Skip to content
Friendly disclaimer: flozi00 TechHub is a solo side-project next to a full-time job — personal learning notes, no official statements. Verify critical steps yourself.

Germany's KI-MIG Handed the AI Act to the Bundesnetzagentur — Here Is What Your Audit File Needs Before It Asks

KI-MIG (BGBl. 2026 I Nr. 223, in force 29 July 2026) makes the Bundesnetzagentur Germany's AI Act market surveillance authority with sectoral carve-outs for BaFin, product law and the Länder. The delegation chain from Art. 70(1), BNetzA's powers under § 11, the reported September 2026 inspection wave, an article-to-artifact audit-file checklist for self-hosters, and the timeline math: 15 calendar months to 2 December 2027.

11 min readflozi00
aicomplianceai-actenforcementregulation

On 29 July 2026 — two days into the Digital Omnibus era and four days before the AI Act's general application date — Germany's KI-MIG entered into force.1 Its opening sentence is administrative and easy to skim past: the law "serves the implementation of Regulation (EU) 2024/1689" and designates the competent authorities under Article 70(1) of that regulation. That is the whole game. Article 70(1) of the AI Act obliges every member state to designate market surveillance authorities; Germany answered with a single named regulator and a list of carve-outs.2 If you run open-weights models on your own hardware in Germany, this law decides who can knock on your door, what they can demand when they do, and which document they will ask for first.

This is not legal news — the law was in force before the summer recess. It is the operational read: the delegation chain with section numbers, the enforcement powers and their start dates, the inspection wave reported for September 2026, the audit-file checklist a self-hoster can build from, and the honest month count to the deferred Annex III deadline.

1. The delegation chain: Article 70(1) plus ten sections

The chain is short and legible:

  1. AI Act Art. 70(1) — each member state designates the market surveillance authority (or authorities) for the AI Act, entrusting them with the powers under Regulation (EU) 2019/1020 and Article 74.3
  2. KI-MIG § 1 — the law implements Regulation (EU) 2024/1689 and regulates, "ergänzend" (in addition), the competent authorities under Art. 70(1)(1), innovation measures, and fines under Art. 99(1)(1).1
  3. KI-MIG § 2(1) — the Bundesnetzagentur is the market surveillance authority for compliance with the AI Act, "soweit in diesem Gesetz nichts anderes bestimmt ist" — unless another section says otherwise.4
  4. Sections 2(2)–(8) then say otherwise, sector by sector. The BNetzA is the default, not the monopolist:4
Domain carved outAuthorityKI-MIG anchor
Everything else (including employment, critical infrastructure, education)Bundesnetzagentur§ 2(1) — default rule
Annex I Section A regulated products (machinery, radio equipment etc.)Existing product-law market surveillance authorities§ 2(2)
Regulated financial activity (25 enumerated institution classes: banks, payment/e-money, securities, insurers...)BaFin§ 2(3)–(4)
Law-enforcement, border-management and justice high-risk AI (Annex III 1) and Annex III 6–8Independent AI Market Surveillance Chamber at the BNetzA§ 2(5), § 4
Federal public bodies' AI systemsBundesnetzagentur (default under § 2(1)); federal tax administration only with Finance Ministry consent (§ 2(7))§ 2(1), § 2(7)
Länder (state) public bodies deploying AIState-level authorities under Landesrecht§ 2(6)
Federal tax administration AIBNetzA only "im Einvernehmen" with the Finance Ministry§ 2(7)
Media services for journalism/advertisingState media authorities; Deutsche Welle under its own law§ 2(8)

Two structural facts follow. First, "BNetzA for everything" was never the design; the law's own press framing calls it a hybrid approach — oversight by the authority with subject-matter proximity, BNetzA for previously unregulated product areas, and Bundesländer may delegate their supervision to BNetzA through Organleihe.5 Second, for a private self-hoster none of the carve-outs matter except one: if your deployment sits in a regulated financial institution, your counterpart is BaFin; otherwise it is the BNetzA — including for personnel management, critical infrastructure and education systems, where BNetzA also polices Article 50 transparency duties and Article 5 prohibited practices.5

2. The powers: § 11 gives the BNetzA the 2019/1020 toolkit

Section 11(1) grants the market surveillance authorities the powers under Article 14(4) and (5) and Article 16 of Regulation (EU) 2019/1020 (the Market Surveillance Regulation) plus those of the AI Act itself, without prejudice to powers from other law.6 Article 14(4) of 2019/1020 is the standard enforcement catalogue — demand information "necessary for their tasks", require documentation (technical, test, risk or other), sample products, and — with authorisation — enter premises and inspect. Section 11(2) adds operator specifics: authorities can call in third parties as technical Verwaltungshelfer and can exercise the Article 14(4)(d) and (j) powers via APIs or other technical means enabling remote access. Under § 11(7), appeals against BaFin (§ 2(3)) measures — including threats and imposition of coercive means — have no suspensive effect; for product-law authority (§ 2(2)) decisions this holds only where radio-equipment (§ 36(1) Funkanlagengesetz) or medical-device (§ 45(5) MPDG) law applies. Either way: the measure stands during your appeal.6

Since when? The KI-MIG entered into force 29 July 2026; the AI Act's general frame and — with it — the market-surveillance and AI Office enforcement machinery apply from 2 August 2026.13 Fine exposure for AI Act breaches is codified nationally: KI-MIG § 17 makes the § 2 authorities the administrative fine authorities — "Verwaltungsbehörden" under § 36 OWiG — for their remits, including AI Act Art. 99(3)–(5); public bodies are exempt from fines (§ 17(2)).7 The AI Act penalty tiers stand at EUR 35,000,000 or 7% of worldwide turnover for Art. 5 breaches and EUR 15,000,000 or 3% for the next tier down.3 Misleading an authority itself is a finable act.

One local analogue will not save you: § 2(7) means the BNetzA needs the Finance Ministry's consent to go after federal tax AI — the consent mechanics do not extend anywhere near the private sector.

3. September 2026: the reported inspection wave

Reported coverage — treated here as reported, because no consolidated official docket was located on Commission or BNetzA pages as of this writing — attributes one detail to the official record: on 10 September 2026, the EU AI Office confirmed that automated résumé-screening and HR decision-making tools are included in the first wave of inspections, coordinated with national market surveillance authorities. The same coverage names algorithmic credit assessment and AI healthcare triage, and lists CNIL, BfDI and AESIA as leading the national requests; the BFDI-Länder carve-out for state bodies makes the BNetzA-BaFin-BfDI triangle Germany's version of the split.8

What is primary, not reported: the enforcement powers activated on 2 August 2026, the KI-MIG authority map, and the fact that a German authority holding § 11 powers can serve an information request today. The wave's composition is reported. Assume the categories (hiring, credit) and treat the individual names as unconfirmed.

The category choice shows the same deferred-and-live logic: résumé screening and creditworthiness are Annex III 4(a) and 5(b) high-risk categories whose Chapter III duties were deferred — but Art. 50 transparency, Art. 5 prohibitions and the information powers of Chapter IX apply now, and those are what a first-wave letter reads.

4. The self-hosters' audit file: from article to artifact

Assume the BNetzA's letter arrives under § 11 + Art. 14(4) 2019/1020. Organize the audit file so that each demand maps to a document you can produce. Note that the Chapter III artifacts are not yet enforceable (deferred) — but building them in 2026 is cheaper than in 2027, and the classification trail is testable today via Art. 6(3) — the no-significant-risk derogation.

AI Act anchorArtifact you produceLive already?Deferred until
Art. 11 — technical documentationSystem dossier covering Annex IV content: general description, design data, data governance, evaluation results, reference to standards or CPSsProvider duty2 Dec 2027 (Annex III)
Art. 12 — record-keeping, logsAuto-recording of events over the system lifetime (Art. 12(1)–(2)); for Annex III point 1(a) systems (remote biometrics): per-use timestamps, reference databases, matched inputs and verifier identification (Art. 12(3)); deployers keep logs ≥ 6 months (Art. 26(6))Provider duty2 Dec 2027
Art. 13(3) — transparency and info for deployersInstructions for use: intended purpose and conditions of use, accuracy metrics (Art. 15), performance characteristics and limitations, human-oversight measures (Art. 14)Provider duty2 Dec 2027
Art. 26 — deployer obligationsRecords: you use the system per the instructions, assign human oversight under Art. 14, inform workers' representatives before first use in the workplace (Art. 26(7)), retain logs, notify on risksDeployer duties per Art. 26, time-sliced by the deferral; the public-body register duty under KI-MIG § 20(3) applies as writtenMajority deferred to 2 Dec 2027 per Art. 1(40)(b) of Regulation (EU) 2026/1744 (Ch. III timing)
Art. 50(1) — first-interaction disclosureChatbot/assistant disclosure text at first contact with natural personsLive since 2 Aug 2026—
Art. 50(4) — deepfake/synthetic disclosureIn-artifact machine-readable disclosure for synthetic content you publishLive—
Art. 5 — prohibited practicesA signed-off one-pager per use case: screened against the ban list, incl. new NCII/CSAM bans from 2 Dec 2026Live since 2 Feb 2025—
Art. 4 — AI literacyTraining records and internal materials evidencing literacy-support measures for staff and persons operating AI on your behalf (Art. 4(1)); no specific level or certification is prescribedLive—
Art. 6 — classificationUse-case register with Annex III mapping incl. the Art. 6(3) no-significant-risk filter argument for borderline cases (Art. 6(5) Commission guidelines pending)Applies now—
Art. 49 + KI-MIG § 20 — registrationEntry in the BNetzA's non-public register (per Art. 49(5) AI Act) for Annex III point 2 systems (critical infrastructure) — providers register before placing on the market (§ 20(2), Annex VIII A information); federal deployers register before putting into service (§ 20(3), Annex VIII C)9Register live since 29 Jul 2026Registration duty tied to Annex III 2 systems

Two rows deserve the math-first eye. The Art. 26 worker-information duty (Art. 26(7): inform workers' representatives before first use in the workplace) is not exotic — every HR-adjacent self-hosted tool in a German company hits it. And the KI-MIG § 20 register is German law live ahead of the December 2027 conformity deadline: it applies to Annex III point 2 systems — critical infrastructure, not the hiring and credit tools of inspection wave one. But BNetzA's own remit examples (critical infrastructure among them) mean a self-hoster running infrastructure-adjacent AI should check § 20 scope first: provider registration is due before placing on the market, not after.

5. The timeline math: 15 calendar months minus the burn-in

From late September 2026 to the deferred Annex III deadline of 2 December 2027:10

  • Calendar months remaining: 15 (counting October 2026 through December 2027 inclusive — exactly the "15 months" headline).
  • Realistic working months: subtract the December 2026 and December 2027 holiday low-points and typical German SME procurement cycles, and you are budgeting 12–13 working months for anything that needs external counsel, tooling or assessment capacity.
  • Per artifact: the Art. 11 documentation alone, for a single high-risk system, is a 2–3 month drafting effort for an SME. The deferral bought 16 calendar months between the original and the moved deadline (2 Aug 2026 → 2 Dec 2027); 15 remain from today. Sequencing, not parallel tracks, decides whether you use that bandwidth or lose it.

For a self-hoster with hiring or credit tools, the honest sequencing is: Art. 50 and Art. 5 screening now (live, inspectable), classification register now, Art. 11 documentation before mid-2027, registration and conformity assessment before December 2027.

6. The verdict

Germany passed a national law whose entire content — designating an authority, granting it the existing 2019/1020 powers, adding a register and a complaints office — went live for a regime whose main obligations were deferred by the Omnibus two days earlier. The irony writes itself: the BNetzA can knock on your door today about an Annex III system whose conformity dossier you do not legally owe until December 2027. But the parts it can enforce — Art. 50 disclosure, Art. 5 bans, Art. 4 literacy, its § 11 information powers, the § 20 register — are exactly the parts of the audit file you can build in a week and maintain forever.

Compared with the member states that fragmented designation across a dozen authorities, Germany's BNetzA-centering is a genuine operational convenience: one counterpart, one register, one complaints office, clearer RFI channel. Germany did not legislate one single new substantive duty. What it did — a hybrid authority map, a KI-Marktüberwachungskammer for law-enforcement AI, a register, § 12 innovation tasks — is that rarest of compliance artifacts: paperwork that mostly points at paperwork. The counterweight is the SME cost side: someone pays for this structure's execution, and reporting obligations and register runs cost real hours in a 20-person shop — which is exactly the shop the law simultaneously promises to help via the KI-Reallabor and service desk. Build the file anyway; it is cheap, it is live where it counts, and December 2027 does not move again.

This article reflects the legal situation as of September 24, 2026 and is general information, not legal advice. Binding classification of your specific system requires individual review.

Footnotes

  1. KI-Marktüberwachungs-und-Innovationsförderungs-Gesetz (KI-MIG), BGBl. 2026 I Nr. 223, announced 22.7.2026, in force 29.7.2026 per Art. 5 of the carrier act, § 1 — https://www.gesetze-im-internet.de/ki-mig/BJNR0DF0B0026.html ↩ ↩2 ↩3

  2. Regulation (EU) 2024/1689 (AI Act), Art. 70(1) member-state designation duty; Art. 70(2) single point of contact — https://eur-lex.europa.eu/eli/reg/2024/1689/oj ↩

  3. Regulation (EU) 2024/1689, consolidated text; Art. 113(2) general application date 2 Aug 2026; Art. 99(3) EUR 35M/7% tier and Art. 99(4) EUR 15M/3% tier — https://eur-lex.europa.eu/eli/reg/2024/1689/oj ↩ ↩2 ↩3

  4. KI-MIG § 2(1) BNetzA default designation; § 2(2) product-law authorities; § 2(3)–(4) BaFin for regulated financial activity (25 institution classes enumerated); § 2(5) AI Market Surveillance Chamber for Annex III 1 and 6–8; § 2(6) Länder public bodies; § 2(7) federal tax consent clause; § 2(8) media services — https://www.gesetze-im-internet.de/ki-mig/__2.html ↩ ↩2

  5. Bundesnetzagentur press release, 29.7.2026: BNetzA becomes market surveillance authority, single point of contact and complaints body; names personnel management, critical infrastructure and education remits; hybrid approach with BaFin and state media authorities unchanged; Länder may delegate via Organleihe — https://www.bundesnetzagentur.de/1112336 (English: https://www.bundesnetzagentur.de/SharedDocs/Pressemitteilungen/EN/2026/20260729_KI_VO.html) ↩ ↩2

  6. KI-MIG § 11(1): powers per Art. 14(4), (5) and Art. 16 of Regulation (EU) 2019/1020 and the AI Act; § 11(2) third-party assistants and remote access via APIs; § 11(7) non-suspensive effect — https://www.gesetze-im-internet.de/ki-mig/__11.html ↩ ↩2

  7. KI-MIG § 17(1): the § 2 authorities are administrative fine authorities for AI Act Art. 99(3)–(5); § 17(2) exempts public bodies from fines — https://www.gesetze-im-internet.de/ki-mig/__17.html ↩

  8. Reported coverage of the September 2026 first inspection wave of the AI Office and national market surveillance authorities, e.g. https://kurums.com/eu-ai-office-launches-first-compliance-inspections-of-ai-hiring-tools-september-2026-what-law-teams-must-do (docket composition reported, not an official consolidated announcement; the AI Office's powers and their 2 Aug 2026 activation are primary: https://digital-strategy.ec.europa.eu/en/policies/enforcement-ai-act) ↩

  9. KI-MIG § 20(1)–(3): BNetzA maintains the non-public register per Art. 49(5) AI Act for Annex III 2 systems; provider registration (per Annex VIII A information) before placing on the market; federal deployers register before putting into service (Annex VIII C) — https://www.gesetze-im-internet.de/ki-mig/__20.html ↩

  10. Regulation (EU) 2026/1744, Art. 1(40)(b), replacing Art. 113(3)(c) of the AI Act: Chapter III Sections 1–3 apply from 2 December 2027 for Annex III and 2 August 2028 for Annex I high-risk systems — https://eur-lex.europa.eu/eli/reg/2026/1744/oj ↩