Brazil: PL 2338 and the bicameral grind

Lesson 3 of 5 in The UK, Canada, Brazil — and the Missing Map: Africa, the Middle East, Latin America.

Brazil is running the most serious attempt in the Global South at a comprehensive AI statute — and it is doing so the slow, deliberate way. PL 2338/2023 did not start as a politician’s draft. It came out of a commission of jurists chaired by Superior Court of Justice (STJ) Justice Ricardo Villas Bôas Cueva, convened after an earlier, much thinner bill (PL 21/2020) passed the Chamber of Deputies in 2021 and was widely panned as a liability shield dressed as regulation. The jurists produced something different: a text that fuses the EU’s risk-based architecture with an explicit rights-based chapter — affected persons get rights to explanation, to contest automated decisions, to human review, and to non-discrimination, enforceable regardless of a system’s risk tier.

On 10 December 2024 the Senate approved a consolidated substitute steered by rapporteur Senator Eduardo Gomes. Since then the bill has sat with the Chamber of Deputies, working through a special committee and its own rapporteur — the second half of a bicameral grind in which the Chamber can amend anything, and any amendment sends the text back to the Senate.

PL 2338’s risk ladder (Senate text)

  1. Excessive risk — prohibited — Banned outright

    Techniques that exploit vulnerabilities to cause harm, general-purpose social scoring by public authorities, and — with narrow public-security exceptions — real-time remote biometric identification in public spaces. Same instinct as EU Article 5, tuned to Brazilian constitutional concerns.

  2. High risk — Impact assessment + obligations

    A revisable list set by the regulator: recruitment, education access, credit, essential public and private services, migration, justice administration and more. Deployers and developers owe algorithmic impact assessments, governance measures, incident reporting, and bias testing.

  3. General-purpose and generative AI — Preliminary assessment

    Providers of general-purpose and generative systems owe a preliminary risk assessment before market placement, transparency about training data and copyright, and content-provenance measures — Brazil’s answer to the GPAI problem.

  4. Everything else — Baseline duties only

    General transparency and the rights chapter still apply — a floor the pure EU model does not have, because PL 2338’s rights attach to people, not only to risk tiers.

Enforcement is where Brazil innovated. Instead of one AI authority, the bill creates the SIA — the National AI Regulation and Governance System — with the data-protection authority ANPD coordinating a network of sectoral regulators (central bank for finance, health agency for medicine, and so on). The ANPD earned that seat: under the LGPD (Brazil’s GDPR analogue) it had already flexed on AI, ordering Meta in 2024 to stop training AI on Brazilian users’ personal data until safeguards were shown. The bill adds regulatory sandboxes, treats adherence to codes of conduct as good-faith evidence in sanctioning, protects workers affected by AI-driven management, grants image-and-voice consent rights against unauthorised synthetic reproduction, and wades into copyright: remuneration for rightsholders whose works train commercial models — one of the provisions industry lobbied hardest against, while civil-society groups like Idec pushed the other way, warning the Senate text had already softened biometric bans and platform duties.

Brazil’s road to an AI law

  • 2023-05-01Brazil’s PL 2338 introduced in the Senate:

    A risk-based AI bill drawing on an expert-commission draft — the start of Latin America’s most advanced AI legislative process.

  • 2025-06-01PL 2338 before Brazil’s Chamber of Deputies:

    After Senate approval (Dec 2024), the AI bill moves to the lower house; ANPD positions itself as the coordinating regulator. Status as of Sept 2026: check current progress.

  • 2024-12-10Brazil’s Senate approves PL 2338:

    A risk-based framework visibly inspired by the EU AI Act clears the Senate; Chamber of Deputies consideration continues.

Key terms: algorithmic impact assessment, prohibited AI practices, general-purpose AI, regulatory sandbox, lgpd

Interactive checkpoint quiz (2 questions) — open this page in a browser to take it.