Brazil has the most advanced AI governance framework in Latin America. PL 2338, the Projeto de Lei approved by the Brazilian Senate and advancing through the legislative process, establishes a risk-based architecture that will create binding compliance obligations for any AI system producing effects on Brazilian territory. For European and global operators deploying AI agents that serve Brazilian users, the framework introduces obligations that run in parallel with those created by Regulation (EU) 2024/1689 and by Brazil's own Lei Geral de Proteção de Dados.
Key takeaways
- PL 2338 establishes two risk categories, not three: risco excessivo in Article 13, which prohibits, and alto risco in Article 14, which imposes obligations. General purpose and generative AI is handled in a separate cross-cutting chapter rather than as a light third tier.
- The Senate-approved text contains no territorial scope provision. An earlier version of this guide asserted extraterritorial reach on the EU model; there is no such clause in the bill.
- The ANPD (Autoridade Nacional de Proteção de Dados) has a central oversight role, building on its existing LGPD enforcement authority. This creates a single regulatory point of contact for AI and data protection compliance in Brazil.
- High-risk obligations require algorithmic impact assessments, transparency registers, human oversight mechanisms, and technical documentation. These mirror EU AI Act deployer obligations closely enough that EU compliance documentation is largely transferable.
- EU operators with Brazilian market exposure face dual-regime compliance: LGPD plus PL 2338 on the Brazilian side, GDPR plus EU AI Act on the European side. The frameworks are compatible, but gaps exist on automated decision-making rights and sectoral exemptions.
Legislative background
PL 2338 of 2023 was introduced to the Brazilian Senate by Senator Rodrigo Pacheco, with Senator Eduardo Gomes as rapporteur, following a commission of jurists process. That commission, CJSUBIA, was chaired by Minister Ricardo Villas Boas Cueva of the Superior Tribunal de Justica, with Laura Schertel Mendes as rapporteur, and produced a draft framework after extensive public consultation. An earlier version of this guide named Eduardo Gomes as the author and Cezar Peluso as the commission chair; both were wrong. The process was modelled partly on Brazil's experience drafting the LGPD and was informed by the European Commission's work on the EU AI Act.
The Senate plenary approved the bill on 10 December 2024 after committee amendments that adjusted the risk classification criteria and strengthened the provisions on algorithmic impact assessments, and the bill was remitted to the Camara dos Deputados on 17 March 2025. Those three dates, and Senator Pacheco's authorship on 3 May 2023, were verified at senado.leg.br on 17 August 2026. Further amendments are expected in the Chamber before the bill returns to the Senate for a final vote. The bill is not yet enacted into law, but it represents the most advanced AI framework in the region and Brazilian regulators, including the ANPD, are already developing implementation guidance on the assumption of enactment.
The legislative record reflects a deliberate effort to position Brazil as a standard-setter for AI governance in Latin America and the Global South more broadly. Brazil's G20 presidency in 2024 included AI governance on the agenda, and the digital economy ministerial declaration was issued in Maceio on 13 September 2024. An earlier version of this guide cited a "Brasilia Ministerial Declaration on AI" endorsing PL 2338 as a model. No such declaration could be found and the citation has been removed. Argentina, Colombia, and Mexico are each developing AI governance frameworks, and PL 2338 will influence all three.
Risk architecture
PL 2338 classifies AI systems into three risk categories. Understanding the classification criteria is the first step for any operator mapping their AI deployments against the Brazilian framework.
Excessive risk (risco excessivo) covers applications that are prohibited outright. The prohibited categories include: AI systems used by public authorities for social scoring of natural persons based on personal behaviour or characteristics; AI systems that use subliminal techniques to manipulate individuals without their awareness in ways likely to cause harm; AI that exploits vulnerabilities of specific groups, including children and the elderly, to produce distorted behaviour; and real-time remote biometric surveillance in publicly accessible spaces by law enforcement, except under judicial authorisation and narrow exceptions. The prohibited categories align closely with the prohibitions in Article 5 of Regulation (EU) 2024/1689, with some adaptations reflecting Brazilian constitutional law's specific protections.
High risk (alto risco) is set out in Article 14 of the Senate-approved text, which lists twelve categories: critical infrastructure; selection for education; recruitment and employment; essential public and private services; emergency call triage; administration of justice; autonomous vehicles; health diagnosis; crime analytics; profiling for evidence credibility; biometric emotion recognition; and immigration and border control. An earlier version of this guide gave eight domains, included a democratic processes and electoral category that is not in the text, and named credit, insurance and housing, which are not named either. In each domain, deployers face a set of obligations that include algorithmic impact assessments, transparency registrations, human oversight mechanisms, incident notification, and technical documentation retention. The obligations are structured similarly to Article 26 of the EU AI Act, with the ANPD as the primary oversight authority.
The text has two risk categories, not three: risco excessivo in Article 13 and alto risco in Article 14. General purpose and generative AI is treated in a separate cross-cutting chapter rather than as a light third tier, and the Chapter II rights apply to all systems regardless of risk grade under Article 5. An earlier version of this guide described a three-tier structure with general use AI as the lightest tier.
The ANPD as primary regulator
The decision to vest primary AI oversight authority in the ANPD is significant for operators already navigating LGPD compliance. The ANPD, established under LGPD in 2020, has developed substantial technical capacity for data protection enforcement. PL 2338 expands its mandate to cover AI-specific obligations, creating a consolidated compliance relationship for operators working with Brazilian personal data and AI systems.
The ANPD has authority under PL 2338 to issue implementing regulations, conduct investigations, impose administrative penalties, and develop sector-specific guidance in coordination with other sectoral regulators. Sectoral regulators retain oversight authority for AI applications within their jurisdictions: the Central Bank of Brazil (Banco Central do Brasil) oversees AI in financial services, the National Supplementary Health Agency (ANS) oversees health AI, and ANATEL oversees AI in telecommunications. This mirrors the EU's model where the AI Office coexists with sector regulators, though the Brazilian version gives sectoral regulators somewhat more autonomous authority than the EU model does.
The ANPD has run a Tomada de Subsidios on AI and the review of automated decisions, and carries the item on its regulatory agenda. An earlier version of this guide said it had already published preliminary guidance under LGPD Article 20; no such published guidance could be located and the claim has been withdrawn. The statutory right itself is real and independent of any ANPD guidance: LGPD Article 20 gives data subjects the right to request a review of decisions taken solely by automated means that affect their interests. PL 2338 would build on that foundation, extending an explanation right to a broader category of consequential AI decisions and requiring operators to provide accessible mechanisms for exercising it.
Algorithmic Impact Assessment (Avaliação de Impacto Algorítmico)
The Avaliação de Impacto Algorítmico (AIA) is the central documentary obligation for high-risk AI deployers under PL 2338. It functions similarly to the Fundamental Rights Impact Assessment required under Article 27 of the EU AI Act, but with a wider scope that also encompasses economic impacts and competition effects alongside fundamental rights considerations.
The AIA must be conducted before deployment and updated whenever there is a material change to the system, the use case, or the population affected. It must address: the system's purpose and technical characteristics; the population that will be affected and the nature of that effect; the risk of discriminatory outcomes based on race, gender, age, disability, religion, or other protected characteristics under Brazil's Constitution; the measures taken to mitigate identified risks; the human oversight mechanism; and the procedure for affected individuals to contest decisions made by the system.
Articles 25 and 26 require the assessment before market introduction and its sharing with the sector authority, not with the ANPD, and the text gives no power of ex ante approval or rejection to anyone. Suspension exists only as an administrative sanction under Article 50(V), after due process. Article 25(1) defines the methodology as risks and benefits to fundamental rights and the mitigation measures and their effectiveness. An earlier version of this guide described an ANPD veto and an economic and competition dimension; neither is in the text.
Extraterritorial reach and implications for global operators
The Senate-approved text has no territorial scope clause. Article 1 sets general rules of a national character for AI in Brazil, and there is no provision on effects abroad, foreign establishment or extraterritorial application anywhere in the 39 page text. An earlier version of this guide described a market-effects principle and worked two examples from it. Both have been removed. A foreign operator serving Brazilian users should plan against the LGPD, which does have extraterritorial reach, and should watch the Chamber stage in case a scope provision is added.
If a scope provision is added at the Chamber stage, a dual-compliance question will follow for European operators, who would need to comply with Regulation (EU) 2024/1689 for EU-facing operations and with PL 2338 for Brazil-facing ones. The frameworks are broadly compatible. The risk classification criteria are similar. The high-risk category maps closely between the two. The impact assessment obligations are structurally equivalent. The transparency and documentation requirements are largely parallel.
The primary gap areas are: the specific content of the AIA versus the FRIA, where Article 25(1) defines the methodology as risks and benefits to fundamental rights and the effectiveness of mitigation measures rather than the wider economic assessment an earlier version of this guide described; the individual rights framework, where PL 2338 builds on LGPD's automated decision rights and creates some procedural requirements that differ from the EU AI Act's person-notification obligations; and the enforcement mechanism, where the ANPD's powers and penalty schedule will differ from those of EU member state market surveillance authorities.
For the EU regulatory context, see the EU AI Act Article 26 deployer obligations guide. For the broader cross-jurisdictional picture, see the EU AI Act's extraterritorial reach and US, EU, UK: three approaches to AI liability.
Latin American context
Brazil is the most advanced jurisdiction in Latin America for AI governance. Argentina has issued Disposicion 2/2023 of the Subsecretaria de Tecnologias de la Informacion, published 2 June 2023, which establishes voluntary principles for public sector AI use. An earlier version of this guide gave the instrument type, number and issuing body incorrectly and provides a framework that private operators are expected to reference. Colombia published a national AI ethics framework in 2021 and is developing binding AI regulation through the Ministry of ICT and the Superintendence of Industry and Commerce. Mexico's AI work sits in the Senate's Comision de Inteligencia Artificial, with the ATDT, SECIHTI and SEP. No binding AI legislation has been enacted. An earlier version of this guide attributed the work to COFECE, the competition authority, which has no role in it.
The Brazilian framework will have regional influence. The ANPD has established working relationships with data protection and AI regulatory bodies across the region. Operators building Latin American AI governance programmes should build to the Brazilian standard as the effective regional ceiling and document how their governance maps onto the lighter requirements in Argentina, Colombia, and Mexico.
Practical preparation steps
For global operators with Brazilian market exposure, four preparation steps are advisable before PL 2338 is enacted and its implementing regulations published.
First, conduct a scope mapping. Identify all AI systems that serve Brazilian users, make decisions about Brazilian residents, or produce effects in Brazilian territory. Classify each against PL 2338's two risk categories, risco excessivo and alto risco. The EU AI Act classification performed for the same system is a useful starting point, and the differences in the Brazilian classification criteria are manageable.
Second, review LGPD compliance for the automated decision-making dimension. LGPD Article 20 is already enforceable, and the ANPD is actively monitoring compliance. Operators whose automated decision-making review procedures are incomplete should address this before PL 2338 adds the AI-specific layer on top of it.
Third, prepare the AIA template. Draft the structure of an AIA using the bill's requirements and the ANPD's preliminary guidance on algorithmic impact. Applying the template to the most significant high-risk deployments before the law is enacted identifies the documentation gaps while there is time to address them.
Fourth, establish ANPD monitoring. The ANPD's implementing regulations, expected within twelve months of enactment, will define the specific procedural requirements for AIA submission, registration, incident notification, and individual rights procedures. Operators who have followed the development process will be positioned to adapt quickly.
Frequently asked questions
What are the risk categories in Brazil's PL 2338?
Two, not three. Risco excessivo in Article 13 prohibits certain uses outright. Alto risco in Article 14 lists twelve categories subject to impact assessment, human oversight and documentation duties. General purpose and generative AI sits in a separate cross-cutting chapter, and the Chapter II rights apply to all systems regardless of risk grade. An earlier version of this guide described a three-tier structure with a light general use tier; that is not in the Senate-approved text.
Does Brazil's AI framework apply to companies based outside Brazil?
The Senate-approved text contains no territorial scope or extraterritoriality provision at all. An earlier version of this guide answered yes and described a market-effects principle; there is no such clause in the bill. A foreign operator serving Brazilian users should plan against the LGPD, which does have extraterritorial reach, and should watch the Chamber of Deputies stage in case a scope provision is added.
How does PL 2338 interact with Brazil's LGPD data protection law?
LGPD already governs personal data processing in Brazil. PL 2338 builds on LGPD and assigns the ANPD a central AI oversight role. Operators compliant with LGPD have a foundation for PL 2338 compliance, but the AI framework adds obligations specific to automated decision-making that go beyond LGPD Article 20.
What is the relationship between PL 2338 and the EU AI Act for compliance planning?
The two frameworks are broadly compatible. An operator that has built EU AI Act compliance for high-risk deployments will find that most documentation and governance work transfers to PL 2338 compliance with adaptation rather than reconstruction. The main differences are that the Brazilian impact assessment goes to the sector authority rather than to the ANPD, and that the bill contains no territorial scope clause, so EU-style extraterritorial planning does not transfer.
References
- Projeto de Lei PL 2338/2023, Marco Legal da Inteligencia Artificial. Introduced by Senator Rodrigo Pacheco on 3 May 2023; approved by the Senate plenary on 10 December 2024; remitted to the Camara dos Deputados on 17 March 2025. Verified at senado.leg.br, 17 August 2026.
- Lei Geral de Proteção de Dados (LGPD), Federal Law No. 13709 of 14 August 2018.
- Autoridade Nacional de Proteção de Dados (ANPD). Tomada de Subsidios on artificial intelligence and the review of automated decisions. This guide previously cited a published ANPD preliminary guidance under LGPD Article 20; no such document could be located and the citation is withdrawn.
- G20 Brazil digital economy ministerial declaration, Maceio, 13 September 2024. This guide previously cited a "G20 Brasilia Ministerial Declaration on AI Governance, November 2024"; that document could not be found and the citation is withdrawn.
- Código de Defesa do Consumidor, Federal Law No. 8078/1990.
- Regulation (EU) 2024/1689 (EU AI Act), Articles 5, 26, 27. OJ L, 12 July 2024.
- Argentina. Disposicion 2/2023 of the Subsecretaria de Tecnologias de la Informacion, published 2 June 2023, establishing voluntary principles for public sector AI use. This guide previously cited a Resolucion 4/2023 of the Secretaria de Innovacion Publica; that citation was wrong and has been replaced.
- OECD AI Principles, adopted May 2019, revised 3 May 2024. OECD/LEGAL/0449.
- ISO/IEC 42001:2023, Artificial intelligence management system.