Regulated AI Navigator

Turn an AI use case into its EU AI Act risk class, the regulations it triggers, the obligations, the architecture and the evidence you owe — in about two minutes.

Community-curated knowledge graph, peer-reviewed by experts across law, engineering and governance. Every change traceable →

Analyse a use case →Browse 35 profiles

The graph in numbers

This page is the knowledge graph looking at itself. Every number below is computed from knowledge-graph.json and the release changelog at render time — nothing is typed in by hand, so nothing here can quietly go out of date. Where the data does not record a value, the gap stays visible instead of being filled with a plausible number.

Graph v2.1.2 · 2026-08-07 · 279 nodes · 957 edges · 6 releases

Size & composition

What kinds of claims the knowledge graph holds, and how they connect.

279nodesEach node is one addressable claim — a law, an article, a control, an artefact.
957edgesThe edges are the product: they are what turns a use case into an obligation list.
29detectorsKeyword detectors map free-text use-case descriptions onto graph nodes.
14 / 16node / edge typesA small, fixed vocabulary is what keeps the graph queryable rather than a wiki.

Nodes per type

Edges per type

Growth

How the graph has grown release by release, and how often it is updated.

Releases are the only way content enters the graph, so the release series is the growth curve. Early releases predate the changelog or did not record their counts; those markers appear without a number rather than with an estimate.

6releases loggedEvery one of them names what changed and who challenged it.
1 daverage release cadenceCadence tells you how fast a correction you report can reach production.
6 / 6releases with recorded countsThe rest are honest gaps in the historical record, not zeroes.
v1.52026-08-04184 nodes416 edgesentry →
v1.62026-08-05243 nodes (+59)645 edges (+229)+1 dentry →
v2.02026-08-06257 nodes (+14)695 edges (+50)+1 dentry →
v2.12026-08-06279 nodes (+22)950 edges (+255)+0 dentry →
v2.1.12026-08-07279 nodes957 edges (+7)+1 dentry →
v2.1.22026-08-07279 nodes957 edges+0 dentry →

Taller bar pair = larger graph at that release. Nodes in gold, edges in blue.

Structure & density

How tightly the claims are linked, and whether any are stranded or overloaded.

1.23e-2directed density (E / N·(N−1))A compliance graph should be sparse: dense would mean everything relates to everything, which is the same as saying nothing.
6.9average edges per nodeThe intuitive reading of density: how many other claims an average claim is tied to.
1 / 5 / 6.9 / 37degree min / median / mean / maxA high max with a low median is normal and healthy: hub laws carry many links, leaf artefacts a few.
0isolated nodesZero is the target — an integrity rule fails the build on any node with no edge, because an unlinked claim can never be reached by a use case.
2connected componentsOne component means every claim is reachable from every other. More than one means an island the reasoning engine can never walk into.
100%use cases with a complete chainThe core promise as a number: risk class + at least one regulation + at least one technical component reachable from the use case.
1 fragment outside the main component: Unacceptable Risk (Prohibited), Art. 5 — Prohibited Practices. A fragment is not an error — the nodes are correct — but it is a missing edge, and it is on the worklist rather than hidden.

The load-bearing nodes

The ten most connected nodes. If one of these is wrong, it is wrong in many answers at once — which is exactly why the verification worklist prioritises them.

  1. EU AI Actregulation · 37 edges
  2. Clinical Imaging Triage & Patient Follow-UpuseCase · 32 edges
  3. GDPRregulation · 30 edges
  4. Algorithmic Portfolio Execution & AdvisoryuseCase · 30 edges
  5. Agentic RDA Stack (6 Layers)blueprint · 26 edges
  6. WORM / Immutable Audit Vaultcomponent · 25 edges
  7. Automated Financial Forecasting & Audit TrailsuseCase · 25 edges
  8. KYC & Client Onboarding Automation (Managed Service)useCase · 25 edges
  9. Art. 15 — Accuracy, Robustness, Cybersecurityarticle · 24 edges
  10. Event Logs & Decision Tracesevidence · 24 edges

Average degree per node type

Shows which layers are well embedded and which hang thin — a standard with a degree of one is cited but not yet woven into the control model.

Trust & coverage

How much of the graph is dated, sourced and independently reviewed.

These four numbers are the ones to read before trusting any answer this tool gives you. They are deliberately not rounded up: the gaps are the public worklist →

20 / 89legal & standards nodes with a verification date (22%) — 0 verified longer than 120 days ago
20 / 89with a lifecycle status (22%) — in-force, amended, withdrawn, published, OJEU-cited
13 / 26evidence artefacts placed on the verifiability ladder (50%) — self-asserted through independently attested
57 / 89legal & standards nodes that resolve to a primary source link (64%) — the "says who?" coverage
9 / 12control objectives with an ISO 42001 or CSA AICM mapping (75%) — 3 deliberately unmapped, because an empty mapping is not a zero
0 / 0community-reviewed of 0 nodes carrying any community signal — 0 currently disputed, 279 with no vote yet

Why it matters: a claim with no verification date is a claim, not a fact, and this tool says so on the node itself. Citation coverage is the stricter test — it asks whether you can click through to the authority, not whether someone asserted it. Read the full reference list →

Integrity

Whether the graph still keeps the structural promises it makes to users.

22 / 30integrity rules passingEach rule checks one structural promise, e.g. every regulation resolves to at least one technical component.
0errorsAn error blocks a release. The target is, and stays, zero.
233warningsWarnings are known thin spots, kept visible on purpose rather than downgraded.

The same suite runs on every change — in unit tests and in CI — so a merge that breaks a structural promise fails before it ships. Open the full validation report →