Since 29 July 2026, Germany has a named authority for artificial intelligence. It is the Bundesnetzagentur — the federal agency most companies already know from telecoms and energy — and it is now the market-surveillance authority, the national contact point and the complaints office for the European Union’s AI Regulation.
If you run AI inside your own company, what that changes is smaller and more specific than the headlines suggest. It is also more useful.
A note on terms first. The EU AI Regulation (often called the AI Act) is the European law governing artificial intelligence. Market surveillance is the enforcement function: the authority that can investigate a product, ask for documentation, and require changes. The German law that assigns those roles is the KI-Marktüberwachungs- und Innovationsförderungsgesetz — the AI market-surveillance and innovation-promotion act, mercifully shortened to KI-MIG.
What the law actually does
The KI-MIG does not create new obligations for AI systems. The obligations come from the EU Regulation, and they apply across the Union whether or not a member state has passed an implementing law. What the KI-MIG settles is the German institutional question: who supervises, who you contact, and where a complaint goes.
Its answer is the Bundesnetzagentur, in three capacities — market-surveillance authority, national point of contact, and complaints office.
The part almost every summary drops
The common framing is that the Bundesnetzagentur has taken over AI supervision in Germany. That is half of what the announcement says, and it is the half that travels.
The other half is in the same paragraph of the ministry’s own press release: the law “builds on the established competences of the existing market-surveillance authorities”, and — the clause worth reading twice — “companies keep their familiar contacts, including for questions about the AI Regulation.”
So this is not a transfer of supervision to a single new regulator. It is a coordination layer placed over an existing structure. If you are in a regulated sector, the authority you already answer to keeps its remit. The Bundesnetzagentur is the central door, the place a complaint lands, and the body that coordinates nationally.
That distinction matters because the two readings imply different work. “A new regulator is coming” suggests a relationship to build from scratch. “Coordination over existing competences” suggests something much less dramatic: knowing which door is which.
The support mandate nobody mentions
There is a second half of the Bundesnetzagentur’s new role that has been almost entirely absent from coverage, and for a mid-sized company it is arguably the more immediately useful part. The agency is mandated to actively support companies in using AI — not only to supervise them.
Two instruments carry that:
- A KI-Service Desk — a first point of contact for questions about the AI Regulation, reachable at bundesnetzagentur.de/ki. If you are trying to work out internally whether an application falls in scope at all, this is somewhere to put that question before you commission an opinion.
- Regulatory sandboxes — supervised environments for trialling new applications before you commit to them. For an organisation that wants to introduce an AI application but cannot yet judge its regulatory classification confidently, this is the more interesting of the two.
Supervision with a support function attached is rarer than it should be. It is worth knowing both exist.
What already applies, and what does not
This is where current coverage is doing real damage, so it is worth being precise.
Applying since 2 August 2026: the AI Regulation’s transparency chapter, Article 50. It reaches systems that interact directly with people, systems generating synthetic content, emotion recognition and biometric categorisation, and deepfakes or AI-generated text published to inform the public. It applies to providers and to deployers, it is not limited to high-risk systems, and open-source systems are not exempt from it. We covered what a compliant disclosure actually looks like in the Article 50 guidelines explainer. The Commission’s enforcement powers over general-purpose AI models activated the same day.
Not applying yet: the high-risk chapter. Several write-ups about the KI-MIG state that high-risk obligations applied from 2 August 2026. They did not. The Digital Omnibus — Regulation (EU) 2026/1744, in force since 27 July 2026 — fixed those duties at 2 December 2027 for stand-alone high-risk systems and 2 August 2028 for high-risk systems embedded in regulated products. Those are legislated dates, not conditional ones, and they are not expected to move again.
The confusion is understandable. 2 August 2026 was the original high-risk date before it moved, and a great deal of material written in 2025 still says so. But a plan built on the wrong date is a plan with sixteen months of phantom urgency in it — or sixteen months of runway you did not know you had. We set out the corrected timeline in EU AI Act readiness: what actually changed in 2026.
What to do about it this week
Nothing in the KI-MIG requires you to file anything or change a system. It is a map, not a duty. But three internal questions are worth answering while the subject is open:
- Which authority currently supervises us for product or sector compliance — and does anyone internally actually know the answer?
- Which of our AI uses, if any, involve a system that interacts directly with people or generates content shown to them? That is the transparency question, and it is live now rather than in 2027.
- Which date is our AI compliance plan built on? If any document in it says high-risk obligations start in August 2026, it needs correcting.
None of those needs a lawyer to start. All three are cheaper to answer now than in the week someone asks.
The honest summary
Germany’s supervisory picture for AI is now named, and it is less disruptive than the headlines imply. A familiar agency has taken on a coordinating role, existing authorities keep their competences, companies keep their contacts, and there is a service desk and a sandbox route for organisations that want to ask before they build.
The most valuable thing in the whole development may simply be this: if you have a question about the AI Regulation and no obvious person to ask, there is now an address.
Frequently asked questions
What is the KI-MIG?
It is Germany's national law implementing the supervisory side of the EU's AI Regulation — the KI-Marktüberwachungs- und Innovationsförderungsgesetz, or AI market-surveillance and innovation-promotion act. It came into force on 29 July 2026. It does not create new obligations for AI systems; the obligations come from the EU Regulation itself. What the KI-MIG does is answer the question of who supervises, who you contact, and where a complaint goes in Germany.
Does the Bundesnetzagentur now supervise all AI in Germany?
Not in the sense most coverage implies. The Bundesnetzagentur becomes the market-surveillance authority, the national contact point and the complaints office for the AI Regulation. But the federal digital ministry's announcement of the law is explicit that it builds on the established competences of the existing market-surveillance authorities, and that companies keep their familiar contacts. In practice: a central door and a coordinating function, with the sectoral authority you already deal with retaining its remit.
What is the KI-Service Desk?
A support offer run by the Bundesnetzagentur as a first point of contact for companies with questions about the AI Regulation, reachable via bundesnetzagentur.de/ki. It sits alongside a mandate to run regulatory sandboxes, information and advisory services. It is worth knowing about because it is a place to put an early scoping question without commissioning a legal opinion first.
Did the EU AI Act's high-risk rules start applying on 2 August 2026?
No, and this is the most common error in current coverage. The high-risk chapter was deferred by the Digital Omnibus — Regulation (EU) 2026/1744, in force since 27 July 2026 — to 2 December 2027 for stand-alone high-risk systems and 2 August 2028 for high-risk systems embedded in regulated products. Those are fixed legislated dates. What did apply on 2 August 2026 was the transparency chapter, Article 50, together with the Commission's enforcement powers over general-purpose AI models.
Does this change anything I have to do today?
The KI-MIG does not add obligations to your AI systems. What changes is the map: you now know which authority is the contact point, where a complaint about your system would land, and that there is a service desk and a sandbox route available. Whether any particular obligation under the AI Regulation applies to your deployment is a question for your own counsel.
Sources & further reading
- BMDS — Neues KI-Gesetz tritt in Kraft (press release 47/2026, 29 July 2026) — the primary announcement: entry into force, the Bundesnetzagentur's role, the service desk and sandboxes
- KI-MIG — statutory text (gesetze-im-internet.de) — the law itself
- Bundesnetzagentur — KI-Service Desk — the authority's own advisory offer for companies
- EUR-Lex — Regulation (EU) 2026/1744 (Digital Omnibus on AI) — the instrument that fixed the high-risk dates at 2 Dec 2027 and 2 Aug 2028