{"id":147278,"date":"2026-08-12T12:34:32","date_gmt":"2026-08-12T12:34:32","guid":{"rendered":"https:\/\/my.legal500.com\/guides\/?post_type=legal-landscapes&#038;p=147278"},"modified":"2026-08-12T12:34:32","modified_gmt":"2026-08-12T12:34:32","slug":"brazil-artificial-intelligence","status":"publish","type":"legal-landscapes","link":"https:\/\/my.legal500.com\/guides\/legal-landscapes\/brazil-artificial-intelligence\/","title":{"rendered":"Brazil- Artificial Intelligence"},"content":{"rendered":"<h4><strong>1. What is the current legal landscape for Artificial Intelligence in your jurisdiction?<\/strong><\/h4>\n<p>Brazil does not yet have a general artificial intelligence statute, but it is not an unregulated AI market. Treating the country as one is the most expensive mistake a client can make. AI in Brazil is already governed through overlapping legal and institutional layers, and those layers have enforcement mechanisms.<\/p>\n<p>The principal horizontal layer is the General Data Protection Law, the LGPD. Most commercially relevant AI systems process personal data during training, operation or output. That processing requires a lawful basis, purpose limitation, necessity, meaningful transparency, security, respect for data subject rights and accountability. The LGPD therefore functions, in practice, as Brazil\u2019s first AI law.<\/p>\n<p>The National Data Protection Authority confirmed the importance of this framework in the Meta generative AI training matter. In July 2024, the ANPD preventively suspended the use of Brazilian users\u2019 personal data for model training. Processing was later permitted to resume after a compliance plan and additional restrictions were accepted. The precedent established that model training is a personal data processing operation and that legitimate interest cannot be treated as self-authorisation. It requires a documented balancing analysis, transparency, functioning rights and proportionate safeguards.<\/p>\n<p>Article 20 of the LGPD already grants individuals the right to request review of decisions taken solely on the basis of automated processing that affect their interests, including decisions concerning credit, employment, consumption and profiling. The ANPD is preparing regulatory guidance on automated decision-making and has placed AI and emerging technologies among its enforcement priorities for the 2026 to 2027 period.<\/p>\n<p>The authority is also conducting a regulatory sandbox focused on AI, data protection and algorithmic transparency. Selected companies entered supervised testing in March 2026, and the authority published an initial monitoring report in July. The sandbox is important because it reveals the ANPD\u2019s regulatory method: supervised experimentation, evidence, technical dialogue and the conversion of practical findings into future regulation.<\/p>\n<p>The second layer is civil and consumer liability. The Consumer Defence Code imposes strict liability on suppliers for defective products and services, subject to the statutory defences. The regime does not cease to apply because the defect is algorithmic. A misleading chatbot, discriminatory recommendation, unsafe automated service or system that exceeds its disclosed function may create liability under rules that already exist.<\/p>\n<p>Outside consumer relationships, the Civil Code provides fault-based liability and, in defined circumstances, objective liability for risky activities. Labour, public, professional and sector-specific regimes may add further duties. Brazil also has effective collective redress through public civil actions, public prosecutors, consumer bodies and representative entities. Foreign providers frequently underestimate the possibility that one AI incident may become a collective rather than an individual dispute.<\/p>\n<p>The Supreme Federal Court\u2019s 2025 judgment concerning Article 19 of the Internet Civil Framework is also relevant. It was not an AI judgment, but it demonstrated that the Court is willing to recalibrate the responsibility of digital intermediaries through constitutional interpretation when existing rules are considered insufficient to protect fundamental rights. AI providers should not assume that Brazilian courts will wait for a specific statute before allocating responsibility.<\/p>\n<p>The third layer is sector regulation. Financial, securities, insurance, health, telecommunications and other regulators already supervise AI through existing rules concerning models, cybersecurity, outsourcing, operational resilience, suitability, professional conduct, safety and third-party risk. A bank\u2019s AI credit model remains a regulated credit model. A healthcare system may fall within the medical-device perimeter. An automated investment recommendation remains subject to securities and suitability rules.<\/p>\n<p>The fourth layer is institutional. National Council of Justice Resolution No. 615\/2025 establishes a comprehensive AI governance framework for the Brazilian judiciary. It addresses risk classification, human oversight, documentation, impact assessment, security, auditability, logging and generative AI. It is currently one of the most detailed AI governance instruments in force in Brazil and already influences procurement, compliance benchmarking and legal debate outside the judiciary.<\/p>\n<p>The Federal Council of the Brazilian Bar approved recommendations on generative AI in legal practice in 2024 and launched the National Plan for the Integration of Artificial Intelligence into the Legal Profession in June 2026. The Plan addresses governance, professional training, modernisation of the Bar\u2019s services, protection of professional prerogatives and support for young lawyers. A national survey developed with Stanford University will inform a future binding regulation.<\/p>\n<p>The Electoral Justice has also introduced specific rules for AI-generated and synthetic political content in the 2026 elections. These rules address disclosure, prohibited uses, platform response and the manipulation of images and voices. The election will be an important test of content provenance, forensic evidence and rapid regulatory enforcement.<\/p>\n<p>The fifth layer is Bill No. 2,338\/2023. The Senate approved the proposal in December 2024. As at 10 August 2026, it remains before a Special Committee of the Chamber of Deputies, awaiting the rapporteur\u2019s opinion, with more than thirty related bills attached, including an Executive proposal for a national AI governance system.<\/p>\n<p>The Bill\u2019s stable core is increasingly predictable: risk-based classification, restrictions on specified applications, enhanced duties for high-risk systems, rights for affected individuals, documentation, impact assessment, transparency, incident management, obligations concerning generative and general-purpose AI, and coordination centred on the ANPD alongside sector authorities.<\/p>\n<p>The principal open fronts are institutional design, civil liability and copyright. The timing of enactment is uncertain, particularly during a general election year. The substance of the future law\u2019s stable core is not.<\/p>\n<p>Finally, the Brazilian State is an active builder of AI, not merely a regulator. The Brazilian Artificial Intelligence Plan for 2024 to 2028 contemplates approximately R$23 billion in public and private investment in infrastructure, research, national capabilities, public services and innovation.<\/p>\n<p>Brazil is therefore neither lawless nor finished. It is a layered jurisdiction in which existing law, sector regulation, institutional governance and a future framework statute must be analysed together. That complexity is precisely where specialised legal advice creates value.<\/p>\n<h4><strong style=\"font-size: 1rem\">2. What three essential pieces of advice would you give to clients involved in Artificial Intelligence matters?<\/strong><\/h4>\n<p>First, stop waiting for the AI Act and map the systems that already exist within the organisation.<\/p>\n<p>The initial legal deliverable should be a complete inventory of AI systems in development or use, including embedded vendor features and shadow AI adopted without formal approval. Each system should be mapped by purpose, provider, model, data, integrations, users, affected persons, jurisdictions, decision impact and named ownership.<\/p>\n<p>The organisation should then classify systems by actual effect, not by marketing description. Systems that influence employment, credit, health, education, insurance, biometrics, children, public services, safety or legal rights require enhanced governance. Public-facing generative systems, synthetic media tools and autonomous agents also require specific controls.<\/p>\n<p>The future Brazilian statute will almost certainly require inventory, classification, documentation, impact assessment and human oversight. Those duties also overlap with obligations that already exist under the LGPD, consumer law and sector regulation. A company that builds now will absorb the future law through mapping and adjustment. A company that waits will retrofit under pressure, after systems and contracts have become expensive to change.<\/p>\n<p>Second, treat documentation as a primary legal asset.<\/p>\n<p>In Brazilian AI enforcement and litigation, the decisive question will often be whether the organisation can prove that it acted diligently. Regulators and courts will ask what the system was intended to do, which data supported it, what was tested, which limitations were known, what was disclosed, who approved deployment, how human intervention operated and what happened after an anomaly.<\/p>\n<p>The answer should not depend on reconstructing events after a dispute. The organisation should maintain an evidence architecture that includes legal basis assessments, data provenance, validation, bias and security testing, impact assessments, model and version records, human oversight, approvals, exceptions, complaints, incidents and corrective action.<\/p>\n<p>Human review must be meaningful. The reviewer needs adequate information, sufficient time, relevant competence and actual authority to reverse the result. A person who merely confirms the machine\u2019s output is not exercising oversight. They are providing a human signature to an automated process.<\/p>\n<p>Third, engineer the supply chain contractually.<\/p>\n<p>Brazilian law will allocate risk even when the parties do not. Contracts should therefore address the roles and responsibilities of model providers, data suppliers, integrators, deployers, distributors and users. They should include provisions on data use, training, confidentiality, security, intellectual property, output rights, audit, regulatory cooperation, subcontractors, model changes, incident response, liability, indemnities, insurance, continuity, portability and termination.<\/p>\n<p>Customers should not accept total downstream responsibility when upstream providers offer no meaningful information about training data, testing, limitations or material model changes. Liability caps should be stress-tested against mandatory consumer and data protection rules that may not be contractually excluded.<\/p>\n<p>For regulated entities, AI governance should be integrated into existing model risk, operational risk, outsourcing and cybersecurity frameworks. Early, documented engagement with the competent regulator is generally preferable to regulatory surprise. In Brazil, the regulator that learns about a system only after an incident is likely to become an adversary. The regulator that receives a disciplined and technically credible explanation can become a source of predictability.<\/p>\n<h4><strong style=\"font-size: 1rem\">3. What are the greatest threats and opportunities in Artificial Intelligence law in the next 12 months?<\/strong><\/h4>\n<p>The principal threat is concentrated uncertainty at the exact points where economic value and legal exposure are allocated.<\/p>\n<p>The Chamber of Deputies must still resolve the most contested elements of Bill No. 2,338\/2023. These include the civil liability regime, the copyright and training-data remuneration model, and the institutional design of the national AI governance system. Each of those issues can materially affect development costs, insurance, contracting, enforcement and market concentration.<\/p>\n<p>The second threat is enforcement under laws that are already in force. AI is an ANPD priority for the 2026 to 2027 period. The authority\u2019s sandbox will generate findings that influence future supervision and regulation. Significant enforcement matters are likely to focus on legal bases, transparency, automated decisions, children\u2019s data, biometrics, discrimination, data subject rights and the distance between public claims of responsible AI and the organisation\u2019s actual controls.<\/p>\n<p>The third threat is the 2026 general election. Synthetic media, deepfakes, manipulated voices and automated political content create risks concerning disclosure, platform response, reputational damage, fraud and democratic integrity. A major incident may generate accelerated enforcement and reactive legislative proposals. Companies involved in media, advertising, platforms, public affairs and content generation should have provenance, escalation and forensic preservation procedures in place before an incident.<\/p>\n<p>The fourth threat is litigation. The post-2025 constitutional environment concerning digital intermediary liability may encourage plaintiffs to test AI providers through consumer, civil, constitutional and collective claims. The organisation that lacks logs, impact assessments and decision records will face both substantive and evidentiary exposure.<\/p>\n<p>The fifth threat is strategic paralysis. Some boards respond to regulatory uncertainty by freezing formal AI adoption while failing to control the informal use of public tools by employees. This creates the worst possible outcome: unmanaged shadow AI, no reliable inventory and no defensible governance file.<\/p>\n<p>The opportunities are the mirror image.<\/p>\n<p>The ANPD\u2019s experimentation model creates a channel for technically credible engagement. The sandbox\u2019s immediate participation is limited, but its methods and conclusions will influence the wider market. Companies that understand the regulator\u2019s evidentiary expectations early will be better positioned for future rulemaking and enforcement.<\/p>\n<p>The Brazilian AI Plan, public procurement programmes, data infrastructure initiatives and national capability agenda create commercial opportunities for technology providers, infrastructure businesses, research organisations and investors. Demonstrable governance will increasingly become a condition for access to public and regulated markets.<\/p>\n<p>The institutional frameworks already in force also provide a competitive advantage. CNJ Resolution No. 615\/2025, the Bar\u2019s professional governance work and the ANPD\u2019s practice provide organisations with usable benchmarks while competitors wait for a definitive statute.<\/p>\n<p>There is also a measurable trust dividend. Customers, investors, lenders, insurers and regulators are beginning to price AI risk. An organisation that can demonstrate inventory, testing, human oversight, incident readiness and contractual discipline can close procurement, financing and due diligence more efficiently.<\/p>\n<p>For companies with European exposure, the EU AI Act adds another opportunity. Its phased application means that general-purpose model and transparency obligations are already relevant, while the principal high-risk duties follow the later timetable. A single governance backbone that supports Brazilian and European requirements is more efficient than parallel programmes and can become a commercial differentiator.<\/p>\n<p>Over the next 12 months, the difference between companies that used the regulatory window and companies that waited will become visible not only in compliance reports, but also in transactions, valuations, insurance and market access.<\/p>\n<h4><strong style=\"font-size: 1rem\">4. How do you ensure high client satisfaction levels are maintained by your practice?<\/strong><\/h4>\n<p>MPUPPE &amp; ASSOCIADOS, does not practise digital law as a spectator activity. We work at the intersection of law, technology, business and institutional governance, including data protection, AI, digital platforms, regulated finance, tokenisation, cybersecurity and international technology transactions.<\/p>\n<p>This operating perspective changes the advice we deliver. Clients do not need a theoretical description of every possible interpretation. They need a decision they can execute, an explanation of the assumptions supporting it and an architecture capable of surviving regulatory, contractual and judicial scrutiny.<\/p>\n<p>Our matters are senior-led. We distinguish clearly between what is legally settled, what is probable and what constitutes our reasoned assessment of a genuine grey area. Artificial certainty is not useful, but neither is an opinion that identifies risk without recommending a course of action.<\/p>\n<p>We provide direct answers with explicit consequences. We explain the regulatory exposure, evidentiary assumptions, commercial implications and available mitigation. Where the law does not provide a complete answer, we construct one through principles, comparative regulation, sector practice, contractual allocation and documented governance.<\/p>\n<p>We also deliver implementation artefacts, not only legal memoranda. Depending on the matter, our work may include system inventories, risk classifications, data protection and algorithmic impact assessments, governance matrices, board papers, procurement protocols, contract suites, incident procedures, regulator submissions and professional training.<\/p>\n<p>The association with ECIJA is particularly important for multinational clients. It allows us to combine specialised Brazilian analysis with an international technology-law platform, particularly across Europe and Ibero-America. The client receives a coordinated architecture rather than a sequence of disconnected local opinions.<\/p>\n<p>We also maintain close involvement after the initial legal advice. AI governance changes as models, vendors, laws and business uses evolve. A document delivered once and never operationalised has limited value. We therefore structure governance so that it can be updated through actual decision-making, procurement, system changes, monitoring and incident response.<\/p>\n<p>Our measure of client satisfaction is practical: did our work allow the client to make the same decision with greater speed, confidence and defensibility? Did it reduce regulatory surprise? Did it create a usable structure rather than an abstract conclusion? Client retention, referrals and the expansion of mandates are the clearest indicators that this standard is being met.<\/p>\n<h4><strong style=\"font-size: 1rem\">5. What technological advancements are reshaping Artificial Intelligence law and how can clients benefit from them?<\/strong><\/h4>\n<p>The first major development is the transition from generative AI to agentic AI.<\/p>\n<p>A generative system produces content. An agentic system can take action. It can call tools, initiate transactions, access databases, alter records, communicate with counterparties, purchase services and operate continuously within predefined or adaptive parameters. This changes the legal analysis because the system moves from expression to execution.<\/p>\n<p>Most current contracts and governance frameworks quietly assume that a human decision exists at the point of consequence. Agentic systems weaken that assumption. Clients should therefore establish authority limits, approved actions, financial thresholds, permitted counterparties, confirmation requirements, escalation triggers, logging, a kill switch and reversal procedures.<\/p>\n<p>The law should continue to attribute responsibility to identifiable actors. Autonomy should not become a mechanism for escaping accountability. The organisation that authorises, configures, benefits from and deploys the agent remains part of the responsibility chain.<\/p>\n<p>The second development is the rapid improvement of synthetic media.<\/p>\n<p>The capacity to reproduce voices, images, video and personal characteristics has direct consequences for fraud, political communication, advertising, evidence, identity and reputation. The 2026 Brazilian electoral rules make labelling, provenance, rapid response and forensic preservation operational legal issues.<\/p>\n<p>Companies in media, advertising, platforms, entertainment, financial services and public affairs should develop content-authentication processes, approval routes, incident escalation and evidence preservation. The legal question will increasingly concern whether the organisation could identify and respond to synthetic content, not merely whether it created the content itself.<\/p>\n<p>The third development is the algorithmic transformation of the justice system.<\/p>\n<p>Brazil has one of the world\u2019s most digitised judiciaries. AI is used for case triage, research, classification, procedural management and other support functions under CNJ Resolution No. 615\/2025. Private litigation analytics are also improving.<\/p>\n<p>For clients, this creates both opportunity and risk. Dispute patterns may become more predictable, but parties must also understand the governance framework applicable to judicial AI. The Resolution provides a normative basis for questioning transparency, risk classification, human supervision and the use of AI in judicial processes.<\/p>\n<p>The fourth development is the convergence of AI with programmable and tokenised financial infrastructure.<\/p>\n<p>Brazil combines instant national payments through Pix, Open Finance, growing virtual asset regulation, tokenisation of real-world assets and increasingly automated compliance, credit and fraud systems. AI is becoming embedded in pricing, distribution, trading, custody, fraud prevention, anti-money laundering and customer interaction.<\/p>\n<p>Clients benefit when financial regulation, data protection, cybersecurity, consumer law and AI governance are designed together. Sequential compliance creates duplication and frequently produces incompatible conclusions.<\/p>\n<p>The fifth development is the improvement of governance technology itself.<\/p>\n<p>Automated system inventories, continuous monitoring, evaluation tools, prompt and output logging, access controls and machine-assisted documentation are reducing the cost of maintaining an effective governance file. These tools do not replace legal judgment. They make judgment traceable and scalable.<\/p>\n<p>The organisations that benefit most will not be those that adopt the largest number of AI tools. They will be those that understand which systems create value, which systems create consequential risk and which controls permit adoption without surrendering accountability.<\/p>\n<h4><strong style=\"font-size: 1rem\">6. Describe a particularly interesting or complex matter you have advised on recently, and explain the challenges involved, your approach, and the outcome achieved for the client.<\/strong><\/h4>\n<p>A particularly significant mandate has been our support to the Federal Council of the Brazilian Bar Association in the development of its artificial intelligence and data governance agenda.<\/p>\n<p>The institutional scale is exceptional. The Council regulates a profession of more than one million lawyers across a continental jurisdiction, including global law firms, major in-house legal departments, small regional practices and sole practitioners. The profession that will advise on and litigate AI disputes also had to regulate its own use of the technology.<\/p>\n<p>The challenge had no complete national template. Brazil had no general AI statute, while legal professionals were already using public and enterprise AI systems for research, drafting, document analysis, client communication and internal management.<\/p>\n<p>Over-regulation could reinforce the technological divide by making safe adoption economically accessible only to large organisations. Under-regulation could expose professional secrecy, client data, legal accuracy, conflicts of interest, professional independence and the integrity of court submissions.<\/p>\n<p>The substantive questions were difficult. They included the use of confidential information in third-party systems, lawful processing of personal data, verification of model outputs, professional supervision, disclosure, procurement, information security, responsibility for AI-assisted work and the distinction between technological assistance and the delegation of legal judgment.<\/p>\n<p>Our approach was regulatory engineering rather than abstract opinion-writing.<\/p>\n<p>Through Matheus Puppe\u2019s institutional role as Data Protection Officer of the Federal Council and the firm\u2019s work in AI governance, we connected professional ethics, the LGPD, cybersecurity, comparative AI regulation and practical adoption.<\/p>\n<p>We adopted proportionality as a central principle. The minimum controls must be executable by an individual lawyer. Larger law firms and legal departments require more structured governance. High-impact uses involving confidential data, client rights or judicial submissions require enhanced review.<\/p>\n<p>We also distinguished the technology from the professional responsibility attached to its use. The central rule is that AI remains a tool. The lawyer who signs remains responsible. Using AI is not professional misconduct. Failing to verify material content may constitute negligence. Presenting information known to be false may constitute intentional misconduct.<\/p>\n<p>The work was benchmarked against the EU AI Act, National Council of Justice Resolution No. 615\/2025, data protection principles and international professional guidance, while preserving the specific constitutional and institutional characteristics of Brazilian legal practice.<\/p>\n<p>The public institutional outcome is already visible. The Council approved recommendations concerning generative AI in legal practice in 2024. In June 2026, it launched the National Plan for the Integration of Artificial Intelligence into the Legal Profession, structured around governance and good practices, nationwide training, modernisation of the Bar\u2019s services, protection of professional prerogatives and support for young lawyers.<\/p>\n<p>A national empirical survey developed with Stanford University is mapping the actual use of AI by Brazilian lawyers and will inform the future binding professional regulation.<\/p>\n<p>The matter illustrates what distinguishes the work of MPUPPE &amp; ASSOCIADOS. We do not only interpret legal frameworks after they are issued. We participate in the architecture through which institutions and businesses can use technology without surrendering confidentiality, responsibility or human judgment.<\/p>\n<p>The lesson applies beyond the legal profession: identify the tool, govern the data, verify the output and preserve a human actor who has both the power and the duty to answer.<\/p>\n","protected":false},"featured_media":0,"template":"","class_list":["post-147278","legal-landscapes","type-legal-landscapes","status-publish","hentry"],"acf":[],"_links":{"self":[{"href":"https:\/\/my.legal500.com\/guides\/wp-json\/wp\/v2\/legal-landscapes\/147278","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/my.legal500.com\/guides\/wp-json\/wp\/v2\/legal-landscapes"}],"about":[{"href":"https:\/\/my.legal500.com\/guides\/wp-json\/wp\/v2\/types\/legal-landscapes"}],"wp:attachment":[{"href":"https:\/\/my.legal500.com\/guides\/wp-json\/wp\/v2\/media?parent=147278"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}