Knowledge Graphs
PROBABLY RIGHT IS THE WRONG TARGET
In regulated work, an approximate answer is a liability. The target is not a more capable model but deterministic integrity: the same answer every time, with every claim traceable to its source.
Probably right is fine for a consumer app. In regulated work it is a liability. The fix is not a more capable model. It is a system whose correctness does not depend on the model being right on any given run — a property we call deterministic integrity.
Why probabilistic retrieval fails in regulated domains
Vector-store and plain RAG designs fail in family law, clinical records and financial disclosure for three structural reasons, none of which a larger model repairs.
- Entity collisions. Two clients named Patel merge into one because identity is nothing more than embedding proximity. There is no schema disambiguating who is who.
- Claims read as established facts. A figure asserted by one party is stored exactly like a figure adjudicated by a tribunal. Without a typed distinction, the system cannot tell an allegation from a finding.
- Answers with no source. A fluent paragraph arrives with no page, no paragraph number, no date. It will not survive cross-examination.
What deterministic integrity actually means
Two properties, both testable:
- Reproducibility. The same inputs return the same answer today and in an audit two years from now.
- Traceability. Every claim carries a path back to the source document, page and paragraph that produced it.
The build discipline: four layers
Meaning has to live in the typing, not in the prose. That is built in order.
- Vocabulary — one name per concept, agreed and enforced.
- Taxonomy — the kinds of thing: a pension is an asset, an asset is a disclosable item.
- Ontology — what can relate to what: parties make assertions, valuations contradict valuations, a DEXA scan supersedes a smart-scale reading.
- Schema — the database refuses writes that break the ontology.
The result is a context graph rather than a pile of embedded text.
The contrast, worked
Probabilistic: "The parties seem to disagree about income, by somewhere around thirteen thousand."
Deterministic: The applicant asserts £55,000 (statement p.15, ¶2.15). The respondent asserts £68,000 (p.16, ¶2.15). Variance £13,000, disputed since 20 January 2025. That answer is tribunal-ready; the first one is not.
What the substrate gives you — and what it cannot
The supporting machinery used to be hand-built: contradiction detection, supersession without deletion, provenance binding, tenant isolation, temporal clocks. It no longer has to be. A modern substrate supplies three independent clocks (system, valid and transaction time), provenance as a stored field carrying source kind, trust level and byte offsets, supersession by end-dating rather than deletion, refusal when a low-confidence fact would override a high-confidence one — logged as an open question rather than silently resolved — and reads that stay traceable end to end.
What no substrate can supply is domain meaning: your entities, your relationships, and which sources count as authoritative. That is the work.
The question worth asking
If your AI system gave a different answer tomorrow to the one it gave today, would you be able to tell? In regulated work, if the answer is no, the system is not fit for purpose — however good the model behind it.
Adapted from "Probably Right Is the Wrong Target" by Jonathan Aiken, first published in Deterministic Integrity: Building AI for Regulated Work.