Certification · the AI Act and compliance

Running an AI
company? Congratulations.
The hard part
is not over.

The AI Act applies regardless of your turnover or headcount. Your customers will demand proof of compliance before they buy. Investors already ask for it. And, contrary to what you hear, the deadline that matters is not the same for everyone.

It applies to everyone

Provider, deployer, importer or distributor: the obligations do not depend on size or turnover.

Customers will demand it

Compliance travels down the supply chain. Sell to a regulated company and you get audited by it.

Capital will demand it

European funding and institutional investors already treat the AI Act as a due diligence prerequisite.

01 · How it works

Based on risk,
not on size.

Most European AI companies sit in limited risk or high risk. Classifying your system is the first task — and the only one you cannot delegate.

Unacceptable

Prohibited

Social scoring, manipulative AI, sensitive biometric categorisation. From December 2026, also AI-generated non-consensual intimate images.

Absolute prohibition · fines up to €35m or 7% of global turnover

High risk

Full compliance

Health, transport, finance, recruitment, education, law enforcement, critical infrastructure.

Risk management · technical documentation · human oversight · EU registration

Limited risk

Transparency

Chatbots, deepfakes, content generation, emotion recognition.

Mandatory identification as AI · marking of synthetic content

Minimal risk

No obligations

Spam filters, entertainment recommendation, AI in video games.

No specific obligations · voluntary code of conduct

Are you at risk? If your system operates in one of these areas, yes.

Article 6 and Annex III of Regulation (EU) 2024/1689.

Recruitment and human resources
Education and training
Essential services and credit
Critical infrastructure
Law enforcement
Justice and democratic processes
Migration and border control
Biometrics and sensitive personal data

02 · What you have to produce

42 documents
and procedures.

That is the total for full high-risk certification, varying with operator type and system classification. None of them is optional once the system falls under Annex III.

Across Europe, manual high-risk certification is estimated to cost between €150,000 and €400,000. ENIA works on the assumption that automation can cut that by an order of magnitude — and that is what we are building.

11

Core — essential system documentation

Always
9

Specific to the provider type

Conditional
7

Market placement and user information

Always
6

GPAI regime, for general-purpose models

Conditional
6

Situational, depending on the use case

Conditional
3

Internal governance and responsibilities

Always
42

Total for full high-risk compliance

03 · The full picture

It is not just the AI Act.

Five other regulations apply at the same time. Treating them as separate projects multiplies the cost and produces contradictory documentation.

RGPD

Data protection

Applies to virtually every AI system that processes personal data.

DSA

Digital services

All digital services with recommendation and moderation algorithms.

NIS2

Cybersecurity

Critical infrastructure and its supply chain.

DORA

Operational resilience

Direct impact on financial services and their IT suppliers.

CRA

Cyber Resilience Act

All connected digital products, from 2027.

PRODUTO

Product safety

Classic safety certifications now extend to digital as well.

04 · Updated timeline

What the Digital Omnibus
changed — and what
it did not.

A lot of communication still cites August 2026 as the high-risk deadline. It is not. But August 2026 remains a deadline — for something else.

February 2025 · in force

Prohibited practices and AI literacy

Social scoring, manipulative AI and sensitive biometric categorisation are already banned. The AI literacy duty (Article 4) is already enforceable against every organisation using AI.

August 2025 · in force

GPAI, the AI Office and the penalties regime

Technical documentation, copyright compliance and a public summary of training data become obligations for general-purpose models.

2 December 2026

Legacy systems and new prohibitions

Article 50(2) starts to apply to systems already on the market. New prohibitions on non-consensual intimate content and child sexual abuse material come into force.

2 August 2027

National sandbox becomes mandatory

Every Member State must have at least one AI regulatory sandbox running (Article 57). Portugal has yet to announce its own.

2 December 2027

High risk — Annex III

Full compliance for stand-alone high-risk systems. Moved from August 2026 by the Digital Omnibus.

2 August 2028

High risk — Annex I

AI embedded in regulated products: medical devices, machinery, vehicles. Moved from August 2027.

One caveat that matters

The Digital Omnibus on AI reached political agreement on 7 May 2026, was approved by the European Parliament on 16 June and finally approved by the Council on 29 June. The new deadlines, however, only take legal effect once published in the Official Journal. Until that publication, the original calendar technically remains applicable.

If you are planning around the new dates, check the publication status. This is the kind of detail that separates a compliance plan from a good intention — and it is what the Radar.

05 · What ENIA does

Making the rules
manageable.

As we put it to ANACOM: we believe the AI Act can benefit Portuguese AI companies if it lets them draw level with Europe’s best in access to funds and finance. But Portugal has to know how to make the system move.

Regulatory mapping

Which regulations apply to your system, and in what order of priority.

Documentation structure

Which documents to produce, with what content and in what sequence.

Audit preparation

What a notified body will ask for, and how not to be caught producing it on the spot.

Continuous monitoring

Compliance is not an event. What changes, changes with warning — if someone is watching.

Team coordination

Joining up technical, legal and product teams, who rarely speak the same language.

AVAILABLE

Automatic classification

The free risk classification test for Portuguese AI. Nine questions and out comes your risk tier, the applicable obligations, the deadlines and the estimated documentation for your case.

Take the test

ENIA leads AI Act testing and planning in Portugal: pilot projects, state-of-the-nation studies and the only free national point of contact. We do not sell compliance — we build the instrument that makes it reachable for anyone without €400,000 to spend on a manual process.

06 · Official European Union sources

Go to the source.
We do, every day.

Do not take our reading on trust. These are the official points of access — and they are free.

07 · Start now

For some of you,
the right time
was yesterday.

Being early pays reputationally — and many procurement processes will exclude anyone uncertified. “AI Act compliant” will become a trust mark like SOC 2 or ISO 27001. Use the AI Act as competitive advantage.