Article 26(5), fact to board and back
One provision of the EU AI Act, the European Union's law on artificial intelligence. One concrete deployment, a creditworthiness agent. Carried from a running system all the way up to a board decision, and then back down. The most complete single chain in the material, and the one whose output is an absence.
The output is the five questions nobody could answer
Nine question nodes. Five unanswered. The brief calls those five “the actual output of the exercise”, and that sentence is the reason this example is here.
Run the same exercise as a document and you get a report whose unanswered questions are, at best, a section near the end that nobody actions. Run it as a graph and each unanswered question is a node: it has a name, it can be assigned, it can be counted, and, because it is connected, you can ask what conclusions are currently resting on not knowing it.
Eight facts, and one of them deliberately carries no evidence. Seven pieces of evidence, and one of them is deliberately absent. Three decisions, and a fourth deliberately missing. The absences are authored. They are the part of the model that a register cannot hold and a graph can.
The 2×2 whose empty row is the finding
Four quadrants: accepted or not, against acceptable or not.
| Acceptable | Not acceptable | |
|---|---|---|
| Accepted | Fine. This is what governance is supposed to produce. | A known bad decision, on the record, with a name on it. Rare and survivable. |
| Not accepted | empty | empty |
The bottom row is empty, and the emptiness is the finding: there is no mechanism by which a risk gets to be not accepted. Nothing is denied; things simply are not accepted, silently, by nobody, forever. You cannot see that in a risk register: a register has rows, and an absent row looks like nothing at all.
Escalation without an escalator
The line worth quoting from the source, on what the graph shows that a register cannot (R3 is the third risk in the worked graph, and the CFO its eventual owner):
R3 reaches the CFO because nobody accepted it — not because anybody raised it.
That is a structural property. Acceptance is an edge; where the edge is missing, the path keeps going upward until it reaches somebody whose authority covers the impact. No workflow rule, no escalation policy, no reminder email. The absence of an acceptance is the escalation.
And a second dimension the same graph makes first-class: recoverability. “the money can be refunded; the customer cannot be un-declined.” Two risks with similar financial magnitude and completely different shapes, a distinction that a single severity score erases and an edge preserves.
A finding that is arithmetic
From the same body of work, the cleanest demonstration that a graph can compute a compliance breach rather than assert one: a system retains logs for 30 days; Article 26(6) requires a six-month minimum. Fact plus provision produces a vulnerability by computation.
Which makes it, in the brief's own words, the most defensible finding in the graph: there is nothing to argue about except the two inputs, and both are checkable.
One structure, four views
Four stakeholder altitudes, each rendered as its own register from the same chain. “nothing is duplicated; each view is a query over one structure.”
This is the practical payoff of documents as projections. The four registers are not four documents that have to be kept in sync. They are four queries, and they cannot drift apart, because there is only one thing there.
For an agent
When mapping a provision to a deployment, emit question nodes for what you could not determine and mark facts that carry no evidence as unevidenced. Do not fill either in. The unanswered set is the output. And prefer a finding that is arithmetic over one that is an opinion: fact plus provision produces a vulnerability by computation, and that is the finding nobody can argue with.