AESIA: What Every Spanish Business Deploying AI Must Know in 2026
If your company uses AI in Spain (a SaaS tool with AI features, an automated CV screen, a customer chatbot), parts of the EU AI Act (Regulation 2024/1689) already apply to you, and AESIA is the authority that supervises them. By the end of this post you will have the correct dates, know which documents the agency can ask for, and hold an eight-step checklist you can start today with a spreadsheet.
What you need
- One hour and a spreadsheet for the inventory.
- Access to whoever buys software in your company, to learn which AI-enabled tools are actually in use.
- The two reference texts: the Regulation on EUR-Lex and the AESIA portal.
- Optional: an AI assistant to help classify systems; the prompt is below.
What AESIA is
AESIA, the Agencia Española de Supervisión de la Inteligencia Artificial, is Spain’s national supervisory authority under the EU AI Act. It was created by Royal Decree 729/2023, published in the BOE on 19 July 2023, before the Act itself entered into force in August 2024. It sits under the Ministry for Digital Transformation and the Civil Service and is headquartered in A Coruña.
Its mandate covers every AI system deployed or placed on the Spanish market, whether the company behind it is Spanish, German or American. If it runs in Spain, AESIA can inspect it. It publishes guidance, runs the regulatory sandbox and coordinates enforcement with the other EU authorities.
What AESIA can do
Supervise: request and review conformity assessments, technical documentation and risk-management records; commission or run tests of a system, including access to training data; monitor incidents reported in Spain; coordinate with other EU authorities.
Correct and sanction: issue corrective orders with a deadline; suspend the use of a non-compliant system; order market withdrawal; impose fines; refer serious cases to the public prosecutor.
Guide: publish guidance and interpretive notes, and operate a regulatory sandbox where AI products can be tested under supervision before launch.
When it asks for documentation, the usual window is 15 business days. Fines follow the Act’s three tiers:
| Infraction | Maximum fine | Turnover cap |
|---|---|---|
| Prohibited practices (Art. 5): social scoring, subliminal manipulation, real-time biometric surveillance | EUR 35,000,000 | 7% of global annual turnover |
| High-risk non-compliance: missing documentation, no conformity assessment, not registered in the EU database | EUR 15,000,000 | 3% of global annual turnover |
| Misleading information given to AESIA or a notified body | EUR 7,500,000 | 1.5% of global annual turnover |
For SMEs the Act applies the lower of the two amounts (Article 99(6)) and requires proportionality: a good-faith first infringement normally ends in a corrective order, not a maximum fine. Treat this as a checklist you can complete, not a threat.
The real dates after the July 2026 Omnibus
The EU Digital Omnibus was published in the Official Journal on 24 July 2026 and entered into force on 27 July. It postponed the high-risk obligations and left the rest in place. Sources: Gibson Dunn and the Cloud Security Alliance.
| Obligation | Applies from | Status in September 2026 |
|---|---|---|
| Prohibited practices (Art. 5) and AI literacy for staff (Art. 4) | 2 February 2025 | In force |
| General-purpose AI models (GPAI) | 2 August 2025 | In force |
| Transparency (Art. 50): tell people they are talking to an AI, label generated or manipulated content | 2 August 2026, with a grace period to 2 December 2026 for systems already on the market | In force |
| Annex III high-risk systems (HR, credit, education, biometrics, critical infrastructure…) | 2 December 2027 | Fifteen months of runway |
| Annex I high-risk systems (AI inside regulated products) | 2 August 2028 | Almost two years of runway |
If you read anywhere that 2 August 2026 was the high-risk deadline, that text predates the Omnibus.
AESIA and the AEPD: you are almost certainly under both
They are separate regulators with overlapping jurisdiction whenever an AI system processes personal data, which is nearly always.
| Dimension | AESIA | AEPD |
|---|---|---|
| Legal basis | EU AI Act (Regulation 2024/1689) | GDPR + LOPDGDD |
| Focus | System safety, risk classification, human oversight, transparency | Personal data processing, data-subject rights, privacy |
| Fines issued by | AESIA | AEPD |
Both agencies have said that coordinated inspections will be the norm in AI matters, so compliance with one does not cover the other. The GDPR obligations that run alongside are in our GDPR and AI convergence guide.
The eight-step action plan
Already in force: do this month
-
Build an AI inventory. List every system or tool with AI that you use, including the AI features inside your HR software, CRM, chatbots and content generators. Most companies have 10 to 30 and have never catalogued them. Columns: tool, vendor, what it is used for, what data it sees, who operates it.
-
Check for prohibited practices. Confirm that no use falls under Article 5: social scoring, subliminal manipulation, emotion recognition at work (with narrow exceptions) or real-time biometric identification in public spaces without a legal basis. For an SME the answer is normally “none”, and that answer gets written down.
-
Document AI literacy. If your staff use AI tools you are a “deployer”, and since 2 February 2025 you must make sure they understand the tools’ capabilities, limits and risks. A short course with a written completion record meets the minimum.
One recent obligation that goes with the inventory: if you run a public-facing chatbot or publish generated images, audio or text, since August 2026 you must tell people they are dealing with an AI and label the generated content (Article 50), with a grace period to December 2026 for what was already running.
Before 2 December 2027: only if you have high-risk systems
-
Classify each system by risk level. For every inventory row, decide whether it falls under Annex III: employment and HR, credit and creditworthiness, education, law enforcement, biometric identification, critical infrastructure, migration and borders, justice and democratic processes. AESIA publishes classification guidance on its site. A useful prompt for your assistant: “Here is my inventory of AI-enabled tools. For each one, say whether it fits any Annex III category of Regulation (EU) 2024/1689, name the category and explain in one sentence why or why not.” Review the result; the assistant proposes, you decide.
-
Build the compliance package for high-risk systems. A documented risk-management system, technical documentation per Annex IV, data-governance records, automatic event logging for traceability, human-oversight controls, accuracy and resilience test results, and a post-market monitoring plan.
-
Register high-risk systems in the EU database. Before putting them into service, and in any case before the application date.
-
Complete the conformity assessment. Self-assessment is enough for most of Annex III. Biometric systems and part of critical infrastructure need a notified body.
-
Rehearse an inspection. Simulate AESIA’s request: can you hand over the risk-management records, the classification rationale and the human-oversight documentation within 15 business days? If yes, you are done.
What AESIA has published
As of this post, the AESIA portal carries guidance you can use directly:
| Document | Key content |
|---|---|
| AI Act implementation guide for operators | Step-by-step obligations by risk category |
| Regulatory sandbox framework | Application process and eligibility for supervised testing |
| High-risk AI classification guidelines | Practical Annex III classification with sector examples |
| AI literacy training minimum standards | What counts as sufficient training |
| Joint AESIA-AEPD statement | How simultaneous AI Act and GDPR compliance works |
| SME fast-track compliance guidance | Simplified path for businesses under 250 employees |
The primary language is Spanish; some material has English translations.
The local AI advantage
When AI runs in a third party’s cloud, your audit trail (data governance, logs, human oversight) depends on what that provider discloses. When it runs on hardware inside your premises, you control the logs, the data flow and the access, and when AESIA asks for documentation you produce it yourself, without waiting on anyone. That is why local deployments are simpler to audit, especially in HR, document processing and customer-facing workflows.
Next steps
- Phased plan to December 2027: EU AI Act after the Omnibus: what applies now.
- What the supervisor means day to day: AESIA: what Spain’s AI watchdog means for your business.
- Start with something minimal-risk: Your first three AI agents, deployed locally.
- Official text: Regulation (EU) 2024/1689 on EUR-Lex.
- Grab the template: Prohibited practices checklist (Article 5).
- Grab the template: Technical documentation template (Annex IV).
Work with us
We include AESIA compliance in every deployment: AI inventory, Article 5 check, Annex III classification report traceable to AESIA guidance, Annex IV technical documentation, AI literacy training with records, and joint AESIA + AEPD coverage in one engagement. All the AI we deploy runs on local hardware, which shrinks the documentation you have to request from third parties. Pricing: an initial compliance scan at EUR 800 flat (inventory, risk classification, gap report); the full package is included in Edge AI deployments; an ongoing retainer at EUR 200 a month covers the annual review, AESIA guidance monitoring and incident support. Book a compliance consultation or see how we work in consulting.