AIUC-1: Building trust in AI agents
Thursday, 25 June 2026 · 4 min read · Listen to the episode ↗
Emil Lassen, co-founder of the Artificial Intelligence Underwriting Company, explains how his firm is building a trust layer between AI agent developers and enterprise buyers through third-party certification, auditing, and insurance. His AIUC1 framework contains 40 mandatory controls updated quarterly, informed by a consortium of 250 security leaders, and is distinct from ISO 42001, SOC2, and NIST guidance.
Emil Lassen, co-founder of the Artificial Intelligence Underwriting Company, argues that his company exists to create a trust layer between AI agent builders and enterprise buyers. His core thesis is that standards, third-party audits, and insurance form a flywheel that has historically enabled adoption of powerful new technologies rather than blocking them, drawing on examples from Benjamin Franklin's first mutual insurance company responding to electricity-related fires through to nuclear power plant certification and car safety standards that produced airbags and seat belts.
The practical problem is that a startup self-certifying its own AI as safe generates limited trust for large enterprise buyers such as banks. Enterprise vendor due diligence questionnaires for AI vendors can contain up to 100 questions, are painful for both sides, and are being updated monthly because the standards landscape changes so rapidly. Lassen describes being a CISO adopting AI today as feeling like standing in a hailstorm where being hit is only a matter of time. The core commercial benefit of third-party certification is framed as unlocking upmarket enterprise revenue rather than providing marketing value.
The AIUC1 certification framework was created because no agentic AI certification standard existed when the company was founded. It sits at the application layer and is distinct from existing frameworks: ISO 42001 is a governance policy management system, SOC2 and penetration testing address infrastructure, and NIST AI Risk Management Framework and the Cloud Security Alliance AI Controls Matrix are voluntary guidance documents rather than auditable certification frameworks. AIUC1 contains 40 mandatory requirements, is updated every quarter, and is informed by a consortium of 250 security leaders including CISOs at Fortune 1000 companies. The controls are published transparently and are free to use. The company has crosswalked approximately 10 different AI frameworks to show how AIUC1 fits the existing environment.
Six of the 40 mandatory requirements relate to red teaming, reflecting the view that technical controls alone may not hold up under robustness testing. Red teaming covers both benign user testing for hallucination rates and adversarial pressure testing including language switches, jailbreaking attempts, multi-turn social engineering, lying, invoking authority, and simulating user distress. Adversarial attacks including language switches have been shown to elevate hallucination rates in deployed agent products. Between 1000 and 5000 unique scenarios are developed per agent under evaluation. Hallucination risk is treated as unique to AI and is not addressed in ISO or SOC2 certifications.
The certification process runs two parallel tracks: a documentation and evidence review covering legal, policy, and technical controls, and a live agent red team evaluation. Companies are given between one and four weeks to mitigate findings between rounds depending on severity, with grades running from P4 insignificant through P0 catastrophic. No P0 or P1 vulnerabilities are permitted to pass. No agent system has ever passed with a 100 percent pass rate because all agent systems are non-deterministic, all can be jailbroken, and all can hallucinate under sufficient pressure. Removing hallucination entirely makes an agent too limited to execute its use case, so tolerance thresholds beyond P0 and P1 are left to the company and its customers to determine. The final audit report runs between 60 and 100 pages and is described as an asset for unblocking enterprise deals, with a report reflecting actual security reality considered more valuable than a spotless one.
Companies obtaining certification gain access to insurance covering residual financial risk, which Lassen frames as the final component of the flywheel. Quarterly re-testing via API access is required to maintain certification because every time an LLM within an agent is replaced the agent will behave differently. Recent quarterly updates have added MCP risk as a priority area as agents began exchanging information rather than operating in isolation, and runtime security and continuous monitoring is the current quarter priority. Relying on a single content filter such as AWS Bedrock's content filter as an agent governance strategy is characterized as insufficient compared to a comprehensive systemic approach. Companies certified range from a three-person Y Combinator startup to publicly traded UiPath, and frontier companies being worked with include 11 Labs and Agentforce, which was acquired by Salesforce for 3.6 billion dollars. Governments are described as behind in enforcing or defining compliance requirements, leaving enterprises as the primary forcing function for AI safety standards.
This summary was generated from the episode transcript and can contain mistakes.