01 AI Consulting 02 Software Development 03 About 04 Blog
DE EN
Arrange a call
← All posts

AI & Law

The Bundesnetzagentur Is Now Your AI Regulator — and the EUR 50,000 Is Not the Ceiling

On July 29, 2026, the KI-MIG entered into force: Germany’s Act on Market Surveillance and Innovation Promotion for Artificial Intelligence (Gesetz zur Marktüberwachung und Innovationsförderung von künstlicher Intelligenz), signed on July 22 and published in the Federal Law Gazette (BGBl. 2026 I No. 223). The Bundestag had adopted the government bill on June 11 in the version of the Digital Affairs Committee. Four days later came August 2 — the date half the compliance industry had prepared for all year.

More interesting than the entry into force is what preceded it. Until July 28, 2026, Germany had no statutorily designated AI market surveillance authority — even though Chapter VII of the AI Regulation (governance) and Chapter XII (penalties) have applied since August 2, 2025. The penalty layer is almost a year older than the authority that enforces it. Not a footnote: the delayed establishment of the national authorities is a reason the European legislator itself cites for postponing the high-risk regime.

At a glance

  • What applies: Since July 29, 2026, the Bundesnetzagentur (Federal Network Agency) is the central AI market surveillance authority (Section 2(1) KI-MIG); for regulated financial activity it is BaFin (the Federal Financial Supervisory Authority), and for regulated products the existing product authorities.
  • What follows: It is both contact point and complaints body. The AI Service Desk is already operating, with a free risk classification tool; Section 13 KI-MIG creates an SME-oriented regulatory sandbox.
  • The catch: The widely quoted EUR 50,000 in Section 15 KI-MIG is not the ceiling, only the national supplementary range. The large fines are in Art. 99 AI Regulation and have applied since August 2, 2025.

Who is competent now

The KI-MIG does not redistribute competence, it fixes it in statute for the first time — one central authority plus exceptions (Sections 2, 3):

CompetenceAuthorityProvision
Residual competence for the entire AI RegulationBundesnetzagenturSec. 2(1)
Products under Annex I Sec. A (machinery, medical devices, vehicles …)existing product market surveillance authoritiesSec. 2(2)
AI directly connected to regulated financial activityBaFinSec. 2(3)
Public bodies of the federal statesauthorities under state lawSec. 2(6)
Media service providersseparate routeSec. 2(8)
Data protectionno market surveillance competence of its ownSecs. 2, 13

The Bundesnetzagentur is competent, in the words of the statute, insofar as the act does not provide otherwise. For the mid-sized company using AI in HR, in customer contact or in administration: Bonn is the address. For credit institutions, payment and e-money institutions, investment firms and crypto-asset service providers it is BaFin — where the AI Regulation and the ICT risk regime under DORA converge at one authority.

One option was expressly not taken: in 2024, the German Data Protection Conference (Datenschutzkonferenz) had called for the data protection authorities to be given broad AI market surveillance powers. They remain involved — in the sandbox, for instance, for the assessment under Art. 59 AI Regulation — but conduct no market surveillance of their own. For you that means two lines of supervision with separate procedures and separate fines.

What the Bundesnetzagentur already offers

The most useful part of this news is not a legal act but an administrative service. Since July 29 the authority has been active in four roles: market surveillance (including AI in radio equipment and in HR, critical infrastructure and education), coordination and competence centre under Section 5 KI-MIG, central contact point for questions on the AI Regulation, and central complaints body.

Three things are immediately usable. The AI Service Desk is operating and provides a free online risk classification tool — a sensible starting point for self-assessment, not a substitute for careful review. Alongside it comes support for building AI literacy. And the AI regulatory sandbox under Section 13 KI-MIG is open for development, training, testing and validation, explicitly SME-oriented. The complaints body works both ways, though: competitors and consumers can now report infringements easily. That is the real difference from July 28 — not new obligations, but an addressee.

The EUR 50,000 is not the ceiling

This is where the advisory literature currently keeps getting it wrong: the new German AI act, one reads, provides for fines of “up to EUR 50,000”. That is indeed what Section 15(3) KI-MIG says — but it is not the answer to the question of what an infringement costs.

Section 15 KI-MIG creates national regulatory offences of its own, expressly for obligations that Art. 99(4) AI Regulation does not cover: Art. 21(1) and (2) (cooperation, access), Art. 27(1) to (3) (fundamental rights impact assessment), Art. 45(1) to (3) (information duties of notified bodies), and deployers of certain Annex III systems that fail to ensure the explanation under Art. 86(1) (Section 15(2)). Gap-filling, not an overall framework.

LayerLegal basisRangeApplies since
National supplementary offencesSec. 15 KI-MIGup to EUR 50,00029/07/2026
Prohibited practicesArt. 99(3) AI Reg.up to EUR 35m / 7 % turnover02/08/2025
Remaining infringementsArt. 99(4) AI Reg.up to EUR 15m / 3 % turnover02/08/2025

Section 16 KI-MIG states it expressly: for infringements under Art. 99(3) to (5) AI Regulation, the German Regulatory Offences Act (OWiG) applies only by analogy, and Section 17 OWiG as well as Section 30(1) and (2) OWiG are not applicable. The European ranges apply directly, not the lower one of German regulatory offences law. For SMEs and — since the Digital Omnibus — for small mid-caps, the lower of the two values applies. That is not an exemption.

One detail with practical effect: under Section 17(2) KI-MIG, no fines are imposed on authorities and public bodies — a public administration deploying AI is supervised, but faces no fine.

Three objections that belong here

First: part of Section 15 currently has nothing to bite on. The offences relating to the fundamental rights impact assessment (Art. 27) and the duty of explanation (Art. 86) attach to Chapter III obligations that only become applicable for Annex III systems on December 2, 2027. To that extent there is no sanctionable conduct today — anyone selling this provision as an acute risk is selling a deadline that has not started.

Second: one incident, two supervisors. If an AI system processes personal data and something goes wrong, two authorities with two legal bases and two fining regimes are involved. Whoever has to serve both in parallel needs clarified internal responsibilities beforehand and a data protection impact assessment that withstands this double view.

Third: we know nothing about enforcement. The launch press release contains no statement on fining or enforcement priorities, and an authority competent for a few days has no practice, no published interpretation, no case history. Forecasts about what the Bundesnetzagentur will tolerate are speculation.

Two nested rectangular frames of fine bone lines against deep ink: a small frame centered in a far larger one that nearly fills the field. Only the small frame carries a short vertical vermilion stroke on its lower edge; the outer stays unmarked.

The marked frame is the small one: the EUR 50,000 under Section 15 KI-MIG. The unmarked, far larger one has applied since August 2, 2025 — Art. 99 AI Regulation. Look only at the marked number and you measure the wrong one.

What this means for your company

Establish which authority is competent for you — before you need it. For most companies it is the Bundesnetzagentur, for financial services providers BaFin, for regulated products the authority that already supervises your product. Put that allocation in writing in your AI policy, together with who in the company answers an enquiry — a regulatory enquiry is the worst moment to start looking for internal responsibilities.

Use the contact point instead of avoiding it. The Bundesnetzagentur is designated by statute as the point of contact, not merely a sanctioning body. Its risk classification tool is a good first step without an assessment of your own — and a cheap cross-check if you have one.

Sort your deadlines by what applies today. Applicable are the transparency and penalty layers, not the high-risk regime. With your inventory of deployed systems, your baseline AI Act classification and your responsibilities settled, you are in good shape for the current state of the law. Everything else is preparation, not compliance.

Conclusion

The KI-MIG is unspectacular and important at once. Unspectacular because it creates hardly any new substantive obligations — those are in the AI Regulation and applied before. Important because it closes a gap that stood open for a year: there is now an authority that is competent, that you can ask, and that can ask you.

On fines I would answer soberly: the EUR 50,000 is the smaller part of the story, and the larger ranges have applied since August 2, 2025. What changed on July 29 is not the size of the risk but the existence of a body able to enforce it.

If you want to clarify which authority is competent for your AI deployment, let’s talk. I read provisions like these as a business lawyer and build the systems in question myself.

FAQ

Which authority is competent for the AI Act in Germany?

In principle the Bundesnetzagentur: Section 2(1) KI-MIG gives it residual competence for the entire AI Regulation. By way of exception, the existing product authorities remain competent for products under Annex I Section A; for AI directly connected to regulated financial activity it is BaFin (Section 2(3)), and for public bodies of the federal states, state law (Section 2(6)). The data protection authorities were not given market surveillance competence.

How high are the fines under the KI-MIG?

The frequently quoted EUR 50,000 in Section 15(3) KI-MIG is not the ceiling but the range for the national supplementary offences — for obligations Art. 99(4) of the AI Regulation does not cover. The large ranges come from Art. 99 AI Regulation: up to EUR 35 million or 7 percent of annual turnover for prohibited practices, up to EUR 15 million or 3 percent for the remaining infringements. Section 16 KI-MIG rules out the lower range of the German Regulatory Offences Act.

Where can I ask questions about the AI Regulation or report an infringement?

At the Bundesnetzagentur: it is the central contact point for questions on the AI Regulation and the central complaints body for infringements. Its AI Service Desk is already operating and provides a free online risk classification tool plus support for building AI literacy. For development, training, testing and validation there is additionally the AI regulatory sandbox under Section 13 KI-MIG, explicitly aimed at SMEs.

Is the act called KI-Durchführungsgesetz or KI-MIG?

KI-MIG is the official short name. The formal citation reads “KI-Marktüberwachungs-und-Innovationsförderungs-Gesetz vom 22. Juli 2026 (BGBl. 2026 I Nr. 223)”. “KI-Durchführungsgesetz” was the working title of the legislative project and still appears in commentary from July 2026. The short form KI-Marktüberwachungsgesetz is likewise wrong.


Sources — as of 08/08/2026

This article is general information, not legal advice for an individual case. As of August 8, 2026; supervisory practice under the KI-MIG is only just emerging, so please check the current position before making decisions.

Leon Lotz

Leon Lotz

Leon Lotz is a business lawyer and founder of MusketierSoftware. He combines legal depth with real software craft.

AI-assisted, editorially reviewed and under editorial responsibility. AI transparency