AI Act: what companies need to do in Spain in 2026 (practical guide)

🔄 Last updated: July 2026. The Digital Omnibus Package was approved by the European Parliament on 16 June 2026 and by the Council on 29 June 2026. Obligations for standalone high-risk AI systems will fully apply from 2 December 2027. Obligations for AI systems integrated into regulated products as safety components will apply from 2 August 2028.

AI Act: What Companies in Spain Need to Do in 2026 (Practical Guide)

The European Artificial Intelligence Act has been partially applicable since 2025, yet many organisations still do not know which obligations apply to them, when they take effect, or what they need to do.

This guide answers those three questions using the most up-to-date information available.

It is not a legal guide—that is the role of legal professionals. Instead, it is a management guide designed for CEOs, IT managers, compliance officers and sustainability leaders who need to make informed decisions about AI governance.

The AI Act is no longer future legislation. Several of its obligations are already in force and apply to any organisation using artificial intelligence in Spain.

What is the AI Act and who does it apply to?

The AI Act (Regulation (EU) 2024/1689) is the world’s first comprehensive legal framework for artificial intelligence. As an EU Regulation, it applies directly in Spain without requiring national transposition.

It applies to any organisation that develops, deploys, imports, distributes or uses AI systems within the European Union, regardless of where the organisation is headquartered.

Its scope is broad and includes generative AI tools such as ChatGPT and Copilot, predictive analytics systems, recommendation algorithms, recruitment tools, online proctoring systems, customer service chatbots and any AI system that makes or supports automated decisions.

Risk classification: where does your organisation fit?

Unacceptable risk — prohibited since February 2025

Social scoring systems, subliminal manipulation, exploitation of vulnerabilities of specific groups and emotion recognition in workplaces or educational settings (with limited exceptions) are prohibited.

High-risk AI systems

This category includes AI systems used for recruitment, access to education, student assessment, creditworthiness, insurance and essential public services.

Key obligations include:

  • Technical documentation.
  • Human oversight.
  • Conformity assessment.
  • Registration where required.

Limited-risk AI systems

Chatbots and AI systems that generate content or interact directly with individuals.

Main obligation:

  • Users must be clearly informed that they are interacting with an AI system.

Minimal-risk AI systems

Most AI-powered productivity tools fall into this category.

They are not subject to additional regulatory obligations under the AI Act.

Key dates for companies in 2026

February 2025 (already in force)

The obligation to ensure AI literacy for staff operating AI systems (Article 4) entered into force.

This requirement applies to organisations of all sizes.

August 2025 (already in force)

Obligations for General-Purpose AI (GPAI) models became applicable.

These primarily affect providers such as OpenAI, Google and Anthropic, although organisations should also ensure that the AI services they procure comply with the Regulation.

December 2026

The prohibition on certain AI systems used to generate non-consensual intimate deepfakes enters into force.

Watermarking obligations also become applicable where required under the Regulation.

December 2027

The obligations for standalone high-risk AI systems listed in Annex III become fully applicable.

The Digital Omnibus Package, approved by the European Parliament on 16 June 2026 and by the Council on 29 June 2026, postponed this deadline from August 2026 to December 2027.

August 2028

Obligations for high-risk AI systems integrated as safety components in regulated products (Annex I) become fully applicable.

What does not change

Article 4 (AI literacy) and Article 5 (prohibited AI practices) are not affected by the Digital Omnibus Package.

Both have remained fully applicable since February 2025.

AESIA: Spain’s AI supervisory authority

The Spanish Agency for the Supervision of Artificial Intelligence (AESIA) has had enforcement powers since August 2025.

Administrative fines may reach:

  • Up to €35 million or 7% of worldwide annual turnover for the most serious infringements;
  • Up to €15 million or 3% of worldwide annual turnover for certain breaches involving high-risk AI systems.

Where should companies start?

1. Map your AI systems

Identify every AI system used within your organisation and determine its risk classification.

Without this initial assessment, compliance efforts are unlikely to be effective.

2. Comply with Article 4

The AI literacy obligation is already in force.

Define the level of AI literacy required for each professional profile according to the AI systems they use, and document the training provided.

3. If you use high-risk AI systems

Begin preparing the required technical documentation and conformity assessment well before the applicable deadlines.

Frequently Asked Questions

Does the AI Act apply to every company in Spain?

Yes.

It applies to any organisation that develops, deploys, imports, distributes or uses AI systems within the European Union, regardless of its size or sector.

The AI literacy obligation under Article 4 has applied to all organisations since February 2025.

What happens if a company fails to comply with the AI Act?

Administrative fines range from €7.5 million or 1.5% of worldwide annual turnover to €35 million or 7%, depending on the type and severity of the infringement.

In Spain, AESIA has had enforcement powers since August 2025.

Raquel López Hernández, fundadora de Ethiceye y consultora en IA responsable

Raquel López Hernández

Raquel López Hernández is the founder of Ethiceye, a consultant and trainer specialising in responsible AI, AI governance and AI literacy. With a long career in education, she collaborates with the European Commission’s European Digital Education Hub on initiatives relating to AI literacy and ethics.

She has trained teachers from across Europe at the Europass Teacher Academy (Florence) and supports schools and organisations in developing frameworks, policies and strategies to integrate AI in line with their own criteria.

Contact with Raquel López
Privacy Summary

This website uses cookies so that we can offer you the best possible user experience. The information from the cookies is stored in your browser and performs functions such as recognising you when you return to our website or helping our team to understand which sections of the website you find most interesting and useful. You can see our Privacy Policy.

Strictly Necessary Cookies

Strictly Necessary Cookie should be enabled at all times so that we can save your preferences for cookie settings.

Analytics

This website uses Google Analytics to collect anonymous information such as the number of visitors to the site, and the most popular pages.

Keeping this cookie enabled helps us to improve our website.