A new startup founded by an early Anthropic employee and the former chief operating officer of an AI safety research organization has raised $40 million to prevent AI agents from going rogue inside companies. Artificial Intelligence Underwriting Company (AIUC), launched by brothers-in-law Rune Kvist and Rajiv Dattani, builds third-party audits and certification for AI agents, modeled on the widely adopted cybersecurity standard SOC 2. The company announced the Series A funding round on Tuesday, led by Ribbit Capital with participation from First Harmonic.

AIUC's approach centers on a proprietary standard called AIUC-1, developed with input from roughly 250 security and risk leaders who buy AI agents for their organizations. The startup puts agents through approximately 5,000 tests that probe behavior in scenarios involving jailbreaks, hallucinations, and data leaks. Those tests produce a report running about 100 pages that details where an agent performs safely and reliably, and where it falls short. Interestingly, AIUC deploys AI agents to conduct the tests and uses AI to analyze the data, though humans verify the final audit, according to Kvist. The company previously secured $15 million in seed funding from Nat Friedman's fund NFDG, along with Emergence, Terrain, and Anthropic co-founder Ben Mann, bringing total capital raised to $55 million. Current customers include Cursor, Lovable, Harvey, and ElevenLabs.

"AI is getting smarter at an increasingly rapid rate. The surprising thing about AI is that it becomes harder to adopt and harder to control as AI gets smarter, not easier," said Kvist, who worked as an early employee at Anthropic. According to Dattani, who served as COO of the AI safety research organization METR from 2024 to 2025, the consortium of security leaders shapes the testing framework by answering monthly questions about what they'd look for when purchasing agents. Kvist explained that banks, hospitals, governments, and militaries no longer reject AI deployment because models aren't smart enough — they reject it because they've committed to customers about what systems will and won't do, and no one can currently guarantee that behavior.

The startup's model resembles work done by Dattani's former employer METR, which tests frontier labs but has focused primarily on performance rather than safety until recently. METR was among the independent research organizations OpenAI used to investigate its Hugging Face incident. Anthropic CEO Dario Amodei recently called for the AI industry to slow frontier development, citing a rapid increase in bad-behavior incidents, and floated the idea of requiring frontier labs to use embedded third-party evaluators to observe and verify safety, naming METR as one possibility. While AIUC doesn't propose embedding itself at customer sites, the concept is similar: provide enterprises with an independent assessment of how safe their AI agents are.

The company's pitch to buyers is straightforward — give them clarity on where they can trust an agent and where concerns exist before they make a purchase decision. As AIUC scales its testing service, the certification layer could become a standard requirement for enterprises deploying AI agents, much like SOC 2 compliance became table stakes for cloud software vendors. Organizations that have spent years building governance frameworks around data privacy and cybersecurity now face a new category of risk that existing controls weren't designed to manage, and AIUC's certification offers a bridge between familiar compliance processes and unfamiliar AI behavior risks.