Germany is establishing an AI Security Institute to systematically assess the risks posed by AI models. The Federal Office for Information Security (BSI) and the Federal Network Agency will henceforth examine AI systems for threats to national security. This marks a new focus in German AI governance and concretizes the implementation of the EU AI Act at the federal level.
Key Facts
- BSI and Federal Network Agency receive AI model assessment mandates
- Focus on threats to national security
- New institute embedded in German AI governance framework
- Advancing EU AI Act implementation at federal level
Who Does What?
The BSI traditionally handles cybersecurity and IT protection. The Federal Network Agency regulates telecommunications and energy infrastructure. Together, they bring complementary expertise: the BSI possesses deep technical security competence, while the Federal Network Agency has experience regulating critical infrastructure. Together, they will develop an assessment procedure to evaluate AI models for risks before deployment in sensitive sectors.
The German government recognizes that AI systems pose significant security challenges alongside opportunities. An AI model could theoretically be manipulated to spread disinformation, influence critical infrastructure, or enable data abuse. The new institute aims to identify such scenarios early.
Aligned with EU Regulation
The establishment of the AI Security Institute is not an isolated step—it follows the EU AI Act, which categorizes AI systems by risk level and imposes strict requirements for high-risk AI. Germany is now concretizing how these EU requirements will be implemented nationally. Other EU member states are watching this move closely, as a German solution could set a precedent.
Assessing AI models is technically complex: it involves not only the models themselves but also their training data, application contexts, and potential misuse scenarios. The BSI and Federal Network Agency must develop standards that are reproducible and internationally comparable.
What This Means for Business
For German AI developers and operators, the new institute could become a key contact point. Those developing or deploying AI models—particularly in critical sectors like energy, transport, or healthcare—may face mandatory government assessment in the future. This creates clarity but could also extend development cycles. At the same time, it signals that Germany takes AI security seriously and builds trust with citizens and partners. Companies should engage early with the BSI and Federal Network Agency to ensure their systems are future-proof.
Sources
Editorially owned by Ideal Syka. Sources and method: Newsroom & method. Tips and corrections: ai@i6eal.de.




