MADRID — Spain will pursue a 12-month program for artificial-intelligence development and oversight, Prime Minister Pedro Sánchez said Monday, arguing that companies controlling the technology cannot be left to regulate themselves.
The roadmap combines industrial policy with public safeguards. It includes a proposed AI “gigafactory,” new models developed with the Barcelona Supercomputing Centre for climate, health and energy applications, and stronger defensive cybersecurity measures aimed at advanced systems.
Growth with public conditions
Sánchez said data centers should meet demanding environmental and energy standards, protect national and European control over data and deliver benefits to the communities that host them.
His remarks place Spain inside a broader European effort to reconcile investment in computing infrastructure with rules governing privacy, discrimination, workplace disruption, misinformation and resource use. The policy challenge is not simply whether to regulate AI, but how to divide responsibility among model developers, deployers, regulators and the public institutions that purchase the technology.
The prime minister’s rejection of self-regulation does not by itself specify new legal duties. The roadmap’s impact will depend on legislation, procurement standards, enforcement powers and the way it interacts with the European Union’s existing AI framework.
A policy race
Governments are trying to build domestic capacity while a small group of companies controls much of the computing power and many frontier models. Spain’s plan treats that concentration as both an economic vulnerability and a regulatory concern.
The announcement also followed warnings from leaders of several U.S. AI laboratories that increasingly capable systems may require a slower and more controlled development path. Spain’s next year of rulemaking will show how those warnings translate into enforceable obligations.
National policy inside a European rulebook
Spain’s program will operate alongside the European Union’s risk-based AI regime, data-protection law and platform rules. A national government cannot replace those obligations, but it can shape enforcement, public procurement, research funding and the infrastructure on which models are trained.
That makes the roadmap a test of coordination. Agencies responsible for cybersecurity, privacy, competition, labor and consumer protection will need a common process so that an AI project is not approved for one purpose while creating an unmanaged risk in another.
The gigafactory question
A large computing facility can expand access to the chips and training capacity required for advanced models. Public support may reduce Europe’s dependence on a few foreign providers. It can also concentrate subsidies and environmental costs in a project whose commercial beneficiaries are unclear.
Conditions attached to financing will be decisive. The government can require transparent access for researchers and smaller businesses, cybersecurity controls, energy reporting and measurable public-interest uses. Without such terms, an industrial-policy project may reproduce the same concentration it was meant to challenge.
Data autonomy and useful models
Models for health, climate and energy need high-quality data, often held by public institutions. “Data autonomy” should mean more than storing information inside Spain. It requires rules about who may use the data, for what purpose, how long it is retained and whether public contributors share in the resulting value.
Health applications raise particularly strict privacy and safety questions. Climate and energy tools may influence public investment and essential services, demanding documentation, testing and a route to challenge harmful decisions.
From a speech to enforceable policy
The next 12 months should produce named agencies, deadlines, budgets and legal instruments. Voluntary principles can guide early projects, but they are not a substitute for inspection powers and remedies when a system causes harm.
Spain’s ambition is to present regulation and growth as mutually reinforcing. The credibility of that claim will depend on whether the state applies the same standards to publicly backed projects that it expects from private companies.

