EU AI Act in Portugal: Supervision and First Steps
This page answers three practical questions for a company building or deploying AI in Portugal: which body can knock on your door, how Portuguese national implementation interacts with a regulation that already applies directly, and what to do in the first fortnight if you have done nothing so far. Enforcement powers have been live since 2 August 2026, so this is not a planning exercise.
What the Act says about national supervision
Regulation (EU) 2024/1689 is a regulation, not a directive. It applies in Portugal without any Portuguese transposing statute. Nothing in your obligations waits for a decree law from São Bento. What national law does is fill in the institutional slots the Act leaves to Member States.
Article 70 requires each Member State to designate at least one notifying authority and at least one market surveillance authority as national competent authorities, and to make contact details and a single point of contact publicly available. Article 74 makes market surveillance authorities responsible for enforcement in their territory, with the investigation and corrective powers of the general market surveillance framework behind them. Article 77 requires Member States to identify the public bodies that supervise fundamental rights obligations and to give them the power to request documentation from providers and deployers of high-risk systems.
Two allocations are fixed by the Act itself rather than by national choice. Under Article 74(8), for high-risk systems used for law enforcement, border management, and the administration of justice and democratic processes, the market surveillance authority is the national data protection supervisory authority. In Portugal that is the Comissão Nacional de Proteção de Dados. And under Article 88, obligations on providers of general-purpose AI models are enforced centrally by the European Commission through the AI Office, not by any Portuguese body, so if you train or fine-tune a foundation model your regulatory counterparty on Article 53 sits in Brussels.
For the rest, Portugal has signalled ANACOM, the national communications regulator, as the coordinating market surveillance authority, with sectoral regulators expected to keep supervision of AI inside the domains they already police, for example financial supervision and medical devices. Portugal was among the Member States that did not complete the full Article 70 designation package by the 2 August 2025 deadline, and the formal national framework is still being consolidated. Before you send anything to a regulator, check the Commission's published list of national competent authorities and the designated authority's own site, because the named body and its contact point can change.
Article 85 gives any person the right to lodge a complaint with the market surveillance authority. In practice, the first contact many Portuguese companies have with the Act will be a complaint from a candidate, a customer or a competitor, not a scheduled audit.
Provider or deployer, and why it decides everything
A provider develops an AI system or model and places it on the market or puts it into service under its own name or trade mark. A deployer uses an AI system under its own authority in a professional capacity. A Lisbon SaaS company selling a CV screening tool is a provider. A Porto manufacturer using that tool to filter applicants is a deployer. The same company is often both, for example when it builds its own internal model and also resells a vendor's.
Establishment in Portugal is not the trigger. Article 2 extends the Regulation to providers established outside the Union that place a system on the Union market, and to providers and deployers outside the Union where the output produced by the system is used in the Union. A Portuguese company with a Delaware parent does not escape. Equally, a Portuguese company selling only to Brazil is largely outside scope for those products.
Article 25 can convert a deployer into a provider. If you put your name on a third-party high-risk system, substantially modify it, or change its intended purpose so that it becomes high-risk, you inherit the full provider obligation set. Rebranding a vendor model as your own feature is the most common way small companies acquire obligations they never budgeted for. See downstream provider duties for the detail.
What is actually required now
Three tranches are live in Portugal today.
Prohibitions. Article 5 has applied since 2 February 2025 and covers, among others, untargeted scraping of facial images to build recognition databases, emotion inference in the workplace and in education outside medical and safety uses, social scoring, and exploitation of vulnerabilities. There is no grandfathering and no transition. A product feature that falls here has to be switched off, not documented.
AI literacy. Article 4 requires providers and deployers to ensure a sufficient level of AI literacy among staff and others operating systems on their behalf. It has applied since 2 February 2025 and is cheap to satisfy: a recorded briefing, an attendance list, and a note of what each role was told.
Transparency and GPAI. Article 50 and Article 53 have been enforceable since 2 August 2026. Article 50 means disclosing to a person that they are interacting with an AI system unless it is obvious, marking synthetic audio, image, video and text in a machine readable format, and labelling deep fakes. If you run a Portuguese-language chatbot, the disclosure has to be in Portuguese and visible at the start of the interaction, not buried in the terms.
Language matters more than most teams expect. Instructions for use under Article 13, and the EU declaration of conformity, can be required in the official language of the Member State where the system is made available. Assume Portuguese versions are needed for anything sold into the Portuguese market, and price the translation of technical documentation into the delivery plan rather than discovering it during a sale.
The dates that bind
| Date | What applies | Status |
|---|---|---|
| 2 February 2025 | Article 5 prohibitions, Article 4 AI literacy | In force |
| 2 August 2026 | Enforcement powers, Article 50 transparency, Article 53 GPAI | In force |
| 2 December 2027 | Annex III standalone high-risk obligations | 457 days away |
| 2 August 2028 | Annex I embedded high-risk obligations | Pending |
The 2 December 2027 date for Annex III comes from the Digital Omnibus provisional agreement of May 2026 and is still awaiting formal adoption. Treat it as the working date and not as a settled one.
Penalties under Article 99 reach 35 million euro or 7 per cent of worldwide annual turnover for breaching Article 5, 15 million or 3 per cent for most other obligations including provider duties under Article 16 and deployer duties under Article 26, and 7.5 million or 1 per cent for supplying incorrect or misleading information to authorities. For SMEs and startups the applicable ceiling is the lower of the fixed amount and the percentage, which for a company at 4 million euro of revenue means the percentage is rarely the binding constraint. The information offence is the one small companies trip over most easily, because it is triggered by a careless answer to a regulator rather than by a product defect.
What a Portuguese company does first
- Build the system inventory this week. One row per AI system or model, listing the intended purpose, whether you are provider or deployer for it, whether any third-party model sits underneath, which Annex III point it might touch, and the named owner inside the company. Fifteen rows is normal for a 60 person company. Without this, every other step is guesswork.
- Run the Article 5 screen against shipped features and the roadmap. Emotion recognition in hiring or workplace monitoring, biometric categorisation, and scraped face databases are the three that catch European product teams. Kill or redesign anything that lands there, and write down the reasoning and the date, because the decision record is what you show if a complaint arrives.
- Fix Article 50 disclosures in Portuguese and English. Audit every chatbot, generated image, synthetic voice and AI drafted output. Add the interaction disclosure, apply machine readable marking to generated content, and label deep fakes. This is a sprint of engineering work, not a legal project, and it is already enforceable.
- Assign an accountable owner and log the AI literacy sessions. One named person, usually the CTO or head of product in a company under 200 people. Record who was trained, on what, and when. Article 4 evidence is a spreadsheet, not a certification.
- Start the Annex III technical file if you are within scope. Risk management under Article 9, data governance under Article 10, technical documentation under Article 11 to the structure of Annex IV, logging under Article 12 with retention appropriate to the intended purpose and at minimum six months, and human oversight under Article 14. Automated logging and data lineage take multiple quarters to retrofit, so they are the parts to begin now rather than in 2027.
Where this leaves you
The Portuguese layer of this regulation is thinner than most teams assume. Your substantive obligations come from the Regulation and are identical to those of a competitor in Rotterdam or Milan. What Portugal adds is the identity of the authority that will handle a complaint, the language your instructions and disclosures need to be in, and the accreditation route through IPAC if your product ever needs a notified body. Everything else is common European text. If you want a quick view of which tranche your systems fall into and what is already enforceable against you, the free screener at https://www.getactcomply.com/check walks through the classification in about ten minutes and produces a written record you can keep with the inventory.