← All posts
29 May 2026
regulation

🇪🇸🔐🏷️ Regulation Friday: AI Law, Big Sleep and mandatory labeling

€35 million fines quoting the Pope. A Google agent that finds vulnerabilities before humans do. And a European law that from August will require labeling all AI-generated content. Three stories that seem disconnected but share the same thread: artificial intelligence is no longer the Wild West. Rules, guardians, and labels are arriving.

🇪🇸 Spain passes its AI Law: €35M fines and an encyclical as moral framework

On Tuesday, May 26, the Council of Ministers approved Spain's AI Law bill. The regulation adapts the European AI Act (approved by the European Parliament in March 2025) to Spanish law, and it does so with an approach that has surprised everyone.

Spokesperson Minister Elma Saiz and Minister of Digital Transformation Óscar López presented the law with three pillars: algorithm transparency, accountability of directors at AI provider companies, and protection of minors. But what drew the most attention was the explicit reference to the Pope's encyclical on AI, published just 24 hours earlier.

López called the owners of big tech companies "great techno-oligarchs" who don't want "regulation, data protection, or protection of minors," and positioned the Vatican document as inspiration for the law's ethical framework. Sanctions range from €500,000 or 0.5% of worldwide revenue in mild cases, up to €35 million or 7% of the infringing company's global business volume in the most serious cases.

My take: A Spanish law citing a papal encyclical. In 2026. If someone tells you AI regulation is just a technical topic, show them this story. Technology has been leaving neutrality behind for a while — and governments and institutions are beginning to agree that it needs an ethical framework, not just a technical one.

From laws that penalize violators, to technology that prevents before it happens.

🔐 Google Big Sleep: the agent that finds bugs before they become exploits

Google presented Big Sleep, an AI cybersecurity agent capable of detecting critical vulnerabilities in software. The name is no accident — it's the spiritual successor to Project Zero, Google's security team that for years found the most serious bugs in the industry. Only now, there are no humans at the wheel.

Big Sleep analyzes source code looking for known vulnerability patterns — buffer overflows, memory leaks, SQL injections — and does so at a speed and scale that no human team could match. Google says it has already found real vulnerabilities in third-party software that human security teams had overlooked.

The approach is smart: it's not about replacing security auditors, but augmenting their capacity. Big Sleep finds the problem, generates a detailed report, and leaves the decision of how to patch it to humans. It's assisted cybersecurity, not autonomous — but the leap is enormous.

My take: Big Sleep seems more important than it looks at first glance. Because if an AI agent can find vulnerabilities in others' code, it can also find them in its own. And that means the next generation of software could be significantly more secure — not because humans have improved, but because AI has our backs.

And while security agents find bugs, European regulators set a date for a new requirement.

🏷️ August 2026: the EU requires AI labeling

The European Commission just opened a public consultation on the guidelines that flesh out the AI Act's transparency obligations. And the key date is August 2, 2026.

From that day onward, providers of AI systems will be required to inform people when they interact with AI systems (chatbots, virtual assistants) and to label certain AI-generated or AI-manipulated content — such as deepfakes or synthetic images — via metadata or machine-readable marks.

This isn't optional or a recommendation. It's law. Any company publishing AI-generated content without properly labeling it faces the sanctions provided for in the regulation. And not just big tech companies: also agencies, content creators, and small businesses using tools like ChatGPT, Midjourney, or any image or video generator.

My take: August seems far away, but it's not. If you use AI to generate content for your business — text, images, videos — you need to have a labeling plan before that date. Not because it's complicated, but because not doing it can be costly. And because, honestly, transparency benefits everyone: users, who know what's real and what's not, and the businesses that play fair.

A law citing the Pope, an agent protecting software, and regulation demanding transparency. AI is no longer an experiment — it's an industry. And like every industry, it needs rules. The good news is that, for the first time, they're starting to be written.

— Max

Related articles
Enjoyed this?
I build AI systems for businesses.
🤖 This analysis was compiled and written with AI assistance, reviewed and approved by Max.
🎁 Free content
10 AI Prompts for Your Business
Free download: 10 ready-to-use AI prompts. Marketing, copy, support, organization.
Download free →
— Max · 29 May 2026🦋 Share on Bluesky
© 2026 Maksipi · 💼 Services · 🏨 HostFlow · 🛒 Shop · 📱 Telegram · 🦋 Bluesky
Content compiled and written with AI assistance · Reviewed and approved by Max.
🇪🇸 Español · 🇺🇦 Українська · 🇷🇺 Русский