AI Agents

SOC 2 for AI Agents: AIUC Raises $55M to Certify What Enterprises Actually Trust

AIUC just raised $55M to scale AIUC-1, a SOC 2-style third-party audit standard that runs roughly 5,000 jailbreak, hallucination and data-leak tests on an AI agent - with KPMG and ElevenLabs already on the roster. Here is how the certification works and what builders should do about it.

Toolbit AI - Team
11 min read
SOC 2 for AI Agents: AIUC Raises $55M to Certify What Enterprises Actually Trust

AIUC - the Artificial Intelligence Underwriting Company - just raised a $40 million Series A led by Ribbit Capital, with First Harmonic participating. Add the $15 million seed it previously landed from NFDG, and the San Francisco startup has $55 million in total funding to scale AIUC-1, a third-party certification standard for AI agents that works a lot like SOC 2, plus an insurance layer stacked on top of it.

Why does this matter? Because the most common story in enterprise AI right now is an agent that wins its pilot and then quietly dies in procurement. AIUC co-founder Rune Kvist says most enterprises get agents approved in pilots only for them to end up "stalled at the security review." Smarter AI should be easier to adopt, yet as Kvist puts it, it "becomes harder to adopt and harder to control as AI gets smarter, not easier."

Here is what the new standard actually is, how the audit works, who already carries the trustmark, and what the $55 million changes.

In short:

  • AIUC raised a $40M Series A led by Ribbit Capital ($55M total with its $15M NFDG seed) to scale AIUC-1, a SOC 2-style third-party audit standard for AI agents.
  • AIUC-1 tests an agent against 5,000 risk-and-attack combinations tailored to its business type, spanning six principles: security, safety, reliability, accountability, data & privacy, and societal impact.
  • Cursor, Lovable, Harvey and Intercom Fin are already certified - and KPMG just became the first Big Four firm on the roster.
  • Certification unlocks AI-specific insurance coverage of up to $50M for risks like hallucinations, data leakage and tool-call failure.
  • The new money extends AIUC's audits, standards and insurance from agents to frontier models.

What is AIUC-1 - a SOC 2 for AI agents?

AIUC-1 is a third-party certification standard for AI agents. Think of it as SOC 2's tougher cousin: where a typical compliance process asks an organization to document its controls, AIUC-1 actually attacks the agent and watches what breaks.

The standard tests how an agent holds up against 5,000 risk-and-attack combinations that are tailored to each type of business - a banking assistant does not face the same threats as a healthcare one. All of those simulations span six principles:

  • Security - the agent resists attacks instead of opening doors for them
  • Safety - the agent refuses to do harmful things
  • Reliability - the agent behaves the way it is supposed to, every time
  • Accountability - when something goes wrong, it is possible to see why
  • Data & privacy - the agent does not leak what it should protect
  • Societal impact - the agent's effects on people are measured, not assumed

The test scenarios are modeled on documented real-world AI failures, from hallucinations to prompt injection attacks - the class of attack where hidden instructions sneak into what an agent reads and hijack its behavior.

Two things make AIUC-1 different from another compliance questionnaire. First, it operationalizes frameworks enterprises already know - ISO 42001, the NIST AI RMF, the EU AI Act and the OWASP Top 10 for LLMs - so it slots into work companies have started rather than competing with it. Second, it is technically tested: the agent gets red-teamed and run through adversarial evaluations, not just audited on paper. You can read the standard itself at aiuc-1.com.


Who built AIUC - and why the Anthropic and METR pedigrees matter

AIUC's two founders bring exactly the two halves of the trust equation: lab-side AI risk experience from Anthropic's product organization and deep underwriting experience from McKinsey insurance and risk-evaluator METR.

Rune Kvist, co-founder and CEO, is a former Anthropic product lead and a board member at the Center for AI Safety - he has spent years close to frontier models and the effort to make them safe. Rajiv Dattani, co-founder, is a former McKinsey insurance partner and the previous COO at METR, a leading AI risk evaluator. (TechCrunch, which covered the round, adds the color that the two are brothers-in-law.)

Dattani has a favorite analogy for what they are building. "When electricity was burning down houses, the insurers paying the bill funded Underwriters Laboratories to test and certify products," he has said - and AI, in his view, needs the same combination of standards, testing and insurance.

The company was founded by experts from Anthropic and developed with Orrick, the Cloud Security Alliance and MITRE, and it has published a research paper, "Underwriting Superintelligence," laying out the thesis. The pedigree shows up in the cap table too: the $15M seed was led by NFDG (Nat Friedman's fund), with Emergence, Terrain, an Anthropic co-founder and former CISOs at Google Cloud and MongoDB participating. You can browse the full team on AIUC's site.


How does a 5,000-test adversarial audit actually work?

Diagram of the AIUC-1 audit flow: an agent enters, faces 5,000 risk tests tailored to its business type, and either earns or misses the trustmark with quarterly recertification

The certification runs in four steps: scoping, then evals, then audit, then certification. Scoping starts fast - AIUC offers a 48-hour gap assessment that shows a builder where their agent stands before the heavy lifting begins.

Then come the evals: 5,000 risk-and-attack combinations per business type, covering the failure modes buyers lose sleep over. Jailbreaks mean an agent can be talked into ignoring its rules. Hallucinations mean it invents facts confidently. Data leaks mean it reveals what it should keep private. Prompt injection means it follows instructions from the wrong source. Unsafe tool execution means it issues a refund or makes a purchase it never should have.

AIUC says its own AI agents run these tests and analyze the results, with humans verifying the final audit - the company described this agents-testing-agents setup to TechCrunch. The output is a 50+ page independent audit report covering how guardrails are implemented and what the red-teaming turned up.

The standard itself updates quarterly, though each certification locks its version for one year. And the audits stay independent: AIUC is the only body that can accredit AIUC-1 auditors. Schellman has been accredited since November 1, 2025, and six more firms - Coalfire, BDO, Grant Thornton, Mastermind, Sensiba and A-LIGN - hold provisional accreditations while they complete witness audits. It is a centralized model that deliberately mirrors FedRAMP and HITRUST.


Who already carries the trustmark - and what KPMG and ElevenLabs announced

The certified roster is the most convincing part of the story: Cursor, Lovable, Harvey and Intercom Fin are all certified against AIUC-1. Cursor is a case study on the standard's site - "the only standard that keeps up with our pace," says Kenneth Thomas Moras of Cursor Security.

Then came the August 2026 news: KPMG became the first Big Four firm to achieve AIUC-1 certification, for its aIQ Capture agentic platform. KPMG put the platform through more than 900 technical tests, including hallucinations, high-risk domain interactions, content safety and prompt injection, building on its existing ISO 42001 certification. The buyer-side quotes tell the story best. "Before the firm put its name behind our own agentic system, we had it independently tested and certified," said Arun Rajappa, KPMG's National Managing Principal. Swami Chandrasekaran, Global Head of AI & Data Labs at KPMG, framed the shift plainly: the challenge "is no longer whether AI agents will be adopted, but how organizations can demonstrate to boards, regulators and stakeholders that those agents behave as intended under real-world conditions."

And in February 2026, ElevenLabs went live with the first AI-agent insurance policy backed by AIUC-1. Insurers can now underwrite customer-deployed voice agents - ElevenAgents powers more than three million of them, and ElevenLabs technology is used by employees at more than 75% of Fortune 500 companies, and the company has grown to over $330 million ARR and an $11 billion valuation. "This certification gives our partners the security framework and AI insurance coverage they need," said co-founder Mati Staniszewski.


Why certification + insurance is the bottleneck-breaker for stalled rollouts

The pattern is everywhere: an agent aces its pilot, the business loves it, and then the security and legal reviews begin - and deployment quietly never happens. It is a big part of why most enterprise agents still need a human in the loop before anyone lets them near production. AIUC itself claims that over 95% of enterprise AI pilots fail to reach deployment, with legal and security concerns cited as the primary barriers - though that is the company's own figure, not an independent one.

Certification attacks the problem from the buyer's side. A 250+ member consortium of security and risk leaders from Fortune 500 and 1000 companies helps shape the standard and drives adoption inside their own organizations - meaning the people who run security reviews are the same people asking for this certification.

Insurance then closes the loop. Certification converts an unknown, unquantifiable AI risk into something an underwriter can actually price: AIUC's policies cover up to $50 million in losses from hallucinations, brand risk, data leakage, IP infringement and tool-call failure (think incorrect refunds or purchase decisions). "Leading insurers are so confident in this certification-based approach that they're offering AI-specific financial coverage to those who earn it," Kvist said. Ribbit Capital's Micky Malka - whose firm has spent more than a decade backing financial services companies where trust counts most - sees the gap plainly: AI "is moving faster than the systems companies use to evaluate it."


What the $55M changes - and what builders should do now

The Series A money has one stated job: extend AIUC's audits, standards and insurance from agents to frontier models. That is a meaningful scope shift - certification would no longer stop at agentic products but reach the foundation-model layer underneath them.

For teams shipping agents today, the practical path looks like this:

  1. Start with the 48-hour gap assessment. It is the fastest way to see where your agent stands before committing to a full audit.
  2. Map what you already have. AIUC-1 crosswalks to ISO 42001, the NIST AI RMF, the EU AI Act and the OWASP Top 10 for LLMs, so existing compliance work counts - this is not a from-zero effort.
  3. Treat certification plus insurance as a sales asset. If enterprise buyers keep stalling at the security review, a third-party trustmark and insurable risk is a concrete answer to hand them.
  4. Put recertification on the engineering calendar now. The standard updates quarterly and attack techniques keep changing, so budget for ongoing audits rather than a one-time stamp.

Zoom out and the bigger signal is on the demand side. A trustmark only matters if buyers ask for it - and a 250-strong consortium of security leaders suggests they already are. If you are wiring governance into your stack as adoption scales, control planes that catch rogue AI agents are one more piece of that puzzle.

One note on the numbers: the $50M coverage cap and the insurance terms around it are AIUC's own published figures, and they can change as the program scales, so confirm current terms directly with AIUC before budgeting around them.


Frequently asked questions

How much does AIUC-1 certification cost, and how long does it take?

AIUC's published pages don't list certification pricing, so cost has to come directly from the company. The publicly documented timeline starts with a 48-hour gap assessment, followed by the evals, audit and certification steps, with the audit producing a 50+ page independent report. Plan for ongoing work too - the standard updates quarterly and each certification locks a standard version for one year.

No - AIUC-1 is a voluntary, third-party standard, not a law or regulator mandate. It is built to operationalize frameworks that do carry legal weight, including the EU AI Act, ISO 42001, the NIST AI RMF and the OWASP Top 10 for LLMs, so many teams use it as evidence of compliance readiness rather than as compliance itself.

What is the difference between AIUC-1, ISO 42001, and SOC 2?

SOC 2 audits an organization's controls and processes, and ISO 42001 certifies an AI management system - both are largely documentation-driven. AIUC-1 is agent-specific and technically tested: the agent itself gets attacked with 5,000 adversarial simulations and red-teaming, not just its paperwork. KPMG's own sequence shows how they fit together - it took ISO 42001 first, then added AIUC-1 for its agentic platform.

Can a small team get AIUC-1 certified, or is it enterprise-only?

There is no published enterprise-scale requirement, and the certified roster already runs from startups to giants: Cursor, Lovable and Harvey sit alongside Big Four firm KPMG. Early-stage agent builders can pursue the same trustmark, and with a 250+ member consortium of security leaders driving adoption inside their own companies, smaller teams may increasingly find buyers asking for it.

Who audits the auditors - is AIUC-1 itself accountable to anyone?

Only AIUC can accredit AIUC-1 auditors, so accountability runs through a single centralized body. Schellman has been an accredited auditor since November 1, 2025, and six more firms - Coalfire, BDO, Grant Thornton, Mastermind, Sensiba and A-LIGN - hold provisional accreditations while they complete witness audits. The structure deliberately mirrors certification paradigms like FedRAMP and HITRUST, where a central body issues the certificates and a network of independent auditors collects the evidence.

Share this article

Related articles

Continue exploring similar guides and insights