
Corporate AI Criminal Risk Defence Lawyers
Algorithmic compliance design and criminal defence for corporate AI use: EU AI Act, discriminatory bias, automated decisions, deepfakes and algorithmic liability.
The criminal risk of corporate AI use does not stem from a standalone artificial intelligence offence, but from the fact that poorly controlled algorithmic systems can bring about offences that already exist: discrimination (Arts. 512 and 314 of the Spanish Criminal Code (CP)) from bias in scoring or personnel selection, fraud (Art. 248 CP) where a commercial chatbot is knowingly used to deceive, or documentary falsification (Arts. 392 and 395 CP) through synthetic content. The EU AI Act (Regulation 2024/1689) classifies systems by risk level and requires conformity assessment, human oversight and traceability for high-risk systems, with fines of up to €15M or 3% of worldwide turnover for breaching its obligations (€35M or 7% for prohibited practices). A director's criminal liability can be triggered by reckless intent (dolus eventualis) where they authorized the deployment without a bias audit or human oversight despite prior warnings. At Alonso Sala we design algorithmic compliance built into the Art. 31 bis CP model and defend companies and directors against these charges.
EU AI Act
Regulation EU 2024/1689 classifies AI systems in four tiers: prohibited (social scoring, cognitive manipulation, real-time biometric identification with exceptions), high-risk (HR, credit scoring, critical infrastructure, healthcare, education, justice), limited risk (chatbots, synthetic content — transparency obligation) and minimal risk. Each tier implies different obligations. Non-compliance generates fines of up to €15M or 3% of worldwide turnover, and up to €35M or 7% for prohibited practices.
Criminal Typologies for AI Misuse
- Discrimination (Arts. 512 and 314 CP): Biased scoring or filtering system that, intentionally or knowingly, denies hiring, credit or service on prohibited grounds.
- Fraud (Art. 248 CP): Commercial chatbot knowingly used to deceive the client for profit (an involuntary erroneous output is not fraud).
- Degrading treatment (Art. 173 CP): Surveillance or labor management system imposing humiliating conditions.
- Privacy offences (Art. 197 CP): Unauthorised seizure, use or alteration of confidential personal data held in files, to the detriment of a third party (Art. 197.2); processing without a legal basis is, in itself, a GDPR infringement.
- Document forgery (Arts. 392 and 395 CP): Generation of synthetic documents with legal value.
Automated Decisions and Willful Blindness
The Gordian knot of AI criminal liability is intent (dolus eventualis or wilful blindness): when does the executive authorizing deployment accept as probable the harmful result? Fraud, discrimination and forgery are not punishable when committed negligently: the executive is only liable if they knew of the specific risk of a criminal outcome and deployed the system anyway. Indicators that may support that inference include (a) the system operating on non-representative datasets; (b) no prior bias audit; (c) no meaningful human supervision; and, above all, (d) ignored alerts from the internal technical team.
Discriminatory Bias
Algorithmic bias systematically disadvantaging persons by gender, race, age or origin may fall, where intentional or knowingly accepted, within Art. 512 CP (discriminatory denial of a service in business activity: special disqualification of 1 to 4 years) and, in the employment context, Art. 314 CP (serious discrimination not corrected after an administrative requirement or sanction: 6 months to 2 years' imprisonment or a 12 to 24 months' fine). Defence requires demonstrating periodic external audit with fairness metrics, statistically representative training datasets, human review procedure for critical decisions, and documented remediation procedure for alerts.
Algorithmic Compliance Design
The Art. 31 bis CP prevention model must be extended with AI governance: internal model registry with risk tiering; technical model cards with intended use and limitations; pre-deployment and recurring bias audit; real and documented human supervision; algorithmic incident channel; specific training for product, data and compliance teams.
An effective criminal-compliance model against AI risk: the six requirements of Article 31 bis(5) of the Criminal Code
There is still no autonomous artificial-intelligence offence. The criminal risk that AI introduces into a company is channelled through the ordinary route of corporate criminal liability under Article 31 bis of the Spanish Criminal Code: the entity may be liable when, in its name and for its direct or indirect benefit, one of the offences in the closed statutory list is committed (fraud, discovery and disclosure of secrets, computer damage, offences against privacy, among others), whether by its directors or representatives, or by subordinates where there has been a serious breach of the duties of supervision, monitoring and control. An AI tool does not create a new offence: it amplifies exposure to those that already exist.
That is why the decisive element is the organisation and management model. For it to produce exempting or mitigating effects, Article 31 bis(5) requires the model to meet six requirements: to identify the activities in whose scope the offences to be prevented may be committed; to establish protocols specifying how the entity forms its will and adopts and executes decisions; to maintain financial-resource management models adequate to prevent those offences; to impose a duty to report possible risks and breaches to the compliance body; to set up a disciplinary system that sanctions non-compliance; and to verify the model periodically, amending it when relevant breaches come to light or the organisation or activity changes.
Translated to AI, this means integrating each algorithmic system into the criminal risk map as one more activity: documenting who decides on its deployment, what human controls intervene before an automated output produces legal effects, how access to personal and third-party data is managed, and what traceability remains of the system's decisions. A model that does not contemplate the risks arising from the use of AI can hardly be presented as suitable, adopted and effectively implemented.
The autonomous oversight body and the burden of proving the exemption
The model's exempting effect depends, beyond its content, on its supervision having been entrusted to a body of the legal person with autonomous powers of initiative and control, or one legally charged with supervising the effectiveness of internal controls. That compliance body must enjoy genuine autonomy from the management body: capacity for initiative, access to information, sufficient resources, and the ability to act independently of any interests of the entity unrelated to the model's effectiveness. In the AI sphere, it is responsible for continuously monitoring the algorithmic systems in use, not as a one-off implementation check, but as a periodic verification of their operation and results.
A technical point worth anticipating is who must prove what. The allocation of the burden of proof on the model's suitability and effectiveness is a debated and evolving question; the Supreme Court's case-law since 2016, safeguarding the presumption of innocence, places on the prosecution the burden of proving the organisational defect that grounds liability, without prejudice to the company in practice producing the evidence of its model, its adoption and its effective implementation before the act. Having a policy document is therefore not enough: one must be able to show real operation, activity records of the compliance body, training delivered, reviews carried out, and disciplinary reaction to incidents. A cosmetic model, adopted after the facts or never verified, does not exempt.
Article 31 bis(4) provides, for offences committed by subordinates, that the exemption applies where, before the commission, a prevention model adequate to prevent offences of that nature or to significantly reduce the risk of their commission had been adopted and effectively implemented. The company's defence is therefore built on documentary evidence contemporaneous with the facts, not on later reconstructions. Anticipating and safeguarding that evidence is a central part of preventive advice.
The company under investigation: its own procedural status, autonomous defence and the penalties of Article 33.7
When an offence that triggers corporate criminal liability is charged, the entity acquires its own procedural status as an investigated party, with rights analogous to those of a natural person: to be informed of the accusation, not to testify against itself, not to confess guilt, and to a defence with legal counsel. The company appoints a representative specifically for the proceedings, who cannot be someone due to testify as a witness at trial and should preferably be distinct from anyone who may be charged as a natural person, to avoid conflicts of interest. This defence is autonomous: Article 31 ter establishes that the legal person's liability may be required even where the specific responsible natural person has not been individualised or it has not been possible to direct the proceedings against that person.
The consequences the entity faces do not follow the penalty scheme of natural-person offences (and the limitation period that applies to it is a debated question). Article 33.7 lists the penalties specific to legal persons: fines by quota or proportional; dissolution; suspension of activities; closure of premises and establishments; prohibition on carrying out in the future the activities in whose exercise the offence was committed, facilitated or concealed; disqualification from obtaining public subsidies and aid, contracting with the public sector, and enjoying tax or social-security benefits and incentives; and judicial intervention to safeguard the rights of workers or creditors. Some of these penalties may be ordered even as a precautionary measure during the investigation.
The proceedings also allow a plea agreement by the legal person, which may be negotiated independently of that of the natural-person defendants. The prior existence of a compliance model, its degree of implementation and cooperation with the investigation bear both on a possible exemption and, subsidiarily, on mitigation: Article 31 quater lists only four mitigating circumstances: confessing the offence before learning that judicial proceedings are directed against it, cooperating by providing new and decisive evidence, repairing or reducing the harm before trial, and establishing, also before trial, effective measures to prevent and detect offences in the future.
The Law 2/2023 reporting channel, internal investigations and Article 130.2 succession in corporate transactions
The disciplinary system and reporting channel required by the compliance model now connect with Law 2/2023 of 20 February, which transposes Directive 2019/1937 and requires private companies with fifty or more workers to set up an Internal Information System. That system rests on three pillars: the internal channel, the system manager, and the management procedure, with guarantees of confidentiality of the informant's identity and a prohibition on reprisals. In the AI field, the channel is the natural route for surfacing incidents early — discriminatory outputs, improper data access, unauthorised use of tools — before they crystallise into a criminally relevant act, and its documented operation reinforces the model's suitability.
Internal investigations triggered by an alert must be conducted respecting the rights of the employees concerned, because the usability of the evidence obtained depends on their lawfulness. Criteria of proportionality must be observed, along with prior notice of the existence of the controls, respect for privacy and data protection, and the duty to inform about the use of work tools. An internal investigation conducted without safeguards may not only invalidate the evidence but also compromise the company's own position. It is therefore advisable to set out in advance protocols for reviewing devices, corporate email and the logs of algorithmic systems.
Finally, the effect of criminal liability on corporate transactions should be borne in mind. Article 130.2 provides that the criminal liability of a legal person is not extinguished by its transformation, merger, absorption or division, passing instead to the resulting or beneficiary entity or entities, nor by its concealed or merely apparent dissolution. This makes auditing criminal risk — including that arising from AI systems and from the robustness of the target company's compliance model — an indispensable part of due diligence in any acquisition or corporate restructuring.
Penalties & Consequences
| Type / Scenario | Criminal Penalty |
|---|---|
| Discrimination (Arts. 512 and 314 CP) | Discriminatory denial of a service (Art. 512): special disqualification of 1 to 4 years. Serious uncorrected employment discrimination (Art. 314): 6 months to 2 years' imprisonment or a 12 to 24 months' fine. |
| AI Act fine | Up to €35M or 7% of worldwide turnover for prohibited systems. |
| Legal person liability | Only for listed offences (fraud, Art. 251 bis; privacy, Art. 197 quinquies; hate speech, Art. 510 bis): a fine and, under the criteria of Art. 66 bis, other Art. 33.7 penalties such as a ban on public contracting or suspension of activities. Not for discrimination under Arts. 314 and 512 or for documentary forgery. |
* Penalties shown are indicative. The actual penalty depends on case circumstances, applicable mitigating and aggravating factors.
Our Defence Strategy
Integral AI risk assessment
Mapping of all deployed AI systems with AI Act classification, legal risks and mitigation plan.
Model cards and internal registries
Technical and operational documentation of each model with owners, training data and metrics.
External bias audit
Independent and recurring audit with fairness, robustness and explainability metrics.
Algorithmic incident protocol
Specific channel for reporting anomalous behavior, with investigation, remediation and communication.
Economic Criminal Law in Spain: Tax Fraud, Money Laundering and Corporate Crimes
Economic criminal law encompasses the most severe financial penalties in the Spanish Criminal Code. Tax fraud over €120,000 (Art. 305 CP), money laundering (Art. 301 CP), and corporate crimes (Art. 290-297 CP) are complex offences where defence requires a combination of criminal law expertise and deep accounting/financial knowledge.
Penalty Comparison: Economic Offences
| Offence | Threshold | Penalty |
|---|---|---|
| Tax Fraud (Art. 305) | >€120,000 | 1 – 5 years + fine of 1x to 6x |
| Aggravated Tax Fraud | >€600,000 | 2 – 6 years |
| Money Laundering (Art. 301) | Any amount | 6 months – 6 years |
| Aggravated Laundering (Arts. 301.1 and 302.1) | Drug trafficking, corruption, organisation members or obliged entities | Upper half (up to 6 years); heads of the organisation, one degree higher (up to 9 years) |
| Corporate Crime (Art. 290) | Balance sheet falsification | 1 – 3 years |
| Punishable Insolvency (Art. 259) | Conduct in actual or imminent insolvency | 1 – 4 years |
Key Defence Strategies
Tax Regularization Defence (Art. 305.4 CP)
Acknowledge and pay the full tax debt before being notified of a tax audit or, failing that, before the prosecutor or state attorney files a complaint, and criminal liability is excluded. This is the most powerful complete defence in tax fraud cases.
Challenge the €120K Threshold
The tax authority's calculation method is often contestable. Independent forensic accounting can challenge the assessed figure below the criminal threshold.
Money Laundering 'Self-laundering' Issues
Spanish courts have debated whether the primary offender can also be convicted of laundering their own proceeds. Challenge the double jeopardy implications.
Corporate Crime: Harm to Company vs. Shareholders
Corporate crimes under Arts. 290-294 CP do not always require actual harm: falsifying accounts (Art. 290 CP) only requires that the falsification be capable of causing financial harm, and actual harm raises the penalty to the upper half. Showing that the falsification could not harm the company, its members or third parties rules out that offence.
Why Choose Us?
Need a criminal defence lawyer for this type of offence? Here's how we work:
Need urgent criminal defence?
Contact our specialist criminal defence lawyers. We evaluate your case confidentially.
Tools for your case
We also serve
View all locations →This page is for information purposes only and does not constitute legal advice: every case requires individual assessment. How this content is produced and verified: editorial policy.
Do you need specialised legal assistance?
The judicial system is complex. We have the criminal-law specialisation and technical resources required to take on the defence.