AI governance, security & compliance

AESIA's 16 Guides to Help Businesses Follow the EU AI Act in Spain

Reference resource Original sources published by AESIA on December 2025 Article by Ricardo Mendoza Castro Last reviewed August 2026

Spain's AI supervisory authority, AESIA, published 16 practical guides to help providers and deployers understand and follow the EU AI Act's requirements in Spain. This article explains what each guide covers, who should own the work, when to use it, and where to download the official documents.

At a glance
The 16 AESIA guides, in three blocks
16
Guides + 1 checklist compendium
761
Pages of compliance guidance
12
High-risk systems tested in the sandbox
2 Dec 2027
New deadline for Annex III high-risk systems
Introductory · 01–02
Does the AI Act apply to you, and in which role?
01Introduction 02Worked examples
Technical · 03–15
One guide per Chapter III requirement for high-risk systems.
03Conformity 04Quality 05Risk 06Oversight 07Data 08Transparency 09Accuracy 10Robustness 11Security 12Logging 13Post-market 14Incidents 15Documentation
Checklists · 16 + ZIP
Turns thirteen technical guides into one sign-off document.
16Checklist manual +Checklists & examples (ZIP)
Free · Spanish-language · Non-binding · Updated periodically by AESIA Official source: aesia.digital.gob.es/es/guias

Short answer: guides 01–02 explain the AI Act, guides 03–15 each cover one technical requirement, and guide 16 plus the ZIP file turn all of it into checklists you can actually sign off. All are free, in Spanish, non-binding, and hosted at aesia.digital.gob.es/es/guias.

What AESIA published, and what AESIA is

AESIA is Spain's public authority for AI oversight. Its remit: ensure public and private entities comply with applicable AI regulation, protecting privacy, equal treatment, and fundamental rights. It sits under the Secretaría de Estado de Digitalización e Inteligencia Artificial (SEDIA) within the Ministerio para la Transformación Digital y de la Función Pública, and it acts as a national market-surveillance authority for AI systems. Its temporary headquarters is in A Coruña.

What it released is a set of 16 non-binding guides plus a checklist file, built to help companies implement and document compliance with the AI Act's high-risk requirements while the European Commission's own harmonized technical standards are still in development. AESIA states plainly that the guides carry no legal force and neither replace nor develop the applicable regulation. Spain's guides are designed to feed into the Commission's working group as it drafts the European versions — which makes them an early signal of where EU-wide guidance is heading, not just a national convenience.

Primary sources: the AESIA publication announcement of 16 December 2025 (English version) and the Ministry press release.

Who these guides are for

Guides 01–02 introduce the AI Act as a whole. They help anyone placing or using AI systems in the EU understand scope, risk classifications, and actor roles, whatever the system's classification.

Guides 03–15 and the checklists address Chapter III obligations, which bind high-risk AI systems only. Classification is the gate for that block, and your role decides which of those guides matter most.

Your roleWhat it meansWhich guides matter most
ProviderYou develop an AI system and place it on the market under your own name or trademark — including systems you build in-house and deploy internallyAll 16. Guides 03, 04, 15 and the checklists are non-negotiable
DeployerYou use an AI system under your own authority in a professional context (e.g. you licence a CV-screening tool and use it to hire)01, 02, 06 (human oversight), 08 (transparency), 12 (record-keeping), 14 (incidents)
Importer / DistributorYou place a third-country or third-party AI system on the EU market01, 02, 03 (conformity assessment), 15 (technical documentation)
Product manufacturerYour regulated product (medical device, machinery) embeds an AI systemAll technical guides, integrated with your existing CE-marking process

Inside the company, the guides split cleanly across functions. Compliance and legal own guides 01–03. Engineering and product own 05, 06, 09, 10, 15. Data teams own 07 and 12. Security owns 11. Quality and operations own 04, 13, 14. If nobody in your organisation currently owns guide 13 (post-market monitoring), that gap is itself a finding.

A note for SMEs: the guides were written with SMEs and start-ups explicitly in mind. Reducing regulatory burden for smaller companies was a stated objective of the sandbox programme that produced them. You don't need a dedicated compliance department to use them — you need someone to run the checklists.

Where these guides came from: Spain's AI Regulatory Sandbox

The guides aren't a desk exercise. They're the documented output of Spain's AI Regulatory Sandbox, a controlled testing environment established under Real Decreto 817/2023 (published in the BOE on 9 November 2023) and launched in April 2025 by SEDIA through its Dirección General de Inteligencia Artificial, with AESIA supporting as market-surveillance authority.

The programme drew 44 applications from AI providers before the January 2025 deadline. Twelve high-risk AI systems from Spanish companies were selected, spanning six sectors: essential services, biometrics, employment, critical infrastructure, machinery, and medical devices. Participants ran simulated conformity assessments and tested both governance requirements (risk management, data traceability, human oversight) and technical performance requirements (robustness, sensitivity, demographic bias, error rates) against the AI Act's actual text. The programme's own documentation is published on the sandbox programme hub and its results page.

That distinction matters when you read the guides. They were written by people who tried to satisfy each requirement on a real system and hit real obstacles — which is why they contain worked examples rather than restated regulation.

Guide by guide: what each one covers, who owns it, when to use it

The 16 guides fall into three blocks. Each card below maps a guide to the AI Act requirement it addresses, the internal owner, and the moment in your project when you should open it.

Block 1 — Introductory guides (01–02)

Start here regardless of your role. Together they answer "does this apply to me, and what does it demand?" Read both even if you conclude that your system is not high-risk, because they help you reach that conclusion defensibly.

01GUIDE

Introduction to the AI Act

The AI Act's structure: risk tiers, actor roles (provider, deployer, importer, distributor), scope, and the logic behind the obligations.

OwnerCompliance, legal, exec sponsor
Use it whenBefore any AI project kicks off — this is the 30-minute read that tells you whether the other 14 guides apply
02GUIDE

Practical guide and examples for understanding the AI Act

The same material applied to worked examples: how classification decisions play out on concrete systems.

OwnerProduct owners, compliance
Use it whenYou're unsure whether your specific system counts as high-risk. Classification is the single most consequential judgement you'll make

Block 2 — Technical guides (03–15)

Thirteen guides, one per requirement. These correspond to the AI Act's Chapter III obligations for high-risk systems.

03GUIDE

Conformity assessment

The conformity assessment procedure: internal control vs. notified-body routes, what evidence an assessor expects, and the declaration of conformity plus CE marking.

OwnerCompliance lead + engineering lead
Use it whenEarly. It defines the finish line, and reading it last means rebuilding documentation you already wrote
04GUIDE

Quality management system

The quality management system a provider must operate: documented procedures, responsibilities, change control, supplier management.

OwnerQuality / operations
Use it whenFormalising process. If you hold ISO 9001 or ISO/IEC 42001, use this guide to map the delta rather than starting from zero
05GUIDE

Risk management

The continuous risk management lifecycle: identifying foreseeable risks to health, safety and fundamental rights, evaluating them, mitigating, and re-testing across the system's life.

OwnerProduct + engineering lead
Use it whenAt design stage, then continuously. This is a live file, not a launch document
06GUIDE

Human oversight

Designing meaningful human oversight: what the human reviewer can actually see, how they can intervene or halt the system, and guarding against automation bias.

OwnerProduct design + operations
Use it whenDesigning the interface and the escalation path. Retrofitting oversight into a shipped product is the expensive version
07GUIDE

Data and data governance

Training, validation and testing datasets: relevance, representativeness, error handling, bias examination, provenance, and traceability.

OwnerData lead / data engineering
Use it whenBefore training. Data provenance you didn't record at ingestion time usually can't be reconstructed later
08GUIDE

Transparency

Instructions for use, what deployers must be told about capabilities, limitations and accuracy, and disclosure to affected people.

OwnerProduct + technical writing
Use it whenDrafting user documentation. Also relevant if you fall under Article 50 obligations on AI-generated content
09GUIDE

Accuracy

Declaring and measuring accuracy: choosing appropriate metrics, defining the operating envelope, and stating accuracy levels in the instructions for use.

OwnerML / data science
Use it whenDuring model evaluation. Pairs directly with guide 10
10GUIDE

Robustness

Resilience to errors, faults, inconsistencies and edge cases; behaviour under drift; redundancy and fail-safe design.

OwnerML engineering + SRE
Use it whenDuring testing and pre-launch hardening
11GUIDE

Cybersecurity

AI-specific threats: data poisoning, model poisoning, adversarial examples, model extraction and evasion — beyond conventional application security.

OwnerSecurity team
Use it whenThreat modelling. Your existing appsec programme does not automatically cover these vectors
12GUIDE

Logging

Automatic event logging: what to record, retention periods, and traceability sufficient to reconstruct how a decision was produced.

OwnerData + platform engineering
Use it whenAt architecture stage. Logging you didn't design in is the hardest requirement to backfill
13GUIDE

Post-market monitoring

The post-market monitoring plan: systematically collecting and analysing performance data once the system is live.

OwnerOperations + product
Use it whenBefore launch — the plan is part of your documentation, not an afterthought
14GUIDE

Incident management

Identifying serious incidents and malfunctions, internal escalation, and reporting to market-surveillance authorities.

OwnerOperations + compliance
Use it whenSet up before launch, execute when something breaks. Reporting deadlines start when you become aware, not when you finish investigating
15GUIDE

Technical documentation

The complete technical file: system description, design choices, architecture, data, performance, risk management, and lifecycle changes.

OwnerEngineering lead + compliance
Use it whenContinuously, from day one. Treat this guide as the table of contents for everything the other guides produce

Block 3 — Checklists (16 + ZIP)

16GUIDE

Requirements checklist manual

How to apply the checklists: interpreting items, evidencing responses, and structuring your self-assessment.

OwnerCompliance lead
Use it whenOnce you've mapped your gaps — this converts thirteen technical guides into one working document
ZIP

Checklists and examples

The full checklist compendium plus worked examples for each obligation.

OwnerWhole team
Use it whenDuring your gap assessment and again before conformity assessment. This is the single most practical asset in the set

The complete list, with direct download links

All guides are hosted as PDFs on AESIA's site, in Spanish. AESIA maintains a multilingual guides page (English, Catalan, Valencian, Galician, Basque), though the PDFs themselves are Spanish-language.

#GuideDownload
01Guía introductoria al reglamento de IAPDF
02Guía práctica y ejemplos para entender el Reglamento de IAPDF
03Guía Evaluación de conformidadPDF
04Guía del sistema de gestión de la calidadPDF
05Guía de gestión de riesgosPDF
06Guía Vigilancia humanaPDF
07Guía de datos y gobernanza de datosPDF
08Guía TransparenciaPDF
09Guía de PrecisiónPDF
10Guía SolidezPDF
11Guía CiberseguridadPDF
12Guía de registrosPDF
13Guía Vigilancia poscomercializaciónPDF
14Guía Gestión de IncidentesPDF
15Guía Documentación TécnicaPDF
16Manual de checklist de guías de requisitosPDF
Checklists y ejemplosZIP

When to use them: your compliance calendar just changed

The deadline most compliance calendars had circled — 2 August 2026 — no longer applies to high-risk systems. The EU's Digital Omnibus on AI, proposed by the Commission on 19 November 2025, was endorsed by the European Parliament on 16 June 2026 and given final approval by the Council on 29 June 2026. It defers high-risk obligations substantially:

2 February 2025 · in force
Prohibited AI practices apply
2 August 2025 · in force
General-purpose AI model obligations apply
2 August 2026
High-risk obligations apply Superseded by the Digital Omnibus on AI
2 December 2027
High-risk obligations — Annex III (standalone systems)
2 August 2028
High-risk obligations — Annex I (AI embedded in regulated products)

Two implications. First, you have runway — roughly 16 additional months for standalone high-risk systems. Second, the underlying obligations did not change. The requirements in guides 03–15 are the same requirements; only the enforcement date moved. Companies that treat the deferral as permission to stop are the ones that will be rebuilding data lineage and logging architecture under time pressure in late 2027.

Use the guides now if any of these are true: you're designing an AI system that will plausibly be classified high-risk; you're procuring one and need to assess a vendor's documentation; you're in a sector where sectoral conformity assessment already applies (medical devices, machinery); or you sell to enterprise buyers who are already asking AI Act questions in their vendor due diligence.

See how Liorant delivers a working AI system in 4 weeks — talk to our team.

How to work through the guides: a 6-step approach

Confirm scope. Read guides 01 and 02. Determine whether your system is high-risk under the AI Act, and which role you occupy — provider, deployer, importer, distributor. Write the classification decision down with its reasoning; you will be asked to justify it.

Assign owners before reading further. Map each technical guide (03–15) to a named person using the ownership lines above. Guides without an owner become gaps by default.

Run a gap assessment against the checklists. Download the ZIP compendium and guide 16, then work each obligation against what you have today. Don't read the thirteen technical guides cover to cover first — use the checklists to find your gaps, then read the specific guides where you're weak.

Fix the architecture-dependent gaps first. Logging (guide 12), data governance and provenance (guide 07), and human oversight design (guide 06) are the three that get exponentially more expensive to retrofit. Sequence them ahead of documentation work.

Build the technical file using guide 15 as your table of contents. Structure documentation the way a conformity assessment body expects to receive it, from the start. Every other guide produces an input to this file.

Set a review cadence tied to updates. Bookmark the AESIA guides page and re-check quarterly. AESIA updates PDFs in place, so a file you downloaded in January may already be superseded.

What's still missing, and when updates land

Three caveats before you build a compliance programme entirely on these guides.

They are non-binding. AESIA states they neither replace nor develop the applicable regulation. The European Commission's harmonized technical standards — which will carry formal weight in conformity assessment — remain in development. Spain's guides feed into that process rather than substituting for it.

They will change. AESIA has committed to periodic revision as European standards mature, and specifically stated the guides will be updated once the Digital Omnibus is approved. That approval landed in June 2026, so a revision pass is now expected. Check the source page rather than relying on a PDF you saved.

They are Spanish-language only. The PDFs have not been published in English. For international teams, guide 02's worked examples are the highest-value translation target.

Complete resource directory

Frequently asked questions

What is AESIA?

AESIA (Agencia Española de Supervisión de Inteligencia Artificial) is Spain's public authority for AI oversight. It supervises how public and private entities use AI in Spain, working to ensure compliance with applicable regulation and to protect privacy, equal treatment, and fundamental rights. It operates under SEDIA within the Ministerio para la Transformación Digital y de la Función Pública.

Are AESIA's 16 guides legally binding?

No. AESIA states explicitly that the guides are non-binding and neither replace nor develop the applicable AI Act text. They provide practical recommendations aligned with regulatory requirements while the European Commission finalises EU-wide harmonized standards.

Which companies need these guides?

Guides 01–02 help any organisation that places or uses AI systems in the EU understand the Regulation's scope and classification. Guides 03–15 and the checklists are for organisations that develop, market, or deploy high-risk AI systems under the EU AI Act. That includes providers, deployers, importers, distributors, and manufacturers embedding AI in regulated products — particularly in the six sectors tested in the Spanish sandbox: essential services, biometrics, employment, critical infrastructure, machinery, and medical devices.

Do the guides apply if my AI system isn't high-risk?

Guides 01–02 still apply and are worth 30 minutes to confirm and document your classification. Guides 03–15 are largely not your obligation set if your system is not high-risk, although several may support voluntary good practice. Guide 08 may also help with Article 50 transparency obligations that reach some non-high-risk systems, including chatbots and synthetic content. The set does not cover general-purpose AI model obligations under Chapter V; those follow a separate regime and Code of Practice.

Which guide should I read first?

Guide 01, then guide 02. They determine whether your system is high-risk, which is the classification decision every other obligation depends on. After that, jump straight to the checklist compendium rather than reading guides 03–15 sequentially.

What is the Spanish AI Regulatory Sandbox?

A controlled testing environment launched in April 2025 under Real Decreto 817/2023, run by SEDIA's Dirección General de Inteligencia Artificial with AESIA's market-surveillance support. Twelve high-risk AI systems from Spanish companies tested their compliance approach inside it; the 16 guides are the documented output.

When do high-risk AI obligations actually apply?

Following the Digital Omnibus on AI — endorsed by the European Parliament on 16 June 2026 and approved by the Council on 29 June 2026 — standalone high-risk systems under Annex III must comply by 2 December 2027, and AI embedded in regulated products under Annex I by 2 August 2028. Prohibited practices and general-purpose AI model obligations already apply.

Will AESIA update the guides?

Yes. AESIA has confirmed the documents undergo ongoing evaluation and periodic revision, and stated they will be updated once the Digital Omnibus is approved. That approval came in June 2026, so expect revisions — always download from the source page rather than reusing a saved PDF.

Are the guides available in English?

The AESIA guides page exists in English, Catalan, Valencian, Galician and Basque, but the guide PDFs themselves are published in Spanish.

Turn 761 pages into a compliance plan

Reading the guides is one thing; mapping them against your actual AI system, closing the architecture gaps, and shipping the technical file is another. Start with a free 30-minute AI discovery session. We identify your highest-value automation opportunity and explain exactly how Liorant can help — no slides, no pitch.

Book your session