Brazil - National AI Regulation (2.338/2023)
Bill No. 2,338/2023 (Legal Framework for Artificial Intelligence — Draft national AI regulatory framework)
Projeto de Lei nº 2.338/2023 (Marco Legal da Inteligência Artificial — Draft national AI regulatory framework)
Brazil
RAI-BR-NA-PDLN2XX-2023Brazil - National AI Regulation (2.338/2023) is Under Review in Brazil as of 8 Sep 2026, according to congressonacional.leg.br.
BillGovernance and OversightRisk ManagementProjeto de Lei nº 2.338/2023, introduced by the Brazilian Senate in 2023, regulates AI developers and deployers by establishing risk categories, governance rules, and rights for affected individuals. The proposed law remains Under Review after its 2023-05-03 filing. Compliance would be supervised by a central AI authority and the ANPD.
Summary
Projeto de Lei no 2.338/2023 remains Under Review as a draft national legislative framework in Brazil. Following plenary approval in the Senate in December 2024, the bill was transmitted to the Chamber of Deputies on 2025-03-17, where the President of the House decreed the creation of a Special Committee on 2025-04-04 and formally constituted it on 2025-04-29 to evaluate the proposal.
Introduced in May 2023 by Senator Rodrigo Pacheco, PL 2338/2023 aims to establish a comprehensive national framework for artificial intelligence. The proposal sets foundational principles, guarantees statutory rights for individuals affected by automated decisions (including prior information, explanation, human review, and contestability), and seeks to balance technological innovation with fundamental rights, human dignity, and democratic values.
The draft adopts a risk-based architecture, categorizing AI applications into prohibited excessive-risk systems, regulated high-risk systems, and lower-risk applications. It mandates algorithmic impact assessments, internal governance programs, audit logging, and effective human oversight for high-risk deployments. Additionally, suppliers and operators face strict transparency duties, including explicit notices and explainability mechanisms for automated outputs.
Enforcement and governance would be overseen by a newly created System for AI Regulation and Governance (SIA), coordinated by a central competent authority designated by the Executive Branch alongside sectoral regulators. The competent authority, envisioned to operate in close coordination with the National Data Protection Authority (ANPD), will possess powers to supervise market actors, conduct audits, issue regulatory guidance, oversee sandboxes, and enforce administrative sanctions including warnings, fines up to R$50,000,000 or 2% of Brazilian turnover, and partial or total suspension of AI operations.
The proposed law operates in alignment with the Lei Geral de Protecao de Dados (LGPD) and the Consumer Protection Code, preserving sector-specific oversight while providing unified national guarantees. Because the measure remains under review in the Chamber of Deputies, its final text and operational rules remain subject to further legislative amendments and subsequent administrative rulemaking.
Full article
Read full text ↗Overview
Projeto de Lei nº 2.338/2023 is a proposed national framework intended to regulate the development, deployment and use of artificial intelligence systems across Brazil. The bill sets out principles (human centrality, non‑discrimination, transparency, robustness and security), substantive rights for persons affected by AI (information, explainability, contestability and human review) and a risk‑based regulatory architecture with differentiated obligations for systems classified as high or excessive risk. The text approved by the Senate and made available publicly consolidates earlier committee substitutive measures; the official consolidated text can be consulted in the Senate's published PDF (see PL 2338/2023 — consolidated text (Senate PDF)). The bill foresees a national governance structure (the System for AI Regulation and Governance — SIA) to coordinate rulemaking and supervision and contemplates the role of sectoral authorities, a committee of specialists and mechanisms such as sandboxes to balance oversight with innovation.
Definitions
PL 2338 provides specific statutory definitions that structure its obligations. Core definitions include "system of artificial intelligence" (computer systems designed to produce predictions, recommendations or decisions that can affect the virtual or real environment), "supplier" (natural or legal person that develops AI systems) and "operator" (user or deployer that employs AI for its own benefit). The draft also defines "authority competent" (to be designated by the Executive, with duties to implement and enforce the law), "risk classification" categories and terms such as "mining of texts and data" and "discrimination" (a broad definition aligned with constitutional non‑discrimination norms). These definitions anchor responsibilities and procedural guarantees throughout the bill.
Governance and Institutional Framework
The bill establishes a multi‑tier governance model named SIA (System for AI Regulation and Governance). The SIA is composed of the designated authority ("authority competent"), sectoral regulators, a permanent Council of Regulatory Cooperation (CRIA) and a Committee of Experts and Scientists on Artificial Intelligence (CECI A). While the Executive is tasked with designating the authority competent, public commentary and technical commentary from the Autoridade Nacional de Proteção de Dados (ANPD) have recommended that ANPD assume a central regulatory coordination role, particularly where AI intersects with personal data and LGPD obligations (see ANPD's Note Technical contributions at ANPD — second analysis of PL 2338/2023). The authority competent will adopt regulations, lead consultations, coordinate with sectoral authorities and oversee public registries, sandboxes and conformity assessment processes. The law anticipates public consultation and regulatory impact analysis in secondary rulemaking.
Key Focus Areas
PL 2338 concentrates obligations across several core domains: rights of affected individuals (information, explanation, contestability and human review); transparency (disclosure of automated interactions, explicit notices for biometric and emotion‑recognition systems, metadata requirements); governance (internal programs of governance, codes of conduct, traceability and logging); risk management (classification, algorithmic impact assessments and mitigation measures); conformity assessment and certification for high‑risk systems; incident reporting of serious incidents to the authority competent; market surveillance powers for enforcement; liability and redress rules including objective liability presumptions for high‑risk systems; and administrative sanctions ranging from warnings to significant fines and operational suspensions. Special attention is given to vulnerable populations, minors and to situations where AI produces effects with legal or significant factual impacts on rights and interests.
Implementation Framework
Implementation is intended to be carried out by the authority competent (designated by the Executive) in coordination with sectoral regulators. The bill delegates many technical and procedural specifications to regulation: the criteria for risk classification, the content and frequency of algorithmic impact assessments, audit and documentation formats, requirements for conformity assessment and the operational rules for sandboxes. The text allows voluntary codes of good conduct and contemplates accreditation and certification mechanisms; adherence to approved codes may be considered as evidence of good faith during enforcement proceedings. The Executive must publish a list of SIA members and the authority will publish annual reports on its activities. The law also foresees differentiated processes and communication channels for micro and small enterprises and startups to avoid disproportionate burdens.
Monitoring and Evaluation
Monitoring mechanisms combine mandatory reporting (serious incidents must be reported to the authority competent) with regulatory supervision, periodic audits, public registries and market surveillance authority powers. The authority may request technical information from public bodies operating AI and may coordinate joint inspections with sectoral agencies. The bill requires the authority to issue annual activity reports and to use public consultation and regulatory impact assessment before issuing norms. Sandboxes are explicit instruments to be monitored and may be conditioned to reporting obligations. Conformity assessment reports, impact assessments and audit trails are expected to form the evidentiary basis for supervision and corrective measures.
Penalties, Liability, and Appeals
PL 2338 sets an administrative sanctioning regime that includes warnings; fines up to R$50,000,000 per infraction (or up to 2% of the company's Brazilian turnover for private legal persons, subject to limits); publicization of infractions; suspension or prohibition from sandboxes; temporary or definitive suspension of development, supply or operation; and prohibition of treatment of certain data sets. Sanctions must observe due process, proportionality and the opportunity for defense. On civil liability, the draft provides objective liability for providers/operators of high‑risk or excessive‑risk systems and presumes the victim's position in many cases (including inversion of the burden of proof) to facilitate redress. The bill preserves judicial and administrative appeals and aligns consumer‑sector claims with the Consumer Protection Code.
Relationship to Other Instruments
The bill explicitly references alignment with the Lei Geral de Proteção de Dados (LGPD) and the Consumer Protection Code. It is designed to operate as a sector‑neutral national framework that coordinates with sectoral regulators (e.g., health, financial, communications and safety regulators) and avoids supplanting sectoral competence. The SIA's model contemplates coordination channels and a forum for sector regulators. The text also anticipates the need for additional executive regulations to operationalize definitions and assessment methodologies.
International Alignment
PL 2338 is explicitly influenced by comparative regulatory models, notably the EU AI Act; it reflects international practices on risk‑based classification, transparency duties and conformity assessment while adapting enforcement and liability rules to Brazil's legal environment. The bill contemplates cross‑border cooperation and international technical cooperation, and delegates to the authority competent the power to coordinate with foreign regulators and international bodies. ANPD contributions have compared the PL's architecture to EU experiences and recommended institutional arrangements that replicate the benefits of centralized coordination in other jurisdictions (see ANPD analysis at ANPD — PL analysis).
Implementation Timeline
2023-05-03: Bill filed in Senate.
2023-10-24: ANPD published its second technical analysis (Nota Técnica).
2024-12-10: Senate plenary approved the consolidated substitutive text.
2025-03-17: Transmitted to the Chamber of Deputies for review.
2025-04-04: Decision to create a Special Committee in the Chamber of Deputies.
2025-04-29: Special Committee formally constituted in the Chamber of Deputies.
Sources and References
| Source | Type |
|---|---|
| Projeto de Lei nº 2.338/2023 — Consolidated text (Senate PDF) | Primary Source |
| Congress of Brazil — PL 2338/2023 record (transmission & tramitation) | Primary Source |
| ANPD — Second analysis / Nota Técnica on PL 2338/2023 | Primary Source |
Requirements for a company
What an organisation has to do under Brazil - National AI Regulation (2.338/2023), at a glance. Not legal advice — the table below gives the provision and deadline for each item.
Not yet in force (Under Review). These requirements apply once the instrument takes effect and may change before then.
Must do
0Nothing in this category.
Must not do
0Nothing in this category.
Should do
6- Report serious incidents involving artificial intelligence systems promptly to the competent authority.Suppliers and operators of AI systems in Brazil
- Perform algorithmic impact assessments and implement risk mitigation measures for high-risk AI systems.Suppliers and operators of high-risk AI systems
- Provide clear disclosure of automated interactions and explicit notices when using biometric or emotion-recognition systems.Suppliers and operators deploying AI interactions, biometrics, or emotion recognition
- Ensure affected individuals can obtain explanations, contest automated decisions, and request human review.Suppliers and operators of AI systems with legal or significant impacts
- Implement internal governance programs, maintain traceability mechanisms, and preserve detailed system operational logs.Suppliers and operators of AI systems
- Complete required conformity assessments and certification procedures before supplying or operating high-risk AI systems.Suppliers and operators of high-risk AI systems
Should not do
1- Do not develop, supply, or operate artificial intelligence systems classified as presenting excessive risk.Suppliers and operators of AI systems in Brazil
Who must do what
The obligations under Brazil - National AI Regulation (2.338/2023), most serious first. Not legal advice — verify against the official text before relying on it.
| # | Who | Requirement | By when | Where | Severity |
|---|---|---|---|---|---|
| 1 | Suppliers and operators of AI systems in Brazil | Do not develop, supply, or operate artificial intelligence systems classified as presenting excessive risk. “differentiated obligations for systems classified as high or excessive risk.” | Before placing on market | — | Recommended |
| 2 | Suppliers and operators of AI systems in Brazil | Report serious incidents involving artificial intelligence systems promptly to the competent authority. “serious incidents must be reported to the authority competent” | — | — | Recommended |
| 3 | Suppliers and operators of high-risk AI systems | Perform algorithmic impact assessments and implement risk mitigation measures for high-risk AI systems. “algorithmic impact assessments and mitigation measures” | Before placing on market | — | Recommended |
| 4 | Suppliers and operators deploying AI interactions, biometrics, or emotion recognition | Provide clear disclosure of automated interactions and explicit notices when using biometric or emotion-recognition systems. “explicit notices for biometric and emotion‑recognition systems” | — | — | Recommended |
| 5 | Suppliers and operators of AI systems with legal or significant impacts | Ensure affected individuals can obtain explanations, contest automated decisions, and request human review. “rights of affected individuals (information, explanation, contestability and human review)” | — | — | Recommended |
| 6 | Suppliers and operators of AI systems | Implement internal governance programs, maintain traceability mechanisms, and preserve detailed system operational logs. “internal programs of governance, codes of conduct, traceability and logging” | — | — | Recommended |
| 7 | Suppliers and operators of high-risk AI systems | Complete required conformity assessments and certification procedures before supplying or operating high-risk AI systems. “conformity assessment and certification for high‑risk systems” | Before placing on market | — | Recommended |
Related Regulations
More AI regulation in Brazil
AI regulation in Brazil: full overview
- Brazil - National AI Policy (5.691/2019)
- Brazil - AI Strategy Amendment (4.979/2021)
- Brazil - PBIA Management Group (8/2025)
- Brazil - São Paulo - AI Surveillance Program (63.552/2024)
- Brazil - Digital Transformation Committee (1/2025)
- Brazil - AI Management Group (2/2025)
- Brazil - AI Governance in Judiciary (615/2025)
- Brazil - Digital Transformation Committee (12.308/2024)
© Regulations.AI · updated on 20 Sep 2026 · reviewed against official sources on 8 Sep 2026 using Gemini 3.6 Flash