tutoriales · 4 min read
AESIA can now fine you: what your company must do this week
Since August 2, 2026, Spain's AI regulator AESIA can move from inspecting to fining. What the AI Act actually requires and how to avoid penalties of up to €15 million.
As of August 2, 2026, AESIA (Spain’s AI Supervision Agency) is no longer a body that only inspects: it can now demand evidence and fine companies directly for breaching the EU AI Act. This isn’t an abstract threat or a far-off date — transparency violations carry fines of up to €15 million or 3% of worldwide turnover, and the most serious breaches up to €35 million or 7%, as reported by Moncloa and Cope. At Evicron, an AI and custom software studio based in Barcelona, we’ve spent the past weeks reviewing with clients which AI systems they run and whether those systems would survive a formal request from the agency. Here’s what actually changed, and what to do this week.
What actually changed on August 2
Until now, AESIA could inspect and request changes, but lacked full authority to impose fines. Since August 2, 2026, that limit is gone: the agency can demand documentation, open a formal case and sanction breaches of obligations that were already in force — chiefly the transparency requirements under Article 50 of Regulation (EU) 2024/1689, which we covered in detail when they were confirmed. AESIA works alongside Spain’s data protection authority (AEPD) and other sector regulators, and its scope covers any company operating in Spain, whether the AI it uses comes from a domestic or foreign provider.
What the Regulation actually requires, in four points
Without repeating all the technical detail (see the linked article above), here’s the part that matters most to an SME:
- Chatbots and virtual assistants must disclose that they’re AI, unless that’s obvious to any reasonable person.
- AI-generated images, audio, video or text must carry a machine-readable technical mark identifying them as synthetic.
- Deepfakes and AI-generated text on matters of public interest must be labeled as such.
- Emotion recognition and biometric categorization require informing the people exposed to them, on top of GDPR obligations.
How much non-compliance can cost
The AI Act’s penalty regime has several tiers, and it’s worth not confusing them:
- Prohibited practices and unauthorized high-risk uses: up to €35 million or 7% of global annual turnover, whichever is higher.
- Transparency and other obligation breaches (chatbots with no disclosure, unmarked content, hidden deepfakes): up to €15 million or 3% of worldwide turnover.
- SMEs and startups: Article 99.6 sets the fine at the lower of the fixed amount or the turnover percentage, rather than defaulting to the ceiling — that moderates the calculation, but it doesn’t exempt anyone from complying.
What’s still delayed (so the deadlines don’t get mixed up)
High-risk systems under Annex III — recruitment screening, credit scoring, education, critical infrastructure — have full compliance pushed back to December 2, 2027, under the Digital Omnibus package agreed in June. That delay doesn’t touch Article 50 transparency, which is exactly what AESIA can now enforce.
What your company should do this week
- Inventory every AI system that interacts with people or generates content: chatbots, voice assistants, image or marketing-copy generators, forms with automated scoring.
- Classify each one: transparency-only (already enforceable and already fineable) or Annex III high-risk (with runway until 2027).
- Add clear disclosures to conversational interfaces and mark generated content, requiring your vendors to provide the documentation to prove it.
- Assign an internal owner who can respond in days, not weeks, if AESIA requests evidence — now that it can actually ask, not being ready is itself a risk.
- Review contracts with AI vendors to confirm who’s liable if disclosure or watermarking fails upstream.
When it’s worth bringing in outside help
We’re not a law firm, and this isn’t legal advice — the fine-grained interpretation of your specific case belongs to your lawyers. Our part is the technical one: auditing which AI systems a company actually runs, how they’re wired together, and what’s missing for disclosure and watermarking to work in production, not just on paper. In our AI consulting for companies we always start with that inventory before touching anything, because most of the gaps we find aren’t bad faith — they’re systems nobody has looked at since the day they went live.
Bottom line
On August 2, 2026, AESIA moved from inspecting to fining, with penalties of up to €15 million for breaching Article 50 transparency and up to €35 million for the most serious infringements. Annex III high-risk systems still have runway until 2027, but that doesn’t cover chatbots without disclosure or unmarked generated content — those are fineable today.
Want us to review which of your company’s AI systems are exposed? Get in touch: the first discovery session is free and we reply within 24 hours.