AI Act vs PL 2338: what they share and how they differ

AI Act and PL 2338 share 18 of 24 control themes and 37 checks. 80% of PL 2338 requirements can be proven with checks AI Act already uses, 70% the other way round.

EURegulationPhasing in

AI Act

How to make an AI system compliant with the EU AI Act

33 requirementsNext Aug 2, 2027
BRBillUnder discussion

PL 2338

Preparing for the Brazil AI Bill (PL 2338/2023)

20 requirementsNext Oct 2026
18/24shared control themes
37shared checks
80%of PL 2338 requirements covered by AI Act evidence
70%of AI Act requirements covered by PL 2338 evidence

At a glance

AI Act PL 2338
JurisdictionEuropean UnionBrazil
KindRegulationBill
StatusPhasing inUnder discussion
BindingYesNo
Object analysedAI system sameAI system same
ScopeProviders, deployers, importers and distributors of AI systems; providers of GPAI models.Developers, distributors and appliers of AI systems.
Territorial reachExtraterritorial: applies when the system is placed on the EU market or its output is used in the EU.Systems provided or used in Brazil.
PenaltiesUp to €35M or 7% of worldwide turnover (prohibited practices); €15M or 3% (other obligations); €7.5M or 1% (incorrect information).Senate text: up to BRL 50M or 2% of turnover per infringement; suspension.
Qualification axesAI Act risk level, Organisation role, General-purpose modelPL 2338 risk level, Role (Art. 4)
RolesProvider, Deployer, GPAI providerDeveloper, Distributor, Applier
Requirements3320
Next milestoneAug 2, 2027, Annex I high risk (regulated products); GPAI placed on the market before Aug 2025Oct 2026, Vote pushed past the October 2026 elections

Theme by theme

requirements per theme

What they share: one piece of evidence, two frameworks

37

CodeCheckRequirements AI ActRequirements PL 2338
VER-002-01Documented process for detecting drift towards prohibited practices
VER-002-02System free of prohibited practices (provider assessment)
VER-002-03System use free of prohibited practices (deployer assessment)
VER-003-02Residual risks communicated to deployers
VER-004-01Documented data governance (collection process, bias, quality)
VER-004-02Input data relevant and representative in view of the intended purpose
VER-005-01Complete technical documentation compliant with Annex IV
VER-005-02Instructions for use obtained and read by the deployer
VER-005-03Use consistent with the intended purpose documented
VER-006-01Documented log retention policy
VER-006-02Automatic logging operational and compliant
VER-006-03Logs accessible and usable by the deployer
VER-007-01Instructions for use complete and compliant with Art. 13
VER-008-01Documented escalation and emergency stop procedure
VER-008-02System designed to allow human oversight (stop button, override)
VER-008-03Competent overseers assigned to the system
VER-AUTO-05Accuracy monitoring in operation
VER-009-01Cybersecurity of the hosting environment
VER-009-02Accuracy and robustness verified and documented
VER-009-03Cybersecurity of the AI system verified
VER-013-F-04Communication to market surveillance authorities in the event of risk
VER-018-D-01Persons informed of the interaction with an AI system
VER-018-D-03AI-generated content marked as such
VER-020-D-01FRIA carried out in accordance with Art. 27
VER-021-D-03Operation monitoring
VER-022-F-01Risk and incident response procedure
VER-022-D-01Serious incident reporting procedure
VER-026-F-01Contractual responsibilities documented between provider and third parties
VER-029-D-01Affected persons informed of the use of the AI system
VER-031-G-01GPAI model technical documentation compliant with Annex XI
VER-031-G-02Documentation for downstream providers compliant with Annex XII
VER-031-G-03Documented copyright compliance policy
VER-031-G-04Published summary of training content
VER-032-G-02Systemic risks assessed and mitigation measures documented
VER-033-D-01Decision explanation procedure documented
VER-033-D-02System explanation capability verified
VER-033-D-03Explanations provided on request within a reasonable timeframe

Differences: requirements specific to each framework

Requirements with no check serving the other framework: the extra work.

AI Act

10

EX-001
EX-010
QMS Art. 17
EX-011
EX-016
CE marking Art. 48
EX-023
Accessibility Art. 16(l)
EX-024

PL 2338

4

BR-01
BR-07
Contestation and human review Arts. 6 II, 6 III, 9
BR-19

Timelines

PastSet in the textPotentialTo verify
Apr 21, 2021AI Act · Commission proposal
May 3, 2023PL 2338 · Filed in the Senate
Jul 12, 2024AI Act · Published in the Official Journal
Aug 1, 2024AI Act · Entry into force
Dec 10, 2024PL 2338 · Senate approval
Feb 2, 2025AI Act · Prohibited practices (Art. 5) and AI literacy (Art. 4)
May 2025PL 2338 · Special committee in the Chamber of Deputies
Jul 10, 2025AI Act · GPAI Code of Practice published
Aug 2, 2025AI Act · GPAI obligations, governance, penalties, notified bodies
Nov 19, 2025AI Act · Digital Omnibus proposal: high-risk delay tied to standards
Aug 2, 2026AI Act · General application: Art. 50, sandboxes, Annex III high risk (unless Omnibus delay)
Oct 2026PL 2338 · Vote pushed past the October 2026 elections
Jun 2027PL 2338 · Possible adoption and start of the vacatio legis
Aug 2, 2027AI Act · Annex I high risk (regulated products); GPAI placed on the market before Aug 2025
Dec 2, 2027AI Act · Omnibus backstop for Annex III high risk
Aug 2, 2028AI Act · Omnibus backstop for Annex I high risk
Aug 2, 2030AI Act · High-risk systems of public authorities already in service (Art. 111)

Run these requirements across all your AI systems

TrustFlow inventories your systems, qualifies them under each regulation and collects evidence once for every referential.

Request a demo