for agents/llms.txtv0.2.90 · 19 Sep 2026

Home / Vaults / Fractal Semantic Graphs

Fractal Semantic Graphs

A semantic graph is nodes joined by edges that mean something — every edge a verb, read in both directions. A fractal semantic graph is one where every node opens into a semantic graph of its own — with its own node types, its own verbs, its own ontology — and so does every node inside that, down to the smallest thing that still matters to the question you are asking. In most of our work that smallest node is a word, a number or a symbol. What stays constant between the worlds is not the schema but the grammar: edges are verbs, meaning lives in connectivity, every claim keeps its provenance. That is what lets everything connect to everything without anyone being forced to share a schema. For a long time we called this graphs of graphs of graphs, or ontologies of ontologies of ontologies. This page defines it, shows it, and then proves it with seven published vaults you can open.

What a Fractal Semantic Graph is

Most visitors here already know three of the four words. A graph is nodes and edges. A semantic graph gives the edges meaning: arises_from, evidenced_by, owned_by, each with a named inverse, so a link reads correctly from whichever end you stand at. An ontology is the agreed vocabulary of node types and verbs a graph is allowed to use. The fourth word is the new one.

Fractal means the graph has no privileged level and no single schema. Zoom into any node and you enter a new world: its own node types, its own verbs, its own taxonomy, its own centre of gravity. A regulation is a node in a graph of instruments and jurisdictions; open it and it is a graph of articles, recitals and amendments — a legal ontology; open an article and it is a graph of paragraphs and points; open a paragraph and it is a graph of the terms it uses, each an edge from the article that defines it — a lexical ontology, nothing like the one two levels up. Each of these worlds was defined by whoever owns it, in its own vocabulary, and none was made to conform to the others. What connects them is that each is still a semantic graph — every edge a verb with an inverse, every node traceable to its source — so an edge can be drawn from any node in one world to any node in another. There is no top and no bottom, only the altitude you happen to be looking from, and how much definition you choose to load at it.

1 · A SEMANTIC GRAPH crosswalks_to mitigates gives_rise_to breaches Law Standard Risk System Four nodes, four verbs (each has a named inverse). The node carries a name; the edges carry the meaning. zoom 2 · ZOOM INTO ONE NODE — IT IS A GRAPH the Law node, opened containscontains amended_by Art 9 9(1) 9(2) 9(3) 2026/1744 A legal ontology: articles, paragraphs, and an amendment as an edge. New types, new verbs. zoom 3 · ZOOM AGAIN — DOWN TO THE WORD the 9(2) node, opened uses_term defined_in 9(2) identify foreseeable risk Art 3(…) A lexical ontology: terms and definitions. A new world, one edge from the world above. The grammar never changes; the ontology does. Each zoom is a new world, joined by an edge to the one above.

The test for the word is what happens when you zoom. If every level has the same node types, the same verbs and the same rules, you are in a hierarchy — a folder tree is the clean example: folders inside folders inside folders, one schema all the way down, and the deeper you go the less you learn. It becomes fractal at the moment zooming in lands you somewhere different — a node whose inside has its own types, its own verbs, its own taxonomy, a new format or a special case — and that new world is still joined by an edge to the one you came from. Graphs of graphs, ontologies of ontologies: the plural is the point. A document can contain a paragraph that is a whole mini-world of its own, with more definition than the document around it, because somebody needed that granularity there and nowhere else.

Two things follow. Nobody is forced to conform. An organisation, a division, a team, a single person, a regulator can each define their own world in their own vocabulary, and connect to everyone else's by drawing edges rather than by adopting a shared schema — graphs.sgit.ai puts it as three layers: shared facts owned by nobody, per-party formulas, declared bridges between them. And granularity is a decision, per situation. The same topic can carry a paragraph's worth of definition in one place and a word-by-word graph in another; you load as much as the question needs, and the two remain connected.

One wording to pass upstream: the boundaries page on graphs.sgit.ai states the test as “if zooming into a node needs a new format or a special case, the system is hierarchical, not fractal”. Read with format meaning “stops being a semantic graph and becomes JSON-plus-prose”, it is the same claim as this page — the grammar is what must survive the zoom. Read with format meaning “schema”, it says the opposite, and the first version of this page read it that way. The sentence should say grammar. Noted 19 September 2026.

Why connect everything with everything

Because in our world everything is already a graph, and so is every file format. A regulation is a graph of articles; a PDF of that regulation is a graph of pages, blocks, lines and glyphs; a spreadsheet is a graph of sheets, rows, cells and formulas; a codebase is a graph of packages, classes, methods and tokens; a JSON document is a tree, which is a graph with one verb. None of them needs to be converted into a graph — each only needs its edges named. Once they are, the boundaries between formats stop mattering, and four things become possible that no document can do:

The one discipline that makes “everything with everything” useful rather than noise is that the edge has to be a verb. relates_to is banned, because two things always relate; an edge with no verb constrains nothing and cannot narrow a query. The granularity of the verb is the precision of the question you can later ask.

Four words, one of them new

WordWhat it addsWhere it stops
GraphNodes and edgesThe edges mean nothing in particular
Semantic graphEvery edge is a verb with a named inverse; meaning is in connectivity, not in propertiesOne level: the nodes are atoms
OntologyThe agreed vocabulary of node types and verbsOne ontology per domain; joining two by merging them is a project that usually fails
Fractal Semantic GraphEvery node opens into a semantic graph with its own ontology, at every altitude, down to the word; ontologies are joined by declared edges, never merged — an ontology of ontologiesWhere somebody has not yet named the edges between two worlds. That is a gap, and it is listed below

How far down does the graph go?

All the way. One grammar, eleven ontologies: from the text of a regulation, through a standard's controls, through a risk and the person who accepts it, down to a threat in one line of code on one compute instance — each rung modelled in its own vocabulary by its own author, and every one joined to the next by a named edge. The rest of this page is the evidence: seven published vaults and three sibling sites, each a live fractal semantic graph at a different altitude, every one openable with the read key printed on its page.

The ladder, and who covers which rung

Eleven altitudes, eleven ontologies, one grammar. The left column is the level of the world being described; the right column names the published vault in which that level is a live graph — each name is a link to that vault's page, where its read key is. No two rungs share a schema: a regulation's articles, a standard's controls, a register's risks and a threat model's methods were each modelled by their own author in their own vocabulary. What they share is the grammar, which is why one traversal can cross all eleven.

ALTITUDE WHERE IT IS A LIVE GRAPH — OPEN THE VAULT'S PAGE THE INSTRUMENT THE DECISION THE SYSTEM Lawarticles · paragraphs · points · recitals · definitions Regulation Graph · Standards Atlas GDPR 1,523 hash-verified nodes · rulings layered on the articles Standardcontrols · requirements · crosswalks to other frameworks AIUC-1 conformance layer 53 controls, 2,788 nodes · 62 crosswalks resolved into the law Evidenceevidenced_by vs attested_by — two edges, never one query AIUC-1 conformance layer per control, per subject, per date · 2 / 48 / 3, by design Fact → Riskanswers become facts; facts give rise to risks Risk Graph Explorer 18 facts, 37 risks, 14 provisions · an empty register is correct Ownerthe same risk read at seven altitudes, IT to Board Agentic Browser Isolation 17 entry points, 7 altitudes · pending until its owner accepts Acceptanceno delegation, no deny button; decisions become work Risk Graph Explorer · the seven views acceptance, what happens next · every path ends at the board Policyconformance → condition or exclusion; attestations expire AIUC-1 conformance layer · Licence to Operate 1 condition, 52 exclusions, 0 of 5 · grant, mandate, policy Agentwhat it can do · what you authorised · the delta · the barrier abp.sgit.ai ↗ 23 capability primitives · where the graph meets a real grant System → Component → Class → Methodthe threat model, zoomed in one layer at a time ThreatModCon 2025 11 linked models, 51 nodes, 179 threats · Customer → … → Method Source code → Environment → Runtime → Computethe last four rungs of the same ladder ThreatModCon 2025 one SQL injection traced to revenue · modelled layers, see below …eleven ontologies, none forced to agree with another; one grammar, checked by one validator.

The grammar that survives every zoom, in full

Each altitude gets its own schema; what none of them gets to change is the grammar. It is published on graphs.sgit.ai and it is short: every edge is a verb, stated in both directions with an inverse a person in the business would actually say (gives_rise_to / arises_from, evidenced_by / evidences); relates-to is banned, because an edge with no verb carries no constraint and cannot narrow a query; properties carry data, never meaning — two nodes both holding 8080 differ only in what they are connected to; supersede, never delete, so a correction becomes a query over everything that rested on the error; and never render the whole graph — render the result of a question.

The consequence is the thing the ladder above shows: zooming from an article into a paragraph, from a control into the attestation behind it, from a threat into the method it lives in, lands you in a different ontology each time — and the walk still works, because every edge on the way is a verb with an inverse and every node knows where it came from. The Standards Atlas below puts it in its own words when you open its graph view: “You are at the top of the fractal. Each domain is its own ontology that connects up to the GDPR root and down to concepts and articles.”

Altitude 0 — the law, as a graph you can cite

Regulation Graph · vault 73heuprz

The EU AI Act, parsed from its own XML and hashed to the byte

Regulation (EU) 2024/1689 read from official Formex XML, decomposed into 113 articles, 500 paragraphs, 417 points, 180 recitals, 13 annexes and 68 definitions — 1,523 nodes and 1,944 edges — with the SHA-256 of the retrieved bytes at the end of every provenance chain. Eleven views, including SQL and RDF exports, all client-side.

This is the bottom of the provenance ladder and the top of the semantic one: when a risk somewhere else says touches Article 12, this is the vault that can say what Article 12 says and prove the bytes. The vault's page →

Article-level citations, with halos on the articles amended by Regulation (EU) 2026/1744 — there is no official consolidated text yet, so the graph composes the two.
Standards Atlas · GDPR · vault 4zv4bvmu

“You are at the top of the fractal”

The GDPR's 99 articles as a graph whose operative meaning lives in a second layer the text never mentions: rulings, regulators' guidance, and per-country variation, modelled as nodes anchored to the articles they bend. The graph view is explicitly navigated by altitude — the Regulation, then a domain, then a concept, then the articles and the rulings that interpret them — and the layout is computed from the graph rather than drawn.

It is also the earliest experiment here and it shows: six of its 227 edges are typed relates, the one verb the grammar bans. Recorded rather than hidden, because the rule was written after this vault was. The vault's page →

Altitude 0: the Regulation and its eight domains. Pick one to descend.
one level down

Same grammar, one altitude lower

Descend into Principles and the ring is Article 5's seven principles — each a concept node connecting up to the domain and down to the articles, rulings and guidance anchored on it. Descend again and one principle shows its provenance: the pipeline stage that proposed it, the confidence it was given, and the official text it points at. Nothing about the rendering changed between the three altitudes; only the question did.

Altitude 1: Principles — “the spine the whole graph hangs from” — and its seven concepts, one article.
the layer the text omits

Why a static PDF of a law is wrong and a versioned graph is not

Article 45 of the GDPR has not changed a word since 2016. What it permits has flipped four times — Safe Harbour, Schrems I, Privacy Shield, Schrems II, the Data Privacy Framework, an appeal pending. The atlas draws that as a timeline of ruling nodes over one unchanged article node, which is the whole argument for the second layer in one picture.

One article, five rulings, twenty-five years. The text is a constant; its meaning is the graph.

Altitudes 1 to 3 — the standard, the evidence, the policy

AIUC-1 conformance layer · vault 2wzct4k7

A standard's controls, joined node-to-node to the law they cite

The AIUC-1 agent standard as data — 53 controls, 2,788 nodes, 11,610 edges, 82 hashed source snapshots — plus a conformance layer added as one directory without changing a byte of the original. Its explorer loads two vaults as one graph: one of its packs is literally The AI Act, by article (vault 73heuprz).

That join is where a crosswalk stops being a string. AIUC-1 publishes 1,126 crosswalks as text; 62 resolve into Regulation Graph node ids at article level, and the traversal returns something neither vault knew alone: 8 of the 27 articles reached are amended, so the crosswalk was written against the pre-amendment text. The vault's page →

Two vaults, one canvas. The chip row is the join: standard, crosswalks, another vault's articles, conformance, bow ties, acceptances.
the evidence rung

Two edges that are never allowed to touch

evidenced_by answers does the standard say this? and lives in the catalogue. attested_by answers does this subject do this? and lives in the layer. A test is red if a layer edge ever reaches a source observation. Every control in scope gets a row whether or not anyone has looked — so the first build of one subject comes out 2 evidenced, 48 unevidenced, 3 contradicted, and that is the designed answer. Unevidenced is a state, and it is the default.

53 rows, a level out of five computed from the attestations behind it, and the date each one expires.
the policy rung

The policy is a query, and time is what breaks it

Each control's conformance state becomes a condition or an exclusion on a policy/v1 object, and bow ties decide which consequences are covered. At build time: 1 condition met, 52 exclusions, 0 of 5 consequences covered. Move the as-of date to January 2027 with nothing edited by anybody and the one condition has expired — “real-timeliness arriving as a consequence rather than as a feature.” The Licence to Operate vault is the same object from the other end: an agent's grant, its mandate, and the policy insuring the mandate, spent one conversational turn at a time.

Coverage by consequence, with why not spelled out for each.

Altitudes 4 to 6 — from a fact about your estate to a board decision

Risk Graph Explorer · vault 3simlnqe

Answers become facts; facts give rise to risks; risks cause risks

Answer questions about a system and the register assembles: 18 facts, 37 risks, 14 provisions, seven views recomputing as you go. Risk chains run inherent-to-corporate left to right and are walkable in both directions — leads to navigates up, led by walks back to the answers that caused it — with cycles drawn as dashed edges because the cycles are real. The app declares permissions: {}: a vault allowed to do nothing at all. The seven views, explained →

Risks that cause risks. Click either end of an edge and the graph is walked from there.
the owner rung

The org chart, with risks flowing up it

The role risk map distinguishes what a role holds from what arrives through it because the graph says it must, so no risk is orphaned and every path terminates at the board. The same organisation under the Typical and Governed presets has the same org chart; only what is true about the agent changes — which is the whole argument in one comparison.

Assigned versus through. Nothing stops short of the board.
Agentic Browser Isolation · vault 0610gsp9

The same exposure, in seven languages

Should an agent browse with your logged-in sessions? Seventy JSON files hold the register — risks, controls, evidence, owners, acceptances — and the same nodes are read at seven stakeholder altitudes, IT to Board, each owning the risk in its own vocabulary. A risk sits pending until its named owner accepts it personally, and only an accepted risk escalates to the altitude above. There is no deny button: accept, mitigate, or ask for more data. The vault's page →

IT has five risks pending; everyone above is waiting, because nothing has been passed up yet.

Altitudes 7 to 11 — all the way down to the compute instance

ThreatModCon 2025 · vault 0ict6flm

Eleven linked threat models, customer to compute

This is the vault that answers the “all the way down” question most directly. A threat model of one system tells you very little; this one is a graph of graphs — eleven models linked down a zoom ladder: Customer → Business → Application → Component → Package → Class → Method → Source Code → Environment → Runtime → Compute. 51 nodes, 179 threats, 3 critical, each layer carrying its own counts.

The demonstration is a single SQL injection traced upward from the method it lives in to the revenue it puts at risk — and then framed four ways, for the Board, the CISO, the CTO and the developer, from one fact. Everything runs inside the vault, offline. The vault's page →

The zoom ladder, counted: 11 layers, 51 nodes, 179 threats. The bottom rung is a compute instance.
the flat view

The whole estate on one screen, because it is one graph

Flatten the eleven layers and the result is still one graph — which is the point. A vulnerability at the bottom and a revenue obligation at the top are not in different tools with a spreadsheet between them; they are nodes a query can connect.

The same eleven layers, flattened.

Between vaults: the edges that cross a boundary

The join above — a control in one vault pointing at an article in another — is the property that turns a set of graphs into a fractal rather than a pile. Two mechanisms carry it. The AIUC-1 layer records 595 anchors that tie its nodes to the exact bytes they came from, verified at build and again in the browser, and resolves its crosswalks into another vault's node ids with the CELEX identifier and a hash on each edge. And sgit's own object model ships typed *.link.json edges between vaults, optionally pinned to a commit in the target's history — a cross-graph edge that cannot silently follow a moving target. Both are documented on graphs.sgit.ai's reality page, which is careful to say which of its claims are running and which are argued.

The vault commit graph underneath all of this is a graph too — content-addressed over ciphertext, multi-parent, with a real merge-base — which is why the read-only query API a vault app gets (sg.history.log, list, read) is the same surface every explorer on this page runs on.

What is still modelled rather than imported

The honest half of the answer. The ladder reaches the compute instance, but not every rung is fed from a live source yet:

Named gaps get filled. Unnamed ones do not, which is why this section is here.

The three sites that carry the argument

graphs.sgit.ai · Graphs & methodFractal Semantic Graphs ↗The grammar in three altitudes: five rules you can apply tomorrow, the working edge set with its numbered gaps, and the full positioning against schemas and vector search — including the four situations in which the argument is wrong. The reality page separates what ships from what is argued, and the examples include Article 26(5) carried from a running system to a board decision and back.“A node is just a node. Meaning lives in the edges.”part of the sgit.ai network
standards.sgit.ai · Risk & governanceLaws, standards and frameworks as addressable provisions ↗A citation scheme where every provision has a constructible URL and a recomputable positional hash, a grounding ladder, and the rule for agents: report which provision a claim points at, never that a requirement is met. One instrument modelled, and a status page that says so in capitals.“Point at the provision, or you are asserting.”part of the sgit.ai network
abp.sgit.ai · Agents & AIThe Agent Behaviour Policy ↗Four objects — the grant, the mandate, the delta between them, and the barrier that decides whether anything is actually in the way — for one agent in one deployment, written in a capability grammar of 23 verb.object.reach primitives. It publishes the record and never the verdict: no score, no rating, no risk level anywhere, including in the data. The rung where the graph meets a real permission set.“You know what you asked for. You do not know what it can do.”part of the sgit.ai network

Open them

AltitudeVaultSizePage, with the read key
LawRegulation Graph 73heuprz207 files · 14.9 MBregulation-graph
Law + its interpretationStandards Atlas GDPR 4zv4bvmu116 files · 6.3 MBstandards-atlas-gdpr
Standard · evidence · policyAIUC-1 conformance layer 2wzct4k7649 files · 43 MBaiuc-1-conformance
Fact · risk · acceptanceRisk Graph Explorer 3simlnqe33 files · 428 KBrisk-graph-explorer
Owner, at seven altitudesAgentic Browser Isolation 0610gsp9104 files · 2.4 MBagentic-browser-isolation
Policy, spent turn by turnLicence to Operate posrhzp3licence-to-operate
System → computeThreatModCon 2025 0ict6flm53 files · 4.1 MBthreatmodcon-2025

Every read key is on the vault's own page, published on purpose; none of them can write. Agents: the machine-readable list of all thirty vaults, with ids and keys, is /demos/vaults/llms.txt. The grammar for drawing your own is at graphs.sgit.ai/llms.txt.