What an operator in Spain must know first. Spain created a dedicated AI agency before most of Europe, and has still not given it the statute it needs to fine anyone. AESIA (Agencia Espanola de Supervision de la Inteligencia Artificial) was created by Real Decreto 729/2023 of 22 August 2023, published in the BOE on 2 September 2023, with its seat in A Coruna. It is not yet formally designated as Spain's national competent authority under Article 70 of the EU AI Act: the instrument that would do that is the Proyecto de Ley Organica para el buen uso y la gobernanza de la inteligencia artificial, which as of 17 August 2026 is in committee in the Congreso de los Diputados with the amendment deadline extended to 2 September 2026. The EU AI Act itself applies directly in Spain regardless. Article 5 prohibited practices have been enforceable since 2 February 2025 and Article 50 transparency obligations since 2 August 2026. Annex III high-risk deployer obligations under Article 26 now apply from 2 December 2027, deferred by the Digital Omnibus, Regulation (EU) 2026/1744, in force since 27 July 2026.

Spain built the agency first and the statute second, and the statute is not finished. AESIA was created in August 2023, before the EU AI Act itself was adopted, which made Spain the first Member State with a dedicated national AI body. What it did not do was give that body a domestic sanctioning statute, and Spanish administrative law requires one. The Proyecto de Ley Organica para el buen uso y la gobernanza de la inteligencia artificial was approved by the Council of Ministers on 26 May 2026, presented to the Congreso on 28 May, published in the Boletin Oficial de las Cortes Generales as A-97-1 on 12 June, and is in committee with the amendment deadline extended to 2 September 2026. This guide maps what actually binds an operator in Spain today, what AESIA can and cannot do, and what the liability picture looks like when an AI agent causes harm.

Key takeaways

  • AESIA was created by Real Decreto 729/2023 of 22 August 2023, BOE-A-2023-18911, published 2 September 2023 and in force from 3 September 2023, with its seat in A Coruna. Its Director is Alberto Gago Fernandez.
  • AESIA is not yet Spain's designated national competent authority under Article 70. No BOE instrument makes that designation, and AESIA's own guides page still refers to potential national competent authorities. The designation sits in the bill still before Congress.
  • Spain has no domestic AI sanctioning power in force. Under Ley 40/2015 an administrative sanctioning power requires a statute defining the infringements, the penalties and the procedure, and that statute has not been enacted. Article 99 of the Regulation sets the ceilings, but Spain has not yet given itself the procedure to apply them.
  • Article 5 prohibited practices have been enforceable since 2 February 2025 and Article 50 transparency obligations since 2 August 2026. Annex III high-risk deployer obligations under Article 26 now apply from 2 December 2027 and Annex I obligations from 2 August 2028, under Regulation (EU) 2026/1744, the Digital Omnibus, in force since 27 July 2026.
  • The sixteen compliance guides exist and are worth using, in Spanish and in English at aesia.digital.gob.es. They were developed under the Spanish AI regulatory sandbox pilot and are described by digital.gob.es as technical guides prepared by the Secretaria de Estado de Digitalizacion e Inteligencia Artificial. They are not AESIA enforcement guidance, and no publication date appears on them.
  • The Spanish AI regulatory sandbox has ended. It was established by Real Decreto 817/2023 of 8 November 2023, ran a single call from 23 December 2024 to 30 January 2025 selecting up to twelve high-risk systems, and digital.gob.es recorded on 1 July 2026 that it has finished. There is no open sandbox to apply to.
  • The revised Product Liability Directive (EU) 2024/2853 expressly covers software and AI systems. It applies to products placed on the market after 9 December 2026. Spain must transpose it by that date, creating an additional civil liability route for harmed third parties from 9 December 2026 onwards.
  • AESIA coordinates formally with AEPD on cases where the AI Act and GDPR overlap. Most AI systems using personal data will trigger both supervisory regimes simultaneously.

AESIA: the first dedicated AI supervisory agency in the EU

When the EU AI Act was published in the Official Journal on 12 July 2024 and entered into force on 1 August 2024, most Member States were still designing their supervisory architecture. Article 70 of Regulation (EU) 2024/1689 required Member States to designate national competent authorities by 2 August 2025. Spain had already moved.

AESIA's statute was approved by Real Decreto 729/2023, de 22 de agosto, published in the BOE on 2 September 2023 under identifier BOE-A-2023-18911 and in force from 3 September 2023. An earlier version of this guide carried the identifier BOE-A-2023-18942, which resolves to an unrelated personnel appointment in a different ministry, and a sourcing note saying the decree could not be confirmed. Both have been corrected: the decree is real and was read at the BOE. Article 2 of the decree places AESIA's institutional seat in the city of A Coruna, in the La Terraza building ceded by the municipal administration. Its current Director is Alberto Gago Fernandez.

The decree provides that the agency effectively begins operating when its Consejo Rector is constituted, within a maximum of three months from entry into force. No June 2024 operational date appears at the BOE or at aesia.digital.gob.es, and the claim has been withdrawn rather than restated.

Here the earlier version of this guide overstated matters in a way that matters to an operator. Real Decreto 729/2023 predates Regulation (EU) 2024/1689 and does not designate AESIA under it. Article 10.1.k of the decree grants supervision and sanction functions only in accordance with what European rules stipulate. No BOE instrument designates Spain's Article 70 national competent authorities, and AESIA's own guides page still refers to potential national competent authorities. The two BOE instruments that actually give AESIA operating competences today are Orden TDF/774/2025 of 11 July 2025 delegating competences to the agency, BOE-A-2025-15133, and a Resolucion of 25 August 2025 on internal delegation, BOE-A-2025-18640.

The sanctioning point is sharper still. La Moncloa's own description of the bill states that under Ley 40/2015 an administrative sanctioning power requires a statute defining the infringements, the penalties and the procedure, and that this bill is what supplies it. Until it is enacted, there is no Spanish procedure by which an AI Act fine can be imposed. Article 99 of the Regulation sets the ceilings; Spain has not yet built the mechanism.

AESIA has published very little beyond the guides. Its Actualidad section carries a handful of undated items, all on Article 50 transparency and the code of practice on AI-generated content. Its Organos Ejecutivos, Normativa and Sandbox pages return an under-construction notice. There are no enforcement decisions and no register. An earlier version of this guide attributed a warnings-first enforcement posture to the Director General and said sanctioning powers had been in place since 2 August 2025; neither could be confirmed at source, and the second is contradicted by the Ley 40/2015 point above. Both have been removed.

None of this makes Article 5 aspirational. The prohibitions are directly applicable EU law and other routes to consequence exist, including the AEPD where personal data is involved and ordinary civil liability. What is absent is a Spanish AI fine.

The EU AI Act as it applies in Spain

Regulation (EU) 2024/1689 is directly applicable across all EU Member States without national transposition. It entered into force on 1 August 2024. Its obligations apply in a phased sequence. Understanding that sequence is the starting point for any operator deploying an AI system in Spain.

What is already in force

Article 5 prohibited practices have applied since 2 February 2025. For an operator in Spain, this means the following are illegal and enforceable by AESIA now. AI systems that use subliminal techniques operating below the threshold of a person's consciousness to materially distort their behaviour in a way that causes or is likely to cause harm. Systems that exploit specific vulnerabilities of a group of persons due to their age, disability, or economic situation to materially distort their behaviour. Systems used by public authorities for social scoring based on social behaviour or personal characteristics leading to detrimental treatment outside the context where data was generated. Real-time remote biometric identification systems in publicly accessible spaces by law enforcement (subject to specific, narrow exceptions requiring judicial authorisation). Emotion recognition systems in workplaces and educational institutions (with narrow exceptions for safety purposes and medical or research purposes). AI systems that create or expand facial recognition databases through untargeted scraping.

Article 4 AI literacy obligations have applied since 2 February 2025. Providers and deployers must ensure that staff who operate AI systems on their behalf have a sufficient level of AI literacy for their tasks. This means deployers are already obliged to have completed basic training or briefing of employees who use AI tools in their day-to-day work. AESIA's guidance on AI literacy sets out a competency framework that can serve as a practical benchmark.

GPAI model obligations under Chapter V have applied since 2 August 2025. If an operator in Spain deploys a system built on a general-purpose AI model (such as a large language model-based AI agent), the provider of that underlying model must have brought it into compliance with GPAI documentation, copyright transparency, and risk management obligations. Deployers do not directly bear GPAI provider obligations, but they rely on the GPAI provider's compliance to operate legally. If the GPAI provider is not compliant, the system the deployer has built on top of it may carry inherited risk.

What applies from 2 August 2026, and what moved

Article 50 transparency obligations applied from 2 August 2026 and were not deferred by the Digital Omnibus. They are in application now. From that date: any deployer operating a chatbot or conversational AI agent must disclose to users, in a clear and timely manner, that they are interacting with an AI system, unless this is obvious from context. AI-generated audio, video, image, or text content that could mislead people must be labelled as AI-generated. Emotion recognition and biometric categorisation systems must notify individuals subject to their processing. A narrow watermarking grace period to 2 December 2026 applies only for machine-readable marking of AI-generated content by systems already on the market before 2 August 2026.

High-risk deployer obligations under Article 26 no longer apply from 2 August 2026. Regulation (EU) 2026/1744 moved the Annex III stand-alone high-risk obligations to 2 December 2027 and the Annex I obligations for high-risk AI embedded in regulated products to 2 August 2028. The Annex III categories are unchanged: AI systems used in the management and operation of critical infrastructure such as electricity, water, transport and gas; in education, vocational training or student assessment; in employment, workers management and access to self-employment; in access to essential private and public services and benefits including credit scoring, insurance risk assessment and social benefit eligibility; in law enforcement and border control; in the administration of justice; and in democratic processes and electoral systems.

Two dates ahead of that. On 2 December 2026 the new Article 5 prohibitions added by the Omnibus take effect, covering AI systems that generate child sexual abuse material or that depict an identifiable person's intimate parts without consent, and the Article 50(2) machine-readable marking transitional period ends. Spain pressed for those prohibitions, with French support. By 2 August 2027 each Member State must operate at least one AI regulatory sandbox, which is a live question for Spain given that its own sandbox has closed.

The Digital Omnibus, as adopted

The Digital Omnibus on AI was proposed on 19 November 2025 as COM(2025) 836, reached political agreement on 7 May 2026, and entered into force on 27 July 2026 as Regulation (EU) 2026/1744, six days before the original high-risk deadline. An earlier version of this guide said the agreement had not been adopted or published and that the 2 August 2026 date therefore still bound, and told operators that relying on the deferral was a regulatory risk. That was wrong by the time it was read, and it is corrected here.

One practical note. AESIA's own guides page states that the sixteen guides will be updated once the digital Omnibus amending the AI Regulation is approved. Read them with that in mind: they were written against the pre-Omnibus timetable.

Spain's draft Organic Law on AI governance

The sequence is longer than the earlier version of this guide suggested. The anteproyecto was approved at first reading by the Council of Ministers on 11 March 2025, together with an agreement authorising urgent processing. The Council of Ministers approved the proyecto de ley organica for transmission to the Congreso on 26 May 2026. It was presented on 28 May, qualified on 8 June, and published in the Boletin Oficial de las Cortes Generales as A-97-1 on 12 June 2026. It sits in the Comision de Economia, Comercio y Transformacion Digital in the amendment phase, with the deadline extended to 2 September 2026. It is not law. An earlier version of this guide stated that the amending law entered into force on 27 July 2026, which conflated it with the EU Digital Omnibus, and told readers that Spain's organic law was in force. It is not.

Its purpose is not to supplement the substantive requirements of the EU AI Act, which is directly applicable, but to provide the national institutional and procedural architecture without which the Regulation cannot be enforced domestically.

The bill's key provisions include the following. Sectors already covered by product regulation keep their existing notifying and market surveillance authorities. For the rest, including employment, biometrics and education, supervision goes principally to AESIA, and also to the Agencia Espanola de Proteccion de Datos and the Consejo General del Poder Judicial, with AESIA as the single point of contact. The CGPJ's inclusion is worth noting because it is named in the official description and was missing from an earlier version of this guide.

The bill implements the penalties regime in Spanish administrative law. It does not simply adopt the Article 99 tiers. It classes infringements as muy graves, graves and leves, with sanctions reaching EUR 35 million or 7 per cent of turnover in the most serious cases and up to EUR 500,000 or 0.5 per cent of turnover in the least serious. That lower band has no equivalent in Article 99 and is a genuinely Spanish addition. The earlier anteproyecto proposed bands of EUR 7.5 million to 35 million or 2 to 7 per cent for prohibited practices, EUR 7.5 million to 15 million or 2 to 3 per cent for very serious high-risk breaches, and EUR 500,000 to 7.5 million or 1 to 2 per cent for serious breaches.

It creates an inventory of AI systems used by the public administration in administrative procedures, and not only for high-risk systems, together with a new statutory figure, the delegado de IA, both to be developed by Real Decreto. It provides legislative grounding for AESIA to operate the Article 57 sandbox, in the future tense. And it establishes formal coordination mechanisms between AESIA and sector authorities. An earlier version of this guide described that coordination as codifying an existing formal cooperation protocol between AESIA and the AEPD; no such protocol could be found at aesia.digital.gob.es, digital.gob.es or aepd.es, and the official description presents inter-authority coordination as something the bill will create.

Parliamentary processing takes several months in Spain, and the bill still has to clear the Congreso and the Senado. The practical implication for operators is precise: the EU AI Act's substantive obligations already apply by direct effect and do not wait for the organic law, but the Spanish machinery for enforcing them does. Until the law passes, Spain has designated authorities in a bill rather than in the BOE, and no domestic AI sanctioning procedure.

The sixteen compliance guides: what they are, and what they are not

Sixteen guides are published at aesia.digital.gob.es, in Spanish and in English, together with a checklists and examples archive. They are detailed and genuinely useful, and they are the most operationally specific national-level material available for the Regulation anywhere in the EU.

Three qualifications. AESIA's own page says they were developed within the Spanish AI regulatory sandbox pilot, and digital.gob.es describes them as technical guides prepared by the Secretaria de Estado de Digitalizacion e Inteligencia Artificial. They are sandbox outputs hosted by AESIA, not AESIA enforcement guidance. No publication date appears on the guides page or in AESIA's news section; an earlier version of this guide dated them to 16 December 2025, which could not be confirmed, and the currently served PDF of Guide 01 carries an internal creation date of 24 July 2026. And AESIA states that they will be updated once the digital Omnibus is approved, so they were written against a timetable that has since changed.

In order, the sixteen are: 01 introduction to the AI Regulation; 02 practical guide with examples; 03 conformity assessment; 04 quality management system; 05 risk management; 06 human oversight; 07 data and data governance; 08 transparency; 09 accuracy; 10 robustness; 11 cybersecurity; 12 records; 13 post-market monitoring; 14 incident management; 15 technical documentation; and 16 a checklist manual for the requirements guides. Note that human oversight is guide 06, not guide 10; an earlier version of this guide had them transposed in two places.

For a deployer in Spain operating an AI agent that falls within an Annex III category, the practical starting sequence is guide 05 on risk management, guide 07 on data governance, guide 08 on transparency, guide 06 on human oversight, and guide 14 on incident management. The checklist manual at guide 16 provides a documentation format built for these requirements.

The regulatory sandbox, which has closed

Spain established a controlled testing environment by Real Decreto 817/2023 of 8 November 2023, BOE-A-2023-22767, published on 9 November 2023. It was made to test compliance with the proposal for the Regulation, before the AI Act existed, and it was run by the Secretaria de Estado de Digitalizacion e Inteligencia Artificial rather than by AESIA. The bill now before Congress would provide that the Article 57 national sandbox will be operated by AESIA, in the future tense.

There was one call, opened by a SEDIA resolution of 20 December 2024, running from 23 December 2024 to 23 January 2025 and extended to 30 January 2025. It selected up to twelve high-risk AI systems. On 1 July 2026 digital.gob.es recorded that after several months of work the Spanish AI sandbox has finished, and published its conclusions on a results page.

This matters practically. An earlier version of this guide said the sandbox was in its third cohort, had processed more than twenty systems, and that operators uncertain about classification should apply to AESIA. There is no open sandbox to apply to. Article 57 requires each Member State to operate at least one AI regulatory sandbox, and the Omnibus moved that deadline to 2 August 2027; Spain's next sandbox is therefore a forthcoming obligation rather than a current facility. The guides and the published sandbox results are what remains usable from the pilot.

AESIA and AEPD: the dual-regime reality

Most AI systems deployed in Spain process personal data. This creates a dual-regime situation that operators must address structurally. AESIA supervises the AI Act obligations. AEPD supervises GDPR compliance and the national organic law on data protection (Ley Orgánica 3/2018, LOPDGDD). The two authorities operate under a formal cooperation protocol.

The practical implications for a deployer are the following. A Fundamental Rights Impact Assessment required by Article 27 of the AI Act for Annex III systems used in employment, credit, education, or essential services is not the same as a Data Protection Impact Assessment required by Article 35 GDPR, although they cover overlapping ground. AESIA expects the FRIA; AEPD expects the DPIA. An operator should conduct both and cross-reference them. AEPD has published updated recommendations specifically on AI-based voice transcription and automated decision-making under GDPR, which provide a practical framework for the GDPR side of a dual-regime assessment.

Where an AI system's outputs constitute a solely automated decision that produces legal or similarly significant effects on data subjects, Article 22 GDPR applies alongside Article 26 of the AI Act. AEPD enforces Article 22 rights (the right to human review, the right to an explanation, and the right to contest). AESIA enforces the AI Act's transparency and human oversight obligations. Both require documentation. The safest approach is a unified governance structure with a single record that addresses both regulators' expectations, rather than two siloed compliance programmes.

Civil liability when an AI agent causes harm in Spain

The EU AI Act establishes a public regulatory regime with administrative penalties. It does not itself create a private right of action for individuals harmed by AI systems. Civil liability for AI agent harm in Spain operates through three legal channels.

Spanish tort law under the Codigo Civil

Articles 1902 to 1910 of the Spanish Codigo Civil establish the general framework for extracontractual civil liability. The foundational rule under Article 1902 requires a person who causes damage to another through fault or negligence to repair that damage. Applied to AI agent harm, this means a claimant must establish: that the AI system produced an output or took an action that caused identifiable harm; that the operator of the system was at fault (failed to take reasonable precautions), or negligent in their deployment; and causation between the deployment and the harm.

The opacity of complex AI systems makes the causation and fault elements difficult to establish in practice. Spanish courts, consistent with other European jurisdictions, have not yet developed a substantial body of case law specifically addressing AI agent liability. The general principles of fault-based tort apply, but claimants face practical evidentiary challenges. The Mata v. Avianca case (Southern District of New York, 2023), while not a Spanish case, illustrates the legal consequences of AI-generated output causing harm in a professional context: the court imposed sanctions on the lawyer who filed the AI-generated brief containing fabricated citations without verification. Spanish courts would likely reach an analogous result under general professional liability principles. The Moffatt v. Air Canada case (British Columbia Civil Resolution Tribunal, 2024) illustrates the principle that an operator cannot disclaim liability for their AI agent's statements to customers: the deployer, not the AI system, bears the legal obligation. Spanish consumer law and general civil liability principles support the same conclusion.

Product liability under the LGDCU and the revised PLD

Spain's existing product liability framework sits in the Real Decreto Legislativo 1/2007 approving the consolidated text of the Ley General para la Defensa de los Consumidores y Usuarios, which carries the transposition of the original Product Liability Directive 85/374/EEC. An earlier version of this guide attributed this to Ley 3/2022; Ley 3/2022 of 24 February 2022 is the Ley de convivencia universitaria, a university conduct statute, and the citation was wrong. Under the existing framework, software and AI systems have generally not been treated as products for product liability purposes in Spain, leaving harm from AI outputs within the fault-based tort framework.

This will change on 9 December 2026, when Directive (EU) 2024/2853 (the revised Product Liability Directive) must be transposed into Spanish law. The revised PLD expressly includes software and AI systems within the definition of product. It applies to products placed on the market or put into service after 9 December 2026. Under the revised PLD, a Spanish claimant will benefit from rebuttable presumptions of defectiveness: where the defendant has not complied with EU-law safety obligations (which include the EU AI Act), or where the technical complexity of the system makes it excessively difficult for the claimant to prove the defect, the burden of proof shifts toward the defendant. The revised PLD also expands the categories of compensable damage to include data loss and medically recognised psychological harm, alongside existing categories of physical and property damage.

The practical consequence for operators placing AI agents on the Spanish market after 9 December 2026 is a materially more demanding civil liability landscape. Non-compliance with the AI Act not only risks administrative penalties from AESIA: it also creates a rebuttable presumption of product defect in civil litigation. The two regimes reinforce each other, and compliant documentation built for AESIA purposes (risk management under Article 9, technical documentation under Articles 16 and 17, incident records under Articles 12 and 73) is simultaneously the evidence base for defending product liability claims.

Contractual liability in B2B deployments

Many AI agents are deployed by a business operator as part of a service delivered to business clients. In these B2B contexts, the contractual framework between the operator and its client allocates liability risk as between the two parties. Spanish contract law under the Codigo Civil and the Codigo de Comercio governs these allocations. Standard AI vendor contracts typically attempt to limit the vendor's liability for AI outputs, exclude consequential loss, and require the deployer customer to use the system in accordance with instructions. These provisions are enforceable between commercial parties under Spanish law (unlike B2C contexts, where consumer protection rules limit exclusion clauses under the LGDCU). Operators on both sides of a B2B AI contract should review their liability allocation in light of the AI Act's deployer obligations: an operator who breaches Article 26 deployer duties cannot simply pass liability to the AI provider where the breach arises from the deployer's own conduct.

Insurance for AI operators in Spain

The commercial insurance market for AI agent liability in Europe is at an early and developing stage. Spanish operators face the same market structure as their counterparts in other EU Member States. No Spanish-specific AI liability product exists as a domestic policy class. Spanish-domiciled operators access the international AI insurance market through the same channels as other European operators.

The instruments available include Munich Re aiSure (performance-based cover, settling on measurable performance data rather than fault-based claims); Armilla, a Lloyd's of London coverholder offering AI liability and performance cover; HSB (Hartford Steam Boiler, Munich Re group), which has offered affirmative AI and algorithmic-risk cover to SMEs; and cover structured around the AIUC-1 standard, which sets out adversarial evaluation benchmarks across data and privacy, safety, security, reliability, accountability, and societal impact. The ElevenLabs policy announced on 12 February 2026 was the first coverage instance backed by the AIUC-1 standard for AI voice agents.

EIOPA's Opinion on Artificial Intelligence governance and risk management (EIOPA-BoS-25-360, published 6 August 2025) is addressed to national competent authorities in the insurance sector, including Spain's DGSFP (Dirección General de Seguros y Fondos de Pensiones). The Opinion does not create new insurance coverage requirements for policyholders but signals that European insurance supervisors expect insurers to address AI governance risk in their own underwriting frameworks. The practical implication is that insurers writing AI liability risks in Spain are likely to increase their documentation requirements for AI governance evidence as the market matures.

For operators preparing to approach the market for AI liability cover, the documentation built for AESIA compliance purposes is the core of the underwriting submission. The risk classification under Annex III, the Article 9 risk management record, the Article 14 human oversight mechanism, and the Article 73 incident reporting register are the primary evidence an underwriter will seek to assess the risk.

What operators deploying AI in Spain should do now

The regulatory environment in Spain is more defined than in most EU Member States because AESIA is operational and has published comprehensive guidance. The compliance pathway for operators is well-mapped.

The first step is classification. Every AI system the operator deploys should be assessed against Article 5, which prohibits outright, Annex III for high-risk with the full deployer obligations, Article 50 for transparency, and the GPAI provisions where the system is built on a general-purpose model. Guide 02, the practical guide with examples, is the most useful starting point.

The second step is to deal with what is enforceable now rather than what is deferred. Article 50 transparency obligations have applied since 2 August 2026: any chatbot or conversational agent must clearly and timely inform users that they are interacting with an AI system, and synthetic audio, image, video and certain published text must be marked. The Article 50(2) machine-readable marking transitional period for systems already on the market ends on 2 December 2026.

For Annex III systems, build the Article 26 posture against 2 December 2027 rather than treating the deferral as a reason to stop. The core elements are unchanged: a record of the provider's instructions for use and confirmation that the system is being used in accordance with them; a Fundamental Rights Impact Assessment under Article 27 where the use context requires one; a named human oversight arrangement under Article 14 with documented competence and intervention authority; an incident monitoring and reporting procedure under Article 73; and the Article 12 logging record where it is within the operator's technical control.

Do not plan on the sandbox. Spain's pilot has closed, and the Article 57 obligation to operate at least one now runs to 2 August 2027. For a genuinely borderline classification, the published sandbox results and the guides are what is available in the meantime.

For operators building commercial insurance into their risk management approach, the coverage gap between existing professional indemnity and cyber policies and AI-specific liability exposure should be mapped against the Annex III classification of the specific system. AI-specific endorsements and the emerging dedicated AI liability products from carriers including Munich Re, Armilla, and HSB provide the clearest route to affirmative coverage, with ISO/IEC 42001 certification increasingly used as an underwriting benchmark for governance maturity.

Frequently asked questions

What is AESIA and why does it matter for operators in Spain?

AESIA, the Agencia Espanola de Supervision de la Inteligencia Artificial, was created by Real Decreto 729/2023 of 22 August 2023, BOE-A-2023-18911, published on 2 September 2023, with its seat in A Coruna. It was the first standalone national AI body in the EU. It is not yet formally designated as Spain's national competent authority under Article 70 of Regulation (EU) 2024/1689: no BOE instrument makes that designation, AESIA's own guides page still refers to potential national competent authorities, and the designating instrument is the organic law still before Congress. Spain also has no domestic AI sanctioning procedure in force. AESIA is nonetheless the right first contact and the publisher of the sixteen compliance guides.

Which EU AI Act obligations apply to deployers in Spain right now?

Article 5 prohibited practices and Article 4 AI literacy obligations have applied since 2 February 2025. GPAI model obligations under Chapter V have applied since 2 August 2025, as has the whole of Chapter XII containing the Article 99 penalty regime. Article 50 transparency obligations applied from 2 August 2026 and are in application now. Annex III high-risk deployer obligations under Article 26 were deferred by Regulation (EU) 2026/1744 to 2 December 2027, and Annex I obligations to 2 August 2028. The new Article 5 prohibitions on child sexual abuse material and non-consensual intimate imagery take effect on 2 December 2026.

What are the deployer obligations under Article 26?

Deployers of high-risk AI systems under Annex III must: use the system in accordance with the provider's instructions; implement technical and organisational measures for compliant use; assign a competent human oversight person under Article 14; conduct a Fundamental Rights Impact Assessment under Article 27 in relevant contexts; maintain logs under Article 12 where technically feasible; monitor the system and report serious incidents under Article 73; and inform individuals subject to consequential decisions.

What is Spain's Organic Law on AI governance, and is it law?

Not yet. The anteproyecto was approved at first reading by the Council of Ministers on 11 March 2025. The proyecto de ley organica was approved for transmission on 26 May 2026, presented to the Congreso on 28 May, and published in the Boletin Oficial de las Cortes Generales as A-97-1 on 12 June 2026 under expediente 121/000096. It is in the Comision de Economia, Comercio y Transformacion Digital in the amendment phase, with the deadline extended to 2 September 2026. It would designate AESIA as single point of contact alongside sectoral authorities including the AEPD and the Consejo General del Poder Judicial, implement the sanctioning regime in Spanish administrative law with a muy grave, grave and leve structure, create a public-sector AI inventory and a delegado de IA, and give AESIA the Article 57 sandbox.

Can I still apply to Spain's AI regulatory sandbox?

No. The Spanish AI sandbox, established by Real Decreto 817/2023 of 8 November 2023 and run by the Secretaria de Estado de Digitalizacion e Inteligencia Artificial rather than by AESIA, ran a single call from 23 December 2024 to 30 January 2025 and selected up to twelve high-risk systems. On 1 July 2026 digital.gob.es recorded that it has finished, and published its conclusions. The bill before Congress would give AESIA the Article 57 sandbox in future. The Omnibus moved the deadline for each Member State to operate at least one sandbox to 2 August 2027.

What is the liability exposure if an AI agent causes harm to a customer in Spain?

Current liability operates through Articles 1902 to 1910 of the Codigo Civil (fault-based tort) and existing product safety law. From 9 December 2026, the revised Product Liability Directive (EU) 2024/2853 applies to AI systems placed on the market after that date, introducing rebuttable presumptions of defectiveness and expanding compensable damage to include data loss and medically recognised psychological harm. Non-compliance with the AI Act creates a presumption of product defect under the revised PLD.

How does AESIA coordinate with the AEPD?

AESIA is intended to supervise AI Act obligations and the AEPD supervises GDPR compliance, and most AI systems processing personal data engage both. No formal cooperation protocol between them could be found at aesia.digital.gob.es, digital.gob.es or aepd.es, and the official description of the bill presents inter-authority coordination as something the bill will create. Operators should still build both records: a Fundamental Rights Impact Assessment under Article 27 of the AI Act and a Data Protection Impact Assessment under Article 35 GDPR. The most on-point AEPD material is its guidance on agentic artificial intelligence from the data protection perspective, of 18 February 2026.

What are the penalties for AI Act violations in Spain?

Article 99 of the EU AI Act sets the ceilings: up to EUR 35 million or 7 per cent of total worldwide annual turnover for Article 5 prohibited practices, EUR 15 million or 3 per cent for other operator obligations, and EUR 7.5 million or 1 per cent for supplying incorrect, incomplete or misleading information, whichever figure is higher in each case, with the lower figure applying to SMEs and start-ups. Spain has no domestic AI sanctioning procedure in force: under Ley 40/2015 an administrative sanctioning power requires a statute defining infringements, penalties and procedure, and the organic law that would supply it is still in committee. That bill would add a Spanish band with no Article 99 equivalent, of up to EUR 500,000 or 0.5 per cent of turnover for the least serious infringements.

What insurance options are available to AI operators in Spain?

Spanish operators access the international AI insurance market. Available instruments include Munich Re aiSure (performance-based cover written with Mosaic Insurance at an initial capacity of EUR, USD or CAD 15 million), Armilla (Lloyd's of London coverholder, affirmative AI liability insurance with limits up to USD 25 million per organisation), HSB (a standalone AI liability product for small and medium-sized businesses launched 18 March 2026 in the United States), and coverage structured around AIUC-1, the standard published by the Artificial Intelligence Underwriting Company that carried the ElevenLabs voice agent policy of 12 February 2026. Governance documentation built for AESIA compliance forms the core of any underwriting submission.

What practical steps should an operator in Spain take now?

Classify all AI systems against Article 5, Annex III and Article 50. Deal first with what is already enforceable: Article 50 disclosure for chatbots and conversational agents, and marking of synthetic content, with the machine-readable marking transitional period ending 2 December 2026. For Annex III systems, build the Article 26 posture against 2 December 2027: work through guides 05, 07, 08, 06 and 14 and the guide 16 checklists, appoint a human oversight person under Article 14, complete a Fundamental Rights Impact Assessment under Article 27 where required, and establish incident reporting under Article 73. Do not plan on the sandbox, which has closed. Map the insurance gap with your governance documentation ready.

References

  1. Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 laying down harmonised rules on artificial intelligence (EU AI Act). Official Journal of the European Union, 12 July 2024. Article 99 penalty tiers verified at the EU AI Act Service Desk.
  2. Regulation (EU) 2026/1744, the Digital Omnibus on AI. Proposed 19 November 2025 as COM(2025) 836, political agreement 7 May 2026, entered into force 27 July 2026. Annex III deferred to 2 December 2027, Annex I to 2 August 2028. digital-strategy.ec.europa.eu.
  3. Real Decreto 729/2023, de 22 de agosto, por el que se aprueba el Estatuto de la Agencia Espanola de Supervision de Inteligencia Artificial. BOE num. 210, 2 September 2023, BOE-A-2023-18911, in force 3 September 2023. Article 2 sets the seat in A Coruna.
  4. Orden TDF/774/2025, de 11 de julio, delegating competences to AESIA, BOE-A-2025-15133, and the Resolucion of 25 August 2025 on internal delegation, BOE-A-2025-18640.
  5. Real Decreto 817/2023, de 8 de noviembre, establishing a controlled testing environment for artificial intelligence. BOE num. 268, 9 November 2023, BOE-A-2023-22767. Single call opened by SEDIA resolution of 20 December 2024, applications 23 December 2024 to 30 January 2025, up to twelve high-risk systems selected. digital.gob.es recorded on 1 July 2026 that the sandbox has finished.
  6. AESIA, sixteen support guides for compliance with the AI Regulation, at aesia.digital.gob.es/es/guias and /en/guides, developed within the Spanish AI regulatory sandbox pilot and described by digital.gob.es as technical guides prepared by the Secretaria de Estado de Digitalizacion e Inteligencia Artificial. No publication date is stated on the guides page.
  7. Consejo de Ministros, 11 March 2025, approving the Anteproyecto de Ley para el buen uso y la gobernanza de la Inteligencia Artificial at first reading with urgent processing. Consejo de Ministros, 26 May 2026, approving the Proyecto de Ley Organica for transmission to the Congreso. lamoncloa.gob.es.
  8. Congreso de los Diputados, Proyecto de Ley Organica para el buen uso y la gobernanza de la inteligencia artificial, expediente 121/000096, presented 28 May 2026, published BOCG Congreso num. A-97-1 of 12 June 2026, in the Comision de Economia, Comercio y Transformacion Digital with the amendment deadline extended to 2 September 2026. congreso.es.
  9. Consejo General del Poder Judicial, Instruccion 2/2026 de 28 de enero de 2026 on the use of artificial intelligence systems in jurisdictional activity, BOE num. 27, 30 January 2026.
  10. Agencia Espanola de Proteccion de Datos, "Inteligencia artificial agentica desde la perspectiva de la proteccion de datos", 18 February 2026; "Exactitud, idoneidad y calidad de los datos en tratamientos de datos personales con Inteligencia Artificial", 21 July 2026; "El uso de imagenes de terceros en sistemas de inteligencia artificial", 13 January 2026; joint AEPD and EDPS report on AI and data protection, 10 June 2025. aepd.es.
  11. Directive (EU) 2024/2853 of the European Parliament and of the Council on liability for defective products. Official Journal of the European Union, 18 November 2024. Transposition deadline 9 December 2026.
  12. EIOPA Opinion on Artificial Intelligence governance and risk management, published 6 August 2025. eiopa.europa.eu. The internal reference number EIOPA-BoS-25-360 is not shown on EIOPA's publication page and is not asserted here.
  13. Real Decreto Legislativo 1/2007 approving the consolidated text of the Ley General para la Defensa de los Consumidores y Usuarios, carrying the transposition of Directive 85/374/EEC. Note that Ley 3/2022, de 28 de febrero, is the Ley de convivencia universitaria and is not a product liability instrument.
  14. Ley Organica 3/2018, de 5 de diciembre, de Proteccion de Datos Personales y garantia de los derechos digitales (LOPDGDD). BOE-A-2018-16673.
  15. Ley 40/2015, de 1 de octubre, de Regimen Juridico del Sector Publico, under which an administrative sanctioning power requires a statute defining infringements, penalties and procedure.
  16. Moffatt v. Air Canada, 2024 BCCRT 149, British Columbia Civil Resolution Tribunal. Mata v. Avianca Inc., 22-cv-1461 (S.D.N.Y. 2023). Both non-Spanish, cited by analogy only.
  17. ISO/IEC 42001:2023, Information technology, Artificial intelligence, Management system.