By TechReg Team.
The Brazilian National Data Protection Authority (ANPD) has published the 1st Monitoring Report of the Testing Phase – Cycle 1 of its Regulatory Sandbox for Artificial Intelligence. The document presents the initial results of the monitoring of participating projects and offers a practical overview of the main challenges faced in implementing AI systems in compliance with the Brazilian General Data Protection Law (LGPD).
More than a monitoring report, the document signals how ANPD intends to build its regulatory approach: based on evidence, dialogue with developers, and the gradual maturation of good AI governance practices. The material is likely to serve as a reference for future regulatory guidance and for companies that develop or use artificial intelligence-based solutions.
Key highlights
• Project evolution: participants made progress in implementing their solutions and improving governance measures during the testing phase.
• AI governance and data protection: ANPD highlights the importance of adopting internal governance structures, defining responsibilities, documenting decision-making processes, and integrating data protection from the design stage of systems (privacy by design).
• Risk management: the monitoring identified progress in carrying out impact assessments and implementing mechanisms aimed at identifying, mitigating, and continuously monitoring risks related to the processing of personal data.
• Transparency and accountability: one of the main challenges for participants remains the development of mechanisms that make it possible to explain how AI systems work, record automated decisions, and demonstrate compliance before the regulatory authority.
• Regulatory learning: in addition to monitoring participating companies, the initiative allows ANPD itself to better understand the technical and legal challenges involved in developing AI applications, contributing to the development of future rules and guidance.
TechReg Analysis
The report reinforces an internationally observed trend: regulators are using regulatory sandboxes as a tool to develop rules collaboratively, reducing information asymmetries between authorities and developers.
For companies that develop or use artificial intelligence, especially in regulated sectors, the message is clear: governance, documentation, risk management, and transparency are becoming central elements of regulatory compliance, regardless of the approval of a specific legal framework for AI in Brazil.
The experience led by ANPD may also influence the future implementation of Brazil’s AI regulatory framework, providing concrete input for defining obligations proportional to the risk level of AI applications.
Read the full report at the link.