AIUC raises $40M to certify and insure AI agents

AIUC, founded by Anthropic product veteran Rune Kvist and former METR COO Rajiv Dattani, is building an AI-agent standard that combines audits with coverage for some business losses caused by agent failures.

By · Published

Primary source: TechCrunch

Why it matters

AIUC is turning AI safety from a policy promise into a procurement and insurance product. If its standard gains adoption, it could shape which agents enterprises buy and what controls vendors must prove.

Two professionals collaboratively review complex data on a tablet and paper documents on a polished conference table.

Artificial Intelligence Underwriting Company (AIUC), founded by Rune Kvist and Rajiv Dattani, announced a $40 million Series A on September 15th to build a certification and insurance layer for AI agents. Ribbit Capital led the round, with First Harmonic participating, according to TechCrunch's report.

The financing brings AIUC's disclosed funding to $55 million. TechCrunch reports that Nat Friedman led its earlier $15 million seed through NFDG, joined by Emergence, Terrain, Anthropic co-founder Ben Mann and former security executives. AIUC's valuation was not disclosed.

Kvist and Dattani are brothers-in-law with backgrounds that map unusually well onto the product. Kvist was Anthropic's first product and commercial hire, according to a Cosmos Institute profile, and later became a board member at the Center for AI Safety. METR identifies Dattani as a board member and lists his previous role as COO.

Their shared bet is that enterprise adoption will depend on somebody turning unpredictable agent behavior into a risk that buyers can measure, contract around and insure. AIUC is trying to become that somebody.

A standard designed to unblock procurement

AIUC describes its product as an AIUC-1 audit and certification process paired with insurance that can cover certain AI-specific losses. The AIUC-1 standard covers data and privacy, security, safety, reliability, accountability and societal risks.

The approach borrows from SOC 2, the controls framework that became a common checkpoint for enterprise software vendors. AIUC-1 adds testing for agent-specific behavior, including prompt injections, jailbreaks, hallucinations, harmful outputs and unauthorized tool calls.

TechCrunch reports that AIUC assembled about 250 security and risk leaders to help shape the standard. The same report says AIUC runs agents through roughly 5,000 tests covering issues such as jailbreaks, hallucinations and data leaks. The results produce a roughly 100-page report that humans verify before it is delivered to customers.

AIUC says its certificate gives buyers and vendors a common language and can shorten security and compliance reviews. AIUC also says its insurance offering can provide coverage for some losses, with limits of up to $50 million depending on the policy.

AIUC names Cursor, Lovable, Harvey and ElevenLabs among its customers. It also identifies KPMG's aIQ Capture platform as a use case and Intercom's Fin agent as AIUC-1 certified. ElevenLabs said it completed more than 5,000 adversarial simulations before obtaining AIUC-1 certification and an associated insurance policy for its voice agents.

Those customer names give AIUC credible early distribution among AI vendors selling into large organizations. They do not establish how much revenue AIUC generates, how certification is priced or how much insurance premium is flowing through the platform.

Kvist and Dattani are betting on incentives

Kvist has framed insurance as a mechanism for making AI development safer without waiting for governments to design every control. In August, he wrote that "Incentives are the final boss of alignment."

Rune Kvist on X

Kvist argues that AI needs an institutional layer for assessing and transferring risk before banks, hospitals and governments will entrust agents with sensitive work.

Dattani's case rests on independent AI evaluation and private verification. He has argued that private verification markets can form faster than government oversight. In July, Dattani wrote that large-scale AI coverage will require standards, audits, catastrophe models and incident response.

Rajiv Dattani on X

The Series A is therefore financing a standards race as much as an insurance operation. Standards become valuable when enough vendors, buyers, auditors and insurers use the same one.

Certification has to keep moving

Agent risk presents a harder technical problem than conventional compliance. A software vendor can change its model, prompts, tools, permissions or underlying model provider after an assessment. The same agent may also behave differently when connected to a customer's private data and internal systems.

The practical test will be whether AIUC can keep its reports aligned with the software customers are actually using as agents and their underlying models change.

Certification also assumes the vendor already has functioning safety and governance processes. An audit can identify weak controls and test defenses, but it cannot manufacture internal accountability for a customer that treats the certificate as a purchasing shortcut.

Other security startups focus on controls inside production systems. Onyx Security says its platform inspects agent prompts, tool calls and responses, with controls to alert, block, mask, steer or request human approval. Hush Security says its software assigns identities and delegated permissions to agents and governs whether their actions remain within an approved scope. AIUC's commercial bet centers on assessments, continued testing and insurance tied to certified systems.

The $40 million round gives AIUC capital to expand that network before another standard becomes the default. The opportunity comes from a basic enterprise problem. AI agents are being sold as workers, while the systems for vetting, supervising and insuring those workers are still being assembled.

Reader comments

Conversation for this story loads after sign-in.