The defining AI development for Brazil in 2026 has been a shift from policy design to practical implementation. Although comprehensive AI legislation remains under debate, existing rules on data protection, consumer protection, civil liability, labour, children and adolescents, intellectual property and other areas are already shaping how AI systems are developed, supplied and used. The result is not yet a unified regulatory framework, but an increasingly operational compliance environment.
Against this backdrop, the main challenge for businesses is no longer simply to follow the progress of Bill No 2,338/2023. Companies must determine which rules apply to each use case, which authorities or sectoral bodies may intervene, and what evidence is needed to show that systems were selected, tested, supervised and corrected responsibly. This becomes particularly important as AI moves into higher-impact decisions, autonomous workflows and vulnerable audiences.
The developments examined below reflect both regulatory risk and market opportunity. They include the evolving legislative framework, evidence-based governance, safeguards for children and adolescents, electoral integrity, AI in the judiciary, intellectual property and synthetic identity, supplier relationships, the implementation of the Brazilian Artificial Intelligence Plan and related infrastructure initiatives. Together, they show that AI governance in Brazil is becoming more concrete and increasingly connected to contracting, investment and business strategy.
AI Regulation in Progress
Bill No 2,338/2023 was approved by the Federal Senate and then moved to the Chamber of Deputies, where, as of July 2026, it was awaiting the rapporteur’s opinion in a special committee. The current text adopts a risk-based approach and provides for transparency, governance, human oversight and impact-assessment duties, with more demanding requirements for systems classified as high risk.
Institutional design is also under development. Bill No 6,237/2025, submitted by the federal government and attached to Bill No 2,338/2023 in March 2026, proposes a National System for the Development, Regulation and Governance of Artificial Intelligence. The proposal points towards a model combining central co-ordination with authorities that retain responsibility for specific sectors and legal regimes.
Key elements remain under discussion and may still change significantly, including risk classification, the treatment of generative models, the allocation of obligations across the AI supply chain and supervisory powers. Businesses should therefore follow the legislative process closely to understand the likely direction of reform and its practical implications.
At the same time, the National Data Protection Agency (ANPD) is becoming increasingly relevant to AI governance. Although it is not a general AI regulator, its powers under the General Data Protection Law (LGPD) and related digital regulation allow it to influence the treatment of AI-enabled systems. The Agency has promoted an Artificial Intelligence Regulatory Sandbox, allowing selected technology companies to test innovative AI systems in a controlled, experimental and supervised environment. In July 2026, it published the first report on the testing cycle involving the three initial participants, identifying areas for improvement in governance, security, transparency, anonymisation, evidence production, communication and use of synthetic data.
Taken together, these developments show that Brazil’s AI framework is emerging through a combination of proposed legislation, existing laws and regulatory experimentation. Companies must prepare for possible comprehensive AI legislation while recognising that many AI-related practices are already subject to legal duties and regulatory scrutiny.
From Principles to Evidence-Based AI Governance
Even though Brazil has not yet enacted comprehensive AI legislation, existing law provides several routes for challenging harmful or poorly governed uses of AI. Depending on the circumstances, liability may arise under the LGPD, the Consumer Protection Code, the Civil Code, labour law, anti-discrimination rules or sector-specific regulation.
The most relevant trend in AI governance is the shift from stating general principles to requiring verifiable evidence of how they are implemented. Companies should be able to explain what a system does, why it is used, who approved its deployment, and which individuals or groups may be affected. Relevant records may include data sources, testing results, known limitations, human oversight, post-deployment monitoring, complaints, incidents and corrective measures.
The level of control should reflect the potential impact of the system. A drafting assistant used by trained professionals does not require the same safeguards as a system that rejects job applicants, influences medical treatment or changes the conditions offered to a consumer. Higher-impact applications should be subject to more robust validation, supervision and review.
Transparency must also be adapted to its purpose. Users may need clear notice that AI is involved, affected individuals may require sufficient information to question or contest an outcome, and regulators or auditors may request technical documentation, validation records and system logs. A generic public description of a model will rarely satisfy these needs.
Agentic AI and other highly autonomous systems create an additional layer of responsibility. Where AI can initiate communications, operate software, place orders or complete multi-step tasks, organisations should define authority limits, access permissions, approval levels, prohibited actions and emergency mechanisms. Greater technical autonomy is unlikely to displace the responsibility of the organisation that selected and deployed the system.
For businesses, the practical consequence is clear: responsible AI governance must be demonstrable, proportionate and embedded throughout the system’s lifecycle. Organisations that can produce reliable evidence of risk assessment, testing, oversight and corrective action will be better positioned to respond to regulators, courts, customers and affected individuals. High-level policies and ethical commitments alone may offer limited protection when an AI-assisted decision or outcome is challenged.
Children and Adolescents in Digital Environments
One of the most important new regimes is Law No 15,211/2025, known as the ECA Digital, which entered into force on 17 March 2026. It applies not only to services expressly directed at children and adolescents but also to products and services likely to be accessed by them. This broader scope is particularly relevant to global platforms offering the same service to mixed-age audiences.
Although the ECA Digital is not formally an AI statute, it directly affects AI systems likely to be accessed by children and adolescents, such as conversational agents, educational platforms, games, social networks, advertising tools and generative services. Providers must consider safety, privacy and the best interests of children and adolescents from the design stage and throughout operation. Relevant issues include profiling, targeted advertising, parental supervision, persuasive design and exposure to harmful content.
Age assurance has become an early focus of implementation. The ANPD’s preliminary guidance seeks to ensure effective safeguards while protecting privacy and observing data minimisation principles, rather than imposing a single standardised age verification method. Its monitoring programme began with app stores and proprietary operating systems, which occupy a structural position in the digital ecosystem, and is expected to expand as the Agency refines its guidance during 2026.
For foreign businesses, age restrictions in terms of use are unlikely to be sufficient when a product’s content, design, marketing or user base suggests probable access by minors. Companies should assess how age is determined or verified, how much personal data is collected, and whether different age groups receive different experiences. Compliance should therefore be assessed by how the service operates in practice, rather than solely by the audience formally identified in its terms of use.
AI and the 2026 Brazilian Elections
Brazil’s general election has accelerated regulatory efforts concerning AI-generated media. Superior Electoral Court Resolution No 23,755/2026 addresses deepfakes and other fabricated, manipulated or synthetic content used in electoral advertising. It also requires political actors and relevant service providers to adopt measures to reduce voter deception and unlawful interference with the electoral process.
A notable rule introduced for the 2026 elections restricts the publication, republication and paid promotion of certain newly created or altered AI-generated content from 72 hours before voting until 24 hours after voting ends. The measure reflects how quickly realistic synthetic content can influence public debate and recognises that corrective measures taken only after voting has ended may come too late to prevent harm to the electoral process. Platforms, agencies, consultants, influencers and technology providers may all play a role in creating, promoting or distributing such content.
Businesses involved in political communications should adopt procedures for reviewing and approving content, disclosing the use of AI where permitted, preventing prohibited deepfakes or deceptive content and responding promptly to potential violations. They should also observe the specific restrictions applicable to certain new synthetic content during the period immediately before and after voting.
Beyond electoral advertising, these rules may influence broader expectations for commercial communications, particularly where synthetic voices, avatars or realistic representations could mislead the public or harm a person’s image or reputation. This reflects a broader trend towards greater transparency, accountability and responsible use of synthetic content.
AI Governance in the Brazilian Judiciary
National Justice Council Resolution No 615/2025 established a framework for the development, procurement and use of AI by Brazilian courts, addressing risk classification, human oversight, testing, transparency, security and auditability. Its implementation progressed in 2026, as courts moved from experimental applications towards more formal governance of generative AI and other automated systems. Judges nevertheless remain responsible for reviewing and validating judicial decisions.
The framework also affects technology providers, which may face stricter requirements concerning data use, confidentiality, model documentation, audit rights and ongoing monitoring. Although primarily applicable to the judiciary, it may serve as a useful reference for law firms and corporate legal departments, particularly regarding confidentiality, human oversight and professional accountability.
Intellectual Property Developments
Alongside these sector-specific developments, the intellectual property debate has expanded in different areas. In patent domain, discussions now extend beyond whether AI-related inventions qualify for protection as computer-implemented inventions. In August 2025, the Brazilian Patent and Trademark Office (BPTO) opened Public Consultation No 3/2025 for discussing the draft examination guidelines for AI-related patent applications. Although not yet formally adopted, the consultation has brought greater attention to the technical character, sufficiency of disclosure, inventive step and claim drafting. Further developments are expected during 2026.
Inventorship and ownership are also under legislative debate. Bill No 303/2024 originally proposed allowing a patent for an invention autonomously generated by AI to be filed and granted naming as inventor the AI system itself. In May 2026, however, the Chamber of Deputies’ Science, Technology and Innovation Committee rejected that approach. The proposal remains pending.
Trade secrets and confidential information also require particular attention. Businesses should avoid entering unpublished inventions, source code, datasets or other sensitive material into external AI tools without reviewing terms of data retention, model training, confidentiality, access and security. Internal policies should also define which tools may be used, by whom and for what purposes.
In copyright, key questions include the use of protected material for training and fine-tuning, the risk that AI-generated outputs may reproduce or closely resemble protected works and the degree of human creative contribution required for copyright protection of these works. Brazil has not enacted a comprehensive statutory regime addressing these issues. The AI Bill nevertheless indicates a possible direction, including greater transparency regarding training data, rules for text and data mining, and mechanisms concerning authorisation and remuneration for use of protected content.
The cloning of images and voices creates a related but distinct risk. Brazilian constitutional and civil-law protections for image, honour, privacy and personality rights may apply even where copyright is not the central issue. Consent should therefore cover the intended synthetic use, duration, media channels, permitted modifications and the applicable commercial context. Uses involving employees, performers, customers and other public-facing representatives require particular care because synthetic representations may continue to circulate after the underlying contractual relationship ends.
Businesses should manage these uncertainties through clear record, appropriate permissions and contractual controls. Developers should document the sources and licence terms of training and fine-tuning data. Users should not assume that every AI-generated output is protected by copyright or free from third-party rights. Agreements with employees, contractors and technology providers should clearly address ownership and permitted use of human-authored contributions, AI-assisted outputs, improvements and inventions.
AI Supplier Relationships as a Governance Priority
As AI moves from isolated pilot projects into core business processes, supplier relationships are becoming a central governance issue in 2026. Companies across many sectors – including those whose core activities are not technology-based – increasingly need AI capabilities to maintain their competitive position but often lack the resources or expertise to develop models and infrastructure in-house. Therefore, demand for third-party foundation models, cloud services, application programming interfaces, software vendors and system integrators is rapidly growing. As a result, the company using an AI system may remain legally responsible for its outcomes, despite having reduced control over the model and limited access to the information needed to understand, explain and audit it.
Given this gap between legal responsibility and technical control, supplier due diligence should extend beyond standard cybersecurity questionnaires. Customers should assess intended and prohibited uses, the origin and permitted use of relevant data, data-processing locations, subcontractors, known limitations, and the supplier’s ability to support audits, complaints and regulatory enquiries. This is particularly important as models are continuously updated and systems are increasingly used to support decisions affecting employees, consumers and others.
The findings of the supplier due diligence should be reflected in agreements, addressing where relevant:
However, these provisions cannot eliminate the customer’s own legal and operational responsibilities. A company may remain directly accountable for an AI-enabled decision even where a technical failure originated from a supplier. Contracts should secure access to information, require supplier co-operation and provide effective remedies while being complemented by internal validation, approval procedures and ongoing human oversight.
AI Investment and Infrastructure
Beyond compliance and contracting, AI policy is creating an investment and infrastructure agenda. The federal government developed the Brazilian Artificial Intelligence Plan to guide national AI policy and strengthen domestic technological capabilities. Covering 2024 to 2028, the Plan envisages investments of up to BRL23 billion in advanced computing infrastructure, workforce training, AI-enabled public services, business innovation and regulatory governance, while promoting AI adoption in strategic sectors.
In 2026, the focus is shifting towards consolidating, scaling and monitoring the Plan’s implementation. As several initiatives were underway or delivered in 2025, attention is turning to whether short-term projects produce measurable results and whether longer-term programmes effectively expand domestic computing capacity, workforce skills, AI public-service applications and support for private-sector innovation. The Plan’s practical impact will depend on sustained funding, co-ordinated execution, research partnerships, public procurement and clearly defined delivery targets.
Within this agenda, data-center policy has gained prominence. Bill No 278/2026 establishes REDATA, a special tax regime designed to encourage investment in data-processing infrastructure and the installation or expansion of data centers in Brazil. The regime was initially introduced through a provisional measure in 2025. After that measure expired in February 2026, the Chamber of Deputies approved a bill to reinstate it, but it remains pending before the Senate as of mid-2026. The debate extends beyond tax incentives to grid connection, power supply, energy efficiency, renewable energy, water use and reuse, environmental licensing and telecommunications infrastructure.
The Plan implementation is creating opportunities in computing infrastructure, workforce training, research, public-sector solutions and enterprise AI adoption. AI and data-center projects nevertheless require co-ordinated legal due diligence covering eligibility for public incentives, power supply, environmental and construction approvals, connectivity, cybersecurity, land rights, international data transfers and access to critical infrastructure. Companies should monitor not only the Plan’s overall investment targets but also specific funding calls, procurement procedures, pilot programmes and implementation requirements.
Government-funded projects and public procurement may create opportunities for technology providers, universities, research institutions and service companies, but may also impose additional requirements concerning transparency, security, risk management, auditability, data governance, intellectual property and, where applicable, technological sovereignty or data-location requirements.
Attention in 2026 is therefore focused on how the Plan’s priorities are translated into funded programmes, procurement opportunities, pilot projects and research partnerships, as well as on the legal and contractual obligations applicable to participating businesses. As the Plan runs through 2028, the relevant question is whether intermediate milestones are being met and longer-term projects remain on schedule.
Practical Priorities for Businesses in 2026
Brazil’s AI regulatory framework remains incomplete, but the developments examined abovepoint to clear practical priorities. Companies entering or expanding operations in Brazil should comply with existing laws while remaining flexible enough to adapt to possible comprehensive AI legislation in the future. In particular, businesses should:
These measures should be proportionate rather than unnecessarily bureaucratic. The objective is not to create identical controls for every AI tool but to ensure greater scrutiny for higher-impact systems and clearly assign responsibilities, evidence requirements and escalation procedures. Governance should be reviewed whenever the system, supplier, dataset or intended use changes materially.
Brazil’s AI landscape in 2026 therefore combines a regulatory framework still under development with concrete legal obligations, governance expectations and investment opportunities. Businesses that can demonstrate how their AI systems are selected, procured, tested, supervised and corrected will be better positioned to manage current risks, respond to regulatory developments and participate responsibly in Brazil’s expanding AI ecosystem.
Rua Cristiano Viana
401 13th Floor
Room 1301
São Paulo/SP
05411-000
Brazil
(+55) 11 3884-9791
contato@muradpma.com www.muradpma.com