AI Act · Germany
EU AI Act enforcement in Germany
Germany's KI-MIG names the Bundesnetzagentur, but BaFin keeps financial AI and a citizen complaints office can trigger enforcement.
Most summaries of German AI Act implementation stop at one sentence: the Bundesnetzagentur will supervise it. That sentence is true and close to useless, because for a large share of German deployers the Bundesnetzagentur is not the authority they will ever meet.
Germany did not appoint one regulator. It appointed four kinds.
The KI-MIG — the Gesetz zur Durchführung der KI-Verordnung, Bundestag printed paper 21/4594 — builds the institutional machinery for the Act in Germany. It adds no substantive obligations; those still come from the Regulation. What it does is decide who acts, and it splits the job:
| Who supervises | Over what |
|---|---|
| Bundesnetzagentur (BNetzA) | Central market surveillance authority; the default supervisor and the contact point for business and citizens |
| BaFin | AI in the financial sector |
| Independent AI market surveillance chamber | High-risk systems in law enforcement, border management, justice and democratic processes |
| Regional (Länder) authorities | Certain public-sector applications |
If you are a German bank or insurer, the practical consequence is that your AI supervisor is BaFin — a regulator that already examines your model governance, already has a view on validation and documentation, and already knows your institution. You are preparing for a supervisor you have met, not a new one.
If you are in any other sector, the Bundesnetzagentur is your authority: an engineering regulator whose habits come from electricity grids, rail, post and telecoms. It is comfortable with technical files and conformity assessment. It is not a rights-based regulator, and that shapes what an inspection will feel like.
The part that changes your risk profile. The KI-MIG creates a central complaints office where citizens can report suspected violations, which are then forwarded to the relevant authority. That makes third-party complaint a live enforcement route in Germany. In a member state where only an inspectorate acts, you are exposed when you are inspected. In Germany you are also exposed whenever a candidate you rejected, a customer you declined, or a former employee decides to file.
A German fine that has nothing to do with your AI
The KI-MIG draft sets administrative fines of up to €50,000 for breaches of cooperation and information obligations. Read that carefully: it penalises how you handle the regulator, not whether your system complies.
It is a small number beside the AI Act's own penalty ceilings, and it is much easier to incur. A missed deadline for producing documentation, an incomplete response, an unanswered request — these are process failures, and process failures are what organisations without a named owner for the file reliably produce.
The sandbox is a real opportunity, and it is time-limited
The KI-MIG provides for regulatory sandboxes and advisory services. This is the part most compliance coverage ignores, and it is the one with an expiry date.
Supervisory relationships are easiest to shape before enforcement begins and hardest afterwards. A regulator that has already seen your architecture in a sandbox, and said something about it, is a different regulator from one that first encounters you through a complaint in 2028. Germany is offering that window now, while the authority is still forming its own practice.
Where Germany actually stands
| Item | Position |
|---|---|
| Article 70 designation | Not complete — deadline was 2 August 2025 |
| Implementing law | KI-MIG, Bundestag printed paper 21/4594, awaiting debate |
| Enforcement start date | Not yet confirmed |
| High-risk obligations apply | 2 December 2027 (stand-alone) · 2 August 2028 (embedded) |
| Prohibitions in force since | 2 February 2025 |
Germany is one of nineteen member states that had not completed designation on the June 2026 count. That is not a reprieve. The Regulation applies directly; only the German procedural layer is outstanding.
What a German deployer should do before the KI-MIG passes
- Work out which of the four authorities is yours. Financial sector means BaFin and a very different conversation. Get this wrong and you prepare for the wrong supervisor.
- Assume complaints, not just inspections. The central complaints office means your first contact may be reactive and adversarial. Documentation that exists but takes three weeks to assemble will not survive that.
- Start the six-month log retention now. Article 26 requires deployers to retain system logs for at least six months. Logs not kept cannot be recreated, so the system has to be running correctly by roughly mid-2027 to have a compliant record on the first day.
- Name an owner for regulator correspondence. The €50,000 cooperation fine is incurred by nobody being responsible for answering, which is the default state in most organisations.
Questions
Who enforces the EU AI Act in Germany?
Under the draft KI-MIG, the Bundesnetzagentur is the central market surveillance authority. But it is not the only one. BaFin retains AI in the financial sector, an independent chamber handles law enforcement, border management, justice and democratic processes, and regional authorities cover certain public-sector applications. Which one reaches you depends on your sector, not your size.
What is the KI-MIG?
The Gesetz zur Durchführung der KI-Verordnung, Germany's act implementing Regulation (EU) 2024/1689. It creates the institutional and procedural machinery — authorities, complaints handling, sandboxes — without adding substantive requirements of its own. The obligations still come from the EU Regulation. It is Bundestag printed paper 21/4594 and had not completed passage as of September 2026.
Can we be fined under German law as well as the AI Act?
Yes, separately. The KI-MIG draft sets administrative fines of up to €50,000 for breaches of cooperation and information obligations — that is, for failing to respond properly to the regulator. That sits on top of the AI Act's own penalty regime and is triggered by how you handle an investigation rather than by the underlying compliance failure.
We are a bank. Does the Bundesnetzagentur regulate our AI?
No. The draft keeps financial-sector AI with BaFin, the federal financial supervisory authority. That matters practically: BaFin already supervises your model governance and arrives with existing expectations about documentation, validation and the three-lines-of-defence structure. You are unlikely to meet the Bundesnetzagentur at all.
Germany missed the designation deadline. Does that help us?
No. Article 70 required designation by 2 August 2025 and Germany missed it, but the AI Act is a Regulation and applies directly without national transposition. High-risk obligations arrive on 2 December 2027 for stand-alone systems and 2 August 2028 for embedded ones regardless of whether the KI-MIG has passed.
Related
Agent Trust Cloud
We publish this because the deployer side of the AI Act is widely misread, and the German split across four authorities is misread more than most. Agent Trust Cloud is building a control plane for AI agents — identity, policy, evidence. The platform is in development and is not sold as a subscription today; what is available now is a fixed-scope assessment of the agents and machine identities you already have.