What Is PL 2338/2023 — and Why It Matters Right Now
Before diving into technical details, context matters: Brazil is Latin America's largest economy, home to over 220 million people, and ranks among the world's highest in smartphone penetration and social media usage. And yet, as of August 2026, artificial intelligence operates in the country without a specific law regulating its risks.
That doesn't mean no regulation exists. The LGPD (Brazil's General Data Protection Law) already applies to the use of personal data in AI systems, and the ANPD (National Data Protection Authority) has taken concrete action — including suspending platform features that used user data for AI training without a proper legal basis. But the LGPD was designed for data, not specifically for AI. PL 2338 is meant to fill that gap.
The bill was introduced by Senator Rodrigo Pacheco in 2023, consolidating debates that had been ongoing since 2019. It was approved by the Federal Senate on December 10, 2024 — with a symbolism that didn't go unnoticed: exactly on International Human Rights Day. In 2026, it's under review by a Special Committee in the Chamber of Deputies, with a floor vote expected before year's end.
PL 2338/2023 is not yet law. It's still being debated in the Chamber of Deputies' Special AI Committee. In the meantime, AI in Brazil continues to be governed primarily by the LGPD and sector-specific rules (such as those issued by the CNJ for the judiciary). But the bill's framework already serves as a reference for best practices — and smart companies are preparing now.
The Core Framework: Risk-Based Regulation
PL 2338 follows the same logic as the EU AI Act: there is no single rule for all AI uses. The law classifies systems according to the level of risk they pose to fundamental rights. The higher the risk, the more obligations and oversight apply.
Unacceptable Risk (Prohibited)
Some AI applications will simply not be allowed in Brazil, regardless of the technology involved. The bill prohibits systems that manipulate human behavior imperceptibly, that apply social scoring of citizens for discriminatory purposes, and that use emotion recognition in public spaces without legitimate justification. These are absolute prohibitions — there is no compliance path for these applications.
High Risk (Strict Regulation)
This is the category that will demand the most from businesses. AI systems are considered high-risk when they operate in sensitive areas: critical infrastructure (energy, transportation, water), education and vocational training, employment and worker management, essential public services, law enforcement applications, the justice system, and democratic processes such as elections.
| Risk Category | Examples | What's Required |
|---|---|---|
| Unacceptable | Social scoring, subliminal manipulation, mass surveillance | Prohibited — no use permitted |
| High Risk | AI in healthcare, credit scoring, hiring, judiciary | Documentation, auditing, mandatory human oversight |
| Low / Moderate Risk | Chatbots, content recommendation, spam filters | Transparency: users must know they're interacting with AI |
Low and Moderate Risk
Most AI applications we use daily — customer service chatbots, streaming recommendation algorithms, spam filters, virtual assistants — fall into this category. Requirements are lighter, but there's one central obligation that will change many user experiences: the duty to inform. Users must know they are interacting with an AI, not a human. Simple, but hugely impactful.
Your Rights as a Brazilian Citizen
One of PL 2338's most important contributions is establishing an explicit set of rights for people affected by AI systems. These rights apply especially when AI makes decisions that affect your life: a denied loan, a job not considered, a social benefit refused.
- Right to transparency: you have the right to know when a decision affecting you was made or influenced by an AI system.
- Right to explanation: you can demand an understandable explanation of the criteria used by the AI to reach that decision.
- Right to contest: decisions made exclusively by AI can be challenged and reviewed by a human.
- Right to non-discrimination: AI systems cannot reproduce illegal discrimination based on race, gender, origin, religion, or other protected characteristics.
- Right to privacy: the use of personal data by AI systems must comply with the LGPD — and the bill reinforces this protection. For a deeper look at what tech companies already know about you today, see our guide on AI and Privacy.
If a bank denies your credit based on an algorithmic decision, you'll be able to demand an explanation of the criteria used and request human review. If a company uses AI in resume screening and you weren't called for an interview, you'll have the right to know why. This represents a structural shift in the relationship between people and algorithms in Brazil.
Was Brazil the first country to regulate AI in the judiciary? Not the first in the world, but it was a pioneer in Latin America: CNJ Resolution No. 332/2020 predates most equivalent rules in the region. Is the R$50M fine a fixed amount? No — it's the ceiling set for the most severe violations; the actual amount factors in company revenue and the severity of harm, following the same logic as the LGPD. Has any company already been fined over AI in Brazil? Not yet under PL 2338 (which isn't law), but the ANPD has already penalized companies under the LGPD for misusing data to train AI models — a preview of what's coming.
What Changes for Brazilian Businesses
For the private sector, PL 2338 means new bureaucracy, but also new legal certainty. Companies that already operate high-risk AI systems will need to adapt across three main areas:
Documentation and Transparency
High-risk systems will need detailed technical documentation: how the model works, what data was used in training, how performance is evaluated, and what known risks exist. This "AI identity card" can be requested by regulatory bodies at any time.
Human Oversight
Full automation in high-impact decisions will not be permitted. AI systems that affect fundamental rights will require effective human oversight — not a pro-forma "review" checkbox, but a real process in which a qualified human can question and reverse algorithmic decisions.
Accountability Chain
The bill defines who's responsible when things go wrong. The developer of the system is responsible for ensuring it works as declared. The deployer — the company using the system in its products — is responsible for appropriate use in the specific context. This accountability chain is inspired by the European model but adapted to Brazil's legal framework.
Brazil vs. Europe: Where the Laws Differ
PL 2338 is frequently described as "inspired by the EU AI Act" — and that comparison is fair but incomplete. There are important differences that reflect Brazilian reality.
The first is structural: while the EU AI Act is a directly applicable regulation across 27 countries, Brazil's AI Framework is a federal law that coexists with state and municipal jurisdictions, with existing sector-specific rules (LGPD, consumer protection code, Central Bank rules for fintechs), and with the country's federative structure. This creates implementation complexity that the European model doesn't face in the same way.
The second difference is governance: the bill creates the National AI Regulation and Governance System (SIA), but leaves room for the ANPD, Cade, the Central Bank, and other sector regulators to maintain their own jurisdictions. The result is a more distributed — and potentially more conflicted — model than the centralized European approach.
Critics point out that the bill still has vague definitions for terms like "AI system" and "high risk." This may generate legal uncertainty in the early phases of implementation. For early-stage startups, compliance costs could be a real obstacle — and this debate hasn't been fully resolved in Congress yet.
What Already Applies Today — Even Without the Law Passed
A common misconception is that until PL 2338 is approved, no AI obligations exist in Brazil. That's wrong. The country already has a set of rules that apply to AI right now, in August 2026:
- LGPD: any AI system that processes personal data of Brazilians must have an adequate legal basis, declared purpose, and respect data subjects' rights. The ANPD enforces this and has already fined companies for non-compliance.
- Consumer Protection Code: AI systems used in consumer relations must already comply with transparency and non-discrimination rules under the CDC.
- CNJ Resolution No. 332/2020: the judiciary already has its own rules for AI use in judicial activities — Brazil was a global pioneer in this area. Judges are already using AI to draft rulings and case memos; see the real cases in our guide AI and Law.
- Central Bank Rules: fintechs and financial institutions using AI-based credit models are already subject to explainability and non-discrimination obligations.
What You Can Do Right Now
Regardless of exactly when PL 2338 is approved, some actions make sense today — whether you're a citizen, a tech professional, or a business manager.
For Citizens
Start exercising rights already guaranteed by the LGPD: you can request access to data companies hold about you, ask for explanations on automated decisions that affect you, and contest situations where you suspect algorithmic discrimination. The ANPD has a complaints channel accessible through gov.br.
For Companies and Developers
The bill's ongoing period in Congress is the best time to map which AI systems you use or develop and classify them by probable risk level. Companies that start building documentation, human oversight processes, and transparency policies now will be far better prepared — and will spend far less — than those that wait for the law to pass before starting.
Conclusion: A Law That Arrives at the Right Time
Brazil's AI Legal Framework isn't perfect. It has definitions that need sharpening, conflicts between regulators that need resolving, and a real risk that industry pressure could weaken important protections before final approval. But it is necessary — and it arrives at a moment when Brazil is already one of the world's highest per-capita users of generative AI.
For the average citizen, the most important message is simple: you will have new rights that don't explicitly exist today. The right to know when AI is making decisions about your life, the right to ask for explanations, and the right to contest. In an era where algorithms decide everything from your credit limit to which job posting you see, these rights aren't a luxury. They're a necessity.
Frequently Asked Questions (FAQ)
Not yet. As of August 2026, PL 2338/2023 has been approved by the Senate and is under review by the Chamber of Deputies' Special AI Committee, with a floor vote expected before the end of the year.
Yes. The LGPD, the Consumer Protection Code, CNJ Resolution No. 332/2020, and Central Bank rules already apply to AI systems today, even without a dedicated AI law in place.
It depends on each party's role. The developer is responsible for ensuring the system works as declared; the deployer (the company using the AI in its products) is responsible for appropriate use in context. Both can be held liable, depending on where the failure occurred.
The strictest requirements fall on high-risk systems, regardless of company size. Small businesses using only chatbots or content recommendation (low risk) have lighter obligations, like disclosing that users are talking to an AI.
You can already use LGPD channels: request access to the data a company holds about you, ask for an explanation of automated decisions, and file a complaint with the ANPD through the gov.br website if you suspect algorithmic discrimination.
Debate continues into the following year — there's no statutory deadline. In that scenario, Brazil keeps regulating AI in a fragmented way, through the LGPD and sector-specific rules, until Congress finishes the vote.
Get analyses like this delivered to your inbox
Tech, artificial intelligence, and the inside story of the tools changing how we live — no spam, straight to the point.