AIUC-1

AIUC-1

AIUC-1

TL;DR

TL;DR

AIUC-1 is a certification standard for AI agents, published by the Artificial Intelligence Underwriting Company, covering safety, security, reliability, privacy, and accountability.

AIUC-1 is a certification standard for AI agents, published by the Artificial Intelligence Underwriting Company, covering safety, security, reliability, privacy, and accountability.

What is AIUC-1?

AIUC-1 is a certification standard for AI agents, published by the Artificial Intelligence Underwriting Company (AIUC). It sets requirements across safety, security, reliability, data privacy, and accountability, and it is backed by insurance, so an agent's conformance carries a financial guarantee as well as a paper one.

Most compliance artifacts a support buyer sees were written before autonomous agents existed. AIUC-1 targets the agent itself: the model, its tools, and the actions it takes on a customer's account, which is the layer procurement teams have had no agent-specific bar to check against.

How AIUC-1 works

Certification against an agent standard runs in four layers, and each layer produces the evidence the next one depends on.

The first is scope definition: which agent, which channels, which actions it may take, and which data it touches. The second is control implementation, where most of the engineering effort lands. AI guardrails constrain what the agent may say, retrieve, and do, turning a written policy into an enforced one. Refusal behaviour, tool permissions, and human handoff thresholds all sit in this layer.

The third layer is adversarial testing. AI red teaming probes the agent with jailbreaks, edge cases, and prompt injection attempts to find the inputs that make it break its own rules, and the results become part of the evidence file rather than an internal note.

The fourth is documentation and attestation: control descriptions, test results, incident history, and named owners, assembled so an external reviewer can trace each requirement back to something that actually happened.

What AIUC-1 requires

The standard groups its requirements into five domains. What each domain demands in detail is set out in the published control catalogue, which is the document to read before making any claim about coverage.

  • Safety: Controls over harmful, discriminatory, or out-of-policy output, including refusal behaviour and the escalation path when an agent should stop answering.

  • Security: Protection of the agent's inputs, tools, and credentials against manipulation, covering the injection and exfiltration paths a free-text interface opens.

  • Reliability: Accuracy and grounding requirements, so answers trace to a source the operator controls, with drift caught by monitoring before customers find it.

  • Data privacy: Handling rules for the personal data an agent reads, stores, and passes to model providers, including retention limits and training-use restrictions.

  • Accountability: Named ownership, logging, and incident response, so a bad answer can be reconstructed afterwards and attributed to a decision someone made.

AIUC-1 vs SOC 2 Type II vs ISO 42001 vs the EU AI Act

Procurement teams ask whether one of these replaces another, and the answer is that they attach to different objects. SOC 2 Type II reports on whether a service organization's security controls operated effectively across an observation window of six to twelve months. ISO 42001 certifies an organization's AI management system: governance, roles, risk process, and lifecycle discipline. The EU AI Act imposes statutory obligations on providers and deployers by risk class, enforceable by regulators. AIUC-1 certifies the AI agent as a product, which is the object the other three reach through the organization that builds it.


Who it binds

What it requires

How it is evidenced

AIUC-1

The AI agent and the team operating it

Controls across safety, security, reliability, privacy, accountability

Certification against the published control catalogue

SOC 2 Type II

Service organizations handling customer data

Security controls that operate effectively over a review period

An independent auditor's report on that stated period

ISO 42001

Organizations developing or deploying AI

A documented AI management system with risk and lifecycle controls

Accredited certification audit plus surveillance

EU AI Act

Providers and deployers in the EU market

Obligations scaled to the system's risk classification

Conformity assessment, technical documentation, registration

If you are buying an AI agent and need assurance about that agent's own behaviour, AIUC-1 is the specific bar. If you need assurance about the company operating it, the organizational certifications answer that, and most regulated buyers end up asking for both.

Why AIUC-1 matters for customer experience

Without an agent-level standard, vendor review falls back on artifacts that describe a company's security posture and say little about how its agent behaves under pressure. The buyer signs, the agent goes live, and the first real evidence of its refusal behaviour arrives in a customer transcript.

The failure that follows is rarely dramatic. An agent confidently states a policy that expired, approves a refund outside its authority, or repeats personal data into a channel where it should never appear. Each is a control gap that structured testing would have surfaced, and none of them shows up in a security questionnaire.

The tradeoff is real. Certification adds procurement time and forces engineering work that ships no features. Teams deploying into low-risk internal use cases can reasonably skip it. Teams touching money, health data, or regulated advice cannot, because one wrong answer there costs more than a CSAT point.

How is AIUC-1 measured?

Conformance is measured control by control, and the unit of measurement changes with the control being examined.

Behavioural controls are measured as pass rates over a fixed adversarial test set: the same prompts run against every release, with each failure logged and triaged. Grounding is measured by sampling answers and checking each one against the source it cited. Neither produces a single headline score, which is why certification is evidence of a process holding up over time.

Some controls attach to thresholds set outside the standard entirely. An agent placing outbound calls or texts inherits the delivery restrictions in 47 CFR 64.1200, which fixes the calling window at 8 a.m. to 9 p.m. local time for the called party and requires an opt-out request to be honored within 30 days. Those are testable numbers: the agent either respects the window and the deadline or it fails, and the log proves which.

How AI agents change certification evidence

Traditional software behaves the same way twice. An AI agent samples from a distribution, calls tools, and composes an answer from retrieved context, so the same question can produce different outputs on Tuesday and Thursday. Point-in-time testing loses much of its meaning against a system like that.

That mechanism forces three changes in how evidence gets gathered. Testing becomes continuous, because a model update, a prompt edit, or a stale knowledge article each shifts behaviour with no code deploy. Logging becomes granular enough to reconstruct one conversation: the passages retrieved, the tools called, the arguments passed. Ownership becomes explicit, because an agent acting on accounts creates decisions someone has to answer for.

The consequence for support teams is that compliance work moves into the delivery loop. Teams running AI agents in regulated support treat evidence generation as part of shipping, and the certificate becomes a snapshot of a practice already running.

Implementing AIUC-1

Preparing for certification is mostly discovery work. Start with coverage: list every action the agent can take, every system it can reach, and every data field it can see. Most teams find the reachable surface is wider than the documented one.

Integration surface comes next, because the controls that matter sit at the boundaries: the CRM write, the refund API, the identity check before an account action. Governance decides who signs off when agent behaviour changes, and that name belongs in the runbook before any audit begins.

On security, ISO 27001 is the framework that genuinely underpins this work, because its ISMS requirements force asset inventory, access control, and supplier management to exist as documented processes an agent's controls can attach to.

The constraint that bites hardest here is model-provider dependency: behaviour shifts when a provider ships a new version, and your evidence file has to survive a change you did not schedule.

AIUC-1 and AI compliance programs

An agent certification is one component of a broader AI compliance program, which is where obligations under GDPR, HIPAA, and sector regulators are tracked and mapped down to controls. The certification answers a narrow question about one system; the program answers what the organization owes across all of them.

ISO 42001 sits on the organizational side of that split, specifying an AI management system with governance, risk, and lifecycle requirements. Many buyers ask for both, because the management system shows the practice exists and the agent certification shows it was applied to the thing being purchased.

What does AIUC-1 mean in plain terms?

Think of AIUC-1 as a roadworthiness test for an AI agent. AIUC stands for the Artificial Intelligence Underwriting Company, and the -1 marks this as its first published standard. A vehicle inspection ignores whether the manufacturer's offices are secure and asks whether this car stops, steers, and signals. The standard applies that idea to a support agent.

Lacking something like it, a buyer's only evidence is the vendor's own description of its own product, plus a demo where the vendor picked the questions. With it, someone outside the room has checked the agent against a written list and produced a file you can read.

The tradeoff is that a certificate describes a moment. An agent that passed in March is a different agent in September if the model behind it changed, so the certificate is a reason to keep asking questions.

Common AIUC-1 mistakes

Three patterns account for most of the wasted effort.

The first is treating certification as a procurement checkbox. A certificate collected at signature and filed says little about the agent running six months later, because the behaviour it attested to came from a model version, a prompt, and a knowledge base that have all since moved.

The second is certifying the demo path. Teams evidence the flows they designed and skip the ones customers invent, so the adversarial test set mirrors the happy path and the first real jailbreak arrives from a user.

The third is buying controls with no owner. Guardrails, logging, and escalation thresholds decay when nobody is accountable for reviewing them, and the decay is silent: the agent keeps answering, just less safely. Building trustworthy support automation depends on someone reading those logs weekly, which is the unglamorous part that actually holds.

Frequently Asked Questions

What does AIUC stand for?

AIUC stands for the Artificial Intelligence Underwriting Company, the organization that publishes the standard. The "-1" identifies this as its first published certification standard for AI agents. In writing, the full form appears on first mention and the short form AIUC-1 is used afterwards, including in procurement documents and vendor security questionnaires.

Is AIUC-1 the same as SOC 2 Type II?

AIUC-1 and SOC 2 Type II attach to different objects. SOC 2 Type II is an auditor's report on whether a service organization's security controls operated effectively over a review period. AIUC-1 certifies an AI agent against a published catalogue spanning safety, security, reliability, privacy, and accountability. Read both scope statements directly before assuming either covers the other.

AIUC-1 vs ISO 42001: which one does a buyer need?

AIUC-1 certifies the agent; ISO 42001 certifies the management system around it, covering governance, roles, risk process, and lifecycle discipline. A buyer worried about how one deployed agent behaves wants the agent-level certification. A buyer assessing whether a company can govern AI generally wants the management system standard. Regulated procurement teams commonly request both.

Who publishes AIUC-1?

AIUC-1 is published by the Artificial Intelligence Underwriting Company. The standard is insurance-backed, which means conformance is tied to financial coverage as well as to documentation. For buyers, that structure matters during vendor review, because the party defining the controls also carries exposure when a certified agent behaves badly in production.

Does AIUC-1 apply to customer support chatbots?

AIUC-1 applies to AI agents, and a support agent that retrieves policy, calls internal systems, and takes actions on customer accounts falls squarely in scope. A purely scripted decision-tree bot with no model-generated output raises fewer of the questions the standard addresses, though it still sits inside general security and privacy obligations.

What should a buyer ask a vendor claiming AIUC-1 certification?

Ask which agent version was certified, when, and against which release of the control catalogue. Ask what changed since, including model versions and prompt updates. Ask to see the adversarial test set and the incident log. A certification that cannot be tied to the deployment you are buying tells you very little.

Learn More

Learn More