- Two unrelated things are being called certification. A management system certification says how a company governs its AI work. An agent certification says how one named system behaved under test on one date. A vendor can hold either without the other.
- A certificate is scoped to a system in a configuration. Your deployment adds your prompts, your data, your connected tools and your users, and none of that was assessed. The certificate is about the supplier, not about you.
- The independent audit layer for AI agents became real in 2026 and it is private. Schellman published on 3 February 2026 that it had become the first accredited auditor for AIUC-1, and KPMG published on 27 August 2026 that KPMG LLP is the first of the Big Four to achieve AIUC-1 certification.
- There is no equivalent public route yet. For most high-risk categories the EU AI Act sets a conformity assessment based on internal control, described in Annex VI as a procedure which does not provide for the involvement of a notified body.
- Six questions turn a badge into information: which standard, which system, assessed by whom, on what date, in what scope, and can you see the report.
The word covers two different objects
When a supplier says it is certified, it is almost always saying one of two things, and the two are not close relatives.
The first is a management system certification. The reference point here is ISO/IEC 42001, an artificial intelligence management system standard. What it certifies is organisational: that a company has defined roles, written policies, set review cycles, assessed risks and can show it follows its own process. It is a statement about how the supplier works. Notably, it is not a statement about any particular product, and it does not involve anybody testing what your agent says to your customers.
The second is an agent certification. The reference point that has emerged here is AIUC-1, which describes itself on its own site as the standard for AI agent security, safety and reliability, and which publishes a mapping to a long list of existing frameworks including the EU AI Act, ISO 42001, the NIST AI Risk Management Framework, MITRE ATLAS and several OWASP catalogues. What it certifies is a specific system, tested against scenarios, with a result.
Both are real. Neither substitutes for the other. A supplier can hold ISO 42001 and ship an agent nobody has adversarially tested, because the standard does not require that any particular product be tested. A supplier can certify one agent under an agent standard while operating twenty others with no governance around them at all, because the certificate was scoped to one system. If a vendor says certified without saying which, the first useful question is simply which one, and the second is which product.
The related question of who carries the loss when the supplier's system is the thing that fails is separate from either certificate, and we treat it at who pays when an AI agent makes a mistake, the vendor or you.
What happened in 2026, and why it matters to a buyer
For most of the last two years, a vendor claiming AI certification was usually pointing at its own testing. That changed during 2026, and the change is worth understanding because it is the reason the claim has started to carry weight.
Schellman published on 3 February 2026 that it had become the first accredited auditor for AIUC-1. What Schellman describes is a division of labour: Schellman provides, in its own words, independent audit evidence collection, detailed reporting, and certification guidance, while the Artificial Intelligence Underwriting Company conducts technical evaluations and issues certification. Schellman also states that agent behaviour is tested quarterly to ensure ongoing compliance, and that the standard operationalises leading frameworks including ISO 42001, the NIST AI Risk Management Framework, MITRE ATLAS and the OWASP Top 10 for LLMs. Separately, Schellman describes itself on its own site as the first ISO 42001 ANAB accredited certification body, which is the older and more conventional accreditation route and a useful point of comparison.
On 27 August 2026 KPMG published that KPMG LLP is the first of the Big Four to achieve AIUC-1 certification, for aIQ Capture, which it describes as a KPMG developed agentic AI organizational intelligence platform. KPMG states the platform underwent more than 900 technical tests including hallucinations, high-risk domain interactions, content safety, prompt injection attacks, and other scenarios. Arun Rajappa, National Managing Principal, Risk Management and Compliance at KPMG LLP, is quoted on the announcement saying that before the firm put its name behind its own agentic system, it had it independently tested and certified.
That sentence is the honest summary of what a good certificate now means: somebody outside the company tested the thing before the company staked its name on it. That is genuinely more than a self-assessment, and a buyer is right to value it. It is still not a statement about your deployment.
Why the certificate does not reach your deployment
A certificate is scoped. It names a system, in a configuration, assessed on a date. Read what your own deployment adds to that system after it leaves the vendor.
- Your instructions. The system prompt, the persona, the rules you gave it about what it may promise. None of that existed at assessment.
- Your data. Whatever knowledge base, document store or product catalogue it reads from. A tested agent grounded in an untested corpus is an untested outcome.
- Your tools. What you connected it to. An agent that can only answer questions and an agent that can issue a refund are different risks wearing the same certificate.
- Your users. Who talks to it, in what language, under what pressure, and whether they are customers or staff.
- Your changes since. Yours and the vendor's both, which is the one people forget.
This is why a certificate helps your supplier selection and does very little for your liability position. If your agent tells a customer something wrong and the customer relies on it, the claim comes to you, and the fact that the underlying model passed 900 tests in somebody else's configuration is background rather than defence. The mechanics of that are set out at if an AI agent gives wrong advice, does insurance cover it, and the contractual side is at how to review an AI vendor contract for liability gaps.
There is no EU certificate to ask for, and the reason is in the Act
A reasonable buyer assumes that a regulation as detailed as the EU AI Act must produce an official certificate that a vendor can hold up. For most categories it does not, and the reason is worth knowing because it explains why private standards moved first.
Article 43 of the AI Act sets out which conformity assessment procedure applies to which kind of high-risk system. For Annex III point 1, which is biometrics, a provider chooses between internal control and an assessment involving a notified body. For Annex III points 2 to 8, which is nearly everything an ordinary business would recognise, covering employment and worker management, education, credit and essential services, law enforcement, migration and the administration of justice, the text states that providers shall follow the conformity assessment procedure based on internal control as referred to in Annex VI, which does not provide for the involvement of a notified body.
Annex VI is exactly what its name suggests. The provider verifies that its own quality management system meets the requirements, examines its own technical documentation, and satisfies itself that design, development and post-market monitoring are consistent with that documentation. No outside party is involved at any step. The full reading of that architecture, and what it means for a European buyer relying on a CE mark, is on our regulatory desk at most high-risk AI needs no outside auditor under the Act.
So when a European vendor tells you it is compliant with the AI Act, that is a different kind of claim from certified. It may be entirely true and it is, by the Act's own design for these categories, self-declared. Whether that matters for your obligations is covered at the plain guide to SME obligations under the AI Act.
How to read a certification claim without being unfair about it
A short worked example, because it teaches the habit better than a rule does. The consortium behind AIUC-1 is described in three places with three different numbers. Schellman, writing in February 2026, describes it as 60 or more chief information security officers and security leaders from Fortune 500 companies. The standard's own site describes it as created with 100 or more Fortune 500 chief information security officers. KPMG, writing in August 2026, describes it as a group of more than 250 Fortune 1000 security leaders.
None of those is a lie. A group grows over six months, and Fortune 500 chief information security officers and Fortune 1000 security leaders are not the same population being counted twice. But a buyer who repeats any one of the three as the number has taken a figure that depends on who wrote it and when, and turned it into a fact. The lesson generalises well beyond this example: when a certification claim comes with a number, ask what is being counted, by whom, and as at when. Most of the time the answer is fine. The habit is what protects you the one time it is not.
Six questions for the vendor
All six are answerable in writing, none of them is aggressive, and a supplier that has done the work will enjoy answering them.
- Which standard, by name and version? Certified is not a standard. ISO/IEC 42001 and AIUC-1 are, and they certify different objects.
- Which system was certified, by product name? Rarely the whole company, and rarely every product. Establish whether the thing you are buying is the thing that was assessed.
- Who performed the assessment, and what is their relationship to the standard's owner? An independent auditor and a self-assessment can both be described as certification. They are not the same evidence.
- On what date, and when is the next test? An AI system changes when nobody touches it, because the underlying model can be updated by its provider. A certificate that is re-earned on a cycle is worth more than one held indefinitely.
- What was in scope and what was excluded? Scope statements are where the useful information lives, and they are almost never on the badge.
- May we see the report, under confidentiality if needed? The answer is informative either way. A supplier that shares it is telling you something. A supplier that will not may still be reasonable, and now you know to weigh the badge accordingly.
Keep the answers. They are procurement diligence records, and they are the part of this that does belong in your own file. The wider version of that exercise is at the AI agent pre-deployment insurance checklist.
What your insurer will actually ask
Here is the part that surprises people. In an underwriting conversation, a vendor certificate is a minor line item, and it is a minor line item for a structural reason rather than a dismissive one. Underwriters price your exposure. Your exposure is your deployment, your controls and your history, and a vendor certificate is evidence about a third party.
It does one thing well. It is part of the answer to how you chose the supplier and what diligence you performed, which is a question that genuinely gets asked and that most small businesses answer badly. Beyond that, the evidence that moves a conversation is evidence about you: what you deployed, who approved it, what limits you set on what it can do, what you tested before launch, what you monitor now, and what you would do in the first hour of an incident. That list is set out at what an underwriter will ask about your AI agent, and the disclosure duty that sits underneath it is at do I need to disclose AI agents to my insurer.
The way certification and coverage genuinely connect is one level up from the vendor badge: it is your own assessed position, not your supplier's. That relationship is treated at agentinsured.eu, on certification, eligibility and premium, and the methodology view of what an assessment examines is at agentcertified.eu, on the arrival of an accredited audit layer.
The honest summary
A vendor certificate is good news and it is narrow news. It means somebody outside that company looked at one of its systems and said so on a date, which is more than most suppliers can show and considerably more than was available two years ago. It does not extend to your configuration, it does not move liability, it is not insurance, and for most European high-risk categories there is no official version of it to ask for, because the Act asks providers to assess themselves.
Treat it as one input into supplier selection, record the six answers, and spend the rest of your effort on the file that describes your own deployment. That file is the one that decides a claim, and unlike the vendor's certificate, it is the one you control.
Questions
Does my AI vendor's certificate cover my business?
No. A certificate is a statement about a named system in a named configuration, assessed on a date. Your deployment adds your prompts, your data, your connected tools, your permissions and your users, and none of those were in scope. The certificate tells you the vendor submitted the system to an external test and it tells you nothing about the thing you actually run. It is a reason to trust the supplier more. It is not a defence, it is not a transfer of liability, and it is not something your insurer will treat as covering you.
What is the difference between ISO 42001 and AIUC-1?
They certify different objects. ISO/IEC 42001 is a management system standard, so it certifies how an organisation governs its AI work: the policies, the roles, the review cycles. AIUC-1 describes itself as a standard for AI agent security, safety and reliability, so it certifies a specific agent against tests. A company can hold ISO 42001 and still ship an agent nobody tested, and a company can certify one agent under AIUC-1 while running twenty others with no governance at all. If a vendor says certified without saying which, that is the first question to ask.
Is there an EU certificate for AI agents I can ask a vendor for?
Not in the sense most buyers imagine. For the majority of high-risk categories under the EU AI Act, which is Annex III points 2 to 8 and covers employment, education, credit, essential services, law enforcement, migration and justice, the Act's own text sets a conformity assessment based on internal control, described in Annex VI as a procedure which does not provide for the involvement of a notified body. In plain terms the provider assesses itself. Where a CE mark eventually appears on such a system it rests on the provider's own file rather than on an outside audit.
Does a vendor certificate reduce my insurance premium?
Not on its own, because it is evidence about somebody else. Underwriters price your exposure, which is your deployment, your controls and your loss history. A vendor certificate helps in a narrow and real way: it is part of the answer to how you selected the supplier and what diligence you performed, which is a question that does get asked. The evidence that moves a premium is evidence about you, and the practical form of that is a record of what you deployed, who approved it, what you tested and what you monitor.
How long is an AI agent certificate valid?
Ask, because it varies and because the answer matters more here than in other fields. An AI system changes when nobody touches it, since the underlying model can be updated by its provider on the provider's timetable. A certificate awarded once and held indefinitely is worth much less than one that is re-earned. Schellman states that under AIUC-1 agent behaviour is tested quarterly to ensure ongoing compliance, which is the shape to look for. The two things to establish are the date of the last test and what happens between tests.
What should I ask a vendor that claims AI certification?
Six things. Which standard, by name and version. Which system was certified, by product name, since it is rarely the whole company. Who performed the assessment and are they independent of the standard's owner. On what date, and when is the next test. What was in scope and what was excluded. And whether you may see the report or only the badge. A vendor that answers all six in writing has told you more than the certificate did. A vendor that cannot answer the second and fourth is describing a marketing asset.
Sources
- Schellman, "Schellman Becomes the First Accredited Auditor for AIUC-1", dated 3 February 2026. Division of responsibility and quarterly testing cadence quoted from that page. Read at schellman.com on 31 August 2026.
- Schellman's description of itself as the first ISO 42001 ANAB accredited certification body, read at schellman.com on 31 August 2026.
- KPMG, "KPMG LLP Becomes First Big Four Firm with AIUC-1 Certified AI Capability", dated 27 August 2026. The aIQ Capture description, the figure of more than 900 technical tests, the categories tested, and the quotation attributed to Arun Rajappa are all taken from that announcement. Read at kpmg.com on 31 August 2026.
- AIUC-1's self description, its stated framework mappings and the phrase created with 100 or more Fortune 500 chief information security officers, read at aiuc-1.com on 31 August 2026. The three differing consortium figures cited in this article come from schellman.com, aiuc-1.com and kpmg.com respectively, and are reported as differing rather than reconciled.
- Regulation (EU) 2024/1689 (EU AI Act), Article 43 on conformity assessment procedures and Annex VI on the procedure based on internal control. The phrase which does not provide for the involvement of a notified body is quoted from Article 43 as served at ai-act-service-desk.ec.europa.eu on 31 August 2026. That page carried a Digital Omnibus notice stating the provision has been amended and that the displayed text has not yet been updated, so the wording should be re-read before it is relied on.
- ISO/IEC 42001 is described here only in general terms as an artificial intelligence management system standard. No clause, requirement or edition detail is asserted, because the standard text is behind a paywall and was not read for this article.
- Nothing in this article should be read as an endorsement of, or a relationship with, AIUC, Schellman, KPMG or any certification body. Each is named because it published the statement attributed to it, on its own domain, on the date given.