RegTech
EU AI Act 2026: How to Comply if You're an SME in Spain
The EU Artificial Intelligence Act has been in force since 2024 and its full application arrives in August 2026. If you are a Spanish SME that uses chatbots, AI tools for HR, or any automated decision system, you need to know exactly which risk category applies to you and what you must do. Most SMEs fall under limited or minimal risk. But getting it wrong can be very expensive.
EU AI ACT (Regulation EU 2024/1689): The world's first comprehensive regulatory framework for artificial intelligence systems. Published in the Official Journal of the EU on 12 July 2024. It classifies all AI systems into four risk levels: unacceptable (banned), high risk, limited risk, and minimal risk. The supervisory body in Spain is the AESIA (Agencia Española de Supervisión de la Inteligencia Artificial).
€35M or 7% of global turnover
«The maximum EU AI Act fine for using prohibited AI systems (Art. 5 + Art. 99). For non-compliant high-risk systems: €15M or 3%. For providing false information to supervisors: €7.5M or 1.5% of global annual turnover.»
— Regulation (EU) 2024/1689, Art. 99
What are the four AI Act risk categories and when do they apply?
| Category | Examples | Application date | Obligations |
|---|---|---|---|
| Unacceptable (banned) | Citizen social scoring, real-time facial recognition in public spaces, subliminal manipulation, exploitation of vulnerabilities | August 2025 | Absolute prohibition. Fine up to €35M or 7% global turnover |
| High risk | AI in HR (recruitment, employee evaluation), credit scoring, education, critical infrastructure, biometric systems | August 2026 | Technical documentation, CE marking, human oversight, EU AI DB registration, conformity assessment |
| Limited risk | Customer service chatbots, deepfakes, emotion recognition in consumer products | August 2026 | Transparency only: inform the user they are interacting with AI |
| Minimal risk | Spam filters, content recommenders, AI-powered video games, spell checkers | — | No specific obligations. Voluntary code of good practice |
How do I know which category my company's AI system falls into?
The classification depends on what the AI is used for, not which technology it uses. The same ChatGPT API can be minimal risk (drafting commercial emails) or high risk (screening job candidates). What matters is the use case and its potential impact on people's rights and interests.
Customer service chatbot (FAQ, support): Limited risk. Your only obligation is to inform the user they are talking to an AI. If you already say «I am the virtual assistant of X», you comply. IgeraFincas, for example, identifies itself as AI at the start of every conversation, automatically satisfying Art. 50 of the AI Act.
Spam filters or content recommenders: Minimal risk. No specific AI Act obligations. GDPR may apply if personal data is involved.
AI for HR (CV screening, candidate ranking, performance evaluation): High risk. This is what surprises most SMEs. If you use Workday, HireVue, or any AI tool that evaluates candidates or employees, you are a «deployer» of a high-risk system. You must verify that the provider holds the required technical documentation and CE marking, and maintain usage logs.
AI for credit scoring or financial assessment: High risk. If your system evaluates customer creditworthiness or automatically decides on loans, all high-risk requirements apply: mandatory human oversight, decision explainability, audit logs.
What must SMEs with a customer service chatbot do by August 2026?
- Verify the risk category: Determine exactly what each AI system is used for. Does the chatbot make decisions affecting people's rights (access to essential services, credit, employment)? If it is only an FAQ bot, it is limited risk.
- Add AI identification: The most basic obligation under Art. 50: «Hello, I am the virtual assistant of X.» If you already do this, you comply. IgeraLegal can help you verify that your identification text meets the regulator's standard.
- Verify your LLM provider: If you use OpenAI, Google, or Anthropic's API, the provider is responsible for the base model's compliance (GPAI). You are a «deployer» and your responsibility is limited to your specific use case implementation.
- Create an AI systems inventory: Document all systems your company uses or develops that could qualify as AI under the AI Act (Art. 3). This includes any system that processes data to make or recommend decisions automatically.
- HR systems with AI: If you use AI for CV screening, candidate ranking, or performance evaluation, you are a deployer of a high-risk system. Verify your provider has CE marking and request their technical documentation.
How does the AI Act affect AI providers for property managers?
IgeraFincas, as an AI provider for property management offices, operates in the limited risk category: it is a chatbot that answers owner questions about bylaws and regulations. It does not make binding decisions on people's rights, does not evaluate job candidates, and does not manage credit.
AI Act obligations that IgeraFincas fulfils by design include: automatic AI identification at the start of each conversation (Art. 50), option to escalate to a human when requested, complete log of decisions and conversations for audit, and a transparent privacy policy in compliance with GDPR. Property managers who use IgeraFincas are «deployers» of a limited-risk system, with minimal obligations.
Need to classify your company's AI systems?
IgeraLegal helps SMEs inventory their AI systems, classify them by risk level, and document applicable obligations under the AI Act 2024/1689. Try it free for 14 days.
Try IgeraFincas freeFrequently asked questions about the EU AI Act for SMEs
Does the AI Act apply to SMEs or only large companies?
The AI Act applies to all companies operating in the EU, regardless of size. However, the Regulation includes specific provisions for SMEs and startups: access to regulatory sandboxes, technical support from national authorities, and simplified documentation for low-risk systems.
Does using ChatGPT to draft emails require AI Act compliance?
Not directly. Using ChatGPT as an assistance tool for drafting is minimal risk. You have no specific AI Act obligations. OpenAI, as the provider of the general-purpose model (GPAI), has its own obligations with the regulator. You are an end user, not a deployer or developer.
What is the AESIA and what role does it play?
The AESIA (Agencia Española de Supervisión de la Inteligencia Artificial) is the national body designated to supervise AI Act compliance in Spain. It can impose sanctions, conduct audits, and handle complaints related to AI systems operating on Spanish territory.
What is the EU AI Database and who must register?
The EU AI Database is mandatory for providers and deployers of high-risk AI systems. SMEs that only use customer service chatbots (limited risk) have no obligation to register in this database.
What if my HR software provider does not have CE marking?
As a deployer, you have an obligation to verify that the high-risk systems you use have the required conformity documentation. If your provider cannot demonstrate AI Act compliance, you must stop using that tool for high-risk functions or risk joint sanctions.
Does IgeraLegal help with AI Act compliance?
Yes. IgeraLegal includes an AI Act compliance module that helps companies classify their AI systems, identify applicable obligations, and generate the basic documentation required for limited-risk and high-risk systems. Available from the Professional plan.
Updated: June 2026 · Sources: Regulation (EU) 2024/1689; AESIA; European Commission · Author: IgeraSolutions Team · Specialised consultation: IgeraFincas