What Your Institution Must Be Able to Demonstrate From 26 August, and What to Require From Every AI Supplier
By Graziela Parente Peduti
Head of Global Regulatory Intelligence, NexTrial.ai
Dozens of articles have been published explaining what Resolução CFM nº 2.454/2026 says. Almost all of them restate the CFM press release.
Very few tell an institution what it needs to have in hand when someone asks. That is what this article covers.
Where you stand, with eighteen days left
The Resolution enters into force on 26 August 2026, 180 days after publication in the Diário Oficial da União on 27 February. Article 23 counts from publication, not from the 11 February adoption. Some coverage published 10 August, counting from the wrong date.
Article 21 is the point most coverage did not reach. The Resolution applies to AI systems already in development and already in use at the date it enters into force. There is no transition regime, no legacy carve out, no phase in. A tool deployed in 2024 is fully in scope.
Note that Article 22 admits a transition regime only for new duties that may arise from future CFM interpretations, which does not reach Article 21 or the norm as published.
So the question is not whether the institution will need to do this. It is what it can demonstrate on 26 August.
The four obligations that produce documents
One. A preliminary risk assessment, per system.
Article 12 requires any institution that develops or uses AI to carry out a preliminary risk assessment, weighing impact on fundamental rights and on health, the criticality of the context of use, the complexity and autonomy of the model, intended and potential purposes, the degree of human intervention, and the volume and sensitivity of the data involved. Article 13 sets four tiers and requires that the classification be disclosed to the user.
The Resolution names an unacceptable tier and does not define it. Annex II defines low, medium and high, with examples. Classify against the three that are defined and do not invent the fourth.
Two. A committee, where you run your own systems.
The sole paragraph of Article 14 requires institutions operating their own AI systems to establish an AI and Telemedicine Committee under medical coordination, subordinate to the technical directorate.
The Resolution requires that the committee exist. It does not say who sits on it, how often it meets, or what it produces.
A defensible operating model, at minimum: medical coordination named, the Technical Director as the accountable officer under Annex III, a standing agenda that owns the Article 12 classification and its periodic review, a register of systems in use with their tier and the evidence supplied by the vendor, and a documented review whenever a system is materially updated or retrained.
The committee is where the paper trail lives. If it produces nothing, the institution has satisfied the letter of Article 14 and nothing else.
Three. A record discipline your physicians actually follow.
Article 4, item V requires the physician to record in the patient's record the use of AI as decision support. A discipline that varies by professional is not a discipline, and the institution is the only party able to standardise it.
Fix a format. Identify the tool and version. Describe the output presented. Record the physician's independent assessment. Record the final decision, including where it diverged from the system output.
The divergences matter more than the agreements. Article 19 protects the physician who declines to follow the system's suggestion, and prohibits the institution from imposing targets or policies that subordinate medical conduct. The record is what evidences that the option to diverge was real.
Four. Access for the bodies entitled to it.
Annex III requires that audit and monitoring reports be available to oversight bodies, and names the Councils of Medicine, CONEP where research is involved, the Public Prosecutor's Office and patient rights entities.
This is the provision that connects a professional conduct resolution to the research system. And it is where the problem addressed next sits.
The norm points at a body that no longer holds those functions
Lei nº 14.874/2024 created the Sistema Nacional de Ética em Pesquisa com Seres Humanos, the Sinep. Decreto nº 12.651/2025, of 7 October 2025, established the Instância Nacional de Ética em Pesquisa, Inaep, linked to SCTICS at the Ministry of Health. Inaep succeeds CONEP. It issues research ethics norms, credentials and accredits the CEPs, supervises them, and sits as the appeal instance over their decisions. Its internal rules were published in the Diário Oficial da União on 6 April 2026.
Resolução CFM nº 2.454/2026 was adopted on 11 February 2026, four months after that Decree, and Annex III still names CONEP.
In practice, provide the access. Do not build a position on the argument that the named recipient no longer holds those functions. Article 22 reserves the resolution of interpretive doubts to CFM, and this is a strong candidate for one. Record your reading in the committee minutes and revisit it when CFM speaks.
The transition was contested. Twenty-six CONEP members resigned collectively in October 2025 and the Conselho Nacional de Saúde publicly opposed the new design. This article describes the system as it stands, without taking a position in that debate.
Two changes have immediate operational effect. The CEPs now divide into credenciado, for low and moderate risk, and acreditado, required for high risk, which covers new medicines, vaccines and procedures not previously used in humans. And the double review of special thematic areas by CONEP no longer exists, leaving the CEP alone to appraise, approve and follow the study.
If the institution runs high risk protocols, verify where the accredited capacity sits before planning a timeline. In a vote of its own collegiate body, covering the window from 5 November 2025 to 26 January 2026, Inaep recorded eight accredited CEPs, all in the state of São Paulo, having reviewed 874 protocols and amendments in the period, and flagged territorial concentration, risk of operational overload and excessive dependence on a restricted number of committees. The number may have changed since and should be confirmed with Inaep.
During the transition, the Conselho Nacional de Saúde resolutions remain in force until Inaep issues its own, to the extent they do not conflict with Lei nº 14.874/2024 or the Decree.
Who else asks you what
CRM. Physician conduct and institutional governance, under Article 15. Asks whether the decision stayed with the physician, whether the record demonstrates it, and whether the institution's governance exists in fact.
ANVISA. The product, where it qualifies as software as a medical device under RDC nº 657/2022. A separate regime with its own classification and regularisation path. Compliance with CFM says nothing about compliance with ANVISA, in either direction.
ANPD. The processing of personal health data under the LGPD. Note that the retificação of 5 March 2026 amended Article 16 to cite the Lei Geral de Proteção de Dados Pessoais explicitly, in place of the generic reference in the original text. Cite the corrected version.
What to require from every AI supplier
This is the part institutions have least prepared for.
Article 3 gives the physician the right to refuse systems that do not present adequate scientific validation or relevant regulatory certification, and the right to clear information on functioning, purposes, limitations, risks and level of scientific evidence. Annex III directs the institution to prefer open, auditable and interoperable solutions over closed ones, requires bias prevention and mitigation with stratified monitoring of outputs, and contemplates discontinuation where a severe bias cannot be corrected.
Read together, they form a set of requirements that can go into a procurement document today.
Ask for the scientific validation, with the population it was established on. Ask for the known limitations and biases, in writing. Ask for stratified performance across the subgroups your patient population actually contains. Ask for the regulatory status with ANVISA and, if the supplier maintains the regime does not apply, ask them to say why in writing. Ask what the system writes to a log and whether you can export it. Ask for the interoperability position and the APIs. Ask what happens on retraining and how you are notified.
And ask whether an auditor could reconstruct how a given output was produced.
Be precise about the limit of that argument. Annex III states a preference, not a prohibition. It is lawful to select a closed system. What does not hold up is selecting one and having no answer when the question is why.
Where this is going
PL 2338/2023, the general AI bill, passed the Senate in December 2024 and remains before the Chamber of Deputies. If enacted, it establishes a national governance system with sanctions well beyond what a professional council can impose, and it will reframe part of this Resolution.
ANVISA is revising RDC nº 657 to address adaptive and continuously learning systems. When that revision lands, it is what will place a change control mechanism on the product side alongside the conduct obligations the institution is implementing now.
Neither is a reason to wait. Article 21 already removed that option.
FAQ
Which institutions must create an AI and Telemedicine Committee?
Under the sole paragraph of Article 14, institutions operating their own AI systems must establish a committee under medical coordination, subordinate to the technical directorate. The Resolution does not define composition, meeting frequency or outputs, which leaves each institution to establish an operating model it can defend under inspection.
Who oversees the use of AI at a research centre in Brazil?
Four bodies, with different questions. The CRM oversees physician conduct and institutional governance under Article 15. The research ethics system reaches AI used in research, and since Decreto 12.651/2025 that means Inaep and the credentialed or accredited CEP. ANVISA regulates the product where it qualifies as software as a medical device. The ANPD reaches the processing of personal health data under the LGPD.
How should the use of AI be recorded in the patient record?
Article 4, item V requires that use of AI as decision support be recorded. A defensible entry identifies the tool and version, describes the output presented, records the physician's independent assessment, and records the final decision, including where it diverged from the system output. The Resolution prescribes no format, so the institution should fix one and apply it uniformly.
What is the unacceptable risk tier under Article 13?
Article 13 names four tiers, low, medium, high and unacceptable, and Annex II defines the first three with examples. The unacceptable tier is named and is not defined anywhere in the Resolution. Classify against the three defined tiers and do not write your own definition for the fourth and present it as the norm's.
Does an institution have to replace closed AI systems?
No. Annex III directs institutions to prefer open, auditable and interoperable solutions over closed ones. It is a stated preference, not a prohibition. A closed system remains lawful, and the practical consequence is that the institution carries a heavier burden of justifying the choice when questioned.