AIUC-1
2026-01-15

January 15, 2026 release

For this update, focus has been on detailing guidance on control implementation - including publishing typical evidence submitted to pass AIUC-1 requirements transparently on the website. In addition, several requirements were updated to integrate, e.g., stronger PII protection in logs, threat modelling in pre-deployment testing, multimodal coverage of AI labelling, pickle-file security tools, and more. Finally, more info on the AIUC-1 certification process and scoping questionnaire was published.

Overview of key updates

Updated 26 requirements based on audit experience, input from technical contributors, feedback from AIUC-1 Consortium members, and external peer-review comments.

Detailed typical evidence submitted to pass AIUC-1 with suggested locations and concrete examples, making it easier for organizations to begin a readiness assessment of AIUC-1

Published AIUC-1 scoping questionnaire and certification process details to ensure consistent application of AIUC-1 across accredited auditors

Detailed changelog

Date

Q1 2026

AIUC-1 Requirement and Control

All requirements

Category
New addition
Change Notes

Enabled Excel export of all requirements and controls for easier readiness assessment

Date

Q1 2026

AIUC-1 Requirement and Control

All requirements

Category
New addition
Change Notes

Tagged all requirements with relevant AI agent capabilities which are used as input for the scoping questionnaire to ensure appropriate application of AIUC-1 requirements

Date

Q1 2026

AIUC-1 Requirement and Control

All requirements

Category
New addition
Change Notes

Defined and published typical evidence for all controls tagged by evidence category and typical location

Date

Q1 2026

AIUC-1 Requirement and Control

Scoping questionnaire

Category
New addition
Change Notes

Published the AIUC-1 scoping questionnaire, enabling consistent approach to scoping by accredited auditors

Date

Q1 2026

AIUC-1 Requirement and Control

Should include and May include control activities

Category
Clarification
Change Notes

Clarified application of control activities

For controls labeled "Should include": Organizations must demonstrate core controls to meet the requirement. Auditors may accept alternative implementations that achieve equivalent outcomes

For controls labeled "May include": Supplemental controls demonstrating additional safeguards. Recommended when particularly relevant to the organization's use case

Date

Q1 2026

AIUC-1 Requirement and Control

A001: Establish input data policy

Category
Specification
Change Notes

Specified evidence requirements across policies and enforcement of policies, particularly for data retention

Date

Q1 2026

AIUC-1 Requirement and Control

A003: Limit AI agent data collection

Category
Revision
Change Notes

Removed optional control activity focused on dynamic context-based restrictions given limited technical pathways for implementation

Date

Q1 2026

AIUC-1 Requirement and Control

A004: Protect IP & trade secrets

Category
Specification
Change Notes

Specified controls with a stricter requirement of user guardrails

Provided specific guidance on foundation model IP protections

Added supplemental safeguards

Date

Q1 2026

AIUC-1 Requirement and Control

A005: Prevent cross-customer data exposure

Category
Revision
Change Notes

Revised controls to avoid overlap and specify the intent of the requirement

Removed optional controls on adapting safeguards to industry-specific risks

Removed optional controls on inference-time data isolation

Date

Q1 2026

AIUC-1 Requirement and Control

A006: Prevent PII leakage

Category
Specification
Change Notes

Increased PII protection requirements for logs

Removed incident management control to avoid overlap with E001

Removed cross-tenant contaminant control to avoid overlap with A005

Date

Q1 2026

AIUC-1 Requirement and Control

A007: Prevent IP violations

Category
Clarification
Change Notes

Clarified controls with emphasis on foundation model IP protections

Added additional safeguards tagged as supplemental controls

Removed third-party IP incident response control to avoid overlap with other requirements

Date

Q1 2026

AIUC-1 Requirement and Control

B006: Limit AI agent system access

Category
Clarification
Change Notes

Clarified the requirement's focus on security aspects of system limiting

Emphasized agent privilege restrictions and monitoring

Date

Q1 2026

AIUC-1 Requirement and Control

B008: Protect model deployment environment

Category
Specification
Change Notes

Included Trail of Bits' Fickling tool as example safeguard in control B008.4 based on peer-review feedback

Date

Q1 2026

AIUC-1 Requirement and Control

B009: Limit output over-exposure

Category
Revision
Change Notes

Tagged user notification control as supplemental, recognizing it is not always in the organization's interest to disclose output limitations

Minor revisions to output fidelity limitations to align with MITRE AML-M0002

Date

Q1 2026

AIUC-1 Requirement and Control

C001: Define AI risk taxonomy

Category
Revision
Change Notes

Simplified controls to focus on AI Risk Taxonomy documentation and reviews

Date

Q1 2026

AIUC-1 Requirement and Control

C002: Conduct pre-deployment testing

Category
Specification
Change Notes

Included explicit reference to threat modelling in controls based on peer-review feedback

Date

Q1 2026

AIUC-1 Requirement and Control

C003: Prevent harmful outputs

Category
Revision
Change Notes

Removed control on review and appeal mechanisms, which are beyond the intent of the requirement

Date

Q1 2026

AIUC-1 Requirement and Control

C006: Prevent output vulnerabilities

Category
Revision
Change Notes

Removed control on logging sanitation activities as this is beyond standard practice for organizations

Date

Q1 2026

AIUC-1 Requirement and Control

C008: Monitor AI risk categories

Category
Revision
Change Notes

Removed control on proactive detection as this is already covered by C008.2

Date

Q1 2026

AIUC-1 Requirement and Control

C009: Enable real-time feedback and intervention

Category
Revision
Change Notes

Revised controls to cover other modalities (e.g. voice, image)

Tagged review of intervention logs as a supplemental control

Date

Q1 2026

AIUC-1 Requirement and Control

D003: Restrict unsafe tool calls

Category
Revision
Change Notes

Revised controls to avoid overlap with A003 and B006

Emphasized tool call validation and monitoring specifically

Date

Q1 2026

AIUC-1 Requirement and Control

E005: Assess cloud vs on-prem processing

Category
Revision
Change Notes

Revised controls to focus on cloud vs. on-prem decisions

Removed security and vendor due diligence controls covered in other requirements

Date

Q1 2026

AIUC-1 Requirement and Control

E007: Document system change approvals

Category
Retired
Change Notes

This requirement was merged into E004: Assign accountability, which already requires documenting approval with supporting evidence

Date

Q1 2026

AIUC-1 Requirement and Control

E009: Monitor third-party access

Category
Clarification
Change Notes

Clarified monitoring configuration requirement in place of purely documenting procedures

Date

Q1 2026

AIUC-1 Requirement and Control

E010: Establish AI acceptable use policy

Category
Clarification
Change Notes

Combined supplemental controls into one without changing the nature of the control activities

Date

Q1 2026

AIUC-1 Requirement and Control

E013: Implement quality management system

Category
Specification
Change Notes

Controls updated to simplify the requirement while fulfilling EU AI Act Article 17

Date

Q1 2026

AIUC-1 Requirement and Control

E014: Share transparency reports

Category
Retired
Change Notes

This requirement was merged into E017 to avoid overlap and to recognize transparency policy sharing procedures

Date

Q1 2026

AIUC-1 Requirement and Control

E015: Log model activity

Category
Specification
Change Notes

Strengthened controls around PII protection

Improved log immutability and tamper-proofing based on peer-review feedback

Date

Q1 2026

AIUC-1 Requirement and Control

E016: Implement AI disclosure mechanisms

Category
Revision
Change Notes

Revised control activities to ensure coverage of multiple modalities (e.g. voice, text, image)

Date

Q1 2026

AIUC-1 Requirement and Control

F001: Prevent AI cyber misuse

Category
Revision
Change Notes

Removed control requiring a signed attestation that cyber misuse safeguards remain active

Encouraged organizations using open-source or fine-tuned third-party models to opt into the supplemental control

Date

Q1 2026

AIUC-1 Requirement and Control

F002: Prevent catastrophic misuse

Category
Revision
Change Notes

Removed control requiring a signed attestation that CBRN safeguards remain active

Encouraged organizations using open-source or fine-tuned third-party models to opt into the supplemental control

Detailed side-by-side comparison

Detailed comparison of October 1, 2025 and January 15, 2026 is available on Github here