At the beginning of August 2025, a decisive chapter for artificial intelligence in Europe comes into force. This is Article 5 of the European Regulation on Artificial Intelligence (RIA), which establishes prohibited AI systems, such as those for remote biometric identification in real time in public spaces. This is not science fiction, it is legislation and it comes with a sanctioning regime under its arm.
Tot i que Espanya encara no ha aprovat la seva pròpia Llei d’IA, l’Agència Espanyola de Protecció de Dades (AEPD) ja ha deixat clara la seva posició: continuarà sent l’autoritat competent per supervisar el tractament de dades personals, fins i tot quan s’utilitzin mitjançant sistemes d’IA. I és que, malgrat que encara no tingui formalment el títol d'»autoritat de vigilància del mercat» en aquesta matèria, l’AEPD ja està preparada per actuar en defensa del dret fonamental a la protecció de dades.
What does this mean for businesses and organizations, whether large, small, or medium-sized? That AI is no longer just a technological opportunity. It is also a legal responsibility. If your company uses or plans to use AI-based tools—from automated customer service systems to data analytics or speech recognition solutions—you need to start taking action.
The AEPD recommends being ready. It's not just about complying when the law comes into full force, but also about being proactive and ensuring that the systems you use comply with current data protection regulations from now on. This involves reviewing suppliers, demanding transparency about how the algorithms you use work, and ensuring that there is no processing of personal data through systems that could be considered high-risk or, worse yet, prohibited.
It is also worth assuming that the demands will not stop there. The AEPD plans to strengthen its internal capacities, which will translate into greater surveillance and possible sanctions for those who ignore its warnings.
Small and medium-sized businesses, as always, are in a delicate position. They don't have the muscle of large corporations, but the law makes no distinction. The key is to act with (human) intelligence before artificial intelligence becomes a legal problem.
Because adapting in time is not an option. It's the difference between taking advantage of AI... or suffering from it.





