by Maria Eduarda X. Soares and Heloísa Nogueira
The use of artificial intelligence in daily business operations has moved beyond being a mere technological differentiator and is now occupying an increasingly central position in the operations of countless companies across the globe.
Amid the current landscape of growing adoption of AI-based solutions—ranging from data analysis and process automation to the formulation of corporate strategies—Brazilian legislation is being put to the test, giving rise to a new need: the creation of regulations to ensure the ethical, transparent, and secure use of this technology.
In recent years, with the rapid growth of artificial intelligence, it has become essential to discuss its regulation, seeking to keep pace—or at least attempt to keep pace—with the speed of innovation in business activities.
In this context, Bill No. 2.338/2023, which proposes a legal framework for artificial intelligence in Brazil, has advanced within the Legislature. The proposal, which defines principles, duties, and obligations directly impacting the business sector, is currently under review by the Chamber of Deputies.
The bill, proposed by Senator Rodrigo Pacheco, establishes a classification system for AI based on the risk they pose to fundamental rights, safety, privacy, and human dignity. It reads as follows:
“Art. 1 This Law establishes general national standards for the development, implementation, and responsible use of artificial intelligence (AI) systems in Brazil, with the aim of protecting fundamental rights and ensuring the implementation of safe and reliable systems for the benefit of individuals, the democratic regime, and scientific and technological development.”
Technology may be classified as posing low, medium, high, or even excessive risk, depending on the severity of the impact. The use of systems considered to pose excessive risk is strictly prohibited, such as those that manipulate human behavior or engage in social scoring of individuals. Conversely, high-risk systems—such as those used in decisions impacting people's lives, including credit, medical diagnoses, or hiring—will be subject to various specific requirements regarding governance, transparency, and, above all, human oversight.
As debates deepen and the legislative process advances, companies must remain attentive to the practical effects this law will have on their operations, especially regarding technological compliance.
In practical terms, this means that companies implementing AI-based solutions must properly map these tools and assess the risk level posed by their various applications. Those classified as high-risk will require measures such as algorithmic impact assessments, traceability mechanisms, explainability for automated decisions, and appropriate channels for affected individuals to raise objections.
Meanwhile, from a corporate governance perspective, the proposal necessitates a redesign of the compliance models for companies that use artificial intelligence at any stage of their operations. This encompasses reviewing internal policies, updating contracts, and ensuring compliance with the General Data Protection Law (LGPD), given that the vast majority of AI applications involve personal data.
It is evident that Brazil is following a global trend. A prime example is the European Union's recent approval of the AI Act, one of the world's most comprehensive pieces of legislation on artificial intelligence. Much like its European counterpart, the national bill values innovation and the protection of fundamental rights, prioritizing principles such as non-discrimination, accountability, human oversight, and safety.
Furthermore, it is clear that Bill 2.338/2023 will require a significant adaptation effort, particularly from smaller companies, which may face technical and operational challenges in meeting legal obligations. Conversely, companies that anticipate the regulation—by implementing algorithmic governance practices and strengthening their compliance—not only mitigate legal and reputational risks but also bolster their institutional image among investors, partners, and clients.
In this context, studying and understanding the implications of artificial intelligence in daily operations goes far beyond a mere competitive advantage; before long, it may become a requirement for all companies. The future of artificial intelligence in Brazil and worldwide is taking shape as we speak, and being prepared is not only a legal necessity but also a strategy for survival and market trust.
Therefore, having the support of a law firm specialized not only in the legislation but also in the relevant technology tools makes all the difference in this process.. Whether your company is growing or undergoing a process of readaptation, it is crucial that this be carried out safely, ethically, and in alignment with global trends.
Chamber of Deputies Portal. Available at: <https://www.camara.leg.br/proposicoesWeb/fichadetramitacao?idProposicao=2487262>. Accessed on: July 31. 2025.
FARIA, W. D. Key points of Bill 2.338/2023, which regulates the use of artificial intelligence (AI) in Brazil. Available at: <https://www.gft.com/br/pt/blog/pontos-chaves-do-projeto-de-lei-sobre-uso-de-ia-no-brasil>. Accessed on: July 31, 2025.
DINO. Artificial Intelligence regulation advances in 2025. Available at: <https://valor.globo.com/patrocinado/dino/noticia/2025/01/31/regulamentacao-da-inteligencia-artificial-avanca-em-2025.ghtml>. Accessed on: July 31, 2025.