Germany’s EU AI Act Competent Authorities: Who Enforces What

Germany does not have a single authority responsible for every EU AI Act case.

The Bundesnetzagentur (BNetzA) is the default market surveillance authority under Germany’s KI-MIG, while other authorities retain responsibility where the AI system falls within a specific sector or product framework. BaFin, for example, is responsible for certain AI systems directly connected with regulated financial activities. Product-related AI systems remain connected to the authorities responsible for the relevant EU harmonisation legislation. State authorities also have responsibility for certain AI systems placed on the market, put into service or used by public bodies of the Länder.

The BfDI and other data protection authorities are different. They are not designated as general AI Act market surveillance authorities, but KI-MIG requires the competent market surveillance authorities to involve data protection authorities where their responsibilities are affected. GDPR supervision therefore continues alongside EU AI Act supervision.

This structure comes from Article 70 of the EU AI Act, which requires every Member State to designate at least one notifying authority and at least one market surveillance authority and to designate a market surveillance authority as the national single point of contact. Member States had to make the relevant information publicly available by 2 August 2025.

Germany implemented that structure through KI-MIG, which entered into force on 29 July 2026.

For background, see our guide to Germany’s KI-MIG.

Not sure which German authority applies to your AI system?

AnnexOps helps AI teams organise AI inventories, risk classifications, obligations and compliance evidence so the relevant regulatory requirements remain connected to each system.

Germany’s AI Act Authority Structure at a Glance

Authority or body Role under the German framework When it matters
BNetzA Default market surveillance authority and national single point of contact AI systems not assigned to another market surveillance authority under KI-MIG
BaFin Market surveillance authority for specified AI systems directly connected with regulated financial activities Certain supervised financial institutions and regulated financial activities
Existing product/sector authorities Continue market surveillance for AI systems connected with products covered by Annex I harmonisation legislation Medical devices, machinery, radio equipment and other covered product sectors
Länder authorities Market surveillance for AI systems placed on the market, put into service or used by certain public bodies of the Länder Relevant state-level public-sector AI use
BfDI and state data protection authorities Data protection supervision and cooperation where GDPR responsibilities are affected AI systems involving personal-data processing and GDPR issues
BSI Transitional cybersecurity role and notifying authority for specified Annex III No. 1 AI systems Cybersecurity-related tasks pending the relevant CRA authority; specified biometric high-risk AI notification

This is not a list of five interchangeable “AI regulators.” Their legal functions are different, and the authority responsible for a particular AI system depends on the system, sector, operator, and applicable legislation.

BNetzA: Germany’s Default AI Act Market Surveillance Authority

The Bundesnetzagentur is the starting point for most AI Act market surveillance questions in Germany.

Section 2(1) KI-MIG makes BNetzA the competent market surveillance authority unless KI-MIG provides otherwise. This qualification is important because several exceptions follow in the same section.

BNetzA also has the role of Germany’s single point of contact under Article 70(2) of the EU AI Act. Section 6 KI-MIG confirms that role and requires the authority to communicate information about Germany’s market surveillance and notifying authorities to the European Commission.

BNetzA also operates Germany’s central complaints function. Complaints concerning alleged EU AI Act violations can be submitted to BNetzA, which forwards them to the authority responsible where another authority has jurisdiction.

The Bundesnetzagentur itself describes its new role as covering market surveillance, the single point of contact and complaints, while also coordinating with other German and European authorities.

What is KoKIVO?

KI-MIG establishes the Koordinierungs- und Kompetenzzentrum within BNetzA.

Its role is not to replace sector-specific regulators. Instead, §5 KI-MIG gives the centre a coordination and expertise function. It can support competent market surveillance authorities, notifying authorities and the German Accreditation Body with specialist expertise on complex decisions and coordinate cooperation between the relevant authorities.

That distinction matters for businesses. A company may still deal with a sector-specific authority even when KoKIVO is involved in supporting the broader German supervisory structure.

The KI-Marktüberwachungskammer: Independent Oversight for Specific High-Risk AI

The chamber has three members and operates independently. Its staff are subject to the chamber while performing its tasks, and the chamber must submit an annual activity report to the Bundestag.

Its jurisdiction covers specific high-risk AI systems, including:

  • High-risk AI systems under Annex III No. 1 used for law enforcement, border management, or justice and democracy
  • High-risk AI systems under Annex III Nos. 6, 7 and 8

This is narrower than saying that the chamber supervises all biometric AI in Germany.

The chamber’s responsibilities also have an explicit limitation. Section 4(5) excludes review of certain formal and substantive requirements concerning the ordering and individual use of high-risk AI systems under Articles 5(2), 5(3) and 26(10) of the EU AI Act.

BaFin: AI Systems Connected to Regulated Financial Activities

BaFin has a defined market surveillance role under §2(3) KI-MIG.

It is responsible for AI systems that are directly connected with regulated financial activities and are placed on the market, put into service or used by specified entities supervised by BaFin. The provision covers defined categories including certain credit institutions, issuers of asset-referenced tokens, crypto-asset service providers and investment holding companies, among others.

This does not create a separate German AI regulation for financial services.

The substantive requirements continue to come from the EU AI Act. The national question is which German authority performs the market surveillance function.

KI-MIG also contains specific arrangements for cybersecurity requirements. For AI systems under BaFin’s market surveillance responsibility, BaFin develops its own specifications for assessing the relevant EU AI Act cybersecurity requirements in agreement with BNetzA and the future Cyber Resilience Act market surveillance authority. The law also preserves BaFin’s existing responsibilities under DORA.

For a financial institution, therefore, AI Act compliance should not be treated as a standalone regulatory track disconnected from existing financial supervision.

Medical Devices: Do Not Assume BfArM Is the AI Act Authority

This is one area where the original version needs a significant correction.

It is too broad to say:

“BfArM is the sector-specific authority for AI in medical devices.”

KI-MIG does not create a blanket rule assigning every medical-device AI system to BfArM.

Section 2(2) instead provides that the authorities already designated under federal or state law as market surveillance authorities for the harmonisation legislation listed in Annex I Section A of the EU AI Act also perform the AI Act market surveillance function when an AI system is connected with products covered by that legislation.

The practical consequence is that the competent authority depends on the underlying product legislation and the authority responsible for it.

For medical-device AI, businesses should therefore verify the applicable medical-device framework and the competent German market surveillance authority rather than automatically assuming that BfArM is the responsible AI Act authority.

This product-based structure reflects the EU AI Act’s approach to high-risk AI embedded in regulated products.

BfDI: GDPR Supervision, Not General AI Act Market Surveillance

The Bundesbeauftragte für den Datenschutz und die Informationsfreiheit (BfDI) should not be described as one of Germany’s general AI Act market surveillance authorities.

KI-MIG’s market surveillance structure is separate from Germany’s data protection supervision.

At the same time, the two regulatory areas can overlap. Section 9 KI-MIG specifically requires market surveillance authorities to involve federal and state data protection authorities where their respective responsibilities are affected. The authorities may also exchange information, including personal data and business secrets, where legally necessary for their respective tasks.

This means an AI system can be subject to two different regulatory tracks.

For example, an organisation might face:

  • an EU AI Act market surveillance matter concerning the AI system itself; and
  • a GDPR matter concerning the lawful processing of personal data.

The two frameworks remain legally distinct. The EU AI Act does not replace the GDPR or Germany’s existing data protection authorities.

BSI: A Transitional Cybersecurity Role

The Bundesamt für Sicherheit in der Informationstechnik (BSI) has a more specific role than simply acting as Germany’s AI cybersecurity regulator.

Under KI-MIG, BSI performs certain cybersecurity-related tasks until the market surveillance authority required under Article 52(2) of the Cyber Resilience Act is designated. After that designation, the relevant CRA authority takes over the functions described in the KI-MIG provisions.

There is also another BSI role that should not be confused with market surveillance.

Germany lists BSI as a notifying authority for high-risk AI systems under Annex III No. 1. The same national notification structure includes other authorities for different Annex I product areas.

So BSI should not be presented as the general German authority for cybersecurity aspects of every high-risk AI system.

Other German Authorities Can Be Involved

Germany’s structure is broader than the five organisations commonly mentioned in summaries.

KI-MIG allows responsibilities to remain with existing federal and state market surveillance authorities where the AI system is connected to products covered by Annex I legislation. It also gives the Länder responsibility for market surveillance when certain public bodies of the Länder place, put into service or use AI systems.

KI-MIG also requires competent authorities to involve other bodies where their responsibilities are affected. Section 9 expressly refers to:

  • federal and state data protection authorities;
  • the future Cyber Resilience Act market surveillance authority; and
  • the Bundeskartellamt.

This is why identifying the correct authority should begin with the AI system and its regulatory context, rather than with the name of a regulator.

Why Germany Uses a Hybrid AI Act Structure

Germany chose a structure that keeps existing sector expertise in place while giving BNetzA a central coordinating role.

The Bundesnetzagentur describes this as a hybrid implementation approach. In product sectors that already have established market surveillance and supervisory authorities, those authorities remain involved. BNetzA provides the central federal structure for areas that are not otherwise assigned and coordinates with the other authorities.

This approach also fits Article 70 of the EU AI Act, which allows Member States to organise national competent authorities according to their organisational needs while requiring them to designate the authorities and ensure that they have adequate resources and expertise.

For companies, the practical result is that “Who regulates my AI?” cannot always be answered from the AI Act risk category alone.

The sector, product legislation, operator, deployment context and public/private status can all affect the answer.

Which German Authority Applies to Your AI System?

A useful starting sequence is:

1. Identify the AI system and its role

Determine whether your organisation is acting as a provider, deployer or another operator under the EU AI Act.

Then identify the system’s intended purpose and whether it falls into a specific risk category.

2. Check whether the AI system is connected to a regulated product

If the system is part of, or connected with, a product covered by the EU AI Act’s Annex I harmonisation legislation, identify the German market surveillance authority responsible for that underlying product framework.

3. Check for financial-sector responsibility

If the AI system is directly connected with a regulated financial activity covered by §2(3) or §2(4) KI-MIG, BaFin or the relevant financial supervisory authority may be responsible.

4. Check the sensitive high-risk categories

If the system falls within the categories assigned to the KI-Marktüberwachungskammer, the independent chamber within BNetzA becomes relevant.

5. Check whether a German public authority is involved

AI systems placed on the market, put into service or used by certain public bodies of the Länder fall under the market surveillance authorities designated under state law.

6. Keep GDPR and cybersecurity responsibilities separate

Even where BNetzA or another market surveillance authority is responsible under the AI Act, data protection authorities and cybersecurity authorities may have separate responsibilities.

The regulatory map is therefore not necessarily one authority per AI system.

How AnnexOps Helps

Authority mapping becomes difficult when an organisation manages dozens of AI systems across different products, business functions and jurisdictions.

AnnexOps helps AI teams maintain an AI inventory, classify systems, track applicable obligations and organise supporting documentation and evidence.

For German operations, this information can support an internal process for recording the relevant supervisory authority alongside each AI system. When the system’s intended purpose, sector or deployment context changes, the regulatory assessment can be reviewed instead of remaining buried in a static compliance document.

AnnexOps does not replace legal advice or the authority’s own jurisdictional determination. It provides a structured way to keep the compliance information connected to the AI systems being managed.

Need to map your AI systems to the relevant EU and German requirements?

AnnexOps helps teams organise AI inventories, risk classifications, obligations and evidence in one structured workflow.

Primary Legal Sources

Legal-status note: This article reflects the EU AI Act and KI-MIG framework available as of September 2026. German supervisory practice and the designation of authorities under related legislation may continue to develop. The article is informational and does not constitute legal advice.

Author: Nitin Grover

Nitin Grover is an AI compliance strategist and writer focused on EU AI Act compliance, AI governance, Annex IV documentation, AI risk management, and AI compliance operations for AI startups, SaaS companies, and enterprise AI teams across Europe.

Post a Comment

Your email address will not be published. Required fields are marked *

Analyse your AI exposure