News
11/5/2026

AESIA Guidelines on the AI Act – Guide n. 1

Share this post
Blog authors
Silvia Martinelli
Strategic Research Manager
Sign up for the Data Valley newsletter
By clicking on “Sign Up” you consent to the processing of data according to our Privacy Policy.
Thank you, your subscription to the newsletter has been received!
An error occurred while submitting the form.

How can the AI Act be interpreted and put intopractice? The Spanish Agency for the Supervision of Artificial Intelligence (AESIA), the first European agency dedicated to artificial intelligence, has published its first guidelines. These guidelines provide a clear and practical overview of the AI Act, the European Union’s regulatory framework for artificial intelligence. It explains the key principles, risk categories, and compliance requirements that organizations need to understand.

The first guide, Guide No. 1, is an introduction to the AI Act, Regulation 2024/1689 of the European Parliament and of the Council, of 13 June 2024 (European Regulation on Artificial Intelligence). The purpose of this introductory guide is to provide a general understanding of the European Regulation on Artificial Intelligence (AI Act),providing the reader who is new to the subject with a clear vision of its regulatory scope, its scope of application and the main obligations that derive from it. It aims to serve as a starting point to familiarise yourself with the essential elements of the Regulation, addressing in a brief and structured way the key concepts that underpin its content.

Firstly, the principles for defining a secure framework for the use of artificial intelligence are recalled.  International organizations such as UNESCO, the OECD and the European Union agree that the human being must always remain at the centre of technological development, maintaining AI as a tool of support and complement. The principles for defining a secure framework for the use of artificial intelligence are:

  • Avoid bias and non-discrimination.Prevent algorithms from having discrimination problems and look for ways tomake the results obtained explainable.
  • Cybersecurity, robustness andaccuracy. Ensure that AI systems are robust against cyberattacks, tampering, orunauthorized alterations, and that they maintain stable, predictable, andaccurate behaviour even under adverse conditions.
  • Quality management system and riskmanagement system. Implement an integrated framework that ensures thedocumentation, traceability, testing, and ongoing maintenance of systems andthat allows for the identification, assessment, and mitigation of risks tohealth, safety, and fundamental rights, and applies preventive and correctivecontrols throughout the system's lifecycle.

The Guidelines focuses on the context and the objectives of the AI Act.

The objectives are:

  • Ensure that AI systems placed on themarket or put into operation in the European Union are safe and respectexisting legislation and EU values.
  • Provide legal certainty to encourageinvestment and innovation.
  • Improve governance and effective enforcement of fundamental rights and safety regulations in the use of AI.
  • Define a single market for AI, enabling a reliable and secure use of artificial intelligence, avoiding regulatory fragmentation.

Concerning the scope, the AI Act defines itslimits of application.

The main areas excluded include:

  1. Research and development (R+D). The Regulation does not apply to AI systems or models that are developed specifically for the sole purposes of scientific research and development. Nor shall it apply to any research, testing or development activities relating to AI systems or AI models prior to their placing on the market or putting into service. Tests under real conditions will not be covered by this exclusion.
  2. Military, defense or national security. AI systems used exclusively for military, defence or national security purposes fall outside the scope of the AI Act, regardless of the entity using them or where they are placed on the market or put into service. This exclusion also extends to AI systems that are not placed on the market in the Union, but whose product is used within the Union solely for those purposes.
  3. Open source- software. AI systems releasedunder free or open-source licenses are not subject to the RIA, unless they aremarketed or put into service as high-risk AI systems or as systems withtransparency obligations. They may not be used for the purposes prohibited bythe Regulation.
  4. Use by natural persons in a non-professionalfield. The Regulation does not apply to the use of AI by natural persons usingAI systems in the exercise of a purely personal activity of a non-professional nature.

The AI Act governance system follows amulti-level model combining EU and national oversight to ensure consistent application across Member States.

Each country designates Competent Authorities: Market Surveillance Authorities (MSAs) and Notifying Authorities (NAs). MSAs monitor and enforce compliance of AI systems on the market, including corrective or sanctioning actions. NAs designate and supervise assessment bodies, while Notified Bodies carry out independent technical checks for high-risk AI systems.

The AI Act is a risk-based regulation of eachAI system, so that the greater the risk, the greater the control.

A) Prohibited systems: uses of AI that are at this level of the hierarchy are prohibited due to the high risk they entail: AIsystems that pose a threat to safety, life or fundamental rights. At this level are, for example, systems with any of the following functions:

  • Subliminal manipulation of aperson's behaviour in a way that may cause physical or psychological harm tohim or others.
  • Exploiting the vulnerabilities ofsocial groups to manipulate their behaviour in a way that may cause harm tothem or others.
  • Evaluation or classification ofpeople or groups by their social behaviour that may disproportionately harmthem in the area of the behaviour observed, or harm them in areas other thanwhere it was observed.
  • Real-time biometric identificationin public access spaces for police authorities, except in assessed cases andwith authorization.

B) High-Risk Systems: the second level is reserved for high-risk systems, but whose use is permitted, to which the AI Act dedicates most of the requirements and obligations that must be met by the different roles involved in the value chain of the implementation of an AI system (operators).

C) Systems with transparency obligations: The regulation establishes the obligation of transparency towards users for this type of product. Among other things, they are obliged to make it clear that their departure is the product of an artificial intelligence system, not a human. At this level are chatbots and deep fake creation systems, among others.

D) Other AI systems: for the rest of the AI systems, only basic obligations are contemplated, such as training users of the systems in AI (literacy). Among them is the application of AI to video games or spam filters for email.

E) Non-AI systems: certain more classical algorithms, such as those based on rules or heuristics, are not considered AI systems under the Regulation, and therefore do not apply to them.

The AI Act also regulates general-purpose AI models (GPAI), AI models that are typically trained with a large volume of data and that are capable of competently performing a wide variety of different tasks such as answering questions, translating, generating all kinds of content, etc. These models can be adapted to a wide variety of tasks through configuration or subsequent training. Depending on its integration into a purpose-driven AI system, the system may be considered high-risk or even prohibited use.

The additional obligation for a high-risk system is established, which consists of the development of an impact assessment relating to fundamental rights.

EIDFs, or FRIAs (Fundamental Rights ImpactAssessments), are mandatory before the deployment of a high-risk AI system and must be carried out by those responsible for its deployment. These assessments include a detailed description of how the system will be used, as well as thetime period and frequency of its operation. They also identify the categories of individuals and groups that may be affected, together with the specific risks of harm that could arise. In addition, the assessment outlines the human oversight measures put in place and defines the actions to be taken if risks materialize, including appropriate grievance mechanisms.

The European Regulation on Artificial Intelligence mentions different potential roles involved in the value chain ofAI systems (operators). The provider is defined as a natural or legal person, public authority, agency or other body that develops or causes to be developed an AI system or a general-purpose AI model and places it on the market or puts it into service under its own name or trademark, whether for consideration or free of charge. The deployer is defined as any natural or legal person, public authority, body or any other entity that uses an AI system under its authority, except when such use is part of a personal activity of a non-professional nature. The Authorised Representative is a natural or legal person located or established in the Union who has received and accepted a written mandate from a provider of an AI system or a general-purpose AI model to comply with the obligations and carry out the procedures set out in this Regulation on behalf of that provider. The importer is defined as any natural or legal person physically present or established in the Union who places on the market an AI system bearing the name or trademark of an AI system from a natural or legal person established outside the Union. They place on the market for the first time the AI system to market in the name or trade mark of a natural or legal person established outside the Union, whether the supply is paid or free of charge. Finally, the distributor is any natural or legal person in the supply chain, other than the supplier or importer, who places an AI system on theUnion market. They place the systems on the market, i.e. they supply an AI system for distribution or use on the Union market in the course of a commercial activity, whether the supply takes place on a paid or free basis.

For SMEs and start-ups, the AI Act introduces several tailored provisions to ease compliance. Penalties are determined at the lower level between a fixed amount and a percentage of turnover, as outlined in the regulation. These companies benefit from priority access to regulatory sandboxes, as well as dedicated channels for advice and consultation. In addition, standardized forms are made available to simplify compliance procedures, while the technical documentation requirements and fees associated with conformity assessments are reduced. Finally, quality management systems are expected to be implemented in a way that is proportionate to the size andr esources of the company.

The main obligations established by the AI Act encompass a comprehensive set of requirements that organizations must follow to ensure the safe, transparent, and accountable development and use of artificial intelligence systems:

  • AI literacy obligations - Thepersonnel in charge of operating the systems have sufficient knowledge ofArtificial Intelligence.
  • Transparency obligations - requiringproviders and those responsible for deployment to provide clear andunderstandable information
  • Obligations of high-risk systems - Arisk management system aims to identify and analyze risks and implementmeasures to mitigate their impact. In the context of the European Regulation onArtificial Intelligence, the risk management system shall pay particularattention to the identification, analysis, assessment and mitigation of risksaffecting the health, safety and fundamental rights of individuals, both intheir intended use and in reasonably foreseeable uses.
  • Data and data governance - In thecontext of AI, data governance is the set of elements (policies, procedures,processes, standards, etc.) which are implemented to ensure that the data usedin the training, validation and testing of AI systems is adequate, relevant,sufficiently representative and meets the established quality and completenessrequirements.
  • Technical documentation - In orderto enable the traceability of high-risk AI systems, to verify whether theycomply with the requirements of the Regulation, as well as to monitor theiroperation and carry out post-market monitoring, it is essential to haveunderstandable technical documentation on how they have been developed and ontheir operation throughout their lifetime.
  • Record-keeping - It is necessary toaddress the development of an adequate records management system, which willnot only make it possible to comply with the requirements of the Regulation,but will also facilitate other tasks such as transparency and accountability,and other evidence-based research and development activities.
  • Transparency - The EuropeanRegulation on Artificial Intelligence establishes the obligation to ensure thedesign and development of systems that allow those responsible for thedeployment to understand and use the system appropriately; to provide instructionsfor use that include concise, complete, correct and clear information that isrelevant, accessible and understandable to those responsible for thedeployment; as well as a set of specific information to be taken into accountin the design and development of the system.
  • Human Oversight - People need to beable to keep an eye on the operation of high-risk AI systems. To this end,systems must provide the necessary tools and interfaces to exercise thissupervision and interact with them in a secure manner.
  • Accuracy - A keyway to be able tomitigate the risks in the use of AI as much as possible is to improve theaccuracy of this AI system. Through the accuracy of the system, we obtain aquantitative measure of the relationship between the intended purpose of thesystem and its performance from design to operation after the implementation ofthe AI system.
  • Robustness - Technical robustness isunderstood as the resilience of the system in relation to harmful, or otherwiseundesirable, behaviour that may result from limitations in the systems or inthe environment in which they operate (e.g. errors, failures, inconsistenciesor unexpected situations).
  • Cybersecurity - In high-riskArtificial Intelligence systems is a key aspect of its design, as these aresystems that are exposed to specific threats that require rigorous protectionmeasures adapted to their context.
  • Quality management system - Thissystem should include compliance strategies, risk management, design anddevelopment control, testing, post-market monitoring, incident reporting, andcommunication with authorities and stakeholders.
  • Conformity assessment - Thisprocedure distinguishes between internal control and third-party evaluation,depending on the nature of the system and the application of harmonisedstandards.
  • Post-market monitoring - TheEuropean Regulation on Artificial Intelligence introduces the need for amonitoring system to be established after the implementation of high-risk AIsystems, as part of a post-market monitoring plan.
  • Reporting of serious incidents - TheRegulation defines as an obligation of HRAI providers the need to report anyserious incident or defect of an AI system to market surveillance authorities.

Are you ready to transform the Data in value for your business?