CAUSA & EFECTO · EDITION Nº 001 · 15 JUL MMXXVI · 8 MIN READ

Brazil is writing the AI law the region will inherit

THE CAUSE — WHAT HAPPENED

Brazil is writing — hearing by hearing, article by article — the most ambitious artificial intelligence law in Latin America. The AI Legal Framework (PL 2338/2023), approved unanimously by the Senate in December 2024 and built on the risk model of the European AI Act, has entered its decisive phase: a special commission of the Chamber of Deputies is dissecting it in public hearings while the rapporteur prepares the report that will define the final text[1][2]. The political signals point the vote toward late 2026[4][5].

It is the first time the region's largest economy has attempted a comprehensive, cross-cutting framework for AI. To understand what is at stake, it helps to take the law apart piece by piece: where it comes from, what it demands and of whom, who will police it — and what is happening around it while Brasília deliberates.

Where PL 2338 comes from

The bill was introduced in May 2023 by the then president of the Senate, Rodrigo Pacheco, on the basis of a draft written by a commission of jurists convened by the chamber itself[1]. After a year and a half of negotiation, the Senate approved it unanimously in December 2024[3]. In the Chamber of Deputies the text did not go to the ordinary committees: a dedicated special commission was created, and since 2025 it has been holding public hearings on the fronts where the law bites — education, labor, small business[2].

The calendar has already slipped once: the vote planned for December 2025 was postponed amid political impasses and criticism of the text[5], and the date now circulating in Brasília is December 2026[4]. And the step that truly matters is still pending: the rapporteur's report, which can rewrite entire pieces before the vote[1][2].

What it demands, and of whom

The heart of the text is a risk pyramid inherited from the European AI Act, with three floors:

  • Excessive risk — prohibited: state social scoring, real-time biometric identification in public spaces (with police exceptions that remain contested), and systems that exploit the vulnerabilities of specific groups[3][7].
  • High risk — permitted with a prior algorithmic impact assessment: credit, hiring and employment, educational evaluation, criminal justice, eligibility for public services, and critical infrastructure[3][6].
  • Significant risk — transparency obligations: disclosing that AI is involved and documenting what the system can and cannot do[3].

On the other side of the equation, the law enshrines the rights of the affected person: to know that an AI made a decision about you, to receive an explanation, and to be able to contest the automated decision[3][7].

Who polices it, and what non-compliance costs

Enforcement falls not to a new agency but to a system: the SIA, coordinated by the ANPD — the authority that already administers the LGPD data-protection law — together with the sectoral regulators (the Central Bank, ANATEL, ANS) and with civil-society participation[3][7]. Fines reach R$ 50 million per infraction or 2% of revenues in Brazil — a deliberately softer ceiling than the 7% of global turnover a company risks under the European AI Act[7].

Nor will it take effect immediately: there is no date yet, and the expected pattern is the LGPD's — staggered implementation, roughly two years between enactment and the full regime[7].

PL 2338 AT A GLANCE
Excessive riskProhibited: state social scoring; real-time biometrics in public spaces (police exceptions contested); exploiting vulnerabilities
High riskPrior algorithmic impact assessment: credit, employment, educational evaluation, criminal justice, public services, critical infrastructure
Significant riskTransparency: disclose that AI is involved, document capabilities
RightsTransparency, explanation, and contestation of automated decisions
GovernanceSIA — national system coordinated by the ANPD with sectoral regulators and civil society
PenaltiesUp to R$ 50 million per infraction or 2% of revenues in Brazil
Entry into forceNo date; staggered LGPD-style implementation expected (~2 years after enactment)
Open frontsBiometric surveillance · foundation-model transparency · fit with the LGPD

The open fronts

Three disputes concentrate the lobbying and will define the final text: how far biometric surveillance gets trimmed — the security industry pushes one way, rights organizations the other —; how much transparency is demanded of foundation models; and how the new law fits with the LGPD so obligations aren't duplicated[4][5][7]. The tech industry, for its part, argues that copying the prescriptive European approach could smother an ecosystem that is barely being born[12].

The regional board is moving at the same time

While Brazil deliberates, the region isn't waiting. Peru has already enacted Latin America's first AI law — a short, promotional text, with its regulations still in development[6]. Chile is taking the middle road: its bill — also a risk pyramid, with fines of up to 20,000 UTM — cleared the lower chamber in October 2025 and is in its second reading in the Senate, tied to the new data-protection institutions that enter into force in December 2026[9]. Mexico has accumulated two initiatives with public security as their axis; Colombia, three bills[6].

The background clock is European. The AI Act entered into force in August 2024; its prohibitions have applied since February 2025, the rules for general-purpose models since August 2025, and the bulk of the high-risk obligations is scheduled from August 2026 — the real compliance bill for the model Brazil is inheriting is coming due right now[13]. And in June, Brazil became the first country in the global south to sign a digital partnership agreement with the European Union — the Brazilian route in one sentence: regulate first, ally with Brussels after, the exact contrast with Argentina's bet on deregulating to attract data centers[8].

The region is also institutionalizing: the Third Ministerial Summit on the Ethics of AI produced a declaration and a 2026–2027 regional roadmap[14], and UNESCO launched an observatory of AI in education for Latin America and the Caribbean[15].

The ground it lands on

One last datum frames everything above: adoption is running faster than the rulebook. Demand for AI fluency multiplied elevenfold between 2023 and 2025 in the region — roughly twice the pace of the United States and Europe — and the bulk of that growth is happening outside engineering: sales, administration, design, content[10]. Meanwhile, 85% of Latin American startups already use generative AI in their products[11].

Those are the facts. What they mean for anyone building in Latin America — who wins, who pays the bill, and what is worth moving before the rapporteur's text freezes — is the business of the section that follows.

Sources: Chamber of Deputies of Brazil · Federal Senate · DIAP · Desinformante · Future of Privacy Forum · Foreign Policy · ITI

THE EFFECT — WHAT IT MEANS

A Brazilian law never stays in Brazil.

Latin America has a regulatory pattern so stable it already works like a law of physics. Europe drafts, Brazil adapts, the region inherits. It happened with personal data: Europe's GDPR of 2016 became Brazil's LGPD of 2018, and the LGPD became the template for Ecuador in 2021, for Chile in 2024, for the half-dozen drafts now circulating through the continent's congresses. The region's regulators don't draft from scratch — they inherit and adapt. That is why PL 2338 is not a Brazilian news item: it is the most probable draft of the rulebook that will govern your product, wherever your server happens to be.

That turns early reading into a material advantage. The rapporteur's text hasn't frozen yet, the vote points to late 2026 and, even once enacted, entry into force would be staggered LGPD-style — roughly two years between signature and the full regime. Added up: whoever reads the text today operates years ahead of their own national framework. On a continent that adopts AI at twice the pace of the rich world but is barely beginning to read its own rules, that anticipation is one of the few competitive advantages being given away.

The uncomfortable part has to be said: the inheritance is not a prize. The tech industry has spent months warning that tracing the prescriptive European approach could smother an ecosystem that is barely being born, and PL 2338 itself concedes the point by setting fines deliberately softer than Europe's — 2% of local revenues against 7% of global turnover. It is a serious objection. But for a builder, the verdict on the law is almost irrelevant: good or bad, soft or hard, the play is the same — know it early, shape it where you can, and price compliance in while it's cheap to do so.

Two caveats keep the argument honest. The inheritance is a probable template, not destiny: Mexico is taking a different shape, centered on public security, and regional divergence is real. And the calendar is not a promise: the vote has slipped once and can slip again. This law is not something to depend on — it is something to anticipate. The distinction matters: anticipating costs little and always pays; depending costs everything if Brasília changes its mind.

THE PLAY

  1. Map your product against the high-risk list today — credit, hiring, educational evaluation, public-service eligibility, critical infrastructure. If you're on the list, prototype the algorithmic impact assessment now, while being small makes it cheap.
  2. Design a single compliance architecture for the strictest market — Brazil as the «regional GDPR»: data traceability, human oversight, explainability — and sell it as an asset. «PL 2338-ready» will be a trust signal for corporates and governments across the region.
  3. Get in through the influence window. The special commission is hearing precisely from small business and the education sector[2][4] — the crack through which regional builders get to speak before the text freezes. And watch where the real rules will live: the secondary regulation of the SIA/ANPD, with Europe's August 2026 as the dress rehearsal[13].

THE ECHO — WHAT REMAINS

Congresses debate in linear time; the models advance in exponential time. Every morning of postponement widens the gap between what we control and what we are already capable of building — and in that gap grow, together, the harm and the possible cure. Does an inherited governance even exist that can improve the risk — and the reward — of the singularity? The question runs faster than the answer.

— Francesco Antonio Ruperti

GRUPO CAUSA COMÚN

← ALL EDITIONS
CAUSA & EFECTO — ANALYSIS BY GRUPO CAUSA COMÚN HAVE A CAUSE? STATE IT →