CFM releases resolution on the use of AI in healthcare

Applications of AI


On February 27, 2026, the Brazilian Federal Council of Medicine (“CFM”) announced that: CFM Resolution No. 2,454/26governs the use of artificial intelligence (“AI”) in healthcare. This resolution will become effective 180 days after its issuance.

According to the CFM, the resolution is the result of 18 months of discussions by a working group convened to discuss how to incorporate AI into medical practice. This initiative responds to the increasing adoption of AI-based tools in healthcare and aims to ensure adherence to the principles of beneficence, non-maliciousness (“do no harm”), medical autonomy, justice, and patient-centered care.

However, the new regulatory framework is not limited to clinical settings. This resolution has significant implications for healthcare organizations, technology companies, software developers, research facilities, and other stakeholders across the digital health ecosystem and requires a structured approach to governance, data protection, and intangible asset management.

Key aspects of the new CFM regulations are listed below.

Scope and general principles

CFM Resolution No. 2,454/26 Establish parameters for research, development, governance, auditing, monitoring, training, and responsible use of solutions that employ AI models, systems, and applications in healthcare. The goal is to promote technological development and efficiency in health services while protecting the fundamental rights of patients.

The governance of these solutions must respect the autonomy of physicians and healthcare organizations and allow for the adoption of technologies tailored to local contexts, as long as they meet audit, transparency, and monitoring standards commensurate with the risks involved.

The resolution also emphasizes that AI systems must be auditable and monitorable in a practical and accessible way, while preserving trade secrets. Transparency must be ensured by scientific metrics that demonstrate accuracy, effectiveness, and safety.

Doctor-patient relationship and duty to notify

The use of AI must not undermine the doctor-patient relationship, active listening, empathy, confidentiality, and respect for human dignity.

If AI models, systems, and applications are to be used as important adjuncts to treatment, they must provide patients with clear and accessible information. The resolution also prohibits the delegation of diagnosis, prognosis, and treatment decisions to AI without human intervention, preserving ultimate authority for physicians.

In particular, this regulation guarantees the patient’s right to refuse the use of such technology in treatment.

Doctor’s rights and obligations

The resolution sets out the rights and obligations of doctors in the use of AI. Below are some of the highlights.

right:

  • Use AI tools as an aid in medical practice, clinical decision-making, health management, scientific research, and continuing medical education.
  • Access to clear, transparent, and easy-to-understand information about the capabilities, purpose, limitations, risks, and degree of scientific evidence of the systems being used.
  • Refuse to use systems that lack proper scientific testing or proper regulatory certification.
  • Maintain professional autonomy and not be forced to uncritically follow automated recommendations.
  • Physicians will be protected from undue liability for failures caused solely by AI if they can demonstrate that they use the tools diligently, critically, and ethically.

Duties:

  • Use AI only as a support tool and be ultimately responsible for clinical, diagnostic, therapeutic, and prognostic decisions.
  • Apply critical judgment to the recommendations provided by AI.
  • Stay informed about the capabilities, limitations, risks, and known biases of the systems being used.
  • Only use solutions that comply with current ethical, technical, legal, and regulatory regulations.
  • Document the use of AI as a medical decision support tool in patient medical records.
  • Report significant failures or risks to competent authorities.

AI governance and accountability:

The new resolution requires healthcare organizations that develop or contract for their own AI solutions to implement internal governance procedures that focus on safety, quality, and ethical compliance.

CFM Resolution 2,454/26 also prohibits the communication of diagnostic, prognostic or therapeutic decisions to patients via AI systems, reinforcing the central role of human mediation in the doctor-patient relationship and the need to document the use of technology in the medical record.

Healthcare organizations implementing their own systems should establish an AI and telemedicine committee, reporting to the Department of Care Coordination and Technology, to ensure ethical and supervised use of these tools. Regional Medical Councils are responsible for overseeing and enforcing compliance within their jurisdictions.

In this context, CFM Resolution 2,454/26 introduces risk assessment and classification logic for AI systems (from low to unacceptable) as a core element to define the governance, supervision and control measures applicable to each solution. These factors are now part of the compliance and risk management challenges for organizations using or developing AI-based solutions in the healthcare sector.

Classification and classification of risks

Healthcare organizations developing or using AI solutions should conduct a preliminary assessment to determine the risk level of the tool, particularly considering the following factors:

  • Fundamental Rights and Potential Impact on Patient Health.
  • Usage context severity.
  • The complexity and degree of autonomy of the system.
  • Intended and potential purposes.
  • Level of human intervention in output. and
  • Amount and sensitivity of data used.

Based on these criteria, systems are classified as low risk, medium risk, high risk, or unacceptable risk. This classification must be disclosed to the user.

Privacy, transparency and health data

Data used for the development, training, validation, and implementation of AI systems must strictly comply with the Brazilian General Data Protection Law (LGPD – Law No. 13,709 of 2018) and specific healthcare information security standards.

CFM Resolution No. 2,454/26 requires the adoption of technical and administrative safeguards commensurate with the importance of the data processed, in line with market practice, to prevent the destruction, loss, alteration, unauthorized access and disclosure of confidential information. Data sharing should only occur when strictly necessary and supported by appropriate legal grounds.

Practical use of AI in the medical field requires:

  • Appropriate legal basis for processing health data.
  • Technical and organizational measures for information security. and
  • Transparency, traceability and accountability policies in the use of algorithms.

The resolution also strengthens a proactive governance approach that requires privacy, information security, and risk mitigation to be considered from design to implementation, with direct implications for contracts, operational workflows, and innovation strategies in this area.

Intellectual property, trade secrets and innovation

Another noteworthy point concerns the balance between regulatory transparency and protection of intellectual property assets.

CFM Resolution 2,454/26 stipulates that AI models, systems and applications must be auditable and monitorable, while also protecting the industrial and trade secrets involved in the development of these technologies.

This scenario requires special attention to the following:

  • Assigning ownership to solutions developed in clinical or research settings.
  • Contract structures for licensing, data sharing, and co-development.

The resolution emphasizes the importance of clear contractual arrangements that encourage collaborative and interoperable models of technology development and balance innovation, data sharing, and preservation of intangible assets.

conclusion

CFM Resolution No. 2,454/2026 marks a notable development in regulatory maturity regarding the use of AI in healthcare, moving the debate from whether AI should be used to how it should be managed.

The resolution imposes an integrated view that aligns medical ethics, innovation, and legal certainty by calling for clear governance structures, transparency, data protection, and preservation of intangible assets.

For organizations in the digital health ecosystem, it is both a challenge and an opportunity to turn these guidelines into a strategic advantage by rethinking internal structures, contracts, and innovation policies according to this new paradigm.

The development of this sector-specific regulation comes within a broader AI regulatory movement in Brazil, as evidenced by the ongoing debate on the general AI legal framework, such as Bill No. 2,338/2023 currently pending in the Brazilian Congress. Legal advances in this area can have a significant impact on the regulations already in place, including in the healthcare sector, highlighting the importance of a dynamic and forward-looking approach to compliance.

Demarest’s life science and, data, Privacy and technologyand Intellectual property, technology and innovation The team will explain further.



Source link