Brazil - AI Governance in Judiciary (615/2025)

CNJ Resolution No. 615/2025

Resolução CNJ nº 615/2025

Brazil

RAI-BR-NA-RCN6CXX-2025
Effective: July 14, 2025
In Force(In Force)
RegulationGovernance and OversightRisk ManagementConformity Assessment and Registration
Export PDF

Resolução CNJ nº 615/2025 sets mandatory guidelines for the design, development, procurement, deployment, audit and governance of artificial intelligence (AI) solutions across the Brazilian Judiciary. It establishes risk classifications, mandatory audits and impact assessments, requirements for human supervision, data protection and transparency, and creates the National Committee for AI in the Judiciary (CNIAJ) to coordinate implementation and oversight.

Summary

Resolução CNJ nº 615/2025 (approved 11 March 2025; published in DJe/CNJ on 14 March 2025) establishes a comprehensive regulatory framework for the responsible development, procurement, deployment and governance of solutions that use artificial intelligence (AI) across the Brazilian Judiciary. The resolution updates and replaces the earlier Resolução CNJ nº 332/2020, expressly addressing modern AI paradigms including large language models (LLMs) and generative AI. Its core objectives are to ensure that AI adoption promotes innovation and efficiency while preserving fundamental rights, fairness, transparency, accountability and security. Key structural elements include a risk-based classification annex that defines high-risk and low-risk use-cases in judicial contexts (e.g., evaluation of evidence, formulation of legal conclusions, biometric identification and profiling are listed as high-risk), mandatory preliminary evaluations and ongoing algorithmic impact assessments, and explicit prohibitions on uses that preclude human oversight or cause abusive discrimination.

The resolution mandates privacy-by-design and privacy-by-default principles, requires secure data curation, storage and versioning, and imposes strict conditions on using third-party cloud or commercial LLMs for judicial work (including prohibitions against processing secret or justice-protected data unless anonymized at origin). It requires registration of research and development projects and production deployments in the Sinapses system (the CNJ digital platform for storing/testing/auditing models), compulsory training and digital literacy programs for magistrates and staff, and the creation of clear public reports and a public catalogue of AI applications used by the Judiciary. A new advisory and oversight body, the Comitê Nacional de Inteligência Artificial do Judiciário (CNIAJ), is established to coordinate risk classification, audits, monitoring, guidance, and to propose further regulation and cooperation agreements.

Operational obligations include (i) submission of systems to proportionate audit and monitoring regimes depending on risk classification; (ii) incident reporting to CNIAJ within 72 hours; (iii) documentation and provision of technical reports and indicators to enable auditability; (iv) contractual clauses for vendors to ensure non-use of judiciary data for model training without legal basis; and (v) a 12-month adaptation period for pre-existing projects. The resolution emphasizes human-in-the-loop supervision, contestability of AI outputs, explainability where technically possible, and the right of stakeholders (e.g., OAB, MP, Defensoria) to access impact assessments. Enforcement is implemented through monitoring, audit findings, referrals to competent authorities and application of administrative or contractual remedies; the resolution itself revokes CNJ Resolution 332/2020 when it comes into force (120 days after publication), and draws on national laws such as the LGPD and international standards (ISO/IEC, NIST) as references. The full official text and the consolidated PDF are published by the CNJ and available in the CNJ atos repository and on the CNJ website.

Full article

Read full text ↗

Overview

Resolução CNJ nº 615/2025 is the CNJ's principal normative instrument for AI governance in the Judiciary. Signed on 11 March 2025 and published in the Diário da Justiça do CNJ on 14 March 2025, the Resolution replaces Resolução CNJ nº 332/2020 and enters into force 120 days after publication (effective date: 14 July 2025). The instrument sets a risk-based governance architecture for AI systems used by courts and other judicial bodies, mandates the registration and auditing of systems via the Sinapses platform, institutes the Comitê Nacional de Inteligência Artificial do Judiciário (CNIAJ) as an oversight and advisory body, and prescribes a set of technical, organizational and procedural safeguards such as privacy-by-design/default, algorithmic impact assessments and human supervision. The full official text and PDF are available at the CNJ acts portal and in the CNJ atos repository: CNJ Act page for Resolução nº 615/2025 and official PDF of Resolução nº 615/2025.

Definitions

The Resolution provides targeted definitions tailored to judicial use. Core terms include system of artificial intelligence (a machine-based system producing probable results that may affect virtual, physical or real environments), cycle of life (conception through decommissioning), Sinapses (the PDPJ-Br module for storage/testing/training/distribution/auditing), developer, internal/external users, LLMs and IAGen (generative AI), preliminary evaluation, algorithmic impact assessment, auditability, explainability and contestability. These definitions prioritize operational clarity for courts, vendors and auditors, and align definitions with obligations such as privacybydesign, privacybydefault and requirements for representativity of datasets used in training.

Governance and Institutional Framework

The Resolution establishes a two-tier governance architecture: (1) internal tribunal-level governance (each tribunal must adopt internal rules, appoint responsible persons, provide training and ensure oversight of local projects), and (2) system-level governance under the CNJ. To operationalize system-level oversight it creates the Comitê Nacional de Inteligência Artificial do Judiciário (CNIAJ) with a plural composition, including CNJ councillors, magistrates, tribunal representatives, public defenders, Ministério Público, OAB and civil society experts. CNIAJ's functions include updating risk classifications, reclassifying systems, defining Sinapses rules, establishing audit methodologies, proposing bilateral/multilateral cooperation agreements, and recommending actions related to procurements and vendor evaluation. The Resolution preserves tribunal autonomy while mandating common standards for auditability, data handling and reporting. Detailed operational rules for CNIAJ's appointment and duties are published on the CNJ portal: CNIAJ information page. The text also contemplates the role of the Presidência do CNJ to issue further regulatory acts and to request external audits where needed.

Key Focus Areas

The regulation focuses on several interlocking priorities: risk classification, fundamental-rights compatibility, data governance, transparency and public reporting, human supervision and contestability, procurement and vendor obligations, technical and organizational security, auditing, and capacity building. The Annex classifies applications into high-risk (AR1–AR5) and low-risk categories (BR1–BR8) with explicit examples: high-risk uses include profiling and pattern identification (AR1), valuation of evidence (AR2), classification of criminal conduct (AR3), formulation of conclusive legal judgments or quantification of damages (AR4), and biometric identification/monitoring (AR5). Low-risk examples cover routine procedural tasks, summarization, jurimetrics and internal decision-support analytics where human oversight remains primary. The Resolution mandates algorithmic impact assessments, public reporting of impact conclusions, and the facility for OAB, Ministério Público and Defensoria Pública to access assessments and petition for audits. It also sets rules for use of commercial LLMs by magistrates and staff: training, limited auxiliary use, contractual safeguards preventing vendor reuse of judicial inputs for model training, and explicit prohibitions on processing secret-case data unless properly anonymized. Transparency obligations include public catalogues and accessible reports in plain language, and the right of external users to be informed when IA-assisted services are in use.

Implementation Framework

Operational implementation rests on several mandatory processes. All new R&D and deployment initiatives must be registered in Sinapses (PDPJ-Br module). Before production use, a tribunal-level preliminary evaluation must classify the system's risk and document mitigation measures. High-risk systems must undergo periodic external audits and ongoing algorithmic impact assessments, and CNIAJ may require reclassification. Contracts procuring AI solutions must include clauses ensuring compliance with LGPD and intellectual property law, commitments on security measures (encryption, isolation, certifications), and vendor obligations not to reuse judiciary-sourced inputs for model training absent explicit legal basis. The Resolution prescribes versioning and dataset retention policies, encryption and access controls, and the ability to remove or decommission models when obsolete. Tribunals have a 12-month adaptation period from publication to bring existing systems into compliance. Training programs—standardized digital literacy and ethics modules—must be provided by tribunal schools in line with CNJ guidance.

Monitoring and Evaluation

The Resolution mandates continuous monitoring, incident reporting (events to CNIAJ within 72 hours), and publication of accountability reports. CNIAJ will publish audit protocols and may propose technical commissions for inspections. Monitoring includes automated and manual checks on model performance, bias detection, data integrity (controls on versioning and tokens), and measurement of impacts on rights. Audit reports and impact assessments are to be published on Sinapses in accessible language; where secrecy or confidentiality prevents full disclosure, redacted or summary information is required. Nonconformities trigger timelines for remediation proportionate to severity, and CNIAJ can recommend corrective actions or trigger further administrative procedures in competent bodies.

Penalties, Liability, and Appeals

The Resolution itself focuses on governance and monitoring rather than prescriptive fines; noncompliance is addressed through audits, mandated corrective measures, suspension or decommissioning of systems, referral to disciplinary or judicial authorities, contractual remedies and potential administrative liability under applicable laws. Art. 40 states that CNIAJ monitoring is non-disciplinary in itself but may report findings to competent organs. Remedies include ordering audits, suspension of operations, revocation of procurement, contractual penalties, internal disciplinary processes against responsible officials, and referrals to bodies such as the National Data Protection Authority (ANPD) when LGPD breaches are suspected. The Resolution preserves the right to administrative and judicial appeal of CNJ/CNIAJ measures under applicable procedural rules.

Relationship to Other Instruments

Resolução nº 615/2025 explicitly revokes Resolução CNJ nº 332/2020 upon entry into force and references existing Brazilian law and norms, notably the Lei Geral de Proteção de Dados Pessoais (LGPD, Lei nº 13.709/2018), Lei Complementar nº 35/1979 (Loman) and intellectual property rules (Lei nº 9.279/1996), among others. It also mandates alignment with international technical standards where appropriate (ISO/IEC 42001, ISO/IEC 27000 series, NIST). The Resolution complements and does not replace sectoral legislation; tribunals must ensure compliance with all applicable federal, state and municipal laws and international treaties. The CNJ may sign cooperation agreements to harmonize practices, and the Resolution anticipates interaction with the ANPD on data protection issues and with procurement and audit institutions for contract oversight.

International Alignment

The text explicitly recommends adopting recognized international technical standards (ISO/IEC, NIST) as reference points and promotes cooperation with international bodies. CNIAJ is mandated to suggest conventions and cooperative arrangements with national and international institutions. The Resolution's risk-based approach, emphasis on human oversight, accountability, and mandatory impact assessments align with global trends in AI governance, including the EU AI Act's risk-based architecture and OECD principles on trustworthy AI. The CNJ positions its framework to facilitate interoperability and cross-border cooperation while preserving national sovereignty and compliance with Brazilian constitutional guarantees.

Implementation Timeline

EventDate
Signature by CNJ President2025-03-11
Publication in DJe/CNJ2025-03-14
Entry into force (120 days after publication)2025-07-14
12-month adaptation deadline for existing systems2026-03-14
Portaria designating CNIAJ membership (example)2025-08-27

Sources and References

SourceType
Resolução CNJ nº 615/2025 — CNJ atos page (official consolidated text)Primary Source
Official PDF — Resolução CNJ nº 615/2025Primary Source
CNJ — Comitê Nacional de Inteligência Artificial do Judiciário (CNIAJ) pagePrimary Source

Requirements for a company

What an organisation has to do under Brazil - AI Governance in Judiciary (615/2025), at a glance. Not legal advice — the table below gives the provision and deadline for each item.

Must do

13
  • Adapt all existing AI systems to comply with this regulation.Tribunals using AI systems.
  • Register all new AI R&D and deployment initiatives in the Sinapses platform.Tribunals developing or deploying new AI systems.
  • Conduct a tribunal-level preliminary evaluation to classify risk and document mitigation measures.Tribunals before production use of an AI system.
  • Perform ongoing algorithmic impact assessments for high-risk AI systems.Tribunals using high-risk AI systems.
  • Undergo periodic external audits for high-risk AI systems.Tribunals using high-risk AI systems.
  • Include specific clauses in AI procurement contracts regarding data reuse, security, and LGPD compliance.Tribunals procuring AI solutions.
  • +7 more in the table below

Must not do

0

Nothing in this category.

Should do

0

Nothing in this category.

Should not do

0

Nothing in this category.

Who must do what

The obligations under Brazil - AI Governance in Judiciary (615/2025), most serious first. Not legal advice — verify against the official text before relying on it.

#WhoRequirementBy whenWhereSeverity
1Tribunals using AI systems.Adapt all existing AI systems to comply with this regulation.
Tribunals have a 12-month adaptation period from publication to bring existing systems into compliance.
Mar 14, 2026Critical
2Tribunals developing or deploying new AI systems.Register all new AI R&D and deployment initiatives in the Sinapses platform.
All new R&D and deployment initiatives must be registered in Sinapses (PDPJ-Br module).
Before placing on marketCritical
3Tribunals before production use of an AI system.Conduct a tribunal-level preliminary evaluation to classify risk and document mitigation measures.
Before production use, a tribunal-level preliminary evaluation must classify the system's risk and document mitigation measures.
Before production useCritical
4Tribunals using high-risk AI systems.Perform ongoing algorithmic impact assessments for high-risk AI systems.
High-risk systems must undergo periodic external audits and ongoing algorithmic impact assessments
Critical
5Tribunals using high-risk AI systems.Undergo periodic external audits for high-risk AI systems.
High-risk systems must undergo periodic external audits and ongoing algorithmic impact assessments
Critical
6Tribunals procuring AI solutions.Include specific clauses in AI procurement contracts regarding data reuse, security, and LGPD compliance.
Contracts procuring AI solutions must include clauses ensuring compliance with LGPD... and vendor obligations not to reuse judiciary-sourced inputs
Before procurementCritical
7Tribunals using AI systems.Implement technical and organizational security measures, including encryption, access controls, and versioning.
The Resolution prescribes versioning and dataset retention policies, encryption and access controls
Critical
8Tribunals using AI systems.Report incidents related to AI systems to CNIAJ within 72 hours.
incident reporting (events to CNIAJ within 72 hours)
Within 72 hours of incidentCritical
9Tribunals developing or using AI systems.Implement privacy-by-design/default, data anonymization, and ensure representativity of datasets.
privacy-by-design/default, and requirements for representativity of datasets used in training.
Critical
10Tribunals using AI systems.Ensure human supervision and contestability for all AI systems.
human supervision and contestability
Important
11Tribunals using AI systems.Publish audit reports and algorithmic impact assessments in accessible language on Sinapses.
Audit reports and impact assessments are to be published on Sinapses in accessible language
Important
12Tribunal schools.Provide standardized digital literacy and ethics training programs for magistrates and staff.
Training programs—standardized digital literacy and ethics modules—must be provided by tribunal schools
Important
13Each tribunal.Adopt internal rules for AI governance, appoint responsible persons, and ensure oversight of local projects.
each tribunal must adopt internal rules, appoint responsible persons, provide training and ensure oversight of local projects
Important

© Regulations.AI · updated on 13-Jun-2026