Brazil's National Data Protection Authority (ANPD) allowed São Paulo metro routing startup Synapse AI to continue testing in its artificial intelligence regulatory sandbox even though the company scored 45 points on a 100-point ethics framework whose stated floor for continuing is 50, according to a 38-page monitoring report on the pilot's second testing cycle. The same document shows a medical chatbot developer, Prevvine Tecnologia, falling from 89 points on its own self-assessment to 60 once external reviewers from the University of São Paulo applied the framework, and records that a data treatment Prevvine had described as anonymisation was reclassified as pseudonymisation, keeping Brazil's data protection law fully in force.
In Short
Brazil's data protection regulator is running a supervised test zone for three AI companies, and a new report shows how each did in the second round of checks. One company scored below the pass mark but was allowed to keep going on conditions, and another company's score dropped sharply when outside experts, not the company itself, did the grading. The report also shows the regulator refusing to accept a company's claim that its data was "anonymous", which matters for anyone who relies on that label to avoid privacy rules.
What the document is
The report is titled "2º Relatório Parcial de Monitoramento - Fase de Teste - Ciclo 2", the second partial monitoring report for the test phase of the ANPD's pilot project for a regulatory sandbox in artificial intelligence and data protection. It carries no publication date. The latest event it records is a results meeting with participant Metatext on July 31, 2026. Its cover lists the ANPD's director-president, Waldemar Gonçalves Ortunho Junior, directors Iagê Zendron Miola, Lorena Giuberti Coutinho and Miriam Wimmer, an eight-member Sandbox Commission and a three-person supervision team.
The technical work is carried out by the Centre for Artificial Intelligence and Machine Learning at the University of São Paulo (CIAAM/USP), coordinated by Cristina Godoy Bernardo de Oliveira. Two international consultants are named: João Pita Costa of IRCAI UNESCO and Vasilka Sancin of the University of Ljubljana, described in the document as a judge of the European Court of Human Rights. Five medical collaborators are listed for the large language model tests in health.
Three companies take part. Synapse AI develops Trajetto, described as a platform for managing passenger flows in rail transport using real-time data. Prevvine Tecnologia develops STAIDOC, which the report calls a medical AI ecosystem with large language models customised for the Brazilian context. Metatext develops Guardion.AI, a security platform designed to control and mitigate risks in autonomous agent and generative AI systems.
According to the ANPD, testing runs across six cycles. Each cycle has three phases: Phase A (pre-test), in which participants fill in technical sheets about their applications; Phase B (test), in which tailored tests run on the software the companies supply; and Phase C (post-test), in which individual opinions are issued that steer the next cycle.
The sandbox matters beyond Brazil's borders. In December 2025, the ANPD approved its 2026-2027 enforcement priorities, which included 20 inspections of AI systems, expanded beyond generative AI to recommendation engines and facial recognition. The sandbox report is the clearest public view so far of the test criteria the authority is building for those systems.
How the scoring works
The core of Phase B is what the report calls a General Framework built on UNESCO recommendations. It converts those recommendations into seven weighted axes worth 100 points in total:
- Axis 1 - centrality of human dignity and fundamental rights (20 points)
- Axis 2 - governance and clear accountability (15 points)
- Axis 3 - impact assessment (15 points)
- Axis 4 - fairness, non-discrimination and algorithmic bias (15 points)
- Axis 5 - transparency, explainability and communication (15 points)
- Axis 6 - technical security and robustness (10 points)
- Axis 7 - proportionality and necessity (10 points)
The method is iterative. In Cycle 1, each organisation assessed itself using its own evidence. From the following cycle onwards, a designated specialist re-examines those answers against documentation, interviews and the company's Sandbox Plan. The aggregate score is then mapped to four maturity bands tied to Technology Readiness Levels (TRL): basic research (TRL 1 to 3), development (TRL 4 to 6), demonstration (TRL 7 to 8) and production and operation (TRL 9).
Thresholds decide what happens next. According to the report, outcomes range "from full continuity in the pilot (≥ 85) to unfitness to proceed in the current format (< 50), passing through intermediate stages subject to action or mitigation plans." The quotations in this article are PPC Land's translations from the Portuguese original.
Synapse: 45 points, below the line, still in
Synapse's solution recommends to São Paulo metro users the best route through a station, taking account of the flow of people at a given time. The CIAAM/USP Cycle 2 report on it was delivered to the ANPD on June 1.
Its score did not move. "In Cycle 2, the score was equal to that of Cycle 1, that is, 45 points," the document states. Three axes scored nothing: impact assessment (Axis 3), fairness and bias (Axis 4), and technical security and robustness (Axis 6). The zero on Axis 6 had a mechanical cause. The adversarial test could not be completed because the data used by the algorithm did not pass through the test tunnel linking USP's infrastructure to Synapse's virtual private network. The security result for Cycle 2 was therefore recorded as inconclusive, and the test is to be repeated in Cycle 3 using a local AI that searches the data for passages that could allow individuals to be identified.
Some tests worked. Encryption and personal data protection protocols proved successful, according to the report. Tests on synthetic data generated by the company succeeded. The algorithm that detects the density of people in a space was tested on company data on an isolated USP machine, with positive results.
The consolidated technical opinion classed the inherent risk of Trajetto as high and the residual risk as medium. It identified risks around integration of system components, the confidentiality and authenticity of information, the possibility of re-identifying individuals by analysing movement patterns, and the sharing of coordinates and identifiers with external providers. The residual rating reflected controls such as a two-layer architecture, logical separation of databases, pseudonymisation, encryption through an outsourced key management service and the deletion of images after coordinates are extracted.
The opinion also listed what Synapse had not yet been able to show. Tests of the incident response plan, an inventory and technical audit of external integrations, proof of controls against information forgery, hardening of access to the integration API and the formal role of the data protection officer were all still outstanding. Then comes the decision. "For this reason, although the score was 45 points, while the minimum for continuity would be 50 points, the continuation of the tests received a favourable opinion with conditions," the report states. Pending measures are to be implemented and evidenced in later cycles "in order to reduce residual risks and avoid the suspension of activities."
The report does not explain how a score in the "unfit" band produced a favourable opinion, beyond attributing the gap partly to tests that could not be run. It is a notable exception. A framework that publishes a 50-point floor and then allows a participant below it to continue raises an obvious question about how binding the floor is.
Self-assessed maturity
Synapse's own Phase A sheets show little change between cycles. The core algorithms stayed at TRL 4. The company raised its rating for pseudonymisation and database security from TRL 5 to TRL 6. No new regulatory documents were supplied, so the A3 and A4 regulatory sheets were unchanged, and the ANPD asked for a list of 17 internal documents for Cycle 3. These include a Data Protection Impact Report (RIPD), a Human Rights Impact Assessment, an end-to-end data flow map, a matrix of legal bases per operation, an inventory of APIs and third parties, validation of where processing takes place, formal go/no-go criteria per cycle, a bias and fairness report and a layered explainability protocol.
The legal references examined for Synapse run to 16 instruments. Among them are the LGPD (Law 13.709/2018), the Marco Civil da Internet, the Consumer Defence Code, the Digital Statute of Children and Adolescents (Law 15.211/2025, known as ECA Digital) and its regulation, Decree 12.880/2026, and the still-pending AI bill, PL 2338/2023. Brazilian web and mobile accessibility standards ABNT NBR 17.225/2025 and 17.060/2022 also appear.
What the ANPD says it learned
From the regulator's side, the main result was a more precise characterisation of Trajetto as a recommendation system, "in which the final decision remains with the user or human operator", rather than as an imposed automated decision mechanism. That distinction, the report says, allowed a proportional assessment of transparency, explainability and governance duties.
The authority found no basis yet for a new rule. "Although Cycle 2 has not yet produced conclusive elements for proposing a new regulation," it identified preliminary lessons on evaluating geolocation-based recommendation systems, distinguishing anonymisation from pseudonymisation in mobility solutions, layered transparency, versioning of models, parameters, algorithms and pipelines, and minimum criteria for validating AI systems in controlled environments. It found insufficient evidence to judge market or competition effects, because the solution was still being validated.
Synapse, for its part, reported that the sandbox helped it set up an internal unit for evaluating and controlling AI products. The success of its Cycle 2 was classified as partial.
Prevvine: from 89 to 60 under outside review
Prevvine's STAIDOC is the most sensitive of the three cases because it processes health data. Its Cycle 2 report was also delivered on June 1, 2026.
The scoring gap is the sharpest number in the document. "According to the spreadsheet used, in Cycle 2, the company Prevvine reached a score of 60, lower than that of Cycle 01, of 89 points," the report says. The difference is explained by who did the scoring: in Cycle 1, the company assessed itself; in Cycle 2, the CIAAM/USP team did. The 29-point gap breaks down across four axes: 8 points on governance (Axis 2), 15 on impact assessment (Axis 3), 4 on transparency (Axis 5) and 2 on technical security (Axis 6). The 15-point drop on Axis 3 equals the axis's full weight. On that basis the reviewers considered the ethical risk "moderate to high, requiring mitigation before scaling."
Sixty points places Prevvine above the 50-point floor but well below the 85 needed for full continuity. The intermediate band, in the report's words, is subject to action or mitigation plans.
Anonymisation that was not
The most consequential finding for anyone handling personal data concerns terminology. "Although the company initially characterised the procedure applied as anonymisation, the assessment indicated that a theoretical possibility of re-identifying data subjects remained," the report states. "Accordingly, the mechanism was classified as pseudonymisation, with the consequent maintenance of the obligations provided for in the LGPD."
Prevvine accepted the point. The company "recognised that the procedure used should not be presented as absolute anonymisation" and said it would adjust its technical documentation and public communication, according to the report. That echoes the European position: the European Data Protection Board's 2025 guidelines confirmed that pseudonymised data remains personal data, and in a case PPC Land reported on October 3, Italy's Garante fined IQVIA €7 million over a database of about one million patients that the company had called anonymous. For ad tech vendors that market audience or measurement data as "anonymous" in Brazil, the sandbox is an early signal of where the ANPD draws the line.
The report also says the absence of proof for certain protections, "such as filtering controls and web application defence", demonstrated the importance of not limiting assessment to company statements.
Four critical elements at TRL 7
Prevvine identified four critical technological elements: the AI engine, an anonymisation layer, a system for checking external bibliographic references, and compliance and LGPD infrastructure. All four were rated TRL 7, "implemented and operational", in both cycles. The report attributes the lack of change at both Prevvine and Synapse partly to "the short time between one cycle and another."
The legal map is wider than for Synapse. It covers 16 instruments, including the electronic patient record law (Law 13.787/2018), the anti-discrimination law for people with HIV/AIDS (Law 12.984/2014), the Organic Health Law, Federal Council of Medicine resolutions on telemedicine and AI (CFM 2.314/2022 and CFM 2.454/2026) and ANVISA's RDC 657/2022 on software as a medical device.
That last instrument creates the overlap the report dwells on. If the chatbot only collects information and refers users to a professional, it may fall outside the medical device category while remaining fully subject to the LGPD. If it produces clinical recommendations, urgency classification or diagnostic or therapeutic output, health regulation may also apply. The report notes that a revision of RDC 657/2022 is expected to bring the two regimes closer, and it recommends that the ANPD seek formal coordination with ANS, ANVISA and the CFM.
The reviewers also questioned the legal basis. A consent form was presented for the chatbot, but the report says it still needs to be assessed whether consent "constitutes the most appropriate legal basis", and it recommends evaluating the health protection basis in Article 7, item VIII, of the LGPD.
The tests: 30 prompts per aspect
Phase B for Prevvine is structured as five tests. Test 1, a conversational model test, covers four aspects: validity and precision, safety, bias and equity, and privacy. Thirty conversation cases were recorded for each aspect, with approval criteria, an expected answer and a field for the reviewer. The prompt bank includes factual knowledge, false premises, outdated information, contextual adequacy, matched demographic pairs (gender, race and ethnicity, age, disability) and robustness. The underlying manual recommends 30 to 50 items per category, validated by two independent clinical reviewers, and tolerance criteria close to zero for direct risks to life, citing the World Health Organization.
Test 2 is red teaming, with attacks that include jailbreaks, fragmentation across several interactions, false clinical authority and urgency inducement. Test 3 is an expert clinical review that classes each answer as approved, moderate failure or serious failure. Test 4 checks three layers of explainability: technical for IT and audit, managerial for leadership and compliance, and accessible for patients and health professionals. Test 5 is a transparency matrix adapted from an article by Maranhão, Junquilho and Tasso (2023) on AI in Brazil's judiciary.
Not all of this has run yet. "In Cycle 2, the preparation of prompts and the structuring for the four tests that will take place in the following cycles began," the report says.
The risk methodology combined a 5 x 5 probability and impact matrix, a controls review against the LGPD and ISO/IEC 27001 and 27002, and a classification of each mitigation as implemented, in progress, planned or not proven. Inherent risk was rated high because health data is processed by an AI system; residual risk was rated medium. The reviewers credited controls including data minimisation, deletion of original data, auditable logs and verification of external references, and recommended continuation with conditions. The ANPD classified Prevvine's Cycle 2 success as partial. Responses from the system now carry a mandatory statement of human supervision, and a pre-access transparency notice was judged legible to doctors, according to the report.
Metatext: the slowest start
Metatext's case reads differently. The report describes it as a startup with a leaner structure, which required its Sandbox Plan and Discontinuity Plan to be rewritten. It will have fewer cycles and longer testing periods than the other two participants.
Guardion.AI sits between users, AI agents and third-party models as a privacy layer. The report says its data flow is structured in 13 main steps and was detailed "satisfactorily", because it ensures third-party models never see data in the clear. Because the solution was "by nature the most abstract of all", the CIAAM/USP team filled in the A1 and A2 sheets itself from company documents and had the company validate them. All of Metatext's documentation was in English, which the report links to its sector, cybersecurity for financial services.
Documents supplied in Phase A describe AES-256 and TLS 1.2+ encryption, least-privilege access with mandatory multi-factor authentication, scheduled key rotation, an incident response plan with notification to the ANPD within 72 hours, a data protection impact report, and automatic log expiry with irreversible anonymisation.
The reviewers found gaps. The company was asked how its "specialised fine-tuning" works, a cited policy was not sent, and "centralised dashboards" were mentioned without screenshots. Metatext listed the LGPD, CMN Resolution 4.893/2021, BCB Resolution 85 of April 8, 2021 and PL 2338/2023 as applicable law; the reviewers said the analysis must extend to rules from the securities regulator CVM and the insurance regulator SUSEP, and to new Central Bank rules published in the first half of 2026. On international transfers, the report records a contradiction: "the participant states that there is no international data transfer, but its website has extensive documentation on the subject."
Self-assessed maturity: infrastructure TRL 5, pseudonymisation TRL 5, the proprietary LLM TRL 7, all unchanged; feature attribution rose from TRL 1 to TRL 2. The A3 and A4 regulatory sheets were not reached in Cycle 2 and will appear in the next report.
Testing will use USP's HarpIA tools. Integration with HarpIA was completed in late May 2026. At a June 1, 2026 meeting between USP, the ANPD and Metatext, two interaction points were defined: adversarial attacks to test the quality of pseudonymisation, and a qualitative review of the alerts Guardion.AI sends to a client's security team. The second depends on a new API from Metatext and will focus on business-to-business explainability, with no adversarial attacks. The report frames this as a possible template for future sandboxes involving B2B cybersecurity and AI infrastructure startups. The question of how to test a product that protects data flowing to AI agents is not abstract for advertising: MLCommons published a draft taxonomy of 25 privacy risks posed by AI agents on October 1.
Inconsistencies in the document
Several details do not line up. The heading "4.2.4" is used twice, for both the ANPD's and Prevvine's views of Cycle 2. The research centre appears as CIAAM/USP throughout but as "CIAA/USP" and "CIAMM/USP" once each. The Synapse discontinuity section lists "evidências concretas de transferência ao titular" (concrete evidence of transfer to the data subject) where the parallel list elsewhere says transparency, which suggests a typo. Section 2 says Synapse and Prevvine feedback sessions were scheduled for June 22, 2026, while the Synapse report date is given only as "1 June" without a year. Synapse's Cycle 1 score is described as a self-assessment under the same method that produced Prevvine's 89, yet Synapse's score stayed at 45 after external review, a pattern the report does not discuss.
Why it matters for marketers
Brazil's data regulator has become noticeably more active this year. In August 2026, the ANPD recommended fines of R$ 153.7 million against ByteDance over TikTok's handling of minors' data. In May, its draft age verification guide barred the use of age verification data for behavioural advertising. In July, the authority published a 163-page technical study on deepfakes. The European Data Protection Board, meanwhile, has been evaluating whether Brazil's framework is adequate for EU data transfers.
The sandbox report adds three things to that picture. First, the gap between self-assessment and external review - 29 points in Prevvine's case - shows how the ANPD is likely to treat vendor self-certification: as an input, not as evidence. The report's conclusion makes that explicit, saying the continuity of solutions "cannot be based exclusively on self-declarations or on the formal existence of policies." Second, the reclassification of Prevvine's anonymisation as pseudonymisation aligns the ANPD with European regulators on the point that matters most to data-driven advertising: the label a company chooses does not decide whether the law applies. Third, the instruments being built here - a weighted 100-point scale, a 5 x 5 risk matrix, layered explainability, model and pipeline versioning - resemble scoring tools elsewhere, such as the fundamental rights impact tool released by Catalonia's APDCAT on October 7. Those criteria are the kind that later reappear in inspections.
The Synapse decision cuts the other way. A floor of 50 that does not stop a participant at 45 suggests the scores, for now, inform the conversation rather than end it. Whether that flexibility survives into enforcement is something the sandbox cannot answer yet.
What comes next
The report sets out ten priorities for Cycle 3. They include finishing tests that were not completed, repeating those affected by integration problems, submitting outstanding documentary and technical evidence, deepening adversarial, pseudonymisation, re-identification, security and continuity testing, consolidating data subject rights and incident response flows, versioning models, parameters, interfaces, APIs and data flows, and updating the TRL matrices. "Cycle 3 should therefore take on a more evidentiary and comparative character," the ANPD states, assessing whether changes "produced an effective reduction of risks, greater technological maturity and improved governance."
No dates for Cycle 3 are given. Three of the six cycles will have been completed once it ends, for Synapse and Prevvine at least; Metatext is on a separate, longer schedule.
Timeline
- August 14, 2018 - Brazil enacts the LGPD, Law 13.709/2018 (EDPB adequacy coverage)
- January 16, 2025 - EDPB releases pseudonymisation guidelines confirming pseudonymised data remains personal data (PPC Land)
- November 4, 2025 - EDPB adopts Opinion 28/2025 on Brazil's adequacy (PPC Land)
- December 22, 2025 - ANPD approves 2026-2027 enforcement priorities, including 20 AI system inspections (PPC Land)
- May 2026 - ANPD releases draft age verification guide barring use of age data for ad targeting (PPC Land)
- Up to May 22, 2026 - Metatext agrees to use the HarpIA Survey system; A1 and A2 sheets sent for validation
- May 22-29, 2026 - Metatext approves its A1 and A2 sheets; supplementary documents requested on May 29; HarpIA integration completed
- June 1, 2026 - CIAAM/USP Cycle 2 reports on Synapse and Prevvine delivered to the ANPD; USP, ANPD and Metatext define two test interaction points
- June 22, 2026 - Scheduled date for Synapse and Prevvine Cycle 2 feedback sessions
- July 29, 2026 - ANPD publishes 163-page deepfakes study (PPC Land)
- July 31, 2026 - Cycle 2 results meeting with Metatext, CIAAM/USP and the ANPD Sandbox Commission
- August 24, 2026 - ANPD investigation report recommends R$ 153.7 million in fines against ByteDance (PPC Land)
- October 1, 2026 - MLCommons releases draft Agent Privacy Risk Taxonomy with 25 risk vectors (PPC Land)
- October 3, 2026 - PPC Land reports Italy's Garante fine of €7 million against IQVIA over "anonymous" patient data (PPC Land)
- October 7, 2026 - APDCAT releases free AI fundamental rights impact scoring tool (PPC Land)
- Undated - ANPD second partial monitoring report on sandbox Cycle 2 (38 pages); Cycle 3 to follow
Related PPC Land coverage
- Brazil's data watchdog adds child protection to enforcement agenda - the ANPD's 2026-2027 priorities, including 20 inspections of AI systems.
- Brazil's ANPD releases draft age verification guide open to public input - a 49-page draft guide implementing ECA Digital and Decree 12.880/2026.
- ByteDance faces R$ 153.7 million in fines over TikTok children's data - the ANPD's recommended fines over five LGPD breaches.
- Brazil bans paid ads for deepfakes in final 72 hours before elections - the ANPD's deepfakes study and the electoral court's paid boosting ban.
- European data protection board evaluates Brazil adequacy decision - the EDPB's 145-page opinion on Brazil's data protection framework.
- Brazil blocks Meta's WhatsApp AI chatbot ban in surprise move - CADE's interim measures against Meta's third-party chatbot policy.
- European data regulators release updated pseudonymisation guidelines for 2025 - EDPB guidance that pseudonymised data stays personal data.
- Italy fines IQVIA €7M over health data of 1M patients it called anonymous - a European case where an anonymisation claim failed.
- APDCAT releases free tool scoring AI impact on fundamental rights - Catalonia's scoring tool for AI Act Article 27 assessments.
- MLCommons catalogues 25 privacy risks posed by AI agents - a draft taxonomy of how AI agents can mishandle personal data.
- Netherlands regulatory sandbox to launch by 2026 as EU clarifies AI rules - the Dutch timetable for a national AI regulatory sandbox.
Summary
Who: Brazil's National Data Protection Authority (ANPD) and its Sandbox Commission, the CIAAM/USP research team, and three participants: Synapse AI (Trajetto, metro route recommendations), Prevvine Tecnologia (STAIDOC, medical LLM chatbot) and Metatext (Guardion.AI, security layer for AI agents).
What: The second partial monitoring report on Cycle 2 of the ANPD's AI and data protection regulatory sandbox. Synapse scored 45 of 100 on a UNESCO-based framework with a 50-point floor and was allowed to continue with conditions; Prevvine fell from a self-assessed 89 to 60 under external review, and its anonymisation was reclassified as pseudonymisation; Metatext's testing was restructured onto a longer schedule.
When: The report is undated. It covers activity from May 2026 through a July 31, 2026 results meeting, with Cycle 1 and 2 reports delivered to the ANPD on June 1, 2026. Cycle 3 is next.
Where: Brazil, with testing run on University of São Paulo infrastructure in São Paulo and coordination in Brasília.
Why: The sandbox is producing the criteria the ANPD will use to supervise AI systems that process personal data, including its stated enforcement plan of 20 AI inspections. The findings show how the authority treats self-declared compliance and "anonymous" data claims, both central to data-driven advertising.
Discussion