View all articles
AESIAEU AI ActComplianceSpainRegulation

AESIA: What Every Spanish Business Deploying AI Must Know in 2026

JG
Jacobo Gonzalez Jaspe
|

If your company uses AI in Spain (a SaaS tool with AI features, an automated CV screen, a customer chatbot), parts of the EU AI Act (Regulation 2024/1689) already apply to you, and AESIA is the authority that supervises them. By the end of this post you will have the correct dates, know which documents the agency can ask for, and hold an eight-step checklist you can start today with a spreadsheet.

What you need

  • One hour and a spreadsheet for the inventory.
  • Access to whoever buys software in your company, to learn which AI-enabled tools are actually in use.
  • The two reference texts: the Regulation on EUR-Lex and the AESIA portal.
  • Optional: an AI assistant to help classify systems; the prompt is below.

What AESIA is

AESIA, the Agencia Española de Supervisión de la Inteligencia Artificial, is Spain’s national supervisory authority under the EU AI Act. It was created by Royal Decree 729/2023, published in the BOE on 19 July 2023, before the Act itself entered into force in August 2024. It sits under the Ministry for Digital Transformation and the Civil Service and is headquartered in A Coruña.

Its mandate covers every AI system deployed or placed on the Spanish market, whether the company behind it is Spanish, German or American. If it runs in Spain, AESIA can inspect it. It publishes guidance, runs the regulatory sandbox and coordinates enforcement with the other EU authorities.

What AESIA can do

Supervise: request and review conformity assessments, technical documentation and risk-management records; commission or run tests of a system, including access to training data; monitor incidents reported in Spain; coordinate with other EU authorities.

Correct and sanction: issue corrective orders with a deadline; suspend the use of a non-compliant system; order market withdrawal; impose fines; refer serious cases to the public prosecutor.

Guide: publish guidance and interpretive notes, and operate a regulatory sandbox where AI products can be tested under supervision before launch.

When it asks for documentation, the usual window is 15 business days. Fines follow the Act’s three tiers:

InfractionMaximum fineTurnover cap
Prohibited practices (Art. 5): social scoring, subliminal manipulation, real-time biometric surveillanceEUR 35,000,0007% of global annual turnover
High-risk non-compliance: missing documentation, no conformity assessment, not registered in the EU databaseEUR 15,000,0003% of global annual turnover
Misleading information given to AESIA or a notified bodyEUR 7,500,0001.5% of global annual turnover

For SMEs the Act applies the lower of the two amounts (Article 99(6)) and requires proportionality: a good-faith first infringement normally ends in a corrective order, not a maximum fine. Treat this as a checklist you can complete, not a threat.

The real dates after the July 2026 Omnibus

The EU Digital Omnibus was published in the Official Journal on 24 July 2026 and entered into force on 27 July. It postponed the high-risk obligations and left the rest in place. Sources: Gibson Dunn and the Cloud Security Alliance.

ObligationApplies fromStatus in September 2026
Prohibited practices (Art. 5) and AI literacy for staff (Art. 4)2 February 2025In force
General-purpose AI models (GPAI)2 August 2025In force
Transparency (Art. 50): tell people they are talking to an AI, label generated or manipulated content2 August 2026, with a grace period to 2 December 2026 for systems already on the marketIn force
Annex III high-risk systems (HR, credit, education, biometrics, critical infrastructure…)2 December 2027Fifteen months of runway
Annex I high-risk systems (AI inside regulated products)2 August 2028Almost two years of runway

If you read anywhere that 2 August 2026 was the high-risk deadline, that text predates the Omnibus.

AESIA and the AEPD: you are almost certainly under both

They are separate regulators with overlapping jurisdiction whenever an AI system processes personal data, which is nearly always.

DimensionAESIAAEPD
Legal basisEU AI Act (Regulation 2024/1689)GDPR + LOPDGDD
FocusSystem safety, risk classification, human oversight, transparencyPersonal data processing, data-subject rights, privacy
Fines issued byAESIAAEPD

Both agencies have said that coordinated inspections will be the norm in AI matters, so compliance with one does not cover the other. The GDPR obligations that run alongside are in our GDPR and AI convergence guide.

The eight-step action plan

Already in force: do this month

  1. Build an AI inventory. List every system or tool with AI that you use, including the AI features inside your HR software, CRM, chatbots and content generators. Most companies have 10 to 30 and have never catalogued them. Columns: tool, vendor, what it is used for, what data it sees, who operates it.

  2. Check for prohibited practices. Confirm that no use falls under Article 5: social scoring, subliminal manipulation, emotion recognition at work (with narrow exceptions) or real-time biometric identification in public spaces without a legal basis. For an SME the answer is normally “none”, and that answer gets written down.

  3. Document AI literacy. If your staff use AI tools you are a “deployer”, and since 2 February 2025 you must make sure they understand the tools’ capabilities, limits and risks. A short course with a written completion record meets the minimum.

One recent obligation that goes with the inventory: if you run a public-facing chatbot or publish generated images, audio or text, since August 2026 you must tell people they are dealing with an AI and label the generated content (Article 50), with a grace period to December 2026 for what was already running.

Before 2 December 2027: only if you have high-risk systems

  1. Classify each system by risk level. For every inventory row, decide whether it falls under Annex III: employment and HR, credit and creditworthiness, education, law enforcement, biometric identification, critical infrastructure, migration and borders, justice and democratic processes. AESIA publishes classification guidance on its site. A useful prompt for your assistant: “Here is my inventory of AI-enabled tools. For each one, say whether it fits any Annex III category of Regulation (EU) 2024/1689, name the category and explain in one sentence why or why not.” Review the result; the assistant proposes, you decide.

  2. Build the compliance package for high-risk systems. A documented risk-management system, technical documentation per Annex IV, data-governance records, automatic event logging for traceability, human-oversight controls, accuracy and resilience test results, and a post-market monitoring plan.

  3. Register high-risk systems in the EU database. Before putting them into service, and in any case before the application date.

  4. Complete the conformity assessment. Self-assessment is enough for most of Annex III. Biometric systems and part of critical infrastructure need a notified body.

  5. Rehearse an inspection. Simulate AESIA’s request: can you hand over the risk-management records, the classification rationale and the human-oversight documentation within 15 business days? If yes, you are done.

What AESIA has published

As of this post, the AESIA portal carries guidance you can use directly:

DocumentKey content
AI Act implementation guide for operatorsStep-by-step obligations by risk category
Regulatory sandbox frameworkApplication process and eligibility for supervised testing
High-risk AI classification guidelinesPractical Annex III classification with sector examples
AI literacy training minimum standardsWhat counts as sufficient training
Joint AESIA-AEPD statementHow simultaneous AI Act and GDPR compliance works
SME fast-track compliance guidanceSimplified path for businesses under 250 employees

The primary language is Spanish; some material has English translations.

The local AI advantage

When AI runs in a third party’s cloud, your audit trail (data governance, logs, human oversight) depends on what that provider discloses. When it runs on hardware inside your premises, you control the logs, the data flow and the access, and when AESIA asks for documentation you produce it yourself, without waiting on anyone. That is why local deployments are simpler to audit, especially in HR, document processing and customer-facing workflows.

Next steps

Work with us

We include AESIA compliance in every deployment: AI inventory, Article 5 check, Annex III classification report traceable to AESIA guidance, Annex IV technical documentation, AI literacy training with records, and joint AESIA + AEPD coverage in one engagement. All the AI we deploy runs on local hardware, which shrinks the documentation you have to request from third parties. Pricing: an initial compliance scan at EUR 800 flat (inventory, risk classification, gap report); the full package is included in Edge AI deployments; an ongoing retainer at EUR 200 a month covers the annual review, AESIA guidance monitoring and incident support. Book a compliance consultation or see how we work in consulting.

Share: LinkedIn X
Newsletter

Access exclusive resources

Subscribe to unlock 230+ workflows, 43 agents, and 26 professional templates. Weekly insights, no spam.

Bonus: Free EU AI Act checklist when you subscribe
Once a week No spam Unsubscribe anytime
EU AI Act is now in effect — Is your organization compliant?

Tell us what you want to run

Tell us what you want to run and on what budget. We will tell you which hardware you need, which model fits, and what to expect from it — before you spend anything.

First call free, 15 min Local-first: your data stays on your network Open tools and guides

136 pages of free resources · 26 compliance templates