Skip to content

Brazil passes comprehensive AI Bill with strict risk tiers and copyrights

by Lucas Almeida 3 min read

The National Congress of Brazil completed the final vote on Bill No. 2338/2023 on Tuesday, September 22, 2026, officially enacting the National Artificial Intelligence Legal Framework. The comprehensive legislation positions South America’s largest economy among pioneering nations implementing algorithmic governance that balances digital innovation with strict consumer safeguards, civil liberties protections, and intellectual property transparency standards.

Risk classification tiers and obligations for foundation model builders

Drawing architecture inspired by the European Union AI Act and OECD guidelines, Brazilian law establishes three operational risk tiers: excessive risk (banned entirely), high risk, and low risk. Prohibited systems include real-time public biometric surveillance without prior judicial warrants and automated public social scoring systems that penalize citizens arbitrarily.

High-risk deployments—spanning credit scoring engines, autonomous hiring platforms, clinical diagnostic aids, and predictive justice algorithms—must publish comprehensive algorithmic impact assessments, maintain immutable development logs, and guarantee qualified human oversight prior to executing decisions that affect civil rights.

Developers must demonstrate that automated systems undergo systematic bias testing against racial, socioeconomic, and gender disparities before deploying models into production environments across the public and private sectors.

Mandatory training data disclosures and creator compensation rights

Intellectual property governance proved the most contentious negotiation across congressional committees. The finalized statute obligates commercial AI providers to publish detailed technical summaries detailing copyrighted training corpora ingested during foundational model training runs.

Furthermore, authors, journalistic outlets, and creative syndicates receive legally binding machine-readable opt-out mechanisms. Unauthorized exploitation of protected Brazilian creative material for generative model refinement subjects technology platforms to collective civil liability and compensation protocols administered through certified copyright management bodies.

Regulatory sandboxes fostering regional startup innovation

To avoid hindering early-stage software companies and emerging healthtech ventures, the framework mandates the creation of experimental regulatory sandboxes supervised by the National Data Protection Authority (ANPD). Within these designated spaces, domestic startups can trial experimental machine learning deployments under expedited compliance oversight and temporary regulatory exemptions.

Industry associations praised the inclusion of safe harbor provisions for academic researchers studying model explainability and algorithmic alignment. The legislation now awaits presidential signing, granting organizations a 360-day transition window to modernize technical data pipelines, conduct risk audits, and align automated systems with statutory compliance standards.

International legal analysts note that Brazil’s hybrid approach successfully blends the precautionary principles of the European Union AI Act with the commercial agility demanded by global venture capital, potentially serving as an influential legislative blueprint for other emerging economies across the Global South.

Frequently asked questions

Does the new law prohibit consumer generative chatbots in Brazil?

No. Consumer applications such as ChatGPT, Claude, and Gemini will operate uninterrupted, requiring only clear visual disclaimers signaling that users are engaging with machine-generated output.

Which federal agency will lead compliance enforcement?

The ANPD will serve as the overarching regulatory anchor, coordinating with sector-specific authorities including central banking, healthcare, and telecommunications regulators.

When will corporate compliance and copyright rules take effect?

The statute provides a 360-day implementation period following presidential publication, allowing content industries and technology firms to build compliance pipelines.

Lucas Almeida
DigitalRadar Newsroom

Detecting and translating the future of technology for you.

Leave a comment

Your email address will not be published. Required fields are marked *