The AI regulation in Spain: what already applies, what has been postponed and what carries no penalty

The AI regulation in Spain: what already applies, what has been postponed and what carries no penalty

The July 2026 Omnibus rewrote the timetable of the European AI regulation and almost everything published still cites the 2024 text. This is what applies today to a Spanish company, with the new dates.

· AI and data compliance

If you have looked up what the European artificial intelligence regulation requires of you, almost everything you have read is out of date. And not by a little: Regulation (EU) 2026/1744, known as the Digital Omnibus on AI, was approved on 8 July 2026, published in the Official Journal on 24 July and entered into force on the 27th. It amends Regulation (EU) 2024/1689 and changes the timetable. Any analysis citing only the 2024 text — which is most of them — no longer holds.

This is the real state of play today.

The timetable, after the Omnibus

  • Prohibited practices (art. 5): in force since 2 February 2025. The Omnibus adds two new prohibitions.
  • AI literacy (art. 4): in force since 2 February 2025, but softened: where it used to say «ensure» a sufficient level of competence, it now says «adopt measures».
  • Transparency (art. 50): applicable from 2 August 2026, with four transitional months for systems already on the market. In other words: this is already in force.
  • High risk under Annex III: postponed to 2 December 2027. It had been due in August 2026.
  • High risk under Annex I: postponed to 2 August 2028.

Translated: what was about to land on companies — the high-risk block — has moved back more than a year. What has just arrived is transparency.

What applies today to an ordinary Spanish company

The first thing is to place yourself. A company that uses AI tools bought from third parties is a deployer, not a provider. The burden is far lighter: the bulk of the regulation falls on whoever builds and markets the system.

For the deployer, in practice:

Transparency (art. 50), already in force

If the customer is interacting with a machine, they have to be told. If you publish AI-generated content, it has to be identified as such. With one exception that changes a lot of people's lives: art. 50.4 exempts published text from labelling where there has been human review and somebody takes editorial responsibility. That is, a corporate blog drafted with AI help and reviewed by an identifiable person does not need a stamp on every article.

And another one hardly anybody knows: private documents sent to a client — a report, a set of submissions, a return — do not fall under art. 50. The transparency in art. 50 is about content addressed to the public and about interaction with people, not about a professional document handed to whoever hired you.

Literacy (art. 4), in force but not penalised

Measures have to be adopted so that whoever handles these tools knows what they are doing. That said, here is the fact no consultancy selling emergency courses will tell you: art. 4 is not among those carrying penalties. Art. 99.4 lists exhaustively the provisions whose breach is fined — 16, 22, 23, 24, 26, 31, 33, 34 and 50 — and 4 is not there.

That does not mean training the team is irrelevant: it means that anybody selling you training on the grounds that you will be fined otherwise is selling with a false argument.

Prohibitions (art. 5)

Here the fines are serious, but the prohibited practices — subliminal manipulation, social scoring, biometric categorisation of certain traits — are a long way from what an ordinary company does. The realistic high-risk case for a small business would be screening CVs with AI, which falls under Annex III.4… and that block does not apply until December 2027.

The fines, and the detail that changes the fright

The maximum figures are always quoted, and they run into tens of millions. For a small business or a sole trader there is a rule rarely mentioned: art. 99.6 provides that the lower of the turnover percentage and the fixed figure applies. The number that frightens people in the headlines is the ceiling for a multinational, not for a five-person practice.

And in Spain, who enforces it?

This is the part that causes most confusion. It is a European regulation: it applies directly, with no need for Spanish legislation. What is missing in Spain is not the rule, it is the national enforcement machinery.

The AI governance bill (121/000096) has still not been passed: it remains at the amendment stage in committee, with the deadline extended to 2 September 2026. AESIA has existed since Real Decreto 729/2023, but Orden TDF/774/2025 only delegates budgetary powers to it: still no market surveillance and no power to impose penalties.

Practical conclusion: today the real enforcement risk from the AI regulation in Spain is low, and anybody telling you otherwise is selling urgency.

So what should you actually worry about?

The GDPR. The Spanish data protection agency is fully operational, has been imposing fines for years and reaches 20 million euros or 4 % of turnover. The day somebody on your team pastes a client list with their tax numbers into an AI chat, the problem is not the AI regulation: it is a disclosure of personal data to a third party with no legal basis, no processor contract and probably an international transfer.

And if your activity is professional — a practice, an advisory firm, a clinic — on top of that there is the professional secrecy in art. 5 of the LOPDGDD, which is not lifted for convenience.

We have developed it in using AI with customer data within the law, which is the part that does have consequences today.

What to do this month, in order

  1. Take an inventory of which AI tools are already used in the company. There are nearly always more than the manager thinks.
  2. Review the contract for each one: whether it trains on your data, how long it keeps it, where the servers are.
  3. Comply with art. 50 where it applies: if there is a chatbot, it identifies itself as a machine.
  4. Put in writing who may use what and what information never leaves.
  5. Document it. Faced with an inspection, doing it right without being able to prove it is worth the same as not doing it.

If this sounds like you

This work is not a months-long project and does not require buying software: it is inventory, contracts, four documents and an internal policy that fits on one page. We do it in AI and data protection compliance, and if what you need is for the team to finally understand what they can and cannot do with these tools, that goes separately in AI training.

We are Mindset & Code: automation, data and development for small businesses. We work on the compliance side of the systems we build, which is why this article cites the regulation number and the Official Journal date instead of repeating headlines. You can see what we do and what it costs, published one by one.

Sources: Regulation (EU) 2024/1689 on artificial intelligence; Regulation (EU) 2026/1744 (Digital Omnibus on AI), Official Journal of 24 July 2026, in force on 27 July 2026; Real Decreto 729/2023 and Orden TDF/774/2025 (AESIA); ley 121/000096 currently before parliament. Verified at official source on 11 August 2026. General guidance; it does not replace legal advice.