Skip to content
Agents for Humanity
Public draft. All results are preliminary desk assessments against criteria v1.0, updated 27 Sept 2026. No agent has been certified yet. How we assess
AssistanthostedProprietary

Claude

Anthropic · claude.ai

Claude offers strong in-product controls: item-level memory editing, readable Skills, custom MCP connectors, published base system prompts, a written no-ads commitment and a one-click JSON export. Structurally it remains a hosted, proprietary service: the agent cannot be run outside Anthropic's infrastructure or with another model, there is no tamper-evident audit trail, and model training is a default-on setting.

Strengths
  • Self-service JSON export of chats and memory
  • Memory viewable, editable and deletable item by item
  • Skills stored as readable SKILL.md files and scripts
  • Custom remote and local MCP connectors
  • Base system prompts published; written ad-free commitment
  • Manual-approval mode for Claude in Chrome
Gaps
  • No runnable export; runtime and models are provider-only
  • No tamper-evident or owner-verifiable audit log
  • Training toggle defaults to on; flagged data retained up to 2–7 years
  • Connector OAuth tokens held by Anthropic
  • Some modifications gated by paid tier (e.g. connector limits on Free)
Evidence

All 34 findings

Consumer Claude apps (claude.ai web, Desktop, mobile, Claude in Chrome) on Free, Pro and Max plans, per public documentation as of 2026-09-27. Team/Enterprise and the API not assessed.

Portable · Can you leave, and take the whole agent with you?

8%
  • P1
    Round-trip portability

    Incomplete, delayed and not restorable: the account export arrives by email, is not documented as including Skills, connectors or credentials, and Anthropic documents no import of it. Memory and Skills can only be brought back separately by pasting text and uploading .zip files.

    Fail
  • P2
    Complete export

    The export includes conversations, account data and memory, but documentation does not state that custom Skills, connector configurations or credentials are included, so the export does not capture the whole agent.

    Partial
  • P3
    Independent execution

    The agent runtime and Claude models are available only as Anthropic-hosted proprietary services; no open-source runtime can execute the exported agent without contacting Anthropic servers.

    Fail
  • P4
    Identity continuity

    The agent's identity is the Anthropic account, which does not travel with an export, so nobody the agent has dealt with can verify after a move that it is the same agent.

    Fail
  • P5
    No kill switch

    The functioning agent exists only on Anthropic infrastructure, so the provider can restrict or close the account; exported JSON files carry no license check but are not an executable agent.

    Fail
  • P6
    Capability independence

    Memory, search, artifacts, connectors and Chrome automation are delivered by Anthropic's service and work only with Claude models, so moving to another model would remove them. Skills and MCP servers use open formats, which partly mitigates this.

    Fail

Transparent · Can you see everything the agent is, with ordinary tools?

50%
  • T1
    Open storage format

    Exported conversations are JSON and Skills use a documented SKILL.md format, but the live internal storage format is undocumented and only reachable through Anthropic's software.

    Partial
  • T2
    No hidden instructions

    Anthropic publishes the base system prompts for claude.ai and the mobile apps, and user/project instructions are visible. Tool definitions, memory injection, safety interventions and other runtime context are not all shown to the owner.

    Partial
  • T3
    No shadow memory

    Deleted chats persist in back-end storage for up to 30 days; flagged inputs/outputs are kept up to 2 years and trust-and-safety classification scores up to 7 years, outside the owner-inspectable state.

    Fail
  • T4
    Complete action history

    Tool calls and connector actions appear inline in conversation transcripts, which the owner can export. Completeness is not documented, and deleted or incognito chats leave no owner-held record.

    Partial
  • T5
    Readable logic

    Custom Skills are human-readable Markdown plus optional scripts. The platform's own agent logic (orchestration, memory, tool routing) is closed source.

    Partial
  • T6
    No third-party influence channel

    Anthropic states that Claude will remain ad-free, with no sponsored links and no advertiser influence or unrequested product placement in responses. The company reserves the right to revisit this with transparency.

    Pass

Auditable · Can you reconstruct exactly what the agent did?

10%
  • A1
    No unrecorded actions

    Anthropic does not document whether every consequential action is durably recorded, or whether an action is blocked when it cannot be recorded.

    Unverified
  • A2
    Tamper evidence

    The owner-visible record is conversation history, which can be deleted or branched by editing messages without a detectable trace, and no other tamper-evident record is documented.

    Fail
  • A3
    Separation from the audited

    Anthropic does not document whether the agent layer can alter or delete records of its own actions; Claude can edit its memory store, which is separate from history.

    Unverified
  • A4
    Readable with ordinary tools

    Exported conversation JSON, including tool-use content, can be read with ordinary tools, but it is an account export rather than a dedicated audit trail.

    Partial
  • A5
    Corroborated interactions

    The consumer apps document no agent-to-agent exchanges whose records each side could match against the other's.

    Unverified

Verifiable · Can you prove the agent runs what it claims?

10%
  • V1
    Open, reproducible runtime

    The Claude apps and service runtime are proprietary; no OSI-licensed, reproducible runtime is published. Open specifications (MCP, Agent Skills) cover interfaces only.

    Fail
  • V2
    Active config is inspectable config

    Base system prompts and user instructions are inspectable, but server-side configuration, classifiers and injected context cannot be verified to match what is published.

    Partial
  • V3
    Attributable messages

    Messages go out through the owner's connected accounts, so recipients cannot verify that they came from this agent under the owner's authority, and no attribution survives leaving Anthropic.

    Fail
  • V4
    Independently checkable record

    No action record is offered whose integrity can be checked with open tools that do not depend on Anthropic.

    Fail
  • V5
    Comparable state

    Server-side state is not fully exposed and the export is partial, so the owner cannot verify whether the agent's state changed between two points in time.

    Fail

Modifiable · Can you change anything, without asking?

42%
  • M1
    Instructions

    Owners can write profile preferences, project instructions, styles and Skills, but cannot rewrite the platform system prompt or safety layers.

    Partial
  • M2
    Memory

    Settings > Memory lists stored memory topics, each of which can be read, edited or deleted; memory can also be updated from chat, and incognito chats are excluded.

    Pass
  • M3
    Logic

    Owners can create, upload and edit custom Skills (SKILL.md with scripts); the core agent logic of the app cannot be changed.

    Partial
  • M4
    Tools and permissions

    Owners can add any remote MCP server as a custom connector, run local MCP servers in Claude Desktop, and disconnect connectors. Free users are limited to one custom connector, and fine-grained per-tool permission policies are documented mainly for Team/Enterprise admins.

    Partial
  • M5
    Model choice

    Only Anthropic's Claude models can be selected; third-party or local open-weight models are not supported.

    Fail
  • M6
    No gatekeeping

    Some modifications are tier-gated, for example the one-custom-connector limit on Free, and all changes are bounded by Anthropic's terms and product surface.

    Fail

Controllable · Is your word final?

50%
Something wrong or out of date?

Vendors and the public can dispute any finding with evidence. Disputes and their resolutions are published.

Dispute a finding