[codicts-css-switcher id=”346″]

Global Law Experts Logo
is spain subject to the eu ai act

Our Expert in Spain

Is Spain Subject to the EU AI Act? 2026, Obligations for Providers & Deployers, AESIA Oversight, Timelines and Fines

By Global Law Experts
– posted 51 minutes ago

If you are asking whether Spain is subject to the EU AI Act, the short answer is yes, Regulation (EU) 2024/1689, commonly known as the EU AI Act, is directly applicable in every EU Member State, including Spain, without the need for national transposition. Spain has gone further than many Member States by establishing AESIA (Agencia Española de Supervisión de la Inteligencia Artificial), a dedicated national supervisory authority charged with overseeing AI Act compliance on Spanish territory. AESIA published its first suite of compliance guides on 16 December 2025, giving providers and deployers operating in Spain a practical roadmap that supplements the obligations set out in the Regulation itself.

This guide walks through every layer that matters in 2026: who must comply, what the phased deadlines require, how AESIA exercises its supervisory powers, and what the penalty exposure looks like for organisations that fall short.

Does the EU AI Act Apply in Spain?

Regulation (EU) 2024/1689 was published in the Official Journal of the European Union on 12 July 2024 and entered into force on 1 August 2024. As an EU Regulation, not a Directive, it applies directly and in its entirety across all 27 Member States. Spain does not need to pass a separate law for the AI Act obligations to take effect; they are already binding on every natural or legal person that falls within the Regulation’s territorial scope.

That territorial scope, set out in the Regulation, catches organisations on several grounds. It covers providers that place AI systems on the EU/EEA market or put them into service within the Union, regardless of whether those providers are established inside or outside the EU. It equally covers deployers, the organisations that use AI systems under their authority, when they are located within the Union. Importers, distributors and authorised representatives also sit within scope. Even providers established in a third country are caught where the output produced by their AI system is used within the EU.

Entity type Trigger for EU AI Act scope Spain-specific note
Provider (EU-based) Places an AI system on the EU market or puts it into service in the EU Must register high-risk systems in the EU database and engage with AESIA on Spanish-market obligations
Provider (third-country) Places an AI system on the EU market or the system’s output is used in the EU Must appoint an EU-based authorised representative; AESIA may request documentation
Deployer Uses an AI system under its own authority while established in the EU Subject to AESIA monitoring and incident-reporting obligations in Spain
Importer / Distributor Makes an AI system available on the EU market Must verify the provider’s conformity documentation before placing the system
General-purpose AI model provider Places a general-purpose AI model on the EU market Transparency and documentation obligations apply; systemic-risk models face additional requirements

EU AI Act Timelines 2026, Key Dates for Spain

The EU AI Act does not switch on all at once. It follows a phased implementation calendar that stretches from August 2024 through to August 2027, allowing industry and regulators, including AESIA, time to prepare. Understanding where your organisation sits in this calendar is the first practical step toward AI Act compliance in Spain.

Date Event Who it affects
12 July 2024 Regulation (EU) 2024/1689 published in the Official Journal (OJ L series) All stakeholders, formal legal text now available
1 August 2024 EU AI Act enters into force All stakeholders, transitional periods begin running
2 February 2025 Prohibited AI practices (Article 5) become enforceable All providers and deployers, banned systems must be withdrawn
2 August 2025 Obligations for general-purpose AI models apply; governance rules for codes of practice take effect General-purpose AI model providers; EU AI Office
2 August 2026 Most remaining obligations apply, including high-risk AI system requirements under Annex III, transparency obligations, deployer duties, and national authority enforcement powers Providers of high-risk AI systems; deployers; AESIA in Spain
2 August 2027 Obligations for high-risk AI systems that are also regulated products under existing EU harmonisation legislation (Annex I) apply Providers of AI embedded in machinery, medical devices, vehicles and other Annex I products

The critical milestone for most businesses operating in Spain is 2 August 2026. From that date, the full suite of obligations for high-risk AI systems listed in Annex III, covering sectors such as biometrics, critical infrastructure, employment, essential services and law enforcement, becomes enforceable. AESIA gains its complete supervisory toolkit on the same date. Industry observers expect the period between now and August 2026 to be the most intensive compliance window most Spanish technology companies have ever faced in the AI sector.

AI Act Obligations for Providers, EU and Third-Country

The Regulation defines a provider as any natural or legal person that develops an AI system (or has one developed) and places it on the market or puts it into service under its own name or trademark. This is the role that carries the heaviest compliance burden under the EU AI Act in Spain and across the Union.

Providers of high-risk AI systems must meet a layered set of requirements before those systems may be placed on the market:

  • Risk management system. Establish and maintain a continuous, iterative risk management process throughout the entire lifecycle of the AI system.
  • Data governance. Ensure that training, validation and testing datasets meet quality criteria set out in the Regulation, including relevance, representativeness and freedom from bias.
  • Technical documentation. Prepare and maintain detailed technical documentation that demonstrates conformity with the Regulation before the system is placed on the market.
  • Record-keeping and logging. Design the system to enable automatic recording of events (logs) for traceability.
  • Transparency and information to deployers. Provide clear instructions for use, including the system’s capabilities, limitations and intended purpose.
  • Human oversight. Design the system so that it can be effectively overseen by natural persons during the period it is in use.
  • Accuracy, robustness and cybersecurity. Ensure the system achieves appropriate levels of accuracy, robustness and cybersecurity throughout its lifecycle.
  • Conformity assessment. Carry out the applicable conformity assessment procedure before placing the system on the market. For certain high-risk categories this requires third-party assessment by a notified body.
  • EU database registration. Register the high-risk AI system in the EU-wide public database before placing it on the market or putting it into service.
  • Post-market monitoring. Implement a post-market monitoring system proportionate to the nature of the AI system and its risk level.

Third-Country Providers Selling into Spain and the EEA

Providers established outside the EU that place AI systems on the Spanish or wider EEA market face additional procedural requirements. They must appoint an authorised representative established in the EU before making their systems available. That authorised representative must be empowered to carry out specific tasks, including maintaining a copy of the technical documentation, cooperating with AESIA and other national authorities, and providing all information necessary to demonstrate conformity.

From a practical standpoint, the likely effect for third-country SaaS companies and AI vendors targeting Spain will be threefold: they will need to formalise an authorised-representative appointment in writing, update their standard customer contracts to include AI Act compliance warranties, and budget for ongoing EU-based compliance infrastructure.

Entity type Top 3 obligations in Spain under the EU AI Act Practical next step
Provider (placing on market) Conformity assessment; technical documentation; register high-risk systems in EU database Run conformity gap analysis; appoint authorised representative if non-EU
Deployer (puts AI into service) Ensure operation matches provider documentation; implement human oversight; monitor and report incidents Update procurement SOPs; maintain monitoring logs; train staff
Distributor / Importer Verify provider documentation; do not place non-compliant systems; cooperate with authorities Add AI Act compliance clauses to supply contracts; conduct due diligence on upstream provider

Obligations for Deployers Operating in Spain

A deployer is any natural or legal person that uses an AI system under its authority, except where the use is a purely personal, non-professional activity. In Spain, deployers range from banks using credit-scoring algorithms to hospitals running diagnostic AI and recruitment firms deploying CV-screening tools. The EU AI Act in Spain imposes a distinct set of obligations on these organisations, separate from, but complementary to, the duties placed on providers.

Deployers of high-risk AI systems must take the following steps:

  • Pre-deployment verification. Before putting a high-risk system into service, confirm that the provider has completed the applicable conformity assessment and that the system has been registered in the EU database where required.
  • Human oversight measures. Assign competent natural persons to oversee the system’s operation and equip those persons with the authority and capability to intervene or override the system.
  • Input data quality. Ensure that input data is relevant and sufficiently representative for the system’s intended purpose.
  • Monitoring and logging. Monitor the AI system’s operation in accordance with the provider’s instructions for use. Retain automatically generated logs for a period appropriate to the system’s purpose.
  • Incident reporting. Report serious incidents to the relevant national authority, in Spain, AESIA, and to the provider without undue delay.
  • Fundamental-rights impact assessment. For deployers that are public bodies, or private entities operating in certain sectors, carry out a fundamental-rights impact assessment before deployment.
  • Transparency to affected persons. Where the AI system interacts with natural persons or generates synthetic content, inform those persons that they are interacting with or consuming AI-generated content.

Early indications suggest that deployer compliance will be the area where Spanish organisations face the steepest learning curve, because many have historically treated AI procurement as a purely IT function rather than a regulated activity requiring legal, compliance and human-resources input.

High-Risk AI Systems, What Counts in Spain and Sector Examples

The EU AI Act classifies AI systems into risk tiers: unacceptable (banned), high-risk, limited-risk and minimal-risk. The most operationally significant category for businesses in Spain is high-risk AI systems. Annex III of the Regulation lists the use-case areas that trigger high-risk classification. These include, among others:

  • Biometric identification and categorisation. Remote biometric identification systems used in publicly accessible spaces.
  • Critical infrastructure management. AI systems used as safety components in the management of water, gas, heating and electricity supply.
  • Education and vocational training. Systems that determine access to education or assess students.
  • Employment and worker management. CV-screening tools, interview-scoring systems and performance-monitoring algorithms.
  • Essential services access. Credit scoring, insurance risk assessment and social-benefit eligibility algorithms.
  • Law enforcement. Predictive policing tools and evidence-reliability assessment systems.
  • Migration and border control. Polygraph and similar tools used in asylum or visa procedures.

In Spain’s economy, industry observers expect the banking, insurance, healthcare and recruitment sectors to be the earliest and most heavily affected. A Spanish fintech using AI for credit decisions, for instance, will need to complete a conformity assessment, maintain technical documentation and register the system, all before 2 August 2026 for Annex III categories. Providers of high-risk AI systems in Spain should conduct an internal classification audit now to identify which of their products or services fall within Annex III.

AESIA Oversight, Roles, Reporting and the Spain AI Sandbox

Spain is among the first EU Member States to have established a dedicated national supervisory authority for artificial intelligence. AESIA, the Agencia Española de Supervisión de la Inteligencia Artificial, was created by Royal Decree and is responsible for monitoring and enforcing the EU AI Act within Spanish territory. It sits within the broader institutional architecture set out in the Regulation, which requires each Member State to designate at least one national competent authority.

AESIA’s remit covers market surveillance, complaint-handling, cooperation with the European AI Office and other national authorities, and guidance publication. On 16 December 2025, AESIA published a set of compliance guidelines designed to help providers and deployers prepare for the obligations phasing in during 2026. These guides address topics including risk classification, documentation standards and interaction protocols with the agency.

Spain AI Sandbox, Eligibility and Application

Spain has also been at the forefront of the EU AI regulatory sandbox concept. The AI Act encourages Member States to establish AI regulatory sandboxes that allow providers to develop, test and validate innovative AI systems under regulatory supervision before placing them on the market. AESIA oversees Spain’s sandbox programme.

The sandbox is open to providers that meet the eligibility criteria published in AESIA’s guidance, and participation follows a structured process:

  • Application. Submit a proposal to AESIA describing the AI system, its intended purpose and the specific regulatory questions to be tested.
  • Assessment. AESIA evaluates the application against eligibility criteria, including innovation potential and risk profile.
  • Controlled testing. Accepted participants operate the system under agreed conditions, with AESIA supervision and defined reporting milestones.
  • Reporting and exit. On completion, AESIA issues findings that may inform the system’s conformity assessment and broader regulatory treatment.

Spain is also pursuing a draft national Organic Law on artificial intelligence that may layer additional obligations onto the EU framework. The legislative process is ongoing, and industry observers expect it to address areas such as liability allocation and sector-specific transparency requirements. Organisations operating in Spain should monitor AESIA announcements and official publications in the Boletín Oficial del Estado (BOE) for updates.

Enforcement, EU AI Act Fines and Practical Risk Mitigation

The EU AI Act establishes a tiered penalty framework that applies across all Member States, including Spain. The Regulation sets out maximum administrative fines calibrated to the severity of the infringement:

  • Prohibited practices (Article 5 violations): fines of up to €35 million or 7 % of total worldwide annual turnover, whichever is higher.
  • Most other obligations under the Regulation: fines of up to €15 million or 3 % of total worldwide annual turnover, whichever is higher.
  • Supplying incorrect or misleading information to authorities: fines of up to €7.5 million or 1 % of total worldwide annual turnover, whichever is higher.

For SMEs and start-ups, the Regulation provides that the lower of the two figures (absolute cap or turnover percentage) applies, offering a degree of proportionality. In Spain, AESIA will be the authority responsible for investigating infringements and imposing sanctions once its full enforcement powers become operational from 2 August 2026.

The likely practical effect of these EU AI Act fines is that compliance will become a board-level priority for any organisation developing or using AI systems in Spain. Effective risk mitigation should include the following measures:

  • Internal compliance programme. Designate an AI compliance lead and embed AI risk assessment into existing governance, risk and compliance (GRC) frameworks.
  • Vendor contract review. Update supply agreements to include AI Act compliance warranties, audit rights and indemnification for non-conformity.
  • Data protection alignment. Where AI systems process personal data, align AI Act obligations with existing GDPR requirements, including conducting Data Protection Impact Assessments (DPIAs) where appropriate.
  • Insurance. Review professional-indemnity and product-liability policies for AI-related exclusions and consider dedicated technology-errors-and-omissions cover.

Practical Compliance Checklist and Contract Clauses for AI Act Compliance in Spain

The following checklist is designed for legal and compliance teams preparing for the EU AI Act in Spain. It can be adapted to fit both provider and deployer workflows:

  1. Conduct a full AI system inventory, identify every AI system your organisation develops, deploys or distributes.
  2. Classify each system by risk tier (prohibited, high-risk, limited-risk, minimal-risk) using Annex III criteria and AESIA guidance.
  3. For high-risk systems: initiate or update technical documentation and begin the conformity assessment process.
  4. Appoint an internal AI compliance lead with cross-functional authority (legal, IT, operations, HR).
  5. For third-country providers: formalise the appointment of an EU-based authorised representative in writing.
  6. Register applicable high-risk AI systems in the EU database before placing them on the market or putting them into service.
  7. Implement human-oversight procedures and train designated oversight personnel.
  8. Establish a post-market monitoring system with defined escalation and incident-reporting protocols to AESIA.
  9. Review and update all vendor, procurement and distribution contracts to include AI Act compliance clauses.
  10. Align AI governance with GDPR requirements, conduct DPIAs where the AI system processes personal data.
  11. Monitor AESIA publications and BOE for updates on Spain’s draft national Organic Law on AI.
  12. Schedule quarterly internal audits of AI compliance status and document all findings.

Key Contract Clauses for Providers and Deployers

When negotiating AI-related agreements in Spain, the following clause categories deserve particular attention:

  • Compliance warranty. The provider warrants that the AI system has undergone the applicable conformity assessment and complies with Regulation (EU) 2024/1689 at the date of delivery and throughout the contract term.
  • Audit rights. The deployer or customer retains the right to audit the provider’s technical documentation, risk-management records and post-market monitoring data upon reasonable notice.
  • Indemnification for non-conformity. The provider indemnifies the deployer against fines, penalties and third-party claims arising from the provider’s failure to comply with AI Act obligations.
  • Data-access obligations. The provider agrees to make training data governance records available to the deployer and to AESIA upon lawful request.
  • Incident notification. Both parties agree to notify each other of any serious incident involving the AI system within a defined timeframe, and to cooperate in reporting to AESIA.

What to Do Next, Immediate Actions and Expert Consultation

For organisations operating in Spain, the compliance window is narrowing. A structured approach over the next 90 days will position your business to meet the 2 August 2026 deadline with confidence:

  • Within 30 days: Complete your AI system inventory and preliminary risk classification. Identify any systems that may fall under Article 5 prohibited practices.
  • Within 60 days: Begin conformity assessments for high-risk systems. Appoint your AI compliance lead and engage with AESIA’s published compliance guides.
  • Within 90 days: Finalise contract clause updates, implement human-oversight procedures and schedule your first internal audit cycle.

The answer to whether Spain is subject to the EU AI Act is unequivocal: yes, and the obligations are extensive, time-bound and carry significant financial penalties. Organisations that begin compliance work now will not only avoid enforcement risk but will also gain a competitive edge in a market where AI governance is rapidly becoming a commercial differentiator. Consulting a qualified technology law practitioner with Spain-specific experience is strongly recommended for navigating the intersection of the EU framework, AESIA requirements and Spain’s evolving national legislation.

Need Legal Advice?

This article was produced by Global Law Experts. For specialist advice on this topic, contact Jesus Osuna at Addwill, a member of the Global Law Experts network.

Sources

  1. Regulation (EU) 2024/1689, Artificial Intelligence Act (EUR-Lex)
  2. European Commission, Regulatory Framework on Artificial Intelligence
  3. AESIA, Spanish Agency for the Supervision of Artificial Intelligence
  4. AESIA, Compliance Guidelines Published 16 December 2025
  5. Official Journal of the European Union, Direct Access
  6. European Data Protection Board (EDPB)

FAQs

Is Spain subject to the EU AI Act?
Yes. The EU AI Act, Regulation (EU) 2024/1689, is an EU Regulation that applies directly in Spain. Providers placing AI systems on the Spanish market and deployers operating in Spain must meet all applicable obligations without the need for separate national transposition.
Spain does not currently have a standalone national AI law. However, Spain has established AESIA as a dedicated supervisory authority and is pursuing a draft national Organic Law on AI that may add supplementary obligations to the EU framework.
Providers, deployers, importers, distributors and authorised representatives who place or put AI systems into service in the EU/EEA must comply. Third-country providers whose AI system outputs are used in Spain are also within scope.
Article 5 of the Regulation prohibits specific AI practices deemed to pose an unacceptable risk, including social scoring by public authorities and AI systems that deploy subliminal or exploitative techniques to materially distort behaviour. These prohibitions have been enforceable since 2 February 2025.
The Regulation sets tiered maximum fines: up to €35 million or 7 % of global annual turnover for prohibited-practice violations; up to €15 million or 3 % for most other breaches; and up to €7.5 million or 1 % for supplying incorrect information to authorities.
AESIA is Spain’s national supervisory authority for artificial intelligence. It oversees AI Act enforcement, operates Spain’s AI regulatory sandbox and has published compliance guides to support providers and deployers. Engagement begins through AESIA’s official portal and published guidance documents.
For high-risk AI systems listed in Annex III of the Regulation, the full suite of obligations, including conformity assessment, registration and deployer duties, applies from 2 August 2026. High-risk systems embedded in existing EU-regulated products (Annex I) follow from 2 August 2027.
vasp authorisation brazil
By Jonathon Richards

posted 3 hours ago

Find the right Legal Expert for your business

The premier guide to leading legal professionals throughout the world

Specialism
Country
Practice Area
LAWYERS RECOGNIZED
0
EVALUATIONS OF LAWYERS BY THEIR PEERS
0 m+
PRACTICE AREAS
0
COUNTRIES AROUND THE WORLD
0
Lawyer Profile Page - Lead Capture
GLE-Logo-White
Lawyer Profile Page - Lead Capture

Is Spain Subject to the EU AI Act? 2026, Obligations for Providers & Deployers, AESIA Oversight, Timelines and Fines

Send welcome message

Custom Message