Spain AI Governance Bill

Organic Law Bill for the Good Use and Governance of Artificial Intelligence

Proyecto de Ley Orgánica para el buen uso y la gobernanza de la inteligencia artificial

Spain

RAI-ES-NA-DADLGXX-2025
Under Review(Under Review)
BillGovernance and OversightRisk Management
Export PDF

The Spanish Government presented on 11 March 2025 the Anteproyecto de Ley for the good use and governance of Artificial Intelligence to transpose and implement the EU AI regulatory framework into national law. The draft sets out prohibited practices, obligations for high‑risk AI systems, transparency requirements (including labelling of AI‑generated content), a national supervisory architecture led by the AESIA and specialized sectoral authorities, sanctions aligned with the EU AI Act, and measures to support sandboxes and innovation.

Overview

The Spanish Government approved in first reading on 11 March 2025 the Anteproyecto de Ley for the Good Use and Governance of Artificial Intelligence to align national law with the European AI regulatory framework. The draft is presented as a hybrid instrument that combines protective regulation (prohibitions, obligations for high‑risk systems, sanctions and market surveillance) with measures to foster innovation (national sandboxes and guidance). The official ministry press release and supporting presentation outline the structure, objectives and staged enforcement dates for specific obligations. Spain positions the Agencia Española de Supervisión de la Inteligencia Artificial (AESIA) at the center of the national supervisory model while preserving sectoral competences for specialized authorities. The draft law addresses prohibited practices, high‑risk compliance obligations, transparency and labelling duties for generative content, data governance and conformity assessment, plus a sanctioning and provisional withdrawal regime. For the ministry announcement and supporting PDFs, see Ministry Press Release (PDF) and Presentation of Measures (PDF).

Definitions

The draft adopts the EU AI Act definitions as baseline: "AI system" (software that can generate outputs such as content, predictions, recommendations or decisions), "provider" (person or entity that develops an AI system or under whose name it is placed on the market), "operator" (person or entity who deploys or uses a system), "high‑risk AI" (systems tied to goods, safety components, or certain sectors such as biometrics, critical infrastructure, education, employment, access to essential services, migration, justice and democratic processes), and "prohibited practice" (uses that create an unacceptable risk and are banned). The bill clarifies terms for national implementation, including "incident" (an event causing death, critical infrastructure failure or major environmental harm) and "market withdrawal" (temporary removal from the Spanish market by competent authorities).

Governance and Institutional Framework

The draft establishes a tiered supervisory architecture anchored on the Agencia Española de Supervisión de la Inteligencia Artificial (AESIA) as the default authority for AI matters not assigned to specialized regulators. Sectoral authorities retain competence in their domains: the Agencia Española de Protección de Datos (AEPD) for biometric and data protection issues; the Consejo General del Poder Judicial (CGPJ) for justice, the Junta Electoral Central (JEC) for electoral matters, the Banco de España (Banco de España), the Dirección General de Seguros y Fondos de Pensiones (DGSFP) for insurance, and the Comisión Nacional del Mercado de Valores (CNMV) for capital markets. The draft requires coordination mechanisms, memoranda of understanding, and a national AI register with public summaries for certain high‑risk systems. The law also empowers these authorities to impose provisional digital withdrawal measures and to cooperate with the European network of AI supervisory bodies.

Key Focus Areas

The bill focuses on: (1) Prohibited practices: explicit national transposition of the EU list (subliminal techniques, exploitation of vulnerabilities, discriminatory biometric categorization, social scoring, predictive criminality, and proscribed emotion inference in employment/education), (2) High‑risk systems: mandatory risk management, human oversight, technical documentation, data governance, logs and records, conformity assessment and CE marking, quality management and cybersecurity; (3) Transparency and labelling: mandatory clear and distinguishable identification of AI‑generated or manipulated content (images, audio, video) at first exposure to combat ultrasuplantación (deepfakes); (4) Market surveillance and incident reporting: obligations to notify grave incidents and requirements enabling authorities to take corrective or provisional removal actions; (5) Support for innovation: national sandboxes overseen by AESIA to enable controlled testing and compliance guidance; and (6) Sanctions: a three‑tiered regime with financial penalties and corrective measures aligned with EU maxima and with specific provisions for SMEs. The draft also addresses public sector use of AI, although critics have argued the draft’s sanctions for public bodies are less stringent than for private actors.

Implementation Framework

The draft outlines procedures for conformity assessment for high‑risk systems, requiring suppliers to produce technical documentation, risk management files, and a declaration of conformity. When harmonized standards apply, conformity assessment routes follow product law; otherwise the AESIA (or delegated conformity bodies) may define assessment modalities. Operators must register certain high‑risk deployments in a national database and demonstrate human oversight policies, cybersecurity controls and training for personnel with supervisory responsibilities. The law mandates the creation of official guidance documents and sectoral technical guides and foresees transitional periods in line with EU dates for when certain obligations become enforceable.

Monitoring and Evaluation

The bill requires periodic reporting by AESIA and sectoral authorities on enforcement activity, incident statistics, sandbox outcomes and guidance publications. AESIA must produce annual public reports and coordinate with the EU supervisory network. The draft mandates impact evaluations of enforcement measures, reviews of prohibited practices, and stakeholder consultation mechanisms to refine guidance and technical standards. It also empowers authorities to commission audits and compliance inspections, including on‑site inspections when necessary, and to maintain a public register of sanctioned entities and corrective orders.

Penalties, Liability, and Appeals

Sanctions are categorized into very serious, serious and minor infringements, with penalties ranging from administrative fines and corrective measures (withdrawal, adaptation orders) to, in very serious cases, fines up to the EU maximum thresholds (tens of millions of euros or a percentage of global turnover). The draft also sets procedural safeguards and administrative appeal mechanisms, and provides for judicial review before the administrative courts. It contemplates differentiated treatment for SMEs and clarifies conditions for provisional measures (market withdrawal) and subsequent remedial steps. The bill discusses civil liability interfaces with existing tort and product liability regimes, requiring operators to maintain incident logs to assist in liability assessments.

Relationship to Other Instruments

The draft is expressly designed to implement and complement the EU AI Regulation and interacts with existing Spanish instruments: data protection law (GDPR implemented by the AEPD), sectoral product safety and medical device regulations, national administrative procedural law, consumer protection law and criminal statutes. It refers to the Real Decreto 729/2023 approving AESIA’s statute and coordinates with digital rights frameworks and the Spanish Digital Rights Observatory. The draft expects conformity procedures to interoperate with EU harmonised rules where present and with national product/sectoral regulators for domain‑specific oversight.

International Alignment

Spain frames the draft as a faithful transposition of the EU AI Act and aligns domestic enforcement dates and sandbox obligations with EU timelines (including the 2 August 2025/2026 milestones where applicable). The law also references international instruments (Council of Europe, OECD, UNESCO recommendations) and envisages cooperation with EU and international supervisory networks for cross‑border incidents, enforcement and exchange of best practices. Spain intends AESIA to be an active participant in the European supervisory architecture.

Implementation Timeline

MilestoneDate
Council of Ministers: first approval (anteproyecto)2025-03-11
Public consultation opened2025-03-11
Public consultation (reported deadline in stakeholder summaries)2025-03-26
EU AI Act prohibited practices entry into force2025-02-02
EU AI Act sanctionable date for prohibited practices2025-08-02
Obligation for Member States to host at least one AI sandbox2026-08-02

Compliance Checklist

RequirementAction
Determine if AI system is 'high‑risk'Classify system per annexes and sectoral lists; document rationale
Risk management systemImplement and document lifecycle risk assessments and mitigations
Human oversightDefine oversight roles, train staff, maintain records
Technical documentation & logsPrepare and retain documentation; ensure records for incidents
Transparency & labellingEnsure AI‑generated content is labelled at first exposure
Conformity assessmentUndergo appropriate conformity route and affix CE if required
Incident reportingNotify competent authority of grave incidents within prescribed timelines

Sources and References

SourceType
Ministry for Digital Transformation and the Civil Service - Press Release: El Gobierno da luz verde al anteproyecto de leyPrimary Source
Ministry Presentation: IA - Our Measures (Presentation)Primary Source
La Moncloa - Council of Ministers reference (11 March 2025)Primary Source
Plain English

Spain is preparing to implement comprehensive new rules for Artificial Intelligence, impacting companies and individuals who develop or deploy AI systems within the country. This draft law aims to align national regulations with the European Union's landmark AI Act, establishing clear boundaries and responsibilities for AI use.

The legislation applies broadly to "providers" who develop AI systems and "operators" who deploy or use them. It specifically targets "high-risk" AI systems, which include those used in critical infrastructure, education, employment, essential services, law enforcement, and justice. The bill outlines several key requirements: - It bans certain AI practices deemed to pose unacceptable risks, such as manipulative subliminal techniques, exploiting vulnerabilities, social scoring, and some forms of predictive policing or emotion recognition in sensitive contexts. - Developers and users of high-risk AI systems must implement robust risk management, ensure human oversight, maintain detailed technical documentation and data governance, and undergo conformity assessments, potentially leading to a CE mark. - A crucial transparency rule mandates clear and distinguishable labelling for all AI-generated or manipulated content, including images, audio, and video, to combat deepfakes. - Companies must also report serious incidents involving AI systems to the authorities.

While the exact effective date for the Spanish law is still unknown, it mirrors the EU AI Act's timeline, meaning some prohibited practices could become sanctionable as early as August 2025. Enforcement will be led by the new Spanish Agency for the Supervision of Artificial Intelligence (AESIA), alongside existing sectoral regulators like the data protection authority. Non-compliance carries significant penalties, including administrative fines that can reach tens of millions of euros or a percentage of global turnover for very serious infringements, along with corrective measures and potential market withdrawal. A practical surprise for many might be the immediate and explicit obligation to label all AI-generated content, requiring careful integration into product design and user interfaces.

Plain-English rewrite by Regulations.ai — not legal advice. Verify against the official text.

What you must do — compliance checklist

0 / 10 marked complete

Plain-English obligations under Spain AI Governance Bill. Not legal advice — verify against the official text before relying on it.

  1. #1CriticalAug 2, 2025

    Applies to: All providers and operators of AI systems.

    Prohibited practices: explicit national transposition of the EU list...
  2. #2CriticalBefore placing on market

    Applies to: Providers of high-risk AI systems.

    High‑risk systems: mandatory risk management...
  3. #3CriticalBefore deployment/use

    Applies to: Providers and operators of high-risk AI systems.

    High‑risk systems: mandatory... human oversight...
  4. #4CriticalBefore placing on market

    Applies to: Providers of high-risk AI systems.

    High‑risk systems: mandatory... technical documentation, data governance, logs and records...
  5. #5CriticalBefore placing on market

    Applies to: Providers of high-risk AI systems.

    High‑risk systems: mandatory... conformity assessment and CE marking...
  6. #6CriticalBefore placing on market

    Applies to: Providers of high-risk AI systems.

    High‑risk systems: mandatory... quality management and cybersecurity...
  7. #7Critical

    Applies to: Providers and operators of AI systems generating content.

    Transparency and labelling: mandatory clear and distinguishable identification of AI‑generated or manipulated content...
  8. #8CriticalWithin prescribed timelines

    Applies to: Providers and operators of AI systems.

    Market surveillance and incident reporting: obligations to notify grave incidents...
  9. #9Critical

    Applies to: Operators of high-risk AI systems.

    Operators must register certain high‑risk deployments in a national database...
  10. #10Important

    Applies to: Operators of AI systems.

    requiring operators to maintain incident logs to assist in liability assessments.

© Regulations.AI — created on 26-Aug-2026