- What AI systems are you certifying?
- What AIUC-1 requirements must be met?
Part 1: What AI systems are you certifying?
Systems in Scope
Two questions determine your certification scope:- What is your role? Are you an AI agent developer, deployer or both? Which agentic AI systems (or “agents”) are in scope?
- Only include agentic AI systems in the scope - AIUC-1 does not cover other systems
Systems in scope: Guidance
What is the difference between an AI deployer and developer?
What is the difference between an AI deployer and developer?
AI developers build the agentic platform and capabilities, and determine the safe-configuration defaults engineered into agents. AI deployers configure the agentic platform for their own use case, and deploy agents in their own environment. AI developers can be AI deployers and vice versa. Developers are responsible for making sure that secure defaults are in place and documented. Deployers are responsible for configuring AI systems securely given their deployment context.
Which agents should you certify?
Which agents should you certify?
AIUC-1 is most relevant for higher risk agentic AI systems that are:
- Critical to the business - for example, customer-facing agents, where brand is on the line
- Highly capable - for example, agents with access to sensitive data or access to tools like a CRM or payment processing
- Subject to legal, compliance, or stakeholder requirements - for example, an AI recruitment system classified as high-risk under the EU AI Act with legal obligations, which may require third-party validation before deployment
What constitutes high-risk agents?
What constitutes high-risk agents?
An agent’s risk profile is driven by three factors:
- Capabilities (what the agent can do) - for example, the modalities it supports (text, voice, image, video) and its level of autonomy
- Architecture (how the agent is built) - for example, what data it can access or which tools it can call
- Deployment context (where the agent operates) - for example, whether it is internally or externally facing, if it’s deployed by a large bank or a small YC company, or designed for consumer or business audiences
How many agents can I certify?
How many agents can I certify?
You can certify multiple agents at once, or start with one high-risk agent and expand your scope after your first certification.
Part 2: What AIUC-1 requirements must be met?
Statement of Applicability
AIUC-1 has 50 requirements. Requirements are either mandatory or optional to earn AIUC-1 certification. Each requirement comes with a list of:- Core controls: These are controls organizations should implement to pass AIUC-1. If core controls are not demonstrated, organizations must submit alternative evidence demonstrating how they meet the requirement
- Supplemental controls: These are controls organizations may implement in addition and are not required to pass AIUC-1. Instead, organizations opt-in to supplemental controls relevant given the AI agent’s capabilities, architecture, and deployment context.
Statement of Applicability: Guidance
- Baseline - all mandatory requirements and core controls apply by default.
- Scoping out - a mandatory requirement can only be excluded with a documented, legitimate business reason signed off by the auditor. A core control can be excluded if the organization demonstrates alternative ways of meeting the requirement.
- Opting in - organizations can add any number of optional requirements and supplemental controls to their scope. Typical reasons to opt in:
- Showcase strengths - demonstrate gold-standard controls beyond industry standard, in areas where your organization already excels
- Meet customer or regulatory demands - where specific buyers or regulations expect controls beyond the baseline given the deployment context & agent capabilities