Skip to main content
Live
Main content

AIUC raises $40M Series A to certify enterprise AI agents against rogue behavior

The startup, founded by an early Anthropic hire and METR's former COO, has built a SOC 2-style audit standard for AI agents.

Jaeden Schafer
Editor in Chief · · 5 min read
AIUC raises $40M Series A to certify enterprise AI agents against rogue behavior

Artificial Intelligence Underwriting Company, or AIUC, has raised a $40 million Series A led by Ribbit Capital to build a third-party audit and certification layer for enterprise AI agents. The round, announced Tuesday, brings AIUC's total funding to $55 million after a $15 million seed from Nat Friedman's NFDG fund, Emergence, Terrain, and Anthropic co-founder Ben Mann. First Harmonic also participated in the Series A. Cursor, Lovable, Harvey, and ElevenLabs are named as customers.

The company was founded by Rune Kvist, an early Anthropic employee, and Rajiv Dattani, who served as COO of the AI safety research organization METR from 2024 to 2025 and remains on its board. The pair are brothers-in-law. Their pitch to investors and to enterprise buyers is that intelligence is no longer the bottleneck for AI deployment inside regulated industries — accountability is.

AI is getting smarter at an increasingly rapid rate. The surprising thing about AI is that it becomes harder to adopt and harder to control as AI gets smarter, not easier.
Rune Kvist, AIUC co-founder

AIUC has modeled its approach on SOC 2, the cybersecurity compliance framework that became a de facto requirement for enterprise software vendors over the past decade. Its standard, AIUC-1, was built with input from a consortium of about 250 security and risk leaders — the people inside banks, hospitals, and governments who sign off on procurement.

Key facts

  • 01AIUC raised a $40M Series A led by Ribbit Capital, bringing total funding to $55M after a prior $15M seed.
  • 02The startup runs AI agents through a suite of about 5,000 tests covering jailbreaks, hallucinations, and data leaks.
  • 03Cursor, Lovable, Harvey, and ElevenLabs are named as early customers of the certification service.
  • 04AIUC's audit standard, AIUC-1, was shaped by a consortium of roughly 250 enterprise security and risk leaders.
  • 05Each audit produces a roughly 100-page report, with humans verifying results generated by AI-run tests.

The core product is a testing service that runs an agent through a suite of roughly 5,000 tests covering jailbreaks, hallucinations, and data leaks. The output is a roughly 100-page report showing where the agent behaves safely and where it fails. AIUC uses AI agents to run the tests and AI to analyze the results, with humans verifying the final audit.

The addressable market is defined less by model capability than by liability. Enterprise buyers have signed contracts promising customers that certain behaviors won't happen, and no vendor can currently prove compliance without an outside evaluator.

Dattani framed the consortium as the source of the standard's specificity — buyers dictate what gets tested, and the tests evolve with what the buyers actually worry about.

The competitive frame is worth naming directly. METR, where Dattani was COO, does similar evaluation work but has focused mainly on capability rather than safety, and it works with the frontier labs themselves rather than downstream enterprises. METR was one of the independent research organizations OpenAI used to investigate its recent Hugging Face incident. AIUC is positioning itself in the tier below — testing the agents that regulated buyers want to deploy in production, not the frontier models that create them.

The timing lines up with a broader shift in how frontier lab leadership talks about deployment risk. Anthropic CEO Dario Amodei has called for the AI industry to pace frontier development, citing a rise in bad-behavior incidents, and floated the idea of requiring frontier labs to use embedded third-party evaluators — naming METR as one possibility. AIUC isn't proposing to embed at customer sites, but the underlying logic is the same: independent verification is becoming a precondition for enterprise adoption. Anthropic researcher Jacob Coxon quit the day before AIUC's announcement, warning that AI could pose an existential risk by the end of the decade.

Related · from this week
Anthropic details four cases of its own AI models hacking outside companies
Jaeden Schafer · 5 min read →

The skeptical read is that AI-audits-AI has an obvious circularity problem. If the tester and the tested share failure modes, a clean report may reflect blind spots rather than safety. AIUC's answer is that humans verify the final audit and that the consortium of buyers constantly updates what gets tested — but the industry has no track record yet for whether a 100-page report meaningfully reduces incident rates once an agent is deployed against real users. AIUC-1 will only matter if procurement teams treat it the way they treat SOC 2, and that adoption curve is a multi-year project.

The bet is that AI safety becomes a compliance business before it becomes a research one. SOC 2 didn't win because it was intellectually elegant; it won because enterprise procurement stopped taking meetings without it. If AIUC can get one large bank or one federal agency to require AIUC-1 for agent vendors, the standard has a path to becoming the default line-item in every enterprise AI RFP. That is a much larger business than red-teaming frontier models, and it explains why Ribbit — a firm built on financial-services infrastructure — led the round rather than a pure AI-focused fund.

ShareXLinkedInEmail
AI Box

Every AI model. One chat.

The latest models from ChatGPT, Claude, Gemini, Sora, ElevenLabs — 80+ models in a single chat. Compare answers side by side. Pick the best one every time.

  • ChatGPT, Claude, Gemini, Grok, DeepSeek — in one chat
  • Generate images & video with Sora, Veo, Ideogram
  • Compare any two models side by side
  • From $8.99/mo · 80+ models, all included
Try AI Boxaibox.ai
Trusted by 3,000+ teams
Got a tip?

Working on something we should cover, or seeing a story we missed? Send leads, documents, or feedback to hello@aichatdaily.com. For sensitive tips, see our secure tips page for Signal and PGP options.

Spotted an error? Email hello@aichatdaily.com with the URL and the issue, or read our full corrections policy.

AI Box Daily briefingFree · Daily · No fluff

Stay ahead of everyone in AI.

The tightly edited AI news email engineers, founders, and investors actually open. One email. Every weekday. Five minutes to finish.

Loved by 10,000+ AI professionals
Free forever. Unsubscribe with one click.

The briefing read inside teams at

Keep reading

More from Security

Anthropic logo
Security

Anthropic details four cases of its own AI models hacking outside companies

A new report catalogs Claude models breaking into third-party systems as a researcher's resignation letter goes viral.

Jaeden Schafer5 min read
AI agent hacks push US and China researchers toward safety cooperation
Security

AI agent hacks push US and China researchers toward safety cooperation

Chinese labs are pouring resources into agentic safety and cyber benchmarks, and researchers on both sides say isolation is becoming untenable.

Jaeden Schafer5 min read
Meta logo
Security

Meta's AI support agent handed over Instagram accounts to attackers who just asked

Attackers told Meta's AI customer support agent to change the email on target Instagram accounts — including the dormant Obama White House handle — and it complied.

Jaeden Schafer5 min read