EU AI Act Lawyer in Spain

AI Act high-risk obligations apply from 2 December 2027. Is your company ready?

We help you comply with the EU Artificial Intelligence Act at every stage. Prohibited practices and transparency rules already apply, and high-risk obligations arrive on 2 December 2027. Whether you develop AI solutions or integrate them into your processes, you need a clear compliance plan.

Request a free initial assessment. We’ll give you a risk diagnosis, an action plan and a quote tailored to your project.

No commitment · We reply the same day

    YEARS OF EXPERIENCE

    + 0

    CLIENTS ADVISED

    + 0

    PROJECTS COMPLETED

    + 0

    PRACTICE AREAS

    + 0

    WHAT SETS US APART

    We Speak the Same Language as Your Tech Team

    We reply the same day
    Innovatech despacho

    ARTIFICIAL INTELLIGENCE LEGAL SERVICES

    What Does Your Company Need?

    We anticipate and identify issues, providing comprehensive legal advice so you can meet the obligations imposed by the new legislation.

    We assess your risk level under Regulation (EU) 2024/1689, design the risk management system and prepare the mandatory technical documentation before your high-risk deadline, which is 2 December 2027 or 2 August 2028 depending on the applicable annex.

    Data protection impact assessments (DPIAs), GDPR compatibility of datasets, data licences for training and legal bases for automated processing.

    Contractual structures that allocate liability when an algorithm makes decisions affecting customers, employees or third parties.

    We assess the lawfulness of datasets, licences, intellectual property and compatibility with data protection rules. We help you build compliance into the project, advise on good practice and design working protocols and data flows fully adapted to each project.

    We carry out preventive reviews to ensure transparency, traceability and regulatory compliance.

    SECTORS AND COMPANIES

    Do You Use AI in Any of These Sectors?

    Fintech

    Credit scoring and fraud detection

    Digital Health

    Processing of medical data

    Human Resources

    Recruitment algorithms

    Marketing and Advertising

    Automated targeting

    Public Sector

    AI in decision-making processes

    PROCESS AND TIMELINES

    How We Work

    From the first call to compliance, in 4 steps

    1 –

    Initial assessment

    We analyse your AI system, its purpose and its risk level under the AI Act. Free of charge and with no commitment.

    2 –

    Risk assessment

    We identify possible regulatory breaches, algorithmic bias and documentation gaps.

    3 –

    Compliance plan

    We design internal policies, contract clauses, human oversight protocols and audit mechanisms.

    4 –

    Ongoing support

    We update your strategy as the regulation and your technology evolve.

    REVIEWS AND RATINGS

    What Our Clients Say

    Reviews from real clients and companies about our artificial intelligence law services.

    Dimas Pérez
    1 review
    Marta combines impeccable professionalism with a remarkable ability to explain complex legal concepts in simple terms...
    Roberto Fernandez
    3 reviews
    Impeccable personal attention, availability and human touch. Broad knowledge and experience in the sector. Outstanding at solving problems. 100% recommended...
    Alina
    1 review
    I have no words to express my sincere gratitude. Marta is a very dedicated and empathetic professional. She also works fast...
    Gregorio Gigorro
    1 review
    Thank you so much, Marta, for your invaluable advice. Without your knowledge of NFT technology in the art market, a new and promising field but one exposed to a lot of fraud, I would have got myself into serious trouble. Marta …

    COMPLIANCE OBLIGATIONS

    Artificial Intelligence Regulation in Spain and the European Union

    Regulation (EU) 2024/1689, known as the AI Act, is the world’s first comprehensive law governing the development, placing on the market and use of artificial intelligence systems. It entered into force on 1 August 2024. Its transparency obligations apply from 2 August 2026, and the high-risk obligations apply from 2 December 2027 or 2 August 2028 depending on the annex.

    Spain also has its own employment-law obligation. Since 5 October 2026, Royal Decree 723/2026 requires employers to explain in writing to each worker the algorithms that decide on their working time, tasks, pay or dismissal, whether or not they are high-risk. We cover it in our guide on algorithmic information for workers.

    The AI Act classifies AI systems into four risk levels: unacceptable (prohibited), high, limited and minimal. The rules on prohibited AI practices have applied since February 2025. Companies that develop or use high-risk AI systems will need a risk management system, technical documentation, data governance, human oversight and registration in the EU public database.

    Fines can reach EUR 35 million or 7% of total worldwide annual turnover for prohibited practices, and up to EUR 15 million or 3% for other infringements. We explain them in our guide to AI Act penalties.

    In Spain, the Spanish Agency for the Supervision of Artificial Intelligence (AESIA) is the competent authority for supervising compliance with the AI Act.

    The General Data Protection Regulation (GDPR) also continues to apply whenever AI systems process personal data. We explain how the two fit together in AI Act and GDPR.

    The Spanish Data Protection Agency (AEPD) supervises this area.

    In our experience, most tech companies don’t know whether their AI systems qualify as high-risk. That is the first thing we assess.

    Marta Suárez – CEO, Innovatech

    FAQ

    Frequently Asked Questions on Artificial Intelligence and the Law

    The AI Act applies in stages. The prohibited practices have applied since February 2025. The obligations for general-purpose AI models (GPAI) have applied since August 2025. Transparency obligations apply from 2 August 2026. High-risk obligations arrive on 2 December 2027 for Annex III and on 2 August 2028 for Annex I. If your company uses AI in recruitment, credit scoring, medical diagnosis or administrative processes, the high-risk obligations probably affect you.

    It depends on the level of control over the system and on compliance with the AI Act’s due-diligence obligations. As a deployer, you must ensure effective human oversight, monitor how the system operates and report serious incidents. Depending on the case, liability may fall on the system provider, on the deployer, or on both.

    Yes, as long as there is human oversight and the transparency obligations of Article 50 of the AI Act are met: informing users that they are interacting with AI and labelling generated content as synthetic. Intellectual property rights and the confidentiality of the data used must also be respected.

    Up to EUR 35 million or 7% of total worldwide annual turnover for prohibited AI practices. Up to EUR 15 million or 3% for breaches of other obligations. SMEs benefit from a proportionate regime, but they are not exempt.

    The AI Act introduces obligations that go beyond data protection: algorithmic risk management, technical documentation, conformity assessments, registration in the EU database and human oversight. A generalist lawyer can cover the GDPR, but AI Act compliance requires technical understanding of how AI systems work as well as knowledge of the regulation.

    The Spanish Agency for the Supervision of Artificial Intelligence (AESIA) is the competent authority in Spain for supervising compliance with the AI Act. Its inspection powers and the penalty regime were to be set out in the Spanish draft Organic Law on the governance of artificial intelligence. The bill lapsed when the Spanish Parliament was dissolved in October 2026 and will have to be reintroduced in the next legislature.

    REQUEST YOUR ASSESSMENT

    Request a free initial assessment and receive a step-by-step plan and a tailored quote.