Skip to content

Regulated AI Navigator

Turn an AI use case into its full regulatory footprint — every domain it touches, from AI law and data protection to cyber, product safety and sector rules — with the obligations, the architecture and the evidence you owe, in about two minutes.

Community-curated knowledge graph — every claim carries its citation across law, engineering and governance. Every change traceable →

Start where you stand →Browse 78 profiles

The graph in numbers

This page is the knowledge graph looking at itself. Every number below is computed from knowledge-graph.json and the release changelog at render time — nothing is typed in by hand, so nothing here can quietly go out of date. Where the data does not record a value, the gap stays visible instead of being filled with a plausible number. standards & guidance lifecycle →

Graph v2.21.0 · 2026-09-22 · 700 nodes · 2290 edges · 87 releases

How the graph works

Before the numbers: what one claim carries, and what an edge does that a list cannot.

One real path through the graph
  1. Use CaseAI Credit Scoring & Loan Decisioning
  2. triggersRegulation / LawConsumer Credit Directive II (CCD2)Directive (EU) 2023/2225 of the European Parliament and of the Council of 18 October 2023 on credit agreements for consumers and repealing Directive 2008/48/EC
  3. imposesAI Act / GDPR ArticleArt. 18 — Obligation to assess the creditworthiness of the consumerArt. 18(8) — where the creditworthiness assessment involves automated processing of personal data, the consumer has the right to human intervention: a clear and comprehensible explanation of the assessment including the logic and risks of the automated processing and its significance and effects on the decision, to express their own point of view, and to request a review of the assessment and of the credit decision; Art. 18(9) — a rejected applicant must be told that the assessment was automated and how to contest it; Art. 18(3) — no GDPR Art. 9 special-category data and no social-network sources
  4. operationalized byControl ObjectiveCO: Oversight Competence & Authority
  5. satisfied byTechnical ComponentHITL Escalation Queue & Review UI

Rendered from graph v2.21.0 — the same edges the analysis walks. Follow this path in the explorer →

Every claim (node) carries:

  • a formal citation — the instrument, not a paraphrase
  • a lifecycle status — in force, amended, withdrawn, published
  • a verification date — 314 of 359 legal claims have one
  • named reviewers — the people who checked it, on the claim
  • a dispute button — one click, source required

A claim without a verification date shows as unverified — honestly.

Why a graph beats a list:

  • 16 node types, 24 relationship types — a fixed, queryable vocabulary
  • answers follow edges: same input, same answer, every time
  • traversable in 4 directions — use case, regulations, control set, existing stack
  • 0 orphan claims / 0 broken references — enforced in CI

Lists tell you what exists. Edges tell you what follows.

Size & composition

What kinds of claims the knowledge graph holds, and how they connect.

700nodesEach node is one addressable claim — a law, an article, a control, an artefact.
2290edgesThe edges are the product: they are what turns a use case into an obligation list.
32detectorsKeyword detectors map free-text use-case descriptions onto graph nodes.
16 / 24node / edge typesA small, fixed vocabulary is what keeps the graph queryable rather than a wiki.

Nodes per type

Edges per type

Growth

How the graph has grown release by release, and how often it is updated.

Releases are the only way content enters the graph, so the release series is the growth curve. Early releases predate the changelog or did not record their counts; those markers appear without a number rather than with an estimate.

87releases loggedEvery one of them names what changed and who challenged it.
1 daverage release cadenceCadence tells you how fast a correction you report can reach production.
87 / 87releases with recorded countsThe rest are honest gaps in the historical record, not zeroes.
v1.52026-08-04184 nodes416 edgesentry →
v1.62026-08-05243 nodes (+59)645 edges (+229)+1 dentry →
v2.02026-08-06257 nodes (+14)695 edges (+50)+1 dentry →
v2.12026-08-06279 nodes (+22)950 edges (+255)+0 dentry →
v2.1.12026-08-07279 nodes957 edges (+7)+1 dentry →
v2.1.22026-08-07279 nodes957 edges+0 dentry →
v2.22026-08-09296 nodes (+17)1030 edges (+73)+2 dentry →
v2.32026-08-09299 nodes (+3)1062 edges (+32)+0 dentry →
v2.3.12026-08-09299 nodes1062 edges+0 dentry →
v2.3.22026-08-10299 nodes1062 edges+1 dentry →
v2.4.02026-08-11389 nodes (+90)1267 edges (+205)+1 dentry →
v2.4.12026-08-11389 nodes1267 edges+0 dentry →
v2.4.22026-08-11389 nodes1276 edges (+9)+0 dentry →
v2.5.02026-08-11401 nodes (+12)1311 edges (+35)+0 dentry →
v2.5.12026-08-11401 nodes1311 edges+0 dentry →
v2.6.02026-08-11404 nodes (+3)1322 edges (+11)+0 dentry →
v2.6.12026-08-11404 nodes1322 edges+0 dentry →
v2.7.02026-08-11405 nodes (+1)1346 edges (+24)+0 dentry →
v2.7.12026-08-11405 nodes1346 edges+0 dentry →
v2.8.02026-08-12405 nodes1346 edges+1 dentry →
v2.8.12026-08-12405 nodes1346 edges+0 dentry →
v2.8.22026-08-12405 nodes1346 edges+0 dentry →
v2.9.02026-08-12408 nodes (+3)1357 edges (+11)+0 dentry →
v2.10.02026-08-15447 nodes (+39)1586 edges (+229)+3 dentry →
v2.10.12026-08-15447 nodes1586 edges+0 dentry →
v2.11.02026-08-15447 nodes1586 edges+0 dentry →
v2.12.22026-08-15447 nodes1586 edges+0 dentry →
v2.12.32026-08-15447 nodes1586 edges+0 dentry →
v2.12.42026-08-16447 nodes1586 edges+1 dentry →
v2.12.52026-08-16447 nodes1586 edges+0 dentry →
v2.12.72026-08-16447 nodes1586 edges+0 dentry →
v2.12.82026-08-16447 nodes1586 edges+0 dentry →
v2.12.92026-08-17447 nodes1586 edges+1 dentry →
v2.13.02026-08-17449 nodes (+2)1591 edges (+5)+0 dentry →
v2.13.12026-08-17449 nodes1591 edges+0 dentry →
v2.13.22026-08-17467 nodes (+18)1683 edges (+92)+0 dentry →
v2.14.02026-08-17467 nodes1683 edges+0 dentry →
v2.14.12026-08-17467 nodes1683 edges+0 dentry →
v2.15.02026-08-17471 nodes (+4)1704 edges (+21)+0 dentry →
v2.15.12026-08-18471 nodes1704 edges+1 dentry →
v2.15.22026-08-18471 nodes1704 edges+0 dentry →
v2.16.02026-08-26473 nodes (+2)1710 edges (+6)+8 dentry →
v2.17.02026-08-26474 nodes (+1)1713 edges (+3)+0 dentry →
v2.16.12026-08-27474 nodes1713 edges+1 dentry →
v2.18.02026-08-27475 nodes (+1)1716 edges (+3)+0 dentry →
v2.21.02026-08-27475 nodes1716 edges+0 dentry →
v2.19.02026-08-28475 nodes1716 edges+1 dentry →
v2.19.22026-08-28475 nodes1716 edges+0 dentry →
v2.22.02026-08-28475 nodes1714 edges (+-2)+0 dentry →
v2.23.02026-08-29475 nodes1714 edges+1 dentry →
v2.24.02026-08-31478 nodes (+3)1723 edges (+9)+2 dentry →
v2.25.02026-09-04478 nodes1723 edges+4 dentry →
v2.25.12026-09-04478 nodes1723 edges+0 dentry →
v2.26.02026-09-05498 nodes (+20)1774 edges (+51)+1 dentry →
v2.26.12026-09-06498 nodes1774 edges+1 dentry →
v2.26.22026-09-07498 nodes1774 edges+1 dentry →
v2.26.32026-09-07498 nodes1774 edges+0 dentry →
v2.27.02026-09-07498 nodes1775 edges (+1)+0 dentry →
v2.28.02026-09-07504 nodes (+6)1802 edges (+27)+0 dentry →
v2.29.02026-09-07505 nodes (+1)1805 edges (+3)+0 dentry →
v2.30.02026-09-08505 nodes1805 edges+1 dentry →
v2.31.02026-09-09505 nodes1805 edges+1 dentry →
v2.32.02026-09-09505 nodes1805 edges+0 dentry →
v2.33.02026-09-10505 nodes1805 edges+1 dentry →
v2.34.02026-09-10505 nodes1805 edges+0 dentry →
v2.35.02026-09-10515 nodes (+10)1824 edges (+19)+0 dentry →
v2.36.02026-09-10529 nodes (+14)1854 edges (+30)+0 dentry →
v2.37.02026-09-10530 nodes (+1)1859 edges (+5)+0 dentry →
v2.38.02026-09-10530 nodes1859 edges+0 dentry →
v2.39.02026-09-10535 nodes (+5)1864 edges (+5)+0 dentry →
v2.40.02026-09-11536 nodes (+1)1868 edges (+4)+1 dentry →
v2.41.02026-09-11536 nodes1868 edges+0 dentry →
v2.42.02026-09-12536 nodes1868 edges+1 dentry →
v2.43.02026-09-12537 nodes (+1)1869 edges (+1)+0 dentry →
v2.44.02026-09-12537 nodes1869 edges+0 dentry →
v2.45.02026-09-12537 nodes1869 edges+0 dentry →
v2.46.02026-09-12537 nodes1868 edges (+-1)+0 dentry →
v2.47.02026-09-12537 nodes1868 edges+0 dentry →
v2.48.02026-09-14537 nodes1868 edges+2 dentry →
v2.49.02026-09-15566 nodes (+29)1955 edges (+87)+1 dentry →
v2.50.02026-09-18596 nodes (+30)2021 edges (+66)+3 dentry →
v2.51.02026-09-18619 nodes (+23)2068 edges (+47)+0 dentry →
v2.52.02026-09-18635 nodes (+16)2115 edges (+47)+0 dentry →
v2.53.02026-09-21653 nodes (+18)2172 edges (+57)+3 dentry →
v2.54.02026-09-21667 nodes (+14)2207 edges (+35)+0 dentry →
v2.55.02026-09-21693 nodes (+26)2275 edges (+68)+0 dentry →
v2.56.02026-09-22700 nodes (+7)2290 edges (+15)+1 dentry →

Taller bar pair = larger graph at that release. Nodes in gold, edges in blue.

Structure & density

How tightly the claims are linked, and whether any are stranded or overloaded.

Schema correspondence. The common enterprise ontology for agentic AI maps onto this graph without a translation layer: VendorTool corresponds to the market examples carried on each vendor category (products are data on a layer, not nodes, so a rename is never a migration), TechStackLayer to the agentic stack layers, RegulatoryFramework to our regulation and article nodes, TechnicalControl to components and control objectives, and EnterpriseUseCase to the use-case profiles. Nothing in the published schemas requires a new node type here.

4.68e-3directed density (E / N·(N−1))A compliance graph should be sparse: dense would mean everything relates to everything, which is the same as saying nothing.
6.5average edges per nodeThe intuitive reading of density: how many other claims an average claim is tied to.
1 / 4 / 6.5 / 89degree min / median / mean / maxA high max with a low median is normal and healthy: hub laws carry many links, leaf artefacts a few.
0isolated nodesZero is the target — an integrity rule fails the build on any node with no edge, because an unlinked claim can never be reached by a use case.
4connected componentsOne component means every claim is reachable from every other. More than one means an island the reasoning engine can never walk into.
100%use cases with a complete chainThe core promise as a number: risk class + at least one regulation + at least one technical component reachable from the use case.
3 fragments outside the main component: Taiwan, AI Basic Act (TW) · African Union (continental), AU Continental AI Strategy · Egypt, PDPL 151/2020 (EG), Egypt AI Strategy 2025–2030. A fragment is not an error — the nodes are correct — but it is a missing edge, and it is on the worklist rather than hidden.

The load-bearing nodes

The ten most connected nodes. If one of these is wrong, it is wrong in many answers at once — which is exactly why the verification worklist prioritises them.

  1. EU AI Actregulation · 89 edges
  2. GDPRregulation · 69 edges
  3. European Unionjurisdiction · 66 edges
  4. United States (federal)jurisdiction · 54 edges
  5. High RiskriskClass · 42 edges
  6. WORM / Immutable Audit Vaultcomponent · 38 edges
  7. Human-in-the-Loop Core Patternblueprint · 36 edges
  8. Minimal RiskriskClass · 35 edges
  9. Clinical Imaging Triage & Patient Follow-UpuseCase · 35 edges
  10. HITL Escalation Queue & Review UIcomponent · 33 edges

Average degree per node type

Shows which layers are well embedded and which hang thin — a standard with a degree of one is cited but not yet woven into the control model.

Trust & coverage

How much of the graph is dated, sourced and independently reviewed.

These four numbers are the ones to read before trusting any answer this tool gives you. They are deliberately not rounded up: the gaps are the public worklist →

314 / 359legal & standards nodes with a verification date (87%) — 0 verified longer than 90 days ago
312 / 359with a lifecycle status (87%) — in-force, amended, withdrawn, published, OJEU-cited
26 / 39evidence artefacts placed on the verifiability ladder (67%) — self-asserted through independently attested
292 / 359legal & standards nodes that resolve to a primary source link (81%) — the "says who?" coverage
12 / 20control objectives with an ISO 42001 or CSA AICM mapping (60%) — 8 deliberately unmapped, because an empty mapping is not a zero
0 / 0community-reviewed of 0 nodes carrying any community signal — 0 currently disputed, 700 with no vote yet

Why it matters: a claim with no verification date is a claim, not a fact, and this tool says so on the node itself. Citation coverage is the stricter test — it asks whether you can click through to the authority, not whether someone asserted it. Read the full reference list →

Jurisdictions

Instruments, maturity tier and verification currency per jurisdiction — computed from meta.jurisdictions and the instrument nodes, never typed in by hand.

29jurisdictions in the registryEvery code the graph is willing to make a claim about, whether or not an instrument is mapped yet.
29jurisdictions with mapped instrumentsThe rest are registered but not yet carrying a regulation, standard or policy node.
9thin-coverage jurisdictionsA stub entry only — represented, not yet built out. Every thin row below links to the verification queue.
88%instruments with a verification dateSame currency question as the trust section above, answered per jurisdiction instead of for the graph as a whole.

Maturity tiers (T1–T4)

A tier is a legal-status statement, not a quality score — T1 is a binding horizontal AI law, T4 is strategy only.

Instruments per jurisdiction

Instruments, tier and verification coverage per jurisdiction
European Union (EU)binding horizontal AI lawenforcement high635395%full
United States (federal) (US)binding data/sector law onlyenforcement high534985%full
Cross-jurisdiction bridges (GLOBAL)soft-law frameworknot yet enforced272656%full
Germany (DE)binding horizontal AI lawenforcement high151567%thin — verify
China (CN)binding horizontal AI lawenforcement high77100%full
Singapore (SG)soft-law frameworkenforcement medium66100%full
United Kingdom (GB)binding data/sector law onlyenforcement high65100%full
Australia (AU)binding data/sector law onlyenforcement medium54100%full
Canada (CA)binding data/sector law onlyenforcement medium53100%full
United Arab Emirates (AE)binding data/sector law onlyenforcement medium43100%full
United States — Colorado (US-CO)binding horizontal AI lawnot yet enforced41100%full
United States — Illinois (US-IL)binding data/sector law onlyenforcement medium44100%thin — verify
India (IN)binding data/sector law onlynot yet enforced33100%full
Japan (JP)binding horizontal AI lawenforcement medium33100%full
United States — New York (US-NY)binding data/sector law onlyenforcement medium32100%full
Brazil (BR)binding data/sector law onlyenforcement medium21100%full
Egypt (EG)binding data/sector law onlydormant in practice20100%thin — verify
Indonesia (ID)binding data/sector law onlyenforcement low21100%thin — verify
Kenya (KE)binding data/sector law onlyenforcement medium20100%thin — verify
Nigeria (NG)binding data/sector law onlyenforcement medium22100%full
Rwanda (RW)binding data/sector law onlyenforcement low20100%thin — verify
Saudi Arabia (SA)binding data/sector law onlyenforcement medium22100%full
South Africa (ZA)binding data/sector law onlyenforcement medium21100%full
South Korea (KR)binding horizontal AI lawenforcement high22100%full
Switzerland (CH)binding data/sector law onlyenforcement medium22100%full
Vietnam (VN)binding horizontal AI lawnot yet enforced22100%full
African Union (continental) (AF-AU)strategy onlynot yet enforced11100%thin — verify
France (FR)binding horizontal AI lawenforcement high110%thin — verify
Taiwan (TW)binding AI law passed — not yet in forcenot yet enforced10100%thin — verify

Thin rows are stub registry entries — represented so a claim about that market is never silently omitted, but not yet backed by a mapped instrument. Help verify a jurisdiction →

Automated freshness pipeline

Regulatory WatchMondays 04:30 UTC

Checks the monitored regulatory feeds for changes to legal status, deadlines, sanctions and standard lifecycle stages, and proposes dated updates to the instruments already in the graph.

2026-09-21·failed·0 findings·0 proposals
Use-Case ScoutWednesdays 04:30 UTC

Scans enforcement news, enterprise deployments, vendor launches, case studies and incidents in regulated sectors for use cases the catalogue does not yet describe.

2026-09-21·failed·0 findings·0 proposals
Graph ReflectionFridays 04:30 UTC

Re-runs the integrity and consistency battery over the graph, reports every violation, and verifies the single stalest claim against its own authoritative source.

2026-09-21·completed·12 findings·0 proposals
Technology WatchTuesdays 04:30 UTC

Tracks technology-capability shifts relevant to compliance — hosting and residency developments (sovereign clouds, confidential computing, the EU data boundary), identity and verification methods, and agentic-architecture capabilities — and proposes updates to the hosting fields on vendor-category examples and to affected component, pattern and blueprint nodes.

2026-09-21·failed·0 findings·0 proposals
Vendor WatchThursdays 04:30 UTC

Watches the vendor landscape for new entrants, discontinued products, changed hosting models and changed compliance claims, and proposes updates to the market examples already recorded — always as disputable observations, never as certifications.

2026-09-21·failed·0 findings·0 proposals
Evidence SourcingMondays 06:30 UTC

Finds the article-level provision behind duty-creating edges that carry no citation yet, and files each find as a curator proposal that attaches the provision to that exact edge — or an explicit “no provision found” verdict for the curator to check, re-base or remove the edge. It never writes to the graph and never raises the coverage metric by itself.

2026-09-21·failed·0 findings·0 proposals

Agents research and propose; every change is decided by a human curator and logged in the changelog. Read every run report →

Evidence layer

How far the graph gets past "here is your obligation" to "here is the artifact that shows you met it" — and how honest it is about where each artifact comes from.

39evidence artifactsDeliverable classes an authority or auditor can request by name.
2.6×reuse factorObligations served per artifact on average — one artifact usually satisfies several regulatory cells.
13 / 26text-derived / practice-derivedText-derived means the cited article names the artifact; practice-derived is customary and openly disputable.
65obligations with an artifactThe rest are open work — visible rather than quietly omitted.

Open the full evidence matrix →

Cross-regime crosswalk

How much of the graph states, in the open, that two obligations from different regimes ask for the same thing. Every crosswalk edge is an interpretive claim, so it is counted by relation and by confidence — an asserted mapping is worth less than an established one, and hiding the difference would be the dishonest move.

21crosswalk mappingsEdges of type equivalent_to, overlaps_with or conflicts_with between obligation-side nodes of different regimes.
8 / 13established / assertedEstablished means the mapping is backed by an official or standards-body correspondence; asserted is our reading, disputable like every other claim.
15regime pairs connectedDistinct pairs of regulatory regimes joined by at least one mapping, across 15 regimes touched.
12artifacts serving several regimesEvidence artifacts reached from obligations in more than one regime — the measurable part of 'comply once, evidence many'.

Open the cross-regime crosswalk →

Integrity

Whether the graph still keeps the structural promises it makes to users.

56 / 68integrity rules passingEach rule checks one structural promise, e.g. every regulation resolves to at least one technical component.
0errorsAn error blocks a release. The target is, and stays, zero.
403warningsWarnings are known thin spots, kept visible on purpose rather than downgraded.

The same suite runs on every change — in unit tests and in CI — so a merge that breaks a structural promise fails before it ships. Open the full validation report →