As companies accelerate the deployment of AI agents, verifying whether these systems are secure and controllable has become a practical concern in the procurement process. AIUC, founded by Rune Kvist, an early employee of Anthropic, and Rajiv Dattani, former Chief Operating Officer of the AI safety research organization METR, is attempting to standardize this process as a service.
Announcing the completion of a $40 million Series A round
AIUC stands for Artificial Intelligence Underwriting Company. The company announced on Tuesday that it has completed a $40 million Series A funding round led by Ribbit Capital, with participation from First Harmonic.
Prior to this, AIUC had completed a $15 million seed round, with investors including Nat Friedman’s fund NFDG, Emergence, Terrain, and Anthropic co-founder Ben Mann. This brings the company’s total funding to $55 million.
AIUC states that current customers include Cursor, Lovable, Harvey, and ElevenLabs.
Featured AI-powered third-party auditing
The company’s core product is a third-party audit and certification layer built for AI agents. Its approach mirrors the compliance verification model common in cybersecurity, which involves establishing unified standards and then evaluating whether systems meet those requirements through external testing.
Drawing on the widely adopted cybersecurity standard SOC 2, the company has introduced a new standard called AIUC-1, along with a corresponding testing service. The company states that many banks, hospitals, government agencies, and military organizations are not rejecting AI deployment due to insufficient model capabilities, but rather because there is currently a lack of verifiable security assurances.
To establish standards, AIUC organized discussions with approximately 250 security and risk leaders, who are also the decision-makers when their companies procure AI agents. Based on these discussions, the company identified the most pressing concerns of buyers and translated these requirements into test criteria.
Approximately 5,000 tests cover jailbreaks and leaks.
In practice, AIUC will have AI agents undergo approximately 5,000 tests, focusing on their performance in scenarios such as jailbreaking, hallucinations, and data leaks. After the tests are completed, the system will generate a roughly 100-page report detailing which areas the agent performs stably in and which areas still pose risks.
It is worth noting that AIUC also uses AI agents to perform certain tests and employs AI to analyze test data, but the final audit results are still verified by humans.
This approach shares similarities with some of METR’s work. METR previously primarily provided independent testing for cutting-edge model labs, with a greater focus on performance evaluation—whether agents can reliably complete tasks. When OpenAI previously investigated the Hugging Face incident, it also engaged METR for independent research.
Dario Amodei, CEO of Anthropic, recently also called for slowing the pace of frontier AI development and suggested introducing third-party evaluation agencies to observe and verify safety performance. AIUC’s approach does not involve direct integration into client environments; instead, it provides enterprises with an independent external assessment to help them evaluate the scope and risk points of AI agents before procurement.
