Spain - Galicia - AI Development Law (2/2025)

Law 2/2025, of April 2, for the development and promotion of artificial intelligence in Galicia

Ley 2/2025, de 2 de abril, para el desarrollo e impulso de la inteligencia artificial en Galicia

Spain

RAI-ES-GA-L2D2DXX-2025
Effective: April 4, 2025
In Force(In Force)
ActGovernance and OversightTransparency and DisclosureFundamental Rights
Export PDF

Galicia's Ley 2/2025 is Europe's first regional AI law, establishing an ethical framework for public sector AI, aligning with EU standards, and protecting citizen rights.

Overview

The Law 2/2025, of April 2, for the development and promotion of artificial intelligence in Galicia (Ley 2/2025, de 2 de abril, para el desarrollo e impulso de la inteligencia artificial en Galicia), marks a pioneering legislative effort within Europe to establish a comprehensive framework for the ethical and responsible use of Artificial Intelligence (AI) within a regional public administration. Enacted by the Parliament of Galicia, this law primarily focuses on regulating the design, acquisition, implementation, and use of AI systems by the General Administration of the Autonomous Community of Galicia and its broader public sector. It serves as a crucial regional development and execution of the overarching European Union AI Act (Regulation (EU) 2024/1689) and national Spanish basic regulations on AI, demonstrating Galicia's commitment to aligning with broader European values and standards in digital governance. The legislation not only sets forth a robust ethical and operational framework for public sector AI but also aims to foster the growth and integration of AI technologies across Galicia's business, research, and innovation ecosystems, positioning the region as a leader in trustworthy AI development.

The law's objectives extend beyond mere regulation, encompassing a strategic vision to leverage AI for improved public services, economic competitiveness, and societal well-being. It responds to explicit requests from the Galician Parliament to adopt the principles of the European AI Regulation and develop necessary regional legislation. Furthermore, it builds upon Galicia's existing digital administration laws and its "Galician AI Strategy 2030," which has already committed significant public investment to AI development. By defining general principles, strengthening citizen rights, and establishing a dedicated governance structure, the law seeks to ensure that AI adoption in Galicia is human-centric, safe, reliable, and respectful of fundamental rights and the environment. This proactive approach aims to balance technological advancement with robust safeguards, ensuring that AI contributes positively to the region's future while mitigating potential risks.

Definitions

The Law 2/2025 establishes clear definitions to delineate its scope and application within the Galician context, aligning with international and European understandings of AI. A central definition is that of an "Artificial Intelligence System" (Sistema de Inteligencia Artificial), which refers to any machine-based system that, for explicit or implicit objectives, infers from the input it receives how to generate outputs such as predictions, content, recommendations, or decisions that can influence physical or virtual environments. This definition is explicitly stated to be in line with the proposals from the Organisation for Economic Co-operation and Development (OECD) and the European institutions, ensuring consistency with broader international standards and the EU AI Act. This foundational definition is critical for determining which technologies fall under the regulatory purview of the law.

Beyond the technical definition of AI systems, the law also clarifies the entities to which it applies, primarily focusing on the "General Administration of the Autonomous Community of Galicia and its public sector" (Administración General de la Comunidad Autónoma de Galicia y su sector público). This encompasses the core governmental departments, agencies, and all instrumental entities that constitute the public sector of Galicia. The law also implicitly defines key operational concepts through its principles, such as "auditability," "traceability," "explainability," "absence of bias," and "human review," which, while not always presented as explicit dictionary definitions, are integral to understanding the expected characteristics and functionalities of AI systems deployed within the public administration. These conceptual definitions guide the ethical and responsible development and deployment of AI, ensuring that systems are understandable, accountable, and subject to human oversight.

Governance and Institutional Framework

The Galician AI Law establishes a robust governance and institutional framework designed to oversee and guide the responsible development and deployment of AI within the autonomous community. A cornerstone of this framework is the creation of the "Artificial Intelligence Office of Galicia" (Oficina de Inteligencia Artificial de Galicia). This office is envisioned as a central coordinating body, tasked with spearheading AI projects, fostering the adoption of best practices, and ensuring coherent implementation of the law's provisions across the Galician public sector. Its mandate includes facilitating inter-departmental collaboration, providing technical guidance, and serving as a point of reference for AI-related initiatives, thereby institutionalizing a dedicated mechanism for AI governance at the regional level.

Complementing the Office, the law also mandates the establishment of the "Galician Council of Artificial Intelligence" (Consejo Gallego de Inteligencia Artificial). This council is designed to function as an advisory body, bringing together diverse expertise to offer strategic recommendations on AI policy, ethical considerations, and long-term development strategies for Galicia. Furthermore, the legislation introduces the figure of an "AI Commissioner" (Comisionado de Inteligencia Artificial), whose role is to supervise the prevention, detection, and mitigation of risks associated with AI technologies. This commissioner will play a critical role in ensuring that AI systems are deployed safely and ethically, acting as an independent oversight mechanism to uphold the principles and rights enshrined in the law. These institutional innovations collectively aim to create a comprehensive, multi-layered governance structure capable of navigating the complexities of AI development and ensuring its alignment with public interest and fundamental rights.

Key Focus Areas

The Galician AI Law is underpinned by a comprehensive set of "Guiding Principles" (Principios Rectores) that must govern the actions of the autonomous administration in the design, acquisition, implementation, and use of AI systems. These principles include good digital administration and due diligence, emphasizing ethical conduct and careful planning. Crucially, the law mandates principles of auditability, traceability, and explainability, ensuring that AI systems' operations and decisions can be understood and reviewed. Transparency and clarity are also paramount, requiring that the use of AI is communicated clearly to citizens. The law explicitly addresses impartiality and the absence of biases, aiming to prevent discrimination and ensure equitable outcomes. Security and privacy are fundamental, aligning with existing data protection regulations.

Furthermore, the law enshrines the principles of human reservation and human review, ensuring that human oversight remains central to administrative processes involving AI. Proactivity, personalization, universality, and accessibility are emphasized to ensure that AI-driven public services are inclusive and responsive to citizen needs. Reliability and responsibility are core tenets, alongside continuous evaluation and a precautionary approach to mitigate unforeseen risks. The law also promotes continuous training, collaboration, and knowledge transfer, recognizing the evolving nature of AI. Importantly, it mandates an assessment of the organizational, economic, social, and environmental impact of AI systems, and requires an "Evaluation of Impact on Fundamental Rights" (Evaluación de Impacto en Derechos Fundamentales) for AI projects, aligning with models from the European Artificial Intelligence Office. Citizens are granted specific rights, including the right to know when an AI system intervenes in an administrative decision, to request a human review of such decisions, and to file complaints regarding AI system operations.

Implementation Framework

The implementation framework of the Galician AI Law is designed to ensure that the principles and objectives of the legislation are translated into practical application within the public administration. A key component of this framework is the requirement for an "AI project report" (informe del proyecto de inteligencia artificial) as a nuclear element of any procedure involving the design, acquisition, implementation, or use of AI systems. This report must detail the functional needs to be covered, justify the necessity and opportunity of employing specific AI systems, and outline the technical characteristics and specifications. It also requires a plan for the management of the data proposed for training, validation, and testing, specifying whether it contains a combination of personal and non-personal data.

Integral to this implementation is the mandatory "Evaluation of Impact on Fundamental Rights" (Evaluación de Impacto en Derechos Fundamentales), which must accompany AI projects. This assessment is to be conducted in accordance with the model provided by the European Artificial Intelligence Office, ensuring alignment with broader EU standards for human rights protection in AI development. The law also emphasizes the provision of guides and self-diagnosis tools to facilitate the adoption and use of AI systems by the Galician public administration, ensuring that public entities have the necessary resources and support for compliance. This comprehensive approach aims to embed responsible AI practices throughout the lifecycle of AI systems within the public sector, from initial conception to operational deployment and ongoing management.

Monitoring and Evaluation

The Galician AI Law places significant emphasis on continuous monitoring and evaluation to ensure the ongoing effectiveness, safety, and ethical compliance of AI systems deployed within the public sector. The established governance bodies, particularly the Artificial Intelligence Office of Galicia and the AI Commissioner, are central to this oversight function. Their roles include coordinating projects, promoting best practices, and supervising the prevention, detection, and mitigation of risks associated with AI technologies. This continuous vigilance is crucial for adapting to the rapidly evolving nature of AI and addressing any emergent challenges or unintended consequences. The law's principles, such as continuous evaluation and a precautionary approach, underscore this commitment to dynamic oversight.

Furthermore, the law implicitly supports monitoring through its requirements for auditability, traceability, and explainability of AI systems. By mandating that AI processes and decisions be understandable and reviewable, it creates an inherent mechanism for scrutiny and accountability. The requirement for an "AI project report" and an "Evaluation of Impact on Fundamental Rights" at the outset of AI initiatives also serves as a baseline for subsequent monitoring, allowing for the assessment of actual impacts against initial projections. The development of an inventory to register the lifecycle of each AI system, from design to deactivation, as mentioned in related discussions, further enhances the ability to track and evaluate AI deployments. This comprehensive approach to monitoring and evaluation aims to ensure that AI in Galicia's public sector remains aligned with its ethical principles and delivers beneficial, safe, and rights-respecting outcomes.

Penalties, Liability, and Appeals

While the Ley 2/2025 primarily focuses on establishing a framework for responsible AI use within the Galician public sector, it operates within a broader Spanish and European legal context that addresses penalties and liability. The Galician law itself outlines the principles and obligations for its public administration, emphasizing compliance with these guidelines to ensure ethical and safe AI deployment. For instance, it grants citizens the right to request a human review of AI-assisted administrative decisions and to file complaints, suggesting internal administrative mechanisms for redress. However, specific monetary penalties or detailed liability regimes for non-compliance by the Galician public administration are generally deferred to the broader framework of administrative law and, increasingly, to national and European AI-specific legislation.

In the wider Spanish context, a Preliminary Draft Law for the Good Use and Governance of Artificial Intelligence has been approved, which explicitly introduces significant penalties for non-compliance, particularly concerning the mandatory labeling of AI-generated content. This national draft law proposes fines ranging from €7.5 million to €15 million (or up to 3% of global turnover) for very serious infringements, and €500,000 to €7.5 million (or up to 2% of worldwide turnover) for serious infringements. The Spanish Agency for the Supervision of Artificial Intelligence (AESIA), based in A Coruña (Galicia), is designated as the enforcement authority for this national framework, with the capacity to impose sanctions from August 2025. While the Galician law sets the regional standard for public sector AI, the enforcement of broader AI regulations, including penalties and liability for providers and deployers, will increasingly fall under the purview of national and EU bodies like AESIA and the EU AI Act.

Relationship to Other Instruments

The Galician AI Law is meticulously designed to integrate with and build upon a layered legal and strategic landscape, encompassing both regional and supra-national instruments. Regionally, it explicitly states its development and execution role in relation to existing Galician laws concerning digital administration, the organization and functioning of the public sector, and the guarantee of quality in public services and good administration. This ensures a cohesive legal environment where AI adoption enhances, rather than disrupts, established administrative principles and citizen rights. For instance, the law aligns with the Ley 4/2019, de 17 de julio, de administración digital de Galicia, and the Ley 1/2015, de 1 de abril, de garantía de la calidad de los servicios públicos y de la buena administración, reinforcing the commitment to efficient, transparent, and citizen-centric public services in the digital age.

At the national and European levels, the Galician AI Law positions itself as a complementary and implementing framework. It explicitly states its conformity with the regulation of the European Union and basic state legislation on AI, acting as a regional development thereof. This is particularly significant in light of the EU AI Act (Regulation (EU) 2024/1689), which establishes a comprehensive, harmonized legal framework for AI across the EU. The Galician law's principles and requirements, such as the mandatory "Evaluation of Impact on Fundamental Rights" following the European AI Office's model, demonstrate a clear commitment to aligning with the EU's risk-based approach and ethical guidelines. This multi-level integration ensures that AI development and deployment in Galicia are consistent with broader legal standards, promoting a unified and trustworthy approach to AI governance across different jurisdictions.

International Alignment

The Galician AI Law demonstrates a strong commitment to international alignment, explicitly drawing inspiration and guidance from leading global and European initiatives on AI ethics and regulation. The preamble and various provisions of the law highlight its connection with the principles and recommendations put forth by multilateral organizations such as the Organisation for Economic Co-operation and Development (OECD), the European Commission, and the Council of Europe. These organizations have actively encouraged governments to develop policy environments that enable the reliable and secure adoption of AI systems, and the Galician law directly responds to this call by integrating widely recognized ethical principles into its framework. This proactive alignment ensures that Galicia's approach to AI governance is not insular but rather contributes to a global consensus on responsible AI.

Crucially, the law is in full connection with the principles and obligations stipulated in the European Union's AI Act (Regulation (EU) 2024/1689), which was published on July 12, 2024. The Galician law explicitly states that it constitutes a development and execution of the EU AI Act within the Autonomous Community of Galicia, indicating a direct legislative lineage and a commitment to harmonized standards. It clarifies that its provisions do not impose additional requirements for high-risk AI systems beyond those already foreseen in the community norm, thus ensuring regulatory consistency and avoiding fragmentation. Furthermore, the law acknowledges the UNESCO Recommendation on the Ethics of Artificial Intelligence, adopted by 193 member states in November 2021, as a systematic normative reflection that can guide societies in responsibly addressing the known and unknown effects of AI technologies. This broad international alignment underscores Galicia's dedication to fostering trustworthy, human-centric, and ethically sound AI development.

Implementation Timeline

MilestoneDateNotes
Approval by Parliament of Galicia2025-04-02The law was approved by the Galician Parliament.
Publication in Diario Oficial de Galicia (DOGA)2025-04-04Official publication in the regional gazette, marking its formal promulgation in Galicia.
Publication in Boletín Oficial del Estado (BOE)2025-10-20Official publication in the national Spanish gazette, ensuring broader legal recognition.
Entry into ForceVariesThe law generally entered into force following its publication, with specific provisions potentially having staggered application dates in line with broader EU AI Act implementation.
AESIA Sanctioning Capacity (National)2025-08-01The Spanish Agency for the Supervision of Artificial Intelligence (AESIA) gains capacity to impose sanctions under national AI frameworks, which may interact with the Galician law.

Compliance Checklist

CheckRequired Action
AI System IdentificationDetermine if the system falls under the definition of an 'Artificial Intelligence System' as per the law.
Public Sector ApplicabilityConfirm if the AI system is being designed, acquired, implemented, or used by the General Administration of Galicia or its public sector.
Principle AdherenceEnsure the AI system and its deployment adhere to all 'Guiding Principles' (Principios Rectores), including transparency, explainability, absence of bias, security, and privacy.
AI Project ReportPrepare a comprehensive AI project report, detailing functional needs, technical specifications, and data management plans for training, validation, and testing.
Fundamental Rights Impact AssessmentConduct an 'Evaluation of Impact on Fundamental Rights' for the AI project, utilizing the model provided by the European Artificial Intelligence Office.
Human Oversight MechanismIntegrate mechanisms for human reservation and review, ensuring human oversight in administrative decisions assisted by AI.
Citizen Rights ProvisionInform citizens about the use of AI in administrative decisions and establish clear procedures for them to request human review and file complaints.
Data Management PlanDevelop and implement a robust plan for the management of data used by the AI system, ensuring compliance with data protection and privacy regulations.
Continuous EvaluationEstablish processes for the continuous monitoring and evaluation of the AI system's performance, safety, and ethical compliance throughout its lifecycle.
Training and Capacity BuildingEnsure relevant personnel involved in AI system development and deployment receive continuous training on ethical AI use and compliance.

Sources and References

SourceType
Ley 2/2025, de 2 de abril, para el desarrollo e impulso de la inteligencia artificial en Galiciaofficial
LEY 2/2025, de 2 de abril, para el desarrollo e impulso de la inteligencia artificial en Galicia.official
Galicia se coloca a la vanguardia en el desarrollo de la IA con la aprobación de la primera ley regional que la regula en Europa - Xunta de Galiciagovernment
Galicia colócase á vangarda no desenvolvemento da IA coa aprobación da primeira Lei Rexional que a regula en Europa | Amtegagovernment
Ley IA | Amtega - Xunta de Galiciagovernment
Plain English

Galicia's new Artificial Intelligence (AI) law, effective April 4, 2025, establishes a pioneering ethical framework for how its regional public administration designs, acquires, and uses AI systems. This legislation applies to the General Administration of the Autonomous Community of Galicia and its entire public sector, aiming to ensure AI deployment is responsible, human-centric, and aligns with broader European Union standards.

The law mandates that all AI systems used by the Galician public sector must adhere to strict guiding principles. These include transparency, explainability (meaning AI decisions can be understood), absence of bias, robust security, and privacy protection. Crucially, human oversight is paramount, with requirements for human review of AI-assisted administrative decisions. For every AI project, the administration must prepare a detailed "AI project report" outlining its purpose and technical specifications, and conduct a "Fundamental Rights Impact Assessment" to evaluate potential effects on citizens. Citizens gain specific rights, including the ability to know when AI is involved in a decision, request a human review, and file complaints about AI system operations.

While this regional law focuses on setting ethical guidelines for public sector AI, the enforcement teeth come from broader national and European frameworks. The Spanish Agency for the Supervision of Artificial Intelligence (AESIA), based in Galicia, will gain sanctioning capacity from August 1, 2025. This agency can impose substantial fines for non-compliance with national AI rules, potentially reaching €15 million or 3% of a company's global turnover for very serious infringements. A key pitfall for private companies is that even though this Galician law targets its public sector, these significant national and EU penalties will apply to *all* AI providers and deployers, including private businesses, especially for high-risk AI systems or those interacting with public administration.

Plain-English rewrite by Regulations.ai — not legal advice. Verify against the official text.

What you must do — compliance checklist

0 / 12 marked complete

Plain-English obligations under Spain - Galicia - AI Development Law (2/2025). Not legal advice — verify against the official text before relying on it.

  1. #1CriticalBefore deployment

    Applies to: Public sector entities in Galicia deploying systems

    This foundational definition is critical for determining which technologies fall under the regulatory purview of the law.
  2. #2CriticalBefore deployment

    Applies to: Public sector entities in Galicia designing or acquiring AI systems

    A key component of this framework is the requirement for an 'AI project report' (informe del proyecto de inteligencia artificial).
  3. #3CriticalBefore deployment

    Applies to: Public sector entities in Galicia deploying AI systems

    requires an 'Evaluation of Impact on Fundamental Rights' (Evaluación de Impacto en Derechos Fundamentales) for AI projects.
  4. #4CriticalBefore deployment

    Applies to: Public sector entities in Galicia deploying AI systems

    Crucially, the law mandates principles of auditability, traceability, and explainability, ensuring that AI systems' operations and decisions can be understood.
  5. #5CriticalBefore deployment

    Applies to: Public sector entities in Galicia deploying AI systems

    the law enshrines the principles of human reservation and human review, ensuring that human oversight remains central to administrative processes involving AI.
  6. #6CriticalBefore deployment

    Applies to: Public sector entities in Galicia designing or acquiring AI systems

    The law explicitly addresses impartiality and the absence of biases, aiming to prevent discrimination and ensure equitable outcomes.
  7. #7CriticalBefore using AI in decisions

    Applies to: Public sector entities in Galicia using AI in administrative decisions

    Transparency and clarity are also paramount, requiring that the use of AI is communicated clearly to citizens.
  8. #8CriticalBefore using AI in decisions

    Applies to: Public sector entities in Galicia using AI in administrative decisions

    Citizens are granted specific rights, including the right to know when an AI system intervenes in an administrative decision, to request a human review.
  9. #9ImportantBefore deployment

    Applies to: Public sector entities in Galicia deploying AI systems

    It also requires a plan for the management of the data proposed for training, validation, and testing.
  10. #10ImportantBefore deployment

    Applies to: Public sector entities in Galicia deploying AI systems

    Security and privacy are fundamental, aligning with existing data protection regulations.
  11. #11ImportantOngoing

    Applies to: Public sector entities in Galicia deploying AI systems

    The Galician AI Law places significant emphasis on continuous monitoring and evaluation to ensure the ongoing effectiveness, safety, and ethical compliance of AI systems.
  12. #12RecommendedOngoing

    Applies to: Galician public administration

    The law also promotes continuous training, collaboration, and knowledge transfer, recognizing the evolving nature of AI.

© Regulations.AI — created on 06-Jan-2026 using Gemini 2.5 Flash