Preparing for the Brazil AI Bill (PL 2338/2023)
Brazil AI Bill (PL 2338/2023)
- Status
- Under discussion
- Binding
- No
- Object analysed
- AI system
- Requirements
- 20
- Next milestone
- Oct 2026
In short
Senate text approved on 10/12/2024, close to the AI Act: excessive risk, high risk (Art. 14), general-purpose AI, preliminary assessment and algorithmic impact assessment.
Steps to compliance
- Qualify each AI systemAxes to decide: PL 2338 risk level and Role (Art. 4).
- Determine your roleDuties vary by role: Developer, Distributor and Applier.
- Apply the 20 requirementsThey focus on: Transparency & notice, Risk management, Technical documentation and Explanation & redress.
- Prove it with checks46 checks to document, 40 of which also serve AI Act, RGPD and ISO 42001.
- Track the deadlinesNext milestone: Oct 2026, Vote pushed past the October 2026 elections (potential).
Scope and penalties
- Kind
- Bill
- Scope
- Developers, distributors and appliers of AI systems.
- Territorial reach
- Systems provided or used in Brazil.
- Penalties
- Senate text: up to BRL 50M or 2% of turnover per infringement; suspension.
- Jurisdiction
- Brazil
Timeline
Qualifying a system
Classification axes and possible verdicts
PL 2338 risk level
Role (Art. 4)
Requirements
20 requirements
| Code | Article | Requirement | Applies to | Checks |
|---|---|---|---|---|
| BR-01 | Arts. 12, 29 | Preliminary assessmentDetailClassify the system's risk before placing it on the market or using it. Optional for most agents but mitigates sanctions (Art. 50 §1); mandatory for developers of general-purpose and generative AI (Art. 29). | ||
| BR-02 | Art. 13 | Excessive-risk practicesDetailNo development, implementation or use of an excessive-risk system; developers take measures to prevent such uses (Art. 13 §1). | ||
| BR-03 | Art. 5 I | Information on interaction with AIDetailEveryone has the right to prior information that they are interacting with an AI system, through standard icons where relevant, in plain language for vulnerable groups (Art. 5 §§1 and 2). | ||
| BR-04 | Art. 19 | Synthetic content identifierDetailSynthetic content generated or modified by the system carries an identifier that allows its authenticity or origin to be verified. | ||
| BR-05 | Arts. 5 III, 18 | Non-discrimination and bias mitigationDetailMeasures to prevent, mitigate and correct discriminatory bias, including on the data used (Art. 18 I.e and II.e). | ||
| BR-06 | Arts. 6 I, 7 | Right to explanationDetailA person affected by a high-risk system may obtain, free of charge and in plain language, an explanation of the decision, recommendation or prediction made about them. | ||
| BR-07 | Arts. 6 II, 6 III, 9 | Contestation and human reviewDetailAffected persons may contest decisions and request human review; the procedures to exercise these rights are published. | ||
| BR-08 | Arts. 8, 18 I.d | Human oversightDetailHuman oversight allowing people to understand, interpret, decide on and intervene in the system; the degree of human oversight in the results is documented. | ||
| BR-09 | Art. 18 I.a, I.c, I.f | Applier documentationDetailThe applier documents the system across its lifecycle, the reliability and safety tests performed, and the information that makes results interpretable. | ||
| BR-10 | Art. 18 II.a, II.d | Developer documentation and explainabilityDetailThe developer keeps a record of its governance measures to inform the applier, and implements explainability measures. | ||
| BR-11 | Art. 18 II.b | Operation loggingDetailThe system automatically logs its operation so that its accuracy and robustness can be assessed. | ||
| BR-12 | Art. 18 II.c | Security testingDetailTests to assess appropriate levels of security, including of the environment the system runs in. | ||
| BR-13 | Art. 18 I.b | Monitoring of resultsDetailThe applier monitors the system's outputs for accuracy, robustness and discrimination, and mitigates what it finds. | ||
| BR-14 | Arts. 25-28 | Algorithmic impact assessmentDetailAn algorithmic impact assessment before placing on the market, kept up to date across the lifecycle. It may be carried out together with the LGPD data protection impact report (Art. 27), and its conclusions are published (Art. 28). | ||
| BR-15 | Arts. 25 §7, 42 | Serious incidentsDetailA serious risk discovered after release is reported immediately to the authority and the value chain, and serious incidents are reported to the sector authority. | ||
| BR-16 | Arts. 18 §3, 32 | Value-chain cooperationDetailAgents cooperate and share the information the others need to meet their obligations; a distributor checks the governance measures before placing on the market (Art. 16 §3). | ||
| BR-17 | Arts. 29, 30 | General-purpose and generative AIDetailThe developer documents development. With systemic risk, before release: model description, test documentation, residual risks, lawful data governance, energy efficiency and downstream documentation (Art. 30 I to VII). | ||
| BR-18 | Arts. 62, 64 | Training content and opt-outDetailA summary of the copyright-protected content used in development is published, and rights holders' opt-out is honoured. | ||
| BR-19 | Arts. 22, 23 | Public-sector dutiesDetailPublic bodies and operators of a public service using a high-risk system keep usage logs (who, which case, which purpose) and publish their preliminary assessments. | ||
| BR-20 | Art. 65 | Remuneration of rights holdersDetailRights holders whose content was used for training are remunerated. This chapter may be removed by the Chamber of Deputies. |
Checks to document
Evidence collected for a check counts for every regulation that uses it.
| Code | Check | Scope | Themes | Also used by |
|---|---|---|---|---|
| CHK-BR-PRELIM | Preliminary assessment carried out and kept on record | System | ||
| VER-002-01 | Documented process for detecting drift towards prohibited practices | Organisation | ||
| VER-002-02 | System free of prohibited practices (provider assessment) | System | ||
| VER-002-03 | System use free of prohibited practices (deployer assessment) | System | ||
| VER-018-D-01 | Persons informed of the interaction with an AI system | System | ||
| VER-029-D-01 | Affected persons informed of the use of the AI system | System | ||
| VER-018-D-03 | AI-generated content marked as such | System | ||
| VER-004-01 | Documented data governance (collection process, bias, quality) | System | ||
| VER-004-02 | Input data relevant and representative in view of the intended purpose | System | ||
| VER-028-D-03 | Input data sufficiently representative | System | ||
| VER-033-D-01 | Decision explanation procedure documented | Organisation | ||
| VER-033-D-02 | System explanation capability verified | System | ||
| VER-033-D-03 | Explanations provided on request within a reasonable timeframe | System | ||
| CHK-BR-CONTEST | Procedure to contest a decision and obtain human review published | Organisation | ||
| VER-008-01 | Documented escalation and emergency stop procedure | Organisation | ||
| VER-008-02 | System designed to allow human oversight (stop button, override) | System | ||
| VER-008-03 | Competent overseers assigned to the system | System | ||
| VER-005-02 | Instructions for use obtained and read by the deployer | System | ||
| VER-005-03 | Use consistent with the intended purpose documented | System | ||
| VER-009-02 | Accuracy and robustness verified and documented | System | ||
| VER-005-01 | Complete technical documentation compliant with Annex IV | System | ||
| VER-007-01 | Instructions for use complete and compliant with Art. 13 | System | ||
| VER-006-01 | Documented log retention policy | Organisation | ||
| VER-006-02 | Automatic logging operational and compliant | System | ||
| VER-006-03 | Logs accessible and usable by the deployer | System | ||
| VER-009-01 | Cybersecurity of the hosting environment | Organisation | ||
| VER-009-03 | Cybersecurity of the AI system verified | System | ||
| VER-021-D-03 | Operation monitoring | System | ||
| VER-AUTO-05 | Accuracy monitoring in operation | System | ||
| VER-020-D-01 | FRIA carried out in accordance with Art. 27 | System | ||
| VER-019-D-02 | DPIA carried out in accordance with GDPR Art. 35 | System | ||
| CHK-BR-AIA-PUBLISHED | Conclusions of the algorithmic impact assessment published | System | ||
| VER-022-D-01 | Serious incident reporting procedure | Organisation | ||
| VER-022-F-01 | Risk and incident response procedure | Organisation | ||
| VER-013-F-04 | Communication to market surveillance authorities in the event of risk | System | ||
| VER-026-F-01 | Contractual responsibilities documented between provider and third parties | Provider | ||
| VER-003-02 | Residual risks communicated to deployers | System | ||
| VER-031-G-01 | GPAI model technical documentation compliant with Annex XI | Model | ||
| VER-031-G-02 | Documentation for downstream providers compliant with Annex XII | Model | ||
| VER-032-G-02 | Systemic risks assessed and mitigation measures documented | Model | ||
| CHK-BR-ENERGY | Energy and resource efficiency of the model documented | Model | ||
| VER-031-G-04 | Published summary of training content | Model | ||
| VER-031-G-03 | Documented copyright compliance policy | Organisation | ||
| CHK-BR-PUBLIC-LOGS | Usage logs record who used the system, for which case and purpose | System | ||
| CHK-BR-PUBLIC-PRELIM | Preliminary assessment published | System | ||
| CHK-BR-REMUNERATION | Rights-holder remuneration arrangements in place | Organisation |
Themes covered
Frequently asked questions
Who is in scope of PL 2338?
Developers, distributors and appliers of AI systems. Systems provided or used in Brazil.
What penalties does PL 2338 carry?
Senate text: up to BRL 50M or 2% of turnover per infringement; suspension.
When do the PL 2338 obligations apply?
Dec 10, 2024: Senate approval; May 2025: Special committee in the Chamber of Deputies; Oct 2026: Vote pushed past the October 2026 elections; Jun 2027: Possible adoption and start of the vacatio legis.
Is PL 2338 binding?
No. Kind: bill. Status: under discussion.
How does PL 2338 relate to other regulations?
The same checks serve several texts. Shared checks: AI Act (37), RGPD (11) and ISO 42001 (9).
Related regulations
Official sources
Data checked on Sep 25, 2026. General information, not legal advice. Check the official texts and get advice for your situation.
Run these requirements across all your AI systems
TrustFlow inventories your systems, qualifies them under each regulation and collects evidence once for every referential.