Yes, Spain is subject to the EU AI Act. Regulation (EU) 2024/1689, known as the EU Artificial Intelligence Act, is an EU Regulation rather than a Directive, which means it applies directly and in its entirety across every EU Member State, including Spain, without the need for national transposition into Spanish law. Spain has moved ahead of many Member States by establishing AESIA (Agencia Española de Supervisión de la Inteligencia Artificial), the country’s dedicated supervisory authority for artificial intelligence, which published its first suite of practical compliance guides on 16 December 2025.
With the broadest tranche of AI Act obligations, covering high-risk AI systems, transparency duties and deployer responsibilities, becoming applicable from 2 August 2026, every provider, deployer, importer and distributor operating in or targeting the Spanish market now faces concrete compliance deadlines backed by fines that can reach up to 7 % of global annual turnover.
This guide covers:
The EU AI Act, formally Regulation (EU) 2024/1689, published in the Official Journal of the European Union on 12 July 2024, is binding in its entirety and directly applicable in all EU Member States. Spain does not need to pass separate legislation to give the Regulation legal effect. From the moment each phased obligation becomes applicable, it is enforceable in Spain on the same terms as in every other Member State.
The Regulation’s territorial scope captures any natural or legal person that:
Third-country providers whose systems reach the Spanish market must appoint an authorised representative established in the EU before placing those systems on the market. This makes the EU AI Act in Spain relevant not only to domestically headquartered companies but also to international SaaS platforms, AI vendors and technology exporters targeting Spanish or wider European customers.
The EU AI Act follows a staggered implementation calendar. Understanding these AI Act timelines for 2026 is essential for any organisation that develops, sells or uses AI systems in Spain. The table below sets out the principal milestones as established by the Regulation and referenced in European Commission guidance.
| Date | Event | Who it affects |
|---|---|---|
| 12 July 2024 | Regulation (EU) 2024/1689 published in the Official Journal of the European Union (OJ L series). | All stakeholders, the legal text becomes the definitive reference. |
| 1 August 2024 | The EU AI Act enters into force. Transitional periods begin running. | EU institutions, Member States and market participants begin preparatory work. |
| 2 February 2025 | Prohibited AI practices under Article 5 become enforceable (e.g., social scoring by public authorities, exploitative subliminal techniques, real-time remote biometric identification in publicly accessible spaces subject to narrow exceptions). | All providers and deployers, banned systems must be withdrawn or ceased immediately. |
| 2 August 2025 | Obligations for providers of general-purpose AI models apply. Governance provisions and codes of practice take effect. | General-purpose AI model providers; EU AI Office. |
| 2 August 2026 | Core operational obligations become broadly applicable: high-risk AI system requirements (Annex III categories), transparency obligations (Article 50), deployer duties (Article 26), AI literacy requirements (Article 4) and national authority enforcement powers. | Providers of high-risk AI, deployers, importers, distributors and AESIA in Spain. |
| 2 August 2027 | Obligations for high-risk AI systems that are also safety components of products covered by existing EU harmonisation legislation (Annex I) apply. | Providers embedding AI in machinery, medical devices, vehicles and other regulated products. |
The critical milestone for most businesses in Spain is 2 August 2026. From that date, AESIA gains its full supervisory toolkit, and organisations that have not completed their conformity assessments, technical documentation or deployer-readiness checks face immediate enforcement exposure. Industry observers expect the months leading up to this date to represent the most concentrated AI compliance effort the Spanish market has ever undertaken.
The Regulation defines a provider as any natural or legal person that develops an AI system or a general-purpose AI model, or that has an AI system or model developed on its behalf, and places it on the market or puts it into service under its own name or trademark. This definition, drawn from the Regulation’s definitional provisions, deliberately captures both in-house developers and companies that commission development by third parties.
Providers of high-risk AI systems bear the heaviest compliance burden under the EU AI Act in Spain. Their core obligations include:
Providers established outside the EU that place AI systems on the Spanish or broader EEA market must appoint an authorised representative established within the Union before making those systems available. The authorised representative must be formally mandated in writing and empowered to maintain copies of the conformity documentation, cooperate with AESIA and other national competent authorities, and provide all information necessary to demonstrate compliance.
From a practical standpoint, the likely effect for third-country SaaS companies and AI vendors targeting Spain is threefold: formalise the authorised-representative appointment via a dedicated contractual instrument; update standard customer agreements to include AI Act compliance warranties and indemnities; and budget for ongoing EU-based compliance infrastructure, including personnel who can respond to AESIA requests.
| Entity type | Top 3 obligations under EU AI Act | Immediate action for Spanish firms |
|---|---|---|
| Provider (placing on market) | Conformity assessment; technical documentation & quality management; register high-risk systems in EU database | Conduct conformity gap analysis; appoint authorised representative if non-EU; prepare technical file. |
| Deployer (putting into service) | Use-as-directed operational checks; human oversight implementation; post-market monitoring and incident reporting | Update procurement and operational SOPs; implement monitoring and logging protocols. |
| Importer / Distributor | Verify provider’s conformity documentation; ensure system labelling and warnings; do not supply non-compliant systems | Add AI Act compliance verification to vendor due diligence; require contractual warranties. |
A deployer under the Regulation is any natural or legal person that uses an AI system under its own authority, except where the system is used in the course of a personal, non-professional activity. In Spain, deployers range from banks running credit-scoring algorithms and hospitals using diagnostic AI to recruitment firms deploying automated CV-screening tools. Article 26 of the Regulation imposes a distinct set of AI Act obligations on these deployers, separate from but complementary to those borne by providers.
Deployers of high-risk AI systems operating in Spain must address the following duties:
Early indications suggest that AI Act compliance in Spain will be sharpest for deployers in the financial services, healthcare and public-administration sectors, where the combination of high-risk classification and fundamental-rights obligations creates the most demanding compliance surface.
The Regulation classifies AI systems into risk tiers: unacceptable (prohibited under Article 5), high-risk, limited-risk (transparency obligations) and minimal-risk. For businesses in Spain, the most operationally significant category is high-risk AI systems. Annex III of the Regulation lists the use-case areas that trigger high-risk classification. These include:
In Spain’s economy, industry observers expect the banking, insurance, healthcare and recruitment sectors to face the earliest and heaviest compliance obligations. A Spanish fintech using AI-driven credit decisions, for instance, will need to complete a conformity assessment, maintain detailed technical documentation, register the system in the EU database and implement post-market monitoring, all before the 2 August 2026 application date for Annex III categories. Organisations should conduct an internal classification audit now to identify which of their systems fall within the high-risk AI systems in Spain framework.
Spain is among the first EU Member States to have established a dedicated national supervisory authority for artificial intelligence. AESIA, the Agencia Española de Supervisión de la Inteligencia Artificial, was created by Royal Decree and is tasked with monitoring and enforcing the EU AI Act within Spanish territory. The AESIA AI Act mandate covers market surveillance, complaint handling, cooperation with the European AI Office and other national authorities, and the publication of compliance guidance.
On 16 December 2025, AESIA published a set of practical compliance guides designed to help providers and deployers prepare for the obligations phasing in during 2026. These guides address topics including risk classification, documentation standards, record generation and retention requirements, AI literacy obligations under Article 4, and the procedural steps for interacting with the agency. AESIA has also published dedicated resources for each key article, offering step-by-step walkthroughs.
Spain has also been at the forefront of the EU AI regulatory sandbox concept. The Regulation encourages Member States to establish sandboxes where providers can develop, test and validate innovative AI systems under regulatory supervision before placing them on the market. AESIA oversees Spain’s sandbox programme, which follows a structured process:
Spain is also pursuing a draft national Organic Law on artificial intelligence that may layer additional obligations onto the EU framework. The legislative process remains ongoing, and organisations operating in Spain should monitor AESIA announcements and official publications in the Boletín Oficial del Estado (BOE) for updates as this legislation progresses.
The EU AI Act establishes a tiered penalty framework that applies across all Member States, including Spain. The Regulation’s penalty provisions set out maximum administrative fines calibrated to the severity of the infringement:
For SMEs and start-ups, the Regulation provides that the lower of the two figures, the absolute cap or the turnover percentage, applies, offering a degree of proportionality. In Spain, AESIA will be the authority responsible for investigating infringements and imposing sanctions once its full enforcement powers become operational from 2 August 2026.
The likely practical effect of these EU AI Act fines is that compliance will become a board-level priority. Effective risk mitigation for Spanish organisations should include:
The following checklist is designed for legal and compliance teams preparing for the EU AI Act in Spain. It can be adapted to fit both provider and deployer workflows:
When negotiating AI-related agreements in Spain, the following clause categories deserve particular attention:
For organisations operating in Spain, the compliance window before 2 August 2026 is narrowing. A structured approach over the next 90 days will position your business to meet the deadline with confidence:
The answer to whether Spain is subject to the EU AI Act is unequivocal: yes, and the obligations are extensive, time-bound and backed by significant financial penalties. Organisations that begin their AI Act compliance work in Spain now will not only reduce enforcement risk but also gain a competitive advantage in a market where demonstrable AI governance is rapidly becoming a commercial differentiator.
This article was produced by Global Law Experts. For specialist advice on this topic, contact Jesus Osuna at Addwill, a member of the Global Law Experts network.
posted 8 seconds ago
posted 3 minutes ago
posted 25 minutes ago
posted 27 minutes ago
posted 50 minutes ago
posted 1 hour ago
posted 1 hour ago
posted 2 hours ago
posted 2 hours ago
posted 2 hours ago
posted 2 hours ago
posted 3 hours ago
No results available
Find the right Legal Expert for your business
Send welcome message