Official Sources

  1. European Commission – AI Act page (timeline, governance, applicability):
    https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai
  2. European Commission – Navigating the AI Act (standardisation FAQ):
    https://digital-strategy.ec.europa.eu/en/faqs/navigating-ai-act
  3. European Commission – Understanding the standardisation of the AI Act:
    https://digital-strategy.ec.europa.eu/en/faqs/understanding-standardisation-ai-act
  4. EUR-Lex – Regulation (EU) 2024/1689 (Artificial Intelligence Act):
    https://eur-lex.europa.eu/eli/reg/2024/1689/oj/eng
  5. EUR-Lex – Directive (EU) 2022/2555 (NIS2):
    https://eur-lex.europa.eu/legal-content/EN/TXT/PDF/?uri=CELEX%3A02022L2555-20221227
  6. European Commission – NIS2 implementing regulation overview:
    https://digital-strategy.ec.europa.eu/en/library/nis2-commission-implementing-regulation-critical-entities-and-networks
  7. EUR-Lex – Regulation (EU) 2024/2847 (Cyber Resilience Act):
    https://eur-lex.europa.eu/eli/reg/2024/2847/oj/eng
  8. EU Cybersecurity Certification Framework / EUCC:
    https://digital-strategy.ec.europa.eu/en/policies/cybersecurity-certification-framework
  9. EDPB Opinion 28/2024 on AI models and GDPR:
    https://www.edpb.europa.eu/system/files/2024-12/edpb_opinion_202428_ai-models_en.pdf
  10. ISO/IEC 27001:2022:
    https://www.iso.org/standard/27001
  11. ISO/IEC 42001:2023:
    https://www.iso.org/standard/42001
  12. ISO/IEC 23894:2023:
    https://www.iso.org/standard/77304.html
  13. ISO/IEC 38507:2022:
    https://www.iso.org/standard/56641.html
  14. ISO/IEC 42005:2025:
    https://www.iso.org/standard/42005
  15. ISO/IEC JTC 1/SC 42 catalogue:
    https://www.iso.org/committee/6794475/x/catalogue/

Closing Note

The core of this standard should not be treated as a one-time legal summary. It should function as a living governance-system document with owners, deadlines, exceptions, KPI/KRI, and regular review.

The standard can later be extended into:

  • a short executive policy,
  • an operational procedure for IT / DevSecOps / MLOps teams.