negocio · 4 min read
Spain's AI law: amendment deadline closes today
Today closes the amendment window for Spain's national AI bill. What authorities it splits power between, what fines it sets, and the AESIA guides you can use now.
The Organic Law bill for the proper use and governance of artificial intelligence closes its extended amendment window today, September 2, 2026, in Spain’s Congress. This isn’t procedural noise: it’s the law that will spell out, in practice, who can inspect a Spanish company over its use of AI, with what fines, and with what split of authority. At Evicron, an AI and custom software studio based in Barcelona, we follow this process closely because it directly shapes how we advise clients who come to us for compliance help. Here’s what the text actually says, what can still change, and what you can do today without waiting for it to hit Spain’s official gazette.
What this law adds on top of the EU Regulation
Regulation (EU) 2024/1689 — the AI Act — already applies directly across the EU and already sets what’s prohibited, what counts as high-risk, and what penalties apply. What’s missing, and what the Spanish bill provides, is the national landing: who supervises, how you file a complaint, and which authority does what. The bill, sent by the government to Congress on May 28, 2026 and published in the Official Bulletin of the General Courts on June 12, designates AESIA as the market surveillance authority, the single point of contact with the European Commission, and the manager of the mandatory regulatory sandbox. It doesn’t act alone: Spain’s data protection authority (AEPD) keeps its remit over personal data and biometrics, the judiciary’s governing body (CGPJ) steps in for AI used in the justice system, and sector regulators — the central bank, the securities regulator, consumer authorities — keep their ground wherever AI touches their own territory (more detail from Law&Trends).
The text also sets a penalty scale — from €500,000 or 0.5% of turnover for the lightest breaches up to €35 million or 7% for the most serious ones, the same ceilings the EU Regulation already sets — and creates a single complaints window at AESIA, so any person or company can report a breach without first having to work out which body to contact.
The amendment window closes today: what can still move
The bill has been sitting since June with the Committee on Economy, Trade and Digital Transformation in Congress, in its amendment phase, and that window — already extended once — closes today (you can follow file 121/000096 in Congress). From here it moves to committee drafting, where parliamentary groups can still amend specific articles before the floor vote. Until the text is definitively passed and published in Spain’s gazette, it remains a bill, not a law in force: what can still shift is procedural detail, deadlines, or how competences are split between authorities — not the substance, which is already locked in by the EU Regulation and can’t be watered down.
For a company, the practical takeaway is that there’s no reason to wait for the final wording before getting ready: the transparency obligations under Article 50 of the AI Act have been enforceable — and enforced — since August, Spanish law or no Spanish law, and the split of who oversees what — AESIA, AEPD, CGPJ — is already clear enough to know who you’ll have to answer to.
While it’s being debated: the AESIA guides you can use now
Even with the law unfinished, AESIA hasn’t waited to hand out practical tools: on August 21, 2026 it updated its 16 guides and checklists for applying the EU AI Regulation, already adapted to the package known as the Digital Omnibus (summary from Garrigues Digital). They’re organized into three tracks — introductory, technical, and self-assessment — and grew out of Spain’s regulatory sandbox pilot, so they aren’t legal theory but material built to turn an obligation into concrete controls and evidence. They’re non-binding, but right now they’re the most complete Spanish-language reference for knowing what documentation to demand from an AI vendor or what’s missing from a system you built in-house. The underlying deadline for Annex III high-risk systems is still December 2, 2027 — but the earlier you use this documentation, the less last-minute scramble is left for then.
What to do in your company, without waiting for the gazette
- Don’t confuse “still a bill” with “nothing to comply with yet.” The EU Regulation already applies and already fines; the Spanish law only adds the authority split and the procedure.
- Download and use the AESIA guides for the specific AI system that worries you, instead of waiting for a generic third-party “AI compliance” checklist.
- Work out now who your point of contact would be — AESIA, AEPD, or both — depending on whether your system touches personal data, decisions about people, or both at once.
How we work on this at Evicron
We’re not a law firm, and the fine-grained legal reading of the text is your lawyers’ job. What we do in our AI consulting for companies is the technical part: auditing which AI systems a company actually runs, applying the AESIA guides to your specific case, and getting the documentation and traceability ready for whenever an inspection comes — whether in 2026 or 2027. If you want the background first, we’ve also written about what AESIA is and which risk tier each system falls into.
Bottom line
Spain’s AI law still isn’t passed, and today only closes one more phase of its journey through Congress — not the final one. But the underlying framework — the EU Regulation, its penalties, and the AESIA guides — is already usable, and waiting to see how the final text lands doesn’t excuse you from the obligations that already apply.
Want to know what’s missing for you to comply with what’s already mandatory today? Get in touch: the first discovery session is free and we reply within 24 hours.