The demo works. ChatGPT lists three tools, calls one, and returns a tidy summary from your staging tenant. The product manager asks when it ships. Engineering asks what happens when the model calls delete_site on the wrong organisation. Legal asks where prompts, tool arguments, and responses are logged. Nobody has a shared checklist yet. That gap is why AIUC-1 matters even if you never pursue formal certification. The Artificial Intelligence Underwriting Company published a readable standard for AI agents across six domains: data and privacy, security, safety, reliability, accountability, and societal risk. Contributors include Stanford, MIT, MITRE, the Cloud Security Alliance, and Google Cloud. For SaaS teams sketching MCP servers or OAuth connections to ChatGPT and Claude, AIUC-1 is a useful pre-flight read, not a substitute for your own threat model.
We wrote the companion pieces on MCP for SaaS and secure assistant access and MCP versus REST APIs from the integration side: scopes, tenant isolation, tool catalogues, and when HTTP should stay the automation path. AIUC-1 sits one layer above implementation detail. It asks whether your agent design is insurable in principle: can you explain who may act, on whose data, with what logging, and what happens when the model misfires?






