<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Compliance on Pfisterer Consulting</title><link>https://pfisterer.xyz/en/tags/compliance/</link><description>Recent content in Compliance on Pfisterer Consulting</description><generator>Hugo</generator><language>en</language><lastBuildDate>Fri, 10 Apr 2026 13:30:00 +0200</lastBuildDate><atom:link href="https://pfisterer.xyz/en/tags/compliance/index.xml" rel="self" type="application/rss+xml"/><item><title>WhatsApp Lawsuit Against Meta: What It Means for Businesses</title><link>https://pfisterer.xyz/en/news/whatsapp-verschluesselung-klage-meta-datenschutz-mittelstand/</link><pubDate>Fri, 10 Apr 2026 13:30:00 +0200</pubDate><guid>https://pfisterer.xyz/en/news/whatsapp-verschluesselung-klage-meta-datenschutz-mittelstand/</guid><description>&lt;p&gt;For ten years, WhatsApp has promised end-to-end encryption. Since January 2026, a class action lawsuit in a U.S. federal court claims that promise was a lie. And today, April 10, 2026, the public debate is escalating. Elon Musk and Telegram founder Pavel Durov are attacking Meta head-on.&lt;/p&gt;
&lt;p&gt;This directly affects German SMEs. Millions of businesses use WhatsApp Business for customer communication, order processing, scheduling, and internal coordination. If the allegations hold up, trade secrets and GDPR compliance are at stake for every one of them. This topic falls squarely within the &lt;a href="https://pfisterer.xyz/en/leistungen/projekte-systeme/"&gt;IT strategy and system selection&lt;/a&gt; work I do with mid-sized companies.&lt;/p&gt;</description></item><item><title>When AI Agents Hack AI Systems: Why Your AI Needs Security Testing Now</title><link>https://pfisterer.xyz/en/news/ki-agenten-hacken-ki-systeme-sicherheit-pruefung/</link><pubDate>Wed, 11 Mar 2026 08:00:00 +0100</pubDate><guid>https://pfisterer.xyz/en/news/ki-agenten-hacken-ki-systeme-sicherheit-pruefung/</guid><description>&lt;p&gt;An autonomous AI agent chains four individually harmless vulnerabilities into a complete platform takeover — severity rating CVSS 9.8 out of 10. Then it gives itself a voice and calls the target system&amp;rsquo;s AI. No human hacker. No sophisticated exploit kit. One AI hacking another AI.&lt;/p&gt;
&lt;p&gt;This isn&amp;rsquo;t science fiction. This happened in March 2026 — to a $20 million-funded AI recruiting startup whose clients included Anthropic, Stripe, and Monzo. AI security is a central aspect of my &lt;a href="https://pfisterer.xyz/en/leistungen/pflicht-themen/"&gt;consulting on compliance and regulatory requirements&lt;/a&gt;.&lt;/p&gt;</description></item><item><title>DATEV ERP: Why You Should Never Change Cost Centers Mid-Year</title><link>https://pfisterer.xyz/en/news/datev-erp-kostenstellen-nicht-unterjaehrig-aendern/</link><pubDate>Tue, 03 Mar 2026 14:00:00 +0100</pubDate><guid>https://pfisterer.xyz/en/news/datev-erp-kostenstellen-nicht-unterjaehrig-aendern/</guid><description>&lt;p&gt;&amp;ldquo;We just created a new department — can we quickly adjust the cost centers?&amp;rdquo; This request comes up in almost every company at least once a year. Usually in April, when the new org structure is in place. Or in September, when a new project starts. The answer should always be the same: &lt;strong&gt;Not now. At year-end.&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;Why? Because &lt;a href="https://www.datev.de/"&gt;DATEV&lt;/a&gt; handles cost centers differently than most users assume. These DATEV-ERP topics are a central part of my &lt;a href="https://pfisterer.xyz/en/leistungen/pflicht-themen/"&gt;consulting on compliance and regulatory requirements&lt;/a&gt;. And the consequences of a mid-year change only become visible when it&amp;rsquo;s too late — in the management report, the cost center analysis, or the annual financial statements.&lt;/p&gt;</description></item><item><title>One Year of Mandatory E-Invoicing: Why the B2B Standard Is Drowning in ZUGFeRD Chaos</title><link>https://pfisterer.xyz/en/news/ein-jahr-e-rechnungspflicht-zugferd-chaos-praxis/</link><pubDate>Tue, 24 Feb 2026 08:00:00 +0100</pubDate><guid>https://pfisterer.xyz/en/news/ein-jahr-e-rechnungspflicht-zugferd-chaos-praxis/</guid><description>&lt;p&gt;&lt;em&gt;Note: This article covers the German e-invoicing mandate (E-Rechnungspflicht). The requirements are specific to companies operating in Germany.&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;Earlier this year, I published a summary of &lt;a href="https://pfisterer.xyz/en/news/e-rechnung-2025-was-mittelstand-wissen-muss/"&gt;what SMEs need to know about mandatory e-invoicing&lt;/a&gt;. Reception mandate since January 2025, sending mandate from 2027, EN 16931 formats. Straightforward enough in theory.&lt;/p&gt;
&lt;p&gt;Now, more than a year after the reception mandate took effect, it&amp;rsquo;s time for an honest assessment: &lt;strong&gt;The reality on the ground is catastrophic.&lt;/strong&gt; E-invoicing is one of the most pressing topics in my &lt;a href="https://pfisterer.xyz/en/leistungen/pflicht-themen/"&gt;consulting on compliance and regulatory requirements&lt;/a&gt;.&lt;/p&gt;</description></item><item><title>Shadow AI: When Employees Secretly Build Their Own AI Agents</title><link>https://pfisterer.xyz/en/news/shadow-ai-wenn-mitarbeiter-eigene-ki-agenten-bauen/</link><pubDate>Mon, 23 Feb 2026 10:00:00 +0100</pubDate><guid>https://pfisterer.xyz/en/news/shadow-ai-wenn-mitarbeiter-eigene-ki-agenten-bauen/</guid><description>&lt;h2 id="the-new-shadow-it-has-a-brain"&gt;The New Shadow IT Has a Brain&lt;/h2&gt;
&lt;p&gt;Shadow IT has been a headache for years — unauthorized tools, private cloud accounts, rogue SaaS subscriptions. But Shadow AI takes it to a different level entirely. This topic is part of my &lt;a href="https://pfisterer.xyz/en/leistungen/ki-automatisierung/"&gt;AI and automation consulting&lt;/a&gt; for SMEs. Because this time, employees aren&amp;rsquo;t just using unapproved software. They&amp;rsquo;re building intelligent workflows that actively process, analyze, and redistribute company data.&lt;/p&gt;
&lt;p&gt;And they&amp;rsquo;re doing it with the best of intentions.&lt;/p&gt;</description></item><item><title>Helsing, AI Weapons, and the Illusion of Human in the Loop</title><link>https://pfisterer.xyz/en/news/helsing-ki-waffen-human-in-the-loop-haftung/</link><pubDate>Wed, 18 Feb 2026 10:00:00 +0100</pubDate><guid>https://pfisterer.xyz/en/news/helsing-ki-waffen-human-in-the-loop-haftung/</guid><description>&lt;p&gt;Helsing is one of Europe&amp;rsquo;s fastest-growing defense companies. Founded in Munich, with offices in London and Paris, the company builds AI-powered weapon systems: the HX-2 strike drone, the CA-1 Europa autonomous combat aircraft (with HENSOLDT), electronic warfare (Cirra), underwater reconnaissance (SG-1). Investors like Daniel Ek (Spotify founder) and former Airbus CEO Tom Enders sit on the board.&lt;/p&gt;
&lt;p&gt;This is not a startup toy. &lt;strong&gt;Helsing is a heavy player in European defense.&lt;/strong&gt;&lt;/p&gt;</description></item><item><title>AI Agents and the EU AI Act 2026: What SMEs Need to Know Now</title><link>https://pfisterer.xyz/en/news/ki-agenten-eu-ai-act-2026-was-mittelstand-jetzt-wissen-muss/</link><pubDate>Tue, 17 Feb 2026 10:00:00 +0100</pubDate><guid>https://pfisterer.xyz/en/news/ki-agenten-eu-ai-act-2026-was-mittelstand-jetzt-wissen-muss/</guid><description>&lt;p&gt;August 2, 2026 is the deadline: the EU AI Act (Regulation (EU) 2024/1689) takes full effect. For German SMEs, this creates a dilemma: if you use AI, you must prove it&amp;rsquo;s compliant. If you don&amp;rsquo;t use AI, you lose the race for talent and efficiency.&lt;/p&gt;
&lt;p&gt;I&amp;rsquo;m currently working intensively on exactly this topic – and sharing my assessment here. The EU AI Act is a central topic in my &lt;a href="https://pfisterer.xyz/en/leistungen/pflicht-themen/"&gt;consulting on compliance and regulatory requirements&lt;/a&gt;.&lt;/p&gt;</description></item><item><title>E-Invoicing 2025: What SMEs Need to Know Now</title><link>https://pfisterer.xyz/en/news/e-rechnung-2025-was-mittelstand-wissen-muss/</link><pubDate>Thu, 12 Feb 2026 10:00:00 +0100</pubDate><guid>https://pfisterer.xyz/en/news/e-rechnung-2025-was-mittelstand-wissen-muss/</guid><description>&lt;p&gt;&lt;em&gt;Note: This article covers German e-invoicing regulations (Wachstumschancengesetz). The requirements are specific to companies operating in Germany.&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;Since January 1, 2025, companies in the B2B sector must be able to &lt;strong&gt;receive&lt;/strong&gt; e-invoices. The e-invoicing mandate is a core topic in my &lt;a href="https://pfisterer.xyz/en/leistungen/pflicht-themen/"&gt;consulting on compliance and regulatory requirements&lt;/a&gt; for SMEs. Starting 2027, &lt;strong&gt;sending&lt;/strong&gt; e-invoices will also be mandatory (with a transition period until 2028 for smaller companies).&lt;/p&gt;
&lt;h2 id="e-invoice-definition-what-qualifies-under-german-law"&gt;E-Invoice Definition: What Qualifies Under German Law&lt;/h2&gt;
&lt;p&gt;A PDF via email is &lt;strong&gt;not&lt;/strong&gt; an e-invoice. Germany&amp;rsquo;s &lt;a href="https://www.bundesfinanzministerium.de/Content/DE/Gesetzestexte/Gesetze_Gesetzesvorhaben/Abteilungen/Abteilung_IV/20_Legislaturperiode/2024-03-27-Wachstumschancengesetz/0-Gesetz.html"&gt;Wachstumschancengesetz (Growth Opportunities Act)&lt;/a&gt; defines e-invoices as structured electronic formats compliant with &lt;a href="https://ec.europa.eu/digital-building-blocks/sites/display/DIGITAL/EN&amp;#43;16931&amp;#43;702"&gt;EN 16931&lt;/a&gt;. In practice, that means:&lt;/p&gt;</description></item></channel></rss>