View all articles
EU AI ActComplianceSMEsEdge AIGDPRSpain

EU AI Act Compliance Guide 2026: What Spanish SMEs Must Do Now

JG
Jacobo González Jaspe
|

Reviewed:

Abstract illustration: classical columns reduced to geometric pillars, side-lit in amber. Safe and legal
Illustration generated with AI on our own machine.
This article is also available in Spanish:EU AI Act: guía práctica para pymes españolas (2026)

Updated 4 October 2026. This post is from February 2026 and names Qwen 2.5 as current. The method and the advice still hold; today you would run it with:

  • Qwen 3.6: Use these larger models for complex reasoning tasks where the compliance overhead of smaller models is acceptable.
  • Gemma 4: Deploy these small models on edge hardware to maintain data sovereignty while handling standard text processing.
  • DeepSeek V4: Use medium-sized versions of this model for more intensive automation tasks that still require local execution.

The EU AI Act is already law and applies in phases. If your company uses any AI system, from a chatbot on your website to an automated hiring tool, some of its rules already apply to you. This guide breaks down where the calendar stands after the Digital Omnibus (in force 27 July 2026) and what Spanish small and medium enterprises can do now to be ready for the Annex III high-risk date of 2 December 2027.

EU AI Act implementation timeline
gantt
    title EU AI Act Compliance Timeline
    dateFormat  YYYY-MM-DD
    axisFormat  %b %Y

    section Prohibited Practices
    Art. 5 — Banned AI practices       :crit, done, p1, 2025-02-02, 1d
    Two new Art. 5 bans apply          :crit, p2, 2026-12-02, 1d

    section GPAI Obligations
    Prepare GPAI documentation          :active, prep1, 2025-04-01, 2025-08-02
    Art. 51-53 — GPAI rules apply       :crit, gpai, 2025-08-02, 1d

    section Transparency
    Art. 50 — Transparency applies      :crit, milestone, tr1, 2026-08-02, 1d
    Art. 50(2) marking, legacy systems  :tr2, 2026-08-02, 2026-12-02

    section High-Risk AI (Annex III)
    Conduct AI inventory & classify     :hr1, 2026-09-01, 2027-02-01
    Implement oversight & risk mgmt     :hr2, 2027-02-01, 2027-08-01
    Conformity assessments              :hr3, 2027-08-01, 2027-12-02
    Art. 6-43 — Annex III applies       :crit, milestone, hr4, 2027-12-02, 1d

    section Annex I High-Risk
    Regulated products (Annex I)        :ann1, 2027-12-03, 2028-08-02
    Annex I fully enforceable           :crit, milestone, ann2, 2028-08-02, 1d
Diagram

Take the 3-minute EU AI Act checklist.

The Four Key Dates You Cannot Ignore

The EU AI Act entered into force on August 1, 2024, but its provisions roll out in phases. Here is the timeline that matters:

February 2, 2025: Prohibited Practices (ALREADY IN EFFECT)

Eight categories of AI are now banned across the EU. These include social scoring systems, manipulative AI that exploits vulnerabilities, real-time biometric identification in public spaces (with narrow law-enforcement exceptions), and emotion recognition in workplaces and schools. If any of your AI systems fall into these categories, you are already in violation. The Digital Omnibus adds two more bans from 2 December 2026: AI that generates non-consensual intimate images of an identifiable person, and AI that generates child sexual abuse material (Regulation (EU) 2026/1744).

Most SMEs do not operate in these categories, but you should audit your tools to confirm. Some third-party AI plugins or SaaS products might include features that cross these lines without your knowledge.

August 2, 2025: General-Purpose AI (GPAI) Obligations (IN EFFECT)

These have applied since August 2025. If you develop or deploy a general-purpose AI model, or use one as a foundation for your products, new transparency and documentation requirements apply. GPAI providers must publish model cards, document training data summaries, and implement copyright compliance measures.

For SMEs that use models like Llama, Qwen, or Gemma in their products, this means you need clear documentation of which models you use, how they were trained, and what safeguards you have in place. Open-source models with permissive licenses (Apache 2.0, MIT) benefit from some exemptions, but the transparency obligations still apply if you deploy them commercially.

August 2, 2026: Transparency Obligations (IN EFFECT)

Article 50 applies. The provider of a chatbot must design it so people know they are talking to an AI (Article 50(1)), and providers of generative AI must mark its output in a machine-readable way (Article 50(2)). As a deployer, you must disclose deepfakes and AI-generated text you publish to inform the public without human review or editorial responsibility (Article 50(4)). The only transition: providers of generative systems already on the market before 2 August 2026 have until 2 December 2026 for the Article 50(2) marking.

December 2, 2027: High-Risk AI Systems (THE BIG ONE)

After the Digital Omnibus (Regulation (EU) 2026/1744, in force 27 July 2026), the full compliance framework for Annex III high-risk AI systems applies from 2 December 2027. AI embedded in regulated products (Annex I) follows on 2 August 2028. High-risk categories include AI used in employment and worker management, education assessment, credit scoring, law enforcement support, and critical infrastructure management. Companies deploying high-risk AI must implement risk management systems, data governance, technical documentation, human oversight, and conformity assessments.

Risk Classification: Where Does Your AI Fit?

The EU AI Act classifies all AI systems into four tiers:

Risk LevelExamplesWhat You Must Do
UnacceptableSocial scoring, manipulative subliminal AI, real-time public biometric IDBanned outright since February 2025
High RiskHR screening tools, credit scoring, medical diagnosis AI, educational assessmentFull compliance: risk management, data governance, human oversight, conformity assessment
Limited RiskChatbots, AI content generators, recommendation systemsTransparency: users must know they are interacting with AI
Minimal RiskSpam filters, inventory optimization, internal analyticsNo specific obligations, but good practices encouraged

The reality for most Spanish SMEs: Your AI likely falls into “limited risk”: customer-facing chatbots, document automation, content generation, or internal process optimization. You need transparency labels and basic documentation, but not the full compliance audit required for high-risk systems.

However, if you use AI for anything related to hiring, employee evaluation, customer creditworthiness, or public-facing decisions that affect people’s rights, you are in high-risk territory and need to start preparing now.

What Spanish SMEs Need to Do RIGHT NOW

1. Conduct an AI Inventory

List every AI tool your company uses. Include SaaS subscriptions (ChatGPT, Copilot, Jasper), embedded AI features in your existing software, custom models, and any automated decision-making systems. You cannot comply with what you do not know about.

2. Classify Each System by Risk Level

Map each AI tool to the EU risk categories above. Most will be minimal or limited risk. Flag anything that touches hiring, credit, education, or public-facing automated decisions.

3. Implement Transparency Measures

For all limited-risk AI: make sure people know when they are interacting with AI. If you built your chatbot, you are its provider and Article 50(1) requires that notice; if you use a vendor’s chatbot, check that it has one. Deepfakes and AI-generated text you publish to inform the public without human review must be disclosed (Article 50(4)). These duties have applied since 2 August 2026.

4. Document Your AI Systems

Prepare technical documentation for your AI deployments. Include the model used, its intended purpose, training data provenance (especially for open-source models), and any safeguards or human oversight in place. This documentation has been part of GPAI compliance since August 2025, and it is the core of the Annex III file you will need by December 2027.

5. Designate a Compliance Point Person

Even small companies need someone responsible for AI compliance. This does not have to be a full-time role, but someone needs to track regulatory updates and ensure your systems stay aligned.

How Local/Edge AI Gives You a Compliance Advantage

Here is where the architecture of your AI deployment matters enormously for compliance. Running AI locally (on your own hardware, in your own office) creates a natural data sovereignty boundary that simplifies multiple compliance requirements simultaneously.

Data Sovereignty by Design

When your AI runs on a local device (a Mac Mini, an NVIDIA Jetson, or an Intel NUC sitting in your office), your data never leaves your premises. GDPR Article 44 restricts international data transfers. The EU AI Act layers additional data governance requirements on top. Local AI eliminates the entire category of cross-border data transfer risk.

Simplified GPAI Documentation

When you deploy an open-source model locally, you control the entire stack. You know exactly which model version is running, what quantization is applied, and what data flows through it. This makes technical documentation straightforward compared to documenting your usage of an opaque cloud API that can change without notice.

Reduced Attack Surface

Fewer network connections mean fewer compliance risks. A local AI system does not expose your data to third-party processors, reducing both your GDPR processor agreements and your AI Act risk assessment scope.

Cost Predictability

Cloud AI billing is variable and hard to budget. Local hardware is a one-time purchase with predictable energy costs. For SMEs managing tight budgets, this predictability also simplifies compliance cost reporting.

The Vorlux AI Approach

At Vorlux AI, we deploy small language models (SLMs) on local hardware specifically designed for Spanish SME compliance needs. Our edge AI deployments run models like Qwen 2.5, Gemma 4, and Phi-4 on devices that sit in your office. Your data stays in Spain, on your network, under your control.

Next Steps

The Annex III date is 2 December 2027. Starting now means you do the work at your own pace, while the harmonised standards and AESIA guidance mature alongside you.


Sources: Regulation (EU) 2024/1689 on EUR-Lex · Regulation (EU) 2026/1744 on EUR-Lex · EU AI Act Official · EU AI Act Service Desk


Work with us

We size the model and the machine by measuring, not by guessing. If you want to see your own task running on real hardware, book a 15-minute call or see how we work in consulting.

Diagram
Share: LinkedIn X
Veredicto semanal

Get new guides before anyone else

Subscribe and we tell you when new guides, templates and workflows go up. One email a week, no spam.

Already published: 69 guides and 25 templates. All free, no signup.

Bonus: the EU AI Act checklist, ready to complete
Once a week No spam Unsubscribe anytime

See what you get

The EU AI Act now applies: a checklist you can complete

Tell us what you want to run

Tell us what you want to run and on what budget. We will tell you which hardware you need, which model fits, and what to expect from it, before you spend anything.

First call free, 15 min Local-first: your data stays on your network Open tools and guides

69 free guides · 17 compliance templates