Compliance And Esg
October 02, 2026
Ethics in Artificial Intelligence and ESG in Brazilian corporate practices
Ethics in Artificial Intelligence and ESG in Brazilian Corporate Practices
Fabiane Baltruchaitis Figueiredo; João Valsecchi Ribeiro de Souza
DOI: 10.22167/2675-6528-202602881
Article derived from a Final Course Work (TCC), with content based on the student’s original work and adapted to the editorial format of the E&S Magazine with the support of the ResumeAI tool, an artificial intelligence solution developed by the Pecege Institute for textual synthesis and organization.
Abstract
The growing adoption of artificial intelligence in the corporate environment has amplified ethical, social, and environmental challenges, demanding the incorporation of practices aligned with governance and sustainability. A lack of clarity was identified regarding the maturity level of artificial intelligence ethical practices in publicly traded Brazilian companies. The study analyzed, in an intentional sample of eight publicly traded Brazilian companies, how artificial intelligence ethical governance guidelines and practices are evidenced in public documents and compared their level of documentary maturity. An exploratory and descriptive research was conducted, with a predominantly qualitative approach and a complementary quantitative component, using a multiple case study design. The methodology was based on the comparative analysis of institutional reports and corporate policies of eight companies listed on B3, from various economic sectors. The data were systematized through a comparative matrix, based on international theoretical and normative references on artificial intelligence ethics. The results showed a heterogeneous adoption of ethical practices among sectors, with greater maturity in organizations under greater regulatory pressure. Gaps persisted in dimensions such as transparency, explainability, and mitigation of algorithmic biases. The observed initiatives were largely reactive, indicating a dissociation between technological advancement and ethical governance. The analysis demonstrated that artificial intelligence ethics remains in a consolidation process in the Brazilian corporate context, demanding more integrated, proactive approaches aligned with ESG principles.
Keywords: Compliance; ESG; Ethics in artificial intelligence; Technological governance; Responsible AI.
1. Introduction
The growing adoption of Artificial Intelligence (AI) technologies has transformed the existing social order, improving business processes in various areas and promoting innovation, efficiency gains, and competitiveness. Data from the 2024 Semestral Innovation Survey (Pintec Semestral) by the Brazilian Institute of Geography and Statistics (IBGE) indicated that the technology whose use grew the most was artificial intelligence, with an increase of 16.9% compared to 2022, and that a significant percentage, 41.9%, of the 10,167 companies investigated used AI in their activities.
However, the intensive use of these technologies also generates social, ethical, and environmental externalities, which go beyond financial results. Among some of these consequences, as observed by Huang et al. (2023), are: algorithmic biases, impact on the number of available jobs in the labor market due to the replacement of human labor, lack of transparency in decision-making processes, risks related to confidentiality, privacy, and data security, increased energy consumption and carbon footprint of computational systems, as well as impacts on human physical and mental health and the violation of copyrights, human rights, and the rule of law itself, when viewed from the perspective of the legal system. These side effects represent real risks to corporate sustainability practices, pressuring organizations to incorporate governance, transparency, and risk mitigation mechanisms aligned with Compliance and ESG (Environmental, Social and Governance) frameworks.
With the intensification of pressures from investors, consumers, regulatory bodies, and civil society, organizations increasingly need to align their technological development with ethical values, human rights, and environmental goals. However, many companies still have gaps in their management programs for the non-financial impacts of AI, whether due to the absence of technological compliance structures or the lack of clear indicators reflecting the social and environmental effects of their digital operations. Thus, the research problem identified was the lack of clarity regarding the maturity level of ethical practices related to artificial intelligence in Brazilian publicly traded companies.
Thus, understanding the risks arising from the business use of AI that can affect companies’ ESG indicators is essential for the advancement of responsible and sustainable corporate practices, as the adoption of ethical practices and adherence to ESG guidelines can mitigate these risks, improving the response of organizations seeking to balance innovation, sustainability, and business ethics to these challenges and contributing to the strengthening of a model in ethical governance. The relevance of this study is supported both by the timeliness of the topic and by the emergent and still little-consolidated nature of applied research that addresses the connection between AI, ESG, and Compliance. By addressing this intersection, it is intended to support companies in formulating responsible, sustainable, and transparent corporate policies, especially regarding ethics in Artificial Intelligence. For the purposes of this study, AI governance is understood as the set of formal and informal mechanisms that guide the development, implementation, and monitoring of algorithmic systems, according to the literature on AI ethics and technological governance.
In this context, the study aimed to analyze, in an intentional sample of eight publicly traded Brazilian companies, how ethical artificial intelligence governance guidelines and practices are evidenced in public documents and to compare the degree of documentary maturity of these practices among the selected organizations and sectors.
2. Material and Methods
This study was characterized as an exploratory and descriptive research, with a multiple case study design and applied character. The methodological approach adopted was predominantly qualitative, based on documentary analysis and content interpretation, seeking to identify contextual evidence. A complementary quantitative component was employed to synthesize frequencies and compare patterns, resulting from the ordinal coding of evidence in a comparative matrix.
The unit of analysis consisted of the ethical artificial intelligence governance guidelines and practices, as evidenced in public corporate documents. The sample was intentional and comprised eight publicly traded Brazilian companies, listed on the B3 and belonging to various economic sectors. The selection of these organizations considered criteria such as size, economic relevance, sectoral diversity, and maturity in the use of artificial intelligence, in addition to the publication of annual reports and the adoption of structured practices for governance, risk management, and compliance.
The inclusion criteria for the documentary corpus were: (i) to be an official and publicly accessible document; (ii) to be the current institutional publication or the most recent one located until April 2026; (iii) to present explicit content about AI or documents related to governance, risks, data, human rights, sustainability, security, ethics, or compliance potentially related to the framework’s dimensions; and (iv) to allow comparison between companies. Promotional materials without normative or governance content, third-party news, and documents with no identifiable institutional authorship were excluded.
The public corporate documents analyzed included integrated reports, sustainability reports, information and cyber security policies, artificial intelligence risk management policies, data ethics guidance documents, codes of ethics and conduct, global human rights policies, and human rights commitment statements. Specifically, documents from B3, Bradesco, Itaú Unibanco, TOTVS, Vale, Petrobras, Magazine Luiza, and Natura &Co were examined, all available for consultation until April 2026.
Data collection was carried out by systematically reading the institutional documents of the eight selected companies. Evidence associated with each dimension of the proposed framework, which served as the basis for the analysis, was identified. The process involved searching for explicit references to artificial intelligence, algorithmic systems, or automated decisions, as well as describing applicable mechanisms, rules, responsibilities, controls, or procedures.
For the comparative analysis, a matrix based on international theoretical and normative references on ethics in artificial intelligence was used. This matrix was inspired by the panorama outlined by Huang et al. (2023) and the guidelines of the “Recommendation on the Ethics of Artificial Intelligence” and “Brazil: artificial intelligence ethics readiness assessment report”, both from UNESCO. The systematization of the dimensions aimed to ensure conceptual clarity and consistency in data interpretation.
The data analysis technique involved the comparative qualitative categorization of evidence. Each dimension was evaluated and classified as “Present” when the document made explicit reference to AI and described at least one applicable mechanism, rule, responsibility, control, or procedure. The “Partial” classification was assigned when the evidence appeared in a generic or indirect way, without explicit linkage to AI, or when AI was mentioned without detailing an operational mechanism. It was classified as “Absent” when no relevant documentary evidence for the dimension was found in the analyzed corpus. This ordinal classification aided in comparing patterns across companies and dimensions.
In the interpretation of the data, a distinction was made between direct evidence of ethical AI governance, which expressly mentions AI, algorithms, models, or automated decisions and establishes principles, responsibilities, controls, supervision, risk assessment, or accountability mechanisms applicable to these systems. Contextual evidence corresponded to general ESG practices, human rights, diversity, privacy, information security, sustainability, and compliance that, although they could support responsible governance, did not, in isolation, demonstrate their direct application to AI. This distinction was crucial to avoid erroneous inferences about AI ethics maturity.
During the study preparation phase, ChatGPT was used as a support tool in the search for papers for the literature review, in the alignment of the methodology for data collection and analysis, and in the systematization of the consulted institutional reports and policies. The author reviewed and edited the generated content, assuming full responsibility for the published material.
The structuring of the analyzed dimensions in the comparative matrix was essential to provide theoretical and methodological support to the study. This approach sought to reduce ambiguities, standardize evaluation criteria, and strengthen the validity of the proposed framework, contributing to methodological transparency and research replicability. The dimensions were defined based on the literature on AI ethics and technological governance.
3. Results and Discussion
The analysis of public documents from eight Brazilian publicly traded companies revealed a heterogeneous panorama regarding the maturity of ethical practices related to artificial intelligence. The findings indicated that the formalization of ethical guidelines and governance mechanisms for AI is in different stages of development across economic sectors, reflecting the complexity of the subject and the diversity of regulatory and market pressures. This variation suggests that the incorporation of ethics in AI is still in a consolidation process within the Brazilian corporate environment, as pointed out by the literature (Huang et al., 2023).
The results showed that the adoption of formal governance, control, and risk mitigation mechanisms associated with AI occurred unevenly across sectors. Companies in more regulated segments with greater technological dependence, such as banking and technology, demonstrated greater progress. In contrast, organizations in sectors like mining, energy, and consumer goods, despite strong ESG performance, presented less explicit detail on AI ethics, addressing it more indirectly within broader corporate policies.
For the interpretation of the results, it was fundamental to distinguish between direct and contextual evidence. Direct evidence refers to explicit mentions of AI, algorithms, or automated decisions, accompanied by specific principles, responsibilities, or controls. Contextual evidence, on the other hand, corresponds to general ESG practices, human rights, privacy, or information security that, although relevant, do not demonstrate their direct application to AI. This distinction was crucial to avoid overestimating ethical maturity in AI based solely on robust corporate ESG or data protection frameworks.
In general, the dimensions of privacy, data protection and security, as well as risk management and impact assessment, showed the greatest adherence among the analyzed companies. This scenario can be attributed to the influence of regulatory frameworks such as the General Data Protection Law (LGPD) and the consolidation of risk management practices within corporate governance. However, more complex dimensions, such as algorithmic transparency and fairness, remained at intermediate or incipient levels, indicating gaps in the operationalization of abstract ethical principles into technical and measurable practices.
Governance, accountability and regulation
The governance, accountability, and regulation dimension has proven to be one of the most developed, especially in financial institutions and technology companies. The presence of formal control and accountability structures was observed, notably Bradesco, which has a specific AI Risk Management Policy, and Itaú Unibanco, with its Data Ethics Guidelines Guide. These initiatives reflect an emerging concern with specific AI governance, driven by the strong regulation of the financial system and the criticality of automated decisions in its operations.
The governance of artificial intelligence, according to Floridi et al. (2018), requires not only regulatory compliance but also internal mechanisms that ensure supervision and auditing throughout the entire lifecycle of the systems. Although financial and technology companies such as TOTVS and B3 present a “Present” level in this dimension, others like Vale, Petrobras, Magazine Luiza, and Natura &Co were classified as “Partial”. This indicates that, in the latter, governance guidelines are more generic, without explicit and detailed linkage to AI, which may limit the effectiveness of accountability.
Transparency, explainability, and contestability
Transparency, explainability, and contestability in artificial intelligence systems showed intermediate levels of development in most companies. Only Itaú, Bradesco, TOTVS, B3, and Magazine Luiza were classified as “Partial”, while Vale, Petrobras, and Natura &Co were considered “Absent”. Although some companies, such as B3 and TOTVS, have shown progress in communicating their processes and control mechanisms, most organizations have not yet provided sufficient detail on the functioning of automated systems.
The absence of mechanisms that allow users or stakeholders to contest algorithmic decisions is a significant gap. Explainability, according to Doshi-Velez and Kim (2017), is fundamental to ensure trust and allow for critical evaluation of systems, and its indirect mention in institutional reports has not translated into clear evidence of operationalization. This scenario suggests that companies still face challenges in translating abstract principles of transparency into technical and measurable practices, which can compromise the legitimacy and social acceptance of AI.
Privacy, data protection and security
Privacy, data protection, and security were the dimensions with the highest adherence among companies, with Itaú, Bradesco, TOTVS, B3, Magazine Luiza, and Natura &Co classified as “Present”. Vale and Petrobras were classified as “Partial”. This result reflects the strong influence of regulatory frameworks such as the General Data Protection Law (LGPD) and the consolidation of risk management practices within corporate governance. Financial institutions, in particular, demonstrated robust information security and privacy policies, evidencing adherence to legal and regulatory requirements.
The protection of privacy, according to Nissenbaum (2010), must be understood within the concept of contextual integrity, respecting social expectations about the appropriate use of information. The broad identification of these practices, especially in organizational contexts that depend intensively on personal data, indicates considerable maturity in managing these aspects. However, the “Partial” classification for some companies suggests that, although general policies exist, the explicit and detailed link to AI can still be improved.
Justice, equity, and non-discrimination
The dimension of justice, equity, and non-discrimination showed more incipient development, with most companies (Itaú, Bradesco, TOTVS, B3, Petrobras, Magazine Luiza) classified as “Partial”. Only Vale and Natura &Co were classified as “Present”, mainly through diversity and inclusion policies. The findings corroborated the difficulty organizations have in translating abstract principles of algorithmic equity into concrete technical mechanisms, as highlighted by Barocas, Hardt, and Narayanan (2019).
The absence of clear evidence on the mitigation of algorithmic biases suggests that this dimension has not yet been fully incorporated into business practices. AI systems can reproduce or amplify existing inequalities when trained with biased historical data, making the adoption of bias detection and mitigation mechanisms essential. The generic approach, without explicit linkage to AI, in many of the observed policies, indicates that the operationalization of these principles is still a significant challenge in the Brazilian corporate context.
Human supervision and autonomy
Human oversight and autonomy was identified as “Present” in Itaú, Bradesco, and B3, and “Partial” in TOTVS, Petrobras, and Magazine Luiza, while Vale and Natura &Co were classified as “Absent”. The presence of human control mechanisms over automated systems was more evident in financial institutions, where the criticality of decisions demands greater human intervention. This principle is associated with the concept of “human-in-the-loop”, in which humans maintain an active role in validating and reviewing automated decisions.
AI autonomy, as proposed by the European Commission (2019), should be limited by safeguards that prevent fully independent decisions in sensitive contexts. The identification of such mechanisms in financial companies and B3 demonstrates a concern for security and responsibility. However, the “Partial” classification for other companies indicates that, although general controls exist, the specificity of human supervision regarding AI systems is not yet fully formalized or detailed in their public documents.
Social and work impacts
The dimension of social and labor impacts showed a mixed distribution, with Vale, Magazine Luiza, and Natura &Co classified as “Present”, and Itaú, Bradesco, TOTVS, B3, and Petrobras as “Partial”. Professional requalification and digital inclusion initiatives were highlighted, especially in companies like Magazine Luiza, which intensively use AI in processes related to customer experience and logistics. The adoption of AI in the organizational environment generates significant impacts on the labor market, requiring adaptation and professional requalification.
Brynjolfsson and McAfee (2014) argue that automation can increase productivity, but also deepen inequalities if not accompanied by adequate policies. The “Partial” classification for most companies suggests that, although there is recognition of the social impacts, the formalization of specific guidelines to mitigate these effects in relation to AI is still incipient. The presence in Vale, Magazine Luiza, and Natura &Co may be linked to their broader corporate social responsibility agendas.
Sustainability and environmental impacts
Sustainability and environmental impacts was a dimension with greater adherence in companies with strong ESG performance, such as Vale, Petrobras, and Natura &Co, classified as “Present”. The other companies (Itaú, Bradesco, TOTVS, B3, Magazine Luiza) were classified as “Partial”. However, even in companies classified as “Present”, the explicit connection between sustainability practices and the use of artificial intelligence was not widely detailed in the analyzed documents. This result suggests an opportunity for integration between agendas that are still treated separately.
Studies such as those by Strubell, Ganesh, and McCallum (2019) show that large-scale AI models can have significant environmental footprints, demanding that AI ethics incorporate environmental concerns. The “Partial” classification for most companies indicates that, although there is a commitment to sustainability, the specificity of how AI is managed to minimize its environmental impact is not yet fully formalized. The proactive integration of AI ethics with ESG principles is a way to promote efficient resource use and the development of more sustainable technologies.
Risk management and impact assessment
Risk management and impact assessment was a widely evidenced dimension, with Itaú, Bradesco, TOTVS, B3, Vale, and Petrobras classified as “Present”. Magazine Luiza and Natura &Co were classified as “Partial”. This result highlights the importance attributed to the identification, analysis, and mitigation of potential adverse effects arising from the use of automated systems. Impact assessment, according to the OECD framework (2019), is an essential tool for anticipating consequences and guiding responsible decisions, being a central element in compliance contexts.
The strong adherence in this dimension, especially in financial institutions and regulated companies, reflects the criticality of their operations and the need to prevent operational and reputational risks. The existence of policies and procedures to manage risks, even if more broadly in some companies, demonstrates a level of maturity in corporate governance. However, the “Partial” classification for Magazine Luiza and Natura &Co suggests that, although risk management is an established practice, its specific application to the impacts of AI may still lack greater documentary detail.
Trust, perception, and social acceptance
The dimension of trust, perception, and social acceptance showed uniformly “Partial” development in all eight companies analyzed. Institutional communication focused on reputation and transparency was observed, but without sufficient detail on how trust in AI systems is built and maintained. Social acceptance of AI depends not only on its technical effectiveness but also on the transparency, responsibility, and communication of organizations, according to Mayer, Davis, and Schoorman (1995).
The absence of structured and explicit initiatives in this area may compromise the legitimacy of AI use in the long term, especially in contexts of growing public concern about privacy, discrimination, and automation. The “Partial” classification for all companies indicates that, although there is a recognition of the importance of reputation and communication, the formalization of specific strategies to foster trust and social acceptance of AI is still a challenge to be overcome, demanding more proactive and integrated approaches.
Education, training, and access to AI
Education, training, and access to AI presented a mixed scenario, with TOTVS classified as “Present”, Itaú, Bradesco, B3, Petrobras, and Magazine Luiza as “Partial”, and Vale and Natura &Co as “Absent”. Initiatives for internal training in technology and innovation were identified, especially at TOTVS, which develops digital solutions. This dimension involves the need to prepare individuals and organizations to understand, use, and critically interact with AI systems, including technical training and the development of ethical and analytical skills.
The democratization of access to AI is fundamental to ensure its equitable and sustainable use, according to UNESCO (2021). The “Partial” classification for most companies suggests that, although there are investments in technological training, the specificity of education in AI ethics and the promotion of equitable access are not yet fully formalized. The absence in Vale and Natura &Co may indicate that, for these companies, AI is not yet a central focus in their training and development strategies, or that such initiatives are not publicly disclosed.
Human rights and dignity
The dimension of human rights and dignity was classified as “Present” in Bradesco, Vale, and Natura &Co, and “Partial” in Itaú, TOTVS, B3, Petrobras, and Magazine Luiza. The practice was identified through documentary evidence in corporate policies, reports, and codes of conduct. In the case of Bradesco, the adoption of a Corporate Human Rights Policy and a Diversity, Equity, and Inclusion Policy demonstrated institutional alignment with fundamental principles of dignity, equality, and respect for individuals.
The relationship between artificial intelligence and human rights includes the guarantee that automated systems respect fundamental principles, making it necessary to incorporate them from the design stage (“by design”), as stated by the UN (2020). The “Partial” classification for most companies indicates that, although there is a general commitment to human rights, the explicit and detailed linkage of these principles to AI governance is still a challenge. Companies classified as “Present” have shown progress in formalizing these guidelines in their public documents.
Sovereignty and technological development
The dimension of sovereignty and technological development showed the lowest level of adherence, with only TOTVS classified as “Present”, while all other seven companies were classified as “Absent”. Technological sovereignty refers to an organization’s ability to develop, control, and use strategic technologies, such as artificial intelligence, autonomously and aligned with its interests. This dimension involves geopolitical, economic, and regulatory issues, including dependence on external suppliers and control over data and infrastructure.
TOTVS’s presence in this dimension can be explained by its role as a technology company, developing and providing digital solutions, which naturally positions it in a role of greater control over its technologies. Its absence in all other companies suggests that the discussion about technological sovereignty in relation to AI is still incipient in the Brazilian corporate context, or that such concerns are not formalized in public documents. According to Roberts (2024), sovereign technological development is essential to ensure security and competitiveness, and the lack of documentary evidence indicates a significant gap.
In summary, the research results revealed that the incorporation of ethics in artificial intelligence in the Brazilian corporate context is heterogeneous and still in the consolidation phase. Companies in more regulated and data-intensive sectors, such as finance, demonstrated greater maturity in dimensions such as governance, risk management, and data protection, driven by regulatory pressures and the criticality of their operations. However, significant gaps persist in more complex dimensions, such as transparency, explainability, algorithmic bias mitigation, and technological sovereignty, indicating the need for more integrated and proactive approaches. The analysis reinforces that, although there is growing recognition of the importance of AI ethics, the translation of abstract principles into operational and measurable practices still represents a challenge for organizations, demanding the formulation of specific and transparent policies that align technological innovation with ethical responsibility and sustainability.
4. Conclusion
This study sought to analyze how ethical artificial intelligence governance guidelines and practices are evidenced in public documents from eight publicly traded Brazilian companies, comparing the degree of documentary maturity of these practices. Heterogeneous adoption of ethical practices was observed among sectors, with greater maturity in organizations subjected to more intense regulatory pressures, such as those in the financial and technology segments. It was observed that dimensions such as privacy, data protection, security, risk management, and impact assessment showed greater formalization. However, significant gaps persisted in more complex aspects, such as transparency, explainability, algorithmic bias mitigation, and technological sovereignty, indicating that artificial intelligence ethics is still in a process of consolidation within the Brazilian corporate context. The main contribution of this work lies in the proposal of a consolidated framework that integrates various ethical dimensions of corporate artificial intelligence use, offering a diagnostic tool for compliance, risk, audit, privacy, sustainability, and technology areas, and signaling the importance of aligning technological innovation with ethical responsibility.
As a main limitation, the exclusive use of public documents was highlighted, which may not fully reflect the internal practices of the analyzed organizations, in addition to the lack of standardization in the disclosure of information about artificial intelligence, which hindered more precise comparisons. It is suggested that future studies complement the proposed framework with interviews, control tests, indicators, and operational evidence, allowing for verification of the effective incorporation of formal commitments into the life cycle of AI systems. It is also recommended that organizations prioritize topics with less documentary evidence, such as explainability, contestability, and bias mitigation, and develop more integrated and proactive approaches, aligned with ESG principles, to promote a more responsible and sustainable use of artificial intelligence.
Bibliographic References
Floridi, L.; Cowls, J.; Beltrametti, M.; Chatila, R.; Chazerand, P.; Dignum, V.; Luetge, C.; Madelin, R.; Pagallo, U.; Rossi, F.; Schafer, B.; Valcke, P.; Vayena, E. 2018. Al4People – An ethical framework for a good Al society: opportunities, risks, principles, and recommendations. Minds and Machines 28(4): 6
Huang, C.; Zhang, Z.; Mao, B.; Yao, X. 2023. An overview of artificial intelligence ethics. IEEE Transactions On Artificial Intelligence 4(4): 799-816.
Instituto Brasileiro de Geografia e Estatística [IBGE]. 2025. De 2022 a 2024, percentual de empresas industriais utilizando inteligência artificial subiu de 16,9% para 41,9%. Disponível em: <https://agenciadenoticias.ibge.gov.br/agencia-noticias/2012-agencia-de-noticias/noticias/44551-de-2022-a-2024-percentual-de-empresas-industriais-utilizando-inteligencia-artificial-subiu-de-16-9-para-41-9>. Acesso em: 30 dez. 2025.
Article originating from the Final Course Work of the Specialization in Compliance and ESG of the MBA USP/Esalq
To learn more about the course, click here and access the MBX Academy platform