A Court Ruling Becomes Executive Rulemaking
On July 20, 2026, Brazil's Decrees No. 12.975/2026 and No. 12.976/2026 took full effect, closing a 60-day transition window that began when President Lula signed them on May 20 and they were published in the Diário Oficial da União the next day. Together they rewrite Decree 8.771/2016, the implementing regulation for the 2014 Marco Civil da Internet, and hand new oversight duties to the Autoridade Nacional de Proteção de Dados (ANPD), Brazil's data protection authority (Câmara dos Deputados legislative record).
The decrees are not writing on a blank slate. They implement a Supreme Federal Tribunal (STF) ruling from June 26, 2025 (Tema 987 of general repercussion), which found Article 19 of the Marco Civil — the rule shielding platforms from liability unless they defied a specific court order — partially and "progressively" unconstitutional. By an 8-3 vote, the STF held that platforms must now proactively remove, without waiting for a judge, content depicting a defined list of serious crimes: terrorism, anti-democratic acts, incitement to discrimination, child sexual abuse material, human trafficking, incitement to self-harm, and violence against women. For everything else — crucially, including crimes against honor such as defamation — the old notice-and-judicial-order regime under Article 19 still applies (ConJur summary of the STF ruling).
The Case for Acting
The strongest argument for this shift is straightforward: forcing victims of non-consensual intimate imagery, coordinated racist harassment, or terrorist recruitment content to wait for a court order before a platform will act is a real and documented harm, not a hypothetical one. Content moderation research and Brazilian courts alike have noted that judicial backlogs mean weeks can pass before a takedown order is issued, by which point viral content has already done its damage. A narrowly drawn proactive-removal duty for the worst, least-contestable categories of illegal content — CSAM, terrorism, human trafficking — is a defensible correction, not regulatory overreach.
What the Decrees Actually Require
Decree 12.975/2026 sets hard deadlines once a platform is notified: two hours to remove non-consensual intimate images, six hours for content amounting to crimes against women, and 24 hours for other cases of digital violence against women. It also imposes advertising due-diligence obligations — platforms must retain advertiser data and apply heightened scrutiny to content distributed via paid promotion or what the decree calls "artificial networks" of coordinated amplification, and liability is presumed where illegal content spreads through those channels. Decree 12.976/2026 layers on specific duties around gender-based digital violence: a ban on AI-generated non-consensual intimate imagery, promotion of the Ligue 180 hotline, and requirements to reduce the reach of coordinated harassment campaigns.
ANPD's new role is deliberately structural rather than editorial. Its own guidance states plainly that "não caberá à ANPD analisar isoladamente cada conteúdo ou publicação" — it will not review individual posts, adjudicate specific user conduct, or order account suspensions, and its jurisdiction excludes private messaging, email, and video-conferencing tools. Instead, the agency evaluates whether platforms' notice-and-removal systems, transparency reporting, and governance processes function at scale, treating 2026 as a guidance-and-consultation year before enforcement becomes permanent in 2027 (ANPD, Marco Civil da Internet guidance).
The Restraint That Deserves Credit
What the decrees do not do is more editorially significant than what they do. Despite years of pressure from parts of Brazil's political establishment to create a general disinformation-takedown mandate, the final text confines proactive removal duties to the seven STF-defined crime categories and explicitly states that an isolated instance of illegal content does not, by itself, establish the "systemic failure" that triggers platform liability. Disinformation and misinformation as such are notably absent from the regulated categories (Tech Policy Press analysis). Brazil's own multistakeholder internet governance body, CGI.br, endorsed this design, framing the systemic (not content-by-content) supervisory model as a safeguard against the oversight mechanism becoming a tool of selective censorship (CGI.br public note).
Where the Design Still Wobbles
Two weaknesses temper the praise. First, "systemic failure" remains an undefined standard, and platforms facing potential fines or suspension have every incentive to over-remove borderline content rather than test ANPD's tolerance — the classic chilling-effect risk of any intermediary-liability regime, however narrowly scoped on paper. Second, this entire framework rests on an executive decree implementing a court's interim rule, not a statute passed by Congress, which has not yet legislated on platform liability despite the STF inviting it to. A law firm advisory covering the rollout noted the decrees took effect exactly 60 days after publication, but the STF is still processing embargoes that could force revisions (Mondaq legal alert). Durable rules for a market of over 190 million internet users deserve the stability of primary legislation, not a regulatory scaffold that could shift again with the next court decision. Congress should codify the narrow, crime-specific scope Brazil has landed on — and resist the urge to bolt a disinformation mandate onto it later.