Spain’s implementation status
Spain established AESIA before most national AI Act implementation structures were settled. AESIA has operated from A Coruña since June 2024. Its current statute defines broad supervisory functions; the proposed Organic Law that would allocate further national AI Act roles remains before Congress.[1][2]
Legislative framework
Three legal instruments anchor AI governance in Spain:
| Instrument | What it does |
|---|---|
| Royal Decree 729/2023 | Establishes AESIA’s statute as Spain’s national competent authority for AI supervision. Approved November 2023.[1] |
| Royal Decree 817/2023 | Creates the EU’s first AI regulatory sandbox; in force since 10 November 2023.[4][10] |
| Proposed Organic Law | Ley Orgánica para el Buen Uso y la Gobernanza de la Inteligencia Artificial. Introduced in Congress 28 May 2026; at the committee-amendments stage as of 26 August 2026. Proposed national duties and penalties are not in force.[2][7][8] |
The proposed national law is in Parliament, not enacted. Its content-labeling and penalty provisions remain proposals and should not be described as current Spanish obligations.
Implementation progress compared to other member states
Spain’s national implementation sits alongside the EU-level calendar. The AI Omnibus is now in force; the picture below uses its enacted high-risk dates.[12]
| Member state | Competent authority | Regulatory sandbox | National AI law |
|---|---|---|---|
| Spain | AESIA operational since June 2024; role allocation remains subject to applicable law and the pending Organic Law | Established under Royal Decree 817/2023 | Bill at committee-amendments stage; not enacted as of 26 August 2026 |
| Germany | Bundestag-adopted KI-MIG assigns BNetzA and KoKIVO roles; verify promulgation and current notices | Confirm the live BNetzA route | Adopted by Bundestag 11 June 2026; entry into force not independently established here |
| France | Decentralised: CNIL, ANSSI, PEReN; multi-authority bill pending | In development | Pending |
| Italy | AgID (notifying), ACN (market surveillance), Garante (GDPR) | Planned | Law 132/2025 in force from 10 Oct 2025 |
AESIA, the national competent authority
The Agencia Española de Supervisión de la Inteligencia Artificial (AESIA) is Spain’s dedicated AI supervisory agency. Headquartered in A Coruña, it has been operational since June 2024.[1][6]
AESIA’s mandate and powers
| Role | Detail |
|---|---|
| Supervisory functions | Royal Decree 729/2023 assigns supervision, advice, awareness, training, and the inspection or sanction functions conferred by applicable law, while preserving named sectoral competences.[1] |
| Sandbox management | Operates the regulatory sandbox under Royal Decree 817/2023. Selects participants, supervises tests, publishes synthesised guidance.[4] |
| Guidance publisher | Released 16 detailed compliance guides on 16 December 2025 covering risk management, technical documentation, conformity assessment and sandbox operation. AESIA flags these as living documents.[5] |
| National implementation | The proposed Organic Law would specify additional governance, authority, and penalty machinery. It remained at the committee-amendments stage on 26 August 2026 and is not an enacted source of duties.[2] |
Proposed and sector-specific allocation
AESIA’s statute preserves existing sectoral competences, and the pending Organic Law proposes a wider allocation of AI Act roles. Treat the following as a working map to verify against the enacted rule and the system’s sector:
| Authority | Domain |
|---|---|
| AESIA | Central role under its current statute; the pending Organic Law proposes additional market-surveillance and single-point-of-contact allocations that are not yet enacted |
| AEPD | AI systems processing personal data; GDPR / LOPDGDD intersection |
| CNMC | Competition and market aspects of AI systems |
| Central Electoral Commission | AI systems affecting democratic processes |
| AEMPS | AI medical devices and in-vitro diagnostics |
Implementation timeline and Omnibus framing
Spanish organizations must track EU-level deadlines and Spain-specific milestones together. Regulation (EU) 2026/1744 is now in force and sets the current Annex III and Annex I product-embedded high-risk dates.[12]
| Date | Milestone | Notes for Spain |
|---|---|---|
| Jun 2024 | AESIA operational | Dedicated Spanish AI supervisory agency operating under its statute. |
| Feb 2025 | Prohibited practices apply | The EU-level prohibitions and AI-literacy provisions began applying. |
| Aug 2025 | GPAI obligations apply | The Commission maintains a live GPAI Code signatory register; current status should be checked at the time of diligence. |
| Dec 2025 | 16 AESIA guides published | Living documents covering risk management, technical documentation and conformity assessment.[5] |
| Jul 2026 | AI Omnibus enters into force | Regulation (EU) 2026/1744 applies from 27 July. |
| Dec 2027 | Annex III high-risk obligations | Relevant duties apply from 2 December. |
| Aug 2028 | Annex I product-embedded high-risk obligations | Relevant duties apply from 2 August. |
The AI Omnibus is in force. Build conformity, technical documentation, and Article 12 logging against the date applicable to the system: 2 December 2027 for relevant Annex III duties or 2 August 2028 for relevant Annex I product-embedded duties. Other provisions retain their own dates.
The AI regulatory sandbox
Spain ran the EU’s first AI regulatory sandbox under Royal Decree 817/2023, in force since 10 November 2023. It is a controlled environment where high-risk AI systems can be tested under AESIA supervision before full market deployment.[4][10]
What the sandbox provides
| For participants | For the wider ecosystem |
|---|---|
| Direct AESIA guidance during development | Public best-practice reports synthesised from sandbox findings |
| Structured pre-market testing and regulatory feedback | Practical lessons that may inform AESIA guidance; participation is not a conformity decision or product approval |
| Reduced regulatory uncertainty for high-risk systems | Inputs into national policy and other member states’ approaches |
| Input into emerging best-practice guidance | EU-wide learnings (the sandbox is open to participants from other member states) |
Current cohort
Twelve projects were selected in April 2025 across healthcare diagnostics, financial-services risk assessment and employment-related AI. The sandbox runs for 36 months from November 2023 or until the EU AI Act becomes fully applicable in Spain, whichever is first. Future cohort calls will be announced by AESIA.[4]
GLACIS can create signed operational records for selected events and control decisions. These records may support integrity and traceability alongside AESIA materials and the binding Regulation, but do not establish complete coverage, control effectiveness or compliance.
High-risk categories for the Spanish market
Annex III applies uniformly across member states, but Spanish economic structure shifts which categories matter most in practice. AESIA’s December 2025 guides walk through each category with Spain-specific examples drawn from sandbox cohort findings.[5]
| Sector | Typical high-risk applications |
|---|---|
| Tourism and hospitality | Biometric identification at hotels (Annex III §1); dynamic pricing affecting accommodation access (essential-services scrutiny); chatbots and virtual concierges (Article 50 transparency). |
| Financial services | Creditworthiness assessment (Annex III §5(a)); insurance pricing and underwriting (§5(b)); fraud-detection systems where they gate consumer access. Major Spanish institutions in scope include Santander, BBVA and CaixaBank. |
| Healthcare | Clinical decision support, medical imaging, and emergency triage require system-specific classification. AESIA and AEMPS may share oversight; relevant Annex I product-embedded high-risk duties apply from 2 August 2028. |
| Public administration | Benefits eligibility (social security, unemployment, housing); permit and license processing; service-allocation systems. Spain’s “Law 40/2015” requirements layer onto Annex III. |
| Employment | Recruitment and CV screening (§4(a)); performance monitoring for platform and gig workers; biometric attendance. The draft national AI law adds specific penalties when biometric attendance lacks proper human oversight.[2] |
Article 12 logging requirements
Article 12 requires high-risk AI systems to support automatic event logging over their lifetime at a level appropriate to intended purpose. AESIA materials can inform implementation in Spain, but the binding baseline is the Regulation.
Core logging requirements
| Layer | What must be captured |
|---|---|
| General rule | Events relevant to traceability, risk identification and post-market monitoring, selected at a level appropriate to intended purpose. |
| Remote biometric identification | Article 12(3) adds specific minimum fields for covered systems: period of use; reference database checked; input data leading to a match; and identity of natural persons involved in verification. |
| Integrity and retention | The Regulation does not generally prescribe cryptography or tamper-evident storage. Apply proportionate access and integrity controls and determine retention from applicable provider, deployer, GDPR/LOPDGDD and sector rules. |
Spain-specific considerations
Article 12 logging in Spain must align with the LOPDGDD (Spain’s GDPR implementation):
- Data minimization: where GDPR applies, assess necessity, purpose, retention, access, and whether protected content can be omitted or represented by bounded commitments. Hashing does not by itself anonymise personal data.
- AEPD coordination: where logs include personal data, establish the applicable GDPR basis and duties and check current AEPD and AESIA guidance for the issues within each authority’s remit.
- Cross-border transfers: if logs are stored outside Spain or the EU, apply Standard Contractual Clauses or an adequacy mechanism. AESIA’s December 2025 template explicitly references this.
Sector-specific considerations
| Sector | What Spanish operators need to align |
|---|---|
| Healthcare | Determine whether the AI is a medical device under MDR or IVDR. Coordinate any required conformity assessment between AEMPS/notified-body and AI Act pathways. Relevant Annex I product-embedded high-risk duties apply from 2 August 2028. |
| Financial services | Layer AI Act high-risk obligations onto Bank of Spain and CNMV supervision. Track EBA guidelines on machine learning in credit institutions. Apply consumer-protection rules under Spanish banking law and the algorithmic-transparency obligations for automated decisions affecting consumers. |
| Public sector | Layer Law 40/2015 requirements for automated administrative decisions; access-to-information transparency obligations; fundamental-rights impact assessments where AI affects citizens; and public-procurement considerations for AI acquisition. |
Conformity assessment pathway
Spanish organizations with covered high-risk systems must complete the applicable conformity assessment before placing a system on the market or putting it into service once the relevant duties apply. The current high-risk date is 2 December 2027 for relevant Annex III duties or 2 August 2028 for relevant Annex I product-embedded duties. Check current AESIA guidance against the binding EU text.[5]
Assessment pathways
| Pathway | Detail |
|---|---|
| Internal control (most high-risk systems) | Provider self-assessment supported by: technical documentation per Annex IV; quality management system (Article 17); post-market monitoring plan; EU declaration of conformity; CE marking affixation. Cost is internal resourcing. |
| Conditional notified-body involvement | For Annex III point 1 biometric systems, Article 43(1) permits internal control or notified-body assessment when applicable standards are fully used, and requires the Annex VII route in the conditions listed there. Annex I products follow their sector legislation’s conformity route. Timing and fees depend on the system, route, and eligible body. |
Spanish notified bodies
Operators whose pathway requires third-party assessment should check current AESIA or notifying-authority material and the EU’s official notified-body listings for the relevant system scope. This page does not imply that a body designated under another product regime is automatically eligible for the AI system at issue.
Enforcement and penalties
The proposed Organic Law sets out a domestic governance and penalty regime, but it is not enacted. The EU AI Act’s directly applicable provisions and penalty framework should be assessed separately from the bill’s proposed national machinery.[2][3]
Penalty structure
| Violation | Maximum fine | Examples |
|---|---|---|
| Prohibited AI practices | €35,000,000 or 7% turnover | Social scoring, manipulative AI, untargeted biometric scraping |
| Serious offences | €7.5M–€35M or 2–7% turnover | Failure to label AI-generated content; high-risk non-compliance |
| Biometric system violations | €500K–€7.5M or 1–2% turnover | Employee attendance monitoring without proper human oversight |
| Other violations | €7.5M or 1% turnover | Providing incorrect information to authorities |
Additional enforcement measures
Beyond fines, the draft national law authorizes:
- System-adaptation orders requiring mandatory modifications to achieve compliance.
- Commercialisation prohibition barring market placement of non-compliant systems.
- Public warnings with reputational impact through official announcements.
- System destruction in extreme cases involving serious harm.
- Temporary operation prohibition: government authority to halt any AI system causing death or serious harm.
AESIA’s enforcement approach
Do not assume a fixed warning-before-fine sequence or a guaranteed benefit for “good-faith” effort. The applicable EU provision, the final Spanish law, sector authority, facts, and current AESIA practice determine the enforcement route. Preserve documentation, respond to lawful requests, and verify current official guidance.[2][5]
Compliance roadmap for Spanish organizations
The roadmap below should be scheduled against 2 December 2027 for relevant Annex III duties or 2 August 2028 for relevant Annex I product-embedded duties. The correct date depends on classification and product-law pathway.
| Phase | Detail |
|---|---|
| 01. AI system inventory and AESIA alignment | Catalogue relevant AI systems within the organization’s scope. Screen for Article 5 prohibitions, Article 6/Annex I and Annex III high-risk conditions, Article 50 transparency duties, GPAI roles, and exclusions. Review the current AESIA materials without treating them as a substitute for the Regulation. |
| 02. Content-labeling implementation | Implement disclosure mechanisms for synthetic media, chatbots and AI-assisted communications. Track the draft national AI law’s progress in Parliament; the deepfake-labeling regime carries €7.5M–€35M ceilings if enacted. |
| 03. Article 12 logging infrastructure | Implement automatic event logging around intended purpose and the applicable Article 12 events. Align with LOPDGDD / GDPR. Apply proportionate access and integrity controls, document the retention basis, and prepare for lawful information requests. |
| 04. Risk management and technical documentation | Stand up Article 9 risk management. Prepare Annex IV technical documentation using AESIA’s templates. Run bias assessments in the Spanish market context. Preserve scoped operational records alongside policy and testing evidence without treating any one artifact as proof of effectiveness or compliance. |
| 05. Quality management and conformity | Stand up the applicable Article 17 QMS. For notified-body pathways, confirm current capacity and work backward from 2 December 2027 for relevant Annex III duties or 2 August 2028 for relevant Annex I product-embedded duties. Coordinate with AEMPS, Bank of Spain or CNMV where applicable. |
| 06. AESIA readiness and post-market monitoring (Ongoing) | Prepare for AESIA information requests and inspections. Stand up Article 73 serious-incident reporting. Maintain living documentation; consider sandbox participation for future high-risk systems. |
Documentation and technical evidence can support a response to an authority, but this page does not establish how AESIA will weigh intent, evidence maturity, or remediation in a particular matter. Match each artifact to the legal requirement and its actual claim boundary.
How GLACIS supports Article 12
Article 12 requires system-specific logging capabilities, not a universal proof that every control executed. GLACIS can add signed operational records for selected policy, control and action events; those records support integrity and traceability but do not establish completeness, effectiveness or compliance.
| Need | What GLACIS produces |
|---|---|
| Selected control events | Timestamped records for configured input validation, output filtering and human-oversight events; coverage depends on the integration and event selection. |
| Signed records | Cryptographically signed entries whose included fields can be independently verified. Article 12 does not set a cryptographic or tamper-evidence bar. |
| Framework mapping | Evidence fields can be mapped to selected EU AI Act, ISO 42001 and NIST AI RMF concepts to support review; mappings are not a conformity assessment. |
FAQ
How does enforcement in Spain differ from other member states?
AESIA has operated since June 2024. Spain’s proposed Organic Law would define additional national governance, supervision, and penalty machinery, but remains at the committee-amendments stage as of 26 August 2026. Confirm the applicable EU provision and current national authority before describing an enforcement route.
Should I participate in the regulatory sandbox?
A regulatory sandbox may provide a structured setting for engagement, but participation does not validate compliance or guarantee an enforcement outcome. Check the current official call, eligibility, authority, timetable, and published outputs before relying on it.
How do I coordinate AESIA with sector regulators?
AESIA has a central role while sector regulators retain domain oversight. Check current AESIA guidance, then layer sector-specific obligations: AEMPS for medical-device pathways, Bank of Spain or CNMV for financial services, and AEPD for personal-data aspects. For covered Annex I product-embedded systems, relevant high-risk duties apply from 2 August 2028.
What makes Spain’s content-labeling rules different?
The draft national law treats unlabelled AI-generated content as a “serious offence” with €7.5M–€35M ceilings that go beyond the EU AI Act’s Article 50 baseline. Operators generating or manipulating content with AI should implement unambiguous disclosure mechanisms now; the deepfake-labeling regime survives in the latest draft text but isn’t yet in force.
How do I access AESIA’s guidance pack?
AESIA published compliance materials on 16 December 2025 covering risk management, technical documentation, sandbox practice, and conformity assessment. Materials are available on the official AESIA site at aesia.digital.gob.es. Check the current version before relying on a template.
Are there SME-specific provisions in the draft AI law?
The current draft includes proportionality language for SMEs, but the proposal is not yet in force and may change. Check the enacted text before relying on a penalty calculation; this page does not establish that AESIA gives smaller organizations a specific enforcement benefit.
References
- AESIA. “AESIA Consolidates Its Role in Europe in Promoting Ethical, Sustainable and Reliable AI.” August 2025. aesia.digital.gob.es
- Congress of Deputies. “Proyecto de Ley Orgánica para el buen uso y la gobernanza de la inteligencia artificial” (121/000096). Current procedure page, accessed 26 August 2026. congreso.es
- Covington & Burling LLP. “Spain Issues Guidance Under the EU AI Act.” Inside Privacy, December 2025. insideprivacy.com
- European Commission. “First Regulatory Sandbox on Artificial Intelligence Presented.” June 2022. ec.europa.eu
- AESIA. “Guidelines Published to Support Compliance with the AI Act.” 16 December 2025. aesia.digital.gob.es
- Holistic AI. “Spain Becomes First EU Member to Establish AI Regulatory Body.” August 2024. holisticai.com
- Linklaters. “Spain Proposes a New AI Bill, Including Significant Fines.” March 2025. linklaters.com
- Euronews. “Spain Could Fine AI Companies Up to 35 Million for Mislabelling Content.” March 2025. euronews.com
- OECD. “Progress in Implementing the EU Coordinated Plan on AI — Spain.” October 2025. oecd.org
- Pinsent Masons. “Spain Legislates for First EU AI Act Regulatory Sandbox.” November 2023. pinsentmasons.com
- European Union. “Regulation (EU) 2024/1689 of the European Parliament and of the Council.” OJEU, 12 July 2024. EUR-Lex
- European Commission. “AI Omnibus enters into force.” 27 July 2026. digital-strategy.ec.europa.eu
- EU Artificial Intelligence Act. “Overview of All AI Act National Implementation Plans.” Updated 2026. artificialintelligenceact.eu