🔄 Last updated: July 2026. The Digital Omnibus Package was approved by the European Parliament on 16 June 2026 and by the Council on 29 June 2026. Obligations for standalone high-risk AI systems will fully apply from 2 December 2027. Obligations for AI systems integrated into regulated products as safety components will apply from 2 August 2028.
AI Act: What Companies in Spain Need to Do in 2026 (Practical Guide)
The European Artificial Intelligence Act has been partially applicable since 2025, yet many organisations still do not know which obligations apply to them, when they take effect, or what they need to do.
This guide answers those three questions using the most up-to-date information available.
It is not a legal guide—that is the role of legal professionals. Instead, it is a management guide designed for CEOs, IT managers, compliance officers and sustainability leaders who need to make informed decisions about AI governance.
The AI Act is no longer future legislation. Several of its obligations are already in force and apply to any organisation using artificial intelligence in Spain.
What is the AI Act and who does it apply to?
The AI Act (Regulation (EU) 2024/1689) is the world’s first comprehensive legal framework for artificial intelligence. As an EU Regulation, it applies directly in Spain without requiring national transposition.
It applies to any organisation that develops, deploys, imports, distributes or uses AI systems within the European Union, regardless of where the organisation is headquartered.
Its scope is broad and includes generative AI tools such as ChatGPT and Copilot, predictive analytics systems, recommendation algorithms, recruitment tools, online proctoring systems, customer service chatbots and any AI system that makes or supports automated decisions.
Risk classification: where does your organisation fit?
Unacceptable risk — prohibited since February 2025
Social scoring systems, subliminal manipulation, exploitation of vulnerabilities of specific groups and emotion recognition in workplaces or educational settings (with limited exceptions) are prohibited.
High-risk AI systems
This category includes AI systems used for recruitment, access to education, student assessment, creditworthiness, insurance and essential public services.
Key obligations include:
- Technical documentation.
- Human oversight.
- Conformity assessment.
- Registration where required.
Limited-risk AI systems
Chatbots and AI systems that generate content or interact directly with individuals.
Main obligation:
- Users must be clearly informed that they are interacting with an AI system.
Minimal-risk AI systems
Most AI-powered productivity tools fall into this category.
They are not subject to additional regulatory obligations under the AI Act.
Key dates for companies in 2026
February 2025 (already in force)
The obligation to ensure AI literacy for staff operating AI systems (Article 4) entered into force.
This requirement applies to organisations of all sizes.
August 2025 (already in force)
Obligations for General-Purpose AI (GPAI) models became applicable.
These primarily affect providers such as OpenAI, Google and Anthropic, although organisations should also ensure that the AI services they procure comply with the Regulation.
December 2026
The prohibition on certain AI systems used to generate non-consensual intimate deepfakes enters into force.
Watermarking obligations also become applicable where required under the Regulation.
December 2027
The obligations for standalone high-risk AI systems listed in Annex III become fully applicable.
The Digital Omnibus Package, approved by the European Parliament on 16 June 2026 and by the Council on 29 June 2026, postponed this deadline from August 2026 to December 2027.
August 2028
Obligations for high-risk AI systems integrated as safety components in regulated products (Annex I) become fully applicable.
What does not change
Article 4 (AI literacy) and Article 5 (prohibited AI practices) are not affected by the Digital Omnibus Package.
Both have remained fully applicable since February 2025.
AESIA: Spain’s AI supervisory authority
The Spanish Agency for the Supervision of Artificial Intelligence (AESIA) has had enforcement powers since August 2025.
Administrative fines may reach:
- Up to €35 million or 7% of worldwide annual turnover for the most serious infringements;
- Up to €15 million or 3% of worldwide annual turnover for certain breaches involving high-risk AI systems.
Where should companies start?
1. Map your AI systems
Identify every AI system used within your organisation and determine its risk classification.
Without this initial assessment, compliance efforts are unlikely to be effective.
2. Comply with Article 4
The AI literacy obligation is already in force.
Define the level of AI literacy required for each professional profile according to the AI systems they use, and document the training provided.
3. If you use high-risk AI systems
Begin preparing the required technical documentation and conformity assessment well before the applicable deadlines.
Frequently Asked Questions
Does the AI Act apply to every company in Spain?
Yes.
It applies to any organisation that develops, deploys, imports, distributes or uses AI systems within the European Union, regardless of its size or sector.
The AI literacy obligation under Article 4 has applied to all organisations since February 2025.
What happens if a company fails to comply with the AI Act?
Administrative fines range from €7.5 million or 1.5% of worldwide annual turnover to €35 million or 7%, depending on the type and severity of the infringement.
In Spain, AESIA has had enforcement powers since August 2025.