The new rules from Brazil’s Federal Council of Medicine place the use of artificial intelligence in healthcare under a clearer framework for responsibility, governance, and oversight. The change affects doctors, hospitals, clinics, and companies that develop or provide AI solutions for the healthcare sector.
What changes under Brazil’s new AI rules for medicine
The new rules establish that artificial intelligence can support medical practice but cannot take final authority over clinical decisions. As of August 26, doctors and healthcare institutions must comply with CFM Resolution No. 2,454/2026, which regulates the research, development, governance, auditing, monitoring, and use of AI systems in medicine.
The most important change concerns responsibility. AI systems can analyze information, generate recommendations, and support medical processes, but diagnoses, prognoses, prescriptions, and other medical acts remain the responsibility of the physician.
The regulation also makes clear that adopting AI cannot be treated simply as a technology decision. The use of these systems now involves governance, security, transparency, data protection, and risk assessment.
AI is formally positioned as a support tool
Physicians retain the authority to accept or reject recommendations generated by AI systems. The resolution also provides for the right to refuse tools that lack adequate scientific validation or relevant regulatory certification, or that conflict with ethical, technical, or legal principles.
Human responsibility remains central
The use of AI does not remove the obligations established by Brazil’s Code of Medical Ethics. Physicians must critically evaluate information produced by technology and consider the patient’s clinical condition, scientific evidence, and accepted medical practices.
Healthcare institutions will need stronger AI governance
For hospitals and clinics, one of the most significant changes is the shift from simply adopting technology to establishing a structured AI governance framework. The resolution requires institutions that develop or contract AI systems to establish internal processes designed to ensure safety, quality, and ethical use.

Hospitals and clinics will need more structured processes to govern artificial intelligence systems used in healthcare.
Institutions must conduct a preliminary assessment to determine the risk level of each solution. Factors include the potential impact on health and fundamental rights, the criticality of the use case, the system’s degree of autonomy, human intervention, and the sensitivity of the data being processed.
The resolution establishes four categories: low, medium, high, and unacceptable risk. Lower-risk systems may be associated with administrative and operational functions, while applications that influence critical clinical decisions require stricter controls.
When AI governance becomes a formal requirement
Institutions that adopt their own AI systems must establish an AI and Telemedicine Committee, coordinated by a physician and reporting to the technical director. Its role is to oversee compliance with governance requirements and promote the ethical use of these systems.
This move brings healthcare AI management closer to a model already emerging across other areas of enterprise technology. Technology, security, legal, and business teams increasingly need to share responsibility for the lifecycle of AI systems rather than treating implementation as an isolated IT project.
Health data moves to the center of AI regulation
Data protection is another major pillar of the new rules. AI systems used in medicine can process highly sensitive information, and the resolution requires this data to be protected throughout the development, training, validation, and deployment of AI solutions.
The rules require technical and administrative measures appropriate to the criticality of the systems and data, including protection against unauthorized access, loss, alteration, and breaches.
This expands the responsibilities of organizations using AI in healthcare. It is no longer enough to determine whether a tool produces useful results. Organizations also need to understand what information enters the system, why it is being processed, and what mechanisms are in place to protect it.
Training AI systems with data also requires controls
The resolution requires the use of personal data for training, validation, or improvement of models to comply with ethical, scientific, and data protection principles.
For companies supplying AI solutions to hospitals and clinics, this increases the importance of contracts, technical documentation, access controls, and clearly defined processes for handling information.
The development also reinforces a concern already emerging across enterprise AI deployments: who controls the data and who is accountable when technology is used improperly.
AI healthcare companies are entering a new phase
The new regulation is not relevant only to physicians. Companies that develop, provide, or integrate AI systems for medical institutions will operate in an environment where validation, security, transparency, and risk classification carry greater weight in procurement decisions.

Healthcare technology providers will need to address security, evidence, and governance requirements alongside model performance.
The resolution introduces concepts such as algorithmic impact assessment, auditability, explainability, and contestability. In practice, this means evaluating an AI solution can no longer focus solely on what the technology can do. Organizations also need to consider whether its results can be understood, challenged, monitored, and corrected.
This could change how hospitals evaluate technology vendors. A system that delivers strong performance but provides insufficient information about its limitations, risks, and supporting evidence may face greater barriers to adoption in medical workflows.
The market will increasingly sell more than model performance
For AI providers, competitive advantage is likely to depend not only on model accuracy but also on governance, documentation, security, and auditability.
The change matters because AI systems deployed in enterprise healthcare environments can remain operational for long periods. Updates, model changes, and new use cases can alter how a system behaves and, consequently, its risk profile.
This brings healthcare AI closer to a lifecycle approach in which development, validation, deployment, monitoring, and review are connected stages rather than separate activities.
Risk classification changes how medical AI systems are evaluated
The CFM classification distinguishes systems according to their potential impact on patients, professionals, and fundamental rights. The approach creates a framework in which the level of control is proportional to the potential risk.
Low-risk solutions include administrative and operational applications with limited influence over clinical decisions. Medium-risk systems may support important decisions, provided that active human oversight can identify and correct problems.
High-risk systems face stricter requirements because failures can result in significant physical, psychological, or moral consequences. The resolution provides for more rigorous validation processes, regular audits, and continuous monitoring for these applications.
Human oversight remains the central principle
Risk classification does not turn AI into a medical authority. On the contrary, the resolution establishes that these systems are not sovereign and that human oversight must remain in place.
This means that adopting a sophisticated AI system does not automatically transfer responsibility to the technology. Physicians remain responsible for medical acts performed with AI assistance, while institutions must establish mechanisms to ensure that the technology is used within the applicable rules.
This principle also helps explain why the regulation may influence procurement decisions. The more critical the application, the more important it becomes to have controls capable of monitoring how the system behaves.
What changes for doctors and hospitals from now on

The new framework requires greater integration between technology, management, security, and medical responsibility when adopting AI.
The entry into force of CFM Resolution No. 2,454/2026 turns AI adoption in medicine into an issue that goes beyond implementing new tools. Physicians need to understand the limitations of the systems they use, document the use of AI as decision support in medical records, and maintain critical judgment over its recommendations.
For hospitals and clinics, the challenge is broader. Organizations need to consider risk classification, governance, auditing, monitoring, information security, and data protection when incorporating AI solutions.
The change also reflects a broader issue already emerging across other enterprise AI applications: the greater the autonomy of the technology, the greater the organization’s ability to supervise it must be. In healthcare, this relationship carries additional weight because AI outputs can directly affect patients’ health and rights.
The issue also connects with the growing discussion about corporate responsibility when AI agents take autonomous actions. In healthcare, however, the need for oversight has an additional regulatory dimension.
The new rules also reinforce the importance of AI governance and AI agent operations inside companies, while introducing specific requirements for a sector where sensitive data and clinical decisions are directly involved.
The most important point is that the CFM is not establishing a barrier to artificial intelligence adoption in medicine. Instead, the resolution creates a framework in which innovation and control must advance together. For physicians, healthcare institutions, and technology providers, the ability to demonstrate safety, governance, and accountability is becoming part of the technology adoption strategy itself.
From now on, the debate over AI in Brazilian healthcare is no longer only about what these systems can do. It is also about who supervises them, which risks are acceptable, and how organizations demonstrate that the technology is being used responsibly.

Comentários
Os comentários utilizam autenticação via GitHub para manter um ambiente mais qualificado, seguro e livre de spam.
Entrar ou criar conta no GitHub