exterior view shows entrance Federal Office Protection

An exterior view shows the entrance to the Federal Office for the Protection of the Constitution (Bundesamt fuer Verfassungsschutz, BfV) in Cologne, western Germany on September 22, 2025.
INA FASSBENDER/AFP via Getty Images

Germany’s federal cabinet unanimously approved a 732-page draft law on August 12, 2026 that would give the country’s intelligence services the authority to conduct cyberattacks on foreign systems, sabotage adversaries’ supply chains, and inject false information into the communications of domestic surveillance targets — offensive and active powers that have been deliberately withheld from German spy agencies since the end of World War II. The same bill would enact the most rigorous statutory framework for regulating AI-generated surveillance outputs adopted by any Western democracy — a provision that the international coverage of the reform has almost entirely overlooked in the rush to report the hacking headlines.

Interior Minister Alexander Dobrindt, who presented the bill after the cabinet meeting, said the government was transforming its spy agencies into “genuine secret services.” The legislation rewrites the legal foundations of both Germany’s foreign intelligence service, the Bundesnachrichtendienst (BND), and its domestic security service, the Bundesamt für Verfassungsschutz (BfV), granting both agencies what the government calls “active, operational powers” for the first time in the postwar era. The bill must still pass the Bundestag, which returns from summer recess in early September; with the governing CDU/CSU and SPD coalition holding a parliamentary majority, passage is widely expected.

Postwar Restraint Was Never an Accident

Germany’s intelligence services have been deliberately confined to watching and reporting rather than acting for eight decades, and the reason is architectural, not bureaucratic. The Gestapo’s domestic terror apparatus and the Stasi’s pervasive surveillance of East German citizens left a political and constitutional inheritance that made operational intelligence powers toxic in German politics for generations. The BND was created on April 1, 1956 from the Gehlen Organization — itself a Cold War instrument built from Wehrmacht intelligence networks — and from its founding has been constrained by design against the kind of operational latitude exercised by the CIA’s Special Activities Center, France’s DGSE, or even Britain’s Secret Intelligence Service, whose statutory immunity framework covers acts abroad that would otherwise be unlawful without spelling them out publicly.

That restraint is now colliding with a security environment that officials say has changed qualitatively. Dobrindt cited daily drone incidents and sabotage by foreign powers as justification — a thinly veiled catalogue of Russian hybrid operations against Germany, which has been among Ukraine’s most significant military supporters. On the same day the cabinet approved the bill, Bloomberg reported that the CIA had warned European partners that Moscow was preparing to intensify sabotage campaigns and false-flag operations against European infrastructure. The confluence of the cabinet decision and the CIA warning on a single news day was striking, whether or not the timing was coordinated.

Germany is also not acting in isolation. On August 12, 2026 — the same day the German cabinet voted — the Trump administration signed a National Security Presidential Memorandum authorizing vetted private companies to conduct offensive cyber operations against foreign criminal networks, the first formal US program of its kind. The parallel suggests a broader Western recalibration of what offensive cyber authorization looks like in democratic legal frameworks.

What the Hacking and Sabotage Authority Actually Permits

The BND’s new offensive powers are extensive but operate within explicit constraints that keep them materially narrower than what allied agencies exercise. The bill authorizes cyberattacks on foreign IT systems operated by hostile state actors, including the authority to disrupt digital infrastructure and block financial payment flows. Chancellery Chief Nina Warken provided concrete examples: substituting faulty components into adversaries’ supply-chain deliveries, penetrating the IT systems of drone factories and chemical weapons laboratories to sabotage production, and disabling servers operated by state-sponsored hacker groups and disinformation networks.

The constraints are equally specific. Any major BND disruption operation would require the agency’s president to formally declare that a named foreign power is persistently threatening German interests — a declaration that expires after 12 months and must be reviewed every six. Operations must target the responsible state rather than individuals and, wherever equally effective, must be conducted outside Germany. The bill explicitly prohibits any measure that would endanger a person’s life or physical safety, meaning the BND has no path to anything resembling the CIA’s lethal paramilitary capabilities or the kind of extra-statutory latitude that Britain’s legal framework extends to SIS.

The domestic BfV gains a shorter but more constitutionally novel list of powers. The agency could block or reroute data traffic, alter transmissions in transit, corrupt data stored for use in an attack, and disable equipment about to be used against a target. Most significantly, the bill would allow the BfV to inject false information into communications of people it is monitoring inside Germany — a domestic disinformation capability that has no direct statutory equivalent in British, French, or American law. A spy agency that can manufacture false messages to steer the behavior of domestic surveillance targets is operating in territory that Germany’s postwar legal tradition never contemplated, and the absence of a comparable Western model means there is no established benchmark for evaluating the safeguards.

Telecommunications carriers and digital service providers would be compelled to assist both agencies. Non-compliance could result in fines or suspension of services, and compliant providers would be compensated.

A Constitutional Clock Is Running

The reform is not purely a political choice. Its most immediate legal origin is a Federal Constitutional Court ruling handed down on October 8, 2024, which held that the BND’s strategic surveillance of domestic-foreign telecommunications in the cyber domain was incompatible with Article 10 of the Basic Law — the constitutional guarantee of the secrecy of correspondence, postal, and telecommunications. The court allowed the existing rules to continue on a transitional basis only until December 31, 2026, creating a hard parliamentary deadline: if the Bundestag fails to pass a new framework before that date, Germany’s intelligence services will lose their current surveillance authority with no legal replacement in place.

The ruling also contains a doctrinal wrinkle that the government is leveraging. The Constitutional Court held that intelligence agencies could be permitted to operate at lower legal thresholds than police forces — precisely because, unlike police, they lacked operational powers. By granting operational powers, the new bill aligns the agencies with the court’s stated framework. Critics have flagged the paradox: once the agencies acquire operational powers, the court’s own justification for lower thresholds may no longer apply, potentially exposing the bill’s provisions to a higher proportionality standard than the government has calculated for.

Where Germany Leads: AI Surveillance Rules No Ally Has Written

The offensive cyber provisions dominate the political headlines, but they are not where the bill breaks the most technically significant new ground. A set of AI governance provisions buried in the 732-page text establishes, for the first time among major Western democracies, a statutory framework for classifying and constraining AI-generated intelligence outputs as intrusions in their own right.

The bill authorizes self-learning systems for intelligence analysis but prohibits discriminatory algorithms and requires that machine-generated outputs be spot-checked by a judge. More consequentially, it treats certain analytical products produced by those systems as privacy-intrusive in themselves: movement profiles, behavioral and personality assessments, and personalized predictions would require additional legal justification before an analyst could retrieve them, with the required threshold calibrated to how revealing the output is. The reasoning maps directly onto the Constitutional Court’s intrusiveness-calibration doctrine from the 2024 ruling — applying the same proportionality logic to algorithmic inference that the court applied to raw data collection.

A new oversight body would be required to review, every two years, whether new categories of machine-generated output had become equally revealing, triggering the stricter access rules automatically. This review mechanism is the most forward-looking element of the entire reform: rather than legislating a fixed list of protected output types that rapidly becomes obsolete as AI capabilities evolve, the bill builds in an adaptive governance cycle timed to catch capability changes before they outrun the legal framework. The United States, the United Kingdom, and France have none of this — their intelligence AI frameworks, where they exist at all, operate through classified policy rather than public statute.

Car Manufacturers Pushed Back Immediately

Among the provisions that landed with immediate industry pushback is a clause requiring automotive manufacturers and service providers to share vehicle telemetry data with the intelligence services on demand. Modern connected vehicles continuously transmit sensor, location, operational, and behavioral data to manufacturer servers, generating a stream of information that can reconstruct a vehicle owner’s movements, driving patterns, and indirect inferences about daily life with considerable precision. The EU’s connected vehicle security risks — particularly concerns about foreign state access — have been a growing policy focus since at least 2025.

The Verband der Automobilindustrie (VDA), Germany’s automotive industry association, published its response on August 12 — the same day the cabinet approved the bill. The VDA demanded that “telemetry data” be precisely defined in the legislation before any compliance obligation could attach, and insisted that manufacturers must not be required to collect or store additional data in anticipation of future intelligence requests — a provision that would effectively transform the industry into a pre-emptive surveillance infrastructure at government direction. The association also called for a clear legal distinction between the new intelligence obligations and Germany’s existing compliance requirements under European law, including the EU Data Act and the GDPR.

The legal tension is real. Vehicle telemetry that includes location and behavioral data qualifies as personal data under the GDPR. Germany’s own implementing law for the EU Data Act — the DADG — entered into force on May 30, 2026, giving the Federal Network Agency authority to enforce data-access rights for connected-product data. A new intelligence statute mandating on-demand government access to the same data streams creates a layered compliance problem that legal experts have already flagged as a genuine conflict: GDPR Article 23 permits member states to restrict data rights for national security purposes, but those restrictions must be both necessary and proportionate — standards that will almost certainly be tested in court.

One observer with specific technical concern is Dr. Thorsten Wetzling of the Interface EU research institute, who flagged whether vehicle telemetry access might be routed through commercial data brokers rather than directly from manufacturers — a pathway that would raise distinct questions about the privacy-preservation standards applied and the security of the data in transit.

Opposition Splits Along Predictable and Unpredictable Lines

Konstantin von Notz, the Greens’ deputy chairman of the parliamentary intelligence oversight committee, has offered the most nuanced public position: he accepts that expanded BND powers are justified by the current threat environment but argues that specific provisions — particularly the BfV’s expanded domestic authorities — risk crossing the constitutional line between intelligence collection and police enforcement, a separation that German law has deliberately maintained since the Nazi era. “This reform represents a fundamental departure from existing norms,” von Notz told reporters, warning that the legislation would “end up before the Federal Constitutional Court.”

The Gesellschaft für Freiheitsrechte (GFF), the civil liberties organization that successfully challenged the BND’s surveillance practices in the 2024 Constitutional Court ruling, has stated it plans to challenge the new legislation as well. GFF’s track record gives that warning credibility: the organization has successfully argued before the Federal Constitutional Court that BND surveillance powers violated the Basic Law, and it has specifically flagged the insufficient documentation of rights intrusions and the inadequacy of oversight mechanisms as the court’s own points of vulnerability.

Germany’s Federal Data Protection Commissioner, Louisa Specht-Riemenschneider, raised a concern that the parliamentary debate has not yet adequately addressed: the new Independent Control Council — the body that would serve as the primary oversight and complaint mechanism for intelligence activity — is not expected to begin operations until early 2029. During the transition period, citizens who believe they have been unlawfully surveilled would effectively have no functioning complaint mechanism. The Commissioner also questioned whether the bill’s provisions for indefinite retention of data gathered from open sources would survive constitutional scrutiny.

The AfD’s Gottfried Curio denounced the proposal as “a deliberate attempt to blur the line” between intelligence collection and policing, describing it as arrogant overreach by the government. The AfD’s position is complicated by the fact that the BfV has for years scrutinized the party under suspicion of harboring extremism, giving the agency expanded surveillance authority over its own political opponents in the opposition — a circumstance that makes the AfD’s civil liberties objections simultaneously principled and self-interested.

What Parliament Will Examine Before Voting

The Bundestag, which reconvenes in early September, has the authority to amend the bill before a final vote. Parliamentary scrutiny is expected to focus on at least four unresolved questions. First, who below the BND’s president may authorize active disruption operations at speed — a question that the 12-month declaration framework does not fully answer for time-sensitive operations. Second, how offensive operations affecting infrastructure outside Germany will be coordinated with European allies and with the EU’s emerging cyber defense architecture under the NIS2 Directive and the proposed Cyber Solidarity Act. Third, under what circumstances journalists, lawyers, and clergy whose communications enjoy professional confidentiality protection might be caught in the BfV’s expanded domestic surveillance net — the bill’s current language does not fully insulate these professional relationships. Fourth, what remedy will be available to individuals later found to have been unlawfully monitored during the period before the Independent Control Council becomes operational.

Germany’s intelligence reform will also carry implications beyond its borders. Germany is a significant intelligence partner to the United States, the United Kingdom, and France, and the new operational authorities will interact with allied intelligence-sharing arrangements in ways that are not yet clearly defined. As one of the largest economies in Europe and the most significant financial supporter of Ukraine among EU member states, Germany’s decision to bring its spy agencies to operational parity with allied counterparts represents a shift in European strategic posture as well as in domestic law.

The BND’s annual budget has already grown to €1.51 billion this year (approximately $1.75 billion USD at mid-market rates as of August 15, 2026) — a roughly 25 percent increase in the current year — with further growth expected. Money alone, BND officials have said, cannot substitute for legal authority. The December 31 deadline changes that calculus: Germany’s intelligence services are acquiring both, under the pressure of a constitutional clock that no parliament can stop.

Frequently Asked QuestionsWhat specifically can Germany’s BND and BfV now do that they could not before?

The 732-page bill, approved by cabinet on August 12 but not yet passed by parliament, would give the BND authority to conduct cyberattacks on foreign IT systems used by hostile actors, sabotage supply-chain deliveries by substituting faulty components, penetrate the IT systems of drone factories and chemical weapons laboratories, and disable servers run by state-sponsored hacker groups. The domestic BfV would gain the ability to block or reroute data traffic, corrupt data being prepared for use in an attack, and — in what legal experts confirm has no equivalent in allied law — inject false information into the communications of people it is monitoring inside Germany.

Why does the December 31, 2026 deadline exist, and what happens if parliament misses it?

Germany’s Federal Constitutional Court ruled on October 8, 2024, that the BND’s existing strategic surveillance of domestic-foreign telecommunications in the cyber domain was incompatible with Article 10 of the Basic Law, which guarantees the secrecy of correspondence and telecommunications. The court allowed the existing rules to continue only on a transitional basis until December 31, 2026. If the Bundestag fails to pass a new legal framework by that date, the current transitional authority expires and Germany’s intelligence services would have no legal basis for the surveillance activities they currently conduct in the cyber domain — a legal vacuum the government describes as an unacceptable intelligence gap. The GFF’s case history provides context for how the 2024 ruling came about and the standards the new law must meet.

What is novel about Germany’s AI oversight framework compared to allied intelligence services?

While the US, UK, and France regulate how intelligence services collect and process data, Germany’s bill goes further by treating certain AI-generated analytical outputs as intrusions that require additional legal justification before an analyst may retrieve them. Movement profiles, behavioral and personality assessments, and personalized predictions generated by AI analysis systems would each require a specific legal basis calibrated to how revealing the output is. A mandatory two-year review would determine whether new AI-generated output categories had become equally revealing, triggering the stricter rules automatically. No allied democracy has enacted comparable statutory protections for AI-generated intelligence inferences.

What should German car owners understand about the vehicle telemetry provisions?

The bill would require automotive manufacturers and service providers to share connected-vehicle telemetry data — including location, movement, and sensor data — with Germany’s intelligence services on demand. The VDA automotive industry association immediately demanded that the term “telemetry data” be precisely defined and that manufacturers not be required to collect or store additional data in anticipation of future intelligence requests. The VDA’s full statement details these concerns and calls for clear separation from existing European compliance frameworks. Legal experts have flagged a genuine conflict between the intelligence access requirement and the GDPR’s requirement that national security restrictions on personal data rights be both necessary and proportionate. The law’s definition of “telemetry data” — and whether the bill as passed resolves the GDPR tension — will determine how much of a vehicle owner’s digital trail becomes accessible to German intelligence.