Spain enacts €35 million fines for AI deepfakes

A unified digital rulebook fragments into twenty-seven incompatible and disconnected national realities.
Image composition · tobriefSpain just passed a comprehensive national AI law with €35 million fines and an outright ban on sexual deepfakes. Three weeks earlier, the EU had pushed back its own enforcement deadlines. The gap between those two events tells the real story of AI regulation in Europe right now.
On 26 May, Spain's Council of Ministers approved what it calls the law for the good use and governance of artificial intelligence, classified as an "organic law," a category Spain reserves for legislation touching fundamental rights. It goes beyond the EU AI Act in two ways: it bans AI-generated sexual deepfakes and child exploitation material, and it creates a new role, the "AI delegate," inside every government agency using automated systems.
The law also makes both AI providers and the companies deploying their tools legally responsible for violations. Think of it like food safety: both the manufacturer and the restaurant that serves the dish can be held liable if a customer gets sick.
Brussels gave everyone more time. Spain said no thanks.
The EU's AI Act entered into force in August 2024, but its toughest rules covering AI used in hiring, medical diagnosis, and law enforcement kept getting delayed. On 7 May, Parliament and the Council agreed to push those obligations back by over a year, bundling the delay into a legislative package called the Digital Omnibus. Most member states hadn't even set up their national AI regulators, and the technical standards companies need to prove compliance weren't ready.
Spain didn't wait. It had already launched AESIA, the EU's first dedicated AI supervisory agency, in June 2024, before the AI Act took effect. The new law gives that agency real enforcement teeth.
Five countries, five playbooks
A patchwork of national AI responses is emerging across Europe, each shaped by domestic politics and legal traditions.
Italy went criminal. Its Law 132/2025 made deepfake distribution a standalone offence, driven partly by a high-profile case involving doctored images of Prime Minister Meloni. Opposition vice-speaker Anna Ascani called criminalisation without platform-removal powers "useless" if authorities cannot force takedowns.
Germany let courts lead. On 12 May, the Oberlandesgericht Hamm, a regional appeals court, ruled that companies are fully liable for their AI chatbots' false statements, even when trained on correct data. A beauty clinic's chatbot had invented medical credentials for its doctors. Germany's national implementation law is still working through parliament.
France chose institutional coordination over new legislation. The CNIL, France's data protection authority, acts as AI regulation coordinator across more than 15 sectoral agencies. Mistral AI founder Arthur Mensch told the National Assembly that the regulatory burden favours US giants over European startups, because a small compliance team must navigate dozens of national implementations of the same EU law.
Ireland is building from scratch. Its AI Office launches 1 August with a skeleton staff and no CEO named yet. The first real test will be enforcement against X's Grok, flagged by Irish regulators for generating non-consensual intimate imagery.
The vacuum no one planned
Spain's law has its own blind spots. Government agencies that misuse AI face reprimands, not fines. Italy's watchdog landscape is split across multiple agencies that critics call poorly coordinated. Ireland hasn't staffed its regulator yet, let alone tested it.
The EU AI Act was supposed to create one rulebook for the continent. The Omnibus delay bought member states time, but it also opened a vacuum that national governments filled with their own priorities. By the time the toughest obligations take effect, Europe may have 27 different versions of the same law. For a company building AI in 2026, the continent looks like this: Spain bans deepfakes, Italy imprisons their creators, Germany holds chatbot operators liable for hallucinations, and Ireland hasn't hired its chief regulator. One rulebook, this is not.
How was this article?
Help us get better
Help us get better
Details about this article
- Model:
- claude-opus-4-6
- Generated:
- 5/27/2026, 3:12:56 AM
- Pipeline run:
- eu_pipeline_20260527_015006
- Watermark:
- SynthID (Google's invisible watermark)
- Human review:
- None before publication