standards.sgit.ai / instruments
Every instrument
One folder per instrument, all the same eight sections, so a reader learns the shape once. Every folder header carries three facts before anything else: what kind of instrument this is, whether its text may legally be republished, and what actually exists here as opposed to what is planned.
The folders
| Instrument | Kind | Republishable | What exists here |
|---|---|---|---|
| EU AI Act Regulation (EU) 2024/1689, amended by (EU) 2026/1744 | Law | YES Official Formex XML from CELLAR | Modelled. 1,523 nodes, 1,944 edges in a shipped vault. Reading layer, worked example, provisions, and a status page naming two real weaknesses |
| GDPR Regulation (EU) 2016/679 · UK GDPR · DPA 2018 · PECR | Law | YES | Method, no artefact. Two white papers on how to build the graph. No vault, no nodes, no provisions. Larger than it looks — the rulings and the guidance are the graph |
| ISO/IEC 27001 and 27002, 27005, 27036, 42001 | Standard | NO Copyrighted and sold | A crosswalk and a reading guide, never the text. Plus the honest page about the paywall, and the open question of whether the model can hold a standard it cannot quote |
| ISO 31000 and ISO/IEC 27005 | Standard | NO | Nothing. Zero occurrences in the source corpus. One paragraph explaining that, and a pointer to where the real risk apparatus lives |
Why the shelf is this short. One instrument done properly is a stronger position than five done thinly, and it reads as weaker — which is a genuine tension rather than a resolved one. The project's own conclusion: “one instrument, done properly, with its working shown and its verification openly incomplete.” Resist filling the shelf is a rule here, not an excuse. What is actually shipped →
The eight sections every folder has
| Section | What it holds |
|---|---|
| index | The label, the issuer, in force since, amendments composed in, republishable yes/no, and the vault credential if there is one |
| structure | The taxonomy, browsable — chapter, article, paragraph, point |
| concepts | Defined terms. One identifier, many labels |
| provisions/<id> | The permalink target: text, both hashes, retrieval record, analysis, crosswalk edges. The scheme → |
| crosswalk | Bridges out, with basis and strength. Empty on every instrument today |
| worked-examples | The proof pages — a specific clause taken through to a finding |
| vault | What is in it, how to open it, how to download the zip |
| status | Not optional. What is done, what is derived from secondary sources, what is stale |
Licensing: what may be republished
The single largest constraint on this site, and it is not uniform. Check per instrument; do not generalise from the EU-law case.
| Material | Regime | What this site may do |
|---|---|---|
| EU law — AI Act, GDPR, NIS2, DORA, CRA | YES Official Formex XML from CELLAR; EU legislative texts are freely reusable | Republish in full, with provenance hashes and retrieval records |
| NIST — CSF, 800-53, AI RMF, SSDF, OSCAL | YES US government work, public domain | Republish; attribute as courtesy |
| OWASP — Top 10, ASVS, SAMM, CRS, WSTG | YES CC-licensed — check the specific licence per project, they are not uniform | Republish per that licence, with attribution |
| MITRE ATT&CK / ATLAS | YES with attribution | Republish per MITRE's terms |
| CycloneDX, SPDX | PARTLY in their open forms | ⚠️ The ISO-numbered twins (ISO/IEC 5962, 20153) are the paywalled versions. Cite the open ones |
| Akoma Ntoso, AKN4EU, ELI, ECLI, LegalRuleML | YES OASIS / EU open specifications | Republish per licence. These are the standards for representing standards — they belong in /method/ |
| ISO/IEC — all of them | NO Copyrighted and sold | Reference only. Clause numbers and titles are citable; the text is not |
| SOC 2, PCI DSS | NO Assume no | Check carefully before writing anything |
Not built, and honestly ranked
The build order is published unresolved. These are the folders that do not exist yet, in the order the evidence supports rather than the order they were asked for:
- /method/ — done. The only material that is itself the product.
- /eu-ai-act/ — done, with its weaknesses stated. Points at the existing Regulation Graph vault rather than rebuilding it.
- The keys vault — not a folder, but it belongs here in sequence: before vault three, not after vault ten. Escrowing a write key is a precondition of publishing, not good practice. Key discipline →
- /gdpr/ — 32,802 words of method, zero artefacts. Real work, and bigger than it looks.
- /owasp/ — the strongest candidate for the first non-law page: deep, already public, CC-licensed so no copyright problem. 15,002 words that have never been executed on.
- /supply-chain/ — CycloneDX, SPDX, VEX/CSAF, SLSA. Small, accurate, and already graph-shaped: these are the standards that are data. A good early win.
- /nis2/ and /dora/ — applied, real, small. DORA has the better artefact; NIS2 has the better precedent in NIS2Onto.
- /nist/ — as a crosswalk target rather than a page. Everybody maps to NIST; that is what it is for.
- /iso-27001/ — crosswalk and reading guide only, leading with the licensing constraint. Stubbed today.
Absent entirely, and worth naming so nobody assumes otherwise. Sector standards — ISO 26262 (automotive), IEC 62304 and the MDR (medical), DO-178C (aviation), rail, energy. Non-EU and non-US jurisdictions — LGPD, PIPEDA/AIDA, China, India, Japan, the Council of Europe AI Convention. And certification, accreditation and attestation mechanics: a site called “standards” will be asked how an attestation actually gets issued, and there is nothing here about it. The gap list →