The German AI Act Implementing Law – Key Provisions and Concerns

This article provides an overview of the background of the German AI Act Implementing Law, its key provisions and the main open questions that remain.

28 July 2026

Publication

Loading...

Listen to our publication

0:00 / 0:00

The German AI Act Implementing Law – whose centrepiece is the AI Market Surveillance and Innovation Promotion Act (KI-Marktüberwachungs- und Innovationsförderungsgesetz, "KI-MIG") – has been published in the Federal Law Gazette (Bundesgesetzblatt) today, on 28 July 2026 – following its adoption by the Bundestag on 11 June 2026 and the Bundesrat's consent on 10 July 2026. The law enters into force on the day after its publication.

This article provides an overview of the background of the German AI Act Implementing Law, its key provisions and the main open questions that remain.

1. Background

The EU AI Act (Regulation (EU) 2024/1689) constitutes the world's first democratically legitimated legal framework governing AI systems. However, for the AI Act to become fully effective, it requires all Member States to adopt national rules on the designation of competent authorities (Article 70 AI Act), the imposition of sanctions (Article 99 AI Act) and the facilitation of innovation (Article 57 AI Act). The KI-MIG seeks to fulfil these obligations for Germany. In line with the government's stated aim of an innovation-friendly, low-bureaucracy implementation, the KI-MIG does not introduce any additional substantive obligations for providers or deployers of AI systems beyond what the AI Act itself already requires ("no gold plating", i.e. no stricter national rules than required by the AI Act) – it is purely an organisational and procedural act.

2. Key Provisions of the German AI Act Implementing Law

2.1 Competent Authorities

The KI-MIG establishes a multi-layered supervisory architecture, distinguishing between notifying bodies and market surveillance authorities.

  • (A) Notifying bodies (section 3 KI-MIG):
    Responsibility is organised on a decentralised basis and assigned to the existing sectoral notifying bodies. For high-risk AI systems, the Federal Office for Information Security (Bundesamt für Sicherheit in der Informationstechnik, "BSI") assumes this role. In accordance with Article 28 AI Act, notifying bodies set up and carry out the procedures for the assessment, designation and notification of conformity assessment bodies, as well as their ongoing supervision.

  • (B) Market surveillance authorities (section 2 KI-MIG):
    The Federal Network Agency (Bundesnetzagentur, "BNetzA") is designated as the central authority with residual competence – i.e. it is competent in all cases where no more specific authority has been designated. Sector-specific responsibilities are allocated to:

    • the Federal Financial Supervisory Authority (Bundesanstalt für Finanzdienstleistungsaufsicht, "BaFin"), which is competent for AI systems directly connected to the provision of a regulated financial activity, including in the insurance sector;
    • the Federal Motor Transport Authority (Kraftfahrt-Bundesamt) and other sector regulators already competent under existing EU harmonised product legislation (Annex I AI Act); and
    • at state level, authorities competent under state law – section 2(6) KI-MIG assigns market surveillance for the use of AI systems by Land (state) authorities themselves (e.g. in schools, the police or the judiciary) to the respective competent Land authority.
      The independent data protection authorities at both federal and state level retain their existing competences alongside the market surveillance authorities. The tasks of market surveillance authorities generally are set out in Article 74 AI Act.
  • (C) Independent AI Market Surveillance Chamber (Unabhängige KI-Marktüberwachungskammer, "UKIM"):
    Within BNetzA, the KI-MIG establishes the UKIM as a body acting with "complete independence" and free from instructions (section 4(3) KI-MIG). It is responsible for particularly sensitive high-risk AI systems, such as those used for law enforcement, border management, and justice and democracy (Annex III AI Act), implementing the special regime of Article 74(8) AI Act. The UKIM is to submit an annual activity report to the Bundestag, starting in 2026.

  • (D) Coordination and Competence Centre (Koordinierungs- und Kompetenzzentrum, "KoKIVO"):
    Given the complexity of this multi-layered structure, section 5 KI-MIG establishes the KoKIVO at BNetzA. It pools AI-related expertise, supports the various notifying, market surveillance and accreditation bodies, promotes the uniform interpretation and application of the law across all competent authorities, and facilitates the development of codes of conduct under Article 95 AI Act.

  • (E) Central contact and complaints point:
    BNetzA also acts as Germany's single national point of contact vis-à-vis the European Commission/AI Office and other Member States and operates a central complaints office under Article 70 AI Act, forwarding submissions from citizens and businesses to the competent specialist authority.

2.2 Supervisory Powers and Procedure

Beyond designating which authority is competent (section 2.1 above), the KI-MIG also defines what those authorities may actually do once they have been designated. Their investigative and enforcement powers mirror those set out in Regulation (EU) 2019/1020 on market surveillance, including on-site inspections and, where appropriate, remote or API-based access to AI systems. Measures taken by a market surveillance authority can generally be challenged following the ordinary national rules on administrative procedure, with review by the administrative courts. For measures concerning AI systems falling under the EU harmonised legislation listed in Annex I AI Act, however, objections and appeals do not have suspensive effect.

2.3 Sanctions & Procedure

  • Sanction catalogue: Section 15(1) and (2) KI-MIG contains a catalogue of AI Act provisions whose infringement constitutes an administrative offence. This catalogue covers only the residual offences not already subject to the fining regime laid down directly in the AI Act (Article 99 AI Act). Overall, the regime on sanctions looks therefore as follows:
    • Residual offences under section 15 KI-MIG (e.g. failure to maintain required technical documentation under Article 21 AI Act, failure to carry out a fundamental rights impact assessment under Article 27 AI Act, or providing incorrect information to a notifying body under Article 45 AI Act): fines of up to EUR 50,000 (section 15(3) KI-MIG).
    • Prohibited AI practices under Article 5 AI Act (e.g. subliminal manipulation, social scoring by public authorities, or unlawful real-time remote biometric identification in publicly accessible spaces for law enforcement purposes): fines of up to EUR 35,000,000 or 7% of worldwide annual turnover, imposed directly by Article 99(3) AI Act.
    • Other AI Act infringements (Article 99(4) AI Act) (e.g. non-compliance with the substantive requirements for high-risk AI systems and the related obligations of providers, importers, distributors and deployers, or breach of the transparency obligations under Article 50 AI Act): fines of up to EUR 15,000,000 or 3% of worldwide annual turnover.
  • Procedure: Fine proceedings follow the German Act on Regulatory Offences (Ordnungswidrigkeitengesetz, "OWiG") together with the Code of Criminal Procedure (Strafprozessordnung, "StPO"), with court challenges heard by the criminal divisions of the ordinary courts. Notably, the general provisions of sections 17 and 30 OWiG on the setting of fine amounts and on corporate liability are excluded, as the level and criteria for fines are regarded as conclusively determined by Article 99 AI Act itself. It remains to be seen in practice how this exclusion interacts with existing case law, including precedent of the Federal Court of Justice (BGH) recognising an effective Compliance Management System (CMS) as a mitigating factor when setting fines under sections 17 and 30 OWiG. How this case-law will be taken into account despite the exclusion of these provisions remains an open question.
  • Whistleblower protection: The KI-MIG also extends protection under the Hinweisgeberschutzgesetz to reports concerning breaches of the AI Act.

2.4 Facilitating Innovation

The KI-MIG contains two principal instruments for the promotion of innovation and encourages competent authorities themselves to use AI to automate their own processes.

  • (A) Regulatory sandbox: Section 13(1) KI-MIG requires BNetzA to establish at least one regulatory sandbox (Reallabor), in which new technologies may be tested under regulatory supervision. This sandbox is to be operational by 2 August 2026, in line with the deadline under Article 57 AI Act. Small and medium-sized enterprises, research institutions and universities are to be granted priority access to the sandbox (section 13(3) KI-MIG).
  • (B) Real-world testing outside sandboxes: Section 14 KI-MIG sets out rules for testing high-risk AI systems under real-world conditions outside regulatory sandboxes (Article 60 AI Act). Providers wishing to conduct such tests must submit a testing plan to the competent market surveillance authority (section 14(2) KI-MIG). Notably, section 14(2) sentence 4 KI-MIG provides for deemed approval if the authority does not respond within 30 days of submission – a rule taken verbatim from Article 60(4)(b) AI Act.

2.5 AI Systems deployed in the Area of Critical Infrastructure

A notable late addition introduced by the Bundestag's Digital Committee is section 20 KI-MIG, which requires BNetzA to maintain a non-public register of AI systems deployed in the area of critical infrastructure (Annex III No. 2 AI Act). Before placing such a high-risk AI system on the market or putting it into service, providers must register both themselves and the system in this register.

3. Concerns about the new enforcement framework

A number of open questions have been raised in the legislative process and the public debate:

3.1 Fragmented Regulatory Oversight

  • The issue: competence is spread across BNetzA, BaFin, other sectoral regulators and the data protection authorities, each potentially forming its own view of the AI Act's requirements.
  • Why it matters: the KI-MIG does not provide a binding conflict-resolution mechanism for cases where these authorities arrive at diverging legal interpretations or jurisdictional conflicts arise.
  • Comparison: the GDPR addresses the same risk through the consistency mechanism under Articles 63 et seq. GDPR, which allows the European Data Protection Board to resolve disagreements between supervisory authorities – the KI-MIG has no equivalent body or procedure.

3.2 Independence of Authorities

  • The issue: it remains disputed in the legal literature whether Article 70(1) sentence 2 AI Act requires "complete independence" in the manner required for data protection authorities, or whether a lower standard suffices.
  • Why it matters: under the KI-MIG, only the UKIM is expressly granted "complete independence"; BNetzA and the other market surveillance authorities are not subject to a comparable safeguard, even though they too take decisions affecting fundamental rights.
  • Open question: even for the UKIM, concerns were raised during the legislative process as to whether its organisational set-up (qualification requirements, budgetary independence) sufficiently guarantees the 'complete independence' required by Article 42 of Directive (EU) 2016/680, which Article 74(8) AI Act expressly refers to for the conditions of such independence; some voices in the Bundestag called for the UKIM to be structured as a separate department along the lines of the Digital Services Act implementation law.

3.3 Designation of the UKIM

Article 74(8) AI Act allows Member States to entrust particularly sensitive high-risk AI systems to "an authority designated pursuant to the same conditions laid down in Articles 41 to 44 of Directive (EU) 2016/680".

  • The issue: this wording arguably presupposes an authority that already exists, rather than one newly created for the purpose of implementing the AI Act – yet the UKIM was set up from scratch by the KI-MIG.
  • Why it matters: if that reading is correct, the UKIM could not validly be "designated" under Article 74(8) at all, which would call into question the legal basis for its decisions in this sensitive area (law enforcement, border management, justice and democracy).
  • Open question: other language versions of the AI Act use a more open formulation that leaves room for a broader reading, so the point is not settled either way; it is likely to be tested in practice once the UKIM starts taking enforcement decisions.

3.4 No fines against public bodies

  • The issue: the KI-MIG does not provide for administrative fines against public bodies at all.
  • Why it matters: Article 99(8) AI Act requires Member States to lay down rules on "to what extent" – rather than "whether" – fines may be imposed on public authorities, which arguably leaves discretion only over the level of fines, not over whether they apply at all; this contrasts with the more permissive wording of Article 83(7) GDPR, which expressly leaves both the "whether" and the "to what extent" to Member States.

4. Compliance Recommendations

With the supervisory and enforcement framework for the AI Act now in place in Germany, providers and deployers of AI systems should:

  • Identify the competent market surveillance and notifying authority for their AI systems – BNetzA as the residual authority, BaFin for AI systems tied to regulated financial activities, sectoral regulators under Annex I AI Act, or the relevant state-level or data protection authority;
  • Review and, where necessary, adapt their compliance management systems in view of the applicable fining framework under the AI Act and the KI-MIG, including the exclusion of sections 17 and 30 OWiG;
  • Assess eligibility for the sandbox or real-world testing regime – in particular for SMEs, research institutions and universities, either under the regulatory sandbox at BNetzA or under the real-world testing regime in section 14 KI-MIG;
  • Prepare for the critical-infrastructure registration obligation – where high-risk AI systems are deployed in that area (Annex III No. 2 AI Act), ahead of placing such systems on the market or putting them into service;
  • Update whistleblowing procedures – to reflect that reports on AI Act infringements now fall under the Hinweisgeberschutzgesetz; and
  • Monitor further guidance – from BNetzA and the KoKIVO, and track how the open questions outlined above develop in supervisory practice.

5. Conclusion

The German AI Act Implementing Law marks a significant step towards establishing a functioning national enforcement framework for the AI Act in Germany. At the same time, the open questions outlined above suggest that further clarification – whether through guidance from the competent authorities or through future amendments – may still be needed.

This document (and any information accessed through links in this document) is provided for information purposes only and does not constitute legal advice. Professional legal advice should be obtained before taking or refraining from any action as a result of the contents of this document.