One point of standing before anything else. The binding texts are the German KI-MIG as published and the AI Regulation in its authentic language versions. This page is a working guide for a reader who does not read German; where it matters, check the instrument, and where this page and the German text diverge the German text governs.
What is the KI-MIG, and what does it not regulate?
The correct short name is KI-MIG: Gesetz zur Marktüberwachung und Innovationsförderung von künstlicher Intelligenz, the Act on market surveillance and innovation promotion for artificial intelligence. The colloquial KI-Durchführungsgesetz circulates widely; the official short form belongs in submissions and internal policies. The Bundestag adopted it on 11 June 2026 and it entered into force on 29 July 2026.
More important than what the KI-MIG regulates is what it does not. It creates no substantive obligations for providers or deployers. The requirements on risk management, data governance, technical documentation, human oversight and conformity assessment sit exclusively in the AI Regulation and apply directly. The KI-MIG organises enforcement: it names authorities, allocates competences, creates procedures, and adds one narrow national fining provision.
For a group compliance function that has a practical upside worth stating plainly. The substantive programme is European and can be built once; the German file answers a narrower question — who comes knocking, and to whom do you write. Anyone searching the KI-MIG for whether a system is high risk is reading the wrong text.
Who supervises whom?
Germany decided against a single regulator and in favour of a hybrid model. The Bundesnetzagentur is the central market surveillance authority, the central point of contact and the central complaints body; a coordination and competence centre is attached to it. Sectoral supervisors keep their competence where they already enforce harmonised product law.
| Body | Competence |
|---|---|
| Bundesnetzagentur (BNetzA) | Central market surveillance authority, central point of contact and complaints body; coordination and competence centre |
| KI-Marktüberwachungskammer (at the BNetzA) | High-risk systems in biometrics and law enforcement; independent in accordance with Directive (EU) 2016/680 |
| BfDI | High-risk AI in law enforcement, migration, asylum, border control, justice and democratic processes (Art. 74(8) AI Act) |
| BaFin | Financial sector |
| BfArM | Medical devices |
| Landesmedienanstalten | Media |
| Länder authorities | Public bodies of the Länder |
The practical consequence of this model: the answer to who supervises us hangs on the sector, not the technology. A credit institution with a scoring model and a medical device manufacturer using the same modelling approach have different supervisory addressees. A group active in several sectors has several — and, since other Member States chose different structures, a German entity may answer to a different authority from its sister company in another Member State for the same model.
The KI-Marktüberwachungskammer and the BfDI
For the applications that touch fundamental rights the legislator took two special routes. Inside the Bundesnetzagentur sits an independent KI-Marktüberwachungskammer (AI market surveillance chamber) of three members, chaired by the President of the Bundesnetzagentur, reporting annually to the Bundestag. Its independence follows the requirements of Directive (EU) 2016/680.
The BfDI, the Federal Commissioner for Data Protection and Freedom of Information, is the market surveillance authority for high-risk AI in law enforcement, migration, asylum, border control, justice and democratic processes under Article 74(8) of the AI Regulation, with rights of access to documentation and to be informed of serious incidents.
Which deadlines apply, and which have moved?
Regulation (EU) 2026/1744 of 8 July 2026, the AI digital omnibus, amends Regulations (EU) 2024/1689, 2018/1139 and 2023/1230 and entered into force on 27 July 2026 — two days before the KI-MIG. It defers the application of the high-risk obligations in Chapter III, Sections 1 to 3.
| Set of duties | Previously | Now |
|---|---|---|
| Prohibited practices (Art. 5) | 02.02.2025 | unchanged 02.02.2025 |
| AI literacy (Art. 4) | 02.02.2025 | unchanged 02.02.2025 |
| General-purpose AI models (Art. 51–56) | 02.08.2025 | unchanged 02.08.2025 |
| Transparency obligations (Art. 50) | 02.08.2026 | unchanged 02.08.2026 (labelling of systems already on the market: transition to 02.12.2026) |
| High risk under Annex III (Art. 6(2)) | 02.08.2026 | 02.12.2027 |
| High risk, product-embedded, Annex I (Art. 6(1)) | 02.08.2027 | 02.08.2028 |
Why German official publications do not mention the postponement
There is an inconsistency in circulation that is worth knowing about. The KI-MIG was expressly drafted in anticipation of the EU digital omnibus and its cross-references were adjusted accordingly. But neither the BMDS press release nor the Bundesnetzagentur publication mentions the deferral to December 2027; the BMDS notice still names 2 August 2026 for the transparency obligations — which, taken on its own, is correct.
The deferral nevertheless applies in Germany, directly by virtue of the Regulation; no national transposition is required. But there is no German official document confirming the new high-risk dates. For deadline registers, board papers and audit evidence that means one thing: cite EUR-Lex and Regulation (EU) 2026/1744 as the source, not a German authority page. A group that relies only on national communication will find either nothing on the high-risk dates or a superseded position — and an auditor who checks the citation will find the same.
What already applies today?
Attention currently sits on the high-risk regime — precisely the part that was deferred. Four other blocks are live: the prohibitions under Article 5 and the AI literacy duty under Article 4 since February 2025, the general-purpose AI obligations since August 2025, and since 2 August 2026 the transparency obligations under Article 50. For systems already on the market the labelling transition runs to 2 December 2026.
Article 50 is the block most likely to catch a customer-facing agent: disclosure that a person is interacting with an AI system, labelling of synthetic content, notice where emotion recognition or biometric categorisation is used. These duties do not depend on an Annex III classification and were not deferred.
How large are the fines really?
§ 15 KI-MIG provides a national fine of up to EUR 50,000, for documentation and information breaches. That is a narrow, specific provision and not the real exposure.
The exposure comes directly from Article 99 of the AI Regulation: up to EUR 35 million or 7 per cent of total worldwide annual turnover for the preceding financial year for prohibited practices, and up to EUR 15 million or 3 per cent for other breaches, whichever is higher where the offender is an undertaking. These amounts apply directly and require no national transposition. An internal risk assessment that puts the ceiling at EUR 50,000 understates the order of magnitude by several powers of ten.
For a foreign parent one word in that provision does the work: worldwide. The percentage is not measured against the German subsidiary's turnover. A small German entity operating a model that the group built somewhere else does not cap the group's exposure by being small.
Which entity in a group is actually caught?
The AI Regulation attaches duties by role, not by nationality, and its territorial reach is deliberately wide. Article 2(1) covers providers placing AI systems or general-purpose AI models on the Union market irrespective of whether those providers are established or located within the Union or in a third country; deployers of AI systems that have their place of establishment or are located within the Union; and providers and deployers located in a third country where the output produced by the AI system is used in the Union.
Three consequences follow for a group with a German entity.
- The typical group shape is one provider and several deployers. Where a parent builds or substantially modifies a system and rolls it out to subsidiaries, the parent is doing provider work and the German entity is deploying. Those are different duty sets, and mapping them entity by entity is the first piece of work, not the last.
- A non-EU parent is not outside the Regulation. Placing a system on the Union market, or having output used in the Union, brings a third-country provider within scope on the face of Article 2(1). A US or UK parent that treats the AI Act as its German subsidiary's problem has misread the scope provision.
- Supervision is German even where the work is not. The Bundesnetzagentur, or the relevant sectoral supervisor, is the authority that corresponds with the German entity. The model may have been built in Bangalore and approved in Boston; the letter arrives in Germany, in German, addressed to a managing director there.
What does a foreign parent have to do differently?
- Build the substantive programme once, at EU level. Germany adds no substantive requirements. Duplicating the risk-management and documentation work per country produces divergence, not assurance.
- Map the supervisor per entity and per sector. One group, several sectors, several German authorities. Record the mapping; it is the first thing anyone will ask for.
- Cite EUR-Lex for the deferred dates. Any German-facing deadline register that sources the high-risk dates to a national page is either empty or wrong on that point.
- Do not put AISI Deutschland on the governance map as a regulator. It has no supervisory function. Misdirected correspondence costs time you will not have.
- Treat § 38 BSIG as the nearer duty. It has been running since 6 December 2025 and was not deferred; see below.
- Expect the correspondence in German. Documentation held only in English remains usable but will be read by someone reconstructing your governance from a structure they have never seen.
What support does the state offer, and who is not a supervisor?
The Bundesnetzagentur hosts a KI-Service Desk as a point of contact for companies and KI-Reallabore, regulatory sandboxes for supervised testing. The BSI supplies technical, expressly voluntary orientation: Generative KI-Modelle – Chancen und Risiken für Industrie und Behörden, AI Security Concerns in a Nutshell (2023), the Kriterienkatalog zur Integration von extern bereitgestellten generativen KI-Modellen (2024), Evasion-Attacks auf LLMs, the AIC4 criteria catalogue for AI cloud services, and the German-French recommendations on AI coding assistants prepared with the ANSSI.
And a clarification, because it is regularly got wrong: AISI Deutschland, the joint AI Safety and Security Institute of the BSI and the Bundesnetzagentur, is still being established and expressly has no regulatory or market surveillance function. It evaluates and advises. Anyone listing it as a supervisory authority on a governance map has invented a competence.
What does this mean for automated processes?
Two levels worth keeping apart. In regulatory terms, a customer-facing agent meets Article 50 first: the transparency duties apply, the high-risk regime does not yet.
Operationally the pressing question is a different one: what is the system allowed to do, who approved that, and which evidence survives the transaction? That control requirement is not currently driven by the deferred high-risk regime but by § 38 BSIG, in force since 6 December 2025, which obliges the Geschäftsleitung (the managing body) to umsetzen und überwachen — to implement the risk-management measures and supervise their implementation. Not to approve them. The distinction is set out in § 38 BSIG and the liability of the managing body, and it matters here because a group that has scheduled its German AI work for December 2027 is waiting on the wrong deadline. The same collision shows up in finance systems, treated in automated invoice processing.
How does this compare with neighbouring markets?
For anyone working across borders: Germany has a statute and a named authority. The three most common comparison markets have neither.
- Switzerland: no AI act. The Federal Council decided on 12 February 2025 to ratify the Council of Europe AI Convention and otherwise to regulate sector by sector. A consultation draft is announced for the end of 2026; as at 2 September 2026 no consultation has been opened.
- United Kingdom: no AI Act, and no corresponding bill before Parliament.
- United States: no federal AI statute binding private companies. Obligations arise from state law.
The cross-market picture is set out in the AI governance guide.
In practice
What Article 50, market surveillance by the Bundesnetzagentur and § 38 BSIG have in common is that none of them asks you to show a system works. Each asks you to show its limits — what it was allowed to do, who allowed it, and what of that is still provable months later. BarzelVault applies policy and approval thresholds ahead of execution and issues signed audit receipts, across nine tools. BarzelOps runs governed cross-system workflow automation with durable state, approval checkpoints and tenant isolation.
Frequently asked questions
Does Germany have a national AI law?
Yes, the KI-MIG, in force since 29 July 2026. It governs enforcement of the AI Regulation, not the substantive obligations.
Which authority is competent?
The Bundesnetzagentur centrally. In harmonised sectors BaFin, BfArM and the Landesmedienanstalten keep competence, and the BfDI has it for certain fundamental-rights-sensitive areas.
Were the high-risk deadlines postponed?
Yes, by Regulation (EU) 2026/1744: Annex III to 2 December 2027, Annex I to 2 August 2028. German official publications do not yet record this — EUR-Lex belongs in the documentation as the source.
Do the transparency obligations already apply?
Yes, since 2 August 2026. For labelling systems already on the market a transition runs to 2 December 2026.
Is AISI Deutschland a supervisory authority?
No. It expressly has no regulatory or market surveillance function and is in any case still being established.
Is a non-EU parent in scope?
It can be. Article 2(1) reaches providers placing systems on the Union market irrespective of establishment, and third-country providers and deployers where the output is used in the Union.
Where this leads
The unusual feature of the German position is the sequencing: the enforcement structure was finished before the substance it enforces became applicable. That is comfortable for a year and awkward afterwards, because the institutional memory being built now — the KI-Service Desk queries, the sandbox files, the complaints — will be the baseline against which December 2027 is judged. The groups that will do well are not the ones that start in 2027. They are the ones whose German entity can already say which authority it answers to, and produce the mapping that says why.
In practice
Permission before the action. Evidence after it.
The duties on this page attach to the moment an automated system acts: who permitted it, on which data, under which policy version, and what a person saw before approving. Barzel enforces that decision before execution and writes the record an auditor, a regulator or a data subject can be shown.
429 days leftEU AI Act high-risk obligations (Annex III) apply from 2 December 2027
BarzelVault
The AI action firewall: decide what an agent may do before it does it.
- Approval thresholds and policy checks enforced before execution; human approvals that expire and escalate.
- Cryptographically signed audit receipts: trigger, inputs, policy version, approver, outcome.
- Credential isolation, spend and action limits, and an emergency kill switch.
Free tier: 10,000 calls a monthPaid plans from $199 a monthLive on MCPize
BarzelOps
Governed workflow automation across the systems that run the business.
- Durable, idempotent execution: a timeout is retried once, never filed twice.
- Human approval checkpoints that pause the workflow and resume it.
- Isolation per entity or client, signed evidence receipts and a portable manifest; HubSpot, Xero, Gmail, Google Drive and Slack.
Free tier: 100 calls a dayPaid plans from $19 a monthLive on MCPize
Enterprise: written quote by email within two business days. No sales call.
Related
- AI governance across markets — the cross-market guide
- § 38 BSIG: implementing and supervising, and what it means for a foreign parent
- Automated invoice processing in Germany: controls and evidence
- Audit trail requirements for AI agents
- Human in the loop: where it belongs and where it does not
- Register of corrections
- Glossary of regulatory and technical terms
Sources
- Gesetz zur Marktüberwachung und Innovationsförderung von künstlicher Intelligenz (KI-MIG), adopted by the Bundestag on 11.06.2026, in force since 29.07.2026.
- Regulation (EU) 2024/1689 (Artificial Intelligence Act) — EUR-Lex; Article 2 (scope), Article 50 (transparency), Article 99 (penalties).
- Regulation (EU) 2026/1744 of 8 July 2026 amending Regulations (EU) 2024/1689, (EU) 2018/1139 and (EU) 2023/1230, in force since 27.07.2026 — EUR-Lex.
- Bundesnetzagentur, market surveillance under the AI Regulation; KI-Service Desk and KI-Reallabore.
- BMDS, press release on the entry into force of the KI-MIG.
- BSI, Generative KI-Modelle – Chancen und Risiken für Industrie und Behörden; Kriterienkatalog zur Integration von extern bereitgestellten generativen KI-Modellen (2024); AIC4.
- § 38 BSIG, in force since 06.12.2025 — gesetze-im-internet.de.
This article is a working guide for English-speaking readers and does not constitute legal advice. The binding texts are the German KI-MIG and the AI Regulation in its authentic language versions. Position as at 3 September 2026.