Drata, the compliance automation company, announced on July 16, 2026, that its platform now natively supports AIUC-1, a certification standard written specifically for AI agents. The support arrives through the Drata Agentic Trust Management Platform, where the standard's requirements are mapped to Drata's own control framework so that customers can scope, implement, and gather evidence against AIUC-1 inside the compliance program they already run. Drata built the mapping with AIUC, the company behind the standard, and says the support is generally available now.
AIUC-1 comes from the Artificial Intelligence Underwriting Company, a San Francisco startup founded in 2024 that describes its business as certifying and insuring AI agents. The standard covers six areas, namely data and privacy, security, safety, reliability, accountability, and society, and it pairs an audited certificate with liability insurance that AIUC says can cover up to $50 million in losses from agent-specific failures. AIUC and Drata describe AIUC-1 as the first standard of its kind, and it draws on existing frameworks such as the NIST AI Risk Management Framework, the EU AI Act, and MITRE's ATLAS to produce requirements an accredited auditor can test against.
The significance for GAIG readers runs past the integration itself to what it signals, which is that agent assurance is starting to come with a price tag attached. By wiring an insurance-backed agent standard into a mainstream compliance platform, Drata is betting that enterprises will soon expect an AI agent to arrive with a certificate the way a software vendor arrives with a SOC 2 report.
“AIUC-1 is designed to strengthen AI security significantly without overburdening security and GRC teams. By integrating AIUC-1 into Drata, we’re taking a big step towards reducing the work required to earn and maintain certification while keeping the bar consistent and high.”
Rajiv Dattani, Co-founder of AIUC
Conditions Driving This Change
AI agents are moving from pilots into production, and enterprise buyers want to adopt them while lacking a repeatable way to confirm that a given agent is safe and reliably governed.
Security reviews and procurement stall when a buyer cannot validate an agent, which turns third-party AI evaluation into an ad hoc process that slows deals on both sides of the table.
Broad governance frameworks such as ISO 42001 and the NIST AI Risk Management Framework describe good practice at a high level, and they leave out the agent-specific technical testing that buyers increasingly ask for.
Agent-specific failure modes, including data leakage, prompt injection, jailbreaks, and hallucinations, have no common yardstick, so different teams evaluate the same risks in different ways.
Compliance teams are handed new AI requirements without added headcount, which leaves many of them building programs by hand in spreadsheets because their GRC tools do not support the standard.
The Artificial Intelligence Underwriting Company built AIUC-1 with a consortium of roughly 150 large-enterprise security and risk leaders, which gave the standard early buy-in from the people who sign off on AI purchases.
Insurers have begun underwriting agent-specific risk, and a certificate that opens the door to coverage gives a standard a commercial weight that a framework on its own does not carry.
Organization | Role in AIUC-1 |
|---|---|
AIUC (Artificial Intelligence Underwriting Company) | Author of the standard, which runs the audits and underwrites the insurance tied to certification |
Drata | Compliance automation platform that maps AIUC-1 to its control framework and collects evidence against it continuously |
What AI Compliance Looked Like Before This
Until recently, a company that wanted assurance about an AI agent had little to point to. The recognized frameworks were written for management systems and broad risk practice, so ISO 42001 and the NIST AI Risk Management Framework could tell an organization how to govern AI in general terms without saying whether a specific agent resisted a prompt injection or leaked data under pressure. A buyer asking a vendor to prove an agent was safe got a policy document instead of a test result.
Compliance teams filled the gap by hand. They took a new AI requirement, built a program for it in spreadsheets, and gathered evidence from scattered systems, because the GRC platforms they already ran had no native support for anything agent-specific. Third-party AI risk was judged case by case, with each reviewer applying personal criteria to the same failure modes.
The cost of that improvisation landed on deals. An AI company trying to sell into an enterprise would reach security review and stall, because the buyer had no standard way to confirm the agent was governed and no way to price the risk of being wrong. Assurance existed as an argument rather than as a certificate anyone could check.
What It Looks Like Now
AIUC-1 turns that argument into an audit. The standard breaks agent risk into six domains and, within each, sets requirements that an accredited auditor can test using technical evaluations and red-teaming, which produces a certificate a buyer can rely on instead of a promise a buyer has to take on faith. UiPath, for one, went through more than two thousand technical evaluations to earn the certification earlier in 2026.
Drata's contribution is to make the standard something a company can run continuously rather than once. With AIUC-1 mapped to its control framework, Drata offers pre-built requirements, controls, and policy templates, and it ties them to continuous monitoring so the evidence stays current as an agent changes. The platform also routes AI-specific risks into its risk register, centralizes audit evidence in one workspace, and lets a company publish its assurance status to customers through a trust center.
The part that sets this apart from earlier compliance work is money. Because AIUC underwrites the agents it certifies, the certificate is paired with insurance that AIUC says covers up to $50 million for failures such as hallucinations, data leakage, intellectual property infringement, and tool call errors. A certificate that pays out when it turns out to be wrong carries a different kind of weight than one that only attests.
Our Take
AI Compliance Take
What matters here is the underwriter standing behind the framework, more than the framework itself. The field has no shortage of frameworks, and this one changes the incentives because the same company that certifies an agent also has to pay when that agent fails. That alignment gives the audit a reason to be rigorous, and it is worth more than another set of controls on paper.
The cautions are the ones that apply to any young standard. AIUC-1 is recent, its ecosystem of auditors and certified vendors is still small, and the claim that it is the first agent standard is a marketing line that sits alongside other agent efforts from bodies such as the Cloud Security Alliance and OWASP. Buyers should ask what a certificate actually covers, how the insurance pays out in practice, and whether the auditors testing against the standard are genuinely independent, because the value of the certificate rests entirely on those answers.
Drata putting native support behind an insurance-backed agent standard is a sign that AI compliance is moving from documentation toward tested, financially accountable assurance, the direction GAIG has argued the whole field is heading. Buyers weighing how to prove an agent is safe, and how to demand the same from their vendors, can compare the platforms and standards in the AI Compliance category at GetAIGovernance.net.