The graph in numbers
This page is the knowledge graph looking at itself. Every number below is computed from knowledge-graph.json and the release changelog at render time — nothing is typed in by hand, so nothing here can quietly go out of date. Where the data does not record a value, the gap stays visible instead of being filled with a plausible number.
Size & composition
What kinds of claims the knowledge graph holds, and how they connect.
Nodes per type
- Technical Component45 · 16%
A concrete technical building block.
- Regulation / Law38 · 14%
A legal act in scope — EU, national or US.
- Use Case35 · 13%
A concrete deployment of AI in a regulated business process.
- Standard / Framework30 · 11%
A standard or framework that can evidence conformity.
- Design Pattern28 · 10%
A reusable design pattern inside a blueprint.
- Evidence Artifact26 · 9%
An artefact that proves an obligation was met.
- Threat (OWASP)22 · 8%
A failure mode or attack the system has to withstand.
- AI Act / GDPR Article21 · 8%
A single article of an act, carrying the obligation text.
- Control Objective12 · 4%
A control objective translating an obligation into practice.
- Architecture Blueprint6 · 2%
A reference architecture for a class of use case.
- Vendor Category6 · 2%
A functional market layer that supplies components.
- AI Act Risk Class4 · 1%
The AI Act risk tier a use case falls into.
- Oversight Mode4 · 1%
A human-oversight mode (HITL / HOTL / HIC).
- Value-Chain Role2 · 1%
A duty-bearing role under the act (provider, deployer).
Edges per type
- triggers165 · 17%
Use Case → Regulation / Law — Use case brings this regulation into scope
- recommends131 · 14%
Use Case → Design Pattern — Use case profile maps to this blueprint / oversight mode
- evidenced by119 · 12%
Use Case → Evidence Artifact — Obligation, regulation or control objective is evidenced by this artifact
- requires103 · 11%
Use Case → Technical Component — Regulation directly requires this component
- includes65 · 7%
Architecture Blueprint → Technical Component — Blueprint bundles this pattern/component
- mitigated by59 · 6%
Threat (OWASP) → Technical Component — Threat is mitigated by this component or pattern
- implemented by58 · 6%
AI Act / GDPR Article → Technical Component — Obligation is architecturally implemented by this component
- threatens56 · 6%
Use Case → Threat (OWASP) — Threat is especially relevant for this use case
- relates to42 · 4%
Threat (OWASP) → AI Act / GDPR Article — General semantic relation
- classified as35 · 4%
Use Case → AI Act Risk Class — Use case falls into this AI Act risk class
- supported by33 · 3%
AI Act / GDPR Article → Standard / Framework — Standard provides presumption of conformity / operational guidance for this obligation
- imposes22 · 2%
AI Act Risk Class → AI Act / GDPR Article — Risk class imposes this legal obligation
- supplied by22 · 2%
Technical Component → Vendor Category — Component or pattern is typically implemented with tooling from this vendor category (named vendors are community-maintained desc content)
- satisfied by19 · 2%
Control Objective → Technical Component — Control objective is satisfied by this component or pattern (alternatives possible)
- produced by15 · 2%
Evidence Artifact → Technical Component — Artifact is generated by this technical component
- operationalized by13 · 1%
AI Act / GDPR Article → Control Objective — Obligation is broken down into this testable control objective
Growth
How the graph has grown release by release, and how often it is updated.
Releases are the only way content enters the graph, so the release series is the growth curve. Early releases predate the changelog or did not record their counts; those markers appear without a number rather than with an estimate.
Taller bar pair = larger graph at that release. Nodes in gold, edges in blue.
Structure & density
How tightly the claims are linked, and whether any are stranded or overloaded.
The load-bearing nodes
The ten most connected nodes. If one of these is wrong, it is wrong in many answers at once — which is exactly why the verification worklist prioritises them.
- EU AI Actregulation · 37 edges
- Clinical Imaging Triage & Patient Follow-UpuseCase · 32 edges
- GDPRregulation · 30 edges
- Algorithmic Portfolio Execution & AdvisoryuseCase · 30 edges
- Agentic RDA Stack (6 Layers)blueprint · 26 edges
- WORM / Immutable Audit Vaultcomponent · 25 edges
- Automated Financial Forecasting & Audit TrailsuseCase · 25 edges
- KYC & Client Onboarding Automation (Managed Service)useCase · 25 edges
- Art. 15 — Accuracy, Robustness, Cybersecurityarticle · 24 edges
- Event Logs & Decision Tracesevidence · 24 edges
Average degree per node type
Shows which layers are well embedded and which hang thin — a standard with a degree of one is cited but not yet woven into the control model.
- Architecture Blueprint16.2
- Use Case14.9
- AI Act Risk Class13
- Oversight Mode9
- AI Act / GDPR Article8
- Technical Component6.3
- Threat (OWASP)5.8
- Regulation / Law5.3
- Evidence Artifact5.3
- Design Pattern5.1
- Control Objective4.8
- Vendor Category4
- Value-Chain Role2.5
- Standard / Framework1.9
Trust & coverage
How much of the graph is dated, sourced and independently reviewed.
These four numbers are the ones to read before trusting any answer this tool gives you. They are deliberately not rounded up: the gaps are the public worklist →
Why it matters: a claim with no verification date is a claim, not a fact, and this tool says so on the node itself. Citation coverage is the stricter test — it asks whether you can click through to the authority, not whether someone asserted it. Read the full reference list →
Integrity
Whether the graph still keeps the structural promises it makes to users.
- currency: 151 warnings
- regulation: 53 warnings
- tech: 29 warnings
The same suite runs on every change — in unit tests and in CI — so a merge that breaks a structural promise fails before it ships. Open the full validation report →