[codicts-css-switcher id=”346″]

Global Law Experts Logo
ai act spain enforcement

Our Expert in Spain

EU AI Act Spain 2026: Litigation and Enforcement Risks Explained

By Global Law Experts
– posted 2 hours ago

The EU AI Act Spain enforcement landscape is entering a decisive phase in 2026, and Spanish companies deploying or supplying artificial intelligence systems now face concrete legal exposure rather than abstract policy debate. Regulation (EU) 2024/1689, the EU AI Act, is being applied in phases across the Union, and its enforcement machinery is moving from statute to application. For in-house counsel and executives, the practical questions are no longer academic: which authorities will act, what fines and remedies are at stake, and how enforcement decisions can be challenged in Spanish courts. This guide sets out a litigation-first roadmap, grounded in the primary sources, for organisations that must assess, mitigate and, where necessary, contest AI Act enforcement in Spain.

What the EU AI Act is and how it applies in Spain

The EU AI Act Spain framework does not derive from a Spanish transposition statute in the ordinary sense. As a Regulation, Regulation (EU) 2024/1689 has direct effect across all Member States, which means it applies in Spain automatically and uniformly without the need for a separate implementing law to give it binding force. Spanish courts and regulators must apply its provisions directly. Member States remain responsible for designating national competent authorities and for laying down national rules on penalties within the framework the Regulation sets, and the Regulation’s obligations take effect in stages according to the dates of application in its text.

Quick statutory snapshot, Regulation (EU) 2024/1689: direct effect and scope

Regulation (EU) 2024/1689 establishes a horizontal, risk-based regime for artificial intelligence across the European Union. Because it is a Regulation and not a Directive, it binds economic operators in Spain directly from the dates of application set out in the text itself. The Regulation applies to providers placing AI systems on the Union market or putting them into service in the Union, to deployers established or located within the EU, and, critically for cross-border businesses, to providers and deployers located outside the EU where the output produced by their AI systems is used within the Union.

For Spanish companies, this means that both domestic deployment and the supply of AI systems into the EU internal market fall squarely within scope, regardless of where the technology was developed.

Definitions: “AI system”, “high-risk”, “provider” and “deployer”

Understanding the EU AI Act Spain exposure begins with the Regulation’s defined terms, because liability attaches according to the role a company plays and the risk category of the system it handles. The Regulation distinguishes between several actors and classifications that determine the intensity of obligations:

  • AI system. A machine-based system designed to operate with varying levels of autonomy and that may exhibit adaptiveness after deployment and that, for explicit or implicit objectives, infers from the input it receives how to generate outputs such as predictions, content, recommendations or decisions that can influence physical or virtual environments.
  • High-risk AI systems. Systems identified by the Regulation as posing significant risks to health, safety or fundamental rights, for example, certain systems used in critical infrastructure, employment, access to essential services, or the administration of justice, as set out in the Regulation and its annexes. High-risk AI systems in Spain attract the most demanding compliance and documentation burdens.
  • Provider. A natural or legal person, public authority, agency or other body that develops an AI system or general-purpose AI model, or has one developed, and places it on the market or puts the AI system into service under its own name or trademark.
  • Deployer. A natural or legal person, public authority, agency or other body using an AI system under its authority, except where the AI system is used in the course of a personal non-professional activity.

Mapping these definitions to a Spanish organisation’s actual activities is the first analytical step in any risk assessment, because obligations, and therefore litigation exposure, differ sharply between a provider of a high-risk system and a deployer of a limited-risk tool.

Enforcement architecture in Spain, who can act and how

The question of AI Act enforcement Spain, who enforces, and with what powers, is central to litigation planning. The Regulation leaves the designation of national competent authorities to each Member State, while establishing EU-level coordination mechanisms, including the European AI Office within the European Commission and the European Artificial Intelligence Board. Spanish companies therefore need to track both the domestic authority landscape and the European bodies whose positions shape enforcement priorities.

National competent authorities in Spain

Spain has moved early on the institutional side. The Spanish Agency for the Supervision of Artificial Intelligence (Agencia Española de Supervisión de la Inteligencia Artificial, AESIA), based in A Coruña, has been established by royal decree as a body attached to the ministry responsible for digital transformation, with a mandate connected to the supervision of AI. Its precise role and powers as a national competent authority and market surveillance authority under the AI Act depend on the designation and implementing measures adopted at national level.

Alongside AESIA, other authorities have roles where AI intersects with their sectors. Where an AI system processes personal data, the Agencia Española de Protección de Datos (AEPD) is the established supervisory authority for data protection and coordinates enforcement in areas where the AI Act and data protection law overlap. Sectoral regulators may also be involved depending on the field in which an AI system is used.

The precise allocation of responsibilities in Spain is being confirmed through national instruments implementing the Regulation. Until those designations are fully consolidated, counsel should assume a layered enforcement environment in which the identity of the acting authority depends on the nature of the AI system and the harm alleged. This matters directly for litigation: a jurisdictional or competence challenge, arguing that the acting body lacked authority to sanction, is a recognised line of defence in Spanish administrative litigation, and it depends on precise identification of the designated Spanish regulator with authority over the AI system in question.

Cooperation with EU bodies and market surveillance

Enforcement under the Regulation is not purely national. The European Commission, through the AI Office, together with the European Artificial Intelligence Board, establishes coordination structures, delegated and implementing acts and guidance that frame how national authorities operate, and market surveillance under the Regulation follows the Union’s established product-safety and market-surveillance architecture. The European Data Protection Board (EDPB) and the AEPD provide guidance where AI and data protection intersect, including on questions of cooperation between authorities. For a Spanish company facing a cross-border investigation, this means that an enforcement action may draw on evidence, positions and coordination originating outside Spain, a factor that shapes both the evidential picture and the potential grounds for challenging procedural regularity.

Criminal, administrative and civil routes, which apply?

Three distinct routes of exposure must be separated. The AI Act enforcement regime is principally administrative: authorities investigate, issue objections and impose administrative fines and corrective measures. Civil liability is a separate track, driven by private claimants seeking damages or injunctions for harm caused by AI systems. Criminal liability is comparatively rare and would arise only where conduct falls within existing offences under the Spanish Criminal Code. Each route carries different procedures, standards of proof and defence strategies, and a company under scrutiny may face parallel proceedings across more than one track simultaneously.

Penalties, remedies and what companies can face in Spain

The commercial stakes of the EU AI Act Spain regime are set by its penalty structure. The Regulation establishes tiered maximum administrative fines calibrated to the seriousness of the breach, and empowers national competent authorities to impose corrective measures alongside monetary penalties. Understanding AI fines Spain exposure, and the defences available, is essential to any litigation risk assessment.

Administrative fines under the AI Act, structure and maximums

The Regulation adopts a graduated fine architecture. The most serious infringements, those involving prohibited AI practices, attract the highest ceilings, expressed both as an absolute euro figure and, alternatively, as a percentage of the undertaking’s total worldwide annual turnover for the preceding financial year, whichever is higher. Lower tiers apply to breaches of specific obligations for high-risk systems and other operator obligations, and to the supply of incorrect, incomplete or misleading information to authorities. The precise ceilings, and the mechanics for calculating turnover-based fines, are set out in the sanctions provisions of Regulation (EU) 2024/1689, and the applicable tier depends on the nature of the obligation breached and the category of the AI system involved.

National implementing measures may also lay down further rules on penalties within the Regulation’s framework.

For litigation purposes, the tiered structure is significant because proportionality is a core reviewable ground. The Regulation directs authorities to consider factors such as the nature and gravity of the infringement, its duration, whether the same operator has committed prior breaches, and the degree of cooperation. Each of these factors is a potential lever for reducing a proposed AI Act penalties Spain figure, and each must be evidenced and argued during the administrative phase to preserve it for later judicial review.

Civil liability exposures and private claims

Beyond administrative fines, Spanish companies face civil liability where an AI system causes harm to individuals or other businesses. Private claimants may pursue damages and injunctive relief through the civil courts, and an adverse administrative finding, even one still under appeal, can materially strengthen a claimant’s evidential position. AI litigation Spain in the civil sphere turns on ordinary principles of causation, foreseeability and fault, and defendants can and should contest the causal link between the AI system’s operation and the alleged loss, as well as raise contributory fault where the claimant’s own conduct contributed to the harm.

Ancillary remedies, product recall, suspension and corrective orders

Administrative fines are only part of the picture. Authorities may order corrective measures that carry greater commercial impact than the fine itself: withdrawal or recall of a system from the market, restriction of its availability, mandatory corrective action, or measures requiring that a system be brought into conformity. For many businesses, an order suspending or withdrawing a revenue-generating AI product is the true emergency, and it is precisely the scenario in which urgent interim relief before the Spanish courts becomes the priority.

Enforcement route Typical sanction / remedy Maximum fine Enforcing authority (Spain) Common defence angles
Administrative (AI Act) Fines, corrective orders, restrictions on use Tiered ceilings under Regulation (EU) 2024/1689, expressed as a fixed euro amount or a percentage of worldwide annual turnover, whichever is higher Designated national competent authority (e.g. AESIA) / AEPD where personal data is involved Effective compliance programme, absence of fault, proportionality, procedural defects
Market surveillance Product restrictions, withdrawal, recall Administrative penalties under the Regulation and national law Designated market surveillance authority Conformity assessment evidence, CE marking, technical documentation
Civil claims (private) Damages, injunctions Indemnity sought by claimants Civil courts Causation, foreseeability, contributory fault
Criminal (where applicable) Criminal penalties (rare) As per the Spanish Criminal Code Public prosecutor / criminal courts Absence of intent, no recklessness, lack of mens rea

How enforcement actions are likely to run in Spain, timeline and corporate checklist

Anticipating the shape of an investigation allows counsel to prepare rather than react. While AI Act enforcement Spain practice will develop as the Regulation’s obligations come into full application, the procedural contours can be mapped from the Regulation’s requirements and from established Spanish administrative procedure under Law 39/2015 on the Common Administrative Procedure of Public Administrations.

Common triggers

Enforcement typically begins from one of several sources: a complaint from an affected individual or competitor; a market surveillance audit or inspection; a referral arising from cross-border cooperation between authorities; or self-reporting following an internal incident. Complaints touching on personal data are especially likely to surface through the AEPD, while product-safety concerns may enter through market surveillance channels. Recognising which trigger initiated an action informs both the likely scope of the investigation and the authority whose competence may be challenged.

Typical timeline from investigation to sanction

A representative administrative sequence in Spain follows a recognisable arc. Counsel should plan around the following stages:

  • Notice of investigation. The authority formally opens proceedings and notifies the company, often accompanied by an initial request for information or documents.
  • Evidence gathering. The authority collects technical documentation, logs, conformity assessments and correspondence; the company responds to information requests and may make preliminary submissions.
  • Statement of objections / proposed decision. The authority sets out its provisional findings and the infringements alleged, giving the company a formal opportunity to respond (trámite de audiencia).
  • Company response and hearing. Written submissions and, where available, oral representations contest the findings, argue proportionality and present mitigating evidence.
  • Decision. The authority issues a reasoned decision imposing any fine and corrective measures.
  • Appeal window. The decision opens the route to administrative appeal and, ultimately, to the contentious-administrative courts within the statutory deadlines applicable to the decision.

The critical discipline is that arguments not raised during the administrative phase are harder to deploy later. Every substantive and procedural objection should be articulated and evidenced before the decision is issued, so that the record supports a subsequent challenge.

Immediate steps for counsel on first notice

On receipt of a notice of investigation, counsel should move immediately to preserve evidence, freezing logs, model documentation and internal communications relevant to the system under scrutiny. Communications should be centralised and controlled to avoid inconsistent or damaging statements. Technical experts should be engaged early to interpret the system’s behaviour and to assemble the conformity narrative. These first moves shape the entire trajectory of the matter.

Challenging enforcement: administrative appeals, interim relief and judicial review in the EU AI Act Spain context

A recurring question from executives is whether an enforcement decision can be resisted. The answer is yes: Spanish and EU law provide layered mechanisms to contest AI Act enforcement, and a well-constructed challenge can suspend, reduce or overturn a sanction.

Administrative remedies and appeal routes

Challenging an AI Act enforcement decision in Spain follows the architecture of Spanish administrative litigation. Depending on the nature of the decision and the authority that issued it, a company may first pursue an administrative appeal, for example an optional appeal for reconsideration (recurso de reposición) before the deciding body, or a hierarchical appeal (recurso de alzada) where the decision does not exhaust the administrative route. The decisive stage is judicial: the contentious-administrative courts (jurisdicción contencioso-administrativa) review the legality of the authority’s decision under Law 29/1998 regulating the contentious-administrative jurisdiction.

On this route, the company can attack the substance of the finding, the calculation of the fine, the competence of the acting authority, and any procedural irregularity in how the proceedings were conducted. Strict deadlines govern each stage, and missing them can extinguish the right to challenge, so calendar control from the moment of notification is essential.

Seeking interim and precautionary measures in Spanish courts

Where an enforcement decision imposes a suspension, withdrawal or other measure with immediate commercial impact, the priority is to seek precautionary measures (medidas cautelares) to suspend the effect of the decision pending resolution of the main challenge. Spanish contentious-administrative procedure permits the courts to suspend the execution of an administrative act where enforcing it would cause harm that is difficult or impossible to repair, weighed against the public interest and the interests of third parties. In genuinely urgent cases, the courts can grant provisional relief on an accelerated basis. An application for interim relief typically requires the applicant to evidence the seriousness of the harm, the arguability of the underlying case, and the balance of interests favouring suspension.

Strategic litigation arguments

The strongest challenges combine several lines of attack. Proportionality is a central reviewable ground under both Spanish administrative law and the general principles applied by the Court of Justice of the European Union, whose case law on the review of EU regulatory acts and on proportionality provides authoritative support for arguing that a sanction exceeds what is necessary and appropriate. A company may also argue lack of competence, that the acting authority was not properly designated or empowered for the system in question. Procedural defects, such as inadequate reasoning, denial of the right to be heard, or failure to consider mitigating evidence, are frequently decisive.

Where fundamental rights are engaged, arguments grounded in the Charter of Fundamental Rights of the European Union, the Spanish Constitution and the case law of the CJEU can reinforce the challenge.

Practical defences and mitigation strategies for Spanish companies

Litigation outcomes are determined long before a decision is issued. AI compliance Spain measures adopted in advance are the most effective defence, because they both reduce the likelihood of an infringement finding and provide the evidence that supports proportionality and absence-of-fault arguments.

Technical and compliance evidence to assemble

The evidential foundation of any defence is documentary. Companies should maintain and be able to produce:

  • System logs. Records of the AI system’s operation, monitoring and outputs across the relevant period.
  • Technical documentation. Descriptions of the system’s design, training data governance, intended purpose and known limitations.
  • Impact and risk assessments. Documented evaluation of risks to health, safety and fundamental rights, together with the mitigation measures adopted.
  • Conformity assessments. Evidence of the applicable conformity procedures and, where relevant, CE marking supporting the lawful placing of the system on the market.
  • Human oversight records. Documentation of the human oversight arrangements applied to high-risk AI systems.

This evidence directly answers the questions an authority will ask, and its absence is itself a vulnerability.

Corporate governance measures to reduce enforcement risk and fines

Governance is where AI governance litigation risk is managed at board level. Companies should establish a defined AI governance structure with clear accountability, maintain an AI risk register that tracks systems by risk category, and ensure that the board and senior management receive regular reporting on AI compliance. A demonstrable, functioning compliance programme is one of the mitigating factors authorities weigh when setting a fine, and it evidences the absence of fault that underpins a proportionality challenge. It also addresses director-level exposure, since documented oversight reduces the risk that governance failures are attributed personally.

Insurance, indemnities and settlement strategy

Risk transfer and resolution strategy complete the picture. Companies should review whether existing insurance responds to AI-related liability and regulatory defence costs, and should scrutinise contractual indemnities allocating AI risk between providers and deployers. Where an infringement is difficult to defend, an early, well-evidenced engagement with the authority, cooperating, demonstrating remediation and adopting corrective measures, can materially reduce both the fine and the reputational fallout compared with a contested outcome.

Two short sample litigation playbooks

The following playbooks translate the strategy above into first-response action for the two most common scenarios.

Playbook A, Responding to a notice of administrative investigation

On receipt of a notice, the objective for the first fourteen days is to preserve position and build the record:

  1. Preserve all relevant evidence immediately, logs, technical documentation, assessments and communications, and issue a litigation hold.
  2. Centralise and control all communications with the authority through a single point of contact.
  3. Confirm the acting authority’s competence and the legal basis cited, noting any grounds for a jurisdictional objection.
  4. Engage technical experts to interpret the system’s operation and prepare the conformity narrative.
  5. Diarise every deadline in the notice and map the appeal windows that will follow a decision.
  6. Prepare an initial, measured response to information requests that avoids admissions while demonstrating cooperation.

Playbook B, Emergency interim relief to stop a product suspension

Where a decision orders suspension or withdrawal, the objective is to suspend its effect before the commercial damage becomes irreparable:

  1. Assemble evidence of the harm that immediate enforcement would cause, quantifying the irreparable or difficult-to-repair loss.
  2. Draft the application for precautionary measures before the contentious-administrative court, setting out the arguability of the main challenge.
  3. Marshal proportionality and competence arguments, supported by CJEU principles on the review of regulatory acts.
  4. Present the balance of interests, showing that suspension does not unacceptably harm the public interest or third parties.
  5. Prepare technical evidence demonstrating conformity and the safety of continued operation pending resolution.
  6. Be ready to seek accelerated provisional relief where urgency justifies it.

Conclusion and next steps for in-house counsel

The EU AI Act Spain enforcement era has arrived, and the difference between a manageable regulatory episode and a costly one will turn on preparation and procedural discipline. Spanish companies should map their AI systems against the Regulation’s risk categories, assemble the technical and governance evidence that underpins any defence, and understand in advance the routes to challenge a decision, administrative appeal, judicial review before the contentious-administrative courts, and precautionary measures to protect operations. This article provides general guidance and does not constitute legal advice; the correct response to any specific enforcement action depends on its facts and the applicable deadlines.

Organisations facing an investigation or fine under the EU AI Act Spain regime should obtain tailored litigation support without delay, and counsel seeking a specialist can use Find a Litigation Lawyer in Spain or review the Litigation, Spain practice overview.

Need Legal Advice?

This article was produced by Global Law Experts. For specialist advice on this topic, contact Jorge Capell at Main Legal, a member of the Global Law Experts network.

Sources

  1. EUR-Lex, Regulation (EU) 2024/1689 (AI Act)
  2. European Commission, European approach to Artificial Intelligence
  3. Agencia Española de Supervisión de la Inteligencia Artificial (AESIA)
  4. Agencia Española de Protección de Datos (AEPD)
  5. European Data Protection Board (EDPB)
  6. Court of Justice of the European Union (CURIA)
  7. Consejo General de la Abogacía Española

FAQs

What is the EU AI Act and does it apply directly in Spain?
The EU AI Act is Regulation (EU) 2024/1689, a directly applicable EU Regulation. As a Regulation, it applies in Spain automatically without a separate transposing law, binding providers and deployers of AI systems from the dates of application set out in its text, which take effect in phases.
Enforcement rests with national competent authorities designated by Spain. Spain has established the Spanish Agency for the Supervision of Artificial Intelligence (AESIA), based in A Coruña, in connection with AI supervision. Where personal data is processed, the Agencia Española de Protección de Datos (AEPD) is the relevant supervisory authority, coordinating with the EDPB, while sectoral and market surveillance authorities may oversee other AI systems under the coordination architecture involving the European Commission’s AI Office and the European Artificial Intelligence Board.
Regulation (EU) 2024/1689 sets tiered maximum administrative fines. The most serious breaches, involving prohibited practices, attract the highest ceilings expressed as a fixed euro figure or a percentage of worldwide annual turnover, whichever is higher, with lower tiers for breaches of other operator obligations and for providing incorrect, incomplete or misleading information to authorities. National implementing measures may add further detail within this framework.
Yes. Under the EU AI Act Spain enforcement framework, decisions can be contested through administrative appeal and, ultimately, before the contentious-administrative courts. Companies can also seek precautionary measures to suspend a decision pending judicial review, arguing proportionality, lack of competence and procedural defects.
Preserve all relevant evidence and issue a litigation hold, appoint technical experts, centralise and control communications with the authority, verify the authority’s competence and legal basis, diarise every deadline, and begin a parallel internal compliance review to identify vulnerabilities and mitigating factors.
By Kerwin Tan

posted 3 hours ago

Find the right Legal Expert for your business

The premier guide to leading legal professionals throughout the world

Specialism
Country
Practice Area
LAWYERS RECOGNIZED
0
EVALUATIONS OF LAWYERS BY THEIR PEERS
0 m+
PRACTICE AREAS
0
COUNTRIES AROUND THE WORLD
0
Lawyer Profile Page - Lead Capture
GLE-Logo-White
Lawyer Profile Page - Lead Capture

EU AI Act Spain 2026: Litigation and Enforcement Risks Explained

Send welcome message

Custom Message