European Artificial Intelligence Regulation
Noticias
29 july 2026
On 2 August, a critical milestone in the implementation timetable will be reached, as the most stringent obligations for systems that affect citizens come into force.
FUENTE: VACIERO
AUTOR: Susana García, Director of the Compliance Department
Regulation (EU) 2024/1689 (the AI Act), which regulates artificial intelligence, is now a reality and is redefining the rules of the corporate landscape within the European Union. Although there is a widespread misconception that this legislation only affects technology developers, the reality is that it directly impacts any company that uses AI-based solutions in its day-to-day operations.
On 2 August, a critical milestone in the implementation timetable will be reached, as the most stringent obligations for systems that affect citizens come into force.
For the first time, the Regulation establishes a common legal framework governing the development and use of artificial intelligence systems within the European Union. Its purpose is to ensure that these technologies are used safely, transparently and with due respect for individuals’ fundamental rights.
1. Entities subject to the Regulation
Although many organisations believe that this legislation only applies to technology companies or developers of AI tools, the reality is that it also affects the vast majority of companies that use artificial intelligence-based solutions in their day-to-day activities, such as ChatGPT, Copilot, Gemini, Claude or similar tools, customer service chatbots, CV selection and screening systems, data analysis platforms or automated content generation tools, among others.
2. Obligations for companies
– AI literacy
Since February 2025, companies have been legally required to ensure that any employee using AI has received the appropriate training to do so safely and in accordance with the rules established by the company.
It is therefore advisable for organisations to have internal procedures or policies in place governing the use of artificial intelligence and defining which tools may be used and under what conditions.
– Particular attention and care regarding the protection of personal data and confidential information
The AI Regulation does not replace the application of data protection legislation. It is essential to be aware that entering personal data or confidential information into AI environments that have not been authorised or audited by the company constitutes a breach of the applicable data protection or confidentiality requirements and may trigger the corresponding penalty regime imposed by the supervisory authorities.
The European Artificial Intelligence Regulation neither replaces nor removes existing obligations concerning the protection of personal data or the obligation to safeguard the confidentiality of corporate information.
Companies must be aware of what information is being entered into these tools, who has access to it and the terms and conditions offered by technology providers. They must also update their internal rules and data protection procedures to ensure data security.
– Additional controls when AI is used in Human Resources
The legislation pays particular attention to artificial intelligence systems that may influence decisions which significantly affect individuals.
Common examples include tools used to screen CVs, select candidates, assess employee performance, decide on internal promotions or support recruitment processes.
The European Union considers that these types of systems may create risks of discrimination, lack of transparency or unjustified decisions if they are not used appropriately.
For this reason, organisations using artificial intelligence tools in these areas must strengthen their control measures and ensure that relevant decisions continue to be subject to human oversight.
3. Penalty regime: an unacceptable financial risk
The European Union has established an unprecedented penalty regime to ensure that companies take this legislation seriously. Fines are not only aimed at AI developers, but also at companies that use these systems incorrectly:
• Up to EUR 35 million or 7% of total worldwide annual turnover for using prohibited AI systems, such as systems that covertly assess employee behaviour.
• Up to EUR 15 million or 3% of total worldwide annual turnover for failing to comply with obligations relating to transparency, data management or staff training.
• Up to EUR 7.5 million or 1% of total worldwide turnover for the preceding financial year for providing inaccurate, incomplete or misleading information to notified bodies or competent national authorities in response to a request.
It should also be noted that these penalties may be imposed in addition to those already provided for under the General Data Protection Regulation, amounting to up to EUR 20 million or 4% of annual turnover, where the privacy of personal data is infringed.
4. Recommendations for complying with AI legislation
In view of the obligations that are already in force and those that will continue to enter into force progressively over the coming months, organisations are advised to begin preparing for compliance with this legislation.
The most advisable measures include identifying the artificial intelligence tools used within the company, drawing up an internal AI use policy, training staff, reviewing potential data protection implications and implementing appropriate oversight and control mechanisms.
In conclusion, adopting AI Codes of Good Practice, together with the remaining oversight and control measures, will help reduce legal risks, avoid potential penalties and ensure that artificial intelligence is used safely, ethically and in accordance with the legislation currently in force.
At VACIERO, we are experts in drafting Artificial Intelligence Policies and Codes of Good Practice in accordance with the applicable legislation and the recommendations published by the competent European authorities.
For further information, please contact:
Susana García García
Director of the Compliance Department
sgarcia@vaciero.es