8 out 2026

Artificial Intelligence in Medicine: Comparative Analysis of CFM Resolution No. 2,454/2026 and Bill No. 2,338/2023

Carolina Caiado
September, 2026

The growing incorporation of artificial intelligence (AI) tools into healthcare has led regulators and sector entities to reflect on the limits, responsibilities, and safeguards applicable to the use of these technologies. In this context, CFM Resolution No. 2,454, of February 11, 2026, represents a relevant initiative by the Federal Council of Medicine (CFM) to regulate, from an ethical and professional perspective, the use of AI in the practice of medicine.

It is important to note, however, that the Resolution should not be confused with a regulatory framework for artificial intelligence in Brazil. It is a normative administrative act, issued by the CFM in the exercise of its legal authority to regulate aspects of the professional practice of medicine and to guide the conduct of physicians subject to oversight by the Medical Councils.

By contrast, Bill No. 2,338/2023, currently under consideration in the National Congress, if approved, will become a law of national scope enacted by the Legislative Branch. Bill No. 2,338/2023 has a significantly broader scope, as it seeks to establish a general legal regime for artificial intelligence, applicable to various sectors of the economy.

Although they differ in legal nature, regulatory reach, and foundations, the Resolution and the Bill present relevant points of convergence, especially with regard to the use of artificial intelligence in activities that may directly affect people’s health.

The preservation of the physician’s professional autonomy as a central element

The most relevant aspect of the Resolution for hospitals, clinics, laboratories, telemedicine services, and other healthcare providers is perhaps the reaffirmation that artificial intelligence should act as an instrument to support medical practice, and not as a substitute for human clinical judgment.

The rule starts from the premise that AI systems can contribute to information analysis, diagnostic support, organization of clinical data, and assistance in decision-making. However, it makes clear that responsibility for the clinical assessment of the patient and for determining diagnostic and therapeutic courses of action remains with the physician.

From this perspective, AI is treated as a tool to support professional practice, without the capacity to replace the technical and scientific autonomy of the professional responsible for the care.

This guideline converges with Bill No. 2,338/2023, which also adopts human oversight as one of the structuring elements of artificial intelligence governance, particularly in cases where the systems may affect individuals’ rights or relevant interests.

For healthcare institutions, this approach signals that the growing use of algorithmic technologies does not eliminate the need for the active participation of healthcare professionals in care-related decision-making processes.

Risk management and transparency gain relevance in the care setting

Another aspect that brings the Resolution closer to the national legislative debate on artificial intelligence is the concern with managing the risks associated with the use of these technologies.

Both the Resolution and Bill No. 2,338/2023 adopt a regulatory logic based on identifying and mitigating the risks arising from the use of AI systems. In both cases, there is concern about potential impacts on fundamental rights, safety, system reliability, the quality of the data used, and the prevention of discriminatory or inadequate results.

In the healthcare context, the discussion is relevant because of the sensitivity of the activities carried out by hospitals, clinics, and other care establishments. Tools designed to support diagnoses, suggest therapeutic courses of action, or assist clinical decisions can have direct impacts on patients’ physical and psychological integrity, a circumstance that justifies the adoption of more rigorous oversight and control mechanisms.

The emphasis placed on transparency also deserves mention. The Resolution seeks to ensure that physicians and patients have access to sufficient information to understand the purpose, limitations, and risks associated with the systems used in clinical practice. This concern directly echoes the ongoing legislative discussion in the National Congress on explainability, transparency, and accountability in artificial intelligence systems.

Data protection and health information

The use of artificial intelligence in medicine is intrinsically linked to the processing of large volumes of data, many of which consist of health information subject to a differentiated legal protection regime.

In this context, both the Resolution and Bill No. 2,338/2023 give special attention to the governance of the data used for training, validating, and operating AI systems.

Although the specific regulation of personal data protection remains tied to the General Personal Data Protection Law (LGPD), both texts reflect the understanding that the reliability of artificial intelligence systems depends directly on the quality, integrity, and governance of the datasets used.

For healthcare providers, this convergence between discussions on AI and data protection reinforces the trend toward integrating technology governance, information security, privacy, and regulatory compliance programs.

Civil liability deserves careful analysis

A point that deserves special attention concerns the treatment of civil liability arising from the use of artificial intelligence systems.

The Resolution contains provisions related to the professional liability of physicians and mentions situations in which failures could be attributed to the AI system itself. Among the physician’s rights listed in the Resolution is “to be protected against undue liability for failures attributable exclusively to AI systems, provided that diligent, critical, and ethical use of the tools is demonstrated.” Legal provisions of this nature should be interpreted with caution.

The civil liability of healthcare professionals, hospitals, clinics, and other agents involved in the provision of medical services derives from laws that are hierarchically superior to the Resolution. Among the laws that deserve mention is the Civil Code.

As an administrative act below the level of statutory law, the Resolution has no authority to alter the legal regimes of civil liability established by law.

Final considerations

CFM Resolution No. 2,454/2026 does not establish a general legal regime for artificial intelligence, nor does it replace the future legislation that may result from Bill No. 2,338/2023. Its purpose is different: to regulate, within the CFM’s institutional authority, ethical and professional aspects related to the use of artificial intelligence in the practice of medicine.

For hospitals, clinics, laboratories, telemedicine companies, and other healthcare providers, the main message to be drawn from the Resolution is that incorporating artificial intelligence technologies does not diminish the centrality of medical practice or the essential nature of the physician-patient relationship. On the contrary, the rule reaffirms that clinical decision-making remains a human act, with AI performing an instrumental role in supporting the professional responsible for patient care.

 

Comentários