Saltar al contenido

negocio · 4 min read

What is AESIA and what does it mean for your company?

AESIA can already inspect and fine companies that breach the EU AI Act. What the agency actually does, who it coordinates with, and what it means if you operate in Spain.

Published on · Evicron

AESIA — Spain’s AI Supervision Agency — has, since August 2, 2026, been the body that can inspect, demand evidence, and fine any company operating in Spain that breaches the EU AI Act (Regulation (EU) 2024/1689). We’ve already covered what it can fine you for today and which risk tier each of your systems falls into. What’s still missing is more basic — and it’s the question we hear most from clients who reach out to Evicron, an AI and custom software studio based in Barcelona, for the first time: what actually is AESIA, where does its authority come from, and what does it have to do with a company that simply runs a chatbot or a third-party AI tool?

What AESIA is, and why it exists

AESIA is the designated Spanish authority for supervising compliance with the EU AI Act. It doesn’t replace Spain’s data protection authority (AEPD) — each covers its own remit, and the two coordinate whenever a given AI system both processes personal data and falls under the AI Act, which describes most chatbots, assistants, and scoring tools a normal company runs. It’s also not a brand-new body invented purely to fine people: it had been operating for a while before the sanctioning regime took effect, precisely so there would be an established authority in place once that moment arrived.

For a company, that has a practical consequence: there’s no need to chase two separate regulators with two separate stories. If an AI system touches customer or employee data, it’s reasonable to expect that both AEPD and AESIA could have something to say, each from its own angle.

What it can actually do today

We covered this in detail before, but it’s worth restating without repeating the full breakdown: since August 2, 2026, AESIA can demand documentation, open a formal case, and fine breaches of Article 50 (transparency — disclosing that a chatbot is AI, labeling synthetic content), with penalties of up to €15 million or 3% of global turnover, and up to €35 million or 7% for the most serious breaches. High-risk systems under Annex III — recruitment screening, credit scoring — have runway until December 2, 2027, but that doesn’t cover transparency, which is already enforceable today.

What doesn’t always get explained is how a case actually lands on AESIA’s desk. In practice, the usual channels for a supervisory body like this are three: complaints from individuals or competitors, proactive inspections targeted at higher-exposure sectors (hiring, banking, insurance, healthcare), and a company’s own track record if it’s already had a prior request for information. You don’t need to be a large corporation to end up on its radar — a single customer or employee complaint about a chatbot that never disclosed it was AI is enough.

The regulatory sandbox: the less-known part of the job

Less well known than its power to fine is AESIA’s role in Spain’s AI regulatory sandbox — a supervised testing space where a company can trial a high-risk system before it’s required to have the full documentation ready, working alongside the regulator instead of waiting for an inspection. Spain was among the first EU countries to run a pilot of this kind, built specifically for companies planning to build or adopt Annex III systems (hiring, credit, education) to prepare their documentation and human-oversight processes with runway, instead of discovering in 2027 that they’re not ready.

For an SME evaluating, say, an AI-based candidate-screening tool, that changes the calculation: it’s no longer just “comply when the deadline hits” — there’s a path to arrive already prepared, with the regulator itself as a point of contact from early on.

What this means for your company, in three questions

  1. Which AI systems touch real people? Chatbots, voice assistants, marketing content generators, forms with automated scoring. If the honest answer is “we’re not sure,” that’s the problem to solve first, before worrying about AESIA.
  2. Does any of them decide or influence something about a person — hiring, credit, access to a service? If so, look at Annex III and the runway until 2027, but start the documentation now.
  3. Who at your company would respond if AESIA requested evidence tomorrow? Not having someone designated isn’t neutral — it’s part of the risk itself.

How we work on this at Evicron

We’re not a law firm, and the fine-grained legal interpretation belongs to your lawyers. Our part is auditing which AI systems a company actually runs, what risk tier each one falls into, and what’s technically missing for disclosure, labeling, or traceability to work in production. In our AI consulting for companies we always start with that inventory, with a free discovery session.

Bottom line

AESIA isn’t just the agency that can now fine you — it’s Spain’s reference authority for the AI Act, coordinated with the AEPD, with inspection channels ranging from a single complaint to sector-wide reviews, and a regulatory sandbox that lets companies prepare high-risk systems before inspection ever comes knocking. The sooner you know which side of that equation your company is on, the less room there is for surprises.

Want to know whether any of your company’s AI systems are on AESIA’s radar? Get in touch: the first discovery session is free and we reply within 24 hours.

Let's talk.

Tell us about your project, challenge or opportunity. We reply within 24 hours with a concrete action plan and indicative budget.