Bundesnetzagentur and the AI Act: what KI-MIG means
The KI-MIG has applied since 29 July 2026. Who enforces the AI Act in Germany, where you can report violations and which fines the law actually sets.
Since 29 July 2026, the European AI Act has had a central supervisory authority in Germany: the Federal Network Agency (Bundesnetzagentur). AI matters reach it in three roles, as market surveillance authority, as single point of contact and as complaints body. As a rule it supervises certain AI systems in particularly sensitive areas such as personnel management, critical infrastructure or education itself. The basis is the KI-MIG (Gesetz zur Marktüberwachung und Innovationsförderung von künstlicher Intelligenz; unofficial translation: Act on Market Surveillance and Innovation Promotion of Artificial Intelligence). We read the text of the law and the authority's pages and sorted them for you: what the law regulates, who is responsible for what, what the Bundesnetzagentur has offered since August, which fines are actually in the law and what you should do now.
TL;DR
- The KI-MIG has applied since 29 July 2026. The Bundesnetzagentur is the competent market surveillance authority unless the law provides otherwise. BaFin and the existing product authorities keep their areas.
- Since August the Bundesnetzagentur has accepted complaints through an online form. The AI Service Desk (KI-Service Desk) with the AI Compliance Compass (KI-Compliance Kompass) helps with a first assessment; an AI regulatory sandbox (KI-Reallabor) is provided for by law and is being set up (unofficial translations of all three names).
- For Art. 4 (AI literacy), neither Art. 99 AI Act nor the KI-MIG names a separate fine range. Sensible steps now: record your AI use, check transparency obligations, document literacy measures.
What the KI-MIG regulates
The KI-MIG implements Regulation (EU) 2024/1689, the AI Act, in Germany. The obligations for providers and deployers remain in the EU regulation. According to § 1, the German law additionally regulates three things: the competent authorities, measures to promote innovation and fines.
The key facts:
- The Bundestag passed the underlying implementing act on 11 June 2026.
- It was signed on 22 July 2026 and promulgated in the Federal Law Gazette (BGBl. 2026 I No. 223). The KI-MIG is Article 1 of that act.
- It has been in force since 29 July 2026.
This is how the law is structured:
| Part | Content |
|---|---|
| Part 1 (§ 1) | Scope and purpose |
| Part 2 (§§ 2 to 10) | Competent authorities, KI-Marktüberwachungskammer (unofficial translation: AI Market Surveillance Chamber), coordination centre, single point of contact, complaints body, cooperation |
| Part 3 (§ 11) | Powers of the authorities |
| Part 4 (§§ 12 to 14) | Innovation promotion, AI regulatory sandboxes, testing in real-world conditions |
| Part 5 (§§ 15 to 17) | Fines and procedure |
| Parts 6 to 8 (§§ 18 to 20) | Retention, evaluation, register |
Three rules affect companies directly, even though they rarely make headlines:
- Testing in real-world conditions (§ 14): Before testing in real-world conditions outside AI regulatory sandboxes, providers or prospective providers of high-risk AI systems under Annex I Section A and Annex III must submit the test plan to the competent market surveillance authority. If no reply comes within 30 days, the approval is deemed granted.
- Register (§ 20): For high-risk AI systems under Annex III point 2 (critical infrastructure), the Bundesnetzagentur keeps a non-public register. Providers or their authorised representatives must register themselves and the system there before placing it on the market or putting it into service; public bodies of the federal states (Länder) are exempt.
- Evaluation (§ 19): The Federal Government first reviews the authority structure within 18 months of entry into force and reviews its effectiveness within three years of entry into force.
EU AI Act
AI literacy under Article 4: build it and document it
Who is responsible: Bundesnetzagentur, BaFin and product authorities
The Bundesnetzagentur calls the model a hybrid approach: oversight is assigned according to the authorities' subject-matter expertise. In fully harmonised product areas and, for example, in the financial sector, the familiar authorities remain responsible. The principle is in § 2(1) KI-MIG: the Bundesnetzagentur is the competent market surveillance authority unless the law provides otherwise.
| Area | Responsible | Basis |
|---|---|---|
| Default responsibility, for example certain AI systems in personnel management, critical infrastructure or education | Bundesnetzagentur | § 2(1) |
| AI in products under Annex I Section A, for example medical devices and machinery | The authorities that already carry out market surveillance for these products (for radio equipment, the Bundesnetzagentur) | § 2(2) |
| AI directly connected to regulated financial activity of companies supervised by BaFin, for example banks, insurers and payment institutions | BaFin | § 2(3) |
| AI at public bodies of the Länder and in media services for journalistic or advertising purposes | Authorities competent under state law, in the media sector for example the state media authorities (Landesmedienanstalten) | § 2(6) and (8) |
| Certain high-risk systems in law enforcement, migration and border control, justice and democratic processes (Annex III points 6, 7 and 8 as well as biometrics in these fields) | Independent AI Market Surveillance Chamber at the Bundesnetzagentur | § 2(5), § 4 |
| General-purpose AI (GPAI) models such as large language models | AI Office of the European Commission | Bundesnetzagentur overview |
What "supervising" means in practice is described by the authority itself: market surveillance means spot checks of AI products on the market, review of technical documentation such as declarations of conformity, and measures when infringements are found. Within its areas of responsibility, the Bundesnetzagentur also supervises the transparency obligations and the prohibited AI practices. For its powers, § 11 refers to the EU Market Surveillance Regulation (EU) 2019/1020. The authorities may also exercise certain powers via programming interfaces or other means of remote access (§ 11(2)).
There are also cross-cutting roles. The Coordination and Competence Centre (Koordinierungs- und Kompetenzzentrum, KoKIVO, § 5; unofficial translation) supports the other authorities on request with complex decisions and is meant to ensure that horizontal legal questions are answered consistently. The single point of contact (§ 6) is the contact for the EU AI Office and the other Member States. And data protection supervision stays in play: § 9(4) obliges the market surveillance authorities to involve the data protection supervisory authorities of the Federation and the Länder as well as the Federal Cartel Office (Bundeskartellamt) where their area is affected.
What the Bundesnetzagentur has offered since August
Since 2 August 2026, the EU Commission's AI Office and the national authorities have enforced the AI Act. Three Bundesnetzagentur services matter for companies, and they are at different stages of development.
AI Service Desk and AI Compliance Compass
According to the Bundesnetzagentur, the AI Service Desk (KI-Service Desk) already provides organisations, in particular SMEs and start-ups, easily accessible information on implementing the AI Act. This includes:
- an online tool for a first assessment of the risk class, the AI Compliance Compass (KI-Compliance Kompass),
- current information on European guidelines and practical guides,
- notes on building AI literacy,
- a contact form for questions the FAQ does not answer.
You should know two limitations. The Bundesnetzagentur itself points out that its information serves as orientation and is non-binding. Only the national courts and the Court of Justice of the EU can interpret the AI Act with binding effect. And advice on classifying a specific system in an individual case is provided by § 12 KI-MIG only for public bodies. Companies receive general information and guidance which, according to § 12 No. 1, are aimed in particular at small and medium-sized enterprises and start-ups.
Central complaints body
Anyone who suspects an infringement of the AI Act can complain to the market surveillance authority under Art. 85 AI Act. In Germany, the Bundesnetzagentur is the central complaints body for this (§ 8 KI-MIG). The main points from its side:
- Complaints are accepted only through the online form, available since 2 August, not by email.
- There are no deadline or form requirements, and submission is free of charge.
- Those affected can complain, but so can providers, downstream providers, deployers, authorised representatives, importers and distributors.
- The Bundesnetzagentur handles the complaint itself or forwards it to the competent authority and informs the complainant about this.
- For AI systems based on a GPAI model where system and model provider are identical or belong to the same company, and for AI systems that are or are integrated into very large online platforms or search engines, the European Commission's AI Act Service Desk is the right route. For platform content, the Digital Services Coordinator is responsible.
Important for companies: according to its own description, the authority can also act on its own initiative. A complaint is therefore not the only way an AI system can land on its desk.
AI regulatory sandbox
§ 13 KI-MIG obliges the Bundesnetzagentur to set up and operate at least one AI regulatory sandbox (KI-Reallabor). A regulatory sandbox is a controlled environment in which innovative AI systems are developed, trained, tested and validated before being placed on the market or put into service, with regulatory guidance from the authority and a final report. It is therefore intended for companies that develop AI systems themselves. The Bundesnetzagentur explicitly names SMEs as a target group. § 13(3) additionally gives research institutions, universities and their spin-offs priority access if they have their registered office or a branch in the EU, meet the EU criteria and thereby facilitate or accelerate market access for AI systems from application-oriented research and development projects. In the sandbox, the data protection supervisory authority assesses the data protection requirements (§ 13(2)).
Important for expectations: according to the Bundesnetzagentur, every Member State must ensure by 2 August 2027 that at least one national AI regulatory sandbox is operational. The detailed rules of the EU Commission in the form of implementing acts are still to follow. The authority has already gathered experience: from May 2025 it simulated a sandbox together with the Hessian digital ministry and the Federal Commissioner for Data Protection, and the final report appeared in March 2026.
Fines in the KI-MIG and the AI Act
With fines it pays to look closely, because two levels come together: the EU framework from Art. 99 AI Act and a separate German framework in § 15 KI-MIG.
The EU framework under Art. 99 AI Act
| Infringement | Maximum amount |
|---|---|
| Prohibited AI practices (Art. 5) | up to EUR 35 million or 7% of worldwide annual turnover |
| Obligations under Art. 99(4), including Art. 16 (providers), Art. 26 (deployers) and Art. 50 (transparency) | up to EUR 15 million or 3% |
| Incorrect, incomplete or misleading information to authorities | up to EUR 7.5 million or 1% |
For infringements under Art. 99(3) to (5), the law on administrative offences applies accordingly in Germany (§ 16 KI-MIG). Fining authorities include the respective competent market surveillance authorities (§ 17(1)). No fines are imposed on authorities and other public bodies (§ 17(2)).
The German addition in § 15 KI-MIG
§ 15 KI-MIG provides its own administrative offences with fines of up to EUR 50,000. They cover:
- providers of high-risk AI systems that fail to submit requested information or documentation to the authority, or submit it incorrectly, incompletely or late, or fail to grant access (Art. 21(1) and (2)),
- infringements around the fundamental rights impact assessment for high-risk AI systems (Art. 27(1) to (3)),
- information obligations of notified bodies (Art. 45),
- deployers of high-risk AI systems under Annex III point 1, 3, 4 or 5 that fail to ensure that an affected person receives the explanation under Art. 86(1). Point 4 includes, for example, AI for recruitment and performance evaluation.
And Art. 4?
For Art. 4 (AI literacy), neither Art. 99 AI Act nor the KI-MIG names a separate fine range. According to the EU Commission, however, the authorities can impose sanctions and other measures, following a proportionate approach. Art. 4 is supervised by the national market surveillance authorities, since 2 August 2026.
What applies from when?
The national authorities and the AI Office have enforced the AI Act since 2 August 2026. The transparency obligations under Art. 50 have applied since then as well: chatbots and other interactive AI systems must disclose that users are talking to an AI, deepfakes must be labelled, and AI-generated or altered content needs machine-readable markings. Only for the marking obligation under Art. 50(2) does a transitional period until 2 December 2026 apply for systems placed on the market before 2 August 2026. Under the Digital Omnibus, the high-risk rules for Annex III apply from 2 December 2027, and for AI in regulated products under Annex I from 2 August 2028.
What companies should do now
The following steps draw on the AI Act, the KI-MIG and the Bundesnetzagentur's recommendations. They do not replace legal advice in an individual case, but they are a sensible starting point.
- Record which AI systems you use or offer. The Bundesnetzagentur starts its notes on AI literacy with exactly this: which people develop, operate or use AI systems, which systems are these, for what purpose, with which risks and opportunities? This list is the basis for all further steps.
- Make a first assessment with the AI Compliance Compass. It shows whether and to what extent the AI Act is relevant for you. The result is orientation, not binding information. Also clarify your role as provider or deployer, because the AI Act attaches different obligations to them, for example Art. 16 for providers and Art. 26 for deployers.
- Check transparency obligations. A chatbot on the website, AI-generated images, video or audio in marketing and communication: here Art. 50 has applied since 2 August 2026, and the Bundesnetzagentur supervises the transparency obligations in its areas. The details are in our article on Art. 50.
- Build and document AI literacy. Art. 4 requires measures to build AI literacy, but no particular level, no mandatory training and no certificate. The Bundesnetzagentur recommends documenting the measures well, for example their type, content and duration and the people taking part. What the new version of Art. 4 requires exactly is explained in our article on Art. 4 after the Digital Omnibus. What an AI policy with rules for agents can look like is shown in the article on the AI policy.
- Flag high-risk candidates. AI intended for job advertisements, candidate selection, decisions on promotion or dismissal, or performance evaluation is named in Annex III point 4. AI for assessing the creditworthiness of natural persons is named in point 5(b). The high-risk rules apply to these systems from 2 December 2027. Anyone who uses such systems should know that § 15 KI-MIG punishes infringements of the explanation obligation under Art. 86 and around the fundamental rights impact assessment under Art. 27 with up to EUR 50,000.
- Think about data protection. Where personal data is involved, according to the Bundesnetzagentur the data protection supervisory authority is generally responsible. How the AI Act and the GDPR interact when AI agents are used is covered in our article on GDPR and agentic AI.
- Know your contacts. For questions there is the AI Service Desk contact form, for infringements the complaints body. For GPAI models such as large language models, the EU AI Office is responsible.
Where your company stands on Art. 4 and the other obligations is shown by the AI Act checklist in 12 questions. For documenting rules and literacy measures, we have a free template:
If you would rather do the assessment together, talk to us for 30 minutes: book a call.
FAQ
Who supervises the AI Act in Germany?
As a rule the Bundesnetzagentur: § 2(1) KI-MIG makes it the competent market surveillance authority unless otherwise provided. For AI in regulated financial activities, BaFin is responsible; for AI in products under Annex I Section A, the product authorities already responsible for them. For GPAI models such as large language models, the AI Office of the EU Commission is responsible.
What does the KI-MIG regulate and when does it apply?
The KI-MIG implements the AI Act in Germany. It regulates the competent authorities, measures to promote innovation such as AI regulatory sandboxes, and fines (§ 1). It has been in force since 29 July 2026.
Where can I report a violation of the AI Act?
To the Bundesnetzagentur as the central complaints body (§ 8 KI-MIG), exclusively through its online form. The complaint is free of charge and not bound to any deadline. If it concerns an AI system based on a GPAI model (system and model provider identical or in the same company) or an AI system that is or is integrated into a very large online platform or search engine, the European Commission's AI Act Service Desk is responsible. For platform content, the Digital Services Coordinator is responsible.
From what date can fines be imposed?
The national authorities and the AI Office have enforced the AI Act since 2 August 2026. Art. 99 AI Act names maximum amounts of up to EUR 35 million or 7% for prohibited practices; § 15 KI-MIG adds its own fines of up to EUR 50,000. For Art. 4, neither Art. 99 nor the KI-MIG names a separate fine range, but according to the EU Commission, sanctions and other measures remain possible.
Does my small company need to take action?
Yes, if you use or offer AI in a professional context. According to the Bundesnetzagentur, Art. 4 applies to providers and deployers regardless of sector or organisation size; purely private, non-professional use by natural persons is not covered (Art. 2(10) AI Act). At the same time, under § 12 KI-MIG the Bundesnetzagentur must provide information and guidance in particular for SMEs and start-ups.
Are the data protection authorities out now?
No. § 9(4) KI-MIG obliges the market surveillance authorities to involve the data protection supervisory authorities of the Federation and the Länder where their area is affected. In the AI regulatory sandbox, the data protection supervisory authority assesses the data protection requirements (§ 13(2)). And for questions on personal data, according to the Bundesnetzagentur the data protection supervisory authority generally remains responsible.
Sources
- Federal Ministry of Justice (Bundesministerium der Justiz), KI-MIG (Gesetz zur Marktüberwachung und Innovationsförderung von künstlicher Intelligenz; unofficial translation: Act on Market Surveillance and Innovation Promotion of Artificial Intelligence), full text in German: gesetze-im-internet.de/ki-mig
- German Bundestag, text archive on the vote of 11 June 2026: bundestag.de
- Bundesnetzagentur, press release of 29 July 2026: bundesnetzagentur.de
- Bundesnetzagentur, overview of the AI Regulation and AI Compliance Compass: bundesnetzagentur.de/ki
- Bundesnetzagentur, complaints body: bundesnetzagentur.de
- Bundesnetzagentur, AI regulatory sandboxes: bundesnetzagentur.de
- Bundesnetzagentur, market surveillance: bundesnetzagentur.de
- Bundesnetzagentur, Coordination and Competence Centre (KoKIVO): bundesnetzagentur.de
- Bundesnetzagentur, AI literacy: bundesnetzagentur.de
- European Commission, enforcement from 2 August 2026 (31 July 2026): digital-strategy.ec.europa.eu
- European Commission, AI omnibus enters into force (27 July 2026): digital-strategy.ec.europa.eu
- European Commission, AI Literacy Questions and Answers (as of 27 July 2026): digital-strategy.ec.europa.eu
- European Commission, FAQ on Art. 50 (as of 24 July 2026): digital-strategy.ec.europa.eu
- AI Act, Art. 99 (penalties): artificialintelligenceact.eu/article/99
- AI Act, Art. 21, 27, 45, 85 and 86: Art. 21, Art. 27, Art. 45, Art. 85, Art. 86
- AI Act, Art. 2 (scope) and Annex III: Art. 2, Annex III
EU AI Act
AI literacy under Article 4: build it and document it
Article 4 asks for measures that build AI literacy, but no specific level and no certificate. The checklist shows in 12 questions where your company stands.
About the author
Co-Founder · Business & Content Lead
Co-Founder of Sentient Dynamics. 15+ years of business strategy (incl. SAP), MBA. Writes about EU AI Act compliance, ROI measurement and how Mittelstand CTOs actually adopt agentic AI.