Brazil - AI Regulation Overview (PL 2338/2023)
Brazil AI Regulation Overview
Visão Geral da Regulamentação de IA no Brasil
Brazil
RAI-BR-NA-SUMMARY-2026Brazil is progressively establishing a robust federal framework for artificial intelligence regulation, balancing innovation with the protection of fundamental rights and democratic values. This landscape includes strategic policies, interministerial governance, and sector-specific binding rules for the judiciary, alongside a significant legislative bill proposing a horizontal, risk-based approach aligned with international standards.
Overview
Brazil is actively constructing a comprehensive federal framework for artificial intelligence regulation, reflecting a commitment to fostering innovation while rigorously safeguarding fundamental rights and democratic principles. This evolving regulatory landscape is characterized by a multi-pronged approach that combines strategic national policies, administrative decrees establishing interministerial coordination bodies, and sector-specific binding regulations. The nation's philosophy centers on a human-centric approach to AI, ensuring that technological advancements serve societal well-being and adhere to ethical guidelines. The maturity level of Brazil's AI regulatory environment is rapidly advancing, moving from initial policy declarations to concrete legislative proposals and operational governance structures.
A cornerstone of Brazil's approach is the Estratégia Brasileira de Inteligência Artificial (EBIA), a non-binding but influential strategic document that outlines principles, priorities, and actions for ethical AI development and deployment across various sectors. Complementing this policy guidance are administrative instruments like the Decreto nº 12.308/2024, which instituted the Comitê Interministerial para a Transformação Digital (CITDigital) to coordinate digital transformation policies, including AI initiatives. Furthermore, the judiciary has taken proactive steps with Resolução CNJ nº 615/2025, a binding regulation that establishes a comprehensive framework for AI use within the Brazilian Judiciary, emphasizing risk management, transparency, and human oversight. The most significant development is Projeto de Lei nº 2.338/2023, a comprehensive legislative proposal currently under review, aiming to establish a horizontal, risk-based regulatory framework for AI across the country, drawing inspiration from international best practices.
Regulatory Approach
Brazil's regulatory approach to AI is characterized by a hybrid model, incorporating both horizontal and sectoral regulations, as well as a blend of binding legal instruments and soft law policy guidelines. The overarching direction is towards a risk-based framework, particularly evident in the proposed Projeto de Lei nº 2.338/2023, which categorizes AI systems into excessive, high, and non-high risks, imposing corresponding obligations to balance innovation with the protection of fundamental rights and democratic principles. This horizontal approach aims to provide a consistent legal environment for AI across all sectors, preventing fragmented regulation and ensuring a baseline of ethical and safety standards. The bill's inspiration from the EU AI Act and OECD recommendations underscores an international alignment in its design, focusing on conformity assessment, documentation, and mandatory impact assessments for high-risk systems.
Alongside this horizontal legislative effort, Brazil employs a sectoral approach for specific domains, exemplified by the comprehensive Resolução CNJ nº 615/2025 for the Judiciary. This binding regulation sets detailed guidelines for the development, use, and governance of AI solutions within the judicial system, including risk classification, mandatory impact assessments, and explicit prohibitions on certain AI uses. The Estratégia Brasileira de Inteligência Artificial (EBIA) serves as a key soft law instrument, providing a strategic vision and guiding principles for AI development and adoption across public and private sectors without imposing direct legal obligations or sanctions. This combination of binding regulations for high-impact sectors and a broader, principles-based national strategy allows for both targeted oversight and flexible policy development, adapting to the rapid evolution of AI technologies while maintaining a focus on human rights and ethical considerations.
Key AI Legislation
- Resolução CNJ nº 615/2025 (CNJ Resolution establishing guidelines for development, use and governance of AI solutions in the Judiciary): Establishes a comprehensive regulatory framework for the responsible development, procurement, deployment, and governance of AI solutions across the Brazilian Judiciary. It includes a risk-based classification, mandatory impact assessments, and explicit prohibitions on certain uses, replacing Resolução CNJ nº 332/2020.
- Portaria CNJ nº 270/2025 (Portaria designating the members of the National Committee on Artificial Intelligence of the Judiciary - Comitê Nacional de Inteligência Artificial do Judiciário): Formally designates the membership and operating arrangements of the National Committee on Artificial Intelligence of the Judiciary (CNIAJ), operationalizing the mandate conferred by Resolução CNJ nº 615/2025.
- Decreto nº 12.308/2024 (Decree instituting the Interministerial Committee for Digital Transformation / Comitê Interministerial para a Transformação Digital): Establishes the Comitê Interministerial para a Transformação Digital (CITDigital) to advise the Presidency and orient federal action on digital transformation, including strategic planning and AI integration.
- Resolução CITDIGITAL nº 1/2025 (Regimento Interno do Comitê Executivo do Comitê Interministerial para a Transformação Digital): Formalizes the Internal Rules governing the Executive Committee of CITDigital, detailing its composition, duties, meeting procedures, and mechanisms for reporting and accountability.
- Resolução CITDIGITAL nº 2/2025 (Resolution establishing the Group of Work to manage the Brazilian Plan for Artificial Intelligence - PBIA): Creates a dedicated Group of Work (GT) under the CITDigital Executive Committee to operationalize the management and oversight of the Plano Brasileiro de Inteligência Artificial (PBIA).
- Portaria nº 8/2025 (Portaria establishing the composition of the Group of Work to manage the PBIA): Formalizes the composition of the GT-PBIA, listing representatives from federal ministries and national institutions, and assigning the MCTI the coordination role.
- Estratégia Brasileira de Inteligência Artificial (Brazilian Strategy for Artificial Intelligence): A non-binding, government strategic document articulating principles, priorities, and actions to foster research, innovation, economic development, and ethical use of AI.
- Portaria MCTI nº 4.979, de 13 de julho de 2021 (Ordinance amending the EBIA annexes): Modifies the Annex to Portaria MCTI nº 4.617, updating the official reference document that states the EBIA's goals, thematic axes, and strategic actions.
- Projeto de Lei nº 2.338/2023 (Marco Legal da Inteligência Artificial — Draft national AI regulatory framework): A wide-ranging legislative proposal seeking to establish general national rules for the development, implementation, and use of artificial intelligence systems in Brazil, currently under review in the Chamber of Deputies.
Governance & Enforcement Bodies
Brazil's AI governance landscape is characterized by a distributed yet coordinated structure, involving several key federal bodies. The Conselho Nacional de Justiça (CNJ) plays a crucial role within the judiciary, having established the Comitê Nacional de Inteligência Artificial do Judiciário (CNIAJ) through Portaria CNJ nº 270/2025. The CNIAJ is an interdisciplinary oversight body tasked with supporting the CNJ in implementing, complying with, and supervising Resolução CNJ nº 615/2025, which sets substantive rules for AI governance in the Judiciary. Its mandate includes risk reclassification, establishing audit standards, recommending adoption or suspension of systems, consolidating governance norms for the national Sinapses platform, advising on data protection, and proposing cooperation agreements. This committee ensures centralized oversight of AI procurement and in-house development within courts, standardized audit and impact-assessment protocols, and integration with the LGPD.
At a broader federal executive level, the Comitê Interministerial para a Transformação Digital (CITDigital), instituted by Decreto nº 12.308/2024, serves as a high-level advisory body to the Presidency on digital transformation issues, including AI. Under CITDigital, the Group of Work for the management and operationalization of the Plano Brasileiro de Inteligência Artificial (GT-PBIA) was established by Resolução CITDIGITAL nº 2/2025 and its composition formalized by Portaria nº 8/2025. Coordinated by the Ministry of Science, Technology and Innovation (MCTI), the GT-PBIA is responsible for monitoring PBIA execution, proposing adjustments, preparing annual operational plans, and supporting inter-agency alignment across key AI development axes. The MCTI also leads the Estratégia Brasileira de Inteligência Artificial (EBIA), a strategic policy document that guides national AI development. The Autoridade Nacional de Proteção de Dados (ANPD), Brazil's data protection authority, is a crucial interlocutor, particularly as the proposed AI regulatory framework (PL 2338/2023) emphasizes strong alignment with the Lei Geral de Proteção de Dados (LGPD). While not explicitly designated as the sole AI regulator, its mandate for data protection naturally extends to AI systems processing personal data, making it a de facto central authority in practice for privacy-related AI governance.
Penalties & Enforcement
The enforcement mechanisms and potential penalties for AI non-compliance in Brazil are currently evolving, with the most comprehensive provisions outlined in the pending Projeto de Lei nº 2.338/2023. This draft legislation proposes a range of administrative sanctions, which may include warnings, fines, publicization of infractions, suspension of operation, or even prohibition from participating in regulatory sandboxes. Notably, the bill specifies significant financial penalties, with fines potentially reaching up to R$50,000,000 or 2% of a company's Brazilian turnover, whichever is greater. Furthermore, the proposal introduces civil liability rules that include objective liability for high-risk or excessive-risk AI systems, with presumptions that favor victims, aligning with principles found in the Consumer Protection Code where applicable. This aims to ensure robust redress mechanisms for individuals harmed by AI systems.
In the judicial sector, Resolução CNJ nº 615/2025 outlines its own enforcement framework, primarily through continuous monitoring, periodic audits, and incident reporting. Non-compliance with the resolution's guidelines can trigger audit findings, referrals to competent authorities, and the application of administrative or contractual remedies. The newly established Comitê Nacional de Inteligência Artificial do Judiciário (CNIAJ) is empowered to recommend the adoption or suspension of particular AI systems and to require tribunals to submit systems for reclassification or audit. While specific criminal penalties for AI misuse are not extensively detailed in the current federal AI regulations, existing laws, such as those related to data protection (LGPD) and consumer rights, would apply to AI-related offenses. The enforcement of these regulations will be carried out by the designated "authority competent" (once established by the Executive Branch under PL 2338/2023) in coordination with sectoral regulators and the ANPD, ensuring a multi-layered approach to compliance and accountability.
Data Protection Framework
Brazil's data protection framework is anchored by the Lei Geral de Proteção de Dados (LGPD, Law No. 13.709/2018), which serves as the country's comprehensive privacy law, akin to Europe's GDPR. The LGPD establishes principles, rights for data subjects, and obligations for data controllers and processors regarding the collection, use, processing, and storage of personal data. This foundational law is explicitly referenced and integrated into emerging AI regulations, ensuring that AI systems operating in Brazil adhere to strict privacy and data security standards. The Autoridade Nacional de Proteção de Dados (ANPD) is the primary enforcement body for the LGPD, overseeing compliance and imposing sanctions for violations. The ANPD's role is expected to be central in the enforcement of AI regulations, particularly where AI systems process personal data.
The integration of data protection principles into AI governance is prominently featured in sector-specific regulations, such as Resolução CNJ nº 615/2025 for the Judiciary. This resolution mandates privacy-by-design and privacy-by-default principles for all AI solutions, requiring secure data curation, storage, and versioning. It also imposes strict conditions on the use of third-party cloud services or commercial large language models (LLMs) for judicial work, specifically prohibiting the processing of secret or justice-protected data unless properly anonymized at the origin. Furthermore, contractual clauses for AI vendors are required to ensure that judiciary data is not used for model training without a legal basis. The proposed national AI regulatory framework (PL 2338/2023) also reinforces these data protection requirements, aligning its provisions with the LGPD to ensure the lawful and ethical handling of personal data used in AI systems, and emphasizing special protections for vulnerable groups.
Sector-Specific Rules
While Brazil is progressing towards a horizontal AI regulatory framework, significant sector-specific rules are already in force, particularly within the judicial and public administration domains. The Brazilian Judiciary, under the guidance of the Conselho Nacional de Justiça (CNJ), has implemented a robust set of regulations for AI use. Resolução CNJ nº 615/2025 establishes comprehensive guidelines for the development, procurement, deployment, and governance of AI solutions across the Judiciary. This includes a detailed risk-based classification system for AI applications in judicial contexts, identifying high-risk use-cases such as the evaluation of evidence, formulation of legal conclusions, biometric identification, and profiling. The resolution mandates preliminary evaluations, ongoing algorithmic impact assessments, and explicit prohibitions on uses that preclude human oversight or cause abusive discrimination.
Further strengthening judicial AI governance, Portaria CNJ nº 270/2025 formally designates the members of the Comitê Nacional de Inteligência Artificial do Judiciário (CNIAJ), an oversight body responsible for coordinating risk classification, audits, monitoring, and technical guidance for AI systems within the Judiciary. In the broader public administration, the Decreto nº 12.308/2024 instituted the Comitê Interministerial para a Transformação Digital (CITDigital) to advise the Presidency on digital transformation, which includes the strategic integration of AI into public services. The Plano Brasileiro de Inteligência Artificial (PBIA), managed by a dedicated Group of Work (GT-PBIA) under CITDigital, focuses on operationalizing AI actions across infrastructure, human capital, public service modernization, and regulatory aspects. These federal initiatives aim to ensure that AI adoption in public services is coordinated, efficient, and adheres to principles of transparency and accountability, laying the groundwork for future sector-specific guidelines in areas like healthcare or finance as the national AI strategy matures.
International Alignment
Brazil's approach to AI regulation demonstrates a strong commitment to international alignment, drawing significant inspiration from leading global frameworks and principles. The Estratégia Brasileira de Inteligência Artificial (EBIA), a foundational policy document, explicitly aligns with international recommendations, including the OECD AI Principles. These principles, such as inclusive growth and well-being, human-centered values and equity, transparency and explainability, robustness, security and safety, and accountability, form the ethical bedrock of Brazil's national AI strategy. This alignment facilitates international cooperation, promotes the exchange of best practices, and positions Brazil as a responsible actor in global AI governance discussions. The EBIA also emphasizes the importance of data governance, privacy protection in the context of Brazil's LGPD, cybersecurity, and impact assessment, mirroring global concerns.
The influence of international frameworks is particularly evident in the Projeto de Lei nº 2.338/2023, the draft national AI regulatory framework currently under review. This bill adopts a risk-based approach largely inspired by the European Union's AI Act and further informed by OECD recommendations. By categorizing AI systems into different risk levels and imposing corresponding obligations, the bill seeks to create a predictable and secure legal environment that balances innovation with the protection of fundamental rights, similar to the EU's comprehensive regulatory model. The ongoing debate in Brazil regarding regulatory competence, scope of prohibitions, and obligations for large models also reflects discussions happening at the international level. This proactive engagement with international standards and comparative law demonstrates Brazil's intent to develop a robust and globally compatible AI regulatory ecosystem.
Future Developments
The future of AI regulation in Brazil is poised for significant developments, primarily centered around the progression of Projeto de Lei nº 2.338/2023, which is currently under review in the Chamber of Deputies. This comprehensive bill, if enacted, will establish a foundational national AI regulatory framework, introducing a risk-based approach, rights for affected individuals, and an institutional governance model. The ongoing legislative process involves detailed analysis by a special committee, and further amendments or refinements are possible before its final approval. Stakeholders will need to closely monitor its progress, as its eventual passage will trigger the need for secondary regulations, technical guidance, and operational rules to be adopted by the designated competent authority. The debate around the allocation of regulatory competence, particularly the role of the ANPD, and specific criteria for risk classification, impact assessments, and audit methodologies, will continue to shape these future implementing acts.
Beyond the legislative front, ongoing work by established governance bodies will continue to shape Brazil's AI landscape. The Comitê Nacional de Inteligência Artificial do Judiciário (CNIAJ), operationalized by Portaria CNJ nº 270/2025, is charged with developing technical guidance on risk classification, governance standards, transparency reporting, audit protocols, and capacity-building for judicial personnel. Similarly, the Group of Work for the management and operationalization of the Plano Brasileiro de Inteligência Artificial (GT-PBIA), established under CITDigital, will continue to coordinate and monitor the implementation of national AI policy actions, influencing future funding decisions and cross-sectoral initiatives. The Estratégia Brasileira de Inteligência Artificial (EBIA) is conceived as a living policy, subject to periodic review and updates by the MCTI as technology and societal impacts evolve. These ongoing administrative and policy-level activities, coupled with the pending national AI bill, indicate a dynamic and continuously evolving regulatory environment in Brazil, requiring sustained attention from all AI stakeholders.
Key Regulations
Enforcement Bodies
| Agency | Mandate | Key Powers | Website |
|---|---|---|---|
| Conselho Nacional de Justiça (CNJ) | To improve the Brazilian judicial system, regarding administrative and procedural control and transparency, including AI governance in the Judiciary. | Issuing normative acts and recommendations; defining strategic planning and evaluation programs; judging disciplinary proceedings; overseeing the CNIAJ and its audit functions. | https://www.cnj.jus.br/ |
| Casa Civil da Presidência da República (for CITDigital) | To assist the President of the Republic in the performance of duties, especially in the management of federal public administration bodies and the coordination, integration, monitoring, and evaluation of government actions related to digital transformation. | Coordinating the CITDigital and its Executive Committee; providing secretariat support; proposing government actions and priorities for digital transformation. | https://www.gov.br/casacivil/pt-br |
| Ministério da Ciência, Tecnologia e Inovação (MCTI) | To formulate and implement national policies for science, technology, and innovation, including the coordination of the Brazilian Artificial Intelligence Strategy (EBIA) and the GT-PBIA. | Coordinating the GT-PBIA; monitoring EBIA implementation; promoting research, development, and innovation in AI; proposing adjustments to national AI plans. | https://www.gov.br/mcti/pt-br |
| Autoridade Nacional de Proteção de Dados (ANPD) | To ensure the protection of personal data and privacy, and to oversee the fulfillment of the Lei Geral de Proteção de Dados Pessoais (LGPD). | Fiscalizing LGPD compliance; issuing guidelines and regulations related to data protection; imposing administrative sanctions for LGPD violations; contributing to AI regulatory discussions. | https://www.gov.br/anpd/pt-br |
Real enforcement actions
6 actions recordedPublic enforcement actions where regulators cited Brazil - AI Regulation Overview (PL 2338/2023). Helps you see how the law is actually applied in practice.
- Feb 18, 2025
Autoridade Nacional de Protecao de Dados (ANPD) vs 23 football clubs (stadium facial recognition)
ANPD opened inspections and issued a preventive measure against 23 football clubs over facial-recognition/biometric systems for ticketing and stadium entry, requiring transparency and impact reports on minors' biometric data within 20 business days under the LGPD.
Source ↗ - Enforcement orderFeb 11, 2025
Autoridade Nacional de Proteção de Dados (ANPD) vs Tools for Humanity (Worldcoin)
Sector: Cryptocurrency / Biometric Data
The ANPD's Board of Directors rejected Tools for Humanity's administrative appeal and maintained the suspension of financial compensation for iris collection, with a daily fine of R$ 50,000 for non-compliance. Tools for Humanity subsequently announced a temporary suspension of iris verification services in Brazil.
Source ↗ - Enforcement orderFeb 5, 2025
Autoridade Nacional de Protecao de Dados (ANPD) vs RaiaDrogasil and Febrafar (pharmacy chains)
ANPD concluded its inspection of pharmacy chains, applying preventive measures and opening a sanctioning process against RaiaDrogasil over biometric authentication in its loyalty program, ordering a non-biometric identity-verification alternative under the LGPD.
Source ↗ - Enforcement orderJan 24, 2025
Autoridade Nacional de Proteção de Dados (ANPD) vs Tools for Humanity (Worldcoin)
Sector: Cryptocurrency / Biometric Data
The ANPD issued a preventive measure to suspend the offer of cryptocurrency or any other financial compensation by Tools for Humanity for the collection of iris biometric data in Brazil, citing concerns about free consent.
Source ↗ - OtherNov 4, 2024
Autoridade Nacional de Proteção de Dados (ANPD) vs TikTok (ByteDance Brasil Tecnologia Ltda. and TikTok Pte. Ltd.)
Sector: Social Media / Technology
The ANPD initiated a sanctioning administrative process and issued compliance orders to TikTok for alleged irregular handling of personal data of children and adolescents, citing inadequate age verification mechanisms and lack of transparency in its privacy policy. The orders included deactivating the 'feed without registration' feature and presenting a compliance plan.
Source ↗ - Enforcement orderJul 2, 2024
Autoridade Nacional de Proteção de Dados (ANPD) vs Meta
Sector: Social Media / Technology
The ANPD issued a preventive measure suspending Meta's new privacy policy in Brazil, which allowed the use of personal data from its platforms for training generative AI systems, citing risks of serious and difficult-to-repair damage to users. A daily fine of R$ 50,000 was established for non-compliance.
Source ↗
Related Regulations
Projeto de Lei nº 2338, de 2023 - Dispõe sobre o uso da Inteligência Artificial
Brazil93% similar
Argentina AI Regulation Overview
Argentina93% similar
Portugal AI Regulation Overview
Portugal92% similar
Central and South America - AI Regulation Overview
Central and South America92% similar
Projeto de Lei nº 2.338/2023 (Marco Legal da Inteligência Artificial — Draft national AI regulatory framework)
Brazil92% similar
© Regulations.AI — created on 10-Apr-2026 using Gemini 2.5 Flash