The graph in numbers
This page is the knowledge graph looking at itself. Every number below is computed from knowledge-graph.json and the release changelog at render time — nothing is typed in by hand, so nothing here can quietly go out of date. Where the data does not record a value, the gap stays visible instead of being filled with a plausible number. standards & guidance lifecycle →
How the graph works
Before the numbers: what one claim carries, and what an edge does that a list cannot.
- Use CaseAI Credit Scoring & Loan Decisioning
- triggersRegulation / LawConsumer Credit Directive II (CCD2)Directive (EU) 2023/2225 of the European Parliament and of the Council of 18 October 2023 on credit agreements for consumers and repealing Directive 2008/48/EC
- imposesAI Act / GDPR ArticleArt. 18 — Obligation to assess the creditworthiness of the consumerArt. 18(8) — where the creditworthiness assessment involves automated processing of personal data, the consumer has the right to human intervention: a clear and comprehensible explanation of the assessment including the logic and risks of the automated processing and its significance and effects on the decision, to express their own point of view, and to request a review of the assessment and of the credit decision; Art. 18(9) — a rejected applicant must be told that the assessment was automated and how to contest it; Art. 18(3) — no GDPR Art. 9 special-category data and no social-network sources
- operationalized byControl ObjectiveCO: Oversight Competence & Authority
- satisfied byTechnical ComponentHITL Escalation Queue & Review UI
Rendered from graph v2.21.0 — the same edges the analysis walks. Follow this path in the explorer →
Every claim (node) carries:
- a formal citation — the instrument, not a paraphrase
- a lifecycle status — in force, amended, withdrawn, published
- a verification date — 314 of 359 legal claims have one
- named reviewers — the people who checked it, on the claim
- a dispute button — one click, source required
A claim without a verification date shows as unverified — honestly.
Why a graph beats a list:
- 16 node types, 24 relationship types — a fixed, queryable vocabulary
- answers follow edges: same input, same answer, every time
- traversable in 4 directions — use case, regulations, control set, existing stack
- 0 orphan claims / 0 broken references — enforced in CI
Lists tell you what exists. Edges tell you what follows.
Size & composition
What kinds of claims the knowledge graph holds, and how they connect.
Nodes per type
- Regulation / Law172 · 25%
A legal act in scope — EU, national or US.
- AI Act / GDPR Article134 · 19%
A single article of an act, carrying the obligation text.
- Use Case78 · 11%
A concrete deployment of AI in a regulated business process.
- Technical Component62 · 9%
A concrete technical building block.
- Standard / Framework53 · 8%
A standard or framework that can evidence conformity.
- Evidence Artifact39 · 6%
An artefact that proves an obligation was met.
- Threat (OWASP)31 · 4%
A failure mode or attack the system has to withstand.
- Jurisdiction / Target Market29 · 4%
- Design Pattern28 · 4%
A reusable design pattern inside a blueprint.
- Control Objective20 · 3%
A control objective translating an obligation into practice.
- Architecture Blueprint19 · 3%
A reference architecture for a class of use case.
- Vendor Category17 · 2%
A functional market layer that supplies components.
- Policy / Strategy8 · 1%
- AI Act Risk Class4 · 1%
The AI Act risk tier a use case falls into.
- Oversight Mode4 · 1%
A human-oversight mode (HITL / HOTL / HIC).
- Value-Chain Role2 · 0%
A duty-bearing role under the act (provider, deployer).
Edges per type
- triggers468 · 20%
Use Case → Regulation / Law — Use case brings this regulation into scope
- recommends233 · 10%
Use Case → Architecture Blueprint — Use case profile maps to this blueprint / oversight mode
- applies in228 · 10%
Regulation / Law → Jurisdiction / Target Market — Instrument applies in this jurisdiction
- requires222 · 10%
Use Case → Technical Component — Regulation directly requires this component
- evidenced by159 · 7%
AI Act / GDPR Article → Evidence Artifact — Obligation, regulation or control objective is evidenced by this artifact
- imposes142 · 6%
Regulation / Law → AI Act / GDPR Article — Risk class imposes this legal obligation
- relates to123 · 5%
Architecture Blueprint → Control Objective — General semantic relation
- includes111 · 5%
Architecture Blueprint → Technical Component — Blueprint bundles this pattern/component
- implemented by106 · 5%
AI Act / GDPR Article → Technical Component — Obligation is architecturally implemented by this component
- mitigated by98 · 4%
Threat (OWASP) → Technical Component — Threat is mitigated by this component or pattern
- threatens96 · 4%
Use Case → Threat (OWASP) — Threat is especially relevant for this use case
- classified as78 · 3%
Use Case → AI Act Risk Class — Use case falls into this AI Act risk class
- supplied by69 · 3%
Technical Component → Vendor Category — Component or pattern is typically implemented with tooling from this vendor category (named vendors are community-maintained desc content)
- supported by43 · 2%
AI Act / GDPR Article → Standard / Framework — Standard provides presumption of conformity / operational guidance for this obligation
- operationalized by28 · 1%
AI Act / GDPR Article → Control Objective — Obligation is broken down into this testable control objective
- satisfied by25 · 1%
Control Objective → Technical Component — Control objective is satisfied by this component or pattern (alternatives possible)
- produced by19 · 1%
Evidence Artifact → Technical Component — Artifact is generated by this technical component
- overlaps with18 · 1%
AI Act / GDPR Article → Standard / Framework — Interpretive mapping: the obligations partially cover each other across regimes — evidence is reusable, duties are not identical (dispute welcome)
- recognized by13 · 1%
Standard / Framework → Jurisdiction / Target Market — Cross-jurisdiction instrument is recognized or adhered to by this jurisdiction
- referenced by5 · 0%
Standard / Framework → Jurisdiction / Target Market — Standard or framework referenced by this jurisdiction's guidance
- signed by2 · 0%
Regulation / Law → Jurisdiction / Target Market — International convention signed or ratified by this jurisdiction
- equivalent to2 · 0%
AI Act / GDPR Article → Standard / Framework — Interpretive mapping: the two obligations ask for substantially the same thing across different regimes (dispute welcome)
- conflicts with1 · 0%
AI Act / GDPR Article → AI Act / GDPR Article — Interpretive mapping: the two obligations pull in opposite directions and the tension must be resolved deliberately (dispute welcome)
- escalates to1 · 0%
Use Case → Use Case — A conditional classification escalation: when the stated condition becomes true, the source use case takes on the target's regulatory profile.
Growth
How the graph has grown release by release, and how often it is updated.
Releases are the only way content enters the graph, so the release series is the growth curve. Early releases predate the changelog or did not record their counts; those markers appear without a number rather than with an estimate.
Taller bar pair = larger graph at that release. Nodes in gold, edges in blue.
Structure & density
How tightly the claims are linked, and whether any are stranded or overloaded.
Schema correspondence. The common enterprise ontology for agentic AI maps onto this graph without a translation layer: VendorTool corresponds to the market examples carried on each vendor category (products are data on a layer, not nodes, so a rename is never a migration), TechStackLayer to the agentic stack layers, RegulatoryFramework to our regulation and article nodes, TechnicalControl to components and control objectives, and EnterpriseUseCase to the use-case profiles. Nothing in the published schemas requires a new node type here.
The load-bearing nodes
The ten most connected nodes. If one of these is wrong, it is wrong in many answers at once — which is exactly why the verification worklist prioritises them.
- EU AI Actregulation · 89 edges
- GDPRregulation · 69 edges
- European Unionjurisdiction · 66 edges
- United States (federal)jurisdiction · 54 edges
- High RiskriskClass · 42 edges
- WORM / Immutable Audit Vaultcomponent · 38 edges
- Human-in-the-Loop Core Patternblueprint · 36 edges
- Minimal RiskriskClass · 35 edges
- Clinical Imaging Triage & Patient Follow-UpuseCase · 35 edges
- HITL Escalation Queue & Review UIcomponent · 33 edges
Average degree per node type
Shows which layers are well embedded and which hang thin — a standard with a degree of one is cited but not yet woven into the control model.
- AI Act Risk Class25.8
- Use Case13.8
- Architecture Blueprint13.8
- Oversight Mode11.3
- Technical Component9.4
- Jurisdiction / Target Market8.6
- Threat (OWASP)6.7
- Control Objective6.5
- Vendor Category5.9
- Design Pattern5.6
- Regulation / Law5
- Evidence Artifact4.7
- AI Act / GDPR Article3.3
- Standard / Framework3.1
- Value-Chain Role2.5
- Policy / Strategy1
Trust & coverage
How much of the graph is dated, sourced and independently reviewed.
These four numbers are the ones to read before trusting any answer this tool gives you. They are deliberately not rounded up: the gaps are the public worklist →
Why it matters: a claim with no verification date is a claim, not a fact, and this tool says so on the node itself. Citation coverage is the stricter test — it asks whether you can click through to the authority, not whether someone asserted it. Read the full reference list →
Jurisdictions
Instruments, maturity tier and verification currency per jurisdiction — computed from meta.jurisdictions and the instrument nodes, never typed in by hand.
Maturity tiers (T1–T4)
A tier is a legal-status statement, not a quality score — T1 is a binding horizontal AI law, T4 is strategy only.
- T1 binding horizontal AI law9
- T2 binding data/sector law only17
- T3 soft-law framework2
- T4 strategy only1
Instruments per jurisdiction
| European Union (EU) | binding horizontal AI law | enforcement high | 63 | 53 | 95% | full |
| United States (federal) (US) | binding data/sector law only | enforcement high | 53 | 49 | 85% | full |
| Cross-jurisdiction bridges (GLOBAL) | soft-law framework | not yet enforced | 27 | 26 | 56% | full |
| Germany (DE) | binding horizontal AI law | enforcement high | 15 | 15 | 67% | thin — verify |
| China (CN) | binding horizontal AI law | enforcement high | 7 | 7 | 100% | full |
| Singapore (SG) | soft-law framework | enforcement medium | 6 | 6 | 100% | full |
| United Kingdom (GB) | binding data/sector law only | enforcement high | 6 | 5 | 100% | full |
| Australia (AU) | binding data/sector law only | enforcement medium | 5 | 4 | 100% | full |
| Canada (CA) | binding data/sector law only | enforcement medium | 5 | 3 | 100% | full |
| United Arab Emirates (AE) | binding data/sector law only | enforcement medium | 4 | 3 | 100% | full |
| United States — Colorado (US-CO) | binding horizontal AI law | not yet enforced | 4 | 1 | 100% | full |
| United States — Illinois (US-IL) | binding data/sector law only | enforcement medium | 4 | 4 | 100% | thin — verify |
| India (IN) | binding data/sector law only | not yet enforced | 3 | 3 | 100% | full |
| Japan (JP) | binding horizontal AI law | enforcement medium | 3 | 3 | 100% | full |
| United States — New York (US-NY) | binding data/sector law only | enforcement medium | 3 | 2 | 100% | full |
| Brazil (BR) | binding data/sector law only | enforcement medium | 2 | 1 | 100% | full |
| Egypt (EG) | binding data/sector law only | dormant in practice | 2 | 0 | 100% | thin — verify |
| Indonesia (ID) | binding data/sector law only | enforcement low | 2 | 1 | 100% | thin — verify |
| Kenya (KE) | binding data/sector law only | enforcement medium | 2 | 0 | 100% | thin — verify |
| Nigeria (NG) | binding data/sector law only | enforcement medium | 2 | 2 | 100% | full |
| Rwanda (RW) | binding data/sector law only | enforcement low | 2 | 0 | 100% | thin — verify |
| Saudi Arabia (SA) | binding data/sector law only | enforcement medium | 2 | 2 | 100% | full |
| South Africa (ZA) | binding data/sector law only | enforcement medium | 2 | 1 | 100% | full |
| South Korea (KR) | binding horizontal AI law | enforcement high | 2 | 2 | 100% | full |
| Switzerland (CH) | binding data/sector law only | enforcement medium | 2 | 2 | 100% | full |
| Vietnam (VN) | binding horizontal AI law | not yet enforced | 2 | 2 | 100% | full |
| African Union (continental) (AF-AU) | strategy only | not yet enforced | 1 | 1 | 100% | thin — verify |
| France (FR) | binding horizontal AI law | enforcement high | 1 | 1 | 0% | thin — verify |
| Taiwan (TW) | binding AI law passed — not yet in force | not yet enforced | 1 | 0 | 100% | thin — verify |
Thin rows are stub registry entries — represented so a claim about that market is never silently omitted, but not yet backed by a mapped instrument. Help verify a jurisdiction →
Automated freshness pipeline
Checks the monitored regulatory feeds for changes to legal status, deadlines, sanctions and standard lifecycle stages, and proposes dated updates to the instruments already in the graph.
Scans enforcement news, enterprise deployments, vendor launches, case studies and incidents in regulated sectors for use cases the catalogue does not yet describe.
Re-runs the integrity and consistency battery over the graph, reports every violation, and verifies the single stalest claim against its own authoritative source.
Tracks technology-capability shifts relevant to compliance — hosting and residency developments (sovereign clouds, confidential computing, the EU data boundary), identity and verification methods, and agentic-architecture capabilities — and proposes updates to the hosting fields on vendor-category examples and to affected component, pattern and blueprint nodes.
Watches the vendor landscape for new entrants, discontinued products, changed hosting models and changed compliance claims, and proposes updates to the market examples already recorded — always as disputable observations, never as certifications.
Finds the article-level provision behind duty-creating edges that carry no citation yet, and files each find as a curator proposal that attaches the provision to that exact edge — or an explicit “no provision found” verdict for the curator to check, re-base or remove the edge. It never writes to the graph and never raises the coverage metric by itself.
Agents research and propose; every change is decided by a human curator and logged in the changelog. Read every run report →
Evidence layer
How far the graph gets past "here is your obligation" to "here is the artifact that shows you met it" — and how honest it is about where each artifact comes from.
- Documents & files: 12 artifacts
- Assessments: 6 artifacts
- Test reports: 3 artifacts
- Log records: 7 artifacts
- Process records: 9 artifacts
- Registry entries: 2 artifacts
Open the full evidence matrix →
Cross-regime crosswalk
How much of the graph states, in the open, that two obligations from different regimes ask for the same thing. Every crosswalk edge is an interpretive claim, so it is counted by relation and by confidence — an asserted mapping is worth less than an established one, and hiding the difference would be the dishonest move.
- equivalent to: 2 mappings
- overlaps with: 18 mappings
- conflicts with: 1 mapping
Open the cross-regime crosswalk →
Integrity
Whether the graph still keeps the structural promises it makes to users.
- regulation: 272 warnings
- currency: 105 warnings
- tech: 20 warnings
- structure: 3 warnings
- standards: 3 warnings
The same suite runs on every change — in unit tests and in CI — so a merge that breaks a structural promise fails before it ships. Open the full validation report →