AI Act vs PL 2338: what they share and how they differ
AI Act and PL 2338 share 18 of 24 control themes and 37 checks. 80% of PL 2338 requirements can be proven with checks AI Act already uses, 70% the other way round.
Phasing in
AI Act
How to make an AI system compliant with the EU AI Act
33 requirementsNext Aug 2, 2027
Under discussion
PL 2338
Preparing for the Brazil AI Bill (PL 2338/2023)
20 requirementsNext Oct 2026
18/24shared control themes
37shared checks
80%of PL 2338 requirements covered by AI Act evidence
70%of AI Act requirements covered by PL 2338 evidence
At a glance
| AI Act | PL 2338 | |
|---|---|---|
| Jurisdiction | European Union | Brazil |
| Kind | Regulation | Bill |
| Status | Phasing in | Under discussion |
| Binding | Yes | No |
| Object analysed | AI system same | AI system same |
| Scope | Providers, deployers, importers and distributors of AI systems; providers of GPAI models. | Developers, distributors and appliers of AI systems. |
| Territorial reach | Extraterritorial: applies when the system is placed on the EU market or its output is used in the EU. | Systems provided or used in Brazil. |
| Penalties | Up to €35M or 7% of worldwide turnover (prohibited practices); €15M or 3% (other obligations); €7.5M or 1% (incorrect information). | Senate text: up to BRL 50M or 2% of turnover per infringement; suspension. |
| Qualification axes | AI Act risk level, Organisation role, General-purpose model | PL 2338 risk level, Role (Art. 4) |
| Roles | Provider, Deployer, GPAI provider | Developer, Distributor, Applier |
| Requirements | 33 | 20 |
| Next milestone | Aug 2, 2027, Annex I high risk (regulated products); GPAI placed on the market before Aug 2025 | Oct 2026, Vote pushed past the October 2026 elections |
Theme by theme
requirements per theme
AI ActPL 2338
Governance
Assessment
Build
People & use
Lifecycle & third parties
What they share: one piece of evidence, two frameworks
37
| Code | Check | Requirements AI Act | Requirements PL 2338 |
|---|---|---|---|
| VER-002-01 | Documented process for detecting drift towards prohibited practices | ||
| VER-002-02 | System free of prohibited practices (provider assessment) | ||
| VER-002-03 | System use free of prohibited practices (deployer assessment) | ||
| VER-003-02 | Residual risks communicated to deployers | ||
| VER-004-01 | Documented data governance (collection process, bias, quality) | ||
| VER-004-02 | Input data relevant and representative in view of the intended purpose | ||
| VER-005-01 | Complete technical documentation compliant with Annex IV | ||
| VER-005-02 | Instructions for use obtained and read by the deployer | ||
| VER-005-03 | Use consistent with the intended purpose documented | ||
| VER-006-01 | Documented log retention policy | ||
| VER-006-02 | Automatic logging operational and compliant | ||
| VER-006-03 | Logs accessible and usable by the deployer | ||
| VER-007-01 | Instructions for use complete and compliant with Art. 13 | ||
| VER-008-01 | Documented escalation and emergency stop procedure | ||
| VER-008-02 | System designed to allow human oversight (stop button, override) | ||
| VER-008-03 | Competent overseers assigned to the system | ||
| VER-AUTO-05 | Accuracy monitoring in operation | ||
| VER-009-01 | Cybersecurity of the hosting environment | ||
| VER-009-02 | Accuracy and robustness verified and documented | ||
| VER-009-03 | Cybersecurity of the AI system verified | ||
| VER-013-F-04 | Communication to market surveillance authorities in the event of risk | ||
| VER-018-D-01 | Persons informed of the interaction with an AI system | ||
| VER-018-D-03 | AI-generated content marked as such | ||
| VER-020-D-01 | FRIA carried out in accordance with Art. 27 | ||
| VER-021-D-03 | Operation monitoring | ||
| VER-022-F-01 | Risk and incident response procedure | ||
| VER-022-D-01 | Serious incident reporting procedure | ||
| VER-026-F-01 | Contractual responsibilities documented between provider and third parties | ||
| VER-029-D-01 | Affected persons informed of the use of the AI system | ||
| VER-031-G-01 | GPAI model technical documentation compliant with Annex XI | ||
| VER-031-G-02 | Documentation for downstream providers compliant with Annex XII | ||
| VER-031-G-03 | Documented copyright compliance policy | ||
| VER-031-G-04 | Published summary of training content | ||
| VER-032-G-02 | Systemic risks assessed and mitigation measures documented | ||
| VER-033-D-01 | Decision explanation procedure documented | ||
| VER-033-D-02 | System explanation capability verified | ||
| VER-033-D-03 | Explanations provided on request within a reasonable timeframe |
Differences: requirements specific to each framework
Requirements with no check serving the other framework: the extra work.
AI Act
10
EX-001
AI literacy Art. 4
EX-010
QMS Art. 17
EX-011
10-year retention Art. 18
EX-015
EU declaration of conformity Art. 47
EX-016
CE marking Art. 48
EX-017
EU database registration Art. 49
EX-023
Accessibility Art. 16(l)
EX-024
Conformity assessment Art. 43
EX-025
EX-030
Information to workers' representatives Art. 26§7
PL 2338
4
BR-01
Preliminary assessment Arts. 12, 29
BR-07
Contestation and human review Arts. 6 II, 6 III, 9
BR-19
Public-sector duties Arts. 22, 23
BR-20
Remuneration of rights holders Art. 65
Timelines
PastSet in the textPotentialTo verify
Apr 21, 2021AI Act · Commission proposal
May 3, 2023PL 2338 · Filed in the Senate
Jul 12, 2024AI Act · Published in the Official Journal
Aug 1, 2024AI Act · Entry into force
Dec 10, 2024PL 2338 · Senate approval
Feb 2, 2025AI Act · Prohibited practices (Art. 5) and AI literacy (Art. 4)
May 2025PL 2338 · Special committee in the Chamber of Deputies
Jul 10, 2025AI Act · GPAI Code of Practice published
Aug 2, 2025AI Act · GPAI obligations, governance, penalties, notified bodies
Nov 19, 2025AI Act · Digital Omnibus proposal: high-risk delay tied to standards
Aug 2, 2026AI Act · General application: Art. 50, sandboxes, Annex III high risk (unless Omnibus delay)
Oct 2026PL 2338 · Vote pushed past the October 2026 elections
Jun 2027PL 2338 · Possible adoption and start of the vacatio legis
Aug 2, 2027AI Act · Annex I high risk (regulated products); GPAI placed on the market before Aug 2025
Dec 2, 2027AI Act · Omnibus backstop for Annex III high risk
Aug 2, 2028AI Act · Omnibus backstop for Annex I high risk
Aug 2, 2030AI Act · High-risk systems of public authorities already in service (Art. 111)
Run these requirements across all your AI systems
TrustFlow inventories your systems, qualifies them under each regulation and collects evidence once for every referential.