When Spain published the statute of the Agencia Espanola de Supervision de Inteligencia Artificial (AESIA) in the Boletin Oficial del Estado in September 2023, it became the first European Union member state with a body dedicated specifically to supervising artificial intelligence, ahead of the AI Act's own entry into force and ahead of every national regulator since asked to absorb AI oversight into an existing mandate. Nearly three years on, with the AI Act's supervisory architecture still being finalised in Spanish law, AESIA is a useful case study in what it takes to stand up a dedicated AI regulator, and in how that body has to share the field with data protection, financial, aviation and judicial authorities that got there first.

Origins and legal foundation

AESIA was not created by the AI Act. Its legal basis predates the regulation by more than a year: the agency was established by the seventh additional provision of Law 28/2022 of 21 December, Spain's law promoting the emerging business ecosystem, commonly known as the Startups Law. That provision authorised the government to create a state agency for AI supervision, and it took a further eight months for the executive to give that agency its operating statute. Real Decreto 729/2023, of 22 August 2023, approved AESIA's statute, was published in the BOE on 2 September 2023, and entered into force the following day. The statute attaches AESIA to what was then the Ministry of Economic Affairs and Digital Transformation, through the State Secretariat for Digitalisation and Artificial Intelligence, and fixes its institutional seat in A Coruna, Galicia, reflecting a broader government push to disperse specialised public bodies across Spain's regions.

Functionally, the Royal Decree gives AESIA a conventional regulatory toolkit: supervision, inspection, certification and sanctioning powers, alongside advisory, awareness-raising and training functions aimed at public administrations and private companies alike. Spain's own account of the agency frames its objectives as promoting responsible, sustainable and trustworthy AI use, and coordinating with other supervisory and data protection authorities rather than displacing them, a distinction that matters in practice, as set out below.

What AESIA actually does today

Ahead of the AI Act's high-risk obligations taking effect, AESIA's most concrete activity to date has been operating Spain's AI regulatory sandbox. The sandbox began practical work in April 2025, when the State Secretariat for Digitalisation and Artificial Intelligence, working with AESIA and other market surveillance authorities including the Spanish Data Protection Agency (AEPD), the Bank of Spain and the State Aviation Safety Agency (AESA), began testing a dozen high-risk AI systems supplied by companies ranging from startups to large enterprises such as Airbus Operations SL, as the ministry's own account of the pilot, published alongside its December 2025 guidance announcement, later confirmed. The systems under test spanned access to essential public and private services, biometric identification, employment, and critical infrastructure, high-risk use cases under Annex III of the AI Act, as well as machinery and in vitro diagnostic medical devices, which fall instead under the AI Act's Annex I product-safety regime for AI embedded in already-regulated products, so the pilot was structured to touch both strands of the Act's high-risk framework rather than Annex III alone.

That pilot fed directly into AESIA's first major compliance output. On 11 December 2025, Spain's Ministry for Digital Transformation and Public Function announced the publication of sixteen guidance documents to help companies, particularly SMEs and startups, bring high-risk AI systems into line with the AI Act: two general explanatory guides and thirteen technical guides covering risk management, data governance, transparency and cybersecurity, together with compliance checklists for each obligation. AESIA's own announcement page dates the Minister's presentation of the same set of guides, in A Coruna, to 16 December 2025, five days after the ministry's press release; the two cited sources do not line up on the exact day, so organisations should treat mid-December 2025 as the publication window rather than rely on either date alone. Industry commentary has cast the set as among the first structured bodies of interpretative criteria that a public authority anywhere in Europe has issued on AI Act compliance, echoing IAPP's own description of the guides. AESIA and the ministry have been explicit that the guides are non-binding and provisional, meant to bridge the gap until the Commission finalises harmonised standards, and will be updated as that guidance matures. Organisations operating in Spain should treat them as a practical reference for an AI Act compliance file, not a substitute for the regulation's own text or the harmonised standards still to come.

AESIA's role under the EU AI Act

The AI Act, Regulation (EU) 2024/1689, requires every member state to designate at least one market surveillance authority and one notifying authority, and to nominate a single point of contact for dealings with the European Commission, the European AI Office and the AI Board. Spain has not yet finished that designation exercise in binding legislative form: it is being carried out through the Proyecto de Ley Organica para el buen uso y la gobernanza de la Inteligencia Artificial, approved by the Council of Ministers on 26 May 2026 and submitted to Congress, where it was published on 12 June 2026 and remains under parliamentary scrutiny, with an amendment period that closed on 30 June 2026 and further committee and plenary stages still to come. Until passed, its allocation of powers is a statement of government intent rather than settled law, to be confirmed against the final enacted text.

As drafted, the bill makes AESIA the centrepiece of Spain's AI Act supervisory architecture in three ways. First, it names AESIA as the general market surveillance authority for AI systems that do not already fall under an existing sectoral product-safety regime, so AESIA picks up oversight of high-risk uses in areas such as employment, education and access to essential services, while sectors already regulated as products, such as machinery, medical devices or motor vehicles, keep their existing sectoral surveillance authority layered on top of the AI Act's requirements. Second, the bill designates AESIA as Spain's single point of contact for the European Commission, the AI Office, the AI Board and other member states' authorities. Third, AESIA is named operator of Spain's mandatory national AI regulatory sandbox, building on the pilot it ran in 2025, with sectoral authorities able to open their own sandbox variants.

Notably, the draft bill does not concentrate every AI Act function in AESIA. The notifying authority role, responsible for accrediting and supervising the conformity assessment bodies that certify high-risk AI systems under Annex III, is assigned instead to the Direccion General de Inteligencia Artificial, a directorate within the digital ministry. The sources reviewed for this piece do not confirm the specific involvement of Spain's national accreditation body, ENAC, in that arrangement, or how it maps onto Article 28 of the AI Act, so that detail should be verified against the bill's final enacted text rather than treated as settled here. The body that supervises the market is thus not, in Spain's current design, the same body deciding who may certify high-risk systems. Proposed sanctions under the draft bill are organised in three tiers: up to 35 million euros or 7 percent of global turnover for very serious infringements, 15 million euros or 3 percent for serious infringements, and 500,000 euros or 0.5 percent for minor ones, alongside measures such as forced withdrawal of non-compliant systems. The bill also creates an interoperable public inventory of AI systems used in Spanish public administration and a designated "AI delegate" role inside public bodies deploying such systems, according to legal analysis of the approved draft.

AESIA and AEPD: two authorities, not one

The most practically important relationship for compliance teams is the one between AESIA and the Agencia Espanola de Proteccion de Datos, Spain's long-established data protection authority. The two agencies are not in competition and do not supervise the same thing: where an AI system processes personal data, the AEPD retains its existing competence over that processing under the GDPR and Spain's data protection law, while AESIA's remit is compliance with the AI Act itself. Because a large share of real-world high-risk AI systems, from recruitment tools to biometric identification, necessarily involve personal data, most organisations operating such systems in Spain will in practice answer to both authorities at once, each acting within its own legal basis.

The two agencies have been working out how that dual supervision functions in practice. AESIA and the AEPD held an institutional meeting at AESIA's A Coruna headquarters on 20 July 2026 to discuss institutional coordination, exchanging information on their respective supervisory actions and exploring collaboration where sandbox projects involve personal data, how the AI Act's single point of contact function should operate, channels for coordinating notification of serious incidents, and joint work on prohibited AI practices and public digital literacy. The message from both sides is that AESIA's arrival is meant to reinforce, not substitute for, the AEPD's existing role, with formal cooperation protocols still to be built rather than the boundary worked out case by case.

Beyond the AEPD, the draft bill and the 2025 sandbox pilot point to a wider constellation of Spanish authorities with a stake in AI oversight. The Bank of Spain and the Comision Nacional del Mercado de Valores retain their existing competence over AI used in banking and securities markets, AESA retains its role for aviation-related systems, and the Consejo General del Poder Judicial is given a role over AI touching judicial functions. Organisations deploying AI in a regulated sector in Spain should map compliance obligations against this fuller landscape, not against AESIA alone.

A wider pattern: the Ley Rider precedent

AESIA and the pending AI Act legislation are not Spain's first venture into binding algorithmic governance. In 2021, Spain enacted what is widely known as the Ley Rider, an emergency decree, Real Decreto-ley 9/2021 of 11 May, which amended the Workers' Statute to protect the labour rights of delivery workers on digital platforms. That decree was subsequently confirmed and its Workers' Statute amendments carried forward by Ley 12/2021, de 28 de septiembre, which is the law currently in force on this point and the one cited in Spain's own draft AI bill when it refers back to this right. Among its provisions, the law inserted a new letter (d) into Article 64.4 of the Workers' Statute, giving works councils the right to be informed of the parameters, rules and instructions underlying algorithms or AI systems that a company uses to make decisions affecting working conditions, access to and continuity of employment, and worker profiling. The Ley Rider's purpose, and the reason for its name, was to secure algorithmic transparency specifically for gig-economy and platform delivery workers; some legal commentary reads Article 64.4.d's wording as capable of reaching labour-relevant algorithmic decisions by employers outside the platform economy as well, but that broader reading remains a matter of legal debate rather than settled, confirmed practice, and organisations should take advice on their own position rather than assume either way. Either way, the Ley Rider is generally regarded as one of the first pieces of national legislation anywhere to grant workers a legal right to algorithmic transparency, predating both AESIA and the AI Act itself.

Practical implications for organisations operating in Spain

For businesses and public bodies active in Spain, several conclusions follow. The EU AI Act, as amended by the Digital Omnibus, is already the binding backbone of AI regulation in Spain regardless of how quickly national implementing legislation is enacted; the Omnibus text was published in the Official Journal on 24 July 2026 and enters into force on 27 July 2026. That amendment pushes the compliance deadline for standalone high-risk systems under Annex III to 2 December 2027 and for AI embedded in regulated products under Annex I to 2 August 2028, but left the Article 50 transparency obligations, covering matters such as disclosure of AI-generated content and chatbot interactions, on their original timetable, so those still apply from 2 August 2026.

Second, the national AI bill that would formally designate AESIA's AI Act roles is still moving through Congress and can change during the amendment process, so organisations should treat AESIA's market-surveillance, single-point-of-contact and sandbox functions as the government's stated intent rather than settled statutory fact, and confirm the final allocation of powers once the Ley Organica is enacted. Third, and regardless of the bill's fate, any AI system touching personal data in Spain is already subject to AEPD oversight today, independent of the AI Act's own timetable. Fourth, AESIA's existing guidance package, drawn from its 2025 sandbox experience, is available now and offers a practical starting point for an AI Act compliance file, even though it is explicitly non-binding and subject to revision as EU harmonised standards emerge. Finally, organisations with any exposure to labour-related automated decision-making should note that the Ley Rider's algorithmic transparency duty toward works councils already applies today, independently of the AI Act, for platform and gig-economy work in particular; whether that duty extends to other employers using comparable algorithmic management systems is a question to confirm against the current consolidated text, Ley 12/2021, and legal advice, rather than to assume in either direction.

Taken together, AESIA's trajectory since 2023 illustrates both the advantage and the limits of moving early. Spain has had more time than most member states to build institutional capacity, run a live sandbox and publish detailed guidance, but it has not yet finished the legislative work needed to give that capacity its final legal force under the AI Act, and it operates inside a landscape that already includes a well-established data protection authority and several sectoral supervisors with their own long-standing mandates.

Primary sources

Related articles