Information Technology 2026

PORTUGAL Law and Practice Contributed by: Luís Portela de Carvalho, Pedro Cortés and Cláudia de Azevedo Neves, Lektou

4. IT Services 4.1 Overlay of Requirements

Suppliers usually try to keep AI liability within the gen - eral liability cap and exclude indirect or consequential loss. Customers, especially in regulated or high-risk deployments, often push for higher caps or carve-outs for data protection breaches and intellectual property infringement. Indemnities are most often seen in relation to third- party intellectual property claims or unlawful use of data. The allocation of liability is also influenced by the AI Act’s distinction between providers, deployers, importers and distributors, since parties increasingly try to align contractual responsibility with the regula - tory role each party performs. 3.3 Key Concerns of Providers Providers of AI solutions are mainly concerned with controlling risk in a fast-moving regulatory and techni - cal environment. Their key concerns include the fol - lowing. • Liability exposure – providers are reluctant to accept uncapped liability for outcomes affected by customer instructions, poor data quality, misuse or model limitations. • Regulatory compliance – the evolving and complex regulatory landscape, including the AI Act, GDPR, cybersecurity requirements and sector-specific rules, creates practical challenges in demonstrat - ing compliance, including through documentation, testing, monitoring, human oversight and govern - ance measures. • Confidentiality and IP protection – providers need to protect model architecture, training data, prompts, evaluation methods and trade secrets while still giving customers enough information for due diligence and compliance. • Data rights – providers often seek contractual rights to use data, particularly non-personal, aggre - gated or properly anonymised data, to improve services and develop models, while managing customer concerns about data use. • Performance expectations – many AI systems can - not deliver complete accuracy or full explainability. Providers therefore try to avoid warranties that imply error-free performance or a level of trans - parency that the technology cannot realistically provide.

The provision of IT services in Portugal is affected by several horizontal regimes, depending on the nature of the service and the customer’s sector. • Data protection – where the service involves per - sonal data, the GDPR and Law No 58/2019 apply, including rules on lawful processing, security, data-processing agreements, sub-processing and breach notification. • Cybersecurity – entities covered by Decree-Law No 125/2025 must adopt cybersecurity risk- management measures and address supply-chain risks, including risks arising from cloud, managed services and other IT suppliers. Sector-specific rules may also apply. Telecoms, finan - cial services, healthcare and public sector customers may be subject to additional requirements on avail - ability, integrity, resilience, outsourcing and incident reporting. Consumer protection rules are also relevant where IT services are supplied to consumers, particularly for conformity, remedies and pre-contractual information. 4.2 Liability Clauses Typical Structure Liability clauses in Portuguese IT services contracts usually combine a general cap with exclusions and specific carve-outs. The cap is often calculated by ref - erence to fees paid or payable during a defined peri - od, commonly 12 months. Contracts also frequently exclude loss of profits, loss of business, reputational damage and other indirect or consequential losses. Depending on the transaction, carve-outs may apply for wilful misconduct (dolo), death or personal injury, confidentiality breaches, data protection breaches and intellectual property infringement. Mandatory Law Considerations Contractual limitations cannot remove mandatory statutory liability. This is relevant, for example, in consumer contracts, product liability, data protection and cases involving wilful misconduct. Portuguese

58 CHAMBERS.COM

Powered by