Law / United States / New Mexico

New Mexico

United States law applies in New Mexico New Mexico is a state of the United States, whose 32 researched instruments are listed on the United States page, not here. The law of New Mexico, described on this page below, applies here too.

6 of 7 named instruments researched to a stage, across four of the six areas of law we track: 3 in force and 3 enacted but not yet in force. As of 16 September 2026.

  1. AI law 2
  2. Privacy law 2
  3. Scraping law 1
  4. Cybersecurity law 1
  5. Age gating law none researched
  6. News aggregation law none researched

in forceenacted but not yet in forceproposedrepealed, withdrawn or blocked

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

AI law2 instruments, 2 in force

Research summary (359 words)

New Mexico's most consequential enacted AI-specific duty lives in its election law.

House Bill 182 (2024) amended the Campaign Reporting Act's disclaimer section, Section 1-19-26.4, and enacted a new Section 1-19-26.8 to require a disclaimer on a political advertisement containing materially deceptive media, an image, video or audio that depicts an individual doing or saying something they did not do or say, is published without that individual's consent, and is produced in whole or in part using artificial intelligence, and separately makes distributing such media without the required disclaimer a crime; the New Mexico Ethics Commission has stated it has never taken enforcement action under the requirement, including against a political-satire outlet that has filed a pre-enforcement lawsuit challenging it.

Outside election law, no New Mexico statute imposes a general consumer-facing duty to disclose AI use, label synthetic content, or govern high-risk automated decisions.

New Mexico's Artificial Intelligence Act (2025 HB 60) and three further 2026 bills, an AI Accountability Act (HB 141), a bill expanding the state's intimate-image distribution offense to synthetic deepfakes (HB 22), and a narrower AI Transparency Act on consequential decisions (HB 28), were all introduced and died without passing, so none binds anyone.

New Mexico's Sexual Exploitation of Children Act already reaches an AI-generated or AI-altered image independent of that legislative activity: its definition of a visual or print medium expressly includes computer or electronically generated imagery, and Section 30-6A-3(F) and (G) separately criminalize manufacturing or distributing an obscene medium in which a real child, who was not an actual participant, is depicted as a participant, reaching a morphed or synthetic depiction of an identifiable child regardless of whether any child was actually photographed engaging in the depicted act.

New Mexico's general Unfair Practices Act, not itself an AI-specific statute, is reported to be the basis of an Attorney General inquiry into AI chatbot and companion-app providers, on the same deceptive-trade-practices terms as any other consumer complaint.

No New Mexico bill naming artificial intelligence specifically has been enacted to expand this coverage; a 2026 bill that would have expanded a different, intimate-image-distribution offense to synthetic deepfakes of any person (HB 22) died before passing.

AI prohibited practices

Sexual Exploitation of Children Act, morphed and computer-generated image provisions

N.M. Stat. Ann. § 30-6A-3(F), (G)New Mexico Statutes Annotated text, FindLaw mirror

In force. Binds public and private bodies.

What this law does

The Sexual Exploitation of Children Act defines a visual or print medium to include a computer diskette, videotape, videodisc, or any computer or electronically generated imagery (Section 30-6A-2(B)), so the Act's coverage is not limited to a photograph of a real event.

Section 30-6A-3(F) makes it unlawful to intentionally manufacture an obscene visual or print medium depicting a prohibited sexual act if the person knows or has reason to know that a real child under eighteen, who is not a participant, is depicted as a participant in that act, a fourth degree felony. Section 30-6A-3(G) makes distributing such a medium a third degree felony.

Neither subsection requires that any child actually engaged in the depicted conduct; both reach a medium, including one that is computer or electronically generated, that depicts an identifiable real child as if they were a participant in a prohibited sexual act when they were not, which covers an artificial-intelligence-generated or artificial-intelligence-altered image or video inserting or morphing a real child's likeness into sexually explicit content.

What it requires

AI transparency

HB 182 (2024), AI-generated and manipulated media disclosure and disclaimer requirements in campaign advertising

N.M. Stat. Ann. §§ 1-19-26.4, 1-19-26.8enrolled bill text, New Mexico Legislature, House Bill 182 (2024)

archived copyRead from a public archive copy, not the publisher directly. The publisher does not serve this page to automated readers, so a direct fetch was not an option here; how we access sources. Archived 2024. Publisher's page: https://www.nmlegis.gov/Sessions/24%20Regular/final/HB0182.pdf

In force. Binds private bodies.

What this law does

Section 1-19-26.4, as amended by 2024's HB 182, requires a person who creates, produces or purchases a campaign advertisement containing materially deceptive media to include a disclaimer stating that the content has been manipulated or generated by artificial intelligence, displayed legibly for the duration of a video and spoken clearly at the start and end of an audio message (and at least every two minutes if longer than two minutes).

Materially deceptive media is defined as an image, video or audio that depicts an individual engaged in conduct or speech in which they did not engage, published without the depicted individual's consent, and produced in whole or in part using artificial intelligence.

The duty does not apply to a bona fide news broadcast that discloses the manipulation, a broadcaster that supplied and disclosed its own disclaimer requirements to advertisement purchasers, or an advertisement that reasonably constitutes satire or parody if it includes the required disclaimer.

A new Section 1-19-26.8, also enacted by HB 182, separately makes it a violation of the Campaign Reporting Act to distribute, or to agree with another person to distribute, materially deceptive media, and allows the attorney general, a district attorney, a falsely depicted individual, an injured or likely-to-be-injured candidate, or a voter-representing organization to seek injunctive relief.

A first conviction under Section 1-19-26.8 is a misdemeanor and a second conviction is a fourth degree felony. Failing to include the Section 1-19-26.4(D) disclaimer is separately subject to a civil penalty of up to one thousand dollars per violation, capped at twenty thousand dollars in total, under Section 1-19-34.6(C).

HB 182 carried no separate effective-date clause, so it takes effect under Article IV, Section 23 of the New Mexico Constitution: a law without an emergency clause takes effect ninety days after the adjournment of the legislature that enacted it. The 2024 legislative session adjourned sine die on February 15, 2024, placing the Act's commencement, ninety days later, at May 15, 2024.

What it requires

Privacy law2 instruments, 2 enacted but not yet in force

Research summary (242 words)

New Mexico has no comprehensive consumer personal-data-protection statute; recent comprehensive bills (HB 307, HB 410, and SB 420 in the 2025 session, and SB 53, the CHISPA Act, in the 2026 session) have not been enacted. New Mexico's privacy law is instead two separate sectoral statutes.

The Data Breach Notification Act, NMSA 1978 Secs. 57-12C-1 to 57-12C-12, requires notice to affected residents within 45 days of discovery and, above a 1,000-resident threshold, to the Attorney General, exempts state government entirely, and creates no private right of action; its personal identifying information definition includes biometric data, but that definition is purpose-bound to authenticating access to a location, device, system, or account rather than to identification generally, so whether it reaches an identifier derived from a public recording for identification purposes cannot be determined from the statute's own text.

The Genetic Information Privacy Act, NMSA 1978 Secs. 24-21-1 to 24-21-7, requires informed written consent before a person obtains, analyzes, retains, transmits, or uses an individual's genetic information, subject to nine statutory exceptions, and expressly arms an injured individual with a private civil action for damages, distinct from and broader than the Attorney General's or a district attorney's own enforcement authority.

New Mexico's official statute compilation portal, nmonesource.com, returns only navigation chrome through a JavaScript application with no statute text, so both instruments below are sourced to their official enrolled bill text on the New Mexico Legislature's own site rather than to the compiled code.

Breach notification

Data Breach Notification Act

NMSA 1978 Secs. 57-12C-1 to 57-12C-12official New Mexico enrolled bill text

Commencement not set. Binds private bodies.

What this law does

A person that owns or licenses computerized data including a New Mexico resident's personal identifying information must notify each affected resident of a security breach in the most expedient time possible and no later than 45 calendar days after discovery, and a breach affecting more than 1,000 New Mexico residents also triggers notice to the Attorney General's office and major consumer reporting agencies.

Personal identifying information includes biometric data, defined as a record generated by automatic measurement of fingerprints, a voiceprint, iris or retina patterns, facial characteristics, or hand geometry used to authenticate access to a physical location, device, system, or account, alongside a Social Security number, a driver's license number, and financial account information, and excludes information lawfully obtained from publicly available sources or government records.

The Act exempts the State of New Mexico and its political subdivisions entirely. The Attorney General has sole authority to bring an action for a violation, may obtain an injunction and damages for actual costs or losses, and may seek a civil penalty of the greater of $25,000 or $10 per failed notification up to $150,000; the Act creates no private right of action.

Enacted by Laws 2017, chapter 36 (House Bill 15); the enrolled bill text does not itself print an explicit commencement sentence, and secondary reporting gives June 16, 2017 without independent primary confirmation, so no effective date is recorded here.

What it requires

Sensitive categories

Genetic Information Privacy Act

NMSA 1978 Secs. 24-21-1 to 24-21-7official New Mexico enrolled bill text

Commencement not set. Binds private bodies.

What this law does

No person may obtain genetic information or samples for genetic analysis from an individual, or perform genetic analysis or collect, retain, transmit, or use genetic information, without first obtaining the individual's or their authorized representative's informed, written consent, subject to nine numbered exceptions covering law enforcement, newborn screening, de-identified use, medical repositories, and research.

Person is not limited to government or insurers; a separate section prohibits genetic discrimination specifically by insurers. Enacted in 1998 (House Bill 331) and amended in 2015 (House Bill 369, which replaced person with individual in the penalties subsection); the enrolled bill text for neither version prints an explicit commencement sentence, so no effective date is recorded here.

What it requires

Scraping law1 instrument, 1 in force

Research summary (235 words)

New Mexico diverges from the federal baseline through its Computer Crimes Act, NMSA 1978 sections 30-45-1 to 30-45-7, which reaches automated computer access through three offenses (computer access with intent to defraud or embezzle, computer abuse, and unauthorized computer use) graded entirely by the dollar value of the resulting property or service damage, from a petty misdemeanor at two hundred fifty dollars or less up to a second degree felony above twenty thousand dollars, rather than by a standalone bare-access element.

Nothing in the Act's own text exempts ordinary, non-disruptive automated access to a publicly available page from its authorization requirement, and no New Mexico case applying the Act to a scraping or bulk-collection fact pattern was located.

New Mexico has no comprehensive consumer data privacy statute reaching scraped public personal data at the state level; its Genetic Information Privacy Act and Data Breach Notification Act are sectoral and are covered under the privacy topic, not restated here. Terms-of-service enforceability rests on ordinary New Mexico contract law, with no statutory modification located.

The New Mexico Unfair Practices Act, NMSA sections 57-12-1 to 57-12-26, prohibits unfair or deceptive trade practices in commerce and is available in principle against a scraping-adjacent unfair-competition claim, untested against scraping specifically. Copyright, text-and-data-mining, database rights, and robots.txt's legal weight raise only the federal and common-law questions the national document already covers; New Mexico adds no state-specific statute on any of them.

Computer misuse

Computer Crimes Act, unauthorized computer use

N.M. Stat. Ann. § 30-45-5New Mexico Statutes Annotated text, FindLaw mirror

In force. Binds public and private bodies.

What this law does

The Computer Crimes Act's definitions section, Section 30-45-2, defines access, computer, computer network, computer property, computer service and related terms broadly, and the Act then creates three offenses. Section 30-45-3 punishes computer access with intent to defraud or embezzle.

Section 30-45-4 punishes computer abuse: altering, damaging, disrupting or destroying computer property or a computer service, or introducing data known to be false with intent to harm another's property or financial interests.

Section 30-45-5 separately punishes unauthorized computer use: knowingly, willfully and without authorization, or exceeding the scope of an authorization obtained, accessing, using, taking, transferring, concealing, obtaining, copying or retaining possession of a computer, computer network, computer property, computer service or computer system.

Each of these three offenses is graded solely by the dollar value of the damage to the computer property or computer service, from a petty misdemeanor at two hundred fifty dollars or less through a misdemeanor, a fourth degree felony, a third degree felony, up to a second degree felony above twenty thousand dollars; the Act does not add a separate, higher-graded bare-access offense the way some peer states do.

Section 30-45-6 allows prosecution under other law in addition to the Act and requires restitution for financial loss in addition to any other punishment. Section 30-45-7 subjects computer property, equipment, materials, conveyances and proceeds used in a violation to forfeiture under the Forfeiture Act.

No New Mexico case was located applying the Act to an automated web-scraping or bulk-data-collection fact pattern, and nothing in the Act's text exempts ordinary, non-disruptive automated access to a publicly available page from the authorization requirement.

What it requires

Cybersecurity law1 instrument, 1 enacted but not yet in force

Research summary (357 words)

New Mexico's product-security and cyber-resilience posture rests on one enacted statute, the Data Breach Notification Act's storage-security and disposal duties, NMSA 1978 Secs. 57-12C-3 to 57-12C-5 (Laws 2017, ch. 36, House Bill 15), which require a person that owns or licenses the personal identifying information of a New Mexico resident to implement and maintain reasonable security procedures and practices appropriate to the nature of the information, to arrange for proper disposal of records containing that information once they are no longer reasonably needed for business purposes, and to require by contract that any service provider it discloses the information to do the same.

This jurisdiction's breach-notification duty, the same Act's Sec. 57-12C-6, is already documented as this jurisdiction's privacy row rather than repeated here. No enacted New Mexico statute sets security requirements a connected device or software product must meet before or after it reaches the market, and no pending bill of that kind was located.

New Mexico has no general private-sector duty to report an exploited vulnerability or a security incident to an authority: NMSA 1978 Chapter 9, Article 27A, the Cybersecurity Act added in 2024, creates a cybersecurity office and a centralized cybersecurity and data-breach reporting process for agencies and political subdivisions of the state, government bodies rather than a private business, so it belongs with this jurisdiction's government-accountability material rather than as a row in this profile's private-sector scope.

Several secondary trackers list New Mexico among the states that have adopted the NAIC Insurance Data Security Model Law, but the citation those trackers give for it is the state-government Cybersecurity Act just described, which does not support that claim, and no other codified New Mexico insurance-sector data-security statute was located; the one primary artifact found is a March 2024 Office of Superintendent of Insurance bulletin directing an information request to major medical carriers and pharmacy benefit managers under the Superintendent's general inquiry power over Insurance Code licensees, a request the bulletin itself describes as aligned with the NAIC model's notification framework rather than as an exercise of a codified security-program duty.

No confirmed New Mexico insurance data-security statute is filed here on that record.

Security baseline statutes

Data Breach Notification Act, security and disposal duties

NMSA 1978 Secs. 57-12C-3 to 57-12C-5official New Mexico enrolled bill text

Commencement not set. Binds private bodies.

What this law does

A person that owns or licenses personal identifying information of a New Mexico resident must implement and maintain reasonable security procedures and practices appropriate to the nature of the information to protect it from unauthorized access, destruction, use, modification, or disclosure.

The same person must arrange for proper disposal, meaning shredding, erasing, or otherwise modifying the information to make it unreadable or undecipherable, of records containing personal identifying information once they are no longer reasonably needed for business purposes.

Where a person discloses personal identifying information to a service provider under contract, that contract must require the service provider to implement and maintain the same reasonable security procedures and practices.

The Act exempts the State of New Mexico and its political subdivisions entirely, and enforcement is confined to the Attorney General, who may obtain an injunction, damages for actual costs or losses, and, for a knowing or reckless violation, a civil penalty of $25,000; the Act creates no private right of action. Enacted by Laws 2017, chapter 36 (House Bill 15); the enrolled bill text does not itself print an explicit commencement sentence, so no effective date is recorded here.

What it requires

This page covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted in the head and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.