Regulated AI Navigator

Turn an AI use case into its EU AI Act risk class, the regulations it triggers, the obligations, the architecture and the evidence you owe — in about two minutes.

Community-curated knowledge graph, peer-reviewed by experts across law, engineering and governance. Every change traceable →

Analyse a use case →Browse 35 profiles

Changelog

Every change to this knowledge graph ships in a numbered release, and every release names the community challenge that caused it. This is the trust engine of the project: if you cannot see who changed a claim and why, you have no reason to believe the claim.

6 releases · 46 recorded changes · 17 named contributors · graph v2.1.2
Want your name in the next release? The open verification worklist shows every claim still missing a dated source. Help verify the graph →

Disagree with something in the graph? That is the intended mode of use — propose a change or dispute a node from its profile page, and the next release will carry your name.

v2.1.2export bridge fields · 2026-08-07

Graph at this release: 279 nodes · 957 edges · 29 detectors · see it on the growth curve →

This release answers two community challenges: Export bridge — a mapping that leaves the graph must say how confident it is / Citation grounding — 'says who?' needs an addressable answer, not a plausible one.

  • WHY 2.1.2: the competitive-gap pass added two new node fields (`mappings`, `citeUrl`) to shipped nodes without a changelog entry. Under the principle the 2.1.1 entry states — an unlogged change is indistinguishable from a change that was never made — that is a silent graph change. This entry records it. No node was added, removed or relabelled; only the two fields below were introduced.
  • NEW FIELD `mappings` (control objectives only): an indicative, non-authoritative pair {iso42001, aicm} used by the export bridge (control-mapping CSV, ISO 42001 / CSA AICM / Vanta-style workflows). MAPPED NODES: ctl-oversight-competence (ISO 7.2 · AICM HRS), ctl-aims-riskassess (ISO 8.2 · AICM GRC), ctl-aims-dataquality (ISO Annex A.7), ctl-aims-traceability (ISO Annex A.8), ctl-aims-perfmon (ISO 9.1), ctl-thirdparty-ai (ISO Annex A.10 · AICM STA), ctl-log-completeness / ctl-log-integrity / ctl-log-access (AICM LOG only). DELIBERATELY UNMAPPED: ctl-adv-robustness and ctl-input-defense (no ISO 42001 clause and no AICM domain can be justified from the node text — both are verification activities whose clause depends on whether the organisation runs them under 8.3 treatment or 9 evaluation), plus the ISO side of the three log control objectives and the AICM side of ctl-aims-dataquality / ctl-aims-traceability / ctl-aims-perfmon, and both sides of ctl-content-disclosure (an Art. 50 transparency duty with no clean AIMS clause home).
  • EMPTY IS NOT ZERO: an empty mapping value means 'not yet mapped by this graph', never 'no clause applies'. The export bridge therefore emits an empty CSV cell rather than a guess — consistent with meta.currency's rule that an unverified claim is not presented as a fact. Every value above is checked against its own node desc; anything that could not be justified from the node text was cleared rather than kept as a plausible guess.
  • NEW FIELD `citeUrl` (any node, optional): a manual override for the citation resolver in src/lib/kg/cite.ts, which otherwise derives an authoritative public URL by pattern (AI Act article pages, EUR-Lex CELEX for regulations/directives, eCFR for CFR cites, Cornell LII for U.S.C., ISO catalogue search for ISO/IEC numbers). Convention: `citeUrl` always wins; when neither an override nor a pattern resolves, the UI renders no link at all, because a guessed source URL is worse than an absent one. No node currently sets `citeUrl` — the field exists so a corrected or non-patterned source can be pinned without a code change.
Contributors to this release: Export bridge — a mapping that leaves the graph must say how confident it is · Citation grounding — 'says who?' needs an addressable answer, not a plausible one

v2.1.1factual corrections · 2026-08-07

Graph at this release: 279 nodes · 957 edges · 29 detectors · see it on the growth curve →

This release answers three community challenges: Penalty tiers — a wrong percentage in a sanction field is a wrong compliance budget / Standards lifecycle — publication is not citation, and citation is what creates the presumption / Withdrawn instruments — the vocabulary had no honest way to say 'this is no longer pending'.

  • WHY A CORRECTION RELEASE: meta.currency states that a node without a lastVerified date is a claim, not a fact. The corollary is that a correction without a changelog entry is indistinguishable from a claim that was never wrong. This release logs the errors found in a review of the shipped 2.1 graph, so the diff is auditable rather than silent.
  • PENALTIES — 'reg-aiact': the third sanction tier read €7.5m / 1.5%. AI Act Art. 99(5) is €7,500,000 or 1% of total worldwide annual turnover, whichever is higher, for supplying incorrect, incomplete or misleading information to notified bodies or national competent authorities. Corrected to 1% and the article citation added. The €35m / 7% (prohibited practices) and €15m / 3% (Art. 9–15 high-risk obligations) tiers were already correct.
  • STANDARDS LIFECYCLE — EN 18286:2026 propagated: 'art-17' and 'ev-qms-doc' still described the QMS standard as harmonised prEN 18286, and 'ev-qms-doc' claimed to be the object of a presumption of conformity. The standard was published as EN 18286:2026 in July 2026 as the first AI Act harmonised-standard candidate to reach publication, but the OJEU citation — and with it any presumption of conformity — is still pending. The presumption claim is removed rather than reworded; both nodes now match 'std-pren18286', which stated the position correctly. Residual prEN reference in 'comp-vendor-dd' updated too.
  • CITATIONS — 'art-48' was labelled 'Art. 48/19'. The EU Declaration of Conformity is Art. 47; Art. 19 is automatically generated logs and is unrelated. Relabelled 'Art. 47/48 — CE Marking & Declaration of Conformity'; the desc already described Art. 47 + 48 correctly. Ten US-layer regulations that carried their citation in prose only now have a 'full' field on the EU convention: reg-sec2042, reg-regbi, reg-sox, reg-bsa, reg-patriot, reg-sec17a4, reg-finra4511, reg-eeoc, reg-tcpa, reg-cfaa.
  • WITHDRAWN INSTRUMENTS — meta.currency.statusVocabulary.legalAct gains 'withdrawn' (previously only in-force / amended / proposed / repealed, which left no honest status for a pulled proposal). 'reg-sec-pda' moved from status draft to withdrawn: the SEC withdrew the predictive-data-analytics / conflicts-of-interest proposal in June 2025 in a bulk withdrawal of pending proposals; no successor has been proposed, and the statusNote records that examiners still expect technology-inventory and conflicts work. 'reg-aild' moved to withdrawn (announced in the Commission's 2025 work programme) and its desc rewritten as historical context, cross-referencing 'reg-pld' as the instrument that now carries the software/AI liability weight; the three nodes that cited an AILD presumption or court order as live law (ev-logs, thr-log-integrity, ctl-log-access) now cite the PLD instead.
  • RETENTION — 'reg-sec17a4' described a flat six-year retention. SEC Rule 17a-4 is tiered: 17a-4(a) six years for blotters, ledgers and customer account records, 17a-4(b) three years for the broader category. Both tiers now stated; the WORM-or-audit-trail wording (2022 amendment to 17a-4(f)) is unchanged.
  • ORPHAN REPAIR — 'std-gaap-ifrs' had zero edges and was therefore unreachable from 'uc-svc-forecast', the use case it exists to serve. Now wired on the established pattern: reg-sox → supported_by → std-gaap-ifrs, uc-svc-forecast → relates_to → std-gaap-ifrs, std-gaap-ifrs → evidenced_by → ev-worm-ledger and → relates_to → ctl-aims-traceability. 950 → 954 edges.
  • UNDATED QUANTITATIVE CLAIMS — 'pat-dual-gate' carried four named guardrail products with specific latency figures and no verification date, the only quantitative vendor claim in the graph without one. It now has lastVerified 2026-08-07, the date of this correction pass, plus a statusNote framing the numbers as indicative order-of-magnitude figures from that period, dependent on model size, hardware and policy count, to be re-measured per stack. 'uc-scribe' summary no longer presents a named vendor and a named customer as fact; it describes the ambient-scribe pattern instead, consistent with how vendorCategory nodes handle named vendors.
  • CHANGELOG INTEGRITY — the 2.1 entry itself was found to be reconstructed from a written description rather than from the data, and overstated almost every count (79 nodes and 482 edges claimed against 22 nodes and 255 edges actual; new threats, evidence artefacts and control objectives claimed where none were added). It has been rewritten from a programmatic diff of the v2.0 and v2.1 graphs and now names only ids that exist. The first rewrite still reported 251 edges (695 -> 946): it diffed an intermediate commit and counted only edges incident to a new node. Re-measured at the 2.1 merge point (950 edges), the delta is 255, and 6 of the new edges connect two pre-existing nodes, so the claim that every new edge touches a new node was also wrong; both are corrected in the 2.1 entry. The 1.6 entry has now been re-derived the same way: all nine of its numeric claims hold against a v1.5 -> v1.6 diff (8 use cases, 14 components, 7 patterns, 6 evidence artefacts, 8 regulations, 3 standards, 9 threats, 4 ISO 42001 control objectives — ctl-aims-riskassess, ctl-aims-dataquality, ctl-aims-traceability, ctl-aims-perfmon with their four 'includes' edges from std-iso42001 — and 6 new detectors, 15 -> 21).
  • ORPHAN REPAIR, ROUND 2 — the last two nodes with no incident edges are wired in: 'std-bsi-genai' via art-15 -> supported_by (accuracy, robustness and cybersecurity when an external generative model is integrated by API) and -> relates_to 'comp-zt-gateway' (input/output validation, least privilege, prompt/permission separation); 'om-4' (Mode 4 - Fully Autonomous) via relates_to 'art-14', recording explicitly that the mode removes the per-decision oversight Art. 14 requires and is therefore a boundary marker rather than a design target. An integrity rule now flags any edgeless node at warning severity so this cannot accumulate silently again. 954 -> 957 edges.
  • CURRENCY HYGIENE — meta.currency.monitoredFeeds still listed the AILD procedure file as monitored, contradicting 'reg-aild.statusNote'; the entry now names the Omnibus and EHDS files and records that the AILD file is closed and watched only for a successor. 'art-4' and 'reg-colorado' carried a status with no lastVerified, against meta.currency.nodeFields; the status is dropped rather than backed by an invented date, and both descs still state the in-force date. meta.version and meta.date are bumped to 2.1.1 / 2026-08-07 so the graph identifies itself as the corrected build.
Contributors to this release: Penalty tiers — a wrong percentage in a sanction field is a wrong compliance budget · Standards lifecycle — publication is not citation, and citation is what creates the presumption · Withdrawn instruments — the vocabulary had no honest way to say 'this is no longer pending'

v2.1us financial layer and agentic stack · 2026-08-06

Graph at this release: 279 nodes · 950 edges · 29 detectors · see it on the growth curve →

This release answers three community challenges: Service-as-a-Software as a node class — outcome-priced work needs its own monetization and oversight fields / The US financial layer — books-and-records law is where agentic execution actually bites / The agentic execution stack — five layers between a prompt and a posted transaction.

  • WHY 2.1: 2.0 answered 'what do I build or buy it with?'. 2.1 answers 'what is actually being sold, under which regime, on which stack?'. Measured against the shipped v2.0 graph: 22 new nodes (257 -> 279) and 255 new edges (695 -> 950; 257 distinct new from/to/type triples, two of which deduplicate entries the v2.0 file carried twice). No nodes or edges were removed. 249 of the new edges attach to at least one of the 22 new nodes; 6 connect two pre-existing nodes and are corrections to the existing layer rather than part of the new one: reg-raise -> comp-vendor-dd / comp-registry / comp-incident (requires) and -> comp-risk-register (relates_to), plus supplied_by edges from comp-model-router and comp-watermark to vc-models. Counts and named ids in this entry were re-derived from a programmatic diff of the two graphs after the original entry was found to overstate them; an earlier correction put the edge delta at 251 (695 -> 946) by measuring an intermediate commit and counting only edges incident to a new node. See the 2.1.1 entry.
  • SERVICE-AS-A-SOFTWARE USE CASES — 9 new 'uc-svc-*' nodes: regulatory change management & policy updating ('uc-svc-regchange'), cross-border statutory tax & wealth filing ('uc-svc-tax'), algorithmic portfolio execution & advisory ('uc-svc-portfolio'), clinical imaging triage & patient follow-up ('uc-svc-imaging'), dynamic deal desk & quoting engine ('uc-svc-dealdesk'), procurement variance & vendor KPI monitoring ('uc-svc-procurement'), enterprise marketing disclosure compliance ('uc-svc-mktgcompliance'), continuous technical documentation generation ('uc-svc-techdoc') and automated financial forecasting & audit trails ('uc-svc-forecast'). The eight outcome-priced workflows shipped in 1.6 are not new here; what is new for them is the field set below. Use-case nodes gain two fields, 'monetization' (what a unit of billable output is) and 'oversightDesign' (the concrete sign-off interface), now carried by 19 use cases: the 9 new ones plus 10 existing workflows backfilled.
  • US FINANCIAL REGULATION LAYER — 7 new regulation nodes: SEC Advisers Act Rule 204-2 books and records ('reg-sec2042'), SEC Regulation Best Interest ('reg-regbi'), the withdrawn SEC predictive-data-analytics proposal ('reg-sec-pda'), Sarbanes-Oxley 302/404 ('reg-sox'), USA PATRIOT 326 CIP ('reg-patriot'), FTC Act 5 and the endorsement / AI-claims guidance ('reg-ftc'), and national tax codes with OECD BEPS / Pillar Two ('reg-tax-beps'). SEC 17a-4, FINRA 4511, BSA/FinCEN, TCPA, CFAA and EEOC Title VII were already in the graph from 1.6 and are not additions here. The point of the layer: an agent that drafts a filing or reconciles a break is inside the books-and-records perimeter, so retention, attribution and immutability stop being AI-governance nice-to-haves and become the primary statutory exposure.
  • EXECUTION STACK — 2 new components and 3 new patterns, all of them serving the new workflows: 'comp-attribution-chain' (supervisor attribution chain, wired to reg-sec2042, reg-sox and Art. 26 and required by five use cases (uc-svc-tax, uc-svc-portfolio, uc-svc-procurement, uc-svc-forecast, uc-svc-contract) and included in the bp-trism chassis) and 'comp-policy-feed' (regulatory feed & policy gap engine, wired to Art. 11 and ctl-aims-traceability); 'pat-cognitive-orchestrator', 'pat-local-perimeter' (MCP local-perimeter execution) and 'pat-materiality-escalation'. No threat, evidence or control nodes were added in 2.1 — the new workflows reuse the existing agentic threat set and artifact layer, including 'ev-worm-ledger' and the four 'ctl-aims-*' objectives, which shipped in 1.6.
  • STANDARDS — 1 new standard: 'std-gaap-ifrs' (IFRS / US GAAP reporting assurance) for figures that enter a reporting cycle. It shipped without edges and was wired into the graph in 2.1.1.
  • DETECTORS — 8 new detectors, each tagged 'introducedIn: 2.1' in the graph, so free-text input can reach the new layer: 'tax-filing', 'financial-reporting', 'portfolio-execution', 'imaging-triage', 'quoting-pricing', 'marketing-disclosure', 'techdoc-annexiv' and 'policy-update'. 21 -> 29 detectors.
  • NEW META BLOCKS — 2: 'sasComparison' (SaaS 1.0 seat-priced software vs. SaaS 2.0 outcome-priced work, and where the provider-role flip under Art. 25 occurs) and 'agenticStack' (the five execution layers with the control surface each one owns), both rendered on /architecture. 'serviceModel' already existed at v2.0 and is not new here. meta.sources gained one entry; the timeline was unchanged.
  • Still open for 2.2 (community): named-vendor verification round on the US layer, control objectives for the remaining AI Act articles, CCPA and state-law detectors, and a currency sweep over every node whose lastVerified predates the 2.1 merge.
Contributors to this release: Service-as-a-Software as a node class — outcome-priced work needs its own monetization and oversight fields · The US financial layer — books-and-records law is where agentic execution actually bites · The agentic execution stack — five layers between a prompt and a posted transaction

v2.0from map to market · 2026-08-06

Graph at this release: 257 nodes · 695 edges · 21 detectors · see it on the growth curve →

This release answers three community challenges: Vendor ecosystem taxonomy — six functional layers, categories as nodes, named vendors as disputable content / Gartner AI TRiSM four-layer chassis & three-lines-of-defense separation / Translational pipeline — use case → risk tier → control layers → vendor stack.

  • WHY 2.0: the graph gains a fourth dimension. Until v1.5 it answered 'what applies?' (norm), 'what must be true?' (control), 'how do I prove it?' (evidence). v2.0 adds 'what do I build or buy it with?' (market): a vendor-category layer, a delivery-model layer, and the enterprise translational pipeline that connects them. Node-type semantics are extended, hence the major version.
  • VENDOR ECOSYSTEM LAYER (delivers the v1.6-queue item 'vendor landscape'): new node type 'vendorCategory' with six nodes mirroring the functional taxonomy — AI GRC & governance platforms, runtime security & guardrails, secure data infrastructure & vector storage, regulated foundation-model platforms, agent orchestration & SDLC toolkits, productized vertical AI / Service-as-a-Software. New edge type 'supplied_by' (component/pattern → vendor category). The graph stays vendor-neutral: categories are nodes with selection metrics; exemplary vendors live in descs as community-maintained, disputable content with lastVerified dates.
  • ENTERPRISE CHASSIS (delivers the v1.6-queue item 'SaaS reference blueprint'): new blueprint 'bp-trism' — the four-layer AI TRiSM enterprise stack (Governance/System-of-Record, Context/System-of-Context, Action/System-of-Action, Defense/System-of-Defense) as the enterprise-wide chassis that per-workload blueprints (Guarded RAG, HITL Core, RDA…) plug into. New pattern 'pat-lines-defense' (three-lines-of-defense separation: never couple second-line governance to a first-line runtime vendor; telemetry feedback loop). New standard node 'std-trism' (Gartner AI TRiSM).
  • DELIVERY MODEL: new pattern 'pat-saas2' (Service-as-a-Software / productized services) — outcome-based SLAs move compliance risk onto the provider; ISO 42001 certification becomes a procurement moat; Art. 25 provider-role flip is the central legal exposure. meta.deliveryModels compares BPO / SaaS / Service-as-a-Software with regulated-market caveats.
  • CONTROL LAYER EXTENSION (continues the v1.5 pilot): two new control objectives — 'ctl-thirdparty-ai' (Embedded-AI Vendor Governance, Art. 26 + ISO 42001 third-party controls: closed SaaS runtimes are governed by contract, attestation and AI-BOM disclosure because inline inspection is impossible) and 'ctl-content-disclosure' (AI Interaction & Content Disclosure, Art. 50: user notification + machine-readable provenance).
  • NEW COMPONENTS: 'comp-intake' (AI intake portal & use-case triage — the operational front door of the translational pipeline, feeding the register and the evaluator) and 'comp-model-router' (multi-model routing & fallback abstraction — capability/cost/latency/regulatory routing, ZDR-VPC pinning for sensitive data, automatic fallback to local open-weight models; the anti-lock-in and resilience workhorse).
  • NEW STANDARD & EVIDENCE: 'std-c2pa' (C2PA Content Credentials — the machine-readable provenance/watermark standard operationalizing Art. 50) and 'ev-aibom' (AI Bill of Materials: base-model metadata, dataset provenance, vector-namespace bindings, active runtime-policy versions, bias/red-team verification history — the composition manifest that complements the SBOM).
  • meta.translationalPipeline added: the four-tier enterprise chain (use-case identification → statutory & risk tiering → architectural control layers → vendor stack mapping) expressed as a graph traversal (useCase → riskClass/regulation → control/component → vendorCategory), aligned with the evaluator pipeline.
  • meta.marketLandscape added: vendor-neutrality principle, per-category selection metrics, thin-wrapper commoditization vs. structural moats (integrated GRC infrastructure / productized vertical execution), and the procurement rule derived from lines-of-defense separation. Cross-framework control deduplication is recognized as the market's rediscovery of this graph's reuse principle — one control, many regimes.
  • Desc enrichments via updateNodes: AI-BOM/Factsheet publication duty on the AI register; audit-packet field spec and 7-year financial retention example on event logs; FRIA node broadened to the generic AI Impact Assessment (AIIA) with annual review cadence; watermarking node wired to C2PA.
  • Still open for v1.6/2.1 (community): control objectives for Art. 9/10/11/13/17, EUCS sovereignty levels, CCPA detector, named-vendor validation round on the six category nodes.
Contributors to this release: Vendor ecosystem taxonomy — six functional layers, categories as nodes, named vendors as disputable content · Gartner AI TRiSM four-layer chassis & three-lines-of-defense separation · Translational pipeline — use case → risk tier → control layers → vendor stack

v1.6service as a software · 2026-08-05

Graph at this release: 243 nodes · 645 edges · 21 detectors · see it on the growth curve →

This release answers three community challenges: Outcome-priced delivery — who answers for algorithmic error when the contract buys completed work / Vertical workflow taxonomy — the same engine lands in four different risk tiers / Artifact automation — compliance evidence must be produced by the pipeline, not written afterwards.

  • THEME 1 — Service-as-a-Software workflows: eight new use cases modelled as outcome-priced managed services (KYC & client onboarding, legal contract & clause extraction, trade lifecycle & settlement reconciliation, omnichannel voice/chat support, enterprise SDLC code automation & QA, digital shelf analytics, generative asset production & virtual try-on, supplier master data & ESG screening) across BFSI, Telecom & Media, High-Tech, Retail, Fashion and Manufacturing — each with risk class, rationale, delivery stack, patterns, threats and artifacts.
  • THEME 2 — Delivery stack & four-stage pipeline: 14 new components (zero-trust ingestion gateway, tenant enclave, segmented vector store with RBAC/CMEK, multi-model orchestration, dynamic router with open-source fallback, confidence-threshold gate, drift monitor, and the domain engines for documents, RPA, marketplace collection, care, screening, code and master data) plus 7 patterns (confidence-threshold HITL routing, human-on-the-loop sampling, model abstraction & graceful fallback, zero-data-retention binding, inline PII/PHI tokenisation, per-tenant retrieval segmentation, outcome-SLA accountability). meta.serviceModel adds the operating-model comparison, the four pipeline stages with obligations, the ISO 42001 loop, the artifact set and a four-phase roadmap — rendered on the new /architecture route.
  • THEME 3 — Artifacts, controls and the wider legal surface: 6 new evidence artifacts (AI Impact Assessment, model card, bias & fairness audit, immutable WORM decision ledger, human-oversight SOP, third-party ZDR certificate) with governing standard, cadence and minimum verifiability; 4 ISO 42001 control objectives wired to Art. 9/10/13/72; 8 new regulations (UCPD, CSDDD, SEC 17a-4, FINRA 4511, BSA/FinCEN, TCPA/FCC AI-voice, CFAA/anti-scraping, EEOC Title VII) and 3 standards (NIST SP 800-218 SSDF, ISO 27001 A.8.28, C2PA content credentials); 9 new threats from the productized-service failure modes; 6 new detectors (managed-service delivery, voice channel, books & records retention, web collection, supply-chain due diligence, synthetic media). All counts in this entry were re-derived from a programmatic v1.5 -> v1.6 graph diff on 2026-08-07 and match: 59 new nodes (184 -> 243) and 229 new edges (416 -> 645), detectors 15 -> 21.
Contributors to this release: Outcome-priced delivery — who answers for algorithmic error when the contract buys completed work · Vertical workflow taxonomy — the same engine lands in four different risk tiers · Artifact automation — compliance evidence must be produced by the pipeline, not written afterwards

v1.5trust and time · 2026-08-04

Graph at this release: 184 nodes · 416 edges · 15 detectors · see it on the growth curve →

This release answers three community challenges: Assurance structure — obligation vs. control objective vs. evidence / Currency — mappings decay silently between audits / Evidence trust — who can rewrite the audit trail.

  • THEME 1 — Trustworthy evidence (answers 'WORM stops your own team, but what about an admin who can rebuild the vault?'): new threat 'thr-log-integrity' (audit-trail manipulation / insider evidence tampering), new component 'comp-trust-anchor' (external trust anchoring: qualified timestamps, cross-organizational anchoring, eIDAS electronic ledgers), new regulation 'reg-eidas2' (Reg. (EU) 2024/1183 — qualified electronic ledgers carry a legal presumption of integrity and sequential ordering, Art. 45k). meta.evidence gains a four-step verifiability ladder (self-asserted → tamper-evident → externally-anchored → independently-attested); evidence nodes carry a new 'verifiability' field stating the minimum credible rung.
  • THEME 2 — Obligation ≠ control objective ≠ control ≠ evidence (answers 'a useful graph may need to separate obligation, control objective and evidence'): new node type 'control' (Control Objective) with new edge types 'operationalized_by' (obligation → control objective) and 'satisfied_by' (control objective → component/pattern). Piloted on the Art. 12 / Art. 14 / Art. 15 chains with six control objectives (log completeness, log integrity & non-repudiation, log access & retention governance, adversarial-robustness testing, runtime injection defense, oversight competence & authority). 'evidenced_by' now also runs from control objectives to artifacts. Community mandate: extend the control layer to the remaining obligations.
  • THEME 3 — Currency & drift (answers 'a node that was accurate at launch can quietly become wrong'): meta.currency added — status vocabularies for legal acts (in-force/amended/proposed/repealed) and standards (draft/enquiry/formal-vote/published/ojeu-cited), per-node 'status' + 'lastVerified' fields, monitored feeds (OJEU, EP Legislative Observatory, JTC 21 dashboard, AI Office guidance), quarterly deepsearch review + community-dispute-triggered re-verification, and change-propagation rule (status change flags all dependent edges for review). Live proof shipped in this very release: prEN 18286 became EN 18286:2026 (published July 2026, first AI Act harmonised-standard candidate to reach publication; OJEU citation still pending) — the node was silently stale and is updated here.
  • Agentic gap-fill from the source dossiers: new threat 'thr-cascade' (cascading multi-agent failure incl. goal drift), new pattern 'pat-shadow-mode' (observe-and-score before enforce), new standard 'std-imda-agentic' (IMDA Model AI Governance Framework for Agentic AI, Jan 2026, updated Jun 2026 — first state-issued agentic-specific guidance).
  • Standards backfill for Art. 13/15 evidence: 'std-pren12792' (prEN ISO/IEC 12792 — transparency taxonomy, the Art. 13 harmonised-norm candidate) and 'std-iso4213' (ISO/IEC 4213 — ML performance measurement, metric basis for declared accuracy).
  • US health layer: 'reg-hipaa' node wired to the clinical use cases (scribing, diagnostics, prior-auth).
  • meta.assuranceEcosystem added: TÜV AI.Lab (JV of the five TÜVs; AI Assessment Matrix; person certifications), DAkkS accreditation chain (ISO/IEC 42006, ISO/IEC 17021-1, Reg. (EC) 765/2008), notified-body pipeline, EN 18286 publication status.
  • Desc enrichments via new 'updateNodes' merge section: MCP protocol has no built-in authn/authz (why the gateway is mandatory), Shadow-AI discovery on the risk register, Human-as-a-Tool naming on the escalation queue, sequential-vs-parallel guardrail latency economics (300–800 ms vs slowest-single-check), JTC 21 mandate M/593, ISO 42001 Annex SL/PDCA plus community-disputed Annex A control count (38 vs 39), Art. 14 'qualified, trained natural persons'.
  • Deferred (logged, not shipped): CCPA detector extension, vendor/market-landscape node type, five-layer SaaS reference blueprint node, EUCS sovereignty levels — queued for community discussion in v1.6.
Contributors to this release: Assurance structure — obligation vs. control objective vs. evidence · Currency — mappings decay silently between audits · Evidence trust — who can rewrite the audit trail