If your company uses AI in Spain (a SaaS tool with AI features, an automated CV screen, or a customer chatbot), parts of the EU AI Act (Regulation 2024/1689) already apply to you. AESIA is the authority that supervises them. By the end of this post you will have the correct dates, know which documents the agency can ask for, and hold an eight-step checklist you can start today with a spreadsheet.
Not sure where you stand? Take the 3-minute EU AI Act checklist for SMEs.
What you need
- One hour and a spreadsheet for the inventory.
- Access to whoever buys software in your company, to learn which AI-enabled tools are actually in use.
- The two reference texts: the Regulation on EUR-Lex and the AESIA portal.
- Optional: an AI assistant to help classify systems; the prompt is below.
What AESIA is
AESIA, the Agencia Española de Supervisión de la Inteligencia Artificial, is Spain’s national supervisory authority under the EU AI Act. It was created by Royal Decree 729/2023, published in the BOE on 19 July 2023, before the Act itself entered into force in August 2024. It sits under the Ministry for Digital Transformation and the Civil Service and is headquartered in A Coruña.
Its mandate covers every AI system deployed or placed on the Spanish market, whether the company behind it is Spanish, German or American. It publishes guidance, runs the regulatory sandbox and coordinates enforcement with the other EU authorities.
What AESIA can do
Supervise: request and review conformity assessments, technical documentation and risk-management records; commission or run tests of a system, including access to training data; monitor incidents reported in Spain; coordinate with other EU authorities.
Correct and sanction: issue corrective orders with a deadline; suspend the use of a non-compliant system; order market withdrawal; impose fines; refer serious cases to the public prosecutor.
Guide: publish guidance and interpretive notes, and operate a regulatory sandbox where AI products can be tested under supervision before launch.
When it asks for documentation, the usual window is 15 business days. Fines follow the Act’s three tiers:
| Infraction | Maximum fine | Turnover cap |
|---|---|---|
| Prohibited practices (Art. 5) | EUR 35,000,000 | 7% of global annual turnover |
| High-risk non-compliance (documentation, conformity assessment, EU registration) | EUR 15,000,000 | 3% of global annual turnover |
| Misleading information given to AESIA or a notified body | EUR 7,500,000 | 1% of global annual turnover |
For SMEs, and since Regulation (EU) 2026/1744 also small mid-caps, the Act applies the lower of the two amounts (Article 99(6) of Regulation (EU) 2024/1689) and requires proportionality: a good-faith first infringement normally ends in a corrective order, not a maximum fine.
The real dates after the July 2026 Omnibus
The EU Digital Omnibus, Regulation (EU) 2026/1744, was published in the Official Journal on 24 July 2026 and entered into force on 27 July. It postponed the high-risk obligations, added two prohibited practices and left the other dates in place. Sources: Gibson Dunn and the Cloud Security Alliance.
| Obligation | Applies from | Status in September 2026 |
|---|---|---|
| Prohibited practices (Art. 5) and AI literacy for staff (Art. 4) | 2 February 2025 | In force |
| General-purpose AI models (GPAI) | 2 August 2025 | In force |
| Transparency (Art. 50): chatbots identified as AI, generated content marked, deepfakes disclosed | 2 August 2026 (Art. 50(2) marking for generative systems already on the market: 2 December 2026) | In force |
| Two new prohibited practices (Art. 5): AI that generates realistic intimate or sexual images of an identifiable person without consent, or child sexual abuse material | 2 December 2026 | Two months away |
| Annex III high-risk systems (HR, credit, education, biometrics, critical infrastructure…) | 2 December 2027 | Fifteen months of runway |
| Annex I high-risk systems (AI inside regulated products) | 2 August 2028 | Almost two years of runway |
If you read anywhere that 2 August 2026 was the high-risk deadline, that text predates the Omnibus.
AESIA and the AEPD: you are almost certainly under both
They are separate regulators with overlapping jurisdiction whenever an AI system processes personal data, which is nearly always.
| Dimension | AESIA | AEPD |
|---|---|---|
| Legal basis | EU AI Act (Regulation 2024/1689) | GDPR + LOPDGDD |
| Focus | System safety, risk classification, human oversight, transparency | Personal data processing, data-subject rights, privacy |
Both agencies have said that coordinated inspections will be the norm in AI matters, so compliance with one does not cover the other. The GDPR obligations that run alongside are in our GDPR and AI convergence guide.
The eight-step action plan
Already in force: do this month
-
Build an AI inventory. List every AI tool you use, including the AI features in your HR software, CRM, chatbots and content generators. Columns: tool, vendor, what it is used for, what data it sees, who operates it.
-
Check for prohibited practices. Confirm that no use falls under Article 5: social scoring, subliminal manipulation, emotion recognition at work (with narrow exceptions) or real-time biometric identification in public spaces without a legal basis. For an SME the answer is normally “none”, and that answer gets written down.
-
Document AI literacy. If your staff use AI tools you are a “deployer”, and since 2 February 2025 you must take measures to support their AI literacy: that they understand the tools’ capabilities, limits and risks. Since Regulation 2026/1744 the Act does not require you to guarantee any individual’s level. A short course with a written completion record is a sound way to show those measures.
Article 50 goes with the inventory, in force since 2 August 2026. Whoever provides a chatbot must make clear to people that it is an AI (Art. 50(1)). If you built it, that’s you. As a deployer, disclose deepfakes and AI-generated text published to inform the public without human review or editorial responsibility (Art. 50(4)).
Before 2 December 2027: only if you have high-risk systems
-
Classify each system by risk level. For every inventory row, decide whether it falls under Annex III: employment and HR, credit and creditworthiness, education, law enforcement, biometric identification, critical infrastructure, migration and borders, justice and democratic processes. A useful prompt for your assistant: “Here is my inventory of AI-enabled tools. For each one, say whether it fits any Annex III category of Regulation (EU) 2024/1689, name the category and explain in one sentence why or why not.” Review the result; the assistant proposes, you decide.
-
Build the compliance package for high-risk systems. A documented risk-management system, technical documentation per Annex IV, data-governance records, automatic event logging for traceability, human-oversight controls, accuracy and resilience test results, and a post-market monitoring plan.
-
Register high-risk systems in the EU database. Before putting them into service, and in any case before the application date.
-
Complete the conformity assessment. Self-assessment is enough for most of Annex III. Biometric systems and part of critical infrastructure need a notified body.
-
Rehearse an inspection. Simulate AESIA’s request: can you hand over the risk-management records, the classification rationale and the human-oversight documentation within 15 business days? If yes, you are done.
What AESIA has published
As of this post, the AESIA portal carries guidance you can use directly:
| Document | Key content |
|---|---|
| AI Act implementation guide for operators | Step-by-step obligations by risk category |
| Regulatory sandbox framework | Application process and eligibility for supervised testing |
| High-risk AI classification guidelines | Practical Annex III classification with sector examples |
| AI literacy training minimum standards | What counts as sufficient training |
| Joint AESIA-AEPD statement | How simultaneous AI Act and GDPR compliance works |
| SME fast-track compliance guidance | Simplified path for businesses under 250 employees |
The primary language is Spanish; some material has English translations.
The local AI advantage
In a third party’s cloud, your audit trail (data governance, logs, human oversight) depends on what that provider discloses. On hardware inside your premises you control the logs, the data flow and the access, and you produce the documentation AESIA asks for yourself. That is why local deployments are simpler to audit, especially in HR, documents and customer service.
Next steps
- Phased plan to December 2027: the EU AI Act calendar after the Omnibus.
- Start with something minimal-risk: Your first three AI agents, deployed locally.
- Grab the template: Prohibited practices checklist (Article 5).
- Grab the template: Technical documentation template (Annex IV).
Work with us
We include AESIA compliance in every deployment: inventory, Article 5 check, Annex III classification, Annex IV documentation, literacy training with records, and joint AESIA + AEPD coverage. All the AI we deploy runs on local hardware, so there is less documentation to request from third parties. Each engagement is quoted per project. Book a compliance consultation or see how we work in consulting.