the art of being legal

AI Act 2026: What an IT company Must Review Before Launching an AI System in Spain

ai checklist conesa legal

A technology company can launch an AI tool on the Spanish market and then find itself unable to answer basic questions: what role it holds under the AI Act, whether its system is high-risk, what data was used to train or fine-tune the model, what information must be disclosed to the client, what human oversight is in place, or who is liable if the system generates an incorrect decision.

Article written by

Josep Conesa Sagrera

Employment and insolvency lawyer

Josep Conesa is a Spanish and English-speaking labour lawyer who holds a master’s degree in European law and Fundamental Rights. Over 25 years of esperience. We’d be delighted to legally help you too, in your language whenever possible.

View professional profile

The European Artificial Intelligence Regulation, known as the AI Act, is no longer a distant prospect. It entered into force on 1 August 2024 and is being rolled out in phases. The prohibitions and AI literacy obligations began to apply from 2 February 2025; the governance rules and obligations for general-purpose AI models started to apply from 2 August 2025; and the general implementation framework takes full effect in 2026, with specific timelines for certain high-risk systems.

For a startup, SaaS, healthtech, fintech, marketplace, legaltech or company that integrates AI into its operations, the legal review must begin before launch. It is not enough to verify that the product works technically. You must be able to demonstrate that the system has been properly classified, documented, tested, explained and governed.

 

What is the AI Act and why does it affect technology companies in Spain?

The AI Act is the European Union's first comprehensive legal framework on artificial intelligence. Its core logic is to classify AI systems according to the risk they may pose to safety, health, fundamental rights and other protected interests. The European Commission sets out the approach across four levels: unacceptable risk, high risk, transparency risk, and minimal or low risk.

For a technology company, this means that legal obligations do not depend solely on "using AI". They depend on what the system does, in which sector it is used, who it affects, what decisions it supports, and the degree of control the company has over its development, integration or deployment.

A customer support chatbot does not carry the same level of risk as a recruitment tool, a credit scoring system, a medical solution, a biometric system, or a model that influences access to essential services.

 

Before launching an AI system, what should a company review?

The review should begin with a clear inventory. Many companies do not have a single "AI product" but rather several scattered uses: generative AI in customer service, internal scoring, recommendation engines, CV analysis, document automation, predictive models, third-party APIs, AI agents connected to internal tools, or functionality embedded in a SaaS platform.

Control question Why it matters
What AI system is being launched? Enables you to define the product, its functions, and its boundaries.
Is the company developing, integrating, or merely using AI from a third party? Determines whether it may qualify as a provider, deployer, distributor, or other operator.
Does the system make decisions or only provide recommendations? Affects the risk level, human oversight requirements, and GDPR obligations.
Does it affect employment, credit, education, health, essential services, or biometrics? May trigger classification as a high-risk system.
Is personal data being used? Requires reviewing the legal basis, transparency, data minimisation, security, and the possible need for a data protection impact assessment.
Does the user know they are interacting with AI? Transparency obligations may apply.
Is synthetic content, deepfake material, or informational text being generated? May require identification or labelling of AI-generated content.
Is there technical traceability? The company must be able to account for tests, logs, errors, changes, and controls.
Do contracts with clients and suppliers address AI? Allocates responsibilities, warranties, data use, audit rights, and limitations.

 

Step 1: Identify your company's role under the AI Act

The first mistake is assuming that all companies face the same obligations. The AI Act distinguishes between several types of operator, and obligations vary depending on the role. A company may act as a provider of an AI system, a deployer, an importer, a distributor, or a product manufacturer, depending on its position in the value chain.

Practical role Example in a technology company Legal risk
Provider Develops and markets an AI system under its own name or brand. Takes on obligations relating to design, documentation, assessment and conformity where applicable.
Deployer Uses an AI tool in the course of its professional activities. Must use it in accordance with instructions, maintain oversight and comply with usage obligations.
Integrator Embeds a third-party AI system into its own SaaS product or platform. May take on provider obligations if it modifies the intended purpose, branding or functionality.
Distributor Markets another provider's AI system within the EU. Must verify information, documentation and basic compliance.
Business customer Procures an AI solution for internal processes. Must require adequate contractual guarantees and supporting documentation.

A startup that uses a third-party API to build its own product should not take comfort in the idea that "the AI belongs to the external provider". If the final product is sold under the startup's own brand, with a purpose defined by the startup, and involves decisions that affect users, customers or employees, liability may shift to, or be shared with, the startup.

 

Step 2: Classify the system according to its risk level

Classification is the cornerstone of the review process. The AI Act prohibits certain practices on the grounds that they pose an unacceptable risk. The European Commission cites, among others: harmful manipulation or deception through AI, exploitation of vulnerabilities, social scoring, certain uses of crime prediction, indiscriminate scraping to build facial recognition databases, emotion recognition in workplaces and educational settings, certain biometric categorisations, and the use of real-time remote biometric identification by law enforcement in public spaces, subject to strict exceptions.

There are also high-risk systems. The Commission includes as examples AI tools used in employment and workforce management, access to education, critical infrastructure, access to essential services, certain biometric uses, migration, justice, democratic processes, and regulated products such as certain medical devices or machinery.

Risk level Technology example What the company must do
Unacceptable risk A system that causes harmful manipulation or exploits vulnerabilities. Do not deploy. Review design and purpose.
High risk AI used for recruitment, credit scoring, healthcare, education or essential services. Implement risk management, documentation, human oversight, data governance, audit logs, cybersecurity and compliance measures.
Transparency risk Chatbots, deepfakes, synthetic content, generative AI visible to users. Inform users, apply labelling where required and document how the system operates.
Minimal or low risk Internal filters, low-impact recommendation engines, assistants with no significant effects. Maintain basic governance, security, privacy and contractual controls.

 

Step 3: Assess whether your system may be high-risk

For a technology company, the question should not be "is my system AI?" but rather "does my system fall within a high-risk use case?" The distinction is critical.

High-risk systems are subject to stricter obligations before they can be placed on the market or put into service. The European Commission highlights obligations such as risk assessment and mitigation, data quality, activity logging, technical documentation, clear information to the deployer, human oversight, and robustness, cybersecurity and accuracy.

Cases where a tech company should exercise particular caution

Use case Why it may be sensitive
AI for recruitment and hiring May affect access to employment and give rise to discrimination.
AI for employee performance evaluation Impacts working conditions and business decisions.
Customer or user scoring May affect access to services, financing or contractual terms.
Healthcare AI or healthtech May affect health outcomes, diagnosis, triage or clinical recommendations.
AI in education May influence access, assessment or academic progression.
Biometric systems May affect identity, privacy and fundamental rights.
AI for compliance or fraud detection May generate false positives with legal or financial consequences.
AI agents with autonomous actions May execute tasks, send communications or modify systems without immediate human intervention.

 

Step 4: Check the relevant application dates

Timing matters, because some obligations are already in force while others are being phased in. According to the European Commission, the AI Act entered into force on 1 August 2024; prohibitions and AI literacy requirements have applied since 2 February 2025; governance rules and obligations for general-purpose AI models apply from 2 August 2025; and the general framework applies from 2 August 2026.

The Commission has also indicated an updated timeline for certain high-risk systems: systems used in specific high-risk areas, such as biometrics, critical infrastructure, education, employment, migration, asylum and border control, would become subject to the rules from 2 December 2027, while systems embedded in products such as lifts or toys would have until 2 August 2028, in the context of the AI Act simplification package.

Date What to review
1 August 2024 AI Act enters into force.
2 February 2025 Prohibited AI practices and AI literacy obligations apply.
2 August 2025 Governance rules and obligations for general-purpose AI models apply.
2 August 2026 General application of the AI Act, with category-specific rules.
2 December 2027 Timeline indicated by the Commission for certain high-risk areas.
2 August 2028 Timeline indicated for certain high-risk systems embedded in regulated products.

The practical takeaway is clear: waiting until the last moment is a poor strategy. Documentation, testing, contracts and governance frameworks cannot be put together in a week.

 

Step 5: Review personal data and GDPR compliance

The AI Act does not replace the GDPR. If the AI system processes personal data, the company must also review the legal basis, the duty to inform, data minimisation, retention, security, international transfers, data subjects' rights and the relationship with data processors.

For AI systems that assess personal aspects, profile users, or may produce significant effects on individuals, a data protection impact assessment may be required. Article 35 of the GDPR requires an impact assessment where a type of processing, in particular using new technologies, is likely to result in a high risk to the rights and freedoms of individuals. It expressly mentions systematic and extensive evaluation of personal aspects based on automated processing, including profiling, where this produces legal effects or similarly significantly affects the individual.

GDPR Question Risk it addresses
What personal data does the system use? Prevents excessive or unidentified processing.
Does it involve sensitive data? Increases the risk level and legal requirements.
What is the legal basis? Without a legal basis, the processing may be unlawful.
Is data used for training, fine-tuning, or evaluation? This must be properly disclosed and justified.
Are there any significant automated decisions? May trigger additional safeguards.
Is data transferred outside the EEA? Requires a review of international transfer safeguards.
Does the provider use client data to improve its model? This must be governed by contract and privacy policy.

 

Step 6: document the purpose and limits of the system

A company must be able to explain what its AI system is for, and what it should not be used for. This delimitation is not merely technical; it is also legal and commercial.

For example, a tool that summarises documents should not be presented as one that automatically determines the legal viability of a claim. An HR assistant should not become, without oversight, a candidate screening filter. A customer service chatbot should not generate contractual commitments without review.

Element What to document
Intended purpose What problem the system solves.
Intended users Who may use it and with what profile.
Context of use Sector, country, language, clients and limitations.
Prohibited uses What the user must not do with the system.
Level of autonomy Whether it recommends, prioritises, generates content or executes actions.
Human oversight Who reviews outputs and when they may intervene.
Escalation When the matter is referred to a responsible person or team.

 

Step 7: prepare technical and legal documentation

Documentation will be one of the key differences between a company that is prepared and one that is exposed. A generic folder containing a privacy policy and terms of use copied from another product will not suffice. Documentation must connect the actual system to its actual risks.

Document Purpose
AI systems inventory Identifies all internal and external uses of AI.
Risk classification sheet Justifies whether the system is minimal risk, transparency-only, high-risk or prohibited.
AI Act impact assessment Analyses risks to rights, safety, discrimination and misuse.
GDPR impact assessment Assesses data protection risks where applicable.
Technical documentation Sets out architecture, data, model, metrics, testing and limitations.
Testing log Evidences testing, validation, biases, errors and corrective measures.
Human oversight policy Defines intervention, review and internal accountability.
Incident response procedure Establishes how to detect, escalate and remediate failures.
Supplier contracts Governs data, security, sub-processors, generative AI and liabilities.
Client and user information Clearly explains the use of AI and its limitations.

 

Step 8: Review transparency obligations

The AI Act introduces specific transparency obligations for certain systems. The European Commission notes that users must be informed when they are interacting with systems such as chatbots, and that certain AI-generated content, such as deepfakes or content published to inform the public on matters of general interest, must be clearly identified or labelled where applicable.

For a technology company, transparency should not be treated as a decorative notice. It must be embedded in the product design, in the terms of use, in the interface, in the privacy policy, in the instructions for business clients, and in the workflows where the user may be affected.

Situation Practical measure
Customer service chatbot Inform users that they are interacting with an AI system.
Generation of images, voice or video Assess obligations regarding watermarking, labelling or disclosure notices.
Deepfakes or realistic synthetic content Review risks relating to image rights, reputation, consent and transparency.
AI assisting in business decisions Inform the client of the scope, limitations and required human oversight.
AI-generated text intended to inform the public Review obligations for identifying AI-generated content.

 

Step 9: Review contracts with clients, suppliers and investors

A technology company must not only comply internally. It must also be able to provide guarantees to clients, investors, partners and suppliers. Contracts must clearly set out what the system does, what it does not do, what data is used, what controls are in place and who is liable in each scenario.

Contract Clauses to review
B2B SaaS agreement Permitted use, AI limitations, liability, SLA, audit and security.
DPA / data processing agreement Data processing, sub-processors, transfers and use for training purposes.
AI supplier agreement Compliance guarantees, documentation, security, traceability and change management.
Terms of use Prohibited uses, responsible use, generated content, suspension and abuse.
Enterprise agreement Audit requirements, logs, reporting, incidents, indemnification and support.
Shareholders' / investment agreement Software ownership, intellectual property, compliance and due diligence.

 

Step 10: Establish internal AI governance

The AI Act requires companies to look beyond the product itself. A company must have control over how AI is designed, procured, tested, used and updated. This affects leadership, legal, data protection, security, product, engineering, sales and human resources teams.

The European Commission has also highlighted the obligation of AI literacy, applicable from February 2025. This requires organisations not only to have policies in place, but to ensure that individuals who use or manage AI systems understand their risks, limitations and responsibilities.

Internal Area Responsibility
Management Approve AI policy and risk tolerance.
Legal / Compliance Classify systems, contracts, evidence and obligations.
DPO / Privacy Review GDPR compliance, impact assessments and user rights.
Security Review access controls, logs, incidents, vendors and cybersecurity.
Product Embed transparency, limitations and oversight into the interface.
Engineering Document architecture, testing, datasets, changes and performance.
HR Train teams and monitor AI use in employment and workforce management.
Sales Avoid commercial commitments that the system cannot legally deliver.

 

Diagram: legal review before launching an AI system in Spain

sistema de ia

 

Pre-launch legal checklist

Area Question Status
Inventory Is there a system record for the AI system? Pending / Reviewed
Role Does the company know whether it acts as provider, deployer or integrator? Pending / Reviewed
Risk Has the system been classified under the AI Act? Pending / Reviewed
Prohibited practices Has it been confirmed that the system does not fall within a prohibited practice? Pending / Reviewed
High risk Has it been assessed whether the system affects employment, health, education, biometrics, credit or essential services? Pending / Reviewed
Transparency Are users informed when they are interacting with AI? Pending / Reviewed
GDPR Has the legal basis, information obligations, data minimisation and security been reviewed? Pending / Reviewed
DPIA Has it been assessed whether a Data Protection Impact Assessment is required? Pending / Reviewed
Data Is it known which data are used to train, fine-tune, test or operate the system? Pending / Reviewed
Vendors Do contracts govern data use, sub-processors, changes and auditing? Pending / Reviewed
Security Are there access controls, logs, incident procedures and cybersecurity measures in place? Pending / Reviewed
Human oversight Is there genuine, documented human intervention where required? Pending / Reviewed
Documentation Is there adequate technical and legal documentation? Pending / Reviewed
Training Have teams received training on the responsible use of AI? Pending / Reviewed
Post-launch Are there monitoring, error review and incident management processes in place? Pending / Reviewed

 

What role does AESIA play in Spain?

Spain established the Spanish Agency for the Supervision of Artificial Intelligence by means of Royal Decree 729/2023, of 22 August. The Spanish Official Gazette (BOE) establishes AESIA as a public-law state agency with its own legal personality, dedicated assets, and administrative autonomy.

The Agency's statutes provide for functions of supervision and, where applicable, sanctioning of artificial intelligence systems, with the aim of reducing risks to personal integrity, privacy, equal treatment, non-discrimination, and other fundamental rights. They also include functions relating to awareness-raising, training, advice, and support for the responsible development of AI.

For a technology company, this confirms that AI oversight in Spain will not be purely a European matter. There will also be national-level engagement, criteria, guidance, enforcement actions, and potential regulatory scrutiny.

 

Common mistakes before launching an AI product

  1. Launching the product without classifying the system by risk level.
  2. Assuming that using a third-party API eliminates your own liability.
  3. Failing to check whether the use case affects employment, credit, health, education, or essential services.
  4. Not informing users that they are interacting with an AI system.
  5. Failing to check whether AI-generated content must be labelled.
  6. Using personal data to train or fine-tune models without a clear legal basis.
  7. Not entering into appropriate contracts with AI providers.
  8. Having no logs, traceability, or technical documentation in place.
  9. Failing to provide for meaningful human oversight.
  10. Marketing the system as "fully automated" without disclosing its limitations, error rates, or the role of human intervention.
  11. Not training commercial, product, and support teams.
  12. Failing to prepare documentation for enterprise clients, investors, or audits.

 

Priority checklist for a technology company

Priority Action When to act
High AI systems inventory Before launching or integrating any AI functionality.
High AI Act risk classification Before placing the product on the market.
High GDPR and personal data review Before processing real personal data.
High Contracts with AI providers Before connecting APIs or processing client data.
High User transparency Before publishing the user interface.
Medium AI Act impact assessment Where there is significant risk or a sensitive sector is involved.
Medium GDPR impact assessment Where there is high risk to individuals' rights and freedoms.
Medium Internal AI policy Before scaling internal use.
Medium Team training Before sales, support, or HR teams begin using AI.
Medium Post-launch audit After deployment and following each significant change.

 

Conclusion

The AI Act requires technology companies to rethink how they bring AI products to market. Legal review can no longer be left until the end, when the product is already designed, sold, and connected to live data. It must be built into the development cycle from the outset.

Before launching an AI system in Spain, a company must be clear on its role, the level of risk it is taking on, the data it processes, what it must disclose to users, what contracts are required, what documentation it can produce, and how it will monitor the system after launch.

At Conesa Legal, we advise technology companies, startups, and businesses integrating artificial intelligence into their products or internal processes. We assess how the system fits within the AI Act framework, its relationship with data protection advice, corporate compliance, contracts with suppliers and clients from a commercial law perspective, the implementation of a whistleblowing channel, and due diligence prior to transactions or investments.

Tell us about your situation and we will assess what your company needs before launching or scaling an artificial intelligence system in Spain.

 

Frequently asked questions about the AI Act 2026 for technology companies

Does the AI Act apply to any company that uses artificial intelligence?

Not all companies will face the same obligations. The level of requirements depends on the company's role, the type of system, the sector, and the risks involved. Using AI to filter spam is very different from using it to screen job applicants, assess creditworthiness, or support medical decisions.

Can a startup using an external AI API also have obligations under the Act?

Yes. Even if the underlying model belongs to a third party, the startup may take on obligations if it integrates the AI into its own product, defines its purpose, markets it under its own brand, or uses it in ways that affect customers, users, or employees.

Which AI systems are considered high-risk?

High-risk systems may include, among others, those used in employment, education, critical infrastructure, access to essential services, certain biometric applications, migration, justice, or regulated products. Each case must be analysed according to the actual purpose of the system.

When does the AI Act apply?

The AI Act entered into force on 1 August 2024. Some obligations have already applied since 2025, and the general framework is being rolled out in 2026, with specific timelines for certain high-risk systems.

Does the AI Act replace the GDPR?

No. If the system processes personal data, the company must also comply with the GDPR. In many AI projects, the data protection review will be just as important as the AI Act review.

What documentation should a company prepare before launching an AI system?

At a minimum, you should prepare a system inventory, risk classification, technical documentation, data review, supplier contracts, user-facing information, a human oversight policy, logs, testing records, and an incident response procedure.

Who supervises the AI Act in Spain?

Spain established the Spanish Agency for the Supervision of Artificial Intelligence (AESIA) under Royal Decree 729/2023. Its statute sets out functions covering supervision, certification, training, awareness-raising, and support for the responsible use of AI.

 

Further reading

 

Key sources

Are you launching or scaling an AI system in Spain?

We review the legal fit of your product before it becomes a commercial, contractual, or regulatory problem. In an initial conversation, we identify your role under the AI Act, your risk level, and the priority next steps.

  • Your company's role: provider, integrator, or deployment operator.
  • System risk classification and documentation roadmap.
  • Combined compliance framework: AI Act, GDPR, and contracts with clients and suppliers.

Nueva llamada a la acción

Date published: 28 July 2026

Last updated: 28 July 2026

Published on Updated on