September 22, 2026
The EU AI Act: what your company must do, and from when
July 2026's Digital Omnibus pushed the high-risk obligations back to 2 December 2027, but it did not push everything back: the AI literacy duty has applied since February 2025 and the transparency duties since 2 August 2026. Here is the current timeline, why HR is the most exposed function, and the fines of up to €35 million or 7% of worldwide turnover.

If you have read that «the AI law has applied to companies since August 2026», that «everything has been pushed back to 2027» and that «Spain still has no law», you have read three things that are all true and mutually incompatible. The problem is not the reporting: the regulation applies in stages, and in July 2026 those stages moved again.
This article brings the timeline up to date as of 22 September 2026 and answers the practical question: what you must do today, what you will have to do and from when, and why a company that develops no technology at all —but uses AI-powered tools to hire or appraise people— falls squarely within the scope.
The essentials in one minute
- The law is Regulation (EU) 2024/1689, directly applicable: no Spanish statute is needed for it to bind you.
- The Digital Omnibus (Regulation (EU) 2026/1744, in force since 27 July 2026) moved the Annex III high-risk duties from 2 August 2026 to 2 December 2027.
- What was not postponed: AI literacy for your staff (Art. 4), binding since 2 February 2025, and the transparency duties of Article 50, enforceable since 2 August 2026.
- Using AI to select, appraise, promote or dismiss is high-risk (Annex III, point 4). It is the door most smaller companies come in through.
- Fines of up to €35 million or 7% of worldwide turnover. For SMEs and start-ups the lower of the two figures applies (Art. 99.6).
- Spain's AI governance bill has not been passed yet: it is still before Parliament. The supervisor that can already act is AESIA, from 2 August 2026.
Two different laws that everyone confuses
The first is European and already binds you. Regulation (EU) 2024/1689, known as the AI Act, was published in the Official Journal of the European Union on 12 July 2024. It is a regulation, not a directive: it applies directly to every Spanish company with no need for national transposition. Waiting for «the Spanish law» before starting to comply is the same mistake as waiting for the digital time tracking decree.
The second is Spanish and does not exist yet. The Organic Bill on the sound use and governance of Artificial Intelligence, approved by the Council of Ministers on 26 May 2026, is still going through Parliament. It creates no new duties: it designates the supervisory authorities, regulates regulatory sandboxes and sets out the national penalty procedure. The duties themselves already come from the European regulation.
And there is a third instrument almost nobody has read, which is the one that changes everything: Regulation (EU) 2026/1744, the so-called Digital Omnibus on AI, published in the Official Journal on 24 July 2026 and in force since the 27th. It rewrote the timeline because the harmonised standards and the notified bodies were not ready to carry the high-risk regime from August 2026.
Be careful with anything written before the summer
Much of the commentary circulating on the AI Act was written before 24 July 2026 and assumes that the high-risk regime applies from 2 August 2026. That is no longer the case. If the piece you are reading does not cite Regulation (EU) 2026/1744, its timeline is out of date.
The current timeline after the Digital Omnibus
These are the dates in force. Note that the postponement is selective: it touches the high-risk regime but leaves untouched both the duties already in force and the transparency ones.
What applies, and from when
- 2 February 2025 (already in force): the prohibited practices of Article 5, and the AI literacy duty of Article 4.
- 2 August 2025 (already in force): obligations for general-purpose AI (GPAI) models and the governance rules.
- 2 August 2026 (already in force): the transparency duties of Article 50 and the market surveillance rules. It is also the date from which AESIA can move from inspecting to fining.
- 2 December 2026: further prohibited practices are added to Article 5.
- 2 August 2027: national regulatory sandboxes operational, and the end of the transitional regime for certain GPAI models.
- 2 December 2027: full obligations for Annex III high-risk systems —employment, education, essential services, justice— previously due in August 2026.
- 2 August 2028: Annex I high-risk systems, those embedded in already-regulated products.
The right way to read the delay is not «I have fifteen more months to do nothing», but that you now have fifteen months to do properly a job —inventorying the systems, documenting them and training your staff— that until two months ago had to be improvised in a matter of weeks.
The four risk tiers, and where your company sits
The regulation does not govern the technology but the use you put it to. The same tool can be minimal-risk in one context and high-risk in another, depending on how you configure it.
The risk pyramid
- Unacceptable risk: banned since February 2025. Social scoring of individuals, real-time remote biometric identification in public spaces for law enforcement, emotion recognition in the workplace and in education, and the exploitation of vulnerabilities.
- High risk: allowed, but with demanding duties on documentation, risk management, data quality, event logging and human oversight. This is where employment and worker management sit.
- Limited risk: transparency duties. If someone is talking to a chatbot they must know they are not talking to a person; synthetic content must be marked in a machine-readable format.
- Minimal risk: the vast majority of everyday tools —spell checkers, spam filters, internal search— with no specific duties beyond Article 4.
Emotion recognition at work is banned outright
It is not high-risk: it is one of the practices directly prohibited since February 2025. Any tool claiming to infer your staff's emotional state, stress levels or engagement from their face, voice or keystrokes falls into the category carrying the regulation's heaviest fine. The only exceptions are medical and safety-related.
Why HR is the most exposed function
If your company ends up inside the high-risk regime, the most likely way in will not be the product it sells: it will be how it hires and how it appraises. Annex III devotes its point 4 to employment and worker management.
AI systems intended to be used for the recruitment or selection of natural persons, in particular to place targeted job advertisements, to analyse and filter job applications and to evaluate candidates; and to make decisions affecting terms of work-related relationships, the promotion or termination of contractual relationships, to allocate tasks, or to monitor and evaluate the performance and behaviour of persons.
Read that with your own operations in mind. A CV filter that ranks applications, a tool that scores video interviews, a system that allocates shifts or tasks based on personal traits, or a dashboard that appraises performance with a predictive model: all of it is high-risk from 2 December 2027.
What deploying a high-risk system will require of you
- Using it in line with the provider's instructions and not repurposing it.
- Meaningful human oversight: a person with the competence and the actual authority to review, qualify or reverse the decision. An automatic rubber stamp does not count.
- Monitoring the quality of the input data feeding the system, to the extent that you control it.
- Keeping the logs the system generates automatically for at least six months.
- Informing staff and their legal representatives before putting a high-risk system to work in the workplace.
- Informing the people affected that they are subject to a high-risk system when decisions are taken about them.
- Reporting serious incidents to the provider and to the market surveillance authority.
None of these duties is entirely new. Article 22 of the GDPR already restricts decisions based solely on automated processing, and Article 64.4.d of Spain's Workers' Statute has since 2021 given works councils the right to be informed of the parameters and rules of algorithms affecting working conditions. What the AI Act adds is a far heavier penalty regime.
The duty that already binds you even with nothing high-risk
It is Article 4, and it is the one most companies breach without realising, because it does not depend on size or sector. If your organisation uses any AI system at all —including a generative assistant to draft job adverts— you are a «deployer», and that duty has applied to you since 2 February 2025.
The Digital Omnibus softened the wording: where it used to say companies must «ensure» a sufficient level of AI literacy, it now says they must «take measures» to support it, having regard to technical knowledge, experience, training and the context of use. It remains an enforceable duty, but it is judged proportionately: nobody expects the same from a four-person practice as from a multinational.
How to evidence that you comply with Article 4
- An inventory of the AI tools used across the company, and of who uses them.
- A written acceptable use policy: what may be done with those tools, what may not, and what data must never be fed into them.
- Training proportionate to the role: someone who only drafts text does not need what someone screening applications needs.
- A record of the training delivered, with dates and attendees. With no paper trail, an inspection will treat it as never having happened.
- Periodic review, because tools change what they do without warning.
Transparency: what has been enforceable since August 2026
Article 50 did come into force on 2 August 2026, and it touches very everyday situations. The underlying rule is simple: nobody should find out by accident that they are dealing with a machine.
Transparency duties now in force
- If a person interacts with an AI system —a chatbot on your jobs portal, say— they must be told, unless it is obvious from the context.
- Synthetic content generated or manipulated by AI must be marked in a machine-readable format that allows its artificial origin to be detected.
- Deepfakes must be disclosed as such.
- AI-generated text published to inform the public on matters of public interest must be labelled, unless it has been reviewed by a human who takes editorial responsibility for it.
- Emotion recognition and biometric categorisation systems must inform the people exposed to them —wherever their use is not banned outright, as it is in the workplace.
Penalties: what it costs and who imposes them
Article 99 of the regulation sets three tiers, and in each case the higher of the fixed figure and the percentage of the previous year's worldwide turnover applies.
The three tiers of Article 99
- Prohibited practices (Article 5): up to €35 million or 7% of worldwide turnover.
- Breaching the other obligations, including those of the deployer of a high-risk system: up to €15 million or 3%.
- Incorrect or misleading information supplied to the authorities: up to €7.5 million or 1%.
- For SMEs and start-ups, paragraph 6 flips the rule: the lower of the two figures applies, not the higher.
- The amount is set having regard to the size of the company, the gravity and duration of the breach, and whether it cooperated with the authority.
In Spain the supervisor is the Spanish Agency for the Supervision of Artificial Intelligence (AESIA), based in A Coruña, which since 2 August 2026 can both inspect and fine. It does not act alone: it shares competence with the data protection authority, the Bank of Spain, the securities regulator and the consumer authorities, depending on the sector. The Spanish bill fills in the penalty procedure, but the amounts already come from the European regulation.
What to do now, with fifteen months in hand
A realistic checklist for a smaller company
- Take inventory. List the AI tools already in use, including the ones individual departments signed up for on their own. Without an inventory there is nothing else to do.
- Classify each use, not each tool. Ask what you use it for: drafting a job advert is minimal risk; ranking applicants by likelihood of success is high risk.
- Ask your providers for documentation. If an HR tool will end up being high-risk, the provider must give you the instructions for use and the technical documentation. If they cannot produce them today, that tells you something.
- Write the use policy and train your staff, which is the only part already enforceable today.
- Review anything doing emotion recognition. If an attendance or productivity tool promises to detect moods, drop it: that is a prohibited practice.
- Inform the workers' legal representatives, as Article 64.4.d of the Workers' Statute already requires for algorithms affecting working conditions.
- Document your decisions. Compliance is evidenced through documentation: the inventory, the use policy, the training records and the providers' instructions.
Keeping it documented: where Horalia helps
Compliance with this regulation is not demonstrated with intentions but with documents. The day AESIA knocks it will ask for the inventory of tools, the use policy signed by your staff, the record of the training delivered and the instructions from the provider of each system. It is the same kind of folder a labour inspection already asks you for.
And that file rarely fails on the drafting: it fails on where it ends up stored. It gets spread across shared folders, email threads and paper signatures, and the day someone asks for it nobody knows which version is current or who signed it.
Horalia's document management exists to have that folder built before anyone asks for it.
Why it stops being a problem
- Classification by type: contracts, payslips, training and policies are categories in their own right, so your AI use policy and your training records do not get mixed in with everything else.
- Assignment in a single click to a person, a team or a location: the policy reaches the whole workforce without emailing it out one by one.
- Advanced electronic signature, carrying the same legal weight as a handwritten one under the eIDAS Regulation and Spain's Law 6/2020, and uniquely linked to the person signing.
- Tamper detection: any change made after signing is detectable, so you can prove the document you produce is the one that was signed.
- Search with filters and tags: you find any document in seconds, without having to remember which folder you filed it in.
- Preview without downloading, so showing a document does not mean handing out copies.
That way, when they knock, there is nothing to prepare: it is already signed, filed and one click away. You can explore Horalia or try it for free.
Conclusion
The Digital Omnibus buys you time, not an excuse: the Annex III high-risk regime does not arrive until 2 December 2027, but the AI literacy duty has applied since February 2025 and the transparency duties since August 2026, and AESIA can already impose fines. If you use AI to hire, appraise or allocate work, you have fifteen months to inventory, classify and document —and the part already enforceable today, the use policy and the training, is precisely the cheapest to get done. As with time tracking, the companies that arrive with their homework finished will have nothing to do that day.

