AIUC-1 in the context of an AI governance programme
As organisations increase their adoption of Agentic AI systems (e.g. AI agents that retrieve data, call tools, take actions and interact with customers with a degree of autonomy), questions from key stakeholders (including enterprise buyers) are less about having an AI policy and governance documentation and more about "does this agent actually do what the policy says, and can you prove it?"
This is an assurance question that is addressed by AIUC-1, published by the Artificial Intelligence Underwriting Company (AIUC). AIUC-1 is one of the first standards built specifically to address AI agent security, safety and reliability. Understanding what it covers, and what it does not, is key to positioning it correctly within an AI governance programme.
What AIUC-1 Is
AIUC-1 is a standard organised around six principles and covering agentic security, safety and reliability. As of the July 2026 release, these contain 51 active requirements, 43 mandatory and 8 supplemental:
- Data & Privacy: Input and output data policies, limiting agent data access, preventing PII, IP, credential and cross-customer data leakage.
- Security: Third-party adversarial robustness testing, adversarial input detection, real-time input filtering, preventing unauthorised agent actions, protecting the deployment environment.
- Safety: AI risk taxonomy, pre-deployment testing, preventing harmful and out-of-scope outputs, flagging high-risk outputs for human review, real-time feedback and intervention, third-party testing.
- Reliability: Preventing hallucinated outputs, restricting unsafe tool calls, and third-party testing of both.
- Accountability: AI failure plans (security breaches, harmful outputs, hallucinations), assigned accountability, vendor due diligence, acceptable use policy, activity logging, AI disclosure mechanisms, regulatory compliance documentation, and a supplemental quality management system.
- Society: Preventing AI cyber misuse and catastrophic misuse.
Three key items regarding the scope of the AIUC-1 standard:
- The unit of certification is the agent, not the organisation. Scoping defines which agentic AI systems are in scope, and the resulting certificate is "typically limited to specific product(s), not the full organization's products and practices." Non-agentic systems are out of scope.
- Technical testing is a requirement, not an option. Certification combines evidence across legal policies, operational practices and technical implementation with third-party evaluations: red-teaming and testing for hallucinations, unsafe tool calls, harmful outputs and adversarial attacks.
- Assurance is continuous rather than annual. The certificate is valid for 12 months, but agents must be submitted for red-teaming every quarter to keep it valid. The standard itself is updated quarterly (15 January, April, July and October), and audits are generally conducted against the latest version.
Not every requirement applies to every agent. Each requirement is either mandatory or supplemental (opted into where relevant to the agent's capabilities, architecture and deployment context), each comes with core and supplemental controls, and the auditor signs off a Statement of Applicability that defines exactly what a given agent is audited against.
Organisations familiar with ISO/IEC 42001 will recognise the logic.
Where AIUC-1 Sits in the AI Governance Stack
In our article on the AI governance stack, we grouped AI governance into two clusters: Strategic Oversight (legal liability and executive accountability, organisational governance, procurement and contractual governance) and Operational Execution (product conformity and societal impact, technical and model governance, data and IP rights).
AIUC-1 sits in the Operational Execution cluster, with selected reach into Strategic Oversight:
| AI Governance Stack Layer | AIUC-1 Coverage | Illustrative AIUC-1 Requirements |
|---|---|---|
| Legal Liability & Executive Accountability | Limited | E004 Assign accountability, E012 Document regulatory compliance |
| Organisational Governance | Partial | E010 AI acceptable use policy, E017 System transparency policy, E008 Review internal processes |
| Procurement & Contractual Governance | Partial | E006 Conduct vendor due diligence, E009 Monitor third-party access |
| Product Conformity & Societal Impact | Partial | C001 AI risk taxonomy, C003–C005 Prevent harmful, out-of-scope and high-risk outputs, F001–F002 Societal misuse |
| Technical & Model Governance | Strong | B001–B010 Security controls, C010–C012 and D002, D004 Third-party testing, E015 Log AI system activity |
| Data & IP Rights | Strong | A001–A008 Data & Privacy controls |
AIUC-1 is narrow and deep: it tests whether controls at the operational layers actually hold under adversarial and real-world conditions. It is not concerned with building the organisational management system that decides which agents should exist, for what purpose, under whose authority and with which objectives. In that sense, it fits nicely and is complementary with existing frameworks such as ISO/IEC 42001.
AIUC-1 and ISO/IEC 42001
AIUC frames the relationship directly: "ISO 42001 focuses on establishing AI governance frameworks and management systems, while AIUC-1 focuses on validating the robustness of safeguards through independent technical testing." Its crosswalk states that AIUC-1 incorporates the majority of ISO/IEC 42001 controls, translates the management system approach into concrete, auditable requirements, and extends it with third-party testing and AI failure plans.
| ISO/IEC 42001 Area | Crosswalk Status | Why It Matters |
|---|---|---|
| 4.2 Interested parties | Full Gap | Who your AI governance serves, and what they require, is outside AIUC-1 scope |
| 6.2 AI objectives | Full Gap | AIUC-1 does not require high-level AI objectives |
| 7.3 Awareness | Full Gap | Internal training is outside AIUC-1 scope |
| A.6.1.2–A.6.1.3 Responsible AI objectives and design processes | Full Gap | AIUC-1 does not require documented responsible AI objectives or processes |
| A.10.4 Customers | Full Gap | No specific requirements on customer expectations and needs |
| 6.1.4, 8.4, A.5.2–A.5.5 AI system impact assessment | Partial Gap | AIUC-1 requires risk assessment, "but does not require impact assessment specifically" |
| 7.2 Competence, 9.3.2–9.3.3 Management review | Partial Gap | Accountability is assigned, but competence and full management review are not required |
| 6.1.2–6.1.3, 8.2–8.3 Risk assessment and treatment | No Gap | Met through C001 AI risk taxonomy and C008 Monitor AI risk categories |
| A.6.2.4 Verification and validation | No Gap | Met through pre-deployment and third-party testing (C002, C010–C012, D002, D004) |
| A.6.2.8 Event logs, A.8.4 Communication of incidents | No Gap | Met through E015 activity logging and E001–E003 AI failure plans |
ISO/IEC 42001 establishes the system that governs AI across the organisation. AIUC-1 generates strong, independently tested evidence that specific agents perform as that system intends. In ISO/IEC 42001 terms, AIUC-1 is an excellent source of evidence for verification and validation, operation and monitoring, event logging and incident communication.
AIUC-1 and the EU AI Act
AIUC positions AIUC-1 as operationalising the EU AI Act. It claims that being AIUC-1 certified is "a strong step towards compliance" that:
- Enables compliance for minimal and limited risk systems.
- Enables compliance for high-risk systems "only if specific control activities are met".
- Provides documentation for internal conformity assessments for high-risk systems as required in Annex VI.
The crosswalk is also explicit that it "is provided for informational purposes only and does not constitute legal advice."
At a glance:
- Article 14 (Human Oversight) maps to a single requirement, C009 Enable real-time feedback and intervention, which is supplemental rather than mandatory. Human oversight under the Act is a design obligation covering the ability to understand, monitor, interpret, override and stop a high-risk system. A feedback and intervention mechanism is part of that, not the whole of it.
- Article 10 (Data and Data Governance) maps only to E013 Implement quality management system, which is also supplemental.
- Article 17 (Quality Management System) maps to E004 Assign accountability, E013 and E007. E007 has since been retired and merged into E004, and E013 was revised in January 2026 "to simplify the requirement while fulfilling EU AI Act Article 17". Unless E013 is in scope, the mandatory coverage of Article 17 rests on accountability assignment alone.
- Article 27 (Fundamental Rights Impact Assessment) maps to C002 Conduct pre-deployment testing. Testing an agent's outputs across risk categories and assessing its impact on the fundamental rights of the people it affects are different exercises, which is consistent with the impact assessment gap the ISO/IEC 42001 crosswalk identifies.
- Articles 43, 44, 47, 48 and 49 (Conformity assessment, certificates, declaration of conformity, CE marking, registration) map to E012 Document regulatory compliance. Documenting that an obligation applies is not the same as having discharged it.
- Article 46 (Derogation from conformity assessment) has no mapped requirement.
It is important to remember that AIUC-1 scopes by agent, whereas the EU AI Act classifies by use case, and the same agent can be minimal risk in one deployment and high-risk in another (AIUC's own scoping guidance gives the example of an AI recruitment system). And AIUC-1 is not a harmonised standard under the Act, so certification does not confer a presumption of conformity in the same way an EN 18286 QMS implementation potentially could in the future.
Positioning AIUC-1 Within an AI Governance Programme
Following the decision logic of the AI governance stack, the Legal Liability & Executive Accountability layer determines which frameworks are required. AIUC-1 then answers a specific question at the operational layers. In practice, its role differs by organisation:
- Providers of AI agents selling into the enterprise: AIUC-1 directly addresses the question enterprise security and procurement teams increasingly ask. Paired with ISO/IEC 42001, it gives buyers both an organisational assurance (the management system) and a system-level assurance (the tested agent).
- Deployers of third-party AI agents: AIUC-1 is a useful procurement and due diligence instrument (Procurement & Contractual Governance layer). Ask for the audit report rather than the badge, and check three things: which agents and versions are in scope, the Statement of Applicability (in particular whether supplemental requirements relevant to your use case, such as C009 human intervention or E013 quality management, were included), and whether quarterly testing is current.
- Organisations with high-risk use cases under the EU AI Act: AIUC-1 can provide meaningful evidence for risk management, logging, robustness and post-market monitoring. But the obligations it maps thinly (human oversight design, data governance, fundamental rights impact assessment, conformity assessment itself) need to be delivered and evidenced through the wider programme.
- Organisations with an existing ISO/IEC 42001 AIMS: AIUC-1 is a natural extension for the highest-risk agents in the AI system inventory, strengthening the evidence behind Annex A controls on verification and validation, operation and monitoring, and incident communication, and turning point-in-time testing into a quarterly cadence.
Conclusion
AIUC-1 reflects a genuine shift in what AI governance must demonstrate. Management systems establish intent, accountability and process. AI agents, however, are probabilistic systems that change with every model update, prompt revision and new tool integration, and the gap between what the policy says and what the agent does is exactly where enterprise risk materialises.
Positioned within a layered governance programme, AIUC-1 helps close that gap:
- Selecting Frameworks and Standards: AIUC-1 is not an alternative to ISO/IEC 42001 or the EU AI Act, but a system-level assurance layer that sits on top of them.
- Implementing Effective Controls: Its requirements translate high-level mandates into testable controls at the operational layers, and its quarterly testing cadence turns controls from documented into demonstrated.
- Selecting AI and Agentic GRC Tools: Its evidence categories (legal policies, operational practices, technical implementation and third-party evaluations) provide a clear specification for the tooling needed to produce continuous, audit-ready evidence at agent level.
Ultimately, a policy states what an agent should do. A management system ensures someone is accountable for it. Independent testing shows what the agent actually does. A mature AI governance programme needs all three, and the organisations that can connect them will be the ones able to answer the question their stakeholders, customers and regulators, are now starting to ask.
Sources: AIUC-1 standard (July 15, 2026 release), certification documentation and changelog (standard.aiuc-1.com), AIUC-1 × ISO 42001 crosswalk (last updated 18 September 2025), AIUC-1 × EU AI Act crosswalk (last updated 22 July 2025). Reviewed 24 September 2026. This article is for information purposes and does not constitute legal advice.