AI Policy Wiki
Dashboard

Resolução CFM nº 2.454/2026 — regulation of AI use in medicine (Brazil, February 2026)

high confidence · updated 2026-07-26

Brazil's Federal Council of Medicine resolution governing AI in medical practice nationwide, published in the Diário Oficial da União on February 27, 2026 and effective 180 days later. Establishes the physician as final decision-maker, prohibits delegating the communication of diagnoses, prognoses, or therapeutic decisions to AI, protects physicians from liability for failures attributable solely to AI systems where diligent use is shown, requires patient notification, and classifies systems by risk level from low to unacceptable.

Published by the Conselho Federal de Medicina in the Diário Oficial da União on Friday, February 27, 2026, regulating the use of artificial intelligence in medicine throughout Brazil. It takes effect 180 days after publication. Rapporteur: federal councillor Jeancarlo Cavalcante, coordinator of the CFM's AI Commission. The resolution followed a working group that spent a year and a half on the proposals, which Cavalcante described as "the fruit of broad debate with specialists and observation of international best practices."

Summarized here from the CFM's own announcement; the resolution's operative text has not been captured.

The physician's authority

The resolution's organizing principle is that AI is decision support and nothing more. It grants physicians the right to use AI tools "as support for clinical decision-making, health management, scientific research and continuing medical education," within the profession's ethical and legal limits, while providing that "the final word on diagnostic, therapeutic and prognostic decisions will always be the physician's."

Two corollaries follow. Physicians may refuse to use technologies that are not scientifically validated, lack relevant regulatory certification, or conflict with the ethical, technical or legal principles of medicine. And they may accept or reject a system's recommendations according to their own technical and ethical judgment "without suffering penalization for choosing not to follow a given recommendation of the tool" — a protection against institutional pressure to defer to a system, distinct from the protection against liability.

The resolution states that AI solutions "are not sovereign" and that human supervision is mandatory: "under no circumstances may the technology substitute or restrict the final authority of the physician."

Prohibited delegation

The resolution "prohibits delegating to artificial intelligence the communication of diagnoses, prognoses or therapeutic decisions." This separates the act of communication from the act of deciding — a system may inform the decision, but the disclosure to the patient may not be automated.

Use of AI must not compromise "the physician-patient relationship, qualified listening, empathy, confidentiality and respect for human dignity."

Liability

The resolution "protects the physician against undue liability for failures attributable exclusively to AI systems, provided that diligent, critical and ethical use of the tool is demonstrated." The conditional does substantial work: the protection is earned by documented practice rather than automatic. Corresponding duties are placed on the physician — to exercise critical judgment over generated recommendations, to remain current on the systems' limitations, and to record in the medical chart that the technology was used as decision support.

Patient rights

Patients have the right "to be informed, clearly and accessibly, whenever artificial intelligence is used" as relevant support in their care, along with rights to clear information about their health status, to seek a second opinion, to protection of their personal data, not to be subjected to experimental interventions without specific consent, and to privacy and confidentiality.

Governance and risk classification

The resolution classifies AI systems by risk level — low, medium, high, or unacceptable — "considering factors such as impact on fundamental rights, complexity of the model, degree of autonomy and sensitivity of the data used." The inclusion of degree of autonomy and data sensitivity alongside rights impact distinguishes it from purely use-case-based schemes.

Medical institutions that develop or operate their own systems must establish internal governance processes and, where applicable, create a Commission on AI and Telemedicine under medical coordination, reporting to the technical directorate.

All data used in developing, training and implementing systems must comply with Brazil's LGPD and health-information security rules, "with technical and administrative measures compatible with the criticality of the information processed."

Supervision and enforcement fall to the Regional Councils of Medicine (CRMs) within their competences — a professional-discipline enforcement route rather than an administrative-regulator one.

Relationships