AI Act and ENS (Spanish National Security Framework) for Spanish Public Administration suppliers: the dual regulatory framework you need to know

TL;DR — The most important points in 60 seconds

Over the past twelve months, I have seen the same pattern repeat in dozens of Spanish tech companies: they reach the procurement notice stage of a public tender, discover that the client requires compliance with the ENS (Spanish National Security Framework) and, when they ask about the AI Act, nobody is quite sure what role they play. Are they providers? Are they users? Does Annex III apply to them?

The short answer is that both regulations probably apply to them — with distinct but complementary obligations — and that starting to prepare them now, before the next call opens, makes the difference between winning or losing the contract.

In this article I break down the dual regulatory framework with the precision you need if you are a tech company that wants, or already has, contracts with the Spanish Public Administration.


Why tech suppliers to Spanish Public Administration are in the AI Act's sights

Regulation (EU) 2024/1689, known as the AI Act, entered into force on 1 August 2024. Although its application is phased, since 2 February 2025 the prohibitions on unacceptable AI practices and the obligation to promote AI literacy for providers and users are already in effect.

The reason why suppliers to Spanish Public Administration are particularly exposed relates to the AI Act's cascade logic: Public Administration bodies, when they use AI systems to make decisions affecting citizens — social benefit management, case file assessment, access control systems — are deployers (users) under the regulation. And when someone is the deployer of a high-risk system, their obligations include requiring their supplier to ensure that system meets all AI Act requirements.

In other words: Spanish Public Administration passes compliance down its technology supply chain. If you sell an AI system to a municipality, a regional ministry or a state body, the contract will require — explicitly or implicitly — that the system has passed the conformity assessment, has technical documentation, allows human oversight and is registered in the EU database if it falls within Annex III.

Moreover, the Organic Law on AI governance that Spain approved in the Council of Ministers in 2026 obliges the state public sector to maintain an inventory of AI systems used in administrative procedures and to pass this requirement on to its contractors. What was previously good practice becomes a contractual condition.


Roles under the AI Act: are you a provider or a deployer?

Before analysing specific obligations, it is essential to clarify what role you play in the AI Act ecosystem. The regulation distinguishes four main figures:

Role Definition Examples in the public sector Obligation level
Provider Who develops or places on the market an AI system under their own name or brand, even if commissioned from a third party Tech company selling a social services case-assessment system to a provincial council Maximum: technical documentation, conformity assessment, CE marking, EU registration
Deployer Who uses an AI system under their own responsibility in their professional activity Municipality using a biometric recognition system for access control High: human oversight, records, fundamental rights impact assessment
Distributor Who markets without modifying an AI system from a provider Reseller selling third-party software to Spanish Public Administration without modification Medium: verify provider compliance, do not market non-compliant systems
Importer Who introduces into the European market an AI system from a provider outside the EU Spanish company importing and selling to Spanish Public Administration a US AI system High: assumes provider obligations if the provider is not in the EU

The most important practical rule: if you develop the system (or significantly adapt it), you are a provider regardless of whether your client is a Spanish Public Administration body or a private company. And being the provider of a high-risk system implies the most demanding obligations in the entire regulation.

In practice, many tech companies working with Spanish Public Administration are providers in some contracts and deployers in others (when they use third-party tools in their own operations). It is essential to classify each system you manage.

Note on Spanish Public Administration: When a Spanish Public Administration body uses high-risk AI systems to make decisions affecting citizens, it acts as a deployer. Under Art. 26(8) of the AI Act, public authorities also have the specific obligation to verify that systems they deploy are registered in the EU database before putting them into use, and to refrain from using unregistered systems.

High-risk AI systems commonly contracted with Spanish Public Administration

Annex III of the AI Act identifies eight domains of high-risk AI systems. Several are especially relevant to the Spanish public sector, and many already appear — or will soon appear — in public tenders:

1. Biometrics

Remote biometric identification systems, biometric categorisation based on sensitive attributes and emotion recognition. In the context of Spanish Public Administration, this includes access control systems in public facilities, facial recognition in citizen digital identification processes or intelligent video surveillance systems.

Obligations this generates for the provider: exhaustive technical documentation, conformity assessment by a notified body, CE marking, registration in the EU database before any commercialisation. Real-time remote biometric identification systems in public spaces are additionally subject to further restrictions and require prior judicial or administrative authorisation.

2. Critical infrastructure

Systems intended as safety components in the management or operation of critical digital infrastructure, road traffic, water supply, gas, heating or electricity. In public tenders, this covers systems from electricity grid management to transport infrastructure control platforms.

Intersection with ENS (Spanish National Security Framework): these systems are typically classified in the high category of the ENS (Spanish National Security Framework), requiring external certification by an ENAC-accredited body. ENS (Spanish National Security Framework) and AI Act compliance reinforce each other here.

3. Education and vocational training

Systems that determine access to or admission to educational institutions, evaluate learning outcomes, assign educational levels or monitor student behaviour. In Spain, any AI system involved in school admission processes, university place allocation or automated educational assessment falls here.

Tender trend: regional governments with education competences are beginning to tender academic performance analysis platforms. The procurement notices for these contracts will require fundamental rights impact assessments and human appeal mechanisms.

4. Employment and human resources management

Candidate selection and assessment systems, decisions on employment relationships (promotion, termination, behaviour-based task assignment), performance monitoring. In the Spanish Public Administration context, this applies to tools for selecting civil servants and employed staff.

Note: AESIA has indicated that AI systems in personnel selection are one of its first proactive inspection priorities. If you sell HR tools to public administrations, you must have all documentation in order before August 2026.

5. Private and public essential services

This is the broadest domain for Spanish Public Administration: systems that determine eligibility for public assistance and healthcare services. This includes any dependency assessment tool, social services, minimum living income or similar. Also emergency call prioritisation.

Specific deployer obligation (Spanish Public Administration): it must carry out a Fundamental Rights Impact Assessment (FRIA, under Art. 27 of the AI Act) before deploying these systems. The provider must supply the documentation needed for this assessment.

6. Law enforcement

Systems for assessing risk of victimisation, reliability of evidence, risk of recidivism, profiling in criminal investigations. Applies to state security forces and regional and local police.

7. Migration, asylum and border control

Risk assessment of persons entering the territory, assessment of asylum and visa applications, travel document verification. In Spain, mainly under the Ministry of the Interior and Government delegations.

8. Administration of justice and democratic processes

Assistance to judicial bodies in fact-finding and application of the law. Judicial decision-support systems are high-risk, with strict limitations on the degree of permitted automation.

In summary: if your product touches any of these eight domains in a public contract, you are dealing with an Annex III high-risk system with the maximum level of obligations as a provider.


ENS (Spanish National Security Framework) in 2026: requirements for providers with AI components

Royal Decree 311/2022, which updates the ENS (Spanish National Security Framework), is mandatory for all Spanish Public Administration bodies and, by direct extension (Art. 2.3), for any private company providing them with digital services.

The three categories and what they mean for the supplier

ENS (Spanish National Security Framework) classifies systems by the dimensions of confidentiality, integrity, availability, authenticity and traceability of managed data. The result of this assessment places the system in one of three categories:

ENS (Spanish National Security Framework) Category Who audits? Required document Validity Typical AI systems
Basic The organisation itself (self-assessment) Declaration of Conformity 2 years General information chatbots, semantic search engines on intranets
Medium External body accredited by ENAC Certificate of Conformity 2 years Document analysis systems, case management with AI components, HR tools
High External body accredited by ENAC Certificate of Conformity 2 years Biometric systems, AI in critical infrastructure, social services platforms with high-impact decisions

How AI architecture affects ENS (Spanish National Security Framework) classification

This is a question very few consultants address, and it has important practical consequences:

Here is the practical key: when a system falls under Annex III of the AI Act AND medium or high ENS (Spanish National Security Framework) category, the company must be certified through two different routes with partially different documentation. Managing this in a coordinated way saves time and cost.


The intersection: what ENS (Spanish National Security Framework) and the AI Act require simultaneously

The good news is that both regulations share a documented risk management logic. The bad news is that the level of granularity and timelines differ. Here is the map of key overlaps and divergences:

Requirement ENS (Spanish National Security Framework) (RD 311/2022) AI Act (Regulation EU 2024/1689) Do they overlap?
Risk management Documented risk analysis, periodically updated Risk management system throughout the entire lifecycle (Art. 9) Yes — a single methodology can feed both frameworks
Technical documentation Security policy, procedures, evidence of controls Exhaustive technical documentation (Art. 11 + Annex IV): architecture, training data, performance metrics Partial — AI Act requires more detail about the model itself
Traceability and logs Activity and access records according to system dimension Automatic event logging throughout the entire lifecycle, minimum retention 6 months (Art. 12) Yes — a well-designed logging system satisfies both
Access control Privilege management, authentication, role-based access control Effective human oversight with designated and competent persons (Art. 14) Yes — AI Act human oversight is documented in ENS (Spanish National Security Framework) procedures
Incident management Notification of security incidents to CCN-CERT Notification of serious incidents or malfunctions to the provider and authorities (Art. 73) Partial — different recipients, but the process can be unified
Data quality Information integrity as a categorisation dimension Data governance: quality, representativeness, absence of bias in training data (Art. 10) No — AI Act goes much further on this point
Certification/conformity Declaration of Conformity (basic) or ENAC Certification (medium/high) Self-assessment (most Annex III) or third-party notified body assessment (specific cases) + CE marking No — completely different processes and bodies
Transparency to users Not directly applicable Clear information to persons affected by high-risk AI decisions (Art. 26(10)) No — exclusive AI Act requirement

The advantage of addressing them together: a well-designed risk management system, with modular technical documentation and a unified logging architecture, can simultaneously satisfy the requirements of the ENS (Spanish National Security Framework) and the AI Act, avoiding documentation duplication and reducing audit cost. Separating ENS (Spanish National Security Framework) and AI Act compliance projects into two teams that do not coordinate is the most common and most expensive mistake.


How procurement notices are changing: what to prepare now

The regulatory framework impacts public procurement notices progressively. Although full Annex III obligations arrive in December 2027, the most advanced contracting bodies are already incorporating AI maturity requirements in their technical specification notices and award criteria.

Requirements already appearing in tech procurement notices with AI components

ISO 42001 as a differentiator in public tenders

ISO 42001, which establishes an artificial intelligence management system, is beginning to appear in tech procurement notices as a criterion for technical solvency or award. Spain's Public Sector Contracts Act allows contracting bodies to require ISO certifications when they are directly and justifiably linked to the contract subject matter.

Although ISO 42001 adoption in Spain is still in its early stages, companies combining ENS (Spanish National Security Framework) + AI Act readiness + ISO 42001 will have a differential position in procurement notices over the next two years. This is not merely a reputational advantage: it is documented evidence of AI management capability that reduces the perceived risk for the contracting body.


AESIA and its role as supervisor of Spanish Public Administration suppliers

The Spanish AI Supervision Agency (AESIA), headquartered in A Coruña with offices in Madrid, is the national competent authority for applying the AI Act in Spain. It was created in 2023, becoming the first agency of its kind in the European Union.

Since 2 February 2025, AESIA has had active inspection powers over prohibited practices and the AI literacy obligation. Its full sanctioning capacity — including Annex III high-risk systems — activates with the entry into force of those obligations, originally planned for August 2026 and now pointing to December 2027 following the political agreement on the Digital Omnibus on AI.

What can AESIA do to a Spanish Public Administration AI supplier?

The regulatory sandbox: an underused tool

AESIA manages a regulatory testing space (sandbox), established by RD 817/2023, which allows companies to develop and test high-risk AI systems under agency supervision, with temporary flexibility in compliance in exchange for transparency and cooperation. Sixteen practical compliance guides have already emerged from the sandbox, which AESIA has published openly at aesia.gob.es.

For an SME (small and medium-sized enterprise) tech company wanting to develop an AI system for Spanish Public Administration and unsure whether its product is high-risk, the sandbox is the safest mechanism to test without immediate sanctioning risk.


Preparation plan for suppliers: 6 months before tendering

If your company wants to be ready for the tech tenders with AI components that will proliferate over the next two years, here are the ten actions ordered by priority and logical sequence:

  1. AI systems inventory (weeks 1-2): list all systems you develop, sell or integrate. For each one, identify whether it incorporates any automated decision-making component. This list is the starting point for everything else.
  2. AI Act classification (weeks 3-4): for each system in the inventory, determine its risk level under the AI Act: unacceptable (prohibited), high-risk (Annex III), limited risk (transparency obligations) or minimal risk. AESIA's guides are a free and reliable resource for this classification.
  3. ENS (Spanish National Security Framework) classification (weeks 3-4, in parallel): for each system you already have or are developing for public contracts, carry out the ENS (Spanish National Security Framework) dimensions analysis. If you already have active contracts with Spanish Public Administration, the ENS (Spanish National Security Framework) analysis should already be done; if not, it is urgent.
  4. Technical documentation gap analysis (month 2): compare the documentation you have today with what Annex IV of the AI Act requires for high-risk systems. The most common gaps are: absence of training data documentation, lack of performance metrics by population subgroups, and absence of documented human oversight procedures.
  5. Risk management system (months 2-3): implement a continuous risk identification, assessment and mitigation process for each high-risk system. This process must be reviewable by AESIA in the event of an inspection.
  6. Unified logging architecture (month 3): design or update the event recording system so that it simultaneously complies with the ENS (Spanish National Security Framework) (traceability) and the AI Act (Art. 12: automatic logging throughout the entire lifecycle, minimum retention 6 months).
  7. Human oversight procedures (months 3-4): document who, how and how often supervises the system's decisions. Define manual intervention thresholds. Train staff. This satisfies both Art. 14 of the AI Act and the ENS (Spanish National Security Framework) personnel measures.
  8. ENS (Spanish National Security Framework) Declaration of Conformity / Certification (months 4-5): depending on the ENS (Spanish National Security Framework) category of your systems, prepare the self-assessment (basic) or initiate the external audit process with an ENAC-accredited body (medium or high). Without this document, you cannot bid in tenders.
  9. AI Act conformity assessment (months 5-6): for Annex III high-risk systems, most allow documented self-assessment. Prepare the technical documentation according to Annex IV and, if the system requires it, contact a notified body for external assessment.
  10. EU database registration (month 6): high-risk systems must be registered in the European database before being commercialised. This is a prerequisite for CE marking and for being able to bid in tenders with Annex III systems.

Financing with Kit Consulting (Spain advisory grant)

The Kit Consulting (Spain advisory grant) programme, managed by Red.es with NextGenerationEU funds, can finance the strategic advisory work needed to prepare all this documentation. The available amounts are:

The programme specifically includes advisory services on artificial intelligence and cybersecurity (ENS (Spanish National Security Framework) medium-high category adaptation). Combined, they can cover a significant part of the dual regulatory framework preparation work.

Current status: The Kit Consulting (Spain advisory grant) call is closed to new applications. A second call is pending official opening. If you are interested in financing your project with this programme, it is advisable to contact your digitisation agent to reserve a place as soon as it opens.

If you want to explore how to structure an ENS (Spanish National Security Framework) + AI Act compliance project financed with Kit Consulting (Spain advisory grant), write to me directly and we can analyse your situation.

If you are a Spanish Public Administration supplier, this intersects with the ENS (Spanish National Security Framework) and it is worth looking at them together. Here you have AI Act compliance.


Frequently asked questions about AI Act and ENS (Spanish National Security Framework) for Spanish Public Administration suppliers

Does the AI Act affect software suppliers to Spanish Public Administration?

Yes, directly. Providers of AI systems that tender with Spanish Public Administration bodies are providers under the AI Act and have the most demanding obligations: technical documentation per Annex IV, risk management system (Art. 9), conformity assessment, registration in the EU database and CE marking for high-risk systems. The fact that the client is a Spanish Public Administration body does not reduce the supplier's obligations; in some cases it expands them, because Spanish Public Administration bodies are subject to additional registration and supervision requirements that they contractually pass on to their suppliers.

What obligations does a Spanish Public Administration body using AI systems have?

Spanish Public Administration bodies are deployers under the AI Act when they use AI systems to make decisions affecting citizens. Their main obligations, set out in Art. 26, include: using the system in accordance with the provider's instructions, assigning competent staff for human oversight, maintaining automatically generated records (minimum 6 months), informing affected workers before deployment, reporting serious incidents, carrying out a DPIA (Data Protection Impact Assessment) — Fundamental Rights Impact Assessment (FRIA, Art. 27) for certain systems, and informing citizens when an AI system has been used to make a decision affecting them. Art. 26(8) adds a specific obligation for public authorities: to verify that deployed systems are registered in the EU database.

Do I need to comply with both the ENS (Spanish National Security Framework) AND the AI Act if I sell AI software to Spanish Public Administration?

Yes, both frameworks are mandatory and apply in parallel. The ENS (Spanish National Security Framework) (RD 311/2022) regulates the security of information systems that handle Spanish Public Administration data: any private supplier managing public information must comply and demonstrate it through a Declaration of Conformity (basic category) or external Certificate of Conformity (medium and high categories). The AI Act regulates AI systems regardless of whether they are secure in the conventional sense: it focuses on managing AI-specific risks, data quality, explainability, human oversight and traceability. Managing both frameworks in an integrated way reduces documentation duplication and compliance cost.

Which Annex III AI systems are commonly contracted with Spanish Public Administration?

The most common in Spanish public tenders include: biometric recognition systems for security and access control in public facilities, dependency assessment and eligibility tools for social services, admission and assessment systems in education, risk analysis platforms in judicial or law enforcement contexts, AI-enabled critical infrastructure management systems, and personnel selection and assessment tools for public employment. All of these are high-risk systems under Annex III and generate maximum obligations for the provider.

When do Annex III obligations for Spanish Public Administration suppliers enter into force?

Originally scheduled for 2 August 2026. Following the political agreement reached in May 2026 on the Digital Omnibus on AI package, the expected date shifts to December 2027 for Annex III systems. However, it is worth acting now for three reasons: first, the political agreement is not law until its publication in the Official Journal of the EU; second, procurement notices are already anticipating these requirements; third, ENS (Spanish National Security Framework) certification and AI Act technical documentation processes take months of work. Starting now means arriving prepared in 2027, not rushing at the last moment.

Does ISO 42001 help win public tenders?

Increasingly so. Spain's Public Sector Contracts Act allows contracting bodies to use ISO certifications as a technical solvency criterion or award criterion, provided they are directly and justifiably linked to the contract subject matter. ISO 42001 (artificial intelligence management system) is beginning to appear in tech procurement notices with AI components, especially in higher-value tenders. Combined with ENS (Spanish National Security Framework) certification and AI Act documentation, it demonstrates a comprehensive AI management capability that reduces the perceived risk for the public buyer and can make the difference in the technical scoring.

What is AESIA and what role does it play with Spanish Public Administration suppliers?

The Spanish AI Supervision Agency (AESIA) is the competent body in Spain for applying the AI Act. Created in 2023 and headquartered in A Coruña, it was the EU's first AI supervision agency. It supervises both providers and deployers, including Spanish Public Administration bodies. Its tools are: proactive inspections (starting with personnel selection systems), complaint investigations by citizens, mandatory incident notifications, and fines of up to €35 million or 7% of global turnover. It also offers the regulatory sandbox for testing AI systems under supervision with temporary compliance flexibility, and has published 16 practical guides freely available at aesia.gob.es.

How to finance adaptation to the AI Act and ENS (Spanish National Security Framework) for Spanish Public Administration suppliers?

The Kit Consulting (Spain advisory grant) programme (managed by Red.es with NextGenerationEU funds) can cover the strategic advisory work needed to prepare the AI Act technical documentation, the ENS (Spanish National Security Framework) gap analysis and the integrated compliance plan. Amounts range from €12,000 (10-49 employees) to €24,000 (100-249 employees). The programme specifically includes advisory services on artificial intelligence and cybersecurity/ENS (Spanish National Security Framework). It is especially useful for SME (small and medium-sized enterprise) tech companies wanting to be ready for tenders over the next two years without bearing the full cost internally.


Do you want to prepare your company for the next AI tech tenders?

If you develop or sell systems with AI components to Spanish Public Administration, I can help you design an integrated ENS (Spanish National Security Framework) + AI Act compliance plan that is cost-efficient and documented to pass the next audit or procurement notice.

Free diagnostic consultation

Related articles you may find useful