There's a question that always comes up once a company starts taking the AI Act seriously: "okay, so who exactly is going to supervise me?" The answer matters, because knowing who you answer to shapes how you prepare. In Spain, AESIA is the central piece, but it isn't the only authority involved, and the way competences are divided has a logic to it.
What AESIA is
The Spanish AI Supervision Agency (Agencia Española de Supervisión de la Inteligencia Artificial, AESIA) is the national authority created by Royal Decree 729/2023. With it, Spain became the first European Union country with a body specifically dedicated to overseeing AI, ahead of the Regulation's own entry into force. It is attached to the Ministry for Digital Transformation and the Civil Service, headquartered in A Coruña with a presence in Madrid.
AESIA isn't just a supervisor that fines. Its mandate combines control and facilitation: assessing the risks of AI systems, issuing technical recommendations, coordinating with other national and European authorities, running the regulatory sandbox, and publishing guidance. That dual role — overseeing and helping with compliance — matters for understanding how it will act.
AESIA isn't alone: the map of authorities
A common mistake is to assume AESIA oversees everything. The Spanish model is more nuanced, and the draft Organic Law on the good use and governance of Artificial Intelligence — published in the Official Gazette of the Spanish Parliament (Boletín Oficial de las Cortes Generales) on 12 June 2026 and currently going through the parliamentary process — sketches it out as follows (its content may change during that process):
- AESIA acts as the lead market surveillance authority and single point of contact, and covers systems not addressed by product legislation — employment, biometrics in certain uses, education.
- Products already regulated under sector-specific rules (medical devices, machinery, toys, vehicles) keep their sectoral market surveillance authority. A clinic with an AI-enabled medical device deals, for that system, with the product authority, not with AESIA.
- The AEPD retains a decisive role in biometrics, data, and border matters.
- The CGPJ (General Council of the Judiciary) is involved in the justice domain.
- Financial and insurance supervisors retain their sectoral competences.
For an SME, the practical consequence is that the relevant authority depends on the specific system and its scope. There's no single answer.
What a market surveillance action looks like
It's worth demystifying this without downplaying it. A market surveillance action isn't a raid. It's a procedure in which the authority can request information, carry out checks, demand corrective measures and, depending on severity, close the case with a reasoned decision or open formal proceedings.
The Spanish draft law also provides for a single reporting channel at AESIA so that anyone — an employee, a customer, an affected party, a competitor — can report possible non-compliance. That means oversight won't depend only on scheduled audits, but also on external tip-offs. It's one more reason to have things in order: you don't control when a tip-off arrives.
What's actually being asked of you
When a surveillance authority looks at an AI system, the underlying question is always the same: can you explain what you use this system for, who oversees it, what risks it creates, and what evidence you keep? Translated into documentation, what gets reviewed centres on:
- The systems inventory and its risk classification.
- The AI use policy and evidence of staff training (Article 4).
- The applicable assessments: a DPIA where the GDPR requires one; for high-risk systems, governance documentation and, in due course, the FRIA.
- The Article 50 transparency notices, where they apply.
- The record of human oversight over the system's decisions.
It isn't a checklist of stamps. It's a body of traceable evidence that demonstrates diligence.
The penalty regime, without the alarmism
Yes, penalties exist, and they're steep. Article 99 of the AI Act sets ceilings depending on the infringement: up to EUR 35 000 000 or 7% of worldwide turnover for the prohibited practices under Article 5 (Article 99(3)); up to EUR 15 000 000 or 3% for non-compliance with the obligations listed in Article 99(4) — among them the deployer's under Article 26 and the transparency ones under Article 50 —; and up to EUR 7 500 000 or 1% for supplying incorrect, incomplete or misleading information to the authorities (Article 99(5)).
But it's worth reading that framing calmly. Those figures are ceilings, not price lists: Article 99(7) requires weighing all the circumstances of the case, Article 99(1) requires taking into account the interests of SMEs and their economic viability, and Article 99(6) caps each fine, for an SME, at the lower of the two magnitudes. The penalty regime that gives those ceilings concrete form in Spain is a matter of national law under Article 99(1), and this article says nothing about it: it neither asserts nor anticipates it. What can be said from the Regulation itself is that the company that can show documented diligence is, by definition, on the right side of that weighing.
How to prepare
Preparing for AESIA isn't different from good AI governance in general. It means having it done before anyone asks: a living inventory, honest classification, policy and training, assessments where they apply, transparency measures in place, and evidence kept on file. If that's all in order, a market surveillance action is a formality, not a crisis.
This article is for informational purposes only and does not constitute legal advice. Spain's institutional framework for AI is under development; check the status of the applicable legislation as it progresses through parliament.