AESIA can now inspect and fine: what it looks for in an HR-tech
From 2 August 2026 the Spanish agency has full inspection and enforcement powers. It is worth understanding what starts now and what does not.
Since 2 August 2026, the Spanish Agency for the Supervision of Artificial Intelligence (AESIA) has full power to inspect, request evidence and impose penalties. Transparency obligations take effect and the market surveillance authorities are set in motion. Fines can reach up to 35 million euros.
A regime of its own built on the AI Act
Spain's Organic Law adapts the EU AI Regulation to domestic law, creates its own penalty regime and distributes competences across several bodies. AESIA coordinates, but it is not alone:
- AESIA as the lead supervisory authority.
- AEPD for anything involving personal data.
- CGPJ, Banco de España and CNMV within their respective remits.
- Regulatory sandboxes to test systems in a controlled setting.
The honest caveat almost nobody mentions
Here you have to be precise. The Digital Omnibus package deferred the full high-risk obligations of Annex III (which includes employment) from 2 August 2026 to 2 December 2027. What starts in August 2026 is transparency and the standing-up of the authorities and market surveillance, not the entire high-risk regime.
Put another way: the authority is already operational and procurement is already asking, even though full high-risk conformity is dated in 2027. A deferred obligation does not mean an inactive agency, nor that your clients will wait until 2027 to question you. For an HR-tech that processes candidates' personal data, there is also an obvious overlap with the AEPD that is worth mapping now.