Skip to content
Rush Commerce
AI & Automation3 min read

AIUC raises $40M to audit the agents you didn't build

AIUC raised a $40M Series A for AI agent audits against its AIUC-1 standard. Cursor and KPMG are certified. What a small operator should ask vendors instead.

Every SaaS tool you pay for is quietly growing an agent. It reads your inbox, touches your CRM, writes to your store. Nobody sends you a test report. On September 15, a company built to produce exactly that report raised $40 million — and the more useful news for a small operator is the checklist it published, not the round.

What actually happened

TechCrunch reports that the Artificial Intelligence Underwriting Company — AIUC — raised a $40M Series A led by Ribbit Capital, with First Harmonic participating. AIUC's own site puts total funding at $55M, following a $15M seed announced in July 2025 led by Nat Friedman's NFDG, with Emergence, Terrain and Anthropic co-founder Ben Mann. Founders are Rune Kvist, an early Anthropic hire, and Rajiv Dattani, former COO of the AI evaluation lab METR.

The product is a standard plus an audit against it. AIUC-1 covers 12 risk categories and was built with input from more than 250 security and risk professionals. AIUC says Cursor's agents passed thousands of AIUC-1 technical evals across those categories, and that KPMG is the first Big Four firm to certify. ElevenLabs and Harvey are also named. TechCrunch describes audits that run roughly 5,000 scenarios — jailbreaks, hallucinations, data leaks — with agents executing the tests and humans signing the final report, which runs to about 100 pages.

Why AI agent audits matter for your business

You are not buying a $55M-backed audit. You are buying software from vendors who might be. That changes one thing in your process: ask. When a vendor ships an agent that can write to your data, ask whether it has been tested against a published standard, and ask to see the result. "We use a frontier model" is not an answer — it describes the engine, not the guardrails around your account.

Then do the cheap version internally. The three failure classes in AIUC-1 are the three that will bite you: prompt injection that makes an agent ignore your rules, confident output that is wrong, and data crossing a boundary it should not. Write ten test cases for each against your own agent — a poisoned support email, a refund the policy forbids, a request to dump a customer list — and run them on every prompt change. That is a regression suite, not a certification, and it costs an afternoon.

The insurance framing is the tell. When underwriters start pricing agent failure, the question stops being whether your agent is clever and becomes whether you can show what it does when someone lies to it.

Key takeaways

  • AIUC raised a $40M Series A led by Ribbit Capital; $55M total, after a $15M seed in July 2025
  • AIUC-1 is an agent risk standard across 12 categories, shaped by 250+ security and risk professionals
  • Cursor, ElevenLabs and Harvey are named; KPMG is cited as the first Big Four firm certified
  • Audits run roughly 5,000 adversarial scenarios — jailbreaks, hallucinations, data leaks — per TechCrunch
  • Ask every agent vendor for a test report against a named standard before granting write access
  • Build the cheap version yourself: 30 adversarial cases, run on every prompt change

An agent with write access needs a test suite, not a demo. We build agent workflows with adversarial cases, scoped credentials, and an audit log you can actually read. See how we build AI agent systems, or send us the agent you're afraid to let write.

Sources: TechCrunch, AIUC, PR Newswire: AIUC seed round.

  • #ai-agents
  • #ai-governance
  • #vendor-risk
  • #security
  • #audits
TR

Tommy Rush — Founder, Rush Commerce

Operator turned builder. 15+ years running operations — now shipping the systems businesses run on. More

Get The Rush Report weekly — one email, zero fluff.