First things first: what role you play under the rules
Your obligations do not depend on your size but on the role you play. And most Spanish companies occupy the second of these roles convinced that none of it applies to them.
Provider
You develop an AI system, or place it on the market under your own name or brand. It is the heaviest role: technical documentation, risk management, conformity assessment, CE marking where applicable.
Deployer
You use an AI system in your professional activity. This is 90 % of companies. You have obligations of your own: use in line with instructions, human oversight, informing the people affected, and staff training.
Importer or distributor
You bring third-party systems into the EU or sell them on. You must verify that the provider complied before putting the product into circulation.
Watch out for one counter-intuitive point: if you take a third-party system, put your brand on it and offer it to your clients, or if you substantially change its purpose, you become a provider with every obligation that entails.
The four risk levels
Unacceptable risk — banned
Social scoring, subliminal manipulation, exploitation of vulnerabilities, emotion recognition at work and in education, biometric categorisation using sensitive data, and untargeted scraping of facial images. Banned since 2 February 2025.
High risk — allowed, with heavy obligations
Recruitment and employment management, creditworthiness assessment, education, biometrics, critical infrastructure, essential public services, and systems acting as a safety component of an already regulated product.
Limited risk — transparency obligations
Chatbots, conversational assistants and synthetic content generation. You must disclose that the user is interacting with an AI, and label generated or manipulated content as such.
Minimal risk — no specific obligations
Most everyday uses: spam filters, recommenders, internal optimisation. No obligations under the Regulation itself, though the GDPR and the rest of the law still apply.
Application timeline
Where to start, in practice
Inventory
A list of every AI system the company uses or sells. That includes the ChatGPT someone on the team uses without permission, and the AI module your long-standing software switched on in an update. It is almost never the three that management thinks.
Classification
For each system: its risk level and your role. This defines everything that follows, so getting it wrong multiplies the work or leaves you exposed.
AI literacy
Documented training for the staff who use these systems. It has been mandatory since February 2025, it is the easiest to breach and the easiest to prove once done.
Governance
An internal AI use policy, an assigned owner, a record of decisions, effective human oversight and an impact assessment where required. Documented: what is not written down cannot be evidenced.
The contract chain
If you use third-party AI, your contracts must allocate liability and guarantee you information from the provider. If you sell AI, your clients will start demanding the same of you — and that is where compliance turns from a cost into a selling point.
The AI Act does not replace the GDPR
If the system processes personal data — and almost all of them do — you still need a legal basis, information for the data subject, minimisation and, in many cases, a data protection impact assessment. In practice both analyses are done at once, because 80 % of the documentation overlaps. Doing them separately means paying twice.
Penalties
Up to €35 million or 7 % of total worldwide annual turnover for engaging in banned practices, and up to €15 million or 3 % for other breaches — including failing to meet the deployer's obligations. For SMEs and startups, the lower of the two figures applies. In Spain, supervision falls to AESIA, the Spanish Agency for the Supervision of Artificial Intelligence.