KI-MIG: What Germany’s AI law means for businesses
The KI-MIG implements the EU AI Act in Germany and has been in force since July 29, 2026: supervision, penalties, deadlines, and a 10-step checklist for your company.
By SIMO GmbH
On February 11, 2026, the German federal cabinet approved the draft, and on July 22, 2026, the law was signed: the KI-Marktüberwachungs-und-Innovationsförderungs-Gesetz (KI-MIG, AI Market Surveillance and Innovation Promotion Act), promulgated in the Federal Law Gazette 2026 I No. 223 and in force since July 29, 2026. It implements the EU AI Act in Germany; the regulation itself applies directly. For businesses, this means responsibilities, penalties, and deadlines are now settled. Violations involving prohibited practices can lead to fines of up to €35 million or 7 percent of global annual revenue (as of October 2026 · not legal advice).
This article explains what the KI-MIG regulates, which authorities take on supervisory roles, what obligations midsize companies face, and how you can prepare with a 10-step checklist.
What is the KI-MIG?
The KI-MIG is the national implementing act for the EU AI Act (Regulation (EU) 2024/1689). The EU regulation sets the obligations; the KI-MIG determines who supervises them in Germany and how violations are penalized. Among other things, it covers:
- Which authorities are responsible for supervision
- How market surveillance is organized
- Which sanctions apply for violations
- How the AI literacy rule is implemented
- Which easements apply for midsize companies
Timeline overview
- Date: August 2024 | Milestone: EU AI Act enters into force
- Date: February 2025 | Milestone: AI literacy rule applies (Art. 4 EU AI Act)
- Date: February 2025 | Milestone: Prohibited AI practices take effect
- Date: July 2026 | Milestone: KI-MIG promulgated (Federal Law Gazette 2026 I No. 223), in force since July 29, 2026
- Date: December 2027 | Milestone: High-risk obligations under Annex III take effect (Regulation (EU) 2026/1744)
- Date: August 2028 | Milestone: High-risk obligations under Annex I take effect
The schedule is tight: about 16 months separate the KI-MIG’s entry into force in July 2026 from the high-risk obligations under Annex III taking effect in December 2027.
Which authorities take on supervision?
The KI-MIG sets up a multi-tier supervisory structure. The central market surveillance authority is the Federal Network Agency (BNetzA), unless the act provides otherwise (Section 2(1) KI-MIG). Its tasks include:
Federal Network Agency as AI supervisory authority
- Market surveillance: Monitoring of AI systems on the German market
- Conformity assessment: Verification of whether high-risk AI systems meet the requirements
- Complaint management: Point of contact for citizens and businesses
- Sandbox programs: Regulatory sandboxes for innovative AI applications
- Advisory services: Support particularly for midsize companies in implementation
Other involved authorities
In addition to the Federal Network Agency, other authorities are involved depending on the area of application:
- Federal Office for Information Security (BSI): Cybersecurity aspects of AI systems
- Federal Data Protection Commissioner: Data protection aspects of AI
- Federal Institute for Occupational Safety and Health (BAuA): AI in the workplace
- Sector-specific supervisory authorities: e.g., BaFin for financial AI, medical device authorities for health AI
For businesses, this means: depending on industry and use case, multiple authorities may be responsible. Early clarification of responsibilities saves time and trouble.
Sanctions: up to €35 million or 7 percent of annual revenue
The sanction structure of the KI-MIG follows the EU AI Act and is structured in three tiers:
Tier 1: prohibited AI practices
Fine: up to €35 million or 7 percent of global annual revenue, whichever is higher
Prohibited practices include:
- Social scoring by public authorities
- Real-time remote biometric identification in public spaces (with exceptions)
- Manipulation through subliminal techniques
- Exploitation of vulnerabilities of specific groups of persons
- AI-based emotion recognition in the workplace and educational institutions
Tier 2: high-risk violations
Fine: up to €15 million or 3 percent of global annual revenue, whichever is higher
This covers violations of:
- Requirements for high-risk AI systems (data quality, documentation, conformity assessment)
- Transparency obligations under Article 50, including the labeling of AI-generated content
- Reporting obligations for serious incidents
Tier 3: incorrect information
Fine: up to €7.5 million or 1 percent of global annual revenue, whichever is higher
This covers:
- Supplying incorrect, incomplete, or misleading information to notified bodies or national authorities in reply to a request
- Article 4 on AI literacy carries no separate fine (as of October 2026 · not legal advice)
- For SMEs and start-ups, the lower of the two amounts applies in each tier (Article 99(6))
Special provisions for midsize companies
A proportionality clause applies for midsize companies and start-ups: sanctions must be proportionate to the company size. This does not mean that midsize companies do not have to pay fines. It means that the specific amount is adjusted to the economic capacity. This is no guarantee of lenient penalties.
High-risk obligations from December 2027
Under Regulation (EU) 2026/1744, providers and deployers of high-risk AI systems under Annex III must meet extensive obligations from December 2, 2027, and from August 2, 2028 for systems under Annex I (as of October 2026 · not legal advice). High-risk AI systems are those used in critical areas.
What are high-risk AI systems?
The EU AI Act defines two categories:
Category 1: AI systems integrated as safety components in regulated products (e.g., medical devices, machinery, elevators).
Category 2: AI systems in sensitive areas (Annex III of the EU AI Act):
- Biometric identification and categorization
- Critical infrastructure (energy, water, transport)
- Education and vocational training
- Employment and human resources management
- Access to public services
- Law enforcement
- Migration and border control
- Administration of justice and democratic processes
Obligations for providers of high-risk AI
- Risk management system: Establishment of a continuous risk management system over the entire lifecycle
- Data quality: Ensuring that training, validation, and test data are relevant, representative, and error-free
- Technical documentation: Comprehensive documentation enabling a conformity assessment
- Logging: Automatic recording of events during operation
- Transparency: Provision of information for operators
- Human oversight: Ensuring that humans can effectively monitor the system
- Robustness and security: Appropriate level of accuracy, robustness, and cybersecurity
- Conformity assessment: Proof of conformity before placing on the market
Obligations for operators of high-risk AI
Even those who only deploy (not develop) high-risk AI systems have obligations:
- Use in accordance with the intended purpose per instructions for use
- Ensuring human oversight
- Monitoring of operations and reporting of incidents
- Conducting a data protection impact assessment
- Retention of automatically generated logs
AI competency requirement since February 2025
Article 4 of the EU AI Act on AI literacy has applied since February 2, 2025. As amended by Regulation (EU) 2026/1744, it requires companies that provide or deploy AI systems to take measures that support their staff’s AI literacy. It no longer prescribes a specific level of literacy.
What does AI literacy include?
The competency requirement is not abstract. It relates to the specific tasks of employees:
- Users: Must understand how the AI system works, what its limitations are, and how to evaluate results
- Executives: Must be able to assess the strategic implications of AI deployment
- IT staff: Must be able to implement the technical requirements for security, data protection, and documentation
- Data protection officers: Must be able to evaluate the data protection implications of AI
Documentation obligation
Companies should be able to show which AI literacy measures they have taken. These include:
- Training certificates
- Documentation of training content
- Regular updating of training programs
According to an analysis by the KI-Trainingszentrum, as of February 2026—one year after the obligation took effect—only 23 percent of German companies have established documented AI training programs. There is an urgent need to catch up.
What midsize companies must concretely do now
For small and midsize companies, the question is: what exactly must we do, and what can we ignore? The answer depends on how you deploy AI.
Scenario 1: you use standard AI tools
If you use AI tools such as ChatGPT, Copilot, or image generators as a pure user, your obligations are manageable:
- Take measures for employees’ AI literacy (Article 4, since February 2025)
- Create internal usage guidelines
- Maintain transparency toward customers (e.g., label AI-generated content)
Scenario 2: you integrate AI into your business processes
If you build AI into your workflows, such as for proposal calculation, customer segmentation, or process automation:
- Additionally: maintain an AI inventory (what AI systems do you deploy where?)
- Conduct risk classification (General Purpose, Limited Risk, High Risk)
- Carry out a data protection impact assessment
- Review contracts with AI providers
Scenario 3: you develop your own AI solutions
If you develop and offer AI systems yourself:
- Full compliance with the EU AI Act, depending on the risk class
- Create technical documentation
- Conduct conformity assessment
- CE marking (for high-risk)
Checklist: 10 steps to KI-MIG compliance
Step 1: create an AI inventory
List all AI systems that you deploy or develop. Categorize them by area of use, provider, and risk class. Many companies are surprised how many AI systems are already in use—from automatic email sorting to the chatbot on the website.
Step 2: conduct risk classification
Assign each AI system to a risk class: prohibited, high-risk, limited risk, or minimal risk. Use the definitions of the EU AI Act (Annexes I and III) as the basis.
Step 3: exclude prohibited practices
Check whether any of your AI systems fall under prohibited practices. If so: shut down immediately. The risk is too high.
Step 4: ensure AI competency
Plan and document training measures for all employees who work with AI systems. Differentiate by roles (users, executives, IT).
Step 5: create an internal AI policy
Create an internal AI policy that governs: Which AI tools may be used? What data may be entered into AI systems? Who approves new AI applications?
Step 6: conduct a data protection impact assessment
For AI systems that process personal data and are likely to pose a high risk, a data protection impact assessment (DPIA) under Art. 35 GDPR is required. Deployers of high-risk AI systems use the information that the provider must supply under the EU AI Act.
Step 7: build technical documentation
Start documenting your AI systems: data sources, training data, model architecture, use cases, and known limitations. For high-risk systems, this becomes mandatory from December 2, 2027.
Step 8: review provider contracts
Review the contracts with your AI providers: Who is responsible for compliance? Where is data processed? Are there certifications? Ensure that the division of responsibilities is clearly defined.
Step 9: establish monitoring and reporting processes
Establish processes for ongoing monitoring of your AI systems and for reporting serious incidents to the responsible supervisory authority.
Step 10: plan regular reviews
AI governance is not a one-time project but an ongoing process. Plan quarterly reviews to update your AI inventory, assess new risks, and adapt training measures.
Frequently asked questions
Does the KI-MIG also apply to sole proprietors and freelancers?
Yes. The obligations under the EU AI Act apply to all providers and deployers of AI systems, regardless of company size; the KI-MIG governs their supervision. The practical obligations are graduated: companies that only use standard AI tools mainly need to take AI literacy measures and observe the transparency obligations.
Do we now have to shut down all AI tools?
No. The EU AI Act prohibits only a narrowly defined list of AI practices (social scoring, manipulation, certain biometric applications). Most business AI applications remain permitted but must meet the requirements of their risk class.
Who controls compliance?
The Federal Network Agency as the national AI supervisory authority. It can conduct audits, request information, and impose sanctions for violations. Additionally, sector-specific authorities can become active.
How does the KI-MIG relate to the GDPR?
The KI-MIG and the EU AI Act supplement the GDPR. Where AI systems process personal data, both frameworks apply in parallel. The data protection impact assessment under the GDPR remains in place. Companies should consider both sets of requirements together.
Are there subsidies for AI compliance?
Yes. Several German states offer funding programs for digitalization that also cover AI compliance measures. In Bavaria, for example, the Digitalbonus. Contact your local Chamber of Industry and Commerce (IHK) or the responsible state ministry for information.
References
- Cortina Consult: KI-MIG Gesetz [in German]. https://cortina-consult.com/ki-compliance/wissen/ki-mig-gesetz/
- Cortina Consult: AI Governance. https://cortina-consult.com/ki-compliance/wissen/ai-governance/
- KI-Trainingszentrum: EU AI Act Mitarbeiterschulungen 2026 [in German]. https://ki-trainingszentrum.com/eu-ai-act-mitarbeiter-schulungen-fuer-unternehmen-2026/
- Advisori: NIS2, KI und AI Governance-Pflicht [in German]. https://www.advisori.de/blog/nis2-ki-ai-governance-pflicht
How our articles are created and who is accountable for them is set out in our editorial standards.
