AI in Brazilian Medicine: CFM Resolution 2,454/2026 Guide
A practical guide to Brazil’s CFM Resolution 2,454/2026 for physicians, clinics, hospitals and technology providers using artificial intelligence.
Direct answer: Brazil's CFM Resolution No. 2,454/2026 requires artificial intelligence in medicine to remain a support tool under human oversight, with transparency, data protection and controls proportionate to risk. Since August 26, 2026, physicians and medical institutions must also assess systems already in use, document accountability and preserve the physician’s authority over clinical decisions.
AI already organizes records, transcribes consultations, automates service workflows and supports analysis in clinics and hospitals. The Brazilian rule does not prohibit this progress. It defines conditions for using technology without weakening medical autonomy, patient safety or data confidentiality.
What is CFM Resolution 2,454/2026?
The CFM Resolution No. 2,454/2026 governs research, development, governance, auditing, monitoring, training and responsible use of AI in Brazilian medicine. It was published on February 27, corrected on March 5 and took effect on August 26, 2026.
CFM is Brazil's Federal Council of Medicine. Its resolution covers predictive models, decision-support systems, generative applications, virtual assistants and other tools used in a medical context. The scope therefore extends beyond software that suggests diagnoses. An administrative tool also requires assessment when it processes health data, affects patient service or creates potential harm.
What changed for physicians, clinics and hospitals?
The central change is that fragmented good practices become an organized governance duty. Clinical decisions remain human. Physicians may accept or reject algorithmic recommendations based on professional judgment and should not be forced to follow a system automatically.
- Medical autonomy: diagnosis, prognosis, prescription and other medical acts remain the physician's responsibility.
- Transparency: patients need clear information when AI plays a relevant role in their care.
- Traceability: relevant decision-support uses must allow appropriate recording and review.
- Governance: institutions need accountable owners, risk classification and ongoing monitoring.
- Validation: adoption must consider scientific evidence, applicable certification, limitations and the intended context.
Buying a software license does not complete the work. The institution remains responsible for purpose, integrations, permissions, data quality, error scenarios and a reliable path for human intervention.
How should administrative automation be separated from medical decisions?
An appointment reminder, an initial message triage and an imaging interpretation tool have different consequences. Assessment should consider purpose, system autonomy, data access and the likely effect of an error.
In administration, AI may confirm appointments, organize requests, classify documents and route patients. These uses often carry lower clinical risk, but still require security, access controls and explicit boundaries. An automated assistant must not invent medical guidance, obscure its nature or block access to a person when professional evaluation is necessary.
Clinical applications require stronger controls. A recommendation that influences diagnosis or treatment needs scientific validation, medical oversight, appropriate records, performance analysis and a route for challenge. The greater the potential impact, the more robust the audit, monitoring and documentation must be.
How does Brazil's LGPD apply to medical AI?
Brazil's General Data Protection Law, known as LGPD, treats health information as sensitive personal data. Every AI project should therefore map what enters the system, why it is needed, where it is stored, who may access it and which suppliers participate in processing.
A clinic using AI in WhatsApp, for example, should distinguish an appointment confirmation from a conversation containing test results, symptoms or treatments. It should verify whether a provider uses customer data to train models, identify subprocessors, document processing locations and define how deletion requests and incidents are handled.
- Apply least-privilege access.
- Protect data in transit and at rest.
- Log relevant access and operations.
- Define retention, disposal and incident response.
- Review contracts, lawful grounds and international transfers.
- Prevent reuse that conflicts with the disclosed purpose.
Compliance does not depend on one certificate. It emerges from architecture, processes, contracts, training, oversight and evidence that the controls work.
What compliance checklist can a medical institution use?
The work can begin with a practical inventory and evolve into governance proportionate to risk. The following sequence turns the rule into verifiable decisions.
- Inventory: list AI systems in production, testing or procurement, including features embedded in existing software.
- Define purpose: document the problem, users, data and decisions affected.
- Classify risk: assess clinical impact, potential harm, reversibility and required oversight.
- Assign owners: identify clinical, technical, privacy and security responsibility.
- Validate: require evidence, documentation, known limitations and applicable certifications.
- Inform: provide clear communication to patients and professionals when use is relevant.
- Monitor: track errors, performance, model changes, incidents and complaints.
- Reassess: repeat the review whenever the system, supplier, data or purpose changes.
This inventory must include systems that are already installed. An institution without a formal AI project may still use transcription, automatic summaries, message prioritization and productivity features embedded in contracted platforms.
How should healthcare organizations select a technology partner?
A supplier should explain how the system works in understandable terms without using trade secrecy as a reason to hide operational risk. The institution needs visibility into limitations, dependencies, data policy, audit options, change history and incident response.
Before contracting, ask which data is processed, whether customer content trains models, how permissions work, when human intervention occurs and how decisions can be reviewed. Examine electronic health record integration, duplicate data, logs, service continuity and data export if the supplier changes.
Web Star Studio applies this diagnostic approach before designing software, integrations, automation and AI agents. Our healthcare technology and AI practice in Brazil starts from the real workflow, regulatory boundaries and the role of each professional. The practical implementation roadmap for clinics adds operational context.
Which implementation mistakes should be avoided?
- Adopting a tool without mapping its purpose and data.
- Confusing an algorithmic recommendation with a medical decision.
- Using personal accounts or plans without adequate safeguards for sensitive data.
- Failing to inform patients and teams about relevant uses.
- Ignoring versions, incidents and system changes.
- Assuming accountability transferred entirely to the supplier.
- Automating communication of a diagnosis, prognosis or treatment without physician participation.
It is equally risky to treat compliance as a one-time document. Models change, integrations evolve and suppliers update their terms. AI governance is an ongoing operational discipline.
Frequently asked questions about CFM Resolution 2,454/2026
When did CFM Resolution 2,454/2026 take effect?
It was published on February 27, corrected on March 5, and took effect on August 26, 2026.
Can artificial intelligence replace a physician’s decision?
No. AI may support analysis, but diagnosis, prognosis, prescription and other medical acts remain the physician’s responsibility.
Must patients be informed when AI is used?
Yes. When AI plays a relevant role in care, diagnosis or treatment, the patient must receive clear and accessible information.
Does an administrative automation need governance?
Yes. Controls should be proportional to the system’s risk, the data it accesses and its possible impact on patients and professionals.
How should a clinic begin its compliance work?
Start by inventorying systems, classifying risks, documenting purposes and owners, reviewing contracts and defining human oversight and monitoring.
Conclusion: responsible innovation requires evidence and human control
The Brazilian rule organizes one essential principle: technology can expand medicine's capacity, but it does not replace professional responsibility. Physicians and managers should assess every system according to purpose, risk, data and its real effect on patients.
The best implementation is not the one that automates the most tasks. It solves a verifiable problem, keeps professionals in control and produces evidence of safety, transparency and performance over time. The official text in Brazil's Federal Gazette should guide any case-specific regulatory analysis.
This article is informational and does not replace individualized legal, regulatory, technical or medical advice.