Boards across Mexico and Latin America are being asked to approve artificial intelligence budgets at a pace that has outrun the frameworks they normally use to evaluate them. The proposals tend to arrive under a single label. Underneath, they almost always contain two very different capabilities — and the difference is not a technical footnote. It determines where risk accumulates, which regulation applies, and what needs to be written into the contract.
Generative models read. They take an unstructured document — a supply agreement, an invoice, a set of financial statements — and return something structured: the extracted clause, the amount, the counterparty, the ratio, a summary someone can act on. What is being bought is interpretation.
Agentic systems act. They take that interpretation and do the next thing: open the case, route the approval, post the entry, raise the exception, initiate the payment. What is being bought is execution, and frequently, a decision.
Deployed together, the pair dissolves a bottleneck that has resisted automation for decades: processes that are slow not because the steps are complicated, but because a person must read something before anything else can happen. Banking is generally the furthest along in the region, which is why board-level examples tend to come from there. The pattern is not specific to financial services, though — it applies to any operation where documents gate the workflow.
What I would put to a board is that the debate worth having is not whether to adopt either capability. It is where the boundary sits between reading and deciding, and who is accountable on each side of it.
Reading and deciding carry different risks
When a generative model reads a document incorrectly, the output is wrong but inert. It sits there until a person looks at it. The failure mode is an error.
When an agentic system acts on that same incorrect reading, the error is executed. The failure mode is a consequence — and it arrives at machine speed and machine volume, which means the same mistake can be made four hundred times before anyone notices it was made once.
This has a practical implication that is easy to miss in a procurement discussion. An accuracy level that is perfectly acceptable for drafting is not acceptable for execution, because in the drafting case a human review step is implicit. Automating the sequence removes that step without anyone deciding to remove it. If it is still needed, it must be put back deliberately, as a designed control rather than a by-product of how the work used to flow.
Where the pairing earns its place
The strongest candidates share a shape: a high volume of documents that resemble one another, and a clearly defined notion of what the right answer looks like. Contract intake and obligation extraction. Invoice matching. Spreading financial statements for a credit decision. Reviewing a client file for onboarding. Processing a claim.
The economics of these processes are worth stating plainly, because they are often misdescribed in business cases. The value is rarely the reading itself, which a competent analyst does quickly. The value is elapsed time: in most document-gated processes, most of the cycle is spent waiting in a queue for someone to become available. Compressing that is what changes the customer’s experience and the working capital position.
The weakest candidates are the mirror image. Where the reading is genuinely a matter of judgement — an ambiguous clause, a non-standard structure, a document that is unusual precisely because the situation is unusual — the pair tends to produce answers that are confident, fluent and wrong in ways that are difficult to catch downstream. My recommendation is to treat "how often is this document unusual?" as a screening question before any pilot, not as something to discover during it.
The operating frame: three boundaries
Most of what a board needs to govern here can be reduced to three questions, each of which produces a boundary that should be written down and owned by someone with a name.
What leaves the perimeter?
Mexican federal data protection rules constrain what private organisations may do with personal data, and the consequence for AI is direct: documents carrying identifying information should not be transmitted to a third-party model in their original form. The workable answer is to strip or mask identifiers before transmission. There is a distinction here that boards should insist on hearing stated correctly, because it is frequently blurred in vendor conversations — anonymised and pseudonymised are not the same thing. Data that can be re-identified using a key the organisation still holds personal data and remains regulated. A masking step that is reversible is security control, not an exemption.
Some processes cannot be masked at all. Client onboarding is the obvious case: the identity is not incidental to the document; it is the subject of it. There the answer is not masking but deployment — a model running inside the organisation’s own environment, so that the data never leaves the perimeter in the first place. That choice costs more and should be made knowingly rather than discovered later.
What may the system decide on its own?
Three tests do most of the work. Is the action reversible, and at what cost? Is it material, by an explicit threshold rather than a general sense? And is it a decision the organisation would have to explain to a regulator, a client or a court? Anything that fails one of those should be structured as a recommendation with human approval, not as an execution. The distinction between "the system recommends and a person approves" and "the system acts and a person may review" is the single most consequential line in the whole design, and it is often left to whoever configures the workflow.
What must be reconstructible afterwards?
Every automated decision should leave behind five things: the source document, the extraction that was produced from it, the rule or threshold that was applied, the action taken, and the version of the model that did the reading. That last item is the one most commonly omitted, and its absence makes the rest incomplete — the system that made last quarter’s decision may no longer exist in the same form, and without a version reference there is no way to explain a decision that would not be made the same way today.
The clause most boards never ask for
There is a contractual point that rarely reaches board level and probably should, because it is one of the few places where a signature genuinely changes the risk position.
Standard commercial terms from AI providers do not always exclude customer data from being used to improve or train models. Enterprise agreements commonly do, but this should be verified against the specific provider’s current terms rather than assumed — vendor policies in this area have changed repeatedly and a summary from last year is not evidence. Where the organisation has leverage, my recommendation is to negotiate that exclusion explicitly, and to negotiate it even for data that has already been anonymised. The reason is not legal formalism. It is that anonymisation performed at speed, on documents nobody re-examined, is a control being trusted more than it has earned.
Four more terms belong in the same conversation: how long the provider retains inputs and outputs and what deletion actually means; which sub-processors are involved and in which countries the data physically rests, since cross-border transfer is regulated separately from processing; what the organisation gets back on exit, including extracted data and any tuning derived from its documents; and whether the provider is obliged to give notice before changing the underlying model, which is the change most likely to alter results without anyone changing anything internally.
One region, several regimes
Latin America is not a single regulatory environment and treating it as one is a recurring source of expensive rework. Mexico, Brazil, Colombia, Chile and Peru each maintain their own data protection regime, and they differ meaningfully on cross-border transfer and on the conditions for automated decision-making. A regional deployment configured once, in one country, inherits the assumptions of that country and not the obligations of the others.
Mexico deserves a specific caution. The federal data protection framework for private organisations has undergone substantial change recently, and the supervisory arrangements changed alongside it. For a board, the practical implication is narrow and useful: any approval resting on a regulatory summary more than a year old should be re-checked before it is relied upon.
The closing question any board should be able to answer at any moment: which decisions in this organisation are currently being made without a person, and who approved that list. If nobody can produce the list, the boundary between reading and deciding still exists. It simply was never chosen — it settled wherever the implementation happened to leave it.
At Rhisco Group we work across both sides of this line: applied AI and automation through our Innovation & AI Lab, and the governance and regulatory frameworks that determine what those systems are allowed to do, through our Risk, Models & AI Governance and Regulatory Risk & Transformation practices. If your organisation approves AI investment faster than it is defining the boundary, that is the conversation worth having first. Write to us at contact@rhisco.com.
This article was co-created with the assistance of artificial intelligence under strict supervision, editing, and verification of our team.