Series: Mexico and the New Global Architecture of Artificial Intelligence 1-16
Category: Artificial Intelligence Governance
Author: María Gabriela Cordero González
Date: September 2026
Artificial intelligence governance is entering a new stage
Over the past several years, much of the international debate on artificial intelligence has focused on establishing principles.
Human rights, transparency, safety, inclusion, human oversight, child protection and accountability have become recurring elements of the world’s leading AI governance frameworks.
This normative consensus represents significant progress. Yet it is beginning to reveal a fundamental limitation: recognizing principles does not mean having the capacity to make them effective.
The next stage of artificial intelligence governance therefore requires a partial shift in the question we are asking.
It is no longer enough to ask which principles should govern artificial intelligence.
We must also ask:
Which institutions have the legal, technical and operational capacity to turn those principles into effective protection?
This question is particularly important for Mexico and the Global South.
From normative consensus to institutional capacity
This reflection is one of the principal conclusions I drew from my participation in the Global Dialogue on Artificial Intelligence Governance, held in Geneva in July 2026, and from the subsequent report I prepared on its implications for Mexico.
International discussions reveal an increasingly complex global governance architecture in which legal instruments, technical standards, scientific assessments, cooperation mechanisms and different regulatory models coexist.
But there remains a gap between this architecture and its implementation.
A law can recognize rights. A standard can establish requirements. An international declaration can define principles.
Yet when an artificial intelligence system affects a public decision, the State must be able to answer much more concrete questions:
Who developed the system? What evidence was used to evaluate it? Does it perform adequately for the population in which it is deployed? Who oversees its operation? What happens when it fails? Who is legally accountable? Can an individual challenge its outcome? Is there institutional capacity to suspend it?
If institutions cannot answer these questions, governance remains largely declaratory.
Recent scholarship points toward precisely this transition. An analysis of 263 academic studies on AI and public-sector governance identifies a shift from literature focused on technology adoption toward one concerned with institutional governance, including tensions between capability and control, efficiency and equity, automation and discretion, and innovation and democratic legitimacy (Syahbar et al., 2026).
Adopting artificial intelligence is not the same as governing it
This distinction is fundamental.
A State may introduce artificial intelligence into public administration while lacking sufficient capacity to govern it.
It may procure a system without fully understanding how it operates.
It may automate a procedure without adequate auditing mechanisms.
It may deploy models developed in other contexts without sufficient evidence of their performance for the Mexican population.
It may even create legal obligations without having the personnel, infrastructure or institutions required to verify compliance.
Therefore, technological adoption capacity and governance capacity are not equivalent.
Research from other Global South institutional contexts identifies similar challenges. AI implementation in public administration may be constrained by insufficient infrastructure, poor data interoperability, limited technical expertise and weak governance mechanisms (Nokele & Matshela, 2026). Research on developing-country governance also indicates that international principles need to be translated into operational mechanisms such as impact assessment, lifecycle monitoring, algorithmic auditing and institutional oversight (Tohopi et al., 2025).
The real divide does not end with access
This raises a particularly important issue for Mexico.
International inequality in artificial intelligence is often measured in terms of access to technology, infrastructure, connectivity or models.
But this measurement is incomplete.
A country may have access to advanced systems while remaining dependent on third parties to develop, evaluate or audit them—or even to determine the conditions under which they should be used.
The issue is therefore not only who can use artificial intelligence.
It is also who has the capacity to understand, evaluate, govern and make decisions about it.
My post-Geneva report identifies precisely this distinction between an access gap and a capacity-and-influence gap. When computing resources, advanced models, infrastructure and specialized expertise are concentrated among a limited number of actors, lower-capacity States risk becoming consumers of systems over which they have limited decision-making power.
Reducing the digital divide without building institutional capacity may therefore reduce one inequality while deepening another: technological dependence.
Mexico needs its own evaluation capacity
There is another challenge that cannot be addressed simply by importing standards.
Artificial intelligence systems may perform differently depending on language, geography, population and institutional context.
An evaluation conducted in another country does not automatically demonstrate that a system is appropriate for Mexico.
Mexican AI governance must therefore develop the capacity to evaluate systems in Mexican Spanish, Indigenous languages and domestic administrative contexts, while measuring differentiated impacts across gender, age, disability, territory, language and income.
This does not mean rejecting international standards.
It means something different: contextualizing them without weakening protection.
Mexico should participate in developing international rules while simultaneously building domestic evidence about how those rules and technologies operate within its own reality.
From regulation to an implementation architecture
If institutional capacity is part of governance, the response must extend beyond passing an artificial intelligence law.
Mexico needs an implementation architecture.
Among other measures, this means knowing which AI systems are being used across the public sector; establishing impact assessments for systems capable of affecting rights; creating technically useful registries and documentation; developing testing and auditing capacity; monitoring systems after deployment; establishing incident-reporting mechanisms; guaranteeing meaningful human oversight; and ensuring effective avenues for information, challenge, review and remedy.
Comparative research similarly suggests that responsible adoption requires legal safeguards and institutional capacity to operate together. For resource-constrained administrations, proposed governance models include AI registries, pre-deployment assessment, monitoring, audits, independent oversight and accessible grievance mechanisms (Ahmad, 2026).
Governance, therefore, does not end when a regulation is published.
That is where its most important test begins.
Capacity to protect
The central question for Mexico should not only be how much of the artificial intelligence revolution it can adopt.
It should also be how much it can govern.
The next stage requires a State capable of understanding the systems it uses, demanding evidence, auditing outcomes, identifying harm, assigning responsibility and guaranteeing remedy.
This leads to an idea that will remain central throughout this series:
Technological sovereignty does not necessarily mean producing everything domestically. It means preserving effective decision-making capacity over technologies that affect rights, institutions and strategic interests.
Mexico does not need to choose between innovation and protection, or between international cooperation and autonomy.
It needs the institutional capacity to participate in global governance from a position of its own.
Because the next stage of artificial intelligence will not be defined solely by who possesses the most powerful models.
It will also be defined by who has the institutions capable of governing them.