Reglamento de la Ley 31814, prohibited AI uses
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
In force 8 months, effective 22 January 2026.
An AI prohibited practices rule binding public and private bodies.
As of 5 September 2026.
What it requires
- Do not use an AI-based system to influence a person's decision-making in a deceptive or manipulative way, including through subliminal techniques or by exploiting cognitive, emotional, or socioeconomic vulnerabilities to substantially alter their behavior.
- Do not deploy an autonomous lethal capability that decides without human supervision and can cause physical harm or affect life or physical integrity in a civilian setting.
- Do not carry out mass surveillance using an AI-based system without a legal basis, or in a way that generates or may generate a disproportionate impact on fundamental rights.
- Do not analyze, classify, or infer a person's racial or ethnic origin, political opinions, union affiliation, religious or philosophical convictions, or sexual life or orientation from their biometric data using an AI-based system, and do not evaluate or classify people in a way that produces discriminatory or disproportionate results violating fundamental rights.
- Do not carry out real-time biometric identification to categorize people in public spaces, except for pure digital-identity authentication or the preliminary investigation of a defined list of serious crimes.
- Do not use an AI-based system to predict that a person will commit a crime based on profiling or an assessment of their personality traits.
- A system that supports a human evaluator's assessment of a person's involvement in an existing, verifiable criminal activity is not itself misuse under the real-time biometric identification prohibition, provided it carries human-oversight, transparency, and auditability mechanisms guaranteeing non-discrimination.
If you get it wrong
Criminal exposureNo
Private right of actionNo
Who enforces it
Enforcement body
Secretaría de Gobierno y Transformación Digital (SGTD), which refers a suspected violation of intellectual-property, personal-data, or other fundamental rights to the competent supervisory or prosecuting authority
What it reaches
Obligation class
Prohibition, Biometric
Who checks it
Audit expectation
none
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
Article 22 classifies AI risk into two named categories, uso indebido (misuse, deemed prohibited by definition) and high-risk use, and treats every other use as acceptable risk. Article 23 deems it misuse to influence a person's decision-making in a deceptive or manipulative way, including through subliminal techniques or by exploiting cognitive, emotional, or socioeconomic vulnerabilities to substantially alter behavior.
It is also misuse to generate an autonomous lethal capability that decides without human supervision and can cause physical harm or affect life or physical integrity in a civilian setting. Carrying out mass surveillance without a legal basis or where it generates or may generate a disproportionate impact on the exercise of fundamental rights is misuse as well.
So is analyzing, classifying, or inferring a person's sensitive data from their biometric data to deduce racial or ethnic origin, political opinions, union affiliation, religious or philosophical convictions, or sexual life or orientation, or evaluating or classifying natural persons or groups in a way that produces discriminatory or disproportionate results violating fundamental rights.
Carrying out real-time biometric identification to categorize natural persons in public spaces is misuse too, except for pure digital-identity authentication or the preliminary investigation of a defined list of serious crimes. Predicting that a natural person will commit a crime based on profiling or an assessment of personality traits is likewise misuse.
Article 23.4 excepts, specifically from the real-time biometric identification prohibition, a system that supports a human evaluator's assessment of a person's involvement in an existing criminal activity, provided the assessment rests on objective, verifiable facts and the system carries human-oversight, transparency, and auditability mechanisms guaranteeing non-discrimination.
The Regulation applies to public-administration entities and to private-sector organizations, civil society, citizens, and academia, and enters into force ninety business days after its publication. It creates no sanctioning regime of its own for a breach of these prohibitions distinct from referring suspected violations to the competent authority.
When LexLint raises it
processes_biometricshigh_risk_decisions