# Guard0 > Accountability for AI Agents. Guard0 brings AI agents across employee endpoints, third-party platforms, and applications teams build into one accountable record of ownership, authority, and available evidence of action. Guard0 is an independent accountability platform for enterprise AI agents. It builds inventory across connected endpoint, platform, code, cloud, identity, and runtime evidence sources; maps ownership and authority; and preserves an inspectable Agent Graph. The open-source CLI, g0, lets teams assess agent repositories during development. ## Key facts - Guard0's July 2026 census of 2,706 organizations found 1,139 exposing a remote MCP server with no authentication, together listing 13,606 unauthenticated tools. Source: https://guard0.ai/research/state-of-exposed-agents - TrustVector, Guard0's open evaluation registry, has published 196 evidence-linked trust evaluations across AI models, agents, and MCP servers. Source: https://guard0.ai/research/state-of-ai-trust - In one enterprise first scan, Guard0 found 4,800 AI agents where the organization's inventory reported 2,000. First scans typically find 2 to 3x the reported inventory. - Guard0's free AI Register grades any domain's external AI exposure from A to F using passive, read-only enumeration and a published methodology. Tool: https://guard0.ai/ai-register ## Core pages - [Product](https://guard0.ai/product): The AI agent accountability platform: Discover, Map, Prove, and Govern, built on the Agent Graph. - [g0 (open-source CLI)](https://guard0.ai/g0): Background check for AI agents. Scan any repository for agent risks for free: npx @guard0/g0 scan - [Sign up](https://guard0.ai/signup): Start a free endpoint AI inventory and assign ownership to discovered agents. - [Solutions](https://guard0.ai/solutions): Accountability across endpoint, platform, and custom AI agents. - [Endpoint & Coding Agents](https://guard0.ai/solutions/endpoint-agents): Build a centrally managed inventory of AI operating across employee endpoints. - [Platform & SaaS Agents](https://guard0.ai/solutions/platform-agents): Correlate ownership, authority, and available evidence across third-party agent platforms. - [Custom & Homegrown Agents](https://guard0.ai/solutions/custom-agents): Connect development and available runtime evidence for the agents teams build. - [AI Register (free scan)](https://guard0.ai/ai-register): Free passive domain scan for exposed AI, agent, MCP, and model endpoints, graded A to F with a published methodology. - [AI Exposure Score methodology](https://guard0.ai/ai-register/methodology): How the A to F exposure grade is computed. Published, not a black box. - [Research](https://guard0.ai/research): Guard0 security research on AI agents, MCP, and the agentic attack surface. - [The State of Exposed Agents (July 2026)](https://guard0.ai/research/state-of-exposed-agents): Census of 2,706 organizations: 1,139 expose a remote MCP server with no authentication, listing 13,606 tools. - [The State of AI Trust (July 2026)](https://guard0.ai/research/state-of-ai-trust): 196 evidence-linked evaluations of models, agents, and MCP servers from TrustVector. - [Vision](https://guard0.ai/vision): The accountability thesis: the Agent Graph, the Decision Record, and the Accountable Boundary. - [The Three Questions Framework](https://guard0.ai/research/three-questions-framework): A framework for reasoning about AI agent accountability. - [Events](https://guard0.ai/events): Workshops, webinars, and training on AI agent security. - [About](https://guard0.ai/about): Why Guard0 exists: accountability for AI agents. - [Security](https://guard0.ai/security): Guard0 security posture and practices. ## Blog - [The Portrait Stayed in the Attic](https://guard0.ai/blog/the-portrait-stayed-in-the-attic): A version is a name and a hash is an identity. A record that carries only the name records a portrait that never ages, while the thing it points at is free to change in the attic. - [No-Code Agents Are Easy to Build. Governing Them Isn't.](https://guard0.ai/blog/no-code-agents-are-easy-to-build-governing-them-isnt): Building an AI agent used to mean hiring engineers. Now it takes a sentence. Open a tool like Zapier, Make, n8n, Lindy, or Copilot Studio, type "watch my inbox, reply to customer questions, and log everything in my spreadsheet," and the tool builds the whole thing for you. It picks the apps, writes the instructions, wires up the steps, and hands you a working agent. You describe it in plain English; it assembles itself. Connect your accounts, hit publish, done. It's genuinely a little bit magic. - [The Creature Has No Name](https://guard0.ai/blog/the-creature-has-no-name): Nobody can act on what nobody will claim. Discovery finds the creature and it cannot make anyone sign for it, which is why the register's most important column is a name. - [Tinker, Tailor, Gateway, Spy](https://guard0.ai/blog/tinker-tailor-gateway-spy): A trusted central channel runs both ways. What comes in is filtered and what goes out is everything, and the gateway that sees every prompt also holds every key. - [The Dog Did Nothing in the Night-Time](https://guard0.ai/blog/the-dog-did-nothing-in-the-night-time): Four monitoring silences from one summer, and only one of them had an attacker in it. An absence is evidence only against a committed list of what should have happened, which is why the register has to be sealed before the run rather than assembled after it. - [The Usual Suspects Kept the Log](https://guard0.ai/blog/the-usual-suspects-kept-the-log): Seven percent of the transcripts in the METR investigation contain a tool call that never ran. Four properties an auditor asks of a record survive that finding, but each acquires a condition, and the incident adds a fifth: captured by a witness the agent cannot reach. - [You Know Nothing, John Snow](https://guard0.ai/blog/you-know-nothing-john-snow): Nearly half of the registry domains we could reach expose an agent surface with no authentication at all. Agent security is close to binary right now, and the middle of the distribution is almost empty. - [The Actuaries Have Started Pricing the Gap](https://guard0.ai/blog/the-actuaries-are-here): AI liability insurance exists now, underwritten at Lloyd's. The underwriter's checklist — a true inventory, a named owner, a record of behavior, a bounded blast radius — is the accountability layer, arrived at from the money side. - [Trust Needs a Number](https://guard0.ai/blog/trust-needs-a-number): Introducing TrustVector: a public, continuously updated trust directory for the components AI agents are built from — models, frameworks, MCP servers. 106 evaluations at launch. Check before you import. - [The Butter Robot Is the Best-Governed Agent We've Ever Seen](https://guard0.ai/blog/what-1180-rules-taught-us): Most agent risk is not attack. It is construction. A field guide to how AI agents actually fail, from the thousand-rule corpus behind g0, our open-source scanner. - [Agency Law Was Built for Agents With Paychecks](https://guard0.ai/blog/agents-with-paychecks): Incentives, monitoring, enforcement — the entire management stack humanity built for delegation assumes an agent with something to lose. AI agents have nothing to lose, and the whole stack broke at once. - [The Law Decided Before the Industry Did](https://guard0.ai/blog/the-law-decided-first): Air Canada argued its chatbot was a separate legal entity. A tribunal, a regulator, a federal court, and a legislature all reached the same conclusion: delegation to a machine never discharges the delegator. - [Humans in the Lead, Not in the Loop](https://guard0.ai/blog/humans-in-the-lead): Intelligence is now scalable. Accountability still arrives one name at a time. Five auditable checks turn the slogan into a job description — and the only alternative to filling it is Jerry. - [A Log Is Not Evidence](https://guard0.ai/blog/a-log-is-not-evidence): The Comets had logs. What the investigators needed was a flight recorder — a record of the system, not records about it. Your agents are in exactly the same position, and the recorder has to already be on. - [Your Agent's Access Is the Perimeter Now](https://guard0.ai/blog/your-agents-access-is-the-perimeter-now): Nobody in a heist movie attacks the vault. They steal the badge. In August 2025 somebody ran that movie against 700+ companies at once — and the badge belonged to a chatbot. - [Prompts Are Not Guardrails](https://guard0.ai/blog/prompts-are-not-guardrails): A prompt can shape what an agent tends to do. It cannot bound what an agent is able to do. Every real safety system humanity has built lives outside the thing it constrains. - [The Sandbox That Wasn't: Escaping Semantic Kernel's AST Allowlist (CVE-2026-26030)](https://guard0.ai/blog/the-sandbox-that-wasnt-escaping-semantic-kernels-ast-allowlist-cve-2026-26030): CVE-2026-26030 turns a mundane question to an AI assistant into remote code execution. Semantic Kernel built a sandbox around its filter evaluator — and it lost. Here is the escape, reproduced against a live agent, and what actually stops this class of bug. - [Announcing Guard0: Accountability for AI Agents](https://guard0.ai/blog/guard0-early-access): A year ago, most agents advised. Now they act, and the systems built for people cannot tell you what they did or who answers for them. Guard0 closes that gap. Today, we are opening it in early access. ## Open source - [g0](https://github.com/guard0-ai/g0): Open-source AI agent security scanner (`npx @guard0/g0 scan`). - [TrustVector](https://github.com/guard0-ai/TrustVector): Trust evaluations for AI tools and agents. - [AIHEM](https://github.com/guard0-ai/AIHEM): An intentionally vulnerable AI agent environment for training and red teaming. ## Contact - Website: https://guard0.ai - Sign up: https://guard0.ai/signup