Caixa Mágica Software is now part of the Claude Partner Network, and architects on our team hold the Claude Certified Architect, Foundations credential from Anthropic.
The announcement arrives in the same weeks as three regulatory dates: the EU AI Act's transparency obligations and full penalty regime became enforceable on 2 August 2026, and the Cyber Resilience Act's 24-hour vulnerability reporting duty starts on 11 September. That overlap is worth pausing on, because the two things are more closely connected than a partnership announcement usually suggests.
For three years the hard question in enterprise AI was whether the technology could do the work. That question is largely settled. The hard question now is different: can you explain how a system reaches its outputs, show what data it touched, demonstrate that a person can intervene, and produce all of it on request to a national supervisory authority. That is an architecture question long before it is a legal one.
What the Claude Partner Network is and what certification covers
The Claude Partner Network is Anthropic's programme for organisations that design, build and operate production systems on Claude. Membership gives access to technical guidance, product roadmap information and a defined support channel for the situation that matters most: when something in production behaves in a way the documentation does not fully explain.
The certification is examined externally, through Pearson VUE, and is held by named individuals rather than by a company. The programme covers practitioner, architect and developer roles, and the architect credential is oriented around system design rather than prompt writing. That distinction carries most of the practical weight here, so it is worth being specific about the work it points at.
Verifying a Claude Partner Network claim
Since more than 40,000 firms have applied to the programme, a partner badge alone tells a buyer very little. Two questions separate signal from decoration. How many individuals at the firm hold an active certification, and which track and tier is the firm in? Both are published information, and the tier requirements are quantitative, covering certified headcount, production deployments in the trailing twelve months and public customer stories. Ask for the answers rather than the logo.
Why the timing matters
Most coverage of the AI Act's August date focused on the delay. The high-risk obligations under Annex III moved to 2 December 2027, which does give some teams meaningful additional time, as our note on what actually changed in August sets out.
What did not move is the part reaching the widest set of organisations. Article 50 transparency obligations are enforceable, as are the general-purpose model requirements, the penalty regime reaching €35 million or 7% of global annual turnover for prohibited practices, and the investigative powers of national authorities. Read alongside the CRA's 24-hour reporting duty, the direction is unambiguous. European regulation is converging on one demand: produce evidence. Not a policy document describing intent, but a record of what the system does, generated by the system itself.
Evidence of that kind cannot be added at the end of a project. Either it is a property of the architecture or it is a retrofit, and retrofits in AI systems are expensive in a specific way. Adding traceability to a system that was not built to emit it usually means changing where decisions are made, which means changing the system.
The distance between a working pilot and a documented production system
That distance is consistently underestimated. A pilot needs to work often enough to be convincing. A production system in a regulated environment needs six things a pilot rarely has: a defined evaluation set, logging at the level of the decision rather than the request, a human oversight point that is real rather than theoretical, a dated and reviewed risk classification, an incident path with a definition of what counts as an AI incident, and predictable per-operation cost.
Teams that build these in from the first sprint spend perhaps ten to fifteen per cent more upfront. Teams that add them afterwards routinely rebuild. The pattern mirrors what we described about software quality evidence, where the assembly cost lands entirely on whoever left the layer out.
Where architecture decisions become compliance decisions
Four decisions carry most of the downstream consequence, and each is cheap at design time.
Agentic systems widen the surface
The systems being commissioned now are not classifiers. They are agents: models that call tools, read and write data, and chain steps toward a goal with limited supervision. That shift changes the security and compliance picture substantially.
Model supply chain matters too. Under the CRA, organisations that bundle third-party components are manufacturers with reporting obligations, and AI components are components. A model served through an API, a vector database, an orchestration framework and an embedding library all belong in a software bill of materials, each one a potential compliance event with a 24-hour clock attached from 11 September. This is why we treat AI architecture and security architecture as one practice rather than two. Offensive security research presented at the August conferences tends to become the European regulatory expectation within a year.
What the Claude Partner Network changes for a client project
What it does not change is the approach. A certification is evidence of discipline, not a substitute for it, and no partner programme makes a badly scoped project succeed.
Why we joined the Claude Partner Network from Portugal
Three of the regulations shaping enterprise technology in 2026 extend obligations directly to third-party ICT providers. DORA requires financial institutions to actively manage the compliance posture of their technology suppliers. The CRA places duties on manufacturers that bundle open source components. The AI Act reaches any provider placing AI systems on the EU market.
A development partner inside the EU starts from a different baseline, as we argued in more detail about nearshore Portugal. GDPR is native rather than adapted. Data residency is a matter of fact rather than of contract. There is no gap to bridge between your regulatory environment and your partner's, because they are the same environment. Portugal placed third in the OECD Digital Government Index 2025 with a score of 0.86, the highest in Europe, and Caixa Mágica has spent more than twenty years delivering software for European institutions in identity, finance, energy, telecommunications and public administration.
What we are building with it
Our AI Lab works on systems where the output has consequences: document-heavy workflows in regulated industries, decision support where the reasoning has to be inspectable, and agentic automation inside organisations that answer to a supervisor. Alongside that we build digital identity infrastructure, including EUDI Wallet integration, and quality engineering platforms that produce the evidence chains DORA requires.
The governance layer the AI Act now mandates, with documented risk classification, real human oversight and auditable outputs, is how we have always built. The partnership and the certification make that faster and better evidenced. They do not change the method.


