Spain Targets AI Deepfakes With €35 Million Fines

A unified digital rulebook fragments into twenty-seven incompatible and disconnected national realities.
Cumadóireacht íomhá · tobriefSpain has moved first while Brussels has slowed down. On 26 May, the Spanish Council of Ministers approved a national AI law carrying €35 million fines and a direct ban on sexual deepfakes. Three weeks earlier, the EU had agreed to delay key enforcement deadlines under its own AI Act. That gap says much about where AI regulation in Europe now stands.
Madrid calls the measure the law for the good use and governance of artificial intelligence. It is being treated as an "organic law", the Spanish category used for legislation touching fundamental rights. The law goes further than the EU AI Act in two respects: it bans AI-generated sexual deepfakes and child exploitation material, and it creates a new post, the "AI delegate", in every public body using automated systems.
It also makes both AI providers and the firms using their tools legally responsible for breaches. The logic is familiar from food safety: responsibility does not stop with the producer if the business serving the product causes harm.
Brussels gave everyone more time. Spain said no thanks.
The EU's AI Act came into force in August 2024, but its hardest rules, covering systems used in hiring, medical diagnosis and law enforcement, have kept sliding down the calendar. On 7 May, Parliament and the Council agreed to push those obligations back by over a year through a legislative package known as the Digital Omnibus.
There was a practical reason for the delay. Most member states had not yet created their national AI regulators, and the technical standards companies need to show compliance were still unfinished. Brussels had written the rulebook, but much of the machinery needed to run it was missing.
Spain chose not to wait for the full European timetable. It had already launched AESIA, the EU's first dedicated AI supervisory agency, in June 2024, before the AI Act took effect. The new law gives that agency the power to enforce, not just advise.
Five countries, five playbooks
Across Europe, the same EU framework is now being filtered through very different national habits: criminal law in one country, courts in another, regulators somewhere else.
Italy went down the criminal route. Its Law 132/2025 made deepfake distribution a standalone offence, partly shaped by a prominent case involving doctored images of Prime Minister Meloni. Opposition vice-speaker Anna Ascani called criminalisation without platform-removal powers "useless" if authorities cannot force takedowns.
Germany let the courts move first. On 12 May, the Oberlandesgericht Hamm, a regional appeals court, ruled that companies are fully liable for false claims made by their AI chatbots, even when the systems were trained on accurate data. The case involved a beauty clinic whose chatbot invented medical credentials for its doctors. Germany's national implementation law is still moving through parliament.
France has leaned on institutional coordination rather than fresh legislation. The CNIL, France's data protection authority, acts as AI regulation coordinator across more than 15 sectoral agencies. Mistral AI founder Arthur Mensch told the National Assembly that the regulatory burden favours US giants over European startups, because a small compliance team has to navigate dozens of national versions of the same EU law.
Ireland is still at the starting line. Its AI Office will launch on 1 August with a skeleton staff and no chief executive named. The first serious test is likely to be X's Grok, which Irish regulators have flagged for generating non-consensual intimate imagery.
The vacuum no one planned
Spain's law is tougher than the European baseline, but it has gaps of its own. Public bodies that misuse AI face reprimands, not fines. Italy's watchdog system is split across multiple agencies, a structure critics say is poorly coordinated. Ireland, meanwhile, has not yet staffed the office that will be asked to enforce the rules.
The EU AI Act was meant to give the continent one framework. The Omnibus delay gave member states more time, but it also created a space for national governments to fill with their own priorities. By the time the toughest obligations apply, Europe may have 27 practical versions of the same law.
For any company building or deploying AI in 2026, the picture is awkward. Spain bans sexual deepfakes and threatens heavy fines. Italy criminalises deepfake distribution. Germany holds chatbot operators responsible for hallucinations. Ireland has yet to appoint its chief regulator. That is a long way from a single rulebook.
How was this article?
Help us get better
Help us get better
Details about this article
- Model:
- claude-opus-4-6
- Generated:
- 5/27/2026, 3:12:56 AM
- Pipeline run:
- eu_pipeline_20260527_015006
- Watermark:
- SynthID (Google's invisible watermark)
- Human review:
- None before publication