Skip to main content

Elevate

AI Governance · AIUC-1

AIUC-1: Prove Your AI Agents Behave Under Pressure

AIUC-1 Readiness for Organizations Building or Deploying AI Agents

AIUC-1 certification has two halves: an audit of your controls and adversarial testing of the agent itself. Most firms can prepare you for one. Elevate runs a GRC practice and a penetration testing practice under one roof, so the controls hold up under audit and the agent holds up under attack.

THE STANDARD

What AIUC-1 is, and why it is different

AIUC-1 was created by the Artificial Intelligence Underwriting Company and developed with Orrick, Stanford, the Cloud Security Alliance, MIT, and MITRE. It is positioned as a SOC 2 for AI agents: an independently audited certification rather than a self-declared framework.

A certification standard written for agents

UiPath became the first enterprise automation platform to certify on March 9, 2026. Cursor, Harvey, Lovable, ElevenLabs and Fin have followed, and the standard now sits in the Cloud Security Alliance STAR Registry. Procurement teams can require third-party certification before an agent is deployed, and the ones that have seen those announcements are starting to.

Buyers have started asking for it

AIUC-1 is not a one-time audit. The standard is revised quarterly, and certified agents go back through technical evaluation each quarter. A readiness program built against one release has to be checked against the current one, and every model update, new tool or new channel is a fresh surface for the next round of testing.

Certification testing recurs every quarter

Management-system standards such as ISO 42001 examine whether the right safeguards exist and operate. AIUC-1 adds mandatory technical evaluation of the agent’s behavior under adversarial conditions. UiPath’s agents were tested across more than 2,000 enterprise risk scenarios alongside an audit of its policies and guardrails.

It tests the agent, not only the organization

UiPath held ISO/IEC 42001 before pursuing AIUC-1. The two answer different questions: ISO 42001 validates that the governance system is in place, AIUC-1 validates that the agents behave safely in real conditions. Organizations with an AI management system already have part of the foundation.

It complements ISO 42001 rather than replacing it

AI AGENT GOVERNANCE

Why agents need a different kind of assurance

AI agent governance is a different problem from AI model governance. A model produces an output that a person reviews. An agent takes an action: it calls a tool, moves data, sends a message, or changes a record, often without a human reviewing each step. The risk moves from what the system says to what the system does.

That shift is why frameworks built for models leave a gap when applied to agents. Governance documentation can describe the intended boundaries of an agent perfectly and still say nothing about whether the agent respects them when someone tries to push it past them. AIUC-1 closes that gap by requiring evidence of behavior, not only evidence of design.

SIX DOMAINS

What AIUC-1 covers

The standard organizes its requirements across six domains, each covering a distinct category of risk that agents introduce. The domains map directly to the questions an enterprise buyer asks when evaluating an agent vendor.

Data and privacy

Domain A

How the agent handles the data it can reach: what it accesses, what it retains, what it can expose, and whether it stays inside the boundaries the organization set.

Security

Domain B

Resistance to attack, including prompt injection, jailbreaking, tool misuse, and attempts to turn the agent against the systems it is connected to.

Safety

Domain C

Whether the agent refuses actions it should refuse, and whether harmful outputs are prevented rather than only detected after the fact.

Reliability

Domain D

Consistency of behavior across conditions, including error prevention and the handling of hallucinations before they become actions.

Accountability

Domain E

Who owns the agent, what records exist of its actions, and whether a decision it made can be traced and explained after the fact.

Society

Domain F

Broader effects of the agent’s deployment beyond the organization that runs it.

AI AGENT COMPLIANCE

Where AIUC-1 connects to what you already run

AIUC-1 publishes crosswalks to ISO/IEC 42001, the NIST AI Risk Management Framework, the EU AI Act, MITRE ATLAS, and the OWASP guidance for agentic applications. An organization already carrying one of those does not start from zero, and the readiness work should reuse existing evidence rather than rebuild it.

Scope and applicability

Establish which agents are in scope, what they can access, and what actions they can take. Agent inventory is the step most organizations get wrong, because agents built into procured tools are rarely catalogued as agents.

Controls gap assessment

Assess organizational controls against the current AIUC-1 version across all six domains, reusing evidence from ISO 42001, NIST AI RMF, or SOC 2 where the published crosswalks allow it.

Adversarial pre-testing

Test agent behavior before the certification testing does: adversarial prompting and jailbreaking, channel testing across voice, SMS, and media, data leakage testing, and output sanitization with downstream risk analysis. Elevate has delivered more than 500 penetration tests, including AI and LLM testing for FedRAMP engagements.

Remediation support

Close control gaps and behavioral failures in sequence, prioritizing the findings that would fail certification rather than the ones that are easiest to fix.

Evidence preparation

Organize control evidence and testing results in the form an independent auditor expects, so the certification engagement tests a prepared environment rather than discovering one.

Version tracking

Check the readiness position against the current quarterly release before the audit engagement begins, because a gap closed against a superseded version may not be closed at all.

WHY ELEVATE

AIUC-1 readiness needs two practices, and most firms have one

The controls half of AIUC-1 is GRC work: policies, ownership, records, evidence, crosswalks to ISO 42001 and NIST AI RMF. The testing half is offensive security work: prompt injection, jailbreaking, tool misuse, data leakage, attacks across voice, SMS and media channels. A GRC firm can prepare the first and hand you off for the second. A testing firm can break the agent and leave you to explain the findings to an auditor.

Elevate runs both, and the handoff between them is where readiness programs usually lose weeks. A finding from adversarial pre-testing goes straight into the control that should have prevented it, and the fix is retested by the same team that found the failure.

500+ penetration tests delivered

Including AI and LLM testing on FedRAMP engagements, which is the closest existing discipline to the adversarial evaluation AIUC-1 requires.

ISO 42001 practice in house

If you already hold ISO 42001, or are building toward it, the management system evidence maps into AIUC-1 through the published crosswalks instead of being rebuilt.

ENGAGEMENT PHASES

How the work runs

Identify every agent in scope, including those embedded in procured platforms, and document what each can access and what actions it can take. Scope decides cost, and it decides what the certification actually covers.

Agent inventory and scope

Assess organizational controls across the six domains against the current version, mapping existing ISO 42001, NIST AI RMF, or SOC 2 evidence through the published crosswalks.

Controls gap assessment

Run the agent through the kinds of attacks certification testing will apply, before the certification testing applies them. Failures found here are cheap; failures found during the audit are not.

Adversarial pre-testing

Close control and behavioral gaps, retesting agent behavior after each material fix rather than assuming the fix held.

Remediation

Assemble control evidence and testing results for the independent auditor, confirmed against the current quarterly release.

Evidence and audit preparation

Support the organization through the independent certification engagement. Elevate prepares; the certification itself is performed by an independent auditor.

Certification support

THE READINESS CALL

What the AIUC-1 readiness call produces

Thirty minutes, no cost, and you leave with four things rather than a proposal to read later.

Which agents you run, including the ones embedded in procured platforms that nobody has catalogued as agents. Scope decides cost, and it decides what the certification covers.

A first cut of your agent inventory

If you hold ISO 42001 or SOC 2, or work against NIST AI RMF, we tell you which AIUC-1 domains that evidence already reaches and which ones start from zero.

How much of your existing evidence carries over

Based on what the agent can access and what actions it can take, the attack surfaces the adversarial evaluation will go after first, so pre-testing starts in the right place.

Where your agent is most likely to fail testing

What has to happen before pre-testing, what the remediation loop looks like, and when an independent audit engagement makes sense to book.

A realistic sequence

Who you meet. The call is run by Elevate’s AI governance practice, led by Angela Polania, who holds CISA, CISM and CRISC and is an ISO 42001 Lead Auditor, with Elevate’s penetration testing team on the adversarial side. You do not have to track which AIUC-1 release is current. We track it.

500+

Penetration tests delivered

+18

Years in cybersecurity and compliance
 

500+

Clients served across industries

100%

Audit pass rate

WHO THIS IS FOR

Roles Elevate works with on this standard

AI risk work in financial services crosses functions that do not usually share a reporting line. These are the roles Elevate works with most often.

GET STARTED

Find out where your agent fails before the certification testing does

Failures found in pre-testing are cheap. Failures found during the audit are not. Thirty minutes and you leave with an agent inventory, the evidence that carries over, and the attack surfaces to test first.

QUESTIONS

Common questions

What is AIUC-1?

AIUC-1 is a certification standard for AI agent security, safety, and reliability, created by the Artificial Intelligence Underwriting Company and developed with Orrick, Stanford, the Cloud Security Alliance, MIT, and MITRE. It combines an audit of an organization’s controls with adversarial technical testing of the agent itself, and it is often described as a SOC 2 for AI agents.

How is AIUC-1 different from ISO 42001?

They answer different questions. ISO/IEC 42001 certifies that an organization has an AI management system in place: the policies, roles, risk processes, and review cycles that govern AI. AIUC-1 certifies that specific AI agents behave safely and securely when tested, including under adversarial conditions. UiPath held ISO 42001 before pursuing AIUC-1, which is a common sequence because the management system supplies part of the foundation.

Who has achieved AIUC-1 certification?

UiPath became the first enterprise automation platform to certify, on March 9, 2026, after an independent audit. Cursor announced its certification on August 13, 2026 and published the report scope and testing results through its trust portal. Harvey, Lovable, ElevenLabs and Fin have also certified.

What does AI agent governance require that model governance does not?

Evidence of behavior. A model produces an output a person reviews; an agent takes actions, often without a human reviewing each step. Governance documentation can describe an agent’s intended boundaries accurately and still say nothing about whether the agent respects them under pressure. AIUC-1 addresses that by requiring technical testing of the agent, not only documentation of the controls around it.

Does Elevate certify organizations against AIUC-1?

No. Elevate prepares organizations for AIUC-1 certification, and the certification itself is performed by an independent auditor. That separation matters for the same reason it matters in SOC 2: a certification issued by the firm that built the controls would carry less weight with the buyer reading it.

How often does AIUC-1 change?

The standard is versioned quarterly, and requirements are added, revised, and retired between releases. A readiness program should be checked against the current version before the certification engagement begins, since a gap closed against a superseded release may no longer be the gap that matters.