Reference

Every AI system Mountain Theory can govern

Mountain Theory can govern 176 AI systems across 14 categories: models, frameworks and agents, in any environment. Model agnostic and platform agnostic.

This is a capability list, not a customer list. It is what the product can govern. What any one organization governs is whatever it connects.

The numbers

  • 176AI systems we can govern
  • 92are autonomous agents and frameworks
  • 101in the decision path, governed inline
  • 55at the integration boundary
  • 20on the roadmap, not enforced yet

What “governed” means here: two ways we govern, and one we do not yet

In the decision path

We sit inline. The action does not execute until it has been checked.

100 systems

At the boundary

We govern the system where it connects to something else, rather than inside its runtime. That is what most hosted products allow, because the vendor does not open the runtime to anyone.

55 systems

On the roadmap

We govern text today. Image, vision and audio inspection are on the roadmap and not enforced yet. These 20 are listed so you can see where the line is.

20 systems

We govern the action, not the input. Multimodal models sit in the decision path even though they read images, because the action they emit is text: a tool call, a command, a write. A pure vision or speech model is different. Its output is the classification itself, and that is what we do not enforce yet.

We could have left that last group out. We list it because a catalog that hides its gaps is the one a CISO catches, and marking these 20 is what makes the other 156 worth believing.

The 14 categories

Search across all 176 systems, or filter by how each one is governed.

Showing 176 of 176 systems

No system matches that search. Every name on this page sits under one of the 14 categories below.

That does not mean we cannot govern it. It means it is not on the list yet.

Ask us to add it

Large language models, open and self-hostable

In decision path 20 systems
  • Meta Llama 4
  • Meta Llama 3.3
  • DeepSeek V3.2
  • DeepSeek R1
  • Alibaba Qwen 3.5
  • Alibaba Qwen 2.5
  • GLM-5 (Zhipu AI)
  • Mistral Large
  • Mistral Small
  • Mixtral
  • Google Gemma 3
  • Google Gemma 2
  • Microsoft Phi-4
  • Microsoft Phi-3
  • Cohere Command R+
  • Falcon 2
  • 01.AI Yi 1.5
  • InternLM
  • Nous Hermes
  • OLMo 2

Small and edge language models

In decision path 10 systems
  • Qwen 3.5 0.8B
  • Mistral Ministral 3B
  • Phi-3 Mini
  • Google Gemma 1B
  • Google Gemma 4B
  • Llama 3.2 1B
  • Llama 3.2 3B
  • SmolLM2
  • TinyLlama
  • StableLM 2 1.6B

Vision and object detection

Future roadmap 10 systems

Listed for visibility. We govern text today. Native image and vision inspection is on the roadmap, not enforced yet.

  • YOLO (v8 to v26)
  • RF-DETR (Roboflow)
  • GroundingDINO
  • Meta SAM 2
  • OpenAI CLIP
  • DINOv2
  • Detectron2
  • EfficientDet
  • OWL-ViT
  • Depth Anything

Multimodal, vision and language

In decision path 10 systems
  • Kimi VL
  • Qwen VL
  • Google Gemma 3 Vision
  • DeepSeek VL
  • GLM-4.6V
  • LLaVA
  • InternVL
  • Allen AI Molmo
  • Mistral Pixtral
  • Phi-3.5 Vision

Speech and audio

Future roadmap 10 systems

Listed for visibility. Audio inspection is on the roadmap, not enforced yet.

  • OpenAI Whisper
  • NVIDIA Canary Qwen 2.5B
  • Meta Omnilingual ASR
  • NVIDIA NeMo
  • NVIDIA Parakeet
  • Vosk
  • Coqui XTTS-v2
  • MeloTTS
  • Moonshine
  • Distil-Whisper

Agent frameworks and runtimes

In decision path 17 systems
  • LangGraph (LangChain)
  • CrewAI
  • OpenAI Agents SDK
  • Google ADK
  • Pydantic AI
  • Hugging Face SmolAgents
  • LlamaIndex Workflows
  • Claude Agent SDK
  • Microsoft Agent Framework
  • Microsoft AutoGen
  • Microsoft Semantic Kernel
  • Mastra
  • Agno
  • Dify
  • Flowise
  • Model Context Protocol (MCP)
  • NVIDIA OpenShell

Autonomous agents, self-hosted and open

In decision path 9 systems
  • Hermes
  • OpenClaw
  • AutoGPT
  • MetaGPT
  • SuperAGI
  • BabyAGI
  • OpenHands (autonomous agent)
  • Browser Use
  • Manus (local mode)

Autonomous agents and assistants, hosted

At the boundary 19 systems
  • ChatGPT (desktop and Work)
  • ChatGPT Atlas
  • OpenAI Operator
  • Claude Desktop (Anthropic)
  • Claude Cowork (Anthropic)
  • Anthropic Computer Use
  • Google Gemini Agent
  • Gemini-in-Chrome
  • Microsoft Copilot (Windows and M365)
  • Copilot Cowork (Microsoft)
  • Snowflake CoWork
  • Apple Intelligence and Siri
  • Perplexity Comet
  • xAI Grok (assistant)
  • Meta AI
  • Manus (Butterfly Effect)
  • MultiOn
  • Genspark Super Agent
  • Amazon Alexa+

Coding agents, open and self-hosted

In decision path 6 systems
  • Aider
  • Cline
  • OpenHands (coding agent)
  • Continue
  • Roo Code
  • Kilo Code

Coding agents and assistants, hosted

In decision path 19 systems

These execute on your machine or in your repo even though the model is hosted, so the action happens where we can sit in front of it.

  • Claude Code (Anthropic)
  • OpenAI Codex
  • Google Gemini CLI
  • Cursor (Anysphere)
  • Windsurf (Cognition)
  • GitHub Copilot
  • Devin (Cognition)
  • Google Jules
  • Replit Agent
  • AWS Kiro
  • Amp (Sourcegraph)
  • Sourcegraph Cody
  • Tabnine
  • Qodo Gen
  • Warp
  • Factory Droids
  • Bolt (StackBlitz)
  • Vercel v0
  • Lovable

Enterprise agent platforms

At the boundary 22 systems
  • Salesforce Agentforce
  • Microsoft Copilot Studio
  • ServiceNow AI Agents
  • Amazon Bedrock AgentCore
  • Google Vertex AI Agent Builder
  • Google Gemini Enterprise
  • IBM watsonx Orchestrate
  • SAP Joule
  • Sierra
  • Decagon
  • Glean Agents
  • Writer
  • Cohere North
  • Lindy
  • Relevance AI
  • Beam AI
  • Kore.ai
  • UiPath Agentic
  • Automation Anywhere
  • Cresta
  • Cognigy (NiCE)
  • Moveworks

Automation and workflow platforms

At the boundary 7 systems
  • Zapier
  • n8n
  • Make
  • Bubble
  • Retool
  • Pipedream
  • Workato

MCP servers and tool plugins

In decision path 10 systems
  • Filesystem MCP
  • GitHub MCP
  • Slack MCP
  • Postgres MCP
  • Google Drive MCP
  • Browser and Playwright MCP
  • Jira MCP
  • custom tool plugins
  • function-calling tools
  • retrieval and RAG tools

Closed and hosted foundation models

At the boundary 7 systems
  • OpenAI GPT-5
  • Anthropic Claude
  • Google Gemini
  • xAI Grok (model API)
  • Cohere Command
  • Amazon Nova
  • Mistral (hosted)

FAQ

What does Mountain Theory mean by a governable AI system?

A governable AI system is any model, framework or agent whose actions Mountain Theory can check against policy before they execute. There are 176 of them across 14 categories.

Does Mountain Theory support my model?

Probably, though the model is usually the wrong question. We are model agnostic. What matters is whether we sit in the path of the action, and that depends on the framework or agent around the model rather than the model itself.

What is the difference between governing in the decision path and at the boundary?

In the decision path we sit inline and the action does not execute until it has been checked. At the boundary we govern the system where it connects to something else, which is what hosted products allow. 100 systems are in the decision path, 55 at the boundary.

Are all 176 systems enforced today?

No, and we mark which are not. 156 are enforced. 20 are on the roadmap and listed for visibility. We govern text today. Image, vision and audio inspection are not enforced yet.

Does this list mean you have 176 customers or 176 deployments?

No. This is what the product can govern. What any organization governs is whatever it connects.

Can Mountain Theory govern models we host ourselves?

Yes. Self-hosted and open models are the strongest case, because we can sit directly in the decision path rather than at the boundary.

Why are Chinese-developed models on the list?

Because customers run them and governing them is the point. The list is what Mountain Theory can govern, not what Mountain Theory is built on.

How does Mountain Theory decide whether an action runs?

Every action is checked against policy before it executes and returns one of three outcomes. ALLOW, the action proceeds. HOLD, the action is suspended and escalated by a policy you set in advance. BLOCK, the action is terminated before it runs. Nothing runs until it has been checked.

Scroll to Top