A surveillance buildout with no statute behind it
On August 19, 2026, Amnesty International published Sensing the Surveillance State, documenting how Argentina's security ministry spent at least US$1.2 million between 2024 and 2025 assembling an AI-driven surveillance apparatus — and did it almost entirely through executive resolutions and decrees, never a vote in Congress.
The paper trail is unusually well-documented for a security procurement story. Resolución 710/2024, published July 29, 2024, created the Unidad de Inteligencia Artificial Aplicada a la Seguridad (UIAAS) inside the Cybercrime Directorate — tasked with patrolling open social media, running facial recognition against camera feeds, and predictive crime analysis. Its own text notes the measure required no budget appropriation, meaning it never touched a legislative process at all. Four months later, Resolución 1234/2024 made a Unified Facial Recognition Protocol mandatory across the Federal Police, Gendarmería, Prefectura Naval, and Airport Security Police — with classified annexes. In October 2025, the ministry directly contracted a Clearview AI facial-recognition license for $33,500, plus a $239,000 Maltego OSINT platform pulling from over 100 open sources including the dark web, and roughly $940,000 in thermal-camera drones and ground stations. Then, on December 31, 2025, Decreto 941/2025 restructured the entire National Intelligence System by decree, expanding data-sharing mandates ahead of any statute governing how AI systems may process that data.
The other AI policy: keep it unregulated
This buildout runs on a parallel track to the government's public AI agenda. In a June 4, 2026 op-ed, President Milei and Deregulation Minister Federico Sturzenegger pledged three pillars to attract AI investment: a low corporate tax rate, a new "non-human corporation" category for AI-run businesses, and — explicitly — "a commitment to keep AI unregulated so that it can develop freely," as reported by the Buenos Aires Times. The corporate-entity bill was submitted to Congress in May 2026.
The contradiction Amnesty surfaces isn't that Argentina regulates commercial AI too little while overregulating state AI — it's the opposite of what the government's own rhetoric implies. The one form of AI deployment that most obviously warrants a floor of legal constraint — government use of biometric identification and mass social-media monitoring against citizens — has none, while the government's loudest public commitment is to make sure AI in general never gets one.
Amnesty's case, taken seriously
The strongest version of Amnesty's argument shouldn't be waved away. Facial recognition and OSINT tools were rolled out via ministerial resolutions with classified annexes, reviewable by no independent data-protection authority with real enforcement teeth — Argentina's Personal Data Protection Law dates to 2000, decades before biometric mass surveillance was technically or financially feasible at this scale. Amnesty documented, through interviews with 21 journalists, activists, and pensioners, a genuine chilling effect: people self-censoring protest and reporting because they believe they're being watched. That's a real and measurable harm, not a hypothetical one, and the EU's AI Act already treats real-time biometric surveillance in public spaces as a high-risk category requiring judicial authorization for exactly this reason.
Why an "AI law" isn't the fix
Where the critique goes astray is in implying the remedy is a general AI statute. Argentina's problem isn't that AI as a technology lacks a framework — it's that specific government powers were expanded by decree instead of law: warrantless biometric identification, no data-retention limits, no independent oversight of a facial-recognition protocol whose annexes are classified. A horizontal AI law aimed at the technology itself would either sweep in unrelated commercial and research uses — undermining the very investment pitch Milei is making to data-center operators — or, given this government's demonstrated pattern of governing security policy by DNU, simply get enacted the same way and entrench the powers rather than constrain them.
The proportionate answer
What's missing predates AI entirely: judicial warrant requirements before biometric identification of an individual, statutory data-retention and deletion limits, an empowered and independent data-protection regulator, and a legislative — not classified-annex — origin for any protocol governing police use of facial recognition. None of that requires touching the corporate-AI framework Milei is pitching to investors, and all of it is compatible with keeping Argentina open for AI business. The failure here isn't too little AI regulation; it's that the one part of the state's AI use with genuine coercive power over citizens got the least scrutiny of all.