Brazil's data protection authority opened two monitoring processes on 21 August 2026 covering 22 agents, and the second group names seven generative AI tools alongside the two app stores

Brazil ANPD Monitors ChatGPT, Claude and Gemini. The Leveraged Years regulation briefing card.

Three things make this easy to overstate. It is monitoring, not enforcement: ANPD makes no allegation and reaches no finding. It is not an AI regulation: the obligations come from the Marco Civil da Internet and the ECA Digital, and generative AI tools are simply named as agents within scope. And the interesting half is the second process, which puts Copilot, Claude, DeepSeek, Gemini, ChatGPT, Meta AI and Perplexity in the same group as the App Store and Google Play.

The short version

Bottom line: A monitoring action, not enforcement. ANPD opened two processes on 21 August 2026 covering 22 named agents. There is no allegation, no finding and no penalty. The only binding element is a deadline: answer within ten business days from notice.

Who this affects: The 22 named agents, and in particular the seven generative AI assistants placed in the second process alongside the two app stores. More broadly, any generative AI provider serving the Brazilian market, and the compliance and DPO functions behind them.

What to do: Be able to describe, evidentially, the mechanisms used to prevent and impede the circulation of criminal or illicit content, with particular attention to risks affecting children, adolescents and women. Nothing has been alleged, so this is a documentation exercise, not a defence.

Primary sources: ANPD news release, 21 August 2026 (Portuguese)

Editorial Note
Informational analysis for working professionals, not legal advice. Confirm how any rule applies to your situation with qualified counsel.
Instrument (EN)
Two monitoring processes, nº 00261.005031/2026-23 and nº 00261.005032/2026-78, opened by ANPD. The release does not say which unit opened them; it says the responses will be analysed by the Superintendência de Fiscalização (SFI)
Authority
Autoridade Nacional de Proteção de Dados (ANPD), Brazil
Jurisdiction
Brazil
Event type
Supervisory monitoring, pre-enforcement. Allegation-free: no determination, no finding, no penalty
Date of legal event
Opened Friday 21 August 2026. The ANPD page byline reads Publicado em 21/08/2026 16:34 and the body says the Agency iniciou, nesta sexta-feira (21)
Legal basis cited
Marco Civil da Internet, regulated by Decreto nº 8.771/2016 as amended by Decretos 12.975/2026 and 12.976/2026, plus convergent obligations in the Estatuto Digital da Criança e Adolescente (ECA Digital), in force since March 2026
Binding element
The notified companies must answer the questions within up to ten business days, counted from notice of the notification
Scope excluded
Email services and private communications made through messaging applications are outside the actions, in respect of the secrecy of communications
Remedy
None at this stage. The release says the responses will be analysed by the Superintendência de Fiscalização (SFI) and may be considered together with other information about how the platforms operate, complaints received and other available technical material
Primary source
https://www.gov.br/anpd/pt-br/assuntos/noticias/anpd-avalia-como-plataformas-digitais-atuam-para-prevenir-conteudos-criminosos-e-proteger-criancas-e-mulheres-na-internet

What ANPD actually did

On Friday 21 August 2026 the Autoridade Nacional de Proteção de Dados opened monitoring actions against the main digital platforms, application stores and generative artificial intelligence tools, to check whether they are adopting measures to comply with obligations set by the Marco Civil da Internet as regulated by Decreto nº 8.771/2016, amended by Decretos 12.975/2026 and 12.976/2026, and with convergent obligations in the ECA Digital.

The stated objective is to collect information to support the Agency's next actions, and to check whether the platforms, app stores and generative AI tools adopt adequate mechanisms to prevent and impede the circulation of criminal or illicit content, with particular attention to risks affecting children, adolescents and women in the digital environment.

This is a monitoring action. ANPD asserts no violation, names no infringement and imposes nothing. Anyone reporting it as an investigation into those companies, or as a finding about them, is reporting something the source does not say.

The two groups, and why the second one matters here

The monitoring covers two distinct groups, split by service type and associated risks. The first, Processo nº 00261.005031/2026-23, gathers digital platforms and messaging applications: Instagram, Facebook, WhatsApp (as to the Canais públicos feature), Telegram (as to Canais públicos and Grupos públicos), TikTok, X, Discord, YouTube, Kwai, LinkedIn, Snapchat, Pinterest and Reddit.

The second, Processo nº 00261.005032/2026-78, covers application stores and generative artificial intelligence tools: App Store, Google Play Store, Copilot, Claude, DeepSeek, Gemini, ChatGPT, Meta AI and Perplexity.

That second list is the reason this is an AI story. Seven generative AI assistants are named as monitored agents in their own right, and they sit in the same process as the two app stores rather than being treated as features of the social platforms in group one.

ANPD says the 22 monitored agents were selected considering, among other criteria, reach in the Brazilian market, the relevance of the services offered, the functionalities made available, and the risks associated with the circulation of third-party content, especially on matters relating to the protection of children, adolescents and women in the digital environment.

What this is not

It is not an AI regulation, and no new AI obligation is created. The duties being tested come from the Marco Civil da Internet and the ECA Digital. Generative AI tools appear because they fall within the scope of those instruments as ANPD reads them, not because a rule about AI has been made.

It is not an enforcement action, and there is no fine, no order and no compliance plan. The only binding element is procedural: answer within ten business days.

It does not reach private correspondence. ANPD states that, in respect of the secrecy of communications, the actions cover neither email services nor the private communications carried out through messaging applications.

The measure forms part of the Agency's action plan for implementing new competences arising from the update to the Marco Civil regulations, whose schedule the Agency published in June 2026.

Key compliance takeaway

Treat this as a scoping exercise with a deadline, not a case. ANPD has told 22 named agents to explain how they prevent criminal and illicit content from circulating, and has given them ten business days from notice to answer. For anyone advising a generative AI provider serving Brazil, the operative point is that the second process treats an AI assistant as a monitored agent under the Marco Civil da Internet and the ECA Digital, on the same footing as an app store. Nothing has been alleged, so the useful preparation is evidentiary: be able to describe the mechanisms, not to defend a finding.

Source File

https://www.gov.br/anpd/pt-br/assuntos/noticias/anpd-avalia-como-plataformas-digitais-atuam-para-prevenir-conteudos-criminosos-e-proteger-criancas-e-mulheres-na-internet

Open the ANPD news release and confirm the byline reads Publicado em 21/08/2026 16:34, above the body. Confirm the body says the Agency iniciou, nesta sexta-feira (21). Search for the two process numbers 00261.005031/2026-23 and 00261.005032/2026-78 and confirm which names belong to which. Confirm the deadline sentence, which spells the number out as dez dias úteis rather than using a numeral, so a search for 10 dias úteis returns nothing. Confirm the exclusion of email and private messaging near the end of the body.

O segundo grupo (Processo nº 00261.005032/2026-78) abrange lojas de aplicativos e ferramentas de inteligência artificial generativa: App Store, Google Play Store, Copilot, Claude, DeepSeek, Gemini, ChatGPT, Meta AI e Perplexity. - ANPD news release, 21 August 2026 (translated: the second group, Process no. 00261.005032/2026-78, covers application stores and generative artificial intelligence tools: App Store, Google Play Store, Copilot, Claude, DeepSeek, Gemini, ChatGPT, Meta AI and Perplexity)

FAQ

Has ANPD accused these companies of anything?

No. This is a monitoring action. The release describes collecting information to support the Agency's next actions and to check whether adequate mechanisms are adopted. It states no allegation, no finding and no penalty.

Is this a new Brazilian AI rule?

No. The obligations tested come from the Marco Civil da Internet, regulated by Decreto nº 8.771/2016 as amended by Decretos 12.975/2026 and 12.976/2026, and from the ECA Digital. Generative AI tools are named as agents within the scope of those instruments.

What is the deadline?

The notified companies must answer within up to ten business days, counted from notice of the notification. The release spells the figure out as dez dias úteis.

Does the monitoring cover private messages?

No. ANPD states that, in respect of the secrecy of communications, the actions cover neither email services nor private communications carried out through messaging applications. Where messaging apps are included it is by named public feature, such as Telegram's Canais públicos and Grupos públicos.

Sponsored Training

Practical AI training for regulated professionals, built around verification, documentation and a defensible process. See the courses.

."}}]}