Agent Zero
Agent Zero is a self-hosted, open-source agentic framework. Its own homepage bills it as an "Open Source Agentic Framework" and as "Autonomous agentic AI that runs on its own computer, uses and creates tools, learns, self-corrects, and executes transparent workflows." The vendor states it runs sandboxed in Docker and connects to the user's local terminal, project files and browser through the A0 CLI, and that it is installed through a guided desktop flow using the Agent Zero Launcher. It is model-agnostic: the page invites users to "Connect any AI provider" and states it exposes zero secrets in doing so. Release notes on the capture checked record project-scoped profiles and tool policies in v2.9, and durable subordinate agent lifecycles plus a built-in ACP bridge in v2.10; MCP-powered data pipelines drawing on web and Salesforce sources are also described, and penetration testing is named as a use case. A pull-quote carried on the vendor's homepage, attributed to Alan Majer of The Linux Foundation, calls it "a highly autonomous agent" - that is a third-party characterisation the vendor has chosen to display, not AI Dispatch's assessment and not the vendor's own claim. Nothing on the pages checked publishes a compliance certification, any insurance, indemnity or liability position, any audit-trail or tamper-evident logging claim, or any outcome-linked payment term. Those four dimensions score 0 on the trust-gap rubric as published absences, not as gaps in our research.
19 fields evidenced · 36 with no public information. Every value below links to the document it came from and the date we checked it.
6 of those are quoted but not yet interpreted: we hold the source sentence and the date we read it, but nobody has written the answer to the question yet. Those rows show the quote and say so rather than repeating it back as an answer. Why these exist
1 of those is flagged for review: our own check found language in the cited source that may address the field. An editor has not adjudicated it yet.
2 of the evidenced values quote wording our own later capture of the same page no longer contains. Marked below, awaiting an editor.
Also appears in
Trust gap
How this is scoredAre scope, spend, and authority enforced while the agent runs?
The 2026-09-02 capture of the vendor homepage records, in release notes, that v2.9 "introduces the Agent Editor, project-scoped profiles and tool policies". A scoping mechanism is therefore claimed to exist by the vendor, which is more than nothing, but the page describes no scope, spend or authority limit enforced at run time, names no enforcement point, and publishes no policy schema. Scored 1, not 0, solely on that changelog line; the earlier v1 rationale here predated this capture and referred to a permission_scopes field that rested on a different span.
Judged Aug 11, 2026; evidence newer. We have since re-read Runtime governance and Permission scopes, most recently on Sep 2, 2026. No one has re-scored this dimension against them — the score above stands, but it is older than the evidence below it. How current a score is
How this gap gets closed →Is there a tamper-evident record of what it actually did?
No public evidence found. The 2026-09-02 capture markets "transparent workflows" and lists "Time Travel retention" among v2.9 changes, but neither describes a customer-reviewable record, log retention policy or tamper-evidence; a state-rollback feature is not an audit trail. Absence is the finding.
How this gap gets closed →Are compliance obligations attached per engagement?
No public evidence found. The page checked publishes no certification, framework mapping, auditor or report date.
How this gap gets closed →Does payment depend on a verified result?
No public evidence found. No pricing or payment terms of any kind appear on the page checked; the three pricing fields previously filed here rested on the site banner "Open Source Agentic Framework" and were rejected in this audit.
How this gap gets closed →Can the deployment be insured, and is the customer indemnified?
No public evidence found. No cover, carrier, limit or customer indemnity is published on the page checked.
How this gap gets closed →Assurance
- Insurance available
- no public informationagent-zero.ai · checked Aug 8, 2026 · source did not state this
- Insurance carriers
- no public informationagent-zero.ai · checked Aug 8, 2026 · source did not state this
- Coverage limits
- no public informationagent-zero.ai · checked Aug 8, 2026 · source did not state this
- Indemnification
- no public informationagent-zero.ai · checked Aug 8, 2026 · source did not state this
- Liability cap
- no public informationagent-zero.ai · checked Aug 8, 2026 · source did not state this
- Audit trail
- no public informationagent-zero.ai · checked Aug 8, 2026 · source did not state this
- Tamper-evident log
- no public informationagent-zero.ai · checked Aug 8, 2026 · source did not state this
- Explainability
- Described as executing "transparent workflows"
“Autonomous agentic AI that runs on its own computer, uses and creates tools, learns, self-corrects, and executes transparent workflows.”
agent-zero.ai · checked Sep 2, 2026 - Runtime governance
- Project-scoped profiles and tool policies, introduced in v2.9
“v2.9 introduces the Agent Editor, project-scoped profiles and tool policies, safer profile lifecycles, Time Travel retention, built-in plugin upgrades, and important security and reliability fixes.”
Not in our latest capture. This quote was on the page when we filed it. We captured the same page again on Sep 10, 2026 and it was not there. The value above has not been re-checked by an editor yet. How we re-check citations
agent-zero.ai · checked Sep 2, 2026 - Permission scopes
- Project-scoped profiles and tool policies (v2.9)
“v2.9 introduces the Agent Editor, project-scoped profiles and tool policies, safer profile lifecycles, Time Travel retention, built-in plugin upgrades, and important security and reliability fixes.”
Not in our latest capture. This quote was on the page when we filed it. We captured the same page again on Sep 10, 2026 and it was not there. The value above has not been re-checked by an editor yet. How we re-check citations
agent-zero.ai · checked Sep 2, 2026 - Compliance certifications
- no public informationagent-zero.ai · checked Aug 8, 2026 · source did not state this
- Regulatory alignment
- no public informationagent-zero.ai · checked Aug 8, 2026 · source did not state this
- Outcome-based pricing
- no public informationagent-zero.ai · checked Aug 8, 2026 · source did not state this
- Settlement mechanism
- no public informationagent-zero.ai · checked Aug 8, 2026 · source did not state this
- Dispute process
- no public informationagent-zero.ai · checked Aug 8, 2026 · source did not state this
- SLA terms
- no public informationagent-zero.ai · checked Aug 8, 2026 · source did not state this
- Evaluation coverage
- no public informationagent-zero.ai · checked Aug 8, 2026 · source did not state this
Agency
- Autonomy level
- Described as "a highly autonomous agent" in a pull-quote attributed to Alan Majer of The Linux Foundation, carried on the vendor's own homepage; not the vendor's own characterisation
“Agent Zero represents a highly autonomous agent, one that can operate across different centralized and decentralized systems and applications.”
agent-zero.ai · checked Aug 8, 2026 - Human oversight
- no public informationagent-zero.ai · checked Aug 8, 2026 · source did not state this
- Goal complexity
- Open-ended: learns, self-corrects, and executes transparent workflows autonomously
“Autonomous agentic AI that runs on its own computer, uses and creates tools, learns, self-corrects, and executes transparent workflows.”
agent-zero.ai · checked Sep 2, 2026 - Action space
“uses and creates tools, learns, self-corrects, and executes transparent workflows.”
agent-zero.ai · checked Aug 8, 2026- Operating environment
- Runs sandboxed in Docker; connects to the local terminal, project files, and browser via the A0 CLI Connector
“Keep Agent Zero sandboxed in Docker, then connect it to your local terminal, project files, and browser through A0 CLI.”
agent-zero.ai · checked Sep 2, 2026 - Initiative
“Autonomous agentic AI that runs on its own computer, uses and creates tools, learns, self-corrects, and executes transparent workflows.”
agent-zero.ai · checked Aug 8, 2026
Safety
- Safety evaluations
- no public informationagent-zero.ai · checked Aug 8, 2026 · source did not state this
- Red teaming
- no public information
Flagged for review — the source below contains language that may address this field. Not yet checked by an editor. How we check absences
agent-zero.ai · checked Aug 8, 2026 - Safety policy
- no public informationagent-zero.ai · checked Aug 8, 2026 · source did not state this
- Usage restrictions
- no public informationagent-zero.ai · checked Aug 8, 2026 · source did not state this
- Model or system card
- no public informationagent-zero.ai · checked Aug 8, 2026 · source did not state this
- Incident reporting
- no public informationagent-zero.ai · checked Aug 8, 2026 · source did not state this
- Third-party evaluations
- no public informationagent-zero.ai · checked Aug 8, 2026 · source did not state this
- Data handling
- States it exposes zero secrets when connecting to AI providers
“Connect any AI provider. Expose zero secrets.”
agent-zero.ai · checked Sep 2, 2026
Practicality
- Pricing model
- no public informationagent-zero.ai · checked Aug 8, 2026 · source did not state this
- Price point
- no public informationagent-zero.ai · checked Aug 8, 2026 · source did not state this
- Availability
- Installed through a guided desktop flow using the Agent Zero Launcher, which also keeps it updated and manages local or remote instances
“Start with Agent Zero Launcher Install Agent Zero through a guided desktop flow, then keep it updated, back up /a0/usr , and manage local or remote Instances from one app.”
agent-zero.ai · checked Sep 2, 2026 - Deployment options
- Self-hosted: runs sandboxed in Docker, connected to the local terminal, project files and browser through A0 CLI
“Keep Agent Zero sandboxed in Docker, then connect it to your local terminal, project files, and browser through A0 CLI.”
agent-zero.ai · checked Sep 2, 2026 - Integrations
- MCP-powered data pipelines that extract from web and Salesforce sources
“Build MCP-powered data pipelines that seamlessly extract from web and Salesforce sources.”
agent-zero.ai · checked Sep 2, 2026 - Supported regions
- no public informationagent-zero.ai · checked Aug 8, 2026 · source did not state this
- Support model
- no public informationagent-zero.ai · checked Aug 8, 2026 · source did not state this
Foundation models
- Base models
- no public informationagent-zero.ai · checked Aug 8, 2026 · source did not state this
- Model provider
- Bring-your-own model: connects to any AI provider
“Connect any AI provider. Expose zero secrets.”
agent-zero.ai · checked Sep 2, 2026 - Model swappable
“Connect any AI provider. Expose zero secrets.”
agent-zero.ai · checked Aug 8, 2026- Open weights
- no public informationagent-zero.ai · checked Aug 8, 2026 · source did not state this
- Fine-tuning
- no public informationagent-zero.ai · checked Aug 8, 2026 · source did not state this
- Context window
- no public informationagent-zero.ai · checked Aug 8, 2026 · source did not state this
Ecosystem
- Protocols supported
“MCP-powered data pipelines”
agent-zero.ai · checked Aug 8, 2026- Tool use
“uses and creates tools”
agent-zero.ai · checked Aug 8, 2026- Multi-agent
- Durable subordinate agent lifecycles and a built-in ACP bridge, introduced in v2.10
“v2.10 introduces an interactive shared Browser runtime, durable subordinate lifecycles, scoped composer context and drafts, Responses streaming fixes, and a built-in ACP bridge.”
agent-zero.ai · checked Sep 2, 2026 - API access
- no public informationagent-zero.ai · checked Aug 8, 2026 · source did not state this
- Open source
“Open Source Agentic Framework”
agent-zero.ai · checked Aug 8, 2026- Marketplace presence
- no public informationagent-zero.ai · checked Aug 8, 2026 · source did not state this
Impact
- User base
- no public informationagent-zero.ai · checked Aug 8, 2026 · source did not state this
- Deployment scale
- no public informationagent-zero.ai · checked Aug 8, 2026 · source did not state this
- Target sectors
- no public informationagent-zero.ai · checked Aug 8, 2026 · source did not state this
- High-risk domains
- Offered for penetration-testing use cases: automated security sweeps, vulnerability analysis and remediation guidance.
“Penetration Testing Deploy automated security sweeps, vulnerability analysis, and remediation guidance.”
agent-zero.ai · checked Aug 8, 2026 - Documented incidents
- no public informationagent-zero.ai · checked Aug 8, 2026 · source did not state this