Compliance 2026: Algorithmic Auditing and High-Risk AI
In this article
Key Takeaways
- Algorithmic discrimination
- Workers' rights crime
- AI Audit
- Digital Compliance
A hiring algorithm that systematically discards candidates on grounds of gender or ethnicity can lead to the offence of employment discrimination (art. 314 CP) if equality is not restored and the damage is not repaired after an administrative requirement or sanction. Liability attaches not to the machine but to the people who knowingly deploy it. Effective human oversight and a documented algorithmic audit are the first barrier against prosecution.
Need help with your case? Talk to a criminal defence lawyer at Alonso Sala.
The EU AI Act creates no criminal offences, but its obligations for 'high-risk' AI systems (HR, Banking, Insurance), applicable from 2 December 2027 (2 August 2028 for AI embedded in regulated products), shape a new landscape: companies using them without proper human oversight face legal risks. What until recently was a purely technical or reputational issue — a biased screening model, an opaque scoring engine — can now end up being examined in a criminal courtroom.
What 'High Risk' Means in Practice
The AI Act reserves its strictest regime for systems that decide on people's access to essential goods: recruitment and personnel management tools, credit scoring engines, insurance pricing models. For these systems, the regulation demands effective human oversight, technical documentation and traceability of decisions. The compliance consequence is direct: a company cannot delegate a hiring or credit decision to a model it does not understand and cannot explain. If the system is high-risk, someone inside the organisation must be able to answer two questions at any moment: how does it decide, and who supervises it. The duty of oversight does not disappear because the software was bought rather than built in-house: the company that uses the system answers for the decisions it makes with it.
Algorithmic Bias as a Crime
Can an algorithm commit a crime of labor discrimination? The algorithm cannot, but the people behind it can. If a company uses CV screening software that systematically discards candidates based on gender or ethnicity due to bias in training data, management knew and consented to this operation and, after an administrative requirement or sanction, equality is not restored and the damage not repaired, we are facing a crime against workers' rights (art. 314 CP: six months to two years in prison or a fine of 12 to 24 months). The company itself is not criminally liable for this offence, which is not in the Art. 31 bis catalogue: art. 318 CP punishes the responsible directors or managers and allows art. 129 accessory consequences to be imposed on the company. The algorithm is a tool: criminal responsibility attaches to the people — directors, managers, those responsible for the system — who knew of the discriminatory operation and allowed it to continue. That is why the knowledge element is the battleground of these proceedings: what did management know, when did they know it, and what did they do once the bias became apparent.
Audit Protocol
The Compliance Officer must integrate data engineers into their team. Algorithm 'explainability' is now a fundamental piece of exculpatory evidence in corporate criminal proceedings.
Explainability as Exculpatory Evidence
A company that can produce documented audits of its models — what data they were trained on, what bias tests were run, what corrective measures were adopted and when — is in a position to show that management neither knew of nor consented to any discriminatory operation. Conversely, the absence of any audit trail makes that defence very difficult to sustain: if nobody ever examined the system, the argument that its results were diligently supervised collapses. The practical recommendation for the Compliance Officer is to treat every audit, test and remediation as evidence that may one day need to be produced in court, with dates, signatures and version control. In practice this also means keeping the documentation alive: an audit carried out years ago says little about the model that is running today.
Practical Steps for 2026
A reasonable algorithmic compliance program starts with an inventory: mapping which AI systems the company actually uses in HR, finance and customer decisions, including tools purchased from third-party vendors, which remain the company's responsibility once deployed. The next layer is risk classification and human oversight — defining who reviews the system's outputs and with what real power to override them, because oversight that exists only on paper protects no one. Finally, periodic bias testing and documented review cycles close the loop. None of this makes a model infallible; what it does is place the company and its managers in a defensible position, with evidence of diligence, if a criminal complaint ever arrives.
Official text: article 314 of the Spanish Criminal Code (BOE)
Frequently asked questions
Can an algorithm commit a crime of labor discrimination?
The algorithm does not bear criminal liability; the people who deploy and maintain it do. If a company uses screening software that systematically discards candidates on grounds of gender or ethnicity due to bias in the data, and management knew of it and consented, there may be a crime against workers' rights (art. 314 CP: six months to two years in prison or a fine of 12 to 24 months) if equality is not restored and the damage is not repaired after an administrative requirement or sanction. The company itself is not criminally liable for this offence: only the accessory consequences of art. 129 may apply (art. 318).
What role does human oversight play?
Overseeing is not the same as signing off on what the machine has already decided: it means that a person with real competence and authority can review the system's decisions, understand why they were made, and correct them or switch off the tool. Purely formal oversight leaves management exposed; effective and documented oversight is the first barrier against prosecution.
What does an algorithmic audit involve?
Translating the logic of compliance into technical terms: an inventory of the systems the company uses and their risk level, a review of the training data where bias usually originates, periodic bias testing, and a documented trail of what was audited, when, with what result, and what corrective measures were adopted.
How does the audit help in a criminal defence?
The algorithm's explainability, the ability to reconstruct and justify each decision, is the central exculpatory evidence: it makes it possible to show that any discriminatory outcome, if it existed, was neither known nor consented to by management. Documented audits establish the company's diligence and dismantle the subjective element of the offence.
What happens if the company detects a bias and does not act?
A company that discovers a deviation, corrects it and keeps a record shows the opposite of the intent and persistence in discrimination required by art. 314 CP, which punishes failing to restore equality after an administrative requirement or sanction. By contrast, one that knew of the reports and kept using the system unchanged will have written the evidence against itself.
Do you need criminal defence in this area?
We are criminal defence lawyers specialising in criminal compliance. We act urgently to protect your rights.
This page is for information purposes only and does not constitute legal advice: every case requires individual assessment. How this content is produced and verified: editorial policy.