The Real Picture: AI Is Already Inside SUS
In January 2026, Brazil's Ministry of Health announced the creation of the National Network of Smart Hospitals and Services for SUS (Rede Nacional de Hospitais e Serviços Inteligentes do SUS), a program bringing artificial intelligence, advanced connectivity, and precision medicine into the public health network, backed by R$1.7 billion (roughly $340 million) in funding secured in partnership with BRICS countries. The first phase covers 14 smart ICUs across 13 states, with one of the main hubs at the University of São Paulo's Hospital das Clínicas — around 800 emergency beds, with capacity to treat more than 20,000 patients a year.
According to Health Minister Alexandre Padilha, the technology can make triage up to five times faster. That's not a distant goal: Brazilian public hospitals already use algorithms to analyze thousands of imaging exams — CT scans, X-rays, MRIs — at a speed no human team could match, reorganizing the reading queue to bump the most critical cases to the top. A patient showing early signs of a stroke, or a suspicious lung nodule, can have their scan prioritized by the algorithm within minutes, not days.
The most misunderstood point about AI in public healthcare is the assumption that the algorithm "diagnoses on its own." In practice, systems currently approved for clinical use in Brazil work as a priority filter: they analyze the exam, flag what looks urgent or abnormal, and hand that result to a human doctor for the final call. Final diagnostic responsibility stays with the healthcare professional — something Brazilian regulation itself, as you'll see below, makes explicit.
The program also opened dialogue with global medical technology manufacturers — including China's Neusoft, which announced investment in an imaging equipment factory in Santa Catarina state, and Mindray, one of the world's largest hospital equipment makers — to accelerate the digitization of Brazil's public network. The government's stated goal isn't to replace healthcare professionals, but to provide technological support for faster, safer clinical decisions, especially outside major urban centers, where the shortage of specialists is most acute.
Where AI Is Already Working Inside the Public System
Pulling together what's already operational or in advanced pilot stages across SUS units, four use cases account for nearly all real-world deployment of the technology today.
| Use Case | What It Actually Does | Status Inside SUS |
|---|---|---|
| Imaging diagnosis | Analyzes CT scans, X-rays, and MRIs, flagging suspicious patterns for priority medical review | In use at hospitals and telerarhiology networks affiliated with SUS |
| Triage and case prioritization | Classifies patient urgency at intake, distributing them across units with available capacity | Advanced pilot within the National Network of Smart Hospitals |
| Bed and resource management | Forecasts ICU bed demand, optimizes staff schedules, and anticipates supply needs | Being rolled out across the first phase's 14 smart ICUs |
| Telehealth and remote monitoring | Tracks chronic patients remotely, reducing avoidable hospitalizations in regions without specialists | Expanding via telemedicine programs regulated by the CFM |
The common thread across all four use cases is that none of them replaces the final medical decision — all of them act as a capacity multiplier in a system serving a continental population with a historically insufficient number of specialists relative to demand, especially outside the country's capital cities.
The Regulatory Framework: Who Regulates What in Brazilian Health AI
Unlike AI at work or in education, healthcare already had a robust, specific regulatory system in place before the explosion of generative AI itself — which changes the game compared to other areas still being regulated "by analogy." Three institutions split that responsibility, each with a different scope.
ANVISA: medical software as a device
Since 2022, Resolution RDC 657/2022 from Brazil's health regulator ANVISA created a specific regulatory regime for SaMD (Software as a Medical Device) — any software with a diagnostic, therapeutic, or clinical decision-support purpose must go through notification or registration, depending on its risk class (I through IV, following the international IMDRF matrix, harmonized with the FDA and European regulation). An AI system that analyzes a CT scan and flags a possible tumor falls squarely under this rule — and must demonstrate safety, performance, and clinical evidence before it can reach a SUS hospital.
CFM: who signs off, and who's responsible for the decision
What was missing until early 2026 was a specific text on the clinical use of AI itself inside the office and the hospital — ANVISA regulates the product, but didn't say who signs the final report. CFM Resolution 2.454/2026 filled that gap: it establishes that responsibility for the clinical decision always rests with the physician, even when they use AI support, sets out what needs to be documented in the medical record about the tool's use, and how the patient must be informed that an AI system took part in their diagnosis or treatment.
LGPD: health data is sensitive data
Brazil's General Data Protection Law (LGPD) classifies health data as sensitive personal data (Art. 5, II), with stricter processing rules than ordinary data — requiring, among other things, a specific legal basis (Art. 11) and reinforcing the right to review of automated decisions (Art. 20) whenever an AI system takes part in a decision that affects the patient, such as care prioritization or triage.
Can a hospital use any AI system it wants? No. If the software has a clinical purpose, it must be regularized with ANVISA as SaMD — using an unregistered tool for diagnostic decisions is a health-code violation. Is the patient told when AI is involved in their diagnosis? Under CFM Resolution 2.454/2026, yes — the physician must disclose this and record it in the patient's chart. Is there a single national electronic health record in Brazil? There's the RNDS (National Health Data Network), which links systems through the Meu SUS Digital app, but integration between municipalities and states remains uneven — one of the biggest technical obstacles to nationwide health AI.
Confirmed vs. Not Yet Confirmed: Separating Policy From Expectation
Few areas mix government announcements, isolated pilots, and long-term promises quite like digital health. Before deciding what to expect from AI at your local health post, it's worth separating what's already policy and funded reality from what's still a goal or an open debate.
Confirmed
- The National Network of Smart Hospitals and Services for SUS exists and is running, with R$1.7 billion in funding, 14 smart ICUs in the first phase, and USP's Hospital das Clínicas as one of the main hubs.
- ANVISA has regulated AI-based medical software since 2022, via RDC 657/2022, with a four-tier risk classification and clinical-evidence requirements proportional to each system's risk level.
- The CFM has already established, via Resolution 2.454/2026, that clinical responsibility always rests with the physician, even with AI support, and that the tool's use must be documented and disclosed to the patient.
- The LGPD already protects health data as sensitive data, with the right to human review of automated decisions that affect the patient — this already applies today, in any unit using AI. We break down that right, with practical examples, in our guide to Brazil's LGPD and AI.
Not yet confirmed
- When the smart hospital network will expand beyond its first phase — the timeline for scaling nationally, beyond the 14 initial hubs across 13 states, has no public date yet.
- How PL 2338/2023 (Brazil's AI Law) will treat healthcare specifically in practice — the bill already classifies systems used in "evaluating criteria for public services" as potentially high-risk, but the final text on healthcare, including algorithmic impact-assessment deadlines, still depends on a vote in the lower house of Congress. We track the full legislative process in our guide to Brazil's AI Law.
- Whether and when the RNDS will achieve truly nationwide, uniform coverage — data integration between small municipalities and major centers remains uneven, which limits how far any AI relying on complete clinical history can actually reach.
- The medium-term impact on wait times at a national level — the reported speed gains (like "5x faster" triage) come from specific units within the pilot network; there's no consolidated national figure yet measuring this effect across all of SUS.
It's common to see news coverage treat any AI pilot at a single state hospital as if it were already implemented nationwide policy. As of this article's publication, the National Network of Smart Hospitals and Services for SUS is in an early expansion phase — real, funded, and operating, but still far from covering Brazil's more than 5,500 municipalities. Distinguishing "exists and works in X units" from "has already solved the problem nationwide" is essential to understanding the technology's actual stage.
The Unique Challenges of Brazil's Public System
AI in healthcare faces similar technical and ethical challenges in any country. But Brazil's scale and inequality create obstacles a smaller or more homogeneous country simply doesn't have.
Continental scale with uneven infrastructure
SUS provides some level of care to more than 200 million people across a territory the size of a continent. An algorithm trained mostly on data from major urban hospitals — where most digitized medical data actually exists — risks performing worse for populations in Brazil's North and Northeast, regions historically underrepresented in Brazilian medical datasets. This isn't hypothetical: it's the same geographic bias pattern already documented in other countries with strong regional inequality.
Racial bias in a country that already measures health inequality by race
Brazil has decades of data from its own Ministry of Health showing racial disparities in maternal mortality, life expectancy, and access to early diagnosis between Black and white patients. An algorithm trained on the health system's own historical data risks learning — and reproducing at scale — that same pattern of inequality, even without any explicit instruction to do so. This is exactly the kind of scenario the Algorithmic Impact Assessment, required for high-risk systems under PL 2338, was designed to catch before a system goes live.
Data fragmentation across municipalities, states, and the federal government
The RNDS (National Health Data Network) and the Meu SUS Digital app have advanced interoperability, but Brazil still doesn't have a truly unified electronic health record across its more than 5,500 municipalities. That means an AI system needing a patient's complete clinical history may simply not have access to it if that person was treated in different municipalities over their lifetime — a structural limitation no algorithm, however sophisticated, can solve on its own.
Connectivity as a prerequisite for telehealth
Remote monitoring and telehealth — one of the most promising fronts for bringing AI to regions without specialists — depend on stable connectivity, still uneven in rural, riverside, and Indigenous areas. The technology that promises to shrink the distance between patient and specialist first runs into a more basic distance: access to quality internet.
Brazil vs. Other Countries: How Health AI Regulation Compares
Brazil isn't building this regulation in isolation. Comparing Brazil's design to other systems helps clarify whether the country is aligned, behind, or in some respects ahead.
| Country / Bloc | Current Status | What It Covers |
|---|---|---|
| Brazil | ANVISA (RDC 657/2022) and CFM (Res. 2.454/2026) already in force; PL 2338 pending in the lower house of Congress | Medical-software risk classification, documented physician responsibility, LGPD for sensitive health data |
| European Union | The AI Act classifies AI-enabled medical devices as high-risk by definition, with reinforced conformity-assessment requirements | Mandatory risk assessment, human oversight, transparency, and registration in the EU's high-risk systems database |
| United States | FDA regulates AI/ML in SaMD via its "AI/ML-Based SaMD Action Plan," with a specific process for algorithms that keep learning after approval | Premarket approval, predetermined change-control plans, post-market surveillance |
| United Kingdom | The NHS has its own evaluation framework (NICE) for digital health technologies, including AI, integrated into the national public system | Cost-effectiveness and clinical-safety evaluation before large-scale adoption by the public system |
The pattern that emerges is similar to what's seen in other areas of AI regulation in Brazil: the health-sector regulatory base (ANVISA and CFM) is already more mature and specific than Brazil's general AI regulation (still pending via PL 2338), putting Brazil in a relatively advanced position specifically on medical devices — even as it faces structural implementation challenges that the EU and the US, with internally less unequal health systems, don't face on the same scale.
Common Misconceptions About AI in Public Health
Among public health managers, healthcare professionals, and the general public, a few misunderstandings come up again and again when the topic is AI inside SUS:
- Assuming "ANVISA-approved AI" means "infallible AI": regulatory approval attests to minimum safety and performance within tested criteria — it doesn't eliminate the need for medical review, nor guarantee equal performance across every patient profile.
- Confusing a regional pilot with national policy: a hospital with cutting-edge AI in São Paulo doesn't mean the same technology is available at a basic health unit in rural Amazonas — unequal access to the technology itself is, in itself, a central ethical issue.
- Ignoring the right to explanation: patients (and healthcare workers) often don't realize they can, under the LGPD, request an explanation of how an automated triage or prioritization decision was made.
- Treating algorithmic bias as a purely "technical" problem, isolated from social inequality: a biased health algorithm is usually reflecting inequality that already existed in the data — fixing the code without addressing the social origin of the bias tends to mask the problem, not solve it.
- Overestimating how much AI solves physician shortages: the technology multiplies analytical capacity, but doesn't replace the structural need for more healthcare professionals in underserved regions.
Beyond the Possible: Where AI in Public Health Could Go
Moving past what's already confirmed public policy, it's worth exploring — with a grounded sense of what's technically plausible — scenarios that aren't yet reality inside SUS, but that come up often in debates about the future of Brazilian digital health.
Remote AI diagnosis for riverside and Indigenous communities via satellite: technically plausible, since low-earth-orbit satellite connectivity is expanding globally, but it depends on infrastructure investment that isn't yet part of the confirmed public timeline for the National Network of Smart Hospitals.
Real-time outbreak prediction cross-referencing SUS data with environmental data: technically possible and already explored in Brazilian academic research (such as studies linking dengue fever to climate-related vectors), but without a fully operational national predictive-surveillance system integrated into the public network yet.
A fully unified national electronic health record, with AI analyzing any patient's complete history at any unit in the country: this is the most distant scenario on the list. It depends first on solving the structural interoperability problem across more than 5,500 municipalities — a data-management challenge, not just an algorithmic one.
Everything in this section is speculation about plausible future scenarios, not a forecast or confirmed public policy in the works. None of these points has an official Ministry of Health timeline — they're technically reasonable medium-to-long-term possibilities, useful for thinking through where the debate is heading, not conclusions about what will happen.
What to Do Now, In Practice
Regardless of how quickly the National Network of Smart Hospitals expands or when PL 2338 finally comes to a vote, there are concrete steps that make sense today for anyone who uses or works within Brazil's public healthcare system.
If you're a SUS patient
You have the right to formally ask whether an AI system took part in your triage, diagnosis, or care prioritization — and to request an explanation of the criteria used, under Article 20 of the LGPD. If you notice treatment differences that seem systematic by region, race, or socioeconomic profile, you can report this to your local SUS ombudsman and to Brazil's data protection authority, the ANPD.
If you're a healthcare professional
Document any use of AI tools in the patient's chart, as required by CFM Resolution 2.454/2026 — this protects both you and the patient. Keep active clinical skepticism: a decision-support system is exactly that, support, not a final verdict, and cases that "fall outside the algorithm's pattern" deserve extra attention, not less. If you're studying for or updating your credentials in the field, our AI for Nursing guide covers AI-assisted study techniques for clinical coursework.
If you're a public or hospital manager
Before adopting any clinical AI system, confirm its ANVISA regularization as SaMD and require performance evidence from populations comparable to yours — not just generic international studies. Prioritize investment in data interoperability (RNDS) before investing in algorithms alone: even an excellent model has limited value without a patient's complete historical data, however strong its isolated technical performance.
Conclusion: The Technology Has Already Arrived — Equity Is Still the Hard Part
AI in Brazilian public healthcare has stopped being a promise and become an executed budget, an operating hospital, and a signed resolution. The National Network of Smart Hospitals and Services for SUS, ANVISA's RDC 657/2022, and the CFM's Resolution 2.454/2026 show a regulatory system that matured faster in this specific area than in almost any other AI use case in Brazil.
What's still unresolved isn't technical — it's structural. Bringing the same technology that speeds up diagnoses at Hospital das Clínicas to a basic health unit in rural Pará state, with the same quality and without reproducing the racial and regional inequalities already present in SUS's own data, is this decade's real ethical test. Technology multiplies what already exists — including inequality. Making sure it multiplies access, not distance, depends on public-policy choices being made right now, in 2026.
Frequently Asked Questions (FAQ)
It's real, active use, not just an isolated pilot. The National Network of Smart Hospitals and Services for SUS, announced in January 2026 with R$1.7 billion in funding, has 14 smart ICUs operating across 13 states, including at USP's Hospital das Clínicas. Even so, it's an early expansion phase, far from covering every Brazilian municipality.
No. Any software with a diagnostic or clinical decision-support purpose must be regularized with ANVISA as Software as a Medical Device (SaMD), under RDC 657/2022, with a risk classification from I to IV and safety and performance evidence proportional to that risk.
The physician. CFM Resolution 2.454/2026 establishes that responsibility for the clinical decision always rests with the healthcare professional, even when they use AI support — which also must be documented in the patient's chart and disclosed to the patient.
The LGPD classifies health data as sensitive personal data, with stricter processing rules than ordinary data. Among other rights, you can request human review of an automated decision that affects you, such as triage or care prioritization carried out with AI support.
Yes, if it's trained on historical data that already reflects that inequality — something well documented in Brazil, where racial and regional health disparities have been measured by the Ministry of Health itself for decades. That's exactly the risk the Algorithmic Impact Assessment, required for high-risk systems under PL 2338, is designed to catch before large-scale adoption.
Not a single, specific law. What already applies today is the combination of ANVISA's RDC 657/2022 (the product), CFM Resolution 2.454/2026 (clinical use and physician responsibility), and the LGPD (protection of sensitive data). PL 2338/2023, which would address AI more broadly and classify certain healthcare uses as potentially high-risk, is still pending in Brazil's lower house of Congress.
Get the news before everyone else
AI, digital security, and technology — every week, straight to your inbox. No spam.