Supply Chain Traceability with Knowledge Graphs

Supply ChainProvenanceFAIR DataKnowledge GraphsCase Study

A European automotive supplier can tell you, to the pallet, where a shipment is right now. It cannot tell you, without a six-week manual investigation, whether the cobalt in a battery module it shipped last quarter passed through a smelter that appeared on a sanctions list in March.

Both facts live in systems the company already owns. The first is a logistics question, and logistics questions have been solved. The second is a provenance question, and provenance questions are not solved by any of the technology the industry bought to solve them.

📋
What kind of case study this is An industry case built on public evidence: regulatory texts, market research, published post-mortems, and survey data from McKinsey, Gartner, and CBP. Not a write-up of a client engagement, and there are no anonymised customer metrics in it. Where a figure is vendor-reported or contested, I say so.

1. The problem

What the mandates demand, what the existing stack already delivers, and the gap between them.

1.1 The forcing function

Traceability used to be a differentiator. Between 2026 and 2029 it becomes a condition of market access.

2026 2027 2029 JUL 2026 ESPR framework live EU central DPP Registry opens FEB 2027 Battery passport JUL 2028 FSMA 204 (US) Delayed 30 months, now binding DEC 2026 EUDR applies Plot-level geolocation. SMEs Jun 2027 END 2027 GS1 Sunrise · 2D barcodes at POS JUL 2029 CSDDD — softened Narrowed to tier 1 by Omnibus I
Amber marks artefact obligations: produce a machine-readable record about a specific item. Grey marks the one process obligation, and the only one that got watered down.

That colour split is the argument. Under pressure, Europe narrowed CSDDD back to tier one and delayed it to 2029, and a reasonable executive reads that as the regulatory wave receding.

The reading is wrong for a structural reason. CSDDD was a process obligation: conduct due diligence, document it, publish a policy. Process obligations soften easily because compliance is judged on effort. EUDR, DPP, and the battery passport are artefact obligations: produce a machine-readable record about this specific item, at this identifier, on demand. Those are much harder to water down, because the artefact either resolves or it does not. Those are the ones that survived the Omnibus untouched.

The regulations that got softened asked companies to describe their processes. The ones that survived ask for a resolvable record about a physical thing. That is a semantics problem, not a reporting problem.

What the surviving mandates actually demand:

EUDR Plot-level geolocation of the land where a commodity was produced, carried through every downstream transformation. Seven commodities plus derived products including leather, chocolate, tyres, furniture. Battery Passport Per-item carbon footprint in kg CO₂e/kWh, and recycled content share for cobalt, lithium, nickel and lead verified through chain-of-custody documentation. DPP A resolvable per-item identifier exposing composition, durability, substances of concern and end-of-life data. Delegated acts phase in by sector to 2030, each with ~18 months to comply. UFLPA Already enforced, and inverted: a rebuttable presumption means the importer must affirmatively prove origin. In FY2025 CBP stopped ~7,325 shipments, over 50% above FY2024; about 6.5% were released.

1.2 What existing technology genuinely solved

Any credible argument for new architecture starts by giving the incumbent stack its due. Six problems were solved, and solved well.

Solved, and still working

  • ERP — transaction integrity inside one company's four walls
  • EDI — high-reliability, low-cost document exchange between partners
  • GS1 — globally unique names for items, locations, and serialised instances

Also solved

  • RTTVP — "where is my shipment" is now a commodity capability
  • WMS / TMS — execution as a measurable optimisation problem
  • EPCIS — a standard grammar for supply chain events, JSON-LD native since 2.0

Every one of those answers a question about a transaction or a location. Traceability asks about a chain of transformations, and transactional excellence does not compose into that answer automatically. The industry’s frustration is not that these systems fail at their jobs. It is that the questions being asked in 2026 sit in the space between them.

1.3 What it did not solve, and what it broke

TODAY ERP MES WMS PLM Portal Certs Point-to-point integrations. Each one encodes one team's reading of what a field means. SUP-04471 ERP Acme Metals Ltd Supplier portal ACME METALS LIMITED Certificate PDF DUNS 04-712-9930 Risk platform One supplier. Four identifiers. Nothing in the stack asserts they are the same entity. TIER 2 — TIER 5 · NOT VISIBLE ~42% of firms report any visibility beyond tier 2, down since 2022 (McKinsey, 2025)
Three failures compounding: unmanaged integration sprawl, unresolved identity, and a hard visibility floor exactly where the new mandates operate.

The integration tax compounds faster than the integrations. The commonly cited MuleSoft benchmark puts the average large enterprise near 897 applications with under a third meaningfully integrated. The shape is not disputed: each new point solution adds N integration surfaces rather than one. Buying another visibility tool makes the problem worse, not better.

Identity does not survive the handoff. GS1 gave the industry global identifiers; most of the industry did not adopt them at the interfaces where they matter. The consequence is the middle band above. It is not that companies cannot get tier-two data. It is that they cannot reliably join it to the tier-one data they already have.

Meaning is stripped at every hop. EDI and REST transmit syntax, not semantics. A carbon_footprint field arrives as a number and a unit, without the system boundary, allocation method, reference period, or whether the figure was measured or modelled. It then gets aggregated into a compliance assertion. Under the battery passport’s per-item requirement, that stops being academic.

Provenance amnesia. Almost no operational system records why it holds a value. The derivation, whether an integration job, a supplier declaration, or an analyst’s correction after a phone call, is gone the moment the write commits. This is what makes investigations take weeks: the question is never “what does the system say,” it is “where did that come from, who asserted it, and on what evidence.”

Compliance work is not reusable. Each regulation gets its own project, its own extracts, its own spreadsheet, and its own mothballing. EUDR gets one, the battery passport a different one, FSMA 204 a third. None reuse each other, because none produced a reusable asset. They produced reports. The cost is not any single project; it is that the marginal cost of the next regulation never comes down.

And the blockchain lesson, which the industry has half-learned. TradeLens was discontinued in November 2022 and offline by Q1 2023. The post-mortems converge on governance and network participation, not cryptography: Maersk led operations, competitors would not join a rival’s platform, and without the network the shared ledger had nothing to be shared about. The quieter lesson is that a distributed ledger guarantees all parties see the same bytes. It guarantees nothing about all parties meaning the same thing by them.

⚠️
The trap this sets for the next cycle Every argument made for blockchain in 2018 is being made for AI agents in 2026, with the same missing premise. An agent querying five systems with inconsistent identifiers and undocumented semantics does not resolve the inconsistency. It produces a fluent, confident, unauditable summary of it — faster, and at greater volume, than the humans it replaced.

1.4 The pain points, ranked

# Pain point Evidence Consequence
1 Visibility collapses past tier one ~95% report tier-1 visibility, ~42% beyond tier 2; declining since 2022 (McKinsey 2025) EUDR and battery passport obligations sit at tiers 3-5
2 No cross-system entity identity Same supplier, four identifiers, no linking assertion Every cross-system question starts with unmeasured fuzzy matching
3 Semantics lost in transit EDI/API carry syntax; boundaries and methods are dropped Supplier carbon figures are not comparable to each other
4 No provenance on held values Operational systems record state, not derivation Investigations take weeks; findings collapse under challenge
5 Integration cost scales superlinearly ~897 apps, under a third integrated Each new tool increases total integration surface
6 Data quality erodes silently ~$12.9M per organisation per year (Gartner) Decisions made on contradictory duplicates
7 Compliance work is not reusable Each mandate handled as a discrete extract project Marginal cost of the next mandate stays flat
8 Shocks arrive faster than mapping Nexperia: Dutch intervention Oct 2025, export controls, volatility into 2026 Exposure found after production stops, not before
9 The AI layer amplifies all of it Reported 72-80% of enterprise RAG never reaches production Confident answers over inconsistent data

Rows 2, 3, and 4 are load-bearing. Fix those and 1, 6, 7, 8, and 9 improve as a consequence. Fix row 1 alone, by buying another visibility platform, and 2, 3, and 4 get worse.


2. Where knowledge graphs fit

The honest boundary first, then the principle-by-principle mapping that turns FAIR into supply chain value.

2.1 The boundary: right tool, wrong tool

Overselling this is how the category loses credibility, so the boundary matters more than the pitch.

Right tool for

  • Asserting four identifiers denote one entity, with the evidence
  • Chains of transformation where path length is unknown in advance
  • Carrying meaning with data: units, boundaries, methods, validity
  • Recording derivation with PROV-O
  • Federating across organisations that will never share a schema
  • Machine-checkable data contracts via SHACL, in CI
  • Grounding agents in queryable structure, not embedding proximity

Wrong tool for

  • Replacing the ERP. It is not a transactional store
  • High-throughput event ingestion. Reference an event store instead
  • Numerical optimisation. Routing belongs in a solver
  • Being a data lake with a graph API. Without an ontology it is a slower join
  • Fixing data nobody owns. It surfaces the gap, it does not fill it
  • Known, fixed, single-hop questions. Use SQL

A knowledge graph is a semantic integration layer, not a storage strategy. It sits above the systems of record, holds identity and meaning, and points back at the sources. Most of the volume stays where it is.

The structural fit is narrow and specific: traceability queries are variable-depth path queries over a heterogeneous, federated, partially-known graph. That is precisely the class of problem relational algebra handles badly and graph traversal handles natively. A five-way self-join of unknown depth is an unpleasant SQL query and a trivial SPARQL property path.

2.2 Mapping FAIR to supply chain value

FAIR came out of research data management, and industry’s reflex is to dismiss it as academic. Each principle maps to a specific supply chain failure with a specific cost.

FAIR Supply chain translation Failure it removes Regulation served
F1 identifiers GS1 GTIN/GLN/SSCC plus resolvable IRIs Same entity, four names, no join DPP per-item identifier
F2 rich metadata Batch carries method, boundary, validity — not just a value Supplier figures not comparable Battery passport carbon footprint
F3 metadata references data Certificate points at the batch it certifies Certificates float free of the goods EUDR due diligence statements
F4 registered + searchable Catalogue of which system asserts what Investigations start with “who has this?” EU central DPP Registry
A1 open retrieval GS1 Digital Link + SPARQL/REST, not emailed files Attachments, re-keyed by hand DPP consumer/authority access
A1.2 authenticated access Tiered disclosure by requesting party The real blocker is confidentiality ESPR trade-secret carve-outs
A2 metadata persist The assertion survives the supplier’s exit Supplier churn erases history Multi-year audit lookback
I1 formal representation RDF/OWL over EPCIS 2.0, PROV-O, QUDT Every integration re-invents the model Cross-sector passport interop
I2 FAIR vocabularies Reuse published, versioned vocabularies Private code lists partners can’t read Catena-X / Manufacturing-X
I3 qualified references Typed edges: derived-from, certified-by, substituted-for Untyped graphs can’t answer causal questions Recycled-content chain of custody
R1 accurate attributes Provenance, confidence, validity time per assertion Measured vs. estimated indistinguishable Verified vs. declared DPP data
R1.1 clear licence Explicit terms on shared supplier data Legal review blocks every exchange IDS / Gaia-X data sovereignty
R1.2 detailed provenance PROV-O derivation on compliance values The defensibility gap under challenge UFLPA rebuttable presumption
R1.3 domain standards EPCIS CTE/KDE structure, GS1 identifiers Bespoke models fail partner onboarding FSMA 204 KDEs

Three rows carry the money.

A1.2 unblocks everything else. Multi-tier programmes stall for commercial reasons, not technical ones: a tier-two supplier will not disclose its sources to a customer who might disintermediate it. Tiered disclosure lets a supplier prove a claim without revealing the relationship behind it.

OEM Asks the question "Does any input to this module originate in region X?" Never sees who the tier-3 supplier is — and does not need to. TIER-2 SUPPLIER Answers it Resolves the query against its own graph. PRIVATE Tier-3 identities, prices, volumes — never cross the line. Shared ontology + SHACL contract SPARQL over the shared model "No." + attestation prov:wasAttributedTo auditor, valid through 2027-06 The supplier proves the claim without revealing the relationship. Neither party centralises anything.
FAIR A1.2 in practice. This is the design requirement TradeLens never satisfied, and why Catena-X and Manufacturing-X put access control at the centre rather than the edge.

R1.2 converts a report into a defence. UFLPA runs on a rebuttable presumption; the importer must affirmatively prove admissibility. A number in a spreadsheet is not proof. A value with a typed derivation chain back to a named document, activity, and asserting party is.

I3 is the row most implementations skip. It is the difference between a graph that says two things are related and one that says how. Only the second answers “did this batch’s cobalt pass through a smelter that was later sanctioned,” because that depends on edge types and their time validity, not on connectivity.


3. The architecture

Where things live, how a record gets in, and what a real query looks like on the other side.

3.1 Four layers and a provenance spine

LAYER 4 — CONSUMPTION SPARQL · agents · DPP endpoint · auditor portal Variable-depth path queries. Every answer carries its derivation. LAYER 3 — VALIDATION & REASONING SHACL shapes in CI · OWL inference · policy rules Bad data fails the build, not the audit. LAYER 2 — SEMANTIC LAYER Ontology · identity resolution · GS1 Digital Link EPCIS 2.0 + PROV-O + QUDT + a thin domain model. LAYER 1 — SYSTEMS OF RECORD ERP · MES · WMS · TMS · PLM · portals · certs · IoT Unchanged. Data stays put; the graph holds identity and meaning. PROVENANCE SPINE PROV-O wasDerivedFrom wasGeneratedBy wasAttributedTo Applied at every layer, not bolted on at the end. ACCESS CONTROL Tiered disclosure per requesting party role. The row that unblocks tier-2 participation.
A semantic integration layer above unchanged systems of record, with provenance and access control as vertical concerns rather than afterthoughts.

The layers say where things live. This is what actually happens to a single record on its way in:

01 Source ERP row · cert PDF · EPCIS event 02 Extract typed fields, raw payload retained 03 Resolve ID GS1 → IRI sameAs with its evidence 04 Map EPCIS 2.0 PROV-O QUDT units 05 SHACL gate runs in CI, not at audit time 06 Graph queryable, every value attributed ✗ violation report build fails, bad data never lands prov:wasGeneratedBy recorded at every stage — the derivation is captured on the way in, never reconstructed later
Identity is resolved before mapping, and validation runs before the write. Reverse either order and provenance becomes a reconstruction exercise instead of a record.

Four commitments separate this from a graph database project that fails.

Reuse standard vocabularies before writing your own. EPCIS 2.0 models supply chain events. PROV-O models derivation. QUDT models units. GS1 provides identifiers. Your domain ontology should be thin — the part that is genuinely yours, on top of published, dereferenceable vocabularies. Teams that model everything from scratch produce ontologies nobody outside the team can consume, which defeats the purpose.

Validate in CI, not in production. A supplier feed missing a required geolocation for an EUDR-scoped commodity should fail before it lands, with a structured violation report naming the offending node.

Federate rather than centralise. The centralisation instinct is what killed TradeLens. Suppliers will not hand data to a customer’s central store; they will expose a governed endpoint over a shared model. Retrofitting that is a rebuild.

Put provenance in from the start. Retrofitting PROV-O means reprocessing every source. It costs almost nothing at ingestion and is what makes the whole structure defensible.

3.2 What changes: a worked traversal

WITH A SEMANTIC LAYER ERP MES WMS PLM Portal Certs SEMANTIC LAYER · ontology + identity resolution + PROV-O Acme Metals Ltd — one node owl:sameAs × 4, each assertion carrying its own evidence Tier 2 — Tier 5, now traversable Module Cell (T1) Cathode (T2) Smelter (T3) Mine (T4) hasComponent transformedFrom processedAt sourcedFrom Every hop typed, time-bounded, and attributed to a named source. prov:wasDerivedFrom → prov:wasAttributedTo → prov:wasGeneratedBy Six weeks of investigation → one query
Same systems, unchanged. What differs is that identity is resolved once, edges are typed, and the derivation travels with the answer.

Stated precisely, the opening question is: for battery module SGTIN:...4471, does any cobalt input trace to a smelter that appeared on a restricted-entity list during that material’s custody?

Today that means pulling the BOM from PLM, finding the cell supplier in ERP, emailing them for their cathode supplier, receiving a spreadsheet, hand-matching names against the risk platform, and reconciling three date formats. Six weeks, and the result is undefendable because none of the joins were recorded.

In the graph it is a path query with a time filter:

PREFIX prov: <http://www.w3.org/ns/prov#>
PREFIX sc:   <https://example.org/supplychain#>

SELECT ?smelter ?listedOn ?evidence
WHERE {
  ?module sc:gtin "...4471" .

  # variable-depth traversal upstream (F1 identity makes the path connect)
  ?module (sc:hasComponent|sc:wasTransformedFrom)+ ?material .
  ?material sc:materialType sc:Cobalt ;
            sc:processedAt   ?smelter ;
            sc:custodyPeriod [ sc:start ?from ; sc:end ?to ] .

  # I3 qualified reference: time validity, not bare connectivity
  ?smelter sc:appearsOnList ?listing .
  ?listing sc:listType sc:RestrictedEntity ; sc:effectiveFrom ?listedOn .
  FILTER (?listedOn <= ?to)

  # R1.2 provenance: what makes the answer survive an auditor
  ?material prov:wasDerivedFrom ?evidence .
  ?evidence prov:wasAttributedTo ?asserter ; prov:wasGeneratedBy ?activity .
}

The + works only because F1 identity resolution already merged the PLM and ERP supplier into one node. The FILTER works only because I3 carried custody time validity, without which every smelter ever listed returns a false positive. The ?evidence binding is what makes the output a claim with a citation chain rather than a claim.

The reusability property The same graph, unchanged, answers the EUDR geolocation question, the battery passport recycled-content question, and the FSMA 204 CTE question. Different queries, one asset. That is why the marginal cost of the next regulation falls instead of staying flat.

4. The business case

How big the market is, how fast it moves, and why the window is narrower than it looks.

4.1 Market size and growth

Estimates vary by a factor of four depending on whether the analyst counts software only, software plus hardware plus services, or folds traceability into broader visibility. Published CAGRs for nominally the same market run from 4.4% to 16.8%. Treat these as directional.

Track & trace ~$5.84bn (2026) → ~$10.87bn (2030), ~16.8% CAGR Traceability, broad ~$8.6bn (2024) → ~$30.2bn (2033), ~14.9% CAGR. Includes hardware and services Knowledge graph ~$1.9bn (2026) → ~$9.88bn (2032), ~31.6% CAGR

The useful reading is the relationship, not any single figure: traceability is large and growing at roughly 15%; the semantic layer inside it is an order of magnitude smaller and growing at roughly twice the rate. That gap is the opportunity and also the risk — small and fast-growing means immature tooling, a thin talent pool, and expensive buyer education.

Two demand signals matter more than the sizing. Compliance budget is not discretionary: EUDR and DPP spend competes against losing EU market access, not against other IT projects, which is why this market grows through a downturn. And the AI budget is looking for grounding: with a reported 72-80% of enterprise RAG never reaching production, the “knowledge graphs ground agents” argument has a receptive audience with money. I would treat the specific vendor-published GraphRAG numbers with scepticism; the directional claim that multi-hop reasoning over typed edges beats embedding proximity for questions with a defined answer path stands independently of them.

4.2 Timing: why the window is 2026 to 2028

The technology has been stable for over a decade. What is new is that four clocks are converging, and they will not stay converged.

Regulatory Fixed dates from Dec 2026 to Jul 2028. Building a semantic foundation takes 12-24 months. Identifier GS1 Sunrise 2027 is a once-in-a-generation re-identification of the world's products. Companies are re-labelling anyway. Data space Catena-X and Manufacturing-X are writing the shared vocabularies now. Shaping them is cheaper than conforming later. AI Agentic pilots are being funded now and will harden into platforms. The window to influence that choice is closing.

The Sunrise convergence is the most actionable and the most overlooked. A company re-labelling its catalogue for 2D barcodes in 2026-27 is touching every product identity it owns. Making those identifiers resolvable during that programme costs a fraction of doing it separately in 2029.

The cost of waiting is not linear Solve EUDR, the battery passport, and FSMA 204 as three point projects and you arrive in 2029 with three incompatible traceability stacks and a migration bill, rather than one asset and a marginal query. The penalty is paid in rework, not delay.

5. Acting on it

Sequencing, the actors who have to move, the measures that prove it worked, and the arguments against.

5.1 A coarse roadmap

PHASE 0 · MONTH 0-3 One question Not a domain. A single competency question with an acceptance test. Ships: a written scope nobody can widen. PHASE 1 · MONTH 3-9 Identity + provenance For that question only. Reuse EPCIS, PROV-O, QUDT. SHACL in CI. Ships: an answer a compliance officer uses. PHASE 2 · MONTH 9-18 Depth, then breadth Add tier 2 before adding a second question. Test access control for real. Ships: one supplier negotiation, survived. PHASE 3 · MONTH 18-36 Second regulation On the same asset. This phase proves or disproves the whole thesis. Ships: a query, not a new project. Depth before breadth. One regulation fully before two partially. Tier-one breadth demos well, proves nothing, and defers the hard problem: cross-organisational identity and disclosure.
Each phase must ship something a business owner would miss if you removed it. That constraint is what prevents the eighteen-month ontology exercise that ships nothing.

The failure mode for this class of programme is modelling the whole domain and delivering nothing. Phase 3 is the honest test: if adding the battery passport to a graph built for EUDR is a vocabulary extension rather than a new project, the architecture works. If it is a new project, phase 1 modelled one regulation’s reporting format instead of the underlying domain.

Throughout, treat the ontology as a versioned public API — semantic versioning, deprecation policy, a compatibility contract. Partners integrate against it, so breaking changes have the blast radius of a broken REST API.

5.2 What the industry must do

The gap is not principally technical. Four actors have to move, and only one is the enterprise.

Enterprises Procure traceability as a data asset, not a compliance report. Put "must support standard vocabularies and export RDF or JSON-LD with provenance" into RFP language. Vendors respond to procurement language. Standards bodies The gap is not new standards, it is published, opinionated profiles. A named EUDR profile over EPCIS 2.0 and PROV-O, with reference SHACL shapes, would eliminate the six months each company spends deciding how to model the same thing. Vendors Accept that the semantic layer is a shared substrate, not a lock-in surface. The network effect TradeLens could not achieve goes to whoever makes participation cheapest. Regulators Specify machine-readable conformance, not document templates. The DPP Registry is the right shape: an identifier that resolves. PDF submissions generate one-off extraction projects and worse data.

5.3 How to measure whether it worked

Time to answer Novel traceability question → defensible answer. Weeks to minutes. Measure on questions you did not build for. Traceable depth Maximum tier reachable with unbroken identity and provenance. The ~42% McKinsey baseline is the benchmark. Marginal cost Second and third mandate as a fraction of the first. Not falling sharply by the third means the architecture is not delivering. Provenance coverage Share of compliance-relevant assertions with a complete derivation chain. Anything without one is undefendable. SHACL trend Violations caught in CI vs. found in production. Rising catch rate, falling incidents. Onboarding time Days to bring a new supplier onto the model. The proxy for whether you built a contract or a bespoke integration.

5.4 Honest limitations

Four arguments cut against this thesis, and a case study that ignores them is marketing.

Willingness is a bigger problem than capability. Most tier-two suppliers can produce their tier-three data; they decline because disclosure threatens their position. Tiered access makes disclosure possible, not attractive. Where the commercial incentive is genuinely adverse, only regulation or buying power moves it.

These programmes fail at a high rate, usually by over-modelling. A team spends a year on a comprehensive ontology, ships nothing, loses its sponsor. The phase discipline above is a direct response, and it is the part of this analysis I would defend most strongly.

The talent market is thin. People who can do ontology engineering, understand supply chain operations, and ship production systems are rare. That argues for reusing published vocabularies rather than building capability you cannot staff.

Regulatory softening is a real risk, not just an excuse. The CSDDD retreat happened. If EUDR is delayed again, the urgency argument weakens. My read is that artefact obligations are structurally harder to soften than process obligations — but that is an argument from structure, not a certainty. A company betting entirely on regulatory pressure, with no operational value along the way, has made a fragile bet. Phase 0’s “ship something a business owner would miss” is partly a hedge against exactly that.


References

Regulatory: European Commission, EUDR implementation; Covington, CSDDD/CSRD Omnibus in the Official Journal (Feb 2026); Norton Rose Fulbright, Omnibus Directive analysis; FDA, FSMA 204 final rule; Federal Register, FSMA 204 compliance date extension; CBP, UFLPA enforcement statistics; Circularise, EU battery passport requirements; GS1 US, Sunrise 2027.

Failure modes: Frontiers in Blockchain, "Exploring the failure factors of blockchain adopting projects: a case study of TradeLens through the lens of commons theory"; PYMNTS on Walmart's blockchain programme; JAGGAER, why visibility breaks down beyond tier 1 (citing McKinsey 2025); Gartner on data quality cost; Resilinc on the Nexperia crisis.

Architecture and market: Catena-X Digital Product Passport use case cluster; International Data Spaces, IDS and the FAIR principles; MarketsandMarkets, knowledge graph market (June 2026); MarketsandMarkets, track and trace solutions.

Market figures are drawn from commercial research with differing scope definitions and are directional. GraphRAG performance figures are vendor-published and should be treated accordingly.