The Pulse
AIUC Raises $40M to Certify Enterprise AI Agents
Artificial Intelligence Underwriting Company has raised a $40 million Series A led by Ribbit Capital to test and certify AI agents for enterprise use. The startup says its AIUC-1 standard evaluates agents for security, reliability, hallucin

AI.info Team ·
AIUC’s $40 Million Test for Enterprise Agents
Artificial Intelligence Underwriting Company has raised $40 million in a Series A led by Ribbit Capital, putting a new certification business at the center of the race to make autonomous software acceptable to large organizations. First Harmonic also participated in the round, according to TechCrunch.
The San Francisco startup, founded by Rune Kvist and Rajiv Dattani, has now raised $55 million. Its earlier $15 million seed round came from Nat Friedman’s NFDG fund, Emergence, Terrain and Anthropic co-founder Ben Mann, among others. AIUC says its customers include Cursor, Lovable, Harvey and ElevenLabs.
AIUC is building a third-party testing and certification layer for AI agents rather than another agent platform. Its stated goal is to give companies a way to examine how an agent behaves before allowing it to access customer data, internal systems or business workflows.
From Anthropic and METR to an Audit Firm for Agents
Kvist is an early Anthropic employee. Dattani served as chief operating officer of the AI safety research organization METR from 2024 to 2025 and remains a board member there. METR has tested whether frontier AI systems can reliably complete tasks, while AIUC is applying a related evaluation model to enterprise risks such as unsafe tool use, data exposure and unreliable outputs.
“Banks, hospitals, governments and militaries no longer decline to deploy AI because a model isn’t smart enough. They decline because they’ve made commitments to their own customers about what a system will and won’t do, and nobody can currently guarantee that.”
Rune Kvist, co-founder, Artificial Intelligence Underwriting Company, quoted by TechCrunch
The distinction matters for procurement teams. Traditional software reviews can examine access controls, code and operating procedures, but an AI agent can produce different results from similar instructions, interact with outside tools and fail in ways that are difficult to predict from documentation alone.
AIUC-1 Puts Agents Through Thousands of Scenarios
AIUC’s standard, called AIUC-1, is modeled partly on SOC 2 and covers six areas: data and privacy, security, safety, reliability, accountability and societal risks. The company says the standard was shaped with a consortium of about 250 security and risk leaders who buy or oversee AI systems.
AIUC runs agents through a suite of about 5,000 tests involving jailbreaks, hallucinations and data leaks. The process produces a roughly 100-page report describing where an agent performs safely and reliably, as well as the areas where it fails or requires additional safeguards.
The company uses AI agents to run tests and AI to analyze the resulting data, but humans verify the final audit. That division of labor is central to AIUC’s pitch: automated testing can cover a large number of cases, while human reviewers remain responsible for the certification decision.
AIUC’s own description of AIUC-1 says certification includes technical evaluations, an audit of operational and policy controls, and a certificate valid for one year. The company’s documentation says technical evaluations are repeated quarterly, while the broader controls are reviewed annually.
Certification Is Not a Guarantee
AIUC-1 does not promise that an agent will never fail. The company’s certification FAQ says no standard can eliminate the risks of deploying probabilistic systems and describes certification as an assessment of controls at a point in time, not a warranty of future behavior.
That limitation is significant as agents gain access to email, payment systems, customer records and software development tools. A certificate can make vendor comparisons easier, but it cannot tell an enterprise whether an agent is appropriate for every workflow or prevent failures caused by a change in model, tools, permissions or deployment conditions.
Dattani told TechCrunch that AIUC’s reports are intended to show buyers both where an agent passes and where concerns remain. The startup is therefore selling an evidence package as much as a badge: test results, audit findings and a defined account of what the certified system can and cannot be trusted to do.
Ribbit’s Bet on the Trust Layer
Ribbit Capital’s investment backs a business model that combines standards, testing and certification around a category that still lacks a single accepted review process. AIUC says its customer list already spans coding, legal, voice and automation products, giving the company access to different classes of agent behavior.
The immediate question is whether enterprises will treat AIUC-1 as a meaningful procurement requirement or as one more voluntary mark among SOC 2, ISO 42001, internal red-team reports and vendor disclosures. AIUC’s $40 million round gives the company the resources to expand its testing operation, auditor network and customer base, but the value of the certificate will depend on how much detail buyers receive and how consistently the standard identifies failures.