
The European Union has taken a decisive step in regulating artificial intelligence. Starting this Sunday, August 2, 2026, the transparency obligations set out in the European Artificial Intelligence Regulation (AI Regulation) will come into effect . This pioneering legislation aims to balance technological innovation with the protection of fundamental rights. From now on, citizens will be able to know when they are communicating with a machine or when content has been generated or manipulated using AI.
The implementation of this phase marks a significant milestone, although the full timeline extends to 2028. Businesses and public administrations face a major organizational challenge , as they must not only comply with the new requirements but also identify and classify all the AI ​​systems they use in their daily operations. Furthermore, Spain is currently drafting its own legislation to adapt the European framework to the country's specific circumstances.
Transparency and content labeling

One of the most noticeable changes for users is the requirement that virtual assistants and chatbots clearly inform users that they are interacting with artificial intelligence . This affects tools like ChatGPT, Gemini, and Claude, but also simpler systems such as conversational FAQs. The measure aims to prevent confusion and strengthen trust in digital services.
Furthermore, content generated or modified using AI—images, videos, audio, or text—must incorporate machine-readable markup to detect its artificial origin. So-called deepfakes must be identified , except in works of fiction, art, or satire. The European Commission clarifies that simple spelling corrections are not considered sufficient human review to exempt content from this requirement.
In the case of content on matters of public interest—politics, electoral processes, health, justice, or the environment— publishers must indicate whether it was generated by AI and has not undergone human editorial review . Otherwise, the responsibility falls on the publisher. This requirement aims to combat disinformation at a time when it is increasingly difficult to distinguish between what is real and what is artificial.
Prohibitions and sanctions

The regulation establishes a strict sanctions regime. The most serious infringements, such as the use of prohibited AI systems, can result in fines of up to €35 million or 7% of global annual turnover , whichever is higher. For breaches related to transparency obligations, penalties reach €15 million or 3% of turnover. Authorities may consider proportionality in the case of SMEs.
From December 2, 2026, the creation of sexualized images using AI without consent will be prohibited , as will any tool designed to generate child sexual abuse material. This measure was implemented following the controversy surrounding images generated with Grok, a tool from the social network X. Social scoring systems, the manipulation of vulnerable individuals, and real-time biometric identification in public spaces will also be banned, except with judicial authorization.
The European AI Office, based in Brussels, now has the authority to oversee general-purpose AI models, such as those that underpin numerous applications. It can request information, access systems, order corrective measures, and even restrict their availability if it detects non-compliance. This oversight is shared with national authorities, such as the Spanish AI Supervisory Agency (AESIA).
Adaptation of companies

One of the biggest challenges for organizations is identifying all the AI ​​systems they use, including those employees have adopted on their own —the so-called "shadow AI." According to a report by the consulting firm Entelgy, nearly 70% of large companies have already begun some adaptation process, but many still lack a complete inventory of their tools.
Experts agree that the first step is to take stock of and classify systems according to their level of risk : from those with minimal risk, such as a simple chatbot, to those with high risk, such as those used in personnel selection, credit assessment, or medical diagnosis. For the latter, the obligations will apply from December 2027, but the analysis work must begin now.
Training employees in the responsible use of AI is the most widespread measure, followed by the creation of governance committees and internal policies. Experts warn that simply trusting the technology provider is not enough , because the risk also depends on the specific use of the tool. For example, using an AI system to filter resumes can make it a high-risk application, regardless of who developed it.

Giovanni Alessandrello, CEO of BIP Iberia, emphasizes that compliance must be approached as a strategic project, not just a technological one . Companies need to develop their own criteria, establish clear policies, and equip their management teams with governance mechanisms. "Compliance has a cost, but failing to govern AI also has a cost, and in many cases, it can be much higher," he points out.
The Spanish AI Law

In parallel with the European regulation, the Spanish government is promoting the Draft Law for the Proper Use and Governance of Artificial Intelligence, currently under parliamentary review. This legislation does not create a separate regime, but rather adapts the application of the AI ​​Act to the Spanish legal system , defining the competent authorities, the oversight system, and the sanctioning procedure.
Among the most notable measures of the future Spanish law is the explicit prohibition of generating sexual deepfakes, an amendment that Spain managed to incorporate into the European text after the Almendralejo girls case. Socialist MEP Laura BallarÃn argued that the legislation will especially protect minors and women , while PP MEP Adrián Vázquez compared the regulation to the use of a knife: "We are not prohibiting knives, but rather using them to assault."
Member States have until September 2026 to adapt their national legislation. Spain has already taken the first steps with the approval of the draft bill in May , and the final law is expected to be ready in the coming months. In the meantime, the European regulation is directly applicable, so companies should not wait for national legislation to begin complying.
The implementation of the AI ​​Act will continue in stages until 2028. New prohibitions on non-consensual sexual content will come into effect on December 2, 2026, followed by those on high-risk systems in December 2027. Finally, in August 2028, provisions for AI integrated into products such as medical devices, vehicles, and toys will be applied. Europe is thus at the forefront of artificial intelligence regulation , with a model that seeks to combine innovation with the protection of citizens' rights, although the real challenge will be keeping the law in step with a technology that is advancing much faster than legislation.
