AI Governance

AIUC-1 compliance,certify your AI agents

AIUC-1 is the AI Underwriting Company's certification standard for organizations that build or deploy AI agents. The July 2026 release defines 51 auditable requirements (43 mandatory, 8 optional) across six pillars — Data & Privacy, Security, Safety, Reliability, Accountability and Society — written to underpin insurance coverage for AI risk and to sit alongside ISO/IEC 42001, SOC 2, the NIST AI RMF and the EU AI Act.

Key requirements

What AIUC-1 asks of you

The requirements below define AIUC-1. ComplyEasyAI maps your environment to each one.

01

Data & Privacy (A001–A008)

Input and output data policies, limits on what the agent can access, protection of IP and trade secrets, and prevention of cross-customer exposure, PII leakage, IP violations and credential leakage.

02

Security (B001–B010)

Third-party adversarial-robustness testing, adversarial-input detection and real-time input filtering, controlled release of technical details, endpoint anti-scraping, prevention of unauthorized agent actions, user access privileges, a protected deployment environment, limited output over-exposure and secure patterns in generated code.

03

Safety (C001–C012)

An AI risk taxonomy, pre-deployment testing, prevention of harmful, out-of-scope and agent-specific high-risk outputs and output vulnerabilities, human review and real-time intervention for high-risk outputs, and third-party testing for harmful, out-of-scope and customer-defined risks.

04

Reliability (D001–D004)

Prevention of hallucinated outputs, restriction of unsafe tool calls, and independent third-party testing of both hallucinations and tool calls.

05

Accountability (E001–E017)

AI failure plans for security breaches, harmful outputs and hallucinations; assigned accountability; documented data-storage security; vendor due diligence; internal process reviews; third-party access monitoring; an AI acceptable-use policy; recorded processing locations; a regulatory compliance register; a quality management system; activity logging; AI disclosure and a transparency policy.

06

Society (F001–F002)

Prevention of AI cyber misuse and of catastrophic misuse, including chemical, biological, radiological and nuclear uplift.

How it works

From scoping to a clean report

  1. Scope

    Define the systems, boundaries and requirements your program will cover.

  2. Connect your stack

    Link cloud, identity, code and ticketing with read-only access; controls are discovered and mapped.

  3. Collect evidence

    AI agents gather configuration and activity evidence on a schedule, building a versioned trail.

  4. Monitor & remediate

    Continuous monitoring flags drift the moment it happens and routes it to an owner.

  5. Track effectiveness

    Operating effectiveness is recorded over time, ready for your observation window.

  6. Report & hand off

    Organized, current evidence is packaged for auditors and stakeholders.

How ComplyEasyAI helps

Automate the work that doesn’t need a human

Control mapping

Your environment is mapped to each requirement, so you see exactly which control satisfies what.

Automated evidence

Read-only integrations build a versioned, timestamped trail instead of manual screenshots.

Continuous monitoring

Drift surfaces as soon as it happens, not during fieldwork.

Readiness dashboards

Real-time views highlight failing or unmapped controls with owners attached.

Multi-framework reuse

Shared controls are mapped once and reused across every framework you run.

Audit-ready reporting

Export organized, current evidence packages on demand.

FAQ

AIUC-1 questions, answered

Who is AIUC-1 for?

Organizations that build or deploy AI agents — systems that take actions through tools rather than only generating text. The standard is written to be audited and to underpin insurance coverage for AI risk.

How does AIUC-1 relate to ISO 42001 and the EU AI Act?

It complements both: ISO 42001 supplies the management-system backbone and the AI Act the regulatory obligations, while AIUC-1 adds agent-specific requirements such as unsafe tool-call restrictions, adversarial-robustness testing and AI failure plans. Shared controls are mapped once and reused.

Is AIUC-1 a certification?

Yes — it is a certifiable standard assessed against its 51 requirements. ComplyEasyAI's control names reuse the official requirement titles (July 2026 release) and its descriptions paraphrase the public per-requirement summaries; the full auditor-facing text is not published, so confirm details with your auditor before relying on them for certification.

How do you help?

The platform maps each agent to the 51 requirements across the six pillars, flags the 8 optional ones, collects evidence from your AI stack and keeps it continuously audit-ready.

Start your AIUC-1 program.

Map the requirements, automate the evidence, stay audit-ready.