On August 2nd, Spain's AI supervision agency (AESIA) got the power to actually fine businesses over a rule that's been sitting quietly in EU law since February 2025: anyone using an AI system has to understand it well enough to explain what it does and where it can go wrong. Not "review everything it produces." Understand it.
If you don't run a business in the EU, none of that law reaches you directly. Keep reading anyway. Underneath it sits a bigger question: is it legal to let an AI act without anyone checking first? That isn't really a Spanish question. It's the question every serious AI rulebook is being forced to answer this year, and watching how Spain answered it tells you roughly where your own rulebook is heading, whichever one eventually lands on your desk.
What Spain actually did
The EU's AI Act only mandates human oversight for "high-risk" systems: eight narrow categories in Annex III, covering hiring screens, credit scoring, biometric surveillance, and essential public services. Ordinary business automation, an agent that drafts invoices or sends quotes, isn't on that list. So the law was never going to force every EU business to review every AI output line by line.
What it does require, under Article 4, is "a sufficient level of AI literacy": you, or whoever runs the tool day to day, actually understanding what it does. Until this month that was mostly theoretical. On August 2nd, AESIA gained full sanctioning power to enforce it, alongside the disclosure rules we already covered. A single complaint is enough to open a file, whatever the business's size. And what they'd actually ask for isn't proof you checked every output: it's proof you understood the tool well enough to know when you should have.
The line every rulebook draws in the same place
Spain isn't alone in drawing it there. In the US, Colorado's revised automated-decision law (effective January 2027) requires a trained human with real authority to override any AI decision about someone's job, housing, credit, insurance, health care, or access to a government service. From what's written so far, it doesn't appear to reach ordinary business paperwork either. Japan takes the opposite enforcement shape: its AI guidelines ask for the same human-oversight habit, but as expectation, not statute: no fines attached, at least not yet, just a framework built to be followed voluntarily.
Three countries, three different amounts of teeth: real fines already active in Spain, fines arriving on a fixed date in Colorado, no fines at all yet in Japan. But the line lands in the same place every time: decisions that affect a person's job, money, or access to something they need get a mandatory human check. Everything else (the invoicing, the quoting, the routine admin) is left to you to supervise as well as you judge is needed. Nobody is regulating your invoice drafts. Understanding the tool well enough to catch its mistakes is still entirely on you.
The bigger reason to check anyway
Here's the part that holds no matter which rulebook applies to you: an AI agent has no legal existence of its own, in Spain or anywhere else. No jurisdiction currently treats an AI system as a legal person, which means whatever it does under your name is, legally, something you did.
Picture an autónoma consultant in Spain who lets an invoicing agent generate bills automatically from her logged hours. One month it double-counts a week she billed to two clients for overlapping project work, and the inflated invoice goes out with nobody looking first. Nothing about that was illegal anywhere: no rule told her to check it. But when the client calls confused, it isn't the agent that apologizes and issues the credit note. It's her. (Spain happens to reward catching your own mistake first: a voluntary correction filed before anyone else notices removes the penalty entirely, and most tax systems, wherever you are, work on some version of the same logic.)
What this doesn't cover
If you're using AI to decide something about a person rather than handle your own paperwork (screening candidates, scoring credit, anything that shows up on these high-risk lists), human oversight stops being a good habit and becomes a hard legal requirement, in Spain, in Colorado, and increasingly everywhere else. That's a different, heavier conversation, worth an actual lawyer's time wherever you are.
Do this one thing today
Write one paragraph (not a policy, a paragraph) describing what your AI tool actually does, what it reads to make its decisions, and the one way you've seen it (or could imagine it) getting something wrong. Nobody, anywhere, is asking for more than that yet. It's also exactly the five minutes of thinking that would have caught the double-billed invoice before it went out. That's the whole idea behind running AI with a human approval step built in: not red tape, but the one habit that keeps an agent honest. It's the same habit we build into every agent we run at Ausavia: nothing goes out under a client's name without someone tapping approve first.
Clara F.