AI governance insight
AIUC-1 explained: six domains for safer, more reliable AI agents
AI agents can read files, call tools, connect to business systems and take actions. AIUC-1 provides a structured way to assess the safeguards around those capabilities. Tier 1 helps firms prepare the scope, controls and evidence, while formal certification remains with AIUC and its accredited process.
Section 02
Start with what the AI system can do
AIUC-1 is a security, safety and reliability standard for organisations that develop or deploy agentic AI systems. Official scoping guidance for the 15 July 2026 release describes 50 requirements organised under six foundational principles.
The standard is refreshed quarterly. An assessment therefore starts with the current release, a defined boundary of in-scope agents and a Statement of Applicability that records which requirements and controls apply.
AIUC-1 is not a general badge for every use of generative AI. A drafting assistant still needs confidentiality, privacy and human-review rules, but formal AIUC-1 scope is aimed at systems that can access data, invoke tools or take actions.
The six domains
Six views of the same agent
AIUC-1 calls these areas foundational principles. Looking across all six prevents a firm from treating an agent as only a privacy project, only a cybersecurity project or only a policy exercise.
The summaries below are Tier 1 explanations, not reproductions of the standard. Follow each link to the current official domain requirements.
Data & Privacy
Set rules for data entering and leaving an agent, restrict what it can reach and protect personal information, confidential material, intellectual property and credentials.
ExploreSecurity
Reduce exposure to prompt injection, jailbreaks, endpoint abuse and unauthorised actions through access control, bounded permissions, protected environments and adversarial testing.
ExploreSafety
Define harmful and out-of-scope behaviour for the use case, test before release, add safeguards and create monitoring, intervention and human-review paths.
ExploreReliability
Reduce hallucinated output and stop tools from acting outside their intended authority. Validate important output and tool calls against the consequence of failure.
ExploreAccountability
Name decision owners, approve material changes, assess suppliers, keep logs and evidence, disclose automation and prepare response plans for AI failures.
ExploreSociety
Assess whether the agent could enable cyber misuse or other severe societal harm, then apply provider evidence, safeguards, monitoring and escalation proportionate to its capability.
ExploreTier 1 support
Turn the six domains into owned controls and evidence
Tier 1 provides independent AIUC-1 readiness and remediation support. The work connects governance, security, privacy, suppliers and technical owners so a firm can address real gaps before formal assessment.
Identify the scope
Separate ordinary assistants from agentic systems, then record purpose, users, data, tools, actions, environments, suppliers and accountable owners.
Assess the gaps
Compare current safeguards and evidence with the requirements likely to apply, while keeping the result clearly labelled as a readiness view.
Implement the controls
Coordinate policies, access restrictions, supplier checks, human review, monitoring, testing and failure processes with the people who operate them.
Prepare the evidence
Organise technical, operational and legal evidence so each safeguard can be traced to its owner, operation, review date and supporting record.
Prepare for assessment
Resolve evidence gaps and help the firm work effectively with AIUC, its accredited auditor and the required independent technical-testing process.
Maintain readiness
Reassess the agent when its model, permissions, tools, supplier, data or business purpose changes, and plan for the standard's quarterly updates.
Section 05
Use formal assurance where the capability justifies it
A high-trust firm should begin with the system's access and possible consequences. Formal AIUC-1 certification is more relevant when an agent can reach confidential information, invoke business tools, affect clients or take action with limited human involvement.
ISO 42001 and AIUC-1 address different layers. ISO 42001 provides an organisation-wide management system for AI. AIUC-1 examines safeguards and testing around defined agents. A firm may use either or both, depending on its systems, clients and assurance needs.
Clear boundary
Readiness support is not certification
Tier 1 Consulting does not issue AIUC-1 certificates and is not presented as an AIUC-1-accredited auditor or official AIUC partner. Only the Artificial Intelligence Underwriting Company issues the certificate after its accredited audit and technical-testing process.
A readiness review does not guarantee certification. Its value is a more accurate scope, fewer unresolved gaps, working controls and evidence that is easier for the formal assessors to examine.
Primary references
Check the current AIUC-1 requirements
These official sources were checked on 25 July 2026. AIUC-1 is updated quarterly, so confirm the current release and assessment process before relying on a requirement or making a certification claim.
AIUC-1 audit scoping
Official guidance on agentic scope, the six principles, requirements and the Statement of Applicability.
ExploreAIUC-1 certification FAQ
Official answers on certification authority, validity, testing and the limits of a certificate.
ExploreAIUC-1 accredited auditors
Official description of the roles played by AIUC, accredited auditors and technical-testing bodies.
ExploreAIUC-1 changelog
Current release date and quarterly changes to requirements and controls.
ExploreOAIC guidance on commercially available AI
Australian privacy guidance for selecting and using AI products.
ExploreJoint legal regulators' AI statement
Australian legal-sector guidance on confidentiality, independent judgement and checking AI output.
ExploreStraight answers
Common questions
Is AIUC-1 relevant to every AI tool?
No. AIUC-1 is scoped to agentic AI systems. An ordinary writing assistant still needs appropriate governance, but formal AIUC-1 assessment is aimed at systems that can access data, use tools or take actions within a defined scope.
Can Tier 1 issue an AIUC-1 certificate?
No. Tier 1 supports readiness, remediation and evidence preparation. Formal assessment involves an AIUC-1-accredited auditor and AIUC technical testing, and only AIUC can issue the official certificate.
How is AIUC-1 different from ISO 42001?
ISO 42001 establishes an organisation-wide AI management system. AIUC-1 focuses on safeguards and testing for defined AI agents. They can complement each other when a firm needs both management-system discipline and agent-specific assurance.
Does a readiness review guarantee certification?
No. A readiness review identifies gaps and prepares controls and evidence. AIUC and the accredited auditor determine the formal scope, testing requirements and certification outcome.
A quiet first step
Know what your AI agents can access before they act
Tier 1 can help identify agentic AI, assess readiness across the six domains and prepare the controls and evidence needed for formal assessment.
Explore AI governance services