Spain has approved the draft Organic Law for the good use and governance of artificial intelligence. The standard adapts the legislation to framework established by the European Union with the AI law and establishes a series of obligations and prohibitions based on the risk classification of these systems. The regulations impose mandatory human supervision in high-risk systems and extend responsibility beyond the company that deploys these systems, also reaching those who use them.
Sanctions. In mild cases, penalties range from 6,000 euros, such as not cooperating with the authorities, to 500,000 euros or 0.5% of the total turnover. In more serious cases, turnover shoots up to 35 million or, failing that, 7% of global turnover in very serious cases. Fines of 15 million or 3% of turnover are also proposed when high-risk systems are used without human supervision.
The double standard. The controversy arises because these fines are not applied when it is the administration that fails to comply with the rule. If, for example, the police or a ministry uses an AI system classified as prohibited, the law contemplates reprimands and disciplinary actions, but no fines. The Government defends that it has “raised the bar for self-demand” with transparency measures, among which is the creation of a public inventory of all AI systems used in administrative procedures. It also introduces the figure of the AI delegate who will be in charge of coordinating its use.
Deepfakes. The creation of deepfakes of a sexual nature and also the creation of child pornography with AI tools is prohibited. Deepfakes that do not fall into these categories (for example of a politician or a public figure) are not prohibited, but must be labeled as AI in a “clear and distinguishable” way from the time they are first shared.
AI content tagging. The ministry establishes that videos and images must have a watermark in a corner of the image in which the acronym AI is clearly read. For audio generated with AI, that same seal must appear in the corresponding application, whether it is Spotify, Apple Music or another service. If you do not choose this label, it will be the audio itself that must incorporate a warning that it is generated with AI. The date to begin applying this labeling is August 2 of this year.
Who will be in charge of controlling it. Supervision will fall mainly on AESIA, the Spanish AI Supervision Agency, but will be supported by other authorities such as the Spanish Data Protection Agency for biometric data, the General Council of the Judiciary for the judicial field and the Bank of Spain for everything related to the financial system. According to The CountryAESIA plans to hire 50 analysts before the end of the year to carry out this task.
When it comes into effect. The law is intended to come into force before the end of 2027, but the obligation to label data with AI will come into force on August 2. However, as the law is not yet applied, in practice it means that for more than a year there will be obligations in place, but with no real ability to impose fines on companies that fail to comply.
Image | Moncloa

GIPHY App Key not set. Please check settings