AIUC-1
ResearchRajiv Dattani
Jul 30, 20265 min read

Harvey achieves AIUC-1 certification

Harvey achieves AIUC-1 certification

Harvey's agentic platform is the first legal AI to achieve AIUC-1 certification. To earn the certificate, Harvey’s platform went through 3,000+ technical evaluations covering top risks of legal professionals.

Some of the most visible AI failures of recent years have come from the legal industry. Courts have sanctioned lawyers for filing briefs built on fabricated case citations generated by AI. Hallucinated authorities continue to surface in filings around the world. Few domains make the case for independent, third-party validation of AI more clearly.

“Legal work leaves no room for error, so it’s fitting that legal AI is where the bar gets set,” said Rajiv Dattani, co-founder of AIUC. “Harvey is the first legal AI company to be certified against AIUC-1, and they earned it the hard way - independent, adversarial technical testing of the actual product, not a paper review.”

Certifying agents in a high-stakes environment

Assuring a legal AI platform poses a distinct certification challenge. Consumer AI service agents would deflect or refuse engagement with topics like medical harm, financial misconduct, or criminal activity. For lawyers, high-risk topics like these are core to the work - analyzing a medical malpractice claim, a securities fraud allegation, or a criminal defense strategy requires an agent that engages rather than refuses.

To obtain certification, Harvey's agentic platform was subjected to 3,063 technical evaluations covering 12 risk categories relevant to Harvey’s use case - including hallucinations, incorrect tool operations, and business data leakage. With accuracy as the foundation of trust in a legal AI platform, reliability risks including hallucinations made up 65% of the evaluations run. Harvey’s platform passed the testing with no critical or major vulnerabilities identified.

"Security and trust aren't a single milestone, they're a continuous commitment," said Joshua McKibben, Harvey's Head of Trust. "AIUC-1 gives our customers an independent, technical answer to the question every enterprise security team is asking about AI agents today: can we trust this system to act responsibly under pressure? For Harvey, the answer is now backed by an independent third party, not just by us.”

Harvey’s commitment to security and trust is also reflected in how the standard's requirements were met by their existing operational, legal and technical practices. For example, AIUC-1 reliability requirement D001: Prevent hallucinated outputs was demonstrated by multiple controls - including providing citation validation for each response, with citations and references displayed alongside outputs for the user to verify. C005: Prevent customer-defined high-risk outputs was met in a way that reflects the realities of legal practice, with the application of multi-level guardrails detecting and blocking outputs that fall outside defined risk boundaries, rather than blanket topic bans.

Setting the standard for legal AI

The legal industry was among the first to learn what unverified AI costs. With this certification, Harvey becomes the first legal AI company to meet the standard for AI agent security, safety, and reliability. Certification is not a one-time badge. Harvey's certificate is valid for twelve months, with quarterly red-teaming required to remain in compliance - keeping pace with how fast AI capabilities and threats evolve.

Read more about the AIUC-1 certification process.