Audience: Brazilian AI deployers subject to LGPD and the forthcoming AI law, LATAM technology companies expanding into regulated markets, multinational firms operating in Brazil, compliance teams managing dual EU-Brazil obligations, and legal counsel advising on ANPD enforcement.
Advancing legislation. EU digital partnership signed. Brazil's AI bill is the most developed AI regulatory framework in Latin America. Inspired by the EU AI Act, it adopts risk-based tiers with specific obligations for high-risk applications including facial recognition and automated hiring. On June 19, 2026, Brazil became the first global south country to sign a digital partnership agreement with the European Union, committing to aligned approaches on ethical AI, data governance, and technical cooperation. Organizations deploying AI in Brazil should prepare for ANPD enforcement now.
Contents
1. Regulatory Landscape 2. Key Legal Instruments 3. Obligation-to-Procedure Mapping 4. SWT3 Procedure Cards 5. LGPD Intersection 6. Quick Reference 7. Quick Start 8. References1. Regulatory Landscape
Brazil's approach to AI regulation draws heavily from the EU AI Act while adapting to Brazilian constitutional principles and the existing LGPD data protection framework. The bill establishes a risk-based classification system where obligations scale with the potential impact of the AI system on fundamental rights.
The Autoridade Nacional de Protecao de Dados (ANPD) is positioned as the primary enforcement authority, building on its existing role as Brazil's data protection regulator. This dual mandate -- data protection and AI governance -- creates natural synergies between LGPD compliance and AI regulatory obligations.
Brazil's June 2026 digital partnership with the EU is significant. It commits both parties to annual meetings on ethical AI, making Brazilian AI governance increasingly aligned with European standards. Organizations that build EU AI Act compliance evidence will find substantial overlap with Brazilian requirements.
2. Key Legal Instruments
| Instrument | Scope | Status |
|---|---|---|
| AI Bill (PL 2338/2023) | Comprehensive risk-based AI regulation. Tiered obligations for high-risk systems. Civil liability for AI harms. | Advanced in Congress |
| LGPD (Lei 13.709/2018) | Data protection. Automated decision-making rights. Data subject access. Purpose limitation. | In force |
| EU-Brazil Digital Partnership | Annual cooperation on ethical AI, tech cooperation, aligned governance approaches. | Signed June 19, 2026 |
| ANPD AI Guidance | Sector-specific guidance on AI and personal data processing. | Ongoing |
3. Obligation-to-Procedure Mapping
| Brazil Obligation | Evidence Needed | SWT3 Procedure |
|---|---|---|
| Risk classification and impact assessment | Risk tier documentation, impact evaluation records | AI-IMPACT.1, AI-RISK.1 |
| Transparency for automated decisions | Disclosure records, decision explanation logs | AI-TRANS.1, AI-EXPL.1 |
| Human oversight for high-risk systems | Reviewer identity, review duration, override records | AI-HITL.1 |
| Non-discrimination and fairness evaluation | Bias evaluation methodology, demographic coverage, results | AI-FAIR.1 |
| Facial recognition safeguards | Consent records, purpose limitation, accuracy validation | AI-CONSENT.1, AI-FAIR.1 |
| Automated hiring system obligations | Fairness evaluation, explainability, human review | AI-FAIR.1, AI-EXPL.1, AI-HITL.1 |
| Record-keeping and audit trail | Inference provenance, model identity, operation logs | AI-INF.1, AI-LOG.1, AI-AUDIT.1 |
| Data governance and LGPD alignment | Data provenance, consent basis, purpose classification | AI-DATA.1, AI-CONSENT.1 |
| Civil liability evidence preservation | Tamper-evident execution records, decision chain | AI-INF.1, AI-AUDIT.1 |
4. SWT3 Procedure Cards
Fairness Evaluation
Brazil context: The AI bill classifies automated hiring and credit scoring as high-risk. These systems must demonstrate they do not discriminate on the basis of race, gender, age, disability, or socioeconomic status. Brazilian constitutional protections against discrimination are among the strongest in Latin America.
SWT3 evidence: Each AI-FAIR.1 anchor records the evaluation methodology, demographic groups tested, statistical metrics used, and whether disparate impact was detected. Anchors provide timestamped, tamper-evident proof that fairness evaluation occurred before deployment and at regular intervals.
Verify that fairness evaluations cover Brazilian-specific protected characteristics, particularly race (five-category IBGE classification) and socioeconomic indicators. Generic US/EU demographic categories may be insufficient for ANPD scrutiny.
Human Oversight
Brazil context: High-risk AI systems, particularly those making decisions with legal consequences (credit, employment, insurance), require meaningful human oversight. LGPD Article 20 already guarantees the right to request human review of automated decisions.
SWT3 evidence: Each AI-HITL.1 anchor records reviewer identity, review duration, whether the human upheld or overrode the AI recommendation, and the rationale. This creates an auditable chain proving human involvement was substantive, not perfunctory.
Check review duration against decision complexity. A 2-second review of a credit denial suggests rubber-stamping, not meaningful oversight. ANPD has signaled interest in substantive review metrics.
Transparency Disclosure
Brazil context: Users must be informed when they are interacting with an AI system and must be able to understand how decisions affecting them were made. The AI bill requires clear, accessible disclosure in Portuguese.
SWT3 evidence: AI-TRANS.1 anchors record that transparency disclosures were served, the disclosure method used, and the content provided. Combined with AI-EXPL.1 (explainability), organizations can demonstrate both notification and comprehension support.
Verify disclosure language is Brazilian Portuguese, not European Portuguese or machine-translated. ANPD expects disclosures accessible to the general population, not just technical staff.
Impact Assessment
Brazil context: High-risk AI systems require documented impact assessments before deployment. The assessment must evaluate potential harms to fundamental rights, discrimination risks, and societal effects. LGPD's DPIA (Data Protection Impact Assessment) requirements extend to AI processing of personal data.
SWT3 evidence: AI-IMPACT.1 anchors record that impact assessments were conducted, the scope of the assessment, identified risks, and mitigation measures implemented. Anchors are timestamped to prove assessment preceded deployment.
Cross-reference AI-IMPACT.1 timestamps with model deployment dates. Impact assessments conducted after deployment suggest retroactive compliance rather than genuine risk management.
Consent Verification
Brazil context: LGPD requires a valid legal basis for processing personal data. For facial recognition and biometric AI systems, explicit consent is typically required. The AI bill adds specific consent requirements for high-risk systems that process sensitive personal data.
SWT3 evidence: AI-CONSENT.1 anchors record consent collection events, the legal basis claimed, purpose classification, and whether consent was freely given. For facial recognition, anchors prove consent preceded biometric processing.
Under LGPD, consent for sensitive data processing (including biometrics) must be specific and highlighted. Generic bundled consent is insufficient. Verify AI-CONSENT.1 anchors reference the specific processing purpose.
5. LGPD Intersection
Brazil's AI bill does not replace LGPD -- it builds on top of it. Organizations deploying AI systems that process personal data must satisfy both frameworks simultaneously. SWT3 procedures address this overlap naturally because witness anchors capture both AI governance evidence (fairness, transparency, human oversight) and data protection evidence (consent, purpose limitation, data provenance) in the same pipeline.
| LGPD Requirement | AI Bill Extension | SWT3 Evidence |
|---|---|---|
| Art. 20: Right to review of automated decisions | Human oversight requirement for high-risk AI | AI-HITL.1 anchors proving human review occurred |
| Art. 18: Data subject access rights | Transparency and explainability obligations | AI-TRANS.1, AI-EXPL.1 anchors |
| Art. 38: Data Protection Impact Assessment | AI-specific impact assessment for high-risk | AI-IMPACT.1 anchors |
| Art. 11: Sensitive data (biometrics) | Facial recognition safeguards | AI-CONSENT.1, AI-FAIR.1 anchors |
The EU-Brazil Digital Partnership (June 2026) adds a third layer. Organizations already compliant with the EU AI Act will find that most SWT3 evidence produced for EU obligations also satisfies Brazilian requirements. The crosswalk between EU AI Act and Brazilian AI bill shares approximately 70% of procedure mappings, reflecting the bill's EU AI Act origins.
6. Quick Reference
| Regulator Question | Where to Look |
|---|---|
| Is this AI system classified as high-risk? | Check AI-IMPACT.1 and AI-RISK.1 anchors for risk classification records. High-risk sectors: hiring, credit, insurance, facial recognition, public safety. |
| Has the system been evaluated for discrimination? | AI-FAIR.1 anchors with methodology, IBGE racial categories, gender, and socioeconomic indicators. Verify evaluation precedes deployment. |
| Can the organization explain how this decision was made? | AI-EXPL.1 anchors with explainability method and key factors. Verify explanation is in Brazilian Portuguese. |
| Was the data subject informed they were interacting with AI? | AI-TRANS.1 anchors recording disclosure served, method, and timestamp. |
| Is there a human in the loop for high-risk decisions? | AI-HITL.1 anchors with reviewer ID, duration, and outcome. Check for substantive review time. |
| What is the legal basis for biometric data processing? | AI-CONSENT.1 anchors with explicit consent record. Verify consent is specific to biometric purpose, not bundled. |
7. Quick Start
# Install the SDK
pip install swt3-ai
from swt3_ai import WitnessClient
client = WitnessClient(
tenant_id="your-tenant-id",
api_key="axm_live_..."
)
# Record fairness evaluation for automated hiring (high-risk)
client.witness_fairness_evaluation(
model_id="hiring-screener-v3",
evaluation_method="disparate_impact_analysis",
demographic_groups=["race_ibge", "gender", "age", "disability"],
pass_threshold=0.8,
result="pass"
)
# Record human oversight for credit decisions (LGPD Art. 20)
client.witness_human_review(
model_id="credit-scoring-v2",
decision_type="credit_application",
reviewer_id="analyst-12",
review_duration_seconds=240,
outcome="approved_with_conditions"
)
# Run the demo to see it in action
python -m swt3_ai.demo
SDK Documentation | Create a free account
8. References
- Brazil AI Bill (PL 2338/2023) -- Brazilian Congress
- Lei Geral de Protecao de Dados (LGPD, Lei 13.709/2018)
- EU-Brazil Digital Partnership Agreement (June 19, 2026)
- ANPD (Autoridade Nacional de Protecao de Dados) -- anpd.gov.br
- EU AI Act Cheatsheet (SWT3 Protocol)
- Africa-EU AI Act Crosswalk (SWT3 Protocol)
- SWT3 SDK Documentation
- Create a free account