KI-MIG Explained: Germany’s EU AI Act Implementation Law
Germany’s KI-MIG (KI-Marktüberwachungs- und Innovationsförderungs-Gesetz) provides the national framework for implementing and enforcing the EU AI Act in Germany.
The law was adopted by the Bundestag on 11 June 2026, promulgated on 28 July 2026 as BGBl. I 2026 No. 223, and entered into force on 29 July 2026. Its purpose is to establish the German authorities responsible for market surveillance, complaints, notification, and cooperation, while also setting national rules for innovation support and certain administrative fines.
This distinction matters because the EU AI Act is a regulation, not a directive. Its substantive requirements apply directly across the EU. Article 70 nevertheless requires each Member State to designate national competent authorities, including market surveillance and notifying authorities, and a single point of contact. Germany uses KI-MIG to establish that national structure.
For businesses operating in Germany, KI-MIG therefore does not replace the EU AI Act. It determines how the German enforcement and supervisory system works around it.
If you are also tracking the EU AI Act’s changing implementation deadlines, see our complete guide to the Annex III deadline.
Need to understand where your AI systems stand?
AnnexOps helps AI teams track AI inventories, obligations, documentation and compliance evidence against the EU AI Act.
What Is KI-MIG?
KI-MIG is Germany’s KI-Marktüberwachungs- und Innovationsförderungs-Gesetz, formally titled the Gesetz zur Marktüberwachung und Innovationsförderung von künstlicher Intelligenz.
Section 1 states that the law serves to implement Regulation (EU) 2024/1689, the EU AI Act. It regulates the German authorities responsible under Article 70 of the EU AI Act, innovation-support measures, and fines for certain violations under the national framework.
This means companies should not think of KI-MIG as a second German AI Act with an entirely separate compliance regime.
The core obligations still come from the EU AI Act. These include requirements relating to prohibited AI practices, high-risk AI systems, transparency, provider and deployer responsibilities, documentation, human oversight and other obligations established by the Regulation.
KI-MIG adds the German institutional and procedural layer: who supervises, where complaints go, how authorities cooperate, which national procedures apply and how certain German administrative penalties are handled.
It also establishes additional national mechanisms, including a register for certain high-risk AI systems and at least one German AI regulatory sandbox.
KI-MIG Legislative Timeline
| Date | Milestone |
| 13 February 2026 | Federal Council legislative documentation records the federal government’s bill as BR-Drucksache 97/26 |
| 11 June 2026 | Bundestag adopted the legislation |
| 10 July 2026 | Bundesrat second reading |
| 22 July 2026 | Law dated and enacted |
| 28 July 2026 | Published in Bundesgesetzblatt I 2026, No. 223 |
| 29 July 2026 | KI-MIG entered into force |
The official Bundestag legislative record confirms the parliamentary stages and publication details. The enacted law itself states that it entered into force on 29 July 2026.
Who Enforces the EU AI Act in Germany?
KI-MIG establishes a multi-authority supervisory structure. The Bundesnetzagentur (BNetzA) is the default market surveillance authority, but the law assigns specific responsibilities to other regulators and authorities depending on the AI system and the sector involved.
BNetzA as the default market surveillance authority
Under Section 2(1) KI-MIG, the Bundesnetzagentur is Germany’s competent market surveillance authority unless KI-MIG assigns responsibility elsewhere.
The BNetzA also acts as Germany’s central point of contact under Section 6. This function includes receiving information from the EU AI Office and other EU or Member State contacts and forwarding information to the relevant German authorities.
The Bundesnetzagentur itself confirmed when the law entered into force that it would take on a central role as Germany’s AI market surveillance, contact and complaints authority.
Sector-specific authorities still matter
NetzA is not the authority for every AI system.
KI-MIG preserves the role of existing market surveillance authorities where AI systems are connected to products covered by the EU harmonisation legislation listed in Annex I of the AI Act.
Financial-sector AI systems can also fall under BaFin or another competent financial supervisory authority. KI-MIG contains detailed provisions allocating responsibility for AI systems directly connected with regulated financial activities.
There are additional arrangements for public authorities at federal and state level and for certain media-related uses of AI. The result is not a single regulator for every use case, but a central structure with defined sectoral responsibilities.
What Is the KoKIVO?
KI-MIG establishes a Koordinierungs- und Kompetenzzentrum within the Bundesnetzagentur under Section 5.
Its role is to support competent market surveillance and notifying authorities with expertise on complex AI Act decisions and to coordinate cooperation between authorities. It is also intended to promote more consistent interpretation of horizontal legal questions across the German supervisory structure.
For businesses, this matters because an AI system may fall under a sector-specific regulator while still being affected by nationally coordinated guidance and cooperation through the BNetzA structure.
What is the KI-Marktüberwachungskammer?
KI-MIG creates an independent KI-Marktüberwachungskammer within the Bundesnetzagentur.
The chamber has three members and operates independently. Its responsibilities cover specific high-risk AI systems, including:
- High-risk AI systems under Annex III point 1 when used for law enforcement, border management, justice and democracy purposes
- High-risk AI systems under Annex III points 6, 7 and 8
The chamber is therefore not a general replacement for BNetzA. Its jurisdiction is limited to the categories specified by Section 2(5) KI-MIG.
How Are Complaints Handled?
KI-MIG creates a central complaints function at the Bundesnetzagentur.
Under Section 8, complaints concerning alleged violations of the EU AI Act can be submitted to BNetzA as the central complaints office. Where another market surveillance authority is responsible, BNetzA forwards the complaint to that authority and informs the complainant about the responsible body.
This complements Article 85 of the EU AI Act, which gives natural and legal persons the right to submit complaints to the relevant market surveillance authority when they have grounds to consider that the Regulation has been infringed.
For companies, the practical implication is straightforward: a complaint may enter through the central BNetzA channel even when another authority ultimately handles the matter.
How Do German Authorities Cooperate?
KI-MIG requires the competent authorities to cooperate within their respective areas of responsibility.
Section 9 provides for information sharing and coordination between market surveillance authorities, notifying authorities and other relevant public bodies. This can include cooperation with data protection authorities and other authorities where their responsibilities are affected.
This is important for AI systems that sit across regulatory boundaries. An AI system can involve product safety, financial regulation, data protection or other regulatory issues at the same time.
The German framework is therefore designed around coordination between authorities, rather than treating the EU AI Act as an isolated regulatory field.
What Does KI-MIG Say About AI Regulatory Sandboxes?
Section 13 requires the Bundesnetzagentur to establish and operate at least one AI regulatory sandbox under Articles 57 and 58 of the EU AI Act.
The EU AI Act defines regulatory sandboxes as controlled environments where innovative AI systems can be developed, trained, tested and validated before being placed on the market or put into service under an agreed sandbox plan.
The EU framework also requires Member States to provide SMEs, including start-ups, with priority access to AI regulatory sandboxes when they meet the applicable eligibility and selection conditions. That requirement comes from Article 62, rather than Section 13 KI-MIG.
One important update for current content is that the consolidated EU AI Act now reflects the amended national sandbox timetable, with national sandboxes required to be operational by 2 August 2027.
What Happens During AI Act Enforcement?
KI-MIG gives German market surveillance authorities the national framework needed to exercise their responsibilities under the EU AI Act.
This includes cooperation between authorities, handling complaints, information exchange, and procedures connected with non-compliant or risky AI systems.
KI-MIG also contains a specific rule for real-world testing outside AI regulatory sandboxes. Providers or prospective providers intending to conduct certain real-world tests of high-risk AI systems must submit their testing plan to the competent market surveillance authority. Under Section 14, approval is deemed granted if the authority does not respond within 30 days, provided the statutory conditions for approval are met.
That makes testing documentation and regulatory records particularly relevant for organisations developing high-risk AI systems in Germany.
What Happens If an AI Provider Shuts Down?
Section 18 KI-MIG addresses an issue that can easily be missed in operational compliance planning.
If a provider or Germany-based authorised representative stops its business activities, the person responsible for the liquidation or dissolution becomes responsible for the documentation-retention obligation under Article 18(1) of the EU AI Act.
The provision connects German company-winding-up procedures with the AI Act’s documentation requirements.
For AI providers, this reinforces the need to treat technical and regulatory documentation as controlled business records rather than temporary project files.
Whistleblower Protection Under KI-MIG
Article 87 of the EU AI Act provides that Directive (EU) 2019/1937 applies to reporting AI Act infringements and protecting people who report them.
Germany amended its Hinweisgeberschutzgesetz (Whistleblower Protection Act) through the KI-MIG legislation. The current German law expressly includes violations of Regulation (EU) 2024/1689 within its material scope.
The German framework therefore connects AI Act reporting with the country’s existing whistleblower protection system.
What Are the Penalties Under KI-MIG and the EU AI Act?
This is one area where the distinction between the EU regulation and the German implementation law matters.
The EU AI Act establishes the main penalty framework in Article 99. For prohibited AI practices under Article 5, administrative fines can reach €35 million or 7% of worldwide annual turnover, whichever is higher. Other specified violations can attract fines of up to €15 million or 3% of worldwide annual turnover, while supplying incorrect, incomplete or misleading information can attract fines of up to €7.5 million or 1% of worldwide annual turnover, subject to the rules and SME limits in Article 99.
KI-MIG adds German administrative provisions around those EU-level penalties.
For example, Section 15 identifies specific violations that constitute administrative offences under German law. It also provides for a fine of up to €50,000 for the specified offence concerning an affected person’s right to an explanation under Article 86 in certain Annex III high-risk AI use cases.
So it would be inaccurate to describe KI-MIG as having no German fine provisions. A more accurate description is that the EU AI Act establishes the principal EU-wide penalty framework, while KI-MIG establishes German administrative provisions and procedures for enforcing the Regulation.
What Does KI-MIG Mean for Businesses in Germany?
For most businesses, the starting point remains the EU AI Act itself.
KI-MIG determines how those EU requirements are supervised and administered in Germany.
The practical impact depends on the type of AI system, sector, role and intended use. Businesses should therefore maintain a clear record of:
- Which AI systems they operate and whether they are providers, deployers or another operator category.
- Which EU AI Act obligations apply to each system.
- Which German authority is responsible for the relevant system or sector.
- What evidence supports the organisation’s compliance position, including documentation, assessments and decisions.
- Which regulatory developments affect the system, particularly where German procedures or supervisory guidance evolve.
For organisations developing or deploying high-risk AI, authority mapping becomes especially useful because KI-MIG distributes responsibilities across BNetzA, sector-specific authorities and the independent AI-Marktüberwachungskammer.
How AnnexOps Helps
AnnexOps helps AI teams organise their compliance operations around the systems they actually develop and deploy.Its AI inventory, risk classification, obligation management, documentation and evidence workflows can help teams connect individual AI systems with their applicable EU AI Act requirements.
For organisations operating in Germany, that information can also be used as part of an internal process for tracking the relevant national supervisory structure, documentation and regulatory developments.
The objective is not to create a separate compliance process for every regulatory update. It is to keep the AI inventory, obligations, evidence and review workflow connected as the regulatory environment develops.
Tracking your EU AI Act and German compliance position?
AnnexOps helps AI teams manage AI inventories, obligations, documentation and evidence through one structured workflow.
Primary Legal Sources
- EU AI Act — Regulation (EU) 2024/1689, current consolidated version: EUR-Lex
- KI-MIG — German federal legal text: Gesetze im Internet
- German legislative record: Deutscher Bundestag – DIP
- BNetzA announcement on KI-MIG entering into force: Bundesnetzagentur
Legal-status note: This article reflects the EU AI Act’s consolidated legal text and the German KI-MIG provisions available as of September 2026. KI-MIG-specific administrative practice, guidance, and supervisory procedures may continue to develop. The article is informational and does not constitute legal advice.
