to establish performance metrics, fairness indicators, error-rate tracking” | Ongoing | Monitoring and Evaluation | Important |
| 8 | Federal agencies deploying AI systems. | Implement internal grievance and appeals channels for affected people. “recommends that agencies implement internal grievance and appeals channels” | Before deployment | Penalties, Liability, and Appeals | Important |
| 9 | Federal agencies developing or using AI. | Retain evidence demonstrating due diligence for AI systems. “retain evidence demonstrating due diligence.” | Ongoing | Implementation Framework | Important |
| 10 | Federal agencies developing or procuring AI. | Conduct staged testing, including pilot deployments and controlled rollouts. “staged testing including pilot deployments and controlled rollouts” | Before full deployment | Implementation Framework | Important |
| 11 | Federal agencies deploying AI in regulated sectors. | Map AI projects against sectoral regulation and engage sector regulators. “map AI projects against sectoral regulation (...) and to engage sector regulators” | Before deployment | Relationship to Other Instruments | Important |
| 12 | Federal agencies adopting AI. | Appoint an AI project owner or steward. “Suggested elements include appointing an AI project owner or steward” | — | Governance and Institutional Framework | Recommended |
| 13 | Federal agencies using AI. | Maintain internal registries of deployed AI systems. “maintain internal registries of deployed systems to support oversight and audits.” | — | Governance and Institutional Framework | Recommended |
| 14 | Federal agencies deploying AI systems. | Publish non-sensitive documentation to enable public scrutiny. “advised to publish non-sensitive documentation to enable public scrutiny” | After deployment | Governance and Institutional Framework | Recommended |
Related Regulations
Hacia una Estrategia de IA en México: Aprovechando la Revolución de la IA (Toward an AI Strategy in Mexico)
Mexico92% similar
Federal Artificial Intelligence legislative initiatives and Senate commission proposal (2023–2025)
Mexico92% similar
Laboratorio Nacional de Inteligencia Artificial (LNIA) — programa anunciado en el marco del Plan México (National AI Laboratory)
Mexico91% similar
Instructivo del Ministerio de Ciencia sobre uso de IA en el Estado (MinCiencia instructive on AI use in government)
Chile89% similar
Disposición 2/2023 – "Recomendaciones para una Inteligencia Artificial Fiable" (Recommendations for a Trustworthy Artificial Intelligence)
Argentina89% similar
© Regulations.AI · updated on 13-Jun-2026