Brazil Is Not Waiting for an AI Act: The Layered Regulation of Algorithmic Power and the Cost of Waiting

Brazil has no general artificial intelligence statute. It nevertheless has an artificial intelligence legal order.

That distinction is not rhetorical. It determines how companies should design, deploy, contract and defend AI systems in Latin America’s largest digital market. The most expensive misconception we encounter in Brazilian and foreign boardrooms is the assumption that, because Bill No. 2,338/2023 has not yet been enacted, AI remains effectively unregulated in Brazil and corporate governance can wait. Every part of that assumption is wrong.

Personal data is already regulated. Automated decisions are already regulated. Consumer products and services are already subject to liability rules. Financial institutions, healthcare companies, telecommunications operators and other regulated entities already face sector-specific duties concerning models, outsourcing, cybersecurity, operational resilience and third-party risk. The judiciary has regulated its own use of AI. The Brazilian Bar has begun constructing the professional governance framework that will apply to more than one million lawyers. The Electoral Justice has imposed rules on synthetic political content. Courts already have the legal instruments required to allocate liability when algorithmic systems cause harm.

The absence of a single statute is therefore the absence of a single map, not the absence of law.

This point matters because AI did not enter the Brazilian legal system through legislation. It entered through practice. It entered law firms, courts, public authorities, banks, technology companies, employment processes, credit decisions, healthcare systems and consumer services before the legal system had completed a unified theoretical or statutory response. Regulation is now being assembled around technology that is already embedded in the economy.

The Brazilian debate frequently oscillates between two equally inadequate positions. On one side is bureaucratic fear, which seeks to prohibit, delay or over-document technology that public institutions do not yet fully understand. On the other is irresponsible enthusiasm, which assumes that innovation is self-justifying and that accountability can be addressed after scale has been achieved. The first position produces formalism, barriers to entry and artificial security. The second scales error, discrimination, fraud and opacity.

The correct legal question is not whether AI is good or bad. AI is an instrument. The legally relevant questions concern purpose, context, power, control and responsibility: what is the system being used for, whose rights may be affected, what data supports its operation, who has authority to intervene, what evidence demonstrates diligence, and who answers when the system fails?

This is the perspective from which MPUPPE & ASSOCIADOS, advises companies, regulated entities and international investors entering or expanding in Brazil. AI cannot be treated exclusively as a technology issue, a privacy issue or a contractual issue. It is a problem of legal and institutional architecture. It requires the integration of data protection, civil liability, consumer law, sector regulation, cybersecurity, intellectual property, corporate governance and international technology contracting.

The law is a meta-technology. Its function is not to compete with technological development, but to organise the conditions under which technological power may legitimately operate. In the AI context, this means creating rights, responsibilities, evidence, review mechanisms and institutional limits that remain effective even as models, architectures and capabilities change.

Technology without governance scales abuse. Governance without technical understanding scales bureaucracy. The challenge is to avoid both.

Brazil’s layered AI legal order

Brazilian AI law is best understood by function, not by label.

A system used to screen candidates for employment is not merely an AI application. It is an employment decision mechanism, a personal data processing operation and a potential source of discrimination. A credit model is simultaneously a financial model, a consumer service and an automated decision governed by data protection law. Clinical decision software may fall within health regulation and medical device requirements. A judicial AI tool is governed by the National Council of Justice. Synthetic political media falls within electoral regulation. A generative assistant offered to consumers may engage privacy, advertising, accessibility, consumer protection, intellectual property and cybersecurity obligations at the same time.

AI is not a sector. It is a layer that crosses multiple sectors and legal relationships. That is why the Brazilian legal order has developed through overlapping regimes rather than through a single regulatory instrument.

The first layer is constitutional. Human dignity, equality, privacy, freedom of expression, access to justice, due process and non-discrimination apply regardless of whether a decision is made by a human being, an algorithm or a hybrid process. The Constitution does not need to mention machine learning for constitutional rights to constrain the use of machine learning. Technology changes the mechanism through which power is exercised, but it does not remove that power from constitutional scrutiny.

The second and most immediate layer is the General Data Protection Law, Law No. 13,709/2018, the LGPD. Most commercially relevant AI systems process personal data during at least one of three stages: training, operation or output. Training datasets may contain personal information collected from public or private sources. Operational inputs may include prompts, documents, images, voice recordings, customer information and connected databases. Outputs may include profiles, scores, recommendations, classifications, predictions and inferences about identifiable individuals.

Where personal data is processed, the LGPD applies. The organisation must establish a lawful basis, define a legitimate and specific purpose, limit processing to what is necessary, provide meaningful transparency, adopt security measures, respect data subject rights and demonstrate accountability. These duties exist today. They do not depend on the enactment of a future AI statute.

The third layer consists of the Consumer Defence Code and the Civil Code. AI-enabled products and services do not leave the ordinary liability system merely because their operation is probabilistic, complex or partially autonomous. A defective recommendation, discriminatory model, misleading chatbot, unsafe automated service or agent that exceeds its authority may create liability through legal doctrines that have existed for decades.

In consumer relationships, suppliers may face strict liability for defective products and services, subject to the statutory defences. The central question is whether the service or product provided the safety and reliability that consumers could legitimately expect, considering its presentation, foreseeable use and disclosed limitations. The fact that the provider used a sophisticated model does not itself constitute a defence.

Outside consumer relationships, the Civil Code provides fault-based liability and, in defined circumstances, objective liability where the activity normally developed creates a particular risk to the rights of others. Labour, public, professional and sector-specific rules may add further duties.

The fourth layer is sector regulation. Financial institutions, payment companies, insurers, capital markets participants, healthcare businesses, telecommunications companies and other regulated entities already operate under governance, security, outsourcing, model validation, suitability, continuity and operational risk obligations. Regulators do not need to issue a rule containing the words “artificial intelligence” to supervise an AI system used within an activity that is already regulated.

A bank’s credit model remains a credit model. A securities firm’s automated recommendation remains subject to suitability and fiduciary expectations. An AI system used in healthcare may be examined through the regulatory perimeter applicable to software as a medical device. An autonomous system used by a payment institution remains part of the institution’s operational, cybersecurity and outsourcing risk.

For regulated entities, AI governance should therefore be integrated into existing risk frameworks. Creating an isolated “AI compliance programme” disconnected from model risk, information security, outsourcing and board governance is usually inefficient and may create contradictions. Regulators are more likely to trust an organisation that can explain how AI fits within established controls than an organisation that presents a generic ethics policy and no operational evidence.

The fifth layer is institutional regulation. Brazil’s justice system has moved before the general legislature. National Council of Justice Resolution No. 615/2025 establishes a comprehensive framework for the development, procurement, use and governance of AI within the judiciary. It addresses risk classification, human supervision, transparency, auditability, testing, documentation, impact assessment, logging and the use of generative AI.

The Resolution is formally directed at the judiciary, but its influence is broader. It is currently one of the most detailed AI governance instruments in force in Brazil. It provides litigants, lawyers, public authorities and private organisations with a concrete indication of what Brazilian institutions consider adequate AI governance. It also matters because future AI disputes will be decided by courts that are themselves learning to operate under algorithmic governance requirements.

The Federal Council of the Brazilian Bar has created another institutional layer. In 2024, it approved recommendations on the use of generative AI in legal practice, addressing applicable law, confidentiality, privacy, professional ethics and communication concerning AI use. In June 2026, it announced the National Plan for the Integration of Artificial Intelligence into the Legal Profession, organised around governance and good practices, nationwide professional training, modernisation of the Bar’s services, protection of professional prerogatives and support for young lawyers.

A national survey developed with Stanford University will map how Brazilian lawyers use AI and will support the preparation of a future binding professional regulation. MPUPPE & ASSOCIADOS is directly connected to this institutional construction through Matheus Puppe’s role as Data Protection Officer of the Federal Council and through the firm’s work on AI governance, data protection and professional responsibility.

The fundamental principle is simple: AI can support professional work, but it cannot absorb professional responsibility. The lawyer who signs a petition, contract, opinion or communication remains responsible for its content. The machine is not an author in the legal or ethical sense. It is a tool. The use of AI is not, by itself, professional misconduct. Failure to verify a material output may constitute negligence. Presenting content known to be false may constitute intentional misconduct.

The sixth layer is private normativity. Global AI is governed not only by legislation and public authorities, but also by contracts, platform policies, technical standards, insurance conditions, cloud-provider rules, model licences, procurement requirements and audit frameworks. The terms of use of a foundation model can prohibit activities that national legislation has not yet addressed. A cloud provider can suspend access. An app store can remove a product. A payment provider can terminate processing. A multinational customer can impose ISO, NIST or EU AI Act-based requirements through procurement.

This private regulatory environment operates at the speed of technological deployment, while legislation operates at the speed of institutional process. Ignoring it is a legal mistake. The correct response is not to replace private governance with total state control. It is to anchor private normativity in public duties concerning transparency, fairness, due process, accountability and responsibility.

This is the Brazilian regulatory path that deserves greater attention: regulated self-regulation supported by public anchors. The State defines fundamental rights, minimum duties, responsibility, evidence, sanctions and institutional coordination. Sector regulators translate those duties into specific contexts. Technical standards provide operational methods. Contracts harden expectations between private actors. Audits verify compliance. Courts allocate responsibility when governance fails.

Brazil does not need a single super-regulator capable of understanding every application of AI. It needs coordinated authorities, technically competent sector regulators and a clear centre of institutional gravity. The ANPD is the natural coordinating authority because most relevant systems process personal data and because the authority already possesses experience with accountability, impact assessments, regulatory guidance and enforcement. Coordination, however, should not eliminate sector expertise.

The country must also recognise that regulation is only part of an AI strategy. Law can require transparency, but it cannot create computing capacity. Law can require impact assessments, but it cannot train auditors. Law can establish rights, but it cannot by itself produce Portuguese-language models, public datasets, research infrastructure or technological independence.

The Brazilian Artificial Intelligence Plan for 2024 to 2028 contemplates approximately R$23 billion in public and private investment in computing infrastructure, research, national capabilities, public services, professional training and innovation. The Federal Government is also developing shared AI tools and governance resources for public administration.

This public investment agenda should not be treated as secondary to regulation. AI is simultaneously a rights issue, an industrial policy issue and a sovereignty issue. Brazil cannot aspire to regulate algorithmic power while remaining completely dependent on foreign models, foreign clouds, foreign chips and foreign infrastructure. At the same time, sovereignty cannot become a pretext for inefficient protectionism or forced isolation.

The objective should be strategic autonomy: the capacity to understand, audit, contract, adapt and, where economically justified, develop AI infrastructure. Foreign investors that approach Brazil through local partnerships, governance transfer, training, security and credible processing options will be better aligned with this agenda than companies that treat the country solely as a distribution market.

The risk of AI must be taken seriously. The risk of not using AI must also be recognised. A healthcare system that refuses responsible AI may preserve inefficient queues. A judiciary that refuses technological support may perpetuate delay. A public administration that does not use data and automation may maintain unequal access to services. Regulation should therefore govern adoption, not simply constrain it.

The pending framework, enforcement and the unresolved fronts

Bill No. 2,338/2023 remains the principal proposal for a general Brazilian AI framework. The Federal Senate approved a substitute text on 10 December 2024. The proposal then moved to the Chamber of Deputies, which created a Special Committee and conducted an extensive programme of public hearings. As at 10 August 2026, the Bill remains before the Committee, awaiting the rapporteur’s opinion, with more than thirty related proposals attached to it, including Executive Bill No. 6,237/2025, which proposes a National System for the Development, Regulation and Governance of Artificial Intelligence.

The delay does not reflect legislative inactivity. It reflects substantive conflict.

The proposed framework affects powerful economic and institutional interests. The creative industries, technology providers, financial institutions, employers, public authorities, civil society organisations, research institutions and regulators do not agree on every point. The most difficult questions concern who regulates, who pays, who proves, who receives remuneration and who is liable.

The 2026 general election also affects the legislative calendar. Comprehensive technology statutes with organised opposition rarely move quickly during a campaign year. The timing of enactment is therefore less predictable than the substance of the law’s stable core.

That stable core is already visible. Every serious version of the proposal includes a risk-based architecture, restrictions or prohibitions for certain uses, enhanced duties for high-risk systems, transparency requirements, governance obligations, documentation, impact assessment, incident management and a coordinating role for the ANPD alongside sector regulators.

The proposal is influenced by the European Union’s AI Act, but it is not merely a translation. It operates within a different constitutional, procedural, consumer and institutional environment. Brazil has a claimant-friendly consumer protection regime, broad collective redress, strong public prosecutors and regulatory institutions with different levels of technical capacity. A European obligation transplanted into Brazil may therefore have different enforcement consequences.

Brazil should resist the temptation to import the administrative cost of Europe without the European market, infrastructure and enforcement capacity. It should also reject the opposite simplification, under which innovation is treated as a sufficient substitute for accountability. The appropriate model must be proportionate, technically executable and compatible with Brazilian institutional reality.

A good AI law should regulate functions, positions and effects, not freeze contemporary technical architectures into statutory definitions. A law based on neural networks, transformers or the current model market will age quickly. A law that distinguishes who develops a general capability, who adapts it, who deploys it in a consequential context and who signs or benefits from the resulting decision can remain effective across technological generations.

Three legislative fronts remain genuinely open.

The first concerns institutional design. The centrality of the ANPD appears likely, but the extent of its authority, the role of sector regulators and the structure of the proposed national system remain under negotiation. The correct design is coordination without duplication. A national authority should establish common principles, terminology, procedures and minimum standards, while sector regulators retain responsibility for the specific risks of finance, health, telecommunications, employment, public services and other areas.

The second concerns civil liability and evidence. The interaction between the future AI framework, the Consumer Defence Code, the Civil Code and procedural rules remains politically and legally sensitive. A highly prescriptive statutory liability model may produce unintended effects, including excessive insurance costs, barriers to entry and concentration in favour of large providers. An excessively protective model may shift the economic cost of algorithmic harm to consumers, workers and affected individuals who lack access to the relevant evidence.

The solution should follow the chain of control. Model providers, data suppliers, integrators, deployers, distributors and professional users make different decisions and control different risks. Liability should not be allocated through slogans. It should be linked to the actor’s role, knowledge, control, benefit and failure to comply with the diligence expected from that position.

The third and most economically contested front concerns copyright and training data. Brazilian Copyright Law, Law No. 9,610/1998, contains no express text and data mining exception for commercial AI training. The fact that a work is publicly accessible does not mean that it is free from copyright, contractual restrictions or data protection requirements.

The Senate-approved text attempted to address the issue. It contemplated a limited non-commercial mining permission for certain research, cultural, educational and journalistic uses, subject to conditions. It also opened the possibility of opposition by rightsholders and remuneration when protected content is used in the development of commercially available AI systems.

The creative industries argue that human works should not be absorbed into commercial models without transparency and economic participation. Technology companies argue that an administratively complex remuneration regime could make the development of national models economically impracticable and push training activities to other jurisdictions.

Both concerns are legitimate. A framework that denies all economic recognition to rightsholders may externalise the cost of model development. A framework that imposes transaction costs incompatible with mass training may reinforce the market position of the largest international companies, which are better able to negotiate licences and absorb compliance costs.

Until Congress resolves the issue, training-data provenance should be treated as a legal, technical and contractual risk. Developers should document data sources, permissions, licences, filtering methods, opt-out procedures and removal mechanisms. Customers should not accept total downstream responsibility where the provider supplies no meaningful information concerning upstream data. Rightsholders and content businesses should also recognise the commercial opportunity: curated, reliable and lawfully licensed datasets may become valuable assets in specialised AI markets.

The legislative uncertainty does not justify inactivity. The correct planning rule is to build for the stable core and contract for the open margins.

Inventory, risk classification, impact assessment, traceability, human oversight, security, incident response and governance correspond to existing duties and to the common denominator of the proposed framework. Liability, copyright and institutional allocation should be addressed through scenario analysis, warranties, audit rights, indemnities, insurance and regulatory engagement until the law becomes final.

The LGPD is already the most important source of operational AI obligations.

The ANPD’s action concerning Meta’s generative AI training plan demonstrated that model training is a personal data processing operation subject to Brazilian law. In July 2024, the authority imposed a preventive suspension on the use of Brazilian users’ personal data for training. Processing was later permitted to resume after a compliance plan and additional restrictions were accepted.

The precedent should not be reduced to the statement that training is prohibited or that legitimate interest is unavailable. Its structural lesson is more important. Legitimate interest is not self-authorisation. It requires a documented balancing analysis, a legitimate and specific purpose, necessity, reasonable expectations, effective transparency, functioning rights and safeguards proportionate to the nature of the data and the affected individuals.

Sensitive data, children’s data, biometric information and large-scale public scraping require enhanced scrutiny. The presence of personal data within a mass dataset cannot be ignored merely because the provider describes the corpus as public or unstructured. The company that purchases a dataset also does not acquire compliance by contract. A contractual warranty may allocate economic recourse, but it does not eliminate the purchaser’s duty to conduct reasonable due diligence.

Article 20 of the LGPD is another central provision. It grants individuals the right to request review of decisions taken solely on the basis of automated processing that affect their interests, including profiling for personal, professional, consumer and credit purposes.

The concept of meaningful review must be distinguished from nominal human involvement. A human reviewer must receive adequate information, have sufficient time, possess the technical or professional competence required to evaluate the result, and have real authority to disagree with or reverse the system. A person who is pressured to approve hundreds of outputs that they do not understand is not exercising human oversight. They are providing a human signature to an automated decision.

The ANPD has signalled that these issues will be enforced. AI and emerging technologies are among the authority’s priority themes for the 2026 to 2027 period. Article 20 has been the subject of regulatory evidence gathering. The authority is also conducting a pilot regulatory sandbox focused on AI, data protection and algorithmic transparency, with selected companies operating in supervised testing.

The sandbox is not a compliance exemption. It is a method of supervised experimentation. Participants obtain a structured environment in which certain regulatory questions can be tested, while the authority receives data, evidence and technical learning. The results will influence future regulatory practice. Companies outside the sandbox should therefore monitor not only its final conclusions, but also the methods, metrics and documentation the ANPD considers relevant.

Liability is also moving independently of the AI Bill.

In 2025, the Supreme Federal Court reconsidered the liability regime applicable to digital platforms under Article 19 of the Internet Civil Framework. The judgment did not concern AI directly, and it should not be described as an AI precedent. Its broader institutional significance is nevertheless clear: the Court is prepared to recalibrate the responsibility of digital intermediaries through constitutional interpretation when it considers existing legal protections insufficient.

AI providers should therefore not assume that courts will wait for a specific statute before assigning responsibility. Generative systems that cause defamation, facilitate fraud, produce discriminatory results, create misleading consumer interactions or enable synthetic abuse can be analysed through existing constitutional, civil, consumer and procedural doctrines.

Brazil’s collective redress system increases that exposure. Public prosecutors, consumer protection bodies and representative entities can pursue public civil actions affecting large groups of consumers or data subjects. Foreign providers frequently underestimate this procedural dimension. Exposure is not limited to a single claimant, a single contract or a single fine.

The quality of evidence may determine the result. Courts and regulators will ask what was tested, what limitations were known, what was disclosed, which alternatives were considered, who approved deployment, which safeguards were implemented, how anomalies were handled and whether logs were preserved. In a technically asymmetric dispute, the organisation that controlled the system may be expected to produce the evidence necessary to explain its operation and governance.

Governance must therefore produce proof, not paper. A policy that is not connected to system access, procurement, development, testing, incident response and board approval has limited evidentiary value. A governance file should be created through the system’s lifecycle, not reconstructed after a regulatory notice or statement of claim.

The Brazilian judiciary’s own governance framework reinforces this logic. CNJ Resolution No. 615/2025 requires risk classification, impact analysis, traceability, security, human supervision and accountability. It also regulates generative AI within judicial activities. These requirements establish a vocabulary that will influence how judges evaluate private governance.

The Electoral Justice has adopted a similarly functional approach. Superior Electoral Court rules for the 2026 elections address the use of synthetic content, disclosure requirements and restrictions on content that reproduces the image, voice or manifestation of candidates and public figures. The electoral context will become a major test of provenance, platform response, forensic evidence and rapid institutional coordination.

The Bar’s work completes this institutional triangle. Courts, lawyers and electoral authorities are all developing AI governance before the general statute. Companies should understand the implication: the institutions that will investigate, litigate and decide AI disputes are already defining their own standards of diligence.

Governance as legal and competitive infrastructure

The practical question for companies is not whether they should wait for Bill No. 2,338/2023. It is what they should build now.

The first requirement is a system inventory. Every AI system in development or use should be identified, including features embedded in vendor software and shadow AI adopted by employees or business units without formal approval. The inventory should record the system’s purpose, provider, model, data, integrations, users, affected individuals, jurisdictions, decision impact, business owner and technical owner.

An organisation cannot govern what it has chosen not to see.

The second requirement is risk and rights classification. Classification should be based on the system’s actual effects, not on the supplier’s description. Systems affecting employment, credit, health, education, insurance, access to essential services, public benefits, biometrics, children, safety or legal rights require enhanced controls. Public-facing generative systems, autonomous agents and systems capable of producing synthetic media also require specific governance.

Risk classification should determine the level of approval, testing, documentation, monitoring and human review required. It should also be connected to rights analysis. Privacy, equality, consumer protection, labour rights, intellectual property, freedom of expression, accessibility and the protection of vulnerable groups cannot be treated as separate afterthoughts.

The third requirement is an evidence architecture. The organisation should maintain a documentation spine that follows the system through design, procurement, development, deployment, monitoring and termination. That spine should include legal basis assessments, data provenance, technical documentation, model and version information, validation, bias testing, security testing, limitations, impact assessments, approvals, exceptions, complaints, incidents and corrective action.

The objective is not maximum documentation. It is relevant documentation generated by actual decisions and controls. Generic templates completed after the fact often create more risk than protection because they expose the distance between the organisation’s formal narrative and its operational reality.

The fourth requirement is meaningful human authority. Governance should identify who can approve, suspend, override and terminate a system. Autonomous and agentic systems require explicit authority limits, financial thresholds, approved counterparties, confirmation rules, escalation triggers, logging, a kill switch and procedures for reversing actions already initiated.

Human involvement must not become a regulatory decoration. The relevant person or committee must have information, competence, time and authority. Responsibility should be attached to identifiable positions. Our practical rule is direct: who signs, answers.

The fifth requirement is contractual engineering. AI risk exists across the supply chain whether the parties address it or not. Contracts should identify the respective roles of model providers, data suppliers, integrators, deployers, distributors and users. They should address data use, training, confidentiality, security, intellectual property, output rights, model changes, audit, regulatory cooperation, subprocessors, incidents, service continuity, liability, indemnities, insurance, portability and termination.

Liability caps should be tested against mandatory consumer and data protection rules that the parties may not be able to exclude. Audit and information rights should be proportionate to the customer’s regulatory exposure. A financial institution or healthcare operator cannot reasonably accept the same level of opacity as a low-risk commercial user.

Concentration risk also matters. Dependence on a small number of foundation model providers creates operational, contractual and strategic vulnerability. A change in price, acceptable use policy, model behaviour, geographic availability or data processing terms can affect an entire product. Portability, continuity and exit planning are therefore components of legal governance.

Cross-border data transfers require additional attention. Brazil does not impose a general obligation to host all personal data locally, but international transfers must comply with the LGPD and the mechanisms recognised by the ANPD. The use of foreign cloud and model providers should be mapped through contractual arrangements, transfer mechanisms, security assessments and vendor governance.

The sixth requirement is board-level responsibility. AI should not be treated solely as an IT matter. Governance requires the participation of legal, compliance, data protection, information security, technology, business, internal audit and senior management. Depending on the organisation’s scale, the structure may include a Chief AI Officer or a designated executive responsible for AI governance.

The board should receive information proportionate to the organisation’s exposure. This may include the number and classification of systems, material incidents, high-risk approvals, vendor concentration, regulatory developments, complaints, litigation and remediation. Directors’ duties of diligence apply to algorithmic operations in the same manner that they apply to other material business risks.

The seventh requirement is integrated incident response. AI incidents frequently cross legal categories. A single event may involve a personal data breach, discriminatory decision, consumer harm, cybersecurity failure, intellectual property claim and contractual default. The organisation should not create five disconnected response processes. AI incidents should be integrated into existing privacy, cybersecurity, consumer and operational risk frameworks, with defined escalation and regulator communication.

Regulatory engagement should occur before a crisis where possible. A regulator that first learns about a material system through an incident is placed in an adversarial position. A regulator that receives a disciplined, technically informed and evidence-based explanation may become a source of predictability.

For international groups, the European overlay must also be integrated. The EU AI Act is already in phased application, with obligations for general-purpose models and specified transparency requirements now relevant, while the principal high-risk duties follow the later legislative timetable. Brazilian companies that place systems in the European market, supply European groups or generate outputs used in the European Union may fall within its scope.

The efficient response is not to build one Brazilian programme and a separate European programme. It is to build a single governance backbone and map jurisdiction-specific requirements onto it. The common backbone should contain inventory, roles, risk classification, data governance, documentation, testing, human oversight, transparency, incident response, vendor management and senior governance.

Brazilian law then adds its specific requirements concerning LGPD legal bases, Article 20 review, consumer liability, collective redress, professional duties and sector regulation. European law adds provider, deployer, general-purpose AI, transparency, market access and high-risk obligations. The systems should be interoperable, but they should not be treated as legally identical.

This is where the association between MPUPPE & ASSOCIADOS and ECIJA provides practical value. International AI matters require more than a sequence of disconnected local opinions. They require a coherent architecture capable of operating across Brazil, Europe and other relevant markets while preserving the specific legal analysis required in each jurisdiction.

The role of specialist counsel is not to produce the longest policy or the most conservative answer. It is to help the client distinguish what is prohibited, what is permissible, what is uncertain, what requires mitigation and what can become a competitive advantage. It is also to convert those conclusions into contracts, approval mechanisms, evidence and operational controls.

Governance is often described as a cost. That description is incomplete. Effective AI governance reduces the time required for procurement, investment, financing, insurance and due diligence. It improves the organisation’s ability to answer customers, regulators, auditors and boards. It creates evidence before disputes arise. It permits faster adoption because the company understands where the boundaries are.

Regulatory trust is an economic asset.

Brazil should no longer be described as a jurisdiction waiting for an AI law. It has already constructed a layered legal order in which the LGPD regulates data and automated decisions, general liability law reaches algorithmic harm, sector authorities supervise AI through established perimeters, the judiciary and the legal profession govern their own transformation, the Electoral Justice regulates synthetic political content, private standards shape market access and the State invests in technological capacity.

Bill No. 2,338/2023 remains important. It can coordinate institutions, standardise impact assessment, strengthen enforcement and provide greater legal certainty. It can also fail if it duplicates regulators, creates obligations without supervisory capacity or fixes technical concepts that become obsolete before implementation.

The statute, when enacted, will consolidate the Brazilian model. It will not create it.

For companies, the strategic conclusion is immediate. Every quarter spent waiting for perfect legislative certainty is a quarter in which ungoverned systems multiply, data flows harden, vendor dependence increases and the cost of correction grows. Competitors that act earlier accumulate assets that cannot be purchased after an incident: reliable records, trained decision-makers, tested escalation mechanisms, contractual leverage and regulator trust.

MPUPPE & ASSOCIADOS, approaches AI as legal, institutional and economic architecture. The objective is to make systems deployable, financeable, scalable, auditable and defensible in Brazil while preserving the ability to operate internationally.

The decision to use AI has already been made across businesses, governments and professions. The decision that remains is whether to govern it with technical competence and human responsibility or to pay later through scandal, litigation and bureaucratic retrofit.