LIVE
EU AI Act enforcement begins · June 2026NIST AI RMF — risk management framework publishedISO/IEC 42001 AI management standard now certifiableOpenAI o3 sets new reasoning benchmarksAnthropic raises $4B Series EEU AI Act enforcement begins · June 2026NIST AI RMF — risk management framework publishedISO/IEC 42001 AI management standard now certifiableOpenAI o3 sets new reasoning benchmarksAnthropic raises $4B Series EEU AI Act enforcement begins · June 2026NIST AI RMF — risk management framework publishedISO/IEC 42001 AI management standard now certifiableOpenAI o3 sets new reasoning benchmarksAnthropic raises $4B Series E

Brazil Artificial Intelligence Bill (PL 2338/2023)

Proposed
high risk
Brazil

ANPD (National Data Protection Authority) proposed as primary authority; specific AI regulator under discussion. Sector-specific regulators (BACEN for finance, ANVISA for health) maintain parallel authority.

Anticipated 2026–2027 after enactment and transition period (bill still in Chamber of Deputies as of mid-2025)

Official Text

Status

Proposed

Risk Level

High

Jurisdiction

Brazil

Enforcement

Anticipated 2026–2027 after enactment and transition period (bill still in Chamber of Deputies as of mid-2025)

high risk framework

Any entity developing or deploying AI that affects persons in Brazil — including foreign companies. Extraterritorial application mirrors EU AI Act.

Overview

Brazil's AI Bill (PL 2338/2023) was approved by the Brazilian Senate in June 2024 and is under review in the Chamber of Deputies. Inspired heavily by the EU AI Act, it adopts a risk-based classification approach (minimal, limited, high risk), establishes AI governance requirements, and creates an oversight authority. Brazil is the 8th-largest economy and home to 215 million people — the largest AI regulatory jurisdiction in Latin America.

Scope

Any entity developing, deploying, importing, or distributing AI systems that affect persons in Brazil — regardless of where the company is based. Extraterritorial reach mirrors EU AI Act model.

Applicability

Who Is Affected

  • Brazilian AI companies developing or deploying AI systems
  • Foreign companies whose AI systems affect persons in Brazil
  • Public sector bodies using AI for decisions affecting citizens
  • Platforms and marketplaces distributing AI-powered products in Brazil
  • Financial institutions using AI for credit, fraud, and customer decisions

Who Is Exempt

  • AI used exclusively for R&D and scientific research with no public deployment
  • AI for national security, defence, and public safety (sector-specific rules apply)
  • Open-source AI components with no commercial deployment

Key Prohibitions

  • AI-based social scoring by public authorities
  • Subliminal manipulation exploiting psychological vulnerabilities
  • Real-time biometric identification in public spaces for mass surveillance
  • AI that discriminates based on sensitive personal characteristics (race, gender, religion, disability)
  • Deepfake content presented as authentic without disclosure

Risk Tier Classification

Minimal Risk

minimal

AI with negligible impact on individual rights — no specific obligations beyond voluntary codes.

Examples

  • AI in video games
  • Spam filters
  • Inventory optimization AI

Requirements

  • Voluntary codes of conduct

Limited Risk

limited

Specific transparency obligations — users must be informed of AI interaction.

Examples

  • Chatbots and virtual assistants
  • AI-generated content
  • Emotion recognition in non-critical contexts

Requirements

  • Disclose AI nature of system
  • Label AI-generated content

High Risk

high

AI with significant potential to affect fundamental rights — full compliance obligations.

Examples

  • Credit scoring AI
  • CV screening tools
  • Medical diagnostic AI
  • AI in judicial or administrative decisions
  • Biometric identification

Requirements

  • Conformity assessment
  • Human oversight
  • Algorithmic impact assessment
  • ANPD registration
  • Audit trails

Key Requirements

  • Risk classification of AI systems into minimal, limited, and high-risk categories
  • High-risk AI must complete conformity assessment before deployment
  • Transparency obligations: users must be informed when interacting with AI
  • Human oversight mechanisms for high-risk AI decision-making
  • Algorithmic impact assessments for high-risk AI applications
  • Data governance requirements aligned with LGPD (Brazil's GDPR-equivalent)
  • Mandatory disclosure of AI-generated content (labeling)
  • AI incident reporting to the supervisory authority
  • Fundamental rights protection: non-discrimination, privacy, due process

Guardrails & Operational Controls

  • Human oversight: all high-risk AI decisions must have a designated human reviewer with override capability
  • Algorithmic impact assessment: mandatory documentation of potential adverse impacts on fundamental rights before deployment
  • Non-discrimination: AI must not produce discriminatory outcomes based on race, gender, religion, disability, or socioeconomic status
  • Transparency register: public registry of high-risk AI systems maintained by ANPD
  • Complaint mechanisms: individuals must be able to contest AI-driven decisions

Technical Requirements

  • Technical documentation describing AI system purpose, capabilities, and limitations
  • Audit logs for high-risk AI decisions retained for minimum defined period
  • Testing and validation results including bias and accuracy assessments
  • Defined process for continuous monitoring of AI system performance
  • Data quality documentation for training datasets

Compliance Roadmap

  1. 1STEP 1 - Monitor: Track bill progression through Chamber of Deputies and enactment timeline
  2. 2STEP 2 - Inventory: Catalogue all AI systems affecting Brazilian users
  3. 3STEP 3 - Risk Classification: Map each AI system against the bill's risk taxonomy
  4. 4STEP 4 - LGPD Alignment: Ensure AI data processing is already LGPD compliant (foundation for AI Bill compliance)
  5. 5STEP 5 - Impact Assessment: Begin drafting algorithmic impact assessments for anticipated high-risk systems
  6. 6STEP 6 - Governance: Establish internal AI governance framework ahead of enactment
  7. 7STEP 7 - Counsel: Engage Brazilian legal counsel specializing in AI and data protection
  8. 8STEP 8 - ANPD: Monitor ANPD guidance and engage with the authority's public consultation processes

Implementation Guidance

  1. 1Begin monitoring Chamber of Deputies progress and legal counsel engagement now
  2. 2Conduct LGPD compliance audit — AI Bill compliance builds directly on LGPD foundation
  3. 3Create AI system inventory of all systems affecting Brazilian users
  4. 4Draft algorithmic impact assessments using EU AI Act FRIA templates as a starting point
  5. 5Engage ANPD public consultations on AI implementation guidance

Industry Impact

Financial Services

Brazil's large unbanked population means credit AI is socially significant. BACEN + ANPD dual oversight expected.

critical

Healthcare

Large public health system (SUS) deploying AI at scale; ANVISA oversight for medical AI. Significant compliance requirements.

high

Technology / AI Platforms

WhatsApp (500M+ Brazilian users), Google, Meta already subject to LGPD; AI Bill adds new obligations on top.

high

Public Sector

Government AI for social programmes, policing, and courts: highest risk tier, strictest oversight requirements.

critical

eCommerce / Retail

Recommendation and personalization AI: limited risk with transparency disclosure requirements.

medium

Legal & Judiciary

AI used in legal proceedings subject to specific transparency and contestation rights.

high

Regulatory Timeline

PastCurrentUpcoming

May 2023

PL 2338/2023 introduced in Brazilian Senate by Senator Rodrigo Pacheco

Jun 2024

Senate approves PL 2338/2023 — sent to Chamber of Deputies (Câmara dos Deputados)

2024–2025

Chamber of Deputies review underway; amendments expected

2025

Final text expected to be passed; presidential signature anticipated

2026

Expected entry into force after 24-month transition period post-enactment

Penalties for Non-Compliance

Not yet finalized — draft includes fines up to 2% of Brazilian revenue (capped at R$50M per violation) and service suspension. Aligned with LGPD penalty structure.

Framework Details

Short Name

Brazil AI Bill

Jurisdiction

Brazil

Enforcement Date

Anticipated 2026–2027 after enactment and transition period (bill still in Chamber of Deputies as of mid-2025)

Enforcing Authority

ANPD (National Data Protection Authority) proposed as primary authority; specific AI regulator under discussion. Sector-specific regulators (BACEN for finance, ANVISA for health) maintain parallel authority.

Status

Proposed

Risk Level

high

Affected Organizations

Any entity developing or deploying AI that affects persons in Brazil — including foreign companies. Extraterritorial application mirrors EU AI Act.

Exposure Areas

  • Financial services: credit scoring, loan origination, insurance pricing AI — high-risk category with conformity assessment required
  • HR and hiring: CV screening, candidate ranking AI — high-risk, prohibited from making autonomous final decisions
  • Healthcare: diagnostic AI and clinical decision support — high-risk, ANVISA oversight applies
  • Public sector: government AI for benefits, policing, education — highest scrutiny level
  • Content platforms: AI-generated disinformation, deepfakes — prohibited without clear labeling

Tags

BrazilLatin AmericaRegulationEnterpriseRisk-Based

This is educational guidance only. Always consult qualified legal counsel for compliance decisions affecting your organization.