GLACIS·EU AI Act series·DE Germany·EU timeline checked August 2026

The EU AI Act in Germany: BNetzA, KoKIVO and the current high-risk dates.

BNetzA, KoKIVO, BaFin, BfDI, sector regulators, and works-council obligations form Germany’s implementation stack. This page gives General Counsel, CCO, CISO, and DPO teams a working view, updated for the AI Omnibus now in force and the current 2027 and 2028 high-risk dates.

Talk to us Read the full EU AI Act guide →
General Counsel CCO CISO DPO
Feb 2025
Prohibited practices in force
Jul 2025
BNetzA AI Service Desk operational
Aug 2025
GPAI obligations live; KI-MIG legislative process active
Dec 2027
Relevant Annex III high-risk obligations
Germany status reviewed 26 August 2026

The Bundestag adopted the amended AI Act implementation bill on 11 June 2026. The adopted KI-MIG text gives BNetzA a central market-surveillance role and creates the KoKIVO coordination center while preserving sector-specific authorities. The public legislative sources reviewed for this page did not establish promulgation or entry into force; confirm the current Federal Law Gazette status before treating those assignments as legally operative.[1][2][8]

After the May 2026 provisional agreement, the AI Omnibus was adopted as Regulation (EU) 2026/1744 and entered into force on 27 July 2026. Relevant Annex III high-risk obligations apply from 2 December 2027; relevant Annex I product-embedded obligations apply from 2 August 2028.

The EU AI Act remains directly applicable regardless of the national implementation bill’s final status. For a live matter, confirm both the provision-level EU date and the currently competent German authority.[1]

Executive summary

The Bundestag-adopted KI-MIG text uses a multi-authority architecture with a central BNetzA role. BNetzA operates an AI Service Desk, and the adopted bill provides for KoKIVO coordination. Confirm promulgation and entry into force before relying on the bill as operative law.[1]

Germany’s existing sector rules continue to matter: works-council co-determination can apply where the statutory conditions for technical monitoring are met; BfArM, BaFin, KBA, and other authorities retain sector roles. The adopted KI-MIG text also provides for an Independent Market Surveillance Chamber (UKIM) in specified sensitive areas.[1][2][3]

The practical position after the Omnibus: classify each system, map it to the applicable 2 December 2027 or 2 August 2028 high-risk date, account for works-council involvement where required, and confirm the national supervisory pathway. Other provisions retain their own dates.

Germany’s implementation status

Germany is implementing the EU AI Act through directly applicable EU regulation plus the national KI-MIG framework. As the EU’s largest economy with significant AI deployment across automotive, manufacturing, healthcare and financial services, Germany’s approach has outsized influence on how the regulation lands in practice.[1][2]

National implementing legislation

The KI-Marktüberwachungsgesetz und Innovationsförderungsgesetz (KI-MIG), the “AI Market Surveillance and Innovation Promotion Act”, began as an August 2025 draft and was adopted by the Bundestag on 11 June 2026. The public sources reviewed for this page did not independently establish promulgation or entry into force; confirm the Federal Law Gazette and current competent-authority notices before relying on the allocations below.

PillarDetail
BNetzA roleThe Bundestag-adopted KI-MIG text assigns the Federal Network Agency the central market-surveillance role, subject to sector allocations and final legal status.
KoKIVO coordination centerCoordination center for AI and connected objects (Koordinierungsstelle für künstliche Intelligenz und vernetzte Objekte) planned within BNetzA to align supervision across sector authorities.
Decentralised supervisionExisting sector regulators (BfArM, BaFin, KBA, Länder authorities) retain their domains.
UKIM Independent ChamberIndependent Market Surveillance Chamber (Unabhängige Kammer für die Marktüberwachung) within BNetzA for sensitive high-risk areas.
Regulatory sandboxesArticle 57 sandboxes operated by BNetzA.
AI Service DeskLive since July 2025; first point of contact for businesses deploying AI in Germany.
Direct applicability

The EU AI Act (Regulation 2024/1689) is directly applicable across all member states. German organizations must comply with the substantive obligations regardless of where the KI-MIG sits in the legislative process. The KI-MIG sets enforcement mechanisms; it does not change the underlying obligations.

National competent authority and sector overlay

Article 70 requires each member state to designate at least one national competent authority. The Bundestag-adopted KI-MIG text layers a central BNetzA role over existing sector regulators. Confirm the bill’s current legal status and the applicable sector route before naming the authority for a particular system.[1][8]

Bundesnetzagentur

BNetzA already regulates telecommunications, postal services, electricity, gas and railway markets. The Bundestag-adopted KI-MIG text assigns the following AI Act functions, subject to final legal status and sector-specific allocation:

FunctionDetail
Market surveillance coordinationLead authority for AI Act compliance; coordinates inspections, complaints handling and cross-border enforcement.
KoKIVO coordination centerHosts the planned coordination center that aligns supervision across sector authorities.
AI Service DeskOperational since July 2025; provides guidance on AI Act compliance, risk classification and documentation.
AI LabTechnical testing facility for evaluating AI systems, conformity assessments and enforcement support.
Regulatory sandboxOperates Article 57 sandboxes for controlled testing under regulatory guidance.

Sector authorities

The Bundestag-adopted KI-MIG text maintains a decentralised supervisory structure in which sector regulators retain roles in their domains. Confirm promulgation, entry into force, and the current allocation before relying on the list below:

AuthorityDomainAI Act relevance
BfArMMedical devices, in-vitro diagnosticsMedical AI, diagnostic algorithms, clinical decision support
BaFinFinancial services supervisionCredit scoring, algorithmic trading, insurance underwriting
KBAMotor vehicles and road trafficAutonomous vehicles, ADAS, vehicle type approval
BfDIFederal data protectionPublishes guidance on AI/GDPR interplay; not designated as AI Act authority
State DPAsData protection in the LänderGDPR/AI Act intersection; biometric AI; employee monitoring
Länder authoritiesProduct safetyConsumer AI products, general market surveillance

UKIM: the Independent Market Surveillance Chamber

The Bundestag-adopted KI-MIG text establishes UKIM (Unabhängige Kammer für die Marktüberwachung) within BNetzA for specified sensitive high-risk areas. Confirm the text’s entry into force before relying on this allocation. The adopted text covers:

  • Law enforcement: risk assessment, evidence evaluation, crime prediction.
  • Migration and asylum: application processing, document verification.
  • Border control: biometric identification, risk assessment.
  • Justice and democratic processes: judicial-decision support, election-related systems.

UKIM reports annually to the Bundestag on AI deployment in these areas, providing democratic oversight of government AI use.

Implementation timeline and Omnibus framing

The EU AI Act timeline applies uniformly across member states. Regulation (EU) 2026/1744 is now in force and sets the current 2 December 2027 Annex III and 2 August 2028 Annex I product-embedded high-risk dates.[12]

DateMilestoneNotes for Germany
Aug 2024EU AI Act entry into forceDirectly applicable across the EU.
Feb 2025Prohibited practices applyThe EU-level prohibited-practice and AI-literacy provisions began applying.
Jul 2025BNetzA AI Service Desk liveFirst point of contact for businesses deploying AI in Germany.
Aug 2025GPAI obligations applyThe Commission maintains a live GPAI Code signatory register; check provider status at the time of diligence.
Jul 2026AI Omnibus enters into forceRegulation (EU) 2026/1744 applies from 27 July.
Aug 2026EU regulatory-sandbox deadlineArticle 57 required at least one sandbox per Member State by 2 August; confirm Germany’s current access route with BNetzA.
Dec 2027Annex III high-risk obligationsRelevant high-risk duties apply from 2 December.
Aug 2028Annex I product-embedded high-risk obligationsRelevant duties apply from 2 August, including covered automotive and medical-device pathways.
Working baseline

The AI Omnibus is in force. Build conformity, technical documentation, and Article 12 logging against the date applicable to the system: 2 December 2027 for relevant Annex III duties or 2 August 2028 for relevant Annex I product-embedded duties. Other provisions retain their own dates.

High-risk AI sectors in Germany

Germany’s industrial structure means certain Annex III categories have outsized relevance, as does the Annex I product-safety pathway.[4][5][6]

Automotive and manufacturing

Germany’s automotive industry (Volkswagen, BMW, Daimler, Bosch) sits at the intersection of two AI Act pathways:

PathwayWhat it covers
Annex I (Article 6(1))AI as a safety component of products requiring third-party conformity assessment. Vehicle type approval falls here.
Annex III §2AI managing critical infrastructure including road traffic.

The Type-Approval Framework Regulation (EU 2018/858) acts as lex specialis for vehicle-related AI safety components; AI Act requirements supplement rather than supersede. The VDA’s KI-Absicherung project develops assurance methods for in-vehicle AI. Key applications for compliance attention: autonomous-driving systems (Level 3+); ADAS features (automatic emergency braking, lane keeping); in-cabin monitoring (driver drowsiness, emotion detection); predictive maintenance (generally minimal risk unless safety-critical).[4]

Healthcare and medical devices

Germany’s healthcare and medical-device sectors may face obligations under both the AI Act and the Medical Device Regulation. BfArM retains responsibilities for medical devices. Classification, conformity assessment, clinical evaluation, post-market surveillance, and vigilance obligations depend on the product and intended purpose. Relevant Annex I product-embedded high-risk duties apply from 2 August 2028 under the AI Omnibus.[6]

Financial services

German financial institutions deploying AI for creditworthiness assessment, insurance underwriting or algorithmic trading face high-risk classification under Annex III §5. BaFin retains supervisory authority; AI Act requirements complement BaFin’s MaRisk minimum requirements for risk management.

Article 12 logging requirements

Article 12 requires high-risk AI systems to support automatic event logging over their lifetime at a level appropriate to intended purpose. In Germany, implementation also intersects with GDPR (DSGVO), works-council rights under BetrVG and sector-specific retention regimes.

Core logging requirements

LayerWhat must be captured
General ruleLogging capabilities enabling traceability appropriate to intended purpose, including events relevant to risk identification and post-market monitoring.
Remote biometric identificationArticle 12(3) adds specific minimum fields for covered systems: period of each use; reference database checked; input data leading to a match; and identity of natural persons involved in verifying results.
Integrity and retentionThe Regulation does not generally prescribe cryptography or tamper-evident storage. Apply proportionate integrity controls and determine retention from the applicable provider, deployer and sector rules.

German-specific considerations

LayerDetail
GDPR / DSGVOLogs containing personal data must satisfy purpose limitation, storage limitation and data-subject rights. Reconcile AI Act logging mandates with GDPR minimization; BfDI’s AI/GDPR guidance applies.[8]
Works council accessUnder §80(2) BetrVG, works councils can request access to AI system logs to verify works-agreement compliance and employee-protection provisions.[3][7]
Sector retentionFinancial services (MaRisk), healthcare (medical records), automotive (product liability) all have retention regimes that must harmonise with Article 12 logging.
Build the evidence trail

GLACIS can create signed operational records for selected events and control decisions, with configurable access and retention. Those records may support a wider evidence set; they do not establish regulator acceptance, complete coverage, control effectiveness or Article 12 compliance.

Talk to us

Works councils and sector overlays

Employment and works councils (Betriebsrat)

German employers deploying AI in employment contexts face dual compliance: EU AI Act obligations and national co-determination rights under the Works Constitution Act (BetrVG). Employment AI is explicitly high-risk under Annex III §4: recruitment and candidate screening; task allocation; promotion decisions; performance monitoring; and termination decisions all qualify.[3][7]

Works council rights under BetrVG

The 2021 Works Council Modernisation Act added AI-specific provisions to BetrVG:

SectionRightPractical implication
§80(3) BetrVGExpert consultationWorks council may engage external AI experts at employer expense.
§87(1) No. 6Co-determination on monitoringVeto power over AI systems capable of monitoring employee behavior or performance.
§90(1) No. 3Information before introductionEmployer must inform the works council in good time before deploying AI.
§95(2a)Personnel selection guidelinesWorks council involvement in AI-based personnel selection criteria.
Critical planning factor

Begin works-council analysis and engagement early when an employment AI system may trigger information or co-determination rights. The required process, agreement, remedies, and timing depend on the system’s capabilities, workplace use, and applicable rights; do not apply a generic negotiation timeline.

Healthcare sector

Covered healthcare AI may need to satisfy both AI Act and medical-device requirements. BfArM oversees medical-device pathways; the DiGA directory has separate requirements. Relevant Annex I product-embedded high-risk duties apply from 2 August 2028, and German healthcare-privacy rules can apply alongside GDPR.

Financial services

BaFin-supervised institutions should classify each system against the Act’s exact pathways. Annex III point 5(b) covers specified natural-person creditworthiness and credit-score uses, subject to its fraud-detection exclusion; point 5(c) covers risk assessment and pricing for natural persons in life and health insurance. Algorithmic trading and other insurance uses are not automatically high-risk under those entries. Separate BaFin, MaRisk, and sector requirements require their own analysis.

Conformity assessment pathway

German organizations with covered high-risk AI systems must complete the applicable conformity assessment before placing a system on the market or putting it into service once the relevant duties apply. The high-risk date is 2 December 2027 for relevant Annex III duties or 2 August 2028 for relevant Annex I product-embedded duties.

PathwayDetail
Internal controlArticle 43(2) uses the Annex VI internal-control route for Annex III points 2 to 8. Point 1 biometric systems have the choices and conditions in Article 43(1). Internal work includes the applicable technical documentation, quality-management, post-market, declaration, and registration duties.
Conditional notified-body involvementFor Annex III point 1 biometric systems, Article 43(1) determines when the Annex VII route applies. Annex I products follow their sector legislation’s conformity route. Timing and fees depend on the system, route, and eligible body.

German notified bodies

Operators that need third-party assessment should consult the current German notifying-authority material and the EU’s official notified-body listings for the relevant legal act and system scope. This page does not treat a testing organization, certification company, or body designated under another regime as automatically designated for an AI Act assessment.

Enforcement and penalties

The EU AI Act sets penalty ceilings, while national competence depends on the applicable provision, system, sector, and effective German implementation law. The Bundestag-adopted KI-MIG text assigns roles to BNetzA and sector authorities; verify promulgation and the current competent authority before describing an enforcement route.

Penalty structure

ViolationMaximum fineEnforcing authority
Prohibited AI practices€35,000,000 or 7% global revenueBNetzA; UKIM for sensitive areas
High-risk non-compliance€15,000,000 or 3% global revenueBNetzA; sector authorities
GPAI obligations€15,000,000 or 3% global revenueEU AI Office (direct)
Incorrect information to authorities€7,500,000 or 1% global revenueBNetzA; sector authorities
Article 50 transparency violations€15,000,000 or 3% global revenueBNetzA; sector authorities

Enforcement powers

German authorities have extensive investigatory powers under Article 74: access to conformity documentation and technical data; access to training, validation and testing datasets; access to source code and algorithms (protected as confidential); and the power to require corrective action or market withdrawal.

Compliance roadmap for German organizations

The roadmap below should be scheduled against 2 December 2027 for relevant Annex III duties or 2 August 2028 for relevant Annex I product-embedded duties. The correct date depends on classification and product-law pathway.

PhaseDetail
01. AI system inventory and classificationCatalogue all AI systems. Classify per Annex III risk categories and Annex I product-safety pathways. Identify systems triggering works-council involvement (§87 BetrVG). Map to BfArM, BaFin, KBA where applicable.
02. Works-council engagementAssess and address applicable information and co-determination rights, including §90 and §87 BetrVG where relevant. Begin early; process, agreement, and expert-consultation timing depend on the system and workplace context.
03. Risk management and documentationStand up Article 9 risk management. Prepare Annex IV technical documentation. Integrate with ISO 42001 and sector requirements. Document risk mitigation and residual risks.
04. Article 12 loggingDesign automatic event logging around intended purpose and the applicable Article 12 events. Ensure GDPR/DSGVO compliance for logged personal data. Apply proportionate access and integrity controls, determine retention from applicable rules, and prepare works-council and regulator access procedures.
05. Conformity assessmentInternal control or notified-body assessment. Prepare EU declaration of conformity, register in EU AI database (Article 71), affix CE marking. For medical AI, coordinate with BfArM and MDR; for vehicles, coordinate with KBA and the type-approval framework.
06. Post-market monitoring (Ongoing)Article 72 post-market monitoring and Article 73 serious-incident workflows. The Bundestag-adopted text assigns roles to BNetzA and sector authorities; verify promulgation and the current reporting destination before filing.
Critical timing insight

German organizations can face tighter effective timelines because works-council negotiations may sit on the critical path. Work backward from the applicable 2027 or 2028 high-risk date and allow time for classification, employee-representation processes, and any required conformity assessment.

FAQ

Who is the competent authority for the EU AI Act in Germany?

The Bundestag adopted an amended KI-MIG bill on 11 June 2026 that gives BNetzA a central role and preserves sector-specific authorities. The public sources reviewed here did not establish promulgation or entry into force, so confirm the current Federal Law Gazette status and sector allocation before naming the competent authority.

What is the KI-Verordnung and when does it apply?

KI-Verordnung is the German term for the EU AI Act (Regulation 2024/1689). Germany is implementing its enforcement architecture through the KI-Marktüberwachungsgesetz und Innovationsförderungsgesetz (KI-MIG). The Act applies directly; under the AI Omnibus, relevant Annex III high-risk obligations apply from 2 December 2027 and relevant Annex I product-embedded obligations from 2 August 2028.

Do German works councils have rights regarding AI systems?

Yes, and they are extensive. Under the Works Constitution Act (BetrVG), employers must inform the works council before introducing AI (§90), works councils can consult external AI experts at employer expense (§80), they hold co-determination rights over systems that could monitor employees (§87), and they must be involved in AI-based personnel selection guidelines (§95). These rights apply in addition to EU AI Act deployer obligations and typically require negotiated works agreements before deployment.

How does the EU AI Act affect German automotive companies?

Vehicle and ADAS systems can enter the Annex I product pathway when they satisfy the AI Act’s high-risk and product-law conditions. Under the AI Omnibus, relevant Annex I product-embedded obligations apply from 2 August 2028. German manufacturers should map each system to the type-approval framework and confirm the applicable conformity pathway; this overview is not legal advice.

What are the penalties in Germany?

Penalties follow the EU ceilings: up to €35M or 7% of global turnover for prohibited practices; €15M or 3% for listed operator obligations, Article 50 transparency duties, and GPAI obligations; €7.5M or 1% for incorrect, incomplete, or misleading information supplied in response to an authority request. Enforcement authority depends on the system and sector.

What is Article 12 logging and why does it matter in Germany?

Article 12 requires high-risk AI systems to support automatic event logging over their lifetime at a level appropriate to intended purpose. In Germany this can intersect with GDPR/DSGVO, works-council information rights and sector retention rules. The Regulation does not generally require cryptography or tamper-evident storage; exact access and retention duties depend on role, system and applicable law.

Are there AI regulatory sandboxes in Germany?

Article 57 required each Member State to ensure at least one AI regulatory sandbox was operational by 2 August 2026. The Bundestag-adopted KI-MIG text assigns a sandbox role to BNetzA. Because operational access and final legal status can change, confirm the current German route directly with BNetzA and the Federal Law Gazette.

References

  1. Technology’s Legal Edge. “State of the Act: EU AI Act implementation in key Member States.” Updated 2025–2026. technologyslegaledge.com
  2. Pinsent Masons. “AI Act: Germany consults on implementation law.” 2025. pinsentmasons.com
  3. Hogan Lovells. “AI in German Employment — Navigating the AI Act, GDPR, and National Legislation.” 2024. hoganlovells.com
  4. VDA. “Position: AI Act.” 2023. vda.de
  5. Taylor Wessing. “AI Act and the Automotive Industry — where does the road lead?” March 2025. taylorwessing.com
  6. European Union. “Regulation (EU) 2024/1689.” OJEU, 12 July 2024. EUR-Lex
  7. Bird & Bird. “First Judgment on the Rights of Works Councils when Employees use AI Systems.” 2024. twobirds.com
  8. White & Case. “AI Watch: Global Regulatory Tracker — Germany.” Updated 2025–2026. whitecase.com
  9. Chambers and Partners. “Artificial Intelligence 2025 — Germany.” Practice Guide, 2025. chambers.com
  10. DLA Piper. “German government provides information on its plans for AI and employee protection.” 2024. dlapiper.com
  11. Simmons & Simmons. “Germany’s Implementation Act for the EU AI Act.” 2025. simmons-simmons.com
  12. European Parliament. “Artificial Intelligence Act: delayed application, ban on nudifier apps.” 23 March 2026. europarl.europa.eu

Make supervision reviewable

EU AI Act evidence from runtime coverage on your highest-risk workflow.

Glacis can preserve signed, scoped records from configured control paths and map fields to selected requirements. Those artifacts do not prove that controls execute correctly or establish compliance. Relevant Annex III high-risk obligations apply from 2 December 2027 under the AI Omnibus now in force.

Talk to us Talk to us

Related guides

Full EU AI Act guideRisk categories, Articles 9 to 15 in detail, GPAI obligations, conformity-assessment paths, Omnibus status.
EU AI Act in SpainAESIA, the December 2025 guidance pack, the regulatory sandbox, draft national AI law.
EU AI Act in ItalyLaw 132/2025 in force; AgID / ACN / Garante triangle; October 2026 implementing decrees.
ISO 42001 guideAI management system standard.
AI governance toolsMarket analysis and vendor comparison.