Rajiv Dattani priced risk inside McKinsey's insurance practice for years, then ran operations at METR, the nonprofit that stress-tests frontier AI models. Both jobs pointed at one conclusion. Enterprise AI is now limited by trust, not by capability.

That conclusion has a price. On September 15, Dattani's company raised $40 million.

🎯
AIUC raised a $40M Series A led by Ribbit Capital, bringing total funding to $55M, to extend its AIUC-1 standard from AI agents to frontier models.

AIUC-1 puts agents through roughly 5,000 adversarial risk-and-attack combinations and recertifies them every quarter. Cursor, ElevenLabs, Harvey, KPMG, Lovable, UiPath and Fin carry the mark.

The open question is whether a venture-backed private standard becomes the trust layer for enterprise AI — or a moat that trades paperwork for proof.

AI agents answer support calls, draft contracts and write production code. Most ship without an independent test. The failures are already public: an airline chatbot that invented a refund policy, a recruiting tool that scored candidates unfairly, an image model that produced offensive material.

The Artificial Intelligence Underwriting Company launched in July 2025 with a $15 million seed led by NFDG, the fund run by former GitHub chief executive Nat Friedman. Its first product was a standard, not a model.

What AIUC-1 actually tests

The standard covers six areas: data and privacy, security, safety, reliability, accountability and societal impact. To certify, an AI company implements more than 50 technical, operational and legal safeguards, then hands the agent to an independent auditor.

$55M raised to date

Total funding, seed plus Series A

A $15M seed in July 2025 and a $40M Series A in September 2026. AIUC, 2026

Certification runs the agent through roughly 5,000 combinations of risk and attack, tailored to the type of business deploying it. Jailbreaks, hallucinations and data leaks sit on the failure list. Each agent is audited independently and recertified every quarter, because attack techniques move faster than annual reviews.

AIUC built the standard with Orrick, MITRE, Stanford and MIT, and with feedback from more than 100 Fortune 500 security chiefs. It maps onto frameworks enterprises already know: the National Institute of Standards and Technology (NIST) AI Risk Management Framework, the EU AI Act, and MITRE's ATLAS threat library.

When electricity was burning down houses, the insurers paying the bill funded Underwriters Laboratories to test and certify products. To this day, the UL mark is on most light bulbs across America.— Rajiv Dattani, co-founder, AIUC

The case for confidence infrastructure

Enterprises adopt technology once they can price its risk. Cloud computing crossed that line when SOC 2 audits — a widely used security-audit standard — and cyber-insurance turned downtime into a line item instead of an unknown. AI agents sit in that same position now.

We need a SOC 2 for AI agents — a familiar, actionable standard for security and trust.— Phil Venables, former chief information security officer

Insurance completes the loop. In February, the voice-AI company ElevenLabs became the first to go live with an AIUC-1-backed policy covering its voice agents, which power more than three million enterprise deployments. Policies can cover losses of up to $50 million, depending on the terms.

Ribbit Capital, which led the new round, argues the hard part is already done: builders, enterprises, auditors and insurers now point at a single document. Harvey is a case in point. As we wrote in September, Harvey's $15.5 billion round put a price on legal AI agents. That agent now carries the AIUC-1 mark, which turns a category-defining valuation into a procurement decision its buyers can defend.

Rune and Rajiv broke through the cold-start problem. Aligning the ecosystem of AI builders, enterprises, security leaders, auditors and insurers around a single standard is required.— Nick Shalek, general partner, Ribbit Capital

The case that the mark becomes a moat

A certificate is only as strong as the incentive behind it. AIUC writes the standard, performs or accredits the audit, and sells the insurance that depends on both. That vertical stack is efficient. It is also self-referential: the company grades the paper it profits from.

The market is not waiting for one winner. On September 14, the Agentic AI Foundation launched MCPA, a competing certification for Model Context Protocol (MCP) expertise. Regulators are moving too, with the EU AI Act's obligations phasing in. A private mark that duplicates public rules adds cost without adding proof.

What the certificate does cover

Adversarial testing across six risk areas, quarterly recertification, insurance underwriting, and a shared vocabulary that shortens security and compliance reviews for buyers.

Confirmation criteria: a regulator or an insurer outside the company's own book treats the mark as sufficient.

What it does not cover

It does not transfer legal liability, does not test behaviour outside its scenarios, and is not a regulatory approval. Open-ended agents that learn after deployment sit beyond any quarterly snapshot.

Disconfirmation criteria: buyers keep running parallel internal tests, or insurers price the mark at a rounding error.

The Underwriters Laboratories precedent

The mark on the light bulb is the model. Underwriters Laboratories grew out of the insurance industry's response to electrical fires in the 1890s: insurers funded a testing lab, the lab wrote standards, and products that passed got a label. Within two decades the label was a purchasing requirement, and the cost had shifted from the insurers to the manufacturers.

AIUC is running the same play in reverse. Instead of insurers funding the lab, a lab is selling insurers a reason to write policies. Certificates and coverage become the "confidence infrastructure" that lets a buyer sign off on an agent without owning the downside alone.

That inversion carries the risk. Underwriters Laboratories answered to an industry it did not own. AIUC answers to its investors, and those investors sit alongside the companies it certifies. A mark cannot be more independent than the revenue standing behind it.

Who ultimately pays is unresolved. Certification fees and insurance premiums land on the AI vendor first, then on the enterprise buyer. For a vendor already absorbing heavy inference costs, the assurance layer is one more line item — cheap if it collapses a nine-month security review, expensive if procurement learns to accept the mark as a formality.

Where the money points

The $40 million is a bet on a sequence: standards, then insurance, then liability. If enterprises can insure an agent's mistakes, procurement stops stalling. The insurers, not the vendors, end up setting the effective bar.

Assurance routeIndependent testLiability transferProcurement speed
Private certification (AIUC-1) ✔ 5,000 adversarial scenarios, quarterly ✔ insurance up to $50M ✔ shortens security review
Regulatory framework (EU AI Act, NIST) ◐ conformity assessment, periodic ✗ none ◐ slow, jurisdiction-bound
Vendor self-attestation ✗ self-reported ✗ none ◐ accepted, low trust

Comparison of enterprise assurance routes, 2026

The distinction that matters for investors is between a standard and a checkpoint. A checkpoint is a one-time gate. A standard is a system other companies build on, price against and insure through. AIUC is selling the second, at the moment when every large enterprise is asking the same question about the agents it deployed last quarter.

Its own answer is the least interesting part. The interesting part is whether anyone outside the company accepts it.

⚠️
The signal to watch
A regulator, or a major insurer outside the company's own book, treating the AIUC-1 mark as sufficient. Until that happens, the standard's authority rests on the customers willing to pay for it.
AIUC raises $40M to begin auditing frontier AI models
The funding announcement and the shift from certifying agents to auditing the underlying frontier models.
The clearest account of what changes when the certification layer moves up the stack.
Launching AIUC-1, the standard for AI agents
The original standard document: six risk areas, 50-plus safeguards, and the institutions that helped draft it.
Primary source — the standard itself, not a summary of it.
ElevenLabs secures first AI-agent insurance policy
The first live policy built on AIUC-1 certification — the point where a standard became an insurable risk.
The precedent that carries the whole investment case.