Skip to main content
TECH_SCIENCE08 / 08 · story of the day3 min · 593 words · 147 sources

Spain Sets €35 Million AI Fines

Written by AIto brief AI · 27 ta’ Mejju 2026, 03:50
How it was written

A unified digital rulebook fragments into twenty-seven incompatible and disconnected national realities.

Image composition · tobrief
the text · 3 min read

Spain has approved a national AI law carrying €35 million fines and a full ban on sexual deepfakes. Three weeks earlier, the EU had given member states more time to enforce parts of its own AI rulebook. The space between those two decisions is where European AI regulation now sits.

On 26 May, Spain's Council of Ministers approved the law for the good use and governance of artificial intelligence. Madrid classified it as an "organic law", the category Spain uses for legislation affecting fundamental rights. It goes further than the EU AI Act in two respects: it bans AI-generated sexual deepfakes and child exploitation material, and it creates an "AI delegate" inside every government agency using automated systems.

The law also makes both AI providers and the companies deploying their tools legally responsible for breaches. The logic is familiar from food safety: the manufacturer and the restaurant can both be liable if the product harms the customer.

Brussels gave everyone more time. Spain did not take it.

The EU's AI Act entered into force in August 2024, but its hardest obligations, covering AI used in hiring, medical diagnosis and law enforcement, have kept slipping. On 7 May, Parliament and the Council agreed to push those obligations back by more than a year, folding the delay into a legislative package called the Digital Omnibus.

The reason was practical as much as political. Most member states had not yet set up their national AI regulators, and the technical standards companies need to show compliance were not ready. For small economies such as Malta, where a new EU compliance layer can land quickly on gaming, fintech, public services and media, that delay matters.

Spain chose a different route. It had already launched AESIA, the EU's first dedicated AI supervisory agency, in June 2024, before the AI Act took effect. The new law now gives that agency enforcement powers with real cost attached.

Five countries, five playbooks

A patchwork of national AI responses is taking shape across Europe. Each country is reading the same EU law through its own politics, courts and administrative habits.

Italy chose the criminal route. Its Law 132/2025 made deepfake distribution a standalone offence, driven partly by a high-profile case involving doctored images of Prime Minister Meloni. Opposition vice-speaker Anna Ascani called criminalisation without platform-removal powers "useless" if authorities cannot force takedowns.

Germany let the courts move first. On 12 May, the Oberlandesgericht Hamm, a regional appeals court, ruled that companies are fully liable for false statements made by their AI chatbots, even when the bots were trained on correct data. The case involved a beauty clinic whose chatbot invented medical credentials for its doctors. Germany's national implementation law is still moving through parliament.

France went for coordination rather than a new statute. The CNIL, France's data protection authority, acts as AI regulation coordinator across more than 15 sectoral agencies. Mistral AI founder Arthur Mensch told the National Assembly that the compliance burden favours US giants over European startups, because small teams must navigate dozens of national versions of the same EU framework.

Ireland is still building the machinery. Its AI Office launches on 1 August with a skeleton staff and no CEO named yet. Its first serious test is likely to be X's Grok, flagged by Irish regulators for generating non-consensual intimate imagery.

The vacuum no one planned

Spain's law is not watertight. Government agencies that misuse AI face reprimands, not fines. Italy's watchdog system is split across multiple agencies in a way critics say is poorly coordinated. Ireland has not yet staffed its regulator, still less tested it.

The EU AI Act was meant to give the continent one rulebook. The Omnibus delay bought governments time, but it also created a gap that national capitals are filling with their own priorities.

By the time the toughest obligations apply, Europe may have 27 versions of the same law. For a company building AI in 2026, the position is already uneven: Spain bans deepfakes, Italy imprisons their creators, Germany makes chatbot operators liable for hallucinations, and Ireland has not yet hired its chief regulator. That is not one rulebook in any meaningful sense.

How was this article?

Help us get better

Details about this article
Model:
claude-opus-4-6
Generated:
5/27/2026, 3:12:56 AM
Pipeline run:
eu_pipeline_20260527_015006
Watermark:
SynthID (Google's invisible watermark)
Human review:
None before publication
Learn more about our methodology