05 — frameworks & standards

AIUC-1

Also written Artificial Intelligence Underwriting Company

The certification standard for AI agents published by the Artificial Intelligence Underwriting Company. Six pillars — data & privacy, security, safety, reliability, accountability and society — carry 51 active requirements, each decomposing into numbered controls such as A008.1 to A008.5. Two things separate it from ISO/IEC 42001 and the NIST AI RMF: the agent itself is put through adversarial testing rather than only the organisation’s paperwork, and that testing repeats at least quarterly to keep a twelve-month certificate alive. Requirements are scoped by capability, and the Q3 2026 release added mandatory ones for code-generating agents — A008 on secrets and B010 on secure generated code. Worth knowing before you weigh the certificate: AIUC publishes the standard, accredits the auditors, is currently the only technical testing body, issues every certificate and sells the matching insurance.

Related terms

  • ISO/IEC 42001 Frameworks & standards

    The certifiable management-system standard for artificial intelligence — the AI equivalent of ISO 27001.

  • NIST AI RMF Frameworks & standards

    The US National Institute of Standards and Technology's voluntary AI Risk Management Framework, organised around four functions — Govern, Map, Measure…

Frameworks & standards

What auditors, buyers and regulators reference. See the compliance crosswalk for the control-by-control mapping.

AIUC-1 is term 8 of 8 in this part of the glossary.

Get started free Full glossary → How we test → Community agent on GitHub ↗

This page is one entry from the agentic AI security glossary, which defines 60 terms in the same style. Where a term belongs to a published taxonomy or standard — the HackAgent attack families, the OWASP lists, AMTSO's guidelines, MITRE ATLAS, ISO/IEC 42001, the NIST AI RMF, the EU AI Act — the authoritative wording is the source document's, not ours, and specifics should be verified there. "Lethal trifecta" is Simon Willison's term. OWASP® is a trademark of the OWASP Foundation; ATT&CK® and ATLAS™ are trademarks of The MITRE Corporation. Naming a framework here is description, not a claim of certification or endorsement.

glick.run — AGPL-3.0