Vigilia.

Methodology · deterministic scoring

How Vigilia scores AI governance.

Every score, gap, and remediation in a Vigilia report comes from a deterministic graph analysis. No black-box AI judgement. You can explain every finding to your regulator and your board.

01

The model

Your AI system, read as a graph.

Vigilia represents your AI system as a directed graph: agents, human approvers, data sources, governance policies, monitoring systems, and decision points are vertices. Their relationships — orchestrates, accesses, approves, monitors, constrained by — are edges.

Compliance signals are then extracted from the graph topology. Missing edges, for example an agent making decisions with no human approval chain, trigger gap findings. Each finding maps to the specific regulatory article it violates, with the affected agent named directly.

Scoring is deterministic. AI is used only to enrich gap narratives — never to determine whether a gap exists.

Frameworks supported

  • EU AI Act — Article 50 transparency from 2 August 2026; Annex III high-risk from 2 December 2027, deferred by the Digital Omnibus
  • NIST AI Risk Management Framework 1.0
  • ISO/IEC 42001 — AI management system
  • US Executive Order 14110 on AI
  • UK AI Regulation Principles
02

Risk classification

Four tiers. The tier decides which articles apply.

Every workspace is classified from the kind of decisions its agents make. Articles that do not apply to your tier are excluded entirely — they neither pass nor fail, so they cannot inflate the score.

  • Minimal riskLow-stakes use cases — spam filters, recommender systems. Standard transparency obligations apply.
  • Limited riskUser-facing AI — chatbots, content generation. Disclosure obligations apply under Article 50.
  • High riskAnnex III use cases — recruitment, credit, healthcare, education, law enforcement. Conformity assessment, risk management, human oversight, and technical documentation required.
  • Unacceptable riskProhibited practices under Article 5 — social scoring, real-time biometric identification in public spaces, manipulative AI. Deployment may be unlawful.
03

Six governance dimensions

What each dimension actually measures.

Each dimension is scored from your graph. The signal is the structural relationship that drives the score; the article is the EU AI Act provision it maps to.

Governance dimensions — signal and mapping
DimensionGraph signalEU AI Act
Human oversightAPPROVES / ESCALATES_TO ratioArt. 14
Data securityACCESSES density + CONSTRAINED_BYArt. 10
TransparencyMONITORING_SYSTEM + AUDIT_LOG flowsArt. 13
AccountabilityDECISION_OUTPUT traceabilityArt. 14 + Art. 9
ReliabilityORCHESTRATES chain depthArt. 9
Regulatory complianceGOVERNANCE_POLICY coverageArt. 9
04

Eight structural anti-patterns

Detected from the graph, not from a questionnaire.

Each detection triggers a gap with a severity, a fine exposure, and a remediation step.

  1. 01Single approval bottleneckTrigger: One approver controls more than 50% of decisionsArt. 14
  2. 02Decision loop without auditTrigger: Decision outputs with no AUDIT_LOG flowArt. 13
  3. 03Data over-accessTrigger: Agent accesses 3+ data sources with no governance policy attachedArt. 10
  4. 04Agent monocultureTrigger: All agents use the same provider and model familyArt. 9
  5. 05Shadow agentTrigger: Agent with no monitoring, no policy, and no human oversightArt. 9 + Art. 11
  6. 06Brittle orchestration chainTrigger: ORCHESTRATES chain depth ≥4 with no escalation pathArt. 9
  7. 07Accountability gapTrigger: Decision outputs with no traceable human ownerArt. 14
  8. 08Undocumented high-risk agentTrigger: EU AI Act Annex III use case with no governance documentationArt. 9
05

Scoring, severity, effort

How a score is computed.

For each selected framework:

  1. Vigilia loads every applicable article for your detected risk tier.
  2. Each article carries a graph signal — a structural condition that must hold, for example “every high-risk agent must have at least one APPROVES edge from a HUMAN_APPROVER”.
  3. The condition is evaluated against your graph index. If it holds, the article passes. If not, it becomes a gap with the affected agents named.
  4. The framework compliance score is passing_articles / total_applicable_articles.
  5. The overall score is the average across selected frameworks.

Severity and effort ratings

Every gap carries a severity — critical · high · medium · low — reflecting regulatory exposure and likelihood of enforcement, and an effort rating — low · medium · high — estimating implementation complexity. Both are relative indicators to help you prioritise remediation; they are not legal opinions.

Fine exposure figures cited in reports are statutory maximums from the underlying regulation. Actual exposure depends on your turnover, the specific circumstances of any enforcement action, and the discretion of the supervisory authority.

What this methodology does not do

  • It does not assess runtime behaviour — only the documented graph you provide.
  • It does not constitute legal advice or a formal conformity assessment.
  • It does not verify the truthfulness of your agent descriptions; the report is only as accurate as the data you submit.
  • It does not guarantee regulatory outcomes. A passing report is evidence of a structurally sound governance posture, not proof of full compliance.

Vigilia reports are designed to give compliance teams, legal counsel, and regulators a clear, structural starting point. Use them alongside qualified legal advice.

The audit itself

The same method, run against your own agent network.

€499, against audits that conventionally cost €5,000 to €40,000. Every finding in your report traces back to a rule on this page and a specific article.

See how the audit works