On September 15, 2026, a company called AIUC, short for the Artificial Intelligence Underwriting Company, raised a $40 million Series A led by Ribbit Capital, with participation from First Harmonic, bringing its total raised to $55 million. The name is the thesis. AIUC is trying to build for AI agents what the insurance industry built centuries ago for ships and buildings: a way to test a risk, certify it, and stand behind it financially. As enterprises move from experimenting with agents to deploying them, that assurance layer is becoming its own market, and this raise is a clear marker of it.
The problem AIUC is pricing
The gap AIUC targets is the one between a demo and a deployment. An agent that works impressively in a controlled test still asks an enterprise to trust it with real actions: sending messages, moving data, updating systems, spending money. The blocker to adoption is often not capability but accountability. If an agent leaks data or takes a harmful action, who is liable, and on what evidence was it deemed safe to run? Without a standard answer, every buyer has to build its own, which is slow and inconsistent.
AIUC's response is to borrow a proven shape. Its standard, AIUC-1, is described as a SOC 2-style framework for AI agents, the same way SOC 2 became a common language for whether a software vendor handles data responsibly. Instead of every enterprise inventing its own agent risk review, a certificate against a shared standard lets a buyer accept one audit rather than run twenty.
What a certification actually checks
AIUC-1 borrows the shape of a security audit. It probes an agent against roughly 5,000 adversarial scenarios grouped into five failure categories, then repeats the check on a schedule rather than once.
Source: AIUC Series A announcement, September 15, 2026. Adopters named include Cursor, ElevenLabs, Harvey, KPMG, Lovable and UiPath.
How AIUC-1 works
The standard probes an agent against roughly 5,000 adversarial risk scenarios, grouped into failure categories that map to the ways agents actually go wrong: jailbreaks that bypass guardrails, hallucinations that produce confident falsehoods, prompt injection that smuggles in hidden instructions, anomalous behavior outside the intended scope, and data leaks. Crucially, certification is not a one-time stamp. AIUC-1 is backed by quarterly audits, so an agent is re-tested against emerging attack methods rather than certified once and assumed safe forever. That cadence is the difference between a standard that tracks a moving threat and a badge that ages out the moment attackers adapt.
The company reports that AIUC-1 is already used to certify agents including Cursor, ElevenLabs, Fin, Harvey, KPMG, Lovable, and UiPath, a list that spans coding, voice, support, legal, and enterprise automation. The founders come from the center of the AI-safety world: Rune Kvist was an early employee at Anthropic, and Rajiv Dattani is a former chief operating officer of METR, the evaluation organization. That lineage is part of the pitch, because a certification is only as credible as the people defining what it tests.
AIUC is trying to build for AI agents what the insurance industry built for ships: test the risk, certify it, and stand behind it.
On the underwriting model
Where the underwriting comes in

The word underwriting is doing real work in the company's name. Certification says an agent met a standard; insurance says someone will pay if it fails anyway. Pairing the two is what turns a test into confidence a buyer can act on, because it aligns the certifier's incentives with the outcome. An underwriter that has to cover losses has a direct reason to make its standard genuinely predictive rather than a rubber stamp. That is the same logic that made insurance markets, from marine cargo to fire risk, into engines of safety standards long before regulators arrived: the party on the hook for losses is motivated to measure risk honestly.
It is also where the honest caveats live. A certificate is a point-in-time judgment against a defined set of tests, not a guarantee an agent will never fail, and the coverage behind it is a commercial product with limits and exclusions like any other. The value is not certainty. It is a shared, repeatable, financially backed way to reason about agent risk, which is a large improvement over each enterprise guessing on its own, but it is not the same as proof of safety.
Why it matters
The emergence of a certification-and-insurance layer is a sign the agent market is maturing. Standards and underwriting tend to appear when a technology moves from early adopters willing to absorb risk to a broader base that needs to justify the risk to someone else, a board, a regulator, a customer. Whether AIUC-1 specifically becomes the common standard, or one of several, is unknowable this early, and competing frameworks are likely. What is clearer is the direction: agents are becoming infrastructure, and infrastructure gets audited and insured.
That direction rewards buyers who keep their agent stack legible and portable. The easier it is to see what an agent is doing and to move it between models and providers, the easier it is to certify, to govern, and to swap out if a certification lapses. Model-agnostic platforms lean this way by design, Metir among them, keeping the model and tooling as inspectable, swappable components rather than a sealed box, which is exactly the property an auditor and an underwriter want to see. A certificate is easier to trust when the thing behind it is not a black box welded to one vendor.
The takeaway
The verifiable facts: on September 15, 2026, AIUC raised a $40 million Series A led by Ribbit Capital, taking its total to $55 million, to scale AIUC-1, a SOC 2-style standard that tests enterprise AI agents against roughly 5,000 adversarial scenarios with quarterly re-audits, already used to certify agents from Cursor, ElevenLabs, Harvey, KPMG, Lovable, UiPath, and others. The larger meaning is that AI agents now have an assurance market forming around them. Certification says an agent passed a test; the insurance beside it says someone will pay if it fails anyway, and that pairing is what turns a promising agent into one an enterprise can actually deploy.
Sources:
- AIUC Raises $40 Million to Certify Enterprise AI Agents | SecurityWeek
- AIUC raises $40M Series A from Ribbit & First Harmonic to build confidence infrastructure for frontier AI | PR Newswire
- AIUC raises a $40M Series A led by Ribbit Capital to audit and certify AI agents against its own SOC 2-style safety standard | Shopifreaks
- AIUC Raises $40M to Build the Certification and Insurance Layer That Makes Agent Governance Auditable | Yahoo Finance
- Series A to build the confidence infrastructure for frontier AI | AIUC
Image credits
Hero photograph: the Lloyd's building in the City of London, historic home of the insurance and underwriting market, by Michael Garlick via Wikimedia Commons, licensed under CC BY-SA 2.0. In-body photograph: the City of London insurance district, by Tom Parnell via Wikimedia Commons, licensed under CC BY-SA 2.0. These photographs illustrate the underwriting tradition AIUC applies to AI agents.

Anthropic