
July 28, 2026
Generative AI and Copyright: What Brazilian Companies Need to Do Now

Generative artificial intelligence is no longer just an experimental tool — it has become part of everyday routines in marketing, software development, research, customer service, design, audiovisual production and knowledge management. This adoption boosts productivity, but it also raises a decisive business question: can a company freely use protected content to train, fine-tune or feed AI systems, and can it freely commercially exploit everything these systems produce?
In Brazil, the answer still requires combining existing rules with a regulation that is under construction. Law No. 9,610/1998, known as the Copyright Law (Lei de Direitos Autorais), was drafted before the current scale of data mining and contains no general exception for commercial model training. At the same time, Bill No. 2,338/2023, approved by the Senate and still under review in the Chamber of Deputies, dedicates specific rules to the use of protected works in the development of artificial intelligence. For business owners and managers, this scenario does not justify halting innovation, but it does demand governance, documentation and more careful contractual decisions.
Development
Current legislation already reaches corporate use of content by AI
The Copyright Law protects original creations expressed or fixed on any medium and grants the author both moral and economic (patrimonial) rights. In business terms, this means texts, photographs, illustrations, music, videos, code, interfaces and other materials do not become free simply because they are accessible on the internet. Articles 28 and 29 of Law No. 9,610/1998 reserve economic exploitation to the rights holder and require prior, express authorization for various forms of use, including reproduction, adaptation and inclusion in databases or systems capable of generating economic benefit.
The limitations set out in Article 46 of the same law must be interpreted restrictively and in a manner compatible with the normal exploitation of the work. This logic appears in Special Appeal (REsp) 2,008,122/SP, in which the Superior Court of Justice (STJ) found it unlawful for a clipping service to commercialize journalistic content without authorization or payment. The STJ applied the so-called three-step test, emphasizing that an exception cannot conflict with the normal commercial exploitation of a work nor cause unjustified harm to the rights holder. Although the case did not involve AI, its rationale is relevant whenever protected content is used as input for a profitable technology product.
Model training and knowledge bases require analysis of source and license
Training a model, fine-tuning a tool, or building an information-retrieval database usually involves copying, storing, fragmenting, indexing or transforming content. Even if the final output does not literally reproduce the work used, intermediate acts may still carry legal relevance. For this reason, a company must know the origin of its data, the applicable licenses, usage restrictions, and whether rights holders have mechanisms to object. A generic claim that material was publicly available does not eliminate the risk.
Special Appeal (REsp) 1,877,336/RJ reinforces another important point. The STJ held that unauthorized reproduction of part of a literary work objectively violates economic rights, and that authorization granted for a specific purpose should not be broadened generically. Applied to technology contracts, this guidance suggests verifying whether licenses for image banks, content platforms, code repositories and document databases permit data mining, training, creation of derivative works, sublicensing, and commercial use of AI-generated outputs.
What Bill No. 2,338/2023 could change
In the version approved by the Senate, the bill requires developers to disclose, through a public summary, the protected content used in developing the system. It also creates an exception for text and data mining carried out without commercial purpose by certain scientific, educational and cultural institutions, provided access is lawful and use is necessary, secure and compatible with the rights holders' economic interests. Outside this exception, the text recognizes the rights holder's right to object and provides for remuneration when protected content is used in mining, training or developing AI systems.
These rules may still be changed by the Chamber of Deputies. As of July 2026, the bill was awaiting the rapporteur's opinion in the Special Committee and had several related proposals attached to it, including initiatives on authorship and ownership of AI-generated works. Even without being in force, the text reveals the regulatory direction: greater transparency about training data, negotiation mechanisms, possible remuneration, and a distinction between non-commercial research and commercial exploitation. Contracts signed today should anticipate this movement, especially in long-term projects.
AI-generated outputs do not eliminate the need for human authorship and third-party verification
Law No. 9,610/1998 defines an author as the natural person who creates a work. As a result, an output produced entirely automatically faces uncertainty regarding copyright protection, while original human contributions — such as selection, creative direction, composition, editing and transformation — may support protection over the elements actually created by people. The STJ has already stated, in a case involving applied art works, that protection depends on the original externalization of intellectual expression, and that whoever claims exclusivity must prove authorship or transfer of rights, as well as originality.
For a company, the issue is not only whether it can prevent copies of an output. It is also necessary to check whether the result incorporates excerpts, characters, images, trademarks, voices, identifiable styles or other third-party elements. In Special Appeal (REsp) 2,121,497/RJ, the STJ distinguished mere creative reference from unauthorized commercial appropriation of song lyrics. The same caution should guide campaigns, packaging, audiovisual pieces and AI-generated content, especially when prompts request direct imitation of a known work, artist, brand or visual identity.
Contracts and trade secrets are a central part of the risk
Corporate use of AI can also move internal assets to external environments. Entering source code, business strategies, proposals, customer data, unpublished research or confidential documents into a tool without adequate controls can compromise trade secrets, data protection, and confidentiality obligations. Law No. 9,279/1996 penalizes the unauthorized disclosure or use of confidential information obtained through contractual or employment relationships, and the General Data Protection Law (LGPD) continues to apply whenever personal data is processed.
Contracts with AI vendors should clarify ownership of inputs and outputs, data retention, use for the vendor's own training, data location and international transfer, confidentiality, security, audit rights, indemnification, cooperation in third-party claims, and service continuity. Employment and service agreements also need to be aligned. For computer programs, Law No. 9,609/1998 assigns, as a default rule, certain rights to the employer or contracting party when software is developed within the scope of the relevant relationship, but creative content unrelated to software requires its own assignment or licensing clauses.
AI governance should be integrated into intellectual property strategy
An effective corporate policy should neither ban AI outright nor release it without criteria. The safest path is to classify tools and uses according to risk, reserve approved solutions for sensitive information, require human review before publication, and keep records of relevant prompts, versions, sources, licenses and creative interventions. This documentation helps demonstrate diligence, trace incidents, and prove human contribution to assets the company intends to protect.
It is also advisable to integrate the legal, technology, information security, marketing, procurement and human resources departments. Intellectual property analysis should begin before a tool is procured and continue throughout the project's life cycle. In investment, partnership or acquisition transactions, due diligence should identify dependency on third-party models, contractual restrictions, the origin of databases, migration capacity, and the consistency of the ownership chain for content used and produced.
The main change brought about by generative AI is not the disappearance of copyright, but the multiplication of points at which a company may create, use or expose intellectual assets. Current legislation already requires authorization for economically relevant uses, protects human authorship, limits exceptions, and preserves rights over software, image, voice, trademarks and confidential information. The regulation under debate tends to add transparency, remuneration and specific mechanisms for model training.
Companies that treat this topic merely as a technology issue take on risks that can affect product launches, contracts, reputation, asset value and business continuity. The strategic response lies in combining innovation with a rights inventory, careful vendor selection, adequate contract clauses, internal controls and documented decision-making. In this still-evolving environment, preventive and specialized legal counsel helps turn regulatory uncertainty into safer business criteria, without promising the absence of litigation or predetermined outcomes.
Written by Guilherme Henrique Soares
