Credo AI
Type: company (AI-governance platform pure-play) Sector: AI governance platform software First seen: 2026-07-11 (as entity page; referenced in sources since 2026-06-22) Last updated: 2026-09-08
Updated 2026-09-08 based on S-2026-08-25-credo-eu-omnibus-playbook (daily AI-governance vendor-intelligence scan; vendor playbook landing page fetched in full, dated 25 Aug 2026 — 14 days old at ingestion, inside the 30-day window) — Credo published an ungated EU AI Omnibus playbook asserting the Omnibus entered into force on 27 July 2026, restating the 2 Dec 2027 / 2 Aug 2028 high-risk deadlines and the 2 Aug 2026 transparency/fining start, and claiming “two new prohibitions” from 2 Dec 2026, under the framing that “not a single core obligation changed”. This is the vault’s first vendor artefact mapping the post-Omnibus calendar and Credo’s first regulatory-alignment move since the Agent Governor launch. ⚠️ Vendor-authored, low authority: the 27 July entry-into-force date and the two-prohibitions claim are not on EU AI Act and are unverified — flagged to the regulatory scan, not adopted as fact.
Updated 2026-07-27 based on S-2026-07-14-credo-agent-governor-launch (daily AI-governance vendor-intelligence scan; primary launch blog fetched directly, published 14 Jul 2026) — the open question “what does Agent Governor actually do” is now answered from the vendor record: it is a runtime enforcement product at the agent-harness layer, installing approved governance as versioned governance-as-code on the harness, resolving every agent action (session start, prompt, before/after each tool call, session end) to allow / block / escalate / advise, and writing a structured evidence record per decision (policy version, session initiator, tool + arguments, decision and rationale). Research Preview supports Claude Code only, ships three curated policy postures (permissive/balanced/strict), and targets design partners in “regulated or high-consequence” enterprises; no GA date, customer, or named regulatory-standard mapping. This supersedes the 17 Jul relay’s “capabilities entirely undisclosed” reading — the primary blog (three days earlier) had disclosed them; the earlier Source page reflected its secondary relay, not the vendor record.
Updated 2026-07-23 based on S-2026-07-17-credo-agent-governor-preview (daily AI-governance vendor-intelligence scan) — Credo AI announced (via LinkedIn/newsletter, relayed by TipRanks, 17 Jul 2026) a research preview of an “Agent Governor” tool with a webinar on 30 Jul 2026, plus selection for Microsoft for Startups Pegasus and participation in the DiMe community convened with the FDA (healthcare read-across). This moves Credo from agentic positioning research (1 Jul) to a product-shaped (pre-GA) agentic move — capabilities entirely undisclosed; secondary auto-generated source only ⚠️.
Created 2026-07-11 from S-2026-07-01-credo-agentic-high-risk (daily AI-governance vendor-intelligence scan). Trigger: second source — Credo AI already appeared in S-2026-06-22-gaig-gartner-mq-full-quadrant as a reported MQ Visionary.
Snapshot
Credo AI is a US-headquartered AI-governance platform vendor — one of the “established AI-governance pure-plays” on Paul’s watchlist and, per the (single-source, GAIG-reported ⚠️) full quadrant, one of five Visionaries in the inaugural Gartner Magic Quadrant for AI Governance Platforms [S-2026-06-22-gaig-gartner-mq-full-quadrant]. It matters to the wiki as a dedicated (non-incumbent) governance platform whose positioning research shapes how regulated buyers frame agentic-AI risk classification.
Positions / Claims they advance
- Published “Seven Novel Governance Considerations for Agentic AI” (1 Jul 2026), arguing agents capable of real-world actions should be classified high-risk by default; names prompt injection as a “master key” data-exfiltration vector for over-permissioned agents and introduces “cascade events” (silent error propagation across multi-agent architectures) as a named risk category; recommends aligning agent access with documented security risk appetite and formal agent-to-agent trust mechanisms [S-2026-07-01-credo-agentic-high-risk]. Vendor thought-leadership via secondary analysis; the seven considerations themselves are not enumerated in the captured source.
- Reported (GAIG-only, not vendor-corroborated ⚠️) as the fifth Visionary in the inaugural Gartner MQ for AI Governance Platforms (Leaders IBM, ServiceNow, Truyo) [S-2026-06-22-gaig-gartner-mq-full-quadrant].
- Announced a research preview of “Agent Governor” (launch blog 14 Jul 2026; webinar 30 Jul 2026) — its first product-shaped agentic-governance move; also announced Microsoft for Startups Pegasus selection and participation in the Digital Medicine Society community convened with the FDA (primarily healthcare; read-across — a pure-play courting a sector regulator’s ecosystem) [S-2026-07-17-credo-agent-governor-preview][S-2026-07-14-credo-agent-governor-launch].
- Agent Governor mechanics (per the primary launch blog): governs at the agent harness — “the software that runs the agent” — installing approved governance as versioned, enforceable governance-as-code; at each step of the agent loop the policy resolves the action to one of four outcomes (allow / block / escalate / advise), arguing a plain allow/deny binary “either blocks too much or catches too little”; every decision yields a structured evidence record (active policy version, session initiator, tool called with arguments, decision and why). Research Preview is Claude Code-only with other harnesses “next”; three curated policy postures (permissive/balanced/strict) “grounded in six years of Credo AI’s AI governance intelligence”; Credo says it ran the product internally before release. All capability claims are the vendor’s own for a pre-GA product; no regulatory standard is mapped in the launch post (EU AI Act / SS1/23 / ISO 42001 relevance is the wiki’s inference) and no customer is named [S-2026-07-14-credo-agent-governor-launch].
- Post-Omnibus regulatory calendar (vendor-relayed ⚠️): Omnibus in force 27 Jul 2026; high-risk deadlines 2 Dec 2027 (stand-alone) and 2 Aug 2028 (product-embedded); transparency and model-provider fining from 2 Aug 2026; “two new prohibitions” from 2 Dec 2026; penalties up to €35M/7%. Framed as “the living EU AI Act” — a scheduling change, not a relaxation — supporting Credo’s continuous-governance narrative [S-2026-08-25-credo-eu-omnibus-playbook].
- Positions the launch with adoption-scale framing: a Gartner-attributed projection of >150,000 AI agents per average Fortune 500 company by 2028 (from <15 in 2025), and its own 371-senior-leader survey (60% deploy AI across multiple departments; 4% govern it at scale) — vendor-relayed statistics [S-2026-07-14-credo-agent-governor-launch].
Relationships
- relates-to → AI Governance Platforms — one of the established AI-governance pure-plays tracked on the category page [S-2026-06-22-gaig-gartner-mq-full-quadrant].
- relates-to → Model Risk Management and Agentic AI — its default-high-risk classification stance and cascade-event risk category bear on agentic-MRM classification and incident response [S-2026-07-01-credo-agentic-high-risk].
- relates-to → EU AI Act — the classification argument is framed against EU AI Act risk tiers; watch item is whether EU AI Office agentic guidance adopts it [S-2026-07-01-credo-agentic-high-risk].
- competes-with → Monitaur — fellow MQ-placed AI-governance platform vendor [S-2026-06-22-gaig-gartner-mq-full-quadrant].
- competes-with → IBM — watsonx.governance is an MQ Leader in the same category [S-2026-06-22-gaig-gartner-mq-full-quadrant].
Tracked changes
- 2026-08-25 — Published “The EU AI Omnibus and the Living EU AI Act: A Playbook for Enterprises” (ungated PDF; landing page read, PDF body not read) [S-2026-08-25-credo-eu-omnibus-playbook].
- 2026-07-14 — Published the Agent Governor launch blog (Research Preview): harness-layer governance-as-code, four-outcome action resolution, per-decision evidence records, Claude Code first [S-2026-07-14-credo-agent-governor-launch].
- 2026-07-17 — Announced Agent Governor research preview via newsletter/LinkedIn relay (webinar 30 Jul), Microsoft Pegasus selection, DiMe/FDA community participation [S-2026-07-17-credo-agent-governor-preview].
- 2026-07-01 — Published “Seven Novel Governance Considerations for Agentic AI” (default-high-risk stance; prompt injection; cascade events) [S-2026-07-01-credo-agentic-high-risk].
- 2026-06 (reported 2026-06-22) — Reported as Visionary in the inaugural Gartner MQ for AI Governance Platforms (GAIG-only source ⚠️) [S-2026-06-22-gaig-gartner-mq-full-quadrant].
Open Questions
- Does the playbook PDF map Omnibus changes to Credo product features (evidence packs, policy packs), and does it cite the Official Journal reference for the 27 July 2026 entry-into-force date — landing page only read [S-2026-08-25-credo-eu-omnibus-playbook].
- No named EU/UK regulated-FS reference customer captured to date.
- Whether the MQ Visionary placement will be corroborated by Credo AI’s own announcement or the gated Gartner report.
- What the enumerated seven governance considerations actually are (primary blog post not yet read).
- ✅ (answered 2026-07-27 from the primary launch blog) What Agent Governor actually does — runtime enforcement at the agent-harness layer: governance-as-code, four-outcome action resolution, per-decision evidence records [S-2026-07-14-credo-agent-governor-launch]. Residual: whether its evidence records meet EU AI Act Art. 12/14 or SS1/23 thresholds (unclaimed by the vendor), coverage of homegrown SDK harnesses, and the path/timeline from Research Preview to GA — the 30 Jul 2026 webinar remains a disclosure point [S-2026-07-14-credo-agent-governor-launch].
Sources
- [S-2026-07-01-credo-agentic-high-risk] → S-2026-07-01-credo-agentic-high-risk
- [S-2026-06-22-gaig-gartner-mq-full-quadrant] → S-2026-06-22-gaig-gartner-mq-full-quadrant
- [S-2026-07-17-credo-agent-governor-preview] → S-2026-07-17-credo-agent-governor-preview
- [S-2026-07-14-credo-agent-governor-launch] → S-2026-07-14-credo-agent-governor-launch — primary launch blog, fetched directly; supersedes the 17 Jul relay on capability disclosure
- [S-2026-08-25-credo-eu-omnibus-playbook] → S-2026-08-25-credo-eu-omnibus-playbook — vendor EU Omnibus playbook, landing page fetched in full (low authority; regulatory dates vendor-relayed, unverified)