Summary
- Germany’s cabinet has approved an overhaul expanding powers for the BND and BfV, including new authorities in cyberspace.
- Proposed active measures include intervening against foreign infrastructure where other agencies cannot respond as effectively.
- The legislation still requires parliamentary approval and places more intrusive measures under strengthened independent oversight.
Germany’s cabinet has approved draft legislation that would substantially widen the operational and cyber powers available to the country’s intelligence agencies as Berlin responds to espionage, sabotage, cyber attacks, and other hybrid threats.
The proposals approved on Wednesday would expand the authorities of the Federal Intelligence Service, or BND, and the Federal Office for the Protection of the Constitution, known as the BfV. The German government says the reform is intended to modernise intelligence powers while restructuring independent oversight.
Among the most consequential provisions are powers for what the government describes as active protective measures. In defined circumstances, intelligence services could intervene where other authorities, such as police, could not respond with comparable effectiveness. Berlin gives the example of disabling a foreign server from which an imminent cyber attack against Germany is being launched.
The proposals also expand digital intelligence capabilities. The government said the use of artificial intelligence for analysing collected information would be placed on a statutory footing, while the BND would be permitted under strategic intelligence provisions to retain telecommunications content for up to six months and traffic data for up to 12 months. Traffic data can include IP addresses and information about when and for how long communications occurred.
Reuters reported that the wider package would also enable intelligence agencies to penetrate hostile IT systems and disrupt foreign operations under certain circumstances. The cabinet decision is not the end of the legislative process: the Bundestag must still approve the reforms.
The shift is substantial for a country whose post-war intelligence framework has traditionally imposed tighter constraints on surveillance and operational activity than some European counterparts. German governments have had to reconcile national-security powers with constitutional protections shaped by the country’s experience of authoritarian surveillance under both the Nazi regime and East Germany.
Those constraints are now being tested against a security environment in which cyber operations increasingly sit alongside espionage, sabotage, influence campaigns, and attacks against infrastructure. The government argues that Germany’s intelligence services require powers comparable with partner agencies if they are to respond effectively to foreign-state activity rather than depend heavily on intelligence provided by allies.
The accompanying oversight changes are therefore central to the reform. The Independent Control Council is set to take over responsibilities currently divided across existing oversight mechanisms and would be required to approve particularly intrusive individual measures in advance. Parliamentary scrutiny arrangements would remain in place.
The government also says the draft incorporates recent rulings by Germany’s Federal Constitutional Court, including requirements for clearer statutory thresholds around surveillance and stronger protection for professional confidentiality and the core sphere of private life.
Cyber powers exercised by intelligence agencies carry a different risk profile from conventional network defence. Disabling infrastructure, manipulating systems, or interfering with an adversary’s operation can create questions around attribution, proportionality, sovereignty, collateral effects, and the boundary between intelligence work and law enforcement. Those questions become more difficult when hostile infrastructure is distributed through commercial cloud providers or compromised systems in third countries.
Germany is therefore moving towards a more operational intelligence model at the same time as it is attempting to consolidate the legal controls around that model. Parliament will now determine how much of the cabinet’s proposed expansion survives into law, and where the thresholds for active cyber intervention will ultimately be drawn.




