Quick Answer:
Brazil still lacks a national legal framework for artificial intelligence: the AI Legal Framework (PL 2,338/2023), approved by the Senate in December 2024, remains without a scheduled final vote. Meanwhile, ANPD runs a regulatory sandbox, and Brazil's Federal Council of Medicine already approved its own AI resolution for healthcare, effective since August 2026.
Key Takeaways:
As of August 2026, Brazilian companies developing or deploying artificial intelligence continue operating without a comprehensive national regulatory framework. The bill known as the AI Legal Framework, approved unanimously by the Federal Senate on December 10, 2024, still has no final voting date in the Chamber of Deputies. While Congress leaves the definitive text unresolved, regulatory agencies and professional councils are moving on their own, publishing sectoral rules that already govern AI use in areas such as medicine, telecommunications, and capital markets. The result is a regulatory patchwork that coexists with legislative uncertainty, right as AI adoption accelerates across the country.
The bill known as the AI Legal Framework (PL No. 2,338/2023) was approved unanimously by the Federal Senate on December 10, 2024. Since then, as reported by the law firm TozziniFreire, the text has remained pending a rapporteur opinion in the Special Commission of the Chamber of Deputies, with no voting date scheduled.
The originally planned timeline called for a final opinion on May 19, 2026, and a plenary vote on May 27, 2026, according to the same dates reported by TozziniFreire. Neither deadline was met, and the bill remains paused as Brazil's Congress faces an increasingly tight electoral calendar.
The Executive Branch added another layer of complexity. In December 2025, it introduced a complementary bill to create the National AI System (SIA), after flagging what TozziniFreire describes as a constitutional defect in the Senate-approved text: the assignment of rule-making authority to Brazil's National Data Protection Authority (ANPD) without adequate legal backing. The proposed SIA would designate ANPD itself as coordinator of the new system, an approach meant to resolve the constitutional objection while keeping the agency at the center of AI governance going forward.
The legislative knot: the Senate approved its version of the AI Legal Framework more than a year and a half ago. What is missing is the Chamber of Deputies' opinion, a new complementary bill from the Executive Branch, and consensus on who ultimately holds authority to regulate AI in Brazil: Congress, ANPD, or a new national system that has not been created yet.
While Congress deliberates, ANPD has not stood still. The agency established an AI regulatory sandbox through Public Notice No. 2/2025, a controlled environment where selected companies test AI solutions under the agency's direct supervision. The program's first cycle runs from March 18 through December 2026, according to TozziniFreire.
Three companies are participating in this first cycle: Metatext, with its Guardion.AI solution focused on autonomous agent security; Synapse AI, with Trajetto, aimed at rail management; and Prevvine Tecnologia, with STAIDOC, a medical AI solution. On July 2, 2026, ANPD published its first partial monitoring report on the program, documenting the progress of these controlled tests.
This move does not happen in isolation. According to Atualidade Política, governments worldwide advanced during 2026 from general ethical principles toward more concrete controls over data, security, and algorithmic accountability. The same outlet places ANPD's July 2, 2026 report alongside other recent regulatory moves: Greece approved oversight authorities and AI regulations on July 16, 2026, China implemented rules for anthropomorphic services and virtual companions on July 15, 2026, the EU AI Omnibus package entered into force on July 27, 2026, and new EU AI Act rules began applying to additional systems on August 2, 2026. Brazil, in other words, is not regulating in a vacuum. It is moving within a global wave of increasingly concrete AI oversight, even though it still lacks a federal law of its own to anchor it.
The absence of a national legal framework has not stopped Brazil's sectoral regulators from acting. The most recent and comprehensive example came from the Federal Council of Medicine (CFM), which deliberated Resolution CFM No. 2,454/2026 on February 11, 2026. The rule takes effect on August 26, 2026, and, according to TozziniFreire, establishes a comprehensive framework for AI use in medical research, development, governance, auditing, and responsible use.
The resolution's core requirement, according to TozziniFreire, is that artificial intelligence function strictly as a support tool: the physician retains the final decision at all times. The rule explicitly prohibits AI from communicating diagnoses directly to patients, a bright line separating permitted medical AI use from the risk of replacing human clinical judgment.
Medicine is not the only sector that moved on its own. TozziniFreire documents that Anatel, the telecommunications regulator, had already codified eight mandatory AI principles in Article 40 of its Resolution No. 777/2025, in effect since April 30, 2025: reliability, fairness, non-discrimination, pluralism, privacy, fundamental rights, sustainability, and transparency. The Securities Commission (CVM), for its part, approved its Resolution No. 246 on July 30, 2026, creating a new Financial Technology Division (Ditec) to oversee how tokenization and AI are reshaping the issuance, trading, and custody of financial assets, under president Otto Lobo, who took office in June 2026.
The pattern repeating across every sector:
This regulatory patchwork is not unique to Brazil, and it is not an abstract problem reserved for the legal departments of large corporations. More consumers across Brazil, the United States, and the rest of Latin America are already using generative AI tools, such as ChatGPT, Claude, Perplexity, and Google AI Overviews, to search for products, services, and local businesses, regardless of whether the legal framework behind those tools is still being debated in Congress.
At MerchandisePROS, we think this raises a question that matters for your business well beyond the legislative debate: if a potential customer asks ChatGPT or Perplexity for the best option in your industry and your city, does your business show up in the answer? This is our own read on the landscape, not a fact confirmed by the sources cited in this article: regulatory uncertainty about how these tools operate does not stop them from recommending businesses today.
That is why we offer an AI Search Optimization (AEO) service: it evaluates whether your business has the structured data, citations, and consistent presence these platforms need to recommend you with confidence. You can see the full detail of this and other services on our services page. Start with our free audit, which gives you a 0-to-100 score and a prioritized action plan in under 60 seconds. If you would rather talk directly with our team about your digital presence, you can book a free consultation here.
No. The AI Legal Framework (PL No. 2,338/2023) was approved by the Federal Senate on December 10, 2024, but according to TozziniFreire, it remains pending a rapporteur opinion in the Chamber of Deputies' Special Commission, with no voting date scheduled.
It is a controlled environment that Brazil's National Data Protection Authority established through Public Notice No. 2/2025, allowing selected companies such as Metatext, Synapse AI, and Prevvine Tecnologia to test AI solutions under direct supervision. The first cycle runs from March 18 through December 2026, and ANPD published its first partial monitoring report on July 2, 2026.
Resolution CFM No. 2,454/2026, in effect since August 26, 2026, requires artificial intelligence to function strictly as a support tool in medical practice. The physician retains the final decision, and the rule explicitly prohibits AI from communicating diagnoses directly to patients.
Because the absence of a national law does not stop regulators such as Anatel (telecommunications) and CVM (capital markets) from advancing their own rules. TozziniFreire documents that Anatel codified eight mandatory AI principles in April 2025, and that CVM created a dedicated financial technology division in July 2026 to oversee AI and tokenization.
"While Congress debates the perfect text, sectoral regulators and AI platforms are already making decisions every day. Your business cannot wait for legal uncertainty to resolve before deciding whether it is visible on those platforms."
Diego Medina F., Founder of MerchandisePROS
Get your free audit and find out exactly which visibility signals you are missing. Score in 60 seconds, PDF report to your inbox.
Check My Score Free Free Consultation