National layer
Spain
The Regulation is directly applicable, so nothing here replaces it. What a Member State adds is an authority, a penalties regime and guidance, and each of those is read against the EU provision it sits beside.
The rule this page follows
National guidance never carries a claim on this site by itself. Every entry names the EU provision it interprets, because the Spanish text of the Regulation is authentic law while a regulator's guide is that regulator's reading of it.
Authorities, law and guidance
AESIA, and what it is for
Article 70 makes every Member State designate at least one notifying authority and at least one market surveillance authority, exercising their powers independently. Spain created the Agencia Española de Supervisión de Inteligencia Artificial by Real Decreto 729/2023, which approves its statute. When Spanish copy on this site refers to the market surveillance authority, this is the body it means.
Worth knowing The agency’s own site did not respond when the corpus was built, so no AESIA publication is captured here. Its founding statute is, and a claim on this page rests on that statute and on the EU provision beside it, never on national guidance alone.
The governance bill, and what it is not
A Proyecto de Ley Orgánica para el buen uso y la gobernanza de la Inteligencia Artificial is in parliamentary procedure. It is not a transposition: this Regulation is directly applicable, and nothing national is needed to make it bind. What a national law does here is fill the room the Regulation leaves to Member States, and the largest of those rooms is Article 99(1), which tells Member States to lay down the rules on penalties and other enforcement measures.
Worth knowing The bill was not published in the Boletín Oficial del Estado and is not in force when this page was last reviewed. Until it is, it states an intention, not law.
The AEPD guides, and the regime they actually interpret
The Spanish data protection authority has published the most detailed engineering-facing material any Spanish regulator has put out on AI systems. Read it, and place it correctly: it interprets data protection law, not this Regulation. Article 2(7) keeps the two regimes separate and both applicable. Where they meet is specific and useful: a deployer uses the Article 13 information to carry out its GDPR impact assessment, and a fundamental rights impact assessment may cross-reference that assessment where it already covers the same ground.
| Guide | What it is useful for |
|---|---|
| Adecuación al RGPD de tratamientos que incorporan IA | The baseline treatment of AI processing under data protection law. |
| Requisitos para auditorías de tratamientos que incluyan IA | What an auditor will ask for, which overlaps heavily with the evidence an operator keeps anyway. |
| Exactitud, idoneidad y calidad de los datos en IA | Data quality expectations, next to the Article 10 data governance requirements. |
| Orientaciones sobre IA agéntica | The most detailed European regulator treatment of agentic systems so far: memory compartmentalisation, tool allowlists, autonomy levels. |
| Listas de tratamientos que requieren evaluación de impacto | The criteria that make a data protection impact assessment mandatory. |
Worth knowing National guidance never carries a claim on this site by itself. Every row above is read against the EU provision cited with it.
The regulatory sandbox
Article 57 makes Member States ensure that their competent authorities establish at least one AI regulatory sandbox at national level, operational by the date the article sets, either alone or jointly with other Member States. A sandbox is a controlled framework in which a provider develops, trains, validates and tests an innovative system under a sandbox plan agreed with the authority, for a limited time and under supervision.
Harmonised standards
Harmonised standards, and what they buy you
Article 40 is the only place in this Regulation where following a standard has a legal effect. A high-risk system or a general-purpose AI model that conforms to a harmonised standard whose reference has been published in the Official Journal is presumed to be in conformity with the requirements that the standard covers, and no further. The chain has three links, and the middle one is the one people skip: a standard exists, its reference is published in the Official Journal, and only then does the presumption attach.
- The standards for this Regulation are being drafted by CEN-CENELEC JTC 21, on a Commission standardisation request.
- They are sold through national standardization bodies, UNE in Spain. They are not free, and this site does not mirror them.
- Until a reference is published in the Official Journal, conformity with a draft buys engineering confidence, not a presumption of conformity.
- Where harmonised standards are missing or insufficient, the Commission may adopt common specifications instead.
Worth knowing This site records no harmonised standard cited in the Official Journal for this Regulation as of its last source verification. That is a statement about what the corpus holds, not a claim about what was published this week: check the Official Journal before relying on it.