AIUC-1 AI Assurance Standard Overview
First assurance standard built specifically for autonomous AI agents operating in live systems.

AI agents don't just answer questions anymore. They call tools, move money, touch customer records, and chain a dozen small decisions together with nobody watching in real time. That shift is what AIUC-1 was built to address: it's the first assurance standard written specifically for autonomous AI agents rather than for software in general, and understanding how it works matters for any organization that has handed an agent the keys to a live system.
AIUC-1 stands for Artificial Intelligence Unified Controls, version 1. It comes from the Artificial Intelligence Underwriting Company, a startup founded by people who spent time at Anthropic, McKinsey, the Center for AI Safety, and METR. The company came out of stealth in July 2025 with a $15 million seed round led by Nat Friedman at NFDG, with Emergence, Terrain, and notable angels including Anthropic co-founder Ben Mann.
More than 100 Fortune 500 CISOs gave input while the standard was being built, and Orrick, Stanford, the Cloud Security Alliance, MIT, and MITRE all contributed technical work. The thesis is simple enough to state in a sentence, even if executing on it is not: certification, audit, and insurance work better as one system than as three separate ones. Certification sets the bar for what "safe enough" looks like. An independent audit checks whether a given agent actually clears that bar. Insurance then puts money behind the result, so there's an actual financial incentive tied to doing this well, not just a certificate to hang on the wall.
AIUC's founders lean on some older analogies to explain why this matters. UL Labs, the group that tests toasters and space heaters for safety, came out of the insurance industry. Car insurers helped develop crash-test standards that shaped how vehicle safety came to be evaluated. SOC 2 gave SaaS vendors a way to prove trustworthiness to buyers who couldn't audit every vendor themselves. AIUC-1 is pitched as that same function, applied to AI agents. As AIUC co-founder and CEO Rune Kvist put it to Fortune, "It's not Toyota that does the car crash testing, it's independent bodies." A company grading its own agent's homework isn't worth much to the enterprise deciding whether to deploy it, and closing that gap is the whole reason AIUC-1 exists.
How AIUC-1 is structured: six pillars, 51 requirements, and 130 controls
The standard breaks down into 51 requirements and 130 controls, split into 65 mandatory and 65 optional, spread across six pillars.
Data & Privacy covers PII leakage, keeping one customer's data walled off from another's, IP protection, and stopping a model from getting retrained on sensitive enterprise data it shouldn't touch. Security handles prompt injection defense, adversarial robustness, and blocking agents from taking actions outside their intended scope. Safety deals with harmful outputs, pre-deployment testing, and a risk taxonomy for classifying what could go wrong. Reliability targets hallucination prevention and restricts tool calls so an agent can't wander into unintended autonomous behavior. Accountability requires failure response plans, vendor due diligence, and disclosure obligations. Society, the broadest pillar, aims at guardrails against agents contributing to larger systemic risks.
The mandatory-versus-optional split matters because it gives organizations a floor to clear and a ceiling to aim for, rather than a single pass-fail bar. What AIUC-1 is not matters just as much, and this is where a lot of buyers get confused: it's not a model-development standard. It doesn't grade training data or bias mitigation the way broader AI governance frameworks do. Its focus sits squarely on how an agent behaves once it's live inside a company's systems with real authority to act, which is a narrower and, frankly, more testable target than "is this model fair." It builds on the NIST AI Risk Management Framework, the EU AI Act, and MITRE's ATLAS threat model, layering agent-specific, testable controls on top of them rather than trying to replace what already exists.
How AIUC-1 certification actually works: from scoping to adversarial testing to a certificate
Certification applies to a specific product or system, not to a company as a whole. Sit with that distinction for a second: a company can have one certified agent and five uncertified ones, so the badge tells a buyer about that particular product, not about the vendor's entire portfolio. A procurement team that reads "AIUC-1 certified" on a vendor's homepage and assumes it covers everything that vendor ships is making exactly the mistake the standard's own scoping rules are designed to prevent.
The process runs in four phases. Scoping and gap analysis comes first: define what's being certified, assign stakeholders, gather early evidence, and figure out where the gaps are against AIUC-1's controls. Remediation follows, where legal, governance, and operational policies get updated and technical safeguards get built to close whatever gaps turned up. Then comes the part that separates this from a paperwork exercise: adversarial technical evaluation, which involves more than 5,000 automated simulations across security, safety, reliability, privacy, and accountability, modeled on documented real-world failures and run in production-like conditions. Finally, an independent audit reviews the test results and policy evidence and issues a report and certificate.
AIUC itself runs the adversarial testing. A separate accredited third-party auditor, currently Schellman, evaluates that evidence and signs off on the certificate, a split meant to keep the technical testing and the audit judgment from sitting in the same hands. Whether that split actually holds up is a question worth returning to later, because AIUC still writes the rules that both the testing and the audit get measured against.
KPMG's aIQ Capture platform shows what this looks like on the ground. It went through more than 900 technical tests covering hallucinations, high-risk domain interactions, content safety, and prompt injection, and came out with no critical or major vulnerabilities flagged, according to the KPMG and AIUC announcement from August 27, 2026. That's the mechanism that makes AIUC-1 different from a checklist audit: nobody self-attests their way through it. Something has to actually try to break the agent first, and the test count is the evidence that something did.
Why the quarterly update cadence is a structural feature, not just a maintenance schedule
AIUC-1 updates every quarter, not once a year, and that pace is deliberate. AI capabilities and the threats against them move faster than an annual review cycle can track, so a yearly standard would be stale before its second edition even shipped. Anyone who has watched a compliance framework calcify around threats from three years ago knows what that staleness looks like in practice: controls that check for the last generation of attack while the current one walks right past them.
The Q2 2026 release, effective April 15, 2026, modified 14 requirements and added 23 new controls, with most of the changes centered on Model Context Protocol and Agent-to-Agent protocol security, third-party risk management, and identity and access controls for agents. A Q3 2026 release was scheduled for July 15, 2026, which gives a sense of the rhythm organizations need to plan around. After each release, a certified company has to check whether the changes opened new coverage gaps and then extend its evidence collection before the next audit cycle comes around. That's a real lift for a compliance team already juggling SOC 2, ISO 42001, and whatever else sits on its plate.
The update process draws on more than 250 members of the AIUC-1 Consortium, made up of CISOs and security leaders from Fortune 1000 companies. In one recent quarterly cycle, more than 120 of them took part in technical sessions and left more than 200 peer-review comments on proposed changes. The January 2026 revision, according to Mindgard, changed dozens of requirements and added voice-specific controls, a direct response to voice agents becoming a deployment category of their own. For companies in regulated industries, the cadence cuts both ways. It's more work to keep up with, sure, but it also means the standard doesn't go quietly out of date the way a lot of annual compliance frameworks do.
Who has been certified so far and what the early adoption pattern reveals
ElevenLabs was the first company to earn AIUC-1 certification, back at launch in mid-2025. Intercom's Fin agent followed in December 2025. UiPath got certified in March 2026. Fieldguide, described as a leading AI-native platform for audit and advisory work, was certified in May 2026, the first AI platform in that specific category to hold the certification. Then in August 2026, KPMG LLP became the first Big Four firm to earn AIUC-1 certification, covering its aIQ Capture agentic AI platform.
Line those up and a pattern shows itself: voice AI, customer service automation, workflow automation software, audit-and-advisory tools, and now a Big Four professional services firm. Different categories, different customers, different failure modes. The one thing they share is that all of them handed an agent real authority to act on live systems, which is the trigger that makes AIUC-1 relevant rather than the industry label on the company.
KPMG's move deserves more weight than the others, and it's worth being direct about why. A firm of that size certifying its own internal AI platform is a different kind of signal than a startup certifying a product to help close enterprise sales. One is a sales tool. The other looks like actual risk management, the kind a firm does because it has to answer for the agent's mistakes to its own clients, not because a badge helps a deal close faster. KPMG also joined the AIUC-1 Consortium, so it's now participating in writing the rules, not simply following them. That's the strongest adoption signal in the list, stronger than the certificate itself.
Fieldguide's certification lands close to home for accounting and audit professionals specifically. AI tools built for audit workflows are starting to face the same scrutiny that auditors themselves apply to the businesses they review, a fairly neat bit of role reversal. Separately, AIUC-1 and the Cyber Risk Institute have started working together to strengthen AI security practices for financial institutions, aiming to support safer adoption of agentic AI while getting banks ready for compliance obligations still coming down the pipe.
The governance tensions in AIUC-1's design that organizations should understand before relying on it
The picture gets more complicated here, and it deserves a straight look rather than a glossed-over one. AIUC writes the standard. AIUC accredits the auditors who check compliance against that standard. AIUC runs the adversarial technical testing itself. AIUC also arranges the insurance that gets priced off the certification result, acting as a managing general agent rather than a licensed underwriter. That's four roles sitting inside one company, and the honest read is that this concentration is the standard's biggest weakness, not a footnote to mention and move past.
Start with the auditor relationship, because it carries a familiar problem. The vendor being certified picks its auditor, and that auditor is competing for repeat business from other vendors down the line. An accredited auditor competing for repeat business from future vendors has a built-in reason to be generous with borderline calls. That's the exact structural tension that has occasionally dogged SOC 2's credibility over the years.
The insurance side is where the concentration gets harder to wave off. Reporting from Mindgard indicates AIUC operates as a managing general agent alongside a licensed carrier, with Beazley named as one partner. AIUC designs the insurance program, prices the risk, and binds the coverage, but doesn't carry the underwriting license itself. Under an MGA arrangement like this, AIUC may collect commissions tied to how well the insurer's overall book performs. Some observers have compared that setup to the issuer-pays model that's drawn criticism in credit ratings for decades: a rating agency paid by the company it's rating has an obvious conflict built in, and the parallel to a certifier that also prices the insurance riding on its own test results is the single fact here that should give a procurement team the most pause. Not because it proves the testing is soft. Because nobody outside AIUC can currently check whether it is.
None of this makes the certification worthless. It does mean a procurement team or a risk committee should treat an AIUC-1 certificate as a strong signal, not a substitute for asking who audited it, who's underwriting the coverage behind it, and what happens when the two roles disagree. KPMG's responsible AI principal offered a useful way to frame the proportionality question: "Not every agent needs an independent certification. The level of testing and certification should be proportionate to its purpose, its authority, its access, and the potential impact." That standard applies just as well to the certification itself as it does to the agents it evaluates.
How to think about AIUC-1 relative to SOC 2, ISO 42001, NIST AI RMF, and the EU AI Act
SOC 2 is the closest comparison, and a useful one. AIUC-1 aims to do for AI agents roughly what SOC 2 does for SaaS vendors: give enterprise buyers a third-party-validated signal they can rely on instead of sending every vendor a 200-question security survey. What gets tested differs, though, and the difference is the whole point. SOC 2 examines whether a service organization's controls over security, availability, processing integrity, confidentiality, and privacy are designed properly and actually operating. AIUC-1 goes a step further and throws adversarial attacks at a live agent to see how it behaves under pressure, not just whether the paperwork says the right controls exist. A SOC 2 report can tell you a company has an incident response policy. It cannot tell you whether a prompt injection attack gets an agent to wire money to the wrong account.
ISO 42001 covers AI management systems broadly: governance structures, risk assessment processes, responsible development practices. It's a solid framework, but it wasn't built to test whether an agent can be tricked by prompt injection or talked into taking unauthorized actions. KPMG actually held ISO 42001 certification, earned in November 2025, before going after AIUC-1, which suggests the two aren't competing standards so much as complementary layers stacked on top of each other.
NIST AI RMF gives principle-based risk guidance that a lot of organizations already use as a governance reference point, but it isn't an auditable, agent-specific control set the way AIUC-1 is. AIUC-1 builds on top of it rather than trying to replace it. The EU AI Act, which took effect in 2024, sets risk-tiered rules around transparency, human oversight, and system robustness at the regulatory level. That's law, with all the weight that carries, while AIUC-1 is a voluntary industry standard, and the two shouldn't be mistaken for equivalent forms of accountability.
Taken together, these frameworks aren't competing for the same job. NIST and the EU AI Act set the principles and the legal floor. ISO 42001 builds the management system around those principles. AIUC-1 is the one that straps the agent to a table and tries to make it misbehave, which is the piece none of the others were designed to do. Whether that combination holds up as agentic AI keeps spreading into finance, healthcare, and other regulated corners is still an open question. Given how much of AIUC-1's authority sits inside one company that writes the rules, runs the tests, and prices the insurance, it's a question worth watching closely rather than assuming settled.


