Summary
Germany’s KI-MIG is the national law that puts the EU AI Act into practice on German soil, naming the Federal Network Agency (BNetzA) as the country’s lead AI regulator while handing the financial supervisor, BaFin, its own separate rulebook for AI risk inside banks and insurers. For nearly two years, companies building or using AI (Artificial Intelligence) in Germany had rules to follow but no clear address to send questions to. That gap has now closed, and it closed with real financial teeth: penalties for the worst violations can reach €35 million or 7% of a company’s global annual revenue, whichever number is bigger.
At a Glance
| Topic | Key Body | What Changed |
| General AI oversight | BNetzA (Federal Network Agency) | Named central AI Act supervisor via the KI-MIG law |
| Financial sector AI | BaFin | Issued guidance on AI-related IT risk under DORA |
| Data protection | BfDI | Continues handling AI’s personal data angle |
| Cybersecurity | BSI | Covers AI security on a transitional basis |
| Accreditation | DAkkS | Certifies bodies that assess high-risk AI systems |
| Worst-case fine | BNetzA / EU AI Act | Up to €35 million or 7% of global turnover |
Why Germany Needed a Law Like This
The EU AI Act is one rulebook shared by 27 countries, but each of those countries still had to pick someone to enforce it locally. Brussels wanted that decided by August 2025. Almost nobody made it — only 8 of the 27 member states had their authority in place by then, and Germany, usually careful about deadlines like this, was one of the ones still scrambling.
Without a clear point of contact, businesses simply didn’t know who to call if a question or complaint came up. Lawyers and compliance teams spent months guessing.
It Took Over a Year to Get It Right
German lawmakers didn’t want to rush out a half-baked fix. So they spent well over a year working on it instead — which meant Europe’s largest economy went without a proper AI enforcement setup for a stretch. The trade-off: the bill reportedly went through more than 1,000 amendment proposals before it was finalized. Slow, but thorough.
KI-MIG: Germany’s Version of the Rulebook
Three Jobs, One Law
Its full name is a mouthful — the SIMSIP Act (AI Market Surveillance and Innovation Promotion Act), thankfully shortened to KI-MIG. The EU AI Act sets the actual rules; KI-MIG is just Germany’s way of making those rules workable day to day.
According to KI-MIG, it handles three things:
- Names which agencies are responsible for what
- Defines the investigative powers those agencies hold
- Sets out penalties for companies that fall short
It doesn’t add new obligations on top of the EU (European Union) rules. It’s mostly plumbing — building the machinery needed to enforce requirements that already existed at the European level.
How It Moved Through Parliament
- February 2026 — The federal cabinet approves the draft bill
- June 2026 — The Bundestag (lower house of parliament) passes it
- July 2026 — The Bundesrat (upper house) gives its approval
- July 29, 2026 — The law officially enters into force
That final date wasn’t a coincidence. It landed just days before August 2, 2026, when the toughest provisions of the EU AI Act became applicable across Europe. Germany finished its homework right before the deadline bell rang.
So Who’s In Charge?
Germany didn’t set up a brand-new agency for this. Lawmakers instead gave the job to a regulator that already handles complicated digital rules — the same body that oversees telecoms and the EU’s Digital Services Act. The Federal Network Agency, or BNetzA, is now the place to go for anything AI Act related.
It’s already opened an AI Service Desk for public questions and runs an internal hub — nicknamed KoKIVO — to keep other regulators on the same page, so companies aren’t getting different answers from different offices depending on who they ask.
Everyone Else Keeps Their Piece
BNetzA doesn’t handle everything alone. A few specialist bodies still cover their own ground:
- DAkkS accredits the labs and inspectors who certify high-risk AI systems before they reach the market
- BfDI still owns anything touching personal data
- BSI covers AI-related cybersecurity on a transitional basis, until a permanent arrangement is finalized under separate EU cyber rules
- BaFin keeps full authority over AI used inside banks and insurers — the subject of the second half of this article
- Sector regulators overseeing products like medical devices, machinery, and radio equipment retain competence for AI embedded in those specific products
What It Costs to Get This Wrong
KI-MIG doesn’t invent its own penalty scale — it just adopts the EU AI Act‘s existing three-tier fine structure, and there’s no special German discount for local companies.
How the Fines Break Down
| Violation Type | Maximum Fine |
| Prohibited AI practices | €35 million or 7% of global annual turnover |
| Other high-risk violations | €15 million or 3% of global annual turnover |
| Providing incorrect information to regulators | €7.5 million or 1% of global annual turnover |
| Cooperation and documentation failures (national add-on) | Up to €50,000 |
Smaller companies aren’t let entirely off the hook, but the rules do scale fines to company size — a firm earning €10 million in annual revenue, for instance, would face a proportionally smaller ceiling than a multinational, even for the same category of violation. Regulators have also signaled they plan active enforcement, including anonymous test purchases in online and physical stores, rather than waiting passively for complaints to arrive.
Three Things Worth Doing Now
If your business builds or deploys what regulators classify as “high-risk” AI — think hiring algorithms, credit scoring tools, or AI embedded in medical devices — three practical items deserve immediate attention:
- Book conformity assessments early. High-risk systems require independent certification before commercial use. Inspection bodies such as TÜV Süd, TÜV Rheinland, and DEKRA are already handling this work, and capacity is limited, so early applications matter.
- Organize your technical documentation now. Regulators can legally demand access to training data, testing records, and technical files. Scattered paperwork will slow down any audit dramatically.
- Don’t mistake quiet enforcement for lenient enforcement. Few public fines had been issued as of mid-2026, but that likely reflects a young system still finding its footing — not a promise of leniency going forward. Regulators overseeing Germany’s GDPR rollout followed a similar pattern, with significant fines arriving roughly 18 to 24 months after enforcement formally began.
BaFin Has Its Own Rulebook, Too
It Builds On Rules That Already Existed
BNetzA handles AI broadly, but Germany‘s financial watchdog decided banks and insurers needed something more specific. In January 2026, BaFin published a 35-page guidance document on treating AI as a genuine technology risk, not just another business feature.
It’s not a standalone new law. It builds on DORA (Digital Operational Resilience Act), an EU regulation that already makes financial firms manage technology risk carefully. What BaFin has really done is translate that — spelling out how AI systems, especially chatbots and large language models, fit inside rules that already existed. The guidance is aimed mainly at institutions covered by the Capital Requirements Regulation and insurers supervised under Solvency II.
“Non-Binding” Doesn’t Mean You Can Skip It
BaFin officially calls this document non-binding advice, not hard law. In practice, that label is a bit misleading.
If a bank ignores the guidance and does its own thing, and something later goes wrong, it will likely have to prove to auditors that its alternative approach was just as safe. That’s a much harder conversation than simply following what BaFin already wrote down. Plenty of compliance teams in German finance are already treating this “advice” as a checklist, because that’s basically how it gets used in supervisory reviews. BaFin also has real fining power of its own, in roughly the same range as the broader AI Act penalties — among the highest in German financial regulation.
What’s Actually In the Guidance
BaFin’s document follows an AI system through its whole life — from the moment data is first collected to the day the system gets switched off. Security and stability come up at every stage.
Four Things BaFin Is Watching Closely
- Data quality — weak or biased training data leads to unreliable, sometimes risky outputs
- Attacks on the model itself — including attempts to manipulate, poison, or trick an AI system into misbehaving
- Third-party and cloud dependence — many banks rent AI infrastructure rather than building it in-house, adding a layer of external risk
- Vendor lock-in — becoming so reliant on a single cloud or AI provider that switching later becomes impractical
The guidance also walks through a real-world-style case study of a bank running a chatbot-based AI assistant across multiple systems, illustrating step by step how those risks should be evaluated and documented.
Look at both moves together and the message is pretty clear. Germany wasn’t willing to treat AI oversight as an afterthought bolted onto older rules — it wanted a dedicated authority in BNetzA, and in finance, its own tailored playbook from BaFin. Both landed just in time for the EU AI Act’s biggest compliance deadline yet.
For any company building or deploying AI in Germany, the practical takeaway is simple: identify exactly which regulator applies to your business, get your technical documentation organized well ahead of any audit, and never assume “non-binding” guidance is something you can quietly ignore. Regulators rarely forget the papers they’ve already published — and they remember even more clearly who chose not to follow them.

