
Spain’s AI Act Asks for Evidence, Not Intentions. How to Prove Runtime Evidence for AESIA
AESIA’s guides and the EU AI Act ask high-risk AI providers to prove risks are controlled, continuously. A runtime prompt firewall and automated red teaming produce that proof.
Reading Time: 5 minutes
TL;DR
- Spain AI Act compliance now has a concrete playbook: on 16 December 2025, AESIA, Spain’s AI supervision agency, published 16 practical guides, including 13 on technical requirements and a per-obligation checklist for providers and deployers of high-risk AI systems.
- The EU AI Act requires high-risk providers, under Articles 8 to 17, to run a lifecycle risk-management system, automatically log events, and design for accuracy, robustness, and cybersecurity. Annex III high-risk obligations apply 24 months after entry into force.
- Both ask for evidence that identified risks are being controlled, not a statement of intent. A runtime AI control produces that evidence as it enforces.
- AccuKnox’s prompt firewall analyzes prompts and responses, blocks sensitive data, restricts out-of-scope interactions, and keeps a complete audit trail. Automated red teaming supplies the adversarial-testing record the guidance expects.
- For the Spanish public sector, the same platform should map to the Esquema Nacional de Seguridad (ENS), which is mandatory for public bodies and their suppliers.
What the Spanish Guidance Actually Requires
AESIA is the Spanish Agency for the Supervision of Artificial Intelligence, a national market-surveillance authority. Its December 2025 release is not an abstract policy. It is 16 guides built out of the Spanish AI regulatory sandbox, the first of its kind in Europe, which tested 12 high-risk AI systems across six sectors including biometrics, employment, healthcare, and critical infrastructure. The guides cover risk management, data governance, transparency, and cybersecurity, and each comes with a checklist tied to a specific obligation.
The guides are not binding and do not replace the regulation. What they do is make the AI Act operational: they tell a provider what a conformity assessment and an impact assessment look like in practice, and what evidence a supervisor will expect. In applicable high-risk scenarios, an organisation has to show that identified risks are effectively controlled. Most AI deployments fall short on the word show. They have a policy document and no runtime proof.

EU AI Act, Article 9, with the Article 8 to 17 requirements for high-risk providers.
Source: Article 9: Risk Management System | EU Artificial Intelligence Act
The EU AI Act Asks for Controls that Run Continuously
The AI Act’s requirements for high-risk providers sit in Articles 8 to 17. Four of them describe a runtime control almost exactly.
- Risk management system across the full lifecycle, not a one-time assessment.
- Record-keeping, where the system automatically logs events relevant to identifying risks and substantial modifications.
- Accuracy, robustness, and cybersecurity by design.
- Human oversight, so a person can intervene in the system’s operation.
General-purpose models with systemic risk, trained above 10^25 FLOPs, carry an extra duty to run model evaluations and adversarial testing and to report serious incidents. The compliance clock is real: Annex III high-risk obligations apply 24 months after the Act’s entry into force, and prohibited-practice rules already applied at six months. A provider who waits for a supervisor to ask is starting the evidence trail too late.
A Prompt Firewall Turns an Assessment Finding into a Running Control
A red-teaming assessment tells you a model can be pushed off-topic or made to leak data. That is a finding. The AI Act wants the finding closed and the closure evidenced, continuously. A stateful prompt firewall is the layer that does both.
The firewall sits between users, applications, and the model as a policy-enforcement point. The firewall analyses prompts and responses. It blocks sensitive data from leaving, restricts out-of-scope queries, and records every decision. A public-sector chatbot meant for tax questions gets manipulated by prompt injection into producing political statements. That is the failure of the framework’s target. A firewall that enforces the chatbot’s boundaries refuses the response and logs the attempt. The refusal satisfies the robustness requirement. The log satisfies the record-keeping requirement.
| AI Act / AESIA obligation | What it demands | The AccuKnox control that produces the evidence |
|---|---|---|
| Risk management (Art. 9) | Lifecycle identification and control of risks | AI-SPM inventory plus continuous policy enforcement |
| Record-keeping (Art. 12) | Automatic logging of risk-relevant events | Prompt firewall audit trail of every prompt, response, and block |
| Robustness and cybersecurity (Art. 15) | Resilience to manipulation and attack | Out-of-scope and injection guardrails enforced inline |
| Adversarial testing (GPAI, systemic risk) | Evidence of adversarial evaluation | AI red teaming run on every model change |

The prompt firewall console, where each blocked prompt is both the enforced control and the logged evidence.
For a Spanish deployer, the evidence is generated as the control operates. An analyst does not assemble it the week before an audit. The EU AI Act compliance tooling overview covers the wider mapping.
Add ENS Mapping for the Spanish Public Sector
If the Spanish public-sector market matters to a vendor, the Esquema Nacional de Seguridad (ENS) is the framework to support. The ENS applies to the entire public sector and to the private companies that supply it, and it sets requirements for access control, confidentiality, integrity, traceability, authenticity, and availability. It was last updated by Royal Decree 311/2022, with detailed measures in the CCN-STIC 800-series guides.
Traceability and integrity are the ENS controls a runtime AI layer supports directly. The audit trail that satisfies the AI Act’s record-keeping duty is the same evidence an ENS assessment wants for traceability. A platform that already carries ENS mappings removes a procurement blocker for any Spanish public body and its suppliers.
Where to Start in the Spanish Market
For go-to-market, the Red Nacional de SOC, the national network of security operations centres led by CCN-CERT, is a public map of mature security organisations.
The requirement across all three frameworks is the same. Prove the risk is controlled, and prove it continuously. Assessment finds the gap. A runtime control closes it and leaves the record that a supervisor, an ENS auditor, or a bank’s risk team can read. Start with the assessment, then put the finding under enforcement.
See Why a Prompt Firewall Belongs Inline
This walkthrough covers what a prompt firewall enforces between users, applications, and the model, and why an enterprise needs one at runtime.
FAQ
What did AESIA publish in December 2025?
Sixteen practical guides for EU AI Act compliance: two informative, 13 on technical requirements, and a checklist per obligation. They are guidance, not a replacement for the regulation.
Does the EU AI Act require runtime controls specifically?
It names no product, but its high-risk requirements in Articles 8 to 17, lifecycle risk management, event logging, and robustness, describe controls that run continuously. A prompt firewall and red teaming satisfy them in practice.
What is the ENS and who does it apply to?
Spain's national security framework, regulated by Royal Decree 311/2022. It is mandatory for the entire public sector and for private companies that supply it.
How does a prompt firewall help with compliance evidence?
It enforces the model's boundaries in real time and logs every prompt, response, and block. The enforcement closes the gap, and the log is the record-keeping evidence an audit asks for.
Get a LIVE Tour
Ready For A Personalized Security Assessment?
“Choosing AccuKnox was driven by opensource KubeArmor’s novel use of eBPF and LSM technologies, delivering runtime security”

Golan Ben-Oni
Chief Information Officer
“At Prudent, we advocate for a comprehensive end-to-end methodology in application and cloud security. AccuKnox excelled in all areas in our in depth evaluation.”

Manoj Kern
CIO
“Tible is committed to delivering comprehensive security, compliance, and governance for all of its stakeholders.”

Merijn Boom
Managing Director




