Brazil AI Regulation Bill (PL 2338/2023)

Bill No. 2338, of 2023 - Provides for the Use of Artificial Intelligence

Projeto de Lei nº 2338, de 2023 - Dispõe sobre o uso da Inteligência Artificial

Brazil

RAI-BR-NA-PL23382-2023

PL 2338/2023

Under Review(Under Review)
BillGovernance and OversightRisk ManagementFundamental Rights
Export PDF

Brazil's Bill No. 2338/2023 establishes a risk-based AI regulatory framework to balance innovation with fundamental rights protection.

Summary

Brazil's Bill No. 2338/2023 proposes a comprehensive AI regulatory framework, adopting a risk-based approach inspired by the EU AI Act and OECD recommendations. It categorizes AI systems into excessive, high, and non-high risks, imposing corresponding obligations to balance innovation with the protection of fundamental rights and democratic principles. The bill, currently under review in the Chamber of Deputies, aims to create a predictable and secure legal environment for ethical AI development and deployment, addressing issues like civil liability and data protection.

Full article

Read full text ↗

Overview

Brazil's Bill No. 2338/2023, known as the Comprehensive AI Regulatory Framework, represents a significant legislative effort to establish general national standards for the responsible development, implementation, and use of artificial intelligence (AI) systems within the country. Introduced by Senator Rodrigo Pacheco, the President of the Senate, the bill aims to strike a balance between fostering technological innovation and ensuring the protection of fundamental rights, democratic principles, and scientific and technological advancement. It is largely inspired by international legislation, such as the European Union's AI Act, and draws from recommendations by the Organisation for Economic Co-operation and Development (OECD). The core of the proposed framework is a risk-based approach, categorizing AI systems into different levels of risk – excessive, high, and non-high/non-excessive – with corresponding obligations and safeguards. This tiered approach is designed to prevent overly burdensome regulations on low-risk applications while imposing stringent requirements on systems that pose significant threats to public safety, human rights, or democratic values.

The legislative journey of Bill No. 2338/2023 began in May 2023 when it was presented to the Senate. After extensive debate and amendments, including a comprehensive report from the Temporary Internal Commission on Artificial Intelligence in Brazil (CTIA), the Senate approved the bill on December 10, 2024. Following its approval in the Senate, the bill was remitted to the Chamber of Deputies on March 17, 2025, where it is currently under review. The bill's overarching goal is to create a predictable and secure legal environment for AI in Brazil, ensuring that AI systems are developed and deployed ethically, transparently, and with accountability. It seeks to protect citizens' rights, including the right to privacy, data protection, and non-discrimination, while also promoting responsible innovation and competitiveness in the AI sector. The framework also addresses critical issues such as civil liability for damages caused by AI systems and the use of copyrighted material for AI training.

Definitions

Bill No. 2338/2023 introduces several key definitions to clarify the scope and application of its regulatory framework. An "artificial intelligence system" or "AI system" is broadly defined as a system that, for explicit or implicit objectives, infers how to generate outputs such as content, predictions, recommendations, or decisions that can influence physical or virtual environments. This definition emphasizes the functional aspects of AI, encompassing various forms of machine learning and automated decision-making processes. The bill also distinguishes between different actors involved in the AI lifecycle. A "provider of an AI system" is identified as a natural or legal person, public or private, who develops an AI system, directly or by order, with a view to placing it on the market or applying it in a service provided by them, under their own name or brand, whether for a fee or free of charge. An "operator of an AI system" refers to any natural or legal person, public or private, who uses an AI system under their authority, except when the system is used for personal and non-economic purposes.

Central to the bill's risk-based approach are the definitions of different risk categories. "Excessive-risk AI systems" are those deemed too dangerous to be permitted, as they inherently pose threats to fundamental rights or democratic principles. These systems are explicitly prohibited within Brazil. "High-risk AI systems" are those that could directly affect individuals' lives or rights in critical areas such as healthcare, justice, credit rating, public safety, or employment decisions. These systems are subject to stricter regulatory requirements, including algorithmic impact assessments, robustness, accuracy, reliability, and coverage tests, as well as human supervision. The bill also defines "non-high/non-excessive risk AI systems" as those presenting lower risks, which are subject to general obligations but fewer stringent requirements. Other important definitions include "indirect discrimination," which occurs when an apparently neutral rule, practice, or criterion has the potential to disadvantage individuals belonging to a specific group, unless such rule, practice, or criterion has a reasonable and legitimate objective or justification in light of the right to equality and other fundamental rights. These definitions provide the foundational legal terminology for the application and enforcement of the proposed AI regulation.

Governance and Institutional Framework

A cornerstone of Brazil's Bill No. 2338/2023 is the establishment of a robust governance and institutional framework to oversee the development, implementation, and use of AI systems. The bill proposes the creation of a National AI Regulation and Governance System (SIA - Sistema Nacional de Regulação e Governança de Inteligência Artificial). This system is envisioned as the central coordinating body responsible for promoting cooperation among various regulatory agencies and ensuring compliance with the established rules for AI. The exact structure and composition of the SIA, including the designation of a specific regulatory authority, are expected to be detailed in subsequent regulations, but the intent is to have a competent and independent authority to enforce the provisions of the law. This authority will play a crucial role in promoting a safe and ethical AI ecosystem, fostering responsible innovation, and protecting citizens' rights.

The proposed governance framework emphasizes the need for a multi-stakeholder approach, encouraging dialogue and collaboration between the government, private sector, academia, and civil society. The regulatory authority will be tasked with developing guidelines, conducting oversight, and imposing penalties for non-compliance. Furthermore, the bill outlines the importance of transparency and accountability within the governance structure itself, ensuring that the regulatory processes are clear, accessible, and subject to public scrutiny. The establishment of the SIA is a strategic move to centralize AI governance, allowing for a coherent and consistent application of the regulatory framework across different sectors and applications of AI. This centralized approach aims to provide legal certainty for AI developers and operators while safeguarding the interests of individuals and society as a whole, preventing fragmented or conflicting regulatory efforts. The framework also anticipates mechanisms for public participation and consultation in the ongoing development of AI policies and regulations.

Key Focus Areas

The Brazilian AI Bill No. 2338/2023 focuses on several critical areas to ensure a comprehensive and effective regulatory framework for artificial intelligence. A primary focus is the risk-based classification of AI systems, which dictates the level of regulatory scrutiny applied. Systems are categorized into three tiers: "excessive risk," which are prohibited due to their potential to violate fundamental rights; "high-risk," which require stringent compliance measures; and "non-high/non-excessive risk," subject to general obligations. High-risk systems include those used in critical infrastructure, law enforcement, justice administration, credit scoring, employment, education, and medical diagnoses, necessitating algorithmic impact assessments, robustness tests, and human oversight. This tiered approach aims to tailor regulatory burdens to the actual risks posed by different AI applications, promoting responsible innovation without stifling technological progress.

Another significant focus is the protection of fundamental rights and data privacy. The bill explicitly aims to protect human rights, including the right to privacy, data protection, and non-discrimination. It aligns with Brazil's General Data Protection Law (LGPD) and reiterates principles such as the right to be informed about AI interactions, the right to explanation of AI decisions, and the right to challenge or seek human intervention for decisions that significantly impact individuals. The bill prohibits AI systems that use subliminal techniques to induce harmful behavior or exploit vulnerabilities of specific groups, and it restricts government use of AI for social scoring. Additionally, the framework addresses transparency and accountability, requiring AI developers and operators to ensure their systems are understandable, auditable, and traceable, facilitating the assignment of responsibility for damages. The bill also touches upon intellectual property, allowing for the automated use of copyrighted works for non-profit purposes like research and journalism, while granting authors the right to prohibit the use of their works for AI training by large technology companies.

Implementation Framework

The implementation framework of Brazil's Bill No. 2338/2023 outlines the practical mechanisms and obligations for AI system providers and operators to comply with the new regulations. A central component is the mandatory self-classification of AI systems by developers according to their risk level (excessive, high, or non-high/non-excessive). For high-risk AI systems, providers and operators will be required to conduct algorithmic impact assessments (AIA) to identify, evaluate, and mitigate potential risks to fundamental rights and public safety. These assessments must cover aspects such as robustness, accuracy, reliability, and coverage, ensuring that systems perform as intended and do not produce discriminatory or harmful outcomes. Furthermore, the bill mandates human supervision for high-risk AI systems, allowing for human intervention, override, or cessation of system operation when necessary to prevent risks. This human-in-the-loop or human-on-the-loop approach is critical for maintaining accountability and control over autonomous systems.

Beyond risk assessment and human oversight, the implementation framework also includes provisions for transparency and explainability. AI system agents are obligated to provide sufficient, objective, clear, and accessible information about the procedures necessary for individuals to exercise their rights, such as challenging AI decisions or seeking explanations. Data protection is also a key aspect, with the bill aligning its provisions with Brazil's General Data Protection Law (LGPD) to ensure the lawful and ethical handling of personal data used in AI systems. To foster innovation, the bill supports the use of regulatory sandboxes, which are controlled environments where developers can test AI systems under relaxed regulatory requirements for a limited period, allowing for experimentation and learning before full market deployment. The framework also specifies that the government will establish a transition regime to ensure that new obligations are met proportionally and efficiently, without prejudicing the interests of affected individuals and groups. These measures collectively aim to create a practical and adaptable regulatory environment that supports responsible AI development.

Monitoring and Evaluation

The monitoring and evaluation mechanisms within Brazil's Bill No. 2338/2023 are designed to ensure ongoing compliance with the AI regulatory framework and to adapt to the rapid evolution of AI technology. The proposed National AI Regulation and Governance System (SIA) will be the central authority responsible for overseeing the implementation of the law. This body will likely be tasked with establishing guidelines for compliance, conducting audits, and monitoring the market for new AI applications and their associated risks. The bill emphasizes the importance of continuous assessment of AI systems, particularly high-risk ones, throughout their lifecycle, from development to deployment and use. This includes verifying that algorithmic impact assessments are regularly updated and that the systems maintain their required levels of robustness, accuracy, and reliability. The regulatory authority will also be responsible for collecting data on AI incidents and non-compliance, which will inform future policy adjustments and enforcement actions.

Furthermore, the framework anticipates a dynamic approach to regulation, recognizing that AI technology is constantly advancing. The monitoring process will involve evaluating the effectiveness of the risk-based classification system and the adequacy of the imposed obligations. This continuous evaluation will allow the regulatory authority to identify emerging risks, assess the impact of the legislation on innovation, and propose necessary amendments or supplementary regulations. The bill also promotes transparency in the monitoring process, encouraging public engagement and feedback on the performance of AI systems and the regulatory framework. This includes mechanisms for individuals to report concerns or violations, ensuring that the oversight process is responsive to societal needs and protects fundamental rights. The goal is to create a responsive and adaptive regulatory environment that can effectively govern AI while fostering its beneficial development for Brazilian society.

Penalties, Liability, and Appeals

Brazil's Bill No. 2338/2023 establishes a clear framework for penalties, liability, and appeals to ensure the enforceability of its AI regulations. For non-compliance with the provisions of the bill, the proposed penalties are substantial, aiming to deter violations and ensure adherence to ethical and safety standards. Fines can go up to BRL 50 million (approximately USD 1.6 million) or 2% of the total turnover of the company in Brazil, whichever is higher. These significant financial penalties underscore the seriousness with which the Brazilian legislature views the responsible development and deployment of AI systems. The specific criteria for imposing penalties, including the severity of the violation and the size of the offending entity, are expected to be further detailed in subsequent regulations issued by the designated regulatory authority.

Regarding liability, the bill introduces provisions for civil liability for damages caused by AI systems. It stipulates that the supplier or operator of an AI system causing damage is required to repair it integrally. For high-risk AI systems, liability is generally considered strict, meaning that the responsible party can be held liable regardless of intent or fault, to the extent of their participation in the damages. However, the bill also provides for exceptions where liability may be excluded, such as when the damage is proven to be the exclusive fault of the victim or a third party, or due to an external force majeure event. In cases involving consumer relations, the bill clarifies that the provisions of Brazil's Consumer Defense Code (Lei nº 8.078/1990) will apply, without prejudice to the additional rules established by the AI law. This comprehensive approach to liability aims to ensure that individuals affected by AI systems have adequate avenues for redress and that accountability is clearly assigned throughout the AI value chain. The bill also implicitly supports the right to appeal decisions or predictions made by AI systems that produce legal effects or significantly impact individuals' interests, reinforcing the fundamental right to due process and contestability.

Relationship to Other Instruments

Brazil's Bill No. 2338/2023 is designed to integrate with and complement existing legal instruments, rather than supersede them entirely. A crucial relationship exists with the Lei Geral de Proteção de Dados Pessoais (LGPD), Brazil's General Data Protection Law (Law No. 13.709/2018). The AI bill explicitly aligns with the LGPD to ensure the protection of privacy and personal data processed by AI systems. It reiterates data protection principles and rights, particularly concerning the use of personal data for AI training and the need for enhanced safeguards for sensitive data. Any processing of personal data by AI systems must comply with the legal bases and principles established by the LGPD, reinforcing the country's commitment to data subject rights.

Furthermore, the bill acknowledges and interacts with other significant pieces of Brazilian legislation. The Código de Defesa do Consumidor (Consumer Defense Code) (Law No. 8.078/1990) remains applicable to civil liability arising from damages caused by AI systems in consumer relations, with the AI bill providing additional specific rules. This ensures that consumers retain their existing protections while gaining new ones tailored to AI. The Lei dos Direitos Autorais (Copyright Law) (Law No. 9.610/1998) is also referenced, particularly concerning the use of copyrighted material for AI training. The AI bill allows for automated use of works by AI systems for non-commercial purposes like research, education, and journalism, under certain conditions, while also granting authors the right to prohibit such use by large technology companies. The bill also mentions the Marco Civil da Internet (Internet Civil Rights Framework) (Law No. 12.965/2014) as a foundational law for digital rights in Brazil, indicating a broader legislative ecosystem for technology governance. This approach ensures a coherent legal landscape where AI regulation builds upon and strengthens existing protections and rights.

International Alignment

Brazil's Bill No. 2338/2023 demonstrates a strong commitment to international alignment in its approach to AI regulation, drawing significant inspiration from global best practices and frameworks. The bill is largely inspired by European legislation, particularly the European Union's Artificial Intelligence Act. This influence is evident in its adoption of a risk-based approach to AI regulation, categorizing systems by their potential to cause harm and imposing differentiated obligations accordingly. The emphasis on fundamental rights, transparency, accountability, and robust governance mechanisms also mirrors the principles enshrined in the EU's pioneering AI framework. By aligning with such a comprehensive and influential international standard, Brazil aims to ensure that its regulatory environment is compatible with major global markets and promotes cross-border cooperation in AI governance.

Beyond the EU AI Act, the Brazilian bill also incorporates insights and recommendations from the Organisation for Economic Co-operation and Development (OECD) on artificial intelligence. The OECD's principles for trustworthy AI, which advocate for human-centered values, robust and secure AI systems, transparency, accountability, and multi-stakeholder governance, have informed the foundational tenets of the Brazilian proposal. This international alignment is crucial for fostering global interoperability and reducing regulatory fragmentation, which can hinder innovation and international trade in AI technologies. By adopting internationally recognized principles and regulatory models, Brazil positions itself as a responsible actor in the global AI landscape, seeking to balance national interests with the broader goal of developing ethical and safe AI for the benefit of humanity. This strategic alignment also facilitates future collaboration on AI research, development, and standard-setting with other nations and international bodies.

Implementation Timeline

MilestoneDateNotes
Bill presented to the Senate2023-05-03Introduced by Senator Rodrigo Pacheco (PSD/MG)
Senate approval2024-12-10Approved by the Plenary of the Senate
Remitted to the Chamber of Deputies2025-03-17Currently under review in the Chamber of Deputies
Awaiting vote in Chamber of DeputiesTBDNext legislative step before presidential sanction
Presidential sanctionTBDRequired for the bill to become law
Entry into ForceTBDExpected to include a transition period for new obligations

Sources and References

SourceType

Read this article-by-article

Plain-English breakdown of 11 key articles, with cross-jurisdiction equivalents where applicable.

Open breakdown →

Requirements for a company

What an organisation has to do under Brazil AI Regulation Bill (PL 2338/2023), at a glance. Not legal advice — the table below gives the provision and deadline for each item.

Not yet in force (Under Review). These requirements apply once the instrument takes effect and may change before then.

Must do

12
  • Do not develop or deploy AI systems classified as excessive-risk.Providers and operators of AI systems.
  • Do not use AI systems for subliminal techniques, exploiting vulnerabilities, or government social scoring.Providers and operators of AI systems, government entities.
  • Mandatorily classify AI systems into excessive, high, or non-high/non-excessive risk categories.Developers of AI systems.
  • Conduct comprehensive algorithmic impact assessments for all high-risk AI systems.Providers and operators of high-risk AI systems.
  • Implement mechanisms for human oversight, intervention, or cessation for high-risk AI systems.Providers and operators of high-risk AI systems.
  • Ensure all personal data processing by AI systems complies with Brazil's General Data Protection Law (LGPD).Providers and operators of AI systems.
  • +6 more in the table below

Must not do

0

Nothing in this category.

Should do

0

Nothing in this category.

Should not do

0

Nothing in this category.

Who must do what

The obligations under Brazil AI Regulation Bill (PL 2338/2023), most serious first. Not legal advice — verify against the official text before relying on it.

#WhoRequirementBy whenWhereSeverity
1Providers and operators of AI systems.Do not develop or deploy AI systems classified as excessive-risk.
"Excessive-risk AI systems" are those deemed too dangerous to be permitted... These systems are explicitly prohibited within Brazil.
Before placing on marketCritical
2Providers and operators of AI systems, government entities.Do not use AI systems for subliminal techniques, exploiting vulnerabilities, or government social scoring.
The bill prohibits AI systems that use subliminal techniques to induce harmful behavior or exploit vulnerabilities... and it restricts government use of AI for social scoring.
Before placing on marketCritical
3Developers of AI systems.Mandatorily classify AI systems into excessive, high, or non-high/non-excessive risk categories.
mandatory self-classification of AI systems by developers according to their risk level
Before placing on marketCritical
4Providers and operators of high-risk AI systems.Conduct comprehensive algorithmic impact assessments for all high-risk AI systems.
For high-risk AI systems, providers and operators will be required to conduct algorithmic impact assessments (AIA)
Before placing on marketCritical
5Providers and operators of high-risk AI systems.Implement mechanisms for human oversight, intervention, or cessation for high-risk AI systems.
the bill mandates human supervision for high-risk AI systems, allowing for human intervention, override, or cessation of system operation
Before placing on marketCritical
6Providers and operators of AI systems.Ensure all personal data processing by AI systems complies with Brazil's General Data Protection Law (LGPD).
Any processing of personal data by AI systems must comply with the legal bases and principles established by the LGPD
Critical
7Providers and operators of high-risk AI systems.Perform and document tests for high-risk AI systems to ensure robustness, accuracy, reliability, and coverage.
These assessments must cover aspects such as robustness, accuracy, reliability, and coverage
Before placing on marketImportant
8Providers and operators of AI systems.Provide sufficient, objective, clear, and accessible information about AI system operations and rights.
AI system agents are obligated to provide sufficient, objective, clear, and accessible information about the procedures necessary for individuals to exercise their rights
Important
9Providers and operators of AI systems.Implement measures to prevent and combat direct and indirect discrimination and protect vulnerable groups.
The bill explicitly aims to protect human rights, including the right to privacy, data protection, and non-discrimination.
Important
10Developers and operators of AI systems.Ensure AI systems are understandable, auditable, and traceable to facilitate responsibility for damages.
requiring AI developers and operators to ensure their systems are understandable, auditable, and traceable, facilitating the assignment of responsibility for damages.
Important
11Providers and operators of AI systems.Adhere to rules regarding the use of copyrighted material for AI training, respecting authors' rights.
granting authors the right to prohibit the use of their works for AI training by large technology companies.
Important
12Providers and operators of AI systems.Continuously assess and update AI systems, especially high-risk ones, throughout their lifecycle.
emphasizes the importance of continuous assessment of AI systems, particularly high-risk ones, throughout their lifecycle
Important

© Regulations.AI — created on 11-Apr-2026 using Gemini 2.5 Flash · updated on 13-Jun-2026