OWASP / OWASP/OWASP-MCP-Governance-and-Risk-Project

Consider AIUC standard (AIUC-1)

Open
#4 0 comments 0 reactions 0 assignees View on GitHub

Nobody has claimed this yet.

Dominant language
No language data
Stars
86
Forks
13
PR merge metrics
No merged PRs in 30d

Description

Link - https://aiuc.com/

AIUC-1, the first dedicated security, safety, and reliability standard for AI agents, was officially introduced in 2025 by the Artificial Intelligence Underwriting Company (AIUC) as a compliance framework for AI agent vendors. The standard was designed to provide enterprises with confidence in deploying agentic AI systems by implementing over 50 technical, operational, and legal safeguards across six domains: Safety, Security, Reliability, Accountability, Data & Privacy, and Society.
The launch aimed to address the growing risks associated with AI agents, including hallucinations, harmful outputs, prompt injection, and unauthorized actions, which were not fully covered by existing certifications like SOC 2 or ISO 42001.
AIUC-1 operationalizes high-level frameworks such as NIST AI RMF, MITRE ATLAS, and OWASP Top 10 for agentic applications into concrete, testable controls.
Since its launch, AIUC-1 has been updated quarterly to keep pace with evolving AI capabilities, enterprise adoption trends, and regulatory requirements, ensuring that the standard remains current and relevant for organizations deploying AI agents.
Certification involves rigorous technical testing, ongoing retesting, and annual audits to validate compliance and safety, making it a SOC-like assurance framework specifically for AI agents.


Key Points
Launched: 2025
Organisation: Artificial Intelligence Underwriting Company (AIUC)
Purpose: Security, safety, and reliability standard for AI agents
Controls: 50+ technical, operational, and legal safeguards
Domains Covered:
Safety
Security
Reliability
Accountability
Data & Privacy
Society
Addresses Risks:
Hallucinations
Harmful outputs
Prompt injection
Unauthorized actions
References Frameworks:
NIST AI RMF
MITRE ATLAS
OWASP Top 10 for Agentic Applications
Assurance Model:
Technical testing
Ongoing retesting
Annual audits
SOC-like certification approach for AI agents

Contributor guide

Open the contributing guide

First steps

  1. Read the whole issue, then the project's contributing guide.
  2. Comment on the issue to say you are picking it up — it saves two people doing the same work.
  3. Fork the repository and make your change on a branch.
  4. Open a pull request that references the issue number.

Research direction

Start by reviewing the linked AIUC-1 standard and comparing its six domains and controls with this repository’s existing MCP governance framework. Determine where the standard should be represented and define an explicit acceptance scope for adding or referencing it; the issue currently names no files, tests, or completed output.

Written by the indexing model from the issue text.

Assessment

Tech stack
ai-infra-agents
Domain
ai, security
Issue type
Feature
Difficulty
5/5
Estimated time
Over a week
Activity status
Active
Clarity
Needs clarification
Newbie friendliness
25/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.