BLOG
August 4, 2026
decorative
Travis Good

What are the AIUC-1 Principles? A Complete Overview

AIUC-1 has six principles for AI agents: Data & Privacy, Security, Safety, Reliability, Accountability, and Society. Here's what each one requires.

AI is being adopted by businesses of all sizes. But often, agents aren’t evaluated for risk, which opens up enterprises to a whole host of potential issues. That’s why AIUC-1 was introduced by the Artificial Intelligence Underwriting Company.

AIUC-1 was designed to help organizations adopt AI with confidence, assessing agents on criteria like data & privacy, security, safety, reliability, accountability and society. The standard was built based on feedback from 500+ enterprise security and compliance experts.

What AIUC-1 Is, and What Principles Means

AIUC-1 is the first certifiable standard built for AI agents. It organizes risk into six principles:

  1. Data & Privacy: keep customer data from leaking or being used in ways the customer never agreed to.
  2. Security: defend the agent against adversarial attacks like jailbreaks and prompt injection.
  3. Safety: prevent the agent from generating harmful or catastrophic outputs.
  4. Reliability: stop hallucinations and unreliable tool calls into business systems.
  5. Accountability: own the agent's decisions and vet the vendors in its supply chain.
  6. Society: prevent broader misuse, most concretely AI-enabled cyberattacks.

You may also see these referred to as the AIUC-1 pillars. The terminology is generally used interchangeably.

Underneath the six principles there are 51 requirements and around 130 individual controls (some mandatory, some optional). AIUC-1 turns higher-level AI-focused frameworks like ISO 42001, the NIST AI Risk Management Framework, and MITRE ATLAS into controls your organization’s AI agents can be assessed against.

Why AI Agents Need Their Own Principles

Just like a human, AI consumes data, makes a judgment and takes action. But with human teammates, we’ve spent decades building guardrails into human workflows to ensure accountability and reduce risk. For AI, that didn't exist until AIUC-1 was introduced.

AI agents are a new type of worker, and the AIUC-1 principles are guardrails that ensure processes and accountability exist for these agents.

Existing frameworks, while still incredibly valuable, are built to tackle different types of risk. For example, a SOC 2 report and a security questionnaire tell an enterprise buyer how you protect systems and manage people. But they don’t cover what happens when an agent makes a decision without human oversight.

In Detail: The AIUC-1 Principles

1. Data & Privacy: Keep Customer Data From Leaking

Data and privacy covers how your agent collects, uses, retains, and protects data. It's built to ensure agents handle sensitive data in a secure way to avoid exposing it to the wrong people (or agents), whether that be sharing it with the wrong customer, adding it into a training set, or making the data publicly accessible.

Data & Privacy governs the flow of customer data through the agent so it doesn't leak or get used in ways the customer never agreed to.

To meet this principle, and its seven requirements, an organization will need a clear input data policy telling customers how their data is used for training, inference, and retention, plus a matching output data policy.

What you have to prove is that you have the data input and output policies in place, available to customers to review, and that the technical controls you have to enforce those policies are working.

2. Security: Defend the Agent Against Adversarial Attacks

This principle aligns fairly closely with traditional security standards. It's focused on ensuring agents are protected from adversarial manipulation like jailbreaks and prompt injection, and have guards in place to stop it from taking unauthorized actions through the tools it can access.

AIUC-1 requires controls focused on third-party adversarial robustness testing, adversarial input detection, and real-time input filtering that screens what reaches the model before it can act, so that organizations can prove their agent has been tested against adversarial inputs and has runtime filters in place.

3. Safety: Prevent Harmful and Catastrophic Outputs

Whereas the Security principle is all about fending off attacks, Safety focuses on the agent's outputs. It exists to make sure the agent won't generate harmful or toxic content, and it requires ongoing monitoring so new risks get caught over time rather than at a single point in time.

The requirements scale with agent responsibilities. If your agent only responds with text-based answers, that's what it's assessed against. If you add in voice, image, or video, additional safeguards will be needed to prove that harmful or toxic content can't be produced in each format.

Safety also includes a monitoring requirement to track AI risk categories on an ongoing basis because models can drift over time and each new model could open up new risks.

4. Reliability: Stop Hallucinations and Bad Tool Calls

If you've used AI long enough you've almost certainly experienced an agent or AI response confidently telling you something that's not quite right. That's where the Reliability principle comes in.

Reliability ensures the agent does what it's supposed to and doesn't take incorrect actions, which is the whole basis for trusting it to operate on its own.

This principle is especially important for agents that make decisions and act. If a chatbot hallucinates and gives you a wrong answer, you can push back or ignore it. If an agent makes a wrong choice and takes an action inside your business's systems, it can cause a lot of damage.

The controls under Reliability require organizations to prove that they have safeguards to catch hallucinations and systems to validate tool calls before they reach the systems they touch.

5. Accountability: Own the Agent's Decisions and Vendors

When an agent does something wrong, who owns it? Accountability assigns clear ownership for the agent's behavior and any wrong outcomes.

In practice that means naming who is accountable for the agent, conducting due diligence on the model and tool vendors you build on, reviewing your internal processes on a regular cadence, and having clear paths in place for escalation and emergency responses.

6. Society: Prevent Broader AI Misuse

The Society principle looks beyond your relationships with customers, and takes a bigger, more holistic look at AI's role in the world. Specifically, it guards against AI enabling societal harm through cyberattacks or causing security issues.

Society requires agents to have clear guardrails that stop them from being turned into tools for cyberattacks and prevent cyber misuse, because, often, the exact same skills and capabilities that make an agent work could also make it dangerous if there aren't guards in place to protect against negative outcomes.

Why These Principles Look Different From ISO 42001 and SOC 2

If you've looked at ISO 42001 or the EU AI Act, the AIUC-1 principles will feel different. Those standards are governance-heavy, focused on policies, documentation, and management systems, whereas AIUC-1 is implementation-heavy. It tests how your systems and controls work, rather than examining the policies and management frameworks you have in place. That's why each principle rolls down into specific, testable controls.

AIUC-1 is also backed by insurance, so if your agent hallucinates, leaks data, or takes an action that costs your customer money, there's an underwritten policy behind it. And because AI moves so quickly, the standard updates quarterly rather than annually.

What the Principles Mean If You're Building Agents

Once you know the six principles, the useful thing is to treat them as a readiness checklist. Each one names a category of risk you'll need evidence for before an enterprise buyer trusts your agent.

The quick way to internalize them is to map the risks you already worry about onto the six: data leaks land in Data & Privacy, prompt injection in Security, harmful output in Safety, wrong actions in Reliability, ownership in Accountability, and misuse in Society. That mapping turns a vague "is your agent safe?" into a concrete, scoped list of what to build and document.

How much you have to prove depends on your agent. The riskier it is, the more controls apply, which is why the same standard asks 40 controls of an internal tool and 65 of a customer-facing agent that moves money. And certification is a point-in-time evaluation, not a guarantee. It shows your controls worked when tested, which is why it pairs with continuous monitoring rather than replacing it.

Working out which controls apply to your agent, and where your current setup falls short, is the bulk of the effort. Our AI GRC practice helps companies scope against the six principles and close the gaps that surface, so your engineers can keep shipping instead of stalling on the audit.

Thinking About How Secure Your Agents Are?

AIUC-1 is designed to help answer the core questions enterprises have about agents and AI workers before they sign a contract. The principles are designed to give a confident answer to: is your agent safe, and can you prove it?

Unlike other frameworks, AIUC-1 is implementation-first. It tests what your agents do and how they're protected against misuse. If you're reading this, there's a good chance you're interested in AI agent security and compliance, and you should be. AI compliance is heading the same direction SOC 2 did a few years ago, just faster. The companies that move on standards like AIUC-1 will be ahead of the curve when AI compliance is table stakes for closing a deal.

If you're weighing AIUC-1 and want to know what it would take to meet the standards, our AIUC-1 team can map it out with you.

Turn compliance into a growth engine: Workstreet delivers full-stack solutions that transform security and compliance into growth accelerators. Talk to an expert →
Build trust, accelerate growth.
Workstreet offers Al-first security solutions that help high growth technology companies get compliant, scale securely, and close bigger deals.
Get started
Ready to Transform Security into a Growth Advantage
Schedule a consultation with our trust solutions experts to see how we can accelerate your security program and compliance journey.
Talk to an engineer
Travis Good

Architect of security and privacy programs for 1,000+ hypergrowth companies. Author of "Complete Cloud Compliance," HITRUST 3rd Party Council member, and recognized speaker on startup security.