Resolution of the Conselho Federal de Medicina published in the Diário Oficial da União on 27 February 2026, in force 180 days after publication, regulating artificial intelligence in medical practice throughout Brazil. Rapporteur: federal councillor Jeancarlo Cavalcante, coordinator of the CFM's AI Commission, following an eighteen-month working group. Primary text: Resolução CFM nº 2.454/2026 — regulation of AI use in medicine (Brazil, February 2026).
Instrument type
A CFM resolution is professional-body regulation with the force of a binding norm over licensed physicians, enforced through the Regional Councils of Medicine (CRMs) by disciplinary process rather than by an administrative regulator. It therefore reaches clinicians and the institutions they practise in, but not AI developers directly — obligations on systems attach through the physicians and institutions that deploy them.
Key provisions
Physician authority. Physicians may use AI "as support for clinical decision-making, health management, scientific research and continuing medical education," but "the final word on diagnostic, therapeutic and prognostic decisions will always be the physician's." They may refuse tools that are not scientifically validated, lack regulatory certification, or conflict with professional ethics, and may reject a system's recommendation "without suffering penalization" — a protection against institutional pressure distinct from the liability protection below.
Prohibited delegation. The resolution "prohibits delegating to artificial intelligence the communication of diagnoses, prognoses or therapeutic decisions." Communication is separated from decision: a system may inform the judgment, but the disclosure to the patient may not be automated.
Conditional liability protection. Physicians are shielded from responsibility "for failures attributable exclusively to AI systems, provided that diligent, critical and ethical use of the tool is demonstrated." The condition carries the provision — protection is earned through documented practice, with corresponding duties to exercise critical judgment, track the systems' limitations, and record AI use in the medical chart.
Patient rights. Patients must be informed "clearly and accessibly, whenever artificial intelligence is used" as relevant support, with rights to clear information on their health status, a second opinion, data protection, freedom from experimental intervention without specific consent, and confidentiality.
Risk classification. Systems are classified low, medium, high, or unacceptable, "considering factors such as impact on fundamental rights, complexity of the model, degree of autonomy and sensitivity of the data used."
Institutional governance. Institutions developing or operating their own systems must establish internal governance and, where applicable, a Commission on AI and Telemedicine under medical coordination reporting to the technical directorate. All data used in development, training and implementation must comply with the LGPD and health-information security rules.
Human supervision. AI solutions "are not sovereign" and supervision is mandatory: "under no circumstances may the technology substitute or restrict the final authority of the physician."
Comparison with other approaches
The four-level risk scheme echoes the EU AI Act's tiering, but its criteria differ in a way that matters for clinical AI: alongside impact on fundamental rights it weighs degree of autonomy and data sensitivity, so an otherwise low-stakes tool may rise a tier by operating with less human intervention. Where the EU Act classifies by intended use, this classifies partly by how the system behaves in operation.
Against the US approach, where the FDA regulates software as a medical device at market entry and California AB 3030 (Healthcare AI Disclosure) requires a disclosure for generative AI in patient communications, the CFM resolution regulates the clinician's conduct rather than the product, and enforces through professional discipline. It sits alongside Brazil's horizontal PL 2338 rather than within it — a sector-specific standard of care arriving before the general statute.
Key tensions
The conditional liability shield transfers documentation burden to the clinician: protection depends on demonstrating diligent use, which in practice requires charting that the physician engaged critically with a recommendation. And the prohibition on delegating communication sits awkwardly with triage and messaging systems that already draft patient-facing text, leaving the boundary between drafting and communicating to be worked out in enforcement.
Relationships
- instance-of: AI Governance (umbrella)
- regulated-by: Healthcare — AI Deployment — a sector-specific standard of care for AI in medicine
- related: Brazil AI Bill (PL 2338/2023), EU AI Act (Regulation 2024/1689), California AB 3030 (Healthcare AI Disclosure), AI Liability, Human Oversight, Resolução CFM nº 2.454/2026 — regulation of AI use in medicine (Brazil, February 2026)