Marco Legal da IA

Global Referral Group

The article shows how the AI ​​Legal Framework will require governance, risk management, transparency, and human oversight from companies even before the new law comes into effect.

Credits: Political Crumbs

Is your organization prepared to demonstrate that it understands the AI ​​tools it uses, comprehends the risks involved, and maintains control over the results they produce?

This question is becoming increasingly relevant for companies that develop, market, or simply use AI systems in their operations.

Bill 2.338/23, authored by Senator Rodrigo Pacheco, was approved by the Senate in December 2024 and is currently being processed in the Chamber of Deputies, under the rapporteurship of Deputy Aguinaldo Ribeiro, with no date set for a vote.

While the discussion about when the text will be definitively approved is important, it shouldn’t delay the attention of those who already use, distribute, or develop AI systems. The project already presents sufficiently consolidated guidelines to guide business decisions, and ignoring them until the future law is sanctioned could be more costly than starting to prepare now.

This text presents what is already planned in the project, the main changes for companies, and the measures that can be adopted immediately.

More than establishing new legal obligations, the project reinforces a trend already observed internationally: AI governance is becoming part of organizations’ strategic agenda. Just as with the LGPD (Brazilian General Data Protection Law), companies are expected to adopt processes capable of demonstrating transparency, risk management, and adequate oversight of technologies that influence business decisions.

Risk management as the central focus of future regulation.

Bill 2338/23 adopts a risk-proportional regulation logic, inspired by the European AI Act, essentially working with three categories:

Excessive risk. These practices are strictly prohibited. Examples include autonomous weapon systems, techniques that exploit the vulnerabilities of specific groups (children, the elderly, people with disabilities) to induce harmful behavior, and social scoring systems implemented by public authorities. No compliance measures can make these systems permissible; their use is banned.

High risk. This category is of greatest interest to the business sector, as it encompasses the AI ​​systems most commonly found on the market. Article 17 of the bill lists various purposes that classify a system as high-risk, including: workforce selection and management (recruitment, performance evaluation, promotion, and termination); credit granting and scoring; admission and evaluation in educational institutions; health diagnosis and treatment recommendations; systems used in public security and the administration of justice; and critical infrastructure management and border control. High-risk systems are subject to the strictest set of governance obligations.

Moderate or low (residual) risk. This applies to the majority of AI tools in common commercial use, such as customer service chatbots, content or product recommendation systems, and writing assistants. Basic transparency requirements—such as informing the user that they are interacting with an automated system—remain mandatory.

Article 18 stipulates that the competent authority may update it, including new scenarios. This means that a system’s classification can change over time, reinforcing the need for periodic reviee.

For organizations, this classification represents a significant shift in perspective. The regulatory focus is no longer solely on the technology employed, but begins to consider the context in which it is used. The same system may require different levels of governance depending on its purpose, the potential impact on people, and the risk associated with the decisions it supports.

The rights that the law guarantees to those affected by an AI decision.

Chapter II of the bill creates a set of rights for anyone impacted by an AI system, even if they are not a data subject within the meaning of the LGPD (Brazilian General Data Protection Law). The main rights are:

Right to prior information regarding interaction with an AI system, its purpose, and the responsible developer and operator.
Right to an explanation (Arts. 9 and 10)—that is, to receive, in a clear and understandable manner, the general criteria that led to a significant automated decision.
Right to contest and to human review (Art. 11), allowing the individual to challenge the decision and request a re-evaluation by a human being.
Right to non-discrimination, including the correction of biases identified in the system.

These guarantees are especially important for decisions that produce relevant legal effects or significantly affect the individual, which, in practice, covers a large part of the uses of AI in consumer relations, work, and access to services.

From a business perspective, these rights require that automated processes be accompanied by mechanisms that ensure transparency, traceability, and the possibility of human review. In practice, the concern ceases to be exclusively technological and begins to involve governance, internal controls, and risk management.

New responsibilities for suppliers and user companies

The project distinguishes between two roles, called “AI agents”: the supplier, who develops or markets the system, and the operator, who uses it in their activities. This distinction is important because, in the day-to-day operations of a company, it is common for it to simply operate a tool developed by a third party and still have its own obligations.

This distinction deserves special attention because a large portion of Brazilian companies do not develop their own AI systems, but rather use solutions provided by third parties. Even so, the status of operator does not eliminate the need to implement internal controls, supervise the use of these tools, and adopt measures commensurate with the risk involved.

For high-risk systems, the project requires AI agents to perform an algorithmic impact assessment: a technical document that analyzes the system’s bias, security, and transparency risks before and during its use.

Public bodies that contract or develop high-risk systems have additional obligations, such as prior public consultation. For systems in general, the central requirement is the adoption of governance measures and good risk management practices, with documentation proving the company’s diligent performance.

From this perspective, AI governance ceases to be merely a future regulatory requirement and becomes an element of organizational maturity. Companies capable of demonstrating structured evaluation, monitoring, and control processes tend to reduce their exposure to regulatory, operational, and reputational risks.

Civil liability: A point that deserves extra attention.

The treatment of civil liability is one of the most relevant chapters of the bill. The bill establishes that the supplier or operator who causes patrimonial, moral, individual or collective damage through an AI system is obliged to fully repair it, regardless of the degree of autonomy of the system.

From a corporate perspective, the greatest impact stems not only from the possibility of liability, but also from the need to produce evidence capable of demonstrating the adoption of diligent governance measures. Just as with compliance and data protection programs, the documentation of AI-related decisions is likely to play a central role in mitigating risks.

For systems classified as high-risk, the project adopts a more rigorous accountability regime, while for other systems, it establishes a presumption of guilt, facilitating the production of evidence by the injured party.

In practice, this significantly reduces the scope for defense of companies that cannot demonstrate, through documentation, that they have adopted adequate governance measures, transforming internal compliance documentation into evidence for the defense, not just a formal requirement.

Administrative sanctions

Failure to comply with legal obligations subjects AI agents to administrative sanctions applied by the competent authority, ranging from warnings to fines, which can reach significant amounts depending on the severity of the infraction, the agent’s economic capacity, and recidivism, in which case the amounts tend to be increased.

The design is similar to what already exists in the LGPD (Brazilian General Data Protection Law), and was built to directly interact with the data protection system already in place in the country.

In addition to the financial consequences of potential sanctions, organizations should also consider reputational impacts, risks to business continuity, and potential repercussions on relationships with customers, investors, and business partners, especially in technology-intensive sectors.

What to do now

Given this scenario, a consistent work plan for companies already using AI, regardless of the project’s stage of development, involves five key areas:

Inventory. Catalog all AI systems in use—whether internal or sourced from third parties—identifying their purpose, the data utilized, and their level of decision-making autonomy. Without this mapping, none of the subsequent steps are possible.

Risk classification. Assess which category each system falls into—based on the criteria in Article 17 and other instances of excessive risk—and periodically review this classification, given that the statutory list is not static.

Contract review. Review liability clauses in contracts with technology providers, clearly defining who is liable for system failures and to what extent; in light of the strict liability regime under Article 27, this shifts from a mere drafting detail to a matter of direct financial exposure.

Documented governance. Structure internal policies, impact assessments, and human oversight mechanisms, while formally recording decisions made. This is necessary not only for legal compliance upon the law's entry into force but also because such documentation serves—right now—as a primary line of defense in potential disputes involving personal data or consumer relations.

Training. Conduct periodic staff training, establish guidelines for the responsible use of AI, and define procedures for human validation of automated decisions. AI governance depends not only on the technology employed but also on how people interact with it.
Final considerations

Organizations that begin structuring AI governance programs now tend to be better prepared to respond not only to future regulatory requirements, but also to the growing expectations of customers, investors, and business partners. In this context, mechanisms for transparency, risk management, and human oversight cease to be exclusively compliance tools and become established factors of trust and competitive differentiation.

Although Bill 2.338/23 may still undergo changes during its passage through the Chamber of Deputies, the foundations of the future legal framework for AI in Brazil are already clearly outlined.

Furthermore, some of what the bill requires can already be demanded of companies under the LGPD (Brazilian General Data Protection Law). Automated decisions involving personal data are already subject to the principles of transparency, purpose limitation, and the right to review.

AI regulation should not be understood merely as a new set of legal obligations. It signals a transformation in how organizations structure technology-based decision-making processes, incorporating principles of transparency, accountability, human oversight, and continuous risk management.

AI has moved beyond being an experimental technology and has become part of the daily routine for companies. In this scenario, the discussion is no longer limited to whether an organization will use AI, but how it will do so in a safe, transparent, and responsible manner.

Companies that structure governance mechanisms now will be better prepared not only to meet future legal requirements, but also to strengthen their reputation, increase the trust of customers, partners and employees, and transform innovation into a sustainable competitive advantage.

In an environment of rapid technological transformation, compliance ceases to be merely a regulatory requirement and becomes a strategic differentiator. After all, AI can accelerate decisions and boost business, but human governance will continue to be the element capable of ensuring that this innovation generates value, trust, and accountability.


Barbara Rita Lamarca Escape

Lawyer registered with the Brazilian Bar Association, São Paulo Section, since 2019. Graduated in Law from the Rio Branco Integrated Faculties of the Rotary Foundation of São Paulo and holds a postgraduate degree in Business Law from the Getulio Vargas Foundation (FGV). She has completed Executive Education in Compliance training at FGV and is currently pursuing an Advanced MBA in Business Management at FIA Business School. She currently serves as Chief of Staff at TM Associados and has been recognized by the international legal ranking Leaders League for her work in Business Law.

Camila dos Santos

Graduated in Law from the Padre Anchieta University Center (2024). Registered with the Brazilian Bar Association, São Paulo Section (OAB/SP) (2025). Author of articles. Lawyer in the Advisory Department at TM Associados.

See our latest News

Gustavo D'Acol Cardoso

AI Legal Framework: Why companies should strengthen their...

July 20, 2026

¿Quién es el mejor abogado en delitos de estafa en España...

July 19, 2026

¿Quién es el mejor abogado en delitos de organización cri...

July 19, 2026

Gustavo D'Acol Cardoso

10% tax on dividends above R$50,000: Why business owners ...

July 17, 2026

Gustavo D'Acol Cardoso

European fines don’t apply to Brazil. The clause, h...

July 17, 2026

Sam Jalaei

Magnusson advises Sports Tours International Limited on t...

July 15, 2026

Sam Jalaei

Magnusson advises CoralPoint International Limited on its...

July 15, 2026

Sam Jalaei

Magnusson Denmark assists vCare in another successful inv...

July 15, 2026

Richard Acheampong

No-Fault Divorce and the Future of Family Law in Ghana: L...

July 13, 2026

Saika Alam

Can “Bad Behaviour” Affect Your Divorce Settlement? The C...

July 9, 2026