Brazil's proposed federal AI legislation, PL 2338/2023, was approved by the Senate in December 2024 and, as of this writing, remains under consideration in the Chamber of Deputies. It would introduce a risk-tiered regulatory framework broadly similar in structure to the EU AI Act: risk categories tied to potential effect on rights, obligations that scale with that risk, and a distinction between those who develop AI systems and those who deploy them. The bill's exact final text, timeline, and whether it will be enacted in its current form are not settled, and agent operators should verify current status before treating any specific provision as final. What is already binding, independent of the bill's fate, is Brazil's data-protection law, the LGPD, which gives individuals enforceable rights around automated decision-making today.
This is a jurisdiction where the direction of travel is clear and worth building against, even though the legislative timeline is not. Brazil has consistently signalled it wants a comprehensive, EU-influenced AI framework; the open questions are about final scope and timing, not about whether Brazil intends to regulate AI more comprehensively than it does today.
The proposed framework's structure
The bill under consideration organizes AI systems by risk to fundamental rights, health, safety, and other protected interests — a structure recognizable to anyone who has worked through EU AI Act classification. Systems assessed as posing excessive risk would face prohibition or severe restriction; systems assessed as high risk would face a heavier obligation set including algorithmic impact assessments, human oversight requirements, and documentation obligations; lower-risk systems would face lighter or no specific obligations beyond general law.
The proposal also follows the EU's pattern of distinguishing between developers (who build and place AI systems into the market) and deployers (who put a developer's system to use), with obligations allocated differently across the two roles — heavier documentation and testing duties on developers, heavier context-specific risk-assessment and oversight duties on deployers.
A notable rights-based element, distinct from the EU AI Act's structure, is an explicit right for individuals affected by significant AI-driven decisions to request meaningful information about the decision and, in defined circumstances, a human review of it — a concept that echoes both the EU AI Act's human-oversight requirements and LGPD's existing automated-decision provisions, but framed as an individual right rather than only a system-design obligation.
What is not settled
Because the bill remains in the legislative process, the following should be treated as directional rather than final: the precise boundaries of each risk category, the specific documentation format for algorithmic impact assessments, which body will have primary enforcement authority (whether ANPD, a new dedicated AI authority, or a shared arrangement), and the timeline for any obligations to take effect. Do not build a compliance program that depends on a specific provision surviving unchanged — build one around the categories that have remained stable across the bill's public drafts: risk-based tiering, developer/deployer allocation, algorithmic impact assessment, and an individual right to explanation and review.
What already binds you: LGPD
Brazil's Lei Geral de Proteção de Dados (LGPD) is Brazil's comprehensive data-protection statute, enforced by the Autoridade Nacional de Proteção de Dados (ANPD), and it already applies to AI agents processing personal data of individuals in Brazil. LGPD includes a right for data subjects to request review of decisions made solely through automated processing that affect their interests — a provision that predates the AI bill and applies to agent-driven decisions today, independent of whether the AI bill is enacted. ANPD has also shown increasing willingness to engage with AI-specific questions within its existing LGPD mandate, making it the most concrete near-term enforcement body for agent operators with Brazilian exposure.
How Brazil's proposal compares
| Dimension | EU AI Act | Brazil's proposed framework |
|---|---|---|
| Instrument type | Enacted, binding statute | Bill under legislative consideration; not yet final |
| Sorting axis | Use-case risk category | Use-case risk category, closely modeled on the EU approach |
| Provider/deployer split | Yes | Yes, similarly structured |
| Individual rights | Contestability implicit in oversight requirements | Explicit right to explanation and human review, plus LGPD's existing automated-decision review right |
| Current enforcement | National market-surveillance authorities | ANPD today (via LGPD); AI-specific authority uncertain pending the bill |
Agent operators who have already built an EU AI Act risk-classification exercise have a considerable head start on Brazil's proposed framework, since the sorting logic is structurally similar. That head start does not extend to LGPD's automated-decision review right, which is already enforceable and needs its own control today.
The six obligation categories to prepare for
| Obligation | LGPD, in force today | Proposed AI bill, direction of travel |
|---|---|---|
| Transparency | Notice requirements for personal-data processing | Would likely add AI-specific disclosure for higher-risk systems |
| Human oversight | Right to review of automated decisions | Would formalise and extend this into a general high-risk obligation |
| Risk/impact classification | Not present in LGPD itself | Central mechanism of the proposed bill |
| Record-keeping | LGPD accountability principle | Would add algorithmic impact assessment documentation |
| Incident reporting | LGPD breach-notification duty to ANPD and affected individuals | Likely to extend to AI-specific incidents for higher-risk systems |
| Data localization | LGPD cross-border transfer conditions | Not a central feature of current bill drafts |
Control mapping: what you need to be able to produce
Agent inventory with an automated-decision flag. Identify every agent that makes decisions "solely through automated processing" affecting a Brazilian individual's interests — this is the trigger for LGPD's existing review right and will likely map closely onto whatever risk tiers the AI bill ultimately adopts. See building an AI agent inventory for a structure that supports this kind of flagging.
Human-review request process. Build a working process for an individual to request review of an automated decision, with evidence that a human genuinely reconsidered the case rather than rubber-stamping the agent's output. This is enforceable today under LGPD, not a future obligation.
Explanation artefact. Maintain the ability to produce a plain-language explanation of what factors drove a given automated decision, sufficient to satisfy both LGPD's existing transparency expectations and the explanation right the AI bill would formalise.
Preliminary risk classification. Even ahead of the bill's enactment, classify agents against the risk categories described in its public drafts — this positions you to comply quickly once the framework (in whatever final form) takes effect, and it is good practice independent of Brazilian law specifically. The methodology in how to classify AI agents under the EU AI Act's risk tiers transfers reasonably well given the structural similarity.
LGPD breach-notification readiness. Maintain an incident-timeline capability — detection, assessment, notification to ANPD and affected individuals, remediation — since this obligation is already binding and does not depend on the AI bill's outcome. See an AI incident readiness checklist for the underlying discipline.
Developer/deployer role determination. For each agent, document whether your organization sits as developer, deployer, or both, since the proposed bill (like the EU AI Act) allocates obligations differently by role, and getting this determination wrong early is a common source of gaps.
What good looks like
- Every agent making automated decisions affecting Brazilian individuals is flagged and mapped to LGPD's existing review-request obligation.
- A functioning human-review process exists for automated-decision requests, with evidence of substantive review.
- Preliminary risk classifications exist for each agent against the AI bill's public risk categories, ready to formalise once the framework is enacted.
- Developer/deployer roles are documented per agent deployment.
- LGPD breach-notification capability meets ANPD's expected timelines with a reconstructable incident timeline.
- Compliance planning treats the bill's stable structural elements — risk tiers, provider/deployer split, impact assessment — as the target, while tracking legislative status for anything more specific.
Common questions
Should we wait for the bill to pass before building risk classification?
No. The bill's risk-tier structure has been stable across public drafts even while specific thresholds and enforcement details remain open. Building a preliminary classification now, using the EU AI Act's approach as a template, means you can formalise quickly once Brazil's framework is enacted, rather than starting the exercise from zero under time pressure.
Is LGPD's automated-decision review right the same as the AI bill's proposed explanation right?
They are related but distinct. LGPD's existing right lets a data subject request review of a decision made solely through automated processing. The AI bill's proposed right is broader in framing — covering explanation and review for significant AI-driven decisions more generally — and would likely extend obligations beyond what LGPD alone requires today. Comply with LGPD's version now; treat the bill's broader version as the direction obligations are heading.
Who enforces AI-related obligations in Brazil today?
ANPD, through its existing LGPD mandate, is the concrete enforcement body operating today. Whether ANPD retains sole authority once the AI bill is enacted, or shares it with a new dedicated body, is one of the open questions in the current legislative process.
This is not legal advice; confirm the current status of Brazil's AI bill and LGPD enforcement practice with counsel before relying on it.
Brazil is a clear case for building ahead of enactment: the proposed framework's structure is stable enough to plan against, even while its final text is not. Pair that preparation with LGPD compliance work you likely already owe, and reuse EU AI Act risk-classification discipline rather than starting from a blank page.