Evidence Library · Frameworks

AAES record properties

Seven selected record properties, the evidence available,and the remaining gaps.

Last reviewed:

Reading this note

These pages describe the product. They are not a certification or a legal opinion.

AIUC-1 is a certification standard. The setter currently states 51 requirements under six principles. This page does not assess that catalog.

Instrument identity
AIUC-1, a certification standard for AI agents issued by the Artificial Intelligence Underwriting Company. Launched July 2025; revised quarterly.
Catalog
The stated requirements are backed by roughly 130 controls, split evenly between mandatory and optional. This note does not assess that catalog.
Certification cadence
A certificate is valid for 12 months, with technical testing repeated at least quarterly to keep it valid.
Assurance ecosystem
Accredited auditors exist (Schellman was named the first, February 2026), and the Cloud Security Alliance added AIUC-1 to its STAR Registry on 30 June 2026 (CSA research note). AAES has not undergone AIUC-1 certification; no audit of AAES against the standard has occurred.

The table is seven selected AAES record properties. Where an exact AIUC-1 requirement association has not been established, this page does not invent one. Read it alongside the source instrument at the AIUC-1 standard setter's site.

AAES writes one sealed, hash-chained record per action. The HTTP API names that object a receipt at /v1/receipts. An export is a downloadable bundle of records that can be verified offline. A records sidecar carries additional sealed fields that are not in the frozen v1 export projection.

How to verify an export is on the verification page.

Each AAES implementation label applies to the product behavior in that row. Read it with the named gap. The labels are not AIUC-1 compliance marks.

Implemented
The described record behavior is implemented in AAES. Read it with the named gap.
Partial
Some of the described property is supported. A required part remains unexercised or absent.
Missing
No implemented record support is recorded for the property.

Record properties

Selected AAES record properties, with gaps.
PropertyWhat records showGapAAES implementation
AttributionActor, work, grant, and accountable human manager are recorded.Named attribution fields only. This is not an AIUC-1 requirement.Implemented.
Audit trailRecords are hash-chained. An export can be verified offline.The default deployment has zero independent witnesses.Partial.
Least privilegeGrants are task-scoped and have a time to live (TTL).Some calls mint and execute in one step. A separate present-grant path exists. One-step path: /v1/brokered. Present-grant path: POST /v1/grants/present.Partial.
Isolation and residencyStores are tenant-scoped.There is no structural VM isolation.Partial.
Segregation of dutiesAn agent cannot approve itself. AAES risk tier R4 (irreversible or destructive) requires a person.There is no executor/verifier model-family separation.Partial.
ReproducibilityThe sealed record and records sidecar support reproducing the recorded decision.The v1 export still omits the policy-bundle hash (policy_bundle_hash).Implemented.
Dependency provenanceModel identity and capability version are on the sealed record and the records sidecar.Those fields are not in the v1 export entry.Partial.

Next step

Scope an evaluation

Identify the application, data, access, and approval path. Define the records the reviewer needs to inspect.

Scope an evaluation