
Brazil’s Federal Medical Council has issued Resolution No. 2.454/2026, creating a mandatory AI governance framework for medical use—without waiting for a national AI law.
What’s Enforced
• Binding compliance scope: Covers AI across research, development, deployment, auditing, and monitoring in healthcare
• Human-in-the-loop mandate: AI can assist—but cannot replace physician judgment or independently deliver diagnoses/treatment
• Risk-tiered controls: Low → unacceptable risk classification, with scaled obligations (aligned with global models like EU AI Act)
• Health data = high-risk governance: Safeguards must match sensitivity under LGPD
• Operational accountability: Hospitals must upgrade vendor management, auditability, training, and incident response before enforcement in 2026
Why It Matters
• Sector regulators are moving first: Enforcement risk is no longer tied to national AI laws
• Compliance exposure is real: While fines aren’t specified here, violations can trigger broader liability under medical ethics + data protection regimes
• Global signal: Expect similar sector-led AI enforcement in healthcare, finance, telecom
Bottom line: AI governance is already enforceable at the sector level. Waiting for omnibus AI laws creates compliance gaps—especially in high-risk industries like healthcare.
S8fe.ai helps organizations operationalize AI governance + data compliance—from risk classification to audit-ready controls.
Source: https://iapp.org/news/a/resoluci-n-cfm-n-2-454-2026-ia-y-protecci-n-de-datos-en-medicina-en-brasil
