Image: Ivan Marc / shutterstock.com

Artificial intelligence is no longer just a topic of the future. It writes texts, analyzes data, assists doctors, and helps companies work faster and more efficiently. But with these new possibilities come new rules. This is precisely where the European AI Act comes in. While the European Union sets the rules, Germany—through its new AI Market Surveillance and Innovation Act (KI-MIG)—ensures that these rules are actually implemented in everyday practice.

For companies, this means one thing above all else: Anyone who uses or develops AI should familiarize themselves with the new regulations now. After all, while there are new opportunities, there is also the risk of severe penalties.

Europe sets the rules—Germany handles enforcement

The AI Act is already in effect as a European regulation and is being implemented step by step. Nevertheless, European law alone is not sufficient. Each member state must determine which authorities will be responsible for monitoring compliance, prosecuting violations, and supporting companies in the future.

Germany took a long time to reach this decision. Although certain authorities were required to be designated earlier, the legal framework was not established until shortly before the start of the AI Act’s most important implementation phase. As a result, many companies have very little time to adapt to the new responsibilities.

In this regard, Germany is taking a different approach than some of its European neighbors. Instead of establishing a completely new AI regulatory agency, it is incorporating existing agencies. While this streamlines administrative structures, it also makes the system significantly more complex.

So many government agencies, so many areas of responsibility—who is actually in charge?

The Federal Network Agency will play a key role going forward. It will serve as the central point of contact in many areas for questions regarding the oversight of AI systems and will consolidate various responsibilities.

However, it is not entirely on its own. Depending on the area of application for artificial intelligence, other specialized agencies remain responsible. When it comes to regulated products or certain areas of finance, for example, existing supervisory structures already apply. The federal states also have their own areas of responsibility—such as when AI is used by state agencies, for example in schools, the judiciary, or other public institutions.

This has its advantages. Agencies with specialized expertise remain responsible for their respective areas. At the same time, however, a complex web of different responsibilities emerges. For businesses, this can quickly make it unclear which agency is actually responsible. To mitigate this problem, a new coordination and competence center is intended to improve communication between agencies and ensure that decisions are as consistent as possible.

Hefty Fines: AI Violations Can Get Really Expensive

Companies should pay particular attention to the potential penalties. The AI Act provides for fines that may even exceed the well-known maximum limits set by the General Data Protection Regulation. In particularly serious cases, fines of up to 35 million euros or seven percent of global annual revenue may be imposed—whichever amount is higher.

This makes it clear that compliance with the new AI regulations is not merely a formality. Companies should assess early on which AI systems are being used, what risks are associated with them, and what documentation and oversight requirements will apply in the future.

There is another challenge as well. Many AI applications process personal data at the same time. As a result, both the provisions of the AI Act and data protection rules may apply. Without effective coordination among the relevant authorities, there is a risk that companies could face multiple proceedings over the same set of facts. How these proceedings are to be coordinated in the future has not yet been clearly defined in every respect.

The goal is not only to promote oversight—but also innovation

However, the new law does not focus exclusively on regulation. Its goal is also to promote innovation in Germany.

So-called AI real-world labs are a key component. These labs are designed to enable startups and small and medium-sized enterprises, in particular, to test new AI solutions under regulatory oversight before they are officially launched on the market. This would allow uncertainties to be identified early on and innovative ideas to be implemented more quickly.

However, exactly how these real-world testing grounds will function in detail—and what requirements companies must meet to participate—will only become clear once they are put into practice. The key question will be whether companies actually experience tangible relief as a result or whether this leads to additional red tape.

Now the real test begins

With the AI-MIG, Germany is establishing the organizational framework for the AI Act. Authorities are designated, responsibilities are assigned, and procedures are defined. On paper, the system appears comprehensive. However, it remains to be seen whether it will work just as well in practice.

Especially with a technology that is evolving almost every month, it will be crucial for regulators to act quickly, clearly, and consistently. Companies need clear points of contact and reliable rules—not an opaque network of regulatory agencies.

One thing is already clear: Anyone who uses artificial intelligence for business purposes should not put off addressing these new requirements. Compliance in the area of AI will become just as standard in the coming years as data protection or IT security.

Subscribe to the newsletter

and always up to date on data protection.