
AI customer service in Spain: two rules that constrain it at the same time
Corpshore Spain editorial team · · 8 min read
In summary: since 2 August 2026 the transparency obligations in Article 50 of the EU AI Act apply, requiring people to be told they are interacting with an AI system. On top of that, Law 10/2025 prohibits support delivered exclusively by automated systems and guarantees human intervention on request.
Through 2025 and much of 2026, the idea of replacing customer service with AI agents was sold with considerable enthusiasm. In Spain, two separate rules have narrowed that idea within months, and they are worth reading together because they overlap.
Neither prohibits using artificial intelligence in customer service. What they do is define how, and both carry concrete design consequences.
What has the EU AI Act required since August 2026?
Regulation (EU) 2024/1689 applies in stages. The prohibitions arrived in February 2025 and the obligations on general purpose models in August 2025. Since 2 August 2026, the Article 50 transparency obligations apply generally.
In practice that means people must be told they are interacting with an artificial intelligence system, and synthetic content generated by such systems must be labelled. It applies squarely to conversational customer service assistants.
It is worth noting what is not yet in force, because there is considerable confusion. The obligations for high-risk systems under Annex III were deferred to 2 December 2027, and those under Annex I to 2 August 2028, through the digital omnibus regulation. Deferred does not mean non-existent: it is worth designing with them in view.
What does the customer service law add?
Law 10/2025 prohibits the exclusive use of automated or artificial intelligence systems as the means of support, and guarantees human intervention from the outset and at any point in the process if the user requests it.
Its scope is narrower than the European regulation's: it applies to companies with 250 or more employees or more than 50 million euros in turnover, and to providers of basic services of general interest regardless of size. The adaptation period ends on 28 December 2026.
Read together, the two rules say something fairly clear: you may use an AI agent, you have to say that it is one, and it cannot be the only route available to someone asking to speak to a person.
So what can be automated?
A good deal, in fact. Repetitive status enquiries, product information, appointment management, order tracking and first-line triage of an incident work well with an automated agent and cut volume significantly.
What changes is the design of the exit. The system has to hand over to a person without friction and without making the customer repeat what they have already explained, and that person has to exist and be available during the hours the customer contacts you. An automation that only works if nobody asks for a human is not an automation, it is a barrier.
The pattern both rules point towards is the one operational experience already recommended before either existed: automate predictable volume, keep human capacity for the rest, and measure how often customers ask to escape the system, because that indicator says more about deployment quality than the containment rate does.
What does this mean for the project's business case?
It means the business case for automation cannot be built on removing the human team entirely, because that removal is not lawful for companies within the scope of Law 10/2025 and is not prudent outside it.
The realistic business case is different and still good: cut the volume reaching people, shorten waiting times, and let the human team concentrate on cases that need them. It is a smaller saving than a sales presentation promises and considerably more durable.
It is also worth budgeting for the human supervision layer over the AI itself, which is real work: reviewing responses, spotting failure patterns and correcting them. A system deployed and left alone degrades, and in a regulated sector that degradation has consequences.
What should you demand from a provider selling you AI agents?
First, an explanation of how they meet the obligation to tell users they are interacting with an AI system, and where that appears in the flow.
Second, how handover to a person works, during which hours people are available, and what happens outside those hours.
Third, what human supervision the system carries, how often, and who does it. If the answer is that the system supervises itself, you are buying a future problem.
And fourth, be sceptical of any proposal whose return depends on eliminating human support entirely. In Spain, for a significant part of the market, that proposal is no longer lawful.
This article is general information, not legal advice. We work alongside your legal advisors, not in their place.