AI Ethics Assessor

What this assessment covers

Agents plan and act through tools, so governing them is different from governing a model that only answers questions. The assessment checks six control domains and compares your maturity with a target that rises with the autonomy and reach of your agents.

Accountability, inventory and risk context
Do you know which agents exist, who owns them and how much risk each carries?
Identity, access and least privilege
Does each agent have its own identity, only the permissions its task needs, and protected credentials?
Tools, data and supply chain
Are the tools, connectors and data an agent touches vetted, and is it defended against prompt injection?
Human control and autonomy boundaries
Which actions need approval, can you stop an agent, and is human oversight effective in practice?
Observability, detection and response
Can you reconstruct what an agent did, spot unsafe behaviour and respond to an agent incident?
Assurance, guardrails and adaptation
Are guardrails enforced consistently, are agents tested adversarially, and do controls improve over time?

Frequently asked questions

What is agentic AI governance?

The accountability, security, oversight and monitoring controls that let an organisation use AI agents without losing control of what they do. Agents can change systems, spend money and contact people, so the controls need to scale with how much freedom the agent has.

Is my data stored or sent anywhere?

No. Scoring runs in your browser. The shareable results link keeps your answers after the # symbol in the address, which browsers never send to a website.

Does this assess EU AI Act compliance?

No. It measures governance and security maturity for agents. Each domain notes the EU AI Act articles it supports, but whether an agent falls under a high-risk obligation depends on its use case and your role. See our EU AI Act timeline for the dates.