The rapid advancement of artificial intelligence (AI) makes it difficult to create norms for its operation, while governments seek to establish limits for systems that are already operating in daily services and decisions. With the constant emergence of new capabilities, the debate transcends the mere decision to regulate AI; it is essential to define which risks must be controlled, who should be held responsible, what companies will need to do to comply with the rules, and how to keep legislation updated in the face of rapid technological mutation.
For Luca Belli, a professor at FGV Direito Rio, the need for regulation is intrinsically linked to the dangers these systems can generate. An AI can operate differently from what developers intended, present inadequate results, or be vulnerable to attacks. Thus, according to the professor, guidelines must serve to identify such risks and implement mitigation mechanisms.
The possibility of operational failure, malfunction, or exposure to cyberattacks drives the need for regulation, requiring the definition of measures to map existing risks and adopt all necessary actions to minimize or eliminate them.
Different Global Approaches to AI
The challenge intensifies after this realization, as different nations have opted for varied paths to manage the technology, reflecting not only concerns about rights and security but also strategic and economic interests.
The European Union was a pioneer in creating comprehensive AI legislation, adopting a risk-based model and prioritizing the safeguarding of fundamental rights. In practice, this means that applications with high potential impact on individuals are subjected to stricter requirements, establishing a correlation between the system's risk and the degree of control applied.
However, Belli points out a gap in the European experience: its regulatory strategy did not initially contemplate the urgency of developing its own alternatives to reduce dependence on external technologies. In this regard, the United States and China have advanced with strategies that combine regulation with technological development policies.
In the United States, AI is also viewed through the lens of national security and technological leadership, using industrial policies and restrictions on access to certain technologies to strengthen its position in the sector. China follows a similar line of stimulating development, but integrates this industrial policy with specific regulations for socially impactful applications, such as rules for deepfakes and algorithmic recommendations.
This strategic disparity demonstrates that regulating AI is not limited to imposing limits on corporations; the rules also shape investments, competitiveness, model development, and a country's ability to build its own technological chain.
For Brazil, this comparison is crucial, as the country needs to adapt international models to its distinct economic and technological reality.
The Brazilian Debate and the Risk Model
The debate in Brazil has moved beyond the initial phase of discussing the need to regulate AI. Bill 2.338/2023 was approved by the Senate in December 2024 and is currently under review by the Chamber of Deputies. This proposal adopts a risk-based methodology, seeking to differentiate AI applications according to their potential impact and establish proportional requirements, rather than applying uniform obligations.
Leandro Alvarenga, a privacy and security consultant and columnist for Olhar Digital, states that the focus of the Brazilian discussion has shifted from the existence of regulation to the practical model the country wishes to adopt, confirming that the senatorial text follows a risk-based regulatory logic.
However, this classification requires numerous deliberations: it is necessary to define what constitutes high risk, which systems will have the most severe obligations, and how these requirements will be applied to companies of different sizes and capacities.
At this point, there is great apprehension from the productive sector. While large corporations have the financial, technical, and human resources to comply with complex regulations, startups and small businesses may lack this structure. For Alvarenga, the challenge lies in finding the right balance: systems affecting fundamental rights require supervision, but excessive obligations can harm national innovation capacity.
He warns that overly exaggerated regulation can result in the export of innovation and the import of technology, while insufficient regulation can lead to the import of problems and the export of rights.
The risk of overly burdensome oversight is that the cost becomes an entry barrier, benefiting larger companies and penalizing smaller ones. This situation can have technological consequences, as if Brazilian companies have more difficulty developing AI while large foreign companies comply with the rules, the regulation could alter the market composition.
Therefore, Alvarenga advocates that Brazil should draw inspiration from international best practices, but without blindly replicating models created for different economic and institutional contexts.
Despite concerns about innovation, the reasons for creating rules persist, given that AI can already participate in decisions with concrete effects on people's lives. A system used in hiring or credit analysis can generate discriminatory or unfair results, even under data protection.
Alvarenga highlights this shift in the debate: the risks of AI are not limited to personal data processing; a system can also issue problematic decisions. Therefore, the regulatory focus should not only be on controlling the technology but also on the situations where it generates impacts, including human oversight in crucial decisions.
Generative AI has accentuated these problems, with tools that produce realistic texts, images, videos, and audio increasing concerns about fraud and deepfakes. However, Alvarenga argues that concentrating regulation on these cases may lead to rules focused only on exceptions, ignoring the countless positive uses of AI.
This reinforces the logic of risk-based regulation: different applications, with diverse impacts, do not need to be subject to the same level of requirement.
Challenges of Speed and Implementation
Even with identified risks, there is another hurdle: the speed of AI evolution. The legislative process is notoriously slow—from drafting to implementation—while technology can undergo drastic changes in just a few months, with new models and applications emerging.
Arthur Igreja, a specialist in technology and innovation, highlights this misalignment, observing that AI has become more powerful and acquired new capabilities at a pace that legislation does not follow.
This does not justify abandoning the regulatory debate; on the contrary, for Igreja, the speed of technology makes proactive rule creation even more vital. Belli agrees, stating that a law is, at most, a portrait of the state of the art and best practices at the time of its approval, which is problematic given the extreme agility of AI evolution.
Overly detailed legislation can quickly become obsolete, while very broad rules can generate legal uncertainty. Belli proposes an adaptable model, where the law establishes principles and obligations, but the execution mechanisms allow for adjustments as new circumstances arise.
The difficulty lies in balancing this flexibility without turning the legislation into something unpredictable for users and companies.
Additionally, there is the post-approval implementation phase. Since AI permeates various economic sectors, oversight may involve multiple public bodies. A single law may require coordination among authorities from diverse topics, making the implementation structure as critical as the text approved by Congress.
Belli warns that formulating good rules is useless if they are not effectively applied. He questions the expectation of automatic coordination between bodies given complex legislation, arguing that the cooperation structure must be planned from the beginning to define responsibilities and prevent conflicts of competence.
This point is vital, as AI systems can operate in finance, health, education, commerce, and security. Regulation, thus, does not end with the sanctioning of the law; it is necessary to define how it will be interpreted, who will conduct the oversight, and how the system will be updated with new applications.
The regulatory discussion also touches upon Brazil's future role in the AI industry, while the US and China consolidate infrastructure and models, and other countries seek technological autonomy.
}} , 2.