AIUC-1: Building trust in AI agents

Summary of AIUC-1: Building trust in AI agents

by Practical AI LLC

45mJune 25, 2026

Overview of AIUC-1: Building Trust in AI Agents

This episode of the Practical AI Podcast features Emil Lawson, standards lead at the Artificial Intelligence Underwriting Company (AIUC), discussing how standards, audits, certification, and insurance can help enterprises trust and adopt AI agents. The conversation focuses on why agentic AI needs a dedicated trust layer, how AIUC-1 fits alongside existing frameworks like ISO 42001, NIST AI RMF, and OWASP, and what companies must do to become certifiable and enterprise-ready.

Why Standards, Audits, and Insurance Matter for AI

Emil argues that standards are not primarily about slowing innovation—they are about enabling adoption by making risk legible and manageable.

The “flywheel” model

He describes a historical pattern seen with:

  • Building codes, fire inspections, and insurance in early electricity adoption
  • Safety standards, inspections, and insurance in the automotive industry
  • Standards and audits in nuclear and other high-risk industries

The idea is that:

  • Standards codify what “safe” should look like
  • Audits verify whether systems actually comply
  • Insurance covers residual risk that remains even after controls are in place

AI agents, especially in enterprise environments, need the same structure.

Why this matters now

AI agents can:

  • Create real business value
  • Introduce security, reliability, and financial risk
  • Be difficult for buyers to evaluate using vendor claims alone

AIUC’s goal is to become the trust layer between builders and adopters of AI.

Where AIUC-1 Fits in the Standards Landscape

Emil breaks the current standards landscape into three layers:

1. Organizational layer

Examples:

  • ISO 27001
  • ISO 42001

This layer focuses on governance, policies, and management systems.

2. Infrastructure layer

Examples:

  • SOC 2
  • Pen testing
  • Access management
  • Transport security

This layer covers the underlying security controls that protect systems and data.

3. Agentic AI layer

This is where AIUC-1 focuses.

It addresses risks that are unique to AI agents, including:

  • Hallucinations
  • Prompt injection
  • Jailbreaking
  • Unsafe tool use
  • Over-broad data or system access
  • Out-of-scope advice in high-risk domains

Emil positions AIUC-1 as more prescriptive and technical than guidance frameworks like NIST AI RMF or CSA’s AI controls matrix, while still crosswalking to those broader frameworks.

What AIUC-1 Covers

AIUC-1 is designed specifically for agentic systems and the practical risks they introduce.

Core control areas include:

  • Safety and behavioral boundaries
  • Data, system, and tool access restrictions
  • Hallucination prevention
  • Secure agent-to-agent communication
  • Change management when models or configurations change
  • Runtime monitoring and observability
  • Incident response and rollback readiness

Red teaming is central

A major part of the standard is active adversarial testing to verify that controls hold under pressure.

How the Certification Process Works

Emil outlines a certification workflow that is meant to improve security, not just produce a compliance badge.

Step 1: Gap assessment

AIUC reviews the company’s current posture against the standard and identifies:

  • What already meets requirements
  • What needs work
  • What engineering, legal, and GRC effort will be required

Step 2: Audit preparation

Companies gather evidence for both:

  • Legal/governance controls
    Examples: acceptable use, data retention, ownership of inputs/outputs
  • Technical controls
    Examples: output filtering, classifiers, grounding checks, tool-call safeguards

Step 3: Independent audit

Third-party auditors such as Schellman or Coalfire validate the evidence and controls.

Step 4: Live red teaming

AIUC runs the in-scope agent through thousands of attack scenarios, including:

  • Benign prompts
  • Multi-turn social engineering
  • Authority manipulation
  • Distress-based pressure
  • Jailbreak attempts
  • Prompt injection attacks

Step 5: Remediation and retest

If issues are found:

  • The company gets a remediation window
  • AIUC retests after fixes
  • The final audit report reflects the system’s real posture

Step 6: Ongoing quarterly re-testing

Certification is maintained through repeat testing every quarter to ensure changes haven’t introduced new vulnerabilities.

What “Passing” Means

One of the most important points in the episode is that AI agent certification is not about perfection.

Key grading principles

  • AIUC uses severity-based findings
  • Critical and catastrophic issues must be fixed before passing
  • Lower-severity issues may be documented if the company chooses to accept them

Important caveat

Emil stresses that no agentic system will ever have a 100% spotless report:

  • Agents are probabilistic and non-deterministic
  • Jailbreaks and hallucinations can still happen
  • The goal is not unrealistic perfection, but meaningful risk reduction and transparency

This is a major mindset shift for enterprises used to deterministic software or traditional audits.

Why Enterprises and Vendors Would Care

Emil identifies several practical forcing functions driving adoption.

For vendors

  • Faster enterprise procurement
  • Less painful security questionnaires
  • Third-party proof of safety and reliability
  • Better enterprise sales conversion

For buyers

  • More confidence in vendor claims
  • Lower due-diligence burden
  • Better visibility into real risk

For the vendor’s security posture

Red teaming often uncovers real issues, including:

  • Hallucination spikes under attack
  • Jailbreak vulnerabilities
  • Prompt injection weaknesses

So the certification process is also a product-improvement mechanism.

Market Direction and Ecosystem Needs

Emil sees the future of AI trust and certification as a broader ecosystem effort.

What needs to happen next

  1. Secure-by-default platforms

    • Agent-building environments should ship with stronger default controls
    • This makes certification easier later
  2. Partner tooling

    • Monitoring, filtering, and safety platforms can help companies satisfy many controls quickly
    • AIUC is already seeing this with various partners and integrations
  3. Better GRC and evidence automation

    • Less screenshot-based evidence
    • More programmatic validation
    • Easier re-certification and ongoing compliance

Long-term vision

AIUC plans to extend this model beyond application-layer agents to:

  • Model layer governance
  • Physical infrastructure
  • Robotics and other AI-enabled systems

Notable Takeaways

  • Standards can accelerate adoption when they make trust measurable.
  • AI agents need their own security category because existing frameworks don’t fully cover their unique behavior.
  • Certification should be evidence-based and adversarial, not just policy-based.
  • A perfect pass is unrealistic for agentic systems; transparency and continuous improvement matter more.
  • Enterprise trust is becoming a market differentiator for AI vendors.

Final Thought

The episode makes a strong case that AI agents will only scale in enterprise environments if the industry can prove they are safe enough to deploy. AIUC-1 is presented as an attempt to codify that proof through standards, audits, red teaming, and eventually insurance—creating the infrastructure for trustworthy agentic AI.