Framework
AIUC-1 (Jul 2026)
AIUC-1 — AI agent security, safety and reliability standard (requirement level)
51 requirements · 30 connected unified controls
Open AIUC-1 (Jul 2026) in the mapAIUC certification standard for deployed AI agents and systems. The July 15, 2026 release has 51 live requirements: 43 mandatory and 8 optional. E007 and E014 are retained as withdrawn placeholders. Numbered sub-controls (for example A008.1) are not modeled. Requirement status, frequency and source links were verified against the official pages on 2026-09-10. The community navigator still uses its April 2026 snapshot: its 51 rows include E007 and E014 and omit A008 and B010. Applicability depends on the agent capabilities and audit scope.
Requirements and control mappings
“Full” and “Partial” describe the catalog mapping to a unified control. A partial mapping includes the remaining requirement. These mappings do not establish an organization’s implementation or certification.
Data & Privacy
| Requirement | Unified control and mapping | Status and frequency |
|---|---|---|
| A001Establish input data policy | Mandatory Every 12 months | |
| A002Establish output data policy | Mandatory Every 12 months | |
| A003Limit AI agent data access | UC-ACCESS-03 — Enforce least privilege, need-to-know, and segregation of dutiesPartial Remaining requirement: agent-specific enforcement: data access scoped per task, user role, agent role, and context at inference time | Mandatory Every 12 months |
| A004Protect IP & trade secrets | UC-DATA-11 — Control data flows, leakage, and cross-border transfersPartial Remaining requirement: leakage of intellectual property and confidential information through AI system outputs, requiring model-output safeguards beyond network and channel flow controls | Mandatory Every 12 months |
| A005Prevent cross-customer data exposure | UC-DATA-11 — Control data flows, leakage, and cross-border transfersPartial Remaining requirement: tenant isolation inside AI systems: retrieval indexes, memory, fine-tuning data, and caches segregated so one customer's data cannot surface in another customer's outputs | Mandatory Every 12 months |
| A006Prevent PII leakage | UC-DATA-12 — De-identify, mask, or pseudonymize personal dataPartial Remaining requirement: personal-data leakage through AI outputs and logs, requiring output-time redaction and log scrubbing in addition to stored-data pseudonymization | Mandatory Every 12 months |
| A007Prevent IP violations | UC-AI-12 — Enforce responsible and lawful use of AI systemsPartial Remaining requirement: output-level safeguards against copyright, trademark, and other third-party intellectual-property infringement by generated content | Mandatory Every 12 months |
| A008Prevent leakage of credentials and secrets | Mandatory Every 12 months |
Security
| Requirement | Unified control and mapping | Status and frequency |
|---|---|---|
| B001Third-party testing of adversarial robustness | Mandatory Every 3 months | |
| B002Detect adversarial input | Optional Every 3 months | |
| B003Manage public release of technical details | UC-ACCESS-14 — Authorize public content and external information sharingPartial Remaining requirement: controlled public release of model, system-prompt, and architecture details so technical over-disclosure does not aid adversaries | Optional Every 12 months |
| B004Prevent AI endpoint scraping | Mandatory Every 12 months | |
| B005Implement real-time input filtering | Optional Every 12 months | |
| B006Prevent unauthorized AI agent actions | Mandatory Every 12 months | |
| B007Enforce user access privileges to AI systems | UC-ACCESS-05 — Enforce approved authorizations for information and functionsPartial Remaining requirement: quarterly review of user access privileges to AI systems, including administrative, configuration, and training-data access | Mandatory Every 3 months |
| B008Protect AI system deployment environment | UC-SDLC-04 — Engineer systems with secure architecture and designPartial Remaining requirement: hardening of the model-serving and agent runtime environment, including model-artifact protection and isolation from other workloads | Mandatory Every 12 months |
| B009Limit output over-exposure | Mandatory Every 12 months | |
| B010Promote secure patterns in generated code | Mandatory Every 12 months |
Safety
| Requirement | Unified control and mapping | Status and frequency |
|---|---|---|
| C001Define AI risk taxonomy | UC-AI-04 — Assess impacts and classify AI systems before deploymentPartial Remaining requirement: a system-specific AI risk taxonomy with severity tiers that drives output filtering, monitoring categories, and third-party test scope | Mandatory Every 12 months |
| C002Conduct pre-deployment testing | Mandatory Every 12 months | |
| C003Prevent harmful outputs | Mandatory Every 12 months | |
| C004Prevent out-of-scope outputs | Mandatory Every 12 months | |
| C005Prevent agent-specific high risk outputs | Mandatory Every 12 months | |
| C006Prevent output vulnerabilities | Mandatory Every 3 months | |
| C007Flag high risk outputs for human review | UC-AI-16 — Ensure human oversight of AI decisionsPartial Remaining requirement: automated flagging of high-risk outputs with routing to a human reviewer before the output takes effect | Optional Every 12 months |
| C008Monitor AI risk categories | UC-AI-08 — Log and monitor AI system behavior in operationPartial Remaining requirement: monitoring keyed to the AI risk taxonomy categories with per-category alert thresholds and response actions | Optional Every 12 months |
| C009Enable real-time feedback and intervention | UC-AI-16 — Ensure human oversight of AI decisionsPartial Remaining requirement: in-product user controls to pause, stop, or override the system and to submit feedback in real time | Optional Every 3 months |
| C010Third-party testing for harmful outputs | Mandatory Every 3 months | |
| C011Third-party testing for out-of-scope outputs | Mandatory Every 3 months | |
| C012Third-party testing for customer-defined risk | Mandatory Every 3 months |
Reliability
| Requirement | Unified control and mapping | Status and frequency |
|---|---|---|
| D001Prevent hallucinated outputs | Mandatory Every 12 months | |
| D002Third-party testing for hallucinations | Mandatory Every 3 months | |
| D003Restrict unsafe tool calls | Mandatory Every 12 months | |
| D004Third-party testing of tool calls | Mandatory Every 3 months |
Accountability
| Requirement | Unified control and mapping | Status and frequency |
|---|---|---|
| E001AI failure plan for security breaches | UC-AI-11 — Operate AI concern, incident, and external reporting channelsPartial Remaining requirement: a pre-approved failure plan for AI security breaches with containment, rollback, and customer-notification steps | Mandatory Every 12 months |
| E002AI failure plan for harmful outputs | UC-AI-11 — Operate AI concern, incident, and external reporting channelsPartial Remaining requirement: a pre-approved failure plan for harmful outputs with containment, rollback, and customer-notification steps | Mandatory Every 12 months |
| E003AI failure plan for hallucinations | UC-AI-11 — Operate AI concern, incident, and external reporting channelsPartial Remaining requirement: a pre-approved failure plan for hallucination incidents with containment, rollback, and customer-notification steps | Mandatory Every 12 months |
| E004Assign accountability | UC-AI-02 — Define AI roles, responsibilities, and competenciesPartial Remaining requirement: define which AI system changes require formal review or approval, assign the accountable approver for each, and retain approval decisions with supporting evidence | Mandatory Every 12 months |
| E005Document data storage security | UC-CRYPTO-01 — Encrypt data at rest and in transitPartial Remaining requirement: a documented storage-security description for AI data stores (training data, prompts, outputs, embeddings) shared with customers | Mandatory Every 12 months |
| E006Conduct vendor due diligence | UC-AI-14 — Manage responsible AI with suppliers and customersPartial Remaining requirement: assess foundation and upstream model providers against explicit data-handling, PII-control, security, and compliance criteria, and retain the due-diligence evidence | Mandatory Every 12 months |
| E008Review internal processes | UC-AI-01 — Maintain and periodically review the AI policyPartial Remaining requirement: periodic internal review of the AI control set and operating processes for continued effectiveness, beyond review of the policy text | Mandatory Every 12 months |
| E009Monitor third-party access | UC-LOG-09 — Monitor providers and exchange audit data across organizationsPartial Remaining requirement: monitoring of third-party API connections, integrations, and sessions into AI systems, including revocation of stale access | Mandatory Every 12 months |
| E010Establish AI acceptable use policy | UC-AI-12 — Enforce responsible and lawful use of AI systemsPartial Remaining requirement: establish and implement an end-user AI acceptable use policy, with violation detection and user notifications beyond intended-use and legal-prohibition screening | Mandatory Every 12 months |
| E011Record processing locations | UC-CONFIG-10 — Map where information resides and how data is processedPartial Remaining requirement: a customer-facing record of the regions and sub-processors where AI inputs and outputs are processed and stored | Mandatory Every 12 months |
| E012Document regulatory compliance | UC-AI-13 — Assign AI value-chain roles and discharge obligationsPartial Remaining requirement: semiannual documentation of the AI system's regulatory compliance posture and obligations register shared with customers | Mandatory Every 6 months |
| E013Implement quality management system | Optional Every 12 months | |
| E015Log AI system activity | Mandatory Every 12 months | |
| E016Implement AI disclosure mechanisms | Mandatory Every 12 months | |
| E017Document system transparency policy | UC-AI-06 — Maintain AI system technical documentationPartial Remaining requirement: external transparency artifacts (model cards, datasheets, AI bill of materials) and a shared-responsibility statement distributed under a documented sharing policy | Optional Every 12 months |
Society
| Requirement | Unified control and mapping | Status and frequency |
|---|---|---|
| F001Prevent AI cyber misuse | Mandatory Every 12 months | |
| F002Prevent catastrophic misuse | Mandatory Every 12 months |