Spain - Asturias - AI Public Administration Decree (2025)

Asturias AI Public Administration Decree 2025

Decreto de Administración Pública de IA de Asturias 2025

Spain

RAI-ES-AS-AAPADXX-2025
Effective: October 31, 2025
In Force(In Force)
DecreeGovernance and OversightTransparency and DisclosureRisk Management
Export PDF

A regional decree regulating the ethical use and governance of AI systems within the public administration of Asturias, Spain.

Overview

The Asturias AI Public Administration Decree 2025, formally known as Decree 98/2025, of July 22, represents a landmark legislative effort by the Principality of Asturias to formalize the integration of artificial intelligence within its regional public sector. This decree is designed to provide a robust legal framework that balances the drive for administrative modernization with the fundamental necessity of protecting citizen rights. As public administrations increasingly turn to automated systems to manage large datasets, streamline service delivery, and enhance decision-making processes, the need for clear, binding rules becomes paramount. This regulation ensures that any AI deployment within the Asturian administration is governed by principles of legality, transparency, and accountability. It serves as a regional implementation of broader European and national strategies, specifically aligning with the European Union's AI Act and the Spanish National Artificial Intelligence Strategy (ENIA). By enacting this decree, Asturias positions itself as a pioneer among Spanish autonomous communities in establishing a specific regulatory environment for the ethical use of AI. The decree aims to improve the efficiency of public services by automating routine tasks, thereby allowing civil servants to focus on more complex, value-added activities. However, it explicitly mandates that such technological adoption must not compromise the human-centric nature of public administration. The framework emphasizes that AI should be a tool for empowerment rather than a replacement for human judgment, particularly in decisions that significantly affect the legal status or welfare of individuals. The regulation also seeks to foster a local ecosystem of innovation by providing clear guidelines for private companies, particularly small and medium-sized enterprises (SMEs) and startups, that wish to provide AI solutions to the regional government. This decree is not merely a technical document but a social contract that defines how technology will serve the public interest in the digital age.

Definitions

The decree adopts and expands upon the terminology established in the European Union AI Act (Regulation 2024/1689). Key definitions include 'AI System,' which is characterized as a machine-based system designed to operate with varying levels of autonomy and that may exhibit adaptiveness after deployment. For the specific context of the Asturian public administration, the decree introduces the concept of 'Auditability,' defined as the capacity to evaluate the algorithms, the underlying data, and the design processes, or the ability to be subjected to formal auditing procedures by third parties or internal oversight bodies. This definition is critical for ensuring that the 'black box' nature of some AI models does not impede the administrative duty to provide reasons for its actions. Furthermore, the decree provides technical definitions for 'Algorithm' as a set of rules to be followed to perform a task or solve a problem, and 'Artificial Hallucination,' which refers to instances where an AI system generates confident but incorrect or nonsensical results. The regulation also defines the roles of 'Provider' and 'Deployer' (responsable del despliegue) in alignment with European standards, ensuring that the legal responsibilities of the regional government and its external contractors are clearly delineated. These definitions serve as the technical foundation for the compliance requirements detailed in the subsequent chapters of the decree, ensuring that all stakeholders use a common language when discussing risk and performance. Additionally, the decree defines 'High-Risk Systems' as those used in critical infrastructure, education, employment, and essential public services, requiring more stringent oversight. 'Biometric Identification' is also defined, with strict limitations on its use in public spaces to protect privacy. The term 'Algorithmic Bias' is explicitly defined as the systematic and unfair discrimination against certain groups resulting from the design or data used in an AI system.

Governance and Institutional Framework

The governance structure established by the decree centers on the Consejería de Presidencia, Reto Demográfico, Igualdad y Turismo, which is designated as the competent body for the authorization, supervision, and control of AI systems within the Principality. This centralized oversight is intended to prevent fragmented or inconsistent AI adoption across different government departments. A key institutional development is the expansion of the functions of the Centro de Innovación y Desarrollo de la Sociedad de la Información (CEDISI), which now serves as the technical arm responsible for evaluating the compliance of AI systems before they are deployed in the public sector. This framework also encourages inter-administrative collaboration. The decree stipulates that the Asturian government will coordinate with the Spanish Agency for the Supervision of Artificial Intelligence (AESIA) and other regional bodies to ensure that local practices remain consistent with national and European trends. The governance model is designed to be dynamic, allowing for the creation of specialized working groups and ethical committees that can provide expert advice on high-risk deployments. By institutionalizing AI oversight, the decree ensures that the transition to an AI-augmented administration is managed by qualified personnel who are accountable to both the government and the public. The framework also includes a 'Chief AI Ethics Officer' role within each major department to ensure day-to-day compliance. This multi-layered governance approach ensures that technical innovation is always balanced with ethical considerations and legal compliance. The decree also mandates the creation of an Inter-departmental AI Commission to coordinate cross-sectoral projects and share best practices across the administration.

Key Focus Areas

The decree identifies several priority areas where AI can significantly impact public administration. The primary focus is the improvement of efficiency in public services, particularly through the optimization of administrative procedures. This includes the use of intelligent systems for the automated digitalization of files, where AI can extract essential data from documents and classify them within administrative systems. Such applications are expected to reduce bureaucratic burdens and significantly shorten the response times for citizen requests. Another major focus is the design and application of public policies through advanced data analysis, enabling more informed decision-making in sectors like healthcare, mobility, and social services. In addition to efficiency, the decree places a heavy emphasis on non-discrimination and the prevention of algorithmic bias. It mandates that any AI system used for automated decision-making must be designed to avoid perpetuating social or economic inequalities. This is particularly relevant in the 'miPrincipado' digital platform, where AI is used to personalize interactions between the administration and citizens. The decree ensures that while services may be personalized, they must remain universally accessible and fair. The protection of vulnerable groups is a recurring theme, with specific prohibitions against AI practices that exploit age, disability, or socio-economic status to manipulate or disadvantage individuals. Furthermore, the decree highlights the importance of 'Green AI,' encouraging the use of energy-efficient models and sustainable computing practices to minimize the environmental footprint of the administration's digital infrastructure. It also focuses on the 'Digital Divide,' ensuring that AI-driven services do not exclude citizens who lack advanced digital skills.

Implementation Framework

The implementation of AI systems under this decree follows a rigorous process of prior authorization and technical monitoring. Before any AI system is deployed, the responsible department must conduct a comprehensive impact assessment that evaluates the potential risks to fundamental rights and the technical robustness of the system. This process is supported by the creation of an 'AI Sandbox' (entorno controlado de pruebas), a secure and controlled environment where new tools can be tested and validated before they are integrated into live public services. This sandbox is especially designed to facilitate the participation of SMEs and startups, providing them with a space to prove the safety and efficacy of their innovations under government supervision. The decree also establishes requirements for the 'Registry of Algorithms,' which serves as a transparency tool for the public. Every AI system used by the administration must be documented in this registry, including information about its purpose, the logic behind its decisions, and the measures taken to ensure human oversight. This 'human-in-the-loop' requirement is a cornerstone of the implementation framework, ensuring that no significant administrative decision is made solely by a machine without the possibility of human intervention or review. The implementation phase also includes mandatory training for civil servants to ensure they possess the necessary digital literacy to interact with and supervise AI tools effectively. Procurement rules are also updated to include specific AI ethics clauses in all government contracts. The framework requires that all data used for training AI systems within the administration must be high-quality, representative, and free from known biases, with documented provenance and cleaning procedures.

Monitoring and Evaluation

Continuous monitoring is mandated to ensure that AI systems remain compliant with ethical and technical standards throughout their entire lifecycle. The decree requires periodic audits to detect and correct any drift in performance or the emergence of unforeseen biases. These evaluations are not merely technical but also include assessments of the social and economic impact of the AI systems. If a system is found to present a high risk that cannot be mitigated, or if it produces 'artificial hallucinations' that lead to administrative errors, the decree grants the competent authority the power to order its immediate withdrawal or suspension. Evaluation results must be made available to the public in an accessible format, reinforcing the principle of transparency. The decree also contemplates a formal review of the regulation itself within a specified timeframe after its entry into force to ensure it remains relevant in the face of rapid technological change. This iterative approach to regulation allows the Principality of Asturias to adapt its oversight mechanisms as AI capabilities evolve, ensuring that the legal framework remains a facilitator of safe innovation rather than a static barrier. Monitoring also involves tracking the 'explainability' of systems, ensuring that as models become more complex, the administration maintains the ability to describe how outputs are reached. Annual reports on the state of AI in the Asturian administration must be submitted to the regional parliament, providing a high level of democratic oversight. These reports will include metrics on efficiency gains, error rates, and any incidents related to algorithmic bias or data breaches.

Penalties, Liability, and Appeals

The decree establishes a clear regime for administrative liability. The Principality of Asturias and its public sector entities are held responsible for the actions of the AI systems they deploy, ensuring that citizens have a clear path for redress if they are harmed by an automated decision. The right to a human explanation is explicitly protected, allowing individuals to challenge AI-generated outcomes and request a review by a human official. This aligns with the broader principles of Spanish administrative law, which requires all government acts to be reasoned and subject to judicial review. While the decree focuses on the public sector's internal use of AI, it also sets out the consequences for providers who fail to meet the technical or ethical standards specified in their contracts. Non-compliance can lead to the termination of contracts, financial penalties, and disqualification from future public procurement processes. The regulation ensures that the burden of proof regarding the safety and fairness of an AI system lies with the administration and its providers, rather than the citizen. This protective stance is intended to build public trust in the digital transformation of the regional government. Penalties for providers can reach up to 5% of their annual turnover for serious breaches of safety or transparency requirements. For citizens, the decree guarantees a simplified appeal process through the 'Sede Electrónica,' where they can report malfunctions or biased outcomes directly to the oversight body. The administration is required to respond to such appeals within 30 days, providing a detailed technical and legal justification for the AI's decision.

Relationship to Other Instruments

Decree 98/2025 is designed to operate in harmony with a hierarchy of legal instruments. Most importantly, it serves as a regional bridge to the European Union AI Act, incorporating its risk-based classification and transparency requirements. It also complements the Spanish Organic Law on the Protection of Personal Data and Guarantee of Digital Rights (LOPDGDD), ensuring that the data used to train and operate AI systems is handled in strict accordance with privacy regulations. The decree frequently references the Spanish Charter of Digital Rights, adopting its humanistic approach to technology. Furthermore, the regulation is a key component of the 'Estrategia de Transformación Digital del Principado de Asturias 2021-2024' and its successors. It provides the legal teeth for the policy goals set out in these strategic documents. By aligning with both national and European standards, the Asturias decree ensures that the regional administration can participate in cross-border digital initiatives and data spaces without facing regulatory hurdles. It also sets a precedent for other Spanish autonomous communities, such as Galicia, which has pursued similar legislative paths. The decree also interacts with the Law on Administrative Procedure (Ley 39/2015), specifically regarding the validity of automated administrative acts. It ensures that the use of AI does not violate the principle of 'legal reserve' or the non-delegability of public powers. By integrating these various legal strands, the decree creates a cohesive and predictable environment for both citizens and technology developers.

International Alignment

The Asturias AI Decree reflects a strong commitment to international standards for trustworthy artificial intelligence. It specifically incorporates the OECD AI Principles, which emphasize inclusive growth, human-centered values, and transparency. By adhering to these globally recognized benchmarks, Asturias ensures that its public sector AI deployments are viewed as credible and ethical on the international stage. This alignment is also crucial for attracting international technology partners and investment to the region. The decree's focus on 'human-centric' AI and the 'human-in-the-loop' principle mirrors the consensus among democratic nations regarding the governance of automated systems. It also anticipates future international standards for algorithmic auditing and certification. By participating in the broader European regulatory framework, Asturias contributes to the development of a 'European way' of AI that prioritizes fundamental rights over purely commercial or state-centric interests. This international outlook ensures that the Principality remains at the forefront of the global conversation on responsible AI governance. The decree also aligns with the UNESCO Recommendation on the Ethics of Artificial Intelligence, particularly regarding the promotion of cultural diversity and the prevention of technological monopolies. By adopting these standards, Asturias signals its readiness to participate in the global digital economy while maintaining high ethical standards. This alignment also facilitates participation in international research projects and the exchange of best practices with other innovative regions worldwide.

Implementation Timeline

MilestoneDateNotes
Approval of Decree 98/20252025-07-22Approved by the Government of the Principality of Asturias.
Publication in BOPA2025-07-31Official publication in Boletín Nº 147.
Entry into Force2025-10-31Three months after publication as per the final provision.
Establishment of AI Sandbox2026-01-31Target date for operational testing environment.
Full Compliance for Existing Systems2026-07-31Deadline for legacy systems to meet new transparency standards.
First Annual Audit Report2026-12-31Submission of the first comprehensive oversight report to Parliament.

Compliance Checklist

CheckRequired ActionResponsibility
Risk ClassificationCategorize the AI system according to the risk levels defined in the EU AI Act.Project Manager
Fundamental Rights Impact AssessmentConduct and document an assessment of the system's impact on citizen rights.Legal Department
Registry EntryRegister the algorithm in the official Public Administration AI Registry.CEDISI
Human Oversight MechanismEnsure a 'human-in-the-loop' is designated for all automated decision-making.Department Head
Transparency NoticeProvide clear information to users when they are interacting with an AI system.Communications
Technical AuditPerform a pre-deployment audit to verify accuracy and lack of bias.Technical Team
Data Quality ReviewVerify that training data is representative and free from historical biases.Data Officer

Sources and References

SourceType
BOPA No. 147 - Decreto 98/2025 de 22 de julioOfficial Gazette
Government of the Principality of Asturias Official PortalGovernment Website
EU AI Act (Regulation 2024/1689)Legal Database
Spanish Organic Law on Data Protection (LOPDGDD)Legal Database
OECD AI PrinciplesInternational Standard
Plain English

The Asturias AI Public Administration Decree 2025 sets clear rules for how the regional government of Asturias, Spain, can develop and use artificial intelligence systems, aiming to ensure ethical deployment and robust protection of citizen rights. This law applies to all departments within the Principality of Asturias' public administration, as well as any private companies that provide AI solutions to the regional government.

Effective October 31, 2025, the decree mandates several key obligations. Before any AI system is deployed, especially those considered "high-risk" (such as those used in critical infrastructure, education, employment, or essential public services), the administration must conduct a comprehensive impact assessment to evaluate potential risks to fundamental rights. A cornerstone of the regulation is the requirement for "human-in-the-loop" oversight, ensuring that significant administrative decisions are not made solely by machines, but always allow for human intervention and review. Transparency is also paramount: all AI systems must be documented in a public "Registry of Algorithms," detailing their purpose and logic, and citizens must be clearly informed when interacting with an AI. The law also strictly prohibits algorithmic bias and demands high-quality, representative data to prevent discrimination. To enforce these principles, each major government department must appoint a Chief AI Ethics Officer.

For private companies providing AI solutions, non-compliance can lead to severe penalties, including contract termination, financial fines of up to 5% of their annual turnover for serious breaches, and disqualification from future public procurement processes. Citizens, conversely, are granted a clear right to challenge AI-generated outcomes and request a human explanation for any decision affecting them. A crucial practical implication for both the administration and its providers is that the burden of proof regarding an AI system's safety, fairness, and compliance with ethical standards lies squarely with them, not with the citizen. This means they must proactively demonstrate that their AI systems are trustworthy and operate without bias.

Plain-English rewrite by Regulations.ai — not legal advice. Verify against the official text.

What you must do — compliance checklist

0 / 14 marked complete

Plain-English obligations under Spain - Asturias - AI Public Administration Decree (2025). Not legal advice — verify against the official text before relying on it.

  1. #1CriticalKey Focus AreasBefore deployment and continuously

    Applies to: Departments deploying AI systems and their providers.

    specific prohibitions against AI practices that exploit age, disability, or socio-economic status to manipulate or disadvantage individuals.
  2. #2CriticalImplementation FrameworkBefore deployment

    Applies to: Departments deploying AI systems within the Asturian public administration.

    This 'human-in-the-loop' requirement is a cornerstone of the implementation framework, ensuring that no significant administrative decision is made solely by a machine.
  3. #3CriticalImplementation FrameworkBefore deployment and continuously

    Applies to: Departments deploying AI systems and their providers.

    all data used for training AI systems within the administration must be high-quality, representative, and free from known biases, with documented provenance and cleaning procedures.
  4. #4CriticalImplementation FrameworkBefore deployment

    Applies to: Departments deploying AI systems within the Asturian public administration.

    Before any AI system is deployed, the responsible department must conduct a comprehensive impact assessment that evaluates the potential risks to fundamental rights.
  5. #5CriticalMonitoring and EvaluationImmediately upon detection

    Applies to: The Asturian public administration.

    If a system presents a high risk or produces 'artificial hallucinations,' the competent authority can order its immediate withdrawal or suspension.
  6. #6CriticalPenalties, Liability, and AppealsOngoing, after deployment

    Applies to: Departments deploying AI systems within the Asturian public administration.

    The right to a human explanation is explicitly protected, allowing individuals to challenge AI-generated outcomes and request a review by a human official.
  7. #7CriticalCompliance ChecklistBefore deployment

    Applies to: Departments deploying AI systems within the Asturian public administration.

    Categorize the AI system according to the risk levels defined in the EU AI Act.
  8. #8ImportantDefinitionsBefore deployment

    Applies to: Providers and deployers of AI systems.

    Auditability is the capacity to evaluate algorithms, data, and design processes, or to be subjected to formal auditing procedures.
  9. #9ImportantCompliance ChecklistBefore deployment

    Applies to: Departments deploying AI systems within the Asturian public administration.

    Perform a pre-deployment audit to verify accuracy and lack of bias.
  10. #10ImportantImplementation FrameworkBefore deployment

    Applies to: Departments deploying AI systems within the Asturian public administration.

    Every AI system used by the administration must be documented in this registry, including its purpose, logic, and human oversight measures.
  11. #11ImportantCompliance ChecklistBefore deployment

    Applies to: Departments deploying AI systems within the Asturian public administration.

    Provide clear information to users when they are interacting with an AI system.
  12. #12ImportantMonitoring and EvaluationOngoing, after deployment

    Applies to: Departments deploying AI systems within the Asturian public administration.

    Continuous monitoring is mandated to ensure AI systems remain compliant. The decree requires periodic audits.
  13. #13ImportantImplementation FrameworkOngoing

    Applies to: Procurement departments within the Asturian public administration.

    Procurement rules are also updated to include specific AI ethics clauses in all government contracts.
  14. #14ImportantImplementation TimelineJul 31, 2026

    Applies to: Departments deploying AI systems within the Asturian public administration.

    Full Compliance for Existing Systems 2026-07-31 Deadline for legacy systems to meet new transparency standards.

© Regulations.AI — created on 03-Jan-2026 using Gemini 3 Flash Preview