When American and Mexican negotiators closed their third round of USMCA review talks in Mexico City in late July, the agenda read the way these agendas always read. Steel and aluminum. Automobiles. Agriculture. Labor. Electronic payments.
And one item that would not have appeared on a trade agenda ten years ago: economic security.
I grew up on this border and worked it from both sides, as a mayor in Nogales and later as chief of staff at U.S. Customs and Border Protection. In all those years, trade talks were about tariffs, quotas and rules of origin. They were arguments about percentages. What is happening now is different, and Arizona companies should understand it before the rules are finished.
Economic security is a question about trust. Who built the equipment running an operation. Where the components came from. Whether a country that never signed the agreement is quietly benefiting from it anyway. The joint statement after the July round described the urgency of growing North American manufacturing, strengthening regional supply chains and addressing free-riding by non-parties. Mexico’s economy secretary was more direct afterward, citing progress on the substitution of imports from Asia.
That is a real shift. For most of my career, the answer to a cheaper supplier was a tariff. The answer now is a standard, and standards travel further. They reach past the border into how a company builds, connects and secures what it uses every day.
Consider what happened the same month those negotiators met. In July, two of the largest artificial intelligence companies in the world disclosed that advanced models had operated outside the boundaries set for them, reaching infrastructure they were not meant to touch. The systems found those paths on their own, without access to anyone’s source code. They were not replaying known attacks. They were inventing them. The security bar is rising faster than the frameworks built to certify it.
Set those two facts side by side. Our trade architecture is being rewritten to define what a trusted supply chain means — at the precise moment the threat model underneath it changed. That is the story of the next three years.
Here is what it means in practice for a company in Phoenix or Tucson importing through Sonora, and it is not speculative. Section 889 of the 2019 defense authorization already bars federal agencies from contracting with any company that merely uses equipment from a short list of Chinese manufacturers, which means the cameras hanging in a business’s own warehouse can cost it a federal customer. CTPAT already requires members to maintain cybersecurity standards and vet their business partners. What is happening at the negotiating table is that logic moving out of procurement rules and voluntary programs into the agreement itself, where it reaches everyone rather than only federal contractors and certified importers.
That is why the trade conversation and the cybersecurity conversation, which used to happen in different rooms with different people and different budgets, are becoming one conversation. The companies that see it early will spend far less than the ones that wait to be told.
One more signal worth watching. The State Department has been building a coalition around trusted technology and supply chains, and this summer it expanded across Latin America. Argentina, Chile, Costa Rica, El Salvador and Panama joined. Mexico did not. The largest trading partner the United States has is absent from the group writing the rules on trusted supply chains, and that absence will eventually carry a price for companies whose goods cross at Mariposa, or any other port of entry, every day.
I am not writing this to alarm anyone. Arizona is unusually well positioned if it moves. We have the manufacturing base that makes trusted supply chains credible, with Intel and TSMC investing at a scale few states can match. We have the busiest produce port in the country and a corridor running from Sonora to Alberta. What we do not have is a habit of thinking about our southern suppliers as part of our own security posture.
Negotiators reconvene in Washington later this month. Between now and then, the useful work is practical. Businesses should ask their suppliers what equipment they run and where it came from. They should read their contracts for who is responsible when something is breached. It’s important they learn the vocabulary, because it is becoming the vocabulary of market access.
The border has always rewarded people who saw the change before it arrived. This one is arriving.
Marco A. López Jr. is founder and CEO of Intermestic Partners, a cross-border strategic advisory firm specializing in U.S.-Mexico trade, investment and border security. A former mayor of Nogales, Arizona, and chief of staff at U.S. Customs and Border Protection, he is a past member of the Council on Foreign Relations. His work focuses on strengthening regional competitiveness, trade and long-term economic growth across North America.



















