Trackers
Trackers

AI Regulation in Brazil: 2026 Update

AI regulation in Brazil is advancing rapidly, with a dedicated Artificial Intelligence Act moving through the legislative process and sector-specific rules already in force. Businesses operating in Brazil - whether deploying AI-powered products, processing personal data through automated systems, or using AI in financial or healthcare services - face a growing set of legal obligations. Non-compliance carries reputational and financial risk, and the regulatory landscape is shifting faster than many foreign investors anticipate. This guide covers the current legal framework, the key obligations under emerging and existing law, sector-specific requirements, enforcement mechanisms, and practical steps for compliance.

The current legal landscape for AI regulation in Brazil

Brazil does not yet have a single, fully enacted AI-specific statute, but the regulatory environment is far from empty. Several existing laws already govern AI-related activities, and a dedicated AI Act - the Marco Legal da Inteligência Artificial - is in advanced stages of the legislative process.

The Lei Geral de Proteção de Dados (LGPD), Brazil';s data protection law, is the most immediately relevant instrument. It applies directly to any AI system that processes personal data, which covers the vast majority of commercial AI deployments. The LGPD grants data subjects the right to request review of automated decisions that affect them, including profiling and credit scoring. Controllers must be able to explain the logic of such decisions and, where requested, provide human review. The Autoridade Nacional de Proteção de Dados (ANPD), the national data protection authority, has issued guidance clarifying that AI-driven profiling falls squarely within the LGPD';s scope.

The Consumer Defence Code (Código de Defesa do Consumidor) adds a further layer. AI systems used in consumer-facing contexts - recommendation engines, chatbots, automated pricing - must meet standards of transparency and non-deception. Suppliers remain liable for defects in products or services regardless of whether those defects originate in an algorithm.

Brazil';s Civil Rights Framework for the Internet (Marco Civil da Internet) also intersects with AI, particularly on questions of algorithmic accountability for online platforms. Platforms that use automated systems to curate or moderate content may face obligations under this framework, and proposed amendments would extend those obligations further.

The Marco Legal da Inteligência Artificial: what the draft law contains

The Marco Legal da Inteligência Artificial is Brazil';s proposed comprehensive AI statute. It has passed through the Senate and is under review in the Chamber of Deputies, with amendments expected before final enactment. Businesses should treat its core provisions as a near-certain future obligation and begin preparing now.

The draft law adopts a risk-based approach broadly comparable to the European Union';s AI Act, though with distinct Brazilian characteristics. It classifies AI systems into risk tiers - excessive risk, high risk, limited risk, and minimal risk - and attaches different obligations to each tier.

Systems classified as excessive risk are prohibited outright. These include AI used for social scoring by public authorities, real-time biometric surveillance in public spaces without judicial authorisation, and systems that exploit psychological vulnerabilities to manipulate behaviour. The prohibition mirrors international consensus but is adapted to Brazil';s constitutional framework, which places strong emphasis on human dignity and the right to privacy.

High-risk systems face the most demanding obligations. These include AI used in credit decisions, employment screening, healthcare diagnosis, critical infrastructure management, and public service delivery. Operators of high-risk systems must conduct conformity assessments, maintain technical documentation, implement human oversight mechanisms, and register their systems in a national registry to be maintained by the competent authority. Transparency obligations require that individuals interacting with high-risk AI be informed they are doing so.

Limited-risk systems - such as chatbots and deepfake-generating tools - must disclose their AI nature to users. Minimal-risk systems, which cover most commercial AI applications, face no specific obligations beyond those already imposed by the LGPD and other existing law.

The draft law also establishes a national AI governance body, though its precise institutional form remains under discussion. It may sit within an existing ministry or be constituted as an independent agency. The choice of institutional home will affect enforcement capacity and regulatory culture significantly.

Sector-specific AI rules already in force in Brazil

While the Marco Legal works its way through Congress, sector regulators have moved ahead with their own AI-related requirements. Foreign businesses often underestimate the density of this sectoral layer.

The Banco Central do Brasil (BCB) has issued resolutions requiring financial institutions to manage algorithmic and model risk as part of their broader operational risk frameworks. Institutions using AI in credit underwriting, fraud detection, or customer onboarding must document model assumptions, validate outputs, and maintain audit trails. The BCB has signalled that AI governance will be a supervisory priority, and examinations increasingly include questions about model explainability and bias testing.

The Agência Nacional de Saúde Suplementar (ANS), which regulates private health insurance, and the Agência Nacional de Vigilância Sanitária (ANVISA), which regulates medical devices and diagnostics, both have frameworks that apply to AI-enabled health products. ANVISA classifies AI-based diagnostic software as a medical device subject to registration and post-market surveillance. Companies bringing AI diagnostic tools to Brazil must navigate this registration process before commercial deployment.

The Comissão de Valores Mobiliários (CVM), Brazil';s securities regulator, has addressed AI in the context of investment advice and algorithmic trading. Firms using AI to generate investment recommendations must ensure those recommendations meet suitability standards and that the AI system';s outputs can be explained to clients and regulators.

In practice, founders entering the Brazilian market with AI products should map their product against all applicable sectoral regulators from the outset, not just the LGPD and the forthcoming AI Act. A single AI product may trigger obligations under two or three different regulatory regimes simultaneously.

If you are assessing your product';s regulatory exposure in Brazil, contact info@vlolawfirm.com. We can help structure the compliance analysis correctly the first time.

Key compliance obligations for businesses deploying AI in Brazil

Regardless of whether the Marco Legal has been fully enacted by the time a business launches in Brazil, a concrete set of obligations already applies. Compliance planning should address each of the following areas.

Data protection by design. Any AI system processing personal data must comply with the LGPD';s principles of necessity, purpose limitation, and data minimisation. Privacy impact assessments are required for high-risk processing activities, and the ANPD has indicated it will scrutinise AI-driven profiling closely. Controllers must appoint a Data Protection Officer (Encarregado) and maintain records of processing activities.

Automated decision-making transparency. The LGPD';s Article 20 gives data subjects the right to request review of automated decisions that affect their interests. Controllers must be prepared to explain the criteria and procedures used, and to provide human review where requested. Building explainability into AI systems from the design stage is far more efficient than retrofitting it after deployment.

Algorithmic impact assessments. The draft Marco Legal requires operators of high-risk AI systems to conduct conformity assessments before deployment. Even before the law is enacted, conducting a voluntary algorithmic impact assessment demonstrates good faith to regulators and identifies risks early. The ANPD has encouraged this practice in its published guidance.

Human oversight mechanisms. High-risk AI systems must include meaningful human oversight - not merely a nominal review step. In practice, this means designing workflows where human reviewers have the information, authority, and time to genuinely assess AI outputs before consequential decisions are made.

Documentation and audit trails. Regulators across sectors expect businesses to maintain technical documentation of AI systems, including training data sources, model architecture, validation results, and records of updates. This documentation must be available for regulatory inspection. Many foreign companies discover too late that their documentation practices, adequate in their home jurisdiction, do not meet Brazilian expectations.

Consumer-facing disclosure. Where AI interacts directly with consumers - chatbots, virtual assistants, automated customer service - Brazilian law already requires disclosure of the AI nature of the interaction. This obligation exists under the Consumer Defence Code and will be reinforced by the Marco Legal.

A common mistake among foreign founders is to treat Brazilian AI compliance as a future obligation contingent on the Marco Legal';s enactment. In reality, the LGPD, sectoral rules, and the Consumer Defence Code already create a substantial compliance burden that applies today.

Enforcement, penalties, and the role of the ANPD

Enforcement of AI-related obligations in Brazil is distributed across multiple authorities, which creates both complexity and risk for businesses.

The ANPD is the primary enforcer of LGPD obligations, including those arising from automated decision-making and AI-driven profiling. It has the power to issue warnings, impose fines of up to two percent of a company';s revenue in Brazil in the prior financial year (capped at a significant absolute amount per infraction), and order the suspension or prohibition of data processing activities. The ANPD has been building its enforcement capacity steadily and has opened investigations into automated profiling practices.

Sectoral regulators enforce their own AI-related requirements independently. The BCB can impose administrative sanctions on financial institutions for inadequate model risk management. ANVISA can prohibit the commercialisation of unregistered AI medical devices. The CVM can sanction investment firms for AI-generated advice that fails suitability standards. These sanctions operate in parallel with ANPD enforcement and can accumulate.

Consumer protection authorities - both the federal Secretaria Nacional do Consumidor (SENACON) and state-level Procons - can act against businesses whose AI systems cause consumer harm or engage in deceptive practices. Class actions under the Consumer Defence Code are a realistic litigation risk for businesses deploying consumer-facing AI at scale.

The Ministério Público (public prosecutor';s office) has broad standing to investigate and litigate matters involving collective rights, which includes AI systems that affect large numbers of individuals. Several state-level Ministério Público offices have established digital rights units with AI expertise.

Many underestimate the cumulative enforcement risk. A single AI deployment that processes personal data, interacts with consumers, and operates in a regulated sector can attract simultaneous scrutiny from the ANPD, a sectoral regulator, SENACON, and the Ministério Público. Coordinating a response across multiple proceedings is costly and time-consuming.

Practical compliance steps for foreign businesses entering Brazil

Foreign businesses deploying AI in Brazil face a set of practical challenges that go beyond reading the law. The following steps reflect what a well-advised market entry looks like in practice.

Conduct a regulatory mapping exercise. Before launch, identify every regulatory regime that applies to the AI system - LGPD, sectoral rules, Consumer Defence Code, and the forthcoming Marco Legal. Map the product';s data flows, decision outputs, and user interactions against each regime. This exercise frequently reveals obligations that were not anticipated at the product design stage.

Localise documentation and disclosures. Brazilian regulators expect documentation in Portuguese. Privacy notices, terms of service, and AI disclosure statements must be drafted in clear, accessible Portuguese and must meet the specific content requirements of Brazilian law. Generic English-language documentation translated by machine is not adequate.

Appoint local compliance contacts. The LGPD requires appointment of an Encarregado (Data Protection Officer), who must be publicly identified and accessible to data subjects and the ANPD. For AI systems in regulated sectors, additional local compliance contacts may be required by sectoral regulators.

Build explainability into the system architecture. Brazilian law';s automated decision-making rights are not satisfied by post-hoc rationalisation. The system must be capable of generating meaningful explanations of its outputs. This is a technical requirement that must be addressed at the design stage.

Engage with the regulatory process. The ANPD and the congressional committees working on the Marco Legal have held public consultations and sandbox programmes. Participating in these processes provides advance intelligence on regulatory direction and can influence outcomes. Several technology companies have engaged constructively with the ANPD';s sandbox, gaining practical experience operating under regulatory supervision before the full framework is enacted.

Scenario: a fintech entering Brazil with an AI credit scoring model. This business must comply with the LGPD';s automated decision-making provisions, the BCB';s model risk management requirements, and the forthcoming Marco Legal';s high-risk AI obligations. It must document the model, validate it for bias, appoint an Encarregado, and be prepared to explain credit decisions to applicants on request. The BCB may also require notification or approval before the model is deployed at scale.

Scenario: a healthtech company deploying an AI diagnostic tool. This business must register the tool with ANVISA as a medical device, comply with the LGPD in relation to health data (a sensitive data category attracting heightened obligations), and ensure the tool meets the Marco Legal';s high-risk AI requirements once enacted. Post-market surveillance obligations under ANVISA require ongoing monitoring and reporting of adverse events.

To discuss your specific compliance requirements in Brazil, contact info@vlolawfirm.com. We can assist with regulatory mapping, documentation, and engagement with Brazilian authorities.

Frequently asked questions

Does the LGPD already apply to AI systems, or do businesses need to wait for the Marco Legal?

The LGPD applies now to any AI system that processes personal data, which covers nearly all commercial AI deployments. Its automated decision-making provisions, data subject rights, and accountability requirements create immediate obligations. The Marco Legal will add a risk-based classification system and additional requirements for high-risk AI, but it does not replace or suspend the LGPD. Businesses should treat LGPD compliance as a current, non-negotiable baseline and plan for Marco Legal compliance as an additional layer. Waiting for the Marco Legal to be enacted before beginning compliance work is a common and costly mistake.

How long does it take to achieve AI compliance in Brazil, and what does it cost?

The timeline depends heavily on the complexity of the AI system and the number of regulatory regimes involved. A straightforward consumer-facing AI product with no sectoral regulation may achieve baseline LGPD compliance within two to three months with adequate legal and technical support. A high-risk AI system in a regulated sector - finance, health, critical infrastructure - may require six months or more to complete regulatory mapping, documentation, bias testing, and any required regulatory notifications or approvals. Professional fees for a comprehensive compliance programme typically start from the low thousands of USD for simpler deployments and rise significantly for complex, multi-sector products. State registration or notification fees, where applicable, are additional.

Should a foreign company establish a Brazilian legal entity to deploy AI in Brazil, or can it operate from abroad?

Brazilian law does not require a local legal entity solely for the purpose of deploying an AI product, but several practical and legal factors push strongly toward local establishment. The LGPD';s Encarregado must be accessible to Brazilian data subjects and the ANPD, which is difficult to manage from abroad. Sectoral regulators - particularly the BCB and ANVISA - typically require local entities for licensed activities. Consumer protection enforcement is significantly easier to manage through a local entity. For businesses with substantial Brazilian operations or user bases, establishing a local entity - most commonly a Sociedade Limitada (Ltda.) - is the standard approach and simplifies compliance considerably.

Conclusion

Brazil';s AI regulatory environment is substantive, multi-layered, and evolving quickly. The LGPD, sectoral rules, and the forthcoming Marco Legal da Inteligência Artificial together create a compliance framework that demands early attention, careful planning, and ongoing monitoring. Foreign businesses that treat Brazilian AI regulation as a future concern risk entering the market with significant unaddressed exposure.

VLO Law Firms advises international clients on AI regulation in Brazil. We can assist with regulatory mapping, LGPD compliance, Marco Legal readiness assessments, sectoral regulatory engagement, and documentation in Portuguese. To request a consultation, contact: info@vlolawfirm.com