Does Brazil AI Bill (PL 2338/2023) require Risk Assessment?
Brazil • proposed
Yes — 1 provision
Requirements at a glance
This regulation imposes 5 specific requirements for Risk Assessment across 1 provision:
- Risk classification — AI systems classified by risk level: excessive (Art. 13), high (Art. 14), and general
- Preliminary assessment — Self-classification before market introduction is optional — Art. 12 makes it a good-practice measure ("poderá realizar") that earns favourable treatment, not a precondition; a sector authority may simplify or waive it, and the competent authority may order reclassification or require an algorithmic impact assessment (Art. 12 § 4)
- Prohibited practices — Art. 13 bans systems that induce harmful behaviour, exploit vulnerabilities, profile people to predict criminality or recidivism, or facilitate child sexual abuse material; plus public-authority social scoring, autonomous weapons systems, and real-time remote biometric identification in public spaces (with judicially authorised exceptions)
- High-risk categories — Art. 14 lists twelve: critical-infrastructure safety devices; student admission selection and evaluations determining academic progress or monitoring; recruitment and employment decisions; access to essential public and private services; triage of emergency service calls; administration of justice; autonomous vehicles in public spaces; health diagnostics and procedures; analytical study of crimes; investigative credibility assessment and profiling; biometric emotion recognition; immigration and border control
- Algorithmic impact assessment — Mandatory for high-risk systems (Art. 25), performed before placing the system on the market (Art. 26); conclusions are public, subject to trade-secret protection (Art. 28)
Risk-Based AI Classification #
Requirements
| Requirement | Details |
|---|---|
| Risk classification | AI systems classified by risk level: excessive (Art. 13), high (Art. 14), and general |
| Preliminary assessment | Self-classification before market introduction is optional — Art. 12 makes it a good-practice measure ("poderá realizar") that earns favourable treatment, not a precondition; a sector authority may simplify or waive it, and the competent authority may order reclassification or require an algorithmic impact assessment (Art. 12 § 4) |
| Prohibited practices | Art. 13 bans systems that induce harmful behaviour, exploit vulnerabilities, profile people to predict criminality or recidivism, or facilitate child sexual abuse material; plus public-authority social scoring, autonomous weapons systems, and real-time remote biometric identification in public spaces (with judicially authorised exceptions) |
| High-risk categories | Art. 14 lists twelve: critical-infrastructure safety devices; student admission selection and evaluations determining academic progress or monitoring; recruitment and employment decisions; access to essential public and private services; triage of emergency service calls; administration of justice; autonomous vehicles in public spaces; health diagnostics and procedures; analytical study of crimes; investigative credibility assessment and profiling; biometric emotion recognition; immigration and border control |
| Algorithmic impact assessment | Mandatory for high-risk systems (Art. 25), performed before placing the system on the market (Art. 26); conclusions are public, subject to trade-secret protection (Art. 28) |
Penalties
| Violation | Fine |
|---|---|
| Non-compliance | Up to BRL 50 million or 2% of revenue |
| Severe violations | Warnings, suspension, or bans on AI system operation |