KI-MIG 2026: What Germany’s AI Law Means for Businesses
The KI-MIG transposes the EU AI Act into German law. Learn everything about obligations, sanctions, supervisory authorities, and a 10-step compliance checklist for your company.
On February 11, 2026, the German federal cabinet approved the KI-Massnahmen-und-Implementierungsgesetz (KI-MIG, AI Measures and Implementation Act). This transposes the EU AI Act into national law. For businesses, this means: the time for abstract discussion is over. Concrete obligations, severe sanctions, and clear deadlines are now in place. Those who fail to act now risk fines of up to 35 million euros or 7 percent of global annual revenue.
This article explains what the KI-MIG regulates, which authorities take on supervisory roles, what obligations SMEs face, and how you can prepare with a 10-step checklist.
What Is the KI-MIG?
The KI-MIG is the national implementing law for the EU AI Act (Regulation (EU) 2024/1689). While the EU regulation sets the European framework, the KI-MIG governs the concrete implementation in Germany. It defines, among other things:
- Which authorities are responsible for supervision
- How market surveillance is organized
- Which sanctions apply for violations
- How the AI competency requirement is implemented
- Which easements apply for SMEs
Timeline Overview
- Date · Milestone
- August 2024 · EU AI Act enters into force
- February 2025 · AI competency requirement applies (Art. 4 EU AI Act)
- February 2025 · Prohibited AI practices take effect
- February 2026 · Cabinet approval of KI-MIG
- August 2026 · High-risk obligations become effective
- August 2027 · Full applicability of all EU AI Act provisions
The time pressure is real: between the cabinet decision in February 2026 and the high-risk obligations taking effect in August 2026, there are only six months.
Which Authorities Take on Supervision?
The KI-MIG establishes a multi-tier supervisory structure. The central authority is the Federal Network Agency (BNetzA), which serves as the national AI supervisory authority. Its tasks include:
Federal Network Agency as AI Supervisory Authority
- Market surveillance: Monitoring of AI systems on the German market
- Conformity assessment: Verification of whether high-risk AI systems meet the requirements
- Complaint management: Point of contact for citizens and businesses
- Sandbox programs: Regulatory sandboxes for innovative AI applications
- Advisory services: Support particularly for SMEs in implementation
Other Involved Authorities
In addition to the Federal Network Agency, other authorities are involved depending on the area of application:
- Federal Office for Information Security (BSI): Cybersecurity aspects of AI systems
- Federal Data Protection Commissioner: Data protection aspects of AI
- Federal Institute for Occupational Safety and Health (BAuA): AI in the workplace
- Sector-specific supervisory authorities: e.g., BaFin for financial AI, medical device authorities for health AI
For businesses, this means: depending on industry and use case, multiple authorities may be responsible. Early clarification of responsibilities saves time and trouble.
Sanctions: Up to 35 Million Euros or 7 Percent of Annual Revenue
The sanction structure of the KI-MIG follows the EU AI Act and is structured in three tiers:
Tier 1: Prohibited AI Practices
Fine: Up to 35 million euros or 7 percent of global annual revenue (whichever is higher)
Prohibited practices include:
- Social scoring by public authorities
- Real-time remote biometric identification in public spaces (with exceptions)
- Manipulation through subliminal techniques
- Exploitation of vulnerabilities of specific groups of persons
- AI-based emotion recognition in the workplace and educational institutions
Tier 2: High-Risk Violations
Fine: Up to 15 million euros or 3 percent of annual revenue
This covers violations against:
- Requirements for high-risk AI systems (data quality, documentation, transparency)
- Conformity assessment procedures
- Reporting obligations for serious incidents
Tier 3: Other Violations
Fine: Up to 7.5 million euros or 1.5 percent of annual revenue
This covers:
- Violations against transparency obligations
- Insufficient AI competency of employees
- Inadequate labeling of AI-generated content
Special Provisions for SMEs
A proportionality clause applies for SMEs and start-ups: sanctions must be proportionate to the company size. This does not mean that SMEs do not have to pay fines. It means that the specific amount is adjusted to the economic capacity. This is no guarantee of lenient penalties.
High-Risk Obligations from August 2026
From August 2, 2026, providers and operators of high-risk AI systems must fulfill extensive obligations. High-risk AI systems are those deployed in critical areas.
What Are High-Risk AI Systems?
The EU AI Act defines two categories:
Category 1: AI systems integrated as safety components in regulated products (e.g., medical devices, machinery, elevators).
Category 2: AI systems in sensitive areas (Annex III of the EU AI Act):
- Biometric identification and categorization
- Critical infrastructure (energy, water, transport)
- Education and vocational training
- Employment and human resources management
- Access to public services
- Law enforcement
- Migration and border control
- Administration of justice and democratic processes
Obligations for Providers of High-Risk AI
- Risk management system: Establishment of a continuous risk management system over the entire lifecycle
- Data quality: Ensuring that training, validation, and test data are relevant, representative, and error-free
- Technical documentation: Comprehensive documentation enabling a conformity assessment
- Logging: Automatic recording of events during operation
- Transparency: Provision of information for operators
- Human oversight: Ensuring that humans can effectively monitor the system
- Robustness and security: Appropriate level of accuracy, robustness, and cybersecurity
- Conformity assessment: Proof of conformity before placing on the market
Obligations for Operators of High-Risk AI
Even those who only deploy (not develop) high-risk AI systems have obligations:
- Use in accordance with the intended purpose per instructions for use
- Ensuring human oversight
- Monitoring of operations and reporting of incidents
- Conducting a data protection impact assessment
- Retention of automatically generated logs
AI Competency Requirement Since February 2025
The AI competency requirement from Article 4 of the EU AI Act has been in effect since February 2, 2025. This obligates all companies that offer or deploy AI systems to ensure that their employees have sufficient AI competency.
What Does “Sufficient AI Competency” Mean?
The competency requirement is not abstract. It relates to the specific tasks of employees:
- Users: Must understand how the AI system works, what its limitations are, and how to evaluate results
- Executives: Must be able to assess the strategic implications of AI deployment
- IT staff: Must be able to implement the technical requirements for security, data protection, and documentation
- Data protection officers: Must be able to evaluate the data protection implications of AI
Documentation Obligation
Companies must be able to demonstrate that they have taken measures to ensure AI competency. This includes:
- Training certificates
- Documentation of training content
- Regular updating of training programs
According to an analysis by the KI-Trainingszentrum, as of February 2026—one year after the obligation took effect—only 23 percent of German companies have established documented AI training programs. There is an urgent need to catch up.
What SMEs Must Concretely Do Now
For small and medium-sized enterprises, the question is: what exactly must we do, and what can we ignore? The answer depends on how you deploy AI.
Scenario 1: You Use Standard AI Tools
If you use AI tools such as ChatGPT, Copilot, or image generators as a pure user, your obligations are manageable:
- Ensure AI competency of employees (mandatory since February 2025)
- Create internal usage guidelines
- Maintain transparency toward customers (e.g., label AI-generated content)
Scenario 2: You Integrate AI into Your Business Processes
If you build AI into your workflows, such as for proposal calculation, customer segmentation, or process automation:
- Additionally: maintain an AI inventory (what AI systems do you deploy where?)
- Conduct risk classification (General Purpose, Limited Risk, High Risk)
- Carry out a data protection impact assessment
- Review contracts with AI providers
Scenario 3: You Develop Your Own AI Solutions
If you develop and offer AI systems yourself:
- Full compliance with the EU AI Act, depending on the risk class
- Create technical documentation
- Conduct conformity assessment
- CE marking (for high-risk)
Checklist: 10 Steps to KI-MIG Compliance
Step 1: Create an AI Inventory
List all AI systems that you deploy or develop. Categorize them by area of use, provider, and risk class. Many companies are surprised how many AI systems are already in use—from automatic email sorting to the chatbot on the website.
Step 2: Conduct Risk Classification
Assign each AI system to a risk class: prohibited, high-risk, limited risk, or minimal risk. Use the definitions of the EU AI Act (Annexes I and III) as the basis.
Step 3: Exclude Prohibited Practices
Check whether any of your AI systems fall under prohibited practices. If so: shut down immediately. The risk is too high.
Step 4: Ensure AI Competency
Plan and document training measures for all employees who work with AI systems. Differentiate by roles (users, executives, IT).
Step 5: Create an Internal AI Policy
Create an internal AI policy that governs: Which AI tools may be used? What data may be entered into AI systems? Who approves new AI applications?
Step 6: Conduct a Data Protection Impact Assessment
For every AI system that processes personal data, a data protection impact assessment (DPIA) according to Art. 35 GDPR is required. The KI-MIG reinforces this requirement.
Step 7: Build Technical Documentation
Begin documenting your AI systems: data sources, training data, model architecture, deployment scenarios, known limitations. For high-risk systems, this becomes mandatory from August 2026.
Step 8: Review Provider Contracts
Review the contracts with your AI providers: Who is responsible for compliance? Where is data processed? Are there certifications? Ensure that the division of responsibilities is clearly defined.
Step 9: Establish Monitoring and Reporting Processes
Establish processes for ongoing monitoring of your AI systems and for reporting serious incidents to the responsible supervisory authority.
Step 10: Plan Regular Reviews
AI governance is not a one-time project but an ongoing process. Plan quarterly reviews to update your AI inventory, assess new risks, and adapt training measures.
Frequently Asked Questions
Does the KI-MIG also apply to sole proprietors and freelancers?
Yes. The KI-MIG applies to all providers and operators of AI systems, regardless of company size. However, the practical obligations are graduated: those who only use standard AI tools as users primarily need to fulfill the AI competency requirement and observe transparency obligations.
Do we now have to shut down all AI tools?
No. The KI-MIG only prohibits a narrowly defined list of AI practices (social scoring, manipulation, certain biometric applications). The vast majority of business AI applications remain permitted but must meet the respective requirements of their risk class.
Who controls compliance?
The Federal Network Agency as the national AI supervisory authority. It can conduct audits, request information, and impose sanctions for violations. Additionally, sector-specific authorities can become active.
How does the KI-MIG relate to the GDPR?
The KI-MIG supplements the GDPR. Where AI systems process personal data, both regulatory frameworks apply in parallel. The data protection impact assessment under GDPR remains unchanged. Companies must consider both compliance requirements in an integrated manner.
Are there subsidies for AI compliance?
Yes. Several German states offer funding programs for digitalization that also cover AI compliance measures. In Bavaria, for example, the Digitalbonus. Contact your local Chamber of Industry and Commerce (IHK) or the responsible state ministry for information.
References
- Cortina Consult: KI-MIG Gesetz—https://cortina-consult.com/ki-compliance/wissen/ki-mig-gesetz/
- Cortina Consult: AI Governance—https://cortina-consult.com/ki-compliance/wissen/ai-governance/
- KI-Trainingszentrum: EU AI Act Employee Training 2026—https://ki-trainingszentrum.com/eu-ai-act-mitarbeiter-schulungen-fuer-unternehmen-2026/
- Advisori: NIS2, AI, and AI Governance Obligation—https://www.advisori.de/blog/nis2-ki-ai-governance-pflicht
