German AI Regulation: Navigating BaFin, DORA, NIS2 and the KI-MIG
German firms deploying AI do not face one regulator or one rulebook. They face the EU AI ActVerordnung (EU) 2024/1689The EU's regulation on artificial intelligence. It sorts AI systems into risk tiers — prohibited, high-risk, limited-risk and minimal-risk — and attaches different duties to the provider that builds a system and the deployer that uses it. It entered into force on 1 August 2024 and applies in stages; the Digital Omnibus, Regulation (EU) 2026/1744, in force since 27 July 2026, moved the high-risk stages later without changing the penalties. Article 99 leaves those at up to €35 million or 7% of worldwide annual turnover for prohibited practices, and up to €15 million or 3% for most other breaches, including the high-risk and transparency duties.Gilt fürAnbieter und Betreiber von KI-Systemen, die in der EU in Verkehr gebracht oder eingesetzt werden.Nächster TerminDezember 2, 2026 — Kennzeichnung KI-generierter Inhalte nach Artikel 50 Absatz 2, für Systeme, die am 2. August 2026 bereits in Verkehr warenZum Quelltext des Rechtsakts (öffnet in einem neuen Tab)Allgemeine Informationen zum genannten Rechtsakt, keine Rechtsberatung. as implemented domestically through the KI-MIGKI-Marktüberwachungs- und Innovationsförderungsgesetz — Germany's AI Act implementation actThe German act that carries the EU AI Act into national law, in force since 29 July 2026. It designates the Bundesnetzagentur as the central AI market surveillance authority outside regulated sectors, and establishes a coordination centre, KoKIVO, there. BaFin keeps the sector-specific mandate for AI systems used in direct connection with a regulated financial activity, which is why a bank and a housing company answer to different regulators for the same kind of model.Gilt fürProviders and deployers of AI systems supervised in Germany. Which authority supervises depends on the sector.Zum Quelltext des Rechtsakts (öffnet in einem neuen Tab)Allgemeine Informationen zum genannten Rechtsakt, keine Rechtsberatung., BaFin’s long-standing supervisory expectations, DORADigital Operational Resilience Act — Verordnung (EU) 2022/2554The EU regulation on digital operational resilience in the financial sector. It covers ICT risk management, incident classification and reporting, resilience testing, and oversight of third-party ICT providers — bringing those providers into a supervisory perimeter that previously stopped at the financial entity. BaFin's guidance of 18 December 2025 addresses entities subject to Articles 5 to 15 of DORA and places AI systems inside that existing ICT framework rather than a separate regime, examining ICT risk across the whole AI lifecycle — data acquisition, model development and provision, ongoing operation and retirement — with particular weight on third-party ICT risk.Gilt fürFinanzunternehmen in der EU sowie die als kritisch eingestuften IKT-Drittdienstleister.Zum Quelltext des Rechtsakts (öffnet in einem neuen Tab)Allgemeine Informationen zum genannten Rechtsakt, keine Rechtsberatung. for operational resilience, and NIS2 as transposed into the BSIG for cybersecurity incidents. These regimes overlap in scope, differ in deadline, and — critically — differ in who you report to and how fast.
Published: March 2026 · updated August 2026 · Author: Dominic Fui Dodzi-Nusenu · Reading time: ~8 minutes
Disclosure: This article was drafted using generative AI assistance and subsequently edited, verified, and expanded by human legal and tech policy specialists. The organizational case study presented below is a composite hypothetical scenario designed to illustrate compliance risks.
In brief
Four regimes govern AI in German financial and critical-infrastructure firms. The KI-MIG implements the EU AI Act domestically and designates the Bundesnetzagentur as market surveillance authority. BaFin continues to supervise institutions through MaRisk and BAIT, which already require model governance and outsourcing controls that predate the AI Act. DORA governs ICT risk and third-party dependency for financial entities. NIS2, transposed through the BSIG, imposes a 24-hour early warning, a 72-hour incident notification and a one-month final report. The reporting clocks are the sharpest edge: they differ per regime, they start on awareness rather than on confirmation, and a single AI-related outage can trigger more than one at once. Build one control set and map it to all four rather than running four projects.
The four regimes, and what each one actually wants
| Regime | Scope | Core demand | Authority |
|---|---|---|---|
| KI-MIG / EU AI Act | Any AI system by use case | Risk classification, Annex IV documentation, oversight, monitoring | BNetzA as market surveillance |
| MaRisk / BAIT | Supervised institutions | Model governance, validation, outsourcing control, IT organisation | BaFin |
| DORA | Financial entities and their ICT providers | ICT risk management, third-party register, resilience testing | BaFin / ESAs |
| NIS2 / BSIGRichtlinie (EU) 2022/2555, in Deutschland umgesetzt durch das NIS2-Umsetzungsgesetz zur Änderung des BSI-GesetzesDie zweite Netz- und Informationssicherheitsrichtlinie der EU und das deutsche Gesetz, das sie in nationales Recht überführt. Sie verlangt Risikomanagementmaßnahmen im Bereich der Cybersicherheit, ein gestuftes Meldeverfahren für Vorfälle und die Registrierung beim BSI. Nach § 38 Abs. 2 BSIG haftet die Geschäftsleitung der Einrichtung gegenüber persönlich für Verstöße gegen diese Pflichten — das unterscheidet es vom früheren deutschen IT-Sicherheitsrecht.Gilt für„Wichtige“ und „besonders wichtige“ Einrichtungen in 18 Sektoren, abgegrenzt nach Beschäftigtenzahl und Umsatz.Zum Quelltext des Rechtsakts (öffnet in einem neuen Tab)Allgemeine Informationen zum genannten Rechtsakt, keine Rechtsberatung. | Essential and important entities | Cyber risk measures and staged incident reporting | BSI |
The useful observation is that these ask for the same underlying artefacts in different vocabularies. An inventory of AI systems, an owner per system, a documented risk assessment, evidence of monitoring, and an incident procedure will carry a very large share of all four. Firms that run four separate programmes produce four inconsistent answers about the same system, which is worse than one imperfect answer.
The KI-MIG: what German implementation adds
The AI Act is a regulation, so it applies directly — the KI-MIG does not restate it. What national implementation supplies is the machinery: which authority conducts market surveillance, how penalties are administered, and how the AI Act’s supervision meshes with existing sectoral supervisors. For financial institutions the practical consequence is that BaFin supervision does not displace AI Act market surveillance. You should expect to evidence the same model to two audiences with different questions.
Where the reporting clocks collide
This is the part that catches firms out, because the regimes measure time differently and the trigger is usually awareness, not confirmation.
| Trigger | Regime | Clock |
|---|---|---|
| Significant cyber incident | NIS2 / BSIG | 24h early warning → 72h notification → 1 month final report |
| Major ICT-related incident | DORA | Initial, intermediate and final reports on defined deadlines |
| Serious incident involving a high-risk AI system | EU AI Act Article 73 | Reporting to market surveillance, with a shortened window for widespread infringement or serious disruption |
A single event — say, a compromised model-serving endpoint producing discriminatory credit decisions — can plausibly trigger all three. If your incident runbook names only one regulator, it is not a runbook. The remedy is unglamorous: one incident register, one clock started on first awareness, and a mapping that fans out to each recipient.
Case scenario: a fintech that thought DORA covered it
A Frankfurt payments firm completed a substantial DORA programme in 2025 — ICT risk framework, third-party register, resilience testing. Asked in a 2026 procurement round for its EU AI Act position, it had none, and discovered three things: its fraud-scoring model was arguably Annex III, its DORA third-party register listed the model vendor as an ICT provider but recorded nothing about model behaviour, and its AI literacy obligation under Article 4 had been live for over a year with no training delivered.
Nothing in its DORA work was wasted — the third-party register was two-thirds of an AI vendor inventory. But DORA asks whether a supplier can keep running; the AI Act asks whether its output is lawful, documented and monitored. Different question, same supplier.
Practical sequencing for German firms
- Build one AI inventory and make it serve the AI Act classification, the DORA third-party register and BaFin outsourcing records simultaneously.
- Close the already-enforceable AI Act duties first — Article 5 prohibitions, Article 4 AI literacy, Article 50 transparency. These are live now, unlike the high-risk tier which moved to December 2027.
- Consolidate incident reporting into a single intake with a mapping to BSI, BaFin and market surveillance, and start the clock on awareness.
- Reuse MaRisk and BAIT model governance rather than rebuilding. Validation, approval and change control already exist in supervised institutions; the AI Act mostly asks for them to be evidenced differently.
- Assign one accountable owner across all four. Splitting AI Act ownership from ICT risk ownership is how the same system ends up described two ways.
Four regimes, one estate — can you evidence the same system to all of them?
Map your AI systems against the AI Act, DORA and NIS2 in one place.
Related reading
- EU AI Act for Financial Institutions: The 2027 Deadline
- EU AI Act Compliance Checklist for High-Risk AI Systems
- How German Banks Are Adopting AI: Market Landscape 2026
Frequently asked questions
Does the KI-MIG create obligations beyond the EU AI Act?
The AI Act applies directly as a regulation, so the KI-MIG’s role is largely institutional — designating market surveillance (the Bundesnetzagentur), administering penalties, and coordinating with sectoral supervisors. Your substantive duties come from the AI Act itself.
If BaFin already supervises our models, is the AI Act duplicated work?
There is real overlap in substance but not in evidence. MaRisk and BAIT model governance gives you validation, approval and change control; the AI Act asks for Annex IV documentation, classification reasoning, and post-market monitoring records. Treat the BaFin work as an input rather than a substitute.
Which incident clock starts first?
In practice the NIS2 24-hour early warning is the tightest, and it starts on becoming aware of a significant incident — not on completing triage. Firms should assume the shortest applicable clock and de-escalate later if a regime turns out not to apply.
Does DORA’s third-party register satisfy AI vendor documentation?
Partly. It identifies the supplier and the dependency, which is most of an AI vendor inventory. It does not record intended purpose, training data provenance, risk classification or monitoring, which the AI Act requires.
We are not a financial entity. Does any of this apply?
The AI Act does, because it regulates by use case rather than sector — employment screening and essential-services eligibility are Annex III wherever they occur. NIS2 may also apply if you are an essential or important entity. DORA and BaFin expectations will not.