Spain’s 12-month AI plan needs public milestones, owners and evidence
Spain’s IA360 roadmap combines governance, infrastructure, labour monitoring and adoption goals. Its decision value will depend on whether each promise is converted into a dated output, accountable owner and public evidence trail.

What happened
Spain’s government presented IA360 on 21 September as a 12-month roadmap for responsible AI deployment, including social dialogue, labour-impact monitoring, technology projects, cybersecurity and governance actions.
Why it matters
A compressed roadmap can coordinate action, but broad pillars do not show whether delivery occurred. Public milestones should distinguish consultations, funded capacity, operational services, adoption and measured outcomes.
Spain’s government presented IA360 on 21 September as a roadmap with actions to be implemented over 12 months. The official account places public safety, trust and protection of vulnerable people at the centre. Reuters reported proposed infrastructure and model-development measures and the prime minister’s argument that the industry cannot regulate itself. El País described four broad pillars, including national dialogue, a labour-impact observatory, technological development and stronger governance.
The scope is deliberately wide. It includes a proposed AI gigafactory, models for climate, health and energy, support for small and medium-sized enterprises, education, cybersecurity and social dialogue. Breadth can help align institutions, but it also makes success easy to declare. Convening a meeting, publishing a call, funding compute and changing an employer workflow are different outputs. None alone proves economic benefit, environmental sustainability or protection of workers.
Convert every promise into a public delivery object
For each action, publish a dated milestone with one accountable institution, the legal or budget basis, dependencies, completion evidence and a named next decision. A social-dialogue milestone could be a published mandate, participant list, disputed issues and response timetable. An infrastructure milestone could state awarded capacity, location criteria, grid and water assumptions, procurement status and expected availability. An SME milestone should separate firms contacted, firms piloting and firms with verified workflow adoption.
The labour observatory needs an explicit measurement design before headline numbers appear. Exposure estimates, job postings, employer surveys and administrative employment data answer different questions. Reports should preserve sector, occupation, region, contract type and time lag, and should not attribute a change to AI without a credible comparison. The observatory should also publish negative or ambiguous results so policy does not become a sequence of success stories.
Build challenge rights into the timetable
A 12-month plan creates pressure to move quickly. That makes complaint, review and pause mechanisms more important, not less. Projects affecting work, education, public services or vulnerable people should name who can challenge an outcome, which evidence is retained and who can suspend a deployment. Cybersecurity measures need incident exercises and response thresholds, while environmental claims need facility-level boundaries and independently reviewable data.
The strongest counterargument is that detailed public reporting can slow delivery and expose sensitive procurement information. A useful minimum does not require publishing secrets. It requires enough information to distinguish announcement, contract, operational capability and outcome. Redactions can protect security while owners, dates, budgets, dependencies and completion criteria remain visible.
The register should also preserve revisions. If a deadline, budget or completion criterion changes, publish the previous value, the reason, the approving authority and the effect on dependent actions. Without that history, a roadmap can appear on schedule because the definition of completion moved. A small independent secretariat or audit function can sample evidence, test whether milestones match the published criteria and flag unresolved dependencies. Its role is not to replace political accountability but to make the evidence usable before a year-end success narrative hardens.
For organisations participating in the plan, the same discipline applies internally. A grant, procurement or pilot should enter a control register with a named business owner, data owner, affected groups, stop condition and evidence-retention rule. That creates a bridge between national promises and operational accountability.
Leaders outside Spain should not copy the plan’s institutional design without context. They can copy the discipline of a finite roadmap only if its promises become testable. The Skills Atlas can help identify capabilities for policy measurement, procurement and accountable operation. The immediate test for IA360 is simpler: within the first quarter, can a citizen see which actions are due, who owns them, what evidence will count and what happens when a milestone slips?