RSA Conference 2026 Edition

AI Governance Leaderboard

We scanned 21 of the most popular AI agent frameworks, ML libraries, and AI SDKs. Here is how they score on structural governance.

21
Repos Scanned
53/100
Average Score
2
EU AI Act Ready
3
Below Grade C
#Repository Category Score Grade EU AI ActScan
1vllm-project/vllmML Libraries78/100BOn trackScan
2BerriAI/litellmLocal AI / Inference72/100BOn trackScan
3Significant-Gravitas/AutoGPTAI Agent Frameworks68/100BGaps identifiedScan
4fastapi/fastapiWeb Frameworks62/100BGaps identifiedScan
5langchain-ai/langchainAI Agent Frameworks61/100BGaps identifiedScan
6pydantic/pydanticWeb Frameworks59/100CGaps identifiedScan
7run-llama/llama_indexAI SDKs58/100CGaps identifiedScan
8geekan/MetaGPTAI Agent Frameworks57/100CGaps identifiedScan
9stanfordnlp/dspyAI SDKs56/100CGaps identifiedScan
10anthropics/anthropic-sdk-pythonAI SDKs55/100CGaps identifiedScan
11scikit-learn/scikit-learnML Libraries54/100CGaps identifiedScan
12huggingface/transformersML Libraries54/100CGaps identifiedScan
13django/djangoWeb Frameworks54/100CGaps identifiedScan
14openai/openai-pythonAI SDKs53/100CGaps identifiedScan
15mudler/LocalAILocal AI / Inference52/100CGaps identifiedScan
16crewAIInc/crewAIAI Agent Frameworks50/100CGaps identifiedScan
17All-Hands-AI/OpenHandsAI Agent Frameworks50/100CGaps identifiedScan
18TransformerOptimus/SuperAGIAI Agent Frameworks41/100CGaps identifiedScan
19ollama/ollamaLocal AI / Inference36/100DNot readyScan
20microsoft/autogenAI Agent Frameworks30/100DNot readyScan
21yoheinakajima/babyagiAI Agent Frameworks17/100FNot readyScan

Last scanned: March 16, 2026. Scores are point-in-time snapshots.

Methodology

All scans were run on March 16, 2026 using the Walseth AI Governance Scanner. Scores are point-in-time snapshots of the default branch.

The scanner analyzes 6 dimensions (100 points total): Enforcement (30), CI/CD (15), Security (20), Testing (10), Governance (15), and Hygiene (10). It checks for structural governance signals -- prevent-by-construction patterns like hooks, tests, and templates -- in the file tree via the GitHub API.

Grades: A (80+), B (60-79), C (40-59), D (20-39), F (below 20). EU AI Act readiness: On track (70+), Gaps identified (40-69), Not ready (below 40).

Enterprise Vendor Landscape

Beyond open-source frameworks, enterprise vendors are building AI agent governance platforms. These are not scored by our repo scanner (they are closed-source enterprise products) but are relevant to the governance landscape.

VendorFocus AreaGovernance LayerStatusCompare
Okta for AI AgentsIdentity & Access ManagementIdentity (who agents are, what they access)GA April 2026Compare
ZenityAI Security PostureDetection (runtime monitoring)GACompare
StraikerAI App SecurityDetection (runtime guardrails)GACompare
WitnessAIAI DLP & VisibilityDetection (runtime DLP)GACompare
Walseth AIStructural EnforcementBehavioral (what agents do, how they comply)GATry Free

Vendor information sourced from public announcements and company websites as of March 2026. Enterprise vendors are not scored by the governance scanner as they are closed-source platforms.

How does your repo score?

Run the same scanner used for this leaderboard on any public GitHub repository. Free, instant, no signup required.

Read the full analysis: AI Governance Leaderboard: We Scanned 21 Top Repos Before RSA 2026