GPU Solutions

Regulatory radar · updated on 6 Oct 2026

Regulatory radar: what is changing in AI and data law in Spain and Europe

This radar tracks, with dates and official sources, the laws, guidance and deadlines that affect organisations using AI with sensitive data in Spain. The next major milestone is 2 December 2027, when the AI Act's high-risk obligations apply to credit scoring, insurance, justice and public services. We review it every two weeks and every entry links to the original document.

In short
  • The AI Omnibus (Regulation (EU) 2026/1744) moves Annex III high-risk obligations to 2 December 2027 and Annex I to 2 August 2028.
  • Spain has not yet transposed NIS2 and the Commission referred it to the CJEU in July 2026.
  • The European Health Data Space starts applying on 26 March 2027.
  • The Spanish Bar, the judiciary council and the AEPD already require human oversight, confidentiality and knowing where data is processed.

Upcoming deadlines

Dates worth keeping in your calendar

Deadlines and dates of application still to come.

  1. EuroHPC AI Gigafactories call closes (up to 7 consortia)

    EU · Deadline ↓
  2. Consumer Credit Directive (EU) 2023/2225 applies: explanation and human review in automated scoring

    EU · Deadline ↓
  3. European Health Data Space Regulation (EU) 2025/327 starts applying in phases

    EU · Deadline ↓
  4. AI Act high-risk obligations for Annex III systems start to apply

    EU · Deadline ↓

All entries

Recent laws, guidance and decisions

Filter by sector to see only what affects your organisation. Each entry shows whether it is a Spanish or EU rule, its status and the official source.

  1. EuroHPC AI Gigafactories call closes (up to 7 consortia)

    Awards are expected in early 2027. Spain is bidding with a public-private candidacy. It signals where European compute capacity for training and running models will be located.

    Official source: EuroHPC ↗

    DeadlinePublic sector · EU
  2. Consumer Credit Directive (EU) 2023/2225 applies: explanation and human review in automated scoring

    When creditworthiness is assessed by automated processing, consumers can ask for a clear explanation, human intervention and a review of the decision. Models must be explainable case by case.

    Official source: EUR-Lex · Directiva (UE) 2023/2225 ↗

    DeadlineBanking and insurance · EU
  3. European Health Data Space Regulation (EU) 2025/327 starts applying in phases

    Obligations arrive in 2027, 2029 and 2031: patient access to their data, requirements for electronic health record systems and secondary use of health data inside secure processing environments.

    Official source: EUR-Lex · Reglamento (UE) 2025/327 ↗

    DeadlineHealthcare · EU
  4. AI Act high-risk obligations for Annex III systems start to apply

    Covers credit scoring, life and health insurance pricing, justice, essential public services and employment. Requires risk management, data quality, logging, human oversight and technical documentation.

    Official source: EUR-Lex · Reglamento (UE) 2026/1744 ↗

    DeadlineEU
  5. First EHDS implementing regulation on MyHealth@EU (Implementing Regulation (EU) 2026/2083)

    Sets technical rules for cross-border exchange of health data between Member States and applies from 26 March 2027. It is the first concrete implementing act under the EHDS Regulation.

    Official source: EUR-Lex · Reglamento de Ejecución (UE) 2026/2083 ↗

    In forceHealthcare · EU
  6. Data Act Art. 3(1): connected products must make their data accessible by design

    Applies to connected products placed on the market from this date. Manufacturers must design them so users can access the data they generate, which shapes architecture, contracts and industrial analytics.

    Official source: EUR-Lex · Reglamento (UE) 2023/2854 ↗

    ApplicableIndustry and intellectual property · EU
  7. Cyber Resilience Act: manufacturers notify ENISA and CSIRT within 24 h of exploited vulnerabilities

    Manufacturers of products with digital elements must report actively exploited vulnerabilities and severe incidents. This includes software with AI components placed on the EU market.

    Official source: EUR-Lex · Reglamento (UE) 2024/2847 ↗

    ApplicableIndustry and intellectual property · EU
  8. Comunidad de Madrid begins deploying its sovereign AI cloud in Alcalá de Henares

    The stated goal is to strengthen data protection and speed up AI use in the regional administration. It confirms the public-sector trend towards infrastructure under its own control.

    Official source: Comunidad de Madrid ↗

    OngoingPublic sector · Spain
  9. AI Omnibus Regulation (EU) 2026/1744 published: new timetable for high-risk AI

    In force since 27 July 2026. Annex III obligations move to 2 December 2027 and Annex I obligations (AI in regulated products such as medical devices) to 2 August 2028.

    Official source: EUR-Lex · Reglamento (UE) 2026/1744 ↗

    In forceEU
  10. Commission refers Spain to the CJEU for failing to transpose NIS2

    A lump sum and daily penalties are requested. Until the Spanish law arrives, essential and important entities are well advised to prepare risk management, incident reporting and supplier control now.

    Official source: Comisión Europea ↗

    OngoingEU
  11. CCN-CERT BP/36: good practices against offensive AI

    Recommends asset inventory, patching prioritised by exploitability, phishing-resistant authentication and governance of AI agents. A practical reference for bodies subject to the ENS.

    Official source: CCN-CERT ↗

    PublishedPublic sector · Spain
  12. Spain's draft Organic Law on good use and governance of AI published in the parliamentary gazette

    It sets out Spain's sanctions regime and the role of AESIA as supervisory authority. It is still in the amendment phase in Congress, so the final text may change.

    Official source: Congreso de los Diputados ↗

    ProposalSpain
  13. Commission proposes the Cloud and AI Development Act (CADA)

    It proposes a framework to assess the sovereignty of cloud and AI services and to encourage their adoption by the public sector. If adopted, it will shape how providers are assessed in tenders.

    Official source: Comisión Europea ↗

    ProposalEU
  14. Royal Decree 415/2026 on health technology assessment in Spain's national health system

    In force since 18 June 2026. It organises health technology assessment, accepts real-world data and covers digital therapies, which matters to anyone building clinical software with AI.

    Official source: BOE-A-2026-11587 ↗

    In forceHealthcare · Spain
  15. Commission consults on draft guidelines for classifying high-risk AI systems

    The guidelines will use examples to clarify which use cases fall under the high-risk regime. The final version is expected at the end of 2026 and will help organisations review their AI system inventory.

    Official source: Comisión Europea ↗

    ProposalPublic sector · EU
  16. CGAE Circular 3/2026: briefs drafted with generative AI are lawful if the signer verifies them

    The signing lawyer must check the output and preserve professional secrecy and data protection. In practice, it matters where client documents are processed and who can access them.

    Official source: Consejo General de la Abogacía ↗

    In forceLegal · Spain
  17. Spain's data protection authority (AEPD) publishes guidance on agentic AI

    It proposes a rule of 2: an agent should not at the same time receive uncontrolled input, access sensitive data and take real-world actions. Useful for designing agent permissions and isolation.

    Official source: AEPD ↗

    PublishedSpain
  18. CGPJ Instruction 2/2026: judges may only use AI tools provided by the Administration

    It requires human control of every output and bans entering case data into non-official AI systems. It sets the confidentiality standard expected around the judiciary.

    Official source: BOE-A-2026-2205 ↗

    In forceLegal · Public sector · Spain
  19. CGAE White Paper on artificial intelligence and the legal profession

    It covers confidentiality, supervision of outputs and choice of providers. It recommends knowing where client data is processed, and under which contract terms, before adopting a tool.

    Official source: Consejo General de la Abogacía ↗

    PublishedLegal · Spain
  20. Spanish Government launches the National Health Data Space

    An interoperable network of regional platforms for secondary use of health data, backed by 70 million euros. It prepares research and AI models on clinical data inside controlled environments.

    Official source: La Moncloa ↗

    OngoingHealthcare · Spain
  21. EBA finds no contradictions between the AI Act and banking rules

    The AI Act complements CRR/CRD, DORA and EBA guidelines on credit scoring. Banks can build on their existing model governance and ICT risk frameworks to comply.

    Official source: EBA ↗

    PublishedBanking and insurance · EU
  22. ESAs designate the first 19 critical ICT third-party providers under DORA

    Most are large cloud platforms, now under direct EU oversight. Financial entities remain responsible for managing concentration risk and exit strategies.

    Official source: EBA · ESAs ↗

    PublishedBanking and insurance · EU
  23. The Data Act (Regulation (EU) 2023/2854) starts to apply

    It governs data access and portability, makes switching cloud providers easier and limits transfers of non-personal data outside the EU. It strengthens the ability to leave a provider.

    Official source: EUR-Lex · Reglamento (UE) 2023/2854 ↗

    ApplicableEU
  24. EIOPA opinion on AI governance and risk management for insurers

    It applies Solvency II, IDD, DORA and GDPR to AI use with an approach proportional to each use case's risk: data governance, documentation, explainability and human oversight.

    Official source: EIOPA ↗

    PublishedBanking and insurance · EU
  25. MDCG 2025-6 / AIB 2025-1: AI medical software must meet both the AI Act and MDR/IVDR

    AI medical software that needs a notified body is high-risk and must meet both frameworks. The guidance explains how to combine the documentation into a single conformity assessment.

    Official source: Comisión Europea · MDCG ↗

    PublishedHealthcare · EU

How we build this radar

We include laws, supervisory guidance, court decisions and calls that change what an organisation can or must do when it uses AI with personal, clinical, financial or confidential data. We leave out opinions, rumours and announcements without a published text.

We only cite official sources: the EU Official Journal (EUR-Lex), Spain's Official Gazette (BOE), the parliamentary gazette, the European Commission, supervisory authorities (AEPD, EBA, EIOPA, CCN-CERT) and professional bodies. We review the radar every two weeks; each entry carries the date of the event and a link to the original document so you can check it.

It is a regulatory monitoring tool for technical, compliance and management teams. For decisions on your specific case, rely on your legal advisers: we help with the infrastructure side, meaning where data is processed, who can access it and how it is documented.

Glossary

AI Act
Regulation (EU) 2024/1689, which classifies AI systems by risk and sets obligations for providers and deployers. Prohibited practices apply since February 2025 and high-risk obligations arrive in phases.
AI Omnibus
Regulation (EU) 2026/1744, which amends the AI Act timetable. It moves Annex III high-risk obligations to 2 December 2027 and Annex I obligations to 2 August 2028.
NIS2
Directive (EU) 2022/2555 on cybersecurity for essential and important entities in sectors such as energy, health, banking and public administration. It requires risk management, incident reporting and supply chain control.
DORA
Regulation (EU) 2022/2554 on digital operational resilience in the financial sector, applicable since 17 January 2025. It requires firms to manage ICT risk, including risk from cloud and AI providers.
ENS
Spain's National Security Framework (Royal Decree 311/2022), mandatory for the Spanish public sector and for providers that handle its systems. It has three categories, Basic, Medium and High, based on the impact of an incident.
EHDS
European Health Data Space, created by Regulation (EU) 2025/327. It governs patient access to their data and the secondary use of health data for research and innovation.
Data Act
Regulation (EU) 2023/2854 on fair access to and use of data, applicable since 12 September 2025. It makes switching cloud providers easier and opens access to data from connected products.
Cyber Resilience Act
Regulation (EU) 2024/2847 setting cybersecurity requirements for products with digital elements. Its reporting obligations apply since 11 September 2026.
GDPR
General Data Protection Regulation (EU) 2016/679, which governs any processing of personal data. Health data is a special category and needs a stronger legal basis.

Frequently asked questions

When does the AI Act high-risk regime apply?

On 2 December 2027 for Annex III systems (credit scoring, life and health insurance, justice, essential public services, employment) and on 2 August 2028 for AI built into Annex I regulated products such as medical devices. These dates come from the AI Omnibus, Regulation (EU) 2026/1744.

Does NIS2 apply in Spain today?

Not yet through a Spanish law: Spain had not transposed NIS2 when the Commission referred it to the CJEU on 8 July 2026. Meanwhile the ENS already binds the public sector and its providers, and DORA binds financial entities, so preparing risk management and incident reporting now is time well spent.

What does the ENS require of an AI provider?

That the service is certified at the ENS category matching the public body's system (Basic, Medium or High), with access control, activity logging, encryption and continuity. Our platform holds ENS Medium certification issued by EQA and our Tier III datacenter in Madrid holds ENS High; see ENS and AI and public sector.

How does DORA affect AI in banks?

DORA treats third-party AI and cloud services as ICT risk: they must be registered, assessed, covered by audit and exit clauses, and monitored for concentration on a few providers. See banking and insurance.

Can I use AI with health data in Spain?

Yes, with a valid GDPR legal basis for special categories, data minimisation and a controlled processing environment, ideally with data processed in Spain and never reused to train third-party models. The EHDS adds secondary-use rules from 2027; we explain it in healthcare.

How often is this radar updated?

Every two weeks, and sooner when a relevant rule is published. The date of the last review appears at the top and every entry links to its official source.

Compliance starts in the infrastructure

Talk to an engineer about compliance-ready AI infrastructure: data in Spain, ENS and GDPR by design.

Talk to an engineer →