-
What is the legal definition of “artificial intelligence” in your jurisdiction, if any? If no definition exists, how do regulators or courts typically describe artificial intelligence?
Brazil does not yet have a generally applicable statutory definition of artificial intelligence. Senate-approved Bill No. 2,338/2023, currently before the Chamber of Deputies, is the principal legislative reference. Article 4, I, would define an AI system as “a machine-based system that, with varying degrees of autonomy and for explicit or implicit objectives, infers, from the data or information it receives, how to generate outputs, particularly predictions, content, recommendations or decisions, that may influence virtual, physical or real environments.” Because the Bill has not been enacted, this definition is not binding and may still be amended.
In the absence of a uniform statutory concept, sectoral authorities have adopted definitions applicable only within their respective fields:
- Judiciary: National Council of Justice Resolution No. 615/2025, as amended by Resolution No. 674/2026, adopts a similar machine-based definition and separately defines generative AI. It governs AI used within the Judiciary; the definition was not developed through judicial adjudication. Neither the STF nor the STJ has established a generally applicable definition; courts instead focus on reliability, human review, evidentiary validity and procedural fairness.
- Electoral regulation: TSE Resolution No. 23,610/2019, as amended by Resolutions Nos. 23,732/2024 and 23,755/2026, defines AI by reference to logic, knowledge representation and machine learning, and separately regulates synthetic content.
- Data protection: The ANPD has issued no binding definition. Its 2024 Technology Radar uses the OECD formulation, including varying autonomy and post-deployment adaptiveness, but is a non-binding technical publication. This is relevant because the Brazilian DPA is currently the expected authority to coordinate the application of Bill 2,338 once approved.
- Other sectors: ANAC Normative Instruction No. 209/2025 defines AI for its internal policy as technology performing tasks ordinarily requiring human intelligence. Anatel Internal Resolution No. 554/2026 broadly covers models, algorithms, techniques and methodologies, but primarily governs AI used or acquired by Anatel. CFM Resolution No. 2,454/2026 distinguishes AI models, systems, applications, generative AI and large language models in medicine. It is professional regulation and takes effect on 26 August 2026.
- Public policy: The Brazilian AI Strategy (EBIA) follows the OECD concept, while the Brazilian AI Plan (PBIA) uses a broader operational definition centred on models, algorithms and learning processes. Both are policy instruments rather than generally applicable legal tests.
Accordingly, Brazilian regulators generally describe AI as machine-based or algorithmic systems that process inputs and generate predictions, content, recommendations or decisions with varying autonomy. Brazil nevertheless lacks a single binding definition applicable across the legal system.
-
Has your country developed a national strategy for artificial intelligence? If yes, what progress has been made in its implementation? Are there plans for updates or revisions?
Yes. Brazil adopted its national AI strategy through the Brazilian Artificial Intelligence Strategy (Estratégia Brasileira de Inteligência Artificial – EBIA), established by MCTI Ordinance No. 4,617 of 6 April 2021, as amended by MCTI Ordinance No. 4,979 of 13 July 2021. Aligned with the OECD AI Principles, the EBIA is the Government’s long-term framework for promoting AI research, innovation and responsible use. Its objectives include developing ethical principles, increasing research and development investment, removing barriers to innovation, training professionals and strengthening cooperation among government, industry and research institutions. Its nine pillars span regulation and governance, international cooperation, education and workforce development, research and entrepreneurship, sectoral applications, public administration and public security.
The MCTI coordinates, monitors and reports on implementation and must periodically assess whether the EBIA requires revision. Implementation entered a more operational phase through the Brazilian Artificial Intelligence Plan (Plano Brasileiro de Inteligência Artificial – PBIA) 2024–2028. A preliminary version was presented in July 2024 and the final Plan was published in June 2025. Coordinated by the MCTI under the guidance of the National Council for Science and Technology, the PBIA translates the EBIA’s objectives into programmes, investment priorities and funding commitments.
The PBIA establishes 54 structural actions across five axes: AI infrastructure and development; diffusion, education and capacity building; AI for improving public services; AI for business innovation; and support for AI regulation and governance. It envisages up to approximately BRL 23.03 billion in investments through 2028. This combines federal budgetary and non-reimbursable resources, public credit principally from Finep and BNDES, state-owned enterprise funding, and private investment.
Accordingly, the EBIA remains Brazil’s national strategy, while the PBIA is its principal implementation and investment instrument through 2028. Progress is reflected in the transition from broad objectives to funded actions and programs. No replacement of the EBIA has been formally announced, but its governing Ordinance requires periodic assessment and permits updates as implementation and technological developments evolve.
-
Has your jurisdiction adopted any AI-specific laws, regulations, voluntary standards, or ethical guidelines? If so, please provide a brief overview. If not, which existing laws could be/are applied to artificial intelligence and the use of artificial intelligence, what are the main interpretive challenges, and are there any pending artificial intelligence legislative initiatives?
Brazil has not yet enacted a comprehensive federal AI statute, but AI-specific rules already exist in particular sectors and institutions, alongside voluntary standards and policy instruments.
The principal pending federal initiative is Bill No. 2,338/2023. The Federal Senate approved the Bill on 10 December 2024 and transmitted it to the Chamber of Deputies on 17 March 2025. As at 10 August 2026, it remained before a Special Committee awaiting the rapporteur’s opinion and may therefore still be amended. The Senate-approved text establishes general rules for responsible AI development and use; adopts a risk-based framework covering prohibited and high-risk uses; creates rights for affected persons; requires preliminary risk and algorithmic impact assessments; regulates general-purpose and generative AI; encourages codes of practice and regulatory sandboxes; and creates a National AI Regulation and Governance System coordinated by the National Data Protection Agency (ANPD), while preserving sectoral regulators’ powers.
Pending comprehensive legislation, AI is governed by existing laws, including the Federal Constitution, General Data Protection Law (LGPD), Consumer Protection Code, Civil Code, Marco Civil da Internet, intellectual property (see Questions 10 and 11) and labour legislation, together with sector-specific AI rules. Examples include CNJ Resolution No. 615/2025 for the judiciary, TSE Resolutions Nos. 23,732/2024 for elections, ANAC Normative Instruction No. 209/2025, Anatel Internal Resolution No. 554/2026and CFM Resolution No. 2,454/2026.
Key interpretive challenges include determining lawful bases for collecting and using personal data to train AI; applying purpose limitation to public, inferred, synthetic or re-identifiable data; allocating data-protection roles across AI supply chains; and applying the LGPD right to review automated decisions. Other uncertainties concern liability among developers and deployers, copyright in training data and AI-generated outputs, algorithmic discrimination, transparency and human review, employment uses of AI, and coordination among the ANPD and sectoral authorities.
Brazil has also adopted non-binding policy instruments, notably the Brazilian Artificial Intelligence Strategy (EBIA) and the 2024–2028 Brazilian Artificial Intelligence Plan (PBIA). Voluntary ABNT standards include ISO/IEC 42001 on AI management systems, ISO/IEC 23894 on risk management, ISO/IEC 22989 on concepts and terminology, and ISO/IEC 38507 on AI governance.
-
Are there legal requirements for artificial intelligence transparency, explainability, or audits? Are there obligations to disclose the use of artificial intelligence to customers/clients?
Yes, although current requirements are fragmented and context-specific. In the absence of comprehensive AI legislation, transparency obligations arise primarily from the Brazilian General Personal Data Protection Law (LGPD), the Brazilian Consumer Protection Code (CDC), and sector-specific rules.
Under the LGPD, transparency is a general principle of personal-data processing (Article 6, VI). Articles 6 and 9 require clear, precise and accessible information about matters including processing purposes and duration, the controller’s identity, data sharing and data-subject rights, subject to commercial and industrial secrecy. These provisions do not require disclosure of source code, model weights, or complete technical architecture.
Article 20 establishes additional rights for decisions made solely through automated processing of personal data that affect a data subject’s interests. The data subject may request review and, upon request, receive clear and adequate information about the criteria and procedures used, subject to trade secrecy. The provision does not expressly require human review, and not every AI-assisted decision falls within Article 20, although the ANPD understands automated decisions to include AI (ANPD, 2025, p. 26-30). Where information is withheld on trade-secret grounds, the ANPD may audit the processing for possible discriminatory aspects (Art. 20, § 2º).
The CDC requires adequate and clear information about products and services and prohibits misleading or abusive practices and advertising. Accordingly, AI use may need to be disclosed when material to a product or service’s characteristics, quality, risks, terms or performance, or where non-disclosure would be misleading. There is, however, no general obligation to label every AI-enabled product, service or internal process.
Pending Bill No. 2,338/2023 would introduce more detailed requirements. Transparency and explainability would operate as general principles and as rights of affected persons, with stronger duties for high-risk systems. Affected persons would have a general right to be informed when interacting with AI, including that the interaction is automated, potentially through standardized icons or symbols. High-risk systems would also trigger a right to explanations of decisions, recommendations or predictions, in plain language and within a reasonable time.
Auditability would apply as a general principle throughout the AI lifecycle, graduated according to risk. Developers and deployers of high-risk systems would have documentation, record-keeping, testing and human-oversight obligations, while competent authorities could conduct or order audits of high-risk systems or systems producing relevant legal effects. Conclusions of algorithmic impact assessments would generally be public, subject to secrecy protections.
Finally, generative-AI systems would be subject to a specific disclosure requirement: synthetic content must contain an identifier enabling verification of its authenticity and provenance.
-
Are there legal requirements or best practice expectations for human oversight and human-in-the-loop in artificial intelligence systems?
Brazil does not currently impose a generally applicable requirement that every AI system operate with a human in the loop. Human oversight obligations instead arise from the Brazilian General Personal Data Protection Law (LGPD), sector-specific rules and governance frameworks, and vary according to the system’s purpose, risk, autonomy and effects on rights.
Under Article 20 of the LGPD, where a decision is based solely on automated processing of personal data and affects the data subject’s interests, the individual may request review. This establishes a right to review rather than a universal requirement for prior human approval. Since its removal from the draft bill in 2019, there has been no requirement that the review be performed by a human.
More specific binding requirements apply in certain sectors. National Council of Justice Resolution No. 615/2025 requires effective, periodic and risk-adjusted human supervision of judicial AI systems, preserves judicial users’ final authority, and requires AI outputs to remain reviewable and correctable. ANAC Normative Instruction No. 209/2025 similarly requires effective human participation and supervision, including critical assessment of AI-generated information used in decision-making. Anatel Internal Resolution No. 554/2026 requires users to verify AI outputs and mandates human supervision of generative-AI content. Federal Council of Medicine Resolution No. 2,454/2026 establishes particularly strong safeguards, preserving physicians’ final authority and prohibiting certain diagnoses, prognoses or therapeutic decisions without appropriate human mediation. The Digital Statute for Children and Adolescents—Law No. 15,211/2025 also requires regular expert review of relevant AI tools.
Pending Bill No. 2,338/2023 would establish a broader risk-based framework. Its Senate-approved text requires effective and adequate human oversight throughout the AI lifecycle and, for high-risk systems, sufficient human capacity to understand, interpret, decide upon and intervene in the system. It does not, however, mandate a universal human-in-the-loop model and permits alternative safeguards where human oversight is demonstrably impossible or disproportionate.
-
Are there specific legal or regulatory requirements addressing algorithmic bias, discrimination, or fairness in AI systems (including gender bias)?
Yes. Although Brazil does not yet have a comprehensive AI statute in force, algorithmic discrimination is already addressed through constitutional equality guarantees, the Brazilian General Data Protection Law (LGPD), anti-discrimination legislation and sector-specific rules. These provisions are generally technology-neutral and apply where AI systems produce or support unlawful discriminatory outcomes.
The Federal Constitution guarantees equality before the law, equal rights for men and women, and prohibits discrimination, including in employment. Under the LGPD, Article 6, IX prohibits processing personal data for unlawful or abusive discriminatory purposes. The principles of data quality, prevention and accountability are also relevant where inaccurate, incomplete or unrepresentative data may generate discriminatory outcomes. Article 11 provides additional safeguards for sensitive data, including processing that reveals sensitive characteristics and may cause harm, while Article 20 permits review of certain solely automated decisions.
Employment law provides particularly relevant protections against gender bias. Law No. 9,029/1995 prohibits discriminatory practices in hiring and employment, while Law No. 14,611/2023 establishes equal-pay and remuneration requirements for women and men. These rules apply to AI used in recruitment, résumé screening, compensation, promotion, performance management or dismissal, including where proxy variables produce discriminatory effects. Other protections apply in credit scoring, disability discrimination, racial discrimination, and homophobic or transphobic discrimination.
Pending Bill No. 2,338/2023 would establish a more systematic AI-specific framework. It prohibits unlawful or abusive discrimination and expressly recognizes indirect discrimination arising from apparently neutral rules, practices or criteria that disadvantage individuals or groups. This captures algorithmic bias resulting from training data, proxy variables, model design or unequal error rates even without discriminatory intent.
The Bill would require developers and deployers of high-risk systems to identify, prevent and mitigate discriminatory outcomes. Employment-related AI systems would expressly qualify as high-risk and would be subject to algorithmic impact assessments. The Bill does not prohibit every statistical disparity, but rather unlawful or abusive discrimination assessed according to purpose, effects, context and legitimate justification. It remains pending before the Chamber of Deputies and is not yet binding.
-
What legal frameworks apply to AI-related harm and defective artificial intelligence systems? Who can be held liable (developer, deployer, victim of the damage, others), how is liability allocated, and what burden of proof applies to victims?
Brazil does not yet have a specific civil-liability regime for harm caused by AI systems. AI systems themselves have no legal personality, so liability must be attributed to natural or legal persons involved in developing, supplying, integrating, deploying or operating them. The applicable framework depends on the relationship between the parties, the nature of the harm, each actor’s role and any sector-specific legislation. The principal regimes are the Civil Code, the Consumer Protection Code (CDC) and, where personal data are involved, the General Data Protection Law (LGPD).
Outside consumer relationships, the Civil Code provides contractual, fault-based and strict liability. Contractual liability may arise from breach of obligations concerning matters such as accuracy, security, documentation, human oversight or incident response. Under the general fault-based regime, the claimant must establish unlawful conduct or omission, damage, causation and, where required, intent, negligence, imprudence or lack of technical ability. Relevant conduct may include inadequate design or testing, poor-quality data, insufficient cybersecurity, failure to disclose limitations, inappropriate deployment, inadequate human supervision or unreasonable reliance on AI outputs. Strict liability may apply where provided by law or where the defendant’s activity inherently creates risks to others, although merely using AI does not automatically make an activity hazardous.
In consumer relationships, the CDC generally provides stronger protection. Suppliers are strictly liable for damage caused by defective products or services. An AI system may be defective where it fails to provide reasonably expected safety, including because of unsafe outputs, material undisclosed limitations, inadequate accuracy, cybersecurity vulnerabilities, insufficient warnings or safeguards. However, an incorrect or undesirable AI output is not automatically a defect. The assessment depends on intended and foreseeable use, supplier representations, risks, warnings, technological conditions, and expected safety. Where multiple suppliers contributed to the harm, joint and several liability may apply.
Where personal-data processing causes harm, Articles 42–45 of the LGPD provide an additional regime. Controllers directly involved in harmful processing may be jointly liable, while processors may also be jointly liable where they breach data-protection obligations or disregard lawful controller instructions.
As a general rule, the claimant bears the burden of proving the facts supporting the claim. In fault-based cases, this normally includes wrongful conduct, fault, damage and causation; under strict liability, fault need not be proved, but defect or legally relevant risk, damage and causation generally must be established. Courts may dynamically reallocate the burden where proof is excessively difficult for one party and more readily available to the other. Consumer law and the LGPD also allow reversal of the burden in specified circumstances.
Pending Bill No. 2,338/2023 would not create a universal strict-liability regime. It would largely preserve the CDC, Civil Code and sector-specific rules, while requiring reversal of the burden of proof where victims are vulnerable or the characteristics of the AI system make proof excessively burdensome.
-
What cybersecurity obligations apply to AI systems?
Brazil does not yet have a general cyber security regime specifically governing artificial intelligence systems. Instead, AI is subject to technology-neutral data-protection, internet, consumer-protection and sector-specific cybersecurity rules. The National Information Security Policy and National Cybersecurity Strategy provide an overarching policy framework but do not establish comprehensive, directly enforceable controls for private-sector AI systems.
The principal cross-sector obligations arise under the General Data Protection Law (LGPD) whenever AI systems process personal data. Controllers and processors must implement technical and administrative measures to protect data against unauthorized access, loss, alteration, disclosure, and other unlawful processing. These safeguards must apply from the design stage onward, reflecting a security-by-design approach. Where a personal data security incident may create relevant risk or damage, controllers must notify the ANPD and affected individuals, generally within three business days.
Additional obligations may apply under the Marco Civil da Internet and Decree No. 8,771/2016, including access controls, authentication, logging, encryption or equivalent safeguards, data minimization and secure deletion.
Sector-specific requirements may also apply. The ECA Digital imposes security duties concerning children’s data and age information. CNJ Resolution No. 615/2025 requires risk-based auditing, monitoring, data protection, integrity, traceability and access controls for judicial AI. Financial-sector rules, No. 4,893/2021 of the National Monetary Council (Conselho Monetário Nacional — CMN) as amended and BCB Resolution No. 85/2021, require cybersecurity controls, incident-response planning and safeguards addressing new technologies, while telecommunications rules in Anatel Resolution No. 740/2020, as amended by Resolution No. 767/2024, require cybersecurity policies, vulnerability and supplier-risk management, cloud-security assessments and incident reporting., require cybersecurity controls, incident-response planning and safeguards addressing new technologies, while telecommunications rules in Anatel Resolution No. 740/2020, as amended by Resolution No. 767/2024, require cybersecurity policies, vulnerability and supplier-risk management, cloud-security assessments and incident reporting.
Pending Bill No. 2,338/2023 would introduce more explicit AI-specific duties, including security, testing, lifecycle documentation, robustness and risk management requirements for high-risk systems, additional duties for systemic-risk general-purpose or generative AI, and reporting of serious security incidents. Sector-specific cybersecurity rules would remain applicable.
-
Is the use of artificial intelligence insured and/or insurable in your jurisdiction, including with cyber policies? Are there market trends, or limitations?
Yes. AI-related risks are insurable in Brazil, although there is no specific legal requirement to insure AI systems. Under Law No. 15,040/2024, insurance may cover any risk not prohibited by law, subject to the risks and exclusions expressly defined in the policy.
AI-related losses may therefore be covered through existing insurance products depending on the nature of the event. SUSEP Circular No. 637/2021 classifies liability arising from incidents affecting IT equipment, systems, stored information or security as “Comprehensive Civil Liability – Cyber Risks.” Accordingly, cyber policies may cover AI-related losses where they result from covered cybersecurity incidents. Other AI risks may fall under different insurance products or, where no specific category applies, General Civil Liability coverage.
Policies may also expressly cover certain fines and penalties when legally permissible. However, coverage does not extend to fines or penalties arising from criminal offences personally committed by the insured, and intentional acts of the insured, beneficiary or their representatives cannot be validly insured.
The Brazilian cyber-insurance market is expanding but remains relatively small. In 2023, direct written premiums reached approximately BRL 203 million, almost twice the 2021 amount, but represented less than 0.2% of non-life insurance premiums (SUSEP, 2024, pp. 13-14). Increasing AI regulation may stimulate demand for more specialized cyber-risk and civil-liability products addressing losses associated with AI development and use (CNseg, 2025, p. 20).
-
Can artificial intelligence be named as an inventor in a patent application filed in your jurisdiction? If not, what is the current legal position?
No. Under the current administrative interpretation of the Brazilian Patent and Trademark Office (INPI), only a natural person may be named as the inventor in a Brazilian patent application.
The Brazilian Industrial Property Law (Law No. 9,279/1996) does not expressly define an inventor as a natural person. However, Article 6 grants the author of an invention or utility model the right to obtain a patent, while Article 6(4) requires the inventor to be named and identified. INPI interprets these provisions, together with the broader legal framework, as presupposing human inventorship.
This interpretation was applied in the Brazilian patent application filed by Dr. Stephen Thaler naming the artificial intelligence (AI) system DABUS as inventor (Request BR112021008931-4). INPI rejected the application because it did not identify a valid inventor. In the administrative appeal, the Federal Prosecutor Office concluded that Article 6 of the Industrial Property Law, Article 4 of the Paris Convention and the TRIPS Agreement presuppose an inventor who is a natural person capable of performing legal acts under the Brazilian Civil Code. The issue has not yet been decided by Brazilian courts, so this administrative interpretation represents the best current statement of the legal position.
This does not mean that inventions developed with AI assistance are necessarily excluded from patent protection. A patent may be granted where a natural person can properly be identified as the inventor and the invention satisfies the ordinary patentability requirements of novelty, inventive step and industrial application. By contrast, where an invention is claimed to have been generated autonomously by AI and no natural person can properly be identified as inventor, Brazilian law currently provides no mechanism for naming the AI itself.
Legislative proposals have considered the issue. Bill No. 303/2024 originally proposed allowing an autonomous AI system to be named as both inventor and holder of patent rights. In May 2026, however, the Chamber of Deputies’ Committee on Science, Technology and Innovation rejected that approach and approved a substitute text to the related Bill No. 3,936/2024 addressing inventions developed with AI assistance. The proposal is awaiting consideration by the Committee on Industry, Commerce and Services and has not become law.
-
Do images or works generated by and/or with artificial intelligence benefit from copyright protection in your jurisdiction? If so, who is the authorship attributed to, and under what conditions?
Brazilian law distinguishes between works generated autonomously by artificial intelligence (AI) and works created by a human with AI assistance. Works generated exclusively by AI cannot benefit from copyright protection, since article 11 of the Brazilian Copyright Law (Law No. 9,610/1998) defines the author as a natural person.
Nonetheless, concerning music generated by AI and played in public spaces, there is a case indicating that royalties may still be due to ECAD (the Brazilian entity responsible for collecting and distributing music copyright royalties to authors and other rights holders). The case has been judged by the State Court of Santa Catarina, and no judgment from superior courts has been made on the matter until August 10, 2026. Therefore, it cannot yet be said that the collection of royalties by ECAD from AI-generated music is binding by case law.
Works generated with AI may benefit from copyright protection insofar as AI has been used as a tool by a human author, and provided that the criterion of originality of the resulting work is met. This requires that the author exercises meaningful creative control over the expressive elements of the work, which must be “a creation of the spirit” expressed in any support (as per article 7 of the Brazilian Copyright Law). This assessment is made on a case-by-case basis. Relevant factors include whether the human author made creative choices regarding the conception, selection, arrangement, editing, or refinement of the output, rather than simply providing generic prompts and accepting the generated result without substantive intervention. There are not yet sufficient cases or binding decisions from the superior courts (STF and STJ) on this matter.
In these circumstances, authorship is attributed exclusively to the human creator, not to the AI system or its developer. Brazilian law recognizes only natural persons as authors, and legal entities may hold copyright only through existent legal mechanisms that do not account for AI (Brazilian Copyright Law, article 11, sole paragraph).
-
What are the main issues to consider when using artificial intelligence systems in the workplace? Have any new regulations, or guidelines, been introduced regarding AI-driven hiring, performance assessment, or employee monitoring?
The main issues when using AI in the workplace are transparency, validity of assessment criteria, employee monitoring, data protection and discrimination.
First, employers should clearly inform candidates and employees when AI is used, for what purpose, what data are analysed, whether the tool assists or determines the outcome, the main assessment criteria, retention periods and how review may be requested. Trade secrets need not necessarily be disclosed, but generic notices are unlikely to be sufficient where AI influences hiring, promotion, remuneration or dismissal.
Second, employers should assess whether the criteria used by AI systems are actually relevant to the work performed. A system may be statistically accurate but rely on inappropriate proxies, such as typing speed for productivity or facial expressions for leadership. Indicators should be work-related, sufficiently accurate, non-discriminatory and periodically reassessed.
Third, AI can intensify workplace surveillance through meeting transcription, email and message analysis, screen capture, keystroke logging, facial recognition, emotion analysis and productivity scoring. Employers’ managerial powers remain limited by constitutional rights to privacy, intimacy, honour and image. Monitoring should therefore have a legitimate and specific purpose, use less intrusive means where available, generally be limited to working hours and corporate equipment, exclude intimate spaces and apply proportionate retention periods. Existing Superior Labour Court case law permits monitoring of corporate email where personal use has been expressly prohibited and employees were previously informed, while personal email accounts remain protected.
The Brazilian General Data Protection Law (LGPD) is also relevant. Article 20 grants a right to request review of decisions based solely on automated processing that affect an individual’s interests, expressly including professional profiling. Employee consent is generally a fragile legal basis because of the employment relationship, while legitimate interests require appropriate balancing. (ANPD, Guia Orientativo sobre agentes de tratamento e encarregado). Employers may face both data-protection sanctions and labour-law damages.
There is currently no legislation specifically governing AI-driven hiring, performance assessment or employee monitoring. However, in March 2026, a Chamber of Deputies committee approved a substitute text to Bill No. 3,088/2024 proposing algorithmic transparency and auditable, non-discriminatory criteria in selection and promotion, safeguards against physical and mental-health harms from AI-based control, collective bargaining where AI affects occupational structures, and graduated enforcement measures.
-
What are the main privacy/data protection issues arising from artificial intelligence development and use (including training data)? Have data protection authorities issued guidelines or rulings on artificial intelligence, and what are the key takeaways?
Regarding AI development, the main privacy and data protection issues concern the lawful collection and processing of personal data for model training, governed primarily by the Brazilian General Data Protection Law (LGPD). The law encompasses the use of publicly available personal data for training foundation models. Although information may be publicly accessible, this does not exempt controllers from complying with LGPD’s legal bases, purpose limitation, necessity, transparency, and data subject rights (ANPD, 2024, p. 20).
The most prominent enforcement action to date involved Meta. In July 2024, the National Data Protection Agency (ANPD) adopted a preventive measure suspending Meta’s planned use of personal data from Facebook, Instagram, and Messenger users in Brazil for training generative AI models after the company announced changes to its privacy policy. The Agency concluded that Meta had failed to demonstrate an adequate legal basis for such processing and identified concerns regarding transparency, purpose limitation, necessity, and the effective exercise of data subject rights, particularly because users were not offered sufficiently clear or effective mechanisms to object to the processing. ANPD also highlighted the heightened risks associated with the massive scale of the processing, the potential irreversible effects of incorporating personal data into AI models, and the possibility that children and adolescents’ data could be included. Following negotiations, Meta revised its practices, expanded transparency measures, and strengthened its opt-out mechanism, leading ANPD to suspend the preventive measure later in 2024.
Regarding AI use that processes personal data, main concerns involve transparency, automated decision-making, purpose limitation, security, and the protection of sensitive personal data.
LGPD requires controllers to provide clear information about data processing activities and grants individuals the right to request review of decisions made solely on the basis of automated processing that affect their interests (Article 20). Although the scope of this right remains subject to academic and regulatory debate, it has become particularly relevant in the context of AI systems used for recruitment, credit scoring, insurance, healthcare, and public administration.
LGPD also imposes obligations relating to data quality, accuracy, security, accountability, and privacy by design. AI developers and deployers are expected to implement technical and organizational measures capable of mitigating risks arising from large-scale processing, including risks of discrimination, excessive data retention, unauthorized reuse of datasets, and data breaches.
-
How is data scraping regulated in your jurisdiction from an IP, privacy and competition perspective? Are there recent precedents addressing the legality of data scraping for training of artificial intelligence systems?
Brazil does not have a specific statutory regime governing data scraping for AI training. Its legality is assessed under general rules of copyright, industrial property, data protection, contract and competition law.
From an intellectual property perspective, the Brazilian Copyright Law (Law No. 9,610/1998) does not expressly regulate web scraping or text and data mining. Facts and ideas are not protected, but scraping may infringe copyright where it reproduces protected expressive content, such as texts, images, audiovisual works or original databases, without authorization. Brazil currently has no specific text-and-data-mining exception. Accordingly, the legality of scraping copyrighted works for AI training remains uncertain. The principal case, Folha de S. Paulo v. OpenAI, included copyright and unfair-competition claims concerning the use of journalistic content for model training, but ended in an agreement and produced no judicial ruling.
The Industrial Property Law (Law No. 9,279/1996) may also apply where scraping involves unfair competition. Publicly available information is not generally protected merely because it is collected automatically, but liability may arise from misappropriation of commercially valuable or confidential information, circumvention of protections, or other dishonest commercial practices. In a leading 2009 case, the São Paulo State Court held that Catho committed unfair competition by systematically scraping hundreds of thousands of résumés from a competing recruitment platform and commercially exploiting that database.
From a privacy perspective, scraping personal data is subject to the LGPD even when the information is publicly available. Controllers must identify a valid legal basis and comply with purpose limitation, necessity, transparency, security, accountability and data-subject rights. The ANPD has emphasized these requirements in guidance and in enforcement concerning Meta’s use of publicly available user data to train generative AI.
From a competition perspective, scraping is not unlawful per se, but may contribute to abuse of dominance where undertaken by a company with market power. In April 2026, the Brazilian antitrust authority (CADE) reopened and converted into a formal administrative proceeding an investigation concerning Google’s use of journalistic content. The authority considered whether changed competitive dynamics associated with generative-AI search features could reduce publishers’ visibility, traffic and monetization. CADE did not conclude that scraping itself was illegal.
Brazilian courts have therefore not yet issued a definitive ruling specifically on scraping for AI training. Bill No. 2,338/2023 proposes transparency and copyright-related obligations concerning AI training datasets, including remuneration mechanisms in certain circumstances, but remains pending and may still be amended.
-
To what extent is the prohibition of data scraping in the terms of use of a website enforceable?
In Brazil, an anti-scraping clause is enforceable only if the person carrying out the scraping is bound by the relevant terms of use. Brazil’s Superior Court of Justice (STJ) has held that terms of use unilaterally drafted by the provider and presented to users constitute a standard-form contract (REsp No. 2,088,236/PR). The provision should therefore be clear and unambiguous, since Article 423 of the Brazilian Civil Code requires ambiguous or contradictory provisions in standard-form contracts to be construed in favour of the party accepting the standard terms. The method by which users accept those terms must likewise make their acceptance clear.
Accordingly, the terms must be presented in a way that gives the party a genuine opportunity to review them, and there must be evidence that the party agreed to be bound. Merely making the terms available through a hyperlink may not suffice, particularly if the link is not prominent or the user’s conduct does not reasonably indicate acceptance. An express mechanism, such as click-wrap, generally provides stronger evidence of agreement than browse-wrap terms accessible only through a hyperlink (Lima, 2023, p. 148). Nor does the inclusion of an anti-scraping provision, by itself, justify enforcement action against a user; it must also be shown that the alleged scraping occurred (São Paulo Court of Appeal, Civil Appeal No. 1029475-38.2024.8.26.0100).
Quite apart from the contractual position, scraping involving personal data must comply with the Brazilian General Data Protection Law (LGPD), irrespective of whether the anti-scraping provision is valid. According to the National Data Protection Agency (ANPD), such processing must rely on a lawful basis under Article 7 or, for sensitive personal data, Article 11. Even where the data are publicly available, the principles of good faith, purpose, adequacy and necessity continue to apply, and adequate transparency must be ensured during collection and storage (ANPD, 2024, p. 20).
Finally, as explained in the response to Question 14, scraping may also be unlawful where it involves the misappropriation of protected information, the circumvention of safeguards or other unfair commercial practices.
-
Does your country have a regulator or authority responsible for supervising the use and development of artificial intelligence? What are its powers and enforcement tools?
Brazil does not currently have a single regulator or dedicated authority responsible for supervising the development and use of artificial intelligence. Instead, oversight is currently decentralised and exercised by existing authorities within their respective statutory mandates, depending on the sector involved and the legal issues arising from the use of AI.
As noted above, Bill No. 2,338/2023 proposes a coordinated regulatory model rather than the creation of a new standalone AI regulator. The Bill authorises the establishment of the National Artificial Intelligence Regulation and Governance System (Sistema Nacional de Regulação e Governança de Inteligência Artificial – SIA), coordinated by the National Data Protection Authority (ANPD) as the competent authority. The SIA is intended to promote cooperation and regulatory harmonisation among the competent authority and sectoral regulators, while preserving the regulatory, supervisory and sanctioning powers already vested in sectoral authorities under their respective legal mandates.
As coordinator of the SIA, ANPD would be empowered to issue general binding rules on the disclosure of information concerning the use of AI systems, algorithmic impact assessments and the reporting of serious incidents; issue general AI rules; enter into regulatory agreements with SIA members to coordinate their respective powers; issue general guidance on certification and accreditation; encourage internationally recognised standards, best practices and certifications; receive and process anonymous complaints; and act as the residual regulator for economic activities not subject to a specific sectoral regulator. Sectoral authorities would retain their regulatory, supervisory and sanctioning powers, issue sector-specific rules, supervise governance measures for high-risk AI systems and enter into commitments with AI agents in administrative proceedings.
-
How widespread is the adoption of artificial intelligence in businesses in your jurisdiction, and which sectors are leading?
AI adoption among Brazilian businesses remains moderate overall but is increasing rapidly, with substantial variation by firm size and sector. The ICT Enterprises 2025 survey, covering companies with ten or more employees, found that 17% used AI in 2025, up from 13% in 2024. Adoption rises sharply with company size: 15% among small enterprises, 32% among medium-sized firms and 50% among large enterprises. (ICT Enterprises 2025, Cetic.br/NIC.br)
IBGE’s Semiannual Innovation Survey found that 41.9% of extractive and manufacturing firms with at least 100 employees used AI in 2024, compared with 16.9% in 2022. Use was concentrated in administrative activities, commercialization and product development rather than core production. (PINTEC Semestral 2024, IBGE)
Information and Communication is the leading sector in the general enterprise survey, with 49% adoption. This category includes information technology, telecommunications, media, advertising and marketing businesses. (ICT Enterprises 2025, Cetic.br/NIC.br)
Financial services also show particularly intensive AI deployment. In the banking sector, 65% of institutions reported being at exploratory or early-implementation stages, while another 30% had AI systems in production at limited or full scale. AI investment by surveyed banks reached R$826 million in 2025, 39% higher than the previous year. (Pesquisa Febraban de Tecnologia Bancária 2025, Febraban/Deloitte)
Healthcare adoption is closer to the national average, at 18% of establishments, but reaches 31% among facilities with more than 50 beds and 29% among diagnostic and therapeutic support services. (ICT in Health 2025, Cetic.br/NIC.br)Retail remains less mature: although 87% of entrepreneurs reported familiarity with AI, only 14% actually used it. (Research by the National Confederation of Shopkeepers (CNDL)
Overall, adoption is strongest among larger firms and digitally intensive sectors, while production-scale deployment remains significantly less widespread than general awareness or experimentation.
-
How is artificial intelligence used in the legal sector, by lawyers and/or in-house counsels? Are AI-driven legal tools widely adopted, and what are the main regulatory concerns?
AI is already widely used in the Brazilian legal sector, both within public institutions and by private lawyers and in-house counsel. Before generative AI, courts and legal departments used narrower systems for classification, information extraction, semantic search, predictive analysis, jurimetrics, document review, contract analytics and automation. Brazilian courts were early adopters: by 2020, 64 AI projects were already operating or under implementation across 47 courts, including systems such as Victor at the Federal Supreme Court and Athos and Sócrates at the Superior Court of Justice.
Generative AI substantially expanded adoption by making AI directly accessible to individual lawyers and enabling open-ended language generation. Current applications include legal research, document drafting, summarization of case files, comparison of legal interpretations, preparation of initial versions of opinions and submissions, repetitive-task automation and knowledge management (CEPI/FGV Direito SP, 2026). In-house departments additionally use AI for contract review against internal playbooks, triage of demands, internal self-service tools and portfolio-level risk analysis.
Individual adoption is now very high: 77% of surveyed professionals reported frequent AI use in 2026, compared with 55% the previous year, while non-users fell to 11% (2nd Report on the Impact of AI on Law, 2026). Organizational governance is considerably less mature: only 20% of organizations report having or implementing formal AI governance structures, and almost half lack dedicated AI experts or committees. CEPI/FGV Direito SP, 2026)
There is no comprehensive AI statute specifically regulating legal practice. The principal professional instrument is Federal Council of the Brazilian Bar Association Recommendation No. 001/2024, which addresses applicable law, confidentiality and privacy, ethical practice and communication regarding AI use. It recommends that lawyers inform clients in advance of their intention to use AI. Professional duties also arise from the Statute of the Legal Profession, ethical rules, procedural law, the Brazilian General Data Protection (LGPD) and contractual obligations.
The main regulatory concerns are confidentiality and data protection, particularly when contracts, litigation documents, investigations or personal data are uploaded to external systems, and accuracy and professional liability. Brazilian courts have already imposed sanctions where lawyers submitted fabricated AI-generated case law or used prompt injection. The Superior Court of Justice has also held that a generative-AI report produced without human reasoning cannot serve as evidence in criminal proceedings. Within the judiciary, the National Council of Justice Resolution No. 615/2025 additionally establishes requirements concerning human supervision, audits, transparency, security and non-discrimination.
-
What are the 5 key challenges and the 5 key opportunities raised by artificial intelligence for lawyers in your jurisdiction?
The principal challenges are:
- Accuracy, hallucinations and professional liability. Generative AI may produce fabricated case law, incorrect legislation, factual errors or misleading interpretations. Lawyers remain responsible for work produced with AI assistance, and Brazilian courts have already imposed fines and disciplinary referrals where fabricated AI-generated authorities were submitted.
- Training, governance and human oversight. Lawyers increasingly need technological literacy alongside traditional legal reasoning. Organizations must also develop governance structures, supervision practices and internal rules for responsible use, while legal education must prepare professionals both to use AI tools and to advise on their legal implications. (MARANHÃO, 2017; MARANHÃO, 2024)
- Confidentiality, data protection and cybersecurity. Uploading contracts, litigation materials, investigations, client communications or commercially sensitive information to external AI systems may expose data to storage, reuse, international transfers or unauthorized disclosure. Use must therefore comply with professional secrecy, ethical duties and the LGPD.
- Workforce and business-model disruption. AI may reduce demand for some entry-level and repetitive legal roles and require firms to reconsider staffing, pricing and service models (MARANHÃO, 2024). The prevailing expectation, however, is that AI will reconfigure rather than simply replace legal work (CEPI/FGV Direito SP, 2026).
- Regulatory uncertainty. Brazil has no comprehensive AI statute in force. Questions concerning liability, copyright, AI-generated content, training data and allocation of responsibility remain governed by fragmented rules and, in some cases, remain unsettled.
The principal opportunities are:
- Productivity and competitiveness. AI can reduce the time and cost of routine work and allow smaller practices to provide capabilities previously associated with larger firms. This diffusion is accompanied by a strong perception of efficiency gains (2nd Report on the Impact of AI on Law, 2026).
- New areas of legal practice. Growing demand exists for advice on AI governance, data protection, cybersecurity, discrimination, intellectual property, contracts, liability, employment, competition, procurement and regulatory investigations.
- Greater access to legal services. AI-assisted research, document automation and intake tools may lower costs, improve preliminary guidance and make legal information more accessible (MARANHÃO, 2024).
- Research, drafting and knowledge management. AI can search and summarize legislation, case law, contracts and precedents, compare interpretations and generate initial drafts, freeing lawyers for strategy and complex judgment.
- Data-driven risk management. Predictive analytics can identify patterns in litigation, contracts and judicial decisions, helping lawyers anticipate risks, improve strategy and shift legal work from dispute response toward prevention (MARANHÃO, 2024).
-
Where do you see the most significant legal developments in artificial intelligence in your jurisdiction in the next 12 months? Are there any ongoing initiatives that could reshape AI governance?
The most significant AI developments in Brazil over the next twelve months are likely to arise from regulatory and judicial activity rather than from enactment of comprehensive legislation.
- First, Bill No. 2,338/2023, Brazil’s general AI bill, remains before a Special Committee of the Chamber of Deputies after Senate approval in December 2024. Approval within twelve months is possible but uncertain, particularly given the October 2026 elections, the end of the legislature in January 2027 and the need for renewed Senate consideration if the Chamber amends the text. Even if enacted, implementation would depend on a vacatio legis and subsequent regulation. Existing laws and sectoral rules are therefore likely to remain the principal framework in the near term.
- Second, the National Data Protection Authority (ANPD) is increasingly functioning as a de facto AI regulator. Its 2026–2027 enforcement priorities include AI and emerging technologies, particularly facial recognition and recommender systems. The ANPD is also supervising an AI and data-protection regulatory sandbox running through December 2026. Lessons from the sandbox are expected to inform future AI regulation.
- Third, the October 2026 general elections will provide the first large-scale application of detailed electoral AI rules, after the 2024 municipal elections experience. Superior Electoral Court Resolution No. 23,755/2026 requires prominent labelling of AI-generated or significantly altered content, prohibits certain deepfakes involving candidates, restricts synthetic content around election day and imposes duties on platforms concerning unlawful material. This is likely to generate significant case law on AI disclosure, platform duties and remedies.
- Fourth, implementation of Resolution No. 615/2025 of the National Council of Justice will continue within the judiciary. The Resolution establishes requirements concerning AI governance, risk classification, transparency, auditability and human oversight. The National Committee on Artificial Intelligence of the Judiciary was established as the body responsible for implementation and supervision, including annual assessment.
- Finally, sector-specific regulation, particularly in telecommunications, is likely to advance. National Telecommunications Agency is developing principles for ethical AI use across the telecommunications value chain, including data processing and automated decision-making. Its 2026 consultation (Anatel, Tomada de Subsídios nº 6/2026) follows a regulatory impact assessment favouring a principles-based approach with continuous monitoring. The resulting framework may affect network operators, software suppliers, cloud platforms, data companies and model developers.
Overall, Brazil’s near-term AI governance is likely to develop through the interaction of the ANPD, electoral and judicial authorities, sectoral regulators and existing legislation, while the approval of the general AI bill remains uncertain.
Brazil: Artificial Intelligence
This country-specific Q&A provides an overview of Artificial Intelligence laws and regulations applicable in Brazil.
-
What is the legal definition of “artificial intelligence” in your jurisdiction, if any? If no definition exists, how do regulators or courts typically describe artificial intelligence?
-
Has your country developed a national strategy for artificial intelligence? If yes, what progress has been made in its implementation? Are there plans for updates or revisions?
-
Has your jurisdiction adopted any AI-specific laws, regulations, voluntary standards, or ethical guidelines? If so, please provide a brief overview. If not, which existing laws could be/are applied to artificial intelligence and the use of artificial intelligence, what are the main interpretive challenges, and are there any pending artificial intelligence legislative initiatives?
-
Are there legal requirements for artificial intelligence transparency, explainability, or audits? Are there obligations to disclose the use of artificial intelligence to customers/clients?
-
Are there legal requirements or best practice expectations for human oversight and human-in-the-loop in artificial intelligence systems?
-
Are there specific legal or regulatory requirements addressing algorithmic bias, discrimination, or fairness in AI systems (including gender bias)?
-
What legal frameworks apply to AI-related harm and defective artificial intelligence systems? Who can be held liable (developer, deployer, victim of the damage, others), how is liability allocated, and what burden of proof applies to victims?
-
What cybersecurity obligations apply to AI systems?
-
Is the use of artificial intelligence insured and/or insurable in your jurisdiction, including with cyber policies? Are there market trends, or limitations?
-
Can artificial intelligence be named as an inventor in a patent application filed in your jurisdiction? If not, what is the current legal position?
-
Do images or works generated by and/or with artificial intelligence benefit from copyright protection in your jurisdiction? If so, who is the authorship attributed to, and under what conditions?
-
What are the main issues to consider when using artificial intelligence systems in the workplace? Have any new regulations, or guidelines, been introduced regarding AI-driven hiring, performance assessment, or employee monitoring?
-
What are the main privacy/data protection issues arising from artificial intelligence development and use (including training data)? Have data protection authorities issued guidelines or rulings on artificial intelligence, and what are the key takeaways?
-
How is data scraping regulated in your jurisdiction from an IP, privacy and competition perspective? Are there recent precedents addressing the legality of data scraping for training of artificial intelligence systems?
-
To what extent is the prohibition of data scraping in the terms of use of a website enforceable?
-
Does your country have a regulator or authority responsible for supervising the use and development of artificial intelligence? What are its powers and enforcement tools?
-
How widespread is the adoption of artificial intelligence in businesses in your jurisdiction, and which sectors are leading?
-
How is artificial intelligence used in the legal sector, by lawyers and/or in-house counsels? Are AI-driven legal tools widely adopted, and what are the main regulatory concerns?
-
What are the 5 key challenges and the 5 key opportunities raised by artificial intelligence for lawyers in your jurisdiction?
-
Where do you see the most significant legal developments in artificial intelligence in your jurisdiction in the next 12 months? Are there any ongoing initiatives that could reshape AI governance?