Blog/ Healthcare regulations
AI use in medicine: what the CFM resolution says
CFM Resolution 2,454/2026 seeks to regulate the use of artificial intelligence in medical practice, ensuring the physician’s final authority, patient safety and the ethical use of AI as a support tool in healthcare institutions
- By
- Rivio, Editorial team
- Published
- Reading time
- 4 minutes
Artificial intelligence has been used in medicine in Brazil for some years now, but the regulatory framework is still taking shape. An important step in this process was Resolution No. 2,454/2026 of the Federal Council of Medicine (CFM) , published on February 11, 2026.
In this article, learn the main points of the resolution, its impact on medical practice and the challenges to making AI use universal in healthcare.
What does CFM Resolution No. 2,454/2026 say?
The resolution regulates the use of artificial intelligence (AI) in medicine in areas such as research, development, governance, auditing, professional training and the responsible use of technological systems and resources.
See the resolution’s main points for healthcare management and clinical practice in Brazil.
Definitions, foundations and general principles
The fundamental principle of the resolution is that, regardless of technological sophistication, final responsibility and authority over clinical judgment remain exclusively with the physician.
AI is strictly defined as a support tool, which cannot replace human clinical judgment.
Transparency in the use of AI is another highlighted point. Reports and records must disclose the use of these models, systems and applications in an accessible way and in plain language, ensuring that patients, physicians and managers understand when and how the technology is being used.
Healthcare institutions must also prioritize the cooperative development of AI models, systems and applications, with the goal of promoting interoperability between technology solutions, without prejudice to medical secrecy and the confidentiality of information.
Physicians’ rights and duties when using AI
Physicians have the right (and also the ethical duty) to disagree with artificial intelligence suggestions when they believe those suggestions are not the best for the patient’s specific case.
They must also have access to clear, transparent and understandable information about how the AI systems they use work, as well as their purposes, limitations, risks and level of scientific evidence.
In the event of failures attributable exclusively to artificial intelligence systems, the physician should not be held liable, provided that the diligent, critical and ethical use of these tools is proven.
Among the professional duties established by the resolution, one stands out: the physician’s obligation to stay up to date on the capabilities, limitations, risks and known biases of the AI systems used in clinical practice.
In addition, professionals must use only AI systems that meet the ethical, technical, legal and regulatory standards in force in the country, and record in the patient’s medical record the use of AI systems to support medical decisions.
Another fundamental point of the regulation is preserving the physician-patient relationship. Physicians must ensure that the use of artificial intelligence does not compromise attentive listening, empathy, the confidentiality of information and respect for human dignity.
Governance of AI solutions in medicine
The resolution also sets guidelines for the institutional governance of artificial intelligence solutions.
The medical institution (or professional) that develops, contracts or implements AI models, systems and applications must establish internal governance processes capable of ensuring safety, quality and ethical compliance.
Healthcare institutions that adopt their own AI systems must create an Artificial Intelligence and Telemedicine Committee, responsible for monitoring the use of the technology and ensuring the ethical and regulatory compliance of its applications.
Oversight and enforcement of compliance with the resolution will be carried out by the Regional Councils of Medicine (CRMs) of the respective jurisdiction.
Personal data protection
The entire cycle of artificial intelligence use in medicine, from model training to implementation and use in clinical practice, must strictly comply with the General Personal Data Protection Law (LGPD) and health information security standards.
Institutions must ensure effective protection against loss, alteration, unauthorized access or leaks of sensitive data.
To that end, it becomes mandatory to adopt technical and administrative measures appropriate to the sensitivity of the information processed, including access controls, traceability and information security policies.
When the resolution takes effect
The resolution will take effect 180 days after its publication date, a period intended for institutions and professionals to adapt to the new regulatory requirements.
AI in hospital management: efficiency with ethics
Although the resolution focuses on the medical act, its guidelines directly affect hospital management.
Artificial intelligence systems used in triage, test prioritization, clinical risk analysis or discharge prediction must be implemented under the governance and supervision of medical technical directors, ensuring ethical compliance and patient safety.
The operational efficiency that technology provides cannot override patient safety or professional responsibility.
By positioning artificial intelligence as a tool that supports (rather than replaces) human judgment, Resolution No. 2,454/2026 preserves an essential principle of medicine: patient-centered care and the ethical responsibility of the healthcare professional.
For managers and professionals, the next step will be to invest in constant upskilling and in rigorous technical curation of the technologies that will be brought into the hospital environment.


