Portugal - Ethical AI in Public Administration

Guide for Ethical, Transparent and Responsible Artificial Intelligence in Public Administration

Guia para uma Inteligência Artificial ética, transparente e responsável na Administração Pública

Portugal

RAI-PT-NA-GPUIAXX-2022
In Force(In Force)
GuidelineGovernance and OversightTransparency and DisclosureRisk Management
Export PDF

The AMA Guide (GuIA) is a non-binding practical framework published by the Portuguese public administration’s modernisation agency to promote ethical, transparent and responsible use of Artificial Intelligence in the public sector. It sets principles, five evaluation dimensions (accountability, transparency, explainability, fairness and ethics), and provides a risk-assessment tool and implementation guidance aimed at public entities, but reusable by academia and private sector actors.

Overview

The "GuIA" is a practical, non‑binding guidance package published by the Portuguese public modernisation agency to support ethical, transparent and responsible AI in public administration. Launched at the AI4PA Digital Innovation Hub event on 26 January 2022 and published for the public on official portals, the GuIA provides principles, operational recommendations and a structured assessment instrument to help public entities plan, procure, implement and monitor AI projects. It is intended primarily for Portuguese public administration practitioners but is explicitly reusable by academia and private-sector actors. The GuIA aims to align good practice with national digital transformation priorities and with European-level initiatives; official project pages and publication notices are available from AMA and Portugal’s digital government portals (see AMA announcement and the public data posting at dados.gov.pt).

Definitions

The GuIA defines core terms in plain language adapted to public administration contexts. "Artificial Intelligence" is described operationally (algorithms, machine learning models and data-driven decision‑support systems) and distinctions are drawn between assistive/decision‑support AI and fully automated decision-making. The guide clarifies "explainability" (the capacity to provide human‑understandable reasons for outputs), "transparency" (documented disclosure of use, purpose and limits), "responsabilization" (clear assignment of roles and legal/operational accountability), "justice/fairness" (measures to prevent discriminatory outcomes) and "ethics" (values‑based constraints, including respect for human dignity and public interest). A short glossary situates these terms in relation to GDPR concepts like personal data and data controllers/processors, and to EU policymaking language.

Governance and Institutional Framework

The GuIA recommends layered governance for AI in public administration: entity‑level leadership (senior sponsor and steering committee), project‑level accountability (product owner, model owner, responsible data steward), and cross‑cutting oversight (ethics or AI review board). It encourages the creation of AI policy owners and designated points of contact for risk assessment and external inquiries. The guide endorses institutional mechanisms for procurement controls and pre‑deployment review and suggests embedding the GuIA's assessment tool into standard project intake and procurement checklists. It explicitly cross‑references existing national strategies and institutional responsibilities and points readers to AMA and digital government resources for coordination and capacity building (see Digital Government Portugal and the AMA resource pages linked on the official publication announcement).

Key Focus Areas

The GuIA is structured around five central evaluation dimensions: (1) Responsabilization — assignable roles, contractual clarity, audit trails and redress pathways; (2) Transparency — user-facing disclosure of AI use, decision summaries and procurement transparency; (3) Explicability — techniques and documentation to make outputs interpretable to technical and non-technical stakeholders; (4) Justice/Fairness — bias identification and mitigation, inclusive datasets, and impact analyses for equity; and (5) Ethics — adherence to democratic values, proportionality, minimisation of harm and respect for fundamental rights. Operational recommendations include: (a) data governance controls (quality checks, lineage and retention policies); (b) model documentation and versioning (design decisions, training data descriptions, performance metrics); (c) testing and validation (pre‑deployment testing across representative subpopulations, adversarial and robustness testing); (d) human oversight provisions (human-in-the-loop or human-on-the-loop depending on risk level); (e) logging and audit readiness (comprehensive logs supporting external review and accountability); and (f) stakeholder engagement (public consultations, accessible information for affected individuals). The guide provides sector examples (benefits allocation, health triage, case prioritisation) and stresses proportionality — more intrusive or higher‑impact uses require stronger governance and controls.

Implementation Framework

The GuIA presents a practical implementation model including an intake and scoping checklist, a staged maturity roadmap (from exploratory research to operationalised and responsible AI), and the complementary "Ethical Risk Assessment Tool" that allows teams to score projects on risk dimensions and receive tailored recommendations. It provides sample procurement clauses to require documentation, maintainability and third‑party audit rights; guidelines for pilot design; templates for user notices and consent language; and a recommended lifecycle of development, testing, deployment, monitoring and decommissioning. The guide stresses integration with existing legal obligations (for instance, data protection impact assessments under the GDPR) and with internal change‑management processes. For capacity building, the GuIA recommends cross-disciplinary teams including technical, legal, ethics and domain experts and encourages training programs and reuse of shared components and datasets with documented provenance.

Monitoring and Evaluation

The GuIA establishes ongoing monitoring practices: routine performance monitoring (accuracy, fairness, drift detection), scheduled re‑validation (periodic re-testing), incident logging and escalation protocols. It proposes metrics and KPIs for transparency and fairness, recommends continuous stakeholder feedback loops, and suggests publishing high‑level audit summaries to promote public accountability. The accompanying assessment tool supports multi‑year evaluation programs and collective learning across entities by aggregating anonymised results and recommending sectoral benchmarks. The guide underscores the need to monitor both technical behaviour and social impact, and to record remediation actions taken after adverse outcomes.

Penalties, Liability, and Appeals

As a guidance framework, the GuIA itself does not establish statutory penalties; rather it frames legal and accountability implications that arise from failure to comply with existing binding obligations (for example data protection requirements under the GDPR, public procurement law and sectoral statutory duties). The guide recommends that entities document decision processes to enable administrative review and to support defence in liability claims. It advises creation of internal appeal routes for individuals affected by AI-assisted administrative decisions and recommends clear contact points for redress and transparent procedures to correct data and contest outputs. Although the GuIA is not an enforcement instrument, adoption of its recommendations is positioned as risk‑mitigating for entities subject to regulatory enforcement under other laws.

Relationship to Other Instruments

The GuIA situates itself as complementary to national strategies and international instruments. It is explicitly designed to be used together with national digital transformation plans, data governance initiatives and general legal frameworks such as the GDPR, national transparency obligations and public procurement rules. The guide references EU-level developments and is intended to assist public bodies in preparing for compliance obligations introduced by the European AI legislative framework. It also cross-references existing AMA documents and other public administration guides and is meant to feed into agency-level policies and procurement templates.

International Alignment

Although written for Portugal’s public administration, the GuIA is aligned with international best practices and policy orientations emerging from the European Commission and Council of Europe — emphasising human rights protection, risk‑based approaches and transparency. The guide cross-checks recommended approaches with contemporary EU guidance and suggests that public bodies use the GuIA as a bridge between operational project practice and incoming EU obligations (for example, the EU AI Act classifications and risk categories), while also pointing to international resources and comparative practices for specialised topics such as biometric systems and law-enforcement use-cases.

Implementation Timeline

EventDateNotes
GuIA launch at AI4PA2022-01-26Public launch event of AI4PA and initial GuIA dissemination.
Public posting on dados.gov.pt2022-02-15Official data portal publication and links to full documents.
Consultation closure (initial)2022-02-28End of first public consultation window for contributions.
Subsequent dissemination and updates2022–ongoingAMA and digital government portals host updated summaries, short versions and tool updates.

Compliance Checklist

Checklist itemAction
GovernanceAppoint senior sponsor and designate model owner; establish review board.
Risk assessmentRun the GuIA Ethical Risk Assessment Tool and document results.
Data governanceDocument data sources, apply quality controls, and record retention/lineage.
TransparencyPublish clear user notices and high-level model summaries for public-facing systems.
ExplainabilityProvide interpretable explanations suitable for affected stakeholders.
TestingPerform pre-deployment validation, fairness tests and robustness checks.
MonitoringImplement runtime monitoring, drift detection and scheduled re‑validation.
RedressDefine appeal pathways and contact points for affected individuals.

Sources and References

SourceType
AMA — GuIA launch announcementPrimary Source
dados.gov.pt — Publication noticePrimary Source
SGEconomia — reference to AMA GuIAPrimary Source
Plain English

Portugal's AMA Guide offers non-binding practical advice for public administration entities on how to use Artificial Intelligence ethically, transparently, and responsibly, though its principles are also valuable for academia and the private sector.

Published by Portugal's public modernisation agency and launched on January 26, 2022, this guideline aims to help public entities plan, procure, implement, and monitor AI projects. While primarily for the Portuguese public sector, its framework is explicitly designed for reuse by other sectors.

The Guide focuses on five core evaluation dimensions for AI projects: - **Accountability**: Assigning clear roles, ensuring contractual clarity, maintaining audit trails, and establishing redress pathways. - **Transparency**: Disclosing AI use to users, providing summaries of decisions, and ensuring procurement transparency. - **Explainability**: Making AI outputs interpretable for both technical and non-technical stakeholders. - **Fairness**: Identifying and mitigating bias, using inclusive datasets, and conducting impact analyses for equity. - **Ethics**: Adhering to democratic values, proportionality, harm minimisation, and respect for fundamental rights.

To achieve these, the Guide recommends robust data governance, comprehensive model documentation, thorough pre-deployment testing (including for fairness and robustness), and human oversight mechanisms. It also stresses the importance of logging, audit readiness, and continuous stakeholder engagement.

Crucially, the AMA Guide itself does not impose new legal penalties. Instead, it serves as a framework to help entities comply with existing binding laws, such as the General Data Protection Regulation (GDPR) and public procurement rules. A key takeaway is that while non-binding, adopting its recommendations can significantly mitigate risks of non-compliance with these other, legally enforceable obligations. Public entities are encouraged to establish internal appeal routes for individuals affected by AI decisions and to document processes for administrative review. The Guide also provides an "Ethical Risk Assessment Tool" to help teams score projects and receive tailored recommendations.

Plain-English rewrite by Regulations.ai — not legal advice. Verify against the official text.

What you must do — compliance checklist

0 / 12 marked complete

Plain-English obligations under Portugal - Ethical AI in Public Administration. Not legal advice — verify against the official text before relying on it.

  1. #1CriticalImplementation FrameworkBefore system deployment

    Applies to: Public entities developing or deploying AI systems handling personal data.

    The guide stresses integration with existing legal obligations (for instance, data protection impact assessments under the GDPR)
  2. #2ImportantGovernance and Institutional Framework

    Applies to: Public entities developing or deploying AI systems.

    Appoint senior sponsor and designate model owner; establish review board.
  3. #3ImportantImplementation FrameworkBefore placing on market

    Applies to: Public entities developing or procuring AI systems.

    Run the GuIA Ethical Risk Assessment Tool and document results.
  4. #4ImportantKey Focus AreasBefore system deployment

    Applies to: Public entities using data for AI systems.

    Document data sources, apply quality controls, and record retention/lineage.
  5. #5ImportantKey Focus AreasBefore system deployment

    Applies to: Public entities deploying public-facing AI systems.

    Publish clear user notices and high-level model summaries for public-facing systems.
  6. #6ImportantKey Focus AreasBefore system deployment

    Applies to: Public entities deploying AI systems affecting individuals.

    Provide interpretable explanations suitable for affected stakeholders.
  7. #7ImportantKey Focus AreasBefore system deployment

    Applies to: Public entities developing or procuring AI systems.

    Perform pre-deployment validation, fairness tests and robustness checks.
  8. #8ImportantMonitoring and EvaluationContinuously after deployment

    Applies to: Public entities operating AI systems.

    Implement runtime monitoring, drift detection and scheduled re‑validation.
  9. #9ImportantPenalties, Liability, and AppealsBefore system deployment

    Applies to: Public entities deploying AI systems affecting individuals.

    Define appeal pathways and contact points for affected individuals.
  10. #10ImportantKey Focus AreasBefore system deployment

    Applies to: Public entities developing or deploying AI systems.

    bias identification and mitigation, inclusive datasets, and impact analyses for equity
  11. #11ImportantKey Focus AreasBefore system deployment

    Applies to: Public entities deploying AI systems.

    human oversight provisions (human-in-the-loop or human-on-the-loop depending on risk level)
  12. #12ImportantKey Focus AreasContinuously after deployment

    Applies to: Public entities operating AI systems.

    logging and audit readiness (comprehensive logs supporting external review and accountability)

© Regulations.AI — created on 13-Jun-2026