Spain's AI Law 2026: What Your SMB Needs to Know Before August
The government approved the Organic Law for the proper use and governance of artificial intelligence in late May. Sounds like something distant, the kind of issue that only affects big tech companies. But it doesn't. If you use ChatGPT to draft emails, have a WhatsApp chatbot, or any automation tool talking with your customers, this law directly affects you.
The problem is most Spanish SMBs don't know this yet. According to Spain's statistics agency, over half of service companies already use some form of AI tool. Very few have done their homework to comply with the regulation arriving this August.
Let's see what exactly changes, what you need to do, what can happen if you don't, and how to prepare without needing a 10-person legal team.
Spain's AI Law vs. EU AI Regulation: they're not the same
Two regulations intersect here, and it's worth not confusing them:
- EU AI Regulation: approved in 2024, in force for two years in phases. Establishes four risk levels and obligations for AI systems across the EU.
- Spain's Organic AI Law: approved by Cabinet in May 2026, adapts EU regulation to Spanish law. Establishes supervisory bodies, the penalty regime, and how all this applies within Spain.
In practice, Spain's law is who watches you. Who issues the fine. Who decides whether your chatbot complies. The EU Regulation makes the rules; Spain's law enforces them with names and penalties.
The enforcement body is AESIA (Spanish AI Supervision Agency), based in A Coruña. Spain was the first EU country to create a specific agency for this, which tells you how serious it is.
Key regulatory dates
This isn't something coming "someday." It's here now:
| Date | What comes into force | Impact for your SMB |
|---|---|---|
| August 1, 2024 | EU AI Regulation enters into force | Regulatory clock starts |
| February 2, 2025 | Prohibition of unacceptable practices + AI literacy requirement | Your team must understand the risks of the AI tools they use |
| August 2, 2025 | General-purpose model obligations (GPT, Claude, Gemini...) | Providers must comply; affects how you use them |
| August 2, 2026 | Full application: AESIA inspects and fines | Critical date. Everything must be documented |
| August 2, 2027 | AI in regulated products (CE marking) | Manufacturers and integrators in specific sectors |
There it is: August 2, 2026—less than two months after reading this—AESIA starts real inspections. What isn't documented by then can cost you money.
There's debate about whether the Digital Omnibus, a European regulatory revision approved by Parliament in March 2026, will delay some obligations until December 2027. But even then, AI literacy requirements (Article 4) and prohibited practices remain in force. And until the EU Council formally adopts the text, August 2026 is the legal deadline.
Who does the law affect?
It affects any company, including freelancers, that uses, develops, or deploys AI systems: chatbots, virtual assistants, content generators, automated decision tools, biometric analysis systems, and much more.
Concrete examples that read like a catalog of what any SMB does today:
- You have a chatbot answering WhatsApp queries on weekends → the law affects you.
- You use ChatGPT Plus to write product copy and social posts → the law affects you.
- Your CRM uses AI to auto-score leads → the law affects you.
- You use HR software that filters CVs with AI → the law affects you, and you're in high-risk territory.
- You use Microsoft Copilot to summarize meetings → the law affects you.
If you use AI and run a business in Spain, the law is for you. Whether you have 1 or 500 employees.
The 4 concrete obligations you should already be meeting
Not all the regulation applies equally to everyone. Real obligations depend on the risk level of the system you use. But four apply to basically any SMB:
Obligation 1: Transparency—your customers must know they're talking to AI
If you have a chatbot or virtual assistant, customers must know they're interacting with a machine, not a person. This was already best practice under the EU Regulation since August 2024. Now, with Spain's law, it's directly auditable.
A small footnote isn't enough. The disclosure must be clear and understandable. If your chatbot says "Hi, I'm Maria, your assistant" and it's AI, you're in breach.
Obligation 2: AI literacy—your team must understand what they're using
Article 4 of the EU Regulation has required since February 2025 that your team members using AI tools have sufficient understanding of the risks, limitations, and legal framework of those systems.
Translated: it's not enough that your employee can use ChatGPT. They need to understand what can go wrong, the risks of feeding customer data to third-party tools, and when AI hallucinates.
This is auditable from August 2026. AESIA can ask for documentation of trainings: who trained, when, on what tools, and how you decided on content and duration.
Obligation 3: Data protection in your AI tools
Many freelancers and SMBs feed customer information—names, addresses, order data, contracts—into tools like ChatGPT, Claude, or Gemini without reading privacy policies. Sometimes to draft a response, sometimes to analyze data.
The law makes clear: you're responsible for that data. You need to know:
- Where the data you input to each tool is stored.
- If the provider uses it to train their models (and if so, get consent or anonymize first).
- If there are international data transfers (OpenAI is in the U.S.; GDPR requires extra safeguards).
Obligation 4: High-risk systems—documentation, assessment, human oversight
If your AI makes decisions affecting people—hiring, credit scoring, service access, medical diagnosis—obligations multiply. In these cases you need:
- Technical system documentation.
- Risk management system.
- Impact assessment on fundamental rights.
- Mandatory human oversight (AI decides, a person reviews).
- Activity log (logging) with minimum 6-month retention.
This especially affects SMBs in HR, fintech, health, and insurance. If that's you, August isn't a date—it's an emergency.
Fines: up to €35 million (or 7% of global revenue)
The penalty regime has three tiers:
| Violation type | Maximum fine |
|---|---|
| Prohibited practices (biometrics in public spaces, subliminal manipulation...) | €35 million or 7% of global revenue |
| High-risk obligation breaches | €15 million or 3% of global revenue |
| Incorrect information to authority | €7.5 million or 1.5% of global revenue |
| Minor violations (missing documentation, undemonstrated literacy...) | €6,000 to €500,000 |
Does this mean a hair salon gets fined €35 million? No. The law applies proportionality by company size. But minor violations start at €6,000, which for a freelancer or microenterprise does hurt.
Most important: in an inspection, undocumented literacy or lack of chatbot transparency can open the door to reviewing everything else. One minor breach can escalate any other violations they find.
Action plan: what to do in the next 60 days
We're not going to tell you to hire a law firm for €15,000. Most SMBs can meet basic requirements with an orderly approach. Here's a realistic plan:
Weeks 1-2: Take inventory
Spend 30 minutes writing down every AI tool you use. Think about:
- Chatbots (WhatsApp, web, social media).
- Writing assistants (ChatGPT, Claude, Copilot, Gemini...).
- Management software with AI (CRM, HR, invoicing, accounting).
- Analysis tools or automated decision-making.
For each, note: what it does, what data you feed it, who provides it, and where their servers are.
Weeks 2-3: Review transparency
If you have chatbots or virtual assistants, verify the customer knows they're talking to AI. Change the avatar name if needed, add a notice, ensure the escalation path to a human is clear and accessible.
Also review each tool's data usage policies. ChatGPT Plus, for example, lets you disable data use for training (Settings > Data Controls). Do it if you haven't.
Weeks 3-4: Document literacy
You don't need an AI master's degree. Just document that your team (or you, if freelance) received basic training on:
- What the AI you use is and how it works at a high level.
- What data not to input (personal, confidential).
- What to do when AI gets it wrong (always verify before sending to a customer).
- When to escalate to a human instead of letting AI decide alone.
An internal email with these guidelines, a documented 30-minute talk with date and attendees, or a saved online course as PDF works. Don't seek perfection; just show you acted.
Weeks 4-6: Establish protocols
Create an internal document—even two pages—with:
Your AI usage policy: what tools are approved, what data can and can't go in, who's responsible for each tool, what to do if something fails.
Your transparency policy: how you identify AI to customers, when you escalate to humans, how you inform the user.
Keep invoices for all your AI tools. You'll need them to justify professional use if asked.
Weeks 6-8: Review and adjust
Do a final pass. Do you have high-risk systems (automatic CVs, scoring, decisions about people)? If so, you need more robust technical documentation and impact assessment. Professional consultation might be worth it here.
Only using AI for productivity and basic support? You're at a reasonable compliance level with the plan above.
Tools that help
Specific ones for compliance without losing your mind:
- Your tools' privacy policies: review those from OpenAI, Anthropic, Google, Microsoft. All have GDPR and EU data storage sections.
- Automation platforms with EU servers: n8n self-hosted gives you complete data control. If using Make or Zapier, check their data location policies.
- LLM monitoring: tools like Langfuse or Helicone monitor what's sent to models and detect sensitive data injection before it leaves your company.
- AESIA: the agency itself has guides at aesia.gob.es. Not all updated to the May 2026 law yet, but helpful context.
Frequently asked questions
If I only use free ChatGPT for email drafts, do I have to do all this?
For basic productivity use (writing, research, summaries), your obligations are mainly three: don't feed customer sensitive data, make sure generated content is reviewed before sending, ensure your team knows these two things. Literacy applies whether free or paid.
Does my WhatsApp chatbot (Tidio, ManyChat...) count?
Yes. Any system interacting with customers using AI and potentially making automated decisions (routing queries, generating answers, collecting data) is in scope. Make sure your chatbot provider also complies: if using an intermediary like Tidio or ManyChat, review their compliance documentation.
Are there exemptions for microenterprises or freelancers?
No total exemption. The law applies to all. But the penalty regime accounts for company size, severity, and intent. Fines will be proportional. Don't use that as an excuse to do nothing.
Can I use the AI Act or Spain's law to shield myself if AI gives a customer wrong information?
The law reinforces your responsibility as a business. If a chatbot gives incorrect information to a customer based on data you provided, you're liable. That's why human oversight and verification are mandatory, not optional.
Does the Digital Kit cover AI Law compliance?
The 2026 Digital Kit includes a new "AI applied to work" category with grants up to €2,000–€3,000 for freelancers and microenterprises. This can fund part of implementing tools to help you comply. Check acelerapyme.gob.es. The complete guide to Digital Kit and Consulting Kit explains how to combine both grants.
Request a free assessment
If you want to implement this in your business, request a free 30-minute assessment. Contact us here or reach out via WhatsApp from the site.