Sources & method
How this content is made
Trust comes from traceability. This page discloses where the content comes from, how it is reviewed, and where an assessment is editorial rather than evidenced.
Principles
- Primary sources before secondary literature. We reference standards, specifications and official frameworks, not hearsay.
- No fabricated facts. No invented customers, metrics or legal claims.
- Assessments are flagged. Where a statement is editorial and not evidenced, it is marked as an “editorial assessment”.
- Dated review. Every source carries a “last checked” date; every mission a change history.
- Terminological consistency. Core terms are used consistently across the whole site (see Glossary).
Terminological consistency & vocabulary
Core terms are written and used deliberately consistently. On first occurrence a technical term is explained or linked to the Glossary. Binding spellings:
- AI and KI — synonymous; "KI" in German running text, "AI" in fixed technical terms (AI-Readiness, AI-SBOM).
- Agent vs. agent system — the single acting actor vs. the overall system of agents, tools and control.
- Copilot — suggests but does not replace; clearly distinguished from the acting agent.
- Tool Call, Eval, Observability — established technical terms, not translated.
- Human-in-the-Loop, Delegation, Least Privilege, context architecture — consistent across all pages.
- Nova-7 — always hyphenated.
Maintenance process
Content is published, dated and revised as needed. Changes to a mission appear in its change history. Sources are checked regularly for reachability and currency; the review date sits with each source. The architecture Radar carries its own as-of date, because classifications change faster than foundations.
Limits
This site is an independent knowledge and architecture project — not legal advice. For regulatory questions (e.g. the EU AI Act) the respective original text is authoritative. Answers from the Nova-7 assistant may contain errors; the cited sources should be verified.
Source directory by topic
These standards and primary sources underpin the missions, ordered here by topic. Each entry names the publisher, type and review date and briefly explains why the source is relevant. On the mission detail pages you will find in which context a source is drawn upon.
AI Risk Management & Governance
- EU AI Act — Regulatorischer Rahmen Europäische Kommission · Regulation · checked 24.06.2026 Risk-based regulatory framework — not legal advice; the original legislation is authoritative.
- ISO/IEC 42001 — AI-Managementsystem ISO/IEC · Standard / RFC · checked 24.06.2026 Management system for the responsible development, deployment and use of AI.
- NIST AI Risk Management Framework NIST · Official framework · checked 24.06.2026 Overarching structure for managing AI risks — the basis for risk classes and responsibilities.
- NIST AI RMF — Generative AI Profile NIST · Official framework · checked 24.06.2026 Generative-AI-specific risks and measures, including data quality and provenance.
Agentic AI & Security
- MITRE ATLAS MITRE · Primary source · checked 24.06.2026 Tactics and techniques against AI-enabled systems — the basis for detection and incident processes.
- OWASP Top 10 for Agentic Applications 2026 OWASP · Primary source · checked 24.06.2026 Memory/context risks (including poisoning) and authorisation problems of agentic systems.
Identity & Authorization
- OAuth 2.0 Security Best Current Practice (RFC 9700) IETF · Standard / RFC · checked 24.06.2026 Security guidelines for OAuth-based authorisation of tool access.
Interoperability & Agent Protocols
- Agent2Agent Protocol A2A Project · Specification · checked 24.06.2026 Interoperability between agents — verify maturity and version at each mention.
- Model Context Protocol — Spezifikation MCP Project · Specification · checked 24.06.2026 Standardised connection of context sources and tools — but replaces neither authorisation nor data quality.
Observability & Reliability
- OpenTelemetry Semantic Conventions OpenTelemetry · Specification · checked 24.06.2026 Vendor-neutral telemetry and semantic conventions, including growing GenAI support.
- OpenTelemetry — GenAI Observability OpenTelemetry · Primary source · checked 24.06.2026 Current classification of the observability of generative and agentic systems.
Software Supply Chain
- SLSA — Supply-chain Levels for Software Artifacts OpenSSF · Specification · checked 24.06.2026 Integrity and provenance of the software supply chain.
- CycloneDX ML-BOM OWASP / CycloneDX · Specification · checked 24.06.2026 Machine-readable components and dependencies of ML/AI systems.
Economics
- FinOps for AI FinOps Foundation · Primary source · checked 24.06.2026 Framework for cost and value management of AI workloads.
Source hierarchy Official frameworks, standards and specifications (incl. NIST, ISO/IEC, IETF, W3C, OWASP, MITRE, OpenTelemetry, European Union) and original scientific publications are preferred. Secondary sources are used only where they offer additional, clearly flagged interpretive value. The maturity of young protocols (e.g. MCP, A2A) is stated when they are referenced.