Conduct AI
Open-source governance platform enforcing compliance policies on AI coding agents with full audit trails.
🔗 Visit Conduct AIDescription
As more teams let AI coding assistants like Claude, Cursor, or Copilot actually make changes to code and systems, a new question comes up fast: who's making sure those AI agents don't do something risky, and how do you prove it to an auditor? Conduct AI is a governance layer that sits between your AI agents and the actions they take, enforcing rules before anything happens.
Conduct AI is an open-source AI agent governance platform combining a policy engine, an LLM proxy router, and an audit interface. It ships with over 20 pre-built compliance packs, including OWASP, SOC 2, HIPAA, PCI DSS, and the EU AI Act, and 22 automation playbooks, records every decision in a hash-chained SHA-256 audit trail for regulatory verification, and can run in a 14-day read-only discovery mode before enforcing anything. Deployable via Docker Compose self-hosted or as a managed SaaS, under Apache 2.0.
💬 Our review
The short version: Conduct AI is aimed squarely at companies that want to let AI agents work autonomously but need a paper trail and guardrails for compliance, and it's free and open source if you self-host.
It competes loosely with Guardrails AI and NVIDIA's NeMo Guardrails, both of which focus more narrowly on validating LLM outputs, and with LiteLLM Proxy, which routes and logs LLM calls but doesn't ship compliance packs or a policy engine out of the box. Conduct AI's edge is bundling governance, audit trails, and ready-made compliance frameworks together, which matters a lot once regulated industries like healthcare and finance start actually shipping AI-agent-driven workflows. Being open source removes the cost barrier to trying it, though realistically this is infrastructure for teams past the experimenting-with-AI-agents stage and into needing to answer to a compliance officer — smaller teams may find it more than they need right now.
💰 Pricing
📊 Global score
🤖 AI-enriched data
Autohébergé gratuit (Apache 2.0) ; option SaaS managée également disponible
Pros
Plus de 20 packs de conformité prêts à l'emploi (SOC 2, HIPAA, PCI DSS, EU AI Act)
Piste d'audit chaînée par hash pour preuve réglementaire
Mode découverte de 14 jours en lecture seule avant application
Fonctionne avec Claude, Cursor, Copilot et autres agents basés sur SDK
Open source, autohébergeable
Cons
Pensé pour les grandes équipes/secteurs réglementés — surdimensionné pour un développeur solo
Projet jeune (23 stars), encore en maturation
Nécessite un investissement pour bien configurer les politiques
