German AI Regulation: Navigating BaFin, DORA, NIS2 and the KI-MIG
label Article

German AI Regulation: Navigating BaFin, DORA, NIS2 and the KI-MIG

calendar_today
schedule 5-min Read
person By Dominic Fui Dodzi-Nusenu

German firms deploying AI do not face one regulator or one rulebook. They face the EU AI ActRegulation (EU) 2024/1689The EU's regulation on artificial intelligence. It sorts AI systems into risk tiers — prohibited, high-risk, limited-risk and minimal-risk — and attaches different duties to the provider that builds a system and the deployer that uses it. It entered into force on 1 August 2024 and applies in stages; the Digital Omnibus, Regulation (EU) 2026/1744, in force since 27 July 2026, moved the high-risk stages later without changing the penalties. Article 99 leaves those at up to €35 million or 7% of worldwide annual turnover for prohibited practices, and up to €15 million or 3% for most other breaches, including the high-risk and transparency duties.Applies toProviders and deployers of AI systems placed on or used in the EU market.Next dateDecember 2, 2026 — Article 50(2) marking of AI-generated content, for systems already on the market on 2 August 2026Read the source text (opens in a new tab)General information about the instrument named, not legal advice. as implemented domestically through the KI-MIGKI-Marktüberwachungs- und Innovationsförderungsgesetz — Germany's AI Act implementation actThe German act that carries the EU AI Act into national law, in force since 29 July 2026. It designates the Bundesnetzagentur as the central AI market surveillance authority outside regulated sectors, and establishes a coordination centre, KoKIVO, there. BaFin keeps the sector-specific mandate for AI systems used in direct connection with a regulated financial activity, which is why a bank and a housing company answer to different regulators for the same kind of model.Applies toProviders and deployers of AI systems supervised in Germany. Which authority supervises depends on the sector.Read the source text (opens in a new tab)General information about the instrument named, not legal advice., BaFin’s long-standing supervisory expectations, DORADigital Operational Resilience Act — Regulation (EU) 2022/2554The EU regulation on digital operational resilience in the financial sector. It covers ICT risk management, incident classification and reporting, resilience testing, and oversight of third-party ICT providers — bringing those providers into a supervisory perimeter that previously stopped at the financial entity. BaFin's guidance of 18 December 2025 addresses entities subject to Articles 5 to 15 of DORA and places AI systems inside that existing ICT framework rather than a separate regime, examining ICT risk across the whole AI lifecycle — data acquisition, model development and provision, ongoing operation and retirement — with particular weight on third-party ICT risk.Applies toFinancial entities in the EU, and the ICT providers designated as critical to them.Read the source text (opens in a new tab)General information about the instrument named, not legal advice. for operational resilience, and NIS2 as transposed into the BSIG for cybersecurity incidents. These regimes overlap in scope, differ in deadline, and — critically — differ in who you report to and how fast.

Published: March 2026 · updated August 2026 · Author: Dominic Fui Dodzi-Nusenu · Reading time: ~8 minutes

Disclosure: This article was drafted using generative AI assistance and subsequently edited, verified, and expanded by human legal and tech policy specialists. The organizational case study presented below is a composite hypothetical scenario designed to illustrate compliance risks.

In brief

Four regimes govern AI in German financial and critical-infrastructure firms. The KI-MIG implements the EU AI Act domestically and designates the Bundesnetzagentur as market surveillance authority. BaFin continues to supervise institutions through MaRisk and BAIT, which already require model governance and outsourcing controls that predate the AI Act. DORA governs ICT risk and third-party dependency for financial entities. NIS2, transposed through the BSIG, imposes a 24-hour early warning, a 72-hour incident notification and a one-month final report. The reporting clocks are the sharpest edge: they differ per regime, they start on awareness rather than on confirmation, and a single AI-related outage can trigger more than one at once. Build one control set and map it to all four rather than running four projects.

The four regimes, and what each one actually wants

Regime Scope Core demand Authority
KI-MIG / EU AI Act Any AI system by use case Risk classification, Annex IV documentation, oversight, monitoring BNetzA as market surveillance
MaRisk / BAIT Supervised institutions Model governance, validation, outsourcing control, IT organisation BaFin
DORA Financial entities and their ICT providers ICT risk management, third-party register, resilience testing BaFin / ESAs
NIS2 / BSIGDirective (EU) 2022/2555, transposed in Germany by the NIS2 implementation act amending the BSI-GesetzThe EU's second network and information security directive, and the German act that carries it into national law. It sets cybersecurity risk-management measures, a staged incident-reporting timetable, and registration with the BSI. Under § 38 Abs. 2 BSIG a company's management is personally liable to the entity for breaches of those duties, which is what distinguishes it from earlier German IT-security law.Applies to"Important" and "particularly important" entities across 18 sectors, sized by headcount and turnover.Read the source text (opens in a new tab)General information about the instrument named, not legal advice. Essential and important entities Cyber risk measures and staged incident reporting BSI

The useful observation is that these ask for the same underlying artefacts in different vocabularies. An inventory of AI systems, an owner per system, a documented risk assessment, evidence of monitoring, and an incident procedure will carry a very large share of all four. Firms that run four separate programmes produce four inconsistent answers about the same system, which is worse than one imperfect answer.

The KI-MIG: what German implementation adds

The AI Act is a regulation, so it applies directly — the KI-MIG does not restate it. What national implementation supplies is the machinery: which authority conducts market surveillance, how penalties are administered, and how the AI Act’s supervision meshes with existing sectoral supervisors. For financial institutions the practical consequence is that BaFin supervision does not displace AI Act market surveillance. You should expect to evidence the same model to two audiences with different questions.

Where the reporting clocks collide

This is the part that catches firms out, because the regimes measure time differently and the trigger is usually awareness, not confirmation.

Trigger Regime Clock
Significant cyber incident NIS2 / BSIG 24h early warning → 72h notification → 1 month final report
Major ICT-related incident DORA Initial, intermediate and final reports on defined deadlines
Serious incident involving a high-risk AI system EU AI Act Article 73 Reporting to market surveillance, with a shortened window for widespread infringement or serious disruption

A single event — say, a compromised model-serving endpoint producing discriminatory credit decisions — can plausibly trigger all three. If your incident runbook names only one regulator, it is not a runbook. The remedy is unglamorous: one incident register, one clock started on first awareness, and a mapping that fans out to each recipient.

Case scenario: a fintech that thought DORA covered it

A Frankfurt payments firm completed a substantial DORA programme in 2025 — ICT risk framework, third-party register, resilience testing. Asked in a 2026 procurement round for its EU AI Act position, it had none, and discovered three things: its fraud-scoring model was arguably Annex III, its DORA third-party register listed the model vendor as an ICT provider but recorded nothing about model behaviour, and its AI literacy obligation under Article 4 had been live for over a year with no training delivered.

Nothing in its DORA work was wasted — the third-party register was two-thirds of an AI vendor inventory. But DORA asks whether a supplier can keep running; the AI Act asks whether its output is lawful, documented and monitored. Different question, same supplier.

Practical sequencing for German firms

  1. Build one AI inventory and make it serve the AI Act classification, the DORA third-party register and BaFin outsourcing records simultaneously.
  2. Close the already-enforceable AI Act duties first — Article 5 prohibitions, Article 4 AI literacy, Article 50 transparency. These are live now, unlike the high-risk tier which moved to December 2027.
  3. Consolidate incident reporting into a single intake with a mapping to BSI, BaFin and market surveillance, and start the clock on awareness.
  4. Reuse MaRisk and BAIT model governance rather than rebuilding. Validation, approval and change control already exist in supervised institutions; the AI Act mostly asks for them to be evidenced differently.
  5. Assign one accountable owner across all four. Splitting AI Act ownership from ICT risk ownership is how the same system ends up described two ways.

Four regimes, one estate — can you evidence the same system to all of them?

Map your AI systems against the AI Act, DORA and NIS2 in one place.

Start your assessment →

Related reading

Frequently asked questions

Does the KI-MIG create obligations beyond the EU AI Act?

The AI Act applies directly as a regulation, so the KI-MIG’s role is largely institutional — designating market surveillance (the Bundesnetzagentur), administering penalties, and coordinating with sectoral supervisors. Your substantive duties come from the AI Act itself.

If BaFin already supervises our models, is the AI Act duplicated work?

There is real overlap in substance but not in evidence. MaRisk and BAIT model governance gives you validation, approval and change control; the AI Act asks for Annex IV documentation, classification reasoning, and post-market monitoring records. Treat the BaFin work as an input rather than a substitute.

Which incident clock starts first?

In practice the NIS2 24-hour early warning is the tightest, and it starts on becoming aware of a significant incident — not on completing triage. Firms should assume the shortest applicable clock and de-escalate later if a regime turns out not to apply.

Does DORA’s third-party register satisfy AI vendor documentation?

Partly. It identifies the supplier and the dependency, which is most of an AI vendor inventory. It does not record intended purpose, training data provenance, risk classification or monitoring, which the AI Act requires.

We are not a financial entity. Does any of this apply?

The AI Act does, because it regulates by use case rather than sector — employment screening and essential-services eligibility are Annex III wherever they occur. NIS2 may also apply if you are an essential or important entity. DORA and BaFin expectations will not.

Alleina AI

Responsible AI governance platform for European enterprises, SMEs, and startups. EU AI Act compliance, bias detection, and model explainability.

Stay Updated

Get the latest on AI governance, regulatory updates, and platform news.

Gefördert durch

Universität Koblenz EXIST – Existenzgründungen aus der Wissenschaft StArfrica – Startup Germany-Africa Bundesministerium für Wirtschaft und Energie Kofinanziert von der Europäischen Union

Die Europäische Union fördert zusammen mit dem Bundesministerium für Wirtschaft und Energie über den Europäischen Sozialfonds Plus (ESF Plus) das Programm „Existenzgründungen aus der Wissenschaft (EXIST)“ in Deutschland.

Alleina AI ist ein an der Universität Koblenz inkubiertes Startup. Die Gründung wurde durch StArfrica („Startup Germany-Africa“) begleitet, ein Projekt des ZIFET an der Universität Koblenz.

© 2026 Alleina AI. Alle Rechte vorbehalten.