Spain - Asturias - AI Regulation (98/2025)

Decree 98/2025, of July 22, regulating the use of Artificial Intelligence in the Administration of the Principality of Asturias and its public sector

Decreto 98/2025, de 22 de julio, por el que se regula el uso de la Inteligencia Artificial en la Administración del Principado de Asturias y su sector público

Spain

RAI-ES-AS-D9D2DXX-2025
Effective: October 31, 2025
In Force(In Force)
DecreeGovernance and OversightRisk ManagementFundamental Rights
Export PDF

Asturias' Decree 98/2025 establishes a pioneering framework for ethical and responsible AI use in its public administration, ensuring fundamental rights and fostering innovation.

Overview

The Decree 98/2025, officially titled 'Decreto 98/2025, de 22 de julio, por el que se regula el uso de la Inteligencia Artificial en la Administración del Principado de Asturias y su sector público,' represents a landmark legislative effort by the Principality of Asturias, Spain. Enacted on July 22, 2025, and subsequently published in the Boletín Oficial del Principado de Asturias (BOPA) on July 31, 2025, this decree entered into force three months later, on October 31, 2025. Its primary objective is to establish a comprehensive and pioneering regulatory framework for the responsible, ethical, and secure deployment of Artificial Intelligence (AI) systems within the regional public administration and its broader public sector. This initiative positions Asturias at the forefront of AI governance within Spain and Europe, demonstrating a proactive approach to managing the transformative impact of AI on public services.

The decree is designed with a dual purpose: first, to guarantee that all AI applications utilized by the Asturian administration adhere strictly to ethical principles, ensure security, and respect fundamental rights; and second, to foster the responsible and controlled development of AI innovation. It seeks to leverage AI to improve the quality, personalization, and proactivity of public services, particularly in critical sectors such as healthcare, social services, and general administrative management. By doing so, the Principality aims to enhance the relationship between citizens and the administration, streamline bureaucratic processes, and optimize public resource allocation, all while maintaining robust public control and accountability over AI systems.

Definitions

While the full text of the Decree 98/2025 is required for precise legal definitions, the overarching themes and specific mentions in official communications and legal analyses provide insight into the key terms addressed. 'Inteligencia Artificial (IA)' refers broadly to systems designed to operate with a degree of autonomy, capable of processing data, learning, reasoning, and making decisions or predictions to achieve specific objectives. The decree specifically targets the 'Administración del Principado de Asturias y su sector público,' defining the scope of entities subject to its regulations, encompassing various regional government bodies and public enterprises.

A central concept introduced is the 'sandbox de inteligencia artificial' or 'entorno de pruebas controlado,' which designates a secure and regulated environment where new AI systems can be tested and evaluated before their definitive implementation in public services. This mechanism is crucial for identifying potential errors, biases ('sesgos'), and risks, ensuring data security, and verifying alignment with ethical and legal principles. Other important terms include 'gobernanza' (governance), referring to the institutional structures and processes for oversight; 'supervisión humana,' emphasizing the necessity of human intervention and control over automated decisions; 'transparencia' and 'explicabilidad,' requiring AI systems to be understandable and their outputs justifiable; and 'ciberseguridad,' highlighting the need to protect AI systems and the data they process from cyber threats.

Governance and Institutional Framework

The Decree 98/2025 establishes a clear governance structure for the oversight and control of AI systems within the Asturian public administration. The primary responsibility for authorizing, supervising, and controlling AI systems falls under the 'Consejería competente en materia de IA,' which is the regional Ministry with jurisdiction over Artificial Intelligence. This central authority ensures a coordinated and consistent approach to AI deployment across various public entities. Complementing this, the 'Dirección General competente en materia de IA' (Directorate General for AI) is tasked with the evaluation of compliance requirements for AI systems, as well as the ongoing supervision and control of their results.

Further institutional support is provided by the 'CEDISI' (Centro de Servicios Compartidos del Principado de Asturias), which assumes new functions related to AI. CEDISI is expected to play a strategic role in areas such as training, evaluation, and dissemination of best practices concerning AI. This collaborative governance model aims to ensure that expertise is centralized while implementation is distributed, fostering a responsible and innovative ecosystem. The framework also emphasizes that these regional competencies operate without prejudice to the broader supervision and market surveillance responsibilities held by various national authorities, in accordance with the provisions of the European AI Regulation.

Key Focus Areas

The Decree 98/2025 places significant emphasis on several key areas to ensure the responsible and beneficial integration of AI into public services. A cornerstone is the protection of 'derechos fundamentales' (fundamental rights), ensuring that AI systems do not infringe upon individual liberties, promote discrimination, or perpetuate biases. This is achieved through strict requirements for data quality, mandating that data used for AI training and operation must be adequate, free from errors, and devoid of biases, while complying with the General Data Protection Regulation (GDPR).

Another critical focus is 'transparencia' and 'explicabilidad,' requiring AI systems to be understandable, their decision-making processes traceable, and their outcomes justifiable to human operators and citizens. This principle ensures accountability and builds trust in AI-driven public services. The decree also mandates 'supervisión humana,' ensuring that human oversight is maintained, and automated decisions do not override human autonomy or judgment, particularly in sensitive contexts. Furthermore, 'ciberseguridad' is a paramount concern, with provisions to guarantee the security and resilience of AI systems against attacks and vulnerabilities. The decree explicitly prohibits practices deemed unacceptable by the European AI Act, such as harmful cognitive-behavioral manipulation or social scoring by authorities, reinforcing a robust ethical stance.

Implementation Framework

The implementation framework outlined in Decree 98/2025 is designed to facilitate the secure and responsible deployment of AI systems within the Asturian public administration. A crucial component is the requirement for 'autorización previa' (prior authorization) before any AI system can be deployed. This authorization process involves a thorough assessment by the competent Consejería, ensuring that all regulatory and ethical requirements are met before an AI system becomes operational. This centralized approval mechanism provides a vital gatekeeping function, preventing the hasty or unvetted introduction of AI technologies.

A distinctive feature of the implementation framework is the establishment of 'entornos controlados de prueba' or 'sandboxes.' These regulatory sandboxes provide a safe and controlled environment for testing AI systems, allowing for the verification, monitoring, and evaluation of their performance, efficacy, and adherence to ethical guidelines before full-scale deployment. This phased approach enables the detection and correction of errors or biases, minimizing potential risks to citizens and public services. The decree also actively promotes 'fomento de la innovación' by encouraging the participation of small and medium-sized enterprises (SMEs) and startups in these testing environments and in public procurement processes, offering favorable conditions to integrate cutting-edge AI solutions into the public sector.

Monitoring and Evaluation

The Decree 98/2025 recognizes the dynamic nature of AI technologies and the necessity for continuous oversight post-deployment. Consequently, it mandates a robust framework for 'monitorización técnica' and ongoing evaluation of AI systems once they are in operation within the public administration. This continuous monitoring aims to track the performance, accuracy, and adherence to ethical principles of AI systems over their lifecycle, ensuring that they continue to meet regulatory standards and deliver intended benefits without unforeseen negative consequences.

A critical aspect of this framework is the provision for 'evaluación a posteriori del impacto y rendimiento' (post-implementation evaluation of impact and performance). This involves periodic assessments to determine the actual effects of AI systems on public services, citizens, and administrative efficiency, allowing for adjustments and improvements as needed. Furthermore, the decree includes a 'capacidad de retirada' (capacity for withdrawal), meaning that AI systems can be suspended temporarily or permanently if they present errors, biases, or artificial 'hallucinations' that compromise their reliability, safety, or ethical compliance. This mechanism ensures that the administration can swiftly respond to and mitigate any identified risks, upholding public trust and safeguarding fundamental rights.

Penalties, Liability, and Appeals

While the Decree 98/2025 primarily focuses on establishing a framework for responsible AI deployment and oversight within the Asturian public administration, the specific details regarding penalties, liability, and appeal mechanisms within the decree itself are not extensively detailed in the provided search snippets. However, the decree's strong alignment with the European Union's AI Act (Regulation (EU) 2024/1689) implies that the broader European and national sanctioning frameworks would apply. The EU AI Act includes provisions for significant penalties for non-compliance, with prohibitions becoming effective in February 2025 and governance rules applicable from August 2025.

The decree does explicitly mention that AI systems can be withdrawn or suspended if they present risks, errors, or biases, indicating a direct consequence for non-compliant or malfunctioning systems within the public sector. For instance, if an AI system fails to guarantee cybersecurity, exhibits uncorrected biases, or poses risks, its deployment can be halted. It is reasonable to infer that severe breaches of the decree's principles, particularly those related to fundamental rights or data protection, would fall under existing Spanish administrative law and potentially the sanctioning powers established by the EU AI Act and any subsequent national implementing legislation. A Spanish national draft law for the good use and governance of AI, approved in March 2025, for example, proposes fines of up to €35 million for failing to label AI-generated content, indicating the direction of national enforcement. The Asturian decree sets the regional operational standards that would likely inform the application of such broader penalties.

Relationship to Other Instruments

The Decree 98/2025 is intricately linked to and largely inspired by the European Union's comprehensive legal framework for Artificial Intelligence, specifically Regulation (EU) 2024/1689, commonly known as the EU AI Act. The Asturian decree explicitly states its alignment with this EU regulation, aiming to adapt the necessary normative measures at a regional level to ensure that the EU AI Act effectively deploys its effects and contributes to its overarching objectives. This relationship positions the Asturian decree not as an isolated piece of legislation, but as a complementary instrument designed to operationalize and localize the broader European principles and requirements for AI governance within the specific context of the Principality's public administration.

The EU AI Act, which entered into force on August 1, 2024, with various provisions becoming applicable in phases from February 2025 to August 2027, establishes harmonized rules for AI across the Union, employing a risk-based approach. The Asturian decree mirrors this approach by focusing on ethical use, transparency, human oversight, and risk management, particularly for AI systems used in critical public services. By anticipating the full application of the EU AI Act, the Principality of Asturias demonstrates its commitment to a unified European approach to AI regulation, while also tailoring specific implementation mechanisms, such as the AI sandbox, to its regional administrative needs and innovative aspirations.

International Alignment

The international alignment of the Asturias AI Decree is primarily and strongly with the European Union's regulatory framework for Artificial Intelligence. As a regional decree within Spain, a Member State of the European Union, its foundational principles and specific provisions are designed to be consistent with, and indeed to facilitate the implementation of, the EU AI Act (Regulation (EU) 2024/1689). This alignment ensures that the Asturian public administration operates within a harmonized European standard for AI governance, promoting trust, safety, and ethical considerations across borders within the EU.

The EU AI Act itself is considered the world's first comprehensive law on AI, setting a global precedent for responsible AI development and deployment. By explicitly referencing and adapting to this regulation, the Asturias AI Decree indirectly aligns with the broader international discourse on AI ethics and governance, which often draws inspiration from the EU's risk-based approach. This includes shared principles such as the protection of fundamental rights, transparency, human oversight, data quality, and accountability, which are increasingly recognized as essential for trustworthy AI globally. The decree's emphasis on fostering innovation while mitigating risks also resonates with international efforts to balance technological advancement with societal well-being.

Implementation Timeline

MilestoneDateNotes
Decree Enactment Date2025-07-22Date the Decree 98/2025 was approved by the Government of the Principality of Asturias.
Publication in BOPA2025-07-31Date the Decree 98/2025 was published in the Boletín Oficial del Principado de Asturias (BOPA), No. 147.
Effective Date of Decree2025-10-31The Decree entered into force three months after its publication in the BOPA.
EU AI Act Prohibitions Applicable2025-02-02Certain prohibited AI practices under the EU AI Act became applicable.
EU AI Act Governance Rules & GPAI Obligations Applicable2025-08-02Rules for governance and obligations for general-purpose AI models under the EU AI Act became applicable.
Full EU AI Act Application2026-08-02The European AI Act will be fully applicable, with some exceptions.
Extended Transition for High-Risk AI in Regulated Products (EU AI Act)2027-08-02Specific high-risk AI systems embedded in regulated products have an extended transition period for EU AI Act compliance.

Compliance Checklist

CheckRequired Action
Prior AuthorizationObtain prior authorization from the competent Consejería before deploying any AI system in the Asturian public administration.
Ethical Principles AdherenceEnsure all AI systems comply with principles of transparency, explicability, fairness, and human oversight.
Fundamental Rights ProtectionVerify that AI systems respect and protect fundamental rights, preventing discrimination and biases.
Data Quality & GDPR ComplianceUtilize adequate, error-free, and unbiased data, ensuring full compliance with GDPR and data protection regulations.
Risk Assessment & MitigationConduct thorough risk assessments for AI systems and implement appropriate mitigation measures to address identified risks.
Sandbox TestingTest new AI systems in a controlled environment (AI sandbox) to evaluate suitability, detect errors, and correct biases before deployment.
Human Oversight MechanismsIntegrate mechanisms for appropriate human oversight, ensuring human autonomy and decision-making are not supplanted by AI.
Cybersecurity MeasuresImplement robust cybersecurity measures to protect AI systems and associated data from threats and vulnerabilities.
Monitoring & EvaluationEstablish ongoing technical monitoring and periodic post-implementation evaluations of AI system performance and impact.
Prohibited Practices AvoidanceEnsure no AI system engages in practices prohibited by the EU AI Act, such as harmful manipulation or social scoring.
Documentation & TraceabilityMaintain detailed documentation of AI systems, their design, data sources, and operational processes to ensure traceability and accountability.

Sources and References

SourceType
Boletín Oficial del Principado de Asturias (BOPA)Official Gazette
Asturias.es: Asturias se posiciona a la vanguardia en el uso responsable de la inteligencia artificial en la AdministraciónGovernment Press Release
Asturias.es: Conoce el nuevo Decreto que regula la IA en AsturiasGovernment Press Release
European Union: AI Act | Shaping Europe's digital futureEU Official Website
Plain English

Asturias's Decree 98/2025 sets the rules for how Artificial Intelligence (AI) systems must be used ethically and responsibly by the Principality of Asturias's public administration and its public sector.

This pioneering regulation applies to all regional government bodies and public enterprises within Asturias that develop, procure, or use AI. Its core aim is to ensure AI improves public services while strictly protecting fundamental rights and fostering innovation. The decree takes effect on October 31, 2025.

Key obligations for any team or department using AI include: - Obtaining prior authorization from the regional Ministry with jurisdiction over AI before deploying any system. - Thoroughly testing new AI systems in a "sandbox" – a controlled environment – to identify and correct errors, biases, and risks before they go live. - Ensuring AI systems are transparent, explainable, and always subject to human oversight, preventing automated decisions from overriding human judgment. - Guaranteeing the quality of data used for AI, ensuring it is adequate, error-free, unbiased, and fully compliant with General Data Protection Regulation (GDPR) and other cybersecurity standards.

The decree also explicitly prohibits AI practices deemed unacceptable by the broader European Union AI Act, such as harmful cognitive-behavioral manipulation or social scoring by authorities. While the decree itself doesn't detail specific financial penalties, non-compliant or malfunctioning AI systems can be suspended or withdrawn. Furthermore, severe breaches, especially concerning fundamental rights or data protection, would fall under existing Spanish administrative law and the significant fines outlined in the EU AI Act, which can reach tens of millions of euros. A practical pitfall to be aware of is the mandatory prior authorization and sandbox testing for *all* AI systems, which can add significant lead time and complexity to deployment plans.

Plain-English rewrite by Regulations.ai — not legal advice. Verify against the official text.

What you must do — compliance checklist

0 / 11 marked complete

Plain-English obligations under Spain - Asturias - AI Regulation (98/2025). Not legal advice — verify against the official text before relying on it.

  1. #1CriticalImplementation FrameworkBefore deploying any AI system

    Applies to: Public administration entities in Asturias deploying AI systems.

    A crucial component is the requirement for 'autorización previa' (prior authorization) before any AI system can be deployed.
  2. #2CriticalKey Focus AreasBefore deploying any AI system

    Applies to: Public administration entities in Asturias using AI systems.

    The decree explicitly prohibits practices deemed unacceptable by the European AI Act, such as harmful cognitive-behavioral manipulation or social scoring by authorities.
  3. #3CriticalKey Focus AreasBefore deploying any AI system

    Applies to: Public administration entities in Asturias using AI systems.

    A cornerstone is the protection of 'derechos fundamentales' (fundamental rights), ensuring that AI systems do not infringe upon individual liberties, promote discrimination, or perpetuate biases.
  4. #4CriticalKey Focus AreasBefore deploying any AI system

    Applies to: Public administration entities in Asturias using AI systems.

    mandating that data used for AI training and operation must be adequate, free from errors, and devoid of biases, while complying with the General Data Protection Regulation (GDPR).
  5. #5CriticalKey Focus AreasBefore deploying any AI system

    Applies to: Public administration entities in Asturias using AI systems.

    Furthermore, 'ciberseguridad' is a paramount concern, with provisions to guarantee the security and resilience of AI systems against attacks and vulnerabilities.
  6. #6CriticalKey Focus AreasBefore deploying any AI system

    Applies to: Public administration entities in Asturias using AI systems.

    The decree also mandates 'supervisión humana,' ensuring that human oversight is maintained, and automated decisions do not override human autonomy or judgment.
  7. #7CriticalImplementation FrameworkBefore full-scale deployment

    Applies to: Public administration entities in Asturias deploying new AI systems.

    These regulatory sandboxes provide a safe and controlled environment for testing AI systems... before full-scale deployment.
  8. #8CriticalImplementation FrameworkBefore deploying any AI system

    Applies to: Public administration entities in Asturias deploying AI systems.

    This phased approach enables the detection and correction of errors or biases, minimizing potential risks to citizens and public services.
  9. #9CriticalOverviewOngoing

    Applies to: Public administration entities in Asturias using AI systems.

    guarantee that all AI applications utilized by the Asturian administration adhere strictly to ethical principles, ensure security, and respect fundamental rights
  10. #10ImportantMonitoring and EvaluationOngoing

    Applies to: Public administration entities in Asturias using AI systems.

    it mandates a robust framework for 'monitorización técnica' and ongoing evaluation of AI systems once they are in operation within the public administration.
  11. #11ImportantKey Focus AreasOngoing

    Applies to: Public administration entities in Asturias using AI systems.

    requiring AI systems to be understandable, their decision-making processes traceable, and their outcomes justifiable to human operators and citizens.

© Regulations.AI — created on 06-Jan-2026 using Gemini 2.5 Flash