AIUC-1
Changelog

AIUC-1 changelog

AIUC-1 is updated formally each quarter to ensure that the standard evolves as technology, risk, and regulation evolves.

The most recent version of AIUC-1 was released on October 1, 2025.

These tenets guide how we update the standard:

Customer-focused. We prioritize requirements that enterprise customers demand and vendors can pragmatically meet— increasing confidence without adding unnecessary compliance.

AI-focused. We do not cover non-AI risks that are addressed in frameworks or regulations like SOC 2, ISO 27001, or GDPR.

Insurance-enabling. We prioritize risks that lead to direct harms and financial losses.

Adapts to regulation. We update AIUC-1 to make it easier to comply with new regulations.

Adapts to AI progress. We update AIUC-1 to keep up with new capabilities, like reasoning capabilities and new modalities.

Adapts to the threat landscape. We update AIUC-1 in response to real-world incidents.

Continuous improvement. We regularly update the standard based on real-world deployment experience and stakeholder feedback.

Predictability. We review the standard and push updates quarterly— on January 1, April 1, July 1, and October 1 of each year.

Transparency. We keep a public changelog and share our lessons.

Backward compatibility. Existing certifications remain valid during transition periods.

We welcome feedback, ideas, suggestions, and criticism— provide input on AIUC-1.

October 1, 2025 release

This is the first quarterly update of AIUC-1. For this update, focus has been on clarifying and specifying requirements to ensure a clear auditing process and avoid ambiguity. In addition, feedback from technical contributors, customers, and audit processes has motivated a stronger adversarial testing requirement and further details on how AIUC-1 compares to ISO 42001.

Overview of key updates

Clarified 13 requirements based on audit experience, customer feedback, and input from technical contributors.

Strengthened adversarial testing requirement to mandate independent third-party testing.

Expanded ISO 42001 crosswalk with gap analysis and descriptive notes to support organizations comparing AIUC-1 and ISO 42001.

Detailed changelog

Date

2025-10-01

AIUC-1 requirement

A001: Establish input data policy, A002: Establish output data policy

Category
Clarification
Change notes

Clarified separation of A001 vs A002: A001 labeled as input data; A002 labeled as output data.

Control activity language adjusted to clarify distinction

Date

2025-10-01

AIUC-1 requirement

A003: Limit AI agent data collection

Category
Clarification
Change notes

Requirement title clarified to emphasize focus on AI agent configuration

Date

2025-10-01

AIUC-1 requirement

A005: Prevent cross-customer data exposure

Category
Specification
Change notes

Specified to reflect that cross-customer data safeguards should apply not just for model training purposes

Date

2025-10-01

AIUC-1 requirement

B001: Third-party testing of adversarial robustness

Category
Specification
Change notes

Specified to require that adversarial testing of system robustness is conducted by a third-party

Date

2025-10-01

AIUC-1 requirement

B003: Manage public release of technical details, B009: Limit output over-exposure

Category
Clarification
Change notes

Clarified separation of B001 vs B009: B001 labeled as managing public release of technical details; B009 labeled as limiting output over-exposure

Requirement text clarified to highlight the distinction

Date

2025-10-01

AIUC-1 requirement

B006: Limit AI agent system access

Category
Clarification
Change notes

Requirement title clarified to emphasize focus on AI agent configuration

Date

2025-10-01

AIUC-1 requirement

B007: Enforce user access privileges to AI systems

Category
Clarification
Change notes

Requirement title clarified to emphasize focus on user access privileges

Date

2025-10-01

AIUC-1 requirement

C005: Prevent customer-defined high risk outputs

Category
Clarification
Change notes

Requirement title clarified to highlight that additional risk areas are defined by customer

Date

2025-10-01

AIUC-1 requirement

C009: Enable real-time feedback and intervention

Category
Clarification
Change notes

Requirement title updated to emphasize human intervention capability in requirement

Date

2025-10-01

AIUC-1 requirement

C012: Third-party testing for customer-defined risk

Category
Clarification
Change notes

Requirement title clarified to highlight that additional risk areas are defined by customer

Date

2025-10-01

AIUC-1 requirement

E013: Implement quality management system

Category
Specification
Change notes

Removed reference to 'high-risk' in requirement to specify that quality management system should apply to entire AI system

Date

2025-10-01

AIUC-1 requirement

ISO 42001 crosswalk

Category
Expansion
Change notes

Expanded AIUC-1 to ISO 42001 mapping with gap analysis and description of gaps to enable easy comparison

Date

2025-10-01

AIUC-1 requirement

Technical testing passing criteria

Category
Specification
Change notes

Specified that companies must pass AIUC-1 technical tests with no P0 or P1 vulnerabilities identified to qualify for an AIUC-1 certificate

Reflected on Certificate overview page

Side-by-side version comparison

AIUC-1 requirement

A001

2025-07-01 version

A001: Establish data use policy

2025-10-01 version

A001: Establish input data policy

AIUC-1 requirement

A002

2025-07-01 version

A002: Define output rights

2025-10-01 version

A002: Establish output data policy

AIUC-1 requirement

A003

2025-07-01 version

A003: Implement contextual data safeguards

2025-10-01 version

A003: Limit AI agent data collection

AIUC-1 requirement

A005

2025-07-01 version

Implement safeguards to prevent cross-customer data exposure when combining customer data from multiple sources for AI model training

2025-10-01 version

Implement safeguards to prevent cross-customer data exposure when combining customer data from multiple sources for AI model training

AIUC-1 requirement

B003

2025-07-01 version

B003: Limit technical over-disclosure

2025-10-01 version

B003: Manage public release of technical details

AIUC-1 requirement

B001

2025-07-01 version

B001: Test adversarial robustness

2025-10-01 version

B001: Third-party testing of adversarial robustness

AIUC-1 requirement

B006

2025-07-01 version

B006: Enforce contextual access controls

2025-10-01 version

B006: Limit AI agent system access

AIUC-1 requirement

B007

2025-07-01 version

B007: Enforce AI access privileges

Establish and maintain access controls and admin privileges for AI systems in line with policy

2025-10-01 version

B007: Enforce user access privileges to AI systems

Establish and maintain user access controls and admin privileges for AI systems in line with policy

AIUC-1 requirement

B009

2025-07-01 version

Implement output limitations and obfuscation techniques to reduce information leakage

2025-10-01 version

Implement output limitations and obfuscation techniques to safeguard against information leakage

AIUC-1 requirement

C005

2025-07-01 version

C005: Prevent other high risk outputs

2025-10-01 version

C005: Prevent customer-defined high risk outputs

AIUC-1 requirement

C009

2025-07-01 version

C009: Collect real-time feedback

2025-10-01 version

C009: Enable real-time feedback and intervention

AIUC-1 requirement

C012

2025-07-01 version

C012: Third-party testing for other risk

2025-10-01 version

C012: Third-party testing for customer-defined risk

AIUC-1 requirement

E013

2025-07-01 version

Establish a quality management system for high-risk AI systems proportionate to the size of the organization

2025-10-01 version

Establish a quality management system for AI systems proportionate to the size of the organization

© 2025 Artificial Intelligence Underwriting Company. All rights reserved.
By accessing or using our website, you agree to our Terms of Service and Privacy Policy.