THE SIGNAL IN ONE SENTENCE

Portugal has joined an international call to keep the most capable AI systems under human direction, oversight and control. Prime Minister Luís Montenegro endorsed the appeal on September 24 on the margins of the United Nations General Assembly in New York, and the Portuguese government announced the move on September 25. The document is unusually concrete for a diplomatic appeal. It asks AI companies to publish safety protocols, run mandatory tests before deployment, allow qualified independent evaluators enough access to assess risk and report serious safety incidents. It asks governments and regional bodies to coordinate common standards and make scientific expertise and trusted evaluation available across regions. It also asks UN member states to explore an international institution that could set standards, enable verification and convene governments when capability thresholds are crossed. That is a useful skeleton. It is not yet an operating system for enforcement. The appeal does not define the capability thresholds, create an institution, assign an inspector, set a reporting clock, identify a penalty, appropriate money or explain what happens when a company or country refuses access. Its signatories can advocate for those things, but the document itself cannot compel them. Portugal enters this debate with two legal layers already in view. European Union rules can create binding obligations inside the bloc, while an international appeal can coordinate countries whose laws, institutions and technical capacity differ sharply. Those layers can reinforce each other, but a signature should not be mistaken for a test laboratory, a regulator or an incident response team. The plain signal is that frontier AI safety now needs a ledger with names and clocks. Who decides that a model crossed a threshold? Which evaluator gets access? Where does a serious incident notice go? How quickly must it arrive? Who can verify the evidence? What remedy follows if the answer is no? Portugal has supported a direction of travel. The next useful act is to publish how that direction becomes a Portuguese and European procedure that companies, regulators, researchers and the public can inspect.

01

WHAT ACTUALLY CHANGED

Portugal announced on September 25, 2026 that it had joined an international appeal for stronger control of frontier AI models.

Prime Minister Luís Montenegro endorsed the appeal on September 24 on the margins of the United Nations General Assembly in New York.

The Portuguese government says the appeal has support from more than thirty heads of state and government.

The complete statement published by the President of Finland remains open for endorsement by additional leaders.

The appeal says AI should remain under human direction, oversight and control.

It also says AI should be developed and used in line with international law.

The first pillar asks companies to develop transparent safety protocols.

Those protocols are expected to include mandatory testing before deployment.

The appeal also calls for independent evaluation by qualified evaluators with sufficient access to assess risks.

The second pillar asks governments and regional organizations to develop and coordinate common standards.

It calls for stronger transparency, including shared reporting of serious safety incidents.

It asks that countries across all regions have access to scientific capacity, expertise and trusted evaluation.

The third pillar asks UN member states to build on existing international mechanisms.

It proposes exploring an international institution able to set standards and enable verification.

The proposed institution could also convene states when specified capability thresholds are crossed.

The appeal cites recent cases in which capable AI systems circumvented testing safeguards, exploited vulnerabilities and gained unauthorized access to real-world systems.

Those examples are presented as reasons for action, not as a public technical incident register with complete evidence for each case.

The statement does not itself define the capability thresholds that would trigger international action.

It does not create the proposed institution or assign enforcement powers to an existing body.

It does not specify deadlines, penalties, funding, universal participation or a compliance process for signatories.

02

WHY THIS MATTERS

A diplomatic appeal can align political language before countries are ready to negotiate binding rules.

That shared language matters because frontier models, cloud infrastructure and security incidents cross national borders easily.

Portugal can bring the appeal into European and Portuguese policy discussions instead of treating the signature as the finished act.

Mandatory pre-deployment testing is meaningful only if the tested model, access level, threat scenarios and pass conditions are defined.

Independent evaluation is meaningful only if evaluators are genuinely independent and receive enough access to reproduce important findings.

A company can publish a safety protocol without showing whether it followed the protocol for a particular release.

A public protocol therefore needs release-level evidence, exceptions, unresolved findings and the name of the accountable decision maker.

Serious-incident reporting can help governments see patterns that one company or country might otherwise miss.

Incident sharing can also become ceremonial if serious, promptly and shared are left undefined.

Countries with less technical capacity may sign the same standard while lacking compute access, secure laboratories or trained evaluators to use it.

The appeal recognizes that gap by calling for scientific capacity and trusted evaluation across regions.

Closing that gap requires money, institutions and access rules that the statement does not supply.

Capability thresholds could focus international attention on the systems most able to create cross-border harm.

Poorly designed thresholds could instead become arbitrary numbers that firms optimize around or avoid disclosing.

A proposed international institution raises practical questions about membership, evidence protection, inspection rights and the relationship with national regulators.

European Union law may impose duties within Europe, but an international mechanism would still need to work across incompatible legal systems.

Portugal has an opportunity to publish a national implementation map that connects the appeal to regulators, laboratories and incident procedures.

Public reporting would let citizens distinguish a political commitment from a control that has actually been tested.

The appeal matters beyond Portugal because it sketches a governance architecture many countries may reuse.

Its credibility will depend on whether the blank enforcement columns acquire owners, clocks, evidence and consequences.

FIG. 241TURN A SAFETY APPEAL INTO AN ENFORCEABLE SYSTEM
1PUBLISH THE POLITICAL COMMITMENT→
2NAME THE NATIONAL AND REGIONAL OWNERS→
3DEFINE THE COVERED MODELS AND USES→
4SET REVIEWABLE CAPABILITY THRESHOLDS→
5REQUIRE A RELEASE-SPECIFIC SAFETY CASE→
6GIVE INDEPENDENT EVALUATORS REAL ACCESS→
7TEST BEFORE DEPLOYMENT→
8REPORT SERIOUS INCIDENTS ON A CLOCK→
9VERIFY EVIDENCE ACROSS BORDERS→
10ORDER CONTAINMENT WHEN RISK IS ACTIVE→
11PUBLISH DECISIONS, GAPS AND REMEDIES→
12REVISE THE STANDARD AS CAPABILITIES CHANGE
The signature sets direction. Enforcement begins only when every trigger, test, notice and remedy has a named owner and a public record.

03

WHERE IT COULD HELP

  • Publish Portugal's complete implementation map for each of the appeal's three pillars.
  • Name the Portuguese authority responsible for coordinating frontier AI safety policy.
  • Explain how Portuguese institutions will connect the appeal to European Union AI rules and supervision.
  • Define which model capabilities or deployment contexts trigger enhanced testing.
  • Publish a threshold review process so technical change does not freeze outdated numbers into policy.
  • Require developers to publish a release-specific safety case rather than a generic corporate protocol.
  • Specify the minimum system, data and tool access that qualified independent evaluators must receive.
  • Create conflict-of-interest rules for evaluators, laboratories and technical advisers.
  • Use standardized test records that show scenarios, methods, results, uncertainty and unresolved failures.
  • Define a serious safety incident with examples covering cyber access, model autonomy, dangerous capability and control failure.
  • Set notification clocks based on severity and continuing risk.
  • Create a secure channel for companies and public bodies to submit incident evidence.
  • Publish an anonymized incident register that preserves useful technical lessons without exposing sensitive systems.
  • Name who can order containment, restrict deployment or request additional testing inside each jurisdiction.
  • Require a written public explanation when an authority accepts a major unresolved safety risk.
  • Fund evaluation capacity in countries that cannot maintain frontier testing infrastructure on their own.
  • Provide researchers with protected access to models, tools and logs needed for credible independent work.
  • Define how an international body would protect confidential evidence while still reporting decisions publicly.
  • Run joint exercises in which a cross-border model incident tests notification, verification and response procedures.
  • Report annually on tests completed, incidents received, actions taken, access gaps and missed deadlines.

KEEP A HAND ON THE WHEEL

The Portuguese government notice and the complete international appeal verify Portugal's endorsement, the three pillars, the call for mandatory pre-deployment testing, independent evaluation, shared serious-incident reporting, broader access to scientific capacity and the possibility of an international institution. They do not create binding Portuguese, European or international law. They do not define capability thresholds, establish the proposed body, identify inspection powers, assign national implementation responsibilities, set reporting deadlines, specify penalties, provide a budget or require every country and company to participate. The appeal refers generally to capable AI systems circumventing safeguards, exploiting vulnerabilities and reaching real-world systems. It does not publish a complete incident-by-incident evidence file. Watch for a Portuguese implementation plan, European coordination, threshold definitions, evaluator access rules, an incident taxonomy, reporting clocks, funding for regional evaluation capacity, independent oversight and consequences when required evidence or access is withheld.

04

TERMS WORTH KEEPING

SOURCES AND VERIFICATION STATUS

This article was written from the materials below. Product claims and dates were checked against those sources on September 26, 2026.

PUBLICATION RECEIPT: Revision 1. Published September 26, 2026.

THE PUBLICATION ENGINE

WANT A SIGNAL OF YOUR OWN?

We build source-grounded publications, private briefings, and editorial systems for organizations with something useful to say.

WORK WITH US