Brazil AI Framework
Evidence request list. 29 controls, 29 carrying auditor artefact guidance. Generated from the compliance knowledge graph on 11 September 2026. Published by The Art of Service.
Brazil AI (PL 2338/2023) Cap. I: Preliminary Provisions
Scope. Article 1 establishes general national norms for the development, implementation and responsible use of artificial intelligence systems in Brazil, to protect fundamental rights and ensure safe and reliable systems.
- Determination of AI systems and roles (provider/operator) in scope
- Inventory of AI systems subject to the law
- AI systems not assessed against the law
- Provider/operator roles not identified
Foundations. Article 2 sets the foundations of AI regulation, including human dignity, autonomy, privacy and data protection, free enterprise and innovation.
- Documentation that AI development reflects the statutory foundations
- Alignment of AI policy with the foundations
- Foundations not reflected in AI governance
- No linkage of policy to foundations
Principles. Article 3 sets the principles governing AI: non-discrimination, transparency, explainability, auditability, reliability, human oversight, accountability and others.
- AI governance policy reflecting the Article 3 principles
- Evidence each principle is operationalised (transparency, human oversight, accountability)
- Principles not operationalised
- No evidence of auditability/explainability
Definitions. Article 4 defines the key terms (artificial intelligence system, AI agent, provider, operator, affected person, algorithmic discrimination and others).
- Mapping of statutory definitions to internal terminology
- Classification of systems as AI / roles per Art 4
- Definitions not applied
- Roles misclassified
Brazil AI (PL 2338/2023) Cap. II: Rights of Affected Persons
Right to non-discrimination. Article 12 gives affected persons the right to non-discrimination and to the correction of discriminatory bias, direct or indirect, produced by AI systems.
- Bias detection and mitigation evidence
- Assessment of discriminatory outcomes and corrective action
- No bias assessment
- Discriminatory outcomes not corrected
Rights of affected persons. Article 5 establishes the rights of persons affected by AI systems, including the right to information, explanation, contestation and human review.
- Procedures to honour affected-person rights
- Records of rights requests and responses
- Rights not honoured
- No procedure for affected persons
Right to information. Article 7 gives affected persons the right to know, prior to or at the time of interaction, that they are interacting with an AI system.
- Notices informing users they are interacting with an AI system
- Process to provide AI-interaction disclosure
- No AI-interaction disclosure
- Notice not provided before interaction
Right to explanation. Article 8 gives affected persons the right to an explanation about decisions, recommendations or predictions made by AI systems that affect them.
- Explanation procedures for AI decisions affecting persons
- Records of explanations provided
- No explanation mechanism
- Explanations not meaningful
Right to contest. Article 9 gives affected persons the right to contest AI decisions and to request human review of decisions that produce relevant legal effects or significantly affect them.
- Mechanism to contest AI decisions and obtain human review
- Records of contestations and human reviews
- No contestation mechanism
- Human review not available
Brazil AI (PL 2338/2023) Cap. III: Risk Categorization of AI Systems
Preliminary assessment. Article 13 requires AI agents to perform a preliminary assessment to classify the risk of an AI system before placing it on the market or putting it into use.
- Preliminary risk-classification assessment per AI system
- Documentation supporting the risk classification
- No preliminary risk assessment
- Classification not documented
Excessive-risk AI. Article 14 prohibits the implementation and use of AI systems posing excessive risk, including subliminal techniques, exploitation of vulnerabilities and certain social-scoring uses.
- Assessment that no excessive-risk/prohibited AI use is deployed
- Controls preventing prohibited AI uses
- Prohibited AI uses deployed
- No screening for excessive-risk uses
Biometric identification. Article 15 restricts the use of remote biometric identification systems in publicly accessible spaces for public-security purposes to defined cases and safeguards.
- Legal basis and safeguards for any remote biometric identification
- Authorisation records for public-security biometric use
- Biometric ID used without legal basis/safeguards
- No authorisation records
High-risk AI. Article 17 designates the categories of high-risk AI systems (e.g. critical infrastructure, education, employment, essential services, justice, biometrics) subject to enhanced governance.
- Classification of AI systems against the high-risk categories
- Enhanced governance applied to high-risk systems
- High-risk systems not identified
- Enhanced governance not applied
Updating the high-risk list. Article 18 empowers the competent authority to update the list of high-risk AI systems, requiring agents to monitor for changes.
- Process to monitor updates to the high-risk list
- Re-classification when the list changes
- High-risk list updates not monitored
- Re-classification not performed
Brazil AI (PL 2338/2023) Cap. IV: Governance of AI Systems
Governance measures. Article 19 requires AI agents to establish governance structures and internal processes to ensure security and the rights of affected persons throughout the AI lifecycle.
- Documented AI governance structures and internal processes
- Lifecycle controls for security and rights
- Roles and responsibilities for AI governance
- No governance structure
- Lifecycle controls absent
- Roles undefined
High-risk governance. Article 20 imposes additional governance measures for high-risk AI, including documentation, testing, data management, logging and human oversight.
- Additional high-risk governance documentation
- Testing, data-management and logging records
- Human-oversight mechanisms for high-risk AI
- Additional measures not applied to high-risk AI
- No logging/testing
- Human oversight absent
Algorithmic impact assessment (AIA). Article 22 requires an algorithmic impact assessment for high-risk AI systems, evaluating risks and mitigation measures.
- Algorithmic impact assessment for high-risk systems
- Identified risks and mitigation measures
- Review/update of the AIA
- No AIA for high-risk systems
- Risks/mitigations not documented
- AIA not updated
AIA methodology. Article 24 sets out the minimum content and methodology of the algorithmic impact assessment.
- Documented AIA methodology meeting the minimum content
- Evidence the methodology was applied
- AIA lacks the required content
- Methodology not followed
Publicity of the AIA. Article 26 requires publication of the conclusions of the algorithmic impact assessment, protecting industrial and commercial secrets.
- Published AIA conclusions (with secrets protected)
- Process for publishing AIA outcomes
- AIA conclusions not published
- No process for publication
Brazil AI (PL 2338/2023) Cap. V: Civil Liability
Civil liability. Article 27 establishes the civil liability of providers and operators of AI systems for patrimonial, moral, individual or collective damage caused.
- Awareness of civil-liability exposure
- Insurance/risk-transfer for AI liability where used
- Records of damage claims and handling
- Liability exposure not assessed
- Claims not handled
- No risk transfer considered
Liability allocation. Article 29 sets out how civil liability is allocated among the AI agents in the value chain.
- Contractual allocation of AI liability across the value chain
- Records identifying provider/operator roles for liability
- Liability allocation undefined
- Roles not documented for liability
Brazil AI (PL 2338/2023) Cap. VI-VII: Incident Communication and Supervision
Incident communication. Article 31 requires AI agents to communicate serious security incidents to the competent authority, including risks to life, safety, critical infrastructure or fundamental rights.
- Procedure to assess and report serious AI incidents to the authority
- Records of incident notifications and timelines
- Incident register
- Serious incidents not reported
- No notification criteria/timelines
- Incident register absent
Competent authority. Article 33 designates the competent authority as the central body for applying the law and issuing norms and guidelines (the national AI governance system, coordinated with the ANPD).
- Engagement and cooperation with the competent authority
- Responses to authority norms, guidelines and requests
- Authority requirements not met
- No cooperation with the authority
Administrative sanctions. Article 36 sets out the administrative sanctions for infractions of the law (warnings, fines, publication of the infraction, suspension or prohibition of the AI system).
- Awareness of sanction exposure under the law
- Controls preventing sanctioned conduct
- Records of any sanctions and remediation
- Sanction exposure not assessed
- No controls against infractions
- Sanctions not remediated
Brazil AI (PL 2338/2023) Cap. VIII-IX: Codes, Sandbox and Final Provisions
Codes of good practice. Article 37 enables AI agents to adopt codes of good practice and governance, and the authority to recognise them.
- Adoption of applicable AI codes of good practice
- Evidence of alignment with recognised codes
- No code of good practice adopted
- Practices not aligned to codes
Regulatory sandbox. Article 38 empowers the authority to authorise experimental regulatory environments (sandboxes) for AI innovation under supervision.
- Sandbox participation authorisation and conditions
- Supervision and reporting during sandbox testing
- Sandbox use without authorisation
- No supervision/reporting
Copyright and TDM. Article 42 provides that the automated use of works for text and data mining by research and other entities does not, under defined conditions, constitute copyright infringement.
- Assessment of TDM/copyright conditions for AI training data
- Records of lawful basis for using protected works
- Protected works used without meeting TDM conditions
- No copyright assessment of training data
Incident database. Article 43 tasks the authority with creating and maintaining a database of AI incidents, to which agents contribute.
- Contribution of AI incidents to the authority's database
- Internal incident records aligned to the database
- Incidents not contributed to the database
- No internal incident records
Entry into force. Article 45 provides that the law enters into force one year after its publication, requiring a transition/implementation plan.
- Implementation/transition plan for compliance by the effective date
- Milestones tracking readiness
- No transition plan
- Readiness not tracked to the effective date
Assembled from the framework’s own control set, so this list is regenerated rather than written and stays current as the graph does. See the Brazil AI Framework framework page.