AIUC applies SOC 2-style audits to keep AI agents from going rogue

A day after Anthropic researcher Jacob Coxon quit over concerns that AI could kill us all by the end of the decade, TechCrunch met with founders and brothers-in-law Rune Kvist and Rajiv Dattani. Their startup, Artificial Intelligence Underwriting Company (AIUC), aims to prevent AI agents from going rogue inside enterprises. Kvist is an early Anthropic employee and married to Dattani’s sister; Dattani is the former COO of AI safety research organization METR. AIUC counts Cursor, Lovable, Harvey, and ElevenLabs as customers. This week it announced a $40 million Series A led by Ribbit Capital with participation from First Harmonic, after a $15 million seed round from Nat Friedman’s NFDG, Emergence, Terrain, and Anthropic co-founder Ben Mann, bringing total funding to $55 million.

Kvist says AI becomes harder to adopt and harder to control as it gets smarter. “The surprising thing about AI is that it becomes harder to adopt and harder to control as AI gets smarter, not easier.” The practical problem, he said, is that banks, hospitals, governments, and militaries decline to deploy AI not because models aren’t smart enough, but because they’ve made commitments to customers about what a system will and won’t do, and nobody can currently guarantee that. AIUC‘s answer is to apply a familiar cybersecurity model to AI risk: it built a third-party audit and certification layer for AI agents, modeled on the widely used SOC 2 standard. Its own standard is called AIUC-1, and it comes with a testing service that validates agents against it.

To build AIUC-1, the startup assembled a consortium of about 250 security and risk leaders — the buyers of agents. Dattani says they meet with these leaders monthly and ask what they look for when buying agents, what questions they want to ask, and what they want addressed. That feedback shapes the tests. AIUC then puts an agent through a suite of roughly 5,000 tests probing scenarios involving jailbreaks, hallucinations, and data leaks. The output is a roughly 100-page report describing where an agent performs safely and reliably and where it doesn’t. In a notable detail, AIUC uses AI agents to run the tests and AI to analyze the data, but humans verify the final audit.

The work echoes Dattani’s former employer METR, where he was COO from 2024 to 2025 and remains a board member. METR does similar testing for frontier labs, but until recently its focus has been mostly on performance, whether agents can reliably complete tasks. METR was also one of the independent research orgs OpenAI used to investigate its Hugging Face incident. Anthropic CEO Dario Amodei recently called for the industry to pace frontier development, citing a rapid increase in bad-behavior incidents, and floated the idea of requiring frontier labs to use embedded third-party evaluators to observe and verify safety; he named METR as one possibility. AIUC isn’t proposing to embed itself at customer sites, but the idea is similar: give enterprises an independent assessment of agent safety. Dattani says the report shows buyers “here’s where it passes and where you can trust it,” and “here’s where there’s concerns,” so they can make an informed purchase decision.

Early Anthropic hire, former METR COO have found a way to rein in rogue AI agents | TechCrunch

View Original