Brazil - National AI Regulation (2.338/2023)

Bill No. 2,338/2023 (Legal Framework for Artificial Intelligence — Draft national AI regulatory framework)

Projeto de Lei nº 2.338/2023 (Marco Legal da Inteligência Artificial — Draft national AI regulatory framework)

Brazil

RAI-BR-NA-PDLN2XX-2023
Under Review(Under Review)
BillGovernance and OversightRisk Management
Export PDF

PL 2.338/2023 is a comprehensive draft framework to regulate the development, deployment and use of artificial intelligence (AI) in Brazil. It sets rights for people affected by AI, creates a national governance architecture coordinated by a designated authority (with the ANPD playing a central role in consultations), defines risk‑based obligations for suppliers and operators, and establishes sanctions and liability rules.

Overview

Projeto de Lei nº 2.338/2023 is a proposed national framework intended to regulate the development, deployment and use of artificial intelligence systems across Brazil. The bill sets out principles (human centrality, non‑discrimination, transparency, robustness and security), substantive rights for persons affected by AI (information, explainability, contestability and human review) and a risk‑based regulatory architecture with differentiated obligations for systems classified as high or excessive risk. The text approved by the Senate and made available publicly consolidates earlier committee substitutive measures; the official consolidated text can be consulted in the Senate's published PDF (see PL 2338/2023 — consolidated text (Senate PDF)). The bill foresees a national governance structure (the System for AI Regulation and Governance — SIA) to coordinate rulemaking and supervision and contemplates the role of sectoral authorities, a committee of specialists and mechanisms such as sandboxes to balance oversight with innovation.

Definitions

PL 2338 provides specific statutory definitions that structure its obligations. Core definitions include "system of artificial intelligence" (computer systems designed to produce predictions, recommendations or decisions that can affect the virtual or real environment), "supplier" (natural or legal person that develops AI systems) and "operator" (user or deployer that employs AI for its own benefit). The draft also defines "authority competent" (to be designated by the Executive, with duties to implement and enforce the law), "risk classification" categories and terms such as "mining of texts and data" and "discrimination" (a broad definition aligned with constitutional non‑discrimination norms). These definitions anchor responsibilities and procedural guarantees throughout the bill.

Governance and Institutional Framework

The bill establishes a multi‑tier governance model named SIA (System for AI Regulation and Governance). The SIA is composed of the designated authority ("authority competent"), sectoral regulators, a permanent Council of Regulatory Cooperation (CRIA) and a Committee of Experts and Scientists on Artificial Intelligence (CECI A). While the Executive is tasked with designating the authority competent, public commentary and technical commentary from the Autoridade Nacional de Proteção de Dados (ANPD) have recommended that ANPD assume a central regulatory coordination role, particularly where AI intersects with personal data and LGPD obligations (see ANPD's Note Technical contributions at ANPD — second analysis of PL 2338/2023). The authority competent will adopt regulations, lead consultations, coordinate with sectoral authorities and oversee public registries, sandboxes and conformity assessment processes. The law anticipates public consultation and regulatory impact analysis in secondary rulemaking.

Key Focus Areas

PL 2338 concentrates obligations across several core domains: rights of affected individuals (information, explanation, contestability and human review); transparency (disclosure of automated interactions, explicit notices for biometric and emotion‑recognition systems, metadata requirements); governance (internal programs of governance, codes of conduct, traceability and logging); risk management (classification, algorithmic impact assessments and mitigation measures); conformity assessment and certification for high‑risk systems; incident reporting of serious incidents to the authority competent; market surveillance powers for enforcement; liability and redress rules including objective liability presumptions for high‑risk systems; and administrative sanctions ranging from warnings to significant fines and operational suspensions. Special attention is given to vulnerable populations, minors and to situations where AI produces effects with legal or significant factual impacts on rights and interests.

Implementation Framework

Implementation is intended to be carried out by the authority competent (designated by the Executive) in coordination with sectoral regulators. The bill delegates many technical and procedural specifications to regulation: the criteria for risk classification, the content and frequency of algorithmic impact assessments, audit and documentation formats, requirements for conformity assessment and the operational rules for sandboxes. The text allows voluntary codes of good conduct and contemplates accreditation and certification mechanisms; adherence to approved codes may be considered as evidence of good faith during enforcement proceedings. The Executive must publish a list of SIA members and the authority will publish annual reports on its activities. The law also foresees differentiated processes and communication channels for micro and small enterprises and startups to avoid disproportionate burdens.

Monitoring and Evaluation

Monitoring mechanisms combine mandatory reporting (serious incidents must be reported to the authority competent) with regulatory supervision, periodic audits, public registries and market surveillance authority powers. The authority may request technical information from public bodies operating AI and may coordinate joint inspections with sectoral agencies. The bill requires the authority to issue annual activity reports and to use public consultation and regulatory impact assessment before issuing norms. Sandboxes are explicit instruments to be monitored and may be conditioned to reporting obligations. Conformity assessment reports, impact assessments and audit trails are expected to form the evidentiary basis for supervision and corrective measures.

Penalties, Liability, and Appeals

PL 2338 sets an administrative sanctioning regime that includes warnings; fines up to R$50,000,000 per infraction (or up to 2% of the company's Brazilian turnover for private legal persons, subject to limits); publicization of infractions; suspension or prohibition from sandboxes; temporary or definitive suspension of development, supply or operation; and prohibition of treatment of certain data sets. Sanctions must observe due process, proportionality and the opportunity for defense. On civil liability, the draft provides objective liability for providers/operators of high‑risk or excessive‑risk systems and presumes the victim's position in many cases (including inversion of the burden of proof) to facilitate redress. The bill preserves judicial and administrative appeals and aligns consumer‑sector claims with the Consumer Protection Code.

Relationship to Other Instruments

The bill explicitly references alignment with the Lei Geral de Proteção de Dados (LGPD) and the Consumer Protection Code. It is designed to operate as a sector‑neutral national framework that coordinates with sectoral regulators (e.g., health, financial, communications and safety regulators) and avoids supplanting sectoral competence. The SIA's model contemplates coordination channels and a forum for sector regulators. The text also anticipates the need for additional executive regulations to operationalize definitions and assessment methodologies.

International Alignment

PL 2338 is explicitly influenced by comparative regulatory models, notably the EU AI Act; it reflects international practices on risk‑based classification, transparency duties and conformity assessment while adapting enforcement and liability rules to Brazil's legal environment. The bill contemplates cross‑border cooperation and international technical cooperation, and delegates to the authority competent the power to coordinate with foreign regulators and international bodies. ANPD contributions have compared the PL's architecture to EU experiences and recommended institutional arrangements that replicate the benefits of centralized coordination in other jurisdictions (see ANPD analysis at ANPD — PL analysis).

Implementation Timeline

EventDate
Project filed in Senate2023-05-03
Senate consolidated report and plenary approval (substitutive text)2024-12-10
Transmitted to Chamber of Deputies (received)2025-03-17
Referral to Special Committee, Chamber of Deputies2025-04-04 (committee established)

Compliance Checklist

RequirementWhoAction
Risk classificationSuppliers/OperatorsAssess and classify system risk level; document methodology
Algorithmic Impact AssessmentSuppliers/OperatorsConduct and retain assessments for high‑risk systems
Governance ProgramSuppliers/OperatorsImplement internal governance, audits, mitigation plans
Transparency NoticesSuppliers/OperatorsProvide prior information, icons and explanations to users
Incident ReportingSuppliers/OperatorsReport serious incidents to authority competent within regulatory timeframe
Conformity Assessment / CertificationSuppliers/OperatorsObtain required conformity/certification for high‑risk systems

Sources and References

SourceType
Projeto de Lei nº 2.338/2023 — Consolidated text (Senate PDF)Primary Source
Congress of Brazil — PL 2338/2023 record (transmission & tramitation)Primary Source
ANPD — Second analysis / Nota Técnica on PL 2338/2023Primary Source
Plain English

Brazil's proposed AI law, Bill 2.338/2023, aims to regulate how artificial intelligence is developed, deployed, and used across the country, applying to both those who create AI systems (suppliers) and those who use them for their own benefit (operators).

This comprehensive framework sets out principles like human centrality and non-discrimination. It places obligations on suppliers and operators based on the risk level of their AI systems, classifying them as high or excessive risk. Key duties include classifying AI systems by risk and implementing appropriate safeguards; ensuring transparency by providing information and explanations to users, especially for biometric or emotion-recognition systems; conducting algorithmic impact assessments and establishing internal governance programs for high-risk systems; and reporting serious incidents to the designated regulatory authority.

The bill also grants individuals rights, such as the right to information, explanation, and human review of AI decisions. While the specific regulatory authority is yet to be named by the Executive, the National Data Protection Authority (ANPD) is expected to play a significant coordinating role, particularly where AI interacts with personal data.

This legislation is currently under review in the Chamber of Deputies and does not have an effective date yet. Once enacted, non-compliance could lead to severe penalties, including fines up to R$50,000,000 per infraction or 2% of a company's Brazilian turnover, as well as operational suspensions. A crucial point for businesses is the provision for objective liability for high-risk AI systems, which can reverse the burden of proof, making it easier for affected individuals to claim harm. Many technical details are left to be defined by future regulations, meaning businesses will need to closely monitor subsequent rulemaking.

Plain-English rewrite by Regulations.ai — not legal advice. Verify against the official text.

What you must do — compliance checklist

0 / 15 marked complete

Plain-English obligations under Brazil - National AI Regulation (2.338/2023). Not legal advice — verify against the official text before relying on it.

  1. #1CriticalBefore placing on market

    Applies to: Suppliers and operators of AI systems.

    risk‑based regulatory architecture with differentiated obligations for systems classified as high or excessive risk.
  2. #2CriticalBefore placing on market

    Applies to: Suppliers and operators of high-risk AI systems.

    algorithmic impact assessments and mitigation measures
  3. #3CriticalBefore placing on market

    Applies to: Suppliers and operators of AI systems.

    algorithmic impact assessments and mitigation measures
  4. #4CriticalBefore placing on market

    Applies to: Suppliers and operators of high-risk AI systems.

    conformity assessment and certification for high‑risk systems
  5. #5CriticalWithin regulatory timeframe

    Applies to: Suppliers and operators of AI systems.

    incident reporting of serious incidents to the authority competent
  6. #6ImportantBefore deployment

    Applies to: Suppliers and operators of AI systems.

    governance (internal programs of governance, codes of conduct, traceability and logging)
  7. #7ImportantContinuously during operation

    Applies to: Suppliers and operators of AI systems.

    governance (internal programs of governance, codes of conduct, traceability and logging)
  8. #8ImportantUpon interaction

    Applies to: Suppliers and operators of AI systems.

    substantive rights for persons affected by AI (information, explainability, contestability and human review)
  9. #9ImportantUpon request

    Applies to: Suppliers and operators of AI systems.

    substantive rights for persons affected by AI (information, explainability, contestability and human review)
  10. #10ImportantUpon request

    Applies to: Suppliers and operators of AI systems.

    substantive rights for persons affected by AI (information, explainability, contestability and human review)
  11. #11ImportantUpon request

    Applies to: Suppliers and operators of AI systems.

    substantive rights for persons affected by AI (information, explainability, contestability and human review)
  12. #12ImportantBefore interaction

    Applies to: Suppliers and operators of AI systems.

    transparency (disclosure of automated interactions, explicit notices for biometric and emotion‑recognition systems)
  13. #13ImportantBefore use

    Applies to: Suppliers and operators of biometric/emotion-recognition AI systems.

    explicit notices for biometric and emotion‑recognition systems
  14. #14ImportantUpon request

    Applies to: Public bodies operating AI systems.

    The authority may request technical information from public bodies operating AI
  15. #15RecommendedContinuously

    Applies to: Suppliers and operators of AI systems.

    adherence to approved codes may be considered as evidence of good faith during enforcement proceedings.

© Regulations.AI — created on 13-Jun-2026