AIUC-1
Changelog

AIUC-1 changelog

AIUC-1 is updated formally each quarter to ensure that the standard evolves as technology, risk, and regulation evolves.

The most recent version of AIUC-1 was released on April 15, 2026.

The next version of AIUC-1 will be released on July 15, 2026.

April 15, 2026 release

For this update, focus has been on MCP and A2A protocol security, third-party risk management, and agent identity and access management. This quarter’s refresh updates 14 requirements and 23 controls.

Overview of key updates

Introduced new controls for MCP and A2A protocol security, standardizing authentication, transport, runtime containment, and logging across agentic interfaces

Expanded third-party risk controls including making third-party access monitoring mandatory

Expanded controls for agent identity, permissions, and access management

Detailed changelog

Date

Q2 2026

AIUC-1 Requirement and Control

All requirements

Category
Revision
Change Notes

Updated typical evidence descriptions to move away from screenshots in favor of substantive and verifiable evidence

Date

Q2 2026

AIUC-1 Requirement and Control

A002: Establish output data policy

Category
Revision
Change Notes

Included both opt-in and out practices

Date

Q2 2026

AIUC-1 Requirement and Control

A002.1 Documentation: Output usage and ownership policy

Category
Revision
Change Notes

Included both opt-in and out practices, ensuring balanced coverage of consent models

Date

Q2 2026

AIUC-1 Requirement and Control

A002.2 Config: Opt-in/opt-out and output deletion implementation

Category
Addition
Change Notes

Added new control to incorporate implementation testing to A002

Date

Q2 2026

AIUC-1 Requirement and Control

A003: Limit AI agent data collection

Category
Specification
Change Notes

Specified that the requirement covers data access more generally, and included more controls on agent IAM within it

Date

Q2 2026

AIUC-1 Requirement and Control

A003.1 Config: Data access scoping

Category
Clarification
Change Notes

Clarified the control to cover agent access and identity management, not just data collection

Date

Q2 2026

AIUC-1 Requirement and Control

A003.3 Config: Agent identity management

Category
Revision
Change Notes

Separated agent identity and access management into distinct controls, with a focus on providing configurable, auditable architecture that integrates with enterprise IAM systems

Date

Q2 2026

AIUC-1 Requirement and Control

A003.4 Config: Agent access and permissions management

Category
Addition
Change Notes

Separated agent identity and access management into distinct controls, with a focus on providing configurable, auditable architecture

Date

Q2 2026

AIUC-1 Requirement and Control

B002: Detect adversarial input

Category
Clarification
Change Notes

Clarified that monitoring is to enable responding to adversarial inputs

Date

Q2 2026

AIUC-1 Requirement and Control

B006: Prevent unauthorized AI agent actions

Category
Revision
Change Notes

Changed on a controls level - MCP coverage and additional execution-level containment controls

Date

Q2 2026

AIUC-1 Requirement and Control

B006.1 Config: Agent service access restrictions

Category
Revision
Change Notes

Covered MCP server access alongside existing API and service-level restrictions

Date

Q2 2026

AIUC-1 Requirement and Control

B006.3 Config: Execution-level safeguards

Category
Addition
Change Notes

Added execution-level containment controls that limit the blast radius when an agent or approved MCP server behaves unexpectedly at runtime

Date

Q2 2026

AIUC-1 Requirement and Control

B008: Protect AI system deployment environment

Category
Revision
Change Notes

Expanded scope of requirement from the AI model only to system

Date

Q2 2026

AIUC-1 Requirement and Control

B008.1 Config: Model access controls

Category
Clarification
Change Notes

Expanded scope of control from the AI model only to system

Date

Q2 2026

AIUC-1 Requirement and Control

B008.2 Config: API and agentic interface authentication

Category
Revision
Change Notes

Expanded deployment security controls to address MCP and A2A protocols alongside traditional API endpoints, with dedicated controls for authentication, transport security, and message integrity across all agentic interfaces

Date

Q2 2026

AIUC-1 Requirement and Control

B008.3 Config: API and agentic interface transport security

Category
Addition
Change Notes

See above

Date

Q2 2026

AIUC-1 Requirement and Control

B008.4 Config: Agentic interface data integrity

Category
Addition
Change Notes

See above

Date

Q2 2026

AIUC-1 Requirement and Control

C001: Define AI risk taxonomy

Category
Specification
Change Notes

Generalized the risk taxonomy requirement and changed testing frequency to every 12 months

Date

Q2 2026

AIUC-1 Requirement and Control

C001.2 Documentation: Risk taxonomy reviews

Category
Specification
Change Notes

Aligned testing frequency to a 12-month cycle consistent with the risk management framework update schedule

Date

Q2 2026

AIUC-1 Requirement and Control

C006: Prevent output vulnerabilities

Category
Clarification
Change Notes

Clarified that the requirement is in scope for AI agents that generate code (see C006.1, C006.2, C006.3), and text (see C006.2)

Date

Q2 2026

AIUC-1 Requirement and Control

C006.1 Config: Output sanitization

Category
Clarification
Change Notes

Clarified that the control is in scope for code-generating AI agents

Date

Q2 2026

AIUC-1 Requirement and Control

C006.2 Demonstration: Warning labels for untrusted content

Category
Clarification
Change Notes

See above

Date

Q2 2026

AIUC-1 Requirement and Control

C006.3 Config: Adversarial output detection

Category
Clarification
Change Notes

See above

Date

Q2 2026

AIUC-1 Requirement and Control

C007: Flag high risk outputs for human review

Category
Clarification
Change Notes

Clarified that C007 is about human in the loop via updated label

Date

Q2 2026

AIUC-1 Requirement and Control

C007.1 Documentation: Definition of high-risk output criteria

Category
Clarification
Change Notes

Expanded requirement scope from recommendations to generalized outputs

Date

Q2 2026

AIUC-1 Requirement and Control

C007.3 Documentation: Human review workflows

Category
Revision
Change Notes

Included example of auditing human review workflows (i.e., checking the effectiveness of oversight over time) to mitigate against ‘automation bias’

Date

Q2 2026

AIUC-1 Requirement and Control

C009: Enable real-time feedback and intervention

Category
Revision
Change Notes

Changed on a controls level - synthesized controls and added in control to action user feedback

Date

Q2 2026

AIUC-1 Requirement and Control

C009.2 Documentation: User feedback & intervention reviews

Category
Clarification
Change Notes

Included practical validation and actioning of relevant user feedback, and streamlined three controls into one

Date

Q2 2026

AIUC-1 Requirement and Control

D003: Restrict unsafe tool calls

Category
Revision
Change Notes

Changed on a controls level - extends tool call validation to cover MCP servers alongside approved functions, expands scope of human approval for sensitive tool operations to cover multi-step workflows

Date

Q2 2026

AIUC-1 Requirement and Control

D003.1 Config: Tool authorization & validation

Category
Revision
Change Notes

Extended tool call validation to cover MCP servers alongside approved functions

Date

Q2 2026

AIUC-1 Requirement and Control

D003.3 Config: Tool call log

Category
Revision
Change Notes

Extended tool call validation to cover MCP servers alongside approved functions

Date

Q2 2026

AIUC-1 Requirement and Control

D003.4 Config: Human-approval workflows

Category
Revision
Change Notes

Expanded scope to cover multi-step workflows, reflecting trends of AI agents increasingly chaining tool calls across sequential operations rather than executing single actions in isolation

Date

Q2 2026

AIUC-1 Requirement and Control

E005: Document data storage security

Category
Clarification
Change Notes

Clarified that the requirement is around ensuring companies establish clear security and compliance requirements for hosting platforms, rather than the act of cloud vs on-prem assessment

Date

Q2 2026

AIUC-1 Requirement and Control

E009: Monitor third-party access

Category
Revision
Change Notes

Enforced E009 as a mandatory control

Date

Q2 2026

AIUC-1 Requirement and Control

E015: Log AI system activity

Category
Revision
Change Notes

Expanded scope of requirement from the AI model only to system

Date

Q2 2026

AIUC-1 Requirement and Control

E015.2 Config: AI agent logging implementation

Category
Addition
Change Notes

Extended logging to cover the intermediate steps between input and output (i.e., tool calls, sub-agent actions, and provenance metadata) getting traceability across the full execution chain

Date

Q2 2026

AIUC-1 Requirement and Control

E016: Implement AI disclosure mechanisms

Category
Specification
Change Notes

Changed on a controls level - adjusts disclosure to AI agents and systems

Date

Q2 2026

AIUC-1 Requirement and Control

E016.4 Demonstration: Automation AI disclosure

Category
Specification
Change Notes

Adjusted disclosure to AI agents and systems

Detailed side-by-side comparison

Detailed comparison of previous standards (October 1, 2025 and January 15, 2026) and current standard (April 15, 2026) is available on Github here

Standard history

Version

January 15, 2026

Link to changelog
Version

October 1, 2025

Link to changelog
Version

July 22, 2025

Link to changelog

First launch of the standard

Tenets that guide the standard update

Customer-focused.We prioritize requirements that enterprise customers demand and vendors can pragmatically meet— increasing confidence without adding unnecessary compliance.

AI-focused. We do not cover non-AI risks that are addressed in frameworks or regulations like SOC 2, ISO 27001, or GDPR.

Insurance-enabling. We prioritize risks that lead to direct harms and financial losses.

Adapts to regulation. We update AIUC-1 to make it easier to comply with new regulations.

Adapts to AI progress. We update AIUC-1 to keep up with new capabilities, like reasoning capabilities and new modalities.

Adapts to the threat landscape. We update AIUC-1 in response to real-world incidents.

Continuous improvement. We regularly update the standard based on real-world deployment experience and stakeholder feedback.

Predictability.We review the standard and push updates quarterly— on January 15, April 15, July 15, and October 15 of each year.

Transparency. We keep a public changelog and share our lessons.

Backward compatibility. Existing certifications remain valid during transition periods.

Provide input on AIUC-1

We welcome feedback, ideas, suggestions, and criticism— provide input on AIUC-1.