Skip to content
Brazil's AI bill (PL 2338): what changes for those operating AI in retail

Brazil's AI bill (PL 2338): what changes for those operating AI in retail

Brazil’s AI bill, PL 2338/23, classifies AI systems by risk level and imposes obligations by band. The rule seems distant. For anyone using scoring and biometrics, it aims straight at them.

The bill passed the Senate in late 2024 and is still moving through the Chamber of Deputies. It is not law yet. But the shape of the text is already readable, and it changes decisions being made right now.

What the bill says, in plain text

The design is risk-based, in the spirit of what Europe did. Low-risk systems stay almost free. High-risk systems get obligations of transparency, documentation, human oversight, and impact assessment.

For retail, the high-risk band reaches what is already running: consumer credit scoring, biometrics for identification, and part of the recommendation that affects access to an offer. Anyone who works the operation needs to know that “using AI” stopped being a single category.

The systems the rule touches

It is not AI in the abstract. It is a specific system, with a specific function.

  • Credit and risk scoring at checkout, likely high risk.
  • Biometrics in store cameras, high risk, and already under the LGPD today.
  • Recommendation and pricing, depending on how they affect the consumer.
  • Automated service, with an obligation to disclose that the customer is talking to AI.

What changes for those who thought they were compliant

Being LGPD-compliant does not cover the AI bill. The difference sits in three points to map now, before the rule closes.

First, the risk classification of each system you operate, which nobody has done yet. Second, the documentation of how the system decides, required for high risk. Third, the human-oversight point, which many projects removed in the name of efficiency and may need to put back.

The second-order effect almost every plan ignores

The rule changes vendor selection. The question stops being “does the system work” and becomes “does the vendor deliver the documentation and auditability that high risk will require”.

Telling law apart from a bill is part of the work. The bill is still moving; publishing a decision as if it were already law is an error in both directions, ignoring and exaggerating. The right move is to map now and have the plan ready for the day of enactment, without stopping the operation meanwhile. It is the same discipline as the EU AI Act for exporters.

Think about the AI system your operation runs that legal has not yet classified by risk. That is first in line.

Send me the list of AI systems your operation uses: scoring, biometrics, recommendation, service, whatever it is. In one hour I will send back a one-page map: the likely risk band of each, what high risk will require, and what you can get ahead of before the law. If a front becomes a project, the two-week Diagnóstico is the next step. We do not give legal opinions; we map the operation against the forming rule.