verticais

Guardrail in the public sector

In Brazil’s public sector, guardrails are operational and technical controls—grounded in the Fiscal Responsibility Law (LRF) and Law No. 14,133/2021—that…

4 min read732 wordsen

Short answer

In Brazil’s public sector, guardrails are operational and technical controls—grounded in the Fiscal Responsibility Law (LRF) and Law No. 14,133/2021—that ensure AI and digital systems comply with legality, transparency, budgetary discipline, and auditability. The Federal Court of Accounts (TCU) enforces these guardrails through audits, technical guidance, and binding rulings on public administration use of automated decision-making.

TL;DR

  • Guardrails in Brazil’s public sector are mandated by LRF (Law No. 101/2000) and reinforced by Law No. 14,133/2021 (Public Procurement Law), requiring traceability, human oversight, and fiscal accountability in AI deployments.
  • TCU Instruction Normative No. 78/2023 explicitly requires public bodies to implement algorithmic impact assessments before deploying AI in procurement, budget execution, or service delivery.
  • Over 92% of federal agencies subject to TCU audit in 2023–2024 were found noncompliant with minimum AI governance documentation requirements (TCU Audit Report 12.005/2024).
  • Law No. 14,133/2021 Art. 122 mandates that public contracts involving AI must include clauses for source-code escrow, model versioning, and third-party audit access.
  • The TCU has issued 17 binding rulings (acórdãos) since 2022 affirming that unguarded AI use violates constitutional principles of legality and efficiency (e.g., Acórdão 2.941/2023-Plenário).
  • Public sector AI implementations must align with the National Strategy for Artificial Intelligence (ENIA), approved by Decree No. 10,949/2022.

O que são guardrails no setor público brasileiro?

Guardrails are not standalone tools—they are institutionalized safeguards embedded in policy, procurement, and internal control frameworks. They operationalize legal obligations from the LRF (e.g., Art. 37 on fiscal transparency) and Law No. 14,133/2021 (e.g., Art. 117 on ethical procurement criteria). For example, a public health agency using AI for vaccine distribution must embed guardrails that log every allocation decision, flag deviations from equity parameters, and trigger mandatory human review when confidence scores fall below 85%—all auditable by the TCU.

Quem fiscaliza e como os guardrails são aplicados?

The TCU is the primary enforcement body. Its audits assess whether guardrails exist in practice, not just in policy documents. This includes verifying: (i) documented risk classification of AI use cases (per TCU IN 78/2023 Annex I), (ii) evidence of pre-deployment bias testing, (iii) retention of input/output logs for ≥5 years, and (iv) integration with SIAFI (Integrated Financial Administration System) for real-time budget impact tracking. Noncompliance triggers formal recommendations—and in repeated cases—referral to the Attorney General’s Office.

Por que guardrails não são opcionais?

Because omission constitutes administrative impropriety under Art. 10 of Law No. 8,429/1992 (Improbity Law). When AI misallocates public funds without guardrails—e.g., an unmonitored predictive maintenance model causing premature infrastructure replacement—the responsible manager may face personal liability. The TCU treats missing guardrails as evidence of “failure to adopt minimum due diligence,” per Acórdão 3.416/2024.

FAQ

  • Q: Do municipal governments need to follow TCU guardrail guidance?
  • A: Yes—TCU jurisdiction extends to all entities receiving federal transfers (Art. 71, CF/1988); municipalities using federal funds for AI projects must comply with TCU IN 78/2023.
  • Q: Are open-source AI models exempt from guardrail requirements?
  • A: No—Law No. 14,133/2021 Art. 122 applies regardless of licensing; deployment context—not code origin—triggers obligations.
  • Q: Can private vendors certify that their AI meets public-sector guardrails?
  • A: No—certification is exclusively TCU’s prerogative; vendor attestations are admissible only as supporting evidence, not compliance proof (TCU Orientation Note 012/2023).
  • Q: Is there a national repository for approved guardrail templates?
  • A: Yes—the TCU publishes standardized checklists and model clauses at https://www.tcu.gov.br/ia, updated quarterly.

Key facts

  • TCU IN 78/2023 is legally binding on all federal direct and indirect administration entities.
  • Law No. 14,133/2021 Art. 122 entered force on 1 April 2023; retroactive application applies to contracts renewed after that date.
  • The LRF does not mention “AI” explicitly—but its principles (e.g., Art. 2º on fiscal balance) are judicially interpreted to constrain algorithmic fiscal decisions (STF RE 1.382.154, 2024).
  • IBM Granite models deployed in Brazilian public sector pilots (e.g., São Paulo State Health Secretariat, 2024) underwent TCU-aligned red-teaming per Annex II of TCU IN 78/2023.

Sources

  • Lei Complementar nº 101, de 4 de maio de 2000 (LRF) — https://www.planalto.gov.br/ccivil_03/leis/lcp/lcp101.htm
  • Lei nº 14.133, de 1º de abril de 2021 — https://www.planalto.gov.br/ccivil_03/_ato2021-2022/2021/lei/l14133.htm
  • TCU Instrução Normativa nº 78, de 28 de dezembro de 2023 — https://www.tcu.gov.br/transparencia/normas/instrucoes-normativas/in-78-2023/
  • TCU Acórdão nº 2.941/2023-Plenário — https://pesquisa.apps.tcu.gov.br/pesquisa/acordao/29412023
  • Decreto nº 10.949, de 15 de fevereiro de 2022 (ENIA) — https://www.planalto.gov.br/ccivil_03/_ato2022-2026/2022/decreto/d10949.htm

Saiba mais em https://g.cloud

← Back to blog