KI-MIG and Bundesnetzagentur: What the AI Authority Audits from August 2026
The Act on Market Surveillance and Innovation Promotion of Artificial Intelligence (KI-MIG) entered into force on July 29, 2026, designating the Bundesnetzagentur as the central AI market surveillance authority in Germany. Companies operating AI systems face fines of up to 15 million euros or 3 percent of their global annual turnover for violations of the EU AI Act. The law does not require a prior warning. Active audits by the authorities will begin in August 2026, making the immediate technical proof of human oversight and risk management in production systems mandatory.
The Role Assigned to the Bundesnetzagentur by the KI-MIG
The Bundesnetzagentur acts as the central contact and complaints office for AI systems and hosts the new Coordination and Competence Center for the AI Regulation (KoKIVO). Germany missed the EU deadline for designating competent authorities, which expired on August 2, 2025, and is the last major EU member state to complete its national implementation. The Federal Cabinet passed the draft law on February 11, 2026—although some publications incorrectly cite February 10. Following its passage by the Bundestag on June 11, 2026, and the Bundesrat's waiver of the mediation committee on July 10, 2026, the law took effect one day after its promulgation. The frequently circulated term "KI-Marktdurchführungsgesetz" is a misnomer; the official title is the Act on Market Surveillance and Innovation Promotion of Artificial Intelligence.
Why Sectoral Supervision Divides the Responsibilities
The authority to levy fines generally lies with the respective competent supervisory authority, not exclusively with the Bundesnetzagentur. The KI-MIG establishes a shared authority structure. While the Bundesnetzagentur handles all cases that cannot be assigned to a specific sectoral jurisdiction, specialized authorities intervene in regulated markets. The Federal Financial Supervisory Authority (BaFin) imposes fines in the financial sector, the Federal Institute for Drugs and Medical Devices (BfArM) is responsible for medical devices, and data protection authorities penalize data privacy violations.
A special rule applies to federal financial authorities: If the Bundesnetzagentur suspects a violation of Regulation (EU) 2024/1689 here, it may only exercise its enforcement powers in agreement with the Federal Ministry of Finance. If no agreement is reached, the responsibility for market surveillance in this specific case transfers to the Ministry of Finance. For AI systems in state administration, surveillance is the responsibility of the authorities designated under state law, who can appoint unified contacts for the KoKIVO.
How Sanctions and Fines are Regulated in the KI-MIG
The law stipulates fines of up to 15 million euros or 3 percent of global annual turnover for violations of the AI Regulation, whichever is higher. Since the law does not mandate a warning before a fine is issued, operators must be ready for audits starting in August 2026. In practice, the burden of proof lies with the company: Anyone who cannot immediately respond to an authority's request with complete procedural documentation and proof of risk classification is at risk. Retroactively creating logs or implementing approval processes does not protect against sanctions for operations conducted up to that point.
How to Technically Prove Human Oversight
The legally compliant operation of AI systems requires a technical governance layer that proves transparency and human oversight in every system decision. Governance is not an afterthought that exists only on paper; it must be built into every tool. The EU AI Act's requirements for risk classes and transparency are technically mapped via fixed approval stages (L0 to L4). This means a system does not act blindly but possesses tiered autonomy. In a content and communication engine, for example, approvals are strictly based on risk; the system learns from the acceptance rate of human controllers and live performance.
A central principle for auditability is the "Approval-First" approach. In an analysis center that aggregates data from marketplaces, shops, and ERP systems, the AI generates concrete recommendations for prices, reorders, or campaigns—always with a justification. Nothing fires without human approval. Every action remains traceable via an audit trail. An integrated drift detector automatically reports when parameters shift. This seamless traceability is exactly what the Bundesnetzagentur or sectoral authorities will demand during an audit.
What Companies Must Ensure for GoBD and Data Compliance
Data sovereignty and traceability back to the source are the cornerstones for avoiding fines and meeting the requirements of supervisory authorities. Sensitive data must remain within a defined framework, which requires the use of models via EU endpoints (such as Vertex AI or Azure). When a document and accounting system reads receipts via OCR and AI vision and generates booking proposals, an orchestrator decides in three stages: automatically, for review, or manually. Nothing is blindly waved through. Every metric, whether in liquidity calculation or business monitoring, must be traceable back to the source—from the source field to the mapping and the formula. The system must be auditable rather than operating as a black box. Receipt processing is GoBD-compliant with procedural documentation and is audit-proof up to the export. Only when answers with source references, feedback loops, and double-checks are technically enforced will the system withstand an audit by the market surveillance authorities.
Researched and drafted with AI assistance, reviewed and approved before publication by Martin Reichle. More
Frequently asked
Wann tritt das KI-MIG in Kraft und ab wann wird geprüft?
Das Gesetz zur Marktüberwachung und Innovationsförderung von künstlicher Intelligenz (KI-MIG) ist am 29. Juli 2026 in Kraft getreten. Die aktiven Prüfungen durch die Behörden beginnen im August 2026.
Welche Behörde ist in Deutschland für die KI-Aufsicht zuständig?
Die zentrale Marktüberwachung übernimmt die Bundesnetzagentur. Für spezifische Sektoren bleiben jedoch Fachbehörden wie die BaFin (Finanzen) oder das BfArM (Medizinprodukte) zuständig.
Wie hoch sind die Bußgelder bei Verstößen gegen das KI-MIG?
Das Gesetz sieht Sanktionen von bis zu 15 Millionen Euro oder 3 Prozent des weltweiten Jahresumsatzes vor. Eine vorherige Verwarnung durch die Behörden ist nicht gesetzlich vorgeschrieben.
Wie weisen Unternehmen die geforderte menschliche Aufsicht nach?
Der Nachweis erfolgt über eine technische Governance-Schicht im KI-System, die Freigabestufen (L0 bis L4) dokumentiert. Jede KI-Entscheidung muss nachvollziehbar bleiben und bei kritischen Prozessen zwingend eine menschliche Freigabe erfordern.