The AI Act, Regulation (EU) 2024/1689, is the European regulation that governs the development and use of artificial intelligence. It entered into force on 1 August 2024 and is being applied in phases. It is directly applicable in all Member States without the need for national legislation, although each country designates its own authority; in Spain, this is AESIA.
A risk-based approach
- Prohibited: practices such as social scoring or subliminal manipulation. This applies from February 2025.
- High risk: systems that affect health, safety, or fundamental rights (recruitment, credit, education, infrastructure…). They require risk management, documentation, logging, data quality, and human oversight.
- Limited risk: transparency obligations, such as warning users that they are interacting with an AI or that content is synthetic.
- Minimal risk: the majority of uses; no specific obligations.
General-purpose AI (GPAI) models have their own chapter, with obligations applying from August 2025.
What already affects every business
Since February 2025, Article 4 has required AI providers and users to ensure a sufficient level of AI literacy among their staff. Obligations for high-risk systems apply from August 2026, and those for regulated products from August 2027. Penalties reach up to 7% of global turnover for the most serious infringements.
In practice, for an SME, the regulation translates into three habits: knowing which AI systems it uses and for what purpose, training those who operate them, and putting a person in charge of the actions that matter (human in the loop).