A standard is only useful when a claim can point at a named provision in a real instrument instead of asserting one. This site publishes the method that turns an instrument into a graph of addressable provisions, the instruments modelled that way so far, and the vaults that deliver them. One instrument is modelled properly. One. The method is published so the second is cheap — and so you can check the first.
That is worth saying before anything else, because the word is imprecise and the imprecision is load-bearing. Law, standard and framework are three different kinds of instrument, they bind in three different ways, and a site that blurs them will mislead you about what you are obliged to do. So the distinction is the first thing here rather than the first mistake.
We see this pattern in cybersecurity broadly: laws vs. frameworks vs. controls. A law (like NIS2 or GDPR) states “what” outcomes must be achieved… often without stating “how.” The “how” is found in frameworks like ISO 27002.
— docs.diniscruz.ai, 31 March 2025
| Kind | What it is | How it binds | Share of what is here |
|---|---|---|---|
| Law | EU AI Act, GDPR/UK GDPR, NIS2, DORA, CRA, HIPAA, PECR, CCPA, SOX, DPA 2018 | Directly. Non-compliance is unlawful, with penalties written into the instrument | ~72% · ~95,000 words |
| Framework | OWASP, NIST CSF/800-53/AI RMF, MITRE ATT&CK and ATLAS, BSIMM, CMMC, SLSA | Not at all, on its own. It binds when a contract, a regulator or a customer points at it | ~20% · ~26,000 words |
| Standard | ISO 27001/27002/42001, SOC 2, PCI DSS, CycloneDX, SPDX, Akoma Ntoso | By certification or attestation — a third party assesses you against it and issues something | ~8% · ~11,000 words |
Every instrument page on this site carries its label in the header, beside whether its text may legally be republished at all. The instrument index →
A risk in a register points at a named obligation in a real instrument instead of being asserted.
Everything else on this site follows from that one sentence. If a claim has to point at a provision, then provisions need to be addressable — which means an identity, a stable citation, and a hash of the bytes the text came from. If the pointing has to be checkable, then the provision has to be readable by somebody who does not trust us. And if a finding has to be grounded rather than plausible, there has to be a path from the finding down to something observed.
Two hashes per provision: one for the slot in the hierarchy, one for the text currently in it. Citations and crosswalks attach to the slot, so they survive amendment.
The citation scheme → CheckableWhere the text was fetched from, when, by what method, and the SHA-256 of what came back. A citation without a retrieval record is a quotation.
The method → GroundedFinding → fact → evidence → measure → twin. A model asked to assess compliance produces a plausible answer; a model asked to attach a finding to a provision hash and a measure either finds the path or reports that it cannot.
The ladder → IncompleteNot a blank. The best worked example on this site ships with five of its nine questions unanswered, and that is the result rather than a gap in it.
What is shipped →This is the whole anti-fabrication argument, and it is short enough to check. Each line says what must exist below a claim for the claim to stand.
Risk := a downward path to a Vulnerability AND an upward path toward a top risk Vulnerability := a Fact (grounded below) AND an upward path to a Risk Fact := a downward path to Evidence Evidence := a downward path to a Measure Measure := an observation of the node it measures, grounded on a Twin
A model asked “are we compliant with Article 26?” will answer. A model asked to produce the path — this finding, from this fact, from this evidence, from this measure, on this twin — either produces it or reports that it cannot. The ladder is the mechanism that turns “sounds right” into “here is the path.” The five rules that follow from it →
Because the value compounds, and it compounds in a way that is easy to state and easy to check.
the AI standard already links to another of the standards… Map a second instrument and the edge resolves; map a third and two more resolve. So each mapping increases the value of the ones already done.
The AI Act refers out to GDPR, to NIS2, to harmonised standards, to conformity assessment bodies. Today every one of those references terminates at nothing. Model GDPR and one class of them resolves. That is the argument for the shelf — and the reason crosswalks are bridges rather than merges, because a bridge you disagree with is a wrong edge you can find, and a merge you disagree with is a silently wrong node.
Counter-intuitive and correct: the meta layer before any instrument. It makes instruments 2–N cheap, and it is the only material here that is itself the product rather than a mapping of somebody else's text.
Read → Build order 2Law 1,523 nodes and 1,944 edges in a shipped vault, composing Regulation (EU) 2024/1689 with its 2026 amendment because no official consolidation exists. With its two real weaknesses stated on the page.
Read → The sellable shapeNobody wants to read eight instruments. Everybody wants the provisions across eight instruments that bear on their problem. “You almost recreate a small standard based on this.”
Agentic access → The restGDPR: two white papers, no artefact. ISO 27001: a crosswalk and a reading guide, never the text. ISO 31000: nothing exists, and the page says so in a paragraph.
Every instrument →So an ISO folder here holds clause references (numbers and titles are citable), the project's own control interpretations, crosswalks to instruments that are publishable, a reading guide, and an honest page about the paywall — and its source/ layer is empty, with the page saying why. The ISO/IEC 27001 folder →
It also raises a question nobody in this project's corpus has answered, and it is published unresolved: can the ontology hold a standard it cannot quote? The model assumes provision text as a node property. For ISO that text cannot be stored. Is a hollow provision node — identity, title, citation, no text — still the same thing, or a different one? Open question Q3 →
Every sibling site ships a /shipped/ page. This is the summary; the full version is unsoftened.
| Thing | Status |
|---|---|
| Instruments modelled | One. The EU AI Act. Regulation Graph is a proof, not a library |
| Cross-instrument mappings | Zero. No AI Act ↔ GDPR, no ISO 27001 ↔ SOC 2, no GDPR ↔ NIS2. All three named as obviously valuable; none done |
| Control catalogue, machine-readable | None. OSCAL is admired from a distance |
| Zip / SQLite distribution | None yet — on any of the twelve published vaults. Net-new across the whole estate |
| The GDPR graph | Does not exist. Two white papers describe how to build it; nothing is assembled |
| AI Act citations | Derived from secondary sources and flagged as such by the corpus itself. Every article citation needs re-derivation from the operative text before it can be relied on |
And the warning this site is most exposed to, in the project's own words: “Publishing security reviews and deployment guidance is useful; implying regulatory readiness that has not been established is the easiest way to create an obligation nobody has met.” Nothing here outputs a pass, a score or a percentage. Where this approach loses →
The data lives in encrypted vaults — source bytes, transformations, graph JSON, SQLite, the apps. The site is what you can read, index, diff, fork and cite. Both, deliberately, with a stated division of labour and one governing rule: nothing exists only in the vault that a reader would need in order to check a claim.
| The vault | The repo & this site | |
|---|---|---|
| Holds | Everything — source bytes, transformations, model outputs, JSON, SQLite, apps, tools | The projection: rendered pages, the raw markdown of this site's own writing, the graph as plain files |
| Is the | Working substrate and distribution unit | Verification surface and citable address |
| Authority | Canonical for data | Canonical for URLs |
This is a genuine architectural fork and it is published as one: the commissioning memo said vault, an internal brief later changed position to “vault authors, repo publishes” on the ground that clear text is what enables verification. Both are right about different things. The vaults, with their read keys → · Open question Q2 →
The node and edge grammar, the two-hash scheme, authority anchoring, and the acceptance test the method must pass before the pipeline is real rather than an AI Act reader.
Read → If you assessA procured agentic underwriting system, taken from fact to provision to finding. Including the one finding that is arithmetic rather than judgement — and the caveat published beside it.
Read → If you are an agentThe grammar as JSON, the per-instrument endpoint, the citation scheme, the contract version, and the one epistemic rule: you may report which provision a claim points at; you may not report that a requirement is met.
Read → If you want a toolThe contract between a tool and a vault, and five tools ranked by value over effort — one of which ships here today.
Read →