Germany splits AI Act supervision: BaFin, BNetzA, Laender | TLY

AI Regulation Tracker  /  Germany

Germany splits AI Act supervision and BaFin gets the banks

The German implementing act was promulgated on 28 July 2026 as BGBl. 2026 I Nr. 223. The part worth reading is not the headline designation of the Bundesnetzagentur. It is the carve-outs in § 2 that decide which regulator actually shows up.

What exactly landed in the gazette on 28 July?

The masthead reads "2026 Ausgegeben zu Bonn am 28. Juli 2026 Nr. 223", and the act carries the date "Vom 22. Juli 2026". Keep those apart. The law is dated 22 July. Publication in the Bundesgesetzblatt happened six days later. Promulgation is publishing, not switching the law on, and a German statute's commencement is set by its own final article.

The tracker has already covered the headline designation. An earlier entry on the KI-MIG addressed the choice to name the Bundesnetzagentur as the central AI market surveillance authority, subject to carve-outs. This piece is about the sentence that follows it, because that is where the practical answer lives.

What does § 2 actually say?

The operative text of the default rule is short:

§ 2 Zuständige Marktüberwachungsbehörden. (1) Die Bundesnetzagentur ist die für die Einhaltung der Verordnung (EU) 2024/1689 zuständige Marktüberwachungsbehörde, soweit in diesem Gesetz nichts anderes bestimmt ist.BGBl. 2026 I Nr. 223, Artikel 1, Teil 2, Abschnitt 1, § 2 Absatz 1

In English: "§ 2 Competent market surveillance authorities. (1) The Federal Network Agency is the market surveillance authority competent for compliance with Regulation (EU) 2024/1689, unless otherwise provided in this Act."

The clause doing the work is soweit in diesem Gesetz nichts anderes bestimmt ist. Unless otherwise provided in this Act. The rest of § 2 then provides otherwise, four times, and each carve-out reaches a different constituency.

So which regulator supervises which AI system?

The answer is not one name.

Which German authority supervises which AI system under KI-MIG § 2
System or deployerCompetent German supervisorProvision
Default. Any AI system not otherwise carved outBundesnetzagentur§ 2(1)
AI systems directly connected to regulated financial activity, across the list of supervised entities that § 2(3) enumerates (reported as 25 items, including banks, insurers, payment and e-money institutions, crypto-asset service providers and fund managers)BaFin§ 2(3)
Annex III No. 1 and Annex III Nos. 6, 7 and 8, the law enforcement, border management, and justice and democracy categoriesIndependent KI-Marktüberwachungskammer inside the Bundesnetzagentur§ 2(5)
AI used by public bodies of a LandLand authorities§ 2(6)
Federal tax authoritiesBundesnetzagentur, but only acting in agreement with the Federal Ministry of Finance§ 2(7)

The supervision split in § 2 can be applied in a decision-tree sequence: sector, then Annex III category, then the default. A German insurance subsidiary running a claims fraud model sits in a different supervisory relationship than the same group's HR screening tool.

Why is the BaFin carve-out particularly relevant for non-German financial institutions with German operations?

Because for AI systems directly connected to regulated financial activity, AI Act compliance will sit within existing prudential supervisory relationships rather than with a separate authority. A bank or insurer with German operations that is already supervised by BaFin will have its AI systems directly connected to the regulated financial activity supervised through that existing BaFin relationship. Under § 2(3), for AI directly connected to the regulated activity, market surveillance runs through that same relationship rather than through an agency the institution has probably never dealt with.

That has potential advantages, because BaFin already supervises model risk and validation and has been building expectations in that direction. It also means AI Act-related observations and prudential observations may be handled within the same supervisory context.

The scope test is the part to get right internally. The carve-out attaches to systems directly connected to the regulated financial activity, not to everything a supervised entity happens to run. A recruitment tool or a marketing model does not obviously ride it, and the default in § 2(1) is the Bundesnetzagentur. Treating BaFin as responsible for all of an entity's AI systems risks filing with the wrong authority.

What is the KI-Marktüberwachungskammer, and why wall it off?

§ 2(5) creates an independent chamber inside the Bundesnetzagentur for Annex III No. 1 and Annex III Nos. 6 to 8, the law enforcement, border management, and justice and democracy categories. Structurally this reflects an acknowledgment that these areas raise heightened independence questions. Supervising police, border and judicial uses of AI raises independence questions that a ministry-supervised agency typically addresses through additional structural safeguards. Creating a more independent internal chamber is one way German administrative law has addressed similar independence concerns in other contexts.

For a private-sector deployer the chamber question mainly arises when acting as a vendor into those Annex III categories. Sell into those Annex III categories and the German counterparty is the chamber, not the general market surveillance side of the agency, and the two may develop different practice.

Which public bodies sit outside the agency's reach?

Two groups, both easy to get wrong. § 2(6) leaves AI used by public bodies of a Land to Land authorities. That creates a federal supervisory allocation, and it is why a flat statement that the Bundesnetzagentur supervises all German AI would be inaccurate. Anyone selling into Land administrations, schools or state police should expect a Land-level counterparty.

§ 2(7) is narrower and more pointed: against federal tax authorities the Bundesnetzagentur may act only in agreement with the Finance Ministry. In practice, this gives the Federal Ministry of Finance a gatekeeping role over action against federal tax authorities. The ministry responsible for the tax administration therefore also influences its AI supervision.

What should in-house counsel do with this before 2 August?

Promulgation on 28 July 2026 preceded the EU AI Act's 2 August 2026 Article 50 date by five days. Three things are worth doing now.

First, classify by supervisor. Most AI inventories are organised by business unit or risk tier. Add a column for the competent German authority and populate it from § 2. That usually surfaces systems nobody had allocated at all.

Second, decide the boundary of "directly connected to regulated financial activity" before a regulator asks, and write the reasoning down. A documented line drawn in July beats one improvised under a request.

Third, update the member-state authority map. Germany is now a multi-authority jurisdiction for AI Act market surveillance. One name per member state is already wrong for it.

Frequently asked questions

Which authority supervises a high-risk AI system deployed in Germany?

It depends on the sector and on the Annex III category. Under § 2(1) of the KI-MIG, promulgated as BGBl. 2026 I Nr. 223, the Bundesnetzagentur is the market surveillance authority for Regulation (EU) 2024/1689 unless the act provides otherwise. It provides otherwise four times: BaFin for AI directly connected to regulated financial activity across the § 2(3) list of supervised entities, an independent KI-Marktüberwachungskammer for Annex III No. 1 and Nos. 6 to 8, Land authorities for Land public bodies, and Finance Ministry agreement before action against federal tax authorities.

Does a US bank with a German subsidiary now answer to BaFin on AI Act compliance?

Where the AI system is directly connected to the regulated financial activity of an entity on the § 2(3) list of supervised entities, yes, BaFin is the market surveillance authority rather than the Bundesnetzagentur. The list covers supervised financial entities including banks, insurers, payment and e-money institutions, crypto-asset service providers and fund managers. AI systems that are not connected to the regulated activity fall back to the Bundesnetzagentur under the default rule in § 2(1).

Is the Bundesnetzagentur now Germany's single AI regulator?

No. It is the default market surveillance authority, which is not the same thing. § 2(6) leaves AI used by Land public bodies to Land authorities, and § 2(7) requires the Bundesnetzagentur to act against federal tax authorities only in agreement with the Federal Ministry of Finance. Treating the agency as a single national AI regulator will produce the wrong answer on both of those.

Last verified: July 28, 2026