Brazil's AI governance landscape in 2026
Brazil has emerged as Latin America's most active jurisdiction for AI governance enforcement, driven by a strengthened data protection authority and an explicit regulatory commitment to supervising AI systems. Understanding Brazil's AI governance framework requires understanding three layers: the LGPD as the foundational binding law; the ANPD's rapidly evolving enforcement posture; and the proposed federal AI Bill that remains before Congress.
The LGPD and AI: binding obligations now
Brazil's General Data Protection Law applies to any processing of personal data of individuals located in Brazil, regardless of where the processing occurs or where the organisation is based. This extraterritorial scope means that international organisations with Brazilian users or customers are within scope. The LGPD's principles, purpose limitation, data minimisation, transparency, and accountability, apply to AI systems that process personal data with the same force as to any other data processing activity.
Automated decision-making is specifically addressed in Article 20 of the LGPD, which gives data subjects the right to request review of decisions made solely on the basis of automated processing that affect their interests. This creates a direct obligation for organisations using AI in consequential decisions, credit, employment, insurance, access to services, to establish review mechanisms. Two limits matter in practice. First, the LGPD does not require that the review be carried out by a human being: the paragraph requiring review by a natural person was vetoed when Law No. 13.853/2019 amended the LGPD, and Congress upheld that veto on 2 October 2019, so on the face of the statute an automated re-review can satisfy Article 20. Second, the accompanying right is a right to clear and adequate information about the criteria and procedures used in the automated decision, and Article 20 expressly makes it subject to commercial and industrial secrecy. Article 20 remains one of the most operationally significant AI governance obligations in Brazil, but it is narrower than the EU GDPR Article 22 provision it is often compared to.
The ANPD: newly independent, newly powerful
In September 2025, Provisional Measure No. 1.317/2025 transformed the ANPD into a full independent regulatory agency, the National Data Protection Agency, with its own assets, administrative autonomy, and significantly expanded enforcement powers. That measure was converted into permanent Law No. 15.352/2026, sanctioned on 25 February 2026, which now formally establishes the ANPD's status as a regulatory agency. The ANPD can now order establishments to cease operations, seize goods, and request police assistance in cases of obstruction. This represents a fundamental shift from an advisory to an enforcement-oriented posture.
The ANPD's 2026-2027 Priority Themes Map, published December 2025, lists AI and emerging technologies in personal data processing as one of four equal priority themes for 2026-2027, alongside data subject rights, protection of children and adolescents, and processing of personal data by the public sector. Supervised areas include facial recognition systems, recommendation and ranking algorithms, and automated decision-making systems, particularly where children's data is involved. Organisations using AI to process personal data of Brazilians should treat this as a signal of imminent enforcement activity.
The Digital Child and Adolescent Statute (ECA Digital)
Law 15.211/2025, signed September 2025 and in force from March 2026, creates sweeping new obligations for platforms and AI systems that may reach children and adolescents in Brazil. The statute introduces privacy by default requirements, age verification obligations, and enhanced ANPD authority over child data protection online. AI systems, particularly recommendation algorithms, content moderation AI, and personalisation systems, that may be used by or affect Brazilian minors face significant new compliance obligations.
Brazil's proposed federal AI Bill
Federal Bill PL 2338/2023 proposes a dedicated AI regulatory framework for Brazil, modelled loosely on the EU AI Act's risk-based approach. The bill was progressing through the Brazilian Congress as of early 2026, with the ANPD expected to be designated as the primary supervisory authority. Full adoption and implementation timeline remains uncertain, but the direction is clear: Brazil is moving toward a dedicated AI governance framework that will layer on top of existing LGPD obligations. Organisations building compliance for the LGPD's current requirements are building the foundation that the proposed AI Bill will extend.
Related reading
- Canada AI Governance 2026: AIDA Is Dead, Quebec Law 25 Leads, and What Organisations Must Do
- GDPR vs Australia Privacy Act vs Singapore PDPA: A Practical Comparison for AI Governance
- GDPR and the EU AI Act: How They Interact and Where They Conflict
- China AI Governance: PIPL, CAC Regulations, and What Companies Need to Know
Further reading: NIST AI RMF