AIUC-1, the AI Agent Certification, Turns to Coding Agents

On July 15, 2026, the Artificial Intelligence Underwriting Company shipped the Q3-2026 revision of AIUC-1 — the AI agent certification standard it launched a year earlier — and pointed it squarely at coding agents. The release changed 8 requirements and 41 controls, adding two mandatory requirements that exist because an agent writing code is not the same risk object as an agent writing text.
Intermediate
What AIUC-1 Is
AIUC-1 launched on July 22, 2025 from the Artificial Intelligence Underwriting Company, a startup that raised a $15 million seed round and describes itself as building “confidence infrastructure” for enterprise AI adoption. The standard is commonly summarised as SOC 2 for AI agents, and the shape of the comparison holds: 51 requirements and 130 controls, split evenly between 65 mandatory and 65 optional, organised into six pillars — Data & Privacy, Security, Safety, Reliability, Accountability, and Society.
Two things separate it from the frameworks it sits alongside. The first is cadence. A certificate is valid for 12 months, technical testing is required at least every three months to keep it valid, and the standard itself is revised quarterly rather than annually — AIUC argues the pace of agent deployment makes a yearly revision cycle useless. The second is that AIUC publishes crosswalks rather than competing: the standard maps to ISO/IEC 42001, the NIST AI Risk Management Framework, the EU AI Act, MITRE ATLAS, the OWASP Top 10 for LLM Applications, the OWASP Agentic Top 10, and CSA AICM, while explicitly declining to duplicate SOC 2, ISO 27001, or GDPR.
Certification runs an agent through more than 5,000 adversarial simulations across security, safety, reliability, privacy, and accountability, with scenarios modelled on documented real-world failures. Schellman is the first accredited AIUC-1 auditor. Certified vendors so far include ElevenLabs, which was first when the standard launched in 2025; Intercom’s Fin agent, certified in December 2025; UiPath in March 2026; and Fieldguide in May 2026.
What Changed in Q3
The two new requirements are both mandatory for code-generating agents.
A008 — Prevent leakage of credentials and secrets adds five controls (A008.1–A008.5) covering “detection and prevention of secrets leakage in AI system inputs, outputs, logs, and credential storage.” A008.1 covers detecting credentials in user input, A008.2 prevents secrets from appearing in generated code, and A008.3 governs secure storage of user-supplied credentials.
B010 — Promote secure patterns in generated code adds six controls (B010.1–B010.6). B010.1 and B010.2 require secure defaults for common vulnerability classes and for authentication and authorisation patterns. B010.3 is the interesting one: safe dependency specification, aimed at preventing hallucinated or typosquatted packages — a supply-chain failure mode that only exists because a model is guessing at package names.
Supporting changes tighten the blast radius. B006.3 was broadened to cover sandboxed execution environments for agent-executed code, not just first-party MCP servers, and to require scanning configuration artifacts for prompt-injection risk. E009 (monitor third-party access) picked up a new supplemental control, E009.2, for anomaly alerting. The release also shipped two new documentation areas for auditors: scoping guidance on which systems a certificate actually covers, and re-certification procedures requiring quarterly red-teaming plus annual compliance validation.
This follows a Q2-2026 release on April 15 that was mostly about protocol surface. That update changed 14 requirements and 23 controls after technical sessions with 120-plus consortium members and more than 200 peer-review comments, restricting agent connections to approved MCP servers (B006.1), extending caller authentication to model APIs, MCP, and A2A channels (B008.2), requiring encryption in transit across those interfaces (B008.3), adding cryptographic message signing for A2A and schema validation on MCP tool calls (B008.4), and pushing MCP server-level metadata such as tool names and parameters into logs (D003.3). It also introduced supplemental controls for unique, cryptographically verifiable agent identities (A003.3) and made third-party access monitoring mandatory.
The Coding-Agent Case
The test case is Lovable, which is pursuing certification as one of the first coding-agent platforms and has a Schellman audit scheduled for summer 2026. AIUC’s accompanying agentic-development whitepaper, co-authored with Lovable, catalogues 75 coding-agent-specific risks and frames the reason the pillars needed extending: “A hallucinated authentication pattern is no longer an inconvenience, it’s a vulnerability shipping to production.”
Lovable makes the same argument about artifacts rather than text. “Coding agents produce executable artifacts like source code, database schemas, API configurations, and deployed applications that directly interact with production infrastructure,” the company wrote, adding that “a vulnerability in generated code is not a hypothetical, it is a live security exposure.” The distinction matters for control design: a chatbot’s bad output waits for a human reader, while a coding agent’s bad output may already be running.
What This Means
The gap AIUC-1 targets is real. SOC 2 covers service controls but says nothing about prompt injection or unauthorised tool calls; ISO/IEC 42001 governs an AI management system but not agent behaviour at runtime. For an enterprise buyer asking a vendor what happens when the agent misfires, “we hold AIUC-1” is a more specific answer than the alternatives.
The structural objections are also real, and the sharpest published version comes from security practitioner Lenny Zeltser. He raises three. Scope ambiguity: the framework does not define what counts as an AI agent, leaving vendors to decide which agent gets certified and which tools and data flows are in scope — which is presumably why Q3 shipped scoping guidance. Auditor incentives: vendors pick their own auditors, and Zeltser notes that promises of “fast and easy” have already threatened SOC credibility. And the conflict of interest, which he puts plainly — AIUC “authors the framework, runs the technical evaluations, issues the certificates, and sells the AI agent insurance that the certification enables,” a structure he likens to the issuer-pays credit rating model that inflated ratings before 2008.
That last point is the one worth sitting with, because the insurance is not incidental to the standard — it is the mechanism. Once an agent is certified, its vendor can bind affirmative AI liability marketed at up to $50 million, covering hallucinations, data leakage, IP infringement, and tool-action failures such as incorrect refunds. Pricing controls into a policy is what makes AIUC-1 more than a checklist; it also means the party writing the controls carries the loss when they fail. Whether that alignment disciplines the standard or corrodes it is an empirical question that will take several claim cycles to answer. Zeltser’s own framing is the fair one for now: “new certifications start as claims and earn credibility through cycles of scrutiny.”
The next revision is scheduled for October 15, 2026.
Related Coverage
- Agents of Chaos: What Happens When Autonomous AI Agents Get Real Tools — the failure modes AIUC-1’s control pillars are written against
- Hugging Face Discloses Intrusion Run End-to-End by an AI Agent — an agent-run intrusion of the kind the Society pillar’s misuse controls target
- BadHost Starlette Bug Puts AI Agent Infrastructure on Alert — the MCP-adjacent infrastructure surface addressed in the Q2-2026 update
This post was drafted with AI assistance and reviewed by RITS staff.
Sources
- AIUC-1 — Q3-2026 standard update
- AIUC-1 — Changelog
- AIUC-1 — Q2-2026 update: MCP security, agent permissions & third-party risk
- AIUC-1 — The world’s first AI agent standard
- Artificial Intelligence Underwriting Company
- Lovable — Setting the standard for agentic development
- Lenny Zeltser — What to Make of AIUC-1, a New AI Agent Certification
- UiPath — UiPath Achieves AIUC-1 Certification
- ElevenLabs — ElevenLabs secures first-of-its-kind AI Agent insurance




沪公网安备31011502017015号