for agents/demos/vaults/llms.txtv0.3.1 · 20 Sep 2026

Home / Vaults / DSIT AI Risk Toolkit

A government toolkit, turned into four connected worlds

Independent and derived. Read this first. This vault is an independent reference edition of the UK Department for Science, Innovation and Technology AI Risk Management Toolkit. In its own words it is "not a formal standard, certification, conformance assessment or official DSIT service", and it does not imply official status or endorsement. Departmental logos and crests are not used. Source text is public sector information under the Open Government Licence v3.0; external standards are referenced rather than reproduced. The official publication is the authority, and where this disagrees with it, it is wrong.

The interesting thing is not that a guidance document was put in a vault. It is that the guidance, the spreadsheet that accompanies it, the risk method it describes and the frameworks it cites are modelled as four separate worlds with named bridges between them, and the vault says plainly why that matters: "containment alone is not fractality. Cross-world edges make the semantic transitions inspectable." 617 nodes, 694 edges, every one declaring its verb, its provenance and whether it was curated or merely found by a lexical match.

Open it yourself. The key is the whole credential.
Read key: sgit_public_read_cdc00d2baaf75361d86ae1b7a40169bd98d71aaae1bd581e181a0f0ba0e0e6bb:0q4sfr57
In the official UI: open it read-only in a new tab · From the CLI: sgit clone sgit_public_read_cdc00d2baaf75361d86ae1b7a40169bd98d71aaae1bd581e181a0f0ba0e0e6bb:0q4sfr57
Submitted under the sgit_public_read_ prefix, which is the form for a key published on purpose. Classified before it touched anything, and verified with an all-zeros negative control: the real key produced 42 files, the control an empty directory. What the prefixes declare →

See it live, here

Open the vault in a new tab ↗Seven sections and a graph canvas. It has more room in its own tab.

The idea worth stealing: four worlds, and the bridges are the point

A guidance document, a spreadsheet, a risk method and a list of external frameworks are not the same kind of thing, and modelling them in one vocabulary would force three of them to pretend to be the fourth. This vault does the opposite. It declares four worlds and lets each keep its own shape:

WorldWhat lives in it
sourceThe publication as retrieved: 30 guidance sections, 67 blocks, and the bytes they came from
risk_methodThe method the guidance describes: risk categories, treatments and appetite
workbookThe official spreadsheet as data: 4 sheets, 490 cells, 208 of them formulas
frameworksThe external standards the text cites, referenced and never reproduced

Eight predicates carry everything between them, and one of the vault's own eight checks is that every predicate declares an inverse, so a link reads correctly from whichever end you stand at: has_artifact, contains, is_derived_from, defines_category, describes_treatment, describes_appetite, mentions, cites.

It states the limit this site spent a week getting right. Its ontology file lists four limits, and the first is "containment alone is not fractality. Cross-world edges make the semantic transitions inspectable." That is the same distinction Fractal Semantic Graphs arrives at from the other direction: a thing inside a thing inside a thing is a hierarchy, and the fractal property is the edge on which you cross into a world with its own rules. Two authors, two vocabularies, one conclusion.
617 nodes across four worlds. Each connection states its verb and how it was obtained: is_derived_from · curated is an authored claim, is_mentioned_by · lexical is a string match, and the vault never lets you mistake one for the other.

The distinction that keeps it honest: curated against lexical

Most attempts to connect a document to a model quietly mix two very different things: an edge somebody decided, and an edge a search found. This vault labels every assertion with which it is, on the face of the link, and then says in its limits that "lexical mentions are not validated meaning."

That single label is what makes the graph arguable rather than impressive. A reader who disagrees with a curated edge is disagreeing with a person, and can say so. A lexical edge claims only that a word appeared. The vault also refuses the inference everyone wants to make from a compliance artefact: "no compliance inference or organisation attestation is made."

The risk-method world, from identification to treatment. Nine categories, each an edge away from the guidance that defines it and the workbook cells that score it.

Every claim carries the bytes it came from

Five source snapshots are retained inside the vault, each with its URL, its retrieval date and the SHA-256 of the bytes: the guidance body, two content-API responses, and the official workbook in both XLSX and ODS. Two of the eight checks exist purely to prove the originals were not touched, and they are named as plainly as that: original XLSX bytes preserved, original ODS bytes preserved.

The workbook is read rather than rewritten. Cached values are not recalculated, dates stay as Excel serials, styling is not reproduced, and the vault says so. That is the difference between publishing a spreadsheet as data and publishing your opinion of a spreadsheet.

"A claim is only as useful as its trace." Eight checks, all passing, and six known gaps published beside them.

The six gaps it publishes about itself

This is the part to copy. The vault ships a known_gaps list, and it is not decorative:

"Inspect. Download. Query." The official files remain unchanged, and SQLite compiled to WebAssembly runs the queries in your tab.

What it demonstrates about vaults

FeatureHow this vault uses it
Read, download, no writefs.read is true and write and delete are both empty arrays. The scoring sandbox is deliberately temporary and is never written back
Queries with no backendsql.js, which is SQLite compiled to WebAssembly, is bundled so the query view works offline. The copies were taken from the published Regulation Graph vault and the provenance of that decision is recorded in NOTICE.md
Versioned in the openTwo releases, each with its own page and JSON record, and the version badge in the app links to the release it is showing
A licence that survives the copySource text under OGL v3.0, application code separately licensable by the owner, bundled sql.js under MIT with SQLite in the public domain. Each is stated rather than blended
Machine-readable on the way outdownloads/graph.jsonld keeps every assertion's provenance and partition, so the graph leaves the vault without losing what made it checkable

The pre-publication audit

Run against a full clone made with the published read key, before this page existed.

CheckedResult
Credentials and secretsNone. No vault key, no credential under any sgit_private_ prefix, no API keys, tokens, delete_auth or append_token values, no private-key blocks
Personal dataNone. Two email addresses appear, alt.formats@dsit.gov.uk and psai-tech@dsit.gov.uk, both published institutional contacts carried over from the official publication
The credential itselfSubmitted as sgit_public_read_, classified by check_credential.py as read-only and declared public before use
Negative controlAn all-zeros key with the same prefix and the same vault id produced no clone at all; the real key produced 42 files
Its own checksRe-read from data/validation.json: 8 of 8 passing, with 6 known gaps published rather than filed away
AttributionOGL v3.0 acknowledged, no crests or logos used, external standards referenced and not reproduced, and official status explicitly disclaimed on the front page and in NOTICE.md

The usual rule applies to this key as to every other one here: revocation is not retroactive. Anyone who fetches these objects keeps them.

Derived facts

42 files · 3.2 MB · app entry index.html · seven sections · 617 nodes, 694 edges across 3 partitions and 4 worlds · 8 predicates, all with declared inverses · 30 guidance sections, 67 blocks · 4 workbook sheets, 490 cells, 208 formula cells · 5 hashed source snapshots retrieved 20 September 2026 · 2 released versions, current 0.1.1 · permissions fs.read with empty write and delete, plus downloads and external links.

Published as row #31. It is also a rung on Fractal Semantic Graphs, beside the Regulation Graph whose sql.js copies it reuses. ← All published vaults · The publishing method