There's a reassuring idea circulating among many SMEs: "the AI Act doesn't fully apply to me yet, so I have time." The first half is debatable; the second is simply false. Because oversight of AI use in Spain didn't start with the AI Act. It started years ago, with a rule that has been fully in force all along and an authority that enforces it consistently: the GDPR and the Spanish Data Protection Agency (AEPD).
AI is already covered by the GDPR
An AI system that processes personal data is, in the eyes of the GDPR, a processing activity like any other — with the added complication that it tends to combine the factors the regulation treats as highest-risk: new technology, systematic evaluation of people, decisions with significant effects. There's no need to wait for any AI Act date for that processing to be subject to oversight. It has been from day one of use.
And the AEPD's own practice confirms it. Without going into specific cases, the patterns that generate the most enforcement files when AI is involved are recurring and, seen with perspective, avoidable:
The impact assessment that was never done. The processing required a Data Protection Impact Assessment (DPIA, Article 35 GDPR) — because it used special-category data, because it evaluated people systematically, because of its scale — and the organisation deployed the system without carrying one out. It's the most frequent failure and the easiest to hold against a company: it isn't a technical error, it's an omission of diligence.
Automated decisions without safeguards. Systems that decide on or profile people without the safeguards of Article 22 GDPR: no meaningful human intervention, no information given to the person affected, no way to challenge the decision. A scoring system that opaquely screens out candidates or customers is a natural candidate for enforcement action, AI Act or no AI Act.
Biometrics without a prior assessment. Processing biometric data — attendance control, identity verification — without the impact assessment and the proportionality judgement that its status as special-category data requires.
Breaches involving data processed by AI systems. When data moves to external providers and services without proper security measures and data processing agreements in place, a breach stops being just a technical incident and becomes a failure the company has to document.
What the AI Act changes (and what it doesn't)
The AI Act doesn't inaugurate AI enforcement in Spain: it expands it. Since 2 August 2025, the market surveillance machinery of the AI Regulation — with its own authorities and its own penalties regime — sits on top of the GDPR regime, and from 2 August 2026 it has Article 50 to supervise as well. In other words: the company that uses AI with personal data today already answers to the AEPD, and answers to the AI Act authorities too.
Read that way, the fear-based sales pitch ("get ready for the AI Act fines") falls short and arrives late at the same time. An SME's real exposure isn't in the future: it's in the present, and it has the names of GDPR articles that have been applying for years.
The common denominator: evidence
Looking at the patterns above, they all share the same root. The company isn't fined for using AI; what's held against it is being unable to show it used AI with due care. The assessment that doesn't exist, the safeguard that was never implemented, the data processing agreement that was never signed: these are, all of them, failures of documented diligence.
That's why sensible preparation isn't about waiting for the AI Act or stockpiling folders for when it arrives. It's about doing, right now, what the GDPR already requires: knowing which AI systems the organisation actually uses, assessing the ones that need it, putting safeguards in place wherever there are decisions about people, and keeping the evidence of all of it. Whoever has that in order will reach the AI Act with most of the work already done; whoever doesn't is already exposed today.
An honest starting point is to measure where you stand: our free situation diagnostic gives you that first snapshot in a few minutes. The snapshot isn't the evidence — but it tells you what's missing.
This article is for informational purposes only and does not constitute legal advice.