Can AESIA Fine You Under the AI Act Today? The Short Answer Is No
TL;DR
- AESIA has existed since September 2023, but today it cannot impose a fine for breaching the AI Regulation. It lacks the law that typifies the infringements.
- That law is the Draft Organic Law on the sound use and governance of artificial intelligence (file 121/000096). It is still before Parliament: the amendment deadline was extended to 2 September 2026 and there is still no committee opinion or approval.
- The draft states this itself: "only a statutory instrument can typify infringements, graduate sanctions and confer sanctioning powers".
- When the law is passed, fines will reach €35 million or 7% of worldwide turnover. For SMEs, the lesser of the two figures will apply, not the greater.
- AESIA not being able to fine you does not mean you are safe. For the same AI uses, today you can be sanctioned by the AEPD (up to €20 million or 4% under the GDPR), the Labour Inspectorate or consumer protection authorities.
- And the EU Regulation already obliges, with or without a Spanish fine: prohibited practices apply from February 2025 and transparency obligations from 2 August 2026.
Where does the idea that AESIA already sanctions come from?
If you search "AI Act sanctions Spain" you will find dozens of pages claiming that the Spanish AI Supervisory Authority (AESIA) has been sanctioning since August 2025, complete with fine tables and headlines like "companies face €35 million". The figure is real. The timeline is not.
The source of the misunderstanding is a date in the EU Regulation: on 2 August 2025 its Chapter XII — the sanctions chapter — began to apply. But that chapter does not sanction anyone. What it does is order Member States to set up their own sanctioning regimes. Spain has not yet done so.
It is a boring distinction with very concrete consequences: if a vendor is selling you urgency with the argument that "AESIA is already fining", they are selling you with a false claim.
What is AESIA and what exactly can it do?
AESIA was created by Royal Decree 729/2023 of 22 August (Official State Gazette No. 210, of 2 September 2023), which approves its Statute. It entered into force on 3 September 2023 and is based in A Coruña.
Its functions are in Article 10 of the Statute. There, in paragraph 1(k), appears a reference to supervision and sanctioning powers — with a decisive qualifier: "in accordance with the provisions of European regulations".
In legal terms, that is a remissive authorisation. The Royal Decree says "AESIA will sanction in accordance with what the relevant regulation provides", but it does not define any infringement, set any amounts or establish any procedure. It cannot: a Royal Decree is a regulatory instrument, and Article 25 of the Spanish Constitution requires statutory rank to typify administrative infringements.
In plain terms: AESIA has the title, the office and the organisational chart. It does not have the catalogue of infringements.
What is missing, then?
What is missing is the Draft Organic Law on the sound use and governance of artificial intelligence, approved by the Council of Ministers on 26 May 2026. This is its actual progress, verifiable in the file record:
| Stage | Date |
|---|---|
| Approved by the Council of Ministers | 26 May 2026 |
| Submitted to Parliament | 28 May 2026 |
| Qualified by the Mesa | 8 June 2026 |
| Published in the BOCG (Series A, No. 97-1) | 12 June 2026 |
| End of initial amendment period | 30 June 2026, 18:00 |
| End of extended amendment period | 2 September 2026, 18:00 |
| Committee opinion | Not on record |
| Approval | Not on record |
The Mesa referred the opinion to the Committee on Economy, Commerce and Digital Transformation. Until that opinion exists — and then a full chamber debate, then the Senate, then publication in the Official State Gazette — there is no sanctioning regime.
The draft itself acknowledges this in its explanatory memorandum, at page 11: the law is necessary because "only a statutory instrument can typify infringements, graduate sanctions and confer sanctioning powers in accordance with the principles of legality, proportionality and legal certainty".
There is one more detail worth knowing, because it sets the real pace. Additional Provision 2 requires the Government, within a maximum of six months of the law entering into force, to transform AESIA into an entity under Article 84 of Law 40/2015, with its own legal personality and "full organisational and functional independence". In other words: when the law passes, the agency will still need to restructure itself internally.
And the law itself will enter into force the day after its publication in the Official State Gazette (Final Provision 8). No vacatio legis, no adaptation period. The day it is published, the catalogue of infringements becomes operational.
How much are we talking about when the law exists?
Article 30 of the draft sets these limits:
| Infringement type | Ceiling |
|---|---|
| Very serious — prohibited AI practice | Up to €35,000,000 or 7% of worldwide business volume |
| Very serious (other) | Up to €15,000,000 or 3% |
| Serious | Up to €7,500,000 or 1% |
| Minor | Up to €500,000 or 0.5% |
Now the nuance that almost no-one mentions, and which completely changes the reading for an SME. Under the general rule, the higher of the two figures applies. But Article 30.8 of the draft, following Article 99.6 of the EU Regulation, establishes that for SMEs and start-ups the lower figure will apply.
For a company of 40 employees billing €6 million, 1% of a serious infringement is €60,000, not €7.5 million. It still hurts. But it is a figure that can be discussed at a board meeting without the conversation becoming panic.
Two more things to add. First: in addition to the fine, Article 30.2 allows the withdrawal of the product or disconnection of the AI system where the authority resolves with reasoned justification that there is an unacceptable or serious risk. For a business that has embedded AI in its operations, switching it off can cost more than the sanction. Second: Article 16 of the draft typifies as a serious infringement, for any operator, resistance or obstruction during an inspection. In other words, the easiest way to turn a small file into an expensive one is to refuse to cooperate.
Does this mean the AI Act does not apply in Spain?
No. Regulation (EU) 2024/1689 is an EU regulation: it applies directly without the need for transposition. What is missing is the Spanish machinery to penalise its breach, not the obligation itself.
Moreover, the timetable shifted this summer. Regulation (EU) 2026/1744, the so-called Digital AI Omnibus, was published in the Official Journal of the EU on 24 July 2026 and has been in force since 27 July. It defers a large part of the high-risk obligations. This is the updated timetable:
| Block | Date of application |
|---|---|
| Prohibited practices (Art. 5) and AI literacy (Art. 4) | 2 February 2025 |
| General-purpose AI models, governance and the sanctions chapter | 2 August 2025 |
| General date of application, including Art. 50 transparency | 2 August 2026 |
| New prohibited practices added by the Omnibus (Art. 5.1 b bis and b ter) | 2 December 2026 |
| Machine-readable marking of synthetic content for systems already on the market (Art. 50.2) | 2 December 2026 |
| High-risk Annex III (Art. 6.2) | 2 December 2027 |
| High-risk Annex I (Art. 6.1) | 2 August 2028 |
If your company has a customer service chatbot, generates images or text with AI, or uses emotion recognition, the date that affects you is 2 August 2026, not 2027. The Article 50 transparency obligations have not been deferred.
The Omnibus also softened Article 4. It no longer requires "ensuring" AI literacy in your workforce, but "adopting measures to support" its promotion, and expressly clarifies that it does not require achieving a specific level in any particular individual. That is a genuine reduction in burden for SMEs.
And there is one exception to all of the above: the European Commission can fine directly, without going through any Spanish authority, the providers of general-purpose AI models — up to 3% of their worldwide turnover or €15 million (Article 101). That is aimed at whoever builds the model, not the SME that uses it.
So what can actually land on you today?
This is where the conversation becomes useful. The AI uses that cause the most problems for Spanish SMEs are already regulated by frameworks with a fully operational sanctioning regime:
| What you do with AI | Regulation already in force | Who sanctions | Ceiling |
|---|---|---|---|
| Training or feeding a system with customer data, CVs or employee data | GDPR (Regulation 2016/679) and LOPDGDD | AEPD and regional data protection authorities | €20M or 4% (Art. 83.5); €10M or 2% (Art. 83.4) |
| Screening candidates or assessing performance with algorithms | Workers' Statute, Art. 64.4(d) | Labour and Social Security Inspectorate | Labour sanctions regime |
| AI-generated or AI-manipulated advertising, prices or reviews | Consumer and unfair competition law | Regional consumer protection authorities | Consumer sanctions regime |
| Automated decisions with legal effects on individuals | GDPR, Art. 22 | AEPD | €20M or 4% |
The employment row deserves a separate paragraph, because it often catches people off guard. Since Law 12/2021 (Official State Gazette No. 233, of 29 September 2021), Article 64.4(d) of the Workers' Statute grants employee representatives the right to "be informed by the company of the parameters, rules and instructions on which the algorithms or artificial intelligence systems affecting decisions that may impact working conditions, access to and retention of employment, including the drawing up of profiles, are based".
That obligation has existed since 2021, does not depend on the AI Act and does not wait for any organic law. If you have a works council or employee delegates and have introduced AI into recruitment, shift allocation or performance evaluation without informing them, you are already in current non-compliance.
The draft law, incidentally, does not touch this: its Additional Provision 1 expressly confirms that the functions of the Labour Inspectorate remain intact.
What about AESIA's guidance documents? Are they binding?
AESIA published on 16 December 2025 a package of sixteen practical guides, plus a checklist compendium: two introductory, thirteen technical (conformity assessment, risk management, human oversight, data governance, transparency, accuracy, robustness, cybersecurity, records, post-market monitoring, incident management and technical documentation) and a usage manual.
They are good material and save work. But the agency itself warns that they "have no binding character and do not substitute or develop applicable legislation". The page also notes they will be updated once the Digital Omnibus is approved — so the versions you download now will change.
Use them as a working template. Do not cite them as if they were law.
Why preparing now costs less
Three practical reasons, without drama.
The law enters into force the day after publication. There is no national grace period, so the only adaptation margin is what you take before the Official State Gazette publishes it — not the time the Gazette gives you.
The inventory is the slow work. Finding out which AI tools are actually in your company (including those a department contracted without telling anyone), what data they touch and what decisions they influence takes weeks of calendar time, even if the actual work hours are few. That inventory is exactly what any authority will ask for, and also what the first large client will ask for in a supplier questionnaire.
And live risk does not wait. The AEPD, the Labour Inspectorate and consumer authorities can act today on the same facts. Preparing for the AI Act and preparing for the GDPR are, in 70% of the work, the same task: knowing what systems you have, what data they use, who supervises their decisions and what you tell affected individuals.
What to do on Monday morning
- Do the inventory. A spreadsheet with every AI tool used in the company, who contracted it, what data goes in, what decision comes out and who reviews it. Include subscriptions that marketing pays for with a card.
- Tick the three real-risk boxes. Does any system influence recruitment, evaluation or dismissal? Does any system process personal data of clients or employees? Does any system generate content you publish without disclosing it is synthetic?
- Review transparency before 2 August 2026. If you have a chatbot, users must know they are talking to a machine. If you publish synthetic content, it must be identified as such.
- If you have employee representatives, inform them. Article 64.4(d) of the Workers' Statute allows no delay, and the conversation is far cheaper before a complaint is filed.
- Keep the evidence. Vendor contracts, system data sheets, decision emails. Demonstrated diligence is an express mitigating factor in Article 31 of the draft law.
- Set an alert for the Official State Gazette. The day the organic law is published, the clock starts. Until then, no timetable for Spanish AI fines is real.
Frequently asked questions
Can AESIA inspect me even if it cannot fine me?
The draft law is what attributes the functions of surveillance, inspection and sanctioning powers over AI systems — and it is still not approved. In the meantime, those who can inspect you for your AI use are authorities that already have competence in other areas: the AEPD for personal data, the Labour Inspectorate for employment relations, consumer authorities for commercial practices.
If I breach the EU Regulation now and the law is passed in 2027, will I be sanctioned retroactively?
No. The principle of non-retroactivity of unfavourable sanctioning provisions is enshrined in Article 9.3 of the Spanish Constitution. What can happen is that the breach is still ongoing the day the law enters into force, at which point it becomes sanctionable from that moment. A badly built system does not fix itself simply because time passes.
I have a company of 30 people. Does the €35 million ceiling apply to me?
As an absolute figure, almost certainly not. For SMEs, Article 30.8 of the draft applies the lower of the fixed amount and the turnover percentage. What does apply to you are the ancillary measures: withdrawal or disconnection of the system can halt an entire business process.
I use ChatGPT or Copilot for internal tasks. Am I an AI provider?
No. You are a deployer, which is a role with lighter obligations. The heavy obligations for technical documentation, conformity assessment and marking fall on whoever develops the system or markets it under their own name. Watch out for that last point: if you integrate a third-party model into a product of your own and sell it under your brand, you may become a provider.
Do AESIA's guides protect me if I follow them?
They do not give a presumption of conformity; the agency itself says they are not binding. However, having followed them documents diligence, and diligence is expressly considered when grading a sanction. They serve as proof that you did the work, not as a shield.
Sources
- Royal Decree 729/2023 of 22 August, approving the Statute of AESIA (BOE-A-2023-18911). boe.es
- Draft Organic Law on the sound use and governance of artificial intelligence. BOCG, Congress of Deputies, Series A, No. 97-1, 12 June 2026. congreso.es
- File 121/000096, Congress of Deputies (progress and amendment deadlines). congreso.es
- Regulation (EU) 2024/1689 (AI Regulation). data.europa.eu
- Regulation (EU) 2026/1744 (Digital AI Omnibus), OJEU of 24 July 2026. data.europa.eu
- Regulation (EU) 2016/679 (GDPR), Art. 83. boe.es
- Law 12/2021 of 28 September (BOE No. 233, 29 September 2021), adding point (d) to Art. 64.4 of the Workers' Statute. boe.es
- AESIA guides. aesia.digital.gob.es
This article describes the state of the legislative process as of 28 July 2026. A draft law changes; check the file record before taking decisions based on these dates.