Mexico deepfake regulation

San Luis Potosí Repeals Its AI-Deepfake Law After Using It to Prosecute 16 Journalists

Facing a Supreme Court challenge and a wave of journalist arrests, San Luis Potosí scrapped its AI-impersonation statute rather than let the SCJN strike it down.

The Rise and Fall of the Ley Serrano People of Internet Research · Mexico 16+ Journalists/activists prosecuted Documented cases of judicial haras… 6 years Maximum prison sentence Penalty for AI-manipulated content… 22-0 Repeal vote Unanimous vote of deputies present… ~8 months Months the law was in force Passed November 14, 2025; repealed… peopleofinternet.com
The Rise and Fall of the Ley Serrano People of Internet Research · Mexico 16+ Journalists/activ ists prosecuted 6 years Maximum prison sentence 22-0 Repeal vote ~8 months Months the law was in force peopleofinternet.com

Key Takeaways

A law born from a governor's denial

The "Ley Serrano" began, by most accounts, as an act of political self-defense. In October 2025, videos circulated online appearing to link San Luis Potosí Governor Ricardo Gallardo Cardona to organized crime. Gallardo denounced them as AI-generated fabrications and publicly urged the state Congress to legislate against the misuse of artificial intelligence. Weeks later, PVEM deputy Héctor Serrano Cortés introduced exactly that, and on November 14, 2025 the state approved new Penal Code provisions — Article 187 Ter and a new Chapter V (Articles 272 Bis and 272 Ter) — criminalizing unauthorized use of a person's image, voice, or identity via AI, plus "deliberate dissemination" of AI-manipulated content intended to cause "alarma social," with penalties up to six years in prison (El Universal).

On July 30, 2026, the same Congress killed it. In an extraordinary session moved up from 10 a.m. to 8:30 a.m., 22 deputies voted unanimously to repeal all three articles, with Serrano himself among them (La Orquesta; R3D). The law lasted eight months.

The steelman: deepfakes are a real governance problem

Before dismissing the Ley Serrano as pure pretext, it's worth taking the underlying concern seriously. Synthetic media genuinely can defame private citizens, fabricate evidence, and — as Gallardo argued about his own case — be weaponized to frame public officials as criminals. Mexico, like most jurisdictions, has no federal deepfake-specific criminal statute, and identity-based AI harms (non-consensual intimate imagery, voice-cloning fraud, impersonation for extortion) are a documented, growing problem across Latin America. A state legislature moving to fill that gap is not inherently illegitimate, and other governments — from the EU's AI Act transparency obligations to several U.S. states' election-deepfake laws — have concluded some criminal or civil backstop is warranted. The instinct to regulate wasn't the failure. The drafting was.

Why it collapsed

The National Human Rights Commission (CNDH) filed a constitutional challenge — Acción de Inconstitucionalidad 132/2025 — before Mexico's Supreme Court (SCJN) on December 17, 2025, barely a month after the law took effect. CNDH's petition argued the offenses violated the taxatividad principle: that "the criminal conduct prohibited, when committed through the use of artificial intelligence, is not described in a clear and precise manner," making the statute disproportionate and incompatible with the ultima ratio character criminal law is supposed to have (CNDH). Press-freedom organization Article 19 filed an amicus brief echoing that the vague "social alarm" standard created an "inhibitory effect incompatible with a democratic society" (Article 19).

While that case sat pending, the vagueness stopped being theoretical. Starting May 21, 2026, prosecutors used the law against working journalists and communicators — including Christian Herrera of the Facebook page Código Rojo and Eréndira Reyes Aguillón — over content critical of local authorities. Human rights groups documented at least 16 journalists and activists subjected to judicial harassment or arrest warrants under the statute before it fell (Infobae). R3D, the Mexican digital-rights group, concluded the "ambiguous" definitions had turned the law into "a mechanism of intimidation and censorship," a risk it flagged as especially acute ahead of Mexico's 2027 elections (R3D).

Faced with a pending Supreme Court loss and mounting documentation of exactly the abuse critics predicted, Gallardo signed his own repeal initiative on July 17, 2026 rather than wait for the SCJN to strike the law down for him — and Congress finished the job two weeks later.

The lesson for the next draft

This is a case study in what goes wrong when a criminal statute is written to solve a governor's political grievance rather than a defined harm. "Alarma social" was never a legally cognizable standard; it was elastic enough to cover a viral meme, an investigative report, or an actual disinformation campaign, and the discretion over which was which sat entirely with local prosecutors. That is precisely the design flaw proportionate deepfake regulation has to avoid: narrow, conduct-specific definitions (non-consensual intimate imagery, financial fraud, impersonation of a specific person for material gain) survive constitutional review and civil-liberties scrutiny; open-ended "causing alarm" or "spreading misinformation" offenses do not, because they hand the state a ready-made tool against its critics.

Gallardo's August 6 announcement of a replacement law — built through an Open Parliament process with academics, media, and civil society at the table — is the right instinct, and a stronger signal than most legislatures give after a rushed law backfires (El Sol de San Luis). Whether it holds will depend on whether the next draft trades vague harm-to-the-state language for narrow, victim-specific offenses — and whether San Luis Potosí's Congress, having just unanimously admitted its first attempt was a censorship tool, is willing to say no to a governor a second time if it isn't.

"Proceedings initiated against journalists and other critical voices evidence [this law's] potential to be used as a mechanism of intimidation and censorship, especially in the face of the 2027 electoral process." — R3D, July 2026

Sources & Citations

  1. CNDH — Acción de Inconstitucionalidad 132/2025
  2. R3D — Ley Serrano bajo escrutinio
  3. Article 19 MX-CA — repeal analysis
  4. Infobae — SLP deroga ley de IA
  5. El Universal — Congreso deroga Ley Serrano
  6. El Sol de San Luis — Gallardo announces new AI law