One point of standing before anything else. The binding text is the German one — the Umsatzsteuergesetz and the BSIG as published, and the BMF-Schreiben as issued. This page is a working guide for a reader who does not read German; where it matters, check the instrument, and where the two diverge the German text governs.
Why is automation a control question here and not a format question?
The formats are settled. The duty to receive has applied since 1 January 2025 to every business established in Germany, with no threshold. The duty to issue starts on 1 January 2027 for issuers whose total turnover in 2026 exceeded EUR 800,000 (§ 19 Abs. 2 UStG) and applies without exception from 1 January 2028. What must be produced is an XRechnung or a ZUGFeRD file from version 2.0.1, excluding the MINIMUM and BASIC-WL profiles, as set out in the format comparison.
That leaves the harder question, and it is not a format question at all: who caused the action, and can it be shown? A German tax audit does not ask whether the software works. It asks what the entity did, on whose authority, and what record of that survives eight years.
Which entities in a group are actually caught?
The obligation is not a group obligation and there is no consolidated discharge. The BMF FAQ sets the test in one sentence: a business is treated as domestic where it has its seat, its place of management (Geschäftsleitung), or a Betriebsstätte participating in the supply within German territory. A German VAT registration on its own is not establishment.
For an automated process this has a consequence that surprises people. Where an accounts-payable shared service centre in Kraków, Manila or Dublin processes the invoices of a German GmbH, the processing has moved and the obligation has not. The German entity remains the taxable person; its retention, its error handling and its evidence have to be attributable to it. A shared centre that handles nine jurisdictions on one rule set will tend to apply the strictest or the most familiar rule to all of them, and in the German case both instincts produce the wrong answer — as the retention section below shows.
What are the four maturity levels, and what does each demand?
| Level | What the system does | Controls required |
|---|---|---|
| 1. Assistance | Prepares the invoice; a human releases each one individually | Validation against EN 16931 before sending, storage of the structured original, a simple log |
| 2. Conditional automation | Sends by itself whatever meets defined criteria and routes the rest to a human | Documented release criteria (amount, new customer, correction), an evidence path per transaction, idempotency |
| 3. Full automation | Sends everything; humans handle exceptions only | The above plus reconciliation against the transmission channel, monitoring for unusual volumes and amounts, a defined route for invoice corrections |
| 4. Agent-assisted processes | Interprets data and decides for itself what is billed | The above plus a release threshold outside the agent, logging of model and configuration version, classification under the AI Act |
The most common implementation error is the jump from level one to level three in a single step, justified by the sentence that it works in test. Level two does not exist out of caution; it is a measuring instrument. It produces data about how the process behaves in production while somebody is still watching. Skipping it switches off the observation before anyone knows what should have been observed.
How must the incoming check be built around the BMF error taxonomy?
This is the single highest-value building block, and it is reflected in almost no inbound check. The BMF-Schreiben of 15 October 2025 distinguishes three classes of error, and only one of them endangers the input VAT deduction.
| Class of error | Subject matter | Appropriate handling |
|---|---|---|
| Format error | Breach of the EN 16931 syntax | Accept with a note; clarify technically with the issuer. No payment stop. |
| Breach of a business rule | A plausibility rule of the standard is violated | Processing may continue; assess case by case. A cluster is a supplier issue, not an accounting issue. |
| Content error | Mandatory particulars under § 14 Abs. 4 UStG missing or incorrect | The only class that endangers the input VAT deduction. Withhold the deduction and the payment; request a correction. |
Both extremes are expensive. A check that turns every validation finding into a rejection blocks payment runs with no legal cause and generates clarification work with suppliers who have done nothing wrong. A check that validates only the syntax misses precisely the class that costs money, because a missing tax number is syntactically unremarkable.
On the return leg: a Rechnungsberichtigung (invoice correction) must itself be an E-Rechnung and must refer unambiguously to the original invoice. A pure reduction in consideration under § 17 UStG requires no correction at all — a distinction routinely absent from the rule sets of automated processes, and a reliable source of unnecessary correction loops.
Why is archiving most at risk in exactly the automated chains?
The retention period is eight years under § 14b UStG, not ten. Numerous internal policies still carry the old figure, and English-language coverage gets it wrong routinely. At least the structured part must be kept intact in its original form. The GoBD apply in addition; storage outside a GoBD-certified system is not in itself a breach. Our register of corrections tracks the ten-year error.
For a group this cuts twice. Over-retention is not a safe default — it is a data-protection exposure and a storage cost with no legal benefit, and a global policy set at ten years is not a conservative reading of German law but a wrong one. Under-retention is the more familiar failure, but it is rarer.
The requirement breaks precisely where automation begins: at import. Any chain that normalises incoming files, converts them to an internal format, or writes only the extracted fields into a database violates it, even where nothing is lost in substance. The test question is not whether all the particulars are still present but whether the original bytes are still present. A group content platform that re-renders, re-compresses or re-indexes on ingest will fail it, and this is usually discovered late because it looks like a solved problem. Anyone who first asks the question after eight years has answered it.
Why must the XML and the image come from one source?
In hybrid formats the XML part governs. Where the PDF image diverges from it in substance, that divergence can amount to a second invoice, with a tax liability under § 14c UStG. From that follows a hard architectural constraint: the two components must not be generated along two separate paths.
In grown system landscapes that is exactly the norm — the PDF comes out of a reporting tool, the XML out of an interface. As long as both read the same master data, nothing shows. They will diverge eventually, and the trigger will be a change nobody connects with invoices: a new address format, a rounding setting, a currency label. On the inbound side the mirror image applies. Many systems still extract from the image, by OCR or through an existing document-capture route, because that works without rebuilding anything. When the two halves diverge, the legally decisive content is the one nobody looked at.
Where do AI agents leave the existing frame?
Level four differs qualitatively, not by degree. A deterministic process does what is configured; an agent does what it judges right in context. Two consequences decide the control design.
The control cannot sit inside the agent. If the same model that triggers the operation also decides whether the operation needs a release, what exists is not a control but a self-declaration. The threshold belongs in a layer the agent must pass through and cannot bypass. This is the same principle as approving AI actions and keeping a human in the loop at defined points, rather than everywhere or nowhere.
Reproducibility requires version data. A deterministic run is reconstructed by executing the same code on the same data. With an agent, the re-run produces a new decision, not an explanation of the old one. Without a recorded model and configuration version it cannot even be established whether the behaviour at the time was correct. The NSA guidance on securing Model Context Protocol environments of May 2026 states the minimum standard in the same terms: log all tool and model calls with exact parameters, identities and cryptographic result hashes, and treat every tool output as untrusted input to the next stage. A durable audit trail for AI agents is therefore a precondition, not a refinement.
Which supervisory duties run alongside?
| Duty | Applies from | Authority |
|---|---|---|
| § 38 BSIG — implement, supervise, train | 6 December 2025 (running) | BSI |
| AI Act transparency obligations | 2 August 2026 | market surveillance |
| KI-MIG in force | 29 July 2026 | Bundesnetzagentur; sectoral supervision remains (BaFin) |
| High risk under Annex III of the AI Act | 2 December 2027 | Bundesnetzagentur |
| High risk under Annex I of the AI Act | 2 August 2028 | Bundesnetzagentur |
Both regimes demand the same thing at heart: that somebody can say what the systems are allowed to do, and can show that the controls work. § 38 BSIG obliges the Geschäftsleitung (the managing body) to umzusetzen und ihre Umsetzung zu überwachen — to implement the risk-management measures and supervise their implementation. It is not a duty to approve them. It establishes a liability towards the entity itself under the company law applicable to its legal form, and a non-delegable training duty; the reporting deadlines are 24 hours, 72 hours and one month. The detail sits in § 38 BSIG and the liability of the managing body, and the distinction matters more to a foreign parent than to anyone else, because the English word most groups have written into their NIS-2 programme is the wrong one.
For prioritisation, one point outranks the rest. The AI Act high-risk deadlines were postponed to December 2027 and August 2028 — § 38 BSIG was not postponed. The nearer duty is the cybersecurity one. A group that takes the AI Act dates as its planning anchor is planning past a clock already running. For the AI Act dates EUR-Lex is authoritative; German authority publications do not all reflect the postponement, which is treated at length in KI-MIG and the Bundesnetzagentur.
What does a foreign parent have to do differently?
- Set the German retention parameter separately. Eight years under § 14b UStG. A group standard of ten is not caution; it is a different rule applied to the wrong jurisdiction.
- Prove the archive keeps original bytes. Test the group content platform with a real XRechnung and a real ZUGFeRD file, and compare the retrieved copy byte for byte. Substantive equivalence is not the standard.
- Split the inbound check three ways. Log format errors, assess business-rule breaches, escalate only content errors under § 14 Abs. 4 UStG. A single global rule of reject-on-any-finding will stop German payment runs.
- Keep the evidence attributable to the German entity. Shared-service processing moves the work, not the obligation. Records that identify only a group service account cannot show which taxable person acted.
- Read § 38 BSIG in German before writing the group control narrative. Implement-and-supervise is a continuing duty; approve is a minuted decision. A programme built for the second does not discharge the first.
- Assume the audit is conducted in German. Control descriptions, field definitions and release records that exist only in English remain usable, but will be read by someone reconstructing your process from a schema they have never seen. Bilingual definitions cost little now.
How do you test the real maturity level?
There is one exercise that shows the maturity level more reliably than any documentation. Take an arbitrary invoice from the stock of three months ago and reconstruct the whole transaction: what triggered it, with which parameters, who released it, what the outcome was. Without application logs.
The exclusion is the point. Application logs rotate, and the retention period is eight years — what exists only in a log does not exist at the moment of audit. If the reconstruction takes longer than a few minutes, or requires a developer, the process has arrived at level three or four without bringing the corresponding controls with it. Run it on the German entity specifically, not on the group instance, because the German answer is the one that has to stand on its own.
In practice
At levels three and four the audit question moves from format to responsibility, and the record of what released a payment becomes the evidence. BarzelVault applies policy and approval thresholds ahead of execution and issues signed audit receipts, across nine tools. BarzelOps runs the cross-system workflow with durable state, approval checkpoints and tenant isolation, so each German entity's operations stay attributable to that entity.
Frequently asked questions
At what level does the process need its own control layer?
At level three at the latest. From that point no control survives that assumes somebody sees the individual document, so release criteria, idempotency, channel reconciliation and volume monitoring have to be explicit.
Must an incoming check reject every faulty E-Rechnung?
No. Only content errors under § 14 Abs. 4 UStG endanger the input VAT deduction. Format errors and business-rule breaches should be recorded but do not justify a payment stop.
How long must automatically processed E-Rechnungen be kept?
Eight years under § 14b UStG, with at least the structured part intact in its original form. Not ten years — that figure is widespread and wrong for Germany.
May an AI agent decide on release by itself?
As a control it does not work. The threshold has to be enforced outside the model that triggers the operation, in a layer the agent cannot bypass.
Which AI Act deadlines affect invoice processes?
Transparency obligations from 2 August 2026, Annex III from 2 December 2027, Annex I from 2 August 2028. The KI-MIG has applied since 29 July 2026 and the Bundesnetzagentur is the market surveillance authority.
Does the group parent have its own duty?
Not unless it is established in Germany. But it sets the retention parameter, the archive platform and the automation rules, so it can breach the German rule on behalf of a subsidiary that never made the decision.
Where this leads
Nothing in this regime is technically difficult. What makes it fail is that the decisions are taken in one place and the liability sits in another: the retention parameter is set by a group policy owner, the archive by an infrastructure team, the inbound rules by a shared service centre, and the consequence lands on a German managing director who was not in any of those meetings. The reconstruction test is worth running for that reason alone. It is the only exercise on this page that cannot be passed by writing something down.
In practice
The control has to run before the invoice becomes irreversible.
An accepted structured invoice can be corrected but never deleted, and from the penalty date every defect has a price. Barzel puts the approval threshold, the duplicate check and the signed record in front of submission, so the process can be defended on the day an auditor or the tax authority asks.
95 days leftE-Rechnung issuing duty from 1 January 2027 for 2026 turnover above €800,000
BarzelVault
The AI action firewall: decide what an agent may do before it does it.
- Approval thresholds and policy checks enforced before execution; human approvals that expire and escalate.
- Cryptographically signed audit receipts: trigger, inputs, policy version, approver, outcome.
- Credential isolation, spend and action limits, and an emergency kill switch.
Free tier: 10,000 calls a monthPaid plans from $199 a monthLive on MCPize
BarzelOps
Governed workflow automation across the systems that run the business.
- Durable, idempotent execution: a timeout is retried once, never filed twice.
- Human approval checkpoints that pause the workflow and resume it.
- Isolation per entity or client, signed evidence receipts and a portable manifest; HubSpot, Xero, Gmail, Google Drive and Slack.
Free tier: 100 calls a dayPaid plans from $19 a monthLive on MCPize
Enterprise: written quote by email within two business days. No sales call.
Related
- The receipt obligation in force since 1 January 2025
- The 2027 issuing mandate and the EUR 800,000 threshold
- XRechnung and ZUGFeRD: formats, profiles and cross-border pitfalls
- § 38 BSIG: implementing and supervising, and what it means for a foreign parent
- KI-MIG and the Bundesnetzagentur: how the AI Act is supervised in Germany
- Audit trail requirements for AI agents
- Workflow automation
- Glossary of regulatory and technical terms
Sources
- § 14, § 14b, § 14c, § 17, § 19 Abs. 2 Umsatzsteuergesetz (UStG) — gesetze-im-internet.de.
- BMF-Schreiben vom 15.10.2025, III C 2 - S 7287-a/00019/007/243 — classes of error, retention, correction.
- BMF, FAQ E-Rechnung, Stand March 2026 — definition of inländisches Unternehmen, e-mail inbox, eight-year retention.
- BMF-Schreiben vom 15.10.2024, III C 2 - S 7287-a/23/10001 :007. No live official URL; the Schreiben of 15 October 2025 supplements it and does not replace it.
- BSIG in the version of the NIS2UmsuCG, in force since 06.12.2025 — in particular § 38.
- Regulation (EU) 2024/1689 (Artificial Intelligence Act) — EUR-Lex.
- Regulation (EU) 2026/1744 of 8 July 2026, in force since 27.07.2026 — deadlines for Annex III and Annex I.
- Gesetz zur Marktüberwachung und Innovationsförderung von künstlicher Intelligenz (KI-MIG), in force since 29.07.2026.
- NSA, guidance on securing Model Context Protocol environments, May 2026. Not linked: no verified official URL.
- EN 16931 — European standard for electronic invoicing, published by CEN. Not linked: the standard is sold, not published openly.
This article is a working guide for English-speaking readers and does not constitute tax, legal or compliance advice. The binding text is the German one. Position as at 3 September 2026.