Germany’s implementation status
Germany is implementing the EU AI Act through directly applicable EU regulation plus the national KI-MIG framework. As the EU’s largest economy with significant AI deployment across automotive, manufacturing, healthcare and financial services, Germany’s approach has outsized influence on how the regulation lands in practice.[1][2]
National implementing legislation
The KI-Marktüberwachungsgesetz und Innovationsförderungsgesetz (KI-MIG), the “AI Market Surveillance and Innovation Promotion Act”, began as an August 2025 draft and was adopted by the Bundestag on 11 June 2026. The public sources reviewed for this page did not independently establish promulgation or entry into force; confirm the Federal Law Gazette and current competent-authority notices before relying on the allocations below.
| Pillar | Detail |
|---|---|
| BNetzA role | The Bundestag-adopted KI-MIG text assigns the Federal Network Agency the central market-surveillance role, subject to sector allocations and final legal status. |
| KoKIVO coordination center | Coordination center for AI and connected objects (Koordinierungsstelle für künstliche Intelligenz und vernetzte Objekte) planned within BNetzA to align supervision across sector authorities. |
| Decentralised supervision | Existing sector regulators (BfArM, BaFin, KBA, Länder authorities) retain their domains. |
| UKIM Independent Chamber | Independent Market Surveillance Chamber (Unabhängige Kammer für die Marktüberwachung) within BNetzA for sensitive high-risk areas. |
| Regulatory sandboxes | Article 57 sandboxes operated by BNetzA. |
| AI Service Desk | Live since July 2025; first point of contact for businesses deploying AI in Germany. |
The EU AI Act (Regulation 2024/1689) is directly applicable across all member states. German organizations must comply with the substantive obligations regardless of where the KI-MIG sits in the legislative process. The KI-MIG sets enforcement mechanisms; it does not change the underlying obligations.
National competent authority and sector overlay
Article 70 requires each member state to designate at least one national competent authority. The Bundestag-adopted KI-MIG text layers a central BNetzA role over existing sector regulators. Confirm the bill’s current legal status and the applicable sector route before naming the authority for a particular system.[1][8]
Bundesnetzagentur
BNetzA already regulates telecommunications, postal services, electricity, gas and railway markets. The Bundestag-adopted KI-MIG text assigns the following AI Act functions, subject to final legal status and sector-specific allocation:
| Function | Detail |
|---|---|
| Market surveillance coordination | Lead authority for AI Act compliance; coordinates inspections, complaints handling and cross-border enforcement. |
| KoKIVO coordination center | Hosts the planned coordination center that aligns supervision across sector authorities. |
| AI Service Desk | Operational since July 2025; provides guidance on AI Act compliance, risk classification and documentation. |
| AI Lab | Technical testing facility for evaluating AI systems, conformity assessments and enforcement support. |
| Regulatory sandbox | Operates Article 57 sandboxes for controlled testing under regulatory guidance. |
Sector authorities
The Bundestag-adopted KI-MIG text maintains a decentralised supervisory structure in which sector regulators retain roles in their domains. Confirm promulgation, entry into force, and the current allocation before relying on the list below:
| Authority | Domain | AI Act relevance |
|---|---|---|
| BfArM | Medical devices, in-vitro diagnostics | Medical AI, diagnostic algorithms, clinical decision support |
| BaFin | Financial services supervision | Credit scoring, algorithmic trading, insurance underwriting |
| KBA | Motor vehicles and road traffic | Autonomous vehicles, ADAS, vehicle type approval |
| BfDI | Federal data protection | Publishes guidance on AI/GDPR interplay; not designated as AI Act authority |
| State DPAs | Data protection in the Länder | GDPR/AI Act intersection; biometric AI; employee monitoring |
| Länder authorities | Product safety | Consumer AI products, general market surveillance |
UKIM: the Independent Market Surveillance Chamber
The Bundestag-adopted KI-MIG text establishes UKIM (Unabhängige Kammer für die Marktüberwachung) within BNetzA for specified sensitive high-risk areas. Confirm the text’s entry into force before relying on this allocation. The adopted text covers:
- Law enforcement: risk assessment, evidence evaluation, crime prediction.
- Migration and asylum: application processing, document verification.
- Border control: biometric identification, risk assessment.
- Justice and democratic processes: judicial-decision support, election-related systems.
UKIM reports annually to the Bundestag on AI deployment in these areas, providing democratic oversight of government AI use.
Implementation timeline and Omnibus framing
The EU AI Act timeline applies uniformly across member states. Regulation (EU) 2026/1744 is now in force and sets the current 2 December 2027 Annex III and 2 August 2028 Annex I product-embedded high-risk dates.[12]
| Date | Milestone | Notes for Germany |
|---|---|---|
| Aug 2024 | EU AI Act entry into force | Directly applicable across the EU. |
| Feb 2025 | Prohibited practices apply | The EU-level prohibited-practice and AI-literacy provisions began applying. |
| Jul 2025 | BNetzA AI Service Desk live | First point of contact for businesses deploying AI in Germany. |
| Aug 2025 | GPAI obligations apply | The Commission maintains a live GPAI Code signatory register; check provider status at the time of diligence. |
| Jul 2026 | AI Omnibus enters into force | Regulation (EU) 2026/1744 applies from 27 July. |
| Aug 2026 | EU regulatory-sandbox deadline | Article 57 required at least one sandbox per Member State by 2 August; confirm Germany’s current access route with BNetzA. |
| Dec 2027 | Annex III high-risk obligations | Relevant high-risk duties apply from 2 December. |
| Aug 2028 | Annex I product-embedded high-risk obligations | Relevant duties apply from 2 August, including covered automotive and medical-device pathways. |
The AI Omnibus is in force. Build conformity, technical documentation, and Article 12 logging against the date applicable to the system: 2 December 2027 for relevant Annex III duties or 2 August 2028 for relevant Annex I product-embedded duties. Other provisions retain their own dates.
High-risk AI sectors in Germany
Germany’s industrial structure means certain Annex III categories have outsized relevance, as does the Annex I product-safety pathway.[4][5][6]
Automotive and manufacturing
Germany’s automotive industry (Volkswagen, BMW, Daimler, Bosch) sits at the intersection of two AI Act pathways:
| Pathway | What it covers |
|---|---|
| Annex I (Article 6(1)) | AI as a safety component of products requiring third-party conformity assessment. Vehicle type approval falls here. |
| Annex III §2 | AI managing critical infrastructure including road traffic. |
The Type-Approval Framework Regulation (EU 2018/858) acts as lex specialis for vehicle-related AI safety components; AI Act requirements supplement rather than supersede. The VDA’s KI-Absicherung project develops assurance methods for in-vehicle AI. Key applications for compliance attention: autonomous-driving systems (Level 3+); ADAS features (automatic emergency braking, lane keeping); in-cabin monitoring (driver drowsiness, emotion detection); predictive maintenance (generally minimal risk unless safety-critical).[4]
Healthcare and medical devices
Germany’s healthcare and medical-device sectors may face obligations under both the AI Act and the Medical Device Regulation. BfArM retains responsibilities for medical devices. Classification, conformity assessment, clinical evaluation, post-market surveillance, and vigilance obligations depend on the product and intended purpose. Relevant Annex I product-embedded high-risk duties apply from 2 August 2028 under the AI Omnibus.[6]
Financial services
German financial institutions deploying AI for creditworthiness assessment, insurance underwriting or algorithmic trading face high-risk classification under Annex III §5. BaFin retains supervisory authority; AI Act requirements complement BaFin’s MaRisk minimum requirements for risk management.
Article 12 logging requirements
Article 12 requires high-risk AI systems to support automatic event logging over their lifetime at a level appropriate to intended purpose. In Germany, implementation also intersects with GDPR (DSGVO), works-council rights under BetrVG and sector-specific retention regimes.
Core logging requirements
| Layer | What must be captured |
|---|---|
| General rule | Logging capabilities enabling traceability appropriate to intended purpose, including events relevant to risk identification and post-market monitoring. |
| Remote biometric identification | Article 12(3) adds specific minimum fields for covered systems: period of each use; reference database checked; input data leading to a match; and identity of natural persons involved in verifying results. |
| Integrity and retention | The Regulation does not generally prescribe cryptography or tamper-evident storage. Apply proportionate integrity controls and determine retention from the applicable provider, deployer and sector rules. |
German-specific considerations
| Layer | Detail |
|---|---|
| GDPR / DSGVO | Logs containing personal data must satisfy purpose limitation, storage limitation and data-subject rights. Reconcile AI Act logging mandates with GDPR minimization; BfDI’s AI/GDPR guidance applies.[8] |
| Works council access | Under §80(2) BetrVG, works councils can request access to AI system logs to verify works-agreement compliance and employee-protection provisions.[3][7] |
| Sector retention | Financial services (MaRisk), healthcare (medical records), automotive (product liability) all have retention regimes that must harmonise with Article 12 logging. |
GLACIS can create signed operational records for selected events and control decisions, with configurable access and retention. Those records may support a wider evidence set; they do not establish regulator acceptance, complete coverage, control effectiveness or Article 12 compliance.
Works councils and sector overlays
Employment and works councils (Betriebsrat)
German employers deploying AI in employment contexts face dual compliance: EU AI Act obligations and national co-determination rights under the Works Constitution Act (BetrVG). Employment AI is explicitly high-risk under Annex III §4: recruitment and candidate screening; task allocation; promotion decisions; performance monitoring; and termination decisions all qualify.[3][7]
Works council rights under BetrVG
The 2021 Works Council Modernisation Act added AI-specific provisions to BetrVG:
| Section | Right | Practical implication |
|---|---|---|
| §80(3) BetrVG | Expert consultation | Works council may engage external AI experts at employer expense. |
| §87(1) No. 6 | Co-determination on monitoring | Veto power over AI systems capable of monitoring employee behavior or performance. |
| §90(1) No. 3 | Information before introduction | Employer must inform the works council in good time before deploying AI. |
| §95(2a) | Personnel selection guidelines | Works council involvement in AI-based personnel selection criteria. |
Begin works-council analysis and engagement early when an employment AI system may trigger information or co-determination rights. The required process, agreement, remedies, and timing depend on the system’s capabilities, workplace use, and applicable rights; do not apply a generic negotiation timeline.
Healthcare sector
Covered healthcare AI may need to satisfy both AI Act and medical-device requirements. BfArM oversees medical-device pathways; the DiGA directory has separate requirements. Relevant Annex I product-embedded high-risk duties apply from 2 August 2028, and German healthcare-privacy rules can apply alongside GDPR.
Financial services
BaFin-supervised institutions should classify each system against the Act’s exact pathways. Annex III point 5(b) covers specified natural-person creditworthiness and credit-score uses, subject to its fraud-detection exclusion; point 5(c) covers risk assessment and pricing for natural persons in life and health insurance. Algorithmic trading and other insurance uses are not automatically high-risk under those entries. Separate BaFin, MaRisk, and sector requirements require their own analysis.
Conformity assessment pathway
German organizations with covered high-risk AI systems must complete the applicable conformity assessment before placing a system on the market or putting it into service once the relevant duties apply. The high-risk date is 2 December 2027 for relevant Annex III duties or 2 August 2028 for relevant Annex I product-embedded duties.
| Pathway | Detail |
|---|---|
| Internal control | Article 43(2) uses the Annex VI internal-control route for Annex III points 2 to 8. Point 1 biometric systems have the choices and conditions in Article 43(1). Internal work includes the applicable technical documentation, quality-management, post-market, declaration, and registration duties. |
| Conditional notified-body involvement | For Annex III point 1 biometric systems, Article 43(1) determines when the Annex VII route applies. Annex I products follow their sector legislation’s conformity route. Timing and fees depend on the system, route, and eligible body. |
German notified bodies
Operators that need third-party assessment should consult the current German notifying-authority material and the EU’s official notified-body listings for the relevant legal act and system scope. This page does not treat a testing organization, certification company, or body designated under another regime as automatically designated for an AI Act assessment.
Enforcement and penalties
The EU AI Act sets penalty ceilings, while national competence depends on the applicable provision, system, sector, and effective German implementation law. The Bundestag-adopted KI-MIG text assigns roles to BNetzA and sector authorities; verify promulgation and the current competent authority before describing an enforcement route.
Penalty structure
| Violation | Maximum fine | Enforcing authority |
|---|---|---|
| Prohibited AI practices | €35,000,000 or 7% global revenue | BNetzA; UKIM for sensitive areas |
| High-risk non-compliance | €15,000,000 or 3% global revenue | BNetzA; sector authorities |
| GPAI obligations | €15,000,000 or 3% global revenue | EU AI Office (direct) |
| Incorrect information to authorities | €7,500,000 or 1% global revenue | BNetzA; sector authorities |
| Article 50 transparency violations | €15,000,000 or 3% global revenue | BNetzA; sector authorities |
Enforcement powers
German authorities have extensive investigatory powers under Article 74: access to conformity documentation and technical data; access to training, validation and testing datasets; access to source code and algorithms (protected as confidential); and the power to require corrective action or market withdrawal.
Compliance roadmap for German organizations
The roadmap below should be scheduled against 2 December 2027 for relevant Annex III duties or 2 August 2028 for relevant Annex I product-embedded duties. The correct date depends on classification and product-law pathway.
| Phase | Detail |
|---|---|
| 01. AI system inventory and classification | Catalogue all AI systems. Classify per Annex III risk categories and Annex I product-safety pathways. Identify systems triggering works-council involvement (§87 BetrVG). Map to BfArM, BaFin, KBA where applicable. |
| 02. Works-council engagement | Assess and address applicable information and co-determination rights, including §90 and §87 BetrVG where relevant. Begin early; process, agreement, and expert-consultation timing depend on the system and workplace context. |
| 03. Risk management and documentation | Stand up Article 9 risk management. Prepare Annex IV technical documentation. Integrate with ISO 42001 and sector requirements. Document risk mitigation and residual risks. |
| 04. Article 12 logging | Design automatic event logging around intended purpose and the applicable Article 12 events. Ensure GDPR/DSGVO compliance for logged personal data. Apply proportionate access and integrity controls, determine retention from applicable rules, and prepare works-council and regulator access procedures. |
| 05. Conformity assessment | Internal control or notified-body assessment. Prepare EU declaration of conformity, register in EU AI database (Article 71), affix CE marking. For medical AI, coordinate with BfArM and MDR; for vehicles, coordinate with KBA and the type-approval framework. |
| 06. Post-market monitoring (Ongoing) | Article 72 post-market monitoring and Article 73 serious-incident workflows. The Bundestag-adopted text assigns roles to BNetzA and sector authorities; verify promulgation and the current reporting destination before filing. |
German organizations can face tighter effective timelines because works-council negotiations may sit on the critical path. Work backward from the applicable 2027 or 2028 high-risk date and allow time for classification, employee-representation processes, and any required conformity assessment.
FAQ
Who is the competent authority for the EU AI Act in Germany?
The Bundestag adopted an amended KI-MIG bill on 11 June 2026 that gives BNetzA a central role and preserves sector-specific authorities. The public sources reviewed here did not establish promulgation or entry into force, so confirm the current Federal Law Gazette status and sector allocation before naming the competent authority.
What is the KI-Verordnung and when does it apply?
KI-Verordnung is the German term for the EU AI Act (Regulation 2024/1689). Germany is implementing its enforcement architecture through the KI-Marktüberwachungsgesetz und Innovationsförderungsgesetz (KI-MIG). The Act applies directly; under the AI Omnibus, relevant Annex III high-risk obligations apply from 2 December 2027 and relevant Annex I product-embedded obligations from 2 August 2028.
Do German works councils have rights regarding AI systems?
Yes, and they are extensive. Under the Works Constitution Act (BetrVG), employers must inform the works council before introducing AI (§90), works councils can consult external AI experts at employer expense (§80), they hold co-determination rights over systems that could monitor employees (§87), and they must be involved in AI-based personnel selection guidelines (§95). These rights apply in addition to EU AI Act deployer obligations and typically require negotiated works agreements before deployment.
How does the EU AI Act affect German automotive companies?
Vehicle and ADAS systems can enter the Annex I product pathway when they satisfy the AI Act’s high-risk and product-law conditions. Under the AI Omnibus, relevant Annex I product-embedded obligations apply from 2 August 2028. German manufacturers should map each system to the type-approval framework and confirm the applicable conformity pathway; this overview is not legal advice.
What are the penalties in Germany?
Penalties follow the EU ceilings: up to €35M or 7% of global turnover for prohibited practices; €15M or 3% for listed operator obligations, Article 50 transparency duties, and GPAI obligations; €7.5M or 1% for incorrect, incomplete, or misleading information supplied in response to an authority request. Enforcement authority depends on the system and sector.
What is Article 12 logging and why does it matter in Germany?
Article 12 requires high-risk AI systems to support automatic event logging over their lifetime at a level appropriate to intended purpose. In Germany this can intersect with GDPR/DSGVO, works-council information rights and sector retention rules. The Regulation does not generally require cryptography or tamper-evident storage; exact access and retention duties depend on role, system and applicable law.
Are there AI regulatory sandboxes in Germany?
Article 57 required each Member State to ensure at least one AI regulatory sandbox was operational by 2 August 2026. The Bundestag-adopted KI-MIG text assigns a sandbox role to BNetzA. Because operational access and final legal status can change, confirm the current German route directly with BNetzA and the Federal Law Gazette.
References
- Technology’s Legal Edge. “State of the Act: EU AI Act implementation in key Member States.” Updated 2025–2026. technologyslegaledge.com
- Pinsent Masons. “AI Act: Germany consults on implementation law.” 2025. pinsentmasons.com
- Hogan Lovells. “AI in German Employment — Navigating the AI Act, GDPR, and National Legislation.” 2024. hoganlovells.com
- VDA. “Position: AI Act.” 2023. vda.de
- Taylor Wessing. “AI Act and the Automotive Industry — where does the road lead?” March 2025. taylorwessing.com
- European Union. “Regulation (EU) 2024/1689.” OJEU, 12 July 2024. EUR-Lex
- Bird & Bird. “First Judgment on the Rights of Works Councils when Employees use AI Systems.” 2024. twobirds.com
- White & Case. “AI Watch: Global Regulatory Tracker — Germany.” Updated 2025–2026. whitecase.com
- Chambers and Partners. “Artificial Intelligence 2025 — Germany.” Practice Guide, 2025. chambers.com
- DLA Piper. “German government provides information on its plans for AI and employee protection.” 2024. dlapiper.com
- Simmons & Simmons. “Germany’s Implementation Act for the EU AI Act.” 2025. simmons-simmons.com
- European Parliament. “Artificial Intelligence Act: delayed application, ban on nudifier apps.” 23 March 2026. europarl.europa.eu