The datasheet for every AI agent

Research

Research reportai-agents

Which AI Agents Can You Self-Host? A Census of 93 Tools

Of the 93 AI agents in our index, 41 can run on infrastructure you control and 52 are cloud-only. Support and sales agents offer zero self-hosting.

Of the 93 AI agents published in The Agents Index on 19 August 2026, 41 can be run on infrastructure you control and 52 are cloud-only. The Deployment field is filled in for 93 of 93 listings, so every count on this page is out of the full index with no unknowns set aside.

That field is easy to skim past because it looks like a formality. It isn’t. If a compliance team needs code and customer data to stay inside a network you control, this one field decides whether a tool is even in the running, regardless of how good its agent is.

The headline count

52 of the 93 tools in The Agents Index (56%) are cloud-only, with no self-hosted or on-premise option at any price. The rest split two ways: 14 of 93 (15%) are self-host only, mostly frameworks and libraries with no managed cloud offering at all, and 27 of 93 (29%) offer both, a cloud-hosted default with a genuine private-deployment path alongside it.

So 41 of the 93 tools (44%) can be run somewhere you control. Which 41 depends heavily on what you are buying.

The category split is the real finding

Category Cloud-only Self-host only Both Any self-host option
Coding agents 9 of 25 (36%) 6 of 25 10 of 25 16 of 25 (64%)
Agent platforms 8 of 15 (53%) 1 of 15 6 of 15 7 of 15 (47%)
Agent frameworks 0 of 14 (0%) 6 of 14 8 of 14 14 of 14 (100%)
Research & data agents 10 of 11 (91%) 1 of 11 0 of 11 1 of 11 (9%)
Voice agents 8 of 11 (73%) 0 of 11 3 of 11 3 of 11 (27%)
Support agents 9 of 9 (100%) 0 of 9 0 of 9 0 of 9 (0%)
Sales & marketing agents 8 of 8 (100%) 0 of 8 0 of 8 0 of 8 (0%)
Agent tools & infrastructure 2 of 2 (100%) 0 of 2 0 of 2 0 of 2 (0%)

The table says one thing plainly: what you are buying predicts whether you can self-host it far better than how much you pay. Agent frameworks are unanimous in one direction, support and sales agents unanimous in the other, and no price tier crosses that line.

(Sierra and Botsify each belong to two categories and are counted once in each, so the category rows sum to 95 against an index of 93 distinct tools. The same convention applies in our open-source license census.)

Support and sales agents offer nothing at any price

All 17 tools across support agents and sales and marketing agents are managed cloud products only. They are Sierra, Intercom Fin, Decagon, Crescendo, Cresta, Ada, Botsify, Zendesk AI Agents, Auto-Respond, Clay, 11x, Artisan, Qualified, Rox, Unify, Warmly and Amplemarket.

If a support or sales team has a hard data-residency requirement, there is currently nothing in either category on this site that clears it. The constraint has to be solved contractually, through data processing agreements and regional hosting commitments from the vendor, rather than architecturally.

The third all-cloud row, agent tools and infrastructure, holds only two listings, Browserbase and SalesTouch. Two tools is far too few to read as a property of that category. It is in the table for completeness, not as a finding.

Agent frameworks are the mirror image

14 of the 14 agent frameworks in The Agents Index offer some form of self-hosting. That is not a coincidence, since a framework you cannot run yourself is a managed service with extra steps. The split inside the category still matters.

6 of the 14 agent frameworks are self-host only, though two carry a caveat. LangChain, Microsoft AutoGen, the OpenAI Agents SDK and Pydantic AI have no managed layer at all. Agno and AgentsKit sit in the same bucket for different reasons: Agno’s paid AgentOS tier still deploys into the customer’s own cloud rather than a vendor-run one, and AgentsKit’s own AgentsKit OS is enterprise-only, early access, reachable only by booking a sales demo, and discloses no public pricing, so it does not read as a generally available second deployment path yet.

The other eight frameworks pair a self-hosted core with an optional managed service: Microsoft Agent Framework, LlamaIndex, Mastra, Letta, Google Agent Development Kit and Claude Agent SDK, whose managed layers are Foundry Hosted Agents, LlamaCloud, Mastra Cloud, Letta Cloud, Google’s Agent Runtime and Anthropic’s Claude Managed Agents respectively, plus CrewAI, which ships a hosted platform with a visual editor alongside its open-source Python framework, and LangGraph, whose deployment and tracing layer is LangSmith.

Coding agents spread across all three modes; platforms split on licence

Coding agents are the most genuinely flexible category, and the only one with real representation across all three deployment modes rather than clustering at one end: 36% cloud-only, 24% self-host only, 40% both. That range exists because “coding agent” spans everything from a $0 terminal binary you point at your own model key to a fully managed cloud IDE, and buyers here actually care about the difference. Our coding agent comparison guide covers the rest of that decision.

Agent platforms are the category where workflow-automation buyers with compliance requirements would most expect on-premise options, and slightly under half of them deliver: 7 of the 15 offer a self-hosted path. They are n8n, whose own hosting docs cover running it on-premises or in a private cloud, plus Dify, Botpress, Sim, Vellum, MindStudio, whose self-hosting is gated to its Business plan, and OpenClaw, the only agent platform in this index with no vendor-hosted option at all.

Every one of the 8 cloud-only agent platforms is closed-source, and every platform with a private path is open source or undetermined. In this category the licence and the deployment option move together exactly, which is the one place in the index where they do.

Among research and data agents, GPT Researcher is the single self-hostable tool against ten cloud-only ones, including Microsoft Fabric Data Agent, which runs only inside a Fabric or Power BI Premium capacity, and Webhound, whose hosted web app and MCP server have no self-run option.

Self-hosting and open source are not the same fact

Read the “any self-host option” column above next to our open-source license census and a pattern breaks. We have determined open-source status for 92 of the 93 listings, and 33 of those are open source.

Of the 41 tools that offer some form of private deployment, 32 are open source and 8 are closed-source products that offer a private-deployment path anyway. For one more, MindStudio, we have not established whether the source is open, so it is counted where the evidence puts it, in neither group.

The reverse gap matters just as much. 32 of the 33 tools in our index recorded as open source have a self-hosted path. 1 of the 33 does not: Cartesia, whose Line voice-agent runtime always runs on Cartesia’s own managed infrastructure even though its Sonic and Ink speech models can be self-hosted into a customer’s environment on an Enterprise contract. So do not assume “open source” means “you can just run it yourself” without checking the deployment column specifically. Our open-source collection and the coding agents self-hosted facet page show how much the work varies, from a single static binary to a real orchestrated deployment.

The eight closed-source tools you can still run yourself

8 of the 41 tools with a private-deployment path are closed-source, and they do it in three genuinely different ways.

Tool Category What the private option actually is
Factory Coding agents Enterprise tier: fully managed SaaS, hybrid (cloud control plane, customer compute), fully on-premise, or air-gapped, across AWS, Azure or GCP, with customer-managed encryption keys
CodeRabbit Coding agents Enterprise tier adds self-hosting and API access on top of the default SaaS review product
Bland AI Voice agents Enterprise tier: dedicated infrastructure, self-hosted or on-premises, with US/EU/APAC data residency and SOC 2, HIPAA and PCI DSS compliance
Deepgram Voice Agent API Voice agents Fully managed, dedicated single-tenant, VPC-hosted, or fully self-hosted (Deepgram’s own self-hosted deployment docs), backed by SOC 2 Type II certification and signed HIPAA BAAs
Augment Code Coding agents Cosmos agent loops execute in the team’s own AWS or GCP account, on developer laptops, or on dev VMs such as Codespaces and Devcontainers, instead of Augment’s managed sandboxes
Windsurf (now Devin Desktop) Coding agents Devin Local: the desktop IDE runs its coding agent on your machine instead of dispatching to Devin Cloud
Junie Coding agents The JetBrains IDE plugin and CLI execute locally and can call a local Ollama or LiteLLM runtime, or your own API key, instead of JetBrains’ credit-metered cloud service
Claude Agent SDK Agent frameworks Self-hosting is the primary free path: you run the subprocess yourself, with no paid tier gating it

The first four are the enterprise pattern: closed-source code, but a paid tier, or in Deepgram’s case an Enterprise-quoted deployment option, that lets a regulated buyer keep data inside their own infrastructure. The vendor sells deployment flexibility as a feature rather than the source code.

Augment Code, Windsurf and Junie are a different shape and worth separating out. None of the three describes an on-premise server you deploy for a team. What they offer is execution you site yourself, on a developer’s own machine or in your own cloud account, pointed away from the vendor’s hosted service. That clears this census’s bar, and it does not carry the same compliance weight as the four above. A procurement team should not read these three rows as an on-prem offering.

Claude Agent SDK is a third shape. Self-hosting is its primary, free path, yet it is still counted closed-source here, because Anthropic’s own docs place overall SDK use under its Commercial Terms of Service and the compiled Claude Code CLI binary the wrapper bundles is not published as source, even though the thin Python and TypeScript wrapper packages carry an MIT license. It clears this census’s self-hosting bar while missing the open-source census’s stricter one, which is the clearest proof on this page that the two questions really are independent.

Method

We read the Deployment field on all 93 published listings in this index on 19 August 2026. The field is populated for 93 of 93, so there is no unknown bucket and no count above is a percentage of a subset. Open-source status is a separate field and is determined for 92 of the 93; where it is not determined, the listing is reported as undetermined rather than counted as closed.

The judgement the deployment field encodes is this: can the agent runtime execute on infrastructure you control, without a mandatory call to the vendor’s own hosted service? Where the answer is no, the listing reads Cloud even when parts of the stack are self-hostable. Cartesia’s speech models can run in your environment while its Line agent runtime cannot, so Cartesia reads Cloud. Muse Code runs in your terminal but reaches Meta’s Model API by its only access path, so it reads Cloud too. Where the agent can run without the vendor’s service, as with Junie pointed at a local model runtime, the listing reads Both. That test is the reason a handful of tools sit in a different bucket than their marketing implies, in both directions.

Counts are a census of this index, not a survey of the market. They describe the 93 tools we have researched and published, and the index grows, so the date above is part of the claim. Corrections are welcome through our methodology page.

Get the next report

New agents rankings and fresh data reports. One short email, straight to your inbox. One-click unsubscribe.