Your Agent Feature Now Needs A Notarized Answer
Certification, insurance, permission layers and shipped admin controls all landed at once, and together they decide whether an enterprise ever switches your agent on.
Why this standard tightens
Buyers ask for eval numbers, not a logo. Ratings agencies never paid for a wrong rating; insurers pay claims. Latent.Space reports Lloyd's of London, roughly 400 years old and never having failed to pay a claim, uses AIUC-1 as its underwriting framework, with eval results feeding pricing directly. ElevenLabs bought what is described as the first AI agent insurance policy. AIUC-1 refreshes quarterly; the Q2 revision added MCP agents and agent-to-agent communication.
What clearing it costs
- Scope: 6 categories of Fortune-1000 CISO concerns, roughly 51 requirements, 130 controls.
- Three control types: technical guardrails, independent third-party testing, policy (named owner, incident plans). Policy controls are nearly free.
- Testing: thousands of simulations quarterly on three numbers: jailbreak resistance, hallucination rate, data leakage.
- Timeline: 3 to 10 weeks with remediation. 3 weeks if the security program is mature, 10 if it isn't.
AIUC says most of its customers optimized the happy path and hold guardrails that do not work.
What negligence law does to a control set
Air Canada is the precedent: a chatbot hallucinated a refund policy and the deployer was held to it. Negligence turns on duty of care measured against widely adopted standards, so once a control set is published and adopted, shipping without it becomes evidence.
Spurious Tool Use, via AI Breakfast, finds RL-trained agents fire tools on surface cues, spurious invocation rates rising up to 39% under counterfactual tests. Happy-path evals pass; users find it in front of a paying customer.
Controls that already shipped
HubSpot's five controls, which TLDR IT calls a de facto spec: install approvals, granular OAuth scopes, MCP access limited to company-provisioned accounts, per-app activity logs, warnings when deactivating a user who owns an integration. Claude Enterprise adds per-user spend visibility and org-level model defaults. Computerworld reduces these to four primitives: scoped credential, permission ceiling, supervision hook, named accountable human. Refactoring adds action-level scoping: read, write, delete, open-a-PR and message-a-customer governed separately.
No single vendor covers install approval, permission granularity, MCP posture, cost visibility and accountability together. Controls down the side, vendors across the top; empty rows are the audit finding.
Where the evidence disagrees
Refactoring's adoption spread rests on a study cited without link or methodology, inside a paid partnership with a vendor selling the category; correlation is not causation, as the author concedes. AIUC has paid zero claims and writes the standard it sells. Requirements barely change across frameworks, and eval awareness is moving the source of truth from pre-launch scores to production monitoring.
The control list is the same whoever wins: adversarial testing, guardrails that work, groundedness on commitments, an incident plan, a named owner, and replayable production traces.
What to do
Measure jailbreak resistance, hallucination rate and data leakage on your single highest-traffic agent surface this sprint, and hand the three numbers to your exec sponsor with a remediation estimate.
Enumerate every path where your agent can commit the company — refund, discount, price quote, policy statement, SLA — and gate each behind retrieval grounding or human confirmation before your next release.
Commission a gap analysis against a published agent-control set this quarter and close the policy controls — named accountable owner and documented incident response — regardless of whether you certify.