sgit newsroom v0.1.29 · snapshot 2026-09-24

Reading room · standards.sgit.ai

On this page

Reading room / standards.sgit.ai · raw text · live ↗

From standards.sgit.ai, the page as fetched on 2026-09-24 · open the live page ↗Everything on this sheet is the source site's own text; the newsroom's chrome is outside it.

standards.sgit.ai — laws, standards and frameworks as addressable provisions

A standard is only useful when a claim can point at a named provision in a real instrument instead of asserting one. This site publishes the method that turns an instrument into a graph of addressable provisions, the instruments modelled that way so far, and the vaults that deliver them. ONE instrument is modelled. One.

Site version: v0.1.4 (24 August 2026). Published by the sgit project — participant disclosure at /about/participant.html. All content CC BY 4.0; the instruments themselves keep their own licences.

The one rule for agents

An agent may report WHICH PROVISION a claim points at. It may NOT report that a requirement is met. This site produces findings and unanswered questions — never a score, never a percentage, never a pass. The full machine surface is at /agents/.

Properties you may rely on

Status, stated plainly

One instrument is modelled (the EU AI Act). ZERO crosswalks exist between any two instruments. There is no GDPR graph, no control catalogue in machine-readable form, and no zip or SQLite export on any of the twelve published vaults on this estate. The AI Act readings are derived from SECONDARY sources and flagged as such; operative text is deliberately withheld from provision pages pending re-derivation from the authority. If you summarise this site, the gaps are the more useful half: /shipped/.

The two opening claims

  1. THE THREE-WAY DISTINCTION. This site is called "standards" and is roughly 72% law, 20% framework, 8% actual standards. Laws bind directly with penalties written in; frameworks bind only when a contract, regulator or customer points at them; standards bind by certification. The distinction leads because the name overstates a third of what is here, and that is better as the opening argument than as the first error.
  2. THE THESIS. "A risk in a register points at a named obligation in a real instrument instead of being asserted."

The method — /method/

Built FIRST, before any instrument folder, because it makes instruments 2..N cheap and because it is the only material here that is itself the product rather than a mapping of somebody else's copyrighted text.

Crosswalks: bridges, not merges — /method/crosswalks.html

A merge asserts two provisions mean the same thing and fails INVISIBLY when one is amended. A bridge asserts a relationship with a stated basis, can be disagreed with, and fails VISIBLY — the content hash moved under a positional hash the bridge is attached to, so the bridge is flagged rather than silently wrong. Every bridge must carry from, to, relation, basis, strength, asserted_by, asserted_at and the source content hash at each end. STRENGTH IS UNDEFINED — the phrase is "shades of compliance" and there is no scale, which blocks the crosswalk browser.

The grounding ladder — /method/ladder.html

Risk := a downward path to a Vulnerability AND an upward path to a top risk Vulnerability := a Fact (grounded below) AND an upward path to a Risk Fact := a downward path to Evidence Evidence := a downward path to a Measure Measure := an observation of the node it measures, grounded on a Twin

A model asked "are we compliant with Article 26?" will answer. A model asked to produce the path either produces it or reports that it cannot. There is no fluent version of a missing edge. Five rules follow: unevidenced facts are first-class findings; absence is output and must be rendered rather than dropped; computed not claimed; regulation as evidence not checklist; coverage is a measurable property of the graph itself.

Instruments — /instruments/

Subsets — /subsets/

The sellable page type: the provisions across N instruments that bear on ONE real problem. "You almost recreate a small standard based on this." A subset cites and interprets and never reproduces, which is also how it sidesteps the ISO blocker. /subsets/agentic-access/ spans eight instruments. Its finding: the throughline is least privilege, data minimisation, access control, supply-chain risk, traceable evidence and accountability — and the divergences matter more, because four instruments start four different reporting clocks and only one is about the agent's autonomy at all.

Vaults and tools

/vaults/ — the vaults are the substrate and this site is a projection of them, with one governing rule: NOTHING EXISTS ONLY IN THE VAULT THAT A READER WOULD NEED IN ORDER TO CHECK A CLAIM. Twelve published vaults, exactly one of which is an instrument vault. Client-side decryption; the read key is published on the host page and handed to a sandboxed iframe over a validated postMessage handshake so it never appears in a URL. Read keys (sgit_rk1_) yes, write keys never.

/vaults/keys.html — escrow is a precondition of publishing, not good practice: a vault that is readable and unwritable is not damaged but FROZEN, permanently readable, never updatable, never revocable, never correctable. Audit before the key, not after.

/tools/ — the contract between a tool and a vault, and five tools ranked. T4, the citation resolver, ships. T1, the crosswalk browser, is blocked on there being no crosswalks — which is a virtue, because it cannot be faked.

Open questions, published unresolved — /admin/comms.html

Q1 who owns the Article 26(5) worked example, this site or risks.sgit.ai · Q2 vault or repo for canonical text (published as a fork, not settled) · Q3 can the ontology hold a standard it cannot quote · Q4 what is a bridge's strength, formally · Q5 when does a composed instrument stop being trustworthy · Q6 was the exposed vault key rotated or only removed from history · Q7 does the method survive instrument two · Q8 should the site be multilingual · Q9 is "standards" the right name.

The warning this site is most exposed to

"Publishing security reviews and deployment guidance is useful; implying regulatory readiness that has not been established is the easiest way to create an obligation nobody has met." Nothing here outputs a pass, a score or a percentage. No page says "compliant", "meets" or "satisfies" without naming the evidence and the measure.

Endpoints

/agents/grammar.json · /agents/vaults.json · /eu-ai-act/eu-ai-act.json · /llms-full.txt · /sitemap.xml · /index.md · /briefs/<filename>.md