🔄 Last updated: July 2026. The Digital Omnibus Package was approved by the European Parliament on 16 June 2026 and by the Council on 29 June 2026. Obligations for standalone high-risk AI systems will fully apply from 2 December 2027, while obligations for AI systems integrated as safety components will apply from 2 August 2028.
AI Act for Universities in Spain: What Higher Education Institutions Need to Do in 2026
The European Artificial Intelligence Act is already in force and applies to universities across Spain, whether public or private. Yet many institutions still lack clarity about which obligations already apply, which ones are approaching, and how they should prepare.
This guide explains the current regulatory landscape in a practical and structured way.
Why the AI Act applies to universities
The AI Act (Regulation (EU) 2024/1689) is directly applicable across all EU Member States, including Spain, without requiring national transposition.
It applies to any organisation that develops, deploys or integrates AI systems. Universities clearly fall within this scope, as they increasingly use artificial intelligence across multiple areas of their activity, including academic administration, student admissions, assessment, research, learning support and communication with students.
The Regulation does not distinguish between public and private universities. What determines the applicable obligations is how AI systems are used and for what purpose.
The difference between public and private institutions lies primarily in their governance and decision-making processes rather than in the legal obligations themselves.
What is already in force and cannot wait
Since February 2025, Article 4 of the AI Act has required organisations to ensure an adequate level of AI literacy among staff who operate or use AI systems.
For universities, this means ensuring that both academic and administrative staff possess sufficient knowledge to use AI responsibly and with appropriate judgement.
There are no exemptions based on institutional size or legal status. This is currently the obligation that most directly affects higher education institutions—and, in many cases, the one that remains the least understood.
Since August 2025, additional obligations have applied to General-Purpose AI (GPAI) models.
Universities using tools such as ChatGPT, Microsoft Copilot or Google Gemini should ensure that their providers comply with the AI Act while documenting how these systems are deployed internally, particularly where they influence institutional processes.
The critical issue: automated student assessment
This is the area no university can afford to overlook.
Under the AI Act, AI systems used to assess learning outcomes or make decisions affecting access to education are classified as high-risk AI systems.
This means that if a university uses AI to grade examinations, support admissions decisions or make academic decisions affecting an individual without meaningful human oversight, those systems may fall within the high-risk category.
High-risk does not mean prohibited.
It means that these systems are subject to significantly stricter obligations, including:
- Comprehensive technical documentation.
- Effective human oversight.
- Conformity assessment procedures.
- Registration where required by the Regulation.
Following the approval of the Digital Omnibus Package, the full obligations for standalone high-risk AI systems will apply from 2 December 2027, extending the original deadline of August 2026.
Although this may appear distant, redesigning assessment processes, governance structures and institutional documentation requires considerable preparation and should not be left until the final months.
What changes for public and private universities
The legal obligations are exactly the same for both public and private universities. What differs is the level of institutional autonomy available to respond.
A private university has greater flexibility to define its own AI strategy, governance framework and institutional policies. It can move more quickly, establish internal standards and implement decisions without relying on external administrative approval. That agility is a significant advantage, but it also means assuming full responsibility for those decisions.
Public universities operate within the framework established by the public administration to which they belong. Many decisions relating to AI governance are coordinated with the relevant regional authority or ministry.
Their challenge is therefore different. Rather than designing an AI strategy entirely from scratch, they need to build a coherent institutional position within the regulatory and administrative framework in which they operate—without waiting for every decision to come from higher authorities.
In both cases, the greatest risk is the same: allowing the absence of an institutional AI strategy to be replaced by individual decisions made independently by faculties, departments or lecturers.
Key regulatory deadlines
February 2025
AI literacy obligation (Article 4) enters into force.
Universities must ensure that staff using AI systems have the knowledge and skills required to use them responsibly.
August 2025
Obligations for General-Purpose AI (GPAI) models become applicable.
Institutions using services such as ChatGPT, Copilot or Gemini should verify supplier compliance and establish internal governance for their use.
December 2026
The prohibition on certain AI systems used to generate non-consensual intimate deepfakes enters into force.
Watermarking obligations also become applicable where required under the Regulation.
December 2027
The full obligations for standalone high-risk AI systems, including AI used for automated student assessment or educational decision-making, become applicable.
The Digital Omnibus Package, approved by the European Parliament on 16 June 2026 and by the Council on 29 June 2026, postponed this deadline from August 2026 to December 2027.
August 2028
Obligations for high-risk AI systems integrated as safety components become fully applicable.
What has not changed
The Digital Omnibus Package does not affect:
- Article 4 (AI literacy).
- Article 5 (prohibited AI practices).
Both provisions have remained fully applicable since February 2025.
What universities should be doing now
The first priority is to create an inventory of every AI system currently used across the institution.
Universities should identify:
- Which AI systems are being used.
- In which departments.
- For what purposes.
- Which types of personal or institutional data they process.
Many institutions discover during this exercise that AI is already being used much more extensively than expected, often through isolated initiatives developed independently by different faculties or administrative units.
The second step is to classify every AI system according to the AI Act’s risk categories, paying particular attention to systems involved in student assessment, admissions or academic decision-making.
Finally—and perhaps most importantly—universities should establish a clear institutional position on AI.
This means developing an AI governance policy that defines:
- What uses of AI are acceptable.
- What practices are prohibited.
- Which responsibilities apply to different roles.
- Which principles guide institutional decision-making.
Without that shared framework, every lecturer, researcher and department is left to develop its own approach, increasing both legal and organisational risk.
Universities that address AI governance proactively are strengthening institutional quality, building trust among students and families and demonstrating leadership to accreditation bodies and external stakeholders.
The AI Act is more than a legal obligation
It may be tempting to treat the AI Act purely as a legal compliance exercise and leave responsibility entirely to the legal department.
However, the Regulation ultimately asks universities a much deeper question:
How should artificial intelligence become part of teaching, assessment and institutional decision-making?
Legal compliance establishes the minimum standard. The real challenge is determining the principles, values and governance model that will guide AI across the institution.
That is not a legal decision. It is an institutional one.
Frequently Asked Questions
Does the AI Act apply to public universities or only to private universities?
It applies equally to both. The AI Act applies to any organisation that uses AI systems, regardless of whether it is public or private. The difference lies not in the legal obligations, but in the level of institutional autonomy: private universities can establish their own AI policies independently, while public universities develop their position within the framework of the public administration to which they belong.
Which AI Act obligation already affects universities in 2026?
The AI literacy obligation (Article 4), which has been in force since February 2025. Every university must ensure that academic and administrative staff who use AI systems have sufficient training to use them responsibly and with informed judgement. It applies regardless of the institution’s size and includes no exemptions.
Is using AI to assess students considered high-risk under the AI Act?
Yes. AI systems used to assess learning outcomes or make decisions regarding access to education are classified as high-risk. They are not prohibited, but they are subject to strict obligations, including technical documentation, effective human oversight, conformity assessment and registration. These obligations will become fully applicable on 2 December 2027.
Did the Digital Omnibus Package change the AI Act?
The Digital Omnibus Package, approved by the European Parliament on 16 June 2026 and by the Council on 29 June 2026, extended the implementation deadlines for high-risk AI systems until December 2027 and August 2028. It did not affect Article 4 (AI literacy) or Article 5 (prohibited AI practices), both of which have remained in force since February 2025.