-
What is the legal definition of “artificial intelligence” in your jurisdiction, if any? If no definition exists, how do regulators or courts typically describe artificial intelligence?
Portugal has not adopted a standalone legal definition of artificial intelligence under national law. As an EU Member State, the applicable definition is that set out in Regulation (EU) 2024/1689 (the ‘AI Act’), which applies directly in Portugal.
Article 3(1) of said diploma defines an AI system as a machine-based system designed to operate with varying levels of autonomy and that may exhibit adaptiveness after deployment, inferring from the inputs it receives how to generate outputs, such as predictions, content, recommendations or decisions, capable of influencing physical or virtual environments. The definition adopts a technology-neutral approach, focusing on the system’s inference capability rather than on specific techniques such as machine learning or generative AI.
Accordingly, Portuguese courts and regulators are expected to interpret the concept consistently with the AI Act, its recitals and any guidance issued by the European Commission and the European Artificial Intelligence Board. To date, there is no relevant Portuguese case law providing an autonomous interpretation of the concept of AI. National policy documents, including AI Portugal 2030, describe AI in broad strategic terms without establishing legally binding concepts. Notably, Portuguese legislation already addressed certain AI-related issues before the AI Act existed: the Portuguese Charter of Human Rights in the Digital Era (Law No. 27/2021), enacted in 2021, addresses the ’use of artificial intelligence and robots‘ without itself defining the term, requiring that AI be used in a manner respecting fundamental rights and balancing explainability, safety, transparency and accountability, and that algorithm-based decisions with a significant impact on individuals be communicated to them and be open to appeal and audit. This provision remains in force alongside the AI Act, illustrating that Portuguese law addressed AI-related principles before the EU framework, even though it did not provide a technical definition of AI. Accordingly, in practice, the legal meaning of artificial intelligence in Portugal is determined primarily by EU law rather than domestic legislation.
-
Has your country developed a national strategy for artificial intelligence? If yes, what progress has been made in its implementation? Are there plans for updates or revisions?
Yes. Portugal adopted its first national artificial intelligence strategy, AI Portugal 2030, in 2019. The strategy sets out a national framework for promoting AI innovation, research, skills development, digital transformation and the responsible adoption of AI across both the public and private sectors. Rather than creating binding legal obligations, it establishes policy objectives aimed at strengthening Portugal’s AI ecosystem and supporting economic growth through trustworthy AI.
Its implementation has been supported through a combination of national initiatives and EU-funded programmes, including investments under the Recovery and Resilience Plan (Plano de Recuperação e Resiliência – ‘PRR’), the Digital Europe Programme and Horizon Europe. Key measures have included support for AI research and innovation centres, digital innovation hubs, business digitalization, advanced digital skills and the development of public sector AI projects. Portugal has also actively participated in broader European initiatives, including the coordinated implementation of the EU Coordinated Plan on Artificial Intelligence.
The entry into force of the AI Act has marked a new phase in Portugal’s policy, shifting the focus towards preparing the national governance framework required under the Regulation, including the designation of the competent supervisory authorities and the implementation of the new EU regulatory framework.
More recently, in January 2026, the Government approved, through Council of Ministers Resolution No. 2/2026, the National Artificial Intelligence Agenda (ANIA) and its accompanying Action Plan (PAANIA) for 2026-2030, which succeeds AI Portugal 2030. In parallel, the broader regulatory framework applicable to AI systems has been reinforced by the adoption of Decree-Law No. 125/2025, which transposes the NIS2 Directive and establishes the new Legal Framework for Cybersecurity, in force since 3 April 2026.
-
Has your jurisdiction adopted any AI-specific laws, regulations, voluntary standards, or ethical guidelines? If so, please provide a brief overview. If not, which existing laws could be/are applied to artificial intelligence and the use of artificial intelligence, what are the main interpretive challenges, and are there any pending artificial intelligence legislative initiatives?
Portugal has not adopted a standalone, comprehensive national AI statute. The applicable legal framework is therefore primarily EU-based, led by the AI Act. The Portuguese Government’s digital strategy portal expressly frames the AI Act as the governing framework, with a phased implementation roadmap and a governance model built around the AI Board, harmonized standards, conformity assessment and national competent authorities.
As noted above, Portugal has adopted policy and soft-law instruments that are relevant in practice. The first national AI strategy, AI Portugal 2030, was adopted (in 2019) as a policy document to promote innovation, skills, research and adoption of AI, but it does not itself create binding obligations. More recently, the Government launched the ANIA, presented as a funding-backed initiative of more than EUR 400 million, focused on trust and the ethical and responsible use of AI, including a Centre of Excellence in AI for the public administration, training programmes for public servants and support for AI adoption by SMEs. In parallel, the public administration has published an ’IA Responsável’ model, built around five assessment dimensions – accountability, transparency, explainability, fairness and ethics – which, although designed for public-sector projects, is expressly presented as relevant also for private and academic organisations seeking to align with good practice and the AI Act.
At the regulatory level, Portugal has mainly relied on existing legal regimes rather than AI-specific legislation. The Portuguese Data Protection Authority (‘CNPD‘) continues to apply the General Data Protection Regulation (‘GDPR‘) and related European Data Protection Board (‘EDPB‘) guidance to AI use cases, including guidance on data protection by design, automated individual decision-making and profiling, virtual voice assistants and video devices, together with sector-relevant opinions such as its 2022 opinion on facial recognition. In 2026, the CNPD also subscribed a joint international statement on AI-generated imagery, highlighting privacy, transparency and removal mechanisms for harmful content. These instruments are not AI laws as such, but they are highly relevant to how AI systems are assessed under Portuguese practice.
Sector-specific institutions have also begun to develop AI-related guidance. The Media Regulator (‘ERC‘) launched a public consultation in 2025 to gather evidence for best-practice guidance on the ethical and responsible use of AI in the media sector, and as previously stated, in a specific media case, that AI tools used in journalism must comply with transparency requirements towards the public. The National Communications Authority (‘ANACOM‘), for its part, publicly consulted in 2026 on draft recommendations for the implementation of Article 5 of the AI Act, expressly relying on the European Commission’s guidelines on prohibited AI practices. Portugal has also already published the list of 14 entities supervising fundamental-rights protection in the context of high-risk AI under Article 77 of the AI Act, including ANACOM and ERC.
In terms of interpretive challenges, the key issue in Portugal is not the absence of rules, but the overlap between the AI Act and pre-existing regimes, especially the GDPR, media regulation, cybersecurity, consumer protection, product liability and employment law. The main practical questions are how to allocate roles and responsibilities across the AI value chain, how to operationalize transparency and human oversight, how to evidence compliance in high-risk systems, and how to reconcile AI-driven processing with Portuguese and EU data-protection requirements. Pending legislative activity is therefore concentrated less on a standalone AI code and more on implementation measures and sectoral guidance, together with targeted proposals such as a recent parliamentary bill proposing rules on the use of AI in electoral campaigns.
-
Are there legal requirements for artificial intelligence transparency, explainability, or audits? Are there obligations to disclose the use of artificial intelligence to customers/clients?
Portugal has not adopted a standalone national AI statute. The AI Act is the principal binding framework for AI in Portugal, but it applies alongside other relevant regimes, including the GDPR and sector-specific legislation, while Portuguese authorities have also begun issuing AI-related guidance and soft-law instruments.
In broad terms, the AI Act requires providers of higher-risk AI systems to ensure that those systems are sufficiently transparent for the people using them to understand how they work and to exercise meaningful oversight over their outputs, including the ability to question or override automated results where appropriate. Separately, a wider set of AI systems is subject to disclosure duties towards end users: organisations deploying tools such as chatbots or systems that generate synthetic content are expected to make clear that people are interacting with, or viewing content produced by, artificial intelligence, rather than leaving that fact to be inferred. Formal audit requirements are more limited in scope and tend to apply mainly to higher risk uses, where independent conformity checks may be required before a system is placed on the market.
In Portugal, these obligations apply directly without the need for national implementing legislation, and organisations are expected to build them into their governance and customer-facing practices as the relevant AI Act provisions come into effect.
-
Are there legal requirements or best practice expectations for human oversight and human-in-the-loop in artificial intelligence systems?
Portugal has not introduced specific national rules on human oversight or human-in-the-loop requirements for AI systems. The applicable legal framework is therefore the AI Act, which applies directly in Portugal. In the absence of AI-specific legislation, Portuguese institutions have started to translate this requirement into practice through sector guidance rather than binding rules.
The High Council for the Judiciary, for example, has issued recommendations on the use of AI within the justice system, making clear that AI may only be used as an auxiliary tool, while preserving full judicial independence, individual accountability and prohibiting the automated substitution of judicial reasoning. This guidance gained prominence following a widely reported case involving a Portuguese appellate court, in which allegations that parts of a judgment had been generated using generative AI prompted public debate about the appropriate use of AI in judicial functions.
In the public administration, the aforementioned ‘IA Responsável ’framework similarly builds human oversight into its five assessment dimensions and is expressly presented as a reference also for private and academic organisations.
In practice, therefore, expectations of human-in-the-loop review in Portugal are currently shaped less by codified domestic rules than by these emerging institutional positions.
-
Are there specific legal or regulatory requirements addressing algorithmic bias, discrimination, or fairness in AI systems (including gender bias)?
Portugal has not adopted AI-specific national legislation addressing algorithmic bias or fairness. These issues are primarily governed by the AI Act, which applies directly in Portugal and requires certain AI systems, particularly high-risk AI systems, to be designed and developed in a way that reduces the risk of discriminatory outcomes and safeguards fundamental rights throughout their lifecycle.
In addition, existing Portuguese and EU legal frameworks apply where relevant. The Portuguese Constitution establishes the principle of equality and prohibits discrimination, while national anti-discrimination legislation, the GDPR and sector-specific rules may also apply depending on the context in which AI is used. In particular, the GDPR requires personal data used in AI systems to be accurate, relevant and processed lawfully, and provides safeguards against decisions based solely on automated processing in certain circumstances.
Although no Portuguese regulator has issued binding AI-specific rules on algorithmic bias, the CNPD has consistently emphasized that AI systems must comply with data protection principles, including fairness, transparency and accountability. On gender-specific bias, the Commission for Citizenship and Gender Equality (‘CIG‘), Portugal’s national equality body, launched a project with the Council of Europe in Lisbon in September 2024 specifically aimed at ensuring that equality and non-discrimination are embedded in the use of AI by public administrations. This reflects a broader European effort under the Council of Europe Framework Convention on AI and Human Rights to equip national equality bodies to address algorithm-based discrimination, including gender bias.
In practice, organisations deploying AI in Portugal are expected to implement appropriate governance measures, including representative datasets, testing and monitoring procedures, and human oversight, to mitigate the risk of biased or discriminatory outcomes.
-
What legal frameworks apply to AI-related harm and defective artificial intelligence systems? Who can be held liable (developer, deployer, victim of the damage, others), how is liability allocated, and what burden of proof applies to victims?
Portugal has not established a specific civil liability regime for AI-related harm. Liability is therefore governed by existing legal frameworks, including the Portuguese Civil Code, the strict product liability regime under Decree-Law No. 383/89, of 6 November (which transposed the original EU Product Liability Directive 85/374/EEC), consumer protection rules and sector-specific legislation, depending on the nature of the AI system and the damage caused.
Liability is assessed on a case-by-case basis and may attach on different actors within the AI value chain, including developers, providers, deployers, manufacturers, distributors or operators, depending on their role, the applicable legal regime and the circumstances of the case. Under general tort law, claimants must generally establish an unlawful act, fault (unless strict liability applies), damage and causation. Product liability may apply where an AI system or AI-enabled product qualifies as a defective product under the applicable legislation.
Although the AI Act does not harmonize civil liability, it is likely to play an important evidentiary role: compliance or non-compliance with its requirements, such as risk management, documentation, logging, human oversight and post-market monitoring, may be relevant when assessing fault or defectiveness under Portuguese law. A more significant development is on the horizon. Directive (EU) 2024/2853 on liability for defective products, which must be transposed into Portuguese law (replacing Decree-Law No. 383/89) by 9 December 2026, expressly extends the definition of ’product‘ to cover software and AI systems, clarifies that manufacturers of defective software or AI components can be held liable, and introduces rebuttable presumptions of defectiveness and of the causal link between the defect and the damage in cases of excessive technical or scientific complexity, easing the evidentiary burden that currently falls on claimants.
To date, there is no significant Portuguese case law addressing civil liability for AI-related harm. Accordingly, liability continues to be determined by applying traditional principles to new technological contexts, pending transposition of the revised EU product liability framework and any future EU initiatives on AI liability.
-
What cybersecurity obligations apply to AI systems?
Portugal has not adopted AI-specific cybersecurity legislation. Depending on the sector and the entity deploying the AI system, however, additional cybersecurity obligations may arise under the Portuguese legal framework implementing the NIS2 Directive, as well as other applicable EU legislation. In this regard, Decree-Law No. 125/2025, of 4 December, approves the Legal Framework for Cybersecurity and transposes Directive (EU) 2022/2555 (NIS2), in force since 3 April 2026. This framework imposes on covered entities duties relating to risk management, incident reporting, business continuity and supply chain risk assessment, and provides for the personal liability of management bodies in cases of wilful misconduct or gross negligence, under the supervision of the National Cybersecurity Centre (‘CNCS’).
Although no Portuguese authority has issued AI-specific cybersecurity guidance to date, the CNCS and ANACOM continue to promote cybersecurity best practices that are equally relevant to AI-enabled technologies. In practice, organisations deploying AI in Portugal should ensure that AI governance and cybersecurity governance are integrated, particularly where AI systems support critical business functions or process sensitive data.
-
Is the use of artificial intelligence insured and/or insurable in your jurisdiction, including with cyber policies? Are there market trends, or limitations?
Portugal has no AI-specific insurance regime, and the use of AI is generally considered insurable under existing insurance products, subject to the terms and exclusions of each policy.
Although the Portuguese insurance market has yet to develop AI-specific insurance products on any significant scale, AI-related risks are becoming increasingly relevant in cyber and technology insurance. Organisations deploying AI should therefore carefully review existing policies to identify any exclusions or limitations relating to autonomous systems, software failures, cyber incidents or regulatory investigations, and assess whether additional cover is appropriate in light of their AI use cases.
-
Can artificial intelligence be named as an inventor in a patent application filed in your jurisdiction? If not, what is the current legal position?
No. Under Portuguese patent law, an inventor must be a natural person. Accordingly, an artificial intelligence system cannot be designated as the inventor in a patent application filed in Portugal.
Although Portuguese courts have not yet ruled on this issue, the position is consistent with the European Patent Convention (‘EPC‘) and the established practice of the European Patent Office (‘EPO‘), which have rejected patent applications naming AI systems, such as DABUS, as inventors. The rationale is that inventorship is intrinsically linked to legal personality, which AI systems do not possess.
This does not prevent patent protection for AI-assisted inventions. Where an invention is generated with the assistance of AI, the patent application must identify the natural person(s) who made the inventive contribution in accordance with the applicable legal requirements. The mere use of AI as a research or development tool does not, in itself, preclude patentability, provided that the substantive patentability criteria, including novelty, inventive step and industrial applicability, are satisfied.
To date, neither the Portuguese Industrial Property Code nor the Portuguese Institute of Industrial Property (‘INPI‘) has introduced AI-specific rules on inventorship. Accordingly, the existing legal framework continues to require that inventorship be attributed exclusively to human inventors.
-
Do images or works generated by and/or with artificial intelligence benefit from copyright protection in your jurisdiction? If so, who is the authorship attributed to, and under what conditions?
Portuguese copyright law does not contain specific provisions on AI-generated works. Under the Portuguese Copyright and Related Rights Code (Código do Direito de Autor e dos Direitos Conexos), copyright protection is based on the concept of authorship, which presupposes a human creator. Accordingly, an AI system cannot be recognized as an author under Portuguese law.
Where AI is used merely as a tool in the creative process, copyright protection may still arise, provided that the resulting work reflects the author’s own intellectual creation. Whether this threshold is met will depend on the specific facts of each case, including the degree of human creative input, control and decision-making exercised over the final output.
By contrast, works generated autonomously by AI, without sufficient creative human contribution, are unlikely to qualify for copyright protection under the current legal framework. To date, Portuguese courts have not addressed this issue, and neither the legislature nor the Portuguese Copyright Office has adopted AI-specific rules on copyright authorship.
As in other EU Member States, the interpretation of Portuguese copyright law is expected to remain closely aligned with the case law of the Court of Justice of the European Union, in particular the principle that copyright protects only works constituting the author’s own intellectual creation.
-
What are the main issues to consider when using artificial intelligence systems in the workplace? Have any new regulations, or guidelines, been introduced regarding AI-driven hiring, performance assessment, or employee monitoring?
The use of AI in the workplace is subject to a combination of the AI Act and existing Portuguese employment and data protection law. Although Portugal has not adopted standalone AI-specific employment legislation, 2023 amendments to the Labour Code already established specific rules on algorithmic-management. These oblige employers to inform employees, in writing, of the parameters, criteria, rules and instructions underlying algorithms or other AI systems used in decisions on access to and continuation of employment, working conditions, profiling and the monitoring of professional activity, with equivalent disclosure duties owed to works councils and trade union representatives. Employers deploying AI systems must also comply with the wider provisions of the Portuguese Labour Code, the GDPR and the constitutional rights to privacy, dignity and non-discrimination.
Portuguese law already places significant limits on employee monitoring, particularly through technological means, and such restrictions continue to apply where AI systems are used. The Portuguese Data Protection Authority (CNPD) has consistently emphasized that the introduction of new technologies in the workplace does not diminish employers’ obligations under data protection law or employees’ fundamental rights.
In practice, organisations implementing AI in employment contexts should carry out appropriate risk assessments, ensure meaningful human oversight of AI-assisted decision-making, provide adequate information to employees and establish internal governance measures to mitigate discrimination and other fundamental rights risks.
-
What are the main privacy/data protection issues arising from artificial intelligence development and use (including training data)? Have data protection authorities issued guidelines or rulings on artificial intelligence, and what are the key takeaways?
In Portugal, the main privacy issues arising from the development and use of AI concern the lawful use of personal data for training and deployment, transparency, automated decision-making, data minimization, purpose limitation and the processing of special categories of personal data. These matters are primarily governed by the GDPR, as supplemented by the Portuguese Data Protection Act (Law No. 58/2019).
The CNPD has not adopted AI-specific binding rules but has consistently applied the GDPR to AI-related processing. The CNPD follows the guidance issued by the EDPB and has emphasized that organisations deploying AI systems must comply with the core principles of data protection, including lawfulness, fairness, transparency, accountability and data protection by design and by default. Where AI systems are likely to result in high risks to individuals’ rights and freedoms, organisations may also be required to carry out a Data Protection Impact Assessment (DPIA). More recently, in May 2025 the CNPD publicly warned organisations about the use of personal data to train AI models, and later that year it assumed coordination of a dedicated international working group on generative AI. In 2026, the CNPD also joined an international joint declaration, signed by over 60 data protection authorities worldwide, on the risks of AI-generated imagery, addressing privacy, transparency and content-removal mechanisms.
The use of personal data for training AI models remains one of the most challenging issues in practice, particularly when identifying an appropriate legal basis, ensuring compliance with the purpose limitation and data minimization principles, and assessing the use of publicly available data. Organisations should therefore assess data protection compliance from the design stage, implement appropriate technical and organisational safeguards and ensure that AI governance is closely aligned with their wider data protection compliance framework.
-
How is data scraping regulated in your jurisdiction from an IP, privacy and competition perspective? Are there recent precedents addressing the legality of data scraping for training of artificial intelligence systems?
Portugal has not adopted specific legislation regulating data scraping for AI training. Instead, its legality is assessed under existing legal frameworks, including copyright law, the GDPR, database rights, competition law and contractual principles, depending on the nature of the data and the means by which it is collected.
From an intellectual property perspective, the Portuguese Copyright and Related Rights Code implements the text and data mining (TDM) exceptions introduced by Directive (EU) 2019/790 on Copyright in the Digital Single Market. Accordingly, certain acts of text and data mining may be permitted, subject to the conditions laid down in the legislation, including the possibility for rightsholders to reserve their rights in relation to commercial TDM.
Separately, where scraping targets a structured database rather than individual copyright works, Decree-Law No. 122/2000, of 4 July, grants the database maker a sui generis right to authorize or prohibit the extraction or re-utilization of the whole or a substantial part of its contents. It also expressly prohibits the repeated and systematic extraction or re-utilization of even insubstantial parts where this would conflict with normal exploitation of the database or unreasonably prejudice the maker’s legitimate interests. This provision is particularly relevant to large-scale scraping of structured web data for AI training.
Where personal data is scraped, the GDPR and the Portuguese Data Protection Act apply. Organisations must identify an appropriate legal basis for the processing, comply with the principles of transparency, purpose limitation and data minimization, and ensure that individuals’ rights are respected. Depending on the circumstances, large-scale web scraping may also raise issues under competition law or amount to a breach of contractual terms governing access to online services.
To date, there is no significant Portuguese case law specifically addressing the legality of data scraping for training AI systems. As a result, organisations operating in Portugal generally rely on existing EU and national legal frameworks, together with evolving European regulatory guidance and case law, when assessing the lawfulness of scraping activities.
-
To what extent is the prohibition of data scraping in the terms of use of a website enforceable?
To a significant extent, subject to the applicable legal framework. The Portuguese rules implementing the DSM Copyright Directive allow rightsholders to reserve their rights in relation to text and data mining, including through website terms and conditions and other machine-readable means.
Therefore, organisations engaging in web scraping for AI training should carefully assess both the applicable contractual restrictions and any reservation of rights before carrying out scraping activities.
To date, there is no Portuguese case law directly addressing this issue in the context of AI training.
-
Does your country have a regulator or authority responsible for supervising the use and development of artificial intelligence? What are its powers and enforcement tools?
Portugal has not established a single regulator dedicated exclusively to artificial intelligence. Instead, AI oversight is based on a multi-authority model, reflecting the framework established under the AI Act. Within this model, ANACOM has been designated as the lead national supervisory authority for the AI Act, responsible for coordinating the network of fourteen sectoral authorities entrusted with supervising fundamental-rights protection in the context of high-risk AI under Article 77 of the AI Act.
The competent authorities responsible for supervising AI systems within their respective areas of competence, include regulators such as CNPD, ANACOM, ERC, the National Authority for Medicines and Health Products (INFARMED), the Bank of Portugal and other sectoral authorities. These authorities are responsible for monitoring compliance with the AI Act within their respective sectors, in coordination with the national market surveillance authorities and the European AI governance framework.
In addition to their powers under the AI Act, these authorities continue to exercise their existing statutory powers under sector-specific legislation, including the ability to investigate infringements, request information, conduct inspections, issue binding decisions and, where applicable, impose administrative sanctions. The AI Act also provides for significant administrative fines for non-compliance, which will be enforced through the national competent authorities designated by each Member State.
Accordingly, AI regulation in Portugal is expected to remain decentralised, with supervision enforcement depending on both the sector in which the AI system is deployed and the applicable legal framework.
-
How widespread is the adoption of artificial intelligence in businesses in your jurisdiction, and which sectors are leading?
The picture in Portugal is one of a two-speed economy. At the top, large companies and a handful of digitally mature sectors are moving quickly, treating AI as a genuine competitive advantage rather than a passing trend. Further down the ladder, the small and micro businesses that make up the backbone of the Portuguese economy are only beginning to experiment, held back less by lack of interest than by a shortage of in-house skills, the upfront cost of adoption, and uncertainty surrounding the applicable regulatory framework. The latest survey published by the National Statistics Office (INE) confirms that Portugal still trails the EU average in AI uptake, with a wider gap between large enterprises and smaller firms than in most other Member States. The National Artificial Intelligence Agenda (ANIA) and the dedicated funding programmes for SMEs launched in 2025 and 2026 are a direct response to that imbalance, seeking to close the gap rather than simply celebrate the leaders.
The sectors leading AI adoption include financial services, telecommunications, technology, healthcare, retail and manufacturing. Financial institutions are using AI for fraud detection, risk management and customer support; telecommunications operators are deploying AI to optimise network management and customer experience; and healthcare providers are increasingly exploring AI-assisted diagnostics and administrative automation. The legal, insurance and public sectors are also expanding their use of generative AI, subject to appropriate governance and regulatory safeguards.
-
How is artificial intelligence used in the legal sector, by lawyers and/or in-house counsels? Are AI-driven legal tools widely adopted, and what are the main regulatory concerns?
The adoption of AI in the Portuguese legal sector has increased significantly, particularly following the emergence of generative AI. Law firms and in-house legal teams are increasingly using AI to support legal research, document review, contract analysis, due diligence, legal drafting, knowledge management and document automation. While adoption is growing rapidly, AI is generally used to assist, rather than replace, legal professionals.
There are currently no AI-specific rules governing the legal profession in Portugal, but lawyers using AI remain subject to the general duties established under the Portuguese Bar Association’s Statute and the Code of Conduct, including duties of competence, independence, confidentiality and professional secrecy. These obligations require lawyers to ensure that the use of AI does not compromise the quality of legal advice, client confidentiality or compliance with applicable legal and ethical standards.
Thus, the main regulatory concerns relate to the protection of confidential and privileged information, compliance with the GDPR, the accuracy and reliability of AI-generated outputs, intellectual property issues and the need for effective human review. As a result, many Portuguese law firms – like CCA Law Firm – and legal departments have adopted internal AI governance policies regulating the approved use of AI tools, risk assessments and employee training. In practice, AI is increasingly regarded as a productivity tool that enhances legal services, provided that its use remains subject to appropriate professional oversight and robust governance.
-
What are the 5 key challenges and the 5 key opportunities raised by artificial intelligence for lawyers in your jurisdiction?
The main challenges raised by AI for lawyers in Portugal are not unique to this jurisdiction. They are the same challenges the legal profession is facing globally: understanding an increasingly complex regulatory environment; protecting confidentiality, privilege and cybersecurity; managing the risk of inaccurate, biased or hallucinated outputs; ensuring meaningful human oversight; and developing the technical literacy needed to advise clients on AI confidently and responsibly.
The main opportunities are equally clear. AI can improve efficiency in legal research, document review and drafting; free up time for higher-value advisory work; support better risk management and compliance; make some legal services faster and more cost-effective; and create new areas of practice, particularly in AI governance, procurement, data protection, intellectual property and disputes.
In Portugal, as elsewhere, the fundamental shift is not that AI will replace lawyers, but that it is reshaping the way they work and what clients expect from them.
-
Where do you see the most significant legal developments in artificial intelligence in your jurisdiction in the next 12 months? Are there any ongoing initiatives that could reshape AI governance?
Over the next 12 months, the most significant developments in Portugal are expected to stem from the implementation and enforcement of the AI Act, rather than from the adoption of standalone national AI legislation. Since 2 August 2026, the AI Act’s transparency rules have applied, requiring chatbots, deepfakes and AI-generated content to disclose that they are AI-generated. At the same time, Regulation (EU) 2026/1744 (the Digital Omnibus on AI), adopted on 8 July 2026, has pushed back application of the principal obligations for high-risk AI systems to 2027 and 2028, easing near-term pressure on organisations preparing for that stage of the AI Act. In parallel, by 9 December 2026, Portugal must transpose the revised EU product liability regime, which will treat defective AI systems as ’products‘ for the first time and give claimants a lighter burden of proof. Alongside these developments, ANACOM’s first year as lead supervisor will be a real test of the multi-authority model, as it moves from designation on paper to coordinating fourteen regulators in practice.
The key priorities will be the consolidation of the national AI governance framework, including the role of the competent authorities responsible for supervising compliance with the AI Act, the publication of sector-specific guidance and the gradual development of enforcement practice. As organisations move from AI experimentation to large-scale deployment, regulatory compliance and AI governance are expected to become central business priorities across both the public and private sectors.
Further guidance from Portuguese regulators, particularly in areas such as data protection, media, telecommunications and cybersecurity, is also expected to shape the practical application of AI in Portugal. In parallel, the first enforcement actions under the AI Act and the development of European-level guidance are likely to provide greater legal certainty in relation to issues that remain open today, including the governance of general-purpose AI models and the interaction between the AI Act and other areas of EU law.
Overall, the next phase of AI regulation in Portugal is likely to be characterized less by new legislation and more by implementation, supervision and the development of practical compliance standards.
Portugal: Artificial Intelligence
This country-specific Q&A provides an overview of Artificial Intelligence laws and regulations applicable in Portugal.
-
What is the legal definition of “artificial intelligence” in your jurisdiction, if any? If no definition exists, how do regulators or courts typically describe artificial intelligence?
-
Has your country developed a national strategy for artificial intelligence? If yes, what progress has been made in its implementation? Are there plans for updates or revisions?
-
Has your jurisdiction adopted any AI-specific laws, regulations, voluntary standards, or ethical guidelines? If so, please provide a brief overview. If not, which existing laws could be/are applied to artificial intelligence and the use of artificial intelligence, what are the main interpretive challenges, and are there any pending artificial intelligence legislative initiatives?
-
Are there legal requirements for artificial intelligence transparency, explainability, or audits? Are there obligations to disclose the use of artificial intelligence to customers/clients?
-
Are there legal requirements or best practice expectations for human oversight and human-in-the-loop in artificial intelligence systems?
-
Are there specific legal or regulatory requirements addressing algorithmic bias, discrimination, or fairness in AI systems (including gender bias)?
-
What legal frameworks apply to AI-related harm and defective artificial intelligence systems? Who can be held liable (developer, deployer, victim of the damage, others), how is liability allocated, and what burden of proof applies to victims?
-
What cybersecurity obligations apply to AI systems?
-
Is the use of artificial intelligence insured and/or insurable in your jurisdiction, including with cyber policies? Are there market trends, or limitations?
-
Can artificial intelligence be named as an inventor in a patent application filed in your jurisdiction? If not, what is the current legal position?
-
Do images or works generated by and/or with artificial intelligence benefit from copyright protection in your jurisdiction? If so, who is the authorship attributed to, and under what conditions?
-
What are the main issues to consider when using artificial intelligence systems in the workplace? Have any new regulations, or guidelines, been introduced regarding AI-driven hiring, performance assessment, or employee monitoring?
-
What are the main privacy/data protection issues arising from artificial intelligence development and use (including training data)? Have data protection authorities issued guidelines or rulings on artificial intelligence, and what are the key takeaways?
-
How is data scraping regulated in your jurisdiction from an IP, privacy and competition perspective? Are there recent precedents addressing the legality of data scraping for training of artificial intelligence systems?
-
To what extent is the prohibition of data scraping in the terms of use of a website enforceable?
-
Does your country have a regulator or authority responsible for supervising the use and development of artificial intelligence? What are its powers and enforcement tools?
-
How widespread is the adoption of artificial intelligence in businesses in your jurisdiction, and which sectors are leading?
-
How is artificial intelligence used in the legal sector, by lawyers and/or in-house counsels? Are AI-driven legal tools widely adopted, and what are the main regulatory concerns?
-
What are the 5 key challenges and the 5 key opportunities raised by artificial intelligence for lawyers in your jurisdiction?
-
Where do you see the most significant legal developments in artificial intelligence in your jurisdiction in the next 12 months? Are there any ongoing initiatives that could reshape AI governance?