Quick Answer:
Brazil's AI bill, PL 2338/2023, approved by the Senate on December 10, 2024, is still awaiting a Chamber of Deputies vote. According to Tech Policy Press, a lack of political consensus pushed the vote from late 2025 to February 2026, and the two most contested issues are copyright for AI training and the definition of high-risk systems.
Key Takeaways:
The bill that would define how Brazil regulates artificial intelligence still has not crossed the finish line. PL 2338/2023 was approved by the Senate on December 10, 2024, but it still needs Chamber of Deputies approval before it can reach presidential signature, according to Artificial Intelligence Act Tracker. While the bill inches forward, Brazil's political calendar is tightening: the second half of 2026 will be dominated by election campaigning, shrinking the window available for deputies to debate and vote on a text this technical.
According to Tech Policy Press, the Chamber of Deputies vote was originally scheduled for late 2025. That date was pushed to February 2026 due to "a lack of political consensus and disagreement over the text." The outlet adds that further delays stemmed from topics such as data centers, which became relevant during the proceedings and broadened the discussion beyond the bill's original scope.
Tech Policy Press also cites an expert identified as Picolo, who noted that the second half of 2026 will be dedicated to campaigning, creating a tight window for the bill to move forward before legislative attention shifts fully to the elections.
The two issues holding up the vote: according to Tech Policy Press, the two most contested points are (1) how copyright law applies to content used to train AI systems, and (2) how "high-risk" systems subject to stricter transparency rules are defined and treated.
According to Artificial Intelligence Act Tracker, PL 2338/2023 takes a tiered, risk-based regulatory approach. There is a "prohibited" tier for excessive-risk systems that would be banned outright, and a "high-risk" tier subject to additional safety and compliance requirements, with particular focus on systems that could affect public safety or fundamental human rights.
The same tracker details that the bill aligns with Brazil's General Data Protection Law (LGPD) and establishes a new regulatory authority for oversight and enforcement. The text also permits the use of copyrighted material for AI training under certain non-profit conditions — though, as noted above, how copyright law applies to commercial AI training more broadly remains one of the two most contested points ahead of the final floor vote.
The penalties, by the numbers:
Source: Artificial Intelligence Act Tracker.
A tiered, risk-based framework like the one Artificial Intelligence Act Tracker describes is a deliberate design choice, not a technicality. Instead of writing one set of rules for every AI system, the bill separates systems into different compliance buckets depending on how much harm they could cause. A chatbot that recommends restaurants faces a very different set of obligations than a system used to screen loan applications or flag people for law enforcement attention. That distinction is precisely what makes the "high-risk" definition — one of the two contested issues Tech Policy Press identifies — so consequential. Get the definition too broad, and ordinary business software gets buried in compliance paperwork. Get it too narrow, and systems that genuinely affect people's lives escape scrutiny entirely.
This is also why the new regulatory authority mentioned by Artificial Intelligence Act Tracker matters as much as the fine schedule. A compliance framework is only as strong as the body that enforces it. Businesses operating in or selling into Brazil should watch not just whether PL 2338/2023 eventually passes, but which agency ends up responsible for interpreting "high-risk" in practice, since early enforcement decisions tend to set the tone for years of subsequent compliance.
Tech Policy Press's framing of a shrinking legislative calendar is not unique to Brazil. Comprehensive technology legislation regularly gets caught behind election cycles in democracies worldwide, because lawmakers redirect floor time toward campaign-adjacent priorities as elections approach. If the Chamber of Deputies does not act on PL 2338/2023 before that shift happens, the practical effect is not that the bill dies — Brazilian legislative sessions can carry pending bills forward — but that final passage, and therefore legal certainty for companies deploying AI in Brazil, gets pushed further out. For businesses already building compliance programs around the bill's current draft, that kind of delay is its own cost: teams end up designing to a moving target instead of a settled rulebook.
According to the technical analysis published by Data Privacy Brasil, the original text of Article 15 listed risk to information integrity, freedom of expression, the democratic process, and political pluralism among the criteria for identifying high-risk AI scenarios. Those criteria were removed. The rapporteur justified the change by citing "the imperative of guaranteeing freedom of expression as a fundamental value for any democratic society."
Data Privacy Brasil also documents the insertion of Article 77, which states that regulation of aspects related to the circulation of online content that may affect freedom of expression — including the use of AI for content moderation and recommendation — may only be done through specific legislation. In other words, the AI bill itself closes the door on using its own text to directly regulate social media content moderation.
On who pushed for these changes, Data Privacy Brasil describes "a pressure movement, possibly supported by the federal government, to relax the wording" of Article 15's caput. It is worth noting that the source uses conditional language — "possibly" — and does not definitively credit the federal government with these amendments.
The cultural and civic response:
According to Data Privacy Brasil, more than 35,000 people voiced support for stronger copyright protections through Brazil's e-Cidadania civic participation portal. A group of artists publicly signed a letter opposing looser copyright rules for AI training. The signatories documented by the source are:
For businesses in Houston, Cypress, Mexico City, Bogota, or Sao Paulo, Brazil's legislative fight is a reminder of something more immediate: the way generative AI cites, recommends, and describes businesses is already shifting, law or no law. While Brazil debates how to regulate AI model training, tools like ChatGPT, Perplexity, and Google's AI Overviews are already deciding today which businesses they recommend when a prospective customer asks for a service.
That gap between "AI regulation is still being written" and "AI is already making recommendations right now" is the core tension running through this entire story. Lawmakers in Brazil are working through how copyright, high-risk classification, and content-moderation boundaries should apply to AI systems going forward. None of that changes the fact that an answer engine somewhere is, this week, telling a potential customer which business to call. Waiting for regulatory clarity before addressing AI visibility means ceding that ground to competitors who did not wait.
That is exactly the gap MerchandisePROS's AI Search Optimization (AEO) service closes: we audit the signals that determine whether your business gets cited by AI — structured data schema, FAQ content, authoritative citations, NAP data consistency — and hand you a concrete action plan. You can review the full breakdown of this and other services on our services page.
"While governments debate how to regulate AI, AI is already deciding which businesses it recommends today. Do not wait for a law to pass to make sure your business is the one being cited."
Diego Medina F., Founder of MerchandisePROS
It is the bill that establishes a risk-based AI regulatory framework for Brazil, with a prohibited tier and a high-risk tier subject to additional safety and compliance requirements. The Senate approved it on December 10, 2024, and it now awaits a vote in the Chamber of Deputies.
Brazil's Senate approved PL 2338/2023 on December 10, 2024, according to Artificial Intelligence Act Tracker. The internal Temporary Committee on Artificial Intelligence (CTIA) had approved the substitute report five days earlier, on December 5, 2024, according to Data Privacy Brasil.
According to Artificial Intelligence Act Tracker, the maximum fine is BRL 50 million (approximately $1.6 million USD) or, alternatively, 2% of the company's total turnover, applying to both providers and operators of AI systems.
According to Tech Policy Press, the Chamber of Deputies vote, originally scheduled for late 2025, was postponed to February 2026 due to a lack of political consensus and disagreement over the text, including added debate over data centers.
According to Data Privacy Brasil, the original text of Article 15 listed risk to information integrity, freedom of expression, the democratic process, and political pluralism as criteria for identifying high-risk AI scenarios. The rapporteur removed those criteria, justifying the change as necessary to guarantee freedom of expression as a fundamental value for any democratic society.
While governments debate AI regulation, answer engines are already citing businesses today. Get your free AEO audit and find out which signals are missing.
Check My AEO Score Free Free Consultation