Don’t be afraid of AI regulation: what the AI-MIG means for local authorities
Blog post
|
12.08.2026
Whether it’s a chatbot in the citizens’ service centre, automated document analysis at the planning office or translation assistance
At the Immigration Office: Artificial intelligence has long since been introduced in many town halls, or is at least on the verge of being introduced. As the range of possible applications grows, so too does the uncertainty as to which legal requirements apply to the use of AI by local authorities – and who is responsible for ensuring compliance.
Since 2 August 2026, most of the obligations under the European AI Regulation (Regulation (EU) 2024/1689 – AI Regulation, as last amended by Regulation (EU) 2026/1744) have been in force. In good time, the German legislature has now passed the Act on Market Surveillance and the Promotion of Innovation in Artificial Intelligence (AI-MIG): it sets out which authorities are responsible for enforcing the AI Regulation in Germany. For local authorities, it sets out a number of key directions – and, on closer inspection, the news is largely positive.
What the AI Regulation requires of local authorities
However, the substantive obligations of local authorities as operators of AI systems do not arise from the AI-MIG, but directly from the AI Regulation. These include, in particular, the development of sufficient AI expertise amongst staff (Article 4(1) of the AI Regulation) and transparency obligations, for example when using chatbots
(Article 50 of the AI Regulation). Furthermore, certain AI practices are prohibited – such as emotion recognition in the workplace (Article 5(1)(f) of the AI Regulation) – although this is unlikely to play a particularly significant role in day-to-day local government operations.
However, high-risk AI systems deserve particular attention: pursuant to Article 6(2) in conjunction with
According to Annex III of the AI Regulation, these include precisely those areas of application typical of public administration, such as the provision of basic public services, for example in the field of social assistance. Such systems are subject to stricter obligations on operators, including a fundamental rights impact assessment (Article 27 of the AI Regulation) and effective human oversight (Article 27(2) in conjunction with Article 14 of the AI Regulation).
Supervision remains within the country
In the Federal Republic of Germany, the Federal Network Agency is now officially the competent market surveillance authority, unless the KI-MIG provides otherwise (Section 2(1) KI-MIG). However, a separate rule applies to towns and local authorities: Where public bodies at state level – including local authorities – place AI systems on the market, put them into service or use them, market surveillance is the responsibility of the authorities competent under state law (Section 2(6), first sentence, of the KI-MIG). The Federal Network Agency will therefore not
keep a close eye on.
This was certainly a contentious issue during the legislative process. Most recently, the Bundesrat had come out in favour of centralising market surveillance at federal level, or, alternatively, of providing for the possibility of delegating this responsibility to the Federal Network Agency by means of an inter-state agreement. However, the Federal Government did not follow this line.
For local authorities, this means that the federal states must each determine for themselves which state authority is specifically responsible. So far, however – as far as can be seen – no federal state has designated such an authority. Given that the AI Act has only recently come into force, this is understandable and does not constitute grounds for suspending the use of AI. For local authorities, however, it means that their supervisory authorities simply do not yet exist and that they should closely monitor developments in their own federal state.
No registration, no fines
On the recommendation of the Digital Committee, the Bundestag has established a national, non-public register
for certain high-risk AI systems at the Federal Network Agency (Section 20 of the AI-MIG).
Apart from service providers, only operators that are federal public bodies are required to register there. State public bodies – and therefore also local authorities – are expressly exempt from this national registration requirement.
In addition, there is a clarification that is likely to provide reassurance in the local government sector: authorities and other public bodies within the meaning of the Federal Data Protection Act are, under Section 17(2) of the AI-MIG, largely exempt from potential fines. This is in line with the framework already established under data protection law (see Section 43(3) of the Federal Data Protection Act). Nevertheless, compliance with the AI Regulation remains an important compliance issue for local authorities, as other measures by the supervisory authority – such as prohibiting the use of a system – remain possible.
Support rather than sanctions: KoKIVO, BLA-KI and real-world laboratories
In other respects, too, the AI-MIG is clearly relying on support from the public sector. The Bundestag has further expanded the remit of the Coordination and Competence Centre for the Implementation of the AI Regulation (KoKIVO) at the Federal Network Agency:
The centre is intended to provide, for example, training and awareness-raising programmes, as well as general information
and provide non-binding guidance on judicial review to promote the consistent application of the law
(Section 5, sentence 2, no. 5 of the AI-MIG). As part of its efforts to promote innovation, the Federal Network Agency is also to develop information and guidance on the application of the AI Regulation, particularly for public bodies, and to advise them on the classification of AI systems as high-risk AI systems (Section 12 KI-MIG). A newly established Federal-State Committee on Artificial Intelligence (BLA-KI) may also ensure uniform standards for federal and state market surveillance authorities on the basis of specific test cases (§ 5, sentence 4, KI-MIG).
In addition, there are the so-called AI real-world laboratories: the Federal Network Agency is to establish at least one such laboratory (Section 13(1) of the KI-MIG, with reference to Articles 57 and 58 of the KI-VO); however, the relevant state authorities may also operate their own real-world laboratories.
The course is set in procurement
It should be noted that a local authority’s AI compliance is usually determined as early as the procurement process [Link to the news item]. Unlike with traditional IT procurement, it is often not sufficient to describe only the technical functions of AI systems. Contracting authorities should therefore clarify, prior to issuing the tender, which administrative problem the system is intended to solve, what data will be processed, and what risks arise for employees and members of the public. AI-specific requirements must then be set out in the tender documents – such as details of the model used and the training data, documentation and reporting obligations, as well as provisions for updates throughout the entire lifecycle. By enshrining these points in the contract, a significant portion of the burden of proof is shifted to where it belongs: the supplier.
The term „digital sovereignty“ is also becoming increasingly important. If an AI system runs on cloud infrastructure outside Europe, extraterritorial access rights – such as those under the US CLOUD Act – may affect the confidentiality and traceability of the basis for decision-making. In many cases, the sovereign availability of the infrastructure is therefore already being discussed as a prerequisite for AI-supported administrative decisions. Local authorities should therefore also take the origin and operation of the infrastructure into account as early as the service specification stage.
Conclusion
The federal supervisory framework of the KI-MIG has been criticised during the legislative process. These concerns cannot be dismissed out of hand, but they primarily concern the federal states in their role as supervisory bodies. From the perspective of the local authorities, as the bodies subject to supervision, the situation looks more favourable: supervision remains in the hands of the federal states and is therefore closer to the structures of local government. At the same time, support services are being expanded through KoKIVO, BLA-KI and the real-world laboratories.
Administrative procedure law remains an area requiring further work: the Administrative Procedure Act (VwVfG) does not yet recognise a separate category for AI-supported decision-making, and Section 35a of the VwVfG permits fully automated administrative acts only where there is neither discretion nor scope for judgement. Until the federal legislature introduces further differentiation in this area (or corresponding enabling provisions are created at state level, as Bavaria is currently planning to do [Link to the news item], local authorities would be well advised to use AI systems solely as a tool for preparing decisions. Ultimate responsibility must remain with humans in a way that is transparent and traceable, and the key steps in the process must be documented. None of this, however, provides a reason to put one’s own use of AI on hold. After all, anyone who uses these new tools and keeps a close eye on their own systems has no reason to fear the new regulatory framework.
My recommendation
With the AI-MIG, the legal framework for the use of AI at local authority level is becoming increasingly clear. Concerns that the use of AI is too legally uncertain for local authorities are becoming increasingly unfounded. There is therefore no reason why local authorities should not take the lead now
should – specifically, I recommend:
- Carry out an inventory: Record all AI systems currently in use and those planned for future use – including those „included“ in specialist software or office software.
- Clarify roles: For each system, check whether the local authority is merely an operator or – for example, in the case of systems it has developed itself or significantly modified – could be regarded as a provider. Different obligations apply depending on this classification.
- Initiate a high-risk audit: Check systems relating, for example, to the granting of benefits, staff recruitment or administrative procedures for a possible high-risk classification, and plan how to fulfil the relevant obligations.
- Ensure human supervision and documentation: Determine who is responsible for reviewing and taking responsibility for AI-generated results, and document the key system requirements and work steps.
- Building AI expertise: Train staff, making good use of the upcoming programmes offered by KoKIVO.
- Keeping an eye on responsibilities: Keep track of the appointment of the market surveillance authority in your own country and designate an internal point of contact for AI-related matters at an early stage.
- Adjust procurement: Before awarding AI contracts, carry out a structured needs and risk analysis; set out in the tender documents the obligations of tenderers to cooperate, provide information and keep details up to date throughout the entire life cycle, whilst also taking into account the digital sovereignty of the infrastructure used.
The mind behind the article.
Michael Jessen-Lieberum is Rechtsanwalt at DOMBERT Rechtsanwälte. He specialises in the legal aspects of the digitalisation of public administration and the government’s use of AI systems.