🇵🇹 Daily Portugal news for expats & investors — FREE Subscribe

The EU's AI Act Reaches Its Enforcement Phase, and Portugal Turns to a Late-Chosen ANACOM to Police the New Rules

The EU's AI Act moves into its enforcement phase on 2 August, with fines reaching €35 million or 7% of global turnover. In Portugal the regulator is a late-chosen ANACOM, now racing to build the teams to police transparency rules, general-purpose models and high-risk AI.

The EU's AI Act Reaches Its Enforcement Phase, and Portugal Turns to a Late-Chosen ANACOM to Police the New Rules

The European Union's landmark law on artificial intelligence crossed a decisive threshold this weekend. From 2 August 2026, the rulebook stops being a paper commitment and becomes something regulators can actually enforce — and in Portugal the job of policing it falls to a watchdog that was chosen late and now has to build the muscle to do the work.

The AI Act (the Regulamento da Inteligência Artificial, the EU's first horizontal law on the technology) entered into force back in 2024 and has been switching on in stages ever since. The stage that began on 2 August is the one with teeth: the European Commission's AI Office and the national authorities of the member states now hold the powers to supervise and sanction. The Commission put it plainly, announcing that it "starts enforcing AI Act rules and new transparency requirements on 2 August."

What actually changes

Three sets of obligations move from theory to practice. The first is transparency, and it is the part most people will notice. Chatbots and other interactive systems must now tell you when you are talking to a machine rather than a person. "Deepfakes" — images, video or audio that have been generated or altered by AI — have to be labelled, with machine-readable marks embedded so the content can be flagged automatically downstream.

The second is the regime for general-purpose AI models — the large systems, such as the engines behind popular chatbots, whose providers have faced obligations on documentation, copyright and systemic-risk management since August 2025. What changes now is enforcement: the AI Office can begin to act against providers that fall short.

The third, and heaviest, is the framework for so-called high-risk systems — AI used in areas such as recruitment, credit scoring and healthcare, where a faulty model can quietly decide who gets a job, a loan or a diagnosis. These uses now sit inside a binding rulebook covering risk management, data quality, human oversight and record-keeping.

The penalties are calibrated to make boards pay attention. The most serious breaches — deploying one of the AI practices the law bans outright — can draw fines of up to €35 million or 7% of a company's worldwide annual turnover, whichever is higher. Lesser infringements carry lower ceilings, but the top tier is deliberately set at a level a multinational cannot shrug off.

Portugal's late arrival

Every member state had to do two things to make enforcement real on home soil: designate the national authorities that will supervise and sanction, and pass domestic law setting out the penalties. Portugal was not among the roughly seven countries that met the original deadline in early August 2025 — it missed it and spent the following weeks deciding who should hold the reins.

The answer, announced on 19 September 2025 by the Secretary of State for Digitalisation (Secretário de Estado da Digitalização), Bernardo Correia, was ANACOM (Autoridade Nacional de Comunicações, the National Communications Authority). ANACOM becomes Portugal's market-surveillance authority for AI and the single point of contact for companies and citizens who need to deal with the regime — a "balcão preferencial", in the government's phrase.

The choice consolidated digital oversight in one place. An earlier plan would have split the work between ANACOM, the CNPD (Comissão Nacional de Proteção de Dados, the National Data Protection Commission) and the ERC (Entidade Reguladora para a Comunicação Social, the media regulator). Instead the government folded the related Digital Services Act (the Regulamento dos Serviços Digitais) into ANACOM as well, betting that a single regulator with long experience of telecoms and technology markets would be steadier than a three-headed arrangement. The enabling bill was approved in the Council of Ministers (Conselho de Ministros) at the end of July 2025 and sent to Parliament to lock down the domestic penalty regime.

Can ANACOM cope?

Designating a regulator on paper is the easy part. Lawyers who follow the file have warned that whether the system works will depend on the resources ANACOM is given — multidisciplinary teams that understand both the law and the engineering, and a genuine national AI office rather than a nameplate. Pedro Lomba and Adolfo Mesquita Nunes, among others, have made the same point: without people and budget, supervisory powers are theoretical.

There is also a moving target. In November 2025 the European Commission floated a package to simplify parts of the digital rulebook, including elements of the AI Act, so some obligations and deadlines could yet be softened or shifted. The direction of travel — disclosure, accountability and real fines — is set, but the fine print is still being argued over in Brussels.

What it means on the ground

For most residents the immediate, visible effect is the transparency layer: the chatbot on a bank or utility website should now identify itself, and AI-generated media should carry a label. For Portuguese businesses that build or deploy AI — from a startup training a model to a company using an automated tool to screen job applicants — the compliance clock is now running, with ANACOM as the authority they will answer to. The law that was easy to ignore while it lived on the page has, as of this weekend, a regulator behind it.

The Portugal Brief tracks how EU rules land in Portugal. This article is for general information and is not legal advice; businesses with AI-compliance questions should seek specialist counsel.