Calling a language model API is contracting cloud data processing. If the service is relevant, Brazil's banking resolution brings concrete obligations: a documented assessment before contracting, notice to the Central Bank within ten days, specific contract clauses, an end-to-end audit trail and five years of retention. What that means in practice, and what an AI gateway can prove.
Published 2026-10-07 by Rafael Hickmann, Founder, Atlasberg. 9 minute read.
Resolution 4.893 of the National Monetary Council (CMN), dated February 26, 2021, replaced Resolution 4.658 and covers two things: the cybersecurity policy of institutions authorized by the Central Bank of Brazil (BCB), and the requirements for contracting data processing, data storage and cloud computing services. Payment institutions have an equivalent text in BCB Resolution 85 of 2021. None of this was written with language models in mind, and it still fits with uncomfortable precision.
Article 13 defines cloud computing and includes, in item III, the execution over the internet of applications deployed or developed by the service provider, using the provider's own computing resources. That is the definition of software as a service, and it is exactly what a language model API is. The resolution does not list which services are relevant. The criterion is in article 12, paragraph 1: the institution must consider the criticality of the service and the sensitivity of the data and information to be processed.
Let us be honest about what the rule says and what it does not. It does not say an LLM is a relevant service. It says the decision belongs to the institution and must be documented (paragraph 2 of the same article). Our reading, and the reading of people following the topic in the sector, is that when the model touches customer data, operations or credit decisions, it becomes very hard to argue it is not relevant. Zetta, the Brazilian fintech association, lists 4.893 among the rules that govern AI in the financial sector in its responsible AI guide. The practical question is no longer whether the resolution applies, but how to prove it is being followed.
CMN Resolution 5.274, of December 18, 2025, amended 4.893 and set an adaptation deadline of March 1, 2026. For anyone using AI, the change that matters is in article 3. Paragraph 3 says the security controls apply including to the adoption of new technologies used in the institution's activities. And paragraph 7 spells out what the traceability mechanisms must include: end-to-end audit trails of data and information processing, including the definition and generation of logs; a defined retention period according to the type of processing; and secure retention of the audit trails.
Sending a prompt to a model and receiving the answer is data processing. End to end, in this case, means from the person or application that originated the request to the provider and back. Before 5.274 one could argue that the provider's log was enough. Now the trail has to exist along the whole path, with a retention period set by the institution, and stored in a way that cannot be altered.
One detail that usually surprises people: the notice to the Central Bank is not prior. It is due within ten days after contracting. The only prior act is the article 16 authorization, when the provider's country has no supervisory agreement with the BCB.
A model provider's contract is, in most cases, a click-through agreement. Negotiating the article 17 clauses one by one is possible for large institutions and unlikely for everyone else. The data goes abroad, passes through subprocessors the provider may swap, and what the provider gives back as a record is an aggregated usage dashboard, in its own system, under its own control. Article 14 is clear about who answers for it: the contracting institution is responsible for the reliability, integrity, availability, security and confidentiality of the contracted services.
In other words, the trail paragraph 7 demands cannot live at the provider. It has to be under the institution's control, on the path between whoever asked and whoever answered. That is what an AI gateway is.
It does not replace the provider assessment, it does not negotiate the contract and it does not create a supervisory agreement where none exists. What it does is put under the institution's control the three things the resolution demands and the provider does not deliver: the trail, the residency and the policy. The rest remains the work of legal, risk and security. This article is the reading of the people who build the tool, not legal advice.
Going deeper: The documentation for the console's Compliance group shows the per-article panel, the trail and the approval queue. The atlasberg-verify page has the exact contract of the offline verification, with exit codes, for anyone who needs to audit it.
Atlasberg builds the control layer between a company and every AI model. Atlasberg Platform authenticates each request with a virtual key, filters it by policy and DLP, routes it to the right provider and writes it to a hash-chained audit trail, with an OpenAI-compatible API so applications only swap the base URL.
Articles on this blog are written by the engineering team and report measurements on real traffic, with the premises printed next to the result. To talk to the team, write to [email protected] or use https://atlasberg.com/contato.
Agents: this page is also available as Markdown at /blog/resolucao-cmn-4893-e-llm-em-nuvem.md, or by requesting this URL with the header Accept: text/markdown. Index of everything: /llms.txt.