It applies to everyone
Provider, deployer, importer or distributor: the obligations do not depend on size or turnover.
Certification · the AI Act and compliance
The AI Act applies regardless of your turnover or headcount. Your customers will demand proof of compliance before they buy. Investors already ask for it. And, contrary to what you hear, the deadline that matters is not the same for everyone.
Provider, deployer, importer or distributor: the obligations do not depend on size or turnover.
Compliance travels down the supply chain. Sell to a regulated company and you get audited by it.
European funding and institutional investors already treat the AI Act as a due diligence prerequisite.
01 · How it works
Most European AI companies sit in limited risk or high risk. Classifying your system is the first task — and the only one you cannot delegate.
Unacceptable
Social scoring, manipulative AI, sensitive biometric categorisation. From December 2026, also AI-generated non-consensual intimate images.
Absolute prohibition · fines up to €35m or 7% of global turnover
High risk
Health, transport, finance, recruitment, education, law enforcement, critical infrastructure.
Risk management · technical documentation · human oversight · EU registration
Limited risk
Chatbots, deepfakes, content generation, emotion recognition.
Mandatory identification as AI · marking of synthetic content
Minimal risk
Spam filters, entertainment recommendation, AI in video games.
No specific obligations · voluntary code of conduct
Article 6 and Annex III of Regulation (EU) 2024/1689.
02 · What you have to produce
That is the total for full high-risk certification, varying with operator type and system classification. None of them is optional once the system falls under Annex III.
Across Europe, manual high-risk certification is estimated to cost between €150,000 and €400,000. ENIA works on the assumption that automation can cut that by an order of magnitude — and that is what we are building.
Core — essential system documentation
AlwaysSpecific to the provider type
ConditionalMarket placement and user information
AlwaysGPAI regime, for general-purpose models
ConditionalSituational, depending on the use case
ConditionalInternal governance and responsibilities
AlwaysTotal for full high-risk compliance
03 · The full picture
Five other regulations apply at the same time. Treating them as separate projects multiplies the cost and produces contradictory documentation.
RGPD
Applies to virtually every AI system that processes personal data.
DSA
All digital services with recommendation and moderation algorithms.
NIS2
Critical infrastructure and its supply chain.
DORA
Direct impact on financial services and their IT suppliers.
CRA
All connected digital products, from 2027.
PRODUTO
Classic safety certifications now extend to digital as well.
04 · Updated timeline
A lot of communication still cites August 2026 as the high-risk deadline. It is not. But August 2026 remains a deadline — for something else.
February 2025 · in force
Social scoring, manipulative AI and sensitive biometric categorisation are already banned. The AI literacy duty (Article 4) is already enforceable against every organisation using AI.
August 2025 · in force
Technical documentation, copyright compliance and a public summary of training data become obligations for general-purpose models.
2 August 2026 · —
This was not postponed. Anyone placing AI-generated content on the European market must label it. If you are shipping generative features, this is your deadline.
2 December 2026
Article 50(2) starts to apply to systems already on the market. New prohibitions on non-consensual intimate content and child sexual abuse material come into force.
2 August 2027
Every Member State must have at least one AI regulatory sandbox running (Article 57). Portugal has yet to announce its own.
2 December 2027
Full compliance for stand-alone high-risk systems. Moved from August 2026 by the Digital Omnibus.
2 August 2028
AI embedded in regulated products: medical devices, machinery, vehicles. Moved from August 2027.
The Digital Omnibus on AI reached political agreement on 7 May 2026, was approved by the European Parliament on 16 June and finally approved by the Council on 29 June. The new deadlines, however, only take legal effect once published in the Official Journal. Until that publication, the original calendar technically remains applicable.
If you are planning around the new dates, check the publication status. This is the kind of detail that separates a compliance plan from a good intention — and it is what the Radar.
05 · What ENIA does
As we put it to ANACOM: we believe the AI Act can benefit Portuguese AI companies if it lets them draw level with Europe’s best in access to funds and finance. But Portugal has to know how to make the system move.
Which regulations apply to your system, and in what order of priority.
Which documents to produce, with what content and in what sequence.
What a notified body will ask for, and how not to be caught producing it on the spot.
Compliance is not an event. What changes, changes with warning — if someone is watching.
Joining up technical, legal and product teams, who rarely speak the same language.
AVAILABLE
The free risk classification test for Portuguese AI. Nine questions and out comes your risk tier, the applicable obligations, the deadlines and the estimated documentation for your case.
Take the test →ENIA leads AI Act testing and planning in Portugal: pilot projects, state-of-the-nation studies and the only free national point of contact. We do not sell compliance — we build the instrument that makes it reachable for anyone without €400,000 to spend on a manual process.
06 · Official European Union sources
Do not take our reading on trust. These are the official points of access — and they are free.
07 · Start now
Being early pays reputationally — and many procurement processes will exclude anyone uncertified. “AI Act compliant” will become a trust mark like SOC 2 or ISO 27001. Use the AI Act as competitive advantage.