Collibra achieves AIUC-1 certification: Holding ourselves to the standard we ask of others

Source: Collibra•

Collibra achieves AIUC-1 certification: Holding ourselves to the standard we ask of others

AI agents are entering production faster than organizations can govern them. According to Deloitte's 2026 State of AI in the Enterprise survey, 74% of organizations expect to be using agents at least moderately by 2027, yet only 21% have a mature governance model for them. Boards want…

AI agents are entering production faster than organizations can govern them. According to Deloitte's 2026 State of AI in the Enterprise survey, 74% of organizations expect to be using agents at least moderately by 2027, yet only 21% have a mature governance model for them. Boards want productivity. Security leaders want proof the agents are safe. And every vendor tells its customers that its AI is secure and responsible. The hard question is how anyone verifies that.

Collibra has taken a concrete step toward answering it. We have achieved AIUC-1 certification, the independent standard for AI agent security, safety and reliability, for Maestro assistant, formerly Collibra AI Copilot, the conversational assistant built into the Collibra Platform through which users ask questions about their data, policies, lineage and AI systems. Collibra is the first data and AI governance platform to hold the certification.

The verification gap

For SaaS, SOC 2 eventually solved the trust problem by giving buyers a shared, auditable benchmark. AI agents had no equivalent. Security leaders were left assembling a patchwork from the EU AI Act, ISO 42001, NIST AI RMF, MITRE ATLAS and OWASP, none of which was written for systems that reason, call tools and act on live enterprise data. Vendor questionnaires grew longer while the answers grew harder to check.

AIUC-1 was built to close that gap. Developed with a consortium of more than 250 Fortune 500 security leaders, it organizes agent-specific controls into six domains: Data & Privacy, Security, Safety, Reliability, Accountability and Society. It is crosswalked to the major frameworks and refreshed quarterly to keep pace with a threat landscape that changes every few months.

What we submitted to

AIUC-1 certification is not a self-attestation. It begins with scoping the agent, its deployment context and the applicable controls. The agent is then red-teamed across thousands of real-world scenarios covering jailbreaks, prompt injection, data leakage, hallucinations and unsafe tool calls. An accredited third-party auditor reviews evidence for policy, operational and technical controls across all six domains. Only then is a certificate and full audit report issued, valid for one year with quarterly retests.

Maestro assistant went through every stage. The outcome is independent confirmation that when a user asks Maestro a question, the answer stays within the guardrails the standard requires: no exposure of data the user is not entitled to see, resistance to manipulation, and responses grounded in governed sources rather than invention.

A shared direction across industries

AIUC-1 certification is still young, and the organizations that have pursued it so far come from very different corners of the AI landscape: Cursor in software development, Harvey in legal, ElevenLabs in voice, UiPath in automation, Intercom's Fin in customer support and, most recently, KPMG in professional services. What they have in common is a decision to let an independent party test and audit their agents rather than ask customers to take security on faith. We are glad to be part of that movement.

Collibra is the first in data and AI governance to join it, and the reason we did is rooted in what a governance platform is. Collibra holds the metadata, policies, lineage and access rules that describe an organization's most sensitive assets. An assistant that answers questions across that estate carries a particular responsibility, because the questions it can answer are precisely the ones an adversary would want to ask. A platform that customers rely on to govern AI should itself be governed to a standard they can verify.

Part of a longer commitment

This certification does not stand alone. Collibra was among the first organizations to achieve ISO 42001 certification for AI management, we signed the EU AI Pact ahead of the AI Act's obligations, and we have consistently built the frameworks our customers need into the platform itself. Since May, Collibra AI Command Center has included an out-of-the-box AIUC-1 assessment, so customers can evaluate every agent in their own portfolio against the same standard, attach evidence, route it through review workflows and keep conformance current as their agents evolve.

Going through certification ourselves made that assessment better. We learned first-hand which controls are hardest to evidence and what an auditor actually asks for. Those lessons now guide customers along the same path.

What it means for our customers

For security and procurement teams, the certification offers something concrete: an independent audit report on how Maestro's guardrails are implemented and how it performed under red-teaming, in place of a questionnaire answered with assurances. For governance and AI leaders, it signals consistency. We ask our customers to hold their agents to an independent, agent-specific standard. We have now held our own to it.

The standard we chose

The gap between agent adoption and agent trust will not close on assurances. It closes on evidence, tested by someone other than the vendor making the claim. That is what AIUC-1 provides, and it is the bar we have chosen to meet, and keep meeting, as our own AI evolves.

To learn more, explore the AIUC-1 assessment in Collibra AI Command Center, the Collibra Trust Center and the AIUC-1 standard.

  • Tara MavrovitisTara MavrovitisSenior Director, GRCCollibra

Tara Mavrovitis

Tara Mavrovitis

Senior Director, GRC

Collibra

What this article says