Written and maintained by CASRAI Editorial Board
Last updated
Last verified against primary sources: 25 September 2026. Regulation (EU) 2024/1689 — the EU AI Act — is a regulation, not a directive, so its substantive rules apply directly in every member state without national transposition. But a regulation of that size still leaves member states real work to do: naming the actual authorities that enforce it, building the complaint and sandbox mechanisms the text only requires in outline, and deciding how domestic penalties attach to EU-defined obligations. Germany’s answer is the KI-Marktüberwachungs- und Innovationsförderungsgesetz (KI-MIG) — in English, the Act on the Market Surveillance and Support of Innovation of Artificial Intelligence — which entered into force on 29 July 2026, per the Bundesnetzagentur’s own announcement of that date.
This page covers what KI-MIG actually adds on top of the Regulation’s own text: the concrete German contact point, the authority’s three distinct statutory roles, the complaints mechanism ordinary people can use, and the sandbox with priority access for SMEs, start-ups and research institutions. It does not re-explain the AI Act itself — see the EU AI Act high-risk compliance checklist for that — and it is written as a companion to CASRAI’s existing page on Italy’s Law 132/2025, the other member-state implementing statute already covered here. The two are worth reading together: they show two different national choices about how much of the AI Act’s institutional plumbing to consolidate versus distribute.
What KI-MIG actually is
KI-MIG’s formal citation is the Gesetz zur Durchführung der Verordnung (EU) 2024/1689 — literally, the “Act Implementing Regulation (EU) 2024/1689” — with KI-MIG as its short title. It is a federal statute, not a strategy paper or a ministry guidance document: it was passed through the ordinary legislative process and carries binding provisions with numbered penalties, not recommendations. The Bundesnetzagentur’s own press release states plainly that the Act “enters into force today,” dated 29 July 2026, which is the operative date for everything below. That timing sits inside the AI Act’s own staged rollout: the Regulation entered into force on 1 August 2024, and its provisions for general-purpose AI models and the governance/market-surveillance framework became applicable on 2 August 2025 and 2 August 2026 respectively — KI-MIG was built to be in place for that second milestone.
The law is organised around the institution it creates work for, rather than around the AI Act’s own article structure. Its early sections (Germany’s implementing legislation is cited by paragraph, “§”) name the Bundesnetzagentur and define its jurisdiction; later sections build the sandbox, the penalty regime, and a national registry. That shape is itself informative: unlike Italy, which spread its AI Act follow-up across a general enabling statute (Law 132/2025) and a later criminal-law-focused decree (D.Lgs. 160/2026), Germany chose to consolidate almost all of its AI Act institutional infrastructure — oversight, contact point, complaints, sandbox, and penalties — into one statute built around a single lead authority.
Bundesnetzagentur’s three statutory roles
The Bundesnetzagentur (Federal Network Agency, BNetzA) — already Germany’s regulator for telecoms, energy networks, post and rail — is KI-MIG’s central institutional choice. The statute gives it three separate, named roles rather than one general oversight mandate:
- Central market surveillance authority (§2 Abs. 1), with a dedicated AI market surveillance chamber established inside the agency (§4) to review contested enforcement decisions. Some sector carve-outs apply: media-provider oversight stays with the state (Länder) media authorities (§2 Abs. 8), oversight of AI in tax administration needs the Federal Finance Ministry’s consent (§2 Abs. 7), and an independent chamber has jurisdiction over the most sensitive high-risk categories (§2 Abs. 5).
- Single point of contact for the AI Act’s Article 70(2) requirement that every member state name one identifiable body for cross-border coordination with the European Commission, the AI Office and other member states’ authorities (§6). BNetzA also hosts a dedicated coordination and competence centre for this purpose (§5).
- Central complaints body implementing Article 85 of the AI Act, which gives any natural or legal person the right to lodge a complaint about a suspected AI Act infringement with a market surveillance authority (§8). KI-MIG requires this channel to be barrier-free and low-threshold: a complaint doesn’t have to be filed against the right authority to count — BNetzA is required to receive it centrally and forward it on to whichever authority actually has jurisdiction over that AI system or sector.
Folding single-point-of-contact and complaints-intake duties into the same body that already does market surveillance is the concrete, national-level choice worth noting for a compliance team: it means one German address handles a cross-border regulator query, a citizen complaint about a chatbot, and an on-the-ground inspection of a deployed high-risk system, rather than three separate agencies with three separate procedures.
The AI regulatory sandbox
§13 obliges Germany to stand up at least one AI regulatory sandbox (KI-Reallabor, literally “AI real-world laboratory”) — a controlled environment where a system can be developed, trained, tested and validated under regulatory supervision before full market launch. The AI Act itself (Articles 57–59) requires member states to have at least one sandbox operational by August 2026 and describes the general shape; KI-MIG is the instrument that actually commits Germany to running one and states who gets priority access to it.
That priority is explicit and three-part: small and medium-sized enterprises and start-ups get preferential access to develop and validate innovative AI systems in a controlled environment, and research institutions and universities get their own preferential-access track, distinct from the general SME provision. The Bundesnetzagentur’s press release frames the sandbox’s function as regulatory support — helping a participant “define individual requirements, identify risks and work out corrective measures” — rather than a blanket exemption from AI Act obligations; a sandbox participant is still building toward compliance, just with the regulator’s help while doing it rather than only its enforcement afterward.
Enforcement: a dedicated chamber, national fines and a registry
KI-MIG adds enforcement infrastructure the Regulation leaves to member states to build. §11 gives BNetzA inspection powers and, notably, limits the suspensory effect of an appeal against certain enforcement orders (Abs. 3, 7) — a contested order can generally still take effect while it is being appealed, rather than being paused by default. §15 creates national administrative-offence provisions (Ordnungswidrigkeiten) with fines of up to €50,000 for conduct that isn’t already captured by the AI Act’s own EU-wide penalty regime, and §16 applies Germany’s general administrative-offences law (OWiG) procedurally, with specified exclusions. §17 designates which German authorities are responsible for which enforcement actions and exempts public bodies from the fines. §19 builds in a review cycle — evaluations at 18 months and again at three years — so the statute is required to check its own working, not just its own passage. §20 creates a non-public registry of high-risk AI systems held at BNetzA, separate from the AI Act’s own EU database, giving the German authority its own internal record to inspect against.
None of this is required by the AI Act’s text in this specific form — the Regulation requires member states to have a penalty regime and sets caps for the most serious EU-defined infringements, but the domestic offence categories, the €50,000 ceiling for nationally-defined conduct, the appeal-suspension rule, and the non-public registry are all KI-MIG’s own additions.
How this compares to Italy’s approach
Italy and Germany both had to answer the same AI Act follow-up questions, and answered them differently in ways worth knowing if you operate in both markets. Italy split its response across two instruments over roughly a year — Law 132/2025 set out general principles, sectoral rules and delegated the government to legislate further, and the later D.Lgs. 160/2026 filled in police-AI biometrics rules, a new criminal offence for missing AI safety controls, and civil liability provisions — with enforcement distributed across multiple existing sectoral regulators rather than concentrated in one. Germany moved in a single statute and concentrated almost the entire institutional apparatus — market surveillance, single point of contact, complaints intake, sandbox, and the bulk of the penalty regime — inside one existing agency. Neither approach changes what the AI Act itself requires of an AI provider or deployer; both change who in that member state you actually contact, complain to, or get inspected by.
What this means for a compliance team
If your organisation places an AI system on the German market, or deploys one there, KI-MIG is the reason a German regulatory question now has one concrete, named answer: the Bundesnetzagentur, for market surveillance, cross-border coordination, and complaints intake alike (with the narrow sectoral carve-outs above). If you are an SME, start-up, or a university or research institution developing an AI system with unresolved compliance questions, KI-MIG’s sandbox is the mechanism built specifically to give you regulator engagement before enforcement rather than only after it, and it names your organisation type as a priority group for access. And if your organisation is already tracking AI Act compliance at the EU level, KI-MIG’s national administrative-offence provisions and its own non-public registry are worth flagging to counsel separately — they sit alongside, not inside, the AI Act’s own EU-wide penalty and database framework.
Is KI-MIG in force now, or still a draft?
In force. The Bundesnetzagentur’s own announcement states the Act “enters into force today,” dated 29 July 2026. Some legal-tracker commentary published earlier in 2026, before that date, still describes it as pending — check the publication date on any secondary source before relying on it.
Does KI-MIG replace the EU AI Act for Germany?
No. The Regulation applies directly and in full; KI-MIG only builds the national institutional layer the Regulation requires member states to build — naming authorities, setting up the sandbox and complaints channel, and adding nationally-defined penalties and a registry. An AI provider’s substantive obligations (risk classification, conformity assessment, transparency duties, and so on) still come from the Regulation itself.
Who enforces KI-MIG against a specific AI system?
The Bundesnetzagentur, as central market surveillance authority, for most cases — subject to the sectoral carve-outs in §2: state media authorities retain jurisdiction over media providers, the Federal Finance Ministry must consent to action against AI used in tax administration, and a separate independent chamber handles the most sensitive high-risk categories.
Can a start-up outside Germany use the sandbox?
KI-MIG’s own text, as covered by the sources reviewed for this page, frames the priority-access groups as SMEs, start-ups, research institutions and universities without stating a nationality or establishment requirement in those terms. Confirm current eligibility criteria directly with the Bundesnetzagentur before assuming access, since sandbox admission procedures are exactly the kind of operational detail that gets set by administrative rule after a framework statute like this one.
Primary sources
- Bundesnetzagentur, press release, “German Act on the market surveillance and support of innovation of artificial intelligence (KI-MIG) enters into force,” 29 July 2026.
- Regulation (EU) 2024/1689 (the EU AI Act), articles 57–59 (regulatory sandboxes), 70 (single point of contact), 85 (right to lodge a complaint).
- Ferner Alsdorf, “Deutschland bekömmt ein KI-Gesetz: Bündelung der nationalen KI-Aufsicht bei der Bundesnetzagentur,” section-by-section summary of KI-MIG (§§1–20).
- activemind.legal, KI-MIG guide — useful background on the AI Act’s own authority-designation deadlines; last updated 26 May 2026, before KI-MIG’s 29 July 2026 entry into force, so treat its in-force-date commentary as superseded by the Bundesnetzagentur announcement above.
Related reading
- EU AI Act Article 70: France, Germany, Spain, and Ireland Compared
- Italy’s Law 132/2025: a national AI statute inside the EU AI Act — the closest parallel already on CASRAI, and a contrasting institutional model.
- Italy’s D.Lgs. 160/2026: police AI, biometrics and AI liability — Italy’s second-stage implementing decree.
- EU AI Act high-risk system compliance checklist — the substantive obligations KI-MIG’s institutions enforce.
- AI regulations around the world: a jurisdiction map — where Germany sits in the wider picture.
- Frontier AI law: 10 jurisdictions compared — how national implementation layers differ across jurisdictions.








