Partnerships

Credo AI Brings AIUC-1, the World's First AI Agent Standard, into the AI Governance Operating Layer

Credo AI turns independent agent assurance into continuous governance and builds a stronger path to independent audit

September 22, 2026
Author(s)
Credo AI
Contributor(s)
Jerome J. Sanders
Enterprise AI enters its verification era

In August, OpenAI disclosed that during internal cybersecurity evaluations, its models circumvented controls meant to isolate them from the internet, exploited vulnerabilities in shared infrastructure, and reached third-party systems at Hugging Face. OpenAI called it a “warning shot.” Weeks later, Anthropic CEO Dario Amodei argued in “We Must Pace the Frontier” that increasingly capable systems need safeguards that keep pace, and proposed embedded third-party evaluators with ongoing access to verify safety commitments.

Those are frontier-model events. The underlying issue is already in the enterprise: as agents take on more autonomy and more access, trust can't rest on a vendor's word or a one-time internal review.

The question changed

Gartner expects 40% of enterprise applications to include task-specific AI agents by the end of 2026, up from less than 5% in 2025,  and the average global Fortune 500 enterprise to run more than 150,000 agents by 2028. Only 13% of organizations say they have the right agent governance in place. Gartner's forecast for what happens next is blunt: by 2027, 40% of enterprises will demote or decommission autonomous agents because governance gaps surfaced only after a production incident.

Security, risk, procurement, and engineering used to ask whether the agent works. Now they ask what evidence proves it can be trusted with this data, these tools, and this much autonomy.

AIUC-1 gives the market a common bar

The Artificial Intelligence Underwriting Company built AIUC-1, the first comprehensive certification standard for AI agents, with enterprise security leaders, covering security, safety, reliability, accountability, data and privacy, and societal risk. It's refreshed quarterly as capabilities, threats, and enterprise requirements change, and certification pairs technical evaluations with an independent audit rather than asking customers to accept a vendor's own claims.

AI-native companies are already using it to clear enterprise procurement. Harvey became the first legal AI platform to certify, passing more than 3,000 evaluations with zero critical failures. Cursor and Lovable became the first coding agents to earn it. Accredited auditors, including Schellman, also a Credo AI Audit & Assurance partner, perform the independent review. Their independence is the point.

Three distinct roles make the model work, and confusing them breaks it. 

  1. AIUC maintains the requirements, runs quarterly technical evaluations, and issues certificates. 
  2. Accredited auditors independently assess the controls and prepare the audit report. 
  3. Credo AI operationalizes the standard inside the enterprise, mapping AIUC-1 requirements to the agents they apply to, where GAIA, our AI governance assistant, helps teams turn requirements into owned controls, current evidence, and a live record of how each agent is actually governed.

Credo AI does not issue AIUC-1 certification and does not replace independent review. We make sure there's something solid underneath it.

“Enterprises don't lack frameworks for AI risk — they lack the evidence to prove their agents meet them. Credo AI already sits where that evidence lives, offering companies a fast-track for AIUC-1 certification.” — Rajiv Dattani, Co-founder, AIUC
From audit scramble to continuous evidence

Anyone who has prepared for an enterprise audit knows the problem. The evidence exists, but it's scattered: policies in one system, approvals in another, test results in engineering tools, vendor information in procurement, remediation status in tickets and spreadsheets. Teams spend weeks reconstructing who approved what.

With AIUC-1 in the Credo AI Governance Platform, that evidence becomes a byproduct of governance instead of a project before every review:

  • Requirements map to the right agents and controls
  • Evidence is captured as the work happens with owners and remediation tracked
  • A reviewable history builds automatically as the system changes
  • The same evidence supports other requirements, such as ISO/IEC 42001, the NIST AI RMF, the EU AI Act, or internal policies, organizations can reuse

This makes organizations better prepared for independent review. It doesn't make the review any less independent, and that distinction matters, because AIUC-1 certificates are valid for twelve months while the agent underneath them never stops changing.

“Independent assurance is becoming essential to enterprise AI. But an audit is a point in time, while agents keep changing. Our role at Credo AI is to make the governance and evidence underneath that assurance continuous, so organizations can move faster without asking customers, boards, regulators, or auditors simply to take their word for it.” — Navrina Singh, Founder and CEO, Credo AI

Both sides of the trust equation
Every agent deployment has two parties: one proving the agent can be trusted, one deciding whether to believe it. AI-native companies live on the first side. Enterprises increasingly sit on both.

If you're proving it, a strong product still stalls in procurement, security wants evidence, risk and legal want documented controls with clear owners, and customers want to know whether anyone independent has tested the safeguards under pressure. AIUC-1 gives you a common standard and a path to independent certification. 

Credo AI makes the governance behind it routine, so evidence isn't rebuilt for every enterprise customer, diligence request, and audit. You keep shipping fast and still have a current basis for trust as the product changes.

If you're evaluating it, independent assurance replaces the bespoke questionnaire with a consistent basis for diligence. And when that same enterprise builds its own agents, it has to produce the proof too, which is why Credo AI holds the portfolio in one place: what agents exist, who owns which controls, what evidence backs them, and what's changed since the last review.


What replaces "trust us"

The OpenAI-Hugging Face incident and the debate about pacing the frontier are reminders of a broader shift. The more capable and autonomous these systems become, the less credible self-attestation becomes on its own.

Credo AI’s role is to make that work trusted, ensuring the scope stays clear, controls stay owned, and evidence stays current as agents change. Credo AI is the same platform Gartner named a Visionary in its inaugural Magic Quadrant for AI Governance Platforms, and that Forrester and IDC have each named a Leader.

In the agentic era, trust cannot be a claim made once at deployment. It has to be demonstrated, reviewed independently, and kept current as things change. The next chapter of trusted AI will not be built on 'trust us.' It will be built on evidence.


Get started with AIUC-1 in Credo AI

Standards set a common bar. Independent auditors keep the review honest. Continuous governance is what makes the bar hold between reviews.

AIUC-1 is available now in the Credo AI Governance Platform. Operationalize it alongside your existing governance requirements and keep the evidence current for ongoing oversight and independent assurance.

Book a call with us to see how it works across the agents you buy and the agents you build. https://www.credo.ai/

DISCLAIMER. The information we provide here is for informational purposes only and is not intended in any way to represent legal advice or a legal opinion that you can rely on. It is your sole responsibility to consult an attorney to resolve any legal issues related to this information.