Germany has launched AISI Germany, its own AI safety institute. The new institute is intended to examine the risks and safety questions of advanced AI models and strengthen Germany’s resilience against AI-related threats. In the first phase, the BSI and the Federal Network Agency will play a central role, with the BSI contributing in particular the cybersecurity perspective.
This does not create an immediate new obligation for companies. Nevertheless, the development is an important signal: AI is no longer viewed only as an innovation or efficiency topic. It is increasingly being understood as a question of security, resilience and governance.
Key Takeaways
Germany is building its own AI safety institute with AISI Germany. The goal is to better understand and assess the capabilities, risks and safety issues of modern AI systems.
The BSI plays a central role, especially in connecting AI and cybersecurity. This makes one thing clear: AI security is becoming part of the national security and resilience agenda.
For companies, this does not create a direct new compliance obligation. However, GRC and security leaders should take the development seriously because it shows where supervision, regulation and security expectations are heading.
Why an AI Safety Institute Matters
AI systems are becoming more powerful, more widely used and more deeply integrated into business processes. At the same time, risks are increasing. These include manipulation, data leakage, uncontrolled model use, automated attacks, deepfakes, incorrect outputs and new dependencies on large AI platforms.
An AI safety institute is intended to better research and assess exactly these risks. The question is not only whether AI is legally permitted. The question is whether AI can be used safely, reliably and in a controlled way.
This is an important shift in perspective. While many companies have so far associated AI governance mainly with the EU AI Act, the security dimension is now moving more strongly into focus. Which models are being used? Which providers are behind them? Which data flows into them? Which misuse scenarios exist? And how can the use of AI be controlled?
AI Governance Does Not End with the AI Act
The EU AI Act remains the most important regulatory framework for AI in Europe. But the launch of AISI Germany shows that AI governance is being understood more broadly. In addition to legal obligations, cybersecurity, resilience, model behaviour, provider dependencies and technical risk management are becoming more important.
For companies, this means that an AI policy alone will not be enough in the long term. Any organisation using AI in production should know where AI systems are used, which risks exist and which controls are in place. This is particularly important for generative AI, agentic AI, automated decisions, customer communication and security-relevant processes.
Even though AISI Germany does not create a new corporate obligation, it will shape the discussion around safe AI use. Recommendations, tests, risk assessments and international cooperation may influence over time what is considered good practice for AI security.
What GRC Teams Should Take Away
For GRC leaders, the most important message is that AI needs to be integrated into existing governance structures. AI security should not sit in isolation with innovation teams or individual business units.
A pragmatic starting point is useful. Companies should maintain an AI inventory, clarify responsibilities, prioritise critical use cases and assess provider dependencies. For external AI platforms in particular, it is important to understand which data is processed, which security commitments exist and how changes to the system are monitored.
Internal controls will also become more relevant. These include approvals for new AI use cases, rules for sensitive data, monitoring of outputs, employee training and clear escalation paths for incidents or problematic system behaviour.
Conclusion: AI Security Is Becoming Mature
With AISI Germany, AI security now has an institutional home in Germany. This is not a new obligation for companies, but it is a clear signal: the secure use of AI is becoming a fixed part of modern governance.
For GRC leaders, it is worth looking ahead. Companies that create transparency today around AI use cases, risks, providers and controls will be better prepared when security requirements and regulatory expectations become more concrete.
AI governance does not begin with the next mandatory requirement. It begins with the question of whether a company can reliably control its AI use at all.
FAQ
What is AISI Germany?
AISI Germany is the new German AI safety institute. It is intended to examine the risks, capabilities and safety issues of advanced AI systems.
What role does the BSI play?
The BSI contributes primarily the cybersecurity perspective. This strengthens the connection between AI security, cyber resilience and technical governance.
Does this create a new obligation for companies?
No. The launch of the institute does not create an immediate new compliance obligation for companies.
Why is the topic still relevant?
Because it shows that AI security is moving further into the focus of policymakers, supervisory bodies and security authorities. Companies should therefore think about AI governance not only from a legal perspective, but also from a security perspective.
What should companies do now?
A pragmatic first step is an AI inventory. Companies should know which AI systems they use, who is responsible, which data is processed and which risks exist.
Table of Contents
- Key Takeaways
- Why an AI Safety Institute Matters
- AI Governance Does Not End with the AI Act
- What GRC Teams Should Take Away
- Conclusion: AI Security Is Becoming Mature
- FAQ
- What is AISI Germany?
- What role does the BSI play?
- Does this create a new obligation for companies?
- Why is the topic still relevant?
- What should companies do now?