Germany's role in EU AI Act enforcement

Germany is not just subject to the EU AI Act, it is one of the central enforcement jurisdictions. As a major EU economy with significant AI deployment across automotive, manufacturing, financial services, and healthcare sectors, Germany's market surveillance authority will be among the most active in Europe. German regulatory practice will set precedent for how the EU AI Act is applied in practice.

The EU AI Act requires each member state to designate a national market surveillance authority responsible for supervising compliance within their territory. Germany missed the EU's 2 August 2025 deadline for this designation. The KI-MIG law designates the Bundesnetzagentur as Germany's lead AI market-surveillance authority, alongside sectoral supervisors such as BaFin (Taylor Wessing, 20 February 2026). It passed the Bundestag on 11 June 2026 and entered into force on 29 July 2026. The German authority will work alongside the EU AI Office on systemic risks and GPAI models, but will have primary responsibility for supervising AI systems in the German market, including imports from outside the EU that affect German users.

BaFin: AI in German financial services

The Federal Financial Supervisory Authority (BaFin) supervises banks, insurers, payment service providers, and other financial institutions in Germany. BaFin has developed specific expectations for AI governance in financial services that layer on top of the EU AI Act's requirements.

BaFin's model risk management expectations, analogous to the US SR 11-7 framework, apply to AI and ML models used in credit risk, market risk, AML, and customer-facing applications. Institutions must maintain model documentation, validate models independently, and monitor performance on an ongoing basis. BaFin's supervisory focus on AI has increased, and AI governance now features in BaFin examinations of major German financial institutions.

For credit scoring and lending AI, BaFin's expectations align with EU AI Act Annex III classification, these are high-risk AI systems requiring conformity assessment, technical documentation, and human oversight. German financial institutions should treat BaFin compliance and EU AI Act compliance as complementary, not separate, exercises.

Works council co-determination: the German employment AI dimension

One of the most practically significant AI governance considerations for employers in Germany is the Betriebsverfassungsgesetz, the Works Constitution Act, which gives works councils (Betriebsrat) substantial co-determination rights over the introduction of technical monitoring equipment and performance assessment systems. AI-based productivity monitoring, algorithmic performance scoring, and AI-assisted workforce management tools all potentially trigger works council consultation and agreement requirements.

Employers implementing AI systems that monitor employee performance, schedule work, or influence employment decisions must engage their works councils before deployment. Failure to do so can result in injunctions, works council orders, and unfair practices findings. This creates a governance requirement that sits alongside GDPR and EU AI Act compliance but derives entirely from German employment law.

BSI: cybersecurity for AI systems

The Federal Office for Information Security (BSI) is Germany's national cybersecurity agency. BSI has issued AI-specific security guidance addressing adversarial robustness, model protection, and secure AI deployment in critical infrastructure. Critical infrastructure operators in Germany, energy, water, transport, financial infrastructure, must comply with BSI cybersecurity requirements that now explicitly address AI system security.

Austria and Switzerland: DACH neighbours

Austria, as an EU member state, is subject to the EU AI Act on the same timeline as Germany. Austria's AI Service Office at RTR-GmbH has operated as the country's central AI contact point since September 2024, but formal designation of its national market surveillance authorities remains pending, according to an April 2026 legal review. Austria's Financial Market Authority (FMA) has AI governance expectations aligned with BaFin's. Switzerland, outside the EU, is watching EU AI Act implementation closely and is developing its own AI regulatory approach under the National AI Strategy. Swiss financial institutions supervised by FINMA face AI governance expectations broadly aligned with EU approaches, and Swiss companies face EU AI Act obligations where they place AI on the EU market or their AI system output is used there.

Related reading

Further reading: BfDI