AESIA and the AEPD: who inspects what
Spain is, today, the only EU member state with an agency built specifically to supervise artificial intelligence. AESIA (the Spanish Agency for the Supervision of Artificial Intelligence), headquartered in A Coruña, was created by Royal Decree 729/2023 — more than a year before the AI Act itself entered into force — and is now the primary market surveillance authority for AI systems not tied to specific sectoral legislation, with particular weight in employment, biometrics and education.
The AEPD, for its part, keeps full jurisdiction over the data protection side of an AI system — which in practice covers almost any system that processes personal data. And if the system operates in a regulated sector (banking, insurance, healthcare), that sector's own regulator gets involved too. It isn't unusual for one company, over a single AI system, to end up answering to more than one authority at once.
The three penalty tiers under Spain's new AI law
On May 26, 2026, Spain's Council of Ministers approved the draft Organic Law for the proper use and governance of artificial intelligence, adapting the AI Act's sanctions regime to Spanish law across three levels of severity:
| Level | Maximum penalty |
|---|---|
| Minor infringements | €500,000 or 0.5% of annual turnover |
| Serious infringements | €15 million or 3% of annual turnover |
| Very serious infringements | €35 million or 7% of annual turnover |
The law includes proportionality criteria and reductions for early payment or corrective action — but for an SME or an early-stage startup, even the "minor" tier can be a serious blow if it lands unannounced.
What triggers an inspection
It doesn't take a catastrophic failure to get a visit. The most common triggers are far more mundane: a complaint from an employee or a customer, a security incident that requires notification, a sector-wide sampling campaign from the authority itself, or simply your system showing up — or failing to show up when it should — in the high-risk system registry AESIA is rolling out.
What they'll ask for first
The pattern repeats with little variation: first, the records of processing activities or the high-risk AI system inventory — if it doesn't exist, there's already a problem before anything else gets reviewed. Then the technical documentation justifying why the system was classified the way it was, the impact assessment (DPIA) if the system required one, and real evidence that transparency and human oversight measures are actually working in production, not just described in a document nobody has opened since.
How to prepare before the letter arrives
What separates an inspection that closes in days from one that drags on for months isn't perfect compliance — it's having the evidence folder ready and someone who knows exactly what to say on the first call. Three concrete things help more than anything else:
- A designated point of contact who knows where every document lives and has the authority to answer without having to "check internally" on every question.
- A centralized evidence folder — records, technical documentation, DPIA, policies — that doesn't depend on scrambling to gather loose files the day the notice arrives.
- A script for the first call, so answers aren't improvised at the most high-pressure moment of the whole process.
The inspection itself isn't the moment that decides whether you're compliant — that was already decided by what you did, or didn't do, in the months before. What preparation changes is whether that inspection turns into an orderly formality or weeks of stress reconstructing information on the fly.