[codicts-css-switcher id=”346″]

Global Law Experts Logo
is spain subject to the eu ai act

Our Expert in Spain

Is Spain Subject to the EU AI Act? 2026, Obligations for Providers & Deployers, AESIA Oversight, Timelines and Fines

By Global Law Experts
– posted 47 minutes ago

Yes, Spain is subject to the EU AI Act. Regulation (EU) 2024/1689, known as the EU Artificial Intelligence Act, is an EU Regulation rather than a Directive, which means it applies directly and in its entirety across every EU Member State, including Spain, without the need for national transposition into Spanish law. Spain has moved ahead of many Member States by establishing AESIA (Agencia Española de Supervisión de la Inteligencia Artificial), the country’s dedicated supervisory authority for artificial intelligence, which published its first suite of practical compliance guides on 16 December 2025.

With the broadest tranche of AI Act obligations, covering high-risk AI systems, transparency duties and deployer responsibilities, becoming applicable from 2 August 2026, every provider, deployer, importer and distributor operating in or targeting the Spanish market now faces concrete compliance deadlines backed by fines that can reach up to 7 % of global annual turnover.

This guide covers:

  • Whether and how the EU AI Act applies in Spain
  • The phased timeline of key dates from 2024 through 2027
  • Specific obligations for providers and deployers under the Regulation
  • High-risk AI system classification and Spain-relevant sector examples
  • AESIA’s supervisory role, reporting duties and the Spain AI sandbox
  • Enforcement powers, EU AI Act fines and practical risk mitigation
  • A ready-to-use compliance checklist and recommended contract clauses

Does the EU AI Act Apply in Spain?

The EU AI Act, formally Regulation (EU) 2024/1689, published in the Official Journal of the European Union on 12 July 2024, is binding in its entirety and directly applicable in all EU Member States. Spain does not need to pass separate legislation to give the Regulation legal effect. From the moment each phased obligation becomes applicable, it is enforceable in Spain on the same terms as in every other Member State.

The Regulation’s territorial scope captures any natural or legal person that:

  • Places an AI system on the market or puts one into service within the EU/EEA, regardless of whether the provider is established inside or outside the Union.
  • Deploys an AI system within the EU, meaning uses an AI system under its own authority in a professional capacity.
  • Is established in a third country but whose AI system’s output is used within the EU.

Third-country providers whose systems reach the Spanish market must appoint an authorised representative established in the EU before placing those systems on the market. This makes the EU AI Act in Spain relevant not only to domestically headquartered companies but also to international SaaS platforms, AI vendors and technology exporters targeting Spanish or wider European customers.

AI Act Timelines 2026, Key Dates and Phased Obligations

The EU AI Act follows a staggered implementation calendar. Understanding these AI Act timelines for 2026 is essential for any organisation that develops, sells or uses AI systems in Spain. The table below sets out the principal milestones as established by the Regulation and referenced in European Commission guidance.

Date Event Who it affects
12 July 2024 Regulation (EU) 2024/1689 published in the Official Journal of the European Union (OJ L series). All stakeholders, the legal text becomes the definitive reference.
1 August 2024 The EU AI Act enters into force. Transitional periods begin running. EU institutions, Member States and market participants begin preparatory work.
2 February 2025 Prohibited AI practices under Article 5 become enforceable (e.g., social scoring by public authorities, exploitative subliminal techniques, real-time remote biometric identification in publicly accessible spaces subject to narrow exceptions). All providers and deployers, banned systems must be withdrawn or ceased immediately.
2 August 2025 Obligations for providers of general-purpose AI models apply. Governance provisions and codes of practice take effect. General-purpose AI model providers; EU AI Office.
2 August 2026 Core operational obligations become broadly applicable: high-risk AI system requirements (Annex III categories), transparency obligations (Article 50), deployer duties (Article 26), AI literacy requirements (Article 4) and national authority enforcement powers. Providers of high-risk AI, deployers, importers, distributors and AESIA in Spain.
2 August 2027 Obligations for high-risk AI systems that are also safety components of products covered by existing EU harmonisation legislation (Annex I) apply. Providers embedding AI in machinery, medical devices, vehicles and other regulated products.

The critical milestone for most businesses in Spain is 2 August 2026. From that date, AESIA gains its full supervisory toolkit, and organisations that have not completed their conformity assessments, technical documentation or deployer-readiness checks face immediate enforcement exposure. Industry observers expect the months leading up to this date to represent the most concentrated AI compliance effort the Spanish market has ever undertaken.

AI Act Obligations for Providers, EU and Third-Country

The Regulation defines a provider as any natural or legal person that develops an AI system or a general-purpose AI model, or that has an AI system or model developed on its behalf, and places it on the market or puts it into service under its own name or trademark. This definition, drawn from the Regulation’s definitional provisions, deliberately captures both in-house developers and companies that commission development by third parties.

Providers of high-risk AI systems bear the heaviest compliance burden under the EU AI Act in Spain. Their core obligations include:

  • Risk management system. Establish and maintain a continuous, documented risk-management process covering the AI system’s entire lifecycle, from design through deployment and decommissioning.
  • Data governance. Ensure training, validation and testing datasets satisfy quality criteria set out in the Regulation, including relevance, representativeness and freedom from errors and bias.
  • Technical documentation. Prepare detailed technical files before the system is placed on the market, demonstrating conformity with all applicable requirements.
  • Record-keeping and automatic logging. Design systems to enable automatic recording of events (logs) that allow traceability of the system’s functioning.
  • Transparency and instructions for deployers. Provide clear, comprehensive instructions for use, including the system’s capabilities, limitations, intended purpose and required human oversight.
  • Human oversight design. Build systems so that natural persons can effectively oversee the AI during its period of use.
  • Accuracy, robustness and cybersecurity. Achieve and maintain appropriate levels of accuracy, robustness and cybersecurity throughout the system’s lifecycle.
  • Conformity assessment. Complete the applicable conformity-assessment procedure, for certain high-risk categories, this requires a third-party assessment by a notified body, before placing the system on the market.
  • EU database registration. Register the high-risk AI system in the EU-wide public database before making it available.
  • Post-market monitoring. Implement a post-market monitoring system proportionate to the system’s nature and risk level, and report serious incidents to the competent national authority.

Third-Country Providers Selling into Spain

Providers established outside the EU that place AI systems on the Spanish or broader EEA market must appoint an authorised representative established within the Union before making those systems available. The authorised representative must be formally mandated in writing and empowered to maintain copies of the conformity documentation, cooperate with AESIA and other national competent authorities, and provide all information necessary to demonstrate compliance.

From a practical standpoint, the likely effect for third-country SaaS companies and AI vendors targeting Spain is threefold: formalise the authorised-representative appointment via a dedicated contractual instrument; update standard customer agreements to include AI Act compliance warranties and indemnities; and budget for ongoing EU-based compliance infrastructure, including personnel who can respond to AESIA requests.

Entity type Top 3 obligations under EU AI Act Immediate action for Spanish firms
Provider (placing on market) Conformity assessment; technical documentation & quality management; register high-risk systems in EU database Conduct conformity gap analysis; appoint authorised representative if non-EU; prepare technical file.
Deployer (putting into service) Use-as-directed operational checks; human oversight implementation; post-market monitoring and incident reporting Update procurement and operational SOPs; implement monitoring and logging protocols.
Importer / Distributor Verify provider’s conformity documentation; ensure system labelling and warnings; do not supply non-compliant systems Add AI Act compliance verification to vendor due diligence; require contractual warranties.

Obligations for Deployers Operating in Spain

A deployer under the Regulation is any natural or legal person that uses an AI system under its own authority, except where the system is used in the course of a personal, non-professional activity. In Spain, deployers range from banks running credit-scoring algorithms and hospitals using diagnostic AI to recruitment firms deploying automated CV-screening tools. Article 26 of the Regulation imposes a distinct set of AI Act obligations on these deployers, separate from but complementary to those borne by providers.

Deployers of high-risk AI systems operating in Spain must address the following duties:

  • Pre-deployment verification. Confirm that the provider has completed the applicable conformity assessment and that the system is registered in the EU database where required, before putting it into service.
  • Human oversight assignment. Designate competent natural persons to oversee the system’s operation and equip them with the authority and technical capability to intervene, override or halt the system.
  • Input data relevance. Ensure that input data is relevant to and sufficiently representative for the system’s intended purpose.
  • Monitoring and log retention. Monitor the AI system’s operation in accordance with the provider’s instructions for use. Retain automatically generated logs for a period appropriate to the system’s intended purpose.
  • Incident reporting to AESIA. Report serious incidents to Spain’s national competent authority, AESIA, and to the provider, without undue delay once the deployer becomes aware of a malfunction, misuse or impact on health, safety or fundamental rights.
  • Fundamental-rights impact assessment. For deployers that are public-sector bodies, or private entities operating in specified sectors, carry out a fundamental-rights impact assessment before deploying the high-risk system.
  • Transparency to affected persons. Under Article 50, where the AI system interacts with natural persons or generates or manipulates synthetic content, inform those persons that they are interacting with or consuming AI-generated material.

Early indications suggest that AI Act compliance in Spain will be sharpest for deployers in the financial services, healthcare and public-administration sectors, where the combination of high-risk classification and fundamental-rights obligations creates the most demanding compliance surface.

High-Risk AI Systems, What Counts in Spain and Sector Examples

The Regulation classifies AI systems into risk tiers: unacceptable (prohibited under Article 5), high-risk, limited-risk (transparency obligations) and minimal-risk. For businesses in Spain, the most operationally significant category is high-risk AI systems. Annex III of the Regulation lists the use-case areas that trigger high-risk classification. These include:

  • Biometric identification and categorisation. Systems used for remote biometric identification in publicly accessible spaces.
  • Critical infrastructure. AI used as safety components in the management and operation of water, gas, heating and electricity supply.
  • Education and vocational training. Systems determining access to educational institutions or assessing student outcomes.
  • Employment and worker management. CV-screening tools, interview-scoring systems, task allocation and performance-monitoring algorithms.
  • Access to essential services. Credit scoring, insurance risk assessment, social-benefit eligibility determination and emergency-service dispatch prioritisation.
  • Law enforcement. Predictive policing tools, evidence-reliability assessment and risk-profiling systems.
  • Migration and border control. Automated tools used in asylum, visa and residence-permit procedures.

In Spain’s economy, industry observers expect the banking, insurance, healthcare and recruitment sectors to face the earliest and heaviest compliance obligations. A Spanish fintech using AI-driven credit decisions, for instance, will need to complete a conformity assessment, maintain detailed technical documentation, register the system in the EU database and implement post-market monitoring, all before the 2 August 2026 application date for Annex III categories. Organisations should conduct an internal classification audit now to identify which of their systems fall within the high-risk AI systems in Spain framework.

AESIA Oversight, Remit, Reporting and the Spain AI Sandbox

Spain is among the first EU Member States to have established a dedicated national supervisory authority for artificial intelligence. AESIA, the Agencia Española de Supervisión de la Inteligencia Artificial, was created by Royal Decree and is tasked with monitoring and enforcing the EU AI Act within Spanish territory. The AESIA AI Act mandate covers market surveillance, complaint handling, cooperation with the European AI Office and other national authorities, and the publication of compliance guidance.

On 16 December 2025, AESIA published a set of practical compliance guides designed to help providers and deployers prepare for the obligations phasing in during 2026. These guides address topics including risk classification, documentation standards, record generation and retention requirements, AI literacy obligations under Article 4, and the procedural steps for interacting with the agency. AESIA has also published dedicated resources for each key article, offering step-by-step walkthroughs.

Spain AI Sandbox, Eligibility and Application

Spain has also been at the forefront of the EU AI regulatory sandbox concept. The Regulation encourages Member States to establish sandboxes where providers can develop, test and validate innovative AI systems under regulatory supervision before placing them on the market. AESIA oversees Spain’s sandbox programme, which follows a structured process:

  • Eligibility check. Confirm that the AI system under development meets the sandbox criteria published in AESIA’s guidance, including demonstrating innovation potential and a defined risk profile.
  • Application submission. Submit a proposal to AESIA describing the AI system, its intended purpose, the deployment context and the specific regulatory questions to be tested.
  • Supervisory assessment and admission. AESIA evaluates the application against eligibility criteria and, if accepted, defines the conditions and reporting milestones for the sandbox period.
  • Controlled testing and reporting. Participants operate the system under agreed conditions with AESIA oversight, filing periodic reports at defined intervals.
  • Exit and regulatory determination. On completion, AESIA issues findings that may inform the system’s conformity assessment and broader regulatory treatment.

Spain is also pursuing a draft national Organic Law on artificial intelligence that may layer additional obligations onto the EU framework. The legislative process remains ongoing, and organisations operating in Spain should monitor AESIA announcements and official publications in the Boletín Oficial del Estado (BOE) for updates as this legislation progresses.

Enforcement, EU AI Act Fines and Practical Risk Mitigation

The EU AI Act establishes a tiered penalty framework that applies across all Member States, including Spain. The Regulation’s penalty provisions set out maximum administrative fines calibrated to the severity of the infringement:

  • Prohibited practices (Article 5 violations): fines of up to €35 million or 7 % of total worldwide annual turnover, whichever is higher.
  • Most other obligations under the Regulation: fines of up to €15 million or 3 % of total worldwide annual turnover, whichever is higher.
  • Supplying incorrect, incomplete or misleading information to authorities: fines of up to €7.5 million or 1 % of total worldwide annual turnover, whichever is higher.

For SMEs and start-ups, the Regulation provides that the lower of the two figures, the absolute cap or the turnover percentage, applies, offering a degree of proportionality. In Spain, AESIA will be the authority responsible for investigating infringements and imposing sanctions once its full enforcement powers become operational from 2 August 2026.

The likely practical effect of these EU AI Act fines is that compliance will become a board-level priority. Effective risk mitigation for Spanish organisations should include:

  • Internal compliance programme. Designate an AI compliance lead and embed AI risk assessment into existing governance, risk and compliance frameworks.
  • Data protection alignment. Where AI systems process personal data, align AI Act obligations with GDPR requirements, including conducting Data Protection Impact Assessments (DPIAs) in coordination with the EDPB’s published guidance on AI and data protection.
  • Vendor and supply-chain contracts. Update supplier agreements to include AI Act compliance warranties, audit rights and indemnification for non-conformity.
  • Insurance review. Check professional-indemnity and product-liability policies for AI-related exclusions and consider dedicated technology errors-and-omissions cover.
  • Escalation and incident-response protocols. Establish documented procedures for reporting serious incidents to AESIA and to the system provider within the timeframes the Regulation requires.

Practical Compliance Checklist and Contract Clauses for AI Act Compliance in Spain

The following checklist is designed for legal and compliance teams preparing for the EU AI Act in Spain. It can be adapted to fit both provider and deployer workflows:

  1. Conduct a complete AI system inventory, identify every system your organisation develops, deploys, imports or distributes.
  2. Classify each system by risk tier (prohibited, high-risk, limited-risk, minimal-risk) using Annex III criteria and AESIA’s published guidance.
  3. For high-risk systems: initiate or update technical documentation and begin the conformity assessment process.
  4. Appoint an internal AI compliance lead with cross-functional authority spanning legal, IT, operations and HR.
  5. For third-country providers: execute a written authorised-representative appointment agreement with an EU-based entity.
  6. Register applicable high-risk AI systems in the EU database before placing them on the market or putting them into service.
  7. Implement human-oversight procedures and train designated oversight personnel on intervention and override capabilities.
  8. Establish a post-market monitoring system with documented escalation and incident-reporting protocols aligned with AESIA requirements.
  9. Review and update all vendor, procurement and distribution contracts to include AI Act compliance clauses.
  10. Align AI governance with GDPR obligations, conduct DPIAs where the AI system processes personal data.
  11. Monitor AESIA publications and the BOE for updates on Spain’s draft national Organic Law on AI.
  12. Schedule quarterly internal audits of AI compliance status and document all findings and remediation actions.

Recommended Contract Clauses

When negotiating AI-related agreements in Spain, the following clause categories deserve particular attention:

  • Compliance warranty. “The Provider warrants that each AI System delivered under this Agreement has undergone the applicable conformity assessment and complies with Regulation (EU) 2024/1689 at the date of delivery and throughout the term of this Agreement.”
  • Audit and access rights. “The Deployer retains the right to audit the Provider’s technical documentation, risk-management records and post-market monitoring data upon reasonable written notice, no more than [twice/year], at the Provider’s premises or via secure data room.”
  • Indemnification for non-conformity. “The Provider shall indemnify and hold harmless the Deployer against all fines, penalties, regulatory costs and third-party claims arising directly from the Provider’s failure to comply with the obligations set out in Regulation (EU) 2024/1689.”
  • Incident notification. “Each party shall notify the other of any serious incident involving the AI System within [48/72] hours of becoming aware of such incident, and shall cooperate fully in any reporting to AESIA or other competent authority.”
  • Authorised representative clause (for third-country providers). “The Provider shall, at its own cost, maintain an authorised representative established within the EU for the duration of this Agreement and shall provide the Deployer with the representative’s contact details and mandate documentation.”

What to Do Next, 30/60/90 Day Compliance Plan

For organisations operating in Spain, the compliance window before 2 August 2026 is narrowing. A structured approach over the next 90 days will position your business to meet the deadline with confidence:

  • Within 30 days: Complete your AI system inventory and preliminary risk classification. Identify any systems that may fall under Article 5 prohibited practices (these bans are already enforceable). Download and review AESIA’s practical compliance guides.
  • Within 60 days: Begin conformity assessments for high-risk systems. Appoint your AI compliance lead. Conduct a gap analysis against the Regulation’s technical documentation and data governance requirements. Initiate or update DPIAs where AI systems process personal data.
  • Within 90 days: Finalise contract-clause updates across your provider and vendor agreements. Implement human-oversight procedures and train designated staff. Schedule your first internal audit cycle. If innovation testing is relevant, prepare your Spain AI sandbox application to AESIA.

The answer to whether Spain is subject to the EU AI Act is unequivocal: yes, and the obligations are extensive, time-bound and backed by significant financial penalties. Organisations that begin their AI Act compliance work in Spain now will not only reduce enforcement risk but also gain a competitive advantage in a market where demonstrable AI governance is rapidly becoming a commercial differentiator.

Need Legal Advice?

This article was produced by Global Law Experts. For specialist advice on this topic, contact Jesus Osuna at Addwill, a member of the Global Law Experts network.

Sources

  1. Regulation (EU) 2024/1689, Artificial Intelligence Act (EUR-Lex)
  2. European Commission, Regulatory Framework on Artificial Intelligence
  3. AESIA, Spanish Agency for the Supervision of Artificial Intelligence
  4. AESIA, Practical Guides for AI Act Compliance
  5. Official Journal of the European Union, Direct Access
  6. European Data Protection Board (EDPB)

FAQs

Is Spain subject to the EU AI Act?
Yes. The EU AI Act is Regulation (EU) 2024/1689, an EU Regulation that applies directly in Spain without national transposition. Providers placing AI systems on the Spanish market and deployers using AI systems in Spain must comply with all applicable obligations.
Spain does not currently have a standalone national AI law in force. However, Spain has established AESIA as its dedicated AI supervisory authority and is pursuing a draft national Organic Law on AI that may introduce supplementary obligations beyond the EU framework.
Providers, deployers, importers, distributors and authorised representatives who place or put AI systems into service in the EU/EEA must comply. Third-country providers whose AI system outputs are used within Spain are also within scope.
Article 5 of the Regulation prohibits AI practices deemed to pose an unacceptable risk, including social scoring by public authorities and AI systems that deploy subliminal or exploitative techniques to materially distort behaviour. These bans have been enforceable since 2 February 2025.
The Regulation establishes tiered maximum fines: up to €35 million or 7 % of global annual turnover for prohibited-practice violations; up to €15 million or 3 % for most other breaches; and up to €7.5 million or 1 % for supplying incorrect information to authorities.
The broadest tranche of obligations, including requirements for high-risk AI systems, deployer duties under Article 26 and transparency obligations under Article 50, becomes applicable on 2 August 2026. AESIA has published practical guides to help Spanish entities prepare.
AESIA has published practical compliance guides and operates Spain’s AI regulatory sandbox. Engagement begins through AESIA’s official portal, where organisations can access step-by-step guidance on reporting, sandbox applications and compliance documentation.
vasp authorisation brazil
By Jonathon Richards

posted 3 hours ago

Find the right Legal Expert for your business

The premier guide to leading legal professionals throughout the world

Specialism
Country
Practice Area
LAWYERS RECOGNIZED
0
EVALUATIONS OF LAWYERS BY THEIR PEERS
0 m+
PRACTICE AREAS
0
COUNTRIES AROUND THE WORLD
0
Lawyer Profile Page - Lead Capture
GLE-Logo-White
Lawyer Profile Page - Lead Capture

Is Spain Subject to the EU AI Act? 2026, Obligations for Providers & Deployers, AESIA Oversight, Timelines and Fines

Send welcome message

Custom Message