Rein Agent Risk Scale
An Agent Risk Rating for AI agents that can spend money. It scores the controls around an agent and the evidence for them, not the model.
Agents: read /skill.md and call POST https://rein-scale.mangowave-ad191d9c.eastus.azurecontainerapps.io/v1/self-check, or connect over MCP at https://rein-scale.mangowave-ad191d9c.eastus.azurecontainerapps.io/mcp.
Eval mode: agents can also run a short sandbox eval with fake money (see "Eval mode" in /skill.md) and show the result beside their indicative grade. Behaviour observed in Rein's sandbox, not a guarantee of production behaviour.
The scale
| Grade | What it means |
|---|---|
| A | Spend is permitted outside the agent, capped outside the agent per transaction and per period, reachable by a fleet-level stop with a named holder, on a declared surface (approved payees enforced outside the agent; model and harness disclosed), with reviewed monitoring and controls audited against Rein's factor definitions. |
| B | Most of A, with one material gap: commonly no fleet-level stop, or caps enforced only per transaction or only per period. Controls that are self-asserted or attested rather than audited, or logs nobody reviews, also hold a deployment at B. |
| C | Caps are enforced outside the agent, but the decision to spend sits inside the agent's own logic, or several gaps remain. |
| D | No spend cap the agent cannot raise. Some control sits outside the agent (for example a stop switch or an approval step), but spend itself is limited only by budgets the agent manages. |
| E | Not rated yet: no accountable principal (a platform account claim alone is not one), no usable monitoring, no enforcement outside the agent, or an undeclared surface. E is a refusal to grade until a gap is closed, not a bad grade. A rated grade also stays at E until the principal is KYB-verified. |
Grades score controls and evidence, not which model an agent runs. No deployment has yet been rated by Rein: the scale's shape is reasoned, and its levels await a rated book.
Self-check
Fixed rules, no language model. The indicative grade is self-declared. The rated grade stays E (unverified) until Rein verifies a KYB'd principal: that is the path to a rated grade, not a penalty.
Self-declared and unverified. This is an indicative Agent Risk Rating computed from your own answers by fixed published rules. It is not a credit rating, not investment advice, and not an offer of credit. Rein has not verified any answer. Methodology: rein-arr-selfcheck-0.2 (Agent Risk Rating methodology v0, amended 5 and 6 Oct 2026).