The 2026 reform of the Militärischer Abschirmdienst — MAD, the German Military Counter-Intelligence Service

Germany’s New Defence-Oriented Counter-Intelligence Code

The 2026 reform of the Militärischer Abschirmdienst (MAD), the German Military Counter-Intelligence Service, is not a merely technical amendment. It constitutes a comprehensive re-legislation of German military counter-intelligence law and represents one of the most significant transformations of Germany’s military security architecture since reunification.

The Gesetz zur Stärkung der Militärischen Sicherheit in der Bundeswehr was enacted on 9 January 2026, published in the Federal Law Gazette (Bundesgesetzblatt, BGBl. 2026 I No. 7) on 15 January 2026, and entered into force, for its core provisions, on 16 January 2026.

Its centrepiece is the new MAD-Gesetz (MADG), contained in Article 1. This is accompanied by the new Bundeswehr-Schutz-Gesetz (BwSchutzG) and by consequential amendments to several statutes and regulations, including legislation on constitutional protection, security clearance, soldiers, reservists, military disciplinary law, telecommunications, data protection and the exercise of coercive powers by military personnel.

The reform transforms German military counter-intelligence law from a relatively fragmented statutory framework into a more systematic defence-oriented intelligence code.

Its central purpose is to strengthen the MAD as the Bundeswehr’s defensive intelligence service in a security environment shaped by espionage, sabotage, cyber operations, hybrid threats, extremist infiltration and the renewed importance of national and collective defence.

The reform pursues three interconnected objectives: reinforcing the Bundeswehr’s resilience against anti-constitutional and extremist penetration; improving protection against foreign intelligence activities; and adapting military security structures to contemporary cyber and hybrid threats.

Politically and functionally, the reform responds to the altered German and European security environment. The official legislative materials present the Bundeswehr as increasingly exposed to hostile intelligence activity, sabotage, cyber operations and extremist infiltration.

The Bundestag approved the bill on 4 December 2025, in the version amended by the Defence Committee. CDU/CSU and SPD voted in favour; AfD and Die Linke voted against; Bündnis 90/Die Grünenabstained. A practical driver of the reform was the Bundeswehr’s deployment in Lithuania. Bundestag materials expressly refer to the need to protect deployed soldiers and their families and to align MAD activity abroad more closely with the requirements of national and collective defence.

The institutional starting point is § 1 MADG. The provision defines the MAD both as a federal constitutional-protection authority (Verfassungsschutzbehörde) and as the Bundeswehr’s defensive intelligence service. It remains a civilian federal superior authority within the Federal Ministry of Defence and may establish external offices.

At the same time, § 1(2) MADG expressly provides that the MAD may not be attached to a police authority.

This is constitutionally important: the reform expands the operational adaptability of the service while formally preserving the German separation between intelligence and policing functions, the traditional Trennungsgebot.

The MAD’s mandate is broadened and clarified in § 2 MADG. The service collects and evaluates information, including personal data, concerning politically determined and targeted conduct directed against the free democratic basic order, the existence or security of the Federation or a Land, including the security of allied troops stationed in Germany, or against international understanding and peaceful coexistence. It also covers security-endangering or intelligence activities for a foreign power, especially sabotage and espionage. The military nexus remains decisive: the relevant activities must emanate from, or be capable of being directed against, persons, offices, facilities or objects within the Federal Ministry of Defence’s area of responsibility. The MAD may also act with respect to persons outside that area, but only where their conduct may affect Defence Ministry interests and in coordination with the competent constitutional-protection authority.

A significant conceptual innovation is the statutory notion of the Abschirmlage. Under § 2(2) MADG, the MAD must compile and assess, from an intelligence perspective, the influences affecting the Bundeswehr at home and abroad. This moves the service beyond a purely case-based counter-intelligence and constitutional-protection role. It gives the MAD a broader threat-picture function relevant to military readiness, force protection and defence planning.

The reform also gives the MAD a clearer role abroad. Section 2(5) MADG provides that the MAD secures the operational readiness of the Bundeswehr outside German territory and protects Defence Ministry personnel, their relatives, Bundeswehr offices and Bundeswehr facilities abroad. This is not, however, a general global intelligence mandate comparable to that of the Federal Intelligence Service (Bundesnachrichtendienst, BND). The statute confines this function to Bundeswehr deployments and their preparation and follow-up, limits it to deployment areas where Defence Ministry personnel serve, requires instruction by the Federal Ministry of Defence, and requires agreement with the BND where BND competence is also affected.

The new MADG is far more systematic than the previous framework. It contains a structured catalogue of powers, safeguards, data-transmission rules, oversight mechanisms and special provisions for the state of tension and the state of defence. Its architecture covers organisation and tasks; general and special powers; special information requests; access to Bundeswehr personnel systems; own-security powers; foreign-deployment powers; limits protecting the core of private life and professional secrecy; domestic and foreign data transmission; executive, parliamentary, judicial and data-protection control; and special rules for national and collective defence.

One of the most consequential innovations is the systematic codification of intelligence powers in Part 2 of the MADG. Section 8 MADG establishes a catalogue of intelligence methods (nachrichtendienstliche Mittel). These include covert inquiries and interviews, covert visual recordings, informants, observation of radio communications, legends and false identities, observation, monitoring of spoken words, residential surveillance, technical location measures, confidential human sources, undercover officials, virtual agents for online investigations, access to information and communication systems, evaluation of seized data carriers and cyber-investigative techniques. Unlike earlier legislation, which often relied on cross-references to the Federal Constitutional Protection Act, the new statute expressly regulates individual operational methods and links their use to differentiated thresholds of necessity and proportionality.

The law introduces a graduated model based on the intrusiveness of the measure.

Some techniques require factual indications giving rise to suspicion of relevant extremist or intelligence-related activity under § 8(1) MADG. More intrusive measures require additional conditions, such as indications of violent conduct, serious discriminatory or extremist objectives, special military capabilities, access to military weapons or explosives, preparation or commission of serious criminal offences, or the existence of an urgent threat to particularly weighty legal interests under §§ 8(2)–(4) MADG. This structure reflects the influence of Federal Constitutional Court case-law on proportionality and the graduated regulation of intelligence powers.

The provisions on human intelligence and undercover operations are particularly important. Sections 13 and 14 MADG regulate confidential human sources (Vertrauenspersonen) and undercover officials (verdeckte Bedienstete). The law lays down eligibility restrictions, excludes certain categories of persons from recruitment, and introduces safeguards designed to prevent operational excesses. Section 13(3) MADG is especially significant: it prohibits the deliberate creation or maintenance of intimate relationships, or comparable personal bonds, between a confidential source and a target person. This provision responds to long-standing concerns in German and European debates over the ethical and constitutional limits of undercover intelligence operations.

The digital dimension of undercover work is addressed in § 15 MADG. This provision introduces “virtual agents” (virtuelle Agenten): MAD officers who operate covertly within social networks and other online communication platforms in order to establish or exploit relationships of trust with targeted individuals. Unlike traditional undercover officials governed by § 14 MADG, virtual agents may operate without a permanent cover identity. The provision therefore recognises that digital environments require forms of covert interaction different from classic physical infiltration and creates a dedicated legal basis for online undercover engagement.

More broadly, the 2026 reform devotes considerable attention to intelligence collection in digital environments. Rather than relying on a single provision, the new framework combines automated collection from publicly accessible sources, online undercover operations, access to digital-service provider data and specialised cyber-counterintelligence powers.

A first element is § 4(3) MADG, which authorises the automated collection of personal data from publicly accessible sources where factual indications demonstrate that such collection is necessary in the individual case for the performance of the MAD’s statutory functions.

The provision establishes an explicit legal basis for intelligence gathering from open digital sources and reflects the increasing operational relevance of open-source intelligence (OSINT). At the same time, the requirement of factual indications and case-specific necessity seeks to distinguish authorised intelligence collection from indiscriminate monitoring of online activity.

The reform also expands the MAD’s ability to obtain information from digital-service providers. Under § 19 MADG, the service may request subscriber and registration data from providers of digital services, enabling the identification of users associated with online accounts and digital identifiers. Section 20 MADG goes further by authorising access to certain categories of usage-related data, including user-identification features, the beginning and end of service use, the extent of such use and the specific digital services used. These provisions concern subscriber and usage-related data rather than the substantive content of communications. Nevertheless, they give the MAD significant capacity to reconstruct patterns of digital behaviour and online activity.

The cyber-intelligence provisions contained in §§ 17 and 21 MADG are among the most important novelties. Section 21 MADG authorises the collection of technical information relating to cyberattacks conducted by foreign powers against defence-related information systems. This may include malware, attack infrastructure, traffic flows, operational techniques and indicators of compromise. Where such information cannot be obtained effectively from the relevant obliged provider, or cannot be obtained without jeopardising the purpose of the measure, § 17 MADG permits covert technical access to information systems for the limited purpose of extracting technical traces necessary to analyse and attribute hostile cyber operations. The statute imposes specific limits: information may not be collected continuously; changes to the system must be confined to what is indispensable; and data that are not required for the statutory purpose must be deleted. These powers are therefore directed primarily at cyber-counterintelligence and attribution, not at broad monitoring of private digital communications.

The reform also introduces automated access to the Bundeswehr personnel-management system. Under § 24 MADG, the MAD may automatically retrieve defined basic data to determine whether a person belongs to, or works within, the Defence Ministry’s area of responsibility. If factual indications justify suspicion of relevant extremist or intelligence-related activity, the MAD may retrieve further necessary personnel data. The provision requires internal rules on authorised users, procedure, search criteria, limits on returned datasets, deletion and logging.

The new Act also regulates information flows to the MAD. Under § 42 MADG, federal authorities and federal public-law entities must inform the MAD of facts indicating relevant extremist or intelligence-related activities where factual indications suggest that the information may be necessary for the MAD’s tasks. The same applies, subject to prosecutorial direction, to prosecutors, police authorities, customs-investigation authorities and certain customs offices. The MAD must immediately assess whether incoming information is necessary for its statutory functions and delete unnecessary information.

The Bundeswehr Protection Act adds a further layer to the reform. Its main function is to replace the previous recruitment-screening model with a faster unterstützte Verfassungstreueprüfung, an assisted loyalty-to-the-constitution check. Under §§ 1–4 BwSchutzG, individuals entering military service on a voluntary basis must undergo this screening. Applicants are required to disclose relationships with anti-constitutional organisations, personal internet presences, memberships in social networks and usernames used online under § 4(1) BwSchutzG. The MAD may obtain information from federal and regional constitutional-protection authorities and the BND, consult the Federal Central Criminal Register, conduct systematic searches of publicly accessible internet platforms and social-media networks, and use automated image-comparison techniques based on photographs supplied by applicants under § 4(3) BwSchutzG. This regime reflects a legislative determination to identify extremist affiliations and anti-constitutional attitudes at the recruitment stage.

The BwSchutzG also introduces stricter security mechanisms for particularly sensitive military functions. Sections 5 and 6 BwSchutzG provide for an intensified extended security clearance with security investigations for soldiers assigned to positions with especially high security requirements. In addition, §§ 7–10 BwSchutzG establish a regime of travel restrictions for Defence Ministry personnel. Private travel to or through regions or States presenting a security risk may be subject to prior notification, authorisation or prohibition, depending on the level of risk. Personnel must also report indications of attempted recruitment or approach by foreign intelligence services in connection with such travel.

The reform further strengthens military-security powers beyond the MAD itself. Amendments to the law on the use of direct force and the exercise of special powers by Bundeswehr soldiers, allied forces and civilian guards expand the ability of authorised personnel to stop, identify and search persons in or near military security areas. The new provisions also address suspicious observation of military activities and the handling of objects such as weapons, observation aids, intrusion tools and unmanned aerial vehicles. The reform therefore links intelligence law, personnel protection and military-security enforcement within a single legislative strategy.

From a constitutional-law perspective, the reform is significant because it expressly restricts fundamental rights and attempts to structure intelligence powers according to intrusion intensity, procedural safeguards and oversight. The MADG contains specific safeguards protecting the core area of private life (Kernbereich privater Lebensgestaltung) in § 28 MADG and professional secrecy holders in § 29 MADG. Particularly intrusive measures require judicial authorisation under § 22 MADG. Parliamentary oversight remains vested in the Parliamentary Control Panel (Parlamentarisches Kontrollgremium) under § 44 MADG, while independent data-protection supervision is entrusted to the Federal Commissioner for Data Protection and Freedom of Information under § 46 MADG.

The special regime for the Spannungsfall and Verteidigungsfall is among the most constitutionally sensitive aspects of the reform. Section 52 MADG modifies the application of the MAD’s mandate in a state of tension or defence, eases certain data-transmission thresholds, postpones notification and access rights until after the end of the emergency, and, where the Federal Government with the consent of the Parliamentary Control Panel determines that this is strictly necessary for defence, reduces the requirement of judicial authorisation to specified cases and suspends parts of the independent data-protection-control regime. These provisions will likely attract close constitutional scrutiny.

The digital-investigation provisions are also likely to become a central focus of future debate. The Federal Constitutional Court has repeatedly emphasised the constitutional importance of informational self-determination, the confidentiality and integrity of information-technology systems, and proportionality in intelligence activities. The combination of automated online collection under § 4(3) MADG, virtual undercover operations under § 15 MADG, systematic social-media screening under § 4 BwSchutzG and access to subscriber and usage data under §§ 19–20 MADG substantially enhances the state’s ability to map digital networks and behavioural patterns. Future constitutional scrutiny will therefore focus on whether the safeguards contained in §§ 22, 23, 28 and 29 MADG provide sufficient protection against disproportionate interference with privacy, freedom of communication and informational autonomy.

The most accurate characterisation is therefore this: Germany has transformed the MADG into a more complete, defence-oriented counter-intelligence code. The reform strengthens the MAD’s role in military counter-intelligence, cyber defence, foreign-deployment protection, personnel screening, own-security and data exchange. It does not turn the MAD into a police authority, nor does it give it a general foreign-intelligence mandate comparable to the BND. Rather, it adapts the Bundeswehr’s defensive intelligence service to a threat environment shaped by national and collective defence, sabotage, espionage, hybrid operations, cyberattacks and the protection of deployed forces.

From a broader constitutional perspective, the reform reflects the continuing attempt to reconcile national security imperatives with proportionality, privacy and democratic accountability. Whether this balance has been successfully achieved will ultimately depend on the scrutiny of the Federal Constitutional Court, the ordinary courts, parliamentary oversight bodies and independent data-protection authorities in the years ahead.


Leave a Reply