Projeto de Lei nº 2338, de 2023 ("Dispõe sobre o uso da Inteligência Artificial" — "Provides for the use of Artificial Intelligence"), commonly called the Marco Legal da IA (Legal Framework for AI) or the Brazil AI Act, is a comprehensive horizontal AI bill modelled broadly on the EU AI Act (Regulation 2024/1689). It was approved by Brazil's Federal Senate on 10 December 2024 and remains pending in the Chamber of Deputies as of April 2026. The bill pairs a risk-based tiered structure with an individual-rights layer built on Brazil's existing data-protection law, and restricts real-time biometric identification and certain other uses (Source: https://www25.senado.leg.br/web/atividade/materias/-/materia/157233).
Status and legislative history
PL 2338/2023 was drafted by a commission of jurists constituted by the Senate in 2022 to draft an AI framework, chaired by Minister Ricardo Villas Bôas Cueva of the Superior Court of Justice. It was introduced in the Federal Senate by Senator Rodrigo Pacheco, then Senate President (PSD-MG), and formally introduced on 3 May 2023. The Senate approved the bill, after amendments, on 10 December 2024.
On 17 March 2025 the Senate forwarded the bill to the Chamber of Deputies. Because it had been referred to more than three standing committees — Labor; Culture; Education; Consumer Protection; Science, Technology and Innovation; and Constitution, Justice and Citizenship — the Chamber president established a special committee on 29 April 2025. As of April 2026 the bill remained under review in the Chamber with no scheduled floor vote.
Enactment requires three steps: Senate approval (achieved 10 December 2024), Chamber of Deputies approval (pending as of April 2026), and presidential sanction (pending).
Scope
The bill applies to the development, implementation, and use of AI systems in Brazil, regardless of where the provider is established, and covers both public-sector and private-sector use. It has extraterritorial reach: providers outside Brazil whose systems affect Brazilian residents fall within scope. The framework uses a risk-based tiered structure of prohibited, high-risk, and excessive-risk categories, analogous to the EU's unacceptable, high, and limited tiers.
The bill excludes AI used exclusively for scientific research and development; AI systems used for national defence and security (subject to a separate regime); and AI systems with open formats and free licences, unless placed on the market as a product or service.
Key provisions (Senate-approved text, December 2024)
Prohibited AI systems (Art. 14–15)
Outright bans include AI that exploits vulnerabilities of specific groups (children, the elderly, people with disabilities, or people in situations of social or economic vulnerability); social scoring by public authorities for purposes unrelated to the underlying behaviour, or disproportionate to it; weapons autonomous in target selection and engagement against persons (the autonomous-weapons carve-out); and real-time remote biometric identification in publicly accessible spaces, except for narrowly defined law-enforcement purposes (finding missing persons, serious crime investigation, and arresting individuals subject to warrants).
High-risk AI systems (Art. 17–26)
A specified list is subject to detailed obligations, covering critical infrastructure management (transport, water, electricity); education and vocational training (access, evaluation); employment (recruitment, promotion, termination); access to essential public and private services (credit, insurance, healthcare eligibility); law enforcement and justice administration; and migration and border management. Generative-AI systems trained at very large scale were contested during Senate debates; the final version includes specific obligations on "AI systems of general purpose," with additional duties for those with systemic impact, tracking the EU AI Act's GPAI structure.
Obligations for high-risk systems include algorithmic impact assessment, data-governance measures, risk management throughout the lifecycle, transparency and explainability, human oversight, and cybersecurity and robustness.
Data-subject rights (Art. 5–13)
PL 2338 grants an extensive set of individual rights, layered on top of Brazil's LGPD (data-protection law). They include a right to information (clear and adequate information about any AI system that produces legal effects or significantly affects a person); a right to explanation (post-hoc explanation of decisions); a right to contest AI-mediated decisions and request human review; a right to non-discrimination (protection against algorithmic discrimination, with a presumption of discrimination if disparate impact is shown); a right to privacy and personal-data protection (cross-referencing the LGPD); and a right to participate in decisions about AI systems that affect collective rights. The collective-rights dimension reflects Brazilian consumer-protection jurisprudence.
Copyright and training data (Art. 42–44)
The bill provides a text-and-data-mining exception for non-commercial research uses. Commercial uses of copyrighted works for AI training require authorisation or an applicable licence. Creators have the right to opt out of having their work used for AI training, with specific disclosure obligations on developers. A remuneration arrangement for creators whose works are used remained contested; CISAC and Brazilian creators' organisations lobbied strongly for this provision (Source: CISAC, "Creators Celebrate Brazil's Senate Approval of AI Bill" (2024)).
Governance and enforcement
The bill establishes a National System for Regulating and Governing AI (SIA), a coordinating structure across regulators. The Senate text designates the ANPD (National Data Protection Authority) as the competent authority, though industry has lobbied for a distinct AI regulator. Sectoral regulators retain authority in their domains under a federated model — the BCB for banking, the ANS for health insurance, and others. Penalties reach up to BRL 50 million per infraction or 2% of group turnover in Brazil, lower than the EU AI Act's 7% cap.
Comparison with other approaches
| Dimension | PL 2338 | [[eu-ai-act | EU AI Act]] | US patchwork | [[china-generative-ai-interim-measures | China CAC framework]] |
|---|---|---|---|---|---|---|
| Structure | Risk-based tiers + individual rights | Risk-based tiers + GPAI | Sectoral + state-level | Content-control + licensing | ||
| Individual rights | Extensive (explanation, contest, non-discrimination, collective rights) | Limited (transparency, complaint mechanism) | Varies (Colorado AI Act (SB 24-205) and SB 25B-004 (Date Amendment) has duty of care) | Minimal | ||
| Copyright/training | Opt-out + remuneration for creators | Opt-out via Art. 53 | Litigation-driven | Unclear; Art. 7 requires "legal sources" | ||
| Regulator | ANPD + sectoral (federated) | EU AI Office + national | Sectoral + state AGs | CAC | ||
| Real-time biometrics | Prohibited with narrow law-enforcement exception | Prohibited with narrow law-enforcement exception | No federal rule | Permitted and extensively deployed | ||
| Penalties | Up to BRL 50M / 2% Brazilian turnover | Up to €35M / 7% global turnover | Varies | Licensing revocation + fines |
Relative to other comprehensive AI statutes, observers have noted three distinctive features of the Brazilian bill: an individual-rights layer that builds on the LGPD and constitutional protection of personality rights and is broader than the EU AI Act's; a creator-remuneration provision for training data not found in other major AI bills; and the collective-rights dimension drawn from Brazilian consumer-protection jurisprudence.
Contested provisions and reactions
Several provisions remained contested as the bill moved to the Chamber of Deputies. Industry — domestic tech firms, banks, and international platforms — lobbied for loosening the Senate text, with concerns focused on narrowing the high-risk list and stripping the creator-remuneration clause. The ANPD, established in 2020 and already engaged in LGPD enforcement, drew resource-adequacy questions over its assignment as AI-regulation lead.
Real-time biometric identification was already in use by several Brazilian states, including São Paulo and Bahia, for policing; the bill's prohibition would require rolling those deployments back, making it a point of contention in the Chamber. On copyright, publishers, music-rights societies (ECAD and CISAC affiliates), and the Authors' Union supported the remuneration clause, while AI developers argued it would be administratively unworkable at training-corpus scale. The GPAI-style obligations were added late in the Senate process, and the mechanism for determining "systemic impact" — whether by compute threshold, user count, or discretionary designation — was left under-specified. Because Brazil is a federation and certain high-risk domains such as public-security biometrics and education are governed at the state level, the bill's preemption scope is also contested.
Commentators have described the bill as a potential regional template, noting that Brazil is the second-largest AI market in Latin America after Mexico and the largest Portuguese-language jurisdiction, and as a test of the limits of the "Brussels effect," since Brazil borrowed structure from the EU AI Act but added LGPD-integrated individual rights rather than cloning EU rules. If enacted in 2026 or 2027, Brazil would become the first Latin American country with a comprehensive AI law, joining South Korea (2025) and the EU (2024). The creator-remuneration provision, if retained, would be the first of its kind among major AI bills, a precedent AI Copyright Litigation — Analysis plaintiffs could cite (Source: Library of Congress, "Brazil: Senate Advances Discussions on Bill to Regulate AI Use" (May 2025); Source: White & Case, AI Watch: Global Regulatory Tracker — Brazil).
Relationships
- related: EU AI Act (Regulation 2024/1689) — the regulatory model PL 2338 most closely tracks
- related: South Korea AI Basic Act — Source Summary — contrast: Korea enacted comparable legislation Dec 2024; Brazil's Senate approved the same month but Chamber pending
- related: Japan AI Promotion Act — Source Summary — contrast: pro-innovation minimalist approach
- related: Canada AIDA (Bill C-27, Part 3) — Source Summary — contrast: Canadian attempt at comparable horizontal law, died
- related: AI Copyright Litigation — Analysis — PL 2338's creator-remuneration provision would be the first of its kind among major AI bills
- related: China — Interim Measures for the Management of Generative AI Services — contrast: content-control model
- related: AI Sovereignty — Brazil asserting regulatory sovereignty distinct from EU, US, China
Sources
- PL 2338 source summary
- Library of Congress, "Brazil: Senate Advances Discussions on Bill to Regulate AI Use" (May 2025)
- Lexology, "Brazilian Bill regulating the use of AI is approved by Senate and goes to the Chamber of Deputies"
- White & Case, AI Watch: Global Regulatory Tracker — Brazil
- CISAC, "Creators Celebrate Brazil's Senate Approval of AI Bill" (2024)
- Senate legislative record:
https://www25.senado.leg.br/web/atividade/materias/-/materia/157233