Brazil - AI Governance in Judiciary (615/2025)
CNJ Resolution No. 615/2025
Resolução CNJ nº 615/2025
Brazil
RAI-BR-NA-RCN6CXX-2025Resolução CNJ nº 615/2025 sets mandatory guidelines for the design, development, procurement, deployment, audit and governance of artificial intelligence (AI) solutions across the Brazilian Judiciary. It establishes risk classifications, mandatory audits and impact assessments, requirements for human supervision, data protection and transparency, and creates the National Committee for AI in the Judiciary (CNIAJ) to coordinate implementation and oversight.
Summary
Resolução CNJ nº 615/2025 (approved 11 March 2025; published in DJe/CNJ on 14 March 2025) establishes a comprehensive regulatory framework for the responsible development, procurement, deployment and governance of solutions that use artificial intelligence (AI) across the Brazilian Judiciary. The resolution updates and replaces the earlier Resolução CNJ nº 332/2020, expressly addressing modern AI paradigms including large language models (LLMs) and generative AI. Its core objectives are to ensure that AI adoption promotes innovation and efficiency while preserving fundamental rights, fairness, transparency, accountability and security. Key structural elements include a risk-based classification annex that defines high-risk and low-risk use-cases in judicial contexts (e.g., evaluation of evidence, formulation of legal conclusions, biometric identification and profiling are listed as high-risk), mandatory preliminary evaluations and ongoing algorithmic impact assessments, and explicit prohibitions on uses that preclude human oversight or cause abusive discrimination.
The resolution mandates privacy-by-design and privacy-by-default principles, requires secure data curation, storage and versioning, and imposes strict conditions on using third-party cloud or commercial LLMs for judicial work (including prohibitions against processing secret or justice-protected data unless anonymized at origin). It requires registration of research and development projects and production deployments in the Sinapses system (the CNJ digital platform for storing/testing/auditing models), compulsory training and digital literacy programs for magistrates and staff, and the creation of clear public reports and a public catalogue of AI applications used by the Judiciary. A new advisory and oversight body, the Comitê Nacional de Inteligência Artificial do Judiciário (CNIAJ), is established to coordinate risk classification, audits, monitoring, guidance, and to propose further regulation and cooperation agreements.
Operational obligations include (i) submission of systems to proportionate audit and monitoring regimes depending on risk classification; (ii) incident reporting to CNIAJ within 72 hours; (iii) documentation and provision of technical reports and indicators to enable auditability; (iv) contractual clauses for vendors to ensure non-use of judiciary data for model training without legal basis; and (v) a 12-month adaptation period for pre-existing projects. The resolution emphasizes human-in-the-loop supervision, contestability of AI outputs, explainability where technically possible, and the right of stakeholders (e.g., OAB, MP, Defensoria) to access impact assessments. Enforcement is implemented through monitoring, audit findings, referrals to competent authorities and application of administrative or contractual remedies; the resolution itself revokes CNJ Resolution 332/2020 when it comes into force (120 days after publication), and draws on national laws such as the LGPD and international standards (ISO/IEC, NIST) as references. The full official text and the consolidated PDF are published by the CNJ and available in the CNJ atos repository and on the CNJ website.
Full article
Read full text ↗Overview
Resolução CNJ nº 615/2025 is the CNJ's principal normative instrument for AI governance in the Judiciary. Signed on 11 March 2025 and published in the Diário da Justiça do CNJ on 14 March 2025, the Resolution replaces Resolução CNJ nº 332/2020 and enters into force 120 days after publication (effective date: 14 July 2025). The instrument sets a risk-based governance architecture for AI systems used by courts and other judicial bodies, mandates the registration and auditing of systems via the Sinapses platform, institutes the Comitê Nacional de Inteligência Artificial do Judiciário (CNIAJ) as an oversight and advisory body, and prescribes a set of technical, organizational and procedural safeguards such as privacy-by-design/default, algorithmic impact assessments and human supervision. The full official text and PDF are available at the CNJ acts portal and in the CNJ atos repository: CNJ Act page for Resolução nº 615/2025 and official PDF of Resolução nº 615/2025.
Definitions
The Resolution provides targeted definitions tailored to judicial use. Core terms include system of artificial intelligence (a machine-based system producing probable results that may affect virtual, physical or real environments), cycle of life (conception through decommissioning), Sinapses (the PDPJ-Br module for storage/testing/training/distribution/auditing), developer, internal/external users, LLMs and IAGen (generative AI), preliminary evaluation, algorithmic impact assessment, auditability, explainability and contestability. These definitions prioritize operational clarity for courts, vendors and auditors, and align definitions with obligations such as privacybydesign, privacybydefault and requirements for representativity of datasets used in training.
Governance and Institutional Framework
The Resolution establishes a two-tier governance architecture: (1) internal tribunal-level governance (each tribunal must adopt internal rules, appoint responsible persons, provide training and ensure oversight of local projects), and (2) system-level governance under the CNJ. To operationalize system-level oversight it creates the Comitê Nacional de Inteligência Artificial do Judiciário (CNIAJ) with a plural composition, including CNJ councillors, magistrates, tribunal representatives, public defenders, Ministério Público, OAB and civil society experts. CNIAJ's functions include updating risk classifications, reclassifying systems, defining Sinapses rules, establishing audit methodologies, proposing bilateral/multilateral cooperation agreements, and recommending actions related to procurements and vendor evaluation. The Resolution preserves tribunal autonomy while mandating common standards for auditability, data handling and reporting. Detailed operational rules for CNIAJ's appointment and duties are published on the CNJ portal: CNIAJ information page. The text also contemplates the role of the Presidência do CNJ to issue further regulatory acts and to request external audits where needed.
Key Focus Areas
The regulation focuses on several interlocking priorities: risk classification, fundamental-rights compatibility, data governance, transparency and public reporting, human supervision and contestability, procurement and vendor obligations, technical and organizational security, auditing, and capacity building. The Annex classifies applications into high-risk (AR1–AR5) and low-risk categories (BR1–BR8) with explicit examples: high-risk uses include profiling and pattern identification (AR1), valuation of evidence (AR2), classification of criminal conduct (AR3), formulation of conclusive legal judgments or quantification of damages (AR4), and biometric identification/monitoring (AR5). Low-risk examples cover routine procedural tasks, summarization, jurimetrics and internal decision-support analytics where human oversight remains primary. The Resolution mandates algorithmic impact assessments, public reporting of impact conclusions, and the facility for OAB, Ministério Público and Defensoria Pública to access assessments and petition for audits. It also sets rules for use of commercial LLMs by magistrates and staff: training, limited auxiliary use, contractual safeguards preventing vendor reuse of judicial inputs for model training, and explicit prohibitions on processing secret-case data unless properly anonymized. Transparency obligations include public catalogues and accessible reports in plain language, and the right of external users to be informed when IA-assisted services are in use.
Implementation Framework
Operational implementation rests on several mandatory processes. All new R&D and deployment initiatives must be registered in Sinapses (PDPJ-Br module). Before production use, a tribunal-level preliminary evaluation must classify the system's risk and document mitigation measures. High-risk systems must undergo periodic external audits and ongoing algorithmic impact assessments, and CNIAJ may require reclassification. Contracts procuring AI solutions must include clauses ensuring compliance with LGPD and intellectual property law, commitments on security measures (encryption, isolation, certifications), and vendor obligations not to reuse judiciary-sourced inputs for model training absent explicit legal basis. The Resolution prescribes versioning and dataset retention policies, encryption and access controls, and the ability to remove or decommission models when obsolete. Tribunals have a 12-month adaptation period from publication to bring existing systems into compliance. Training programs—standardized digital literacy and ethics modules—must be provided by tribunal schools in line with CNJ guidance.
Monitoring and Evaluation
The Resolution mandates continuous monitoring, incident reporting (events to CNIAJ within 72 hours), and publication of accountability reports. CNIAJ will publish audit protocols and may propose technical commissions for inspections. Monitoring includes automated and manual checks on model performance, bias detection, data integrity (controls on versioning and tokens), and measurement of impacts on rights. Audit reports and impact assessments are to be published on Sinapses in accessible language; where secrecy or confidentiality prevents full disclosure, redacted or summary information is required. Nonconformities trigger timelines for remediation proportionate to severity, and CNIAJ can recommend corrective actions or trigger further administrative procedures in competent bodies.
Penalties, Liability, and Appeals
The Resolution itself focuses on governance and monitoring rather than prescriptive fines; noncompliance is addressed through audits, mandated corrective measures, suspension or decommissioning of systems, referral to disciplinary or judicial authorities, contractual remedies and potential administrative liability under applicable laws. Art. 40 states that CNIAJ monitoring is non-disciplinary in itself but may report findings to competent organs. Remedies include ordering audits, suspension of operations, revocation of procurement, contractual penalties, internal disciplinary processes against responsible officials, and referrals to bodies such as the National Data Protection Authority (ANPD) when LGPD breaches are suspected. The Resolution preserves the right to administrative and judicial appeal of CNJ/CNIAJ measures under applicable procedural rules.
Relationship to Other Instruments
Resolução nº 615/2025 explicitly revokes Resolução CNJ nº 332/2020 upon entry into force and references existing Brazilian law and norms, notably the Lei Geral de Proteção de Dados Pessoais (LGPD, Lei nº 13.709/2018), Lei Complementar nº 35/1979 (Loman) and intellectual property rules (Lei nº 9.279/1996), among others. It also mandates alignment with international technical standards where appropriate (ISO/IEC 42001, ISO/IEC 27000 series, NIST). The Resolution complements and does not replace sectoral legislation; tribunals must ensure compliance with all applicable federal, state and municipal laws and international treaties. The CNJ may sign cooperation agreements to harmonize practices, and the Resolution anticipates interaction with the ANPD on data protection issues and with procurement and audit institutions for contract oversight.
International Alignment
The text explicitly recommends adopting recognized international technical standards (ISO/IEC, NIST) as reference points and promotes cooperation with international bodies. CNIAJ is mandated to suggest conventions and cooperative arrangements with national and international institutions. The Resolution's risk-based approach, emphasis on human oversight, accountability, and mandatory impact assessments align with global trends in AI governance, including the EU AI Act's risk-based architecture and OECD principles on trustworthy AI. The CNJ positions its framework to facilitate interoperability and cross-border cooperation while preserving national sovereignty and compliance with Brazilian constitutional guarantees.
Implementation Timeline
| Event | Date |
|---|---|
| Signature by CNJ President | 2025-03-11 |
| Publication in DJe/CNJ | 2025-03-14 |
| Entry into force (120 days after publication) | 2025-07-14 |
| 12-month adaptation deadline for existing systems | 2026-03-14 |
| Portaria designating CNIAJ membership (example) | 2025-08-27 |
Sources and References
| Source | Type |
|---|---|
| Resolução CNJ nº 615/2025 — CNJ atos page (official consolidated text) | Primary Source |
| Official PDF — Resolução CNJ nº 615/2025 | Primary Source |
| CNJ — Comitê Nacional de Inteligência Artificial do Judiciário (CNIAJ) page | Primary Source |
Requirements for a company
What an organisation has to do under Brazil - AI Governance in Judiciary (615/2025), at a glance. Not legal advice — the table below gives the provision and deadline for each item.
Must do
13- Adapt all existing AI systems to comply with this regulation.Tribunals using AI systems.
- Register all new AI R&D and deployment initiatives in the Sinapses platform.Tribunals developing or deploying new AI systems.
- Conduct a tribunal-level preliminary evaluation to classify risk and document mitigation measures.Tribunals before production use of an AI system.
- Perform ongoing algorithmic impact assessments for high-risk AI systems.Tribunals using high-risk AI systems.
- Undergo periodic external audits for high-risk AI systems.Tribunals using high-risk AI systems.
- Include specific clauses in AI procurement contracts regarding data reuse, security, and LGPD compliance.Tribunals procuring AI solutions.
- +7 more in the table below
Must not do
0Nothing in this category.
Should do
0Nothing in this category.
Should not do
0Nothing in this category.
Who must do what
The obligations under Brazil - AI Governance in Judiciary (615/2025), most serious first. Not legal advice — verify against the official text before relying on it.
| # | Who | Requirement | By when | Where | Severity |
|---|---|---|---|---|---|
| 1 | Tribunals using AI systems. | Adapt all existing AI systems to comply with this regulation. “Tribunals have a 12-month adaptation period from publication to bring existing systems into compliance.” | Mar 14, 2026 | — | Critical |
| 2 | Tribunals developing or deploying new AI systems. | Register all new AI R&D and deployment initiatives in the Sinapses platform. “All new R&D and deployment initiatives must be registered in Sinapses (PDPJ-Br module).” | Before placing on market | — | Critical |
| 3 | Tribunals before production use of an AI system. | Conduct a tribunal-level preliminary evaluation to classify risk and document mitigation measures. “Before production use, a tribunal-level preliminary evaluation must classify the system's risk and document mitigation measures.” | Before production use | — | Critical |
| 4 | Tribunals using high-risk AI systems. | Perform ongoing algorithmic impact assessments for high-risk AI systems. “High-risk systems must undergo periodic external audits and ongoing algorithmic impact assessments” | — | — | Critical |
| 5 | Tribunals using high-risk AI systems. | Undergo periodic external audits for high-risk AI systems. “High-risk systems must undergo periodic external audits and ongoing algorithmic impact assessments” | — | — | Critical |
| 6 | Tribunals procuring AI solutions. | Include specific clauses in AI procurement contracts regarding data reuse, security, and LGPD compliance. “Contracts procuring AI solutions must include clauses ensuring compliance with LGPD... and vendor obligations not to reuse judiciary-sourced inputs” | Before procurement | — | Critical |
| 7 | Tribunals using AI systems. | Implement technical and organizational security measures, including encryption, access controls, and versioning. “The Resolution prescribes versioning and dataset retention policies, encryption and access controls” | — | — | Critical |
| 8 | Tribunals using AI systems. | Report incidents related to AI systems to CNIAJ within 72 hours. “incident reporting (events to CNIAJ within 72 hours)” | Within 72 hours of incident | — | Critical |
| 9 | Tribunals developing or using AI systems. | Implement privacy-by-design/default, data anonymization, and ensure representativity of datasets. “privacy-by-design/default, and requirements for representativity of datasets used in training.” | — | — | Critical |
| 10 | Tribunals using AI systems. | Ensure human supervision and contestability for all AI systems. “human supervision and contestability” | — | — | Important |
| 11 | Tribunals using AI systems. | Publish audit reports and algorithmic impact assessments in accessible language on Sinapses. “Audit reports and impact assessments are to be published on Sinapses in accessible language” | — | — | Important |
| 12 | Tribunal schools. | Provide standardized digital literacy and ethics training programs for magistrates and staff. “Training programs—standardized digital literacy and ethics modules—must be provided by tribunal schools” | — | — | Important |
| 13 | Each tribunal. | Adopt internal rules for AI governance, appoint responsible persons, and ensure oversight of local projects. “each tribunal must adopt internal rules, appoint responsible persons, provide training and ensure oversight of local projects” | — | — | Important |
Related Regulations
Brazil - National AI Committee (270/2025)
Brazil94% similar
Argentina - AI Use Guidelines (206/2025)
Argentina91% similar
Brazil - AI Management Group (2/2025)
Brazil90% similar
Buenos Aires AI Guidelines for the Judiciary
Argentina90% similar
Argentina - San Juan - AI Judicial Protocol (2024)
Argentina90% similar
© Regulations.AI · updated on 13-Jun-2026