Autonomous agents AI tools

Tools that act on their own: they open files, browse the web, call APIs. The risk is not what the person types, it is what the agent does unsupervised — a central category in both the EU AI Act and ISO 42001.

37 critical308 high112 moderate13 low
Critical:
Direct harm is possible: identity fraud, biometric data, or autonomous action without oversight.
High:
Naturally receives sensitive corporate data — source code, contracts, customer records.
Moderate:
Risk depends on what goes in. Requires an explicit classification in your policy.
Low:
Narrow scope and clear vendor governance. A candidate for the allowed list.
How we classify risk →

470 tools

How many of these are running in your company?

A list of risky tools only becomes governance when you cross it with what is actually in use. The free assessment returns your maturity level per dimension in 5 minutes, with no signup.

Take the free assessment