Anthropic lands in Spain: creates a subsidiary in Madrid to market AI software

The American company creator of Claude has established Anthropic PBC Spain SL in Madrid, as stated in the Official Bulletin of the Commercial Registry.

1 minute

fotonoticia 20260613065002 1920

fotonoticia 20260613065002 1920

Add DEMÓCRATA to Google

Ask FREN

Published

Last updated

1 minute

Most read

Anthropic, the American company specialized in artificial intelligence and creator of Claude, has taken a new step in its international expansion with the establishment of a company in Spain. Anthropic PBC Spain SL has been registered in Madrid, according to the Official Bulletin of the Mercantile Registry.

The new company has as its sole partner the American parent company, Anthropic PBC, and its corporate purpose includes the marketing, distribution, and licensing of artificial intelligence software. The establishment of the subsidiary took place on March 27, 2026.

Anthropic PBC Spain SL was established with a share capital of 3,000 euros and has its registered office on Goya Street in Madrid, according to the information published in the BORME. The sole administrator of the company is Thomas Remy, an executive of Anthropic linked to the company's expansion in Europe, the Middle East, and Africa.

Spain joins Anthropic's European deployment

The arrival of Anthropic in Spain occurs at a time of growth for its European structure. The company itself announced in November 2025 the opening of offices in Paris and Munich, which joined those already maintained in London, Dublin, and Zurich. In May 2026, it also announced that it would open another office in Milan, the sixth for the company in Europe.

The expansion is not limited to a commercial presence. Anthropic explained when announcing its centers in Paris and Munich that its European structure encompasses areas such as research and engineering, sales and operations, in addition to institutional collaboration activities and business development. The company has also strengthened its management team for the EMEA region during this process.

Anthropic has linked this international deployment to the growth of demand for artificial intelligence tools among companies and organizations. In Spain, this market has also gained weight: according to the latest definitive data published by the INE, 21.1% of companies employed artificial intelligence technologies in the first quarter of 2025, with a higher implementation in the services sector, where the percentage reached 25.7%.

More key points, information and questions with FREN

AI-GENERATED CONTENT

What additional legal procedures must a foreign company carry out to market artificial intelligence software in Spain?

To market artificial intelligence (AI) software in Spain, a foreign company is not limited to "selling licenses": it must fit within the European framework (AI Regulation, General Data Protection Regulation) and various Spanish regulations on data, cybersecurity, and consumer protection. It is not always mandatory to establish a subsidiary in Spain, but it is necessary to comply with a series of preliminary procedures, launch requirements, and ongoing monitoring.

1. Starting point: establishment and representative in the EU

  • Establishment in the EU: if the company already has a headquarters in any Member State (subsidiary, branch, or other permanent establishment), it can usually operate in Spain from there, applying the single market principle.
  • Third-country company without establishment in the EU: the future European AI Regulation will generally require AI system providers offering products or services in the EU to appoint an authorized representative in the Union, responsible for being the point of contact with authorities such as the Spanish AI Supervisory Agency (AESIA).
  • This is not a classic commercial procedure (it is not always mandatory to incorporate a company in Spain), but it is a regulatory requirement as a "gateway" to the European market.

2. Before launching the product

  • Classify the system according to the AI Regulation: determine if the software is:
    • Of high risk (for example, in health, employment, education, biometric surveillance, critical infrastructures).
    • Of limited risk (mainly requiring transparency obligations).
    • Of minimal risk (much lighter obligations, but not nonexistent).
    This classification determines the technical procedures and marking requirements.
  • Risk management system and technical documentation: high-risk systems must have:
    • Risk management throughout the system's lifecycle.
    • Data governance (quality, non-discrimination, traceability).
    • Detailed records of design, training, testing, and human oversight.
  • Conformity assessment and, where applicable, CE marking:
    • AI systems integrated into regulated products (medical devices, machinery, radio equipment, etc.) are subject to the CE marking procedures of their sectoral regulation, incorporating AI requirements.
    • In other cases, the AI Regulation provides evaluation schemes (self-assessment or assessment by a notified body) before placing the system on the market.
  • Personal data protection (GDPR + Organic Law 3/2018):
    • Identify whether the company acts as controller or processor for Spanish or European clients.
    • Carry out a data protection impact assessment (DPIA) when the use of AI may involve high risk (profiling, automated decisions, surveillance, etc.).
    • Establish legal bases, clear information to users, minimization and security measures.
    • If there is no establishment in the EU but offers are directed to residents in the EU, also designate a representative in the EU for GDPR purposes.
  • Cybersecurity: depending on whether the software provides essential digital services or is integrated into critical infrastructures, Royal Decree-Law 12/2018 and its regulatory development may apply, requiring:
    • Technical and organizational security measures proportional to the risk.
    • Capability to detect and notify serious incidents to CSIRTs and competent authorities.
  • Contracts and terms with clients: adaptation of license terms, SLAs, liability clauses, acceptable use policy, and conditions on automated decisions, ensuring consumer and user protection according to the consolidated text of the General Law for the Defense of Consumers and Users.

3. At the time of launch in Spain

  • Information and transparency towards the user:
    • Clearly indicate when interacting with an AI system if it is not obvious.
    • Inform about the general logic of relevant automated decisions, their effects, and rights of objection or human review when applicable.
  • Documentation available for authorities: the provider must be able to present, upon request by AESIA, AEPD, or other authorities:
    • Technical file of the system.
    • Usage and incident logs.
    • Internal AI and data governance policies.
  • Sectoral adaptation: if the software is used in regulated sectors (health, finance, transport, justice, education, security, etc.), there may be:
    • Requirements for prior authorization or product/service registration.
    • Specific limitations on the types of admissible automated decisions.

4. Monitoring and supervision obligations

  • Post-market surveillance: the high-risk AI provider must:
    • Monitor the system's performance under real conditions.
    • Detect performance degradation, biases, or unforeseen impacts.
    • Update the system and, when appropriate, review the conformity assessment.
  • Incident management and notifications:
    • Notify significant security incidents related to networks and information systems when within the scope of NIS regulations.
    • Notify personal data breaches to the AEPD and, if applicable, to affected individuals, according to the GDPR.
    • Cooperate with AESIA or other authorities' requests regarding risks to fundamental rights.
  • Continuous compliance review: the company must adapt its system to:
    • European harmonized technical standards as they are approved.
    • Guidelines and supervision criteria from AESIA and other authorities.
    • Possible changes in the AI Regulation and Spanish data, cybersecurity, and consumer regulations.

In practice, the key "additional procedure" for a foreign company compared to a purely local development is to ensure an integrated compliance architecture at the European level (EU representative, common technical file and conformity assessment, data and risk governance) and then adapt it in Spain with sectoral, data protection, and consumer adjustments, in dialogue with specialized advisors and, when appropriate, with supervisory authorities.

What are the functions and powers of a sole administrator in a Spanish limited liability company according to current legislation?

In a Spanish limited liability company, the sole administrator is the management body when the bylaws assign the management and representation of the company to a single person. Its general framework is found in the current commercial legislation (especially the Capital Companies Act), which regulates its management and representation powers, its legal duties, and its liability regime.

Scope of functions and powers

The sole administrator concentrates all management powers not reserved by law to the general meeting. This translates into:

  • Ordinary management: day-to-day business direction (hiring personnel, suppliers, clients, managing collections and payments, opening and closing bank accounts, operational supervision, etc.).
  • Extraordinary management: significant decisions such as acquisition or transfer of significant assets, arranging important financing (loans, guarantees), modification of operational structure or closure of establishments, provided they are not reserved to the general meeting.
  • Internal organization: implementation of internal policies and procedures, control systems, and, where appropriate, delegation of executive functions to managerial staff (without delegating ultimate responsibility).

Power of representation

Unless the bylaws validly limit the form of representation, the sole administrator holds the general organic representation of the company:

  • He/she can bind the company vis-à-vis third parties by his/her sole signature or action.
  • His/her power of representation extends to all acts included in the corporate purpose and those necessary for its development.
  • Towards bona fide third parties, the company is bound even if internally the administrator has exceeded certain instructions, except in cases of nullity or manifest illegality.

Relationship with the general meeting

The general meeting retains non-delegable powers (for example, approval of accounts, allocation of results, appointment and dismissal of administrators, amendments to bylaws, capital increases or reductions, dissolution, structural operations). The sole administrator:

  • Must call the meeting in cases provided by law and bylaws.
  • Must execute the resolutions validly adopted by the meeting, even if personally disagreeing, unless they are contrary to the law.
  • Has a duty to inform the shareholders under legal terms (making accounts, reports, documentation of relevant operations available, responding to information requests at the meeting, etc.).

Legal duties of the sole administrator

The law establishes a particularly demanding duty regime:

  • Duty of diligence: act with the diligence of a prudent businessman, adequately informing before deciding, supervising the company’s progress, and establishing reasonable controls.
  • Duty of loyalty: act in the interest of the company, avoiding placing personal or third-party interests above it. This includes:
    • Refraining from taking advantage of business opportunities of the company.
    • Not using company assets or information for personal benefit.
    • Avoiding conflicts of interest and, when they exist, disclosing them and abstaining from intervening.
  • Duty of confidentiality: not disclose sensitive company information, even after cessation, except by legal obligation.
  • Duty to avoid unattended insolvency situations: if causes for dissolution or insolvency arise, must promote the adoption of legally provided measures (calling meetings, filing for bankruptcy when appropriate).

Liability towards the company, shareholders, and third parties

The sole administrator is liable to:

  • The company, through the social liability action, for damages arising from acts or omissions contrary to the law, bylaws, or performed without due diligence.
  • Shareholders and third parties, through individual action, when his/her conduct causes them direct harm (e.g., false information, concealment of relevant data, transactions fraudulent to creditors).
  • In cases of company debts, if failing to react to causes of dissolution, may be personally liable for certain debts incurred after the cause arises.

Limits and controls on his/her actions

Although concentrating great power, his/her actions are subject to important limits:

  • Resolutions reserved for the meeting: cannot alone adopt decisions reserved by law to the general meeting.
  • Prohibitions and conflicts of interest: restrictions on competition with the company, non-transparent related-party transactions or market-condition operations, and obligation of authorization or ratification by the meeting in certain cases.
  • Control by shareholders and external bodies: approval of accounts, possibility of dismissal ad nutum by the meeting, audits, and judicial control in case of abuse or breach of duties.

In summary, the sole administrator has broad management and representation powers but is subject to a strict regime of duties of diligence and loyalty, with important liability and control mechanisms to protect the company, shareholders, and third parties dealing with it.

What requirements does Spanish legislation establish for granting licenses to use artificial intelligence software?

In Spain, there is currently no specific "administrative license" required to use artificial intelligence (AI) software. Usage licenses are mainly governed by common intellectual property law and contracts, but they are conditioned by horizontal regulations on data protection, cybersecurity, consumer protection, public procurement, and progressively by the deployment of the European AI Regulation (AI Act) and specialized national supervision.

1. General framework for software and AI licenses

AI software usage licenses rely on the general intellectual property regime:

  • Consolidated Text of the Intellectual Property Law, approved by Royal Legislative Decree 1/1996, of April 12 (amended, among others, by Law 23/2006 and Law 2/2019). Computer programs are protected works, and only the holder can authorize their reproduction, transformation (including derivative developments), and making available to third parties.
  • The license (OEM, SaaS, open source, on-premise, etc.) is a contract defining the scope of user rights (number of users, territorial scope, permitted modifications, sublicenses, commercial use, etc.). There are no special formal requirements for being AI, but every license must respect the limits and copyrights of the Intellectual Property Law.
2. Data protection and automated processing

When AI software processes personal data, the granting and use of the license are conditioned by:

  • The Regulation (EU) 2016/679 (GDPR) and Organic Law 3/2018 on Personal Data Protection and Guarantee of Digital Rights, whose preamble explains the adaptation of Spanish law to the GDPR. They impose:
    • Appropriate legal basis (consent, contract, legal obligation, public interest, legitimate interest).
    • Data protection impact assessment (DPIA) when processing involves systematic and extensive evaluation of personal aspects based on automated processing or profiling.
    • Principles of minimization, purpose limitation, accuracy, and limited retention.
    • Rights of access, rectification, erasure, objection, restriction, and, where applicable, not to be subject to solely automated decisions with significant legal effects.
  • Organic Law 7/2021, on data processed for criminal purposes, which strengthens guarantees when AI is used in prevention, investigation, or prosecution of offenses.

In practice, many AI licenses must include clauses on:

  • GDPR responsibilities and roles (controller/processor).
  • International transfers and data location.
  • Technical and organizational measures and, where applicable, DPIA and audits.
3. Cybersecurity and system security

The marketing and use of AI software are affected by network and information system security regulations:

  • Royal Decree-Law 12/2018 on the security of networks and information systems, which transposes the NIS Directive, obliges operators of essential services and certain digital service providers to:
    • Manage information security risks with proportionate measures.
    • Notify relevant incidents to competent authorities or CSIRTs.
  • Royal Decree 311/2022, National Security Framework, applicable to the public sector, which sets minimum requirements (information classification, access control, activity logging, continuity, etc.) that are passed on, via specifications and contracts, to licensees and AI providers working with the Administration.
4. Public procurement of AI solutions

When the AI license is granted to an Administration or public sector entity, the Law 9/2017 on Public Sector Contracts applies. This implies that:

  • The licensor selection is carried out through competitive and transparent procedures.
  • The specifications usually introduce additional requirements of:
    • Security (alignment with the National Security Framework and NIS regulations).
    • Intellectual property (usage rights, access to code in certain cases, update guarantees).
    • Transparency and explainability of algorithms when they impact citizen rights.
5. Startups, sandboxes, and specific AI supervision

Law 28/2022 on the promotion of the startup ecosystem, and Royal Decree 817/2023 (controlled testing environment in AI matters) introduce:

  • “Sandbox” environments where AI systems can be tested under supervision before full commercialization.
  • Additional requirements for reporting, risk assessment, and compliance during the testing phase.

Royal Decree 729/2023 approves the Statute of the Spanish AI Supervisory Agency (AESIA), which will be the national supervisory authority of the future European AI Regulation and will issue guidelines, quality seals, and technical criteria that will likely affect licensing conditions (conformity assessments, technical documentation, etc.).

6. AI Act and emerging material requirements

The European AI Regulation (AI Act), directly applicable in Spain, establishes graduated obligations according to the system's risk:

  • For high-risk AI systems: risk management system, training data governance, detailed technical documentation, registration in European databases, and appropriate human oversight.
  • Cross-cutting transparency obligations (informing the user they are interacting with AI, synthetic content labeling, etc.).

Although the AI Act does not replace contractual licenses, its requirements are de facto integrated into them: clauses on compliance with the Regulation, access to documentation, audits, incident management, and liabilities towards third parties.

In summary, in Spain the “granting of licenses” for AI software is an intellectual property contract conditioned by a framework of horizontal regulations: data protection, cybersecurity, public procurement, startup promotion, and increasingly by the AI Act and AESIA supervision, which impose material requirements of transparency, risk assessment, security, and respect for fundamental rights on those who develop or exploit these systems.

Play

Test your knowledge with FREN!

How much do you know about this topic? Answer the following 3 questions.

What is the main activity of Anthropic PBC Spain SL in Spain?

Question 1 of 3

On which street in Madrid is the registered office of Anthropic PBC Spain SL located?

Question 2 of 3

What percentage of Spanish companies used artificial intelligence technologies in the first quarter of 2025 according to the INE?

Question 3 of 3

Hola, soy Fren. ¿Cómo te ayudo?