Acerete Abogados
Book a consultation
Guide · AI compliance

EU AI Act: what you have to do, and when

If your company uses or sells artificial intelligence, you already have obligations — not in the future, now. Regulation (EU) 2024/1689 applies in phases and several are already in force. This guide places you: what role you play under the rules, what risk level your systems carry and where to start. Last reviewed: 27 August 2026.

First things first: what role you play under the rules

Your obligations do not depend on your size but on the role you play. And most Spanish companies occupy the second of these roles convinced that none of it applies to them.

·

Provider

You develop an AI system, or place it on the market under your own name or brand. It is the heaviest role: technical documentation, risk management, conformity assessment, CE marking where applicable.

·

Deployer

You use an AI system in your professional activity. This is 90 % of companies. You have obligations of your own: use in line with instructions, human oversight, informing the people affected, and staff training.

·

Importer or distributor

You bring third-party systems into the EU or sell them on. You must verify that the provider complied before putting the product into circulation.

Watch out for one counter-intuitive point: if you take a third-party system, put your brand on it and offer it to your clients, or if you substantially change its purpose, you become a provider with every obligation that entails.

The four risk levels

·

Unacceptable risk — banned

Social scoring, subliminal manipulation, exploitation of vulnerabilities, emotion recognition at work and in education, biometric categorisation using sensitive data, and untargeted scraping of facial images. Banned since 2 February 2025.

·

High risk — allowed, with heavy obligations

Recruitment and employment management, creditworthiness assessment, education, biometrics, critical infrastructure, essential public services, and systems acting as a safety component of an already regulated product.

·

Limited risk — transparency obligations

Chatbots, conversational assistants and synthetic content generation. You must disclose that the user is interacting with an AI, and label generated or manipulated content as such.

·

Minimal risk — no specific obligations

Most everyday uses: spam filters, recommenders, internal optimisation. No obligations under the Regulation itself, though the GDPR and the rest of the law still apply.

Application timeline

DateWhat comes into play
2 February 2025Banned practices and the duty to provide AI literacy training to staff (article 4).
2 August 2025General-purpose AI models (GPAI), the governance structure and the penalty regime.
2 August 2026The bulk of the Regulation, including Annex III high-risk systems and the transparency obligations.
2 August 2027High risk embedded in already regulated products (Annex I), and GPAI models already on the market.

Where to start, in practice

01

Inventory

A list of every AI system the company uses or sells. That includes the ChatGPT someone on the team uses without permission, and the AI module your long-standing software switched on in an update. It is almost never the three that management thinks.

02

Classification

For each system: its risk level and your role. This defines everything that follows, so getting it wrong multiplies the work or leaves you exposed.

03

AI literacy

Documented training for the staff who use these systems. It has been mandatory since February 2025, it is the easiest to breach and the easiest to prove once done.

04

Governance

An internal AI use policy, an assigned owner, a record of decisions, effective human oversight and an impact assessment where required. Documented: what is not written down cannot be evidenced.

05

The contract chain

If you use third-party AI, your contracts must allocate liability and guarantee you information from the provider. If you sell AI, your clients will start demanding the same of you — and that is where compliance turns from a cost into a selling point.

The AI Act does not replace the GDPR

If the system processes personal data — and almost all of them do — you still need a legal basis, information for the data subject, minimisation and, in many cases, a data protection impact assessment. In practice both analyses are done at once, because 80 % of the documentation overlaps. Doing them separately means paying twice.

Penalties

Up to €35 million or 7 % of total worldwide annual turnover for engaging in banned practices, and up to €15 million or 3 % for other breaches — including failing to meet the deployer's obligations. For SMEs and startups, the lower of the two figures applies. In Spain, supervision falls to AESIA, the Spanish Agency for the Supervision of Artificial Intelligence.

Frequently asked questions

We only use ChatGPT in the office. Does it apply to us?+

Yes. You are a deployer, and that already carries obligations: staff literacy, use in line with the provider's instructions, human oversight, and transparency if you generate content for third parties. You also have a parallel data protection problem if personal or confidential information gets pasted into the prompt.

We are a small startup. Are there exemptions?+

There is proportionality, and there are regulatory sandboxes designed precisely for SMEs and startups, plus the lower penalty cap. What there is not is an exemption: the Regulation sets no size threshold below which it does not apply.

If we already comply with the GDPR, are we covered?+

No, but you have covered much of the ground. The GDPR governs the processing of personal data; the AI Act governs the system itself, whether or not it processes personal data. Your records of processing, impact assessments and vendor policy can all be reused as a foundation.

What will an auditor or a large client ask for first?+

The inventory of systems with their risk classification, and evidence of staff AI training. They are the two things asked for before anything else, and the two that almost nobody has ready.

Keep reading

If your company uses or builds AI

This guide is general information. To find out which duties apply to you, see how I can help with AI compliance.

Your case

Let us start with the inventory

In one session we draw up the real list of AI systems in your company, their risk level and which obligations are already overdue.

Book a consultation