AI Act · Spain
EU AI Act enforcement in Spain
Spain built a dedicated AI regulator in 2023 and the EU's first sandbox. Twelve high-risk systems went through it and produced sixteen published guides.
Every other page in this series describes a country preparing for a regulator. Spain is the one that already has three years of it.
Royal Decree 729/2023, approved on 22 August 2023 and in force from 2 September, created AESIA — the Spanish Artificial Intelligence Supervisory Agency, operational since June 2024 and headquartered in A Coruña rather than Madrid. It was the first dedicated national AI regulator in Europe, and it existed before the AI Act obliged anyone to build one.
The part that is genuinely without equivalent
Royal Decree 817/2023, in force from 10 November 2023, created the EU's first AI regulatory sandbox. In April 2025 it admitted its first cohort: twelve high-risk AI systems, spanning essential services, biometrics, employment, critical infrastructure, machinery and medical devices.
By December 2025, AESIA had published sixteen practical compliance guides built from what those participants actually ran into.
This is the asset, and most organisations do not know it is there. Compliance guidance elsewhere is written by lawyers reading a Regulation. Spain's is written by a supervisor watching twelve real high-risk systems attempt conformity under observation, then writing down what broke. Whether or not you operate in Spain, that is the closest thing in the Union to a worked example — and it is public.
Note what the sandbox does and does not do. It is a controlled environment for testing high-risk systems before market launch. It buys supervised time and a documented relationship with the regulator. It does not waive the rules.
Who holds what
On 26 May 2026 the Council of Ministers sent the Draft Organic Law on the proper use and governance of artificial intelligence to parliament. It sets the supervisory map.
| Authority | Domain |
|---|---|
| AESIA | General AI systems. Reference market surveillance authority, single point of contact with the EU, sandbox operator, and chair of the Joint Coordination Committee |
| Banco de España, CNMV, DGSFP | Banking, securities markets, insurance and pension funds |
| AEPD — data protection agency | Border management AI, biometric identification and biometric categorisation |
| CGPJ — General Council of the Judiciary | AI in the administration of justice |
| Junta Electoral Central | AI in its electoral domain |
| Sectoral product regulators | AI inside products already covered by an existing framework |
The divergence that matters most to a multinational
Look at what the Spanish data protection authority did not get.
The AEPD's designated scope is borders, biometric identification and biometric categorisation. That is narrow and specific. Employment and recruitment are not carved out to the privacy regulator — they sit with AESIA as the general supervisor.
Set that beside the rest of the series and a pattern appears that no tracker shows:
| Member state | Who supervises AI in hiring | Institutional type |
|---|---|---|
| France | CNIL | Privacy regulator |
| Netherlands | AP | Privacy regulator |
| Ireland | Workplace Relations Commission (prohibited practices) | Employment body |
| Spain | AESIA | Purpose-built AI regulator |
One recruitment system, four countries, four different kinds of regulator. A group AI policy written from any single one of them will misroute in the other three. That is not a drafting nuisance — it decides which vocabulary your documentation has to be written in, because a privacy regulator, an employment adjudicator and a technical agency do not ask the same first question.
Penalties, with a floor
Spain graded its own infringements rather than simply importing the Act's tiers.
| Grade | Ceiling |
|---|---|
| Very serious | €35m or 7% of worldwide annual turnover |
| Serious | Intermediate band |
| Minor | €500,000 or 0.5% |
Two adjustments sit on top. SMEs and startups face reduced fines. And public administrations face warnings and internal disciplinary measures rather than financial penalties — a different answer from Ireland, which set a €1m ceiling for public bodies instead of exempting them.
The minor band is worth noticing on its own. A floor of €500,000 or 0.5% of turnover means Spain has created a category for the small, procedural failure — and given it a price.
Four obligations that go past the Act
The draft law adds requirements the Regulation does not impose, all aimed at Spanish public administration:
- An inventory of every administrative AI system — not only the high-risk ones.
- AI delegates, named individuals responsible for coordinating compliance.
- Mandatory AI training for staff.
- Sector-specific sandboxes, in addition to the national one.
The inventory obligation is the interesting one, because it drops the filter the rest of the Act is built on. Everywhere else the first question is which tier is this system in, and the inventory follows from the answer. Spain inverts it: list everything, then classify. That is the right order, and it is the order almost nobody follows — you cannot triage an estate you have not enumerated, and a system you never listed is never classified as anything.
Where Spain stands
| Item | Position |
|---|---|
| Article 70 designation | AESIA operating as reference authority; the Organic Law is in parliament, sent 26 May 2026 |
| Dedicated regulator | AESIA, Royal Decree 729/2023, operational June 2024, A Coruña |
| Sandbox | Royal Decree 817/2023 — first in the EU; first cohort April 2025, twelve high-risk systems |
| Published guidance | Sixteen practical guides by December 2025, drawn from sandbox experience |
| Coordination | Joint Coordination Committee of Market Surveillance Authorities, chaired by AESIA |
| Penalties | Very serious / serious / minor — €35m or 7% down to €500,000 or 0.5% |
| High-risk obligations apply | 2 December 2027 (stand-alone) · 2 August 2028 (embedded) |
| Prohibitions in force since | 2 February 2025 |
What a Spanish deployer should do now
- Read AESIA's sixteen guides before you commission legal advice. They are derived from supervised attempts at conformity by real high-risk systems. No other member state has published anything comparable, and reading them first will make the legal conversation shorter.
- Do not assume the AEPD. If your system is not about borders or biometrics, your supervisor is AESIA. Organisations arriving from a French or Dutch group position routinely get this backwards.
- Enumerate before you classify. Spain will require its own administration to list every AI system irrespective of tier. The logic holds for a private estate too: classification applied to an incomplete inventory produces a confident answer about the wrong population.
- Consider the sandbox if you are pre-launch. It is a real mechanism with a real cohort history, not a consultation exercise, and participation produces a documented relationship with the supervisor.
- Start the six-month log retention now. Article 26 requires deployers to keep system logs for at least six months. Logs not kept cannot be reconstructed, so the system needs to be running correctly by roughly mid-2027 to have a compliant record on day one.
Questions
Who enforces the EU AI Act in Spain?
AESIA, the Spanish Artificial Intelligence Supervisory Agency, is the reference market surveillance authority and single point of contact, and it chairs a Joint Coordination Committee of the other supervisors. Financial and insurance AI goes to the Bank of Spain, the CNMV and the insurance directorate; the judiciary and the Central Electoral Commission cover their own domains; and the AEPD holds a deliberately narrow slice — border management, biometric identification and biometric categorisation.
What makes Spain different from other member states?
It rehearsed. Spain created the first dedicated AI regulator in Europe by Royal Decree 729/2023 and the first European AI regulatory sandbox by Royal Decree 817/2023. Twelve high-risk systems entered the first cohort in April 2025, and by December 2025 AESIA had published sixteen practical compliance guides drawn from what those participants actually encountered. Everywhere else you are reading the law. In Spain you can read the practice.
Does the Spanish data protection authority supervise AI in hiring?
No. This is where Spain diverges most sharply from France and the Netherlands. The AEPD's designated scope is border management AI, biometric identification and biometric categorisation. Employment and recruitment are not carved out to the privacy regulator the way they are in Paris and The Hague; they sit with AESIA as the general supervisor.
What are the Spanish penalties?
The draft Organic Law grades infringements as very serious, serious or minor. The most serious reach €35m or 7% of worldwide annual turnover; minor infringements carry up to €500,000 or 0.5%. Fines are reduced for SMEs and startups, and public administrations face warnings and internal disciplinary measures rather than fines.
What does Spain require beyond the AI Act?
Four things, all aimed at the public sector. An inventory of every administrative AI system rather than only the high-risk ones; designated AI delegates to coordinate compliance; mandatory AI training for staff; and sector-specific sandboxes in addition to the national one. The inventory obligation is the notable one, because it drops the risk-tier filter that the rest of the Act is organised around.
Related
Agent Trust Cloud
We publish this because the deployer side of the AI Act is widely misread, and Spain is misread as an outlier when it is closer to a preview. Its own draft law tells its administration to enumerate every AI system before classifying any of them — which is the same order of operations we work in. Agent Trust Cloud is building a control plane for AI agents — identity, policy, evidence. The platform is in development and is not sold as a subscription today; what is available now is a fixed-scope assessment of the agents and machine identities you already have.