Skip to content

Invest1 publisher2 min readPublished

Ribbit puts $40M behind an AI agent trust mark that expires every quarter

A $40M Series A led by Ribbit Capital pays for AIUC's move from auditing application-layer agents into underwriting frontier models, on its founders' argument that enterprise pilots stall in security review.

The Investor · Invest desk

Illustration accompanying Ribbit puts $40M behind an AI agent trust mark that expires every quarter

What happened

  • AIUC's $40M Series A, led by Ribbit Capital with participation from First Harmonic, follows a $15M seed led by NFDG and brings the company's total funding to $55M.
  • Its AIUC-1 standard tests agents against about 5,000 risk and attack combinations, covering jailbreaks, prompt injection, hallucinations, data leaks and unsafe tool execution.
  • The founders are Rune Kvist, Anthropic's first product hire, and Rajiv Dattani, a former McKinsey insurance partner who was COO of METR.

Compiled by The InvestorSomething wrong?How this is made

Why it matters

  • cost Certification is a recurring expense on the vendor's side, four audits a year for every certified agent, and it renews on AIUC's calendar instead of the customer's contract cycle.
  • decision Security reviewers who have been holding up pilots can now accept or reject an outside audit instead of weighing the vendor's own evidence.
  • constraint Because cover is tied to the assessment, AIUC can insure only what it has tested, and an agent that changes between quarterly audits drifts away from the evidence its price was set on.
  • precedent If the audit-plus-policy pairing works one layer up, frontier model developers acquire a paying counterparty with a direct commercial interest in their failure rates.

The Artificial Intelligence Underwriting Company gets paid twice off one test [22]. It sells certification, and it links insurance cover to the same assessment [13]. An audit is a fee collected. A policy is a liability carried, priced off loss experience, and there is very little loss experience for autonomous agents running inside enterprise workflows.

So the standard doubles as the data collection. An agent is independently audited before it carries the AIUC-1 mark, then recertified every quarter [7]. Each name on the holder list therefore produces four observations a year. Seven are named: Cursor, ElevenLabs, Harvey, KPMG, Lovable, UiPath and Fin [8]. That comes to 28 audits a year [20] at about 5,000 risk and attack combinations each [6], or roughly 140,000 test runs [21].

Ventureburn did not report which insurer stands behind the cover, or the premium [18].

The pitch rests on where deployments die. Rune Kvist and Rajiv Dattani argue that capability is no longer the only barrier and that enterprises need evidence systems will operate reliably [11]; the company says organisations have approved agents in pilots and then watched some deployments stall during security reviews [12]. Kvist and Dattani are describing their own market. More than 250 security and risk leaders at Fortune 1000 companies shape the standard through AIUC's consortium [9], so the buyer side is helping write the test it will later ask vendors to pass. KPMG sits on the holder list alongside the software vendors [8].

Maybe enterprise reviewers start naming AIUC-1 in their requirements, and quarterly recertification becomes a subscription with an audit attached. Or the cyber insurers price agent failure inside policies they already write, off claims data AIUC does not have, and AIUC keeps the audit fee while losing the premium. Or the consortium members absorb the test into their own vendor questionnaires and pay nobody for it.

The new round is about 73% of the $55M raised to date [19][2], and it is pointed up the stack: from agents at the application layer toward frontier models, with expanded audits, technical evaluations and insurance infrastructure for frontier systems [14][15]. Dattani was COO of METR before this [10]. The money is not going into thickening the application-layer book where the seven named holders sit.

I'd expect certification revenue to grow well ahead of premium, because a quarterly audit can be sold on procurement friction alone while a policy needs a loss curve. A disclosed paid claim on a certified agent would show the loss curve exists. And if enterprise pilots mostly stall on cost and accuracy, a security certificate leaves them stalled [12].

What to watch

  • Any disclosure of written premium or the reinsurance capacity standing behind AIUC-1 policies.
  • Whether an established cyber carrier extends an existing enterprise policy to agent failure, priced off its own claims data.
  • The first frontier model developer to sign for an AIUC audit, and what it agrees to publish.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories