Germany’s KI-MIG puts BNetzA in charge of AI oversight as BaFin addresses financial-sector AI risks

Summary

Germany’s KI-MIG is the national law that puts the EU AI Act into practice on German soil, naming the Federal Network Agency (BNetzA) as the country’s lead AI regulator while handing the financial supervisor, BaFin, its own separate rulebook for AI risk inside banks and insurers. For nearly two years, companies building or using AI (Artificial Intelligence) in Germany had rules to follow but no clear address to send questions to. That gap has now closed, and it closed with real financial teeth: penalties for the worst violations can reach €35 million or 7% of a company’s global annual revenue, whichever number is bigger.

At a Glance

Topic Key Body What Changed
General AI oversight BNetzA (Federal Network Agency) Named central AI Act supervisor via the KI-MIG law
Financial sector AI BaFin Issued guidance on AI-related IT risk under DORA
Data protection BfDI Continues handling AI’s personal data angle
Cybersecurity BSI Covers AI security on a transitional basis
Accreditation DAkkS Certifies bodies that assess high-risk AI systems
Worst-case fine BNetzA / EU AI Act Up to €35 million or 7% of global turnover

Why Germany Needed a Law Like This

The EU AI Act is one rulebook shared by 27 countries, but each of those countries still had to pick someone to enforce it locally. Brussels wanted that decided by August 2025. Almost nobody made it — only 8 of the 27 member states had their authority in place by then, and Germany, usually careful about deadlines like this, was one of the ones still scrambling.

Without a clear point of contact, businesses simply didn’t know who to call if a question or complaint came up. Lawyers and compliance teams spent months guessing.

KI-MIG: Germany’s Version of the Rulebook

Three Jobs, One Law

Its full name is a mouthful — the AI Market Surveillance and Innovation Promotion Act, thankfully shortened to KI-MIG. The EU AI Act sets the actual rules; KI-MIG is just Germany’s way of making those rules workable day to day.

According to KI-MIG, it handles three things:

  1. Names which agencies are responsible for what
  2. Defines the investigative powers those agencies hold
  3. Sets out penalties for companies that fall short

It doesn’t add new obligations on top of the EU (European Union) rules. It’s mostly plumbing — building the machinery needed to enforce requirements that already existed at the European level.

How It Moved Through Parliament

  • February 2026 — The federal cabinet approves the draft bill
  • June 2026 — The Bundestag (lower house of parliament) passes it
  • July 2026 — The Bundesrat (upper house) gives its approval
  • July 29, 2026 — The law officially enters into force

That final date wasn’t a coincidence. It landed just days before August 2, 2026, when the toughest provisions of the EU AI Act became applicable across Europe. Germany finished its homework right before the deadline bell rang.

So Who’s In Charge?

Germany didn’t set up a brand-new agency for this. Lawmakers instead gave the job to a regulator that already handles complicated digital rules — the same body that oversees telecoms and the EU’s Digital Services Act. The Federal Network Agency, or BNetzA, is now the place to go for anything AI Act related.

It’s already opened an AI Service Desk for public questions and runs an internal hub — nicknamed KoKIVO — to keep other regulators on the same page, so companies aren’t getting different answers from different offices depending on who they ask.

Everyone Else Keeps Their Piece

BNetzA doesn’t handle everything alone. A few specialist bodies still cover their own ground:

  • DAkkS accredits the labs and inspectors who certify high-risk AI systems before they reach the market
  • BfDI still owns anything touching personal data
  • BSI covers AI-related cybersecurity on a transitional basis, until a permanent arrangement is finalized under separate EU cyber rules
  • BaFin keeps full authority over AI used inside banks and insurers — the subject of the second half of this article
  • Sector regulators overseeing products like medical devices, machinery, and radio equipment retain competence for AI embedded in those specific products

What It Costs to Get This Wrong

KI-MIG doesn’t invent its own penalty scale — it just adopts the EU AI Act‘s existing three-tier fine structure, and there’s no special German discount for local companies.

How the Fines Break Down

Violation Type Maximum Fine
Prohibited AI practices €35 million or 7% of global annual turnover
Other high-risk violations €15 million or 3% of global annual turnover
Providing incorrect information to regulators €7.5 million or 1% of global annual turnover
Cooperation and documentation failures (national add-on) Up to €50,000

Smaller companies aren’t let entirely off the hook, but the rules do scale fines to company size — a firm earning €10 million in annual revenue, for instance, would face a proportionally smaller ceiling than a multinational, even for the same category of violation. Regulators have also signaled they plan active enforcement, including anonymous test purchases in online and physical stores, rather than waiting passively for complaints to arrive.

Three Things Worth Doing Now

If your business builds or deploys what regulators classify as “high-risk” AI — think hiring algorithms, credit scoring tools, or AI embedded in medical devices — three practical items deserve immediate attention:

  1. Book conformity assessments early. High-risk systems require independent certification before commercial use. Inspection bodies such as TÜV Süd, TÜV Rheinland, and DEKRA are already handling this work, and capacity is limited, so early applications matter.
  2. Organize your technical documentation now. Regulators can legally demand access to training data, testing records, and technical files. Scattered paperwork will slow down any audit dramatically.
  3. Don’t mistake quiet enforcement for lenient enforcement. Few public fines had been issued as of mid-2026, but that likely reflects a young system still finding its footing — not a promise of leniency going forward. Regulators overseeing Germany’s GDPR rollout followed a similar pattern, with significant fines arriving roughly 18 to 24 months after enforcement formally began.

BaFin Has Its Own Rulebook, Too

It Builds On Rules That Already Existed

BNetzA handles AI broadly, but Germany‘s financial watchdog decided banks and insurers needed something more specific. In January 2026, BaFin published a 35-page guidance document on treating AI as a genuine technology risk, not just another business feature.

It’s not a standalone new law. It builds on DORA (Digital Operational Resilience Act), an EU regulation that already makes financial firms manage technology risk carefully. What BaFin has really done is translate that — spelling out how AI systems, especially chatbots and large language models, fit inside rules that already existed. The guidance is aimed mainly at institutions covered by the Capital Requirements Regulation and insurers supervised under Solvency II.

“Non-Binding” Doesn’t Mean You Can Skip It

BaFin officially calls this document non-binding advice, not hard law. In practice, that label is a bit misleading.

If a bank ignores the guidance and does its own thing, and something later goes wrong, it will likely have to prove to auditors that its alternative approach was just as safe. That’s a much harder conversation than simply following what BaFin already wrote down. Plenty of compliance teams in German finance are already treating this “advice” as a checklist, because that’s basically how it gets used in supervisory reviews. BaFin also has real fining power of its own, in roughly the same range as the broader AI Act penalties — among the highest in German financial regulation.

What’s Actually In the Guidance

BaFin’s document follows an AI system through its whole life — from the moment data is first collected to the day the system gets switched off. Security and stability come up at every stage.

Four Things BaFin Is Watching Closely

  • Data quality — weak or biased training data leads to unreliable, sometimes risky outputs
  • Attacks on the model itself — including attempts to manipulate, poison, or trick an AI system into misbehaving
  • Third-party and cloud dependence — many banks rent AI infrastructure rather than building it in-house, adding a layer of external risk
  • Vendor lock-in — becoming so reliant on a single cloud or AI provider that switching later becomes impractical

The guidance also walks through a real-world-style case study of a bank running a chatbot-based AI assistant across multiple systems, illustrating step by step how those risks should be evaluated and documented.

Look at both moves together and the message is pretty clear. Germany wasn’t willing to treat AI oversight as an afterthought bolted onto older rules — it wanted a dedicated authority in BNetzA, and in finance, its own tailored playbook from BaFin. Both landed just in time for the EU AI Act’s biggest compliance deadline yet.

For any company building or deploying AI in Germany, the practical takeaway is simple: identify exactly which regulator applies to your business, get your technical documentation organized well ahead of any audit, and never assume “non-binding” guidance is something you can quietly ignore. Regulators rarely forget the papers they’ve already published — and they remember even more clearly who chose not to follow them.

 

Due Diligence Resources

Sanctions Due Diligence in India

Sanctions and due diligence are interconnected concepts in international...

Defining Due Diligence in India

Due diligence is a structured investigative and analytical process...

What is Enhanced Due Diligence

What is Enhanced Due Diligence? Enhanced Due Diligence (EDD) is...

Mystery Shopping services for Banks in India

Mystery shopping is termed as seeding in the banking...

InstaReports for Global Due Diligence Practitioners

Riskpro Technology is a company that specializes in providing...

India–EU FTA: What 91% Tariff Coverage Means for Indian Exporters

Summary India and the EU (European Union) concluded negotiations for...

India and Germany: Navigating AML, sanctions and compliance across borders

Summary India and Germany are strengthening their economic relationship through...

Riskpro Technology Built Ledgerlens for Modern Financial Intelligence

Financial investigations today are no longer limited to reviewing...

Power Your Business Billing Directly Inside WordPress with Billflow by Riskpro

Billflow is a powerful invoicing and billing solution built...

Corporate Due Diligence: Purpose and Company Assessment

Summary Corporate due diligence is a structured process of evaluating...

Why legal due diligence matters before signing business deals

Every day, businesses sign contracts, strike deals, and enter...

Related Articles

Popular Categories