Spain did something no other EU country has done: it created a dedicated AI supervision agency before the EU AI Act even fully applies. The Agencia Española de Supervisión de la Inteligencia Artificial (AESIA) has been operational since June 2024, making it the first AI-specific regulatory body in the European Union.
If your business operates in Spain and uses AI, AESIA’s guides are the clearest map of what compliance looks like. By the end of this post you will know what the 16 guides cover, which ones apply to you, and the six steps to work through them.

What AESIA Has Done So Far
AESIA is not waiting for the EU AI Act’s high-risk dates (2 December 2027 for Annex III, after the Digital Omnibus). It has already built a substantial compliance infrastructure:
- 16 detailed compliance guides: the most comprehensive set of any national authority in the EU as of March 2026
- 12 regulatory sandbox projects: real AI systems tested under supervised conditions
- Inspections under way: AESIA already inspects AI systems, ahead of its full sanctioning powers
- The IAPP called AESIA’s output “genuinely pioneering regulatory work”
flowchart TD
AESIA["AESIA<br/>Spain's AI Watchdog"]
AESIA --> GUIDES["16 Compliance Guides<br/>Most detailed in EU"]
AESIA --> SANDBOX["12 Sandbox Projects<br/>Real-world AI testing"]
AESIA --> ENFORCE["Enforcement<br/>Inspections active now"]
AESIA --> SANCTION["Sanctioning Powers<br/>Pending Spanish AI Law"]
style AESIA fill:#F5A623,color:#0B1628
style GUIDES fill:#059669,color:#FAFAFA
style SANDBOX fill:#1E293B,color:#FAFAFA
style ENFORCE fill:#1E293B,color:#FAFAFA
style SANCTION fill:#1E293B,color:#FAFAFAWhat Makes AESIA Different
Unlike traditional regulatory bodies that only punish violations, AESIA was designed as a “Think & Do” organization. It investigates problems and proposes solutions, not just fines. This matters because:
-
The guides are practical, not theoretical. They were developed through the regulatory sandbox with industry input, real companies tested real AI systems and the guidance reflects what actually works.
-
They represent AESIA’s interpretation. While technically non-binding, these are the guidelines inspectors use when they evaluate compliance, so they are the reference to work from.
-
Spain is ahead of the curve. Most EU countries don’t have equivalent guidance yet. Spanish businesses have an advantage: a clear compliance roadmap while competitors in other countries are guessing.
The 16 Guides: What They Cover
AESIA’s compliance guides span the full lifecycle of AI system governance:
| Guide Area | What It Covers | Who Needs It |
|---|---|---|
| Risk classification | How to determine if your AI is high-risk | Every AI deployer |
| Transparency | What users must be told about AI interactions | Customer-facing AI |
| Data governance | Training data documentation and quality | Model developers |
| Human oversight | Required human-in-the-loop controls | High-risk systems |
| Technical documentation | What to document and how | All AI providers |
| Conformity assessment | Self-assessment vs third-party audit | High-risk systems |
| Post-market monitoring | Ongoing compliance after deployment | All AI deployers |
| Incident reporting | When and how to report AI incidents | All operators |
When AESIA Gets Sanctioning Powers
AESIA currently conducts inspections and issues guidance. Full sanctioning powers are pending the Draft Spanish AI Law (Ley de Inteligencia Artificial), which will implement the EU AI Act at the national level.
When that law passes, AESIA will be able to impose the EU AI Act’s penalty structure:
| Violation | Maximum Fine |
|---|---|
| Prohibited AI practices | EUR 35 million or 7% of global turnover |
| High-risk non-compliance | EUR 15 million or 3% of turnover |
| Incorrect information | EUR 7.5 million or 1% of turnover |
For SMEs, and since Regulation (EU) 2026/1744 also small mid-caps, the lower of the two amounts applies (Article 99(6) of Regulation (EU) 2024/1689).
Businesses that already follow AESIA’s guides will be in compliance when the law passes, with little left to change.
What This Means for Your Business
If you use AI for customer interactions
Under Article 50(1), whoever provides a chatbot or AI-powered support must make clear to customers that they are interacting with AI; if you built it, that’s you. As a deployer, you must disclose deepfakes and AI-generated text published to inform the public without human review (Art. 50(4)). AESIA’s transparency guides detail exactly how and when to make this disclosure.
If you use AI for hiring, credit, or healthcare
These are classified as high-risk under the EU AI Act. You need technical documentation, human oversight controls, and likely a conformity assessment. AESIA’s guides walk you through each requirement.
If you deploy AI on local hardware
This is where VORLUX AI clients have a structural advantage. Local deployment simplifies several AESIA/EU AI Act requirements:
- Data governance: When data never leaves your premises, documentation is straightforward
- Transparency: You control the full stack, so you know exactly what your AI does
- Human oversight: Local systems are easier to monitor and override
- Post-market monitoring: Local logs give you complete audit trails
The dates that already apply
AESIA already conducts inspections. Its sanctioning powers come with the Spanish law, with no grace period beyond what the EU AI Act already provides. Transparency duties have applied since 2 August 2026 (only the Art. 50(2) marking by providers of generative systems already on the market has until 2 December 2026), and the EU AI Act calendar after the Omnibus is fixed by the Digital Omnibus, Regulation (EU) 2026/1744.
Your AESIA Compliance Checklist
- Classify your AI systems: Use AESIA’s risk classification guide to determine which category each system falls into
- Document everything: Technical specs, training data sources, intended use, known limitations
- Implement transparency: Ensure users know when they’re interacting with AI
- Set up human oversight: Define who monitors AI decisions and how they can intervene
- Establish incident reporting: Create a process for detecting and reporting AI incidents
- Review AESIA’s 16 guides: Available at datos.gob.es
How VORLUX AI Helps
We don’t just deploy AI, we deploy compliant AI. Every Edge AI deployment we deliver includes:
- Risk classification aligned with AESIA’s framework
- Technical documentation covering model specs, data handling, and limitations
- Human oversight controls built into the system architecture
- GDPR compliance by design: data never leaves your building
- Audit-ready logs for post-market monitoring
When AESIA inspects your AI system, you’ll have everything they need. That’s not an afterthought: it’s how we build.
Want a second pair of eyes? Book a free 15-minute assessment and we will go through your AI systems against AESIA’s guidelines with you.
Related: EU AI Act Compliance Guide | 8 Prohibited AI Practices | GDPR + Local AI
Sources: AESIA Official Site | AESIA Compliance Guides (datos.gob.es) | EU AI Act in Spain (EU AI Compass) | IAPP: AESIA’s AI Guidelines | Spain Issues Guidance (Inside Privacy)
Next steps
- Use the AESIA risk classification guide to categorise your AI systems.
- Review the technical documentation and training data sources for your models.
- Check your chatbot transparency settings under Article 50(1).
- Read the EU AI Act Compliance Guide 2026 for the full calendar.
Related reading
- EU AI Act Compliance Guide 2026: What Spanish SMEs Must Do Now
- The EU AI Act Calendar After the Digital Omnibus
- GDPR and AI Convergence in 2026: Why Local Deployment Is the Only Clean Answer
- Grab the template: AI risk classification worksheet.
Work with us
We size the model and the machine by measuring, not by guessing, and we document the classification as we go. If you want your own AI systems checked against AESIA’s guides, book a 15-minute call or see how we work in consulting.