Skip to content

Regulated AI Navigator

Turn an AI use case into its full regulatory footprint — every domain it touches, from AI law and data protection to cyber, product safety and sector rules — with the obligations, the architecture and the evidence you owe, in about two minutes.

Community-curated knowledge graph — every claim carries its citation across law, engineering and governance. Every change traceable →

Start where you stand →Browse 45 profiles

Method

Correctness measurements

The suite compares what the reasoner derives against expectations authored from statutory text, and it injects deliberate faults into the graph to find out which errors the suite is blind to. Both results are published here in full, including the parts that are unfavourable. There is no single accuracy figure on this page: an average over unlike assertions hides the one number that matters, which is how often a law is claimed that does not apply.

Fixture and version

Graph version
2.13.0
Graph nodes
475
Cases in the fixture
60
Expectations met
54 met · 6 unmet

Graph content hash 9d0641791cb90d00ce812f89b29da690de324b255edf6db48e8ca9585a70a94c · dated 2026-08-28. Every case, expectation, negative reason and source URL lives in one file: src/testing/golden/cases.ts.

5 of 60 cases are not independently verified: their expectations do not yet carry an article-level source with a URL and a retrieval date for every value. They still run and are reported, and they are excluded from the sourced counts above.

Cases per category

Composition is part of the result. 26 of 60 cases assert that something does not apply, 18 of 60 are one half of a paired case where only one variable differs, and 8 of 60 turn on the status of an instrument in time rather than on its subject matter.

Golden cases per category
CategoryCasesSourcedNot independently verifiedMetUnmetAccepted
Externally-authored scenarios303002733
Jurisdiction pairs651600
Temporal status880800
Adversarial input550500
Degenerate input220200
Confidence calibration404400
Role pairs550233

Metric matrix

Exclusion precision
100.0%

32 negative assertions — how often an instrument the fixture says does not apply was nevertheless presented as applicable

Inclusion recall
100.0%

61 containment assertions — how often a duty the fixture requires was actually derived

Flag recall
83.3%

12 flag assertions — contested, deferred, stayed, not-in-force, role-dependent, insufficient input, prohibited

Read these three separatelyThey fail differently. A gap in inclusion recall means a duty is missing and the reader under-prepares. A gap in exclusion precision means a law is asserted that does not apply, which is the error class that makes an output wrong rather than incomplete. Exclusion precision below 1.0 is a release-blocking defect for the affected cases, and it is below 1.0 today.

Mutation kill rate, per operator

A green suite may be green because the graph is right or because the cases assert nothing that could go wrong. The harness settles that: it injects one plausible graph fault, re-runs the suite, and asks whether any previously-met case now fails. Faults that nothing notices are named below. Recorded 2026-08-28 against graph v2.13.0: 8 mutants per operator, 58 of 475 nodes actually asserted about by the fixture.

Injected graph faults and whether the suite detected them
Fault operatorWhat it simulatesInjectedDetectedKill rateCandidates (asserted / total)
applies-in-flipan instrument is mapped to the wrong jurisdiction (copy-paste across a border)8675%16 / 86
status-force-in-forcea pending, withdrawn or repealed instrument is presented as applicable law8338%5 / 23
triggers-deletea duty-creating edge is lost in an edit, so a real obligation disappears8225%164 / 229
triggers-spuriousan obligation is attached to a use case it does not govern (over-claiming)800%19 / 45
tier-shifta classification lands one step off — the single most consequential error8675%19 / 45
gate-inverta boolean gate on a node is inverted (profiling, scoring, always-applicable)8338%34 / 120
crosswalk-swapa crosswalk claims equivalence where the mapping is only an overlap800%12 / 21

Surviving mutants — the blind spots

Each line is a specific graph error the suite does not currently detect. This list is the useful output of the harness; the percentages above are only its summary.

applies-in-flipan instrument is mapped to the wrong jurisdiction (copy-paste across a border)

  • · reg-co-admt applies_in jur-us-co → jur-us-il (Colorado ADMT Act (SB 26-189))
  • · reg-colorado applies_in jur-us-co → jur-us-il (Colorado AI Act)

status-force-in-forcea pending, withdrawn or repealed instrument is presented as applicable law

  • · reg-aild status "withdrawn" → "in-force" (AI Liability Directive (withdrawn))
  • · reg-colorado status "repealed — reenacted by SB 26-189 (2026); never took effect" → "in-force" (Colorado AI Act)
  • · ae-pdpl status "enacted-not-yet-applicable" → "in-force" (Federal PDPL — Decree-Law 45/2021 (AE))
  • · au-mandatory-guardrails status "withdrawn" → "in-force" (Mandatory AI guardrails proposals paper (AU))
  • · ca-bill-c36 status "pending" → "in-force" (Bill C-36 — Protecting Privacy and Consumer Data Act (CA))

triggers-deletea duty-creating edge is lost in an edit, so a real obligation disappears

  • · delete uc-admissions-utility triggers art-49
  • · delete uc-admissions-utility triggers reg-aiact
  • · delete uc-admissions-utility triggers reg-gdpr
  • · delete uc-biometric-access triggers reg-aiact
  • · delete uc-biometric-access triggers reg-gdpr
  • · delete uc-biometric-access triggers reg-il-bipa

triggers-spuriousan obligation is attached to a use case it does not govern (over-claiming)

  • · add uc-admissions-utility triggers art-13 (Art. 13 — Transparency to Deployers)
  • · add uc-biometric-access triggers art-13 (Art. 13 — Transparency to Deployers)
  • · add uc-chatbot triggers art-13 (Art. 13 — Transparency to Deployers)
  • · add uc-codegen triggers art-13 (Art. 13 — Transparency to Deployers)
  • · add uc-confidential-summary triggers art-13 (Art. 13 — Transparency to Deployers)
  • · add uc-credit triggers art-13 (Art. 13 — Transparency to Deployers)
  • · add uc-diagnosis triggers art-13 (Art. 13 — Transparency to Deployers)
  • · add uc-emotion-interview triggers art-13 (Art. 13 — Transparency to Deployers)

tier-shifta classification lands one step off — the single most consequential error

  • · uc-admissions-utility classified_as rc-limited → rc-high
  • · uc-emotion-interview classified_as rc-prohibited → rc-high

gate-inverta boolean gate on a node is inverted (profiling, scoring, always-applicable)

  • · br-pl2338.operatorBinding false → true (PL 2338/2023 AI framework (BR))
  • · ca-aida.operatorBinding false → true (AIDA — Bill C-27 (CA))
  • · reg-aild.operatorBinding false → true (AI Liability Directive (withdrawn))
  • · reg-co-admt.operatorBinding false → true (Colorado ADMT Act (SB 26-189))
  • · reg-colorado.operatorBinding false → true (Colorado AI Act)

crosswalk-swapa crosswalk claims equivalence where the mapping is only an overlap

  • · art-15 overlaps_with std-iso27001 → equivalent_to
  • · art-15 overlaps_with std-nist600 → equivalent_to
  • · art-27 overlaps_with std-iso42005 → equivalent_to
  • · art-72 overlaps_with nis2-23 → equivalent_to
  • · art-9 overlaps_with std-iso23894 → equivalent_to
  • · art-9 overlaps_with std-nist → equivalent_to
  • · gdpr-22 overlaps_with art-14 → equivalent_to
  • · gdpr-33 overlaps_with nis2-23 → equivalent_to

Failures accepted with an owner

A case whose expectation is not met may be accepted rather than fixed, but only in writing: with an owner, the date it was accepted, and the reason. The suite asserts that every case marked this way still fails, so an accepted failure cannot quietly become a passing one.

  • s-legalresearch · Externally-authored scenarios

    tier lands on rc-limited; role-dependent reading not surfaced as a flag

    Owner kg-curators · accepted 2026-08-15

  • s-admissions-utility · Externally-authored scenarios

    authored contested reading not surfaced as a flag

    Owner kg-curators · accepted 2026-08-15

  • r-hr-provider · Role pairs

    provider/deployer duty split not applied to Art. 43

    Owner kg-curators · accepted 2026-08-15

  • r-hr-deployer · Role pairs

    provider/deployer duty split not applied to Art. 43

    Owner kg-curators · accepted 2026-08-15

  • r-rebrand-user · Role pairs

    Art. 25 role shift not applied

    Owner kg-curators · accepted 2026-08-15

  • g-scope-drift-before · Externally-authored scenarios

    The reasoner tiers this as high risk on the employment keyword alone ('HR handbook'), although the described system evaluates no person and matches no Annex III point — the over-triggering failure the deep-search audit predicted. Recorded as a disclosed recall/precision gap on the tier, not as a claimed duty: the case asserts no negative expectation, so nothing wrong is published while the detector is narrowed.

    Owner RAIN editorial · accepted 2026-08-17

What this does not cover

  • It is not legal advice and not a legal opinion. The expectations were authored by reading statutory text; agreement with them is agreement with a reading, not a determination by a competent authority or a court.
  • No independent third party has checked this fixture. Where a case is marked not independently verified, no article-level source is attached to every expected value yet.
  • 60 cases are a sample, not a population. The graph carries 475 nodes and the fixture asserts about 58 of them. A fault in a node no case asserts about cannot be detected here — by construction, not by oversight.
  • The mutation figures describe a sample of faults (8 per operator), chosen from the asserted region. A 100% kill rate for an operator would be a statement about those mutants only.
  • Crosswalk faults remain 0/8 killed, and the zero is real — a declared assertion-vocabulary gap, unchanged by the latest release. The crosswalk-swap operator turns an overlaps_with mapping into equivalent_to. The derivation path the fixture asserts over never reads the relation type — the crosswalk view is a separate surface — so no case can observe the change. This is a coverage gap in the assertion vocabulary, not a fixture-authoring gap, and it is reported rather than papered over with a case that cannot fail.
  • Nothing here measures the law itself being current. Instrument status and dates are tracked separately, per node, with a retrieval date and a source; the suite only checks that the derivation respects the status the graph records.
  • Confidence bands are ordinal. Cases may assert that one situation is banded strictly lower than another; no case asserts an absolute confidence number, because that would be a claim about the implementation rather than about the law.
  • Coverage of markets is uneven. Most cases run against EU and US expectations; other jurisdictions in the graph carry far fewer, or none.

Related: the public track record logs every correction made after publication, and sources and references lists the instruments behind the graph.