Our Expert in Germany
No results available
Who this guide is for: Management boards, supervisory boards, general counsel, chief compliance officers and in-house legal teams in German corporates.
What you will get: A clear allocation of duties, a side-by-side comparison table for boards, actionable roadmaps for management and supervisory boards, contractual and procurement checklists, sample reporting templates, and a ready-to-use FAQ for board packs and compliance teams.
The EU AI Act Germany compliance picture has moved from theoretical debate to operational reality, and in 2026 boards face a supervisory environment that expects demonstrable action rather than good intentions. Regulation (EU) 2024/1689 (the “AI Act”) entered into force on 1 August 2024 and applies in phases: certain prohibitions and AI literacy obligations began to apply from 2 February 2025, rules on general-purpose AI models from 2 August 2025, and the bulk of the high-risk obligations apply from 2 August 2026, with certain obligations for high-risk systems that are safety components of regulated products applying from 2 August 2027.
Because the AI Act is a Regulation, it applies directly in Germany without transposition, although national implementing measures (including the designation of competent authorities) are being finalised. This guide is written for management and supervisory boards, general counsel and compliance leaders in German companies who need concrete, board-level steps to manage AI risk and reduce personal and corporate liability. What follows is a prescriptive playbook, not a survey, designed to be lifted directly into board minutes, compliance workstreams and vendor negotiations.
The Regulation establishes a risk-based framework that classifies AI systems and imposes graduated obligations on the organisations that build and deploy them. For German boards, the essential task is to understand where your systems fall within that framework and which obligations flow to your company as a provider, a deployer, or both. The EU AI Act Germany compliance exercise begins with definitions and classification, because everything downstream, documentation, conformity assessment, monitoring, depends on getting the categorisation right.
The Act applies across sectors and reaches organisations placing AI systems on the EU market or putting them into service, as well as those deploying such systems, and it can apply extraterritorially where the output of a system is used in the EU. The core definitions distinguish an AI system from conventional software, a provider (the entity that develops or has an AI system developed and places it on the market or puts it into service under its own name) from a deployer (the entity using the system under its authority), and a high-risk system from lower-risk categories.
These definitions and the legislative objectives are set out in the AI Act itself and in the European Commission’s accompanying materials, and boards should anchor their internal classification policy to that primary text rather than to secondary summaries.
High-risk classification is the trigger for the most demanding obligations, so understanding which AI systems are classified as high-risk is the first substantive board question. The framework captures AI used in areas such as employment and worker management (recruitment screening, performance evaluation), access to essential private and public services (including creditworthiness assessment and credit scoring, subject to the Act’s exceptions), certain critical infrastructure, education and vocational training, and safety components of regulated products, as set out in the AI Act and its annexes. For German industry, the practical exposure is concentrated in finance (credit decisioning, model-driven underwriting), healthcare and medical devices (diagnostic support systems), and HR technology (automated CV filtering and candidate ranking).
A system’s placement in one of these categories materially expands the compliance burden and, correspondingly, the board’s oversight duty. Boards should treat classification as a documented, defensible decision, not an informal judgement, because regulators and litigants will scrutinise how the determination was reached.
For high-risk systems, providers and deployers must operate a range of controls that map directly onto board oversight responsibilities. For providers these include a documented risk management system that runs across the lifecycle of the AI system; data governance measures addressing the quality, relevance and representativeness of training, validation and testing data; comprehensive technical documentation and record-keeping (including automatic logging) sufficient to demonstrate compliance; a conformity assessment before the system is placed on the market or put into service; human oversight arrangements; and post-market monitoring together with serious-incident reporting. Deployers have their own, more limited set of obligations, including using the system in accordance with instructions, ensuring appropriate human oversight, and monitoring operation.
Each of these is not merely an engineering task, it is a governance obligation that the management board must implement and the supervisory board must monitor. The intersection with data protection law is significant: the European Data Protection Board and European Data Protection Supervisor have issued guidance relevant to data governance and data protection impact assessments, and cybersecurity controls should be aligned with guidance from the EU Agency for Cybersecurity (ENISA) on model robustness and incident response. Boards that fail to connect these regulatory strands leave gaps that enforcement will expose.
German corporate governance is dualistic: the management board (Vorstand or, in a GmbH, the Geschäftsführung) runs the business, while the supervisory board (Aufsichtsrat) oversees management. (Note that a supervisory board is mandatory for an AG but only required for a GmbH in defined circumstances, for example under co-determination legislation.) Allocating EU AI Act Germany duties across these organs is among the most important governance decisions boards must make, because it determines who acts, who monitors, and where liability crystallises if something goes wrong. The comparison table below is the centrepiece of this guide and should inform your delegation of duties and your board minutes.
Under the German Stock Corporation Act (Aktiengesetz, AktG), management board members owe a statutory duty of care under § 93 AktG and are protected by the business judgment rule only where they act on an adequately informed basis and in the company’s interest. Implementing an effective compliance and risk-early-warning system is a core management responsibility; failure to establish and maintain one where the company’s risk profile demands it can constitute a breach of duty. The supervisory board’s duty under § 111 AktG is to monitor management, and that duty is not passive, it requires the supervisory board to obtain adequate information, question management, and intervene where risk management is deficient.
AI risk now falls squarely within these established duties; the technology is new, but the governance principles are not.
The management board may delegate the operational execution of AI compliance to a named AI compliance lead or a cross-functional committee, but it cannot delegate away its supervisory responsibility for the compliance system as a whole. Effective delegation means clear mandates, defined reporting lines, and a cadence of reporting to the full management board and onward to the supervisory board. The supervisory board should insist on structured, periodic reporting and reserve certain decisions, such as approving the AI risk appetite and signing off on material high-risk deployments, to itself where appropriate.
Use the decision framework below to determine which board organ should take the lead on a given AI risk matter. The distinction is practical: management leads execution, the supervisory board leads strategic and oversight-failure questions. When the two overlap, document the interface explicitly in board minutes so that oversight is evidenced.
| Dimension | Management Board (Vorstand / Geschäftsführung) | Supervisory Board (Aufsichtsrat) |
|---|---|---|
| Legal basis of duties | Statutory duty of care and business judgment rule (§ 93 AktG); operational responsibility to implement compliance and risk systems | Oversight and appointment/removal powers; duty to supervise management and monitor risk management (§ 111 AktG) |
| Direct obligations linked to AI Act | Implementing AI Act obligations into processes, gap remediation, technical documentation, conformity assessments (as provider), incident reporting | Oversight: approving risk appetite, monitoring management’s AI risk programme, escalation, reviewing major AI deployments |
| Exposure to regulatory enforcement | Company-level sanctions apply; management may face administrative orders where statutory duties are breached or omissions occur | Generally oversight-level exposure; potential supervisory liability where a breach of the duty to supervise can be shown under German corporate law |
| Personal liability risk | Higher for executives who fail to implement required systems, leading to regulatory violations or duty-of-care claims | Arises if the supervisory board failed to monitor adequately or ignored known AI risks; standards vary by proof of breach |
| Practical near-term actions | 1) Map AI inventory; 2) classify systems; 3) appoint an AI compliance lead; 4) start conformity assessment for high-risk systems where a provider; 5) implement incident reporting | 1) Approve AI risk policy; 2) require regular reporting from management; 3) require external assurance or audit for high-risk systems; 4) set escalation triggers |
| Documentation & reporting | Maintain technical documentation, risk registers, post-market monitoring logs, vendor due-diligence records | Require board minutes evidencing oversight, a periodic AI risk dashboard, and an audit trail of queries and management responses |
| Vendor & procurement control | Conduct detailed AI vendor due diligence; secure contractual warranties, SLAs, audit rights, model transparency clauses | Approve procurement policy changes; require management to present vendor risk assessments for high-risk systems |
| Enforcement & sanctions | Administrative fines, deployment bans, corrective orders; company reputational risk | Sanctions typically focused on the company, but members may face derivative claims; regulators may require governance fixes |
| Timing & urgency | Immediate: inventory and initial risk assessment within c. 3 months; remediation plan within c. 6 months | Immediate oversight setup within 1–2 months; board-level policy adoption within c. 3 months |
| Escalation & external counsel | Engage external AI/compliance counsel for high-risk conformity assessments or cross-border incidents | Consider independent expert review or a special committee for material AI risk |
Choose Management Board lead when:
Choose Supervisory Board lead when:
The management board owns execution. The roadmap below sequences AI risk management for boards into concrete phases with indicative timelines, so that the board can demonstrate a structured, informed approach if challenged. Treat each phase as a deliverable with an owner, a deadline and a documented output. The indicative timings below are practical planning suggestions, not statutory deadlines; the binding dates are those set out in the AI Act itself.
Begin by creating an AI inventory that records every AI system in use or under development, its business owner, its function and its data inputs. Run a first-pass classification to flag potential high-risk systems using the Act’s categories. Appoint an AI compliance lead with a clear mandate and reporting line to the management board. Where a flagged system presents obvious near-term risk, for example, an automated hiring tool with no human oversight, impose immediate stop-gap controls such as mandatory human review pending full assessment. The goal in the first 30 days is visibility and containment.
With the inventory in place, design the risk management system that the Act requires for high-risk systems. This means defining how AI risks are identified, assessed, mitigated and monitored across each system’s lifecycle. Begin conformity assessment mapping, identify which systems require assessment, which route applies, and what documentation is missing. Stand up data governance processes addressing the quality and provenance of training, validation and testing data, coordinating with data protection obligations and any required data protection impact assessments consistent with EDPB and EDPS guidance. Establish logging and record-retention protocols so that system behaviour is traceable. Review vendor contracts and identify where audit-clause triggers and model-transparency obligations are absent, flagging these for renegotiation.
This phase converts the inventory into a working AI Act compliance programme.
Complete conformity assessments for high-risk systems where you act as provider, and implement mitigation for every gap identified during mapping. Where a system cannot be brought into conformity, the board must decide whether to remediate, retire or replace it, and record that decision. Deliver training programmes so that operational teams understand their obligations, particularly around human oversight and incident escalation; note that the Act’s AI literacy obligations already apply. Critically, integrate AI controls into your existing compliance management system (CMS) and information security management system (ISMS) rather than building a parallel structure; alignment with recognised frameworks such as ISO/IEC 27001 (and emerging AI management standards such as ISO/IEC 42001) reduces duplication and strengthens the evidentiary record.
By the end of month six, the management board should be able to show a documented compliance position for all high-risk systems, which is the core of credible AI governance practice in Germany.
Compliance is not a project with an end date. Establish incident reporting protocols that define what constitutes a reportable serious incident, who is notified internally, and the timeline for external reporting to the competent authority as required by the Act. Institute periodic model performance reviews to detect drift, degradation or emerging bias, and apply change control to every model update so that modifications are assessed before deployment. Maintain and update technical documentation continuously, treating it as a living record rather than a one-off deliverable. Prepare for regulator queries and market surveillance by rehearsing how the company would respond to a request for documentation, a dry run will expose weaknesses before a regulator does.
Draw on ENISA guidance to keep security controls and incident response current as threats evolve. This ongoing discipline is what distinguishes durable EU AI Act Germany compliance from a snapshot that decays the moment it is signed off.
The supervisory board’s task is oversight, and oversight must be evidenced to be effective. Supervisory board obligations in relation to the AI framework are not satisfied by receiving management assurances at face value; the board must demand structured information, test it, and record its scrutiny.
The supervisory board should support and monitor adoption of a board-level AI policy that defines the company’s risk appetite for AI deployment, what is permitted, what requires escalation, and what is prohibited. The policy should specify the classification standard, the approval thresholds for high-risk deployments, and the reporting obligations owed by management. Deliberation should be minuted to show the board understood the risks it was accepting. The policy is the anchor against which all subsequent oversight is measured.
Set a defined reporting cadence, for example quarterly, and more frequently for companies with significant high-risk exposure. Require management to deliver an AI risk dashboard with clear KPIs: number of high-risk systems, conformity assessment completion rates, open remediation items, incidents reported, and vendor risk status. Use red-amber-green indicators so that deterioration is visible at a glance. Define red flags that trigger escalation to the full supervisory board or a committee, such as a missed conformity deadline, a material incident, or a regulator contact. Dashboards without escalation triggers create the appearance of oversight without its substance.
For material high-risk systems, the supervisory board should consider commissioning independent assurance rather than relying solely on management’s self-assessment. Independent technical audits, external conformity reviews, or expert briefings give the board an objective basis for its oversight and strengthen its position if liability is later alleged. Engage external experts when management lacks the technical depth to assess a system, when a material incident occurs, or when a significant new high-risk deployment is proposed. The cost of independent review is modest against the exposure it mitigates.
Documentation is the supervisory board’s principal defence against liability. Minutes should record not only decisions but the questions the board asked, the information it received, and the responses management gave. Where the board escalated a concern, the record should show the escalation, the action demanded, and the follow-up. Maintain an audit trail linking supervisory queries to management responses over time, so that a pattern of active, informed oversight is demonstrable. Under German law, the difference between a supervisory board member who is exposed and one who is protected often turns on whether contemporaneous records show that the board discharged its duty to monitor.
Treat minute-taking as a compliance control in its own right, and use a standard template so that oversight is captured consistently.
Much of a company’s AI exposure is imported through third-party systems, which makes AI vendor due diligence and contractual control a frontline defence. Boards must ensure that procurement processes are updated so that AI risk is assessed before a system is acquired, not after it fails.
Before contracting for any AI system, the buyer should require and assess:
Record the assessment in a vendor due diligence scorecard so that the board can see, and evidence, that risk was assessed before acquisition.
Contracts should convert due diligence into enforceable obligations. Require representations and warranties as to AI Act compliance and data provenance; ongoing compliance covenants; audit rights allowing the buyer or its auditors to verify compliance; model update notification obligations so that material changes are disclosed before deployment; and clear allocation of responsibility for conformity assessment where roles could be contested. Scrutinise proposed liability caps and exclusions carefully: a vendor cap that leaves the deployer exposed to the full weight of regulatory sanction for a defect in the vendor’s system is not acceptable and should be resisted or offset by indemnities.
In transactions, AI assets require specific diligence. Buyers should require sellers to disclose their AI inventory, classification decisions and conformity status, and should test those disclosures against the underlying documentation. Reps and warranties should cover AI Act compliance, data provenance and the absence of known material AI incidents. Consider escrow arrangements for models or for the funds needed to remediate identified gaps, and use purchase price adjustments where diligence reveals non-conformity. Where remediation cannot be completed before closing, negotiate a post-closing remediation schedule with defined milestones and remedies for failure.
AI risk that is invisible in a data room will surface as a liability on the buyer’s balance sheet, so integrate AI diligence into the standard transaction workstream rather than treating it as a specialist add-on.
Understanding board duties in relation to the AI framework requires understanding how enforcement translates into legal risk for the company and for individual directors. The exposure operates on two levels: regulatory sanction against the company, and personal liability under German corporate law.
The Act empowers authorities to impose administrative fines, to issue corrective orders requiring remediation, and to restrict or prohibit the deployment of non-compliant systems. The Act sets tiered maximum fines, the highest tier, for breaches of the prohibited-practices rules, can reach up to €35 million or 7% of total worldwide annual turnover, whichever is higher, with lower ceilings for other infringements; the applicable figure will depend on the nature of the breach and the enforcement decision. For a business whose operations depend on a high-risk system, a deployment restriction can be more damaging than the fine itself. Regulators may also require governance changes as a condition of continued operation.
The company-level consequences, financial, operational and reputational, are the primary driver for board action, and they escalate where non-compliance is systemic rather than isolated.
Personal liability under the AktG arises where a management board member breaches the duty of care under § 93 AktG, for example, by failing to implement a compliance system that the company’s risk profile required, and that breach causes loss. Supervisory board members can face liability under § 116 AktG where they failed to monitor adequately or ignored known risks. In both cases, the decisive factor is frequently documentation: a director who can show that decisions were made on an adequately informed basis, and that oversight was actively exercised and recorded, is far better protected than one who cannot. This is why the roadmaps above emphasise documented decisions and minuted scrutiny, they are not bureaucracy, they are protective evidence.
Review D&O cover, cyber and technology errors-and-omissions policies, and contractual indemnities together to identify gaps. AI-related claims can fall between traditional policy definitions, so confirm that AI exposures are addressed rather than assumed to be covered.
Assemble the following artefacts into board packs and compliance records so that oversight is consistent and evidenced:
EU AI Act Germany compliance in 2026 is a board-level obligation that rewards early, structured and well-documented action. Management boards must own execution, inventory, classification, conformity assessment, vendor control and monitoring, while supervisory boards must demand evidence, test it, and record their scrutiny. The comparison table and decision framework above indicate which organ leads; the phased roadmaps set out what to do and by when; and the documentation checklist gives you the artefacts to prove it. Boards that treat these steps as a genuine governance programme, integrated into their existing CMS and ISMS, will manage AI risk effectively and materially reduce both corporate and personal liability.
Given the phased application dates and the pace of supervisory activity, the prudent course is to begin now and to seek tailored legal advice on Germany-specific liability wording and template language before relying on any of it.
This article is provided for general information and does not constitute legal advice. Companies should obtain advice tailored to their specific circumstances.
See also our related coverage of Germany Compliance Changes 2026. For deeper practical guidance, consult our resources on AI vendor & procurement due diligence, AI in M&A diligence for German buyers, and integrating AI risk into your CMS & ISMS, as well as our GLE Compliance practice page for Germany and the GLE lawyer directory for Germany Compliance.
This article was produced by Global Law Experts. For specialist advice on this topic, contact Markus Bauer at RITTERSHAUS Rechtsanwalte PartmbB, a member of the Global Law Experts network.
posted 1 minute ago
posted 2 minutes ago
posted 13 minutes ago
posted 33 minutes ago
posted 1 hour ago
posted 1 hour ago
posted 1 hour ago
posted 2 hours ago
posted 2 hours ago
posted 2 hours ago
posted 3 hours ago
posted 4 hours ago
No results available
Find the right Legal Expert for your business
Send welcome message