Since 2 August 2026 the EU Artificial Intelligence Act has been in general application, and in Spain AESIA holds full inspection and enforcement powers. If your organisation uses AI — even a customer support chatbot or an internal assistant — you already have obligations that are enforceable today.
What is enforceable today and what has been postponed
The Regulation did not land all at once: it applies in phases. Telling apart what is already due from what still has room matters, because the recent postponement has caused a good deal of confusion.
1
Prohibited practices and AI literacy
Certain uses banned outright, plus the duty to ensure that staff using or deploying AI have sufficient training. Enforceable for over a year now.
February 2025
2
General-purpose AI models
Obligations for foundation model providers: technical documentation, copyright policy and a summary of training content.
August 2025
3
General application and transparency
Transparency obligations take effect and AESIA assumes full enforcement powers in Spain. This is the date that changes the picture for most companies.
2 August 2026
4
Annex III high-risk systems
Employment, education, biometrics, critical infrastructure and essential services. Postponed by the Digital Omnibus from its original date.
December 2027
5
Annex I high-risk systems
AI embedded in already regulated products, such as medical devices. Also postponed.
August 2028
The high-risk postponement does not touch prohibitions or transparency. What is already enforceable stays enforceable. If a vendor told you “there is time until 2027”, you were told half the story.
The obligations that already apply to you
Disclose that the user is talking to an AI at the first point of interaction: chatbots, virtual assistants, voice agents.
Mark synthetic content — AI-generated text, image, audio and video — with machine-readable technical markers.
Label deepfakes with a visible indicator that the content was artificially created or manipulated.
Inform affected people in advance where emotion recognition or biometric categorisation is used.
AI literacy for staff who use or deploy it. This is an obligation of result, not of intent: it must be demonstrable.
Stay clear of prohibited practices, which carry the heaviest penalty tier in the Regulation.
What is at stake
Top tier
Up to €35M or 7%
For engaging in the prohibited AI practices of Article 5. The higher of the two figures applies, on worldwide annual turnover.
General tier
Up to €15M or 3%
For failing to meet the rest of the obligations under the Regulation, transparency included.
Information
Up to €7.5M or 1%
For supplying incorrect, incomplete or misleading information to authorities or notified bodies.
For SMEs and start-ups the Regulation applies the lower of the two figures rather than the higher. It is still material.
The blind spot: the AI nobody declared
In practice, the first gap in almost every organisation is not the AI system bought with a contract and an invoice. It is the one nobody approved: staff pasting confidential documentation, proprietary code or personal data into public chatbots because it gets their day done.
That creates two problems at once. A compliance one, because you cannot govern what you do not know exists. And a data protection one, because in many cases there is an international transfer and a processor with no Article 28 GDPR contract behind it.
The usual answer — banning it by internal memo — does not work: the usage turns invisible instead of disappearing, and you lose the productivity without gaining the control. What works is providing an approved alternative and measuring it.
How we approach it
The same method we use for ENS, NIS2, DORA or ISO 27001: first know where you stand, then what is missing, then close it.
1
Inventory and classification
Which AI systems the organisation actually uses, including the ones nobody declared. For each of them, your legal role: provider or deployer. Without this, everything else is guesswork.
2
Gap analysis
Your real position measured against what is enforceable today, not against what falls due in 2027. With documented evidence, not a list of good intentions.
3
Action plan
Prioritised by risk and deadline, with an owner, effort and cost for each item. What can be closed in weeks, kept separate from what needs a project.
4
Remediation
Actual implementation: transparency notices, content marking, records, governance, demonstrable staff training and technical control over where the data ends up.
Where it meets what you already have
If you are already working another framework, much of the effort carries over. Governance, risk analysis and supplier control are the same assets.
GDPR — lawful basis, international transfers, processor contracts and impact assessment where applicable.
NIS2 — supply chain security covers AI providers too.
DORA — an external AI API is a third-party ICT service provider: it enters the register of information and requires an exit strategy.
ISO/IEC 27001 — your existing management system absorbs AI controls without duplicating structure.
ENS — if you are public sector or serve it, AI use inherits the scheme’s requirements.
Frequently asked questions
Does it apply if we only use third-party tools and build nothing ourselves?
Yes. In that case your organisation is a deployer rather than a provider, but it still carries obligations of its own: transparency towards users, staff literacy, and staying clear of prohibited uses. Most Spanish companies sit in exactly that position.
Does the postponement to 2027 not give me room?
Only for high-risk systems. Prohibited practices, literacy and transparency obligations are already enforceable and AESIA can already inspect. Conflating the two is the most common mistake we are seeing.
Is approving an internal AI policy enough?
No. A policy is the starting point, but an inspection asks for evidence: which systems exist, who approved them, what training was delivered and to whom, how users are informed. A document with no trail behind it does not survive a review.
Who inspects and enforces in Spain?
The Spanish Agency for the Supervision of Artificial Intelligence (AESIA), exercising full powers since August 2026. Where personal data is involved, the AEPD also has jurisdiction.
Are you lawyers?
No. We are a technical cybersecurity team with governance and audit certifications, and we handle inventory, gap analysis, evidence and technical control. The final legal qualification is always validated with the client’s legal advisors, or we put you in touch with specialists if you have none.
Know what is enforceable today, not in 2027
Half an hour with an auditor to review which AI systems your organisation actually uses, what role you hold in each, and what a reasonable gap analysis scope would look like. No commitment and no forms.
Phone: 686 250 244 · Email: info@jaymonsecurity.com
You may also be interested in

