AI agent governance is changing fast
Microsoft, NIST, ISO, OWASP, the EU, Google, the Cloud Security Alliance, and MITRE are publishing new guidance every quarter. AgentProof tracks those named sources and turns them into a practical compliance-readiness model — what to document, not a verdict on the law.
Know what kind of agent you are building
AgentProof's Capability Zones (Knowledge, Task / Tool-Assisted, Autonomous Action) plus five cross-cutting modifiers tell you which controls matter and which evidence a stakeholder will expect before your compliance review.
See what good design should include
20 documented good-design patterns covering least-privilege tool access, human approval, audit trails, fallback paths, sensitive-data handling, and continuous reassessment.
Avoid weak agent design patterns
20 documented anti-patterns linked to the named risks they create — including excessive permissions, broad autonomy without approval, and prompt-injection exposure.
Use controls and evidence
Each readiness control names what acceptable, strong, and weak evidence looks like — so the record captures documented proof, and a stakeholder review is grounded rather than improvised.
Produce a compliance-readiness record
The compliance-readiness record brings the whole story of an agent into one place — readiness, evidence, gaps, controls, and review flags — version-stamped. When the library evolves, AgentProof surfaces a calm advisory to reassess; it never silently re-scores.
Stay current with the AI Landscape Radar
AgentProof tracks watch-status signals (autonomy boundaries, identity, oversight, regulation, injection testing) and flags when an agent's record may need reassessment when supporting sources publish guidance.
Start with the Compliance Readiness Pilot
Start with the Compliance Readiness Pilot — a fixed €1,500 engagement covering up to 5 AI agents — and build a versioned compliance-readiness record for each agent in your own workspace.
AgentProof learns continuously, but changes are human-reviewed
AgentProof's source-tracking + change-detection + proposed-update engine surfaces source changes. Nothing reaches scoring, the compliance-readiness record, or buyer-facing guidance without a recorded reviewer decision.