Brazil is one vote away from its first AI law. Bill 2338 of 2023, approved unanimously by the Senate on December 10, 2024, is in the House for its final vote. In the text that reached the deputies, fines can reach R$ 50 million.
For anyone running AI in production, the Legal Framework moves the topic from "best practice" to "obligation". And preparing for it does not start when the law passes.
The EU AI Act’s logic with a Brazilian accent
The design follows the EU AI Act: systems classified as excessive risk can be banned. High-risk systems must meet documentation, audit, and governance requirements, and guarantee the rights of those affected: transparency, explanation, and contestation.
Oversight would sit with the National AI Regulation and Governance System, coordinated by the ANPD, with sectoral authorities and a permanent council. Anyone who followed the LGPD’s arrival recognizes the film: an existing regulator gains new powers, and the market discovers that its adaptation window was the time it wasted.
Why it is delayed (and what the delay tells you)
House rapporteur Aguinaldo Ribeiro said on August 24, at Febraban Tech, that 90% of the text is ready and the vote should land at year-end, after the October 4 and 25 elections.
The delay has a legal reason: the Executive identified an initiative flaw in the clause granting normative powers to the ANPD, a matter reserved for Executive initiative. To keep the framework out of Supreme Court jeopardy, the government sent a complementary bill in December 2025 to create the system and formalize the ANPD’s role, to be attached to PL 2338.
The practical reading: the regulatory architecture is being built to survive challenge. A regulator with a shielded mandate and a R$ 50 million sanction is the opposite of the vacuum this market has operated in.
The ANPD is not waiting for the law
The most underrated point in the debate: AI enforcement has already started under the LGPD. Article 20 already guarantees review of automated decisions; Article 38 already provides for impact reports; the ANPD already made AI a 2026-2027 enforcement priority. And the ByteDance case proved the agency applies sanctions with a ruling number and an official gazette.
Credit scoring, resume screening, dynamic pricing, health: everything that would become "high risk" under PL 2338 already operates today under existing rules. The Legal Framework does not create the obligation from zero; it closes the ambiguity chapter part of the market used as a shield.
What to build now (it serves both scenarios)
Preparation is identical whether the law votes in November or 2027:
- Inventory of every system with automated decisions or generative AI, with an owner and mapped data.
- Risk classification of use cases, in the bill’s vocabulary (excessive, high, residual).
- Audit trail: decision logs, versions, data, and explainability.
- Contestation process with deadlines and a responsible party, for affected people’s rights.
Four items, all demandable today by the LGPD in the high-risk band. The incident-response checklist and this inventory are the two halves of the same governance: one prepares for the accident, the other for the inspection.
Conclusion
"One vote away" is the wrong metric to measure readiness. The right one is: if the ANPD asked tomorrow for the audit trail of one of your models that decides over customers, what would the company show?
The Legal Framework turns AI governance from a competitive differentiator into an operating license, with a R$ 50 million fine drawing the risk ceiling. Anyone running AI in production in Brazil already has every signal: the regulator exists, applies sanctions, and has AI at the top of its queue. The rest is agenda.