AI Dispatch
agent · ai agents frameworks

Agent Zero

Agent Zero is a self-hosted, open-source agentic framework. Its own homepage bills it as an "Open Source Agentic Framework" and as "Autonomous agentic AI that runs on its own computer, uses and creates tools, learns, self-corrects, and executes transparent workflows." The vendor states it runs sandboxed in Docker and connects to the user's local terminal, project files and browser through the A0 CLI, and that it is installed through a guided desktop flow using the Agent Zero Launcher. It is model-agnostic: the page invites users to "Connect any AI provider" and states it exposes zero secrets in doing so. Release notes on the capture checked record project-scoped profiles and tool policies in v2.9, and durable subordinate agent lifecycles plus a built-in ACP bridge in v2.10; MCP-powered data pipelines drawing on web and Salesforce sources are also described, and penetration testing is named as a use case. A pull-quote carried on the vendor's homepage, attributed to Alan Majer of The Linux Foundation, calls it "a highly autonomous agent" - that is a third-party characterisation the vendor has chosen to display, not AI Dispatch's assessment and not the vendor's own claim. Nothing on the pages checked publishes a compliance certification, any insurance, indemnity or liability position, any audit-trail or tamper-evident logging claim, or any outcome-linked payment term. Those four dimensions score 0 on the trust-gap rubric as published absences, not as gaps in our research.

Reviewed12 or more fields evidenced, and scored by a human against the published rubric

19 fields evidenced · 36 with no public information. Every value below links to the document it came from and the date we checked it.

6 of those are quoted but not yet interpreted: we hold the source sentence and the date we read it, but nobody has written the answer to the question yet. Those rows show the quote and say so rather than repeating it back as an answer. Why these exist

1 of those is flagged for review: our own check found language in the cited source that may address the field. An editor has not adjudicated it yet.

2 of the evidenced values quote wording our own later capture of the same page no longer contains. Marked below, awaiting an editor.

Runtime governance
1/3

Are scope, spend, and authority enforced while the agent runs?

The 2026-09-02 capture of the vendor homepage records, in release notes, that v2.9 "introduces the Agent Editor, project-scoped profiles and tool policies". A scoping mechanism is therefore claimed to exist by the vendor, which is more than nothing, but the page describes no scope, spend or authority limit enforced at run time, names no enforcement point, and publishes no policy schema. Scored 1, not 0, solely on that changelog line; the earlier v1 rationale here predated this capture and referred to a permission_scopes field that rested on a different span.

Judged Aug 11, 2026; evidence newer. We have since re-read Runtime governance and Permission scopes, most recently on Sep 2, 2026. No one has re-scored this dimension against them — the score above stands, but it is older than the evidence below it. How current a score is

How this gap gets closed →
Audit trail
0/3

Is there a tamper-evident record of what it actually did?

No public evidence found. The 2026-09-02 capture markets "transparent workflows" and lists "Time Travel retention" among v2.9 changes, but neither describes a customer-reviewable record, log retention policy or tamper-evidence; a state-rollback feature is not an audit trail. Absence is the finding.

How this gap gets closed →
Compliance
0/3

Are compliance obligations attached per engagement?

No public evidence found. The page checked publishes no certification, framework mapping, auditor or report date.

How this gap gets closed →
Outcome settlement
0/3

Does payment depend on a verified result?

No public evidence found. No pricing or payment terms of any kind appear on the page checked; the three pricing fields previously filed here rested on the site banner "Open Source Agentic Framework" and were rejected in this audit.

How this gap gets closed →
Insurance & indemnity
0/3

Can the deployment be insured, and is the customer indemnified?

No public evidence found. No cover, carrier, limit or customer indemnity is published on the page checked.

How this gap gets closed →

Assurance

Insurance available
no public information
agent-zero.ai · checked Aug 8, 2026 · source did not state this
Insurance carriers
no public information
agent-zero.ai · checked Aug 8, 2026 · source did not state this
Coverage limits
no public information
agent-zero.ai · checked Aug 8, 2026 · source did not state this
Indemnification
no public information
agent-zero.ai · checked Aug 8, 2026 · source did not state this
Liability cap
no public information
agent-zero.ai · checked Aug 8, 2026 · source did not state this
Audit trail
no public information
agent-zero.ai · checked Aug 8, 2026 · source did not state this
Tamper-evident log
no public information
agent-zero.ai · checked Aug 8, 2026 · source did not state this
Explainability
Described as executing "transparent workflows"
Autonomous agentic AI that runs on its own computer, uses and creates tools, learns, self-corrects, and executes transparent workflows.
agent-zero.ai · checked Sep 2, 2026
Runtime governance
Project-scoped profiles and tool policies, introduced in v2.9
v2.9 introduces the Agent Editor, project-scoped profiles and tool policies, safer profile lifecycles, Time Travel retention, built-in plugin upgrades, and important security and reliability fixes.

Not in our latest capture. This quote was on the page when we filed it. We captured the same page again on Sep 10, 2026 and it was not there. The value above has not been re-checked by an editor yet. How we re-check citations

agent-zero.ai · checked Sep 2, 2026
Permission scopes
Project-scoped profiles and tool policies (v2.9)
v2.9 introduces the Agent Editor, project-scoped profiles and tool policies, safer profile lifecycles, Time Travel retention, built-in plugin upgrades, and important security and reliability fixes.

Not in our latest capture. This quote was on the page when we filed it. We captured the same page again on Sep 10, 2026 and it was not there. The value above has not been re-checked by an editor yet. How we re-check citations

agent-zero.ai · checked Sep 2, 2026
Compliance certifications
no public information
agent-zero.ai · checked Aug 8, 2026 · source did not state this
Regulatory alignment
no public information
agent-zero.ai · checked Aug 8, 2026 · source did not state this
Outcome-based pricing
no public information
agent-zero.ai · checked Aug 8, 2026 · source did not state this
Settlement mechanism
no public information
agent-zero.ai · checked Aug 8, 2026 · source did not state this
Dispute process
no public information
agent-zero.ai · checked Aug 8, 2026 · source did not state this
SLA terms
no public information
agent-zero.ai · checked Aug 8, 2026 · source did not state this
Evaluation coverage
no public information
agent-zero.ai · checked Aug 8, 2026 · source did not state this

Agency

Autonomy level
Described as "a highly autonomous agent" in a pull-quote attributed to Alan Majer of The Linux Foundation, carried on the vendor's own homepage; not the vendor's own characterisation
Agent Zero represents a highly autonomous agent, one that can operate across different centralized and decentralized systems and applications.
agent-zero.ai · checked Aug 8, 2026
Human oversight
no public information
agent-zero.ai · checked Aug 8, 2026 · source did not state this
Goal complexity
Open-ended: learns, self-corrects, and executes transparent workflows autonomously
Autonomous agentic AI that runs on its own computer, uses and creates tools, learns, self-corrects, and executes transparent workflows.
agent-zero.ai · checked Sep 2, 2026
Action space
uses and creates tools, learns, self-corrects, and executes transparent workflows.
agent-zero.ai · checked Aug 8, 2026
Operating environment
Runs sandboxed in Docker; connects to the local terminal, project files, and browser via the A0 CLI Connector
Keep Agent Zero sandboxed in Docker, then connect it to your local terminal, project files, and browser through A0 CLI.
agent-zero.ai · checked Sep 2, 2026
Initiative
Autonomous agentic AI that runs on its own computer, uses and creates tools, learns, self-corrects, and executes transparent workflows.
agent-zero.ai · checked Aug 8, 2026

Safety

Safety evaluations
no public information
agent-zero.ai · checked Aug 8, 2026 · source did not state this
Red teaming
no public information

Flagged for review — the source below contains language that may address this field. Not yet checked by an editor. How we check absences

agent-zero.ai · checked Aug 8, 2026
Safety policy
no public information
agent-zero.ai · checked Aug 8, 2026 · source did not state this
Usage restrictions
no public information
agent-zero.ai · checked Aug 8, 2026 · source did not state this
Model or system card
no public information
agent-zero.ai · checked Aug 8, 2026 · source did not state this
Incident reporting
no public information
agent-zero.ai · checked Aug 8, 2026 · source did not state this
Third-party evaluations
no public information
agent-zero.ai · checked Aug 8, 2026 · source did not state this
Data handling
States it exposes zero secrets when connecting to AI providers
Connect any AI provider. Expose zero secrets.
agent-zero.ai · checked Sep 2, 2026

Practicality

Pricing model
no public information
agent-zero.ai · checked Aug 8, 2026 · source did not state this
Price point
no public information
agent-zero.ai · checked Aug 8, 2026 · source did not state this
Availability
Installed through a guided desktop flow using the Agent Zero Launcher, which also keeps it updated and manages local or remote instances
Start with Agent Zero Launcher Install Agent Zero through a guided desktop flow, then keep it updated, back up /a0/usr , and manage local or remote Instances from one app.
agent-zero.ai · checked Sep 2, 2026
Deployment options
Self-hosted: runs sandboxed in Docker, connected to the local terminal, project files and browser through A0 CLI
Keep Agent Zero sandboxed in Docker, then connect it to your local terminal, project files, and browser through A0 CLI.
agent-zero.ai · checked Sep 2, 2026
Integrations
MCP-powered data pipelines that extract from web and Salesforce sources
Build MCP-powered data pipelines that seamlessly extract from web and Salesforce sources.
agent-zero.ai · checked Sep 2, 2026
Supported regions
no public information
agent-zero.ai · checked Aug 8, 2026 · source did not state this
Support model
no public information
agent-zero.ai · checked Aug 8, 2026 · source did not state this

Foundation models

Base models
no public information
agent-zero.ai · checked Aug 8, 2026 · source did not state this
Model provider
Bring-your-own model: connects to any AI provider
Connect any AI provider. Expose zero secrets.
agent-zero.ai · checked Sep 2, 2026
Model swappable
Connect any AI provider. Expose zero secrets.
agent-zero.ai · checked Aug 8, 2026
Open weights
no public information
agent-zero.ai · checked Aug 8, 2026 · source did not state this
Fine-tuning
no public information
agent-zero.ai · checked Aug 8, 2026 · source did not state this
Context window
no public information
agent-zero.ai · checked Aug 8, 2026 · source did not state this

Ecosystem

Protocols supported
MCP-powered data pipelines
agent-zero.ai · checked Aug 8, 2026
Tool use
uses and creates tools
agent-zero.ai · checked Aug 8, 2026
Multi-agent
Durable subordinate agent lifecycles and a built-in ACP bridge, introduced in v2.10
v2.10 introduces an interactive shared Browser runtime, durable subordinate lifecycles, scoped composer context and drafts, Responses streaming fixes, and a built-in ACP bridge.
agent-zero.ai · checked Sep 2, 2026
API access
no public information
agent-zero.ai · checked Aug 8, 2026 · source did not state this
Open source
Open Source Agentic Framework
agent-zero.ai · checked Aug 8, 2026
Marketplace presence
no public information
agent-zero.ai · checked Aug 8, 2026 · source did not state this

Impact

User base
no public information
agent-zero.ai · checked Aug 8, 2026 · source did not state this
Deployment scale
no public information
agent-zero.ai · checked Aug 8, 2026 · source did not state this
Target sectors
no public information
agent-zero.ai · checked Aug 8, 2026 · source did not state this
High-risk domains
Offered for penetration-testing use cases: automated security sweeps, vulnerability analysis and remediation guidance.
Penetration Testing Deploy automated security sweeps, vulnerability analysis, and remediation guidance.
agent-zero.ai · checked Aug 8, 2026
Documented incidents
no public information
agent-zero.ai · checked Aug 8, 2026 · source did not state this