Brazil’s AI Adoption Gap
When Innovation Outpaces Governance
-
August 19, 2026
-
Brazil is in the midst of an artificial intelligence inflection point. Across industries, organizations are exploring how AI can streamline operations, improve decision-making and support new products and services. According to the latest Digital Risks Index,1 published by the Markets Innovation & Technology Institute (“MiTi”) with the support of FTI Consulting, more than one-third of Brazilian organizations surveyed already report having AI initiatives that influence products, services or business models.
This momentum reflects a broader global trend. FTI Consulting’s recent research among general counsel found that generative AI adoption in legal departments has surged from 44% to 87% in just one year.2 Findings from our Annual Chief Legal Officers Survey, conducted by FTI Consulting with the Association of Corporate Counsel (“ACC”), similarly point to growing executive focus on AI and technology capabilities.3 As AI becomes more deeply embedded in business operations, organizations face increasing pressure to capture its benefits while managing the risks that accompany it.
The MiTi report suggests governance is not advancing at the same pace as AI ambition in Brazil. While AI maturity among the surveyed organizations stands at 51%, ethical and legal exposure risk reaches 53%, approaching the study’s higher criticality range. These challenges extend beyond cybersecurity to include privacy, compliance, accountability and oversight. This gap highlights a growing disconnect between Brazilian organizations’ enthusiasm for AI and their preparedness to govern it responsibly.
The AI Readiness Gap
The governance challenge identified by the MiTi research is organizational. While AI initiatives are advancing across sectors, the policies, training programs, accountability mechanisms and cross-functional processes required to manage risk consistently have not developed with the same maturity.
Cross-Functional Collaboration Remains Limited.
One of the clearest indicators of this gap is the readiness gap between business and technology functions. Half of organizations surveyed report only sporadic interaction between business units and IT regarding AI initiatives. With AI now embedded in products, services and operational decision-making, effective governance becomes more dependent on close collaboration between technical, legal, compliance and business stakeholders. In many organizations, those connections appear to remain underdeveloped.
AI Governance Training Gaps Persist.
The readiness gap also extends to workforce preparedness. Three-quarters of organizations surveyed either lack structured training programs on AI governance and risk management or rely primarily on informal awareness efforts. Awareness of AI’s opportunities appears to be growing faster than the organizational capabilities needed to govern its use.
Formal AI Oversight Structures Are Still Emerging.
Formal governance structures also remain underdeveloped in many companies. Only one-quarter of organizations report AI strategies that are formally integrated into strategic planning through governance mechanisms such as executive oversight, defined performance metrics or dedicated funding. Consistent with the report’s broader findings, many organizations appear to be advancing AI initiatives before establishing the policies, accountability structures and monitoring processes needed to govern them effectively.
Where AI Exposure is Growing
As AI adoption expands, weaknesses in oversight, accountability and preparedness will increasingly translate into operational, legal, regulatory and reputational exposure. Three areas of exposure stand out in the MiTi research:
- Privacy and compliance: AI ethical and legal exposure risk reaches 53%, driven by concerns around personal data use, intellectual property and oversight of automated decision-making. Privacy awareness, supplier oversight and compliance monitoring also appear to be areas of relative weakness.
- Accountability and oversight: Governance structures often exist but are inconsistently executed. Many organizations report having processes for addressing noncompliance, yet lack systematic follow-up and effectiveness measurement. The research also suggests a potential blind spot around whether existing governance frameworks have been adapted for AI-specific risks.
- Cybersecurity: Just 22% of organizations report having a proactive cybersecurity strategy for AI systems that includes capabilities such as penetration testing, real-time monitoring and incident response planning. Broader governance challenges related to cybersecurity leadership, policy maintenance and strategic investment further contribute to organizational exposure.
Notably, exposure isn’t evenly distributed across sectors. Government and Healthcare face particularly elevated AI risk levels, due to a combination of sensitive data, high public interest and comparatively unstructured governance practices. By contrast, companies in Financial Services, Telecommunications and Technology generally demonstrate stronger governance maturity and lower levels of ethical and legal exposure.
Closing the AI Gap Before Regulation Does
Regulatory expectations are also evolving. Brazil’s AI framework remains under development, while enforcement of Lei Geral de Proteção de Dados (“LGPD”), Brazil’s personal data protection law, and broader expectations around accountability, transparency and risk management continue to mature. Internationally, developments such as the EU AI Act point to a broader emphasis on accountability, documentation, risk assessments, governance oversight and explainability.
These trends become more significant when viewed through the lens of the Digital Risks Index, which combines cybersecurity, data governance and AI maturity into a single measure of organizational resilience. The Index assigns Brazil an overall score of 58%, indicating a market that is making progress but has not yet achieved resilience. Closing the readiness gap will require building governance, accountability and operational foundations that enable AI to be deployed consistently and responsibly. Key priorities include:
- Establish governance structures before AI scales. Clear ownership, executive oversight, defined responsibilities and documented governance processes can help ensure that AI initiatives develop alongside accountability and risk management capabilities.
- Strengthen cross-functional collaboration. Companies should create mechanisms that bring legal, compliance, privacy, security and business stakeholders into decision-making earlier and more consistently.
- Invest in training and organizational readiness. Building a common understanding of responsible AI use, governance obligations and risk management expectations can help reduce organizational blind spots and improve preparedness.
- Integrate AI governance with existing privacy and cybersecurity programs. Many of the risks identified in the MiTi study, including personal data misuse, weak oversight and cybersecurity exposure, are extensions of challenges organizations already manage through privacy and data security functions. AI governance should build on these existing capabilities rather than operate separately.
- Apply governance across the broader AI ecosystem. As organizations rely more heavily on external AI models, vendors and technology partners, governance frameworks should extend beyond internal use cases to include vendor risk management, supplier due diligence and ongoing compliance monitoring.
Moving From AI Ambition to AI Readiness
Brazilian organizations must continue to innovate with AI to keep pace with rapid global adoption. With the technology taking a growing share of boardroom agendas and transformative use cases emerging, it is imperative that governance capabilities evolve alongside adoption. The organizations best positioned for the next phase of AI adoption will have established policies, accountability structures and the risk management practices required to deploy responsibly.
Footnotes:
1: Unless otherwise indicated, the data cited in this article is drawn from MiTi’s 2025 report on digital risks, an annual assessment of cybersecurity, data governance and AI maturity among Brazilian organizations, sponsored by FTI Consulting. See Cornacchione, E., et al., “Digital Risks 2025,” Markets Innovation & Technology Institute (6 May 2026).
2: FTI Consulting, “The Seventh Annual General Counsel Report” (18 February 2026).
3: FTI Consulting, “2026 ACC Chief Legal Officers Survey” (January 2026).
Related Insights
Published
August 19, 2026
Key Contacts
Senior Managing Director, Head of Brazil Technology and Risks & Investigations