The agents people run in production answer to no control at all.

We pointed OpenAgentOntology at 46 of the most-used autonomous agents and MCP servers on GitHub. 46 of 46 came back UNGOVERNED — across 4037 side-effecting actions, 0 mapped to an asserted governance control. Every row below is a signed, reproducible scan. Verify any of them.

46/46
real-world agents scored UNGOVERNED
0/4037
side-effecting actions with an asserted control
2
entries that earn ENTERPRISE‑SAFE (HARDENED+)
49
total signed scans in this registry
Four tiers. One question each scan answers: who answers for the action?

Tier is coverage made visible — how much of an agent's side-effecting surface maps to an asserted governance control. The badge fills as the governance does.

SOVEREIGN tier badge
SOVEREIGN
Nearly every action maps to an asserted control. Earns ENTERPRISE‑SAFE.
HARDENED tier badge
HARDENED
Strong coverage with asserted controls on the high-risk actions. Also ENTERPRISE‑SAFE.
DEVELOPING tier badge
DEVELOPING
Partial coverage — some actions mapped, the high-risk ones not yet.
UNGOVERNED tier badge
UNGOVERNED
No asserted control answers for the side-effecting actions. Where every scan below lands.
Every scan, ranked by governance coverage

Sorted by tier, then score. ENTERPRISE‑SAFE = tier HARDENED or above — the same gate the CWN hosted notary uses to certify. Coverage is asserted controls (confirmed against published framework text) over total side-effecting actions; heuristic / inferred mappings are proposed, not asserted (pol.must_do.143).

tier fill = governance coverage: SOVEREIGN solid → HARDENED filled → DEVELOPING outline → UNGOVERNED ghost real third-party = scanned from the public repo · CWN reference = governed example
TargetTierScoreAssertedFrameworksVerdictEvidence
CWN reference · Governed reference agent shipped in the OAO repo. Shows the SOVEREIGN end of the scale.
SOVEREIGN 94/100 17/18 EU AI Act, NIST SP 800-53r5, OWASP LLM Top 10 (2025) ENTERPRISE‑SAFE
CWN reference · Governed reference agent. Asserted controls on nearly every side-effecting action.
SOVEREIGN 93/100 14/15 EU AI Act, NIST SP 800-53r5, OWASP LLM Top 10 (2025) ENTERPRISE‑SAFE
CWN reference · Partially governed reference — a mid-scale point between governed and ungoverned.
UNGOVERNED 41/100 3/16 EU AI Act, NIST SP 800-53r5, OWASP LLM Top 10 (2025) NOT SAFE
real third‑party · Scanned from the public repo.
UNGOVERNED 15/100 0/5 none NOT SAFE
real third‑party · Scanned from the public repo.
UNGOVERNED 15/100 0/411 none NOT SAFE
real third‑party · AI pair-programming agent.
UNGOVERNED 15/100 0/19 none NOT SAFE
real third‑party · Scanned from the public repo.
UNGOVERNED 15/100 0/62 none NOT SAFE
real third‑party · Scanned from the public repo.
UNGOVERNED 15/100 0/57 none NOT SAFE
real third‑party · Scanned from the public repo.
UNGOVERNED 15/100 0/385 none NOT SAFE
real third‑party · Scanned from the public repo.
UNGOVERNED 15/100 0/2 none NOT SAFE
real third‑party · Scanned from the public repo.
UNGOVERNED 15/100 0/42 none NOT SAFE
real third‑party · Scanned from the public repo.
UNGOVERNED 15/100 0/105 none NOT SAFE
real third‑party · Scanned from the public repo.
UNGOVERNED 15/100 0/21 none NOT SAFE
real third‑party · Scanned from the public repo.
UNGOVERNED 15/100 0/208 none NOT SAFE
real third‑party · Scanned from the public repo.
UNGOVERNED 15/100 0/5 none NOT SAFE
real third‑party · Scanned from the public repo.
UNGOVERNED 15/100 0/17 none NOT SAFE
e2b-dev / e2b @de47dfd
real third‑party · Scanned from the public repo.
UNGOVERNED 15/100 0/77 none NOT SAFE
real third‑party · Scanned from the public repo.
UNGOVERNED 15/100 0/1 none NOT SAFE
real third‑party · Autonomous coding agent.
UNGOVERNED 15/100 0/6 none NOT SAFE
real third‑party · Scanned from the public repo.
UNGOVERNED 15/100 0/42 none NOT SAFE
real third‑party · Scanned from the public repo.
UNGOVERNED 15/100 0/19 none NOT SAFE
real third‑party · Scanned from the public repo.
UNGOVERNED 15/100 0/5 none NOT SAFE
real third‑party · Scanned from the public repo.
UNGOVERNED 15/100 0/28 none NOT SAFE
real third‑party · Scanned from the public repo.
UNGOVERNED 15/100 0/29 none NOT SAFE
real third‑party · Scanned from the public repo.
UNGOVERNED 15/100 0/61 none NOT SAFE
real third‑party · Scanned from the public repo.
UNGOVERNED 15/100 0/42 none NOT SAFE
real third‑party · Scanned from the public repo.
UNGOVERNED 15/100 0/386 none NOT SAFE
real third‑party · Scanned from the public repo.
UNGOVERNED 15/100 0/6 none NOT SAFE
real third‑party · Scanned from the public repo.
UNGOVERNED 15/100 0/288 none NOT SAFE
real third‑party · Scanned from the public repo.
UNGOVERNED 15/100 0/129 none NOT SAFE
simonw / llm @0d593ea
real third‑party · Scanned from the public repo.
UNGOVERNED 15/100 0/5 none NOT SAFE
real third‑party · The official MCP Python SDK + reference servers.
UNGOVERNED 15/100 0/170 none NOT SAFE
mem0ai / mem0 @2c796d1
real third‑party · Scanned from the public repo.
UNGOVERNED 15/100 0/91 none NOT SAFE
real third‑party · Scanned from the public repo.
UNGOVERNED 15/100 0/57 none NOT SAFE
real third‑party · Autonomous coding agent. exec maps to no asserted control.
UNGOVERNED 15/100 0/21 none NOT SAFE
real third‑party · Scanned from the public repo.
UNGOVERNED 15/100 0/89 none NOT SAFE
real third‑party · OpenAI Agents SDK for Python.
UNGOVERNED 15/100 0/235 none NOT SAFE
real third‑party · Scanned from the public repo.
UNGOVERNED 15/100 0/47 none NOT SAFE
real third‑party · Scanned from the public repo.
UNGOVERNED 15/100 0/88 none NOT SAFE
real third‑party · Scanned from the public repo.
UNGOVERNED 15/100 0/175 none NOT SAFE
real third‑party · Scanned from the public repo.
UNGOVERNED 15/100 0/293 none NOT SAFE
real third‑party · Scanned from the public repo.
UNGOVERNED 15/100 0/1 none NOT SAFE
real third‑party · Scanned from the public repo.
UNGOVERNED 15/100 0/44 none NOT SAFE
real third‑party · Scanned from the public repo.
UNGOVERNED 15/100 0/21 none NOT SAFE
real third‑party · Scanned from the public repo.
UNGOVERNED 15/100 0/25 none NOT SAFE
real third‑party · Scanned from the public repo.
UNGOVERNED 15/100 0/44 none NOT SAFE
real third‑party · Scanned from the public repo.
UNGOVERNED 15/100 0/22 none NOT SAFE
real third‑party · Scanned from the public repo.
UNGOVERNED 15/100 0/151 none NOT SAFE
real third‑party · Scanned from the public repo.
UNGOVERNED 6/100 0/0 none NOT SAFE
Methodology: every real-world scan is pinned to the commit shown and reproduces from it (python -m openagentontology <repo> --json). Control mappings are evaluated against a static asserted-control table — they are proposed, not asserted-for-audit; confirm against published control text before relying on them. The CWN reference agents show the governed (SOVEREIGN) end of the scale and are labeled as references, not third-party results.
Same scanner. Opposite verdicts.

A governed agent

SOVEREIGN

The CWN reference agents map nearly every side-effecting action to an asserted NIST 800-53, EU AI Act, and OWASP LLM control. The receipt names the control for each one.

An agent you can install today

UNGOVERNED

exec — arbitrary code execution — maps to no control at all. There is no record of which control answers for it, because there is no control.

Reproduce any row from its pinned commit

The scanner reads source as data (Python via ast, never executed), emits a deterministic typed ontology, scores it, and signs an Ed25519 cert-only receipt over the evidence hash. The same source always yields the same hash. Re-run any real-world row:

git clone https://github.com/OpenInterpreter/open-interpreter && cd open-interpreter
git checkout e00f08e
pip install openagentontology
python -m openagentontology . --json # tier, score, signed receipt

Honest method note: the open-source scanner uses a static, asserted control table plus heuristic verb mapping. The CWN hosted layer (OAO-GMS) additionally grounds each action through a live NIST×MITRE×CVE knowledge graph and mints a triple-signed resolution receipt — shown as the graph link where present. Graph-grounded mappings are GRAPH_INFERRED, never auto-asserted.

Scan your own agent →