Blog · AI Governance

VIGIA: A Pipeline to Accelerate AI Governance in Mexico

§Abstract

In this paper we argue that the main problem for accelerating AI Governance in nations such as Mexico is constrained by the almost nonexistent AI safety vocabulary in the country. As a result, AI risks are not conceptualized in the official discourse, which makes those risks invisible to the various spheres that drive the progress of AI regulation. We call this bottleneck a higher-order risk.

ScopeWe do not claim that this is the only bottleneck for AI Governance in Mexico, but rather one that we believe is important and that is also upstream of several of the others.

To overcome this bottleneck we propose a pipeline whose ultimate goal is to make visible the risks of AI, and we produced a first implementation of this pipeline for Mexico. We also suggest future steps that can be built on top of it. In the end, we believe this could be replicated for other countries that are in a similar state.

1Introduction

What is not mentioned does not exist.

To overcome this bottleneck we propose a pipeline whose ultimate goal is to make visible the risks of AI, and we produced a first implementation of this pipeline for Mexico. We also suggest future steps that can be built on top of it. In the end, we believe this could be replicated for other countries that are in a similar state.

Pipeline
The strategy we propose, divided into steps, to unblock the bottleneck and thereby accelerate AI Governance.
First-type and second-type nations
First-type nations have the capacity to produce frontier models. Second-type nations do not have it and are mainly consumers of that technology.
Invisibilization of AI risks
The phenomenon we study: that the use of AI appears in the discourse without any associated risk being named. It does not mean that the use is hidden, but that the operation of naming it as a risk is missing.
Higher-order risk
Invisibilization itself, understood as a risk, because it acts on the capacity to manage all the others. The term is ours.
Official discourse and public discourse
The first is where the State speaks in its own voice and with legal effects. The second is the conversation in the press and digital media.

In the field of AI we can categorize nations into two types: those with the capacity to produce frontier models and those without it.

First-type nations, being in direct contact with the frontier, can observe the risks of AI, they have institutions, research centers and, above all, their own conceptualization and language for the discourse on the risks related to artificial intelligence.

Second-type nations are mainly consumers of the frontier technology of the former, but institutions and research centers for artificial intelligence safety are almost nonexistent. We say "almost" because AI Safety México [1] is the only Mexican organization we know of whose declared purpose is to make these risks visible, in a register different from that of ethics and responsible AI, where the Mexican field is older and more populated. There is no public promotion of these risks, and much less can these conceptualizations be spoken of. Therefore, at an epistemic level these risks are nonexistent in the public discourse and, much worse, they do not exist in the official discourse.

If this language does not exist, then it is practically impossible to progress toward the recognition of AI risks and therefore toward AI Governance in Mexico. It is thus a bottleneck for AI Governance.

It is worth giving the previous problem a name in order to address it. The risks documented by first-type countries are first-order risks: a system fails, discriminates, surveils, displaces work. The invisibilization of those risks in public and official discourse operates one level above, because it does not cause harm by itself but rather prevents first-order harms from being noticed and corrected, and for that reason we call it a higher-order risk. It also has the property of concealing itself: a legislator who reviews an AI deployment agreement and finds in it no mention of bias or human oversight does not perceive an omission, because the document looks normal.

To overcome this higher-order risk we propose a pipeline whose objective is to make visible the risks of AI through the analysis of official and public discourse. In this way, the actors and agents who could contribute to governance would already have the conceptual framework to begin regulating in order to avoid the risks of AI.

2Similar work

The idea that a problem without a name does not reach the agenda has theoretical support. Kingdon [2] distinguishes between a condition and a problem, and notes that the category in which an issue is placed determines which remedies are considered appropriate. The formulation closest to what we argue here comes from the sociology of law: Felstiner, Abel and Sarat [3] show that an injurious experience that is never named does not become a grievance and therefore never reaches an institution that could address it.

It is worth stating which part of this pipeline is not novel. Counting AI mentions in official text was the method of the AI Index between 2016 and 2024 [4], coding government documents against a fixed taxonomy is the trade of the Comparative Agendas Project [5], and using an LLM for this has been evaluated with published figures [6]. Mexico already has its registry of public algorithms in Algoritmos CIDE [7] and Cação et al. [8] tracked environmental policy in the Diário Oficial da União. The closest precedent is Trielli, Stark and Diakopoulos [9], who built a vocabulary of 61 terms precisely because agencies do not say «AI».

3Operationalization

The operationalization of the pipeline, in the abstract and without reference to any particular country, suggests the following methodology.

  1. Identify official documents in which official discourse publishes its initiatives and use of artificial intelligence.
  2. Identify in each of these documents both explicit and implicit mentions of the use of artificial intelligence.
  3. Identify official documents in which official discourse publishes its initiatives and use of artificial intelligence.
  4. Report the finding: explain why it is a risk, with what level of urgency, and give some initial recommendations on how to resolve this gap.
  5. Create concrete reports for the potential drivers of AI Governance, such as researchers, legislators and the general public.
  6. Monitor in public discourse how far the AI risk lexicon is being adopted, through media such as digital newspapers. That is, measure how far the language of AI risks is used.

4Implementation in Mexico

Create concrete reports for the potential drivers of AI Governance, such as researchers, legislators and the general public.

The DOF is the natural choice because it is the vehicle through which the acts of the Mexican State acquire legal validity, so a use of AI that appears there has moved past the stage of a plan: it is a fact of government with a date and a signature. It is also public and downloadable, which makes the exercise reproducible. The corpus is 153 issues of the morning edition, from 3 November 2025 to 12 June 2026.

An LLM (Claude Opus 4.8) reads each complete issue, identifies explicit and implicit mentions of AI use and classifies each one against the 15 categories in Appendix A with a severity level. For each finding it outputs the original text fragment, its location in the document, the relevance analysis, the risk categories with their severity and one or more recommendations. Steps 5 and 6 are outside the scope of this iteration. The observatory with the results of this implementation is published at vigia-3-0.us-central1.run.app.

1 · Sources 2–3 · Identification and classification 4–5 · Outputs 6 · Monitoring DOF Diario Oficial de la Federación 153 issues Doc 2 Doc N full text Language model Claude Opus 4.8 2 Detects mentions of AI use explicit and implicit 3 Classifies the associated risk categories R1 to R15 and severity reads each complete issue findings Finding original text fragment risk, severity and urgency recommendation Reports by audience researchers legislators general public · Report N dissemination Public discourse monitoring media and digital newspapers measures how far the AI risk lexicon circulates the lexicon enters official discourse implemented in this iteration planned or extensible
Figure 1. High-level architecture of the pipeline. Note that in this case we represent the implementation for Mexico, VIGIA, where the DOF was used as the only document. "Doc N" indicates that more documents can be added to the pipeline, and likewise for the reports. That the lexicon returns to the official discourse, marked in color, is the sign that the pipeline would be working.

5Results

We analyzed 153 issues of the DOF from 03-11-2025 to 12-06-2026 and observed the following.

249literal mentions of «inteligencia artificial» [artificial intelligence], in 57 issues
545implicit mentions of AI use
0mentions of any AI risk named as such

Implicit mentions are passages where the State deploys what is in fact an AI system without naming it as such, and they are four times as many as the 136 explicit ones counted by the model.

5.1 The AI risk lexicon is absent

We searched for the AI safety vocabulary in the complete corpus.

AI risk lexicon in 153 issues of the DOF
TermOccurrencesNote
risks of artificial intelligence0
artificial intelligence safety · AI safety0
artificial intelligence governance0
artificial intelligence ethics0
algorithmic transparency0
explainability · interpretability0
algorithmic auditing0
algorithmic impact assessment0there is 1 of «data protection impact assessment», which is a different instrument
high-risk AI system0
frontier model · frontier AI0
model alignment0
red teaming · dangerous capabilities0
deepfake · ultrafalso0
misuse of AI0
meaningful human oversight0there is 1 of «intervención humana mínima» [minimal human intervention], in the Value Added Tax Law, unrelated
automated decisions (as a regulated instrument)05 of «automated processing», in treaty titles and medical equipment data sheets
algorithmic bias1institutional program of El Colef, an academic center
responsible AI · ethical AI2one is a footnote citing UNESCO, the other a strategic plan of CIDESI

Occurrences is the total number of times the expression appears in the 153 issues, not the number of documents that contain it.

Sixteen of the eighteen terms do not appear even once, and the three cases that do appear come from two public research centers and a bibliographic citation, none of them a regulator. We also searched for which words accompany each mention of AI: of the 249, only 17 (6.8%) have any risk or safeguard word within 200 characters. Widening the window to 500 characters yields 40 cases, but on reviewing them one by one none refers to AI risks, because in all of them «seguridad» means food, water, social or public security, or cybersecurity.

5.2 How AI appears when it appears

We manually classified the 249 mentions according to the framing with which AI appears in the passage.

Framing of the 249 mentions
FramingMentions%
Capability, benefit or line of research18172.7
Procurement, procurement line item or technical data sheet2911.7
Glossary, list of acronyms or bibliography208.0
Harm framing, AI as a source of harm or subject to a limit187.2
Other10.4

Mentions counts each appearance of the expression «artificial intelligence» in the corpus, classified by how the passage containing it frames it.

The central result is in those 18 mentions with harm framing: none uses vocabulary proper to AI risks, and all of them borrow the framing of an earlier legal regime. Six come from copyright and image and voice rights, four from academic integrity, two from public ethics, two from gender violence via CEDAW, two from consumer law, one from administrative sanctioning law and one from patient data protection.

5.3 Risks identified

Of the 665 findings, 636 (95.6%) are marked as a regulatory gap, and they are distributed across 1,466 finding-risk pairs over 15 categories. In severity, 582 pairs (39.7%) are High or above, and 50 of the 153 issues are marked as requiring urgent attention.

Finding-risk pairs by category
CategoryPairsIssues
R3 Invasion of privacy406134
R2 Discrimination and bias301127
R1 Failures and errors233107
R9 Authoritarian surveillance17796
R10 Concentration of power7450
R7 Labor displacement7252
R15 Emerging risks4527
R4 Disinformation and deepfakes4430
R8 Social connection3423
R5 Copyright2721
R13 Loss of control2417
R12 Military escalation1211
R6 Labor exploitation119
R11 Bioterrorism66
R14 Agent misalignment00

Pairs is how many times that risk category was assigned to a finding; a single finding can receive several categories. Issues is in how many of the 153 issues of the DOF at least one finding of that category appears.

5.4 Some examples

  • National AI infrastructure without a risk framework. On 29 May 2026 the Technical Committee of the Coatlicue supercomputer is created, in order to strengthen «las capacidades nacionales en materia de supercómputo e inteligencia artificial» [national capabilities in supercomputing and artificial intelligence]. It is the most explicitly AI-oriented instrument in the corpus and it contains no provision on permitted uses, model evaluation or access.
  • When risk enters, it enters borrowed. On 30 January 2026 the INE Strategy against gender-based political violence takes up General Recommendation 40 of CEDAW and calls for a response to «contenido generado por usuarios e inteligencia artificial que constituya un acto de violencia de género» [content generated by users and artificial intelligence that constitutes an act of gender-based violence]. It is the only explicit mention of AI in that issue and it arrives by way of an international recommendation.

Appendix B collects further examples, organized by the way in which the risk is rendered invisible.

6Limitations

There are some limitations in our first implementation of the proposed pipeline.

  • For this we used an LLM to do all the identification and classification, in this case Claude Opus 4.8, and we did not use any other model to compare the results. So these results are framed by the model's interpretation and by known limitations, such as hallucination or lost in the middle effects, aggravated by the enormous length of the documents: the median DOF issue is around 389 pages.
  • The risk categories used are inherited from frameworks of first-type countries, as we defined them at the beginning, and it could be the case that we need additional or adapted categories that make more sense for the nature of second-type countries, such as Mexico. For example, the invisibilization of the existing risks of AI, which is the higher-order risk we define here, is not classifiable within this taxonomy. Other similar risks could be identified.
  • We note that for the monitoring layer of the pipeline we want to exclude our own dissemination of reports; otherwise we may be contaminating the "metric", and we do not want that: we want to measure the organic infiltration of AI risk language into the discourse.

7Future work

On the pipeline

  • Test the current LLM classification approach and define a more robust one, running at least a second model and validating a subsample with human reviewers.
  • Add to the current operation the channel and the actors that best make use of the information, since our objective is to accelerate AI Governance.
  • Identify which format works best for communicating the results to the promoters of AI Governance.
  • Define better metrics that we can use to monitor how far AI risks are made visible in public discourse.

We also think that this pipeline can be used, in a very similar version, in other second-type countries.

On the Mexican implementation

  • Use the results to identify Mexico's most urgent needs in terms of regulation.
  • Use the results to define the largest future step that could have the greatest impact.

And what we think is the largest future step is to build on top of it a defense strategy that is specific to second-type countries such as Mexico. For first-type countries there are other strategies, such as MAIM (Mutual Assured AI Malfunction, the deterrence regime based on preventive sabotage of Hendrycks, Schmidt and Wang [10]) or the Mutual Assured Compute Destruction of the AI 2040 plan [11], but they respond to the nature of those nations with the capacity to produce frontier models: MAIM does not mention middle powers, the Global South or Mexico even once, and the agreement in the second is bilateral between the United States and China. In the concrete case of Mexico, we think that the defense strategy can be operationalized via regulation, along the lines of Viri Ríos [12], who argues that the country «no puede desarrollar una IA que compita con las de Estados Unidos o China, pero sí puede protegerse contra los abusos de estas» [cannot develop an AI that competes with those of the United States or China, but it can protect itself against their abuses]. That will be crucial for balancing the power dynamics of AI between first-type and second-type nations.

8Conclusion

In this work we proposed a pipeline to advance AI Governance in countries that do not produce frontier AI but do use it. We established that one of the main bottlenecks is the invisibilization of AI risk and that, because of this conceptualization, AI Governance cannot progress. We conceptualized this bottleneck as a higher-order risk that needs to be addressed, and our pipeline is the operationalization for addressing this risk.

We built a first version of this pipeline for Mexico, and further iterations can be made to make this implementation more robust and to have more material. We also invite other second-type nations to apply this pipeline to their own official discourse.

AAppendix A. Risk categories

VIGIA classifies each detected AI use against a fixed taxonomy of fifteen categories, adapted from two published frameworks: BlueDot Impact's review of AI risks [13] and Annex A on future risks of frontier AI from the UK Government Office for Science [14].

In checking the sources for this text we found that neither one is a formal taxonomy, and it is worth saying so before the table. The British Annex A contains no table of categories with names and definitions: its paragraph 85 is a list of eight loose, unlabeled sentences, preceded by the warning that it is not exhaustive, and its paragraph 89 separately lists three pathways to catastrophic risk. The BlueDot text, for its part, is a pedagogical blog entry with thirteen risk headings plus a catch-all for unknown risks, without formal definitions. The labels R1 to R15 are ours and the correspondence with the sources is one of inspiration and not of citation.

Categories R1 to R15
CategoryWhat it coversPairs
R1Failures and errorsThe system makes a mistake or behaves in an unforeseen way and the erroneous decision produces harm.233
R2Discrimination and biasThe system reproduces or amplifies disadvantages affecting particular groups.301
R3Invasion of privacyCollection, inference or cross-referencing of personal data beyond what was consented to or what is necessary.406
R4Disinformation and deepfakesGeneration of false or manipulated content and its circulation at scale.44
R5CopyrightUse of protected work in training or generation, and impersonation of a work, voice or performance.27
R6Labor exploitationConditions of those who label data, moderate content or are subject to algorithmic management.11
R7Labor displacementReplacement of human work by automated systems.72
R8Social connectionDeterioration of the social bond through the mediation of systems.34
R9Authoritarian surveillanceCapacity to observe, identify and track people at population scale.177
R10Concentration of powerDependence on few providers and accumulation of decision-making capacity.74
R11BioterrorismFacilitation of the design or acquisition of dangerous biological agents.6
R12Military escalationMilitary use and acceleration of decision cycles in conflict.12
R13Loss of controlGradual delegation of decisions without an effective capacity to reverse them.24
R14Agent misalignmentAutonomous systems that pursue objectives other than those entrusted to them.0
R15Emerging risksWhat does not yet have a category of its own.45

Pairs is how many times that category was assigned to a finding in the corpus; a single finding may receive several categories.

BAppendix B. How language is rendered invisible in the mentions

B.1 The capability framing

This is the dominant mode, with 181 of 249 mentions (72.7%). AI appears as an input to modernization, in a list alongside other technologies and always on the benefit side. The structure of the sentence leaves no syntactic slot for a risk.

«…impulse la creación y adopción de soluciones innovadoras en generación, transmisión, distribución y uso eficiente de energía eléctrica, con incorporación de la inteligencia artificial, el internet de las cosas, la digitalización, la ciberseguridad industrial y los materiales avanzados.» ["…promote the creation and adoption of innovative solutions in the generation, transmission, distribution and efficient use of electrical energy, with the incorporation of artificial intelligence, the internet of things, digitalization, industrial cybersecurity and advanced materials."]

DOF, 1 June 2026 · Institutional Program of INEEL

B.2 The procurement line item

29 mentions (11.7%). AI enters the State through the administrative door, in a tender, a budget line or an equipment specification sheet. The document format does not provide for the question of risk, so the question is not asked.

«Licitación Pública Internacional Abierta Número ASF-DGRMS-LPIA-07/2025. Descripción de la licitación: Suscripción de Chatbot de Inteligencia Artificial y Servicio de Suscripción de Software Gestor de PDF.» ["International Open Public Tender Number ASF-DGRMS-LPIA-07/2025. Description of the tender: Subscription to an Artificial Intelligence Chatbot and Subscription Service for PDF Manager Software."]

DOF, 4 November 2025 · Auditoría Superior de la Federación

B.3 The system that is never called AI

This is the most consequential form and it does not appear in the count of mentions because by definition there is no mention. The instrument describes in technical detail a biometric recognition system, and does so in the vocabulary of the administrative registry. There are 545 implicit uses against 136 explicit ones.

«Verificar que la información biométrica contenga, al menos, tres de los siguientes registros: a) Registro de datos de identificación, incluyendo el Código de Identificación Biométrica; b) Registro decadactilar; c) Registro de íris; d) Registro de reconocimiento facial, y e) Registro de voz.» ["Verify that the biometric information contains at least three of the following records: a) Record of identification data, including the Biometric Identification Code; b) Ten-fingerprint record; c) Iris record; d) Facial recognition record, and e) Voice record."]

DOF, 30 January 2026 · Biometric registry of Persons Deprived of Liberty

B.4 The borrowed framing

When risk is in fact named, in 18 mentions (7.2%), it arrives wrapped in an earlier legal regime. In the example below the framework is copyright and related rights, that is, an intellectual property regime that already protected the performer’s voice and image and that simply extends that protection to what an AI system produces.

«…la suplantación de sus interpretaciones o ejecuciones por sistemas de inteligencia artificial o cualquier otra tecnología que resulten en generación de clones de sus interpretaciones o que simulen su voz de manera identificable.» ["…the impersonation of their performances or renditions by artificial intelligence systems or any other technology resulting in the generation of clones of their performances or simulating their voice in an identifiable manner."]

DOF, 14 May 2026 · Amendments to the Ley Federal del Trabajo and the Ley Federal del Derecho de Autor

B.5 The exception

In all the law published during those seven months, the only sentence in the corpus that states an AI risk in its own vocabulary is in the internal program of an academic center.

«Entenderla y saber utilizarla no solo puede significar oportunidades para potencializar la investigación y la docencia […] sino que también conlleva riesgos, como los sesgos algorítmicos, el plagio y los fraudes en los trabajos académicos.» ["Understanding it and knowing how to use it may not only mean opportunities to enhance research and teaching […] but it also carries risks, such as algorithmic biases, plagiarism and fraud in academic work."]

DOF, 23 December 2025 · Institutional Program of El Colegio de la Frontera Norte

·References

  1. AI Safety México. aismx.org
  2. Kingdon, J. W. (1993). How Do Issues Get on Public Policy Agendas?. In Wilson (ed.), Sociology and the Public Agenda, Sage.
  3. Felstiner, W. L. F., Abel, R. L., and Sarat, A. (1980-81). The Emergence and Transformation of Disputes: Naming, Blaming, Claiming…. Law & Society Review 15(3-4), 631-654.
  4. Stanford HAI (2026). AI Index Report 2026, Chapter 8: Policy and Governance.
  5. Sebők, M., Máté, Á., Ring, O., et al. (2025). Leveraging Open Large Language Models for Multilingual Policy Topic Classification. Social Science Computer Review 43(2), 295-317.
  6. Halterman, A., and Keith, K. A. (2026). Codebook LLMs: Evaluating LLMs as Measurement Tools for Political Science Concepts. Political Analysis 34, 188-204.
  7. Algoritmos CIDE. Inventario de aplicaciones de inteligencia artificial en el gobierno mexicano. Centro de Investigación y Docencia Económicas.
  8. Cação, F. N., Reali Costa, A. H., Unterstell, N., et al. (2022). Tracking environmental policy changes in the Brazilian Federal Official Gazette. arXiv:2202.10221.
  9. Trielli, D., Stark, J., and Diakopoulos, N. (2017). Algorithm Tips: A Resource for Algorithmic Accountability in Government. Computation + Journalism Symposium.
  10. Hendrycks, D., Schmidt, E., and Wang, A. (2025). Superintelligence Strategy: Expert Version. arXiv:2503.05628.
  11. Kokotajlo, D., Greenblatt, R., Larsen, T., et al. (2026). AI 2040: Plan A. AI Futures Project.
  12. Ríos, V. (2026). La trampa de la IA que México no está viendo. Milenio, «No es normal» column, 15 June 2026.
  13. Jones, A. (2024). What risks does AI pose?. BlueDot Impact. blog.bluedot.org/p/ai-risks
  14. UK Government Office for Science (2023). Future Risks of Frontier AI (Annex A), October 2023. assets.publishing.service.gov.uk

Corpus: 153 morning editions of the Diario Oficial de la Federación, from 3 November 2025 to 12 June 2026.
VIGIA. Valoración de Impactos Gubernamentales de IA. Working paper.