E2. Sources and Currency
This work is designed as a living reference (see chapter A1) and is updated as relevant developments occur.
What this chapter delivers: the as-of-date convention, the key sources by topic area, and how change is handled.
As-of-date convention
Chapters with a high rate of change, regulation in particular, carry their own as-of-date note right at the start of the chapter, with a date and the underlying sources. The most current example is in chapter B8: as of July 2026, reflecting the Digital Omnibus to the EU AI Act (approved by Parliament and Council in June 2026).
Principle: an as-of-date note always states the date, the legal or market status as of which the claim was verified, and makes explicit what was still open at the time of writing (see chapter B8: the note on the pending publication in the EU Official Journal).
Key sources
The central statements of this work rest on the following sources, grouped by topic area:
| Topic area | Source |
|---|---|
| EU AI Act, Digital Omnibus | European Commission (digital-strategy.ec.europa.eu), Council of the EU (consilium.europa.eu), EU Official Journal |
| GDPR | General Data Protection Regulation (Regulation (EU) 2016/679) |
| Financial supervision (insurance, banking) | BaFin circulars (VAIT, MaGo), DORA Regulation |
| Product liability | EU Product Liability Directive (Directive (EU) 2024/2853) |
| Co-determination | German Works Constitution Act (Sections 80, 87, 90 BetrVG) |
| AI security (chapter B9) | OWASP Top 10 for LLM Applications (genai.owasp.org), MITRE ATLAS (atlas.mitre.org), NIST AI Risk Management Framework incl. Generative AI Profile (nist.gov), BSI publications on generative AI (bsi.bund.de) |
| Ethics and responsible AI (chapter B10) | EU Ethics Guidelines for Trustworthy AI (HLEG), ISO/IEC 42001 (AI management system), NIST AI RMF |
| Cost and FinOps (chapter D2) | FinOps Foundation (finops.org), FinOps Framework |
| GPAI obligations | GPAI Code of Practice (European Commission, since July 2025) |
| National AI supervision (Germany) | AI Market Surveillance and Innovation Promotion Act (KI-MIG); Bundesnetzagentur (Federal Network Agency) |
| Cybersecurity (cross-sector) | NIS2 Directive (EU) 2022/2555 and the German NIS2 implementation act |
Update cadence
Sources age at different speeds. Fixed review intervals keep the work reliably current:
- Regulatory chapters: reviewed on every relevant legislative change, at least semi-annually.
- All other chapters: reviewed on significant market developments (new model generations, evolving best practices), at least annually.
- Triggers for a special review: new EU legal acts, significant BaFin circulars, fundamental shifts in mainstream AI architectures.
Not legal advice
All content in this work, particularly on regulation and compliance, is for orientation purposes and does not replace legal advice. Binding classifications and measures must always be coordinated with the responsible legal, data-protection, and compliance functions.