The general entry into force of Regulation (EU) 2024/1689 of the European Parliament and Council, on the 13th of June 2024, establishing harmonised regulations regarding artificial intelligence, marks a transformation of the European regulatory framework governing technology and the protection of fundamental rights. Far from being a sector-specific regulation aimed exclusively at technology developers, this legislation introduces obligations that affect any organisation that designs, commercialises or simply uses artificial intelligence systems in its operations, from recruitment to customer service or the creation of corporate content.

The 2nd of August 2026 marked the date on which these obligations became fully enforceable, and with that, the national supervisory authorities in Spain – the Spanish Agency for the Supervision of Artificial Intelligence (AESIA) – were authorised to carry out inspections and to impose sanctions.

In this context, companies must understand that regulatory compliance in relation to AI can no longer be approached as an exclusively technological issue, but rather as a strategic factor that directly influences legal risk management, contractual relationships with suppliers and corporate reputation.

The Regulation

As with other recent methods designed to bring about the harmonisation of European frameworks, the Regulation of AI is directly applicable in all Member States, without the need for transposition. Unlike other regulations, this legislation is not structured around a physical object, but rather around a risk-based approach: the extent of the obligations does not depend on the sector in which the company operates, but on the specific function that each system performs in relation to the individuals affected by its use.

Who does this apply to?

The scope of the Regulation is remarkably broad, and it is not limited to the suppliers who develop artificial intelligence systems. It also covers those responsible for its deployment, that is, any company that uses said systems under its own authority, as well as importer, distributors and, of particular relevance to corporate practice, those organisations who substantially modify an existing system or alter its intended purpose.

Regulated systems

The Regulation distinguishes between levels of risk rather than product categories. At the upper end of the scale are practices involving unacceptable risk, which are absolutely prohibited; these include the subliminal manipulation of behaviour, the exploitation of vulnerabilities of specific groups or the social grading of citizens.

Next, there are high risk systems, linked to decisions that significantly affect individuals – recruitment, access to credit, insurance, education, healthcare o the administration of justice – which are subject to stringent requirements regarding risk management, data quality, technical documentation and human oversight. A third level, classified as ‘limited risk’, brackets systems that interact with people of generate content, and are primarily subjected to obligations of transparency. Finally, most internal productivity tools are found in the minimal risk level, without any specific obligations beyond best practice.

Latest News

From a substantive point of view, the Regulation introduces obligations which until now did not expressly exist in European law. Among those, it is necessary to highlight the duty to inform individuals when they interact with an artificial intelligence system, the mandatory labelling of synthetic content generated or altered by AI, including those known as ‘deepfakes’, and the specific restrictions applicable to systems which infer emotions o categorise individuals based on biometric data, particularly in the workplace and educational settings. In addition to this, a general and often underestimated obligation has been added: AI literacy, which requires suppliers and those responsible for deployment to ensure that their personnel have an adequate understanding of the systems which they use.

The incorporation of these elements represents a significant change in the way in which companies mist approach the use of technology in their internal matters. It is no longer sufficient to evaluate the lawfulness of personal data processing in accordance with data protection regulation; rather, it is necessary to incorporate, right from the design stage of each process, a specific analysis of the risk classification of the system used, a requirement which calls for widespread coordination between the legal, technology, and human resources departments.

The impact on companies

From a practical perspective, the impact of the Regulation is widespread. It has a direct impact on the management of legal risk, given that non-compliance may result in substantial administrative sanctions, of up to 7% of global annual turnover in the case of prohibited practices, and up to 3% for other relevant infringements, figures which are of a comparable magnitude to those of the General Data Protection Regulation (GDPR).

Timeline

Although the obligations applicable to high-risk systems as set out in Annex III with not be fully enforceable until August 2027, the transitional period until then should not be interpreted as an opportunity to postpone the required adaptations. The obligations in relation to transparency, AI literacy and the prohibition of unacceptable practices, instead, have already been fully enforceable since 2025 and 2026 respectively, independent of whether a company does or does not deploy high-risk systems.

Recommendations

From a legal perspective, it seems highly advisable to conduct a regulatory impact assessment to identify the AI systems in use, including those integrated into third-party tools, and to classify their level of risk in accordance with the criteria set out in the Regulation. This analysis should also cover a review of notices of transparency addressed to employees, candidates and customers, the audit of AI-generated content in corporate communications, and the renegotiation of contractual clauses with technology suppliers, with a view to clearly defining the allocation of regulatory obligations throughout the value chain.

In conclusion, EU Regulation 2024/1689 represents a decisive step in the construction of a European AI framework focused on the protection of individuals, but it also poses significant organisational challenges for companies. Its proper implementation not only helps to prevent regulatory sanctions but can also become a differentiating factor in terms of trust, governance and positioning regarding clients, shareholders and investors.

 

Kengo Matsuoka

Vilá Abogados

 

For more information, please contact:

va@vila.es

 

4th of September 2026