On July 28, 2026, Germany promulgated the Act Implementing Regulation (EU) 2024/1689, the KI-Durchfuehrungsgesetz or KI-MIG, published as BGBl. 2026 I Nr. 223. The federal statute, adopted by the Bundestag on June 11, 2026 and authenticated (Ausfertigung) on July 22, 2026, builds the national supervisory architecture that enforces the EU AI Act (Regulation (EU) 2024/1689) on German soil. It lands days before the AI Act's general applicability date of August 2, 2026, closing a gap that had seen Germany miss the EU deadline of August 2, 2025 to designate its market surveillance authority under Article 70(2).
The KI-MIG makes the Federal Network Agency (Bundesnetzagentur, BNetzA) the central market surveillance and notifying authority for AI, while preserving sectoral supervisors for financial services, medical devices, vehicles and workplaces. For German AI providers and deployers of high-risk systems, the law fixes who supervises them, how complaints are handled, and the fines for breaching the AI Act.
Who supervises AI in Germany under the KI-MIG?
BNetzA is the central AI market surveillance authority under section 2(1) KI-MIG. It hosts the Coordination and Competence Centre for the AI Regulation (KoKIVO, section 5), acts as the national single point of contact to the EU AI Office (section 6), runs the central complaint body (section 8) and operates at least one AI regulatory sandbox (section 13).
Sectoral market surveillance authorities are retained under section 2(2): BaFin for financial services (section 2(3)), BfArM for medical devices under the MDR and IVDR, BAuA for workplace and employment contexts, KBA for motor vehicles alongside Regulations (EU) 2018/858 and 2019/2144, and BVL for plant protection products. The BSI handles cybersecurity tasks transitional under section 10(4) until the Cyber Resilience Act designation takes effect. A new body is the Independent AI Market Surveillance Chamber (UKIM, sections 2(5) and 4), an organizationally independent chamber within BNetzA for sensitive biometric high-risk AI in law enforcement, border control and justice. State-level public bodies, such as Land police and regional courts, remain under authorities designated by Land law (section 2(6)), not BNetzA.
What changed for BaFin-supervised banks and insurers?
BaFin gains an explicit AI supervision competence under section 2(3) KI-MIG for AI used in financial services, making it the sectoral market surveillance authority for banks, insurers and other supervised entities. A BaFin press release of July 29, 2026 confirmed the agency's expanded mandate, and a BaFin technical interview the same week set out its supervisory expectations.
For BaFin-supervised institutions, the practical consequence is that AI systems used in credit scoring, fraud detection, algorithmic trading or customer-facing chatbots now sit under a named sectoral supervisor with direct enforcement powers. Compliance teams should map their AI inventory early, because the KI-MIG assigns competence by function and sector, not by the provider's legal form.
What penalties apply, and how high can they reach?
Penalties are set under section 15 KI-MIG in conjunction with section 30 OWiG for legal persons, with the AI Act's Article 99 maxima applying nationally. The top tier reaches up to 35 million EUR or 7 percent of global annual turnover for breaches of the Article 5 prohibitions.
| AI Act breach | Maximum fine under Article 99 |
|---|---|
| Article 5 prohibited practices | 35 million EUR or 7% of global turnover |
| Obligations on operators other than Article 5 | 15 million EUR or 3% of global turnover |
| Supply of incorrect or misleading information | 7.5 million EUR or 1% of turnover |
Section 15 KI-MIG makes these EU figures enforceable through German administrative fine proceedings, so a BaFin, BfArM or BNetzA finding can trigger them directly.
What should affected organisations do now?
German AI providers and deployers, plus BaFin-supervised financial institutions, BfArM-regulated medical-device manufacturers and KBA automotive type-approval holders, should identify which supervisor now owns their AI systems and align their conformity and documentation to that authority's expectations. Although the Digital Omnibus, in force since July 27, 2026, deferred the Annex III high-risk product rules to December 2, 2027, the AI Act's general applicability date of August 2, 2026 still brought transparency and other obligations into force, and the KI-MIG supervisory architecture applies immediately.
Continuous, per-jurisdiction monitoring surfaces this kind of national implementation the moment it publishes in the official gazette.
Take advantage of this real-time watch
Next steps: confirm whether your AI systems fall under BNetzA or a sectoral supervisor, review the section 15 penalty exposure for any Article 5-adjacent use cases, and brief your compliance, data protection and product teams on KoKIVO guidance as it lands. Obsidian tracks the remaining EU AI Act milestones as they emerge.


