BRBrazilUnder discussionPL 2338

Preparing for the Brazil AI Bill (PL 2338/2023)

Brazil AI Bill (PL 2338/2023)

Status
Under discussion
Binding
No
Object analysed
AI system
Requirements
20
Next milestone
Oct 2026

In short

Senate text approved on 10/12/2024, close to the AI Act: excessive risk, high risk (Art. 14), general-purpose AI, preliminary assessment and algorithmic impact assessment.

Steps to compliance

  1. Qualify each AI systemAxes to decide: PL 2338 risk level and Role (Art. 4).
  2. Determine your roleDuties vary by role: Developer, Distributor and Applier.
  3. Apply the 20 requirementsThey focus on: Transparency & notice, Risk management, Technical documentation and Explanation & redress.
  4. Prove it with checks46 checks to document, 40 of which also serve AI Act, RGPD and ISO 42001.
  5. Track the deadlinesNext milestone: Oct 2026, Vote pushed past the October 2026 elections (potential).

Scope and penalties

Kind
Bill
Scope
Developers, distributors and appliers of AI systems.
Territorial reach
Systems provided or used in Brazil.
Penalties
Senate text: up to BRL 50M or 2% of turnover per infringement; suspension.
Jurisdiction
Brazil

Timeline

May 3, 2023Filed in the Senate
Dec 10, 2024Senate approval
May 2025Special committee in the Chamber of Deputies
Release
Oct 2026Vote pushed past the October 2026 electionsPotential
Jun 2027Possible adoption and start of the vacatio legisPotential
PastSet in the textPotentialTo verify

Qualifying a system

Classification axes and possible verdicts

PL 2338 risk level

Excessive risk (Art. 13)High risk (Art. 14)General-purpose, systemic riskGeneral-purpose or generativeOtherOut of scope

Role (Art. 4)

DeveloperDistributorApplier

Requirements

20 requirements

CodeArticleRequirementApplies toChecks
BR-01Arts. 12, 29Preliminary assessment
Detail

Classify the system's risk before placing it on the market or using it. Optional for most agents but mitigates sanctions (Art. 50 §1); mandatory for developers of general-purpose and generative AI (Art. 29).

DeveloperDistributorApplier
BR-02Art. 13Excessive-risk practices
Detail

No development, implementation or use of an excessive-risk system; developers take measures to prevent such uses (Art. 13 §1).

DeveloperDistributorApplier
BR-03Art. 5 IInformation on interaction with AI
Detail

Everyone has the right to prior information that they are interacting with an AI system, through standard icons where relevant, in plain language for vulnerable groups (Art. 5 §§1 and 2).

DeveloperDistributorApplier
BR-04Art. 19Synthetic content identifier
Detail

Synthetic content generated or modified by the system carries an identifier that allows its authenticity or origin to be verified.

DeveloperApplierGeneral-purpose or generative
BR-05Arts. 5 III, 18Non-discrimination and bias mitigation
Detail

Measures to prevent, mitigate and correct discriminatory bias, including on the data used (Art. 18 I.e and II.e).

DeveloperApplierHigh risk
BR-06Arts. 6 I, 7Right to explanation
Detail

A person affected by a high-risk system may obtain, free of charge and in plain language, an explanation of the decision, recommendation or prediction made about them.

ApplierHigh risk
BR-07Arts. 6 II, 6 III, 9Contestation and human review
Detail

Affected persons may contest decisions and request human review; the procedures to exercise these rights are published.

ApplierHigh risk
BR-08Arts. 8, 18 I.dHuman oversight
Detail

Human oversight allowing people to understand, interpret, decide on and intervene in the system; the degree of human oversight in the results is documented.

DeveloperApplierHigh risk
BR-09Art. 18 I.a, I.c, I.fApplier documentation
Detail

The applier documents the system across its lifecycle, the reliability and safety tests performed, and the information that makes results interpretable.

ApplierHigh risk
BR-10Art. 18 II.a, II.dDeveloper documentation and explainability
Detail

The developer keeps a record of its governance measures to inform the applier, and implements explainability measures.

DeveloperHigh risk
BR-11Art. 18 II.bOperation logging
Detail

The system automatically logs its operation so that its accuracy and robustness can be assessed.

DeveloperApplierHigh risk
BR-12Art. 18 II.cSecurity testing
Detail

Tests to assess appropriate levels of security, including of the environment the system runs in.

DeveloperHigh risk
BR-13Art. 18 I.bMonitoring of results
Detail

The applier monitors the system's outputs for accuracy, robustness and discrimination, and mitigates what it finds.

ApplierHigh risk
BR-14Arts. 25-28Algorithmic impact assessment
Detail

An algorithmic impact assessment before placing on the market, kept up to date across the lifecycle. It may be carried out together with the LGPD data protection impact report (Art. 27), and its conclusions are published (Art. 28).

DeveloperApplierHigh risk
BR-15Arts. 25 §7, 42Serious incidents
Detail

A serious risk discovered after release is reported immediately to the authority and the value chain, and serious incidents are reported to the sector authority.

DeveloperDistributorApplierHigh risk
BR-16Arts. 18 §3, 32Value-chain cooperation
Detail

Agents cooperate and share the information the others need to meet their obligations; a distributor checks the governance measures before placing on the market (Art. 16 §3).

DeveloperDistributorApplier
BR-17Arts. 29, 30General-purpose and generative AI
Detail

The developer documents development. With systemic risk, before release: model description, test documentation, residual risks, lawful data governance, energy efficiency and downstream documentation (Art. 30 I to VII).

DeveloperGeneral-purpose or generative
BR-18Arts. 62, 64Training content and opt-out
Detail

A summary of the copyright-protected content used in development is published, and rights holders' opt-out is honoured.

Developer
BR-19Arts. 22, 23Public-sector duties
Detail

Public bodies and operators of a public service using a high-risk system keep usage logs (who, which case, which purpose) and publish their preliminary assessments.

ApplierHigh risk
BR-20Art. 65Remuneration of rights holders
Detail

Rights holders whose content was used for training are remunerated. This chapter may be removed by the Chamber of Deputies.

DeveloperApplier

Checks to document

Evidence collected for a check counts for every regulation that uses it.

CodeCheckScopeThemesAlso used by
CHK-BR-PRELIMPreliminary assessment carried out and kept on recordSystem
—
VER-002-01Documented process for detecting drift towards prohibited practicesOrganisation
VER-002-02System free of prohibited practices (provider assessment)System
VER-002-03System use free of prohibited practices (deployer assessment)System
VER-018-D-01Persons informed of the interaction with an AI systemSystem
VER-029-D-01Affected persons informed of the use of the AI systemSystem
VER-018-D-03AI-generated content marked as suchSystem
VER-004-01Documented data governance (collection process, bias, quality)System
VER-004-02Input data relevant and representative in view of the intended purposeSystem
VER-028-D-03Input data sufficiently representativeSystem
VER-033-D-01Decision explanation procedure documentedOrganisation
VER-033-D-02System explanation capability verifiedSystem
VER-033-D-03Explanations provided on request within a reasonable timeframeSystem
CHK-BR-CONTESTProcedure to contest a decision and obtain human review publishedOrganisation
VER-008-01Documented escalation and emergency stop procedureOrganisation
VER-008-02System designed to allow human oversight (stop button, override)System
VER-008-03Competent overseers assigned to the systemSystem
VER-005-02Instructions for use obtained and read by the deployerSystem
VER-005-03Use consistent with the intended purpose documentedSystem
VER-009-02Accuracy and robustness verified and documentedSystem
VER-005-01Complete technical documentation compliant with Annex IVSystem
VER-007-01Instructions for use complete and compliant with Art. 13System
VER-006-01Documented log retention policyOrganisation
VER-006-02Automatic logging operational and compliantSystem
VER-006-03Logs accessible and usable by the deployerSystem
VER-009-01Cybersecurity of the hosting environmentOrganisation
VER-009-03Cybersecurity of the AI system verifiedSystem
VER-021-D-03Operation monitoringSystem
VER-AUTO-05Accuracy monitoring in operationSystem
VER-020-D-01FRIA carried out in accordance with Art. 27System
VER-019-D-02DPIA carried out in accordance with GDPR Art. 35System
CHK-BR-AIA-PUBLISHEDConclusions of the algorithmic impact assessment publishedSystem
—
VER-022-D-01Serious incident reporting procedureOrganisation
VER-022-F-01Risk and incident response procedureOrganisation
VER-013-F-04Communication to market surveillance authorities in the event of riskSystem
VER-026-F-01Contractual responsibilities documented between provider and third partiesProvider
VER-003-02Residual risks communicated to deployersSystem
VER-031-G-01GPAI model technical documentation compliant with Annex XIModel
VER-031-G-02Documentation for downstream providers compliant with Annex XIIModel
VER-032-G-02Systemic risks assessed and mitigation measures documentedModel
CHK-BR-ENERGYEnergy and resource efficiency of the model documentedModel
—
VER-031-G-04Published summary of training contentModel
VER-031-G-03Documented copyright compliance policyOrganisation
CHK-BR-PUBLIC-LOGSUsage logs record who used the system, for which case and purposeSystem
—
CHK-BR-PUBLIC-PRELIMPreliminary assessment publishedSystem
—
CHK-BR-REMUNERATIONRights-holder remuneration arrangements in placeOrganisation
—

Themes covered

Frequently asked questions

Who is in scope of PL 2338?

Developers, distributors and appliers of AI systems. Systems provided or used in Brazil.

What penalties does PL 2338 carry?

Senate text: up to BRL 50M or 2% of turnover per infringement; suspension.

When do the PL 2338 obligations apply?

Dec 10, 2024: Senate approval; May 2025: Special committee in the Chamber of Deputies; Oct 2026: Vote pushed past the October 2026 elections; Jun 2027: Possible adoption and start of the vacatio legis.

Is PL 2338 binding?

No. Kind: bill. Status: under discussion.

How does PL 2338 relate to other regulations?

The same checks serve several texts. Shared checks: AI Act (37), RGPD (11) and ISO 42001 (9).

Related regulations

Official sources

Data checked on Sep 25, 2026. General information, not legal advice. Check the official texts and get advice for your situation.

Run these requirements across all your AI systems

TrustFlow inventories your systems, qualifies them under each regulation and collects evidence once for every referential.

Request a demo