Brazil AI Bill (PL 2338/2023)

Jurisdiction:
Brazil
proposed
Effective:
Authority:
National Data Protection Authority (ANPD)
Official text Verified Mar 26, 2026

Obligations Covered

Risk Assessment Transparency & Disclosure Human Oversight

Risk-Based AI Classification #

Obligation:
Risk Assessment
proposed
Risk tier:
high-risk
Scope:
providers, deployers
upcoming

Requirements

RequirementDetails
Risk classificationAI systems classified by risk level: excessive, high, and general
Prohibited practicesBan on subliminal manipulation, mass surveillance, exploitative systems
High-risk categoriesHealth, justice, security, credit, employment, education, infrastructure, biometrics
Safety testingHigh-risk systems require safety testing before deployment
Algorithmic impact assessmentPublic algorithmic impact assessments for high-risk systems

Penalties

ViolationFine
Non-complianceUp to BRL 50 million or 2% of revenue
Severe violationsWarnings, suspension, or bans on AI system operation

Transparency and Explainability #

Obligation:
Transparency
proposed
Risk tier:
all
Scope:
providers, deployers
upcoming

Requirements

RequirementDetails
Right to explanationIndividuals have the right to explanation of AI-driven decisions
Understandable systemsAI systems must be understandable and auditable
DocumentationAI operations must be documented
DisclosureUsers must be informed when interacting with AI systems

Penalties

ViolationFine
Non-complianceUp to BRL 50 million or 2% of revenue

Human Oversight and Contestation #

Obligation:
Human Oversight
proposed
Risk tier:
high-risk
Scope:
providers, deployers
upcoming

Requirements

RequirementDetails
Human reviewMandates human review of AI-driven decisions in sensitive processes
Right to contestIndividuals can contest automated decisions
Oversight mechanismsOrganizations must establish oversight mechanisms for high-risk AI

Penalties

ViolationFine
Non-complianceUp to BRL 50 million or 2% of revenue