Colorado AI Act in · EU AI Act (High-Risk) in · ISO 42001 + NIST AI RMF + Agentic AI — unified in one toolkit

Free AI governance tools

Browser-based governance checks for shadow AI, MCP servers, OpenClaw agents, agentic AI deployments, and regulatory readiness. Every tool runs in your browser. No login. No data collection. No answers leave your device.

18 tools · All free · All browser-only
Browser-only processing No data stored or transmitted No login required

AI Governance & Compliance (2 tools)

AI Governance Readiness Assessment

50-question self-assessment scoring AI governance maturity across 12 control domains. Covers ISO 42001, NIST AI RMF, and Colorado AI Act. Generates on-page RAG dashboard with per-domain scores.

⏲ ~15 min☑ 50 questions
Start assessment →

Consequential AI Trigger Check

Quick triage for consequential AI use cases. Checks human review, appeal readiness, disclosure practices, data sensitivity, and likely Colorado AI Act relevance.

⏲ ~4 min☑ Scored
Start check →
👁

Shadow AI & Visibility (2 tools)

Shadow AI Exposure Check

Diagnose unmanaged AI tool usage, weak policy coverage, confidential data exposure, ownership gaps, and visibility blind spots across the enterprise.

⏲ ~4 min☑ 9 questions
Start check →

Shadow MCP Exposure Check

Identify unmanaged MCP servers, registry gaps, local or containerized deployments, weak auth patterns, poor logging, and offboarding blind spots.

⏲ ~4 min☑ Scored
Start check →
🔒

MCP Security Governance (2 tools)

MCP Server Approval Gate

Structured approval decision for MCP server onboarding. Reviews maintainer trust, authorization model, tool scope, data boundary, logging, credential handling, and production readiness.

⏲ ~4 min☑ 12 questions
Start gate →

MCP Credential & Scope Governance Check

Evaluate credential issuance, scope control, secret storage, rotation discipline, revocation readiness, and ownership accountability for MCP connections.

⏲ ~4 min☑ Scored
Start check →
🤖

OpenClaw Agent Governance (4 tools)

OpenClaw Security Readiness Assessment

Comprehensive security posture check for OpenClaw deployments. Scores deployment exposure, identity hygiene, skill and MCP governance, logging, kill-switch readiness, and oversight.

⏲ ~5 min☑ Scored
Start assessment →

OpenClaw Shadow Deployment Governance Check

Score policy stance, shadow discovery, inventory completeness, credential exposure, sandbox availability, logging, containment readiness, and executive visibility.

⏲ ~5 min☑ Scored
Start check →

OpenClaw Skill Approval Gate

Structured approval decision for OpenClaw skill installations. Reviews provenance, sandbox testing, permission scope, rollback path, logging, and production fit.

⏲ ~4 min☑ Scored
Start gate →

OpenClaw Incident Containment Readiness Check

Evaluate disable path, credential revocation, isolation capability, evidence preservation, forensics, rollback, escalation, and board reporting readiness.

⏲ ~5 min☑ Scored
Start check →

Agentic AI Security (3 tools)

Agentic AI Deployment Gate

Score human override controls, tool access boundaries, logging depth, kill switch availability, delegation patterns, and production readiness for AI agent deployments.

⏲ ~5 min☑ Scored
Start gate →

Kill Switch & Rogue Agent Readiness Check

Review shutdown controls, credential revocation capability, network isolation, evidence retention, escalation procedures, and board-ready containment reporting.

⏲ ~5 min☑ Scored
Start check →

AI Agent Identity & OAuth Grant Exposure Check

Review shadow agent visibility, OAuth grant ownership, scope control, revocation readiness, and attribution discipline for AI agent identity patterns.

⏲ ~4 min☑ Scored
Start check →
🛡

AI Security & Risk (5 tools)

Prompt Injection & Excessive Agency Governance Check

Review autonomy boundaries, tool permission controls, approval workflows, kill switch readiness, logging depth, and high-impact oversight for prompt injection and excessive agency risk.

⏲ ~5 min☑ Scored
Start check →

RAG / Vector Trust & Data Disclosure Check

Assess source trust, retrieval access controls, data leakage exposure, takedown readiness, traceability, and disclosure risk in RAG and vector database pipelines.

⏲ ~5 min☑ Scored
Start check →

AI Supply Chain / AIBOM Readiness Check

Review AI inventory completeness, provenance tracking, vendor diligence, update control, traceability, and AI bill of materials readiness across the supply chain.

⏲ ~5 min☑ Scored
Start check →

AI Red Teaming & Vendor Evaluation Gate

Assess red teaming scenario design, scope coverage, test environment maturity, vendor evaluation discipline, remediation tracking, and deployment pressure governance.

⏲ ~5 min☑ Scored
Start check →

AI Vendor Pre-Screen Lite

Quick vendor risk triage across transparency, subprocessor disclosure, data retention, security evidence, incident commitments, sensitive data exposure, and lock-in risk.

⏲ ~4 min☑ 7 questions
Start screen →

Tools show the gaps. The toolkit closes them.

These free tools diagnose governance exposure across individual risk areas. The AI Controls Toolkit (ACT) provides the unified cross-framework implementation system that turns those findings into documented compliance.

Start Free Assessment Compare Toolkit Tiers