On August 2, the transparency obligations regulated by the European AI Regulation, also known as the AI Law, came into force. Despite this, some large Spanish companies still have to adapt to this new regulation. And 31.7% of CEOs of large companies claim that they have not yet implemented measures to respect this law.
This is the conclusion of Entelgy’s latest study, The BusinessTech Consultancy, carried out with 300 Spanish managers, to find out the perceptions of the leaders of large companies. The obligations applicable to high-risk systems, such as those used in personnel selection, biometrics or solvency assessment, will be postponed until December 2027 as soon as the recently approved Digital Omnibus on AI is published in the Official Journal of the European Union.
Transparency obligations maintain their effective date on the same date, including mandatory marking of synthetic content for new systems. In addition, there are two other obligations that have been in force for more than a year and that, however, many companies still do not comply with. On the one hand, the obligation of the AI Law to guarantee AI literacy of staff, in force since February 2025 and applicable to any company that uses AI systems, not only those who develop them. On the other hand, the regime applicable to general purpose models, in force since August 2025 and which contemplates sanctions of up to 15 million euros or 3% of global turnover.
Added to this is that prohibited AI practices, such as social scoring, covert manipulation, or unauthorized biometrics, can reach 35 million euros or 7% of global turnover, the highest ceiling in the entire Regulation. In contrast to the most lagging organizations, among the almost 70% of companies that have already adopted measures to adapt to the AI Law, the most notable actions are training employees in the responsible use of AI (70.7%), followed by the creation of an AI governance committee or person (47.3%) and the establishment of internal policies for its use (33.7%).
False myths that threaten senior management
Although many companies have already begun to prepare for the entry into force of the AI Law, there is still a lot of confusion about what the law really requires in the short term. Against this backdrop, Entelgy experts warn of several false beliefs that are widespread in management committees and that can lead to serious non-compliance.
1. Wait for local regulations to start complying. We must not confuse the Organic Law Project, which is still being processed in Congress, with the framework that really obliges companies today. The European Regulation is directly applicable, it does not require local regulations to come into force, and its compliance is already under the supervision of the Spanish AI Supervision Agency (AESIA).
2. The provider’s privacy contract protects legally. The risk is not determined by the tool, but by its use. Using any AI to, for example, screen candidates in a selection process makes the system “high risk.” The data contract protects privacy, but does not exempt the company from its risk classification.
3. The postponement until 2027 eliminates the urgency. Although the full conformity assessment is delayed, there is an urgent need to identify and classify which systems fall into the high-risk category. In addition, the obligation for those who operate these systems to have creditable AI literacy has been present since February 2025.
The data contract protects privacy, but does not exempt the company from its risk classification
4. Basic virtual assistants do not require additional measures. On August 2, 2026, the obligation to warn the user that they are interacting with artificial intelligence comes into force without any delay. A conversational FAQ that omits this notice will violate the law from that day on, even if its overall risk is minimal.
“There is a false sense of relief in the market. The new calendar of the AI Law does not stop transparency obligations or the urgency of classifying high-risk systems. Companies must assimilate that compliance with the AI Law is not solved simply by purchasing software with secure licenses. It is an organizational challenge that requires own criteria, clear policies and immediate action by management committees,” says Alfredo Zurdo, Head of Digital Change at Entelgy.
