Beyond detection: Brazil's emerging approach to deepfake governance

A Technology Radar series published by Brazil's ANPD demonstrates that the risks associated with deepfakes arise well before content is generated and may persist long after it is published.

Contributors:
Ana Silvia Martins
CDPO/BR
Partner
Failla Lima e Riva Advogados
Lucas de Bulhões Gomes
CDPO/BR
Lawyer
Failla Lima e Riva
In the sixth edition of its Technology Radar series, Brazil's National Data Protection Agency focuses on deepfakes, examining how synthetic content is created and detected, legitimate and harmful uses and measures being considered to mitigate associated risks.
Although it is published by Brazil's ANPD, the Technology Radar series — which serves as a forum for the agency's technical analysis of emerging technologies and their data protection implications — is relevant to any organization that develops, procures or deploys systems capable of generating synthetic media. The issue extends well beyond privacy, touching on cybersecurity, fraud prevention, product design, third-party risk management and trust in digital communications.
Determining whether content is fake is only part of the problem. Organizations also need to understand how deepfake content originated, including where the underlying data came from, which systems were used or compromised, which malicious actors may have been involved and, crucially, how to respond to the incident. Put differently, governing deepfakes cannot be reduced to detecting them after they have been created.
The ANPD's radar, published 29 July, does not create new regulatory obligations or establish a standalone legal regime for deepfakes or synthetic media. Its purpose is educational: to demonstrate that the risks associated with deepfakes arise well before content is generated and may persist long after it is published.
This analysis comes at a time when the ANPD's institutional role in Brazil's digital environment is expanding. In May 2026, Decrees Nos. 12,975 and 12,976 granted the agency powers to assess the systemic conduct of platforms and oversee duties relating, among other matters, to the prevention of digital fraud and the AI-enabled generation or modification of intimate content.
While the radar itself is not regulation, it forms part of a broader institutional movement toward monitoring and responding to digital risks.
Contributors:
Ana Silvia Martins
CDPO/BR
Partner
Failla Lima e Riva Advogados
Lucas de Bulhões Gomes
CDPO/BR
Lawyer
Failla Lima e Riva