By Rafael Luque Ocaña

Market surveillance from 2 August: what they can ask you, and who

2 August doesn't just activate obligations: it starts up the machinery that can ask about them. What a market surveillance action is, what documentation it will request, and why the enforcement powers coming into play shouldn't cost you any sleep — if your file is in order.

2 August 2026 is almost always discussed in terms of obligations: Article 50 transparency enters into application. It usually comes paired with a second idea that needs correcting: the AI Act's supervision system doesn't switch on that day. Market surveillance authorities and the penalties regime — Chapter VII and, in part, Chapter XII — have applied since 2 August 2025. What 2 August 2026 changes is what there is to supervise: from that day, on top of Article 4 and Article 5, most companies owe something concrete under Article 50, and there's someone with the power to ask about it.

What market surveillance is (and isn't)

Market surveillance is the classic European architecture for product oversight, now applied to AI: national authorities with the power to request information, check systems, demand corrective measures and, where appropriate, impose penalties. It doesn't work as a universal scheduled inspection — it works on signals: complaints, incidents, sector-wide campaigns, findings from other authorities. For an SME deployer, the realistic scenario isn't "they'll come and see me on day 3", but "if something draws attention to my use of AI — a customer complaint, a labour dispute, an incident — there will be a formal channel through which I'll be asked to explain".

In Spain, we've already mapped out the authorities: AESIA, the Spanish AI supervisory agency, as the central piece and single point of contact, with the AEPD, the Spanish data protection authority, and sector-specific authorities keeping their own remits, and the national legal framework still going through the parliamentary process. That map doesn't change on 2 August; what changes is that it stops being an org chart and starts being practice.

The conversation is always the same

Whatever the authority and the reason, an action concerning AI use revolves around a very stable script. The questions, in essence:

  • What AI systems do you use? — the inventory, with its reasoned risk classification.
  • Who operates them, and with what training? — the use policy and the record of literacy measures — Article 4 doesn't require a register, but it's your way of evidencing the measures taken.
  • What have you assessed? — the impact assessments where the GDPR requires them, and the written rationale for why not, where it doesn't.
  • How do you comply with what applies to you today? — the transparency notices, the verification carried out on the provider, the labelling of content.
  • Can you show it? — the question that subsumes all the previous ones.

Note what is not in an SME deployer's script: product technical files, conformity assessments, provider documentation. Each link in the chain answers for its own part, as we saw with the Article 50 split — and knowing how to say "that's on my provider; this is mine, and here it is" is, in itself, a demonstration of competence that works in your favour.

The penalties, read with a level head

Yes: the AI Act's penalty regime deals in large figures, with tiers based on severity — the maximum is reserved for the prohibited practices under Article 5, and below that sit non-compliance with other obligations and the provision of incorrect information to the authorities. Each tier has its own article and its own logic, and the Regulation itself does the scaling: they are ceilings that Article 99(7) requires weighing case by case, and which, for SMEs, Article 99(6) caps at the lower of the two magnitudes. The regime that gives them concrete form in Spain is a matter of national law (Article 99(1)), and this article says nothing about it.

But the useful reading for an SME isn't memorising the amounts — it's understanding who the regime is designed for: persistent non-compliance, prohibited practice, and obstruction. The company that can show its inventory, its assessments, its records and its rationale — even with imperfections — falls into the "correct and move on" category, not the "headline" one. The one that can't show anything turns any minor signal into a bigger problem, because the underlying infringement is compounded by the inability to demonstrate diligence.

Preparation fits in a single folder

The operational conclusion is deliberately unepic. Preparing for market surveillance isn't a new project: it's having organised and accessible what good governance already produces — a living inventory, reasoned classifications, policy and training with a record, assessments where they're due, dated transparency checks. The evidence, not the checklist: the folder that turns an uncomfortable meeting into a formality.

On 2 August the machinery starts up. It's not coming for you; but from that point on, it exists. The only variable you control is what it finds if it ever asks.

This article is for informational purposes only and does not constitute legal advice. Spain's institutional framework is going through the parliamentary process and may change.

Get analysis like this in your inbox

Alethexis regulatory and product news. No noise.

I agree to receive communications from Alethexis: content about AI and regulation, and product news. I can unsubscribe at any time.

Controller: ALETHEXIS, S.L. (CIF B88758057). Purpose: to send you the Alethexis newsletter (content about AI and regulation, and product news). Legal basis: your consent (Art. 6(1)(a) GDPR), which you can withdraw at any time. Retention: until you unsubscribe or after 24 months of inactivity. Rights of access, rectification, erasure, objection, restriction and portability: [email protected]. You may lodge a complaint with the Spanish Data Protection Authority (AEPD, www.aepd.es). More information in the privacy policy.