In short
Germany's AI Market Surveillance and Innovation Promotion Act (KI-MIG) of 22 July 2026 entered into force on 29 July 2026 and makes the Bundesnetzagentur the national market surveillance authority for AI. It establishes a central coordination and competence centre, mandates at least one AI regulatory sandbox, and provides for fines of up to 50,000 euros.
Table of Contents
- 1.Short answer: who supervises AI in Germany?
- 2.The KI-MIG in five sentences: enactment, entry into force, regulatory purpose
- 3.What the Bundesnetzagentur may now do: Sections 2 and 5 KI-MIG
- 4.Who nonetheless remains competent: BaFin, the state media authorities and the sectoral remainder
- 5.EU level and national level in direct comparison
- 6.The date conflict around the AI sandbox: 2026 or 2027?
- 7.AI service desk and AI sandbox: the two concrete offerings for companies
- 8.What to do now: eight items with a named owner
- 9.Delimitation from NIS2, DORA and the CRA: which supervisor for which duty
Short answer: who supervises AI in Germany?
The AI Market Surveillance and Innovation Promotion Act (KI-MIG) of 22 July 2026 entered into force on 29 July 2026 under its Article 5. Under Section 2(1) KI-MIG the Bundesnetzagentur is the market surveillance authority competent for compliance with Regulation (EU) 2024/1689. Section 5 establishes a central coordination and competence centre there, and Section 15 provides for national fines of up to 50,000 euros (see https://www.gesetze-im-internet.de/ki-mig/BJNR0DF0B0026.html).
One sentence for the next steering board: since 29 July 2026 AI supervision in Germany has a name, an address and a legal basis — the Bundesnetzagentur, Section 2(1) KI-MIG.
The KI-MIG in five sentences: enactment, entry into force, regulatory purpose
The act carries the enactment date 22 July 2026 and was promulgated in the Federal Law Gazette 2026 Part I No. 223; Article 5 sets entry into force at 29 July 2026 (see https://www.gesetze-im-internet.de/ki-mig/BJNR0DF0B0026.html). Its name already summarises its regulatory purpose: market surveillance on one side, innovation promotion on the other. Both are tasks that Regulation (EU) 2024/1689 assigns to member states without filling them in itself. The German Federal Ministry for Digital Affairs and State Modernisation announced entry into force in press release 47/2026 of 29 July 2026 (see https://bmds.bund.de/aktuelles/pressemitteilungen/detail/neues-ki-gesetz-tritt-in-kraft).
The reason a separate national act was needed lies in the construction of the AI Act itself. The regulation applies directly in all member states and creates the substantive catalogue of obligations entirely at European level (see https://eur-lex.europa.eu/eli/reg/2024/1689/oj). It leaves three questions to the member states, however: which authority enforces that catalogue, where companies find a regulatory sandbox for testing AI systems, and which national penalties apply alongside the European ones. Those are exactly the three gaps the KI-MIG closes — no more and no less.
For delivery practice the distinction is decisive. The KI-MIG does not change what your organisation has to do. It changes who asks you about it, where third parties can turn, and which additional sanctions track you must reckon with in national law. The catalogue of obligations stays European; enforcement becomes German. Organisations that already built their compliance position along the regulation — clarifying the provider versus deployer role, classifying risk per system, handling transparency marking — do not need to redo that work. Anyone still facing it will find the structured entry point in our EU AI Act compliance guide.
What changes with a designated market surveillance authority is the same in every product regulation: the timetable becomes binding. As long as no authority is designated, the obligations exist on paper but without a counterpart. From the moment of designation there is a body that can demand information and a channel through which competitors, employees and customers can raise concerns. That is precisely why 29 July 2026 matters more for internal prioritisation than its modest media coverage suggests.
What the Bundesnetzagentur may now do: Sections 2 and 5 KI-MIG
The core of the act sits in Section 2(1): the Bundesnetzagentur is the market surveillance authority competent for compliance with Regulation (EU) 2024/1689 (see https://www.gesetze-im-internet.de/ki-mig/BJNR0DF0B0026.html). That is a decision of principle with signalling effect. The legislator could equally have distributed supervision across several sectoral authorities — the result would have been a competence map that companies first had to decipher. Instead there is one principal addressee.
Section 5 adds a central coordination and competence centre at the Bundesnetzagentur for Regulation (EU) 2024/1689. For groups with a distributed AI landscape this is the practically more important provision: it prevents implementation from fragmenting into as many readings as there are bodies involved. For your own governance it means interpretation questions now have a visible destination — and that a position documented there carries more weight than an in-house interpretation.
heise online summarises the new allocation of roles by noting that the Bundesnetzagentur takes on three functions at once: central market surveillance authority, national contact point and official complaints body for infringements of the EU AI regulation (see https://www.heise.de/news/Neue-Befugnisse-Bundesnetzagentur-uebernimmt-KI-Aufsicht-in-Deutschland-11383935.html). The third role is routinely underestimated in risk analyses. An official complaints body means the first contact with the supervisor usually does not start with a filing of your own, but with a third-party report.
Operationally that calls for an unspectacular but effective preparation: a named contact towards the Bundesnetzagentur with a designated deputy, a defined internal escalation route for official correspondence, and a storage location where the product-related documentation per AI system can actually be found. Settling those three points before the first request for information turns a potential fire drill into a routine matter.
- Central market surveillance authority for Regulation (EU) 2024/1689 — legal basis Section 2(1) KI-MIG
- Central coordination and competence centre for the regulation — legal basis Section 5 KI-MIG
- National contact point for companies and official complaints body for infringements — as characterised by heise online
- Operating at least one AI regulatory sandbox — legal basis Section 13 KI-MIG
- Pursuing national administrative offences with fines of up to 50,000 euros — legal basis Section 15 KI-MIG
Who nonetheless remains competent: BaFin, the state media authorities and the sectoral remainder
A central addressee is not the same as an exclusive one. heise online explicitly notes that BaFin and the state media authorities retain their sectoral competences alongside the Bundesnetzagentur (see https://www.heise.de/news/Neue-Befugnisse-Bundesnetzagentur-uebernimmt-KI-Aufsicht-in-Deutschland-11383935.html). Concluding that there is now only one counterpart plans past reality — particularly in financial services and in anything touching media distribution.
For governance this produces a two-axis allocation. Axis one is the classification of the system under Regulation (EU) 2024/1689: prohibited practice, high-risk system, transparency case or uncritical. Axis two is the sectoral classification of the use case: financial services, media, general industry. Only the combination of both axes answers the question of who writes to you when something happens — and who reads along. An AI-supported scoring model inside a supervised institution is a different matter from the same model in an industrial company, even though the AI Act states identical requirements for both.
In practice: keep a dedicated column for sectoral supervision in the AI inventory. It is cheap to maintain and answers within minutes a question that would otherwise require enquiries to three departments. For systems producing AI-generated or manipulated content, the media law perspective is added on top — the substantive framing is set out in our article on the Article 50 transparency obligations.
The KI-MIG concentrates market surveillance; it does not clear the supervisory landscape. BaFin and the state media authorities keep their sectoral competences — plan for a principal addressee, not for the only one.
EU level and national level in direct comparison
The most common misconception after a national implementing act enters into force is that the act has "transposed" and therefore replaced the European requirements. With the KI-MIG the opposite is true. The substantive catalogue of obligations remains unchanged in Regulation (EU) 2024/1689 (see https://eur-lex.europa.eu/eli/reg/2024/1689/oj); the KI-MIG governs competence, coordination, the regulatory sandbox and a supplementary national sanctions track. The comparison below separates the two cleanly.
The sanctions logic deserves particular attention. Section 15 KI-MIG provides for fines of up to 50,000 euros — this national administrative-offence track sits alongside the sanctions regime of Regulation (EU) 2024/1689 and does not replace it (see https://www.gesetze-im-internet.de/ki-mig/BJNR0DF0B0026.html). Carrying only the national figure in the risk register structurally understates the exposure; carrying only the European regime misses an additional track that bites faster. Both belong in the register, with the legal basis stated per line.
| Obligation or function | Legal basis | Competent body | Sanctions regime |
|---|---|---|---|
| Substantive requirements for AI systems (risk classes, provider and deployer duties) | Regulation (EU) 2024/1689 | Market surveillance by the Bundesnetzagentur (Section 2(1) KI-MIG) | Sanctions regime of Regulation (EU) 2024/1689 |
| Transparency duties for AI-generated or manipulated audio, image, video and text content | Regulation (EU) 2024/1689, applicable since 2 August 2026 | Bundesnetzagentur; state media authorities retain their sectoral competence | Regime of the regulation, supplemented by Section 15 KI-MIG |
| Central coordination of implementation | Section 5 KI-MIG | Central coordination and competence centre at the Bundesnetzagentur | No separate sanctions regime — coordination and implementation function |
| National contact point and official complaints body | KI-MIG, as characterised by heise online | Bundesnetzagentur | No separate sanctions regime — intake channel for third-party reports |
| Provision of an AI regulatory sandbox | Section 13 KI-MIG, Article 57 of Regulation (EU) 2024/1689 | Bundesnetzagentur (establishment and operation) | Not a sanctions instrument but an enabling one |
| National administrative offences | Section 15 KI-MIG | Bundesnetzagentur | Fines of up to 50,000 euros, alongside the regime of the regulation |
| AI use in supervised sectors (e.g. financial services, media) | Sectoral law alongside Regulation (EU) 2024/1689 | BaFin or the state media authorities; sectoral competence persists | Sectoral regime, in addition to the rows above |
The date conflict around the AI sandbox: 2026 or 2027?
On one point the sources contradict each other openly, and that contradiction belongs in every document that touches the topic. Article 57 of the AI Act, in the version originally adopted, requires member states to have established at least one AI regulatory sandbox at national level, operational by 2 August 2026 (see https://artificialintelligenceact.eu/article/57/). The Bundesnetzagentur, by contrast, names 2 August 2027 on its own information page and points companies to the EUSAiR pilot project until then (see https://www.bundesnetzagentur.de/ki-reallabor).
The only way to resolve this is through the amending mechanism: the AI Act timetable is modified by Regulation (EU) 2026/1744. Quoting only one of the two dates in a board document means looking wrong against the other source sooner or later — and having to correct it under time pressure in front of an audience. The defensible formulation names both dates and the mechanism in a single sentence. We broke down the systematics of these deadline shifts in our piece on the Digital Omnibus and the new AI Act deadlines.
For planning this conflict has one concrete consequence. A sandbox is not evidence of conformity but a testing environment — basing a product roadmap on a fully built national offering being available from a given date rests on an assumption that two sources date differently. The safe planning premise is therefore: your own conformity path must hold without a sandbox; the sandbox accelerates it once it is available.
Both dates belong on the same slide: Article 57 in the version originally adopted names 2 August 2026, the Bundesnetzagentur names 2 August 2027 on its own page and points to the EUSAiR pilot project until then. The amending mechanism is Regulation (EU) 2026/1744.
AI service desk and AI sandbox: the two concrete offerings for companies
The KI-MIG is not only a supervisory act. In its press release 47/2026 of 29 July 2026 on entry into force, the German Federal Ministry for Digital Affairs and State Modernisation names two concrete offerings to companies: an AI service desk and regulatory sandboxes (see https://bmds.bund.de/aktuelles/pressemitteilungen/detail/neues-ki-gesetz-tritt-in-kraft). Both are designed as support, not as further obligations — and both become relevant precisely when an interpretation question would otherwise circle internally without resolution.
The service desk is the instrument for cases where the classification of a system is contested and the cost of misclassification is asymmetric: classifying too low costs you in a supervisory case, classifying too high costs you permanently in development. For questions of that kind an official contact point is the cheapest resource available. Define internally who may use the channel and how the answer received is documented — an answer remembered from a phone call is not evidence after the fact.
The sandbox has its legal basis in Section 13 KI-MIG, which obliges the Bundesnetzagentur to establish and operate at least one AI regulatory sandbox (see https://www.gesetze-im-internet.de/ki-mig/BJNR0DF0B0026.html). It addresses supervised testing — the case where a use case is regulatorily novel and, absent precedent, the in-house legal function tends towards the maximally conservative reading. Until the national offering is fully available, the Bundesnetzagentur points to the EUSAiR pilot project (see https://www.bundesnetzagentur.de/ki-reallabor).
The realistic expectation: neither offering replaces your own compliance work. They reduce the cost of uncertainty at the two points where uncertainty is most expensive — classification and testing. The groundwork of inventory, role clarification and evidence remains inside your organisation. For collecting it in a structured way our clients use the assessment templates instead of reinventing a survey grid each time.
- AI service desk — official channel for classification and interpretation questions; define internal usage rights and documentation duties
- AI regulatory sandbox under Section 13 KI-MIG — supervised testing; a legal duty of the Bundesnetzagentur to establish and operate at least one
- EUSAiR pilot project — the interim offering the Bundesnetzagentur points to until the national sandbox is fully available
What to do now: eight items with a named owner
The list below is deliberately not the full catalogue of AI Act obligations. It is the list of what shifted in priority when the KI-MIG entered into force — that is, what has to work when the first enquiry from the Bundesnetzagentur arrives or a third party files a report there. Assign each item to a named role, not a team. In dealings with an authority, collective ownership is the most reliable way to miss a deadline.
The most effective test of that list is not a document review but a walkthrough: a letter from the Bundesnetzagentur arrives in the general company mailbox on a Friday afternoon and refers to an AI system a business unit introduced 18 months ago. Measure how long it takes for someone with decision authority to hear about it, whether the classification of the system exists in documented form, and who signs the reply. Whatever stalls in that walkthrough will stall in a real case too — only with a deadline attached.
- 1Complete the AI inventory: every AI system used or offered, with its classification under Regulation (EU) 2024/1689 and a statement of whether you act as provider or deployer. Owner: IT leadership together with business unit owners.
- 2Add sectoral supervision per system: a dedicated inventory column for BaFin or media law relevance, so nobody has to research it under pressure. Owner: compliance.
- 3Name a contact towards the Bundesnetzagentur — with a deputy, defined availability and mailbox routing for official correspondence. Owner: managing director or chief compliance officer.
- 4Review the marking of AI-generated content: the transparency duties for AI-generated or manipulated audio, image, video and text content have applied since 2 August 2026, with marking via watermarks or metadata. Owner: product management together with marketing.
- 5Make AI literacy under Article 4 of Regulation (EU) 2024/1689 demonstrable: training evidence per role, documented per person rather than as a broadcast email. Owner: HR together with business unit leadership.
- 6Build an evidence store per system: classification rationale, technical documentation, test records, release decision — in one place, findable without asking the engineering team. Owner: delivery leadership.
- 7Extend the risk register to both sanctions tracks: the regime of Regulation (EU) 2024/1689 and the national fines of up to 50,000 euros under Section 15 KI-MIG, each with the legal basis stated per line. Owner: risk management.
- 8Govern the use of the AI service desk and the sandbox internally: who may ask, how the answer is documented, and in which cases the sandbox route is the cheaper one. Owner: compliance together with the architecture function.
Delimitation from NIS2, DORA and the CRA: which supervisor for which duty
The KI-MIG lands in an environment where most mid-sized and large organisations already maintain several parallel supervisory relationships. The temptation to push everything into one shared "EU regulation" work package is understandable and expensive in outcome. NIS2 addresses the cybersecurity of entities, DORA digital operational resilience in the financial sector, the Cyber Resilience Act the security properties of products with digital elements — and the AI Act the properties and use of AI systems. Four regulatory subjects, four supervisory logics, partly the same internal roles.
In practice, errors arise less in substance than at the interfaces: an AI-supported module in a shipped product can be relevant under both the CRA and the AI Act without that implying the same reporting route or the same addressee. The construction that holds is a shared detection and assessment process with several output paths — one detection, one assessment decision, then a branch by legal basis, addressee and deadline. Where the frameworks overlap and where they genuinely diverge is broken down in detail in our 2026 regulatory collision piece.
For a quick position check in the two frameworks with the shortest deadlines, our free self-assessments are the cheapest entry point: the NIS2 readiness check and the CRA reporting readiness check each produce, in a few minutes, a result you can lift straight into a steering deck — no login required.
If you want to set up the mapping of obligation, supervisor and internal ownership properly once, instead of improvising it again with every new legal act, the scope and terms of our delivery governance engagements are set out under services and pricing; who we are and how we work is described here. The fastest first step, though, remains your own: the AI inventory, this week, one line per system, with a classification and a named owner.
Key Takeaways
- The AI Market Surveillance and Innovation Promotion Act of 22 July 2026 (Federal Law Gazette 2026 I No. 223) entered into force on 29 July 2026 under its Article 5.
- Under Section 2(1) KI-MIG the Bundesnetzagentur is the market surveillance authority competent for compliance with Regulation (EU) 2024/1689 unless the Act provides otherwise; Section 5 establishes a central coordination and competence centre there.
- The Bundesnetzagentur takes on three roles at once — central market surveillance authority, national contact point and official complaints body; BaFin and the state media authorities retain their sectoral competences alongside it.
- Section 15 KI-MIG provides for fines of up to 50,000 euros. This national administrative-offence track sits alongside the sanctions regime of Regulation (EU) 2024/1689 and does not replace it.
- On the AI sandbox the sources conflict: Article 57 in the version originally adopted names 2 August 2026, while the Bundesnetzagentur names 2 August 2027 and points to the EUSAiR pilot project until then; the amending mechanism is Regulation (EU) 2026/1744.
- The concrete offerings to companies, per ministry press release 47/2026, are the AI service desk and the regulatory sandboxes; transparency duties for AI-generated or manipulated content have applied since 2 August 2026, with marking via watermarks or metadata.
Related Assessment Templates
Continue Reading
EU AI Act Compliance Guide: What Organizations Must Do Before August 2026
Read articleThe Digital Omnibus Is Adopted: What Regulation (EU) 2026/1744 Actually Changes About the AI Act Deadlines
Read articleEU AI Act Article 50: What Applies to Chatbots and AI Content from 2 August 2026
Read articleRegulatory Collision 2026: NIS2, DORA, CRA and the AI Act — a CIO Map
Read articleFrequently Asked Questions
The AI Market Surveillance and Innovation Promotion Act carries the enactment date 22 July 2026 and was promulgated in the Federal Law Gazette 2026 Part I No. 223. Under its Article 5 it entered into force on 29 July 2026 (see https://www.gesetze-im-internet.de/ki-mig/BJNR0DF0B0026.html). It governs the national implementation structure for Regulation (EU) 2024/1689: competence, coordination, regulatory sandbox and a supplementary national sanctions track. The substantive catalogue of obligations remains European.
No, but it is the central addressee. Under Section 2(1) KI-MIG it is the market surveillance authority competent for compliance with Regulation (EU) 2024/1689 and, as characterised by heise online, simultaneously takes on the roles of national contact point and official complaints body (see https://www.heise.de/news/Neue-Befugnisse-Bundesnetzagentur-uebernimmt-KI-Aufsicht-in-Deutschland-11383935.html). BaFin and the state media authorities retain their sectoral competences alongside it. Plan therefore for one principal addressee plus a sectoral secondary axis.
Section 15 KI-MIG provides for fines of up to 50,000 euros (see https://www.gesetze-im-internet.de/ki-mig/BJNR0DF0B0026.html). The classification matters: this national administrative-offence track sits alongside the sanctions regime of Regulation (EU) 2024/1689 and does not replace it. Both tracks therefore belong in the risk register, each with its legal basis stated. Carrying only the national figure structurally understates total exposure.
The sources conflict, and both dates should be named. Article 57 of the AI Act, in the version originally adopted, requires an operational national sandbox by 2 August 2026 (see https://artificialintelligenceact.eu/article/57/). The Bundesnetzagentur names 2 August 2027 on its own page and points companies to the EUSAiR pilot project until then (see https://www.bundesnetzagentur.de/ki-reallabor). The amending mechanism for the timetable is Regulation (EU) 2026/1744. Section 13 KI-MIG obliges the Bundesnetzagentur to establish and operate at least one AI regulatory sandbox.
In its press release 47/2026 of 29 July 2026 the German Federal Ministry for Digital Affairs and State Modernisation names the AI service desk and the regulatory sandboxes as concrete offerings to companies (see https://bmds.bund.de/aktuelles/pressemitteilungen/detail/neues-ki-gesetz-tritt-in-kraft). The channel is useful wherever the classification of a system is contested and misclassification is expensive in both directions. Define internally who may ask and how the answer received is documented.
No. Regulation (EU) 2024/1689 applies directly and contains the substantive catalogue of obligations itself (see https://eur-lex.europa.eu/eli/reg/2024/1689/oj). The KI-MIG governs who enforces that catalogue in Germany, where central coordination sits, who provides a regulatory sandbox and which national fines apply in addition. For your work packages that means the substantive preparation along the regulation remains valid; what is added is the addressee, the named contact and the second sanctions track.
According to the press release of the German Federal Ministry for Digital Affairs and State Modernisation, the transparency duties for AI-generated and manipulated audio, image, video and text content have applied since 2 August 2026, with marking via watermarks or metadata (see https://bmds.bund.de/aktuelles/pressemitteilungen/detail/neues-ki-gesetz-tritt-in-kraft). Check concretely which of your output channels create or alter content, and who owns the technical implementation of the marking. The detail is covered in our article on the Article 50 transparency obligations.