AIUC-1 readiness

Your AI agent is in production. Can you prove it is controlled?

AIUC-1 is a certification standard built specifically for AI agents — security, safety, reliability, privacy, and accountability controls that enterprise buyers and insurers are beginning to ask for. Cyberneza prepares your organization for AIUC-1 certification and coordinates with the accredited auditor you select. We prepare; the independent audit and AIUC's own technical evaluation decide certification.

Readiness and advisory only · Senior-led delivery · Veteran-owned

The standard

What AIUC-1 is

AIUC-1 is a certification standard for AI agents, published by the Artificial Intelligence Underwriting Company. It gives enterprise buyers a way to evaluate whether an AI agent has appropriate controls across security, safety, reliability, privacy, accountability, and misuse risk — the questions procurement teams are now asking and that a SOC 2 report was never designed to answer.

Certification runs through two independent stages: AIUC performs technical evaluation testing of the agent against adversarial scenarios, and an accredited AIUC-1 auditor independently assesses evidence and submits a certification recommendation — the certificate itself is issued through AIUC. Certificates carry ongoing obligations rather than being a one-time exercise. That structure is deliberately familiar: it works the way SOC 2 and ISO 27001 work, which is exactly why a readiness practice sits in front of it.

Standard details, control criteria, and the current auditor ecosystem are published by AIUC. Requirements evolve; we scope against the criteria in force at the time of your engagement.

Why it matters now

AI agents are being bought like vendors — and reviewed like them

When you ship an AI agent that touches customer data or takes actions on a customer's behalf, you become a vendor with a new risk profile. Enterprise security reviews have caught up: buyers now ask how the agent is constrained, what it can and cannot do, how failures are detected, and who is accountable when it gets something wrong.

Answering those questions with a general security certification is increasingly unconvincing, because the risks are agent-specific. AIUC-1 exists to close that gap, and getting ahead of it is considerably cheaper than retrofitting controls after a deal stalls.

What we do

AIUC-1 readiness support

Control-gap assessment

An assessment of your AI agent and the program around it against the AIUC-1 criteria, with findings tied to specific controls and a prioritized view of what to close first.

Remediation planning

A sequenced plan with owners and effort estimates — covering both the technical controls on the agent itself and the governance around how it is built, changed, and monitored.

Policy & control documentation

The documented program behind the agent: acceptable use, operational boundaries, change management, incident handling, and accountability — written for how your team actually works.

Evidence preparation

Assembling the evidence that demonstrates controls are operating, organized the way an auditor will ask for it rather than reconstructed under deadline.

Auditor coordination

Support through certification with the accredited AIUC-1 auditor you select. We prepare and coordinate; the audit belongs to the independent auditor, AIUC's technical evaluation and certificate issuance belong to AIUC.

Ongoing advisory

AIUC-1 certification carries continuing obligations. Retained advisory keeps controls operating and evidence current across the cycle rather than only at renewal.

How it fits

One AI governance program, not three

AIUC-1 does not stand alone. It overlaps substantially with ISO/IEC 42001 and the NIST AI Risk Management Framework, and it sits on top of the security program you already run for SOC 2 or ISO 27001. We scope it as one AI governance program on a shared control set and a shared evidence base — because maintaining three parallel programs is how compliance becomes the thing that slows product down.

Independence

What we do not do

Cyberneza provides AIUC-1 readiness and advisory support only. We are not an accredited AIUC-1 auditor and we do not perform AIUC-1 audits or AIUC technical evaluations, issue AIUC-1 certificates, or make certification decisions — the audit belongs to the independent accredited auditor and the technical evaluation and certificate to AIUC. We do not guarantee certification or audit outcomes. As with every framework we support, we prepare you and then step aside for the independent party.

FAQ

Common questions

Is Cyberneza an accredited AIUC-1 auditor?

No. An accredited auditor independently assesses evidence and AIUC performs technical evaluation and issues the certificate. We provide readiness and advisory support and coordinate with the auditor you select.

Do we need AIUC-1 if we already have SOC 2?

They answer different questions. SOC 2 addresses your organization's security controls; AIUC-1 addresses the controls on the AI agent itself. If your buyers are asking agent-specific questions, a SOC 2 report will not settle them.

How does this relate to ISO 42001?

ISO/IEC 42001 is a management-system standard for AI governance across the organization; AIUC-1 is focused on the agent and its controls. They overlap enough to run as one program. See AI governance services →

Where do we start?

A scoping call, then a control-gap assessment against the AIUC-1 criteria. That tells you the real distance to certification before you commit to it.

Talk through AIUC-1

Tell us what your agent does and who is asking — a stalled enterprise deal, an insurer, or a board — and we'll recommend a right-sized starting point.