The Council of Ministers has approved today the bill for an ethical, inclusive, and beneficial use of artificial intelligence (AI), which aims to bring order to the practical application of these technologies and tools. The regulation adapts to our legislation what is established in the European Artificial Intelligence Regulation, agreed upon by the community institutions on December 8, 2023, and approved by the European Parliament on March 13 of last year, from a “humanist and guarantor” perspective, according to the spokesperson minister, Elma Saiz.
Read more Iran accuses the US of violating the truce by attacking military targets and threatens to respond
“It is a debate that affects the present and the future of everything,” assured later the Minister of Digital Transformation, Óscar López. “That is why a vision like the one the Pope conveyed yesterday is very much appreciated,” López said referring to the first encyclical of Leo XVI. “A vision that protects human rights, with which we feel fully identified,” the minister assured when presenting this law, in contrast to “the great technolords,” who are “against regulation, data protection, and the protection of minors.”
This organic law establishes responsibility for AI providers and the obligation of human supervision of the models, “something that is at the heart of all debates,” according to the minister. Transparency of algorithms, responsibility of executives, and protection of minors, López insisted, are core issues of this regulation. “It is a civilizational debate, to advance or retreat,” the minister insisted. “When we talk about a trustworthy AI model that protects citizens’ rights, we are the most advanced country in the world,” López assured before listing the Government’s initiatives in this field.
On the way to Rome and the meeting with the Pope, a shared conviction: either we put progress at the service of people, or the future will be the condemnation of entire generations.
The encyclical ‘Magnifica Humanitas’ of Leo XIV challenges us all. AI is not neutral, and power…
— Pedro Sánchez (@sanchezcastejon) May 26, 2026
The text of the law incorporates into the Spanish legal system the sanctions for non-compliance provided for in the European Regulation, which range from 6,000 euros in minor cases to 35 million and/or between 5% and 7% of global turnover in serious cases. One of the novelties of the law, which was not initially foreseen in the European regulation, is the prohibition of sexual deepfakes, or hyperrealistic videos. The EU agreed this month to introduce this amendment, proposed by Spain, in the simplified text of the digital regulation on which Brussels is working. Non-sexual deepfakes will remain legal but must be marked “clearly and distinguishably at the latest on the occasion of the first interaction or exposure,” according to the European regulation.
How exactly should this labeling be done? The Ministry has not yet specified. It will be the Spanish Artificial Intelligence Supervisory Agency (Aesia) that will set the rules in this regard. Who will control compliance? The management and processing of biometric data will be the responsibility of the Spanish Data Protection Agency (AEPD), although AI systems that may affect democracy will be under the jurisdiction of the Central Electoral Board and those that may impact the administration of justice, under the General Council of the Judiciary.
The rest of the cases will be studied by Aesia. Based in A Coruña, the agency is led by Alberto Gago and plans to have 50 analysts before the end of the year, who will have to review the compliance of different AI applications with the regulation. So far, Aesia has not found any system classified as prohibited operating in Spain.
The bill, which reaches the Council of Ministers one year after the draft was presented and after undergoing a period of allegations and public information, must now begin its parliamentary processing. The goal is for it to obtain final approval before August 2 of this year, the date on which most of the provisions of the European AI Regulation will come into force.
Adaptation of the European framework
The European AI Regulation, considered the most advanced in the world on this matter, classifies the different AI applications based on the risk their use implies and establishes different requirements and obligations. These range from unrestricted use (for example, a spam filter or a content recommender) to total prohibition. These more serious cases refer to those applications “that transcend a person’s consciousness or deliberately manipulative techniques,” those that exploit their vulnerabilities, or those that infer emotions, race, or political opinions of people.
Between both extremes are the so-called “high-risk” technologies, subject to permanent supervision. These are the ones monitored by Aesia. Included in this category are remote biometric identification systems, biometric categorization systems, or emotion recognition. Also, systems that affect the security of critical infrastructures and those related to education (behavior evaluation, admission systems, and exams), employment (personnel selection), and the provision of essential public services, law enforcement, or migration management.
The Regulation also establishes that periodic reports must be made to update this classification, so that when new applications not contemplated in the document arise, it is determined in which category they fall (unrestricted use, use subject to restrictions, or prohibition).
The same happened, for example, with generative AI, the technology behind tools like ChatGPT: its emergence occurred when the regulation negotiation was already very advanced. It was discussed whether to make specific mention of it or not. Finally, it was included and it was established that the so-called foundational models will have to meet transparency criteria, such as specifying if a text, a song, or a photograph has been generated through AI, as well as ensuring that the data used to train the systems respect copyright.
One of the most criticized aspects of the law during the consultation phase is the fact that the sanctioning regime provided does not affect the Administration. The regulation leaves it to the discretion of each Member State to establish what type of sanctions apply in that case. In Spain, the law approved today only foresees “warnings,” “reprimands,” and “disciplinary actions.” That is, misuse by the Administration of a prohibited technology, such as real-time remote biometric identification systems, would only entail a warning, compared to fines of up to 35 million euros that would be imposed on a private company.