Legal Landscapes: Portugal- Artificial Intelligence
1. What is the current legal landscape for Artificial Intelligence in your jurisdiction?
The Portuguese legal landscape for AI is evolving rapidly, driven primarily by the AI Act and the broader EU digital regulatory framework. Rather than introducing standalone domestic legislation, Portugal has opted to implement the AI Act through a multi-authority governance model involving sector-specific regulators. As part of this approach, Portugal has published its list of the fourteen entities responsible for supervising fundamental-rights protection in the context of high-risk AI systems, with the National Communications Authority (‘ANACOM’) appointed as the lead national supervisory authority responsible for coordinating that network.
At the same time, businesses must navigate a complex regulatory environment in which the AI Act intersects with the General Data Protection Regulation, cybersecurity legislation, intellectual property law, consumer protection and sector-specific rules governing areas such as financial services, healthcare and telecommunications.
As AI adoption gathers momentum, the focus is shifting from understanding the new rules to embedding effective AI governance into day-to-day operations. Businesses are therefore increasingly expected not only to comply with their legal obligations, but also to demonstrate such compliance. According to Portugal’s Statistics Office, 11.5% of Portuguese companies were using AI technologies in 2025, up from 8.6% in the previous year. Although adoption remains relatively modest, the upward trend highlights the growing importance of establishing effective governance models.
A significant step in the national strategy was the formal approval of the National Artificial Intelligence Agenda (Agenda Nacional para a Inteligência Artificial – ‘ANIA’) by Council of Ministers Resolution 2/2026. The strategy establishes a five-year action plan (‘PAANIA’) for 2026–2030 structured around four strategic pillars: infrastructure and data, innovation and adoption, talent and skills, and responsibility and ethics.
The ANIA is implemented through 32 concrete initiatives spanning universities, research centres, businesses (including startups) and public administration, and is expressly intended to serve as Portugal’s primary vehicle for aligning national policy with the European Commission’s AI Continent Action Plan and Apply AI Strategy. Among its stated ambitions, the ANIA envisages that faster AI adoption could contribute between EUR 18 billion and EUR 22 billion to Portugal’s GDP over the next decade while increasing productivity growth by as much as 2.7 percentage points. AI governance is therefore being framed not simply as a matter of regulatory compliance but as a driver of economic competitiveness.
This strategic layer sits alongside, rather than replaces, the AI Act’s binding requirements, and businesses operating in Portugal are increasingly expected to read the two together: the ANIA provides a clear indication of where public investment and institutional attention will be directed over the coming years, while the AI Act continues to set the binding floor for lawful AI development and deployment. How successfully these two layers are reconciled in practice will do much to determine whether Portugal’s ambitions for AI-driven growth translate into a genuinely workable compliance environment for businesses.
2. What three essential pieces of advice would you give to clients involved in Artificial Intelligence matters?
First, approach AI as a governance issue rather than merely a technology project. Effective governance, including risk management, internal policies and well-defined accountability across the AI lifecycle is becoming as important as technical capability. In practice, this means assigning clear owners for AI risk within the organisation, maintaining an inventory of AI use cases and their risk classification, and ensuring that governance is embedded from the outset of any AI initiative rather than retrofitted once a system is already in use. This is particularly important for organisations procuring AI systems from third-party vendors rather than building them in-house, since legal responsibility for compliance does not simply transfer to the vendor by virtue of a supply contract. Clients are therefore advised to negotiate contractual protections covering audit rights, liability allocation and cooperation obligations in the event of a regulatory investigation, rather than relying solely on general representations of compliance.
Second, take a holistic view of AI systems. Compliance with the AI Act alone is unlikely to be sufficient; businesses should also consider data protection, cybersecurity, intellectual property, employment and consumer protection requirements, as well as sector-specific rules that may apply depending on the industry in which the AI system is deployed. In our experience, the most common blind spot is not the AI Act itself, but the interaction between the AI Act and pre-existing regimes: an AI system used in recruitment, for example, may simultaneously raise questions under the AI Act, the GDPR, Portuguese labour law and equality and non-discrimination rules, each with its own compliance logic and enforcement authority.
Third, prepare early. Businesses that map their AI use cases, identify regulatory obligations and implement governance measures at an early stage will be significantly better placed as the AI Act is phased into full application. This remains particularly relevant following the recent Digital Omnibus on AI, which has deferred the application of the high-risk AI rules rather than removed them altogether. Early preparation also has a commercial dimension: clients, business partners and public sector procurers are increasingly asking AI vendors and deployers to demonstrate their governance maturity as a condition of doing business, meaning that readiness is becoming a competitive differentiator rather than merely a defensive compliance measure.
3. What are the greatest threats and opportunities in Artificial Intelligence law in the next 12 months?
The greatest challenge will be helping businesses translate high-level regulatory requirements into practical compliance. Many businesses are already using AI but are still developing the governance structures needed to manage legal, operational and reputational risks. That task has become more complex due to ongoing regulatory change: the recently adopted Digital Omnibus on AI has postponed the main obligations for high-risk AI systems to 2 December 2027 for systems under Annex III, and to 2 August 2028 for systems under Annex I. However, the AI Act’s transparency obligations under Article 50 have applied since 2 August 2026, including requirements relating to AI systems that interact with natural persons, deepfakes and certain AI-generated or AI-manipulated content, subject to limited transitional provisions. Clients who interpret these changes as a general reprieve, rather than a staggered implementation timeline, risk overlooking obligations that already apply.
A related, less visible challenge lies in enforcement capacity. As ANACOM and the other competent national authorities build up their supervisory practice, businesses should expect a period of learning-by-doing on both sides, in which early enforcement decisions and regulatory guidance will do much of the work of clarifying how the AI Act applies in practice.
The greatest opportunity lies in enabling innovation through legal certainty. As noted above, Portugal’s National Artificial Intelligence Agenda frames rapid AI adoption as a material driver of GDP and productivity growth over the next decade, and that ambition is already shaping how public and private investment is being directed. Businesses that implement robust AI governance now will be better placed to adopt AI confidently, build trust with customers and regulators and gain a competitive advantage as enforcement ramps up.
The coming months also present a significant opportunity for legal advisers. As businesses move beyond pilot projects towards enterprise-wide AI deployment, many are actively looking to embed compliance into procurement and vendor selection from the outset, rather than treating it as an afterthought. This creates growing demand for advice that is genuinely value-adding rather than purely remedial. Firms that combine regulatory knowledge with a practical understanding of how AI systems are designed, procured and deployed, and that can translate national strategic priorities into workable governance and contractual solutions, will be best placed to capture that opportunity and help clients turn the next months of regulatory transition into a lasting competitive advantage.
4. How do you ensure high client satisfaction levels are maintained by your practice?
AI rarely raises issues confined to a single area of law. Our approach is therefore inherently multidisciplinary, bringing together expertise in TMT, data protection, cybersecurity, intellectual property, employment and consumer protection to provide clients with coordinated and commercially focused advice. A typical AI governance mandate will draw on lawyers from several of these practice areas working as a single team, rather than being handled sequentially by different departments, so that clients receive one coherent view of their risk position instead of a patchwork of separate opinions that may not fit together.
We place a strong emphasis on responsiveness, clear communication and setting realistic expectations from the outset. Clients value pragmatic, risk-based guidance that reflects their commercial objectives. In a fast-moving area such as AI, that means staying close to developments, identifying issues early and helping clients move from legal analysis to implementation with confidence. It also means being honest about areas of genuine legal uncertainty, such as the interaction between the AI Act and national liability rules, rather than presenting false certainty, and being available to revisit advice quickly as guidance, case law or enforcement practice develops.
We are also investing in cross-disciplinary training so that our lawyers develop a broad understanding of the legal issues that AI projects typically engage. This enables them to spot issues outside their individual areas of specialism and provide professional advice that reflects the wider regulatory landscape.
5. What technological advancements are reshaping Artificial Intelligence law and how can clients benefit from them?
The rapid evolution of foundation models, generative AI and, increasingly, autonomous AI agents capable of planning and executing multi-step tasks with limited human intervention, is fundamentally changing both the regulatory landscape and the way organisations operate. AI agents in particular raise questions that go beyond the AI Act’s original focus on single, discrete decisions: when an agent can chain together several actions, procure services, or interact with third-party systems on a company’s behalf, questions of accountability, human oversight and liability become considerably harder to allocate along a traditional value chain.
At the same time, advances in AI governance tools, model monitoring, explainability and compliance automation are making it easier for organisations to operationalise legal requirements, for example by automatically generating audit trails, flagging high-risk use cases for review, or documenting the human oversight measures applied to a given system. Clients that combine these technologies with appropriate governance can accelerate innovation while strengthening compliance and reducing legal risk, turning what might otherwise be seen as a purely defensive exercise into a source of operational efficiency.
In practice, this means legal advice increasingly needs to be embedded into the technical design of AI systems from the outset, for instance through concrete design constraints such as mandatory checkpoints for human review before an autonomous agent takes certain categories of action, rather than delivered as a standalone memorandum once the system is already built.
6. Describe a particularly interesting or complex matter you have advised on recently, and explain the challenges involved, your approach, and the outcome achieved for the client?
We have advised clients across multiple sectors, including financial services, healthcare, retail and technology, on the assessment and deployment of AI systems, including the design of AI governance frameworks aligned with the AI Act and other applicable legislation. These matters typically involve multidisciplinary issues spanning data protection, intellectual property, cybersecurity, procurement and sector-specific regulation, and increasingly require us to assess not only single AI tools but entire portfolios of AI use cases developed or procured across different parts of a client’s business, each with its own risk profile and regulatory classification. In several cases, this has meant working alongside a client’s procurement and IT teams from the earliest stages of vendor selection, so that AI Act considerations, data protection requirements and contractual protections are built into the negotiation of AI licensing and services agreements from the outset, rather than being addressed retrospectively once a system is already in use.
A particularly complex aspect has been helping clients move from experimental AI use to enterprise-wide deployment, including the adoption of AI agents that operate with a degree of autonomy across internal workflows. This requires not only assessing legal compliance but also establishing internal governance structures, allocating responsibilities between business, technology and legal teams, reviewing contractual arrangements with AI providers, including provisions on liability, IP ownership and data use, and embedding practical controls throughout the AI lifecycle, from procurement and testing to deployment and post-market monitoring. Our approach focuses on delivering solutions that are both legally robust and operationally workable, enabling clients to adopt AI confidently while managing regulatory and business risks, and to demonstrate that confidence to regulators, business partners and their own customers.