Brazilian Government Plans to Create Its Own Cloud Storage with Control Over Code and Data
Read more
Olhar Digital
olhardigital.com.br

Brazilian Government Plans to Create Its Own Cloud Storage with Control Over Code and Data

The Brazilian government favors a partnership model between Serpro and private companies, whose capital is predominantly Brazilian, for the development of the so-called 'Brazilian cloud.' The specific model is still being defined and could potentially involve several companies.

The main goal is to ensure Brazil has a higher level of control over the code, operation, and jurisdiction of the infrastructure used for strategic data. Although foreign companies are not yet excluded from the process, their participation has not been determined.

The most likely path, according to Esther Zweck, Minister of Management and Innovation in Public Services, is the formation of a public-private partnership. Initially, Serpro will be the only state company involved in the project. Meanwhile, Dataprev has reported its inability to participate in the development.

Zweck told the publication Tele.Síntese that 'the idea, in principle, is a public-private partnership that can include more than one private company.'

The cooperation format may change after market consultations. Public hearings in Brasília gathered 59 interested companies, including both Brazilian and international ones. The government prefers companies with predominantly Brazilian capital. However, Zweck acknowledged that there are currently few companies in the country with sufficient in-house competence in cloud services, mentioning Magalu Cloud.

The technology to be used does not necessarily have to be created in Brazil. The national company can use technology originally developed abroad, provided it maintains control over the code and can operate the platform without dependence on a foreign supplier. Zweck emphasized: 'the technology can be developed outside the country, but part of it, provided the code is completely open.'

There is also the issue of jurisdiction. The government seeks to avoid decisions that support legal dependence on another country, especially in the case of critical or strategic data. The minister noted: 'Our biggest concern is that the jurisdiction is Brazilian.'

As an example, she cited the US Cloud Act, which allows US cloud companies to provide user data upon request, even if that data is stored on servers in Brazil.

According to Zweck, one of the obstacles for Brazilian companies is the cost of creating the cloud platform. Without pre-established demand, investments become more difficult. She explained that 'we understood that the only way companies can enter is when the government finances, and most importantly, after that the service acquisition process takes place.'

The initial idea is for the government to acquire ready-made technology, thereby creating initial demand. The platform can also be offered to private companies. Zweck clarified: 'the idea is that this cloud solution is not just for the government. Obviously, we want it to be available to companies as well.'

The market consultation attracted 270 participants from 70 institutions, including 59 private companies. After the feedback collection stage, the government began holding individual meetings with interested companies.

The planned schedule includes ABDI's participation in dialogue with the private sector, and BNDES may contribute through financing or another support instrument. The demarcation between public and private markets is yet to be determined. The central point that has already been established is the expansion of Brazilian control over the code, operation, and jurisdiction of infrastructure intended for strategic data.

Similar stories

Artificial Intelligence Regulation May Determine Whether Brazil Becomes a Technology Producer or Consumer
Read more
olhardigital.com.br

Artificial Intelligence Regulation May Determine Whether Brazil Becomes a Technology Producer or Consumer

The rapid advancement of artificial intelligence (AI) makes it difficult to create norms for its operation, while governments seek to establish limits for systems that are already operating in daily services and decisions. With the constant emergence of new capabilities, the debate transcends the mere decision to regulate AI; it is essential to define which risks must be controlled, who should be held responsible, what companies will need to do to comply with the rules, and how to keep legislation updated in the face of rapid technological mutation.

For Luca Belli, a professor at FGV Direito Rio, the need for regulation is intrinsically linked to the dangers these systems can generate. An AI can operate differently from what developers intended, present inadequate results, or be vulnerable to attacks. Thus, according to the professor, guidelines must serve to identify such risks and implement mitigation mechanisms.

The possibility of operational failure, malfunction, or exposure to cyberattacks drives the need for regulation, requiring the definition of measures to map existing risks and adopt all necessary actions to minimize or eliminate them.

Different Global Approaches to AI

The challenge intensifies after this realization, as different nations have opted for varied paths to manage the technology, reflecting not only concerns about rights and security but also strategic and economic interests.

The European Union was a pioneer in creating comprehensive AI legislation, adopting a risk-based model and prioritizing the safeguarding of fundamental rights. In practice, this means that applications with high potential impact on individuals are subjected to stricter requirements, establishing a correlation between the system's risk and the degree of control applied.

However, Belli points out a gap in the European experience: its regulatory strategy did not initially contemplate the urgency of developing its own alternatives to reduce dependence on external technologies. In this regard, the United States and China have advanced with strategies that combine regulation with technological development policies.

In the United States, AI is also viewed through the lens of national security and technological leadership, using industrial policies and restrictions on access to certain technologies to strengthen its position in the sector. China follows a similar line of stimulating development, but integrates this industrial policy with specific regulations for socially impactful applications, such as rules for deepfakes and algorithmic recommendations.

This strategic disparity demonstrates that regulating AI is not limited to imposing limits on corporations; the rules also shape investments, competitiveness, model development, and a country's ability to build its own technological chain.

For Brazil, this comparison is crucial, as the country needs to adapt international models to its distinct economic and technological reality.

The Brazilian Debate and the Risk Model

The debate in Brazil has moved beyond the initial phase of discussing the need to regulate AI. Bill 2.338/2023 was approved by the Senate in December 2024 and is currently under review by the Chamber of Deputies. This proposal adopts a risk-based methodology, seeking to differentiate AI applications according to their potential impact and establish proportional requirements, rather than applying uniform obligations.

Leandro Alvarenga, a privacy and security consultant and columnist for Olhar Digital, states that the focus of the Brazilian discussion has shifted from the existence of regulation to the practical model the country wishes to adopt, confirming that the senatorial text follows a risk-based regulatory logic.

However, this classification requires numerous deliberations: it is necessary to define what constitutes high risk, which systems will have the most severe obligations, and how these requirements will be applied to companies of different sizes and capacities.

At this point, there is great apprehension from the productive sector. While large corporations have the financial, technical, and human resources to comply with complex regulations, startups and small businesses may lack this structure. For Alvarenga, the challenge lies in finding the right balance: systems affecting fundamental rights require supervision, but excessive obligations can harm national innovation capacity.

He warns that overly exaggerated regulation can result in the export of innovation and the import of technology, while insufficient regulation can lead to the import of problems and the export of rights.

The risk of overly burdensome oversight is that the cost becomes an entry barrier, benefiting larger companies and penalizing smaller ones. This situation can have technological consequences, as if Brazilian companies have more difficulty developing AI while large foreign companies comply with the rules, the regulation could alter the market composition.

Therefore, Alvarenga advocates that Brazil should draw inspiration from international best practices, but without blindly replicating models created for different economic and institutional contexts.

Despite concerns about innovation, the reasons for creating rules persist, given that AI can already participate in decisions with concrete effects on people's lives. A system used in hiring or credit analysis can generate discriminatory or unfair results, even under data protection.

Alvarenga highlights this shift in the debate: the risks of AI are not limited to personal data processing; a system can also issue problematic decisions. Therefore, the regulatory focus should not only be on controlling the technology but also on the situations where it generates impacts, including human oversight in crucial decisions.

Generative AI has accentuated these problems, with tools that produce realistic texts, images, videos, and audio increasing concerns about fraud and deepfakes. However, Alvarenga argues that concentrating regulation on these cases may lead to rules focused only on exceptions, ignoring the countless positive uses of AI.

This reinforces the logic of risk-based regulation: different applications, with diverse impacts, do not need to be subject to the same level of requirement.

Challenges of Speed and Implementation

Even with identified risks, there is another hurdle: the speed of AI evolution. The legislative process is notoriously slow—from drafting to implementation—while technology can undergo drastic changes in just a few months, with new models and applications emerging.

Arthur Igreja, a specialist in technology and innovation, highlights this misalignment, observing that AI has become more powerful and acquired new capabilities at a pace that legislation does not follow.

This does not justify abandoning the regulatory debate; on the contrary, for Igreja, the speed of technology makes proactive rule creation even more vital. Belli agrees, stating that a law is, at most, a portrait of the state of the art and best practices at the time of its approval, which is problematic given the extreme agility of AI evolution.

Overly detailed legislation can quickly become obsolete, while very broad rules can generate legal uncertainty. Belli proposes an adaptable model, where the law establishes principles and obligations, but the execution mechanisms allow for adjustments as new circumstances arise.

The difficulty lies in balancing this flexibility without turning the legislation into something unpredictable for users and companies.

Additionally, there is the post-approval implementation phase. Since AI permeates various economic sectors, oversight may involve multiple public bodies. A single law may require coordination among authorities from diverse topics, making the implementation structure as critical as the text approved by Congress.

Belli warns that formulating good rules is useless if they are not effectively applied. He questions the expectation of automatic coordination between bodies given complex legislation, arguing that the cooperation structure must be planned from the beginning to define responsibilities and prevent conflicts of competence.

This point is vital, as AI systems can operate in finance, health, education, commerce, and security. Regulation, thus, does not end with the sanctioning of the law; it is necessary to define how it will be interpreted, who will conduct the oversight, and how the system will be updated with new applications.

The regulatory discussion also touches upon Brazil's future role in the AI industry, while the US and China consolidate infrastructure and models, and other countries seek technological autonomy.

}} , 2.
Brazil Approves Special Tax Regime Redata to Attract Data Centers
Read more
olhardigital.com.br

Brazil Approves Special Tax Regime Redata to Attract Data Centers

When internet users, banking application users, or artificial intelligence system users access services, the main computational load does not occur on their devices but in data centers—facilities filled with powerful servers and computers.

According to the Ministry of Finance, about 60% of data and AI services used in Brazil are processed outside the country. To attract this infrastructure to the nation's territory, the Senate approved Bill No. 278/2026 on Monday (the 1st), which establishes Redata (Special Tax Regime for Data Center Services).

Since the bill was passed by the Senate without changes to its core content, it does not require re-examination in the Chamber of Deputies, where it was approved in February. Consequently, the PL is sent directly to the President of the Republic, Luiz Inácio Lula da Silva (PT), who has up to 15 working days to decide—either approve or veto (fully or partially).

Building and operating data centers in Brazil is expensive, mainly due to the tax burden placed on technological equipment. Furthermore, processing data abroad leads to connection slowdowns, reduced competitiveness of domestic companies, and threats to national sovereignty.

Senator Cid Gomes (PSB-CE), the bill's rapporteur, noted that 'this external dependence entails serious risks to national sovereignty, delays in critical communications, and loss of competitiveness for Brazilian technology companies.' He added that 'without local high-performance data centers, Brazil risks becoming merely a digital colony of foreign platforms.'

The Redata mechanism essentially represents a proposal by the Brazilian government to offer a 'tax discount' to encourage technology companies to locate their data centers in the country. Redata is a package of fiscal incentives that suspends federal taxes when purchasing equipment intended for three purposes: 1) data storage and processing; 2) artificial intelligence; and 3) cloud computing.

According to government estimates, a tax exemption of about 5.2 billion reais will be provided in 2026, which will decrease to 1 billion over the next two years.

An important condition is that the import duty discount applies only to goods that do not have an equivalent product manufactured in Brazil. If a similar product already exists nationally, the company must pay the standard import tax. Additionally, if an electronic component is manufactured in Manaus (AM), VAT is still charged to prevent the underpricing of imported components compared to products from the Free Trade Zone.

During the vote, senators can propose changes to the original text, known as amendments. In the case of the Redata PL, 39 amendments were presented. The rapporteur rejected most of them to maintain the essence of the law, which would require it to return to the Chamber of Deputies for further review.

Four accepted amendments brought joy among senators. Senator Astronaut Marcos Pontes (PL-SP) stated: 'Brazil will benefit greatly from this, not only immediately, thanks to new business opportunities for the country.' Senator Teresa Leitão (PT-PE) praised the provision in the text that directs funds from potential legal fines to the National Fund for Children and Adolescents. She emphasized: 'Brazil must become a powerhouse of the digital economy, combining technological sovereignty, development, sustainability, and public safety.'

The senator also noted the presence of Minister of Human Rights and Citizenship Janine Melo at the plenary session to observe the vote on the Redata PL.

Luiz Tossi, Vice-President of the Brazilian Data Center Association (ABDC), believes that the approval of Redata in the Senate marks a new stage. According to him, 'with the adoption of the new law, Brazil raises its status and begins to participate in global investments intended for artificial intelligence infrastructure, with the potential to attract over 1 trillion in the coming years.'

The Brazilian Association of Information and Communication Technologies and Digital Technologies (Brasscom) characterized the approval of Redata in the Senate as 'a decisive step to ensure Brazil's leading role in the 21st-century global economy.' The association stated that this 'strengthens the conviction that Brazil possesses the necessary conditions to become a global benchmark in digital infrastructure, stimulating innovation, job creation, technological development, and economic growth.'

However, market enthusiasm and parliamentary support are not shared by all segments of society. One day before the approval of Redata in the Senate, the coalition Direitos na Rede, which unites researchers, organizations, and social movements, published a manifesto against the initiative. The central argument of these organizations is that the government 'changed the rules': it granted billions in tax benefits to large technology companies before establishing clear rules regarding how and where these structures can be built in Brazil.

Popular