German AI Regulation

The EU AI Act and German Implementation

The EU Artificial Intelligence Act (Regulation 2024/1689), adopted in August 2024 and entering into force in phases through 2027, establishes the first comprehensive horizontal regulatory framework for AI systems in the world. As a directly applicable EU regulation, the AI Act applies uniformly in Germany without requiring transposition into national law for most provisions. However, the Act leaves certain matters — particularly the designation of competent authorities, penalties, and the regulation of AI systems used for law enforcement and administrative purposes — to member state discretion. The Bundesregierung has proposed the Gesetz zur Regulierung Künstlicher Intelligenz (AI-Regulierungsgesetz), which designates the Federal Network Agency (Bundesnetzagentur, BNetzA) as the market surveillance authority (Marktüberwachungsbehörde) for AI systems under Article 64 of the AI Act. The BNetzA will coordinate with the Federal Commissioner for Data Protection and Freedom of Information (Bundesbeauftragter für den Datenschutz und die Informationsfreiheit, BfDI), the Federal Office for Information Security (Bundesamt für Sicherheit in der Informationstechnik, BSI), and BaFin to form a coherent German AI supervisory framework. The German implementation law also establishes a German AI Committee (KI-Ausschuss) composed of representatives from federal ministries, the Länder, and independent experts to advise the government on AI regulatory matters.

Data Protection Authority Guidance on AI

The German data protection authorities (Datenschutzbehörden), both federal and state-level, have been among the most active in Europe in issuing guidance on AI systems, particularly generative AI and large language models. The Conference of Independent Data Protection Authorities (Datenschutzkonferenz, DSK) published an orientation paper in 2023 on the application of the GDPR to AI systems, addressing the core tension between the GDPR’s principles of purpose limitation, data minimisation, and transparency on the one hand, and the operational requirements of AI training and inference on the other. The DSK has taken the position that the use of personal data for training AI models requires a legal basis under Article 6 GDPR, and that legitimate interest (Article 6(1)(f)) may be available only where the processing is strictly necessary and the interests of data subjects do not override the controller’s interests. The DSK has also addressed the question of whether AI-generated outputs containing personal data constitute a new processing of that data, and has held that the right to explanation under Articles 13–14 GDPR applies to automated decision-making, including AI-based systems, requiring controllers to provide meaningful information about the logic involved. The Hamburg Commissioner for Data Protection has been particularly active, issuing orders against companies using AI-based applicant screening systems without adequate transparency and conducting investigations into the processing of personal data by AI system developers.

AI in Administrative Procedures

German administrative law (Verwaltungsrecht) has begun to address the use of AI in public administration. The Verwaltungsverfahrensgesetz (VwVfG) was amended in 2024 by the Gesetz zur Digitalisierung von Verwaltungsverfahren to permit fully automated administrative decisions (vollautomatisierter Verwaltungsakt) under § 35a VwVfG, provided that the decision is not based on discretionary powers (Ermessen) or a margin of appreciation (Beurteilungsspielraum), and that the administrative procedure does not require human judgment. The provision was drafted specifically to accommodate AI-based decision-making in mass administrative procedures — such as the determination of social benefits, tax assessments, and exam grading — where the factual and legal criteria are sufficiently standardised that a machine can reliably apply them. The Bundesverfassungsgericht in the Recht auf algorithmische Entscheidung decision (BVerfGE 161, 1) held that the right to a hearing under Article 103(1) GG requires that an individual affected by an automated decision be given an effective opportunity to challenge it before a human decision-maker. The Bundesverwaltungsgericht has further held that AI systems used in administrative decision-making must be explainable (Erklärbarkeit) and that the authority bears the responsibility for ensuring that the AI system operates correctly — a principle it called Algorithmenverantwortung (algorithmic accountability).

Autonomous Driving Law

Germany was the first country in the world to enact a comprehensive regulatory framework for autonomous driving, with the Gesetz zum autonomen Fahren of 2021 and the subsequent Autonome-Fahrzeuge-Genehmigungs- und Betriebsverordnung (AFGBV). The legislation creates a legal framework for Level 4 autonomous vehicles (SAE classification) — vehicles that can perform all driving tasks under specific conditions without human intervention. The StVG was amended to introduce the concept of the technical supervisor (Technische Aufsicht) — a person who monitors the autonomous vehicle remotely and can intervene if the system fails. The autonomous vehicle must have a type approval (Typgenehmigung) from the Kraftfahrt-Bundesamt (KBA), and the manufacturer must demonstrate that the vehicle can comply with traffic rules, detect obstacles, and navigate safely. The legislation also imposes strict liability on the vehicle keeper and the manufacturer, with liability caps of €10 million for personal injury and €2 million for property damage. The data recorder (Datenrecorder) mandated by the StVG records sensor data continuously during autonomous operation, and this data is available to accident investigators, law enforcement, and courts to establish liability. Germany’s approach has influenced the EU Regulation on Type-Approval of Automated Vehicles (Regulation 2022/1426), which creates a Europe-wide framework for autonomous vehicle approval.

Algorithmic Accountability

The Algorithmenaufsicht (algorithmic oversight) framework in Germany is emerging through a combination of sector-specific regulation and general principles. The NetzDG (Network Enforcement Act) requires social media platforms to disclose the criteria for automated content moderation decisions. The Medienstaatsvertrag (MStV) requires platforms operating media intermediaries to ensure non-discriminatory access and algorithmic transparency. The Gesetz gegen Wettbewerbsbeschränkungen (GWB, § 19a) empowers the Bundeskartellamt (Federal Cartel Office) to address algorithmic collusion and self-preferencing by digital platforms — a power it exercised in the Facebook case (Bundeskartellamt, 2019) prohibiting the combination of user data across platforms. The EU Digital Services Act (DSA) supplements national law with EU-level requirements for risk assessments, transparency reports, and algorithmic auditing for very large online platforms. The KI-Beirat (AI Advisory Council), established by the federal government in 2023, has recommended establishing a right to explanation for significant AI-based decisions in both the public and private sectors, directly inspired by Article 22 of the GDPR. The Bundesregierung’s 2024 AI strategy (KI-Strategie 2.0) commits to developing an AI liability framework that addresses the specific challenges of algorithmic harm, including the problem of the “black box” and the difficulty of proving causation in complex AI systems.