Skip to main content
IASeptember 29, 202611 min

EU AI Act: A Practical Guide for Spanish Companies in 2026

Prohibited practices and AI literacy already apply; high-risk obligations move to 2027–2028 under the Digital Omnibus. How to classify your systems and what to do now.

Gorka GonzaloFounder & CEO
Isometric illustration: AI systems sorted into four risk tiers along a regulatory timeline

Part of the EU AI Act already applies and, after this summer's reform, high-risk obligations now fall due in 2027 and 2028. This guide sets out, as of September 2026, what it requires, how to classify your systems and what to do now.

What the AI Act is and who it applies to

Regulation (EU) 2024/1689, known as the AI Act, was published in the Official Journal of the EU on 12 July 2024 and entered into force on 1 August 2024 [1]. As a regulation, it applies directly in Spain without a transposition law, although each Member State designates its authorities and sets out its penalty regime.

Obligations depend on the risk of the use an AI system is put to and on the role each company plays in the value chain. Article 3 defines the main roles [1]:

  • Provider: develops an AI system or model, or has one developed, and places it on the market or puts it into service under its own name or trademark. Carries most high-risk obligations (Art. 16).
  • Deployer: uses an AI system under its authority in a professional activity. This is the most common role for Spanish companies, and it has its own obligations (Art. 26).
  • Importer: established in the EU, places on the market a system from a provider outside the Union.
  • Distributor: any other actor in the supply chain that makes the system available on the market.

The scope is extraterritorial: it covers non-EU providers placing systems on the Union market and third-country operators whose system output is used in the EU (Art. 2) [1]. Your foreign vendors are in scope too.

At Hodeitek we often see the same company holding different roles for different systems: deployer of the AI assistant it buys and provider of the scoring model it offers to clients. The analysis is done system by system.

The real timeline as of September 2026

Since 2 February 2025, the general provisions, including AI literacy (Art. 4), and the prohibited practices (Art. 5) have applied [1] [2]. Since 2 August 2025, so have the rules on general-purpose AI models, governance, penalties (Arts. 99 and 101) and notified bodies [1].

On 19 November 2025 the Commission proposed the Digital Omnibus on AI. The Council adopted it on 29 June 2026 [4]; it was published on 24 July as Regulation (EU) 2026/1744 and has been in force since 27 July 2026 [3] [5]. Its main changes:

  • Annex III high-risk (employment, credit, education…): postponed to 2 December 2027.
  • Annex I high-risk (AI in regulated products): postponed to 2 August 2028, linked to the availability of technical standards.
  • AI literacy: softened; Article 4 now speaks of supporting its development rather than ensuring a sufficient level.
  • Simplified registration, and simplified technical documentation extended to small mid-cap companies (Recommendation (EU) 2025/1099).
  • AI Office with consolidated powers over systems built on general-purpose models from the same provider and over AI in very large online platforms and search engines.
  • New prohibited practice: generating non-consensual intimate imagery and child sexual abuse material.
DateWhat happensStatus
1 Aug 2024Regulation enters into force [1]Done
2 Feb 2025General provisions, AI literacy and prohibited practices [1] [2]Applicable
2 Aug 2025General-purpose models, governance, penalties [1]Applicable
27 Jul 2026Omnibus enters into force [3]Applicable
2 Aug 2026Transparency obligations (Art. 50) [7]Applicable
2 Dec 2026Marking and detection of generated content (Art. 50.2) for generative systems placed on the market before 2 Aug 2026 [7]Pending
2 Dec 2027Annex III high-risk [3]Pending
2 Aug 2028Annex I high-risk [3]Pending

The Commission has already issued guidelines on prohibited practices (C(2025) 884) and on the definition of an AI system, plus a Code of Practice for general-purpose models (July 2025) [6]. The Article 6 high-risk guidelines, due in February 2026, were published in draft on 19 May 2026; check whether a final version is out. And although CEN-CENELEC sped up standardisation in October 2025 [8], as of June 2026 no harmonised standard had been cited in the Official Journal: there is not yet any presumption of conformity based on standards.

How to classify your systems by risk

The AI Act classifies by intended purpose and context of use, not by technology: the same model can be minimal-risk in one process and high-risk in another.

Prohibited (Art. 5). Harmful manipulation; exploitation of vulnerabilities; social scoring; predicting offending based solely on profiling; untargeted scraping of facial images; emotion inference in the workplace and education (with narrow exceptions); biometric categorisation of sensitive data; and real-time remote biometric identification for law enforcement, save for exceptions [1]. The Omnibus adds the new practice above [3].

High risk (Art. 6). Two routes [1]: Annex I, AI in products subject to third-party conformity assessment (machinery, toys, lifts, medical devices…), and Annex III, uses in biometrics, critical infrastructure, education, employment, access to essential services (creditworthiness, life and health insurance), law enforcement, migration, and justice and democratic processes. Article 6(3) excludes Annex III systems that only perform a narrow procedural task, improve a previously completed human activity, detect patterns without replacing human assessment, or perform a preparatory task — never where they profile natural persons, and the provider must document it. High-risk systems must meet Articles 9 to 15: risk management, data governance, technical documentation, logs, transparency, human oversight, and accuracy, robustness and cybersecurity.

Transparency (Art. 50). Chatbots, emotion recognition or biometric categorisation, deepfakes, and AI-generated text on matters of public interest [1] [7]. These obligations apply since 2 August 2026, with a grace period until 2 December 2026 only for the marking and detection of content (Art. 50.2) of generative systems already placed on the market before 2 August 2026 [7]; content generated before 2 August 2026 does not need to be marked retroactively [7].

Minimal risk. Everything else. General-purpose models follow their own track (Arts. 53 to 55) [1].

Typical use caseIndicative classification
CV screening or candidate assessmentHigh risk (Annex III, employment)
Creditworthiness assessment of individualsHigh risk (+ FRIA in banking)
Life and health insurance pricingHigh risk (+ FRIA)
Inferring employees' emotionsProhibited
AI as a safety component of a machineHigh risk (Annex I)
Customer-service chatbotTransparency
Synthetic images or video for campaignsTransparency
Internal copilot for drafting or summarisingUsually minimal
Alert classifier in an in-house SOCUsually outside Annex III

It is indicative: the copilot that drafts emails changes category if it is used to decide promotions. We analyse the SOC case in how AI is transforming threat detection.

What to do now

The postponement is no invitation to start in 2027: documentation, risk management and human oversight are designed into the system.

  1. AI system inventory. Per system: description and purpose; business area and internal owner; origin (in-house, SaaS, API, embedded AI) and underlying model; the company's role; data processed; affected persons; decision supported and degree of automation; classification and rationale; human oversight; logs; vendor contract; review date. AI embedded in tools you already use is usually what is missing.
  2. Role per system. Provider, deployer, importer or distributor: this sets which articles apply.
  3. Prohibited-practices review. Already applicable and carrying the highest fines. Watch emotion analysis at work and biometric uses.
  4. AI literacy. Even with Article 4 softened, without training there is no effective human oversight. Tier it: leadership, users, technical teams.
  5. Vendors and contracts. Declared classification, instructions for use, known limitations, access to logs, notice of incidents and changes, and a compliance commitment.
  6. Governance. An owner, an AI use policy and a risk register, built into the existing risk or security committee.
  7. High-risk documentation. If you develop an Annex III system, start on Articles 9 to 11 now; if you buy one, ask for the conformity plan.
  8. FRIA. The fundamental rights impact assessment (Art. 27) falls to public bodies, private entities providing public services and anyone using AI to assess creditworthiness or price life and health insurance [1].
  9. Logging and human oversight. Sufficient logs, and people with the authority to intervene in or stop the system.
  • Complete inventory, including embedded AI
  • Role documented per system
  • Prohibited practices ruled out in writing
  • Tiered AI literacy programme
  • AI clauses in contracts
  • Owner, policy and risk register approved
  • High-risk documentation plan
  • FRIA identified where applicable
  • Logs and human oversight verified

Our AI governance and security solution starts precisely from inventory and classification.

Spain: AESIA, a bill in Parliament and the sandbox

The Spanish Agency for the Supervision of Artificial Intelligence (AESIA), whose Statute was approved by Royal Decree 729/2023 [10], is based in A Coruña, has operated in person since 14 February 2025 and is attached to the Secretariat of State for Digitalisation and Artificial Intelligence.

In May 2026 the Council of Ministers approved the Organic Bill on the proper use and governance of artificial intelligence (Proyecto de Ley Orgánica para el buen uso y la gobernanza de la inteligencia artificial) [11], published in the Official Gazette of the Cortes Generales in June [12]. At the time of publication, and according to the information available, it is still going through Parliament and is not law. The text sent to Parliament designates AESIA, the AEPD (data protection agency) and the CGPJ (General Council of the Judiciary) as authorities in their areas, and provides for proportionate penalties, testing environments, public-sector transparency and a single complaints channel. Spain also has a regulatory sandbox (Royal Decree 817/2023), in which 12 high-risk systems were selected in April 2025.

Penalties. Article 99 sets maximums of €35 million or 7% of worldwide turnover for prohibited practices; €15 million or 3% for most obligations; and €7.5 million or 1% for incorrect information; for SMEs and start-ups, the lower amount applies [1]. The Commission fines general-purpose model providers up to €15 million or 3% (Art. 101) [9]. Spain's specific regime depends on the bill in Parliament.

How it fits with GDPR, NIS2, DORA and cybersecurity

GDPR. Where personal data is involved, both apply. Article 10(5) allows special categories of data to be processed, under strict safeguards, to correct bias in high-risk systems [1]. A FRIA is not a DPIA: it covers rights beyond privacy; they are separate documents that should be coordinated.

NIS2, DORA and Article 15. Article 15 requires appropriate accuracy, robustness and cybersecurity for high-risk systems [1] and is designed to interlock with NIS2, DORA and the Cyber Resilience Act. An ISO 27001, ENS or NIS2 programme gives a head start: asset inventory, risk methodology, vendor management, monitoring, incident management and change control. What remains is extending it to AI and adding AI-specific threats such as data poisoning or prompt injection, which is what we work on in our AI security consulting service.

Frequently asked questions

Is the AI Act already mandatory for my company? Partly. Prohibited practices and AI literacy have applied since 2 February 2025; rules on general-purpose models, governance and penalties since 2 August 2025; and transparency obligations under Article 50 since 2 August 2026. After the Digital Omnibus, high-risk obligations arrive on 2 December 2027 (Annex III) and 2 August 2028 (Annex I).

Does using a commercial generative AI assistant make me a provider? Usually not: if you use a third party's system under your authority, you are a deployer. You are a provider if you develop it, or have it developed, and place it on the market under your name. Risk depends on use: drafting emails is usually minimal-risk; selecting candidates may be high-risk.

What did the Digital Omnibus change? Regulation (EU) 2026/1744, in force since 27 July 2026, postpones high-risk obligations to December 2027 (Annex III) and August 2028 (Annex I), softens AI literacy, simplifies registration, extends simplified documentation to small mid-cap companies, and prohibits generating non-consensual intimate imagery and child sexual abuse material.

Who supervises the AI Act in Spain? AESIA, based in A Coruña and attached to the Secretariat of State for Digitalisation and AI. The Organic Bill on the proper use and governance of AI splits supervision between AESIA, the AEPD and the CGPJ, but at the time of publication it is still going through Parliament.

What penalties does the AI Act provide for? Up to €35 million or 7% of worldwide turnover for prohibited practices; €15 million or 3% for most obligations; and €7.5 million or 1% for incorrect information. For SMEs and start-ups, the lower amount applies. Spain's specific regime depends on the bill currently in Parliament.

Does a FRIA replace the GDPR impact assessment? No. The FRIA (Art. 27) is carried out by public bodies, private entities providing public services and those using high-risk AI to assess creditworthiness or price life and health insurance, and it covers rights beyond privacy. The DPIA remains required where applicable; the sensible approach is to coordinate them.

Conclusion

The high-risk postponement is breathing room, not a pause. The systems designed today are the ones that will have to comply in 2027 and 2028. A company that knows which AI it uses, in what role and at what risk has already solved the hardest part. If you want a second view on your starting point, talk to our team.

This article is for information only and does not constitute legal advice. It reflects the position as of September 2026 and will be updated when the consolidated text after the Omnibus, the final Article 6 guidelines and the Spanish law are published.

Sources

  1. Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 (Artificial Intelligence Act), EUR-Lex — https://eur-lex.europa.eu/eli/reg/2024/1689/oj
  2. European Commission, AI Watch — First rules of the Artificial Intelligence Act are now applicable (2 February 2025) — https://ai-watch.ec.europa.eu/news/first-rules-artificial-intelligence-act-are-now-applicable-2025-02-02_en
  3. Regulation (EU) 2026/1744 (Digital Omnibus on AI), EUR-Lex — https://eur-lex.europa.eu/eli/reg/2026/1744/oj/eng
  4. Council of the EU — Artificial intelligence: Council gives final green light to simplify and streamline rules (29 June 2026) — https://www.consilium.europa.eu/en/press/press-releases/2026/06/29/artificial-intelligence-council-gives-final-green-light-to-simplify-and-streamline-rules/
  5. European Parliament, Legislative Train — Digital omnibus on AI — https://www.europarl.europa.eu/legislative-train/package-digital-package/file-digital-omnibus-on-ai
  6. European Commission — General-Purpose AI Code of Practice — https://digital-strategy.ec.europa.eu/en/policies/contents-code-gpai
  7. European Commission — FAQ: transparency obligations under Article 50 — https://digital-strategy.ec.europa.eu/en/faqs/transparency-obligations-under-article-50-ai-act
  8. CEN-CENELEC — AI standardisation (23 October 2025) — https://www.cencenelec.eu/news-events/news/2025/brief-news/2025-10-23-ai-standardization/
  9. European Commission, AI Act Service Desk — Article 101 — https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-101
  10. España Digital — Statute of the Spanish Agency for the Supervision of Artificial Intelligence approved — https://espanadigital.gob.es/en/actualidad/aprobado-el-estatuto-de-la-agencia-espanola-de-supervision-de-la-inteligencia-artificial
  11. Spanish Ministry for Digital Transformation and Civil Service — Press release on the approval of the Bill (May 2026) — https://digital.gob.es/comunicacion/notas-prensa/mtdfp/2026/05/el-gobierno-aprueba-el-proyecto-de-ley-que-garantizara-una-super
  12. Congreso de los Diputados — BOCG, Series A, No. 97-1 (15th Legislature) — https://www.congreso.es/public_oficiales/L15/CONG/BOCG/A/BOCG-15-A-97-1.PDF

Self-check your AI governance

Classify your AI systems by AI Act risk level and spot governance gaps, in 2 minutes.

Take the self-check

Was this article useful?

Gorka Gonzalo

Founder & CEO

Founded Hodeitek in 2023 and runs the company. A cybersecurity and AI expert, he sets the technical and product direction of HodeiShield and personally leads the most critical engagements.

Need help with this?

Request a meeting with our team and see how to apply it to your organization.

Request a meeting