How Spanish SMEs Can Prepare for the EU AI Act in 2026
Only 21% of Spanish SMEs with 10+ employees use AI (INE), yet the EU AI Act's high-risk rules take effect August 2, 2026. Here's what changes and a 90-day compliance roadmap.

August 2, 2026 is the date most of the EU AI Act's substantive rules — including the high-risk system obligations — enter into application. For any Spanish SME using AI in hiring, credit scoring, or other sensitive processes, that's not a distant deadline anymore.
The August 2026 Deadline: What Actually Changes
The EU AI Act rolls out in stages. February 2025 brought the first prohibitions and AI-literacy obligations. August 2025 activated the rules for general-purpose AI models and required EU member states to set up national oversight bodies. August 2, 2026 is the big one: the majority of the Act's rules apply from this date, including the obligations for high-risk AI systems listed in Annex III, new transparency requirements, and the start of real enforcement at both national and EU level. A final wave, covering high-risk AI embedded in regulated products like medical devices, follows in August 2027.
Are You a 'Provider' or a 'Deployer'? Why It Matters
Most Spanish SMEs are not building AI models — they're using third-party tools for hiring, customer screening, or credit decisions. That makes you a 'deployer,' not a 'provider,' under the Act. It still matters: deployers of high-risk AI systems must complete a Fundamental Rights Impact Assessment (FRIA) before putting the system into use, and must be able to show it on request. Buying a compliant tool from a vendor does not automatically make your use of it compliant.
- Inventory every AI tool currently in use across the business, including tools embedded in HR, CRM, or finance software.
- Flag anything that touches hiring, credit scoring, biometric identification, or other 'sensitive' Annex III areas — these are the high-risk cases.
- Request compliance documentation (technical documentation, risk classification) directly from your AI vendors; don't assume it exists.
The SME Relief Nobody's Talking About: the 'AI Omnibus'
A legislative package known as the 'AI Omnibus' is being negotiated in Brussels and is expected to be finalized around mid-2026. It proposes extending some high-risk compliance deadlines and simplifying technical documentation requirements for smaller businesses. It is not law yet, and the exact terms can still change — plan around the existing August 2026 deadline, and treat any Omnibus relief as a possible bonus, not a reason to wait.
| AI Use Case | Risk Tier | What To Do Now |
|---|---|---|
| CV screening / hiring tools | High-risk | Complete a Fundamental Rights Impact Assessment |
| Customer service chatbot | Limited risk | Disclose AI use to customers (transparency, Art. 50) |
| Internal automation / analytics | Minimal risk | No new obligation, but document the use case |
A 90-Day Compliance Roadmap
- Days 1-30: Inventory every AI system in use, internal or vendor-supplied.
- Days 31-60: Classify each by EU AI Act risk tier and flag anything touching hiring, credit, or biometric data.
- Days 61-90: For high-risk uses, start the Fundamental Rights Impact Assessment and request compliance documentation from vendors.
This isn't just a legal exercise. Spanish SMEs are already behind on baseline AI adoption — only 21.1% of companies with 10 or more employees report using AI, according to INE, even as intent to invest is rising fast. Getting compliance right from the start means you can adopt AI with confidence instead of retrofitting governance onto tools you're already dependent on. At Apoga, our consulting and custom AI development work already builds in the same rigor we've applied to GDPR compliance for past clients — the AI Act is a similar discipline, applied to a newer technology.