View all articles
AESIAEU AI ActComplianceSpainRegulation

AESIA: What Every Spanish Business Deploying AI Must Know in 2026

JG
Jacobo González Jaspe
|

Reviewed:

Abstract illustration: concentric rings of a vault mechanism with amber light in the seams. Safe and legal
Illustration generated with AI on our own machine.

If your company uses AI in Spain (a SaaS tool with AI features, an automated CV screen, or a customer chatbot), parts of the EU AI Act (Regulation 2024/1689) already apply to you. AESIA is the authority that supervises them. By the end of this post you will have the correct dates, know which documents the agency can ask for, and hold an eight-step checklist you can start today with a spreadsheet.

Not sure where you stand? Take the 3-minute EU AI Act checklist for SMEs.

What you need

  • One hour and a spreadsheet for the inventory.
  • Access to whoever buys software in your company, to learn which AI-enabled tools are actually in use.
  • The two reference texts: the Regulation on EUR-Lex and the AESIA portal.
  • Optional: an AI assistant to help classify systems; the prompt is below.

What AESIA is

AESIA, the Agencia Española de Supervisión de la Inteligencia Artificial, is Spain’s national supervisory authority under the EU AI Act. It was created by Royal Decree 729/2023, published in the BOE on 19 July 2023, before the Act itself entered into force in August 2024. It sits under the Ministry for Digital Transformation and the Civil Service and is headquartered in A Coruña.

Its mandate covers every AI system deployed or placed on the Spanish market, whether the company behind it is Spanish, German or American. It publishes guidance, runs the regulatory sandbox and coordinates enforcement with the other EU authorities.

What AESIA can do

Supervise: request and review conformity assessments, technical documentation and risk-management records; commission or run tests of a system, including access to training data; monitor incidents reported in Spain; coordinate with other EU authorities.

Correct and sanction: issue corrective orders with a deadline; suspend the use of a non-compliant system; order market withdrawal; impose fines; refer serious cases to the public prosecutor.

Guide: publish guidance and interpretive notes, and operate a regulatory sandbox where AI products can be tested under supervision before launch.

When it asks for documentation, the usual window is 15 business days. Fines follow the Act’s three tiers:

InfractionMaximum fineTurnover cap
Prohibited practices (Art. 5)EUR 35,000,0007% of global annual turnover
High-risk non-compliance (documentation, conformity assessment, EU registration)EUR 15,000,0003% of global annual turnover
Misleading information given to AESIA or a notified bodyEUR 7,500,0001% of global annual turnover

For SMEs, and since Regulation (EU) 2026/1744 also small mid-caps, the Act applies the lower of the two amounts (Article 99(6) of Regulation (EU) 2024/1689) and requires proportionality: a good-faith first infringement normally ends in a corrective order, not a maximum fine.

The real dates after the July 2026 Omnibus

The EU Digital Omnibus, Regulation (EU) 2026/1744, was published in the Official Journal on 24 July 2026 and entered into force on 27 July. It postponed the high-risk obligations, added two prohibited practices and left the other dates in place. Sources: Gibson Dunn and the Cloud Security Alliance.

ObligationApplies fromStatus in September 2026
Prohibited practices (Art. 5) and AI literacy for staff (Art. 4)2 February 2025In force
General-purpose AI models (GPAI)2 August 2025In force
Transparency (Art. 50): chatbots identified as AI, generated content marked, deepfakes disclosed2 August 2026 (Art. 50(2) marking for generative systems already on the market: 2 December 2026)In force
Two new prohibited practices (Art. 5): AI that generates realistic intimate or sexual images of an identifiable person without consent, or child sexual abuse material2 December 2026Two months away
Annex III high-risk systems (HR, credit, education, biometrics, critical infrastructure…)2 December 2027Fifteen months of runway
Annex I high-risk systems (AI inside regulated products)2 August 2028Almost two years of runway

If you read anywhere that 2 August 2026 was the high-risk deadline, that text predates the Omnibus.

AESIA and the AEPD: you are almost certainly under both

They are separate regulators with overlapping jurisdiction whenever an AI system processes personal data, which is nearly always.

DimensionAESIAAEPD
Legal basisEU AI Act (Regulation 2024/1689)GDPR + LOPDGDD
FocusSystem safety, risk classification, human oversight, transparencyPersonal data processing, data-subject rights, privacy

Both agencies have said that coordinated inspections will be the norm in AI matters, so compliance with one does not cover the other. The GDPR obligations that run alongside are in our GDPR and AI convergence guide.

The eight-step action plan

Already in force: do this month

  1. Build an AI inventory. List every AI tool you use, including the AI features in your HR software, CRM, chatbots and content generators. Columns: tool, vendor, what it is used for, what data it sees, who operates it.

  2. Check for prohibited practices. Confirm that no use falls under Article 5: social scoring, subliminal manipulation, emotion recognition at work (with narrow exceptions) or real-time biometric identification in public spaces without a legal basis. For an SME the answer is normally “none”, and that answer gets written down.

  3. Document AI literacy. If your staff use AI tools you are a “deployer”, and since 2 February 2025 you must take measures to support their AI literacy: that they understand the tools’ capabilities, limits and risks. Since Regulation 2026/1744 the Act does not require you to guarantee any individual’s level. A short course with a written completion record is a sound way to show those measures.

Article 50 goes with the inventory, in force since 2 August 2026. Whoever provides a chatbot must make clear to people that it is an AI (Art. 50(1)). If you built it, that’s you. As a deployer, disclose deepfakes and AI-generated text published to inform the public without human review or editorial responsibility (Art. 50(4)).

Before 2 December 2027: only if you have high-risk systems

  1. Classify each system by risk level. For every inventory row, decide whether it falls under Annex III: employment and HR, credit and creditworthiness, education, law enforcement, biometric identification, critical infrastructure, migration and borders, justice and democratic processes. A useful prompt for your assistant: “Here is my inventory of AI-enabled tools. For each one, say whether it fits any Annex III category of Regulation (EU) 2024/1689, name the category and explain in one sentence why or why not.” Review the result; the assistant proposes, you decide.

  2. Build the compliance package for high-risk systems. A documented risk-management system, technical documentation per Annex IV, data-governance records, automatic event logging for traceability, human-oversight controls, accuracy and resilience test results, and a post-market monitoring plan.

  3. Register high-risk systems in the EU database. Before putting them into service, and in any case before the application date.

  4. Complete the conformity assessment. Self-assessment is enough for most of Annex III. Biometric systems and part of critical infrastructure need a notified body.

  5. Rehearse an inspection. Simulate AESIA’s request: can you hand over the risk-management records, the classification rationale and the human-oversight documentation within 15 business days? If yes, you are done.

What AESIA has published

As of this post, the AESIA portal carries guidance you can use directly:

DocumentKey content
AI Act implementation guide for operatorsStep-by-step obligations by risk category
Regulatory sandbox frameworkApplication process and eligibility for supervised testing
High-risk AI classification guidelinesPractical Annex III classification with sector examples
AI literacy training minimum standardsWhat counts as sufficient training
Joint AESIA-AEPD statementHow simultaneous AI Act and GDPR compliance works
SME fast-track compliance guidanceSimplified path for businesses under 250 employees

The primary language is Spanish; some material has English translations.

The local AI advantage

In a third party’s cloud, your audit trail (data governance, logs, human oversight) depends on what that provider discloses. On hardware inside your premises you control the logs, the data flow and the access, and you produce the documentation AESIA asks for yourself. That is why local deployments are simpler to audit, especially in HR, documents and customer service.

Next steps

Work with us

We include AESIA compliance in every deployment: inventory, Article 5 check, Annex III classification, Annex IV documentation, literacy training with records, and joint AESIA + AEPD coverage. All the AI we deploy runs on local hardware, so there is less documentation to request from third parties. Each engagement is quoted per project. Book a compliance consultation or see how we work in consulting.

Diagram
Share: LinkedIn X
Veredicto semanal

Get new guides before anyone else

Subscribe and we tell you when new guides, templates and workflows go up. One email a week, no spam.

Already published: 69 guides and 25 templates. All free, no signup.

Bonus: the EU AI Act checklist, ready to complete
Once a week No spam Unsubscribe anytime

See what you get

The EU AI Act now applies: a checklist you can complete

Tell us what you want to run

Tell us what you want to run and on what budget. We will tell you which hardware you need, which model fits, and what to expect from it, before you spend anything.

First call free, 15 min Local-first: your data stays on your network Open tools and guides

69 free guides · 17 compliance templates