Liquid AI: LGPD, GDPR and a company-wide AI-first culture

Mapping LGPD and GDPR into a written security and privacy framework, governing the data pipelines beneath it, putting agents into the critical workflows, and making AI a habit across the whole company rather than a pilot inside engineering.
02Narrative
Context
Liquid AI builds product-led software for the Brazilian real-estate market. Adopting AI across a company of that shape raises two problems at once: what the models are allowed to touch, and whether anyone outside engineering will actually use them.
Problem
Governance written after adoption is a cleanup. Adoption without governance is an incident waiting for a regulator. Both had to be built at the same time, by a small team, without slowing product delivery.
Approach
I mapped the applicable laws and standards (LGPD in Brazil and GDPR in Europe) and turned the map into a written security and privacy framework, so each control traces to a specific obligation instead of to a general sense of caution. On top of that sits the governance of the data pipelines themselves, and the intelligent agents that automate critical workflows and let a small team ship at scale. The cultural half decides whether any of it lasts: mentoring and training on LLMs for productivity, product and AI-assisted development, aimed at each person's real workflow rather than at a tool.
Non-obvious decisions
- Map the obligations before writing a single control. A framework derived from articles can be audited; one derived from best practice can only be argued about.
- Cover GDPR alongside LGPD even where only LGPD applies today. The two overlap enough that mapping both costs little, and a company that may handle European data later cannot retrofit the difference cheaply.
- Make AI adoption a habit problem, not a tooling problem. A new tool without a new habit reverts within a month, which is why the work is mentoring and training rather than a licence rollout.
- Put agents in the critical workflows rather than in the visible ones. Automating a demo produces a demo; automating the path a deal actually travels is what lets a small team hold scale.
Outcome
A written security and privacy framework traceable to LGPD and GDPR, governed data pipelines beneath it, intelligent agents inside the workflows that carry the product, and an AI-first practice that survives the person who introduced it.
03Evidence
Stack
- LGPD
- GDPR
- Data warehouse
- Data pipelines
- LLM agents