Skip to content

What is AIUC-1 and why it matters for enterprise AI trust

Written by
Jack Limebear
Published

ListenListen to this article

Enterprise AI is maturing. Agents that began as pilots now handle customer conversations, trigger workflows, and act on live business data in production. As enterprises move AI agents into production at this scale, trust, safety, and reliability become critical.

Every transformative technology reaches this point. Payment systems have PCI DSS. Cloud infrastructure has SOC 2. Independent standards are what turned both into systems that businesses deploy without extensive one-off vetting. AI agents are now getting theirs.

The AIUC-1 certification is the world's first security, safety, and reliability standard built specifically for AI agents. Developed by the Artificial Intelligence Underwriting Company (AIUC) with researchers from MIT, MITRE, and Stanford, it gives enterprises an independent benchmark they can use today.

ElevenLabs is the first voice AI company to achieve AIUC-1 certification alongside the AI insurance of agents. Our agents underwent 5,835 technical tests across 14 risk categories, demonstrating robustness for enterprise deployment and unlocking first-of-its-kind insurance coverage for the AI agents our customers deploy.

This guide explains what the AIUC-1 standard covers, how it compares to other compliance frameworks like SOC 2 and ISO 42001, and what the certification process involves.

This guide is for general information and does not constitute legal advice. Requirements depend on your systems, data, and jurisdictions, so confirm your obligations with legal counsel.

Summary

  • AIUC-1 certification is the first independent standard for AI agent security, safety, and reliability focused on specific testing of agents.
  • The framework organizes 51 requirements across six risk pillars, with the underlying controls scoped to each agent's capabilities.
  • AIUC-1 tests agent behavior through thousands of adversarial simulations.
  • ElevenLabs is the first voice AI company to earn AIUC-1 certification with AI Insurance and serves as a Technical Contributor on voice-specific requirements.

What is AIUC-1?

AIUC-1 is an AI agent certification standard created by the Artificial Intelligence Underwriting Company. It verifies that an AI agent implements the technical safeguards, operational controls, and legal policies designed to reduce the risk of unsafe or unauthorized behavior in production. AIUC-1 has six pillars: data and privacy, security, safety, reliability, accountability, and society.

This certification exists because AI agents go beyond the traditional limits that SOC 2 and ISO 27001 anticipated. They access customer data, trigger workflows, consult internal business policies, escalate cases to human agents, and can act autonomously within a framework. With that, the risk for unauthorized tool calls, hallucinations, data leakage, or prompt injection becomes much more significant.

AIUC-1 gives enterprises independent evidence of how an AI agent performs under adversarial conditions with sensitive data. It shows that an agent has been tested against defined security and reliability risks.

Understanding the six pillars of AIUC-1

The AIUC-1 framework consists of 51 requirements and 130 controls, organized into six risk pillars. Of these controls, 65 are mandatory and 65 are optional, depending on the scope of what the agent does.

The six pillars of AIUC-1 cover the full lifecycle of an AI agent deployment and are as follows:

  • Data and privacy: The first pillar of AIUC-1 aims to protect against data leakage, training on user data without consent, and IP leakage. Its full requirements extend across establishing an input and output data policy, limiting AI agent data access, protecting IP and trade secrets, preventing cross-customer data exposure, and safeguarding against PII leakage, IP violations, and the exposure of credentials or secrets. For more information on how to demonstrate conformance with each part of the AIUC-1 data and privacy requirements, consult the official page.
  • Security: Aims to protect against adversarial attacks like prompt injections and jailbreaks, as well as unauthorized tool calls. Requirements include third-party adversarial robustness testing, prevention of unauthorized agent actions, user access controls, protection of the deployment environment, and safeguards against AI endpoint scraping and probing.
  • Safety: Reduces the risk of harmful AI outputs and brand risk through safeguards and monitoring. The main requirements include a documented risk taxonomy, pre-deployment testing, and controls against harmful outputs (such as bias, deception, high-risk advice, and offensive content). The safety pillar of AIUC-1 also covers out-of-scope outputs and the escalation of high-risk outputs to humans for review.
  • Reliability: Aims to prevent hallucinations and unreliable tool calls to connected business systems. There are only four subsections to this principle, spanning safeguards against hallucinated outputs, restrictions on unsafe tool calls, and third-party testing for both of these protections.
  • Accountability: Assigns accountability and enforces oversight. Requirements in this pillar include three distinct AI failure plans, vendor due diligence on upstream providers, activity logging, data processing, and disclosure mechanisms that tell users when they’re speaking to AI.
  • Society: Reduces the risk of AI causing societal harm through cyberattacks or other security risks. This category has two components, AI cyber misuse and catastrophic misuse, both of which implement guardrails to reduce the risk of the system being put to nefarious use.

The specific requirements a model has to comply with also depend on its capabilities. For example, there are set requirements for voice generation, automation, code generation, or text generation models, meaning a voice agent is tested against voice-specific risks rather than a generic checklist.

A system will undergo thousands of adversarial simulations to achieve AIUC-1 certification. Each of these simulations is modeled on a real-world AI incident, with the standard constantly being refreshed to test models against the most recent threats in AI research.

What is AIUC-1 and what are its six risk pillars: data privacy, security, safety, reliability, accountability, and society.

How AIUC-1 fits into enterprise AI risk management

AIUC-1 may complement existing certifications. It tests for agent-specific risks that frameworks like ISO 42001, the NIST AI RMF, the EU AI Act, MITRE ATLAS, and the OWASP Top 10 for LLM applications weren’t built to cover, such as prompt injection, unauthorized tool calls, and agentic data exfiltration.

For risk teams, the standard also produces quantified pass/failure rates across defined risk categories. Major risks related to AI deployment are quantified and measured. This gives enterprises a documented basis for assessing AI deployment risk.

At the ElevenLabs Summit in London, ElevenLabs' Marco Mancini presented our vision for AI agent security: what it takes to deploy AI systems at scale, the risks involved, and how independent standards can support trust in AI agents.

marco mancini

The session sets out the thinking behind our decision to pursue AIUC-1 certification first among voice AI companies, and how testing, insurance, and standards work together to reduce risk in enterprise deployment.

Comparing AIUC-1 to other compliance frameworks

AIUC-1 sits alongside a handful of other frameworks enterprises use to evaluate vendors, although not all of them are AI-specific. Each tackles a different set of questions.

Here is what each framework validates and how enterprises use it:

What it validates
AIUC-1
AI agent security, safety, and reliability in production
SOC 2
Organizational controls for data security
ISO 42001
AI management systems and governance
NIST AI RMF
Voluntary risk management practices
Scope
AIUC-1
Agent-specific: prompt injection, hallucinations, tool misuse, data leakage
SOC 2
Infrastructure and processes, not AI behavior
ISO 42001
Policies, leadership review, documentation
NIST AI RMF
Internal risk architecture, no certification
Cadence
AIUC-1
Quarterly retests, annual re-audit
SOC 2
Annual, point-in-time or period review
ISO 42001
Annual surveillance, three-year cycle
NIST AI RMF
Guidance, not audited

In plain language, SOC 2 tells an enterprise buyer that a vendor's infrastructure was secure over a historical review period, while AIUC-1 shows that an AI agent is tested against real-world attack vectors. They work together to provide infrastructure-wide security, but AIUC-1 deliberately avoids duplicating the work you’ll already have done for SOC 2 or ISO 27001.

Another factor that sets AIUC-1 apart is its accreditation mechanism. The AIUC accredits AIUC-1 auditors and then pairs the audit with its own technical testing.

What the AIUC-1 certification process looks like

AIUC-1 certification typically takes between four and eight weeks, depending on how mature an organization’s existing guardrails and AI safeguards are. 

The certification process moves through four distinct stages:

  1. Gap assessment: The first stage audits an AI platform to determine what scope its agents have, what existing policies they use, what technical documentation they have, and what safeguards they use. This scoping and kick-off stage identifies all initial gaps to test and is where you sign a certification contract.
  2. Remediation: Next, your organization will address all gaps in any guardrails, legal policies, or technical implementations you have. This fixes any initial gaps identified and allows you to proceed to the technical testing stage.
  3. Technical evaluation: AIUC runs adversarial testing against your production system, probing for hallucinations, prompt injection opportunities, data leakage, unsafe tool calls, harmful outputs, or unsafe practices. 
  4. Certification audit: Based on your agents' performance in stage 3, an auditor will independently evaluate all evidence and then decide whether to issue the AIUC-1 certification.

By the end of the audit process, organizations get:

  • A comprehensive audit report with a full breakdown of results
  • The AIUC-1 certificate (upon passing)
  • The AIUC-1 badge to display on sales or marketing collateral (upon passing)

How long does an AIUC-1 certification last?

The AIUC-1 certification is valid for 12 months, but is not a one-time snapshot of company security measures. Technical tests run on AI agents quarterly, with all full technical and legal controls being re-audited annually. Based on new research emerging or distinct AI-based threat vectors appearing, the AIUC may update the standard each quarter and certify agents against the new threat landscape.

Which industries are watching AIUC-1 certification?

AIUC-1 is a voluntary standard but one that’s being used by enterprises to evaluate AI agent providers on reliability, security, and safety. 

A few industries are paying attention to AIUC-1 certification:

  • Healthcare: Agents that handle PII or other sensitive data benefit from explicit, independently tested safeguards against leakage and hallucinations.
  • Enterprise SaaS: Enterprise vendors adding AI agent capabilities may find AIUC-1 certification appearing in buyer security questionnaires and vendor requirements.
  • Insurance: Carriers that deploy agents to handle customer policy and claims conversations want confidence that their AI systems deliver accurate information, reducing the risk of underwriting exposure.
  • Financial services: Banks and fintechs deploying voice and chat agents face strict obligations around data handling and auditability. Our AI agent playbook for financial services covers how certified platforms can support these deployments.

There is a reason that employees at nearly 70% of Fortune 500 companies use ElevenLabs. ElevenLabs' AIUC-1 certification gives enterprise buyers independent evidence of how our agents perform under adversarial conditions.

Get started with ElevenAgents

ElevenAgents is the first voice AI platform to achieve AIUC-1 certification, and ElevenLabs serves as a Technical Contributor to the standard, helping to shape voice-specific security requirements. The platform also holds SOC 2 Type II and is certified as a PCI DSS Level 1 service provider, the highest of the four PCI DSS compliance levels.

The certification path extends to customers. Because AIUC-1 requirements are integrated into the platform, companies building on ElevenAgents start with up to 75% of certification requirements already met, and typically achieve full certification in four weeks. Immobiliare.it, Italy’s largest real estate platform, certified its 24/7 property inquiry voice agent in four weeks, with less than two hours of engineering time needed to configure testing.

Sign up for ElevenLabs to build your first agent, or contact sales to discuss compliant enterprise deployment. 

Frequently asked questions about AIUC-1 and AI compliance

Similar articles

Create with the highest quality AI Audio