AIUC Closes $40M Series A to Scale AI Agent Certification
AIUC (Artificial Intelligence Underwriting Company), a San Francisco-based startup building a certification standard for enterprise AI agents, has raised $40 million in Series A funding led by Ribbit Capital, with participation from First Harmonic. The round brings AIUC's total funding to $55 million, following a previously disclosed $15 million seed round.
AIUC was founded in 2024 by Rune Kvist, who was Anthropic's first product hire, alongside co-founder Rajiv Dattani, formerly COO of AI safety evaluator METR. The company positions itself at the intersection of security auditing and insurance underwriting — certifying that an AI agent meets a defined risk bar, then tying insurance coverage to the results of that audit.
What AIUC Actually Certifies
The company's core product is AIUC-1, a certification standard developed in consultation with roughly 250 security and risk leaders, explicitly modeled on SOC 2 — the audit framework enterprises already use to vet how cloud vendors handle customer data. Where SOC 2 evaluates data-handling controls, AIUC-1 evaluates whether an AI agent can be trusted to operate with a degree of autonomy inside an enterprise environment.
Certification runs an agent through approximately 5,000 adversarial test scenarios, probing for:
- Jailbreaks — attempts to bypass an agent's guardrails through crafted prompts
- Prompt injection — malicious instructions smuggled in through untrusted input the agent processes
- Hallucinations — confidently wrong outputs presented as fact
- Anomalous behavior — actions that fall outside an agent's intended scope
- Data leaks — unintended exposure of sensitive information
The process produces a roughly 100-page audit report, and results are reviewed quarterly. AIUC says AI tooling is used to help run and analyze the tests, but human reviewers verify the final findings before a certification is issued.
Who's Already Using It
AIUC says its standard is already being used to certify a set of widely deployed AI agents and platforms, including Cursor, ElevenLabs, Fin, Harvey, KPMG, Lovable, and UiPath. That customer list spans coding assistants, voice AI, legal AI, and enterprise automation — a signal that the certification pitch is landing across categories rather than a single vertical.
Why Agent Certification Is Becoming Its Own Market
Enterprises have spent the past two years piloting AI agents that can take autonomous action — filing tickets, executing transactions, writing and deploying code — rather than just generating text. That autonomy is precisely what makes agents useful, and precisely what makes security teams reluctant to sign off on production deployment without independent evidence the agent behaves safely under adversarial conditions.
Founder Rune Kvist framed the problem bluntly: "Most enterprises have a list of AI agents that were approved in pilots but stalled at the security review. Evidence of security and reliability is now the main bottleneck." That framing echoes the earlier evolution of cloud security, where SOC 2 became a de facto prerequisite for enterprise sales once buyers needed a standardized way to evaluate vendors they couldn't audit themselves. AIUC is betting the same dynamic will play out for agentic AI, with certification and insurance becoming the mechanism that lets security teams say yes.
AIUC plans to use the new capital to expand its audits, standards, and insurance offerings to frontier models, not just the narrower agent products it has certified so far.
What It Signals for Security Teams
For security teams evaluating agentic AI tools, AIUC's raise is a data point that the "trust layer" for AI agents is starting to formalize rather than remain ad hoc. A standardized, third-party-audited framework gives buyers a common vocabulary for comparing agent vendors on security posture, rather than relying on vendor self-attestation.
It's also worth noting the structural question this model raises: AIUC writes the standard, sells the audit against it, and helps arrange the insurance that follows — a bundled arrangement that puts a premium on auditor independence, transparent methodology, and a real appeals process if a vendor disputes a finding. As more of these certification schemes emerge, security teams evaluating agentic AI should expect to weigh not just whether a vendor is certified, but by whom, and under what standard.