AI governance, security & compliance
AESIA's 16 Guides to Help Businesses Follow the EU AI Act in Spain
Spain's AI supervisory authority, AESIA, published 16 practical guides to help providers and deployers understand and follow the EU AI Act's requirements in Spain. This article explains what each guide covers, who should own the work, when to use it, and where to download the official documents.
Short answer: guides 01–02 explain the AI Act, guides 03–15 each cover one technical requirement, and guide 16 plus the ZIP file turn all of it into checklists you can actually sign off. All are free, in Spanish, non-binding, and hosted at aesia.digital.gob.es/es/guias.
What AESIA published, and what AESIA is
AESIA is Spain's public authority for AI oversight. Its remit: ensure public and private entities comply with applicable AI regulation, protecting privacy, equal treatment, and fundamental rights. It sits under the Secretaría de Estado de Digitalización e Inteligencia Artificial (SEDIA) within the Ministerio para la Transformación Digital y de la Función Pública, and it acts as a national market-surveillance authority for AI systems. Its temporary headquarters is in A Coruña.
What it released is a set of 16 non-binding guides plus a checklist file, built to help companies implement and document compliance with the AI Act's high-risk requirements while the European Commission's own harmonized technical standards are still in development. AESIA states plainly that the guides carry no legal force and neither replace nor develop the applicable regulation. Spain's guides are designed to feed into the Commission's working group as it drafts the European versions — which makes them an early signal of where EU-wide guidance is heading, not just a national convenience.
Primary sources: the AESIA publication announcement of 16 December 2025 (English version) and the Ministry press release.
Who these guides are for
Guides 01–02 introduce the AI Act as a whole. They help anyone placing or using AI systems in the EU understand scope, risk classifications, and actor roles, whatever the system's classification.
Guides 03–15 and the checklists address Chapter III obligations, which bind high-risk AI systems only. Classification is the gate for that block, and your role decides which of those guides matter most.
| Your role | What it means | Which guides matter most |
|---|---|---|
| Provider | You develop an AI system and place it on the market under your own name or trademark — including systems you build in-house and deploy internally | All 16. Guides 03, 04, 15 and the checklists are non-negotiable |
| Deployer | You use an AI system under your own authority in a professional context (e.g. you licence a CV-screening tool and use it to hire) | 01, 02, 06 (human oversight), 08 (transparency), 12 (record-keeping), 14 (incidents) |
| Importer / Distributor | You place a third-country or third-party AI system on the EU market | 01, 02, 03 (conformity assessment), 15 (technical documentation) |
| Product manufacturer | Your regulated product (medical device, machinery) embeds an AI system | All technical guides, integrated with your existing CE-marking process |
Inside the company, the guides split cleanly across functions. Compliance and legal own guides 01–03. Engineering and product own 05, 06, 09, 10, 15. Data teams own 07 and 12. Security owns 11. Quality and operations own 04, 13, 14. If nobody in your organisation currently owns guide 13 (post-market monitoring), that gap is itself a finding.
A note for SMEs: the guides were written with SMEs and start-ups explicitly in mind. Reducing regulatory burden for smaller companies was a stated objective of the sandbox programme that produced them. You don't need a dedicated compliance department to use them — you need someone to run the checklists.
Where these guides came from: Spain's AI Regulatory Sandbox
The guides aren't a desk exercise. They're the documented output of Spain's AI Regulatory Sandbox, a controlled testing environment established under Real Decreto 817/2023 (published in the BOE on 9 November 2023) and launched in April 2025 by SEDIA through its Dirección General de Inteligencia Artificial, with AESIA supporting as market-surveillance authority.
The programme drew 44 applications from AI providers before the January 2025 deadline. Twelve high-risk AI systems from Spanish companies were selected, spanning six sectors: essential services, biometrics, employment, critical infrastructure, machinery, and medical devices. Participants ran simulated conformity assessments and tested both governance requirements (risk management, data traceability, human oversight) and technical performance requirements (robustness, sensitivity, demographic bias, error rates) against the AI Act's actual text. The programme's own documentation is published on the sandbox programme hub and its results page.
That distinction matters when you read the guides. They were written by people who tried to satisfy each requirement on a real system and hit real obstacles — which is why they contain worked examples rather than restated regulation.
Guide by guide: what each one covers, who owns it, when to use it
The 16 guides fall into three blocks. Each card below maps a guide to the AI Act requirement it addresses, the internal owner, and the moment in your project when you should open it.
Block 1 — Introductory guides (01–02)
Start here regardless of your role. Together they answer "does this apply to me, and what does it demand?" Read both even if you conclude that your system is not high-risk, because they help you reach that conclusion defensibly.
Introduction to the AI Act
The AI Act's structure: risk tiers, actor roles (provider, deployer, importer, distributor), scope, and the logic behind the obligations.
Practical guide and examples for understanding the AI Act
The same material applied to worked examples: how classification decisions play out on concrete systems.
Block 2 — Technical guides (03–15)
Thirteen guides, one per requirement. These correspond to the AI Act's Chapter III obligations for high-risk systems.
Conformity assessment
The conformity assessment procedure: internal control vs. notified-body routes, what evidence an assessor expects, and the declaration of conformity plus CE marking.
Quality management system
The quality management system a provider must operate: documented procedures, responsibilities, change control, supplier management.
Risk management
The continuous risk management lifecycle: identifying foreseeable risks to health, safety and fundamental rights, evaluating them, mitigating, and re-testing across the system's life.
Human oversight
Designing meaningful human oversight: what the human reviewer can actually see, how they can intervene or halt the system, and guarding against automation bias.
Data and data governance
Training, validation and testing datasets: relevance, representativeness, error handling, bias examination, provenance, and traceability.
Transparency
Instructions for use, what deployers must be told about capabilities, limitations and accuracy, and disclosure to affected people.
Accuracy
Declaring and measuring accuracy: choosing appropriate metrics, defining the operating envelope, and stating accuracy levels in the instructions for use.
Robustness
Resilience to errors, faults, inconsistencies and edge cases; behaviour under drift; redundancy and fail-safe design.
Cybersecurity
AI-specific threats: data poisoning, model poisoning, adversarial examples, model extraction and evasion — beyond conventional application security.
Logging
Automatic event logging: what to record, retention periods, and traceability sufficient to reconstruct how a decision was produced.
Post-market monitoring
The post-market monitoring plan: systematically collecting and analysing performance data once the system is live.
Incident management
Identifying serious incidents and malfunctions, internal escalation, and reporting to market-surveillance authorities.
Technical documentation
The complete technical file: system description, design choices, architecture, data, performance, risk management, and lifecycle changes.
Block 3 — Checklists (16 + ZIP)
Requirements checklist manual
How to apply the checklists: interpreting items, evidencing responses, and structuring your self-assessment.
Checklists and examples
The full checklist compendium plus worked examples for each obligation.
The complete list, with direct download links
All guides are hosted as PDFs on AESIA's site, in Spanish. AESIA maintains a multilingual guides page (English, Catalan, Valencian, Galician, Basque), though the PDFs themselves are Spanish-language.
| # | Guide | Download |
|---|---|---|
| 01 | Guía introductoria al reglamento de IA | |
| 02 | Guía práctica y ejemplos para entender el Reglamento de IA | |
| 03 | Guía Evaluación de conformidad | |
| 04 | Guía del sistema de gestión de la calidad | |
| 05 | Guía de gestión de riesgos | |
| 06 | Guía Vigilancia humana | |
| 07 | Guía de datos y gobernanza de datos | |
| 08 | Guía Transparencia | |
| 09 | Guía de Precisión | |
| 10 | Guía Solidez | |
| 11 | Guía Ciberseguridad | |
| 12 | Guía de registros | |
| 13 | Guía Vigilancia poscomercialización | |
| 14 | Guía Gestión de Incidentes | |
| 15 | Guía Documentación Técnica | |
| 16 | Manual de checklist de guías de requisitos | |
| — | Checklists y ejemplos | ZIP |
When to use them: your compliance calendar just changed
The deadline most compliance calendars had circled — 2 August 2026 — no longer applies to high-risk systems. The EU's Digital Omnibus on AI, proposed by the Commission on 19 November 2025, was endorsed by the European Parliament on 16 June 2026 and given final approval by the Council on 29 June 2026. It defers high-risk obligations substantially:
Two implications. First, you have runway — roughly 16 additional months for standalone high-risk systems. Second, the underlying obligations did not change. The requirements in guides 03–15 are the same requirements; only the enforcement date moved. Companies that treat the deferral as permission to stop are the ones that will be rebuilding data lineage and logging architecture under time pressure in late 2027.
Use the guides now if any of these are true: you're designing an AI system that will plausibly be classified high-risk; you're procuring one and need to assess a vendor's documentation; you're in a sector where sectoral conformity assessment already applies (medical devices, machinery); or you sell to enterprise buyers who are already asking AI Act questions in their vendor due diligence.
How to work through the guides: a 6-step approach
Confirm scope. Read guides 01 and 02. Determine whether your system is high-risk under the AI Act, and which role you occupy — provider, deployer, importer, distributor. Write the classification decision down with its reasoning; you will be asked to justify it.
Assign owners before reading further. Map each technical guide (03–15) to a named person using the ownership lines above. Guides without an owner become gaps by default.
Run a gap assessment against the checklists. Download the ZIP compendium and guide 16, then work each obligation against what you have today. Don't read the thirteen technical guides cover to cover first — use the checklists to find your gaps, then read the specific guides where you're weak.
Fix the architecture-dependent gaps first. Logging (guide 12), data governance and provenance (guide 07), and human oversight design (guide 06) are the three that get exponentially more expensive to retrofit. Sequence them ahead of documentation work.
Build the technical file using guide 15 as your table of contents. Structure documentation the way a conformity assessment body expects to receive it, from the start. Every other guide produces an input to this file.
Set a review cadence tied to updates. Bookmark the AESIA guides page and re-check quarterly. AESIA updates PDFs in place, so a file you downloaded in January may already be superseded.
What's still missing, and when updates land
Three caveats before you build a compliance programme entirely on these guides.
They are non-binding. AESIA states they neither replace nor develop the applicable regulation. The European Commission's harmonized technical standards — which will carry formal weight in conformity assessment — remain in development. Spain's guides feed into that process rather than substituting for it.
They will change. AESIA has committed to periodic revision as European standards mature, and specifically stated the guides will be updated once the Digital Omnibus is approved. That approval landed in June 2026, so a revision pass is now expected. Check the source page rather than relying on a PDF you saved.
They are Spanish-language only. The PDFs have not been published in English. For international teams, guide 02's worked examples are the highest-value translation target.
Complete resource directory
AESIA
- Guides hub (ES) — canonical source, always check here first
- Guides hub (EN)
- AESIA homepage — mandate, mission, services
- Publication announcement, 16 Dec 2025 (English version)
- Divulgación sobre IA — explanatory material beyond the guides
- Recursos europeos — EU-level resources curated by AESIA
- Article 50 Code of Practice on AI-generated content transparency
- Contact AESIA
Spanish Government
European Union
- Regulation (EU) 2024/1689 — the AI Act, full text (available in all EU languages)
- Regulation (EU) 2026/1744 — Digital Omnibus on AI
Related reading
- EU AI Act: what businesses need to know and how to prepare
- AI-powered data & analytics — relevant to guides 07 and 12
Frequently asked questions
What is AESIA?
AESIA (Agencia Española de Supervisión de Inteligencia Artificial) is Spain's public authority for AI oversight. It supervises how public and private entities use AI in Spain, working to ensure compliance with applicable regulation and to protect privacy, equal treatment, and fundamental rights. It operates under SEDIA within the Ministerio para la Transformación Digital y de la Función Pública.
Are AESIA's 16 guides legally binding?
No. AESIA states explicitly that the guides are non-binding and neither replace nor develop the applicable AI Act text. They provide practical recommendations aligned with regulatory requirements while the European Commission finalises EU-wide harmonized standards.
Which companies need these guides?
Guides 01–02 help any organisation that places or uses AI systems in the EU understand the Regulation's scope and classification. Guides 03–15 and the checklists are for organisations that develop, market, or deploy high-risk AI systems under the EU AI Act. That includes providers, deployers, importers, distributors, and manufacturers embedding AI in regulated products — particularly in the six sectors tested in the Spanish sandbox: essential services, biometrics, employment, critical infrastructure, machinery, and medical devices.
Do the guides apply if my AI system isn't high-risk?
Guides 01–02 still apply and are worth 30 minutes to confirm and document your classification. Guides 03–15 are largely not your obligation set if your system is not high-risk, although several may support voluntary good practice. Guide 08 may also help with Article 50 transparency obligations that reach some non-high-risk systems, including chatbots and synthetic content. The set does not cover general-purpose AI model obligations under Chapter V; those follow a separate regime and Code of Practice.
Which guide should I read first?
Guide 01, then guide 02. They determine whether your system is high-risk, which is the classification decision every other obligation depends on. After that, jump straight to the checklist compendium rather than reading guides 03–15 sequentially.
What is the Spanish AI Regulatory Sandbox?
A controlled testing environment launched in April 2025 under Real Decreto 817/2023, run by SEDIA's Dirección General de Inteligencia Artificial with AESIA's market-surveillance support. Twelve high-risk AI systems from Spanish companies tested their compliance approach inside it; the 16 guides are the documented output.
When do high-risk AI obligations actually apply?
Following the Digital Omnibus on AI — endorsed by the European Parliament on 16 June 2026 and approved by the Council on 29 June 2026 — standalone high-risk systems under Annex III must comply by 2 December 2027, and AI embedded in regulated products under Annex I by 2 August 2028. Prohibited practices and general-purpose AI model obligations already apply.
Will AESIA update the guides?
Yes. AESIA has confirmed the documents undergo ongoing evaluation and periodic revision, and stated they will be updated once the Digital Omnibus is approved. That approval came in June 2026, so expect revisions — always download from the source page rather than reusing a saved PDF.
Are the guides available in English?
The AESIA guides page exists in English, Catalan, Valencian, Galician and Basque, but the guide PDFs themselves are published in Spanish.
Turn 761 pages into a compliance plan
Reading the guides is one thing; mapping them against your actual AI system, closing the architecture gaps, and shipping the technical file is another. Start with a free 30-minute AI discovery session. We identify your highest-value automation opportunity and explain exactly how Liorant can help — no slides, no pitch.
Book your session