Spain - Galicia - AI Regulation (2/2025)

Galicia AI Law 2/2025

Ley de Inteligencia Artificial de Galicia 2/2025

Spain

RAI-ES-GA-GALAI22-2025
Effective: April 4, 2025
In Force(In Force)
ActGovernance and OversightRisk ManagementFundamental Rights
Export PDF

The Galicia AI Law 2/2025 establishes a comprehensive framework for AI systems in the public sector, promoting ethical deployment, innovation, and citizen rights.

Overview

The Galicia AI Law 2/2025, formally known as "Ley 2/2025, de 2 de abril, para el desarrollo e impulso de la inteligencia artificial en Galicia," represents a landmark legislative effort by the Autonomous Community of Galicia, Spain, to establish a comprehensive and forward-looking regulatory framework for artificial intelligence. Enacted on April 2, 2025, and published in the Diario Oficial de Galicia (DOGA) on April 4, 2025, this law is designed to govern the entire lifecycle of AI systems, from their initial design and acquisition to their implementation and ongoing use within the General Administration of Galicia and its broader public sector. The core objective is to ensure that the deployment of AI technologies is conducted responsibly, ethically, and with a steadfast focus on human well-being and fundamental rights. This regional initiative is particularly significant as it anticipates and complements the broader European Union AI Act, demonstrating Galicia's commitment to aligning its digital transformation strategy with leading international standards for AI governance.

Beyond its regulatory scope over public administration, the law also strategically aims to stimulate and support the growth of artificial intelligence capabilities across Galicia's private enterprise, research institutions, and innovation ecosystem. By fostering a conducive environment for AI development, the legislation seeks to enhance regional productivity, bolster competitiveness, and position Galicia as a hub for advanced AI solutions. This dual focus—regulating the responsible use of AI in the public sphere while simultaneously promoting its innovative application in the private sector—underscores a holistic approach to integrating AI into the region's socio-economic fabric. The law is a direct response to the transformative potential of AI, acknowledging both its capacity to drive efficiency and address societal challenges, as well as the imperative to mitigate associated ethical, legal, and social risks.

Definitions

The Galicia AI Law 2/2025 provides foundational definitions to ensure clarity and consistent application of its provisions. Central to the law is the definition of a "Sistema de Inteligencia Artificial" (Artificial Intelligence System). This term is explicitly aligned with the definitions established by the European Union's independent high-level expert group on artificial intelligence and the Organisation for Economic Co-operation and Development (OECD). According to this framework, an AI system is understood as any system that demonstrates intelligent behavior by analyzing its environment and taking actions, with a certain degree of autonomy, to achieve specific objectives. This broad definition encompasses a wide array of AI applications, ranging from purely software-based programs to those integrated into physical hardware.

Specifically, the law clarifies that AI systems can manifest as software programs, such as voice assistants, image analysis applications, search engines, or facial and voice recognition systems. Alternatively, they can be embedded within hardware devices, including advanced robots, autonomous vehicles, unmanned aerial vehicles, or various applications within the Internet of Things (IoT). This comprehensive scope ensures that the regulatory provisions of the law are applicable across the diverse spectrum of AI technologies currently in use or under development. The inclusion of these internationally recognized definitions underscores Galicia's commitment to harmonizing its regional AI governance with broader European and global standards, facilitating interoperability and a shared understanding of AI's operational boundaries and ethical considerations.

Governance and Institutional Framework

The Galicia AI Law 2/2025 establishes a robust governance and institutional framework designed to oversee and guide the responsible development and deployment of artificial intelligence within the autonomous community. A cornerstone of this framework is the creation of the "Comité Gallego de Inteligencia Artificial" (Galician AI Committee). This collegiate body serves as a central coordinating, advisory, promotional, and monitoring entity for AI policy across Galicia. Its composition is designed to be multi-stakeholder, including representatives from the autonomous administration, leading AI experts, academic institutions (specifically universities and technological centers), and representatives from the economic and social sectors. This diverse representation ensures that AI policies are informed by a wide range of perspectives, fostering a balanced approach that considers technological advancement, ethical implications, and societal impact.

Further reinforcing the governance structure, the law introduces the novel figure of "Comisionados de Inteligencia Artificial" (AI Commissioners). These commissioners are entrusted with a critical role in ensuring adherence to the principles and obligations stipulated by the law, particularly concerning the prevention, detection, and mitigation of risks and negative outcomes associated with AI system implementation. They constitute a crucial element within the internal governance mechanism of the autonomous administration, acting as dedicated guardians of responsible AI deployment in the public sector. Additionally, an "Oficina de Inteligencia Artificial" (Office of Artificial Intelligence) is established to monitor and track AI projects, providing ongoing oversight throughout their lifecycle, from design to deactivation. This multi-layered institutional setup reflects a proactive strategy to embed ethical considerations and accountability mechanisms directly into the operational fabric of Galician public administration's engagement with AI.

Key Focus Areas

The Galicia AI Law 2/2025 delineates several key focus areas, underpinned by a comprehensive set of principles and citizen rights, to ensure the ethical and responsible integration of artificial intelligence. The law emphasizes that the design, acquisition, implementation, and use of AI systems by the Galician public administration must strictly adhere to principles of good digital administration and due diligence. Core principles guiding AI development and deployment include auditability, traceability, and explicability, ensuring that AI decisions and processes can be understood and reviewed. Transparency and clarity are paramount, mandating that the operation and outcomes of AI systems are comprehensible to both administrators and citizens. Furthermore, the law explicitly promotes impartiality and the absence of biases, alongside robust provisions for security and privacy, safeguarding against discriminatory outcomes and protecting personal data.

Crucially, the legislation enshrines the principle of human oversight, often referred to as 'reserva de humanidad' or human review, ensuring that human intervention is always possible, especially in decisions with significant impact. Universal accessibility is also a key tenet, aiming for AI systems that are usable by all citizens, including those with disabilities. Reliability and responsibility are stressed, requiring AI systems to function consistently and predictably, with clear accountability mechanisms. The law also mandates continuous evaluation and impact assessments—organizational, economic, social, and environmental—to proactively identify and address potential negative consequences. Principles of precaution, continuous training, collaboration, and technical capacity, proportionality, and financial sufficiency further guide the responsible development and implementation of AI. Complementing these principles, the law establishes specific citizen rights, including the right to transparency regarding AI involvement in administrative decisions, the right to request human review of automated decisions, and the right to equality and legal protection against adverse AI outcomes.

Implementation Framework

The implementation framework for the Galicia AI Law 2/2025 is designed to integrate its principles and requirements into the operational practices of the Galician public sector and to foster AI innovation across the region. A significant aspect of this framework involves strategic planning, where the potential of artificial intelligence is to be analyzed and incorporated into the master plans for various industrial sectors. This ensures that AI is not merely a technological add-on but an integral component of Galicia's industrial policy, driving development and competitiveness. The law promotes the identification of AI-related projects as strategic, aligning them with the objectives of the European Union and recognizing the AI sector as one of special importance for regional growth. This strategic prioritization aims to channel resources and support towards initiatives that leverage AI for public benefit and economic advancement.

Furthermore, the implementation framework emphasizes mechanisms for inter-administrative coordination and robust collaboration between the public and private sectors. This collaborative approach is vital for knowledge transfer, resource sharing, and the co-creation of AI solutions that meet the specific needs of Galicia. The law mandates that the design, acquisition, and deployment of AI systems by the public administration must adhere to principles of good digital administration, ensuring diligence and proactive risk management throughout the AI lifecycle. A public registry of AI systems used by the autonomous public sector is also envisioned, which will document the entire lifecycle of these systems, from design to deactivation, thereby enhancing transparency and accountability. The law aims to provide a secure and ethical environment for both citizens and businesses, while simultaneously attracting investments linked to the AI sector, thereby consolidating Galicia's position as a leading region in AI development and application.

Monitoring and Evaluation

The Galicia AI Law 2/2025 places significant emphasis on robust monitoring and continuous evaluation mechanisms to ensure the ongoing responsible and ethical use of artificial intelligence systems. A core requirement is the obligation for the public administration to actively identify, trace, and manage risks associated with the design and implementation of AI systems. This proactive risk management approach is intended to span the entire lifecycle of an AI system, from its initial conceptualization and development through its deployment and eventual deactivation. The law recognizes that AI systems, particularly those with a high degree of autonomy and decision-making capacity, necessitate vigilant oversight to prevent unintended negative consequences and to ensure their continued alignment with legal and ethical standards.

To facilitate transparency and accountability, the law mandates that AI systems employed in the autonomous public sector must be auditable, traceable, and understandable by all relevant stakeholders, including citizens. This commitment to explicability is further supported by the requirement for these systems to be accessible in a public registry. This registry is designed to capture comprehensive information about each AI system's lifecycle, providing a transparent record of its design, operational parameters, and any modifications or deactivations. The establishment of the Office of Artificial Intelligence is central to this monitoring function, as it is tasked with following and overseeing AI projects. The AI Commissioners also play a vital role in ensuring compliance with principles and obligations, particularly concerning risk prevention and the detection of negative outcomes. This multi-faceted approach to monitoring and evaluation underscores the law's dedication to fostering trustworthy AI that is both lawful and ethically sound.

Penalties, Liability, and Appeals

While the provided summaries of the Galicia AI Law 2/2025 highlight a strong emphasis on responsible AI development, ethical principles, and robust governance structures, they do not explicitly detail specific penalties, liability regimes, or appeal mechanisms. The law establishes a comprehensive framework of obligations for the Galician public administration and other entities involved in the design, acquisition, and use of AI systems, particularly concerning risk management, transparency, and the protection of fundamental rights. The creation of AI Commissioners and the Galician AI Committee, along with the Office of Artificial Intelligence, signifies a dedicated oversight and enforcement architecture. This institutional setup inherently implies that non-compliance with the established principles and obligations would lead to administrative consequences, consistent with general administrative law principles governing public sector conduct and accountability.

It is reasonable to infer that the full text of the law, or subsequent implementing regulations, would detail the specific administrative sanctions for breaches of its provisions, potentially referencing existing regional or national administrative penalty frameworks. For citizens, the rights to transparency, human supervision, equality, and legal protection in AI-driven administrative decisions suggest avenues for appeal and redress. These rights would likely be exercised through established administrative procedures, allowing individuals to challenge decisions made or influenced by AI systems and seek human review or other forms of recourse. The law's alignment with the EU AI Act and national Spanish regulations further suggests that its liability and appeals provisions would be harmonized with these broader legal instruments, ensuring a coherent and effective system for addressing grievances and enforcing compliance in the evolving landscape of artificial intelligence. Specific details regarding fines, compensation, or other forms of redress would be elaborated within the complete legislative document.

Relationship to Other Instruments

The Galicia AI Law 2/2025 is intricately positioned within a broader legal and strategic landscape, demonstrating a clear relationship with both European Union and national Spanish instruments. The law explicitly states its objective to establish a framework for AI in Galicia "in conformity with the regulation of the European Union and the basic state regulations in this matter, of which it constitutes its development and execution in the Autonomous Community of Galicia." This foundational statement underscores its role as a complementary and implementing piece of legislation, designed to localize and operationalize higher-level directives. Notably, the law was approved after the publication of the EU AI Act (Regulation (UE) 2024/1689), and its development was influenced by explicit requests from the Parliament of Galicia for the Xunta de Galicia to adopt the framework of the European AI Regulation even before its full entry into force.

Furthermore, the Galician law builds upon existing regional legislation that governs the organization and functioning of the autonomous administration and its public sector. This includes, but is not limited to, Ley 16/2010 on the organization and functioning of the Galician public sector, Ley 14/2013 on the rationalization of the public sector, Ley 1/2015 on the guarantee of quality in public services and good administration, and Ley 4/2019 on digital administration in Galicia. These prior laws provide the foundational legal and administrative context within which the AI Law operates, ensuring continuity and integration with established governance principles and digital transformation efforts. The regional law also complements national Spanish initiatives, such as the establishment of the Spanish Agency for the Supervision of Artificial Intelligence (AESIA) and the AI Regulatory Sandbox, contributing to a multi-level governance approach for AI across Spain.

International Alignment

The Galicia AI Law 2/2025 demonstrates a strong commitment to international alignment, particularly with leading European and global frameworks for artificial intelligence governance. The law explicitly states its intention to conform with and develop upon the regulations of the European Union, making it a key regional implementation of the broader European strategy for AI. This alignment is most evident in its relationship with the European Union AI Act (Regulation (EU) 2024/1689), which establishes harmonized rules for artificial intelligence across the EU. The Galician law was drafted with the EU AI Act in mind, even responding to parliamentary requests to adopt its framework prior to its full entry into force, showcasing a proactive approach to regulatory harmonization.

Moreover, the law's definition of "Artificial Intelligence System" itself is aligned with the definition proposed by the Organisation for Economic Co-operation and Development (OECD) in May 2019, as well as the EU's independent high-level expert group on artificial intelligence. This adherence to internationally recognized definitions ensures conceptual consistency and facilitates cross-border understanding and cooperation in AI development and regulation. By adopting principles such as human-centricity, safety, reliability, transparency, and ethical considerations, the Galician law mirrors the core values promoted by international bodies seeking to foster trustworthy AI. This strategic international alignment not only positions Galicia at the forefront of responsible AI governance but also facilitates collaboration, research, and innovation within a globally recognized ethical and regulatory landscape.

Implementation Timeline

MilestoneDateNotes
Parliamentary Approval2025-04-02Law 2/2025 approved by the Parliament of Galicia.
Publication in Diario Oficial de Galicia (DOGA)2025-04-04Official publication of the law, marking its entry into force unless otherwise specified.
Publication in Boletín Oficial del Estado (BOE)2025-10-20National official publication for record-keeping and broader dissemination.
Establishment of AI Governance BodiesOngoing from 2025-04-04Creation and operationalization of the Galician AI Committee, AI Commissioners, and Office of Artificial Intelligence as per the law's provisions.
Integration of AI Principles into Public AdministrationOngoing from 2025-04-04Implementation of principles like transparency, auditability, human oversight, and risk management in public sector AI projects.
Development of Public AI System RegistryTo be determinedEstablishment of a public registry for AI systems used by the autonomous public sector, detailing their lifecycle.

Compliance Checklist

CheckRequired Action
AI System Design and AcquisitionEnsure all AI systems are designed and acquired in full compliance with the principles of good digital administration, due diligence, and human-centricity.
Risk Management FrameworkEstablish and maintain mechanisms for identifying, tracing, and actively managing risks throughout the entire lifecycle of AI systems, involving public and private agents where applicable.
Transparency and ExplicabilityGuarantee that AI systems are auditable, traceable, and their decision-making processes are explicable and understandable to citizens and oversight bodies.
Bias Prevention and Non-DiscriminationImplement measures to ensure impartiality and the absence of biases in AI systems, upholding fundamental rights and preventing discriminatory outcomes.
Data Security and PrivacyAdhere to strict data security and privacy protocols in the handling of personal data by AI systems, in line with applicable data protection regulations.
Human Oversight and ReviewEnsure mechanisms for human supervision and intervention are in place for AI-driven administrative decisions, allowing for human review and challenge.
Public Registry ComplianceRegister all AI systems used by the autonomous public sector in the designated public registry, providing comprehensive lifecycle information.
Impact AssessmentConduct continuous organizational, economic, social, and environmental impact assessments for AI systems.
Training and Capacity BuildingPromote continuous training and ensure adequate technical capacity and financial sufficiency for responsible AI development and use.
Collaboration and TransferFoster collaboration and knowledge transfer between public and private sectors, as well as research and innovation ecosystems.

Sources and References

SourceType
LEY 2/2025, de 2 de abril, para el desarrollo e impulso de la inteligencia artificial en Galicia. DOG Núm. 66, Viernes, 4 de abril de 2025.official
Ley 2/2025, de 2 de abril, para el desarrollo e impulso de la inteligencia artificial en Galicia. BOE núm. 252, lunes 20 de octubre de 2025.official
Ley 2/2025, de 2 de abril, para el desarrollo e impulso de la inteligencia artificial en Galicia - Portal Transparenciagovernment
Plain English

The Galicia AI Law 2/2025 establishes a comprehensive framework for how artificial intelligence systems are designed, acquired, and used by the public sector in Galicia, Spain, ensuring ethical deployment, innovation, and the protection of citizen rights. This landmark legislation primarily applies to the General Administration of Galicia and its public entities, aiming to integrate AI responsibly while also fostering its growth in the private sector and research institutions across the region.

Taking effect on April 4, 2025, the law mandates that all AI systems within the public administration adhere to strict principles. These include transparency, auditability, and explicability, meaning AI decisions and processes must be understandable and reviewable. Impartiality, security, and privacy are also paramount, preventing bias and protecting data. Crucially, the law requires human oversight, ensuring that human intervention is always possible, especially for decisions with significant impact on citizens. Public bodies must also proactively identify, trace, and manage risks throughout an AI system's entire lifecycle, and maintain a public registry detailing these systems for accountability.

While the law doesn't explicitly detail specific fines, it establishes a robust governance structure, including a Galician AI Committee, dedicated AI Commissioners, and an Office of Artificial Intelligence. This framework implies that non-compliance will lead to administrative consequences, consistent with general public sector accountability. Citizens gain specific rights, such as the right to transparency about AI involvement in decisions and the right to request human review of automated outcomes, providing avenues for appeal. A practical pitfall for teams is the law's broad definition of an "Artificial Intelligence System," which aligns with EU and OECD standards, encompassing a wide range of software and hardware applications. This means many systems might fall under its stringent requirements, necessitating early and thorough compliance checks, particularly regarding the mandatory human oversight for critical functions.

Plain-English rewrite by Regulations.ai — not legal advice. Verify against the official text.

What you must do — compliance checklist

0 / 11 marked complete

Plain-English obligations under Spain - Galicia - AI Regulation (2/2025). Not legal advice — verify against the official text before relying on it.

  1. #1CriticalKey Focus AreasOngoing from 2025-04-04

    Applies to: Galician public administration deploying AI systems.

    The design, acquisition, implementation, and use of AI systems by the Galician public administration must strictly adhere to principles of good digital administration and due diligence.
  2. #2CriticalMonitoring and EvaluationOngoing from 2025-04-04

    Applies to: Galician public administration deploying AI systems.

    A core requirement is the obligation for the public administration to actively identify, trace, and manage risks associated with the design and implementation of AI systems.
  3. #3CriticalKey Focus AreasOngoing from 2025-04-04

    Applies to: Galician public administration deploying AI systems.

    Core principles guiding AI development and deployment include auditability, traceability, and explicability, ensuring that AI decisions and processes can be understood and reviewed.
  4. #4CriticalKey Focus AreasOngoing from 2025-04-04

    Applies to: Galician public administration deploying AI systems.

    Furthermore, the law explicitly promotes impartiality and the absence of biases, alongside robust provisions for security and privacy, safeguarding against discriminatory outcomes.
  5. #5CriticalKey Focus AreasOngoing from 2025-04-04

    Applies to: Galician public administration deploying AI systems.

    Furthermore, the law explicitly promotes impartiality and the absence of biases, alongside robust provisions for security and privacy, safeguarding against discriminatory outcomes and protecting personal data.
  6. #6CriticalKey Focus AreasOngoing from 2025-04-04

    Applies to: Galician public administration deploying AI systems.

    Crucially, the legislation enshrines the principle of human oversight... ensuring that human intervention is always possible, especially in decisions with significant impact.
  7. #7ImportantImplementation FrameworkTo be determined

    Applies to: Galician public administration deploying AI systems.

    A public registry of AI systems used by the autonomous public sector is also envisioned, which will document the entire lifecycle of these systems, from design to deactivation.
  8. #8ImportantKey Focus AreasOngoing from 2025-04-04

    Applies to: Galician public administration deploying AI systems.

    The law also mandates continuous evaluation and impact assessments—organizational, economic, social, and environmental—to proactively identify and address potential negative consequences.
  9. #9ImportantKey Focus AreasOngoing from 2025-04-04

    Applies to: Galician public administration deploying AI systems.

    Reliability and responsibility are stressed, requiring AI systems to function consistently and predictably, with clear accountability mechanisms.
  10. #10ImportantKey Focus AreasOngoing from 2025-04-04

    Applies to: Galician public administration deploying AI systems.

    Universal accessibility is also a key tenet, aiming for AI systems that are usable by all citizens, including those with disabilities.
  11. #11RecommendedKey Focus AreasOngoing from 2025-04-04

    Applies to: Galician public administration.

    Principles of precaution, continuous training, collaboration, and technical capacity, proportionality, and financial sufficiency further guide the responsible development and implementation of AI.

© Regulations.AI — created on 03-Jan-2026 using Gemini 2.5 Flash