The regulatory map for conversational AI in LATAM: what a bank needs to know before deploying

AI regulation in banking is already enforceable in LATAM: Peru has the first regulation in force (Supreme Decree 115-2025-PCM, effective January 22, 2026), classifies banking as high risk and sets a financial sector deadline of September 10, 2026; Argentina enforces Communication A 7724 since 2023; Colombia audits through the SFC without a law; Mexico supervises via the CNBV. Data governance is the real bottleneck.

Deploying conversational AI in banking is, today, one of the most strategic decisions a financial institution can make. And like any strategic decision, it has a dimension that goes beyond technology: the regulatory one. What many banking innovation teams discover along the way is that behind a conversational agent lies a different regulatory maze for each market. A maze that changes faster than most roadmaps anticipate. At Delto we have spent more than 10 years working with financial institutions in over 15 countries across Latin America. And what we see in every project is always the same tension: innovation teams that want to move fast, and risk and legal structures that need certainties the regulatory environment has not yet finished building. We wrote this article to close that gap. It is not a generic regulatory map. It is what a bank needs to understand, market by market, before putting a conversational AI agent into production. Why conversational agents carry a specific regulatory burden Not all uses of AI draw the same level of regulatory attention. A fraud-detection model running in the backend has a completely different risk profile from a conversational agent that talks directly to customers over WhatsApp, makes or suggests decisions about credit products, and captures sensitive financial data in real time. That difference matters because regulators see it clearly. When an AI system operates as an official customer-service channel, it automatically enters the radar of three overlapping regulatory dimensions: financial consumer protection, where the customer does not always know they are talking to an automated agent or understand how that agent reached a decision that affects them; data privacy, since conversations are, by definition, continuous flows of sensitive personal and financial data; and automated decisions, where several countries already have legislation, or case law, that requires explainability when an AI system impacts user rights. That is why conversational agents are probably the type of AI with the greatest regulatory exposure surface in retail banking today. And it is exactly where the region's regulators are focusing their attention. Mexico: no AI law, but active supervision and a precedent that changes the game Mexico still has no specific artificial intelligence law. A bill was introduced in the Senate in April 2025, but it has seen no significant progress. What does exist, and applies today, is the CNBV's supervision under the umbrella of the 2018 Fintech Law, which includes provisions for emerging technologies, and the Bank of Mexico's guidelines for the safe use of generative AI. One data point illustrates the ecosystem's maturity well: according to a review of transparency requests from March 2026, the Bank of Mexico is one of the few public institutions in the country with formal documentation of its AI systems; seven operational systems, with a defined governance framework. The contrast with the rest of the public sector speaks volumes. The most relevant precedent for banks came in May 2026, when the CNBV authorized FIDUZ as an Independent Investment Advisor with an AI-based business model, accompanied by a governance manual that the regulator itself now uses as a reference. The message is clear: the CNBV is willing to engage with AI projects, but it needs to see technical rigor and solid legal documentation on the other side. What does this mean for a bank that wants to deploy conversational AI in Mexico? Having the models in use documented, an internal policy for the responsible use of generative AI, and explicit mechanisms to avoid bias in automated decisions that affect the consumer. PROFECO has jurisdiction there. The absence of a specific law does not remove that exposure. Colombia: the regulator that did not wait for a law Colombia is probably the most interesting case in the region, and also the most demanding for anyone looking to deploy AI in the financial sector. It has no general AI law, Bill 442 was filed in May 2025 and is still in process, but it has the Financial Superintendency (SFC) acting as if it already did. The SFC created its own Center of Excellence in Artificial Intelligence. It operates two regulatory sandbox environments, LaArenera and elHub, so entities can test technology under controlled conditions. In October 2025 it launched its own AI tool for money-laundering detection. This is not a regulator that supervises from the outside: it is a regulator that adopted the technology and, from that position, defines how it expects the sector to use it. Add to that the weight of case law: the Colombian Constitutional Court has already ruled twice on AI. In 2024 it established that decision-making processes that use AI must preserve human rationality. The Judiciary Council had to issue the country's first formal protocol for the use of AI in the judicial branch. Those rulings have a direct bearing on how sector regulators, including the SFC itself, interpret their own obligations. In practice, a bank operating in Colombia needs: a data-governance framework aligned with the SFC's principles, documented human-validation processes in high-impact decisions, and full traceability of the conversational agent's interactions. An agent running without that governance architecture will not pass a Superfinanciera review. On the ground, we already covered how banking in Colombia is changing with generative AI . Peru: the first LATAM country with an AI regulation in force, and banking classified as high risk Peru is the most advanced case in the region in regulatory terms. In September 2025, the Peruvian government published Supreme Decree 115-2025-PCM, which approves the regulation of Law 31814 and makes Peru the first country in Latin America with a general AI regulation in force. It took effect on January 22, 2026. The regulation classifies AI systems into three risk levels. And here is the part every banking team should underline: banking, credit scoring and social programs are expressly classified as high-risk sectors. It is not an interpretation; it is in the text of the rule. For systems classified as high risk, the obligations are concrete. Transparency: informing the user about what the system does and how it makes decisions. Explainability: being able to justify outcomes when they impact user rights. Documented human oversight in significant decisions. Impact analysis before putting the system into production. Strict compliance with the Personal Data Protection Law. The timeline for the financial sector expires on September 10, 2026. It is not a tentative date: it is the official deadline. One critical point worth highlighting: Hiperderecho, a leading organization in Peruvian digital law, warned that the greatest risk is not the regulation itself, but data governance. The regulation is ready; the data, in many cases, is not. That is the real bottleneck for most institutions. Argentina: the most technical and detailed rule in the region, enforceable since 2023 Argentina has no AI law; there are bills in Congress still under discussion. But what it does have, since September 2023, is Communication "A" 7724 from the Central Bank, which is probably the most technical and detailed regulatory instrument on AI in the financial sector in the entire region. And it is in force. It is not a bill. It is not a best-practices guide. It is a rule enforceable today. Communication A 7724 requires all financial institutions to: identify and document every use of AI and machine learning, whether their own or third-party; carry out impact assessments and define specific risk appetites for each system; analyze, at a minimum, the risks to user privacy, the quality of training data, and the possible discrepancies between what the model predicts and reality; and implement the three-lines-of-defense scheme for managing technological risk. There is an operational detail that many banks overlook: those obligations also apply to AI systems contracted from third parties. If the conversational agent is provided by an external vendor, the bank needs contractual clauses that guarantee access to the technical documentation required to comply with the rule. Trusting that the provider "has it covered" is not enough. On top of that, the Province of Buenos Aires published its own risk-classification framework for AI systems in November 2025, based on the European AI Act, adding another regulatory layer for entities operating there. In this context, we also looked at how generative AI is changing banking in Argentina . The comparison chart: what each market requires today The five common denominators no project can ignore Despite their differences, Mexico, Colombia, Peru and Argentina share a regulatory logic: it is not about slowing innovation. It is about documentation, governance and traceability. In practice, that translates into five concrete imperatives: 1. An inventory of systems before deploying a new one. It sounds basic, but most banks do not have an up-to-date inventory. Without knowing which AI systems are already running, it is impossible to carry out a coherent impact assessment, or to comply with Communication A 7724 in Argentina. 2. Impact assessment before deployment, not after. Risk analysis cannot be a step taken to close out the project. It has to happen before the agent reaches production. In Peru, it is an explicit regulatory requirement. In Argentina and Colombia, it is the difference between passing an audit or not. 3. Human oversight designed for real. Not as a formal checkbox that adds no value. The regulator, especially the Colombian SFC, already knows how to tell real human validation from a paper one. If the agent makes high-impact decisions, there has to be a person in the loop with judgment and documented responsibility. 4. Transparent communication with the customer. The user has to know they are talking to an AI agent and has to be able to challenge an automated decision that affects them. This is not just good practice: in Peru it is a legal obligation. In Colombia and Mexico, it is an active consumer-protection risk today. 5. Traceability of conversations. Every interaction by the agent must be retrievable, auditable and explainable. Not only for the regulator: also to resolve disputes, detect errors and improve the model with real data. The equation many innovation teams have backwards There is a belief entrenched in many banking innovation teams: that waiting for "the regulator to say something" is the safest option. But when Peru already has a regulation in force, Argentina has a technical communication enforceable since 2023, and Colombia has a supervisor that audits actively without needing a law, that equation flips. And it is not uniform across markets: what is still in the legislative process in Brazil is already auditable in Argentina. What is a best-practices guide in Mexico already has a hard deadline in Peru. Projects born with governance built in from the design stage not only comply with the regulator: they have less internal friction, they get approved faster in risk and legal committees, and they build more trust among the teams that need to sign off to scale. How we solve it at Delto At Delto, compliance is not something we add at the end of the project. It is part of the architecture from day one. Our conversational AI platform for banking is designed to operate within the regulatory frameworks of each country where our clients have a presence. That means documented data governance, native conversation traceability, the ability to integrate human validation into decision flows, and contracts with our clients that allow them to comply with oversight obligations over third-party systems, as Communication A 7724 in Argentina requires. The full detail is available in the platform's security and compliance . Not because the regulator requires it, although it does, but because it is the only way for conversational AI projects in banking to truly scale in LATAM without friction or surprises. If your bank is evaluating whether to deploy conversational AI and wants to understand how to navigate this regulatory map in your specific market, we can help you build that architecture from the start.

Which LATAM country already has an AI regulation in force for banking? Peru. Supreme Decree 115-2025-PCM approved the regulation of Law 31814 and has been in force since January 22, 2026. It classifies banking and credit scoring as high risk, with a deadline for the financial sector of September 10, 2026.

What does Argentina's Central Bank Communication A 7724 require? In force since September 2023, it requires financial institutions to identify and document every use of AI (in-house or third-party), run impact assessments, define risk appetites, and implement the three-lines-of-defense model. It also applies to AI systems contracted from external vendors.

Can a bank wait for an AI law before deploying a conversational agent? It is not advisable. Peru already has a regulation in force, Argentina an enforceable communication since 2023, and Colombia a supervisor (the SFC) that audits actively without a law. Projects built with governance, traceability and human oversight from the design stage clear risk and legal committees faster.

How does AI regulation affect KYC and anti money laundering processes? KYC and anti money laundering processes that use AI fall under the same traceability, explainability and human oversight requirements as any other system. In Colombia, the SFC even runs its own AI tool for detecting money laundering, a clear sign that regulators audit these flows with technical criteria.

What does compliance by design mean in conversational AI for banks? It means governance is part of the architecture, not something added at the end of the project: documented data governance, native traceability of every conversation, human validation integrated into decision flows and contracts that cover oversight obligations over third party systems, as Argentina's Communication A 7724 requires.