Product1 publisher3 min readPublished
AIUC raises $40M to aim its 5,000-combination agent audit at frontier models
The AIUC-1 standard runs an agent through roughly 5,000 risk and attack combinations and has to be renewed every quarter. Eleven Labs used its certificate in February to buy insurance covering a voice agent that misinforms a customer.
The Product Desk · Product desk

What happened
- AIUC, the AI agent certification startup, said it raised $40 million to start auditing frontier AI models, having until now certified only the agents companies build on top of those models.
- Eleven Labs used its certification in February to secure what it called first-of-its-kind AI agent insurance, including coverage for a voice agent that gives a customer incorrect information.
- More than 250 security and risk leaders from Fortune 1000 companies sit in the consortium that shapes the standard and presses for its adoption inside their own employers.
Compiled by The Product DeskSomething wrong?How this is made
Why it matters
- decision Teams sitting on an approved pilot now have something purchasable to put in front of a reviewer. The first question they have to answer is whether the blocker was a missing document or a missing control.
- cost Quarterly recertification makes the audit a standing operating expense with four renewal dates a year. The team that owns the agent owns the scheduling.
- exposure With a policy attached to the audit, the bill for a voice agent's wrong answer can land on an underwriter instead of the company that deployed it. Legal then has a different question to ask than security's.
- contradiction The account of the bottleneck comes from the company selling the remedy, so a buyer has to test it against their own review queue rather than take the diagnosis on trust.
The agent cleared its pilot and then stopped moving. Rune Kvist, AIUC's co-founder and chief executive, said most enterprises have a list of agents that were approved in pilots but "stalled at the security review" [4]. Proof of security and reliability, he added, has become the main bottleneck [5]. What the company sells into that stall is a document a risk owner will accept.
The document has a shelf life. One certification runs the agent through about 5,000 combinations of risk and attack chosen for the type of business deploying it [6], with jailbreaks, hallucinations and data leaks among the failure modes tested [7]. AIUC audits each agent independently and recertifies every quarter as attack techniques change [8]. Four audits a year at that size works out to roughly 20,000 combinations annually for a single agent [20]. It also means the certificate in the file describes the threat picture as of the last audit, up to about three months back [21]. Much of the testing is done by AI agents, with humans verifying the final audit, according to TechCrunch [9].
Rajiv Dattani, the co-founder who was a partner in McKinsey's insurance practice and then chief operating officer of the model evaluation nonprofit METR [14], described the sequence in older terms. "When electricity was burning down houses, the insurers paying the bill funded Underwriters Laboratories to test and certify products," he said. "To this day, the UL mark is on most light bulbs across America. AI needs the same combination of standards, testing and insurance." [15]
A consortium of more than 250 security and risk leaders from Fortune 1000 companies shapes the standard and pushes for its adoption inside their own organizations [12]. Certificate holders include Anysphere, the developer of Cursor, plus Harvey AI, KPMG, Lovable Labs, UiPath and Fin, the customer service software maker formerly called Intercom [11].
AIUC's own argument is that uncertainty over risk now slows adoption more than any shortfall in what the technology can do [3]. The company also argues that the security reviews which blocked application rollouts first are now building around the models themselves [16]. Ribbit Capital led the Series A with participation from First Harmonic [17]. That follows the $15 million seed that Nat Friedman at NFDG led when the company launched in July 2025, for $55 million raised in total [18]. The two rounds are about 14 months apart [22]. The report does not state what certification costs [23]. Micky Malka of Ribbit said AI is heading down the same road as financial services, "and it is moving faster than the systems companies use to evaluate it." [19]
For the person who has to move a blocked pilot, the queue sorts on who the reviewer is and what the agent can do. Does a named risk owner in your company treat third-party attestation as sufficient, or do they want your own test results? And can the agent take an action nobody can reverse, such as a payment or a statement to a customer that becomes the company's position? Where attestation is accepted and the actions are reversible, a certificate is the cheapest way to get the signature. Where the actions are not reversible, the audit is a prerequisite for coverage, and the coverage is what Eleven Labs said it went and bought in February [10]. Where the reviewer wants their own evidence, buying the standard adds four renewal dates a year to your calendar and leaves the internal testing where it was [8].
What to watch
- Whether AIUC publishes a frontier-model audit, and which lab agrees to sit for one.
- Whether an insurer beyond the Eleven Labs policy writes coverage priced off an AIUC-1 certificate, and on what terms.
- Whether a certified agent fails between quarterly recertifications, and who absorbs the loss.