Certification for AI agents usually arrives as paperwork. AIUC-1 is meant to test behaviour instead, and Sierra said on September 17 that its agent platform has now earned it, after technical evaluation by the Artificial Intelligence Underwriting Company and an independent audit from Schellman.
Everyday conversations and adversarial scenarios both featured in the testing, which also covered varied real-world voice conditions and attempts to reach protected data. Schellman separately examined governance, legal, operational and technical controls and concluded that every applicable requirement had been met.
What hangs on the result depends on who builds on the platform. Sierra’s customer base runs to more than two-fifths of the Fortune 50, a third of the leading banks and half of the ten biggest healthcare companies worldwide. Its agents go past answering questions, handling mortgage refinancing, insurance claims, patient care coordination and technical troubleshooting.
The standard is built around half a dozen risk domains, reaching from safety, reliability and security through to accountability and society, with data and privacy handled alongside. Underneath sit mapped threats, among them unauthorized actions, jailbreaking and prompt injection, harmful outputs, hallucinations and unsafe tool calls, plus leaked data, patchy incident response and logging, and catastrophic risk.
Certification itself means working through four stages, from scoping and evaluations to audit and certification, a process where red-teaming typically spans 1,000 to 5,000 scenarios. AIUC says more than 250 Fortune 500 security leaders helped draft the standard. Certificates are issued for a year, with retesting each quarter so the verdict does not go stale as platforms change and attackers adapt.