AI Compliance in Latin America: Brazil, Mexico, Colombia, Argentina
Latin America does not have a single unified AI regulation — but it has data protection laws, sector rules, and emerging AI frameworks that apply now. Brazil leads with active LGPD enforcement and a pending AI Bill. Mexico, Colombia, and Argentina each have different requirements. Here is what applies to your business.
Latin America AI Compliance at a Glance
| Country | Primary Law | AI-Specific | Max Fine |
|---|---|---|---|
| Brazil | LGPD (2021) | AI Bill (PL 2338/2023): Senate-approved, in Chamber of Deputies | R$50M per violation |
| Mexico | LFPDPPP (new law, Mar 2025) | No specific AI law | ~$1.8-1.9M USD (320,000 UMA) |
| Colombia | Ley 1581 (2012) | SIC 2021 AI Guidance | ~$800-850K USD |
| Argentina | PDPA (2000) | AI Strategy (non-binding) | Low currently |
| Chile | Ley 21.719 (2024) | AI Strategy published | Moderate |
| Peru | Ley 29733 | No AI-specific rules | Limited enforcement |
Brazil
LGPD Enforced + AI Bill PendingAuthority: ANPD (Autoridade Nacional de Proteção de Dados)
Penalty: Up to 2% of Brazilian revenue, capped at R$50M (~$10M) per violation
LGPD and AI systems
Brazil's Lei Geral de Proteção de Dados (LGPD), in force since 2021 with enforcement powers since August 2021, is the primary AI compliance framework in Brazil. Brazil's national data protection authority, ANPD, has issued specific guidance on AI.
LGPD Article 20 gives data subjects the right to request review of decisions made solely through automated processing that affect them — including profiling. The right applies when the decision produces "legal effects" or "significantly affects" the person. This is materially similar to GDPR Article 22.
What LGPD requires for AI systems: - **Legal basis**: Processing personal data requires one of 10 legal bases. For commercial AI, consent or legitimate interests are most common. - **Data subject rights**: Access, correction, deletion, data portability, and the right to review automated decisions must be implemented. - **DPO (Data Protection Officer)**: Required for companies that process large volumes of personal data or process sensitive data. - **Privacy Impact Assessment**: Required for high-risk processing, including most AI systems that process personal data. - **ANPD registration**: Not currently required, but expected to expand.
ANPD enforcement has been active since 2023. Its first sanctions were issued in 2023 against a company that failed to respond to data subject requests. Fines are calculated as a percentage of Brazilian turnover, not global turnover — but the R$50M cap is per violation, and each data subject's data processed unlawfully can constitute a separate violation.
Brazil AI Bill (PL 2338/2023)
Brazil's AI Bill (PL 2338/2023) passed the Senate in December 2024 and is before the Chamber of Deputies as of early 2026. If enacted in its current form, it creates a risk-based AI framework modeled on the EU AI Act.
Key provisions of PL 2338/2023: - **High-risk AI systems**: Defined by impact on fundamental rights, safety, and critical infrastructure. Hiring AI, credit AI, and healthcare AI are expected to qualify. - **Prohibited AI**: Subliminal manipulation, social scoring, real-time biometric surveillance in public spaces. - **Transparency requirements**: High-risk AI systems must disclose AI use to affected parties. - **Human oversight**: High-risk systems must allow human intervention. - **Impact assessment**: "Technical Due Diligence Report" required before deploying high-risk AI. - **Enforcement**: ANPD is proposed as the primary AI authority, with fines up to R$50M or 2% of revenue.
The Senate approved its version of the bill on December 10, 2024; as of 2026 it remains under review by a special committee in the Chamber of Deputies and has not been enacted — timing for final passage is not fixed. Companies operating in Brazil should design systems now that meet the probable requirements — given that the LGPD already covers most of the data processing aspects, the AI Bill adds governance, transparency, and documentation obligations.
Key actions for Brazil
- ·If you process personal data of Brazilian residents: ensure LGPD compliance — legal basis, data subject rights, DPO if required.
- ·Implement Article 20 LGPD right to review automated decisions: log all AI decisions affecting individuals, create a review request mechanism.
- ·Prepare Privacy Impact Assessments for any AI system processing sensitive categories of data (health, financial, biometric).
- ·Monitor PL 2338/2023 — expect enactment in 2026. Design AI systems with transparency and human oversight now.
- ·Appoint a DPO or data protection point of contact visible to Brazilian users.
Mexico
New LFPDPPP in force since March 2025Authority: Secretaría Anticorrupción y Buen Gobierno (SABG) — replaced the dissolved INAI, March 21, 2025
Penalty: Up to 320,000 UMA for standard infractions, doubled for sensitive data (~$1.8-1.9M USD at 2026 UMA rates)
LFPDPPP and AI
Mexico replaced its data protection framework entirely on March 21, 2025: a new Ley Federal de Protección de Datos Personales en Posesión de los Particulares (LFPDPPP), published March 20, 2025, repealed and replaced the original 2010 law of the same name. The same reform dissolved INAI (part of a December 2024 constitutional reform eliminating seven autonomous bodies) and transferred enforcement to the Secretariat of Anti-Corruption and Good Governance (Secretaría Anticorrupción y Buen Gobierno, SABG). Neither law specifically addresses AI, but the LFPDPPP's provisions apply to AI systems that process personal data.
LFPDPPP key requirements for AI: - **Privacy notice**: Before collecting personal data used in AI, a clear privacy notice must be provided. It must explain the purpose of the processing. - **Consent**: For personal data used in sensitive processing (including profiling), explicit consent is required. - **Data subject rights**: ARCO rights — Access, Rectification, Cancellation, Opposition — were preserved by the 2025 law and must still be honored. - **Security measures**: Administrative, physical, and technical security for personal data. - **Data transfers**: Cross-border transfers require consent or that the recipient country provides "adequate" protection. - **Penalties**: Fines are now denominated in UMA (Unidad de Medida y Actualización) rather than the old "days of minimum wage" formula — 100 to 160,000 UMA for standard infractions, up to 320,000 UMA for aggravated ones, doubled where sensitive data is involved.
The SABG inherited INAI's enforcement track record (ARCO-rights violations, inadequate security) and its powers under the new law. Mexico has no AI-specific statute as of 2026; the GDPR-aligned interpretation of automated decisions remains a reasonable compliance baseline pending dedicated AI guidance from SABG.
For AI systems in Mexico: the primary obligation is ensuring compliance with the 2025 LFPDPPP for any personal data used in training, inference, or decision-making — including verifying that data-transfer and ARCO-rights processes route to the correct current authority (SABG, not INAI, which no longer exists).
Sectoral rules for AI in Mexico
Several Mexican regulatory bodies have issued sector-specific guidance relevant to AI:
**Financial sector (CNBV)**: Mexico's banking regulator requires that credit scoring models be explainable to applicants who are denied credit. This applies to AI models used in lending decisions. The CNBV has broad authority to require model documentation and testing from regulated financial institutions.
**Telecommunications (IFT)**: The Federal Telecommunications Institute regulates algorithmic recommendation systems that are part of telecommunications services, with provisions around user consent and transparency.
**Healthcare (COFEPRIS)**: AI systems used in medical diagnosis or treatment are regulated as medical devices and require COFEPRIS clearance — similar to the FDA's SaMD framework.
**Competition (COFECE)**: Mexico's competition authority has indicated interest in algorithmic price coordination — the use of competing AI pricing systems that produce parallel pricing without explicit agreement.
Mexico's comprehensive AI legislation is expected to develop following Brazil's lead. Companies operating in Mexico should establish LGPD-equivalent practices even in the absence of an equivalent law, as this will ease future compliance requirements.
Key actions for Mexico
- ·Ensure compliance with the new (March 2025) LFPDPPP for any AI system processing Mexican residents' personal data: privacy notice, ARCO rights implementation, explicit consent for sensitive processing.
- ·Update compliance contacts and filings from INAI to the Secretaría Anticorrupción y Buen Gobierno (SABG) — INAI no longer exists.
- ·For financial AI: document credit model methodology in a form that can explain individual denials to CNBV if required.
- ·For healthcare AI: determine whether COFEPRIS medical device classification applies before deployment.
- ·For cross-border data transfers involving Mexico: review whether the recipient jurisdiction provides adequate protection under the LFPDPPP.
- ·Monitor for Mexican AI legislation expected to emerge 2026-2027.
Colombia
Ley 1581 Enforced + SIC AI GuidanceAuthority: SIC (Superintendencia de Industria y Comercio)
Penalty: Up to 2,000 monthly legal minimum wages (SMMLV) — roughly $800K-$850K USD at 2026 rates, recalculated annually
Ley 1581 and AI
Colombia's data protection law, Ley 1581 de 2012, governs personal data processing and applies to AI systems that process personal data of Colombian residents. The Superintendencia de Industria y Comercio (SIC) enforces the law and has issued AI-specific guidance.
SIC issued "Guía para el Tratamiento de Datos Personales en el Contexto de la Inteligencia Artificial" in 2021 — one of the first AI-specific guidance documents in Latin America. Key points:
- ·Transparency: AI systems that make decisions about individuals must be explainable. The SIC guidance emphasizes that data subjects have a right to understand how AI decisions are made.
- ·Data minimisation: AI should process only the data necessary for the stated purpose.
- ·Bias prevention: Organisations are expected to test AI systems for discriminatory outcomes.
- ·Accountability: There must be a human responsible for AI decision-making outcomes.
Colombia has no dedicated AI law as of 2026, but the SIC guidance is the most detailed AI-specific regulatory document in Latin America outside of Brazil. Companies with Colombian operations should review the 2021 SIC guidance directly.
SIC enforcement has been active. The authority has issued fines for inadequate privacy notices, unauthorized data sharing, and failure to honor data subject rights. AI compliance in Colombia is primarily a data protection compliance exercise under Ley 1581, with additional guidance from the SIC AI document.
Key actions for Colombia
- ·Register a data controller with SIC's National Registry (RNBD) for data processing operations in Colombia.
- ·Implement Ley 1581 rights: habeas data (access, correction, suppression) for Colombian data subjects.
- ·Review SIC's 2021 AI guidance and assess compliance for AI systems affecting Colombian residents.
- ·Document explainability of AI decisions affecting individuals — a key SIC requirement.
- ·Implement bias testing for hiring, credit, or other high-impact AI systems.
Argentina
PDPA Enforced + New Law ProposedAuthority: AAIP (Agencia de Acceso a la Información Pública)
Penalty: Currently low — new law proposes significant increase
PDPA and AI
Argentina's Personal Data Protection Act (Ley 25.326, PDPA) has been in force since 2000 and is one of the oldest data protection laws in Latin America. Argentina was the first Latin American country to receive an EU adequacy decision for data transfers, which it has maintained.
PDPA applies to AI systems that process personal data of Argentine residents: - **No automated decision-making right today**: Article 10 is actually a confidentiality-duty provision, not an automated-decisions right — the current Ley 25.326 has no equivalent to GDPR Article 22 at all. This is a genuine, widely-noted gap; individuals have access/rectification/updating/deletion rights (below), but no standalone right to contest a purely automated decision. - **Data subject rights**: Access, correction (rectification), updating, and suppression rights must be implemented. A separate confidentiality duty (Art. 10) binds anyone who handles the data. - **Sensitive data**: Biometric data, health data, and political opinions require explicit consent. - **Registration**: Data controllers must register databases with the AAIP.
Argentina is in the process of modernizing its data protection framework. The AAIP circulated a preliminary reform draft in 2023, but that specific text lost parliamentary status at the end of 2024. Two new bills built on the same AAIP draft — one from deputy Pablo Carro, one from senator Martín Doñate — were introduced in Congress in 2026; both would add a GDPR/LGPD-style automated-decision-making right and raise fines to a proposed 5-to-1,000,000-unit scale (roughly 2%-4% of global annual turnover, at the top end matching GDPR's own top tier rather than falling short of it). Neither bill had been enacted as of this writing.
**AI Strategy**: Argentina published a National AI Strategy in 2023 with ethical principles for AI, but no binding AI law is in force as of 2026. The strategy emphasizes transparency, accountability, non-discrimination, and human oversight.
Key actions for Argentina
- ·Register data processing operations with AAIP if processing Argentine residents' personal data.
- ·Voluntarily offer a human-review path for automated AI decisions affecting Argentine individuals even though current PDPA has no Art. 22-style right — this closes a real gap and gets ahead of the pending reform bills.
- ·For cross-border transfers: Argentina has EU adequacy — data can flow freely from EU. Ensure Argentine data sent to other countries has adequate protection.
- ·Monitor the Carro and Doñate reform bills in Congress — either would add an automated-decision right and raise fines significantly if enacted.
- ·Align with Argentina's AI ethical principles (transparency, accountability, non-discrimination) as a baseline for any AI deployment.
Chile: New Law in 2024
Chile's Congress approved a new Personal Data Protection Law (Ley 21.719) on August 26, 2024, and it was published in the Diario Oficial on December 13, 2024, replacing the 1999 Ley 19.628. The new law is significantly more comprehensive — modeled on GDPR — and includes automated decision-making rights similar to GDPR Article 22. It establishes a new data protection authority, the Agencia de Protección de Datos Personales (APDP), and creates fines based on annual turnover.
Not yet in force: the law carries a 24-month transition period from publication — full enforcement, and the APDP's formal start of operations, begins December 1, 2026, still a few months out as of this writing. Chile also published an AI Policy in 2021 and has been active in regional AI governance discussions. If you have operations in Chile, use the runway before December 2026 to review Ley 21.719 and track its implementing regulations, which the incoming APDP is still developing.
The Latin America AI compliance picture
Latin America does not have a single AI law. What it has is data protection laws that apply to personal data in AI systems, sector-specific requirements for financial and healthcare AI, and emerging AI frameworks led by Brazil and Colombia.
For most companies operating in Latin America, the practical compliance requirement is: implement LGPD-equivalent data protection practices across all countries, add automated decision review rights for all AI systems affecting individuals, and monitor Brazil's AI Bill closely.
Brazil's AI Bill is likely to become the regional standard — similar to how GDPR became the global standard. Designing for LGPD + AI Bill compliance now reduces future compliance costs across the entire region.
Check your Latin America compliance risk
Aegis Firma covers Brazil LGPD, Mexico LFPDPPP, Colombia Ley 1581, and Argentina PDPA. Get your free risk report in 4 questions.
Get my free risk report