XMACNA
AI Legal Framework for Businesses (PL 2338): what changes

AI Legal Framework for Businesses (PL 2338): what changes

The AI legal framework (PL 2338) is not yet law: it was approved in the Senate and is pending in the Chamber. But you can already prepare — classify uses by risk, record decisions, and maintain human escalation.
XMACNA Team

9 min read

Analysis

Direct answer: the AI legal framework for businesses (PL 2338) is not yet law — it was approved in the Senate and is under review in the Chamber, with voting postponed on 2026. There is nothing to comply with today. But the draft already allows for preparation: classify uses by risk, record automated decisions, and maintain human escalation.

Before looking at the project details, the important question: why will this change a real decision of yours, still this year?

Because the rule coming won't just demand "use AI responsibly" in the abstract. It will require proof. Proof that you know which AI systems you use, proof that you recorded what each decided about your client, and proof there is a human responsible when something goes wrong. Companies that just turn on a tool and forget will find out at the worst moment that they can't show any of this. Companies that treated AI as an auditable operation from the start will have half their homework done.

At XMACNA, operating more than 600 Digital Employees in production serving real clients daily, we see closely the difference between the two scenarios. Those who operate AI with traceability sleep peacefully. Those who operate in the dark have a problem waiting to happen — with or without law.

What is PL 2338 (and what it is NOT yet)

PL 2338/2023 is the bill intended to establish the AI legal framework in Brazil. It was unanimously approved in the Senate plenary in 10 December 2024 and since then is being processed in the Chamber of Deputies, where a Special Committee — led by deputy Aguinaldo Ribeiro (PP-PB) — analyzes the text and its annexes.

Critical point, no alarmism: it is not yet law. The text approved by the Senate must pass the Chamber and, if changed, return for review. Voting has been postponed multiple times: it was expected at the end of 2025, then pushed to 2026, and remained without a confirmed date midyear, amid impasses on copyright and exceptions for high-risk systems. The Chamber Speaker conditioned progress on prior alignment with the Senate.

In other words: the schedule is uncertain, but the direction is not. Those waiting for "law enactment" to start organizing will begin late.

How the text is designed (mirror of the European model)

PL 2338 generally follows the logic of the European AI Act. The most relevant structural points for companies:

  • Risk classification. AI uses are separated by level: excessive risk (prohibited practices), high risk (strong obligations), and low or moderate risk. Obligations vary by use, not by company.
  • Rights of those affected. Transparency (knowing you are interacting with AI), explanation (understanding how an automated decision was made), and contestation (being able to challenge that decision).
  • Institutional governance. Provision for a national AI regulation and governance system, with ANPD playing a coordinating role.
  • Sanctions. Penalties can reach high fines for violations, in the tens of millions of reais.
  • Prohibited practices. Subliminal manipulation and mass surveillance, for example.
  • Regulatory sandboxes. Controlled environments to test AI under supervision.

Don't memorize the articles. Memorize the logic: the law will ask "why do you use AI, who does it affect, and how do you prove what happened."

Why looking at Europe helps anticipate Brazil

The European AI Act is the best mirror of what is coming because it is already in force and shows how obligations work in practice. It's worth following the European regulatory framework and its implementation timeline, especially as deadlines have been flexible.

An important updated detail: obligations for high-risk systems in Annex III, scheduled for 2 August 2026, are likely postponed to 2 December 2027 — according to a provisional May 2026 political agreement on the "Digital Omnibus" package, still pending formal adoption and publication in the EU Official Journal (AI embedded in already regulated products would stay for August 2028). The lesson isn't "relax, it was postponed." It's the opposite: even Europe, which led the way, is discovering that documenting, testing, and auditing AI is hard — and thus needed more time. Companies that start early don't suffer from deadlines.

XMACNA already covered this from another perspective in the post about taking AI out of pilot and putting it into real production: the hard part is never turning on the model, it's operating with control.

AI compliance for companies: the by-design checklist

Good news for SMEs: you don't need an AI legal department. You need five operational habits, built from the start — “compliance by design.” Each also improves operation, law or no law.

  1. Classify your AI uses by risk. List where AI appears in your business: service, lead screening, billing, analysis. Mark which decisions directly affect a client (credit, scheduling, service) — these are candidates for "high risk" and deserve more care.
  2. Document and record automated decisions. For each relevant interaction, save what was decided, when, and based on what information. Without records, there's no possible explanation — and the law demands explanation.
  3. Ensure the right to explanation for the customer. If a customer asks "why did I receive this answer / scheduling / denial?", you need to answer understandably, not just technically.
  4. Maintain a human escalation point. There must always be a clear path for a human to take over — by customer decision or system trigger. AI that doesn’t know when to call a person is a risk, not a saving. XMACNA has already written about why good AI depends on human judgment, not the other way around.
  5. Review AI suppliers and contracts. Ask your suppliers: do you record decisions? Is there an auditable trail? Who is responsible? If the answer is vague, the problem will knock on your door, not theirs.

XMACNA's thesis: execution governance already solves half

Here is the game-changing point. Most of what this law will demand is not a new layer of bureaucracy — it is a natural consequence of operating AI that executes with a trail, instead of AI that only chats.

When the Digital Employee records every decision in the Intelligent Dashboard, you already have the "document automated decisions". When there is a default human escalation point embedded, you already have item 4. When there is a trail of what the Digital Employee decided and why, you already have the basis for the right to explanation. That is the difference between a chatbot, which gives answers and disappears, and a Digital Employee that executes and leaves history.

At XMACNA, auditable records and human escalation are not "premium modules": they come embedded with the Digital Employees by default, in the over 600 operating in production today. Not because a law mandated it — because serious operations need this. Operational memory matters for the same reason, as we detailed in the post about CRM with operational memory: without history, there is no proof nor learning.

Those who set up their operations this way will look at the AI legal framework and realize that half the work was already done.

FAQ

Is the AI legal framework for companies (PL 2338) already in effect?

No. PL 2338 was approved by the Senate in December 2024 and is still pending in the Chamber of Deputies, with voting postponed several times in 2026. It is not law and there is no obligation to comply today. But the text’s design already allows preparation.

What changes in PL 2338 for my company when it becomes law?

The law should classify AI uses by risk and require transparency, recording automated decisions, the right to explanation to the customer, and a human escalation point. The more sensitive the decision (serving, scheduling, charging, denying), the more caution and proof will be required.

What sanctions are provided in Brazil’s artificial intelligence law?

The text provides penalties that can reach fines in the tens of millions of reais per infraction, in addition to prohibited practices such as subliminal manipulation and mass surveillance. Details may still change during the legislative process.

How to start AI compliance for companies without turning it into a giant project?

Start with five habits: classify uses by risk, record decisions, ensure explanation to the client, maintain human escalation, and review suppliers. Operating AI that executes with an auditable trail already delivers much of this.

Do I need to wait for the law to be voted on to get organized?

No. The timeline is uncertain, but the direction is clear and the effort to document and audit AI takes time — Europe itself postponed deadlines because of this. Starting early avoids a last-minute scramble.

In summary

  • The AI legal framework for companies (PL 2338) is not yet law: approved in the Senate, under analysis in the Chamber, with voting postponed in 2026.
  • The text follows the European model: risk classification, rights to explanation and challenge, governance coordinated by ANPD, and relevant sanctions.
  • The European AI Act is the best mirror — and even it postponed high-risk deadlines, proof that documenting AI is hard work.
  • The SME path is "compliance by design": classify by risk, record decisions, ensure explanations, maintain human escalation, and review suppliers.
  • Execution governance already solves half: auditable recording in the Intelligent Dashboard, embedded human escalation, and a trail of what the Digital Employee decided.
  • XMACNA embeds recording and escalation by default in the more than 600 Digital Employees in operation — not a chatbot, a Digital Employee that executes and leaves proof.

Want to know if your AI operation is ready for what the law will demand? Take the free assessment from XMACNA and find your blind spots in recording and escalation. For a tailored compliance plan, talk to XMACNA’s AI consultancy.