Standards, AIUC-1
Answer the AIUC-1 question before enterprise buyers ask it
AIUC-1 is becoming the standard software companies certify their AI agents against before enterprise customers will buy. Several of its requirements ask the same thing VeriProof does every day: check the action before it runs, involve a person where the stakes call for it, and keep a record that can't be quietly changed.
About the standard
The Artificial Intelligence Underwriting Company publishes AIUC-1 and updates it every quarter; the current release is from July 15, 2026. It groups requirements under six principles: data and privacy, security, safety, reliability, accountability, and society. Accredited audit firms such as Schellman audit organizations against the standard, AIUC runs the technical testing, and AIUC issues the certificate. UiPath, Cursor, Harvey, and Sierra are among the companies that have certified agents.
AIUC-1 applies to the companies that build agents and to the organizations that deploy them. Which requirements apply to you gets settled with your auditor at the start.
Where VeriProof does the work
Scroll horizontally to see all columns.
| AIUC-1 requirement | What it asks for | What VeriProof provides | What your auditor sees |
|---|---|---|---|
| D003 Restrict unsafe tool calls | Safeguards so tool calls can't take unauthorized actions or act beyond scope. Controls include tool authorization, a tool call log, and human approval for high-risk operations. | A policy decision before each consequential action: Allow, Warn, Transform, Escalate, or Deny. High-risk actions escalate to a person with authority. | The rule version applied to each action, the outcome, and the reviewer's decision where one was needed |
| B006 Prevent unauthorized AI agent actions | Stop agents acting beyond their intended scope and privileges. | Rules checked against business facts, not only credentials. When evaluation can't complete, the action is denied. | Denied and escalated actions with the facts and rule that caused them |
| C007 Flag high risk outputs for human review | Criteria for high-risk outputs, detection, and a review workflow. | Escalation rules that send the action to a reviewer with the context and the responses available to them. | The review case, who handled it, when, and the decision returned to the agent |
| E004 Assign accountability | Name who approves changes to the AI system and keep the approvals. | Rule changes run in Shadow first, then need independent approval at the level of control you set. Each role has a named owner in its own portal. | Who drafted each rule change, who approved it, and when it took effect |
| E015 Log AI system activity | Logs of AI actions, including agent tool calls and human approvals, stored with integrity protection. | A decision record for each action, with reviewer identity, timestamps, and decisions, sealed so later changes can be detected. | An evidence pack with a signed inventory, a redaction report, and proofs a reviewer can check independently |
The OWASP connection
AIUC's own crosswalk ties D003 to OWASP's LLM06:2025 Excessive Agency and to several items on the OWASP Top 10 for Agentic Applications, including ASI02 Tool Misuse and ASI03 Identity and Privilege Abuse. The same policy decisions and records cover all three, so one integration gives your security team and your auditor the same evidence.
What pairs well with VeriProof
AIUC-1 also asks for adversarial testing (B001), pre-deployment testing (C002), and third-party testing of harmful outputs and tool calls. Red-teaming and evaluation tools cover that ground, and their findings belong in the same audit file as your VeriProof records.