When the European Union's AI Regulation – the Artificial Intelligence Regulation – was passed, many of us felt that we finally had clear rules about what could and could not be done with artificial intelligence.
However, anyone who has worked with technology regulations knows that a regulation rarely answers all the questions. The text establishes principles, obligations and risk categories, but leaves numerous spaces open. What exactly does it mean to properly monitor a system? How should the use of generative AI in an office be documented? What measures are reasonable to avoid bias or hallucinations?
The answer begins to be found outside the Regulation itself.
Soft law also matters
In Law we are used to distinguishing between mandatory rules and recommendations without binding legal effects. But in the technological field this border is much more diffuse. The guides, circulars, codes of conduct and recommendations end up becoming authentic survival manuals.
They do not replace the law, but they help interpret it. They anticipate the judgment of supervisors, show what practices are considered diligent, and sometimes serve to assess whether an organization acted responsibly.
In terms of artificial intelligence, this informal normative production is growing at high speed.
The White Paper on the Legal Profession: an x-ray of what is already happening
One of the most useful documents published in Spain is the White Paper on the use of AI in the Legal Profession, presented on January 30, 2026 by the General Council of the Spanish Legal Profession together with the Illustrious Bar Association of Valencia and the University of Valencia.
It is not a futuristic text, but a deliberately realistic document. It starts from a fact that is difficult to ignore - according to the CGAE, around 60% of legal services professionals already use applications that incorporate artificial intelligence - and sets three very specific objectives: analyze to what extent AI has already been adopted in Spanish law firms, identify its uses and risks, and offer a framework to integrate it without losing legal criteria, ethics or professional responsibility.
Their conclusions sound like common sense, and that is precisely why it is worth keeping them in mind: AI is a complement and not a substitute for the lawyer; every tool must be subject to informed, transparent and explainable human supervision; and training in digital skills stops being an added value and becomes a basic condition of the exercise. It also warns of the risks that we cannot ignore: algorithmic biases, opaque systems, data protection and confidentiality problems, and even the progressive loss of basic legal skills when we delegate without understanding.
Basically, it is a translation of the AI Regulations into the everyday language of an office.
CGAE Circular 3/2026: hallucinations already have deontological consequences
Another document that deserves careful reading is Circular 3/2026 of the General Council of Spanish Lawyers, approved by its Plenary Session in April 2026.
Until recently, many professionals viewed incorrect responses from generative AI as a simple technical annoyance. The Circular introduces a different perspective: if a lawyer incorporates erroneous information generated by an AI tool into a writing without checking it, the problem ceases to be technological and becomes an issue of professional responsibility.
In reality, the Circular does not create new obligations. What it does is remind us that the duty of diligence, professional secrecy and the obligation to verify the content of our writings continue to exist even if we use the most sophisticated tools on the market.
Artificial intelligence can make mistakes. And we continue signing.
The AESIA: observe before it sanctions
There is also an actor that will probably gain prominence in the coming years: the Spanish Agency for the Supervision of Artificial Intelligence, based in A Coruña.
Many lawyers will only go to it when sanctioning files appear. It may be a mistake.
The guides, recommendations and informative materials that the Agency publishes can become a very valuable source to understand how it will interpret certain obligations of the Regulation, especially in matters related to risk assessment, transparency or protection of fundamental rights.
Reading the person who will supervise compliance in time is usually a good legal strategy.
The Digital Omnibus and the rules that are still being written
Added to all this is the so-called Digital Omnibus, a set of European proposals aimed at simplifying and adjusting part of the existing technological regulation. The European Commission presented it in November 2025, and in May 2026, Parliament and the Council reached a provisional agreement to simplify the AI Regulation, which includes, among other things, postponing some obligations for high-risk systems until December 2027.
It is still pending formal adoption, but it demonstrates something important: the AI Regulation is not a finished product. Just as with the GDPR, we will need years of guidelines, interpretative criteria, and sector-specific documents to truly understand how it should be applied.
Perhaps we should start studying it differently.
Many lawyers were trained to believe that knowing the law and case law was sufficient. In artificial intelligence, that is no longer enough.
Today, it is important to read regulations, yes, but also guidelines, white papers, codes of conduct, circulars, technical standards, and recommendations from supervisory authorities.
In my opinion, the AI Regulation establishes the rules of the game. But it is "soft law" that begins to explain how the game is played.

