Banking Law And Critical Infrastructure Ai Defense Spain .
1. The basic legal architecture in Spain
Spain does not regulate banking, critical infrastructure, cybersecurity and AI through one single statute. Instead, there is a layered framework:
| Area | Main legal framework | Main purpose |
|---|---|---|
| Banking | Spanish banking legislation + EU banking law | Prudential supervision, payment systems, governance |
| ICT resilience of banks | DORA – Regulation (EU) 2022/2554 | Cyber/ICT resilience of financial entities |
| Critical infrastructure | Law 8/2011 + RD 704/2011 | Protection of essential/critical infrastructure |
| Network & information security | RDL 12/2018 + RD 43/2021 | Security and incident reporting |
| Cybercrime | Spanish Criminal Code, especially Arts. 264 et seq. | Criminal liability for attacks on IT systems |
| Personal data/AI profiling | GDPR + Spanish Organic Law 3/2018 | Privacy, profiling and automated decisions |
| AI | EU AI Act, Regulation 2024/1689 | Risk-based regulation of AI |
| National security | Law 36/2015 on National Security | National-security coordination |
| Defence | Spanish defence/national-security legislation + EU/NATO obligations | Military and defence cybersecurity/AI |
The important point is that a Spanish bank can simultaneously be a financial entity subject to DORA, an operator of an essential service, potentially a critical operator, a personal-data controller and an AI deployer.
2. Critical infrastructure in Spain
The starting point is Law 8/2011 of 28 April, on protection of critical infrastructures.
It creates the Spanish Sistema de Protección de Infraestructuras Críticas and establishes cooperation between public authorities and private operators.
The implementing regulation is Royal Decree 704/2011, which establishes the planning and organisational framework for protection of critical infrastructure.
The objective is not simply physical security. It includes protection against deliberate attacks, including threats facilitated by communications technologies.
Critical infrastructure sectors
The framework covers strategically important sectors, including areas such as:
- energy;
- transport;
- telecommunications;
- health;
- water;
- food;
- finance and taxation;
- information technologies;
- government and other strategic services.
Thus, banking and financial infrastructure can fall within the critical-infrastructure/security framework where the statutory requirements for criticality are met.
3. What makes an infrastructure “critical”?
The legal distinction is important.
A critical infrastructure is not simply any large or important company.
The legal framework concentrates on infrastructure whose disruption or destruction can have a serious impact on essential services and society, taking into account factors such as:
- number of people affected;
- economic consequences;
- public/social consequences;
- interdependence with other infrastructures;
- significance for national security.
Once an operator is formally designated as a critical operator, additional security and planning obligations arise.
RD 704/2011 provides for instruments such as:
- National Critical Infrastructure Protection Plan;
- Sector-specific strategic plans;
- Operator Security Plans;
- Specific Protection Plans;
- security officers and coordination mechanisms.
The National Plan is designed to maintain secure infrastructure providing essential services and to establish preventive measures against deliberate attacks.
4. Banking + critical infrastructure: why the combination matters
A bank is not automatically treated as a critical infrastructure operator merely because it is a bank.
But modern financial infrastructure has become systemically important.
Consider:
Bank → payment processor → cloud provider → telecom network → central payment infrastructure.
A cyberattack on one component can therefore create a cascading failure.
This is precisely why European financial regulation increasingly focuses on operational resilience rather than merely traditional banking prudential risk.
5. DORA: the most important modern rule for banking cybersecurity
The Digital Operational Resilience Act (DORA), Regulation (EU) 2022/2554, is now central to the European banking cybersecurity framework.
DORA requires financial entities to establish ICT-security policies and procedures designed to guarantee:
- resilience;
- continuity;
- availability;
- authenticity;
- integrity;
- confidentiality of data.
It expressly covers systems supporting critical or important functions.
This is extremely important for AI.
Example
Suppose a Spanish bank uses AI for:
- fraud detection;
- credit scoring;
- anti-money-laundering monitoring;
- cyberattack detection;
- customer authentication;
- automated trading;
- risk management.
The AI system may become part of the bank's ICT infrastructure.
If it is sufficiently important to a critical function, the bank cannot treat it as an ordinary software application.
It must be incorporated into the bank's:
ICT risk-management → testing → incident response → business continuity → third-party risk-management framework.
6. DORA and third-party AI/cloud providers
One of the most important issues is that banks increasingly do not develop AI systems themselves.
They may rely on:
- cloud providers;
- AI-model providers;
- cybersecurity vendors;
- data analytics providers;
- SaaS platforms;
- outsourced IT providers.
DORA therefore becomes particularly significant for ICT third-party risk.
A bank cannot simply argue:
“The cyberattack occurred at our cloud/AI provider, therefore it is not our responsibility.”
The bank retains regulatory obligations concerning its ICT risk-management framework.
This is one of the major changes in modern banking law: outsourcing does not mean outsourcing regulatory responsibility.
7. Spanish cybersecurity legislation
Spain implemented the first EU NIS framework through Royal Decree-Law 12/2018.
It covers security of networks and information systems used to provide essential services and creates an incident-notification and institutional-coordination framework.
It is supplemented by Royal Decree 43/2021, which develops the security obligations, institutional framework, supervision and incident management.
The Spanish framework connects cybersecurity regulation with:
- Law 8/2011 on critical infrastructures;
- Law 36/2015 on National Security;
- the Spanish CSIRT system;
- CNPIC;
- CCN-CERT;
- INCIBE-CERT;
- ESPDEF-CERT.
For critical operators, CNPIC plays a particularly important role.
8. NIS2 and the banking sector
At EU level, NIS2 significantly expands cybersecurity obligations.
However, there is an important legal point for banking:
DORA is the specialised financial-sector regime.
Where DORA applies to a financial entity, it functions as the sector-specific cybersecurity/ICT-resilience framework rather than simply applying a second, identical set of NIS obligations.
Therefore, in an examination answer, it is better to say:
Banking cybersecurity in Spain must be understood through DORA together with the broader Spanish critical-infrastructure and national cybersecurity framework, rather than treating NIS2/DORA as completely independent regimes.
9. Criminal liability for attacks against critical infrastructure
The Spanish Criminal Code, Article 264, is particularly important.
Unauthorised serious deletion, damage, deterioration, alteration, suppression or making inaccessible computer data, programs or electronic documents can constitute a criminal offence.
The penalty becomes more serious where, among other circumstances:
- the conduct affects a large number of systems;
- it seriously harms essential public services;
- it affects the IT system of a critical infrastructure;
- it creates a grave danger to the security of Spain, the EU or a Member State.
This is extremely relevant to AI-enabled attacks.
Imagine an attacker uses an AI agent to:
- discover vulnerabilities;
- compromise a bank;
- manipulate payment systems;
- disable authentication;
- disrupt financial infrastructure.
The fact that AI was used does not automatically create a new offence.
The criminal liability derives from the underlying conduct and its consequences.
AI is the means of attack, while Article 264 and potentially other provisions determine the criminal liability.
10. AI and banking
The EU AI Act creates another layer.
A particularly important provision for banking is the treatment of AI used for creditworthiness/credit scoring.
The AI Act classifies specified financial AI uses as high-risk, subject to the conditions in the Regulation.
Therefore, a bank using AI to decide whether a consumer receives credit cannot assume that:
“It is only an algorithm, so ordinary banking rules apply.”
Instead, several regimes may apply simultaneously:
AI Act + GDPR + banking regulation + consumer law + DORA.
11. Very important case: SCHUFA — C-634/21
Although this is a CJEU case rather than a Spanish judgment, it is extremely important for Spanish banking law.
SCHUFA Holding (C-634/21) concerned automated credit scoring.
The Court held that where an automated probability score concerning a person's ability to repay debts is transmitted to a third party and that third party relies on it decisively in deciding whether to establish a contractual relationship, the generation of that score can itself constitute automated decision-making under Article 22 GDPR.
Legal significance
Suppose:
AI produces a credit score → bank relies decisively on score → loan refused.
The bank cannot necessarily avoid GDPR Article 22 simply by saying:
“The final decision was technically made by the bank; the AI only supplied a score.”
The CJEU rejected an overly formalistic approach.
This is highly relevant to Spanish banks using AI scoring systems.
12. Another important AI case: CK v Magistrat der Stadt Wien — C-203/22
In C-203/22, decided in February 2025, the CJEU examined the GDPR right to obtain meaningful information about automated decision-making.
The Court held that the individual can require an explanation of the procedure and principles actually applied in obtaining the automated result.
Importantly, merely giving someone:
“Here is our mathematical formula”
is not necessarily enough.
The explanation must be:
- relevant;
- concise;
- transparent;
- intelligible;
- accessible.
Banking implication
If a Spanish bank uses an AI system to reject a credit application, its governance must allow the bank to explain the relevant decision logic.
This creates a practical problem:
Black-box AI + banking + GDPR = significant legal risk.
13. AI Defence and national security in Spain
Now we reach the “AI Defence” component.
The legal treatment of AI used for:
- military operations;
- national defence;
- intelligence;
- military cybersecurity;
- national-security activities
is different from ordinary commercial AI.
The EU AI Act contains specific limitations concerning AI systems used exclusively for military, defence and national-security purposes.
Therefore, one should not simply apply the AI Act's ordinary commercial high-risk rules to every Spanish military AI system.
But this does not mean that military AI is legally unregulated.
Other legal regimes remain relevant, including:
- Spanish constitutional law;
- defence legislation;
- national-security legislation;
- public procurement;
- data protection where applicable;
- cybersecurity rules;
- international humanitarian law;
- EU law where applicable;
- NATO standards and obligations.
14. AI as a weapon against critical infrastructure
This is an emerging legal problem.
AI can be used offensively to:
- automate phishing;
- generate malware;
- discover vulnerabilities;
- conduct reconnaissance;
- manipulate employees;
- create deepfakes;
- evade cybersecurity systems;
- attack operational technology;
- coordinate large-scale cyberattacks.
The law generally does not need a special “AI cyberattack offence” for these acts to be criminal.
The existing criminal law can attach liability to the underlying conduct.
The significance of AI is instead that it can:
increase speed, scale, sophistication and autonomy of an attack.
That may influence the seriousness of the conduct, evidence, attribution and sentencing.
15. Important Spanish case: the 2025 nationwide blackout
A particularly useful recent example is the 28 April 2025 Spanish/Portuguese electricity blackout.
The Audiencia Nacional initially opened proceedings to investigate whether the nationwide blackout could have resulted from computer sabotage affecting critical infrastructure. The judge expressly considered whether such conduct could potentially fall within the terrorism provisions of Article 573 of the Criminal Code.
This demonstrates something very important:
Cyberattack + critical infrastructure + national impact
can potentially move the legal issue beyond ordinary cybercrime and into:
- national security;
- terrorism;
- critical infrastructure protection;
- public safety.
However, the investigation was subsequently provisionally closed in January 2026 because the technical evidence did not provide a minimum indication of terrorist sabotage. The investigation relied, among other things, on technical reports and analysis of operational-technology security data.
Why this case matters
It demonstrates the importance of technical attribution.
A major infrastructure failure does not automatically become a cyberattack.
And a suspected cyberattack does not automatically become terrorism.
The prosecution must establish the legally required elements with evidence.
16. Banking fraud case: STS 571/2025
A very useful banking case is Spanish Supreme Court Judgment 571/2025, 9 April 2025.
The case concerned unauthorised banking/payment transactions.
The Supreme Court established the principle that, in the case of an unauthorised payment transaction, the payment service provider must generally refund the amount immediately unless it establishes fraud or gross negligence by the user.
This doctrine has subsequently been applied in lower-court banking fraud cases.
One 2025 case concerning BBVA involved a sophisticated impersonation/phishing-style fraud. The court concluded that the customer's conduct did not amount to gross negligence because the fraud was highly convincing and ordered repayment.
Relevance to AI
Imagine an AI-generated phishing attack impersonates a bank perfectly.
The fact that the attacker used generative AI does not automatically transfer the loss to the customer.
The legal questions remain:
- Was the transaction authorised?
- Was there fraud?
- Was the customer grossly negligent?
- What security controls did the bank employ?
- Did the bank satisfy its payment-services and cybersecurity obligations?
AI therefore increases the technical sophistication of the fraud, but established banking liability principles remain relevant.
17. AI + critical infrastructure: liability model
A useful way to analyse a Spanish AI incident is:
Stage 1 — AI governance
Was the AI system lawfully designed and deployed?
↓
Stage 2 — Cybersecurity
Were adequate security controls implemented?
↓
Stage 3 — Operational resilience
Was the system adequately tested and monitored?
↓
Stage 4 — Critical infrastructure
Did the system support an essential/critical service?
↓
Stage 5 — Incident
What actually happened?
↓
Stage 6 — Liability
Potentially:
- regulatory;
- civil;
- contractual;
- administrative;
- criminal;
- data-protection;
- banking/payment-services liability.
18. Who may be liable?
Consider this hypothetical:
A Spanish bank deploys an AI fraud-detection system. A malicious actor compromises the model and causes thousands of fraudulent transactions.
Potentially relevant parties include:
Bank
Possible issues:
- inadequate ICT risk management;
- inadequate testing;
- inadequate incident response;
- inadequate authentication;
- inadequate vendor management;
- breach of DORA obligations.
AI provider
Possible issues:
- contractual breach;
- security defects;
- negligence;
- defective system;
- failure to comply with applicable AI obligations.
Cloud provider
Potentially relevant under:
- contractual obligations;
- DORA third-party ICT risk;
- cybersecurity requirements.
Attacker
Potential criminal liability under the Criminal Code, including Article 264 where its elements are satisfied.
Directors/management
Potential liability depends on the specific facts, applicable duties and causation.
19. Relationship between DORA, AI Act and GDPR
This is probably the most important conceptual point for an examination.
They regulate different risks.
| Regulation | Primary concern |
|---|---|
| DORA | ICT/operational resilience of financial entities |
| AI Act | Risks created by AI systems |
| GDPR | Personal data and individual rights |
| Critical Infrastructure Law | Protection of strategically essential infrastructure |
| Criminal Code | Punishment of cybercrime and attacks |
| Payment-services law | Liability for unauthorised payment transactions |
They are therefore cumulative rather than mutually exclusive.
20. A practical hypothetical problem
Facts
A Spanish bank uses an AI system to automatically approve/reject loans.
An attacker compromises the AI system and manipulates its scoring.
As a result:
- legitimate customers are rejected;
- fraudulent customers are approved;
- €50 million is lost;
- the bank's payment system is temporarily disrupted.
Legal analysis
First: AI Act.
Determine whether the AI falls into a regulated/high-risk category.
Second: GDPR.
If personal data and automated decision-making are involved, Articles 22 and related transparency requirements must be examined.
Third: DORA.
The bank must examine ICT risk management, resilience, testing, incident management and third-party risk.
Fourth: critical infrastructure.
If the relevant banking infrastructure is designated within the critical-infrastructure framework, the Law 8/2011/RD 704/2011 regime becomes particularly relevant.
Fifth: Criminal Code.
The attack may constitute computer damage/interference under Article 264 if the statutory elements are established.
Sixth: banking/payment law.
Customers may have claims concerning unauthorised payment transactions.
Seventh: civil liability.
Losses may generate contractual/tort claims depending on the relationships involved.
21. Case-law principles to remember
For an exam or dissertation, I would remember these cases/principles:
1. STS 571/2025 — Spanish Supreme Court
Principle: unauthorised payment transactions generally trigger the payment provider's obligation to refund unless fraud or gross negligence of the user is established.
2. SCHUFA — CJEU, C-634/21
Principle: an automated creditworthiness score can itself amount to automated individual decision-making when it plays a decisive role in the subsequent contractual decision.
3. CK v Magistrat der Stadt Wien — C-203/22
Principle: GDPR transparency concerning automated decisions requires meaningful information about the actual procedure/principles used, not merely disclosure of a complicated mathematical formula.
4. Spanish Audiencia Nacional — 2025 blackout investigation
Principle: a major disruption of critical infrastructure can justify investigation of potential cyber-sabotage and, depending on evidence and intent, potentially terrorism; but criminal classification requires evidence.
22. Key legal proposition
The strongest way to formulate the issue academically is:
In Spain, the legal protection of banking as critical digital infrastructure is based on a multi-layered framework combining financial regulation, ICT operational resilience, critical-infrastructure protection, cybersecurity, data protection, AI governance and criminal law. The increasing use of artificial intelligence does not replace these regimes; rather, it creates an additional layer of risk and compliance obligations.
The particularly important development is the shift from “cybersecurity” to “digital operational resilience.”
A bank is no longer expected merely to prevent hacking. It must be capable of:
preventing → detecting → responding → recovering → learning
from ICT and AI-related incidents.
23. Exam-ready conclusion
For a Spanish Banking Law + Critical Infrastructure + AI Defence answer, structure the conclusion around five propositions:
- Banks are part of a highly regulated digital financial ecosystem, and important financial services may have critical-infrastructure significance.
- Law 8/2011 and RD 704/2011 provide Spain's critical-infrastructure protection architecture.
- DORA is central to modern banking cybersecurity, requiring financial entities to manage ICT risk, resilience, continuity and third-party ICT risk.
- AI creates additional legal questions, particularly concerning automated credit decisions, transparency, profiling, cybersecurity and accountability. The SCHUFA and CK judgments are particularly valuable authorities.
- AI-enabled attacks against critical infrastructure can trigger ordinary cybercrime, critical-infrastructure and potentially national-security/terrorism law, but liability depends on proof of the relevant statutory elements. The 2025 Spanish blackout investigation is an excellent contemporary illustration.

comments