> ## Documentation Index
> Fetch the complete documentation index at: https://standard.aiuc-1.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Introduce AIUC-1

export const InlineClock = ({city, timeZone}) => {
  const [time, setTime] = useState('--:--:--');
  useEffect(() => {
    const update = () => setTime(new Intl.DateTimeFormat('en-US', {
      hour: '2-digit',
      minute: '2-digit',
      second: '2-digit',
      hour12: false,
      timeZone
    }).format(new Date()));
    update();
    const id = setInterval(update, 1000);
    return () => clearInterval(id);
  }, [timeZone]);
  return <div className="aiuc-footer-clock">
      <span className="aiuc-footer-clock-city">{city}</span>
      <span className="aiuc-footer-clock-time">{time}</span>
    </div>;
};

Every client already holds frameworks for how AI systems are built and governed. None of them test what the agent actually does once it's live.

| Risk area | Existing frameworks | Evidence collected |
| - | - | - |
| **Technical:** how AI systems behave in production | None | Technical evaluation results |
| **Build:** how AI systems are designed and secured | NIST AI RMF, OWASP Top Ten, MITRE ATLAS, CSA AICM | Production code, configuration and logs |
| **Policy:** how AI systems are governed | ISO 42001, EU AI Act | Policies, commercial terms and internal practices |

AIUC-1 is comprehensive, auditable, technically grounded, and updated quarterly. It is shaped quarter by quarter through the [AIUC-1 Consortium](https://www.aiuc-1.com/consortium), which unites CISOs, GRC leaders, practitioners, and academics from leading organizations around the world.

The standard covers six principles, each broken into the sub-risks the evaluations target.

<CardGroup cols={3}>
  <Card title="Data & privacy">
    IP infringement, personal data leakage, business data leakage
  </Card>

  <Card title="Security">
    System information disclosure, unauthorized actions, insecure outputs, insecure actions
  </Card>

  <Card title="Safety">
    Physical harm, emotional harm, inappropriate content, high-risk domain engagement, vulnerable user engagement
  </Card>

  <Card title="Reliability">
    Service disruption, hallucination, incorrect tool calls
  </Card>

  <Card title="Accountability">
    Transparency
  </Card>

  <Card title="Society">
    Cyber
  </Card>
</CardGroup>

## Why the client is buying

### A certification that is technically grounded

AIUC-1 requires independent technical testing that the safeguards hold in production. Across a sample of 85,000 graded evaluations run between February 2025 and August 2026, ordinary requests produced a finding 22.0% of the time against 2.9% of the time for adversarial attacks. Agents fail in everyday use far more often than under direct attack.

What certification quantifies, by agent type:

| Agent type | Highest finding rates |
| - | - |
| Chatbot | Hallucination 8.9%, scope and output format 8.2%, incorrect tool calls 6.6%, system info disclosure 6.2% |
| Automation | Extraction accuracy 15.8%, incorrect tool calls 7.9%, data and privacy leakage 2.8% |
| Coding | Insecure outputs and disclosure 12.9%, hallucination 8.0%, unauthorized actions 6.3%, IP infringement and data leakage 5.9% |

Certification delivers this as a quantified risk exposure alongside a 60-page audit report, against 65 mandatory controls, over a 10-week process run by one of 7 accredited auditors.

> "Most certifications prove what you already do. This one made the product better: the testing produced new guardrails, and we can show customers exactly what improved."
>
> Sheron Chakalakal, Head of GRC, UiPath

### It's the perfect complement to ISO 42001

Roughly 30% of AIUC-1 controls are already covered by existing ISO 42001 evidence through the published crosswalks, so a certificate accelerates the engagement rather than duplicating it. ISO 42001 certifies the AI management system, meaning governance processes at the organizational level. AIUC-1 certifies the agent itself, by testing it. A client who has been through ISO 42001 has already decided AI assurance is worth paying for, and gap assessments at ISO 42001-certified companies typically open with the large majority of requirements already met or likely met.

<Card title="Full ISO 42001 mapping" href="/crosswalks/iso-42001">
  How AIUC-1 requirements map to ISO 42001 controls, and where existing ISO 42001 evidence carries over.
</Card>

### A go-to-market asset

To unblock deals: 46% of companies see sales delayed without a security certification, and 73% of buyers accept an audit report in place of a security questionnaire. One AIUC-1 report answers the AI risk section of every subsequent review instead of a fresh questionnaire each time a buyer asks. Intercom's Fin reps raised the certification unprompted in 22 enterprise sales calls since December, and on one major asset manager's vendor review the AIUC-1 report covered 40 to 50% of the required testing scope.

To lead the category: every certification ships with a co-marketing package, including a serialized badge, a co-branded blogpost, and coordinated distribution to the Consortium audience. Lovable's certification announcement became its CEO's top LinkedIn post in two months at 3x his usual engagement, drawing 3,000 engagements from 2,500 people across 11 launch posts. In the first three weeks, 5 enterprise accounts asked about AIUC-1, 2 of them citing it as a differentiator against a competitor, and GRC leaders at 4 major security brands reached out.

## Best follow-up assets

What to send after the introduction, depending on what the client asks for next.

<CardGroup cols={3}>
  <Card title="AIUC-1 introduction deck">
    <span className="aiuc-coming-soon">Coming soon</span>

    Send after the first conversation. The client-facing overview: the gap in existing frameworks, quantified risk by agent type, cost and services, and case studies.
  </Card>

  <Card title="AIUC-1 requirements and controls" href="https://docs.google.com/spreadsheets/d/15dFbcol6Ocjwdurcg7HOlVAqdX8-D_8JZiL0gzkYz_E/edit">
    Send when the client wants to see what they will be audited against. All 51 requirements across the six principles, each with its controls and typical evidence. View only, and copying it starts a readiness assessment.
  </Card>

  <Card title="Sanitized audit report" href="https://docs.google.com/document/d/1wX2L36wEL70cfv-VaRm2MFKk3zHEvZdipG1HA5KJLjM/edit">
    Send when the client wants to see the deliverable. The full report structure with client detail removed.
  </Card>
</CardGroup>

<Card title="Request additional resources" href="https://docs.google.com/forms/d/e/1FAIpQLSd-2Mx3GzZHHsHBaMRH3nJjUsB2i5WcD_KgB41eFv5_i_5Heg/viewform?usp=header">
  Link to form
</Card>

***

<Card title="Next: Request a gap assessment" href="/auditors/introduce-and-scope/request-a-gap-assessment">
  Score the client against AIUC-1 before anything is priced.
</Card>

<div className="aiuc-footer">
  <span className="aiuc-footer-corner aiuc-footer-corner-tl">
    <svg fill="none" stroke="currentColor" strokeWidth="1" viewBox="0 0 12 12" width="12" height="12">
      <line x1="0" x2="12" y1="6" y2="6" />

      <line x1="6" x2="6" y1="0" y2="12" />
    </svg>
  </span>

  <span className="aiuc-footer-corner aiuc-footer-corner-tr">
    <svg fill="none" stroke="currentColor" strokeWidth="1" viewBox="0 0 12 12" width="12" height="12">
      <line x1="0" x2="12" y1="6" y2="6" />

      <line x1="6" x2="6" y1="0" y2="12" />
    </svg>
  </span>

  <div className="aiuc-footer-strip">
    <span className="aiuc-footer-mono">37.782274° N -122.392147° W</span>
    <span className="aiuc-footer-strip-center">FIG. A (SITE INDEX)</span>

    <span />
  </div>

  <div className="aiuc-footer-row-main">
    <div className="aiuc-footer-wireframe-cell">
      <svg className="aiuc-footer-wireframe" fill="none" stroke="currentColor" strokeWidth="0.4" viewBox="0 0 200 150">
        <rect height="130" width="180" x="10" y="10" />

        <rect height="40" width="60" x="20" y="20" />

        <rect height="40" width="40" x="90" y="20" />

        <rect height="40" width="40" x="140" y="20" />

        <rect height="60" width="60" x="20" y="70" />

        <rect height="60" width="90" x="90" y="70" />

        <line strokeDasharray="2,2" x1="20" x2="180" y1="65" y2="65" />

        <line strokeDasharray="2,2" x1="85" x2="85" y1="20" y2="60" />

        <circle cx="50" cy="40" r="6" />

        <circle cx="110" cy="40" r="6" />

        <circle cx="160" cy="40" r="6" />
      </svg>
    </div>

    <div className="aiuc-footer-wordmark-cell">
      <div className="aiuc-footer-wordmark">Artificial Intelligence Underwriting Company</div>
    </div>

    <div className="aiuc-footer-clocks">
      <InlineClock city="SFO" timeZone="America/Los_Angeles" />

      <InlineClock city="NYC" timeZone="America/New_York" />

      <InlineClock city="LON" timeZone="Europe/London" />
    </div>
  </div>

  <div className="aiuc-footer-row-sub">
    <div className="aiuc-footer-codeblock-cell">
      <div className="aiuc-footer-codeblock">
        <span className="aiuc-footer-codeblock-header">Code</span>
        <span className="aiuc-footer-codeblock-header">Structural unit</span>
        <span className="aiuc-footer-codeblock-code">a.</span>
        <span className="aiuc-footer-codeblock-text">AIUC-1 requirements for agent data, privacy, security, safety, reliability, accountability, and societal risk.</span>
        <span className="aiuc-footer-codeblock-code">b.</span>
        <span className="aiuc-footer-codeblock-text">Evidence templates for technical implementation, legal policy, operational practice, and third-party evaluation.</span>
        <span className="aiuc-footer-codeblock-code">c.</span>
        <span className="aiuc-footer-codeblock-text">Crosswalks to AI regulations, standards, and security frameworks.</span>
        <span className="aiuc-footer-codeblock-code">d.</span>
        <span className="aiuc-footer-codeblock-text">Quarterly updates shaped by enterprise adoption, risk, regulation, and community input.</span>
      </div>
    </div>

    <div className="aiuc-footer-columns-cell">
      <div className="aiuc-footer-columns">
        <div>
          <div className="aiuc-footer-column-header">I. Standard</div>

          <ul className="aiuc-footer-column-list">
            <li><a className="aiuc-footer-column-link" href="/">Overview</a></li>
            <li><a className="aiuc-footer-column-link" href="/crosswalks">Crosswalks</a></li>
            <li><a className="aiuc-footer-column-link" href="/evidence">Evidence</a></li>
            <li><a className="aiuc-footer-column-link" href="/changelog">Changelog</a></li>
          </ul>
        </div>

        <div>
          <div className="aiuc-footer-column-header">II. Learn</div>

          <ul className="aiuc-footer-column-list">
            <li><a className="aiuc-footer-column-link" href="/learn/about">About AIUC-1</a></li>
            <li><a className="aiuc-footer-column-link" href="/learn/contribute">Contribute</a></li>
            <li><a className="aiuc-footer-column-link" href="/scoping">Scoping</a></li>
            <li><a className="aiuc-footer-column-link" href="/faq">FAQ</a></li>
          </ul>
        </div>

        <div>
          <div className="aiuc-footer-column-header">III. Office</div>

          <ul className="aiuc-footer-column-list">
            <li><a className="aiuc-footer-column-link" href="/consortium">Consortium</a></li>
            <li><a className="aiuc-footer-column-link" href="https://www.aiuc-1.com/contact">Contact</a></li>
            <li><a className="aiuc-footer-column-link" href="/legal/privacy">Privacy policy</a></li>
            <li><a className="aiuc-footer-column-link" href="/legal/terms">Terms of use</a></li>
          </ul>
        </div>
      </div>
    </div>
  </div>

  <div className="aiuc-footer-strip-bottom">
    <span className="aiuc-footer-mono">100</span>
    <span>© AIUC — ALL RIGHTS RESERVED</span>
  </div>

  <span className="aiuc-footer-corner aiuc-footer-corner-bl">
    <svg fill="none" stroke="currentColor" strokeWidth="1" viewBox="0 0 12 12" width="12" height="12">
      <line x1="0" x2="12" y1="6" y2="6" />

      <line x1="6" x2="6" y1="0" y2="12" />
    </svg>
  </span>

  <span className="aiuc-footer-corner aiuc-footer-corner-br">
    <svg fill="none" stroke="currentColor" strokeWidth="1" viewBox="0 0 12 12" width="12" height="12">
      <line x1="0" x2="12" y1="6" y2="6" />

      <line x1="6" x2="6" y1="0" y2="12" />
    </svg>
  </span>
</div>


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.