Topic

Business and regulation

Buying software, funding delivery and navigating governance, contracts and regulation.

Blog posts
32
Focused clusters
02

Focused clusters

Start with the cornerstone

Latest in this collection

CRA incident timeline with 24-hour, 72-hour, and final-report checkpoints Business & Regulation

Cyber Resilience Act Reporting: 24-Hour Playbook

Build the evidence pipeline, decision rights, and incident workflow needed when CRA reporting starts on 11 September 2026.

Software evidence chain linking requirements, tests, releases, incidents, and updates Business & Regulation

EU Product Liability for Software: Evidence Checklist

Build the release, test, incident, and update evidence chain needed for software placed on the EU market after 9 December 2026.

AI bill of materials comparing CycloneDX and SPDX for models, datasets, and software Business & Regulation

AI Bill of Materials: CycloneDX vs SPDX

Choose an AIBOM format, define model and dataset provenance, and generate signed inventory from the release pipeline.

A prompt passing through a pseudonymization layer, with the re-identification key staying on the controller side Business & Regulation

LLM Pseudonymization Gateways: Does the Prompt Leave GDPR Scope?

Platforms in this category promise that pseudonymizing a prompt makes a hosted model safe to use. The 2025 CJEU ruling and the EDPB guidance say something narrower. Here is the evidence a buyer actually has to collect.

Semantica decision provenance graph connecting evidence, policy gates and an AI agent outcome Business & Regulation

Semantica Review 2026: Can It Explain Every AI Agent Decision?

A buyer-focused review of Semantica for decision provenance, policy gates and regulated AI audit trails, including security limits and a two-week pilot scorecard.

Two software providers transferring a live codebase through a controlled transition Business & Regulation

Software Project Takeover: A 30-Day Provider Change Plan

Changing the team behind a live product is not a repository transfer. Use this 30-day plan to regain control, prove releases and recovery, and select a provider that can inherit before it rebuilds.

Complete article directory

  1. Cyber Resilience Act Reporting: 24-Hour Playbook
  2. EU Product Liability for Software: Evidence Checklist
  3. AI Bill of Materials: CycloneDX vs SPDX
  4. LLM Pseudonymization Gateways: Does the Prompt Leave GDPR Scope?
  5. Semantica Review 2026: Can It Explain Every AI Agent Decision?
  6. Software Project Takeover: A 30-Day Provider Change Plan
  7. AI Agent Contract Signing: eIDAS QES Integration Guide
  8. What "Dienstleister" Commits Your Vendor To
  9. Terafab: Who Controls the AI Stack From Silicon to Orbit?
  10. Can AI Create Viruses? What Stanford Actually Proved
  11. Stripe Billing and E-Invoicing 2027
  12. EU AI Act Article 50 Checklist for SaaS and AI Agents
  13. Software Agencies in Tyrol Compared 2026
  14. AI Agent SLA Template: Accuracy, Latency, Human Handoff and Auditability
  15. EU AI Vendor Security Questionnaire: 45 Questions Before You Sign
  16. DACH AI Adoption Benchmark 2026: What SMEs Put Into Production
  17. Software Agency Proposal Teardown: 12 Clauses That Change Price, Scope and Ownership
  18. AI Consulting in Austria 2026: An Honest Guide for SMEs
  19. EU Data Residency for AI APIs in 2026: Provider Guide
  20. AI Funding in Austria 2026: aws, FFG, Premium, KMU.DIGITAL
  21. The One-Page AI Policy for a DACH Company
  22. MVP Development for Startups in Austria: Agencies, Cost and Selection 2026
  23. When Not to Hire Wavect
  24. Can a Software Studio Claim Austria's Forschungsprämie?
  25. How Austrian Startup Funding Actually Stacks
  26. EU AI Act Cost for a 5-Person Startup
  27. Werkvertrag vs T&M for Austrian SaaS
  28. Scope-Creep Rates. Our Numbers
  29. MiCA + FMA Reality Austria 2026
  30. GDPR + EU AI Act for DACH SaaS
  31. Why People think Agencies suck
  32. Pricing Software Projects the Right Way