Brazilian Artificial Intelligence Act
· About Brazilian Artificial Intelligence Act
Key Takeaways
- Brazil does not yet have a comprehensive AI law in force: Bill 2338/2023, the proposed Marco Legal da Inteligência Artificial, passed the Senate on 10 December 2024 but remains pending in the Chamber of Deputies, so it does not currently impose binding compliance duties or penalties.[6][4]
- The proposed law would apply risk-based obligations to developers, providers and deployers of AI systems in Brazil: the bill is designed as a horizontal framework covering AI across sectors, with stricter duties for high-risk and prohibited uses.[1][4]
- If enacted in its current form, the bill would create a national AI governance system and assign oversight to the data protection authority: the proposed ANPD would coordinate the regime through a national system for AI regulation and governance.[4][9]
- The bill’s core compliance model would require transparency, risk management, human oversight and documentation: especially for high-risk AI, providers would need governance controls, impact assessments, monitoring and recordkeeping.[1][4]
- No deadline or fine applies today because the bill is not yet law: any penalty exposure remains prospective until final approval, promulgation and entry into force.[6][9]
- Brazil’s 2025–2026 legislative activity has delayed rather than replaced PL 2338/2023: reports in 2026 describe the bill as still under Chamber review, with additional AI bills introduced in 2026 but no enacted general AI statute yet.[1][11][13]
What It Is
Bill 2338/2023 is Brazil’s proposed national framework for artificial intelligence, commonly called the Marco Legal da IA. It establishes a risk-based regime for the development, marketing, deployment and use of AI systems, with special rules for high-risk systems and specific restrictions for practices considered unacceptable or prohibited.[1][4]
The bill was approved by the Federal Senate on 10 December 2024 and then moved to the Chamber of Deputies, where it remained under consideration through September 2026.[4][6][14] As of 13 September 2026, it has not been enacted into law, so there is no effective date in force and no operative compliance timetable yet.[6][9]
The proposed enforcement architecture would place coordination with a national governance structure and the ANPD as the expected central authority for oversight, guidance and enforcement design.[4][9] Any exact phase-in milestones remain uncertain until the Chamber completes consideration and the final text is promulgated.
Who Must Comply
The bill is designed to apply broadly to entities that develop, provide, distribute or deploy AI systems in Brazil, including both domestic and foreign actors where the system is offered or used in the Brazilian market.[1][4] The framework is horizontal rather than sector-specific, so it can capture finance, health, employment, consumer services, public-sector uses and other sectors where AI is deployed.[1][9]
The bill’s risk-based logic means the strictest duties would fall on actors involved with high-risk AI systems, while lighter obligations would apply to lower-risk or limited-risk systems.[1][4] The proposed text also contemplates special treatment for certain general-purpose or foundational AI uses, but the exact compliance profile depends on the final enacted wording.
No binding exemption regime applies today because the bill is not yet law.[6] If enacted, any exemptions would need to be read from the final text and from implementing regulation, not from current practice.
Core Requirements
- Risk classification and governance: Covered actors would need to classify AI systems by risk and maintain governance controls proportionate to the risks posed, including internal accountability and documented decision-making.[1][4]
- Transparency and disclosure: Providers and deployers would need to inform users when they are interacting with AI and provide meaningful information about purpose, functioning and limitations, especially where automated decisions affect rights.[1][4]
- Human oversight: High-impact or high-risk uses would require human supervision mechanisms so that people can monitor, intervene in or override AI outputs where necessary.[1][4]
- Documentation and traceability: The bill contemplates technical and operational documentation, logging and traceability to support audits, incident review and regulatory accountability.[1][4]
- Risk management and testing: Responsible parties would need ex ante and ongoing risk controls, including testing, monitoring, mitigation and review of adverse effects over the system lifecycle.[1][4]
- Protection of rights and non-discrimination: The framework aims to reduce discriminatory outcomes, protect fundamental rights and require safeguards where AI affects access to employment, credit, health, public services or other protected interests.[1][4]
- Special duties for high-risk systems: Systems placed in higher-risk categories would face more formal obligations, potentially including impact assessments, stronger auditability and tighter oversight expectations.[1][4]
Deadlines and Penalties
| milestone | date | what applies | |---|---:|---| | Senate approval | 10 December 2024 | Bill 2338/2023 passed the Senate and advanced to the Chamber of Deputies.[4][5] | | Chamber review pending | 2025–13 September 2026 | The bill remains under consideration and has not become law.[1][6][9] | | Current legal effect | 13 September 2026 | No binding AI-specific compliance deadline or penalty applies yet.[6][9] |
If enacted, the bill would likely authorize administrative sanctions, with the final penalty ceiling and enforcement mechanics depending on the approved text and implementing rules. Because the law is not in force, no maximum fine is currently operative under PL 2338/2023.[6][9]
Other sanctions discussed in analysis of the bill include orders to suspend, limit or prohibit processing or deployment, remediation obligations, and public enforcement measures for non-compliance once the regime is active.[1][4]
How to Comply
- Map your AI inventory: Identify all AI systems used, developed, procured or embedded in products and services, including vendor tools and employee-facing systems.
- Classify risk now: Build a risk taxonomy aligned to the bill’s likely structure so systems can be triaged quickly once the final text is published.
- Adopt an AI management system: Use ISO 42001 as the governance backbone for policy, roles, review cycles, incident handling and continuous improvement.
- Align controls to enterprise security and resilience: Map technical controls to ISO 27001 and the NIST CSF 2.0 functions of Govern, Identify, Protect, Detect, Respond and Recover where AI systems affect confidentiality, integrity and availability.
- Create model documentation and testing files: Maintain records for data provenance, training or tuning inputs where applicable, evaluation results, bias testing, monitoring metrics and known limitations.
- Implement human oversight and approval gates: Define where humans can approve, reject, pause or override AI outputs, especially for decisions with legal or similarly significant effects.
- Prepare rights and complaints workflows: Stand up processes for notices, explanations, challenge requests, incident escalation and remediation, so the organization can operationalize transparency and accountability quickly.
- Track legislative change continuously: Re-check the final Chamber text, any amended scope, and any ANPD implementing rules before setting hard deadlines or revising contracts.
Related Regulations
Brazil’s LGPD overlaps because AI systems that process personal data still must comply with data protection rules on lawful basis, transparency, minimization, security and data subject rights.
The EU AI Act is relevant for multinational groups because it uses a similar risk-based structure, but it is an EU regime and does not govern Brazilian operations unless EU market access is involved.
Brazil’s consumer protection law can conflict or overlap where AI-driven recommendations, profiling or automated decisions affect consumers and create misleading, discriminatory or abusive practices.
Brazil’s Internet Civil Framework can matter for online platforms using AI, especially where content moderation, logging, liability and intermediary obligations intersect with automated systems.
The proposed AI bill itself would sit above sectoral guidance and fill gaps left by privacy and consumer rules, but until it is enacted, sectoral regulators and general laws remain the operative framework.
FAQ
Does the Brazilian AI Act apply to companies outside Brazil?
Potentially yes, if the company develops, offers or deploys AI systems in the Brazilian market or otherwise targets use in Brazil. The bill is designed with extraterritorial-style reach typical of modern digital regulation, but the final wording will determine the exact test.
As of 13 September 2026, there is still no enacted AI statute, so this remains a prospective obligation rather than a current legal duty.[6][9]
Is PL 2338/2023 in force right now?
No. The Senate approved the bill on 10 December 2024, but it is still pending in the Chamber of Deputies and has not been promulgated as law.[4][6]
That means there is no current AI-specific compliance deadline or statutory penalty under PL 2338/2023.[6][9]
What kinds of AI systems would be most heavily regulated?
High-risk systems would face the strictest obligations, especially where they affect employment, credit, health, essential services, safety or fundamental rights.[1][4] The bill also contemplates stronger transparency and oversight duties for systems with broader societal impact.
Lower-risk systems would still face baseline transparency and governance duties, but the regime is explicitly risk-tiered.[1][4]
Which regulator would enforce the law?
The proposal centers oversight in the ANPD, which is intended to coordinate the national system for AI regulation and governance.[4][9] That said, enforcement architecture will depend on the final enacted text and any secondary regulations.
What changed in 2025 and 2026?
The main change is delay rather than adoption: reports throughout 2025 and 2026 describe the bill as still pending Chamber action, with the legislative timetable slipping into 2026.[1][6][13] Additional AI bills were introduced in 2026, but they did not replace the need for final approval of PL 2338/2023.[11]
Should companies start compliance work before the law is enacted?
Yes, because the proposed obligations are clear enough to justify early governance preparation, documentation and risk management. Companies that already align with ISO 42001, ISO 27001 and NIST CSF 2.0 will be better positioned to adapt once the final text is known.
Early preparation is especially prudent for high-risk uses and for groups already subject to privacy, consumer protection or sectoral rules in Brazil.[1][4]
Sources
- Brazil Senate bill record for PL 2338/2023
- Brazil Senate news release on approval of AI bill
- Brazil Chamber of Deputies legislative portal
- Brazil Chamber special committee on AI bill
- Análise jurídica do PL 2338/2023 por TozziniFreire
- Campos Thomaz note on Senate approval of PL 2338/23
- Brazilian Data Protection Authority, ANPD
- ISO/IEC 42001 overview from ISO
- NIST Cybersecurity Framework 2.0
Put it into practice
- Generate the policy: LGPD policy generator (generatepolicy.com)
- Buy the policy pack: Brazil LGPD Compliance Policy (cyberpolicy.shop)
- Build it yourself: GDPR & DPIA Compliance Workbook (ciso.diy)