Spain and Europe are designing AI policies centered on three priorities: investment, regulation, and adoption. They are necessary dimensions, but incomplete, because a fourth is missing: the capacity of institutions to learn, control, and correct the systems they incorporate. Without that capacity, the transformation can increase immediate efficiency while at the same time weakening the autonomy of public organizations.
Digital sovereignty is often measured in infrastructures, data, providers, or in-house models. However, an administration can acquire advanced technology and still be fragile if it depends on the provider in later stages, whether to interpret the results, adjust the criteria, or even respond to failures that may arise. In this sense, technological dependency is also a dependency of capabilities. Therefore, it is not enough to possess tools; institutions must retain the knowledge necessary to govern them.
From compliance to institutional capacity
Regulatory compliance is essential, but it does not guarantee that an organization can govern artificial intelligence. In other words, an entity can formally meet the requirements (documentation, supervision, data protection, etc.) and still lack the resources to question an automated recommendation. The presence of a person in the process does not by itself amount to effective human control.
“Responsibility remains human on paper, but the decision-making power has, in fact, shifted toward the system and toward the provider”
For supervision to be real and effective, the professional must have access to the relevant information in order to understand the system’s limits. They must also have time to review its results and have the authority to suspend or reject an automated decision. If these conditions do not exist, we find that responsibility remains human on paper, but the decision-making power has moved toward the system and toward the provider.
This is a problem that substantially affects public administrations. Here, outsourcing external solutions can address an operational need, but it can also progressively erode internal capacity to diagnose problems, design alternatives or ensure service continuity. If every modification requires turning to the provider, the organization loses maneuvering room. But if the provider changes strategy, raises prices, or abandons the product, dependence becomes institutional vulnerability.
The capability gap
The public debate on artificial intelligence often centers on the access gap. That is, who has the best tools and who is left out. And that inequality exists, but it is not the only one to watch. Consider an example: two people with access to the same system can follow opposing career trajectories. One can use it to test hypotheses, review evidence, and improve their judgment. The other may settle for prefabricated answers and gradually lose the practice required to decide autonomously.
In this case, the difference depends on how work is organized. Many professions are learned through routine and intermediate tasks: comparing files, drafting initial versions, reviewing anomalies, preparing preliminary diagnoses, or justifying a recommendation. If those activities disappear entirely, young professionals may produce more from day one, but they may also stop going through the process by which experience is built. In the long run, the organization risks not having experts capable of detecting errors, managing exceptions, or supervising complex systems.
“In administration, automation can speed up case processing, but the ability to explain a decision, review a bias, and offer an effective avenue for recourse must be preserved”
There are several areas where exposure would be critical. In health care, a tool may help prioritize cases, but professionals must retain the ability to recognize atypical symptoms. In education, generative systems can assist in preparing materials, but they should not replace pedagogical reasoning or the contextual assessment of learners. In administration, automation can streamline case processing, but it must preserve the ability to explain a decision, review a bias, and offer an effective avenue for redress.
A public agenda for Spain and Europe
Public policy should assess these dimensions before funding, acquiring, or deploying AI systems. The criterion cannot be only how much time or money a tool saves. It is also important to ask what competencies it creates, which it reduces, what knowledge remains within the institution, and what would happen if the system were no longer available.
First, every major public AI project should include a human-capacities audit. It would not be just about evaluating technical risks, but identifying what knowledge is strengthened, which is outsourced, and which critical functions may deteriorate.
Second, public contracts should include clear obligations for training, documentation, and knowledge transfer. The acquisition of a tool should not end with its installation. There should be a plan for the organization to understand how it works, to modify procedures, and to maintain operational alternatives.
Third, human control must be verifiable. Institutions should demonstrate who can halt an automated decision, with what information, and within what timeframe. A generic clause of supervision is not enough if professionals lack competencies or real authority.
Fourth, it is necessary to preserve professional pathways that allow the development of experts. Automation should not erase all learning tasks. Part of the work can be deliberately reserved for the development of judgment, especially in the early years of a career.
Fifth, organizations should measure dependency on providers and their ability to ensure continuity. This implies evaluating data portability, the possibility of replacing the system, access to sufficient documentation, and the existence of internal teams capable of incident management.
“A mature AI policy is not limited to accelerating adoption; it protects the conditions that permit using the technology without losing institutional autonomy”
None of these measures is intended to slow innovation. On the contrary, they aim to prevent immediate efficiency from creating long-term fragility. A mature AI policy is not limited to accelerating adoption, but it protects the conditions that allow using the technology without losing institutional autonomy.
A European opportunity
Europe can differentiate itself not only through rules but through a doctrine of institutional capacity. Its advantage will not lie in competing solely on the size of models, but in proving that artificial intelligence can be integrated without eroding professional judgment, public accountability, and strategic autonomy.
For Spain, this agenda offers a concrete opportunity. The digitization of administrations, the health system, education, and small and medium-sized enterprises can become a policy of institutional strengthening if every technology investment is paired with investment in human capabilities. Productivity will be more sustainable when automation expands the knowledge available rather than replacing the conditions that generate it.
“A truly sovereign institution is not the one that avoids all technological dependency, but the one that retains enough knowledge and authority to choose, correct, and replace its systems”
Digital sovereignty begins with infrastructure but ends with a society’s capacity to understand, question, and govern what it depends on. A truly sovereign institution is not the one that avoids all technological dependency, but the one that retains enough knowledge and authority to choose, correct, and, when necessary, replace its systems.