1. Three rules, one framework
There is no single "AI law": there is a directly applicable European regulation, a national agency that supervises it, and data protection rules that apply in parallel whenever the system processes information about people.
The EU AI Act
Regulation (EU) 2024/1689 of 13 June 2024 is the world's first comprehensive law on artificial intelligence. It was published in the Official Journal on 12 July 2024 and entered into force on 1 August 2024, with a staggered application timeline. It classifies AI systems by risk level and imposes obligations proportionate to that risk: risk management, data governance, technical documentation, logging, human oversight, accuracy, robustness and cybersecurity.
In July 2026 the Act was amended by Regulation (EU) 2026/1744 of 8 July 2026 (the "Digital Omnibus on AI", Official Journal of 24 July 2026), which simplifies part of the requirements and defers the obligations for high-risk systems. Transparency obligations, by contrast, were not deferred.
Oversight in Spain: AESIA
The Spanish Agency for the Supervision of Artificial Intelligence (AESIA) was created by Royal Decree 729/2023 of 22 August and is based in A Coruña. It was the first agency of its kind in the European Union and is the body set to supervise the application of the AI Act in Spain, as well as to publish reference technical guidance.
Data protection: GDPR and the AEPD
If the AI system processes personal data — in training, at inference time or in its logs — then Regulation (EU) 2016/679 (GDPR) and the Spanish LOPDGDD also apply, under the supervision of the Spanish Data Protection Agency (AEPD). The AI Act does not replace the GDPR: it adds to it.
2. Application timeline
The AI Act did not apply all at once. These are the dates that matter, already updated with the July 2026 reform:
- 1 August 2024 Regulation (EU) 2024/1689 enters into force.
- 2 February 2025 Prohibited AI practices (Art. 5) and the AI literacy obligation for staff (Art. 4) become applicable.
- 2 August 2025 Obligations for general-purpose AI (GPAI) models, the European and national governance structure, and the penalties regime.
- 2 August 2026 General application of the Act, including the Article 50 transparency obligations: disclosing that a person is interacting with an AI, marking artificially generated or manipulated content, and notifying people subject to emotion recognition or biometric categorisation.
- 2 December 2026 End of the transition period granted by the reform for marking synthetic content in systems already placed on the market before 2 August 2026.
- 2 December 2027 Obligations for Annex III high-risk systems (employment, education, biometrics, essential services, critical infrastructure…). The original deadline was 2 August 2026; Regulation (EU) 2026/1744 deferred it.
- 2 August 2028 Obligations for high-risk systems embedded in products covered by EU sectoral legislation (machinery, toys, lifts, medical devices…).
What the deferral really means: the 2026 reform gives more room to whoever builds or deploys high-risk systems, but it does not delay the prohibitions, the general-purpose model obligations, or transparency towards users. If your project uses a conversational assistant or generates content, 2 August 2026 is still your date.
The European Commission maintains an official timeline and interactive tooling on the AI Act Service Desk, including a compliance checker to work out which obligations reach you.
3. The four risk tiers
The Act does not regulate "AI" in the abstract, but each specific use. The classification determines which obligations apply:
-
Unacceptable risk — prohibited
Practices banned in the EU since February 2025 (Art. 5): subliminal manipulation, exploiting vulnerabilities, social scoring, predicting criminal offences from personality profiles, untargeted scraping of facial images, emotion recognition at work or in education, and biometric categorisation of sensitive data, among others.
-
High risk — demanding requirements
Systems that decide on or influence sensitive areas: recruitment and HR management, access to education, creditworthiness, life and health insurance, essential public services, biometrics, critical infrastructure, justice or migration. They require a risk management system, data governance, technical documentation, traceability, effective human oversight, conformity assessment and registration in the EU database.
-
Transparency risk — duty to disclose
Chatbots and conversational assistants, generation of text, images, audio or video, deepfakes, emotion recognition. The core duty is that people know they are dealing with an AI and that synthetic content is marked in a machine-readable way. This is the tier most business projects fall into.
-
Minimal risk — no specific obligations
Internal recommenders, spam filters, demand forecasting, document classification, route optimisation or predictive maintenance. They add no obligations under the AI Act, though they remain subject to the GDPR if they process personal data, and to voluntary codes of conduct.
4. Who supervises in Spain
The European regulation leaves it to each Member State to designate its authorities. In Spain the intended split is as follows:
- AESIA — the reference authority for market surveillance of AI systems, coordination, advice and regulatory sandboxes. It publishes a body of technical guidance (in Spanish) on risk management, data governance, transparency, human oversight, cybersecurity, technical documentation and conformity assessment.
- AEPD — everything concerning the processing of personal data, including biometric uses.
- Banco de España — AI systems in the financial sector.
- General Council of the Judiciary (CGPJ) — uses within the administration of justice.
That split, together with the penalties regime, complaint channels and regulatory sandboxes, is set out in the Draft Organic Law on the good use and governance of artificial intelligence, approved by the Council of Ministers on 26 May 2026 and published in the Official Gazette of the Spanish Parliament on 12 June 2026.
Note: as of this review the bill is still going through Parliament — it is not yet law. The European regulation, on the other hand, is directly applicable and needs no Spanish statute to bind you.
5. GDPR and AI: what the AEPD expects
When an AI system processes personal data, two compliance layers coexist. The GDPR layer arrives first and is usually the one that gets overlooked: a lawful basis for the processing, data minimisation, information to data subjects, retention periods, the Article 22 rules on automated decisions and, in many cases, a prior data protection impact assessment (DPIA).
The AEPD publishes reference material that applies directly to AI projects, in its Innovation and technology area:
- Adapting processing that incorporates AI to the GDPR (PDF, Spanish) — the baseline document for designing GDPR-compliant AI processing.
- Guidance on agentic AI and data protection (PDF, Spanish) — key when the system does not just answer but takes actions autonomously.
- Requirements for audits of processing that includes AI (PDF, Spanish).
6. What it means for your company
The first question is not "am I compliant?" but "which role am I in?". The Act allocates very different obligations depending on each party's position:
- Provider — whoever develops an AI system and places it on the market or puts it into service under their own name. Carries most of the obligations.
- Deployer — whoever uses an AI system under their authority in the course of a professional activity. This is the usual role of a company adopting AI: use it according to the instructions, ensure human oversight, inform affected workers and, for high-risk systems, keep logs.
From there, a sensible compliance plan for an SME comes down to five steps:
- Inventory the AI systems in use, including those that arrive inside third-party tools (everyday "shadow AI").
- Classify each use by risk tier and establish your role: provider or deployer.
- Document purpose, data used, known limitations, human oversight points and the internal owner.
- Disclose: flag AI interactions, mark generated content, and update your record of processing activities and privacy notices.
- Train the team. After the 2026 reform, Article 4 was reworded as an obligation to support AI literacy among staff, taking their technical knowledge into account, without requiring a specific level for any individual. It still binds you — and in practice it is what prevents most incidents.
7. How we apply it at CAPTIA tech
Compliance is not a layer bolted on at the end: it drives architectural decisions from the first sprint. In every project we deliver:
- We classify the use case by risk tier before writing any code, and record it in the roadmap.
- We document which model is used, on what data, with what known limitations, and where a human steps in.
- We apply data minimisation and, where the case demands it, deploy on the client's own infrastructure or with zero-data-retention providers. Your data is never used to train third-party models.
- We implement the Article 50 transparency duties from day one: AI interaction notices and marking of generated content.
- We leave enough traceability and logging to audit decisions, and we train the team that will operate the system.
Disclaimer: this page is informational and educational; it is not legal advice. The rules evolve and their application depends on the specific case. For decisions with legal impact, consult the official sources linked here and your own legal advisers.
8. Official links
Every reference on this page, linked to its primary source:
-
European Union · EUR-Lex
Regulation (EU) 2024/1689 — Artificial Intelligence Act
Official text of the EU AI Act in the Official Journal of the European Union.
-
European Union · EUR-Lex
Regulation (EU) 2026/1744 — Digital Omnibus on AI
The July 2026 reform that simplifies requirements and defers the high-risk obligations.
-
European Commission
AI regulatory framework — Shaping Europe's digital future
The Commission's reference page on the AI Act and its timeline.
-
European Commission
AI Act Service Desk and Single Information Platform
AI Act explorer, compliance checker, timeline and the official helpdesk for questions.
-
Spain · AESIA
Spanish Agency for the Supervision of Artificial Intelligence
The agency's official site. Includes its technical guides on the Act's requirements.
-
Spain · BOE
Royal Decree 729/2023 — AESIA Statute
The instrument creating the agency and setting out its supervisory, inspection and sanctioning powers.
-
Spain · AEPD
AEPD — Innovation and technology
Guides, infographics and tools from the Spanish Data Protection Agency on AI and the GDPR.
-
European Union · EUR-Lex
Regulation (EU) 2016/679 — GDPR
The General Data Protection Regulation, applicable in parallel with the AI Act.
-
Spain · Congress of Deputies
Draft Organic Law on the good use and governance of AI
Text published in the parliamentary gazette on 12 June 2026. Still going through Parliament.