CG-AG Open Standard · Discover. Govern. Explain. Audit. Comply.

The Operating System
for AI Agent Governance

Discover every AI agent in your codebase. Classify it against the EU AI Act. Govern it with an open standard. Prove it to your board — in minutes.

"The future problem is not creating AI agents. The future problem is governing thousands of them."

Scan Now →

GitHub, GitLab, Bitbucket, Azure DevOps, Gitea, Forgejo

12
CG-AG Controls
13
Regulations mapped
16+
AI frameworks detected
6
Source control providers
7
Lifecycle states

How it works

Five steps. One platform. Every agent governed.

🔗
01
Connect
GitHub, GitLab, Azure DevOps, Bitbucket — or any Git host
🔍
02
Discover
16+ AI frameworks, MCP configs, .claude/, CI/CD, IaC AI resources
03
Classify
AI Act risk class, DORA exposure, 13 regulations, CG-AG score per agent
🛡
04
Govern
Lifecycle (7 states), approval workflows, human oversight gates, ledger immutável
📄
05
Prove
Board Report PDF, Talk to Governance, audit trail, certification (Bronze→Platinum)
Open Standard · CC BY 4.0

CG-AG Framework
The OWASP for AI Agents

12 controls. Every AI agent in production should satisfy all of them. Mapped to EU AI Act article by article, DORA, ISO/IEC 42001, NIST AI RMF, ISO 27001.

Free to use, implement, and reference. Built to become the industry baseline for AI agent governance — like CIS Benchmarks for cloud, but for agents.

EU AI ActDORAISO/IEC 42001NIST AI RMFISO 27001LGPDGDPR
View Spec (JSON)Get the Markdown →
📋CG-AG-001
Agent Inventory
Every agent formally registered before operating
👤CG-AG-002
Agent Owner
Accountable human owner assigned to every agent
🧠CG-AG-003
Model Registration
Model name, provider, and version documented
🔧CG-AG-004
Tool Authorisation
Tools and resources explicitly authorised
💬CG-AG-005
Prompt Governance
Prompts registered, versioned, injection-assessed
🔌CG-AG-006
MCP Server Governance
MCP connections registered, classified, reviewed
👁CG-AG-007
Human Oversight
Oversight level calibrated to risk (L1–L4)
📖CG-AG-008
Audit Trail
Activities in immutable ledger — provable
🔒CG-AG-009
Data Governance
PII / PHI / financial data review completed
CG-AG-010
Risk Classification
Operational + AI Act risk class assigned
🕸CG-AG-011
Agent-to-Agent
A2A edges registered in the governance graph
🤖CG-AG-012
Autonomous Governance
Elevated oversight + fallback for autonomous agents

Everything you need to govern AI agents

Six pillars. One platform. No compromises.

🔭
Scanner
Discovery Intelligence Engine
Scans code, configs, IaC. Detects 16+ frameworks, MCP servers, .claude/, Cursor agents, Bedrock, Azure OpenAI. Every agent found becomes a governance record.
🕸
Graph
GraphOS
Knowledge graph of your entire AI ecosystem. Agents, models, tools, risks, data flows, regulations — all connected. 10 executive lenses (CEO, CISO, DPO…).
💬
NL Interface
Talk to Governance
Ask "Which agents process personal data?" and get a cited, evidence-backed answer in EN/PT/ES. 12 deterministic intents — no LLM hallucination, fully auditable.
📋
Inventory
Agent Inventory
7-state lifecycle (pending → registered → approved → active → suspended → under_review → decommissioned). Banking-grade 4-eyes approval, immutable ledger, PATCH transitions enforced by state machine.
📄
Reports
Board Ready Reports
AI Act readiness, DORA compliance, Risk & Governance — auto-generated PDF. Certification levels Bronze/Silver/Gold/Platinum. Real evidence, every finding traced to a control.
🔔
Automation
Continuous Governance
GitHub webhook → auto-rescan on push. Daily cron across all repos. Shadow agent detection (diff between scans). No more stale inventories.

Connect any source

Where AI agents are created, CodeGuard governs them.

GitHubGitLabAzure DevOpsBitbucketGitea / ForgejoGitHub ActionsGitLab CIAzure PipelinesJenkinsArgoCDClaude CodeCursorLangGraphCrewAIOpenAI Agents SDKAutoGenDifyMCP Serversn8n AIAWS BedrockAzure OpenAIVertex AIEntra IDOktaKeycloakConfluenceSharePointNotion+ 100 more →

The governance gap
is already here

78%of enterprises deploying AI agents have no formal inventory
€35Mmax fine under EU AI Act for non-compliant high-risk AI systems
4%of global turnover under GDPR — now extended to AI systems
2026EU AI Act Art. 6-15 full enforcement begins — you need to be ready now
NOW
is the window to set the standard

Every company building with AI is creating agents today. In 3 years, enterprises will have hundreds or thousands of them. The ones that govern them proactively will be compliant, auditable, and trusted.

CodeGuard gives you the OS to govern that future — and the open framework that becomes the market standard.

Start governing
your agents today

Paste a repo URL. Get a full governance report in minutes.
AI Act readiness. CG-AG score. Board-ready PDF.

Scan Your Repo →Read the CG-AG Spec

Open standard · Free to use · Built for AI Act compliance

"The future problem is not creating AI agents.

The future problem is governing thousands of them."

— CodeGuard AI Governance OS