Compliance & Governance

The EU AI Act in Spain: What Companies Need to Know in 2026

The AI Act is already in force, and its implementation is being rolled out progressively across the European Union. Here is what your company needs to review and prepare for this year.

The Cloud Collective Google Cloud Premier Partner 8-minute read

The EU Artificial Intelligence Act (AI Act) is already in force, and its implementation is being rolled out progressively across the European Union, including Spain. By 2026, companies that develop, deploy, or use AI systems must assess their level of regulatory exposure and prepare compliance measures as soon as possible.

What is the EU AI Act?

The EU AI Act is the first comprehensive regulatory framework for artificial intelligence in Europe. Its approach is risk-based and distinguishes between prohibited practices, high-risk systems, systems subject to transparency obligations, and systems with minimal or no risk.

In Spain, these regulations affect technology companies, service providers using AI, financial organizations, human resources companies, the healthcare sector, and any entity deploying AI systems with a significant impact on individuals or fundamental rights.

Risk levels of the AI Act

The regulation establishes four main categories based on the potential impact of each system:

Unacceptable risk

Prohibited

Practices such as social scoring, harmful manipulation, and certain uses of biometrics and the exploitation of vulnerabilities.

High risk

Strict requirements

Systems used in employment, education, critical infrastructure, access to essential services, justice, and biometrics.

Limited risk

Transparency

Chatbots and systems that interact with people and require transparency notices.

Minimal risk

Without specific obligations

Low-impact uses without specific obligations, although they may follow voluntary best practices.

Compliance in Spain

For a company operating in Spain, the first step is to inventory existing AI systems. This includes marketing automation, predictive analytics, customer service, personnel selection, and operational automation. Next, it is advisable to classify each system according to its risk level and document the data processed, operational logic, human oversight, and potential impact.

If a system falls into the high-risk category, the company must strengthen its governance, document the model, establish traceability, conduct robustness testing, and define processes for human review and complaints.

Governance and audit

AI governance is not limited to an internal document. It must include a designated person in charge, usage policies, pre-deployment testing, bias control, activity logs, and continuous monitoring.

It is also advisable to conduct periodic audits of AI systems to identify whether any use case has changed in purpose or risk level over time. This is particularly important in areas such as HR, credit, healthcare, and automated customer service.

Google Cloud and compliance

Google Cloud publishes specific information regarding the AI Act and offers useful controls to support compliance, such as audit logs, access controls, encryption, and data protection solutions.

It also notes that, in its Google Cloud and Gemini for Google Cloud offerings, prompts and responses are not used to train its models by default—a factor that may be relevant for enterprise environments with privacy requirements.

No single platform guarantees legal compliance on its own; ultimate responsibility depends on each company's use case, configuration, contracts, governance, and data processing.

Sanctions for non-compliance

The sanctions under the AI Act can be very high. Article 99 provides for fines of up to 35 million euros or 7% of annual global turnover for the most serious infringements, and other tiers of €15 million or 3%, as well as €7.5 million or 1% for providing incorrect or incomplete information.

Therefore, the risk is not merely financial. There is also a reputational impact, operational disruptions, and potential regulatory restrictions if the company fails to demonstrate adequate controls.

2026 Roadmap

  1. Inventory all AI systems.
  2. Classify them by risk and document their use.
  3. Define governance, responsibilities, and controls.
  4. Implement transparency, traceability, and human review.
  5. Conduct periodic audits and maintain evidence of compliance.

Conclusion

The EU AI Act is not a barrier to innovation, but rather a framework for deploying AI with greater confidence and security. Companies that get a head start on compliance will be better positioned to scale, protect their operations, and reduce regulatory risks in Spain.

Frequently Asked Questions

Yes. The AI Act has extraterritorial scope: it applies to any company that develops, imports, distributes, or uses AI systems intended for the EU market, even if it is established outside the European Union.

Active obligations (prohibitions, transparency, certain high-risk requirements) apply starting in 2025–2026, but not all deadlines fall at the same time. Companies must review the implementation timeline and make progress on auditing, inventory, and governance.

No. The AI Act complements the GDPR: the GDPR continues to apply to all processing of personal data, while the AI Act adds specific requirements regarding the design, safety, and transparency of AI systems.

These are systems that impact fundamental rights or safety—such as those involved in hiring, credit, education, healthcare, biometrics, or judicial decisions. They are subject to stricter requirements regarding documentation, risk control, and human oversight.

Yes. Regulations place value on the explainability and interpretability of decisions. Enterprise AI solutions (such as Google Cloud or other platforms) can help generate logs, traceability, and explanations, but they do not replace the company's responsibility or the need for its own governance framework.

Sanctions can reach up to 35 million euros or 7% of global annual turnover, depending on the type of infringement. There is also a risk of system bans, regulatory investigations, and reputational damage.

Yes. If your AI interacts with people, in many cases it must indicate that the user is dealing with a machine and, in some cases, provide information about data usage. This applies to both internal and external chatbots.

A cloud platform featuring audit log controls, encryption, DLP, and policies prohibiting the use of data for training is highly useful, but it does not guarantee compliance on its own. The company must combine this infrastructure with a governance framework, roles, and internal processes.

Is your company prepared for the AI Act?

At The Cloud Collective we help companies in Spain inventory, classify, and govern their AI systems on Google Cloud , with the technical controls necessary for compliance.

Speak with our team