Research
Defining accountability.
What agents are actually doing, measured from the outside and published in full. Every figure below carries the sample it came from.
- Guard0 Research
- Public record
- 196 agents evaluated
A1,716Nothing answers
B10Reachable, gated
C0No such posture
D836Open and capable
F144Open and destructive
2,706 organizations graded from the outside. Not one scored C.
Original research
What we measured.
Guard0's own data and frameworks, in the order they matter. Each entry states its sample and its method.
- The AI Exposure IndexA standing benchmark of AI exposure across 2,706 organizations, graded A to F from the outside. Read your own grade against the distribution, the authentication posture, and what the open surfaces can actually do.
- Live
- 2,706 organizations
- Passive external scan
- Updated continuously
- The State of Exposed AgentsA passive census of every organization publishing a remote MCP server. 1,139 answer to anyone, exposing 13,606 unauthenticated tools; nearly half expose an agent surface with no auth at all.
- Live
- 1,139 exposed servers
- Passive census
- July 2026
- The State of AI Trust196 evidence-linked evaluations of models, agents, and MCP servers. Average security scores decline across the evaluated layers, and the accountability layer is missing.
- Live
- 196 evaluations
- Unweighted means
- July 2026
- The Three Questions FrameworkAn accountability framework for AI agents: what agents do we have, what can they access, and is behavior aligned. With methodology, maturity levels, and a self-assessment.
- Live
- Framework
- Methodology and maturity levels
- Self-assessment included
Field notes
The written record.
Security research, framework guides, and compliance analysis. Ordered within each subject by how much of your surface it touches.
Threat reports
Framework security
- Severity
- Critical
- High
- Medium
- Set by surface reach
Instruments
Run the measurements yourself.
The tools behind the research, open where they can be.
- g0The open-source scanner. 1,128 rules across 12 domains, run from your own terminal.
- The AI RegisterLook up any domain and read the public accountability record we hold for it.
- Training and eventsWorkshops and talks on agent security, run by the researchers who publish here.
- The blogEverything else we write, in one feed.
Guard0 / accountability systemOpen
What this is for
Intelligence is scalable. Accountability is not.
Run the same measurements against your own environment. The first scan takes about fifteen minutes.
G0-RES-00guard0.ai/research2,706 organizations graded196 agents evaluated