Local AI: Governance Before Hardware Purchase
Benedikt Langer
10 min readFour developments over two weeks show that locally operated AI goes far beyond the tech stack. ...
9 Min. read time
As of late May 2026, around 11,000 affected companies in Germany still lack BSI registration-and the legal deadline expired on March 6. What’s being called a “grace period” is, according to law firms, merely regulatory forbearance until July 31, 2026: the BSI expects late filings but isn’t extending the statutory deadline. For management, Section 38 of the BSIG sets the bar: risk management must be approved, implementation monitored, and training documented. A single portal click won’t suffice.
Key Takeaways
RelatedSovereign AI: responsibility stays in-house / AI writes the code. Who’s liable?
The public debate fixates on reporting channels and portal logins. The tougher question lies elsewhere: What can be proven when an incident, regulatory scrutiny, or internal recourse targets management? Simply catching up on registration while leaving the evidence framework unaddressed swaps one visible gap for an invisible one.
The legal situation is clearer than many headlines suggest. The statutory registration deadline under the BSI Act expired on 6 March 2026. The BSI itself states on its information page: The legal deadline has passed. Those affected who are still unregistered should act immediately.
What runs until 31 July 2026 is, according to widespread law firm interpretation, administrative tolerance – a form of enforcement discretion. It is not a statutory extension of the deadline. In its letter to business associations, reported by heise online among others, the BSI assumes that all outstanding registrations will be completed by 31 July 2026 at the latest. This is a statement of expectation and prioritisation; the word “tolerance” does not appear in the BSI’s letter. The BSI’s information page simultaneously states: The legal deadline has passed. Anyone registering now remains formally in default – enforcement discretion does not retroactively remedy the breach of duty. This distinction separates operational relief from legal cure.
The figures explain why the authority is proceeding this way. Of around 29,500 affected companies in Germany, only about 11,500 had registered by the statutory deadline. By the end of May, the number stood at around 18,500. As of the end of May 2026, a gap of around 11,000 obligated parties remains. Enforcement discretion is thus also an admission: enforcement has encountered an economy that underestimated the timeline.
A registration violation remains subject to fines. Under Section 65 BSIG, the institution faces fines of up to 500,000 Euro. The fine targets the institution. The natural person in a leadership role is not the addressee of this fine provision. More serious for executives is the internal liability under Section 38(2) BSIG: Anyone who violates the duties under paragraph 1 is liable to their own institution for damages caused by negligence – according to the corporate law rules of the respective legal form. The registration record protects precisely in cases of recourse. The fine remains a side issue. The ability to seek recourse determines the personal risk for leadership.
§ 38 BSIG places responsibility squarely on the leadership level. Executive management must approve risk management measures, monitor their implementation, and undergo training on cyber risks. BSI President Claudia Plattner puts it literally: executives are “obliged to implement risk management measures, monitor their implementation, and undergo training on the assessment and management of cyber risks.” Operational tasks can be delegated to CISOs, IT leadership, or external service providers-but ultimate responsibility remains.
Delegation does not absolve accountability. Appointing a CISO and dropping the topic from the agenda does not fulfill the duty. The obligation to approve and oversee remains. If there is no written approval, no quarterly reports to leadership, or no proof of executive training, an audit will reveal a gap-even if the data center’s technology is running smoothly.
§ 30 (1) sentence 3 BSIG requires organizations to document compliance with their risk management obligations. The focus is on proving the measures taken under this duty. In a crisis, those who cannot present documentation risk sanctions-regardless of whether much was “somehow” handled operationally. Consulting experience reveals a consistent pattern: technical controls are often in place, but records of management decisions, approvals of security concepts, and leadership training are missing.
Whether the Business Judgment Rule (BJR) offers protection in the NIS-2 context remains legally unresolved-case law is lacking. A common interpretation among law firms draws a sharp line: the BJR protects business discretion, but under this reading, it does not cover mandatory obligations under § 38 BSIG. Where § 38 BSIG explicitly requires approval, oversight, and training, there is no room for discretion-the BJR simply does not apply. Gaps in training and documentation thus constitute independent breaches of duty, whether for a sole managing director of a GmbH or a multi-member executive board.
Consultants often pitch leadership seminars and tool roadmaps. The weak spot? Proof. Leaving a workshop without a resolution protocol means you’ve attended an event-not created an audit trail. The DACH region’s reality adds pressure: works councils and data protection requirements impact monitoring and training formats. Co-determination and commissioned processing don’t block compliance, but both demand early involvement-otherwise, documentation stalls the moment protocols and attendance lists must meet formal standards.
Shifting perspectives is easy to articulate but hard to execute. The critical question becomes: Which document supports which claim? Who signed it, and when? Two columns separate assertion from evidence.
Unsubstantiated Claims
Provable in a Crisis
Three risks will shape the coming months. First: Registration is completed, but the evidence file remains patchy-visibility increases, but defensibility does not. Second: Multiple managing directors share responsibility in a way that leaves no one signing off on approvals. Third: After July 31, 2026, regulators will target laggards without portal entries or documentation trails. Ownership is the scarce resource: Who maintains the evidence file? Who approves management training and record-keeping? Who escalates when the CISO reports and the agenda stays silent?
Sources don’t always align. Law firm and association briefings often mention a “grace period,” suggesting delayed compliance can be remedied. But the BSI’s wording is stricter: The legal deadline has passed, and while the authority expects late registrations by July 31, 2026 (heise online, June 17, 2026), “tolerance” is a legal interpretation of enforcement discretion-not a term found in the BSI’s statement. Digital Chiefs endorses this reading because it sharpens leadership’s decision-making: act now and build evidence in parallel. No cure for delay should be expected.
The first step isn’t buying a tool. It’s compiling a file with five key elements within ninety days-driven by senior management and operationally supported by the CISO and legal teams.
Days 1–30: Status and gap mapping. Clarify or confirm your exposure. Verify your registration status in the BSI portal and complete any pending access requirements (ELSTER/MUK). In parallel: take inventory of existing documents-risk assessments, ISMS scope, incident and continuity plans, and previous board resolutions. Anything missing gets an owner and a deadline.
Days 31–60: Approval and training. Senior management formally approves the risk management framework and action plan. The minutes document the scope, exceptions, and responsible parties. Mandatory executive training is scheduled and recorded-with attendance lists and documented content. The CISO delivers the first written monitoring report to leadership.
Days 61–90: Operational rhythm. Establish a quarterly calendar for leadership reports, reporting channels, and escalation procedures. Assign roles in the BSI portal for registration and incident reporting. Address gaps from the inventory with deadlines and budget owners. Those who’ve only ticked off registration have met half their obligations. Those who maintain an evidence file can respond when it matters.
The trade-offs are real. Speed in registration without documentation quality creates a false sense of security. Perfectionism in the file without portal registration leaves the most visible obligation unmet. The smart move: use the post-registration window to build provability within the same ninety days. It’s unglamorous. But it’s what regulators and liability claims will scrutinize later.
Executives who face personal liability know the difference between “we’re handling it” and “we can prove it.” NIS-2 doesn’t treat this as a matter of style. It makes it a leadership obligation with personal risk-especially when your own organization seeks recourse.
No. The statutory deadline expired on 6 March 2026. According to a letter from the BSI to industry associations, the agency expects late registrations until 31 July 2026, which law firms interpret as a grace period (enforcement discretion). However, this is not a legal extension of the deadline, and late submissions do not retroactively remedy the delay.
No. While operational tasks can be delegated, management remains responsible for approving risk management measures, overseeing their implementation, and completing their own training. Without documented oversight, liability risks stay firmly with the executive level.
Key documents include recorded approvals, up-to-date risk assessments, ISMS evidence, management training records, incident and continuity plans, and the BSI registration confirmation. § 30 (1) sentence 3 BSIG requires proof of compliance with risk management obligations. Missing documentation can lead to penalties-even if measures were actually in place.
A registration violation can result in fines of up to 500,000 euros for the organization under § 65 BSIG. Additionally, management may face internal liability claims from their own company under § 38 (2) BSIG for negligent breach of duty. Once the late registration window closes, stricter enforcement is expected.
Unclear-and often overestimated. The Business Judgement Rule protects discretionary business decisions, but mandatory obligations under § 38 BSIG typically fall outside its scope. Without proof of training and a robust ISMS, the rule may not apply at all-and case law on NIS-2 is still lacking.
Read more on Digital Chiefs
Digital ChiefsToken-OPEX: Inference Controls, Not the Seat BudgetDigital ChiefsHardware Outperforms Software Deals – Rethinking Capital Expenditure PrioritiesDigital ChiefsThe Bill for Ten Years of Island SolutionsMore from the MBF Media Network
cloudmagazinKRITIS in the Cloud: Securing Your Migration mybusinessfutureCybersecurity Boom: How NIS2 is Transforming Germany’s Security Sector securitytodayThe AI Act Is Actually a Security LawImage source: AI-generated (July 2026)