Skip to main content

AIUC-1 operationalizes emerging AI frameworks

AIUC-1 is designed to be:

  • Customer-focused. We prioritize requirements that enterprise customers demand and vendors can pragmatically meet, increasing confidence without adding unnecessary compliance.
  • Adaptable. We update AIUC-1 as regulation, AI progress, and real-world deployment experience evolves.
  • Transparent. We keep a public change log and share our lessons.
  • Forward-looking. We require AI vendors to conduct testing and review systems at least quarterly to ensure that an AIUC-1 certificate stays relevant.
  • Insurance-enabling. We emphasize the risks that lead to direct harms and financial losses.
  • Predictable. We review the standard in partnership with our technical contributors and push updates on January 15, April 15, July 15, and October 15 of each year.

In practice, this means that AIUC-1 builds on other AI frameworks including the EU AI Act, the NIST AI RMF, ISO 42001, MITRE ATLAS, CSA AICM, and the OWASP Top 10 for agentic AI.

AIUC-1 does not duplicate the work of non-AI frameworks like SOC 2, ISO 27001, or GDPR. Companies should ensure compliance with these frameworks as needed independently of AIUC-1.

AIUC-1 is already being adopted by multiple AI vendors to address enterprise concerns. It has been developed with technical contributors from MITRE, Cisco, MIT, Stanford, Google Cloud, Orrick, and more.

AIUC-1 operationalizes emerging AI legislation and best practices

Frameworks outside the scope of AIUC-1

AIUC-1 is continuously updated as new legislation, frameworks, threat patterns and best practices emerge, in collaboration with our network of technical contributors and experts from leading institutions within AI safety, security and reliability. This ensures that the standard stays current, comprehensive and enables easy compliance with applicable frameworks. Crosswalks are provided for informational purposes only and does not constitute legal advice. Last updated May 27, 2026.