Germany has a regulator, whatever the Commission list says
If you sell an AI system into Germany, the question of who enforces the AI Act there has had a statutory answer since 29 July 2026. The KI-MIG, Germany's AI Act implementing law, was signed on 22 July 2026, published in BGBl. 2026 I Nr. 223 and brought into force by Article 5 of that law. Its § 1 states its purpose plainly: it implements Regulation (EU) 2024/1689 for AI systems within Article 3(1), and governs the competent authorities under Article 70(1), innovation measures, and fines under Article 99(1).
The source of record is the consolidated text on gesetze-im-internet.de, which flags that it has not yet been editorially processed ("dokumentarisch noch nicht bearbeitet"). Every section reference on this page is to that text.
The confusion comes from Brussels. The Commission's page on market surveillance authorities under the AI Act, last updated 7 September 2026, lists the Bundesnetzagentur for Germany but marks it with an asterisk, which the page explains as "the national designation decision is still pending final adoption". Read that as a lag in the Commission's record, not a gap in German law. § 6(1) KI-MIG names the Bundesnetzagentur as the single point of contact under Article 70(2), and § 6(3) requires it to notify the Commission of the authorities and their tasks. The wider designation picture across all 27 Member States is on the national authorities tracker.
Which German authority supervises your system
The starting rule is § 2(1): "Die Bundesnetzagentur ist die für die Einhaltung der Verordnung (EU) 2024/1689 zuständige Marktüberwachungsbehörde, soweit in diesem Gesetz nichts anderes bestimmt ist." In English: the Federal Network Agency is the market surveillance authority responsible for compliance with the AI Act, except where the KI-MIG provides otherwise. Everything else in § 2 is an exception, so the practical question is whether one of them catches you.
| Your system | Market surveillance authority | Source |
|---|---|---|
| Any AI system not caught by an exception, including most standalone Annex III systems and Article 50 transparency duties | Bundesnetzagentur | § 2(1) KI-MIG |
| AI connected with a product under the Annex I Section A legislation (toys, lifts, radio equipment, medical devices and the rest; machinery now sits in Section B, point 21) | The authority already designated by federal or Land law for that product legislation | § 2(2) KI-MIG |
| AI directly connected with a regulated financial activity of a BaFin-supervised undertaking | BaFin | § 2(3) KI-MIG, Art 74(6) |
| AI connected with regulated financial activity of a financial institution BaFin does not supervise | The financial supervisor competent by law or agreement with BaFin | § 2(4) KI-MIG |
| Annex III point 1 biometrics used for law enforcement, border management or justice and democracy, and Annex III points 6, 7 and 8 | The independent KI-Marktüberwachungskammer within the Bundesnetzagentur | § 2(5), § 4 KI-MIG, Art 74(8) |
| AI placed on the market, put into service or used by public bodies of the Länder | Authorities competent under Land law | § 2(6) KI-MIG |
| AI used by media service providers for journalistic or advertising purposes | Authorities competent under Land law, with Deutsche Welle under its own statute | § 2(8) KI-MIG |
Two points in that table catch people. First, § 2(2) is an add-on, not a new regime: if your AI is a safety component of a product already supervised under Annex I Section A legislation, the authority you already deal with for that product now also enforces the AI Act on it. Second, the Kammer in § 2(5) is the German answer to Article 74(8), which requires the high-risk law enforcement, migration and justice systems to be supervised by a data protection authority or a body meeting the independence conditions of Directive (EU) 2016/680. § 4(3) states that the Kammer "handelt völlig unabhängig", acts in complete independence, and takes no instructions.
General-purpose AI models are outside this map altogether. The KI-MIG applies to AI systems under § 1, and the obligations of general-purpose AI model providers are enforced by the AI Office under Article 88, with fines under Article 101. Before working out which German authority is yours, it helps to be clear which role you hold, because the authority follows the system and its use, not your letterhead.
BaFin and AI in regulated finance
For financial services, § 2(3) is the provision that matters. BaFin is the market surveillance authority for AI systems "in direktem Zusammenhang mit einer regulierten Finanztätigkeit", in direct connection with a regulated financial activity, that are placed on the market, put into service or used by any of 25 listed categories of BaFin-supervised undertakings. The list runs from credit institutions, payment institutions, e-money institutions and investment firms through crypto-asset service providers, crowdfunding service providers and management companies to insurers, pension funds and their holding companies.
Three extensions are worth checking. BaFin is also competent where the ECB is the prudential supervisor of a credit institution established in Germany, so a significant bank does not fall back to the Bundesnetzagentur. § 2(4) sends AI at financial institutions that BaFin does not supervise to whichever financial supervisor is competent by law or agreement, but expressly not for trade-licensed intermediaries under §§ 34d, 34f, 34h, 34i and 34k of the Gewerbeordnung. The Act names no other authority for them, so on its text the general rule in § 2(1) is the remaining route. And § 11(7) provides that objections and court actions against BaFin's market surveillance decisions under § 11(1) to (4), including the threat and imposition of coercive measures, have no suspensive effect, so a BaFin order applies while you contest it.
The test is the direct connection with the regulated activity, not the identity of the customer alone. A creditworthiness model at a bank sits with BaFin; the same bank's AI for something unconnected with its regulated activity reads as falling back to § 2(1). How Annex III point 5 treats credit scoring and insurance pricing is set out in the credit scoring and insurance guide.
Notifying authorities: BSI, DAkkS and the existing product authorities
Article 70(1) requires a notifying authority alongside the market surveillance authority, and Article 28 gives it the job of designating and monitoring conformity assessment bodies. The KI-MIG splits that role in § 3.
- Annex I Section A products. The authorities already designated as notifying authorities for that product legislation take on the AI Act role too, under § 3(1). For AI connected with cableways under Regulation (EU) 2016/424, the Länder designate the authority.
- Annex III point 1 biometrics. The notifying authority is the market surveillance authority to be designated under Article 52(2) of the Cyber Resilience Act, Regulation (EU) 2024/2847. Until that designation, § 3(2) gives the task to the Bundesamt für Sicherheit in der Informationstechnik (BSI).
- Assessment and monitoring of conformity assessment bodies. § 3(4) leaves this with the bodies already doing it under the Annex I Section A legislation, except for bodies assessing Annex III point 1 systems, where it lies with the Deutsche Akkreditierungsstelle (DAkkS).
For most providers this matters only if your system needs third-party conformity assessment, which under Article 43 is chiefly the biometric systems in Annex III point 1 and AI inside Annex I products. The route is set out in the conformity assessment explainer. The BSI also carries the cybersecurity coordination tasks in § 10 until the Cyber Resilience Act authority is designated, including joint test criteria with the Bundesnetzagentur for the Article 15 cybersecurity requirements.
Fines in Germany: Article 99 plus a national tier
The fine structure in Germany has two layers, and the KI-MIG builds only one of them.
The first layer is Article 99 itself. Its ceilings apply as written in the Regulation, and § 16(1) KI-MIG applies the Gesetz über Ordnungswidrigkeiten (OWiG), Germany's regulatory offences law, to infringements under Article 99(3) to (5), with one important carve-out: § 17 OWiG, alone or with § 30(3), and § 30(1) and (2) OWiG do not apply. § 17 OWiG is the general rule on the amount of a fine, which by default caps it at 1,000 euro unless the law provides otherwise and halves the maximum for negligence; § 30 OWiG is the general regime for fines against legal persons. Disapplying both leaves the amount to be measured against Article 99's own ceilings and the Article 99(7) criteria. Procedure follows the OWiG and the Code of Criminal Procedure under § 16(2), and a public prosecutor may discontinue proceedings only with the consent of the authority that issued the fine notice. Under § 17(1) the fining authorities, for both the Article 99 infringements and the § 15 offences, are the market surveillance authorities under § 2, the notifying authorities under § 3(1) and (2) and the bodies that assess and monitor conformity assessment bodies under § 3(4), each for its own area.
The second layer is national. § 15 KI-MIG makes it a regulatory offence, committed intentionally or negligently, to breach a set of duties that the Article 99(4) catalogue does not name by article number, and § 15(3) sets the ceiling: "Die Ordnungswidrigkeit kann mit einer Geldbuße bis zu fünfzigtausend Euro geahndet werden", the offence can be punished with a fine of up to 50,000 euro. Because § 16(1) switches off § 17 OWiG only for Article 99 infringements, the general OWiG rules still govern this tier: under § 17(2) OWiG a negligent breach can be fined at most half the ceiling, 25,000 euro, and under § 17(4) OWiG the ceiling may be exceeded where needed to strip out the economic benefit of the offence.
| Tier | What it covers | Ceiling | Source |
|---|---|---|---|
| Prohibited practices | Article 5 | 35,000,000 euro or 7 percent of worldwide turnover, whichever is higher | Art 99(3) |
| Operator and notified body duties | Articles 16, 22, 23, 24, 25(2) and (4), 26, 31, 33(1), (3), (4), 34 and 50 | 15,000,000 euro or 3 percent, whichever is higher | Art 99(4) |
| Incorrect information | Incorrect, incomplete or misleading replies to notified bodies or national competent authorities | 7,500,000 euro or 1 percent, whichever is higher | Art 99(5) |
| National offences | Provider cooperation under Article 21(1) and (2); deployer FRIA under Article 27(1), (2) third sentence and (3) first sentence; notified body information duties under Article 45(1) to (3); deployer explanations under Article 86(1) for Annex III points 1, 3, 4 and 5 | 50,000 euro | § 15 KI-MIG |
For SMEs, including start-ups, each Article 99 fine is capped at the lower of the amount and the percentage under Article 99(6), and for small mid-caps the same applies to the Article 99(4) and (5) tiers under Article 99(6a). Public bodies are outside both layers: § 17(2) provides that no fines are imposed on federal or Land public bodies within § 2(1) or (2) of the Bundesdatenschutzgesetz, a choice Article 99(8) leaves to Member States. The full Article 99 structure is on the penalties and enforcement page.
The national tier lands on deployers. Two of the four duties in § 15 sit with the deployer, not the vendor: the fundamental rights impact assessment under Article 27 and the explanation to an affected person under Article 86(1). A bank or insurer using an Annex III point 5(b) or (c) credit scoring or life and health insurance pricing system, or a private entity providing public services, must carry out the FRIA under Article 27(1), and any deployer of an Annex III point 1, 3, 4 or 5 system, an employer using a recruitment tool included, owes the Article 86(1) explanation under § 15(2). Either breach carries fine exposure under § 15 KI-MIG on top of Article 99(4)(e) for the deployer's Article 26 duties. The FRIA itself is covered in the fundamental rights impact assessment explainer.
Two details on § 15 are easy to miss. It refers to the Regulation "in der Fassung vom 13. Juni 2024", the text as adopted, rather than as amended. On the Commission's consolidated text as at 27 July 2026, the Digital Omnibus amended Article 27(4) and (5) but left Article 21, Article 27(1) to (3), Article 45 and Article 86 unmarked, so the provisions § 15 points to read as adopted. And the high-risk duties it sanctions follow the AI Act's own timetable: Article 113(c), as amended, applies Chapter III Sections 1 to 3, which include Articles 21 and 27, from 2 December 2027 for Annex III systems.
Sandbox, real-world testing and the national register
The KI-MIG also gives the Bundesnetzagentur work that is not enforcement. Three provisions change what a provider can do in Germany.
KI-Reallabor. § 13(1) requires the Bundesnetzagentur to set up and run at least one AI regulatory sandbox under Articles 57 and 58, without prejudice to sandboxes run by other authorities. § 13(3) gives research institutions, universities and their spin-offs with a seat or branch in the EU priority access alongside the SME priority in Article 62(1)(a), and § 13(4) lets the Federal Ministry for Digital Affairs and State Modernisation lay down the operating details by ordinance.
Testing outside the sandbox. § 14(2) requires a provider or prospective provider of an Annex I Section A or Annex III high-risk system to submit its real-world testing plan to the competent market surveillance authority before testing, and the testing must take place before placing on the market or putting into service. Approval is deemed given if the provider receives no answer within 30 days of the plan being received.
National register for critical infrastructure. Article 49(5) requires Annex III point 2 systems to be registered at national level rather than in the EU database. § 20 KI-MIG sets up that register as a non-public register at the Bundesnetzagentur, and providers or their authorised representatives must register before placing on the market or putting into service, supplying the Annex VIII Section A information.
The guidance role is narrower than it looks. § 12 no. 2 lets the Bundesnetzagentur advise on whether a system is an AI system or high-risk in an individual case, but only at the request of a public body, and only under an administrative agreement with the responsible ministry. A company has no statutory route to a classification opinion under the KI-MIG, though § 12 no. 1 commits the agency to general information and guidance, in particular for SMEs and start-ups. For a first read on classification, the triage classifier covers the Annex III categories.
What to check if you sell AI into Germany
The KI-MIG adds few duties of its own beyond the AI Act: the real-world testing plan submission in § 14(2), the national register in § 20, and the § 18 rule that the person winding up a provider or German authorised representative inherits the Article 18(1) documentation-keeping duty. What it settles is who asks the questions and how fines are imposed. Work through it in this order.
- Fix your role and your system's classification under the AI Act first. The authority map follows from it, and the high-risk guide covers the classification rules.
- Find your authority in § 2. Product-linked AI goes to the existing product regulator, regulated-finance AI to BaFin, the most sensitive Annex III uses to the Kammer, Land public bodies and media to the Länder, and everything else to the Bundesnetzagentur.
- Know where complaints arrive. § 8 makes the Bundesnetzagentur the central complaints office, without prejudice to Article 85, and requires it to forward a complaint to the competent authority. A complaint about your system can reach the right authority even if it was filed with the wrong one.
- Check the national tier against your deployers. If you supply an Annex III system to German deployers, the Article 27 duty (for the deployers Article 27(1) names) and the Article 86(1) duty (for Annex III points 1, 3, 4 and 5) now carry their own fines under § 15, which makes your instructions for use and explanation tooling part of your customers' exposure.
- Plan real-world tests around the 30-day clock in § 14(2), and register Annex III point 2 systems nationally under § 20 rather than in the EU database.
- Do not rely on the Commission list. It marks Germany as pending; the statute is in force. If you need contact details, § 6(3) requires the Bundesnetzagentur to publish the electronic contact addresses of all competent authorities on its website.
The structure is not fixed for good. § 19 requires a first federal evaluation of the authority structure within 18 months of entry into force and a second within three years, and the Cyber Resilience Act designation will move the BSI's interim tasks under §§ 3(2) and 10(4) to whichever authority is named under Article 52(2) of that Regulation.