Brazil Artificial Intelligence Bill (PL 2338/2023)
ANPD (National Data Protection Authority) proposed as primary authority; specific AI regulator under discussion. Sector-specific regulators (BACEN for finance, ANVISA for health) maintain parallel authority.
Anticipated 2026–2027 after enactment and transition period (bill still in Chamber of Deputies as of mid-2025)
Status
Proposed
Risk Level
High
Jurisdiction
Brazil
Enforcement
Anticipated 2026–2027 after enactment and transition period (bill still in Chamber of Deputies as of mid-2025)
high risk framework
Any entity developing or deploying AI that affects persons in Brazil — including foreign companies. Extraterritorial application mirrors EU AI Act.
Overview
Brazil's AI Bill (PL 2338/2023) was approved by the Brazilian Senate in June 2024 and is under review in the Chamber of Deputies. Inspired heavily by the EU AI Act, it adopts a risk-based classification approach (minimal, limited, high risk), establishes AI governance requirements, and creates an oversight authority. Brazil is the 8th-largest economy and home to 215 million people — the largest AI regulatory jurisdiction in Latin America.
Scope
Any entity developing, deploying, importing, or distributing AI systems that affect persons in Brazil — regardless of where the company is based. Extraterritorial reach mirrors EU AI Act model.
Applicability
Who Is Affected
- Brazilian AI companies developing or deploying AI systems
- Foreign companies whose AI systems affect persons in Brazil
- Public sector bodies using AI for decisions affecting citizens
- Platforms and marketplaces distributing AI-powered products in Brazil
- Financial institutions using AI for credit, fraud, and customer decisions
Who Is Exempt
- AI used exclusively for R&D and scientific research with no public deployment
- AI for national security, defence, and public safety (sector-specific rules apply)
- Open-source AI components with no commercial deployment
Key Prohibitions
- AI-based social scoring by public authorities
- Subliminal manipulation exploiting psychological vulnerabilities
- Real-time biometric identification in public spaces for mass surveillance
- AI that discriminates based on sensitive personal characteristics (race, gender, religion, disability)
- Deepfake content presented as authentic without disclosure
Risk Tier Classification
Minimal Risk
minimalAI with negligible impact on individual rights — no specific obligations beyond voluntary codes.
Examples
- • AI in video games
- • Spam filters
- • Inventory optimization AI
Requirements
- ✓ Voluntary codes of conduct
Limited Risk
limitedSpecific transparency obligations — users must be informed of AI interaction.
Examples
- • Chatbots and virtual assistants
- • AI-generated content
- • Emotion recognition in non-critical contexts
Requirements
- ✓ Disclose AI nature of system
- ✓ Label AI-generated content
High Risk
highAI with significant potential to affect fundamental rights — full compliance obligations.
Examples
- • Credit scoring AI
- • CV screening tools
- • Medical diagnostic AI
- • AI in judicial or administrative decisions
- • Biometric identification
Requirements
- ✓ Conformity assessment
- ✓ Human oversight
- ✓ Algorithmic impact assessment
- ✓ ANPD registration
- ✓ Audit trails
Key Requirements
- Risk classification of AI systems into minimal, limited, and high-risk categories
- High-risk AI must complete conformity assessment before deployment
- Transparency obligations: users must be informed when interacting with AI
- Human oversight mechanisms for high-risk AI decision-making
- Algorithmic impact assessments for high-risk AI applications
- Data governance requirements aligned with LGPD (Brazil's GDPR-equivalent)
- Mandatory disclosure of AI-generated content (labeling)
- AI incident reporting to the supervisory authority
- Fundamental rights protection: non-discrimination, privacy, due process
Guardrails & Operational Controls
- Human oversight: all high-risk AI decisions must have a designated human reviewer with override capability
- Algorithmic impact assessment: mandatory documentation of potential adverse impacts on fundamental rights before deployment
- Non-discrimination: AI must not produce discriminatory outcomes based on race, gender, religion, disability, or socioeconomic status
- Transparency register: public registry of high-risk AI systems maintained by ANPD
- Complaint mechanisms: individuals must be able to contest AI-driven decisions
Technical Requirements
- Technical documentation describing AI system purpose, capabilities, and limitations
- Audit logs for high-risk AI decisions retained for minimum defined period
- Testing and validation results including bias and accuracy assessments
- Defined process for continuous monitoring of AI system performance
- Data quality documentation for training datasets
Compliance Roadmap
- 1STEP 1 - Monitor: Track bill progression through Chamber of Deputies and enactment timeline
- 2STEP 2 - Inventory: Catalogue all AI systems affecting Brazilian users
- 3STEP 3 - Risk Classification: Map each AI system against the bill's risk taxonomy
- 4STEP 4 - LGPD Alignment: Ensure AI data processing is already LGPD compliant (foundation for AI Bill compliance)
- 5STEP 5 - Impact Assessment: Begin drafting algorithmic impact assessments for anticipated high-risk systems
- 6STEP 6 - Governance: Establish internal AI governance framework ahead of enactment
- 7STEP 7 - Counsel: Engage Brazilian legal counsel specializing in AI and data protection
- 8STEP 8 - ANPD: Monitor ANPD guidance and engage with the authority's public consultation processes
Implementation Guidance
- 1Begin monitoring Chamber of Deputies progress and legal counsel engagement now
- 2Conduct LGPD compliance audit — AI Bill compliance builds directly on LGPD foundation
- 3Create AI system inventory of all systems affecting Brazilian users
- 4Draft algorithmic impact assessments using EU AI Act FRIA templates as a starting point
- 5Engage ANPD public consultations on AI implementation guidance
Industry Impact
Financial Services
Brazil's large unbanked population means credit AI is socially significant. BACEN + ANPD dual oversight expected.
Healthcare
Large public health system (SUS) deploying AI at scale; ANVISA oversight for medical AI. Significant compliance requirements.
Technology / AI Platforms
WhatsApp (500M+ Brazilian users), Google, Meta already subject to LGPD; AI Bill adds new obligations on top.
Public Sector
Government AI for social programmes, policing, and courts: highest risk tier, strictest oversight requirements.
eCommerce / Retail
Recommendation and personalization AI: limited risk with transparency disclosure requirements.
Legal & Judiciary
AI used in legal proceedings subject to specific transparency and contestation rights.
Regulatory Timeline
May 2023
PL 2338/2023 introduced in Brazilian Senate by Senator Rodrigo Pacheco
Jun 2024
Senate approves PL 2338/2023 — sent to Chamber of Deputies (Câmara dos Deputados)
2024–2025
Chamber of Deputies review underway; amendments expected
2025
Final text expected to be passed; presidential signature anticipated
2026
Expected entry into force after 24-month transition period post-enactment
Penalties for Non-Compliance
Not yet finalized — draft includes fines up to 2% of Brazilian revenue (capped at R$50M per violation) and service suspension. Aligned with LGPD penalty structure.
Framework Details
Short Name
Brazil AI Bill
Jurisdiction
Brazil
Enforcement Date
Anticipated 2026–2027 after enactment and transition period (bill still in Chamber of Deputies as of mid-2025)
Enforcing Authority
ANPD (National Data Protection Authority) proposed as primary authority; specific AI regulator under discussion. Sector-specific regulators (BACEN for finance, ANVISA for health) maintain parallel authority.
Status
Risk Level
Affected Organizations
Any entity developing or deploying AI that affects persons in Brazil — including foreign companies. Extraterritorial application mirrors EU AI Act.
Exposure Areas
- Financial services: credit scoring, loan origination, insurance pricing AI — high-risk category with conformity assessment required
- HR and hiring: CV screening, candidate ranking AI — high-risk, prohibited from making autonomous final decisions
- Healthcare: diagnostic AI and clinical decision support — high-risk, ANVISA oversight applies
- Public sector: government AI for benefits, policing, education — highest scrutiny level
- Content platforms: AI-generated disinformation, deepfakes — prohibited without clear labeling
Tags
This is educational guidance only. Always consult qualified legal counsel for compliance decisions affecting your organization.