standards.sgit.ai / instruments

Every instrument

One folder per instrument, all the same eight sections, so a reader learns the shape once. Every folder header carries three facts before anything else: what kind of instrument this is, whether its text may legally be republished, and what actually exists here as opposed to what is planned.

The folders

InstrumentKindRepublishableWhat exists here
EU AI Act
Regulation (EU) 2024/1689, amended by (EU) 2026/1744
LawYES
Official Formex XML from CELLAR
Modelled. 1,523 nodes, 1,944 edges in a shipped vault. Reading layer, worked example, provisions, and a status page naming two real weaknesses
GDPR
Regulation (EU) 2016/679 · UK GDPR · DPA 2018 · PECR
LawYESMethod, no artefact. Two white papers on how to build the graph. No vault, no nodes, no provisions. Larger than it looks — the rulings and the guidance are the graph
ISO/IEC 27001
and 27002, 27005, 27036, 42001
StandardNO
Copyrighted and sold
A crosswalk and a reading guide, never the text. Plus the honest page about the paywall, and the open question of whether the model can hold a standard it cannot quote
ISO 31000
and ISO/IEC 27005
StandardNONothing. Zero occurrences in the source corpus. One paragraph explaining that, and a pointer to where the real risk apparatus lives
Why the shelf is this short. One instrument done properly is a stronger position than five done thinly, and it reads as weaker — which is a genuine tension rather than a resolved one. The project's own conclusion: “one instrument, done properly, with its working shown and its verification openly incomplete.” Resist filling the shelf is a rule here, not an excuse. What is actually shipped →

The eight sections every folder has

SectionWhat it holds
indexThe label, the issuer, in force since, amendments composed in, republishable yes/no, and the vault credential if there is one
structureThe taxonomy, browsable — chapter, article, paragraph, point
conceptsDefined terms. One identifier, many labels
provisions/<id>The permalink target: text, both hashes, retrieval record, analysis, crosswalk edges. The scheme →
crosswalkBridges out, with basis and strength. Empty on every instrument today
worked-examplesThe proof pages — a specific clause taken through to a finding
vaultWhat is in it, how to open it, how to download the zip
statusNot optional. What is done, what is derived from secondary sources, what is stale

Licensing: what may be republished

The single largest constraint on this site, and it is not uniform. Check per instrument; do not generalise from the EU-law case.

MaterialRegimeWhat this site may do
EU law — AI Act, GDPR, NIS2, DORA, CRAYES Official Formex XML from CELLAR; EU legislative texts are freely reusableRepublish in full, with provenance hashes and retrieval records
NIST — CSF, 800-53, AI RMF, SSDF, OSCALYES US government work, public domainRepublish; attribute as courtesy
OWASP — Top 10, ASVS, SAMM, CRS, WSTGYES CC-licensed — check the specific licence per project, they are not uniformRepublish per that licence, with attribution
MITRE ATT&CK / ATLASYES with attributionRepublish per MITRE's terms
CycloneDX, SPDXPARTLY in their open forms⚠️ The ISO-numbered twins (ISO/IEC 5962, 20153) are the paywalled versions. Cite the open ones
Akoma Ntoso, AKN4EU, ELI, ECLI, LegalRuleMLYES OASIS / EU open specificationsRepublish per licence. These are the standards for representing standards — they belong in /method/
ISO/IEC — all of themNO Copyrighted and soldReference only. Clause numbers and titles are citable; the text is not
SOC 2, PCI DSSNO Assume noCheck carefully before writing anything

Not built, and honestly ranked

The build order is published unresolved. These are the folders that do not exist yet, in the order the evidence supports rather than the order they were asked for:

  1. /method/ — done. The only material that is itself the product.
  2. /eu-ai-act/ — done, with its weaknesses stated. Points at the existing Regulation Graph vault rather than rebuilding it.
  3. The keys vault — not a folder, but it belongs here in sequence: before vault three, not after vault ten. Escrowing a write key is a precondition of publishing, not good practice. Key discipline →
  4. /gdpr/ — 32,802 words of method, zero artefacts. Real work, and bigger than it looks.
  5. /owasp/ — the strongest candidate for the first non-law page: deep, already public, CC-licensed so no copyright problem. 15,002 words that have never been executed on.
  6. /supply-chain/ — CycloneDX, SPDX, VEX/CSAF, SLSA. Small, accurate, and already graph-shaped: these are the standards that are data. A good early win.
  7. /nis2/ and /dora/ — applied, real, small. DORA has the better artefact; NIS2 has the better precedent in NIS2Onto.
  8. /nist/ — as a crosswalk target rather than a page. Everybody maps to NIST; that is what it is for.
  9. /iso-27001/ — crosswalk and reading guide only, leading with the licensing constraint. Stubbed today.
Absent entirely, and worth naming so nobody assumes otherwise. Sector standards — ISO 26262 (automotive), IEC 62304 and the MDR (medical), DO-178C (aviation), rail, energy. Non-EU and non-US jurisdictions — LGPD, PIPEDA/AIDA, China, India, Japan, the Council of Europe AI Convention. And certification, accreditation and attestation mechanics: a site called “standards” will be asked how an attestation actually gets issued, and there is nothing here about it. The gap list →