By Rafael Luque Ocaña

What you can ask your tax advisor about AI — and what's not in their power to give you

For most Spanish SMEs, the tax advisor is the first place they ask. Some things it handles well, others depend on information only you have, and one thing no outsider can take on.

When a Spanish SME asks itself what it needs to do about AI, the first place it turns to isn't a specialist law firm or a software vendor. It's its tax advisor — the same firm that handles payroll, taxes and, often, data protection too.

It's a reasonable choice, and this article isn't here to argue with it. It's here to separate out three things that get asked for together and aren't the same: what a tax advisor handles well, what depends on information only you have, and what no outsider can take on.

What it handles well, and it's no small thing

A good part of the work a company associates with the AI Act is actually data protection work, and that's exactly where a tax advisor with GDPR practice contributes directly.

The record of processing activities, the legal basis for each processing operation, contracts with processors, information provided to data subjects, responses to rights requests, and impact assessments where they apply. None of that comes from the AI Act: it came from the earlier regulation, and it remains enforceable regardless of any calendar.

If your company already has that sorted, a considerable part of the effort is already done — and if it doesn't, that's the outstanding work before any other.

What depends on information only you have

This is where most of the disappointment lies, and it isn't anyone's fault.

Classifying a system requires knowing what it does. Not what the brochure promises: which functions are switched on, with what data, deciding about whom, and with what consequence. That information lives in the operation, not in the accounts, and a tax advisor has no way to get it unless someone inside hands it over.

The same goes for each system's intended purpose, which is what the whole classification hangs on. And for the inventory: no outsider can list tools that aren't even written down internally.

So the realistic request isn't “classify my systems for me”, it's “here's a list of what each one does — help me interpret it”. It's a difference in what's being asked for, and it changes the outcome.

What no outsider can take on

And this comes from the text itself, not an opinion about professional services.

Article 26(2) requires human oversight to be assigned to persons "who have the necessary competence, training and authority". Authority can't be outsourced: the person who can stop a system in your company is inside your company. An advisor can describe the role; they can't fill it.

Article 4 requires literacy measures "taking into account their technical knowledge, experience, education and training and the context the AI systems are to be used in". That proportionality judgement is made by whoever knows the team.

And deciding what's acceptable — what a system can do without intervention, what always gets reviewed — is a risk decision, and the organisation is the one that bears the risk.

Five questions that actually work

They replace the general question — “can you handle the AI Act for me?” — which almost never produces a useful answer.

Is our record of processing activities up to date, including the ones that use AI? It's the first thing, and it's entirely their territory.

Of our processing operations, which would require an impact assessment? A GDPR question, not an AI Act one, and with years of practice behind it.

What contracts do we have with the providers of these tools, and what do they say about data processing? Reviewing contracts is classic advisory work.

Given this list of systems I'm giving you, which ones do you see potentially falling under an Annex III category? Note the order: you're the one who supplies the list.

Which of all this is enforceable today, and which isn't? The correct answer distinguishes Article 4 and Article 5 — in force since 2 February 2025 — from the high-risk regime, which doesn't apply until 2 December 2027.

A red flag, in both directions

If the answer includes an urgency that isn't on the calendar — “it has to be ready before August”, “it's already mandatory” — it's worth checking, because a good deal of what circulates uses deadlines that don't exist.

And so does the promise to have it all sorted without asking you for information about your systems: that's exactly what can't be done from outside.

The good answer tends to be more boring — it starts by asking you for a list.

Content in accordance with Articles 4, 5 and 26 and Annex III of Regulation (EU) 2024/1689, as amended by Regulation (EU) 2026/1744 (Official Journal of the EU, 24 July 2026), and Regulation (EU) 2016/679.

This article is for informational purposes only and does not constitute legal advice.

Get analysis like this in your inbox

Alethexis regulatory and product news. No noise.

I agree to receive communications from Alethexis: content about AI and regulation, and product news. I can unsubscribe at any time.

Controller: ALETHEXIS, S.L. (CIF B88758057). Purpose: to send you the Alethexis newsletter (content about AI and regulation, and product news). Legal basis: your consent (Art. 6(1)(a) GDPR), which you can withdraw at any time. Retention: until you unsubscribe or after 24 months of inactivity. Rights of access, rectification, erasure, objection, restriction and portability: [email protected]. You may lodge a complaint with the Spanish Data Protection Authority (AEPD, www.aepd.es). More information in the privacy policy.