The Alleged (Un)regulation of AI Use in Brazil: The Impact Assessment as a Solution
摘要
Brazil, despite its recent advances in the regulatory sphere for Privacy and Data Protection, still remains unregulated regarding the use of artificial intelligence. In 2020, two years after the enactment of the General Law on Data Protection (LGPD), a Bill emerged that was the first Brazilian attempt not only to regulate, but also to define, classify, and identify AI-powered tools. However, among confusing meanings and vague typifications, the proposal failed to become the prototype that would generate a regulatory framework that encompasses both preventive compliance methods and possible remedial solutions for eventual disputes. Thus, the need emerges to seek pre-existing solutions in the Brazilian legislation that, although still undefined and precariously implemented, may be consolidated in the future as indispensable tools for the identification of eventual failures. This is where the mandatory implementation of the impact assessment comes in as a potential solution for the detailed analysis of AI-powered systems. Software architectures that are programmed to make automated decisions by means of machine learning techniques, for example, present certain risks, but the level of risk is unknown, precisely because of the lack of transparency about how their internal architectures work. Thus, a continuous and properly documented risk assessment will provide essential analysis both to substantiate a preventive system that survives the wear and tear of time in relation to inexorable technological advancement, and to serve as a broad and precise regulation, which will work as a legal instrument for any legal dispute that may arise in the years to come.