Rune Kvist, co-founder of the Artificial Intelligence Underwriting Company (AIUC), often hears the same story from potential clients. “Banks, hospitals, governments and militaries no longer decline to deploy AI because a model isn’t smart enough,” Kvist told TechCrunch. “They decline because they’ve made commitments to their own customers about what a system will and won’t do, and nobody can currently guarantee that.”
This trust gap is the primary reason that 95% of enterprise AI pilots fail to reach production. While companies like those recently funded in the $50M AIR Security seed round are building tools to protect the perimeter, AIUC is taking a different approach. They are building the infrastructure to make the emerging governance stack auditable. As Ribbit Capital founder Micky Malka noted, “We have spent over a decade backing companies in financial services where trust is the most important metric of success. AI is on that same path, and it is moving faster than the systems companies use to evaluate it.”
AIUC, which recently raised a $40 million Series A led by Ribbit Capital with First Harmonic participating, isn’t just another security vendor. Their core product is the AIUC-1, a third-party audit and certification standard developed alongside a consortium of over 250 security and risk leaders from Fortune 1000 firms. The certification process is rigorous, requiring over 5,000 adversarial tests across six risk domains: data and privacy, security, safety, reliability, accountability, and society. These tests are modeled on documented real-world AI failures, and companies must undergo quarterly retests to keep their certification valid.
The “underwriting” in the company’s name is the real differentiator. By partnering with Lloyd’s of London, AIUC provides insurance coverage for AI agents, effectively putting capital behind their certification. When ElevenLabs secured the first AIUC-1-backed policy, it provided $50 million in coverage for risks like hallucination-driven loss, data leakage, and faulty tool actions. As Kvist explained, “AIUC-1 certification was built to address the AI risks that keep enterprises from deploying agents at scale—hallucinations, unauthorized actions, data leakage, security vulnerabilities.”
This model addresses the industry’s ongoing measurement problem, where a lack of standardized metrics makes it impossible to objectively compare the safety of different systems. By providing a concrete, insured standard, AIUC gives procurement teams a clear path forward. Instead of relying on internal assessments, enterprises can now require third-party certification before deployment. This shift is already visible: KPMG became the first Big Four firm to achieve AIUC-1 certification in August 2026, and the inclusion of the standard in the CSA STAR Registry allows organizations to display a trustmark to their customers.
For practitioners, this means moving from abstract safety discussions to verifiable risk transfer. As co-founder Rajiv Dattani put it, “Here’s where it passes and where you can trust it. And here’s where there’s concerns. You should be aware of those references before you make the decision to buy.” Companies like Cursor, Lovable, Harvey, and UiPath are already engaging with these standards to provide a verifiable guarantee that their systems have been tested against known failure modes.
However, it is worth keeping a healthy dose of skepticism. While AIUC-1 is a significant step toward professionalizing AI safety, it is still a nascent category. The effectiveness of these audits depends entirely on the quality of the adversarial testing and the ability of the auditors to keep pace with the rapid evolution of AI capabilities. We have yet to see how these insurance policies will perform in the event of a large-scale, systemic failure. For now, AIUC provides a necessary bridge between the promise of AI agents and the reality of enterprise risk management, but the industry is still in the early stages of defining what “safe enough” actually means in practice.
