Credo AI
The deepest regulation-to-control translation in the category, and the sharpest thinking about where agent governance actually belongs. But the product that acts on that thinking, Agent Governor, is a research preview on one harness with no production SLA, and the open-source assessment framework Credo AI built its early reputation on has been archived as unmaintained.
PRICING
| Platform (modular) | Quote only | land with AI Registry, add Risk Intelligence, then Runtime Governance; priced on number of AI use cases; observed $30,000-$150,000+/yr |
| Advisory Services | Quote only, separate engagement | forward-deployed AI governance experts, maturity assessments, workflow configuration |
| Agent Governor | No charge, design partners only | research preview, Claude Code only, no production SLA, admission by application |
No free tier and no published price. Two independent reviews put the floor at $30,000 to $45,000 per year, which rules out most companies under 1,000 employees. The platform is sold as SaaS only; no self-hosted or air-gapped deployment is documented, which is a hard blocker for defence, central-bank and data-residency-constrained buyers.
checked 2026-08-13 · vendor pricing page
Element scores
Strengths
Credo AI's regulation-to-control translation is the deepest in the category, and that is not a marketing claim: Forrester gave it the highest possible score in twelve criteria including AI Policy Management in the Q3 2025 Wave, and Gartner named it a Visionary in the inaugural Magic Quadrant for AI Governance Platforms in June 2026. Policy Packs turn the EU AI Act, NIST AI RMF and ISO 42001 into specific controls with defined evidence, written by a team that sits in the standards rooms. The Knowledge Graph is the real differentiator underneath, because it means a control set resolves from jurisdiction, sector and data sensitivity automatically rather than being picked off a menu. And the Agent Governor thesis is the sharpest argument anyone in this market has published: a policy that cannot reach the moment an agent acts is a description of intent, not a control, so enforcement belongs in the agent harness where session start, every tool call and session end can be checked. Credo AI shipped that idea into Claude Code with four outcomes, allow, block, escalate and advise, and the escalate and advise cases are what make runtime governance workable instead of something engineers route around.
Honest dings
Three things to price in. First, the flagship is not shipping. Agent Governor is a research preview on a single harness with no production SLA, admission by application, and an enterprise running Claude Code plus Codex plus Cursor plus homegrown agents governs one of four. Codex, Cursor and Copilot are listed as in development. Second, the evaluation story went backwards. credoai_lens, the open-source assessment framework that gave Credo AI its early technical credibility, is archived on GitHub carrying an explicit deprecation warning, and nothing customer-runnable replaced it. The product page lists automated red-teaming, but there is no published eval you can run and no eval discipline disclosed for GAIA's own output. Third, no model is named anywhere. A vendor that asks enterprises to inventory every model they run does not disclose what runs GAIA, and does not let you choose. Add to that SaaS-only deployment with no self-hosted or air-gapped option documented as of July 2026, a $30,000-plus entry price with no self-serve tier, and a Gartner Peer Insights page carrying zero reviews as of 25/11/2025, which for a category-defining vendor is a thin independent evidence base.
Sources (18) — every claim traceable
Every audit lists the research it rests on — transparency and traceability are the product. Tools evolve: each audit is a snapshot of its audit date, and re-audits supersede older versions (kept below for reference).
- credo.ai/product — Official platform page: four modules (AI Registry & Discovery, Risk Intelligence, Compliance & Policy Engine, Runtime Governance), Governance Knowledge Graph, GAIA agent set, Platform & MCP Server governance, dependency graphs, automated red-teaming and drift detection, planned CI/CD and API-gateway enforcement, integration list across AWS/Azure/GCP/Databricks/LangChain/CrewAI/AutoGen/ServiceNow, Forrester 12 perfect scores (accessed 2026-08-13)
- credo.ai/agent-governor — Official product page: research preview status and Beta Service disclaimer, no production SLA, four outcomes (block/allow/escalate/advise), harness lifecycle checkpoints, Claude Code live with Codex, Cursor and Microsoft Copilot listed in development, 'create your own policy' and 'policy audits' marked coming soon, live counters showing 12 deployed policies and 1,300 sessions governed (accessed 2026-08-13)
- credo.ai/blog/announcing-general-availability-of-go… — Official 13/05/2026: general availability of GAIA, Credo AI's governance agent (accessed 2026-08-13)
- credo.ai/ai-agent-registry — Official: agent registry with autonomy classification, third-party model tracking, model and vendor lineage graphs, risk-to-policy mapping, drift alerts; page still invites users to 'join the public preview' (accessed 2026-08-13)
- credo.ai/customers — Official customer page: Mastercard generative-AI governance case study, Booz Allen federal partnership, Chevron, Madrigal Pharmaceuticals, AdeptID EU AI Act compliance, Ruffalo Noel Levitz, IBM and Microsoft partner quotes. No customer count published anywhere on the site (accessed 2026-08-13)
- docs.sdk.credo.ai — Official SDK documentation: Python (sync and async) and TypeScript clients, resources limited to use cases, models, vendors and their relationships plus system health; Pydantic type safety, cursor-based pagination (accessed 2026-08-13)
- github.com/credo-ai/credoai_lens — Official repository, status ARCHIVED, README carries 'DEPRECATION WARNING: This project is no longer maintained'. 50 stars, Apache 2.0, created 10/12/2021. This was the customer-runnable assessment framework (accessed 2026-08-13)
- github.com/credo-ai/credoai-plugins — Official public Claude Code plugin marketplace: eight aigov skills (onboarding, intake, plan, plan-viz, evidence, audit, audit-viz, share); aigov-plan and aigov-audit require the Governance Intelligence Pro MCP, access obtained by emailing engineering@credo.ai (accessed 2026-08-13)
- credo.ai/recognition/gartner-magic-quadrant-ai-gove… — Official: named a Visionary in the inaugural Gartner Magic Quadrant for AI Governance Platforms; company's own framing of governance platforms versus AI security platforms as separate buyer and owner (accessed 2026-08-13)
- credo.ai/blog/the-hidden-risk-layer-in-agentic-ai-a… — Official 26/05/2026: Credo AI security analysis of MCP as a risk layer, background to MCP-server governance in the registry (accessed 2026-08-13)
- gov.uk/ai-assurance-techniques/credo-ai-responsible… — Independent UK government assurance-techniques entry, 19/09/2023: platform assesses fairness, performance, transparency, security and privacy; Policy Packs as modular technical/process/documentation requirements; audit log of all governance actions per use case; standardised transparency artefacts including model cards and impact assessments (accessed 2026-08-13)
- getaigovernance.net/blog/credo-ai-agent-governor — Independent analysis 14/07/2026: three policy postures (permissive, balanced, strict), per-decision structured record content, worked example under balanced posture, and the coverage criticism that an enterprise running four harnesses governs one. Cites Credo AI's own survey of 371 senior leaders finding 60% run AI across multiple departments while only 4% govern it at scale (accessed 2026-08-13)
- kosmoy.com/resources/blog/credo-ai-alternatives — Independent comparison (competitor-authored, treat directionally), published 06/07/2026 and verified 15/07/2026: no gateway, no in-line guardrails and no agent containment outside the preview; SaaS-only with no self-hosted or air-gapped deployment documented; Agent Registry in public preview since September 2025; Forrester highest scores in AI Policy Management and AI Regulatory Compliance Audit (accessed 2026-08-13)
- co-aims.com/blog/credo-ai-review-2026-compliance-of… — Independent review (competitor-authored, treat directionally), 01/02/2026: custom enterprise pricing $30,000-$150,000+/yr, first-year total $40,000-$200,000+, and the argument that Credo AI governs the ML development lifecycle rather than automating state-law regulatory compliance (accessed 2026-08-13)
- xyzeo.com/product/credo-ai — Independent review 11/02/2026: entry around $45,000/yr on AWS Marketplace with 12/24/36-month contracts priced on number of AI use cases, no free tier, enterprise-only, rated 82/100 (accessed 2026-08-13)
- gartner.com/reviews/product/credo-ai-governance-pla… — Gartner Peer Insights product page, updated 25/11/2025: company type private, Palo Alto HQ, 51-200 employees, and zero customer reviews published (accessed 2026-08-13)
- cbinsights.com/company/credo-ai — Independent company record: $39.3M total raised, latest round Series A-II, founded 2020, Palo Alto; investors include AI Fund, Decibel Partners, Sands Capital, FPV Ventures, Mozilla Ventures and Booz Allen Ventures (accessed 2026-08-13)
- workos.com/blog/credo-ai-vs-workos-agentic-security — Independent comparison (competitor-authored, treat directionally), 11/11/2025: Fortune 500 customers named as Microsoft, Amazon, Mastercard, Booz Allen and Databricks; the distinction that Credo AI documents what agents do rather than supplying the auth infrastructure that determines what they can do (accessed 2026-08-13)