
Spain's new customer service law has taken effect. Formally enacted as Ley 10/2025, de 26 de diciembre, por la que se regulan los servicios de atención a la clientela, the framework officially took effect on December 28, 2025. It grants a strict twelve-month adaptation window, meaning corporate entities must be fully compliant by December 28, 2026.
For issuing banks operating in Spain, this represents a live operational milestone. While transactional card disputes (chargebacks) remain fundamentally tethered to payment network rules, this statute acts as a supplement to existing financial service standards under Ley 44/2002, imposing rigid new performance thresholds for how bank Customer Service Departments (SAC) manage official consumer complaints and inbound queries.
What the law actually requires
The law's requirements read like a checklist for how a bank should run its complaints and disputes operation:
- 95% of calls must be answered within three minutes.
- Customers have a guaranteed right to a human agent on request.
- Complaints resolved within fifteen days, or five days where the complaint concerns an undue charge.
- Furthermore, every single interaction must be tracked against a unique reference case ID and be backed by mandatory annual external audits to verify systemic compliance, a framework thoroughly analysed in the Clifford Chance Customer Service Law Briefing.
The mandate applies immediately to essential-service providers, including banks, regardless of size. For all other consumer-facing sectors, compliance becomes mandatory for large enterprises that maintain at least 250 employees alongside either an annual turnover exceeding €50 million or a balance sheet total over €43 million, as outlined in the Augusta Abogados Legal Framework Review.
Why the "AI helps you comply" pitch misses the point
In response to this regulation, some customer service software vendors are already using it as a reason to sell conversational AI agents into support teams: regulation is coming, so automate the conversation. That argument skips over the part of the law that matters most for card disputes: guaranteed human escalation on request and a mandatory, auditable record of what happened to every complaint. Those two requirements are not solved by making a chatbot more articulate. They require absolute certainty of what your system did and why.
The Air Canada precedent
That distinction has already been tested in a real dispute. In February 2024, Canada's Civil Resolution Tribunal held Air Canada liable for a fare policy its own website chatbot had invented. Air Canada argued the chatbot was "a separate legal entity," responsible for its own words. The tribunal rejected that outright, ruling that a company is responsible for everything on its website, whether the words come from a static page or a chatbot, as documented by the American Bar Association. The chatbot did not just produce a plausible-sounding mistake in a vacuum; it hallucinated a retroactive discount that directly contradicted the airline's actual bereavement policy, even while linking the user to the correct rulebook.
That is the structural problem with large language models sitting in a regulated complaint or dispute channel. An LLM generates the most probable response to a prompt. It does not, by default, execute a fixed rule and leave a record of which rule fired. When a Spanish regulator or an internal auditor asks why a complaint was resolved in a particular way, or whether the five-day undue-charge window was met, "the model generated this response" is not an answer a compliance officer wants to give.
Deterministic systems answer the question an auditor actually asks
A deterministic system gives a different answer. Every action traces back to a defined rule: this complaint was logged under a case reference at this timestamp and resolved according to this workflow within this window.
That is the same operating principle behind Amiko, Rivero's dispute management platform for card issuers. Amiko's core decisioning runs on the chargeback and dispute rulebooks of Visa, Mastercard, and the other payment networks, with machine intelligence layered on top for specific tasks such as evidence review, not sitting in the primary decision path.
The rules define what is permissible; the intelligence layer determines what is optimal within that. Every case carries its own audit trail and reference ID, the same complaint-tracking discipline Spain's and other countries’ laws now require.
What this means for your dispute workflow
This does not eliminate AI from bank operations, but it mandates that the parts an auditor will actually inspect, such as escalation paths and resolution trails, must be built on verifiable rules rather than model-generated predictions.
Spain will not be the last European country to introduce stricter customer service laws: France, Germany, and the Netherlands are already moving in the same direction on dispute timelines and audit trails. Getting the architecture right once is worth more than patching a chatbot each time a new mandate lands.
How Amiko fits: Amiko's Virtual Agent core decisioning runs on encoded payment network rulebooks, not on a model's best guess, so every case carries a defined rule, a timestamp and a reference ID from the moment it's logged, the same audit-trail discipline many regulators and countries now require.