Trackers
Trackers

AI Regulation in Spain: 2026 Update

AI regulation in Spain is shaped primarily by the EU AI Act - the world';s first comprehensive legal framework for artificial intelligence - combined with Spain';s own national implementation measures. Businesses developing, deploying or using AI systems in Spain must now navigate a layered compliance environment that carries real enforcement risk. This guide explains the current regulatory framework, the key obligations by risk tier, Spain';s national supervisory structure, and the practical steps companies should take to remain compliant.

The EU AI Act and its application in Spain

The EU AI Act is a directly applicable EU regulation that entered into force in the summer of recent years and is being phased in progressively. Because it is a regulation rather than a directive, it applies uniformly across all EU member states, including Spain, without requiring transposition into national law. However, member states retain responsibility for designating national competent authorities, setting penalties within the permitted ranges, and enforcing the rules on the ground.

The Act classifies AI systems into four risk tiers: unacceptable risk, high risk, limited risk, and minimal risk. Each tier carries a different set of obligations. Systems that pose an unacceptable risk - such as social scoring by public authorities or real-time biometric surveillance in public spaces in most circumstances - are prohibited outright. High-risk systems, which include AI used in employment decisions, credit scoring, critical infrastructure, education, and law enforcement, face the most demanding requirements. Limited-risk systems, such as chatbots, must meet transparency obligations. Minimal-risk systems, which cover the vast majority of commercial AI tools, face no mandatory requirements under the Act, though voluntary codes of conduct are encouraged.

The phased timeline matters for planning. Prohibitions on unacceptable-risk systems became applicable first. Requirements for general-purpose AI models followed. High-risk system obligations are applying progressively, with the full framework expected to be operational across all categories in the near term. Businesses should not treat the phased rollout as a reason to delay compliance work; regulators in Spain have signalled that they expect proactive engagement.

Spain';s national AI supervisory authority: AESIA

Spain moved ahead of most EU member states by establishing a dedicated national AI supervisory body. The Agencia Española de Supervisión de la Inteligencia Artificial, known by its acronym AESIA, was created by Royal Decree and is headquartered in A Coruña. AESIA is the primary competent authority for AI Act enforcement in Spain and coordinates with the European AI Office, which oversees general-purpose AI models at the EU level.

AESIA';s mandate covers several functions. It supervises compliance by providers and deployers of AI systems operating in Spain. It handles complaints from individuals and organisations affected by AI systems. It issues guidance, conducts audits, and can impose administrative sanctions. It also promotes AI literacy and supports the development of regulatory sandboxes, which are controlled environments where companies can test innovative AI systems under regulatory supervision before full market deployment.

Spain';s regulatory sandbox for AI, established under the framework of the Digital Spain agenda, is one of the few operational AI sandboxes in the EU. Participation is voluntary and competitive, but it offers a meaningful benefit: companies accepted into the sandbox can test their systems with legal certainty and receive direct feedback from AESIA. For startups and scale-ups developing novel AI applications, this is a practical route to de-risk compliance before a full commercial launch.

A common mistake among foreign companies entering the Spanish market is assuming that compliance with their home country';s rules - or even general GDPR compliance - is sufficient. AI Act obligations are distinct and additive. A company that has invested heavily in data protection may still face significant gaps when assessed against AI Act requirements for transparency, human oversight, and technical documentation.

High-risk AI systems: obligations that apply in Spain

For businesses operating high-risk AI systems in Spain, the compliance burden is substantial. The EU AI Act sets out a detailed list of requirements that providers - meaning those who develop or place high-risk AI systems on the market - must satisfy before deployment.

The core obligations for high-risk AI providers include:

  • Establishing and maintaining a quality management system covering the full AI lifecycle, from design through post-market monitoring.
  • Preparing and keeping up to date comprehensive technical documentation that demonstrates conformity with the Act';s requirements.
  • Implementing a logging system that enables traceability of the AI system';s outputs and decisions.
  • Ensuring the system is designed to allow effective human oversight, including the ability to intervene, override or shut down the system.
  • Registering the AI system in the EU database for high-risk AI systems before placing it on the market.

Deployers of high-risk AI systems - companies that use such systems in their operations rather than developing them - also carry obligations. They must use the system in accordance with the provider';s instructions, monitor its operation, and report serious incidents to AESIA. In employment contexts, this is particularly relevant: companies using AI tools for recruitment, performance evaluation or workforce management are likely deploying high-risk systems and must comply accordingly.

In practice, many businesses underestimate the documentation burden. The technical documentation required under the Act is not a brief summary; it must cover the system';s intended purpose, the data used for training and testing, the risk management process, and the results of testing. Preparing this documentation retrospectively, after deployment, is significantly harder than building it into the development process from the outset.

If your business develops or deploys AI systems in Spain and you are uncertain about your risk classification or documentation obligations, contact info@vlolawfirm.com. We can help structure the compliance approach correctly from the start.

General-purpose AI models: a distinct compliance track

General-purpose AI models - large-scale models trained on broad data that can perform a wide range of tasks - are subject to a separate set of rules under the EU AI Act. This category covers the foundation models and large language models that underpin many commercial AI products. Providers of these models face obligations regardless of whether the model is ultimately deployed in a high-risk context.

The baseline obligations for all general-purpose AI model providers include maintaining technical documentation, complying with EU copyright law in relation to training data, and publishing a summary of the content used for training. Models that are made available under open-source licences benefit from some reduced obligations, though not a complete exemption.

Models that are assessed as posing systemic risk - typically the most powerful models, assessed by reference to the computational resources used in training - face additional requirements. These include conducting adversarial testing, reporting serious incidents to the European AI Office, and implementing cybersecurity measures appropriate to the model';s capabilities. The European AI Office, rather than AESIA, is the primary supervisor for general-purpose AI models, though AESIA remains involved in cases where the model is deployed in Spain in a high-risk context.

For Spanish companies that have built products on top of third-party foundation models, the compliance picture is nuanced. The provider of the underlying model carries the obligations relating to the model itself. The company that builds an application on top of it - the downstream provider - carries obligations relating to the application, including any high-risk classification that arises from the application';s intended use. This layered responsibility structure requires careful contractual and technical coordination between model providers and application developers.

Data protection and AI: the GDPR dimension in Spain

AI regulation in Spain cannot be understood in isolation from data protection law. The General Data Protection Regulation applies to any AI system that processes personal data, which covers the vast majority of commercial AI applications. Spain';s national data protection authority, the Agencia Española de Protección de Datos, known as AEPD, has been one of the most active data protection regulators in the EU on AI-related matters.

The AEPD has published guidance on the intersection of GDPR and AI, addressing issues such as the lawful basis for processing personal data in AI training, the rights of individuals whose data is used to train AI systems, and the obligations of organisations that use AI for automated decision-making. Article 22 of the GDPR, which restricts solely automated decisions that produce significant effects on individuals, is directly relevant to many AI deployments in HR, credit, and public services.

The AEPD and AESIA are expected to coordinate closely on cases that engage both data protection and AI Act obligations. In practice, this means that a company facing an AI Act investigation may simultaneously face GDPR scrutiny. The two frameworks have overlapping but distinct requirements, and satisfying one does not guarantee compliance with the other. Companies should conduct a combined assessment rather than treating the two regimes as separate workstreams.

A non-obvious requirement that catches many foreign companies off guard is the obligation to conduct a Data Protection Impact Assessment before deploying AI systems that involve high-risk processing of personal data. This obligation exists under the GDPR independently of the AI Act and applies even to AI systems that are classified as minimal risk under the Act.

Sector-specific AI rules applying in Spain

Beyond the horizontal AI Act framework, several sector-specific rules apply to AI in Spain. These are particularly relevant for companies operating in regulated industries.

In financial services, the European Banking Authority and the European Securities and Markets Authority have issued guidance on the use of AI in credit risk assessment, algorithmic trading, and customer-facing applications. Spanish financial institutions supervised by the Banco de España and the Comisión Nacional del Mercado de Valores must align their AI governance frameworks with both the AI Act and these sector-specific expectations.

In healthcare, AI systems used for diagnosis, treatment recommendations, or patient monitoring are likely to qualify as medical devices under the EU Medical Device Regulation or the In Vitro Diagnostic Regulation. These systems face conformity assessment requirements that operate in parallel with the AI Act. The Spanish Agency of Medicines and Medical Devices, known as AEMPS, is the relevant national authority.

In employment, Spanish labour law adds a further layer. The Workers'; Statute and recent amendments introduced through social dialogue require employers to inform workers'; representatives about the use of algorithmic systems that affect working conditions. This obligation applies independently of the AI Act and has been actively enforced by Spanish labour inspectors.

Consider two practical scenarios. A fintech company based in Madrid that uses an AI model to make credit decisions must comply with the AI Act';s high-risk requirements, GDPR obligations for automated decision-making, and EBA guidance on model risk management - three distinct frameworks with overlapping but not identical requirements. A logistics company using AI to optimise delivery routes faces minimal AI Act obligations but must still comply with GDPR if the system processes driver location data, and must inform workers'; representatives under Spanish labour law.

Penalties and enforcement in Spain

The EU AI Act sets out a tiered penalty structure. Violations involving prohibited AI practices can attract fines of up to thirty million euros or six percent of global annual turnover, whichever is higher. Violations of other obligations, including those applicable to high-risk systems, can attract fines of up to fifteen million euros or three percent of global turnover. Providing incorrect or misleading information to authorities can attract fines of up to seven and a half million euros or one percent of global turnover.

AESIA is responsible for investigating and imposing these penalties in Spain. The authority has the power to conduct audits, request documentation, and require access to AI systems for testing purposes. It can also issue interim measures to suspend or restrict the use of an AI system where there is an urgent need to protect health, safety or fundamental rights.

Enforcement is still in its early stages, but the direction of travel is clear. AESIA has indicated that it will prioritise cases involving high-risk AI systems and cases where individuals have suffered harm. Companies that have made a genuine and documented effort to comply are likely to be treated more favourably than those that have ignored the framework entirely. This makes early compliance investment a rational risk management decision, not merely a legal formality.

If your business needs to assess its exposure under the AI Act or prepare for a potential AESIA inquiry, contact info@vlolawfirm.com. We can assist with compliance gap analysis, documentation preparation, and regulatory engagement.

FAQ

What is the first practical step a company should take to comply with AI regulation in Spain?

The starting point is an AI inventory: a structured mapping of all AI systems the company develops, deploys or procures, together with an assessment of their risk classification under the EU AI Act. Without knowing which systems you operate and how they are classified, it is impossible to prioritise compliance work. Many companies discover during this process that systems they assumed were minimal risk are in fact high-risk under the Act';s definitions. The inventory should be documented and reviewed regularly, as the risk classification of a system can change if its intended use or technical characteristics change. AESIA has indicated that it expects organisations to be able to produce this kind of documentation on request.

How long does it take to achieve compliance with the EU AI Act for a high-risk AI system in Spain?

For a company starting from scratch, achieving full compliance for a high-risk AI system typically requires several months of sustained effort. The technical documentation alone - covering system architecture, training data, risk management, and testing results - can take weeks to prepare properly. Establishing a quality management system, implementing logging and human oversight mechanisms, and registering the system in the EU database each add further time. Companies that have already invested in ISO or other quality management frameworks may be able to move faster. The cost varies significantly depending on the complexity of the system and the maturity of the company';s existing governance processes, but professional fees for a comprehensive compliance project typically start from the low tens of thousands of euros.

Does a company outside Spain need to comply with Spanish AI regulation if it offers AI services to Spanish users?

Yes. The EU AI Act applies on the basis of where the AI system is placed on the market or put into service, not where the provider is established. A company based outside the EU that offers AI services to users in Spain - or whose AI system produces outputs used in Spain - is subject to the Act. Such companies are required to appoint an EU-authorised representative if they do not have an establishment in the EU. The authorised representative acts as the point of contact for AESIA and other competent authorities. This requirement is analogous to the GDPR';s representative obligation and is enforced in the same way.

Conclusion

AI regulation in Spain is now a concrete compliance reality, not a future concern. The EU AI Act is applying progressively, AESIA is operational, and enforcement is beginning. Companies that act early - by mapping their AI systems, assessing risk classifications, and building compliant documentation and governance processes - will be better positioned than those who wait.

VLO Law Firms advises international clients on AI regulation in Spain. We can assist with AI system risk classification, EU AI Act compliance documentation, AESIA engagement, regulatory sandbox applications, and coordination with data protection obligations under the GDPR. To request a consultation, contact: info@vlolawfirm.com