Skip to content
Reality Graph

Compliance

NIS2, Germany's BSIG, and AI Code

Last updated: 2026-07-173 min read

NIS2 and Germany’s BSIG do not name AI coding. For in-scope entities they establish cybersecurity risk-management and management duties. Treating an AI-assisted workflow as a development or supplier-risk input is an editorial mapping-not a legal scope, compliance, breach, or liability decision.

tests greendiff readauth.py geändertapprovalblockedgreen tests do not clear this
Contents

Management duty is not an automatic AI-liability result

BSIG § 38 says management of particularly important and important entities must implement the § 30 measures, oversee their implementation, and attend regular training. Its liability paragraph concerns culpably caused damage to the entity through applicable corporate-law rules, with a statutory fallback. It does not say that an executive is automatically liable whenever AI-generated code contributes to damage, and this article does not predict that outcome.

Five layers, four questions

The existence of a policy or evidence artifact does not answer legal scope, adequacy, breach, causation, or liability.
Legal scopeOrganizational policyTechnical or organizational measureEvidence artifactRegulatory or liability outcome
AuthorityWho defines or decides this layer?Legislature, current law, competent authority, and ultimately courtsDecision-layer mapping · 2026-07-17Plain-language orientation; current law and competent decision makers control.The accountable organizationDecision-layer mapping · 2026-07-17Plain-language orientation; current law and competent decision makers control.The organization, within applicable legal and risk requirementsDecision-layer mapping · 2026-07-17Plain-language orientation; current law and competent decision makers control.The process records an observed fact; reviewers assess relevanceDecision-layer mapping · 2026-07-17Plain-language orientation; current law and competent decision makers control.Authority, court, or agreed dispute processDecision-layer mapping · 2026-07-17Plain-language orientation; current law and competent decision makers control.
DecisionWhat is actually being decided?Whether the entity and activity fall within the relevant regimeDecision-layer mapping · 2026-07-17The exact question varies with the facts and process.Which tools, data, identities, checks, exceptions, and owners are approvedDecision-layer mapping · 2026-07-17The exact question varies with the facts and process.How a selected risk is treated and effectiveness evaluatedDecision-layer mapping · 2026-07-17The exact question varies with the facts and process.What happened in one configuration, change, test, approval, or exceptionDecision-layer mapping · 2026-07-17The exact question varies with the facts and process.Breach, enforcement, damage, causation, fault, remedy, or liabilityDecision-layer mapping · 2026-07-17The exact question varies with the facts and process.
AI-code connectionHow AI coding enters the analysisTool and code use are facts in the organization, not a shortcut to scopeAI-coding exampleAI coding is not named in the cited provisions.AI-specific rules can implement part of risk treatmentAI-coding exampleAI coding is not named in the cited provisions.Review gates, access restrictions, supplier review, and testing are examplesAI-coding exampleAI coding is not named in the cited provisions.A verification report can record task and selected check resultsAI-coding exampleAI coding is not named in the cited provisions.AI-code facts may be evidence if relevantAI-coding exampleAI coding is not named in the cited provisions.
Residual limitWhat remains unresolved?Sector, size, structure, exceptions, and facts require analysisLegal claim boundary · 2026-07-17Not legal advice or an outcome prediction.A policy does not prove operation, effectiveness, or complianceLegal claim boundary · 2026-07-17Not legal advice or an outcome prediction.Suitability, proportionality, effectiveness, and full coverage remain contextualLegal claim boundary · 2026-07-17Not legal advice or an outcome prediction.It does not decide legal adequacy, causation, or organization-wide operationLegal claim boundary · 2026-07-17Not legal advice or an outcome prediction.No blog or tool can pre-decide the outcomeLegal claim boundary · 2026-07-17Not legal advice or an outcome prediction.
The existence of a policy or evidence artifact does not answer legal scope, adequacy, breach, causation, or liability.

A bounded implementation example

Feed one AI-assisted development path into the existing risk process: record assistant and model endpoints, repository context and data classification, supplier and access decisions, required tests and review gates, exception authority, evidence retention, and effectiveness-review cadence. This can make oversight reviewable. It is not a statutory safe harbour and does not replace the broader measures that may apply.

Where Reality Graph fits

Reality Graph can record the written task, selected checks, changed files, observed outcomes, and operator decision for a governed run. That last item is a gate rather than a log line: the product is built so that a run stops in front of a named person instead of writing or committing on its own. That evidence may be relevant to an internal control owner, auditor, authority, counsel, or court, but each evaluates it within a different scope. Reality Graph does not determine entity status, prescribe the complete risk program, certify compliance, or decide who is liable. See also what an evidence report contains.

A bounded record can show

  • The task, approved rule, owner, and selected checks for one run
  • Observed results, changed files, exceptions, and operator decision
  • When and under which source revision the evidence was captured

It cannot decide

  • Whether the organization is a particularly important or important entity
  • Whether all suitable, proportionate, and effective measures exist and operate
  • Breach, causation, fault, fine, remedy, or management liability in a concrete matter
A governed development record can support oversight; it does not determine NIS2 or BSIG scope, compliance, breach, or liability.

FAQ

Does NIS2 or Germany's BSIG specifically regulate AI-generated code?
Neither the cited NIS2 provisions nor BSIG sections 28, 30, and 38 name AI coding tools or AI-generated code. They establish entity scope, cybersecurity risk-management measures, documentation, and management duties. Applying those categories to an AI-assisted development workflow is an editorial risk mapping, not quoted law.
Does the BSIG apply to our company?
This article cannot decide that. BSIG section 28 uses entity types, sectors, size thresholds, special inclusions, exclusions, and interactions with sector-specific regimes. Corporate structure and activities matter. Use the current law and obtain qualified legal advice for a scope determination.
What does BSIG section 38 say about management?
For particularly important and important entities, section 38 requires management to implement the section 30 risk-management measures and oversee implementation, and to attend regular training. It also addresses liability to the entity for culpably caused damage through the applicable corporate-law rules, with a statutory fallback. That text does not decide liability for a particular AI-code incident.
Does a verification report prove NIS2 or BSIG compliance?
No. It can record selected checks and observed results for one change. The organization still needs an appropriate, proportionate, effective risk-management system and documentation across the applicable scope. Authorities, auditors, counsel, and courts make their own determinations under the relevant process.
What is a bounded AI-coding implementation example?
Treat the assistant, model endpoint, repository context, generated change, dependencies, and review path as inputs to the organization's existing risk assessment. Define owners, allowed configurations, checks, exceptions, evidence, and review cadence. This is an implementation example under the law's general risk categories, not a statutory safe harbour.

Keep reading

Sources

Want to see what your last agent run would have looked like?

Request access