← Back to blog

AIUC-1: A New Standard for Trustworthy AI Agents

AIUC‑1 offers a new, governance‑focused way to address AI malfunctions in the age of agentic systems. Instead of only checking whether security and AI policies exist, it tests how AI agents behave under attack, whether they can be jailbroken, leak sensitive data, or misuse tools autonomously. Positioned alongside standards like ISO/IEC 27001, ISO/IEC 42001, SOC 2, and GDPR, AIUC‑1 adds what those frameworks largely lack: independent, behaviour‑based assurance and documented human oversight through human‑in‑the‑loop workflows. With 50+ technical, operational, and legal safeguards and frequent adversarial testing, it shifts the core question from “Is the AI compliant on paper?” to “Can this AI be trusted to operate safely, securely, and under human control in real‑world enterprise environments?”

Anand Prabhu·Co-founder, AramGRC·July 3, 2026·5 min read

Artificial intelligence has been present in industry for a long time, but we are now entering a new phase: the deployment of agentic AI systems that can call tools, trigger APIs, and make decisions across an entire workflow with minimal human involvement at the moment of decision‑making. These systems are no longer just “chatbots”, they are operational actors in the enterprise ecosystem. What if an AI agent that can read your emails, access your CRM, execute API calls, approve expenses, and make business decisions without waiting for human approval and now imagine someone manipulates that agent through a single prompt injection attack.

From a governance perspective, this shift exposes a structural gap. Our existing standards and frameworks, though valuable, were not designed with autonomous AI agents in mind and do not fully address how these systems can malfunction in practice.

Why traditional standards are not enough

Information security and AI governance standards ask important questions, but they often remain high‑level and technology‑agnostic:

  • ISO/IEC 27001 focuses on whether security policies exist, whether encryption is used, and whether access controls are in place. These controls are foundational, yet they say little about how an AI system behaves under adversarial conditions such as prompt injection, jailbreaking, or data‑exfiltration attempts.
  • ISO/IEC 42001 asks whether you govern AI responsibly, whether you have assessed AI‑related risks, and whether you document AI systems appropriately. It anchors AI management, but it does not specifically test whether an AI system can withstand attacks or prevent unsafe autonomous actions.

Other standards and regulations also address governance, privacy, and accountability, but most still treat AI as if it were a static IT system rather than a dynamic, learning‑driven agent. In effect, they help you document controls on paper, they rarely show whether the AI itself can be trusted in real‑world conditions.

What AIUC‑1 is and is not

AIUC‑1 is designed to sit in this gap. AIUC‑1 is a third‑party standard and certification scheme for agentic AI systems. It certifies the implementation and operation of AI agents rather than only the underlying model or product. Its goal is to demonstrate that an AI system has concrete, testable controls for:

  • Data privacy
  • Security
  • Safety
  • Reliability
  • Accountability
  • Societal risk

Unlike frameworks that focus primarily on policies, AIUC‑1 emphasizes results: does the AI resist attacks, avoid leaking sensitive data, and behave reliably under stress?

Much like SOC 2 in broader IT assurance, AIUC‑1 certification is accompanied by an independent audit report. It is designed to complement existing standards and regulations like ISO/IEC 27001, ISO/IEC 42001, SOC 2, GDPR, and emerging AI laws, rather than replace them, by adding a layer of behaviour‑based, agent‑specific assurance.

AIUC-1 deliberately avoids duplicating requirements already addressed by ISO/IEC 27001, SOC 2, or GDPR. Instead, it focuses exclusively on AI-specific risks such as prompt injection, unsafe tool use, hallucinations, agent autonomy, model behavior, and human oversight. Rather than replacing existing compliance programs, it adds an assurance layer specifically for AI agents.

Human oversight: demonstrating control over autonomous AI

A key concern for regulators and in‑house counsel is human oversight: how do you prove that humans can supervise and intervene in autonomous AI decisions?

AIUC‑1 embeds human oversight directly into its control set. For high‑risk or autonomous actions, the standard requires documented, auditable human‑in‑the‑loop (HIL) workflows. In practice, this means:

  • Critical actions taken by an AI agent must either be approved by a human or be subject to real‑time intervention and rollback.
  • The system must allow humans to pause, correct, or override AI‑initiated workflows when risks or anomalies are detected.
  • Oversight processes and escalation paths must be documented, monitored, and tested, so that “human oversight” is more than a policy statement, it is an operational reality.

By enforcing real‑time feedback and intervention for high‑impact decisions, AIUC‑1 aligns closely with emerging legal requirements such as the EU AI Act’s human‑oversight provisions, and it offers tangible evidence that organizations are not delegating unfettered control to AI agents.

One of the most distinctive aspects of AIUC‑1 is its risk‑driven, insurance‑enabling approach to AI assurance. Instead of treating AI risk as an abstract governance issue, AIUC‑1 prioritizes scenarios that cause direct financial loss and real‑world harm, including:

  • Customer data leakage
  • AI‑enabled fraud
  • Unauthorized API or tool execution
  • Incorrect financial or operational transactions
  • Autonomous misuse of enterprise systems

These incidents are not simply “technical bugs”. They can generate operational disruption, regulatory penalties, reputational damage, and insurance claims. AIUC‑1 focuses on controls that mitigate these high‑impact risks and produce evidence that the system has been meaningfully tested against them.

This shifts the central question from:

“Is the AI compliant with a checklist?” to

“Can the AI be trusted to operate safely, securely, and under human oversight in real‑world enterprise environments?”

For boards, risk committees, and insurers, this is a more practical, outcome‑oriented way to evaluate AI assurance.

AIUC‑1 also evaluates systems from the perspective of a customer or end‑user of the AI agent. It tries to answer practical trust questions such as:

  • Will this agent leak my data to other users?
  • Can someone else gain access to my personal emails or documents through this system?
  • Can the agent be jailbroken or manipulated into bypassing safeguards or executing harmful actions?

In this sense, AIUC‑1 is risk‑driven rather than control‑driven. Its focus is not only whether controls exist, but whether users and organizations can reasonably rely on the AI agent to respect boundaries, maintain confidentiality, and stay within its intended role even when challenged.

What certification involves

AIUC‑1 certification is structured as ongoing assurance, not a one‑time attestation. At a high level, it involves:

  • More than fifty technical, operational, and legal safeguards, covering adversarial robustness, data protection, governance, and accountability.
  • Frequent, independent technical testing, including adversarial evaluation of AI behaviour under realistic attack scenarios (for example, jailbreaks, prompt injections, and misuse of tools).
  • Audit evidence and continuous maintenance, so certification reflects how the system actually performs over time, rather than how it looked at a single point in time.

The certificate is generally valid for 12 months, but technical testing must be carried out at least every three months to keep the certification current. Organizations are assessed through both technical testing and review of operational and legal controls, with annual re‑audits to capture material changes in systems or risk.

AIUC‑1 is particularly relevant for:

  • Organizations building or procuring autonomous or agentic AI
  • Customer‑facing systems and digital channels
  • AI systems with access to confidential, regulated, or high‑value data
  • Tools that make or support business‑critical operational decisions

As regulations such as the EU AI Act and future AI laws evolve, AIUC‑1 is designed to incorporate new compliance expectations rather than remain frozen in time. The underlying principle is that organizations following AIUC‑1 should find it easier to align with changing regulatory requirements, because the standard evolves alongside them.

To make this manageable, AIUC‑1 commits to:

  • Public version history
  • Public changelog
  • Clearly documented updates

This transparency allows organizations to understand what has changed and why, instead of discovering new expectations only at audit time. Importantly, existing certifications remain valid during defined transition periods. Without this, every update could immediately invalidate prior assessments and destabilize assurance programs.

By giving organizations time to adopt new or updated controls while maintaining confidence in existing certifications, AIUC‑1 supports a more stable, continuous approach to AI governance. It creates a bridge between fast‑moving technical change and the slower, but binding, evolution of legal and regulatory frameworks.

AI-Agent
WhatsApp