GLACIS·EU AI Act series·ES Spain·EU timeline checked August 2026

The EU AI Act in Spain: AESIA, sandbox, and the current high-risk dates.

Spain stood up an early national AI authority and regulatory sandbox. This page gives General Counsel, CCO, CISO, and DPO teams a working view, updated for the AI Omnibus now in force and the current high-risk dates for 2027 and 2028.

Talk to us Read the full EU AI Act guide →
General Counsel CCO CISO DPO
Feb 2025
EU prohibited-practice and AI-literacy provisions apply
Aug 2025
GPAI obligations apply; EU-level enforcement timetable begins
Dec 2025
AESIA publishes 16 detailed compliance guides
Dec 2027
Relevant Annex III high-risk obligations
What changed by August 2026

AESIA released a compliance pack on 16 December 2025 covering risk management, technical documentation, sandbox practice, and conformity assessment. Treat those materials as guidance alongside the binding EU text.

After a provisional agreement in May 2026, the AI Omnibus was adopted as Regulation (EU) 2026/1744 and entered into force on 27 July 2026. Relevant Annex III high-risk obligations apply from 2 December 2027 and relevant Annex I product-embedded obligations from 2 August 2028.

Spain’s proposed Organic Law for the Proper Use and Governance of Artificial Intelligence entered the Congress of Deputies on 28 May 2026. As of 26 August 2026 it remains a bill in the Committee on Economy, Trade and Digital Transformation, at the amendments stage; the current amendment deadline is 2 September 2026. Its proposed duties and penalties are not yet enacted.

Executive summary

AESIA (the Agencia Española de Supervisión de la Inteligencia Artificial) has operated since June 2024. Its statute assigns supervision, advice, awareness, training, and the inspection or sanction functions conferred by applicable law, while preserving sectoral competences.[1]

The proposed Organic Law would further allocate Spanish AI Act governance and penalty machinery. It remains a bill, so its proposed content-labeling, authority, and penalty provisions should not be presented as enacted duties.[2][3]

The practical compliance position after the Omnibus: classify each system, map it to the applicable 2 December 2027 or 2 August 2028 high-risk date, and use AESIA materials where relevant without treating them as a substitute for the Regulation. Other provisions retain their own dates.

Spain’s implementation status

Spain established AESIA before most national AI Act implementation structures were settled. AESIA has operated from A Coruña since June 2024. Its current statute defines broad supervisory functions; the proposed Organic Law that would allocate further national AI Act roles remains before Congress.[1][2]

Legislative framework

Three legal instruments anchor AI governance in Spain:

InstrumentWhat it does
Royal Decree 729/2023Establishes AESIA’s statute as Spain’s national competent authority for AI supervision. Approved November 2023.[1]
Royal Decree 817/2023Creates the EU’s first AI regulatory sandbox; in force since 10 November 2023.[4][10]
Proposed Organic LawLey Orgánica para el Buen Uso y la Gobernanza de la Inteligencia Artificial. Introduced in Congress 28 May 2026; at the committee-amendments stage as of 26 August 2026. Proposed national duties and penalties are not in force.[2][7][8]

The proposed national law is in Parliament, not enacted. Its content-labeling and penalty provisions remain proposals and should not be described as current Spanish obligations.

Implementation progress compared to other member states

Spain’s national implementation sits alongside the EU-level calendar. The AI Omnibus is now in force; the picture below uses its enacted high-risk dates.[12]

Member stateCompetent authorityRegulatory sandboxNational AI law
SpainAESIA operational since June 2024; role allocation remains subject to applicable law and the pending Organic LawEstablished under Royal Decree 817/2023Bill at committee-amendments stage; not enacted as of 26 August 2026
GermanyBundestag-adopted KI-MIG assigns BNetzA and KoKIVO roles; verify promulgation and current noticesConfirm the live BNetzA routeAdopted by Bundestag 11 June 2026; entry into force not independently established here
FranceDecentralised: CNIL, ANSSI, PEReN; multi-authority bill pendingIn developmentPending
ItalyAgID (notifying), ACN (market surveillance), Garante (GDPR)PlannedLaw 132/2025 in force from 10 Oct 2025

AESIA, the national competent authority

The Agencia Española de Supervisión de la Inteligencia Artificial (AESIA) is Spain’s dedicated AI supervisory agency. Headquartered in A Coruña, it has been operational since June 2024.[1][6]

AESIA’s mandate and powers

RoleDetail
Supervisory functionsRoyal Decree 729/2023 assigns supervision, advice, awareness, training, and the inspection or sanction functions conferred by applicable law, while preserving named sectoral competences.[1]
Sandbox managementOperates the regulatory sandbox under Royal Decree 817/2023. Selects participants, supervises tests, publishes synthesised guidance.[4]
Guidance publisherReleased 16 detailed compliance guides on 16 December 2025 covering risk management, technical documentation, conformity assessment and sandbox operation. AESIA flags these as living documents.[5]
National implementationThe proposed Organic Law would specify additional governance, authority, and penalty machinery. It remained at the committee-amendments stage on 26 August 2026 and is not an enacted source of duties.[2]

Proposed and sector-specific allocation

AESIA’s statute preserves existing sectoral competences, and the pending Organic Law proposes a wider allocation of AI Act roles. Treat the following as a working map to verify against the enacted rule and the system’s sector:

AuthorityDomain
AESIACentral role under its current statute; the pending Organic Law proposes additional market-surveillance and single-point-of-contact allocations that are not yet enacted
AEPDAI systems processing personal data; GDPR / LOPDGDD intersection
CNMCCompetition and market aspects of AI systems
Central Electoral CommissionAI systems affecting democratic processes
AEMPSAI medical devices and in-vitro diagnostics

Implementation timeline and Omnibus framing

Spanish organizations must track EU-level deadlines and Spain-specific milestones together. Regulation (EU) 2026/1744 is now in force and sets the current Annex III and Annex I product-embedded high-risk dates.[12]

DateMilestoneNotes for Spain
Jun 2024AESIA operationalDedicated Spanish AI supervisory agency operating under its statute.
Feb 2025Prohibited practices applyThe EU-level prohibitions and AI-literacy provisions began applying.
Aug 2025GPAI obligations applyThe Commission maintains a live GPAI Code signatory register; current status should be checked at the time of diligence.
Dec 202516 AESIA guides publishedLiving documents covering risk management, technical documentation and conformity assessment.[5]
Jul 2026AI Omnibus enters into forceRegulation (EU) 2026/1744 applies from 27 July.
Dec 2027Annex III high-risk obligationsRelevant duties apply from 2 December.
Aug 2028Annex I product-embedded high-risk obligationsRelevant duties apply from 2 August.
Working baseline

The AI Omnibus is in force. Build conformity, technical documentation, and Article 12 logging against the date applicable to the system: 2 December 2027 for relevant Annex III duties or 2 August 2028 for relevant Annex I product-embedded duties. Other provisions retain their own dates.

The AI regulatory sandbox

Spain ran the EU’s first AI regulatory sandbox under Royal Decree 817/2023, in force since 10 November 2023. It is a controlled environment where high-risk AI systems can be tested under AESIA supervision before full market deployment.[4][10]

What the sandbox provides

For participantsFor the wider ecosystem
Direct AESIA guidance during developmentPublic best-practice reports synthesised from sandbox findings
Structured pre-market testing and regulatory feedbackPractical lessons that may inform AESIA guidance; participation is not a conformity decision or product approval
Reduced regulatory uncertainty for high-risk systemsInputs into national policy and other member states’ approaches
Input into emerging best-practice guidanceEU-wide learnings (the sandbox is open to participants from other member states)

Current cohort

Twelve projects were selected in April 2025 across healthcare diagnostics, financial-services risk assessment and employment-related AI. The sandbox runs for 36 months from November 2023 or until the EU AI Act becomes fully applicable in Spain, whichever is first. Future cohort calls will be announced by AESIA.[4]

Build the evidence trail

GLACIS can create signed operational records for selected events and control decisions. These records may support integrity and traceability alongside AESIA materials and the binding Regulation, but do not establish complete coverage, control effectiveness or compliance.

Talk to us

High-risk categories for the Spanish market

Annex III applies uniformly across member states, but Spanish economic structure shifts which categories matter most in practice. AESIA’s December 2025 guides walk through each category with Spain-specific examples drawn from sandbox cohort findings.[5]

SectorTypical high-risk applications
Tourism and hospitalityBiometric identification at hotels (Annex III §1); dynamic pricing affecting accommodation access (essential-services scrutiny); chatbots and virtual concierges (Article 50 transparency).
Financial servicesCreditworthiness assessment (Annex III §5(a)); insurance pricing and underwriting (§5(b)); fraud-detection systems where they gate consumer access. Major Spanish institutions in scope include Santander, BBVA and CaixaBank.
HealthcareClinical decision support, medical imaging, and emergency triage require system-specific classification. AESIA and AEMPS may share oversight; relevant Annex I product-embedded high-risk duties apply from 2 August 2028.
Public administrationBenefits eligibility (social security, unemployment, housing); permit and license processing; service-allocation systems. Spain’s “Law 40/2015” requirements layer onto Annex III.
EmploymentRecruitment and CV screening (§4(a)); performance monitoring for platform and gig workers; biometric attendance. The draft national AI law adds specific penalties when biometric attendance lacks proper human oversight.[2]

Article 12 logging requirements

Article 12 requires high-risk AI systems to support automatic event logging over their lifetime at a level appropriate to intended purpose. AESIA materials can inform implementation in Spain, but the binding baseline is the Regulation.

Core logging requirements

LayerWhat must be captured
General ruleEvents relevant to traceability, risk identification and post-market monitoring, selected at a level appropriate to intended purpose.
Remote biometric identificationArticle 12(3) adds specific minimum fields for covered systems: period of use; reference database checked; input data leading to a match; and identity of natural persons involved in verification.
Integrity and retentionThe Regulation does not generally prescribe cryptography or tamper-evident storage. Apply proportionate access and integrity controls and determine retention from applicable provider, deployer, GDPR/LOPDGDD and sector rules.

Spain-specific considerations

Article 12 logging in Spain must align with the LOPDGDD (Spain’s GDPR implementation):

  • Data minimization: where GDPR applies, assess necessity, purpose, retention, access, and whether protected content can be omitted or represented by bounded commitments. Hashing does not by itself anonymise personal data.
  • AEPD coordination: where logs include personal data, establish the applicable GDPR basis and duties and check current AEPD and AESIA guidance for the issues within each authority’s remit.
  • Cross-border transfers: if logs are stored outside Spain or the EU, apply Standard Contractual Clauses or an adequacy mechanism. AESIA’s December 2025 template explicitly references this.

Sector-specific considerations

SectorWhat Spanish operators need to align
HealthcareDetermine whether the AI is a medical device under MDR or IVDR. Coordinate any required conformity assessment between AEMPS/notified-body and AI Act pathways. Relevant Annex I product-embedded high-risk duties apply from 2 August 2028.
Financial servicesLayer AI Act high-risk obligations onto Bank of Spain and CNMV supervision. Track EBA guidelines on machine learning in credit institutions. Apply consumer-protection rules under Spanish banking law and the algorithmic-transparency obligations for automated decisions affecting consumers.
Public sectorLayer Law 40/2015 requirements for automated administrative decisions; access-to-information transparency obligations; fundamental-rights impact assessments where AI affects citizens; and public-procurement considerations for AI acquisition.

Conformity assessment pathway

Spanish organizations with covered high-risk systems must complete the applicable conformity assessment before placing a system on the market or putting it into service once the relevant duties apply. The current high-risk date is 2 December 2027 for relevant Annex III duties or 2 August 2028 for relevant Annex I product-embedded duties. Check current AESIA guidance against the binding EU text.[5]

Assessment pathways

PathwayDetail
Internal control (most high-risk systems)Provider self-assessment supported by: technical documentation per Annex IV; quality management system (Article 17); post-market monitoring plan; EU declaration of conformity; CE marking affixation. Cost is internal resourcing.
Conditional notified-body involvementFor Annex III point 1 biometric systems, Article 43(1) permits internal control or notified-body assessment when applicable standards are fully used, and requires the Annex VII route in the conditions listed there. Annex I products follow their sector legislation’s conformity route. Timing and fees depend on the system, route, and eligible body.

Spanish notified bodies

Operators whose pathway requires third-party assessment should check current AESIA or notifying-authority material and the EU’s official notified-body listings for the relevant system scope. This page does not imply that a body designated under another product regime is automatically eligible for the AI system at issue.

Enforcement and penalties

The proposed Organic Law sets out a domestic governance and penalty regime, but it is not enacted. The EU AI Act’s directly applicable provisions and penalty framework should be assessed separately from the bill’s proposed national machinery.[2][3]

Penalty structure

ViolationMaximum fineExamples
Prohibited AI practices€35,000,000 or 7% turnoverSocial scoring, manipulative AI, untargeted biometric scraping
Serious offences€7.5M–€35M or 2–7% turnoverFailure to label AI-generated content; high-risk non-compliance
Biometric system violations€500K–€7.5M or 1–2% turnoverEmployee attendance monitoring without proper human oversight
Other violations€7.5M or 1% turnoverProviding incorrect information to authorities

Additional enforcement measures

Beyond fines, the draft national law authorizes:

  • System-adaptation orders requiring mandatory modifications to achieve compliance.
  • Commercialisation prohibition barring market placement of non-compliant systems.
  • Public warnings with reputational impact through official announcements.
  • System destruction in extreme cases involving serious harm.
  • Temporary operation prohibition: government authority to halt any AI system causing death or serious harm.

AESIA’s enforcement approach

Do not assume a fixed warning-before-fine sequence or a guaranteed benefit for “good-faith” effort. The applicable EU provision, the final Spanish law, sector authority, facts, and current AESIA practice determine the enforcement route. Preserve documentation, respond to lawful requests, and verify current official guidance.[2][5]

Compliance roadmap for Spanish organizations

The roadmap below should be scheduled against 2 December 2027 for relevant Annex III duties or 2 August 2028 for relevant Annex I product-embedded duties. The correct date depends on classification and product-law pathway.

PhaseDetail
01. AI system inventory and AESIA alignmentCatalogue relevant AI systems within the organization’s scope. Screen for Article 5 prohibitions, Article 6/Annex I and Annex III high-risk conditions, Article 50 transparency duties, GPAI roles, and exclusions. Review the current AESIA materials without treating them as a substitute for the Regulation.
02. Content-labeling implementationImplement disclosure mechanisms for synthetic media, chatbots and AI-assisted communications. Track the draft national AI law’s progress in Parliament; the deepfake-labeling regime carries €7.5M–€35M ceilings if enacted.
03. Article 12 logging infrastructureImplement automatic event logging around intended purpose and the applicable Article 12 events. Align with LOPDGDD / GDPR. Apply proportionate access and integrity controls, document the retention basis, and prepare for lawful information requests.
04. Risk management and technical documentationStand up Article 9 risk management. Prepare Annex IV technical documentation using AESIA’s templates. Run bias assessments in the Spanish market context. Preserve scoped operational records alongside policy and testing evidence without treating any one artifact as proof of effectiveness or compliance.
05. Quality management and conformityStand up the applicable Article 17 QMS. For notified-body pathways, confirm current capacity and work backward from 2 December 2027 for relevant Annex III duties or 2 August 2028 for relevant Annex I product-embedded duties. Coordinate with AEMPS, Bank of Spain or CNMV where applicable.
06. AESIA readiness and post-market monitoring (Ongoing)Prepare for AESIA information requests and inspections. Stand up Article 73 serious-incident reporting. Maintain living documentation; consider sandbox participation for future high-risk systems.
Spain-specific insight

Documentation and technical evidence can support a response to an authority, but this page does not establish how AESIA will weigh intent, evidence maturity, or remediation in a particular matter. Match each artifact to the legal requirement and its actual claim boundary.

How GLACIS supports Article 12

Article 12 requires system-specific logging capabilities, not a universal proof that every control executed. GLACIS can add signed operational records for selected policy, control and action events; those records support integrity and traceability but do not establish completeness, effectiveness or compliance.

NeedWhat GLACIS produces
Selected control eventsTimestamped records for configured input validation, output filtering and human-oversight events; coverage depends on the integration and event selection.
Signed recordsCryptographically signed entries whose included fields can be independently verified. Article 12 does not set a cryptographic or tamper-evidence bar.
Framework mappingEvidence fields can be mapped to selected EU AI Act, ISO 42001 and NIST AI RMF concepts to support review; mappings are not a conformity assessment.

FAQ

How does enforcement in Spain differ from other member states?

AESIA has operated since June 2024. Spain’s proposed Organic Law would define additional national governance, supervision, and penalty machinery, but remains at the committee-amendments stage as of 26 August 2026. Confirm the applicable EU provision and current national authority before describing an enforcement route.

Should I participate in the regulatory sandbox?

A regulatory sandbox may provide a structured setting for engagement, but participation does not validate compliance or guarantee an enforcement outcome. Check the current official call, eligibility, authority, timetable, and published outputs before relying on it.

How do I coordinate AESIA with sector regulators?

AESIA has a central role while sector regulators retain domain oversight. Check current AESIA guidance, then layer sector-specific obligations: AEMPS for medical-device pathways, Bank of Spain or CNMV for financial services, and AEPD for personal-data aspects. For covered Annex I product-embedded systems, relevant high-risk duties apply from 2 August 2028.

What makes Spain’s content-labeling rules different?

The draft national law treats unlabelled AI-generated content as a “serious offence” with €7.5M–€35M ceilings that go beyond the EU AI Act’s Article 50 baseline. Operators generating or manipulating content with AI should implement unambiguous disclosure mechanisms now; the deepfake-labeling regime survives in the latest draft text but isn’t yet in force.

How do I access AESIA’s guidance pack?

AESIA published compliance materials on 16 December 2025 covering risk management, technical documentation, sandbox practice, and conformity assessment. Materials are available on the official AESIA site at aesia.digital.gob.es. Check the current version before relying on a template.

Are there SME-specific provisions in the draft AI law?

The current draft includes proportionality language for SMEs, but the proposal is not yet in force and may change. Check the enacted text before relying on a penalty calculation; this page does not establish that AESIA gives smaller organizations a specific enforcement benefit.

References

  1. AESIA. “AESIA Consolidates Its Role in Europe in Promoting Ethical, Sustainable and Reliable AI.” August 2025. aesia.digital.gob.es
  2. Congress of Deputies. “Proyecto de Ley Orgánica para el buen uso y la gobernanza de la inteligencia artificial” (121/000096). Current procedure page, accessed 26 August 2026. congreso.es
  3. Covington & Burling LLP. “Spain Issues Guidance Under the EU AI Act.” Inside Privacy, December 2025. insideprivacy.com
  4. European Commission. “First Regulatory Sandbox on Artificial Intelligence Presented.” June 2022. ec.europa.eu
  5. AESIA. “Guidelines Published to Support Compliance with the AI Act.” 16 December 2025. aesia.digital.gob.es
  6. Holistic AI. “Spain Becomes First EU Member to Establish AI Regulatory Body.” August 2024. holisticai.com
  7. Linklaters. “Spain Proposes a New AI Bill, Including Significant Fines.” March 2025. linklaters.com
  8. Euronews. “Spain Could Fine AI Companies Up to 35 Million for Mislabelling Content.” March 2025. euronews.com
  9. OECD. “Progress in Implementing the EU Coordinated Plan on AI — Spain.” October 2025. oecd.org
  10. Pinsent Masons. “Spain Legislates for First EU AI Act Regulatory Sandbox.” November 2023. pinsentmasons.com
  11. European Union. “Regulation (EU) 2024/1689 of the European Parliament and of the Council.” OJEU, 12 July 2024. EUR-Lex
  12. European Commission. “AI Omnibus enters into force.” 27 July 2026. digital-strategy.ec.europa.eu
  13. EU Artificial Intelligence Act. “Overview of All AI Act National Implementation Plans.” Updated 2026. artificialintelligenceact.eu

Make supervision reviewable

EU AI Act evidence from runtime coverage on your highest-risk workflow.

Glacis can preserve signed, scoped records from configured control paths and map fields to selected requirements and AESIA materials. Those artifacts do not prove correct execution or compliance. The AI Omnibus is in force; use the enacted date applicable to the system.

Talk to us

Related guides

Full EU AI Act guideRisk categories, Articles 9–15 in detail, GPAI obligations, conformity assessment paths, Omnibus status.
EU AI Act in GermanyBundestag-adopted KI-MIG, proposed BNetzA and KoKIVO roles, BaFin overlay, and current-status caveat.
EU AI Act in ItalyLaw 132/2025 in force; AgID / ACN / Garante triangle; October 2026 implementing decrees.
ISO 42001 guideAI management system standard; mapping to EU AI Act articles.
AI governance toolsMarket analysis and vendor comparison.