LATEST
15 SEP 2026 · AIUC raises $40m Series A17 SEP 2026 · Sierra earns AIUC-1 certification24 SEP 2026 · MSCI details tests of its security agent

Company profile / AI risk

The Insurance Policy for a Machine That Can Act

AIUC wants companies to trust autonomous agents the way they trust elevators: after testing, inspection, and someone agreeing to pay when things go wrong. Its wager is that a certificate becomes more persuasive when an insurer stands behind it.

The agent had a rather sensitive job. At MSCI, it helped manage privileged access: the sort of system that can let a person through a digital door they ought to enter, or one they ought not. A description of its good intentions was never going to be enough for John Rogers, the company’s chief information security officer. He needed evidence an external auditor could use.

So MSCI let a red team at Artificial Intelligence Underwriting Company try to make the agent misbehave. Roughly 1,400 tests later, MSCI had an evaluation report and signed attestation to share as input to its 2026 audit. This is AIUC’s business in miniature. It turns a slippery question - “Can we trust this thing?” - into a set of tests, an audit trail, and, when coverage is purchased, an insurance contract.

The short version
  • AIUC sets a standard called AIUC-1 for agent security, safety, reliability, privacy, accountability and wider harm.
  • It tests agent behavior; accredited auditors examine the operational controls; certified systems are retested at least quarterly.
  • AI vendors can buy AI-specific insurance intended to protect enterprise customers against covered losses.
  • The useful question for any buyer: which agent, which actions, which failure modes, and which policy terms?

A certificate with a financial consequence

Rune Kvist, who was Anthropic’s first product hire, founded AIUC with Rajiv Dattani, formerly a McKinsey insurance partner and a leader at model-evaluation nonprofit METR, and Brandon Wang, its CTO at launch. The company came out publicly in July 2025 with a $15 million seed round. In September 2026 it announced another $40 million, led by Ribbit Capital. It says it has raised $55 million in all.

AIUC co-founders Rajiv Dattani, Rune Kvist and Brandon Wang seated together
Three founders, three disciplines. Rajiv Dattani, Rune Kvist and Brandon Wang brought insurance, AI product and technical experience to the same rather inconvenient question: who carries the loss? Photo: AIUC, via Fortune.

The name sounds as though AIUC uses AI to underwrite ordinary insurance. It does something more peculiar: it underwrites the consequences of AI itself. Its public product runs in three connected stages. AIUC-1 defines what an agent should demonstrate. Technical evaluations try to expose failures under adversarial conditions. Independent auditors review the controls around the system. Insurance can then put money behind covered agent risks.

The division of labor matters. Schellman, the first accredited AIUC-1 auditor, collects audit evidence and reviews governance, security and operational practices. AIUC performs the technical evaluations and issues certification. Its standard is shaped by a consortium it says includes more than 250 security and risk leaders. The same company still maintains the standard and runs the technical testing, so a buyer should read the certification scope and the underlying report, rather than treating the badge as a magic word.

The question changes with the job

A voice agent can misunderstand a caller. A coding agent can publish a secret or install an unsafe package. A legal agent can invent a case. Those are all “AI failures,” but an interchangeable checklist would be absurd. AIUC says its library contains about 5,000 risk-and-attack combinations tailored to business type; individual assessments use a relevant subset. Harvey’s legal platform went through more than 3,000 evaluations. Sierra’s conversational system faced thousands of scenarios, including voice tests with 160 caller personas. Cursor’s coding agent received a review of both agent behavior and operational controls.

~1,400tests of MSCI’s SecOps agent
5,000risk-and-attack combinations in AIUC’s library

Here is the part a buyer can copy without buying anything: start with one agent whose authority makes you nervous. List what it can read, change and send; choose the failures that would hurt; test those, not a generic chatbot; and keep a record that a skeptical outsider could inspect. Rogers and MSCI built risk tiers around that logic. A read-only internal agent gets a smaller set of controls. An agent touching regulated workflows or customer data faces the full bar.

“Pick one high-stakes agent you understand well and test it against AIUC-1 before your auditor asks.”JOHN ROGERS · MSCI CISO

That advice also explains what changed the procurement conversation. Earlier governance frameworks could show a policy existed. MSCI wanted proof of how its agent behaved under pressure. AIUC’s tests produced an attestation and report for external auditors. The move from declared intention to observed behavior is modest in language, substantial in practice.

The price of letting the bot speak

ElevenLabs supplied AIUC’s clearest public insurance example. In February 2026, the voice-AI company announced an AIUC-1-backed policy for its agents. Its systems had undergone more than 5,000 adversarial simulations before coverage went live. The possible loss is easy to picture: an agent tells a customer something wrong, and the mistake becomes a financial claim. AIUC advertises coverage limits up to $50 million, though that ceiling says nothing about what any particular policy covers.

There is no published menu price for an AIUC certification or a standard insurance premium. The public commercial sequence is clearer than the invoice: an AI vendor seeks assessment and certification, then may buy coverage for enterprise customers. Terms, exclusions and price need to be settled for the specific agent and risk. A buyer should ask for the scope, the current evaluation report, the retesting date, and the policy wording. A logo cannot answer a claims adjuster’s questions.

The practical test

Ask the vendor: What can the agent do? What attacks were tried? Who audited its controls? What loss is covered, and for whom?

Where the wager gets harder

AIUC sits between AI security testing, traditional compliance, and commercial insurance. SOC 2 and ISO 42001 can document processes; internal red teams can find flaws; insurance can shift some financial exposure. AIUC’s pitch is to connect those pieces around the behavior of a particular agent. That is attractive when a vendor needs an enterprise buyer to approve an agent with real authority, especially one that talks to customers, touches sensitive data or acts inside important systems.

It is less useful as a shortcut for a small, read-only tool whose failures are cheap and reversible. Nor can a quarterly test guarantee that a changed model, new tool permission or clever attacker will behave like yesterday’s test cases. AIUC itself updates the standard and reruns technical evaluations because that target moves. Insurance only helps to the extent the actual loss fits the actual policy. The unromantic paperwork is, for once, the product.

The company’s next announced step is to extend its audits, standards and insurance from agents toward frontier models. That ambition is larger than the evidence presently available for a single deployed agent. Yet the small version already has a shape: MSCI’s test report, Sierra’s certified conversational system, Cursor’s coding agent and ElevenLabs’ insured voice agents. The old question was whether an AI could do the job. The next one is whether anyone can show what happens when it does the job badly.