AIUC-1 compliance,certify your AI agents
AIUC-1 is the AI Underwriting Company's certification standard for organizations that build or deploy AI agents. The July 2026 release defines 51 auditable requirements (43 mandatory, 8 optional) across six pillars — Data & Privacy, Security, Safety, Reliability, Accountability and Society — written to underpin insurance coverage for AI risk and to sit alongside ISO/IEC 42001, SOC 2, the NIST AI RMF and the EU AI Act.
What AIUC-1 asks of you
The requirements below define AIUC-1. ComplyEasyAI maps your environment to each one.
Data & Privacy (A001–A008)
Input and output data policies, limits on what the agent can access, protection of IP and trade secrets, and prevention of cross-customer exposure, PII leakage, IP violations and credential leakage.
Security (B001–B010)
Third-party adversarial-robustness testing, adversarial-input detection and real-time input filtering, controlled release of technical details, endpoint anti-scraping, prevention of unauthorized agent actions, user access privileges, a protected deployment environment, limited output over-exposure and secure patterns in generated code.
Safety (C001–C012)
An AI risk taxonomy, pre-deployment testing, prevention of harmful, out-of-scope and agent-specific high-risk outputs and output vulnerabilities, human review and real-time intervention for high-risk outputs, and third-party testing for harmful, out-of-scope and customer-defined risks.
Reliability (D001–D004)
Prevention of hallucinated outputs, restriction of unsafe tool calls, and independent third-party testing of both hallucinations and tool calls.
Accountability (E001–E017)
AI failure plans for security breaches, harmful outputs and hallucinations; assigned accountability; documented data-storage security; vendor due diligence; internal process reviews; third-party access monitoring; an AI acceptable-use policy; recorded processing locations; a regulatory compliance register; a quality management system; activity logging; AI disclosure and a transparency policy.
Society (F001–F002)
Prevention of AI cyber misuse and of catastrophic misuse, including chemical, biological, radiological and nuclear uplift.
From scoping to a clean report
Scope
Define the systems, boundaries and requirements your program will cover.
Connect your stack
Link cloud, identity, code and ticketing with read-only access; controls are discovered and mapped.
Collect evidence
AI agents gather configuration and activity evidence on a schedule, building a versioned trail.
Monitor & remediate
Continuous monitoring flags drift the moment it happens and routes it to an owner.
Track effectiveness
Operating effectiveness is recorded over time, ready for your observation window.
Report & hand off
Organized, current evidence is packaged for auditors and stakeholders.
Automate the work that doesn’t need a human
Control mapping
Your environment is mapped to each requirement, so you see exactly which control satisfies what.
Automated evidence
Read-only integrations build a versioned, timestamped trail instead of manual screenshots.
Continuous monitoring
Drift surfaces as soon as it happens, not during fieldwork.
Readiness dashboards
Real-time views highlight failing or unmapped controls with owners attached.
Multi-framework reuse
Shared controls are mapped once and reused across every framework you run.
Audit-ready reporting
Export organized, current evidence packages on demand.
Map once, reuse across programs
AIUC-1 questions, answered
Who is AIUC-1 for?
Organizations that build or deploy AI agents — systems that take actions through tools rather than only generating text. The standard is written to be audited and to underpin insurance coverage for AI risk.
How does AIUC-1 relate to ISO 42001 and the EU AI Act?
It complements both: ISO 42001 supplies the management-system backbone and the AI Act the regulatory obligations, while AIUC-1 adds agent-specific requirements such as unsafe tool-call restrictions, adversarial-robustness testing and AI failure plans. Shared controls are mapped once and reused.
Is AIUC-1 a certification?
Yes — it is a certifiable standard assessed against its 51 requirements. ComplyEasyAI's control names reuse the official requirement titles (July 2026 release) and its descriptions paraphrase the public per-requirement summaries; the full auditor-facing text is not published, so confirm details with your auditor before relying on them for certification.
How do you help?
The platform maps each agent to the 51 requirements across the six pillars, flags the 8 optional ones, collects evidence from your AI stack and keeps it continuously audit-ready.
Start your AIUC-1 program.
Map the requirements, automate the evidence, stay audit-ready.