← All posts / Industry

SOC 2 for AI Agents: AIUC Raises $40M to Turn Agent Safety Into a Certifiable, Insurable Product

Founded by an early Anthropic hire and METR's former COO, the Artificial Intelligence Underwriting Company raised a $40M Series A led by Ribbit Capital for AIUC-1, a SOC 2-style audit standard that has already certified agents from Cursor, Lovable, Harvey, and ElevenLabs.

SOC 2 for AI Agents: AIUC Raises $40M to Turn Agent Safety Into a Certifiable, Insurable Product

The most telling quote from AIUC’s $40 million Series A announcement does not come from an investor. It comes from co-founder Rune Kvist, an early Anthropic employee: “Banks, hospitals, governments and militaries no longer decline to deploy AI because a model isn’t smart enough. They decline because they’ve made commitments to their own customers about what a system will and won’t do, and nobody can currently guarantee that.”

That gap — between what AI agents promise and what anyone can independently verify — is the business. On September 15, 2026, the San Francisco startup Artificial Intelligence Underwriting Company (AIUC) announced the round, led by Ribbit Capital with participation from First Harmonic, bringing its total disclosed funding to $55 million. Its previous $15 million seed round included Nat Friedman through NFDG, Emergence, Terrain, and Anthropic co-founder Ben Mann.

Who is behind it

The founding team is a study in the industry’s current moment. Kvist was an early Anthropic employee; his brother-in-law and co-founder Rajiv Dattani was chief operating officer of METR from 2024 to 2025 and remains a METR board member. METR, the independent AI evaluation organization, has spent years running task-completion assessments for the frontier labs and was one of the research orgs OpenAI enlisted to investigate its Hugging Face incident.

In other words, this is not a compliance startup opportunistically pivoting to AI. It is built by people from the safety-evaluation world who concluded that the bottleneck for enterprise adoption is no longer model capability, but provable trust.

What AIUC-1 actually is

AIUC’s model borrows deliberately from cybersecurity. Just as SOC 2 became the de facto audit standard that let enterprises buy cloud software without bespoke security reviews, AIUC has developed a standard called AIUC-1 and a testing service that validates AI agents against it.

The standard was not written in a vacuum. AIUC assembled a consortium of roughly 250 security and risk leaders — the people who actually buy agents inside banks, hospitals, and governments — and meets with them monthly. The question, per Dattani: “When you’re buying agents from someone, what would you look for? What are the questions you’d want to ask, and what would you want to see addressed?”

The product of that feedback is a suite of approximately 5,000 test scenarios covering jailbreaks, hallucinations, and data leaks. An agent is run through the suite, and the output is a roughly 100-page report detailing where the agent performs safely and reliably — and where it does not. Certification is not permanent: agents are independently audited and recertified every quarter to keep pace with evolving threats.

Notably, AIUC uses AI agents to run the tests and AI to analyze the data, with humans verifying the final audit. The certification is also tied to insurance coverage — the “underwriting” in the company’s name is literal, with audit results feeding directly into whether an agent can be insured.

The customers are the tell

AIUC’s named customers read like a list of the most widely deployed AI agents in the enterprise: Cursor (arguably the world’s most popular coding agent), Lovable, Harvey (the first legal AI company to achieve AIUC-1 certification, in July 2026), and ElevenLabs (the first voice AI company, certified after its agents underwent 5,835 technical tests across 14 risk categories). In February 2026, ElevenLabs secured what it described as first-of-its-kind AI agent insurance backed by AIUC-1 certification.

The direction of demand matters here. These are not companies being dragged into auditing by regulators — the binding US mandates do not exist yet. They are vendors pre-emptively buying certification because their enterprise buyers are asking for it in procurement. One ElevenAgents customer cited in AIUC’s materials built a voice agent handling property transactions; certification was what made the deployment signable.

Why this lands now

The timing is not accidental. The same week as the Series A, the AI industry is consumed by a public fight over pacing: Dario Amodei’s September 12 essay urging frontier labs to slow down, executive responses from Microsoft, OpenAI, and xAI, and legislative proposals ranging from mandatory third-party audits (the FRONTIER Act, which OpenAI has endorsed) to an outright superintelligence ban. Amodei specifically floated requiring frontier labs to accept embedded third-party evaluators, naming METR as one candidate.

AIUC is not proposing to embed itself at frontier labs — its focus is the agent layer that enterprises deploy. But the underlying thesis is identical: independent assessment is the mechanism that converts safety pledges into checkable claims. If the FRONTIER Act’s audit provision becomes law, someone has to run those audits, and a company co-founded by an ex-METR operator, with Cursor and Harvey already signed, is positioned about as well as anyone to be the auditor of record for the agent economy.

There is also a hard-nosed financial reading. As TechCrunch notes, the financing layers a familiar cybersecurity model onto a new set of AI risks, and the buyers’ consortium means the standard is shaped by demand rather than by the vendors being graded. That is how SOC 2 won, and it is why an A-list investor group — Ribbit, which led the round, plus Friedman, Mann, Emergence, and Terrain at seed — bet early.

What to watch

Two questions will decide whether AIUC-1 becomes infrastructure or a footnote. First, independence: quarterly recertification and a buyer-shaped standard are good signs, but a certification industry earns trust only by failing vendors in public occasionally, and it remains to be seen whether AIUC will publish negative results. Second, scope: the current customers are well-scoped agents — coding assistants, legal research, voice interfaces. The hard problem on the horizon is auditing composite systems, where multiple agents from multiple vendors chain together, and where the 404 Media catalogue of real-world agent failures (deleted inboxes, cancelled flights, compromised accounts) actually originates.

For enterprises, though, the practical takeaway is immediate. If you are deploying agents and your procurement process has no answer to “who verified this,” a SOC 2-style certification market now exists, with named reference customers, quarterly cycles, and an insurance hook. The safety debate argues about the frontier; AIUC is quietly building the plumbing for everything behind it.