Soares, Goulart & Caetano Advogados

April 10, 2026

Artificial Intelligence Regulation in Brazil and Its Impacts on Businesses

Back to articles
Artificial Intelligence Regulation in Brazil and Its Impacts on Businesses

Artificial intelligence has ceased to be a mere technological promise and has become an integral part of business operations across various sectors of the economy. Algorithm-based tools are used for data analysis, process automation, customer service, strategic decision-making, and the development of new products. This technological advancement, however, also raises relevant legal questions related to civil liability, data protection, algorithmic transparency, and the protection of fundamental rights.

In Brazil, the debate over the regulation of artificial intelligence has gained momentum in recent years and culminated in the drafting of Bill No. 2,338/2023, which seeks to establish a legal framework for the responsible development, implementation, and use of this technology. The proposal was approved by the Federal Senate in December 2024 and is currently being reviewed by the Chamber of Deputies, amid intense political, economic, and regulatory discussions.

For entrepreneurs and managers, understanding the fundamentals of this future regulation is not merely a theoretical matter. It is an essential element of corporate governance, risk management, and regulatory compliance. As artificial intelligence becomes central to business strategies, the need to understand the legal limits of using this technology in the corporate environment also grows.

The Current Regulatory Landscape for Artificial Intelligence in Brazil

Despite the growing use of artificial intelligence systems in the country, Brazil still does not have a specific general law in force regulating this technology. Currently, the use of algorithmic systems is indirectly governed by various rules already existing within the Brazilian legal system.

Among these rules, the General Personal Data Protection Law (Lei Geral de Proteção de Dados Pessoais, or LGPD), Law No. 13,709/2018, stands out, establishing rules for the processing of personal data and imposing relevant limits on the use of automated decisions. Article 20 of the LGPD guarantees data subjects the right to request a review of decisions made exclusively based on automated processing of personal data, which includes systems based on artificial intelligence.

In addition to the LGPD, other legal frameworks may also apply to the use of artificial intelligence in the business context. The Consumer Protection Code may apply in cases of misleading advertising or abusive commercial practices arising from the use of automated systems. Competition law and intellectual property legislation may also be relevant when algorithms influence market decisions or generate content protected by copyright.

In this scenario of regulatory fragmentation, the absence of a specific legal framework creates legal uncertainty for both companies and technology users. This regulatory gap has driven the advancement of the legislative debate on creating a dedicated legal regime for artificial intelligence in Brazil.

Bill No. 2,338/2023 and the Future Legal Framework for Artificial Intelligence

Bill No. 2,338/2023 currently represents the main legislative initiative aimed at regulating artificial intelligence in Brazil. The proposal establishes principles, guidelines, and governance mechanisms for the development and use of artificial intelligence systems, focusing on the protection of fundamental rights and the promotion of technological innovation.

Inspired by international regulatory models, especially the European Union's AI Act, the bill adopts a risk-based approach. Under this model, artificial intelligence systems are classified according to the level of risk they may pose to individuals or society, with regulatory obligations established proportionally to these risks.

Applications considered high-risk, such as systems used in decisions affecting fundamental rights or in sensitive sectors such as healthcare, public safety, and labor relations, may be subject to stricter requirements for transparency, human oversight, and auditing.

The bill also provides for the creation of governance and oversight mechanisms, as well as the definition of responsibilities for developers, providers, and users of artificial intelligence systems. The proposal seeks to balance two objectives that are often in tension in the regulatory debate: on one hand, the need to protect individual and collective rights; on the other, the importance of encouraging technological innovation and economic competitiveness.

For the business environment, the eventual approval of the bill could bring about a significant change in the way artificial intelligence systems are developed and implemented within organizations.

Legal Liability and Risk Management in Corporate Use of AI

One of the main legal concerns related to the use of artificial intelligence in the corporate environment concerns liability for automated decisions. As algorithmic systems increasingly influence commercial, financial, or operational decisions, there is a growing need to determine who is liable for any damages caused by these technologies.

This legal discussion involves different liability models, including strict liability (responsabilidade civil objetiva, liability regardless of fault), fault-based liability, and shared liability among the various parties involved in the development and operation of the artificial intelligence system.

In certain contexts, especially when there is a direct impact on consumers or data subjects, Brazilian courts may interpret that companies have a duty to ensure transparency, human oversight, and control mechanisms over automated decisions.

Another relevant aspect involves the risk of algorithmic discrimination. Artificial intelligence systems trained on large volumes of data may reproduce existing biases in society, generating potentially discriminatory decisions in recruitment processes, credit granting, or performance evaluations.

This type of risk reinforces the importance of algorithmic audits, regulatory impact assessments, and the implementation of internal technology governance policies.

Regulatory Trends and Strategic Impacts for Businesses

The advancement of artificial intelligence regulation is not a phenomenon exclusive to Brazil. Several jurisdictions around the world have been developing regulatory frameworks aimed at governing this technology, most notably the European Union, which recently approved the first comprehensive legal framework on artificial intelligence.

In this global context, Brazil seeks to build a regulatory model that combines the protection of fundamental rights, the stimulation of innovation, and legal certainty for the business environment.

The regulatory trend points toward the adoption of corporate governance mechanisms specifically aimed at the responsible use of artificial intelligence-based technologies. Among these practices are the implementation of technology compliance programs, the creation of internal data and algorithm governance committees, and the periodic conduct of regulatory impact assessments.

Companies that adopt these practices proactively tend to reduce legal risks, strengthen the trust of consumers and investors, and position themselves more competitively in a scenario of increasing technological regulation.

The regulation of artificial intelligence in Brazil represents one of the most relevant legal topics of the current era for the business environment. The advancement of Bill No. 2,338/2023 signals that the country is moving toward the creation of a specific legal framework to govern the development and use of this technology.

For companies that already use or intend to use artificial intelligence in their operations, monitoring this regulatory process is essential for risk management and for building sustainable business strategies in the long term.

In this context, the adoption of practices related to technological governance, algorithmic transparency, and data protection tends to become a central element of contemporary corporate management. Preventive analysis of legal and regulatory risks can help companies use artificial intelligence in an ethical, safe, and legally responsible manner.

Written by Guilherme Henrique Soares