AI Agent Certification: What AIUC-1 Actually Proves
Do I need an AI agent audit? If you buy or deploy agents that touch your data, ask for evidence, not a badge. AIUC-1 — the standard its own company markets as the “SOC 2 for AI agents” — is a third-party report on how one agent behaved against a defined scenario set at a point in time. Worth reading; not proof your deployment is safe.
What is AI agent certification?
An outside firm examines an agent against a written standard and reports what it found, so the vendor cannot grade its own homework. The limit is scope: the firm only sees what was put in it. AIUC-1, launched on 17 July 2025, is a security, safety and reliability standard across six areas — data and privacy, security, safety, reliability, accountability and society — requiring more than 50 safeguards plus third-party testing, and shaped by more than 250 security and risk leaders at Fortune 1000 companies per the company’s current materials (AIUC; the standard’s site).
The AIUC-1 standard: what it actually tests
The tests are adversarial, not documentary. AIUC says certification runs an agent through risk-and-attack scenarios in three classes. A jailbreak makes an agent ignore its own rules; the dangerous version is indirect, hidden in content it was asked to read. A hallucination is confident output that is not true — worse for an agent than a wrong answer, because the wrong answer can be acted on. A data leak is information leaving through a prompt, a tool call or an over-broad permission.
Scale is a range: the funding release cites 5,000 combinations tailored to the business type, the standard’s own site says red-teaming “typically involves 1,000 to 5,000 test scenarios”, and published audits ran 900+ (KPMG) and, from a single outlet, 2,000+ (UiPath). The tests are buyer-defined: AIUC asks its consortium, not vendors.
Is AIUC-1 the “SOC 2 for AI agents”?
That is the company’s framing: marketing language, not technical equivalence. AIUC’s table puts an “audit report with certificate” for AIUC-1 against an “attestation report” for SOC 2, both displayed for 12 months, and contrasts AIUC-1’s forward-looking adversarial tests with SOC 2’s backward-looking assessment. AIUC also says AIUC-1 “does not duplicate the work of non-AI frameworks like SOC 2, ISO 27001, or GDPR”. Not regulator-endorsed; no law requires it.
What a 100-page audit report proves, and what it does not
TechCrunch reports that AIUC’s testing produces a roughly 100-page report on where an agent performs safely and reliably, and where it does not. Read it as evidence of tested behaviour on a defined scenario set at a point in time: not a guarantee the agent never fails, and not coverage of your configuration or data — Cursor’s certification ran against its key product surfaces on a representative configuration, not your deployment. A material finding produces a qualified or adverse report and re-testing.
How often should AI agents be audited?
Quarterly technical testing under a 12-month certificate: the term is 12 months, operational controls are reviewed annually, testing and retesting happen at least quarterly, and the standard is revised quarterly — 1 January, 1 April, 1 July, 1 October. The funding release compresses that to “independently audited and recertified every quarter”; the annual renewal is what keeps the mark valid. A certificate issued last year describes last year’s configuration. This site treats an audit as a loop: see the step-by-step agent security assessment and the AI agent risk checklist.
Who audits the auditor’s automation?
The recursion problem is stated, not hidden: AIUC uses AI agents to run the tests and AI to analyse the data, with humans verifying the audit. That is the same question this site raises about agents gaming their own benchmark scores — any automated evaluator becomes something to be optimised against — and about agents running code nobody wrote, where the toolchain performing the check is itself attack surface.
Who is certified today, and what to do if your vendor is not
TechCrunch names four: Cursor, Lovable, Harvey and ElevenLabs. KPMG LLP, UiPath and Fin (formerly Intercom) appear in the company’s own materials; KPMG’s covers one platform, aiQ Capture, the first Big Four capability certified. Schellman became the first authorised AIUC-1 auditor on 3 February 2026. If your vendor is not listed, ask for the report anyway, then scope, date and re-test schedule — not a logo. ElevenLabs certified at launch and used it for what AIUC calls first-of-its-kind agent insurance.
AI agent insurance vs certification: three different things
Certification, insurance and a warranty transfer different things: a certificate is evidence, a policy is financial protection, a warranty is a promise enforceable between the parties.
| AIUC-1 certification | Self-attestation | Insurance | |
|---|---|---|---|
| What it is | A report plus a 12-month certificate | The vendor’s own statement, its own criteria | A policy that responds after a loss |
| What it evidences | Tested behaviour on a defined scenario set, at a point in time | That the vendor says it did the work | Nothing about how the agent behaved |
| What it does not cover | Your configuration and data | Anything the vendor chose not to test | Whether a loss is a covered claim |
Coverage is separate: see what current AI agent policies do and do not cover. If an agent of yours touches a third party’s system, the RubyGems agent attack shows why scope and log retention get asked first.
What to ask your agent vendor
When a vendor claims certification, ask which standard, who ran the tests, what was in scope, when it was last run and when it is next due:
- Who ran the tests? Schellman was the first authorised AIUC-1 auditor; the standard’s site also names Coalfire.
- What was in scope? Which product, surfaces and configuration — KPMG’s covers one platform, not the firm.
- Will you share it? A certificate without the report is a logo, not a finding.
Agency buyers: what to demand in the contract.
Questions owners are asking
Do I need an AI agent audit if my vendor is certified?
Yes, a smaller one than the vendor’s. A certificate is evidence about the vendor’s agent on a defined scenario set at a point in time; it does not cover your configuration or data. Yours: what the agent can reach, what is logged, who can stop it.
What is AI agent certification?
An outside firm examines an agent against a written standard and reports what it found, so the vendor cannot grade its own homework. AIUC-1 covers six areas — data and privacy, security, safety, reliability, accountability and society — with more than 50 safeguards plus third-party testing.
What does the AIUC-1 standard test?
Jailbreaks (inputs that make an agent ignore its rules, including indirect ones hidden in content it reads), hallucinations (confident output that is not true) and data leaks (information leaving through a prompt, a tool call or an over-broad permission). Scopes run 1,000 to 5,000 scenarios.
Is AIUC-1 the SOC 2 for AI agents?
That is the company’s framing, not an equivalence. AIUC contrasts its audit report with certificate against SOC 2’s attestation report, and quarterly testing against an annual cycle. AIUC says AIUC-1 does not duplicate SOC 2, ISO 27001 or GDPR.
How often should AI agents be audited?
Under AIUC-1: technical testing and retesting at least quarterly, controls reviewed annually, a 12-month certificate, and a standard revised on 1 January, 1 April, 1 July and 1 October. Treat an audit as a quarterly loop.
Is AI agent insurance the same as certification?
No. A certificate is evidence about tested behaviour; a policy is financial protection after a loss. AIUC says insurers are offering AI-specific coverage to certified agents, and ElevenLabs took agent insurance off its February 2026 certification.
Where a figure is the company’s own claim or single-sourced, this page says so. AIUC-1 is not regulator-endorsed; no law requires it.
Sources
- AIUC, “Introducing AIUC-1”, 17 July 2025, and the AIUC-1 standard site — https://aiuc.com/updates/introducing-aiuc-1 · https://aiuc-1.com/
- AIUC Series A release, PR Newswire, 15 September 2026 — https://www.prnewswire.com/news-releases/aiuc-raises-40m-series-a-from-ribbit--first-harmonic-to-build-confidence-infrastructure-for-frontier-ai-302879036.html
- TechCrunch, 15 September 2026 — https://techcrunch.com/2026/09/15/early-anthropic-hire-former-metr-coo-have-found-a-way-to-rein-in-rogue-ai-agents/
- AIUC updates — https://aiuc.com/updates/aiuc-1-certificate-overview