Regulation (EU) 2024/1689, known as the AI Act, is the world’s first comprehensive law governing the development, placing on the market and use of artificial intelligence systems. It entered into force on 1 August 2024. Its transparency obligations apply from 2 August 2026, and the high-risk obligations apply from 2 December 2027 or 2 August 2028 depending on the annex.
Spain also has its own employment-law obligation. Since 5 October 2026, Royal Decree 723/2026 requires employers to explain in writing to each worker the algorithms that decide on their working time, tasks, pay or dismissal, whether or not they are high-risk. We cover it in our guide on algorithmic information for workers.
The AI Act classifies AI systems into four risk levels: unacceptable (prohibited), high, limited and minimal. The rules on prohibited AI practices have applied since February 2025. Companies that develop or use high-risk AI systems will need a risk management system, technical documentation, data governance, human oversight and registration in the EU public database.
Fines can reach EUR 35 million or 7% of total worldwide annual turnover for prohibited practices, and up to EUR 15 million or 3% for other infringements. We explain them in our guide to AI Act penalties.
In Spain, the Spanish Agency for the Supervision of Artificial Intelligence (AESIA) is the competent authority for supervising compliance with the AI Act.
The General Data Protection Regulation (GDPR) also continues to apply whenever AI systems process personal data. We explain how the two fit together in AI Act and GDPR.
The Spanish Data Protection Agency (AEPD) supervises this area.
In our experience, most tech companies don’t know whether their AI systems qualify as high-risk. That is the first thing we assess.
Marta Suárez – CEO, Innovatech