Laws · standards · frameworks — as addressable provisions

Point at the provision,
or you are asserting

A standard is only useful when a claim can point at a named provision in a real instrument instead of asserting one. This site publishes the method that turns an instrument into a graph of addressable provisions, the instruments modelled that way so far, and the vaults that deliver them. One instrument is modelled properly. One. The method is published so the second is cheap — and so you can check the first.

Read the method → The EU AI Act, modelled → What is actually shipped →

First: this site is called “standards” and is three-quarters law

That is worth saying before anything else, because the word is imprecise and the imprecision is load-bearing. Law, standard and framework are three different kinds of instrument, they bind in three different ways, and a site that blurs them will mislead you about what you are obliged to do. So the distinction is the first thing here rather than the first mistake.

We see this pattern in cybersecurity broadly: laws vs. frameworks vs. controls. A law (like NIS2 or GDPR) states “what” outcomes must be achieved… often without stating “how.” The “how” is found in frameworks like ISO 27002.
— docs.diniscruz.ai, 31 March 2025
KindWhat it isHow it bindsShare of what is here
LawEU AI Act, GDPR/UK GDPR, NIS2, DORA, CRA, HIPAA, PECR, CCPA, SOX, DPA 2018Directly. Non-compliance is unlawful, with penalties written into the instrument~72% · ~95,000 words
FrameworkOWASP, NIST CSF/800-53/AI RMF, MITRE ATT&CK and ATLAS, BSIMM, CMMC, SLSANot at all, on its own. It binds when a contract, a regulator or a customer points at it~20% · ~26,000 words
StandardISO 27001/27002/42001, SOC 2, PCI DSS, CycloneDX, SPDX, Akoma NtosoBy certification or attestation — a third party assesses you against it and issues something~8% · ~11,000 words

Every instrument page on this site carries its label in the header, beside whether its text may legally be republished at all. The instrument index →

Second: the thesis

A risk in a register points at a named obligation in a real instrument instead of being asserted.

Everything else on this site follows from that one sentence. If a claim has to point at a provision, then provisions need to be addressable — which means an identity, a stable citation, and a hash of the bytes the text came from. If the pointing has to be checkable, then the provision has to be readable by somebody who does not trust us. And if a finding has to be grounded rather than plausible, there has to be a path from the finding down to something observed.

Addressable

A provision has an address

Two hashes per provision: one for the slot in the hierarchy, one for the text currently in it. Citations and crosswalks attach to the slot, so they survive amendment.

The citation scheme →
Checkable

Provenance on the retrieved bytes

Where the text was fetched from, when, by what method, and the SHA-256 of what came back. A citation without a retrieval record is a quotation.

The method →
Grounded

The grounding ladder

Finding → fact → evidence → measure → twin. A model asked to assess compliance produces a plausible answer; a model asked to attach a finding to a provision hash and a measure either finds the path or reports that it cannot.

The ladder →
Incomplete

An unanswered question is an output

Not a blank. The best worked example on this site ships with five of its nine questions unanswered, and that is the result rather than a gap in it.

What is shipped →

How you know: five lines

This is the whole anti-fabrication argument, and it is short enough to check. Each line says what must exist below a claim for the claim to stand.

Risk          := a downward path to a Vulnerability AND an upward path toward a top risk
Vulnerability := a Fact (grounded below) AND an upward path to a Risk
Fact          := a downward path to Evidence
Evidence      := a downward path to a Measure
Measure       := an observation of the node it measures, grounded on a Twin

A model asked “are we compliant with Article 26?” will answer. A model asked to produce the path — this finding, from this fact, from this evidence, from this measure, on this twin — either produces it or reports that it cannot. The ladder is the mechanism that turns “sounds right” into “here is the path.” The five rules that follow from it →

Why a multi-instrument site rather than one very good page

Because the value compounds, and it compounds in a way that is easy to state and easy to check.

the AI standard already links to another of the standards… Map a second instrument and the edge resolves; map a third and two more resolve. So each mapping increases the value of the ones already done.

The AI Act refers out to GDPR, to NIS2, to harmonised standards, to conformity assessment bodies. Today every one of those references terminates at nothing. Model GDPR and one class of them resolves. That is the argument for the shelf — and the reason crosswalks are bridges rather than merges, because a bridge you disagree with is a wrong edge you can find, and a merge you disagree with is a silently wrong node.

Build order 1

The method, first

Counter-intuitive and correct: the meta layer before any instrument. It makes instruments 2–N cheap, and it is the only material here that is itself the product rather than a mapping of somebody else's text.

Read →
Build order 2

The EU AI Act

Law 1,523 nodes and 1,944 edges in a shipped vault, composing Regulation (EU) 2024/1689 with its 2026 amendment because no official consolidation exists. With its two real weaknesses stated on the page.

Read →
The sellable shape

Subsets across instruments

Nobody wants to read eight instruments. Everybody wants the provisions across eight instruments that bear on their problem. “You almost recreate a small standard based on this.”

Agentic access →
The rest

Honest stubs

GDPR: two white papers, no artefact. ISO 27001: a crosswalk and a reading guide, never the text. ISO 31000: nothing exists, and the page says so in a paragraph.

Every instrument →

The constraint that reshapes a third of this site

You cannot republish ISO. ISO/IEC standards — 27001, 27002, 27005, 31000, 42001 — are copyrighted and sold, and that revenue is how ISO and its national members are funded. Not the requirement text, not Annex A verbatim, not a close paraphrase presented as a summary. This is a licensing blocker, not a writing task, and it is the single largest constraint on a site called standards.

So an ISO folder here holds clause references (numbers and titles are citable), the project's own control interpretations, crosswalks to instruments that are publishable, a reading guide, and an honest page about the paywall — and its source/ layer is empty, with the page saying why. The ISO/IEC 27001 folder →

It also raises a question nobody in this project's corpus has answered, and it is published unresolved: can the ontology hold a standard it cannot quote? The model assumes provision text as a node property. For ISO that text cannot be stored. Is a hollow provision node — identity, title, citation, no text — still the same thing, or a different one? Open question Q3 →

What is not here

Every sibling site ships a /shipped/ page. This is the summary; the full version is unsoftened.

ThingStatus
Instruments modelledOne. The EU AI Act. Regulation Graph is a proof, not a library
Cross-instrument mappingsZero. No AI Act ↔ GDPR, no ISO 27001 ↔ SOC 2, no GDPR ↔ NIS2. All three named as obviously valuable; none done
Control catalogue, machine-readableNone. OSCAL is admired from a distance
Zip / SQLite distributionNone yet — on any of the twelve published vaults. Net-new across the whole estate
The GDPR graphDoes not exist. Two white papers describe how to build it; nothing is assembled
AI Act citationsDerived from secondary sources and flagged as such by the corpus itself. Every article citation needs re-derivation from the operative text before it can be relied on

And the warning this site is most exposed to, in the project's own words: “Publishing security reviews and deployment guidance is useful; implying regulatory readiness that has not been established is the easiest way to create an obligation nobody has met.” Nothing here outputs a pass, a score or a percentage. Where this approach loses →

The vaults are the substrate; this site is a projection of them

The data lives in encrypted vaults — source bytes, transformations, graph JSON, SQLite, the apps. The site is what you can read, index, diff, fork and cite. Both, deliberately, with a stated division of labour and one governing rule: nothing exists only in the vault that a reader would need in order to check a claim.

The vaultThe repo & this site
HoldsEverything — source bytes, transformations, model outputs, JSON, SQLite, apps, toolsThe projection: rendered pages, the raw markdown of this site's own writing, the graph as plain files
Is theWorking substrate and distribution unitVerification surface and citable address
AuthorityCanonical for dataCanonical for URLs

This is a genuine architectural fork and it is published as one: the commissioning memo said vault, an internal brief later changed position to “vault authors, repo publishes” on the ground that clear text is what enables verification. Both are right about different things. The vaults, with their read keys → · Open question Q2 →

Where to go next

If you build

The method

The node and edge grammar, the two-hash scheme, authority anchoring, and the acceptance test the method must pass before the pipeline is real rather than an AI Act reader.

Read →
If you assess

The worked example

A procured agentic underwriting system, taken from fact to provision to finding. Including the one finding that is arithmetic rather than judgement — and the caveat published beside it.

Read →
If you are an agent

The machine surface

The grammar as JSON, the per-instrument endpoint, the citation scheme, the contract version, and the one epistemic rule: you may report which provision a claim points at; you may not report that a requirement is met.

Read →
If you want a tool

Tools outside the vault

The contract between a tool and a vault, and five tools ranked by value over effort — one of which ships here today.

Read →