Context: Why Brazil Needed a Specific Law

Before PL 2338/2023, Brazil regulated AI in a fragmented way — LGPD covered personal data, the Internet Civil Framework regulated online liability, and sector-specific legislation handled specific cases like credit and health. But AI created new risks that these laws could not address: systems that make autonomous decisions about people, models that generate disinformation at scale, algorithms that discriminate without leaving an auditable trail.

What the Bill Establishes: Five Pillars

1. Risk classification: AI systems are classified into three categories: low risk (most applications), high risk (decisions affecting people in critical areas), and excessive risk (prohibited).

2. Mandatory transparency: Citizens have the right to know when they are interacting with AI. Companies using AI in customer service, recruitment, credit, or health must clearly disclose this.

3. Decision explainability: When an automated decision affects a citizen — credit refusal, rejection in a selection process, insurance denial — they have the right to an explanation in understandable language about the factors that influenced the decision.

4. Impact assessment: High-risk systems must undergo an Algorithmic Impact Assessment (AIA) before deployment, including technical documentation, bias analysis, and a continuous monitoring plan.

5. Governance and accountability: Companies that develop or deploy high-risk AI must designate an AI compliance officer — similar to the LGPD's DPO — and maintain auditable records of automated decisions.

What Is Prohibited: Excessive Risk Uses

The bill categorically prohibits: social scoring systems that rank citizens by behavior to restrict rights; AI that manipulates behavior in a subliminal way; real-time facial recognition in public spaces for mass surveillance; and AI that classifies people based on sensitive characteristics for discriminatory purposes.

Who Is Affected: Extraterritorial Reach

The bill applies to any company that develops or offers AI systems to users located in Brazil, processes data of individuals located in Brazil, or makes automated decisions affecting people in Brazil. This means Google, Meta, OpenAI, Microsoft, and any other foreign company operating in Brazil is subject to the law.

What Changes for Companies: Practical Obligations

HR and recruitment: Companies using automated resume screening must inform candidates, ensure the system does not discriminate, and offer human review when requested. Credit and finance: Fintechs and banks must explain refusals in accessible language. Healthcare: AI-assisted diagnostic systems are classified as high risk and require AIA before deployment. Customer service: Chatbots must identify themselves as AI.

New Rights for Citizens

The bill creates new digital rights: right to information, right to explanation, right to human review, right to correction, and right to non-discrimination based on sensitive characteristics.

The Regulator: Who Will Enforce

The bill designates ANPD (National Data Protection Authority) as the central AI regulation body. Fines can reach 2% of the company's annual revenue in Brazil, capped at R$50 million per violation — identical structure to LGPD.

What Should Already Be Done Now

Companies that want to be in compliance when the law takes effect need to start now: inventory all AI systems and classify them by risk level; designate an AI Compliance Officer; begin technical documentation of high-risk systems; train teams on the legal obligations that AI-assisted decisions entail.