03.03.2026

Federal Network Agency to take over AI supervision

AI Snack with Inga | Digital Marketing Project Manager | AI Manager & Trainer

The decision had already been anticipated in political circles in Berlin: the Federal Government intends to make the Federal Network Agency the central supervisory authority for AI applications under the European AI Act. Under the planned AI Market Surveillance and Innovation Promotion Act (KI-MIG), it is set to act as a coordinating body in future and centralise market surveillance in Germany.

The Federal Network Agency is now the regulatory authority

The choice comes as little surprise. The authority has experience in regulating complex, technology-driven markets – such as the telecommunications, energy and platform sectors. Furthermore, it is already integrated into European regulatory networks. The aim is to provide a central point of contact for businesses, rather than a patchwork of different authorities.

At the same time, the so-called ‘one-stop shop with sector-specific oversight’ will remain in place: in regulated sectors, specialised authorities will retain their remit – such as BaFin in the financial sector or data protection authorities for GDPR matters. The Federal Network Agency will take on coordination and market oversight in accordance with the AI Act.

The AI Act has been in force since August 2024. However, the obligations will come into effect in stages:

  • From 2025: The first bans (e.g. certain forms of real-time biometric monitoring) and requirements for high-risk systems will come into effect.
  • 2026: Most regulatory obligations will apply in full, including comprehensive market surveillance and the power to impose sanctions.

The national supervisory framework must be fully operational by then. Companies should therefore not assume that inspections will only begin ‘at some point in the future’.

Market surveillance is based on traditional EU product safety mechanisms. This means:

  • Review of documentation
  • Request for technical documentation
  • Random checks
  • Orders to rectify defects
  • Sales bans in the event of serious breaches
  • Fines (up to 35 million euros or 7 per cent of global annual turnover)

Particularly in the case of high-risk AI, regulatory authorities will systematically check whether risk management, transparency and documentation requirements are being met.

Anyone who uses or provides AI professionally should now adopt a structured approach:

1. Maintain an internal AI inventory

Create a central register of all AI systems in use:

  • Purpose of use
  • Provider
  • Data types (personal data?)
  • Risk category under the AI Act
  • Responsible person within the organisation

This forms the basis for every compliance audit.

2. Document the risk classification

Systematically assess whether the risk is:

  • minimal risk
  • limited risk
  • high-risk AI
  • or unauthorised AI

This assessment should be documented in a comprehensible manner.

3. Take training requirements seriously

Staff who work with AI or base decisions on it must be trained:

  • How the systems work and their limitations
  • Risks of bias and discrimination
  • Documentation requirements
  • Human oversight mechanisms

This significantly reduces liability risks.

4. Ensuring transparency

  • Clearly label AI-generated content
  • Inform users when they are interacting with AI
  • Disclose automated decision-making processes where relevant

5. Review contracts with providers

For external AI tools:

  • Who is the provider within the meaning of the AI Act?
  • Who bears which compliance responsibilities?
  • Is there documentation, a risk assessment and a declaration of conformity?

The allocation of roles is particularly crucial in the case of SaaS solutions.

6. Establish a governance structure

It is recommended to have an internal AI policy with:

  • Approval processes
  • Audit mechanisms
  • Areas of responsibility
  • Escalation procedures

Larger organisations should appoint an AI compliance board or designate a responsible body.

Where AI is used purely for content generation, the risk remains manageable.
For HR, financial decisions, medicine, credit scoring or automated assessment systems, however, the regulatory implications are becoming serious.

The supervisory authorities will not start with mass raids. But they will take action where:

  • fundamental rights are affected
  • economic risks arise
  • complaints are received

or market participants attract attention.

OK, the AI Regulation is certainly not a bestseller that you’d voluntarily sit down to read on the sofa with a coffee and a croissant. Nevertheless, I believe regulating AI makes sense.

AI can be a huge productivity booster. But that’s precisely why its use needs clear rules. After all, many companies have been using AI for some time now without having clearly defined who is allowed to use it and for what purposes, what data may be processed, and where particular risks lie. This is precisely when things become critical – for example, when working with sensitive customer, company or personnel data.

In my view, this is where one of the greatest risks in day-to-day business lies: not in the technology itself, but in its uncoordinated use. When staff use AI tools without training, without guidelines and without clear processes, errors, uncertainties and, in the worst case, genuine compliance issues can quickly arise.

At the same time, this is precisely where there is enormous potential. Well-trained staff not only use AI more safely, but usually also derive significantly greater benefit from it than when it is used merely on an ad hoc basis. Anyone who understands how to instruct AI effectively, develop powerful prompts, critically evaluate results, or configure their own assistants – or even agents – appropriately can make processes significantly more efficient and improve the quality of the results.

That is why, in my view, two things are particularly important:

  • Training employees in the use of AI
  • clear processes and responsibilities within the organisation

Ideally, there should be one person or a small team within the organisation who takes the lead in coordinating this area and works closely with the specialist departments. Some organisations are already taking a very sensible approach here — for example, through internal workshops, small AI challenges or a targeted assessment of where AI delivers genuine efficiency gains and where particular caution is required.

AI can open up enormous opportunities — but only when expertise, clear processes and a sense of responsibility come together.

✨ Bonus resource on the topic: ✨ AI Regulation Checklist: We’veput together a handychecklist to provide a concise overview of the requirements.

Sources and further links:

https://artificialintelligenceact.eu/
Factsheet for small and medium-sized enterprises and start-ups
https://www.heise.de/news/AI-Act-Bundesregierung-bringt-KI-Gesetz-auf-den-Weg-11173623.html
https://www.bundesnetzagentur.de/DE/Fachthemen/Digitales/KI/start_ki.html
 

Transparency note on AI: AI assists me in creating the AI Snacks. However, the content is based on reliable sources, my experience from real-world projects and questions that clients repeatedly ask me on specific topics. Ultimately, each post contains a significant amount of my own original input.

Your point of contact for AI training courses and workshops

Inga Roser

Projektleitung Digitales Marketing / KI-Management und -Beratung

+49 7644 92092-17

About Inga

Inga Roser is an AI manager who helps companies future-proof their corporate communications. Her focus is on developing high-quality content systems that combine quality, efficiency and visibility.

Through workshops and training sessions, she provides practical guidance on how companies can use AI responsibly, develop clear standards and create content that resonates with people whilst remaining relevant to AI systems – from GEO and custom system prompts to automated content workflows and AI agents.

Feel free to contact Inga with no obligation if this is exactly the area you’re currently working on. Often, just a few concrete ideas or a concise team training session are enough to integrate AI into corporate communications in a meaningful way that delivers real added value.

=> CONTACT