The Regulation and Its Structure
The European Artificial Intelligence Regulation (EU 2024/1689), published in the Official Journal of the European Union (OJEU) on 12 June 2024 [2], marked a shift in approach to managing compliance for these types of systems. It is a human-centered regulation with a risk-based approach, which classifies systems and models according to the following framework.
Regarding the systems in the above diagram, four groups are established according to their use or characteristics (illustrative and non-exhaustive list):
Article 5 - Unacceptable Risk AI Systems (Prohibited):
▪️Systems that manipulate behaviour through subliminal, deceptive or manipulative techniques.
▪️Systems that exploit vulnerabilities due to age, disability, or social or economic circumstances.
▪️Social scoring systems that lead to detrimental or disproportionate treatment.
▪️Systems that predict the commission of crimes based solely on profiles or personality traits.
▪️Systems that create facial recognition databases through the indiscriminate collection of images.
▪️Emotion inference systems in the workplace or educational institutions.
▪️Biometric categorisation systems used to infer sensitive attributes (race, political opinions, religion, sexual
orientation, etc.).
▪️Real-time remote biometric identification systems for law enforcement purposes in publicly accessible spaces
(except for legal exceptions).
Article 6 / Annexes I and III - High-Risk AI Systems:
▪️Systems subject to conformity assessment under EU sector-specific legislation.
▪️Biometric identification and categorisation systems.
▪️Systems for the management or operation of critical infrastructure.
▪️Systems used for educational admission, evaluation or assignment.
▪️Systems for the selection, recruitment, evaluation, promotion or dismissal of workers.
▪️Systems that determine access to, or the conditions of, essential services (public and private).
▪️Systems used by competent authorities in the field of law enforcement.
▪️Systems employed in migration and border control procedures.
▪️Systems that support judicial decisions or influence democratic processes (elections or referendums).
Article 50 - AI Systems with Specific Transparency Obligations:
▪️Systems that interact directly with natural persons.
▪️Systems, including general-purpose systems, that generate synthetic audio, image, video or text content.
▪️Emotion recognition and biometric categorisation systems.
▪️Systems that generate or manipulate images, audio or video constituting deepfakes.
▪️Systems that generate or modify text intended to inform the public on matters of public interest.
AI Systems with Non-Existent/Minimal Risk or Not Subject to Specific Obligations under the Regulation:
▪️AI systems not falling within the scenarios covered by Articles 5, 6 and 50.
Regarding the models in the above diagram, two groups are established according to their capabilities and risk (illustrative and non-exhaustive list):
General-Purpose AI Models (GPAI):
▪️Models with capabilities below those specified for general-purpose AI models with systemic risk.
General-Purpose AI Models with Systemic Risk:
▪️Models with high-impact capabilities (where the cumulative amount of computing power used for their training,
measured in floating-point operations, exceeds 10²⁵), evaluated using appropriate technical tools and methodologies,
such as indicators and benchmarks.
▪️Models with capabilities or an impact equivalent to those established in the previous point, taking into account the
criteria laid down in Annex XIII (number of parameters, quality or size of the dataset, amount of computing power,
number of registered users, etc.).
Requirements and Obligations for High-Risk AI Systems
Within the sections corresponding to High-Risk AI Systems (Articles 6-49), a series of requirements and obligations are defined to demonstrate compliance, as illustrated in the following framework.
The compliance requirements set out in Articles 8 to 15 establish the minimum standards that systems of this nature must meet and include the following:
▪️Ensuring compliance with the applicable requirements.
▪️Establishing and maintaining a Risk Management System.
▪️Ensuring data quality and data governance.
▪️Maintaining technical documentation prior to deployment into production.
▪️Maintaining event records (logs).
▪️Providing information and instructions for use (transparency).
▪️Ensuring effective human oversight throughout the period during which the system is in use.
▪️Achieving an appropriate level of accuracy, robustness, and cybersecurity.
In addition, entities that develop, place on the market, or put these AI systems into service must comply with the obligations set out in Articles 16 to 27, including:
▪️Ensuring compliance with the requirements described above.
▪️Maintaining a quality management system.
▪️Retaining technical documentation and quality management system documentation.
▪️Retaining logs where these are under their control.
▪️Taking immediate corrective action whenever the system does not comply with the AI Act.
▪️Cooperating with the competent authorities.
▪️Appointing, through a written mandate, an authorised representative established within the EU with sufficient
authority to perform the required tasks.
▪️Complying with the obligations applicable to importers, distributors, and deployers.
▪️Defining responsibilities throughout the value chain.
▪️Conducting fundamental rights impact assessments.
What Will Authorities Review During an Inspection of a High-Risk AI System?
The Regulation establishes a supervisory framework supported by the national competent authorities and, where applicable, by notified bodies responsible for carrying out certain pre-market conformity assessment activities.
In Spain, the authority designated to oversee compliance in the field of Artificial Intelligence is the Spanish Agency for the Supervision of Artificial Intelligence (AESIA)[1], which will exercise inspection, verification, supervisory, and enforcement powers. In practice, however, market surveillance authorities, sector-specific regulators, and even the European AI Office may also become involved.
An inspection will not be limited to verifying whether certain documents exist. What will truly matter is the analysis performed to assess the consistency between the different pieces of evidence available. If the risk assessment describes a scenario that differs from the one reflected in the technical documentation, if performance metrics do not match those used during validation, or if human oversight exists only on paper, these inconsistencies are likely to be identified during the review.
Based on the specific requirements discussed in the previous sections, together with other general obligations under the AI Act, the key aspects that authorities would be expected to examine during an inspection of a High-Risk AI System include the following:
Timeline for Application and Amendments Introduced by the European AI Omnibus Regulation
The AI Act establishes a phased timeline for the application of its requirements. However, in a subsequent legislative measure, the European regulator adopted the Digital AI Omnibus Regulation (EU) 2026/1744[3] to simplify the implementation of harmonised AI rules, particularly those applicable to High-Risk AI Systems.
As a result, the consolidated implementation timeline is as follows:
| Date | Milestone |
| 1 August 2024 | Entry into force of the AI Act. |
| 2 February 2025 | Application of Chapters I and II, including the general provisions and the prohibitions under Article 5, with the exceptions introduced subsequently by the Omnibus Regulation. |
| 2 August 2025 | Application of Chapter III, Section 4; Chapter V (GPAI); Chapter VII; Chapter XII; and Article 78, with the exception provided for Article 101. |
| 2 August 2026 | General application of the AI Act and, among other provisions, the transparency obligations under Article 50. |
| 2 December 2026 | Application of certain new prohibitions introduced by the Omnibus Regulation. In addition, systems already placed on the market before 2 August 2026 have until this date to adapt the labelling requirements set out in Article 50(2). |
| 2 December 2027 | Application of Chapter III, Sections 1, 2 and 3, for high-risk AI systems classified under Article 6(2) and Annex III. |
| 2 August 2028 | Application of Chapter III, Sections 1, 2 and 3, for high-risk AI systems classified under Article 6(1) and Annex I. |
Conclusion
As mentioned at the beginning of this article, the AI Act establishes a new risk-based regulatory framework that introduces specific requirements and obligations for AI systems and, in particular, for the high-risk AI systems discussed in this article. Compliance requires not only the availability of the necessary documentation, but also the implementation of processes, controls, and evidence capable of demonstrating that these requirements are effectively in place and are reviewed over time, including after deployment into production.
Preparation for future inspections should therefore be approached as a continuous process of reviewing and maintaining compliance, rather than as a one-off exercise carried out in anticipation of a potential inspection.
Furthermore, as the technical capabilities of AI systems continue to evolve, the regulatory framework is also subject to change. The amendments introduced by the AI Omnibus Regulation provide a clear example of how the legal framework is adapting, while rapid technological developments may continue to create new scenarios and risks.
Organizations should therefore maintain ongoing monitoring of both regulatory developments and the evolving capabilities of AI systems, periodically reviewing their processes and controls to ensure that compliance remains current and effective.
References
[1] Spanish Agency for the Supervision of Artificial Intelligence (AESIA). (August 7, 2026). Ensuring Ethical and Responsible AI. Retrieved from https://aesia.digital.gob.es/es
[2] Official Journal of the European Union. (July 12, 2024). Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 (Artificial Intelligence Act). Retrieved from https://www.boe.es/buscar/doc.php?id=DOUE-L-2024-81079
[3] Official Journal of the European Union. (July 8, 2026). Regulation (EU) 2026/1744. Retrieved from https://eur-lex.europa.eu/legal-content/ES/TXT/PDF/?uri=OJ:L_202601744