Germany now runs two separate machines for disciplining powerful technology companies, built four years apart on opposite theories of how enforcement should work.
The newer one, the KI-Marktüberwachungs- und Innovationsförderungsgesetz (KI-MIG), took effect July 29, 2026 — ahead of August 2, 2026, the date the EU AI Act's own market-surveillance obligations for high-risk Annex III systems became directly applicable across the bloc. The law makes the Bundesnetzagentur (BNetzA), Germany's telecoms and energy regulator, the country's central AI market-surveillance authority: contact point, complaints office, and inspector of technical documentation for AI products sold in Germany. For a defined category of the most sensitive systems — biometric identification, law enforcement, border and migration control, and justice or democratic processes — KI-MIG creates an independent three-member AI Market Surveillance Chamber inside BNetzA, chaired by the agency's president with its two vice presidents as members, reporting annually to the Bundestag.
The Case for a Dedicated Chamber
The argument for treating this category differently is a strong one, and regulators shouldn't have to apologize for making it. Facial-recognition and predictive-policing systems have repeatedly shown documented accuracy gaps across demographic groups, and errors in border, asylum, or criminal-justice AI don't just cost money — they can mean a wrongful stop, a denied entry, or a flawed evidentiary record that's difficult to unwind after the fact. Unlike a defective consumer app, these harms are largely invisible to the people affected and to the market generally, which is precisely the case for a standing, well-resourced check rather than after-the-fact litigation.
Where the Design Falls Short
But KI-MIG's institutional architecture doesn't fully match that ambition. Legal commentary on the law (LTO, August 2026) points out that the chamber's three members are BNetzA's own president and vice presidents — the agency effectively reviews itself for its most sensitive cases, not a panel drawn from outside the regulator. Penalties run up to €35 million or 7% of global annual turnover, higher than the GDPR ceiling, yet first-instance disputes are routed to ordinary district courts (Amtsgerichte), which have no particular grounding in AI systems or fundamental-rights adjudication. And the law arrived without two changes that digital-rights groups including AlgorithmWatch had pushed for: a mandatory public transparency register for high-risk systems, and moving oversight of law-enforcement AI to data protection authorities rather than a telecoms regulator (Heise, June 2026). Germany hit its EU deadline — after missing the original August 2025 date for simply naming an oversight body — but the design reads like a compliance sprint, not a considered build.
A Regime That Already Works, Sitting Next Door
Germany didn't need to start from scratch. Since 2021, Section 19a of the Act Against Restraints of Competition (GWB) has let the Bundeskartellamt designate firms of "paramount significance for competition across markets" and pursue targeted abuse cases against them. Five companies now carry that designation — Alphabet/Google (January 2022), Meta (May 2022), Amazon (July 2022), Apple (April 2023), and Microsoft (September 2024) — and the Federal Court of Justice has upheld the designations against Amazon and Apple on appeal.
The regime's signature feature is patience paired with proportionality. On August 17, 2026, the Bundeskartellamt closed a four-year investigation into Apple's App Tracking Transparency Framework, which it found nudged users toward consenting to Apple's own ad tracking while discouraging consent for competitors' apps through unequal prompt design. Rather than impose a fine, the authority extracted binding commitments: Apple must redesign the prompts to be genuinely neutral, streamline the consent flow for developers, and submit to an independent trustee's monitoring for seven years, with four months to implement the fix. France and Italy fined Apple roughly €249 million combined for comparable conduct; Germany instead engineered a structural remedy it can verify for most of a decade.
The Lesson KI-MIG Didn't Import
That contrast is the real story here. The Bundeskartellamt's slower, commitment-based model produces outcomes that are durable and checkable — a trustee watching Apple's prompts for seven years does more for the underlying problem than a one-time transfer to the treasury. KI-MIG, by contrast, imported the blunt instrument of GDPR-scale fines and routed enforcement through generalist courts, while stopping short of the external independence and transparency that would justify wielding a penalty that size against systems touching liberty and due process.
None of this means the AI Act's stricter treatment of biometric and law-enforcement AI is misplaced — irreversible rights harms warrant a firmer hand than a mistargeted ad prompt. But firmness without institutional credibility invites exactly the legal challenges and public skepticism that slow enforcement down. Germany had a proportionate, remedy-first template sitting one ministry over. KI-MIG would have been stronger, not weaker, for borrowing it.