Germany governs artificial intelligence through the directly applicable EU AI Act, not a separate national AI statute. What it is building nationally is the supervision: an implementation law, the KI-MIG, that makes the Bundesnetzagentur the central authority for the AI Act, alongside the data-protection role of the BfDI and the security work of the BSI. This page sets out the instruments, the dates, and what is binding versus proposed, with links to the sources for each. For our German-language coverage, see the German site.
Last reviewed: 21 July 2026 · The KI-MIG is still in the legislative process; confirm against the primary sources linked below
The binding backbone in Germany is the EU AI Act, which as an EU regulation applies directly and phases in on the EU-wide timeline, together with existing law such as the GDPR and the German Federal Data Protection Act. Germany is not writing a separate AI code; it is deciding who enforces the AI Act and how.
That is the job of the KI-MIG, the AI Market Surveillance and Innovation Promotion Act. The government adopted its draft in February 2026, designating the Bundesnetzagentur (Federal Network Agency) as the central market-surveillance authority, notifying authority and single point of contact, supported by sector regulators, with the BfDI keeping data protection and the BSI addressing AI security. The KI-MIG has passed the Bundestag but still needs Bundesrat approval, so the supervisory architecture is settled in draft and not yet finally in force. Germany also missed the EU’s August 2025 deadline to designate authorities, which is part of why the implementation law matters.
Germany refreshed its national AI strategy, positioning the country as a leading AI innovation hub while emphasising responsible, human-centric AI, research and transfer to industry, regulatory sandboxes and AI safety and security.
As an EU regulation, the AI Act applies directly in Germany and phases in on the EU-wide timeline, rather than through a separate German AI statute. The German task is to designate supervisors and set enforcement, not to write the substance.
Member states were to designate their national AI Act authorities by this date. Germany missed the deadline, leaving its supervisory architecture to be settled by a dedicated implementation law.
The government adopted the draft AI Market Surveillance and Innovation Promotion Act (KI-Marktueberwachungs- und Innovationsfoerderungsgesetz, KI-MIG), which designates the Bundesnetzagentur (Federal Network Agency) as the central market-surveillance authority, notifying authority and single point of contact for the AI Act, with DAkkS as the accreditation body.
The KI-MIG passed the Bundestag but still requires Bundesrat approval before it becomes law, so as of 2026 the supervisory design is settled in draft but not yet fully in force. In parallel the BSI (Federal Office for Information Security) published its draft A5 assessment architecture for trustworthy AI systems for consultation.
The distinction that matters most for compliance is whether an instrument carries legal force now, is guidance, or is still moving through the legislature. The table below sorts the main instruments accordingly.
| Instrument | Status | Applies to / owner |
|---|---|---|
| EU AI Act (Regulation (EU) 2024/1689) | Binding | Providers and deployers of AI systems in the EU; phased in on the EU timeline |
| GDPR and the German Federal Data Protection Act (BDSG) | Binding | Any organisation processing personal data; enforced by the BfDI and the state data protection authorities |
| KI-MIG (AI Market Surveillance and Innovation Promotion Act) | Proposed, in the legislative process | The implementation law that sets Germany’s AI Act supervisors and penalties; passed the Bundestag, awaits Bundesrat approval |
| Bundesnetzagentur as central AI market-surveillance authority | Being established (via KI-MIG) | Designated central authority for AI Act compliance, subject to sector-specific regulators |
| BfDI guidance on AI and the GDPR | Guidance | Data-protection aspects of AI; the BfDI is not an AI Act enforcement authority |
| BSI A5 assessment architecture for trustworthy AI | Draft / voluntary | A technical assessment approach for AI security and trustworthiness (Federal Office for Information Security) |
| National AI Strategy (updated 2024) | Strategy, not a rule | Whole-of-government direction, not an obligation on firms |
For the roles the AI Act allocates between providers and deployers, see our guide to EU AI Act roles, and for the phasing dates, the EU AI Act timeline. Germany also operates the strictest data-centre efficiency law in force, the EnEfG, covered in our data-centre regulation briefing.
Two practical points follow. First, the substantive obligations come from the EU AI Act, so a German organisation should scope which of its systems the Act covers and in what role, exactly as anywhere else in the EU. Second, the German-specific question is supervision and enforcement: once the KI-MIG is in force, the Bundesnetzagentur is the authority most organisations will deal with for the AI Act, alongside the BfDI for data protection, so it is worth tracking the bill through the Bundesrat.
While the supervisory design is still being finalised, the weight of day-to-day AI governance sits with each organisation’s own framework and controls. Our AI GRC guide covers how those pieces fit together, and a short governance assessment benchmarks where an organisation stands against a structured model.
There is no standalone German AI Act that replaces the EU AI Act. The EU AI Act applies directly in Germany. What Germany is adding nationally is an implementation law, the KI-MIG, which designates the supervisory authorities and sets the enforcement and penalty regime for the AI Act. As of 2026 the KI-MIG has passed the Bundestag but still needs Bundesrat approval, so it is a draft in the legislative process rather than a law fully in force.
Under the draft KI-MIG the Bundesnetzagentur (Federal Network Agency) becomes the central market-surveillance authority, notifying authority and single point of contact for the EU AI Act, working alongside sector-specific regulators. The BfDI (Federal Commissioner for Data Protection and Freedom of Information) retains its role on data protection and issues guidance on AI and the GDPR, and the BSI addresses AI security. Germany chose a hybrid model: a strong central authority rather than a brand new agency.
Not yet fully. The Federal Cabinet adopted the KI-MIG government draft in February 2026 and it passed the Bundestag, but it still requires approval from the Bundesrat before it becomes law. Until then, Germany’s AI Act supervisory architecture is settled in draft but not finally enacted.
Because the AI Act is an EU regulation, its obligations phase in across Germany on the same EU-wide schedule rather than on a separate national one. See our EU AI Act timeline for the current phasing, including the deferred dates under the Digital Omnibus.
The GDPR and the German Federal Data Protection Act (BDSG) apply in full to personal data used in AI, enforced by the BfDI and the state data protection authorities. The BfDI publishes guidance on how data-protection law applies to AI, which sits alongside, and is separate from, AI Act market surveillance.
A short, free assessment benchmarks where your organisation stands against a structured AI governance model, useful while Germany’s supervisory architecture is still being finalised.
This page is general information describing the state of Germany AI policy as at 21 July 2026, not legal or compliance advice. The KI-MIG is still moving through the legislature and EU dates can change; always confirm the current position against the primary sources linked above and obtain advice from your own qualified counsel before relying on it.