Germany’s KI-MIG puts BNetzA in charge of AI oversight as BaFin addresses financial-sector AI risks

Summary

Germany’s KI-MIG is the national law that puts the EU AI Act into practice on German soil, naming the Federal Network Agency (BNetzA) as the country’s lead AI regulator while handing the financial supervisor, BaFin, its own separate rulebook for AI risk inside banks and insurers. For nearly two years, companies building or using AI (Artificial Intelligence) in Germany had rules to follow but no clear address to send questions to. That gap has now closed, and it closed with real financial teeth: penalties for the worst violations can reach €35 million or 7% of a company’s global annual revenue, whichever number is bigger.

At a Glance

Topic Key Body What Changed
General AI oversight BNetzA (Federal Network Agency) Named central AI Act supervisor via the KI-MIG law
Financial sector AI BaFin Issued guidance on AI-related IT risk under DORA
Data protection BfDI Continues handling AI’s personal data angle
Cybersecurity BSI Covers AI security on a transitional basis
Accreditation DAkkS Certifies bodies that assess high-risk AI systems
Worst-case fine BNetzA / EU AI Act Up to €35 million or 7% of global turnover

Why Germany Needed a Law Like This

The EU AI Act is one rulebook shared by 27 countries, but each of those countries still had to pick someone to enforce it locally. Brussels wanted that decided by August 2025. Almost nobody made it — only 8 of the 27 member states had their authority in place by then, and Germany, usually careful about deadlines like this, was one of the ones still scrambling.

Without a clear point of contact, businesses simply didn’t know who to call if a question or complaint came up. Lawyers and compliance teams spent months guessing.

It Took Over a Year to Get It Right

German lawmakers didn’t want to rush out a half-baked fix. So they spent well over a year working on it instead — which meant Europe’s largest economy went without a proper AI enforcement setup for a stretch. The trade-off: the bill reportedly went through more than 1,000 amendment proposals before it was finalized. Slow, but thorough.

KI-MIG: Germany’s Version of the Rulebook

Three Jobs, One Law

Its full name is a mouthful — the SIMSIP Act (AI Market Surveillance and Innovation Promotion Act), thankfully shortened to KI-MIG. The EU AI Act sets the actual rules; KI-MIG is just Germany’s way of making those rules workable day to day.

According to KI-MIG, it handles three things:

  1. Names which agencies are responsible for what
  2. Defines the investigative powers those agencies hold
  3. Sets out penalties for companies that fall short

It doesn’t add new obligations on top of the EU (European Union) rules. It’s mostly plumbing — building the machinery needed to enforce requirements that already existed at the European level.

How It Moved Through Parliament

  • February 2026 — The federal cabinet approves the draft bill
  • June 2026 — The Bundestag (lower house of parliament) passes it
  • July 2026 — The Bundesrat (upper house) gives its approval
  • July 29, 2026 — The law officially enters into force

That final date wasn’t a coincidence. It landed just days before August 2, 2026, when the toughest provisions of the EU AI Act became applicable across Europe. Germany finished its homework right before the deadline bell rang.

So Who’s In Charge?

Germany didn’t set up a brand-new agency for this. Lawmakers instead gave the job to a regulator that already handles complicated digital rules — the same body that oversees telecoms and the EU’s Digital Services Act. The Federal Network Agency, or BNetzA, is now the place to go for anything AI Act related.

It’s already opened an AI Service Desk for public questions and runs an internal hub — nicknamed KoKIVO — to keep other regulators on the same page, so companies aren’t getting different answers from different offices depending on who they ask.

Everyone Else Keeps Their Piece

BNetzA doesn’t handle everything alone. A few specialist bodies still cover their own ground:

  • DAkkS accredits the labs and inspectors who certify high-risk AI systems before they reach the market
  • BfDI still owns anything touching personal data
  • BSI covers AI-related cybersecurity on a transitional basis, until a permanent arrangement is finalized under separate EU cyber rules
  • BaFin keeps full authority over AI used inside banks and insurers — the subject of the second half of this article
  • Sector regulators overseeing products like medical devices, machinery, and radio equipment retain competence for AI embedded in those specific products

What It Costs to Get This Wrong

KI-MIG doesn’t invent its own penalty scale — it just adopts the EU AI Act‘s existing three-tier fine structure, and there’s no special German discount for local companies.

How the Fines Break Down

Violation Type Maximum Fine
Prohibited AI practices €35 million or 7% of global annual turnover
Other high-risk violations €15 million or 3% of global annual turnover
Providing incorrect information to regulators €7.5 million or 1% of global annual turnover
Cooperation and documentation failures (national add-on) Up to €50,000

Smaller companies aren’t let entirely off the hook, but the rules do scale fines to company size — a firm earning €10 million in annual revenue, for instance, would face a proportionally smaller ceiling than a multinational, even for the same category of violation. Regulators have also signaled they plan active enforcement, including anonymous test purchases in online and physical stores, rather than waiting passively for complaints to arrive.

Three Things Worth Doing Now

If your business builds or deploys what regulators classify as “high-risk” AI — think hiring algorithms, credit scoring tools, or AI embedded in medical devices — three practical items deserve immediate attention:

  1. Book conformity assessments early. High-risk systems require independent certification before commercial use. Inspection bodies such as TÜV Süd, TÜV Rheinland, and DEKRA are already handling this work, and capacity is limited, so early applications matter.
  2. Organize your technical documentation now. Regulators can legally demand access to training data, testing records, and technical files. Scattered paperwork will slow down any audit dramatically.
  3. Don’t mistake quiet enforcement for lenient enforcement. Few public fines had been issued as of mid-2026, but that likely reflects a young system still finding its footing — not a promise of leniency going forward. Regulators overseeing Germany’s GDPR rollout followed a similar pattern, with significant fines arriving roughly 18 to 24 months after enforcement formally began.

BaFin Has Its Own Rulebook, Too

It Builds On Rules That Already Existed

BNetzA handles AI broadly, but Germany‘s financial watchdog decided banks and insurers needed something more specific. In January 2026, BaFin published a 35-page guidance document on treating AI as a genuine technology risk, not just another business feature.

It’s not a standalone new law. It builds on DORA (Digital Operational Resilience Act), an EU regulation that already makes financial firms manage technology risk carefully. What BaFin has really done is translate that — spelling out how AI systems, especially chatbots and large language models, fit inside rules that already existed. The guidance is aimed mainly at institutions covered by the Capital Requirements Regulation and insurers supervised under Solvency II.

“Non-Binding” Doesn’t Mean You Can Skip It

BaFin officially calls this document non-binding advice, not hard law. In practice, that label is a bit misleading.

If a bank ignores the guidance and does its own thing, and something later goes wrong, it will likely have to prove to auditors that its alternative approach was just as safe. That’s a much harder conversation than simply following what BaFin already wrote down. Plenty of compliance teams in German finance are already treating this “advice” as a checklist, because that’s basically how it gets used in supervisory reviews. BaFin also has real fining power of its own, in roughly the same range as the broader AI Act penalties — among the highest in German financial regulation.

What’s Actually In the Guidance

BaFin’s document follows an AI system through its whole life — from the moment data is first collected to the day the system gets switched off. Security and stability come up at every stage.

Four Things BaFin Is Watching Closely

  • Data quality — weak or biased training data leads to unreliable, sometimes risky outputs
  • Attacks on the model itself — including attempts to manipulate, poison, or trick an AI system into misbehaving
  • Third-party and cloud dependence — many banks rent AI infrastructure rather than building it in-house, adding a layer of external risk
  • Vendor lock-in — becoming so reliant on a single cloud or AI provider that switching later becomes impractical

The guidance also walks through a real-world-style case study of a bank running a chatbot-based AI assistant across multiple systems, illustrating step by step how those risks should be evaluated and documented.

Look at both moves together and the message is pretty clear. Germany wasn’t willing to treat AI oversight as an afterthought bolted onto older rules — it wanted a dedicated authority in BNetzA, and in finance, its own tailored playbook from BaFin. Both landed just in time for the EU AI Act’s biggest compliance deadline yet.

For any company building or deploying AI in Germany, the practical takeaway is simple: identify exactly which regulator applies to your business, get your technical documentation organized well ahead of any audit, and never assume “non-binding” guidance is something you can quietly ignore. Regulators rarely forget the papers they’ve already published — and they remember even more clearly who chose not to follow them.

 

Latest

Employee Due Diligence

What actually does the term Due Diligence mean? The term...

Operational Due Diligence – A Critical Review Of Business Operations

Defining Operational Due Diligence Operational due diligence (ODD) is...

Forensic Due Diligence Services

Certified Due Diligence Specialists are some times required to...

Reputational Due Diligence Services

Auditronix which is the leader in due diligence certifications...

Join Us

spot_img

Don't miss

Apurva Joshi
Apurva Joshi
Apurva Joshi is the Director of Riskpro. She handles the Due Diligence segment for the company. She is a Certified Forensic Accounting Professional and has completed Management Consultancy Certification from IIM - Bangalore. She is the author of Best Selling Textbook " Students Handbook on Forensic Accounting"

India–EU FTA: What 91% Tariff Coverage Means for Indian Exporters

Summary India and the EU (European Union) concluded negotiations for a FTA (Free Trade Agreement) on 27 January 2026. Legal scrubbing of the agreement was...

India and Germany: Navigating AML, sanctions and compliance across borders

Summary India and Germany are strengthening their economic relationship through trade, technology, investment and financial services. Germany remains India's largest trading partner within the European...

The India–EU FTA Isn’t Just About Lower Duties—It’s About Winning the Next Global Supply Chain Race

The proposed India–European Union (EU) Free Trade Agreement (FTA) is shaping up to be one of the most significant trade deals negotiated by either...