Without A Legal Framework, ANPD And Sectoral Regulators Advance AI Regulation

August 21, 2026

Bill No. 2,338/2023, which establishes the Legal Framework for Artificial Intelligence, is one of the main initiatives related to AI regulation in Brazil and remains under consideration by the Chamber of Deputies. Approved unanimously by the Federal Senate on December 10, 2024, the bill has been awaiting the rapporteur"s opinion before the Special Committee for months, with no scheduled voting date.

 

 

The President of the Chamber of Deputies, Hugo Motta, even agreed with rapporteur Aguinaldo Ribeiro on a specific timetable, which provided for the final opinion to be issued on May 19, 2026, and for a plenary vote on May 27, 2026. However, this schedule did not materialize and was repeatedly postponed due to political deadlocks, the lack of consensus on sensitive provisions of the bill, and the 2026 electoral calendar.

 

The legislative scenario became even more complex when, in December 2025, the Executive Branch submitted a complementary bill to establish the National Artificial Intelligence System (SIA) and formally designate the National Data Protection Authority (ANPD) as the coordinating entity.

 

Therefore, as of August 2026, companies that develop or use artificial intelligence systems in Brazil continue to operate without a specific regulatory framework for the subject in the country.

 

The available regulatory response: ANPD"s Sandbox

Considering this regulatory gap, the ANPD has opted for an experimental and collaborative approach. Rather than simply waiting passively for legislative approval, the agency established a regulatory sandbox for artificial intelligence, an environment in which selected companies test solutions under the agency’s direct supervision.

 

On July 2, 2026, the ANPD published the 1st Partial Monitoring Report for this sandbox, compiling the results of its first operating cycle.

 

Three companies were selected through Public Call No. 2/2025:

  • Metatext, with the Guardion.AI platform, focused on security of autonomous agents;
  • Synapse AI, responsible for the Projeto Trajetto for real-time railway management; and
  • Prevvine Tecnologia, developer of STAIDOC, a medical AI solution using customized language models.

 

Cycle 1, which began on March 18, 2026, focused on structuring the testing environments and mapping technological, legal and operational challenges.

 

Among the findings, the need to improve communication between the participating companies and the University of São Paulo’s Center for Artificial Intelligence and Machine Learning (CIAAM/USP) stands out, as does the development of emerging governance practices.

 

In this regard, concrete solutions are being explored. Metatext uses synthetic data to mitigate risks; Synapse applies pseudonymization in secure environments; and Prevvine uses the HarpIA tool for assessments involving medical professionals.

 

The sandbox, which will remain in operation until December 2026, will devote its upcoming cycles to analyzing digital security, transparency and data governance.

 

Sectoral Regulation of Artificial Intelligence in Brazil

The ANPD’s sandbox, however, is not the only initiative underway. In the absence of a federal legal framework, sectoral regulators have been advancing their own rules for the use of artificial intelligence within their respective areas of activity.

 

Healthcare

The Federal Council of Medicine (CFM) issued Resolution CFM No. 2,454/2026, adopted on February 11, 2026, establishing a comprehensive framework for the use of artificial intelligence in medicine.

 

The regulation covers research, development, governance, auditing, monitoring, training and the responsible use of technology. It also defines artificial intelligence strictly as a support tool, with the physician retaining final authority over diagnoses, treatments and prognoses.

 

In addition, the resolution expressly prohibits artificial intelligence systems from communicating diagnoses, prognoses or therapeutic decisions directly to patients.

 

Medical institutions that develop or hire AI solutions must establish internal governance processes to ensure safety, quality and ethics.

 

The regulation will enter into force on August 26, 2026, meaning that hospitals, clinics and digital health companies must promptly review their artificial intelligence applications.

 

Telecommunications

Anatel published Resolution No. 777/2025 on April 30, 2025, as part of the new General Regulation on Telecommunications Services (RGST).

 

Article 40 of the regulation is groundbreaking, as the regulator codified specific principles for artificial intelligence in binding regulation.

 

There are eight mandatory principles:

  • reliability;
  • fairness;
  • non-discrimination;
  • pluralism;
  • privacy and data protection;
  • respect for fundamental rights and democratic values;
  • sustainability; and
  • transparency and explainability.

 

In practice, this means that telecommunications operators and service providers that use AI-based solutions—whether for network management, automated customer service, fraud detection or traffic analysis—must observe these principles in all their operations.

 

Capital Markets

The Brazilian Securities Commission (CVM), in turn, issued Resolution No. 246 on July 30, 2026, establishing the Financial Technology Division (Ditec), linked to the Superintendence for Intelligence Development (SDI).

 

Ditec’s mission includes establishing guidelines for the use of advanced analytical and computational solutions, in accordance with AI governance policies. The division will also support the tokenization project for 2026–2027 and the regulator’s next regulatory sandbox cycle.

 

CVM Chairman Otto Lobo, who took office in June 2026, stated that “tokenization and artificial intelligence are reshaping the way assets are issued, traded and held in custody.”

 

The message is unequivocal: the capital markets regulator already treats AI governance as a strategic priority, which will have concrete implications for asset managers, brokerage firms and other market participants.

 

Companies Should Prepare for the AI Legal Framework

Active monitoring of the legislative process in the Chamber of Deputies remains equally relevant to corporate strategic planning. However, waiting for the law does not justify operational inaction.

 

Against this fragmented regulatory backdrop, companies that develop or use artificial intelligence in Brazil should adopt a proactive approach. Key measures include:

  • mapping the requirements of the sectoral regulations applicable to their activitie;
  • monitoring developments related to the ANPD’s sandbox; and
  • establishing internal AI governance policies aligned with principles already emerging from the legal system, such as transparency, non-discrimination, data protection and accountability.

 

The Brazilian regulatory framework for AI is being developed through multiple channels. In this context, companies that anticipate their compliance efforts may gain a competitive advantage once the AI Legal Framework finally enters into force

Publication produced by our Cybersecurity & Data Privacy