May 26, 2026, will mark a fundamental milestone in the technological and institutional ecosystem of our country. The Council of Ministers, at the proposal of the Ministry for Digital Transformation and Civil Service, has approved for submission to the Congress of Deputies the draft Organic Law for the good use and governance of artificial intelligence. This new regulation not only represents the adaptation to the Spanish legal system of the European Artificial Intelligence Act (AI Act) —in force since August 2024—, but also consolidates Spain as a global benchmark in the creation of a secure, ethical, and humanistic digital environment.
At a time when artificial intelligence is redefining business models, public sector operations, and the daily lives of citizens, this legislation seeks a perfect balance: combining a strict regulatory approach to protect fundamental rights with a decisive push for secure and guaranteed innovation.
The context: Spanish leadership in innovation and regulation
During the presentation of the project, the Minister for Digital Transformation and Civil Service, Óscar López, highlighted a key premise for the business and technology sector: regulation and innovation are not opposing forces, but complementary ones. According to the minister, Spain is the best example that establishing clear rules fosters a more robust and competitive ecosystem.
Our country is already internationally recognized for both the adoption and regulation of AI, backed by studies from prestigious institutions such as Stanford University and tech giants like Microsoft. This leadership materializes in tangible projects of great strategic significance:
- The installation of two European Union AI factories on national territory.
- The development of an ambitious gigafactory project.
- The promotion of leading companies in the sector, such as Multiverse Computing.
- The creation of ALIA, a proprietary artificial intelligence model trained specifically in Spanish.
As the minister highlighted, we are facing an "absolutely civilizational" debate. The new law fulfills government commitments to make digital environments safer, demanding accountability, promoting algorithmic transparency, and including specific measures for the protection of minors.
A clear and structured governance framework
For regulation to be effective, companies need legal certainty and to know which bodies they must be accountable to. The new Law establishes a precise governance framework through the designation of notifying authorities and market surveillance authorities.
The approach adopted is highly pragmatic. Those products that already have sector-specific regulations (such as machinery, toys, vehicles or medical devices) will maintain their current authorities, aligning with the European Regulation. However, for systems not regulated by product legislation —such as those applied in human resources, education or biometrics— oversight will fall mainly on:
- The Spanish Agency for the Supervision of Artificial Intelligence (AESIA).
- The Spanish Data Protection Agency (AEPD).
- The General Council of the Judiciary (CGPJ), depending on the specific field.
In addition, the AESIA is established as a single point of contact for supervision matters, thus facilitating communication and procedures for companies developing and supplying AI.
Red lines: Prohibited AI systems
The AI Regulation classifies systems according to their risk. The new Spanish law is uncompromising with those that present an unacceptable risk to people's safety, health or fundamental rights.
A notable achievement of Spanish technological diplomacy is the inclusion of new prohibitions at the European level. At Spain's initiative, with the firm support of France, the EU agreed last May 7 to add two prohibited systems to the eight already existing. The most notable is the total ban on AI systems that generate sexual 'deepfakes', an urgent measure following the incidents of non-consensual nudity created by virtual assistants such as Grok.
Among the systems that are strictly prohibited on the market, the following stand out:
- Subliminal manipulation: Systems that use imperceptible techniques to alter decisions without consent, causing serious harm. For example, a chatbot that detects gambling addiction vulnerabilities and uses hidden stimuli to incite betting.
- Exploitation of vulnerabilities: AI that takes advantage of age, disability or socioeconomic situation. A clear case would be a smart toy that incites minors to carry out dangerous challenges.
- Discriminatory biometric categorization: Systems that classify people by race, political, religious or sexual orientation based on biometric data, such as facial analysis on social networks.
- Social Scoring: Evaluating individuals based on their social behavior to deny them essential services, subsidies or bank loans.
Sanctioning regime: Proportionality and support for SMEs
Compliance with the law is backed by a sanctioning regime based on the principles of proportionality and effectiveness. Infringements are classified as very serious, serious, and minor.
Fines are deterrent for large corporations, potentially reaching up to 35 million euros or 7% of global turnover in the most extreme cases. For minor infringements, sanctions can reach up to 500,000 euros or 0.5% of turnover.
However, the law introduces vital flexibility for the Spanish business fabric. Authorities will be able to adapt sanctions based on severity, intentionality, or recidivism. Correction is prioritized over penalization through early payment reductions and the adoption of corrective measures. Furthermore, specific consideration of business size is included, actively protecting SMEs and startups so as not to stifle emerging innovation.
Modernization and good use of AI in the public sector
One of the major innovations of the Spanish law, which goes beyond mere European adaptation, is the regulation of AI use within the state public sector itself. Responding to the demands of the public hearing, the Administration assumes an exemplary role.
To ensure maximum transparency for citizens, a public inventory of AI systems used in administrative procedures will be created, covering not only high-risk systems but all those implemented.
Likewise, the figure of the 'AI Delegate' is born, a specialized profile responsible for coordinating regulatory application, advising on technological projects, and supervising the public procurement of these tools. All this will be accompanied by a strong push for training and awareness among public employees, ensuring that the Administration is prepared for the challenges of the 21st century.
Sandboxes: Fostering innovation in secure environments
Spain was already a pioneer by anticipating the European obligation by creating the first controlled testing environment (Sandbox) for AI. Now, the new law formally articulates the governance of these spaces.
The national-scale controlled testing environment will be operated by AESIA. These 'sandboxes' are fundamental for companies, as they allow them to test their innovations in a secure environment, receiving regulatory advice before launching their products on the market. The law also allows for the creation of additional sectoral sandboxes by other supervisory authorities, always ensuring the participation of the bodies responsible for fundamental rights.
Conclusion
The draft Organic Law for the good use and governance of artificial intelligence places Spain at the global legislative forefront. For technology companies, this represents a scenario of clear rules that penalizes bad practices but fosters, protects, and supports those who commit to ethical technology. Ultimately, Spain demonstrates that it is possible to lead the AI revolution without compromising human values, ensuring that the digital future is secure, transparent, and trustworthy for everyone.






