AI Act: a guide to the EU Artificial Intelligence Act for businesses in Spain (2026)

The AI Act is Regulation (EU) 2024/1689, the world’s first comprehensive law governing the development, marketing and use of artificial intelligence systems. It was adopted on 13 June 2024 and applies directly in Spain, with no need for transposition. It affects any company that develops, distributes or simply uses AI, not just technology companies. Since 2 August 2026 the transparency duties in Article 50 have been enforceable. The obligations for high-risk systems were postponed by the Digital Omnibus on AI and apply from 2 December 2027 or 2 August 2028, depending on the type of system.

This guide explains what the AI Act is, who it applies to, how it classifies risk, what obligations it imposes, what penalties it provides for and how to prepare your company before those deadlines arrive.

If you need a technology lawyer in Spain, request a consultation with us.

Table of contents

What the AI Act is and who it applies to

The AI Act is a directly applicable EU regulation that governs artificial intelligence systems according to the risk they pose to health, safety and fundamental rights. Unlike the GDPR, which protects personal data, the AI Act regulates the AI systems themselves: their design, their placing on the market and their use. It came into force on 1 August 2024 and rolls out its obligations in phases until 2028.

The regulation applies regardless of where the company is established. If an AI system is placed on the market or used within the European Union, it is subject to the regulation. This includes providers outside the EU whose systems are used in European territory.

The three roles defined by the regulation

The AI Act assigns different obligations according to each company’s role in the system’s life cycle. The same organisation can play several roles at once.

  • Provider: develops an AI system or places it on the market under its own brand. It carries the heaviest obligations, especially for high risk.
  • Deployer: uses an AI system in its professional activity. Most SMEs that use ChatGPT, chatbots or scoring tools fall here.
  • Importer and distributor: brings into or makes available in the EU AI systems developed outside Europe.

If your company uses a customer service chatbot, a CV screening system or any AI-based tool, you are a deployer and the AI Act applies to you. You do not need to develop the technology to be subject to the regulation.

The Spanish law that was to complement the regulation

In Spain the main layer is the European AI Act, which applies directly. The second was to be the Organic Law bill on the proper use and governance of artificial intelligence. The Council of Ministers approved it on 26 May 2026, the Spanish Congress published it on 12 June and the Economic and Social Council endorsed it in its Opinion 3/2026. It lapsed when the Spanish Parliament was dissolved, as published in the Official State Gazette (BOE) on 6 October 2026. The government formed after the elections of 29 November will have to approve it again and submit it to the new chambers.

That bill regulated what the European regulation leaves to each Member State: the penalty regime, the allocation of powers among authorities and internal governance. It also introduced a new digital right, allowing the competent authority to provisionally withdraw from the market an AI system that has caused a serious incident. Until there is a law, the AI Act applies all the same, but Spain still has no penalty regime of its own.

The four risk levels of the AI Act

The AI Act classifies AI systems into four risk levels, with obligations that increase with the potential impact on people and their rights. The higher the risk, the stricter the requirements. This risk pyramid is the axis around which the whole regulation turns.

Risk levelWhat it includesMain obligation
Unacceptable (prohibited)Social scoring, subliminal manipulation, sensitive biometric categorisationTotal ban
HighRecruitment, credit scoring, education, critical infrastructureStrict and documented compliance
LimitedChatbots, deepfakes, emotion recognitionTransparency towards users
MinimalSpam filters, recommender systems, productivity toolsVoluntary good practice

Unacceptable risk: prohibited practices

Unacceptable-risk systems have been banned in the European Union since 2 February 2025. They are uses the legislator considers incompatible with fundamental rights. They include social scoring by authorities, subliminal manipulation that causes harm, exploitation of vulnerabilities due to age or disability, and biometric categorisation based on sensitive data such as race or political opinions. Real-time remote biometric identification in publicly accessible spaces is banned, save for listed security exceptions. The full list, with the two prohibitions added by the Digital Omnibus, is in our guide to AI Act prohibited practices.

High risk: the bulk of the obligations

High-risk systems are those that can significantly affect people’s safety or rights, and they carry the most demanding obligations in the regulation. Following Regulation (EU) 2026/1744, those obligations apply from 2 December 2027 to Annex III uses and from 2 August 2028 to systems built into Annex I products. They include AI for recruitment, credit scoring, educational assessment systems, critical infrastructure management and access to essential public services.

A provider of a high-risk system must implement a documented risk management system, ensure the governance of training data, draw up complete technical documentation, log the system’s activity, ensure effective human oversight and maintain appropriate levels of accuracy, robustness and cybersecurity. How to tell whether your system is high-risk, and when the Article 6(3) exception applies, is explained in our guide to high-risk AI systems.

Limited risk: the transparency obligation

Limited-risk systems must tell users that they are interacting with artificial intelligence. Most business uses of generative AI fall into this category. A chatbot must identify itself as AI. Artificially generated content, such as deepfakes, must be labelled as such. Emotion recognition systems must inform the people affected.

These obligations have been enforceable since 2 August 2026 and the Digital Omnibus did not postpone them. The exact split between provider and deployer is set out in our guide to AI transparency obligations for businesses.

Minimal risk: the vast majority of systems

Minimal-risk systems have no specific obligations under the AI Act, although the regulation encourages voluntary codes of conduct. This is where spam filters, content recommender systems and most productivity tools sit. One point is often misunderstood: using a minimal-risk tool does not exempt you from the AI literacy obligation, which has applied to all deployers since February 2025.

What obligations your company has according to its role

Obligations under the AI Act depend on two variables: the company’s role (provider or deployer) and the system’s risk level. A deployer of a high-risk system does not carry the same burden as its provider, but it is not exempt either.

If your company…Key obligations
Uses chatbots or AI assistants with customersDisclose that it is AI, document internal use, supervise the content
Uses AI to recruit staffData protection impact assessment, human oversight, information to staff and candidates
Uses generative AI internallyUse policy, team training, control of confidential data, verification of output
Develops or markets its own AIAll provider obligations according to the system’s risk level

The AI literacy obligation deserves a separate mention: since 2 February 2025, providers and deployers must ensure that their staff have a sufficient level of knowledge of the AI systems they work with. An internal memo is not enough; it requires real training.

AI Act application timeline

The AI Act does not apply all at once, but in stages between 2025 and 2028. The regulation came into force on 1 August 2024, but its obligations are triggered in phases. Knowing the timeline makes it possible to prioritise what has to be done and when.

DateWhat applies
1 August 2024Entry into force of Regulation (EU) 2024/1689
2 February 2025Ban on unacceptable-risk practices and AI literacy obligation
2 August 2025Obligations for general-purpose AI models (GPAI) and application of the penalty regime
2 August 2026Transparency obligations in Article 50 and governance. Mandatory national sandbox
2 December 2026New prohibitions in Article 5 and marking of synthetic content already on the market
2 December 2027High-risk systems under Article 6(2) and Annex III
2 August 2028High-risk systems under Article 6(1) and Annex I

2 August 2026 is the critical date for most companies. On that day the transparency obligations for chatbots and AI-generated content stopped being theory. The requirements for high-risk systems were postponed by Regulation (EU) 2026/1744, the Digital Omnibus on AI. General-purpose models, such as the large language models on which generative AI is built, have been subject to obligations since August 2025.

Penalties for breaching the AI Act

The AI Act provides for three tiers of penalty according to the seriousness of the infringement, and they have applied since 2 August 2025. The amount is calculated as a fixed sum or as a percentage of total worldwide annual turnover, with the higher figure applying to large companies and the lower one to SMEs.

Type of infringementMaximum penalty
Using a prohibited AI system35 million euros or 7% of worldwide turnover
Breaching transparency or high-risk obligations15 million euros or 3% of worldwide turnover
Supplying incorrect information to the authorities7.5 million euros or 1% of worldwide turnover

For an SME, even the 1% tier can be a significant sum. The amount is not the only thing at stake: a penalty for using prohibited AI also means withdrawing the system and the reputational damage that comes with it. The tiers, the SME rule and who will impose penalties in Spain are covered in detail in AI Act penalties.

AESIA: the Spanish supervisory authority

AESIA is the Spanish Agency for the Supervision of Artificial Intelligence, created by Royal Decree 729/2023 and based in A Coruña. It is the national authority designated to supervise the AI Act in Spain and acts as the point of contact with the European AI Office. Its designation as market surveillance authority and the national penalty regime depend on an organic law that does not yet exist. The bill approved on 26 May 2026 lapsed when the Spanish Parliament was dissolved in October 2026.

Spain was one of the first EU countries to designate a national supervisory authority. The government even moved ahead of the European sandbox requirement: in December 2024 it launched a call to select up to twelve high-risk AI systems to take part for a year in a regulatory sandbox.

AESIA’s seat in A Coruña has a practical implication for companies that need to deal with the Agency. As a firm based in Santiago de Compostela, 70 kilometres away, we work in close proximity to the supervisory authority.

AI Act and GDPR: how they relate

The AI Act does not replace the GDPR: the two laws coexist and complement each other. The GDPR governs the processing of personal data; the AI Act governs AI systems. When an artificial intelligence system processes personal data, which is almost always, the company must comply with both laws at the same time. The same use can give rise to liability under both.

AspectGDPRAI Act
SubjectPersonal dataAI systems
ScopeAny processing of dataAI systems according to their risk
Impact assessmentDPIA for high-risk processingFundamental rights impact assessment
Control figureData Protection Officer (DPO)Human oversight of the system

The good news is that a company with sound GDPR compliance starts with an advantage: data governance, documentation and impact assessment processes can be reused. How the two laws fit together after the Omnibus is analysed in AI Act and GDPR.

AI in recruitment, what the GDPR already requires and what the AI Act will add

Using AI to screen CVs already carries obligations today, even though the AI Act’s high-risk requirements do not arrive until 2 December 2027. They come from the GDPR. The Spanish Data Protection Agency (AEPD) made this point on 23 September 2026. It published a warning to a company that was about to deploy a candidate screening tool (in Spanish). The AEPD requires an impact assessment if the processing is high-risk, clear information for candidates and staff, and real human involvement in the final decision.

The AI Act classifies these systems as high-risk in point 4(a) of Annex III. That point expressly mentions analysing and filtering job applications and evaluating candidates. From 2 December 2027, a company that uses them will add the obligations in Article 26 as a deployer. It will have to assign human oversight to people with the necessary competence, training and authority. It will also have to inform workers’ representatives and the affected staff before using the system, and the candidates it helps to decide on.

In Spain there is a third layer. Article 64.4(d) of the Workers’ Statute gives the works council its own right to information. It can find out the parameters, rules and instructions of the algorithms that affect access to employment.

One point is often confused. The fundamental rights impact assessment in Article 27 of the AI Act does not apply to every employer. It only applies to public bodies and private entities providing public services. Also to those using AI to assess creditworthiness or price life and health insurance. A private company that screens CVs does not need it.

Once hired, the worker also has a right of their own since 5 October 2026. They must receive in writing the rules of the algorithms that decide on their working conditions, as explained in our guide to algorithmic transparency for workers in Spain.

Generative AI, copyright and intellectual property

The AI Act requires providers of generative AI to document and publish a sufficiently detailed summary of the data used to train their models. This transparency obligation connects directly with copyright: if a model has been trained on protected works, questions arise about licences, authorship and liability that the regulation does not fully resolve. It is one of the most complex and least discussed points in the regulation. The obligations of those who build these models and those who integrate them are in our guide to general-purpose AI models.

For a company that uses generative AI, the risk is twofold. On the one hand, the generated content may incorporate elements protected by third parties’ copyright. On the other, ownership of what the AI produces is legally uncertain in many cases. This particularly affects creative sectors, marketing and content production.

Many technology companies do not know whether their AI systems are high-risk, nor what intellectual property implications they take on when using generative AI. That is the first thing we assess.

How to prepare your company for the AI Act

Adapting to the AI Act follows three steps: map all AI systems, classify them by risk level and close the compliance gaps. You cannot comply with what you have not identified, and most companies underestimate how many AI systems they actually use.

  1. Inventory. List all AI systems in use: internal, commercial and experimental tools, and third-party tools built into your processes.
  2. Risk classification. Determine which level each system falls into and under which legal framework, cross-checking the AI Act, the GDPR and sector rules.
  3. Closing the gaps. Put in place the missing technical and organisational measures: transparency, documentation, human oversight, training and an evidence system for audits.

An example shows why the initial diagnosis is decisive. A scaleup using an AI system to screen CVs usually assumes it is just a productivity tool. In fact, automated candidate screening is a high-risk use under Annex III. From 2 December 2027, as a deployer, it will have to assign human oversight to people with training and authority and inform staff and candidates. Many of those safeguards are already required today under the GDPR.

Does the AI Act apply to my company if I only use ChatGPT?

Yes. Using ChatGPT or another generative AI tool makes your company the deployer of an AI system, subject to the AI Act. Most of these uses are limited or minimal risk, with transparency and AI literacy obligations. You do not need to develop your own technology to be subject to the regulation.

The AI Act is a legal instrument with a penalty regime, not a technical guide. A consultant can help implement measures, but risk classification, the fundamental rights impact assessment and the interpretation of legal obligations require legal judgement. The interplay with the GDPR and with intellectual property makes it advisable to have legal advice focused on technology law.

From 2 August 2026, breaching the transparency obligations in Article 50 can be penalised with up to 15 million euros or 3% of worldwide turnover. Using prohibited systems, which has been punishable since August 2025, reaches 35 million or 7%. In addition to the fine, the authority can order the system to be withdrawn.

No. The AI Act and the GDPR are separate laws that apply simultaneously. The GDPR governs personal data; the AI Act governs AI systems. If your AI system processes personal data, you must comply with both laws at the same time and you may face penalties under both.

The supervisory authority in Spain is AESIA, the Spanish Agency for the Supervision of Artificial Intelligence, based in A Coruña. It was created by Royal Decree 729/2023 and is responsible for market supervision and coordination with the European AI Office. Its penalty regime depended on the Organic Law bill on the governance of artificial intelligence, which lapsed when the Spanish Parliament was dissolved in October 2026 and will have to be reintroduced in the next legislature.

Yes, but with safeguards from day one. The AI Act’s high-risk obligations for recruitment apply from 2 December 2027. Until then the GDPR applies. It already requires an impact assessment if there is high risk, clear information for candidates and real human involvement in the final decision. The AEPD made this point in September 2026 with a warning to a company that was about to deploy a tool of this kind. In Spain, the works council also has the right to know the algorithm’s parameters.

If your company uses artificial intelligence and needs to know which obligations apply and from when, Innovatech carries out an AI Act compliance diagnosis. See our AI Act legal service and book a free initial assessment.

Managing Partner at Innovatech Legal | Website | + posts

Marta Suárez-Mansilla is Managing Partner of Innovatech Legal and a Spanish lawyer (abogada), Madrid Bar (ICAM), working in technology law. She completed Harvard Law School's Copyright course and BerkeleyX's Blockchain programme, and has advised technology companies for more than eight years.