AIUC-1 asks for the approver's name in exactly one place, and it is not the human-review control

AIUC-1 describes itself as the world's first AI agent standard. It is not law. It is a private certification scheme: the Artificial Intelligence Underwriting Company conducts the technical evaluation and issues the certificate, and Schellman, the first authorized auditor, states its own role as providing “independent audit evidence collection, detailed reporting, and certification guidance”.

Every other instrument this project has read is a statute, a regulation or a governance framework. This one is the first where the test is whether an auditor can collect the evidence a control names. That makes it worth reading closely, because a control that asks for something no agent framework emits is a control whose evidence has to come from somewhere.

InstrumentAIUC-1, the AI agent standard
KindCertification scheme, audited. Not law.
Sourceaiuc-1.com, control set published without registration
Read on12 September 2026
Live controls51 across six families, plus two retired
RevisionQuarterly. E007 was merged into E004 and E014 into E017 in the Q1 2026 update
Certificate holdersKPMG (first Big Four firm, 27 August 2026), Cursor, Harvey (first legal AI) and ElevenLabs (first voice AI), named on aiuc-1.com, plus Intercom for its Fin agent, which aiuc-1.com does not list and which AIUC's own certificate overview and Intercom's announcement of 8 December 2025 both state. Checked 13 September 2026. UiPath and Lovable are NOT holders and are recorded here because both are easy to miscount: UiPath is a founding technical contributor and Lovable co-authored a whitepaper

The six families

FamilyLiveWhat it asks for
A. Data & Privacy8Input and output data policies, and safeguards against leakage of PII, IP, credentials and cross-customer data
B. Security10Adversarial testing, endpoint protection, access privileges, and prevention of agent actions beyond authorised scope
C. Safety12A risk taxonomy, pre-deployment testing, prevention of harmful and out-of-scope outputs, and third-party evaluation
D. Reliability4Hallucination prevention, restriction of unsafe tool calls, and quarterly third-party evaluation of both
E. Accountability15Failure plans, assigned ownership, vendor due diligence, internal review, disclosure, transparency, and logging
F. Society2Guardrails against AI-enabled cyber misuse and against chemical, biological, radiological and nuclear misuse

E015 is where the person is

E015, “Log AI system activity”, is mandatory and applied every 12 months. Its requirement reads: “Maintain logs of AI system processes, actions, and agent outputs where permitted to support incident investigation, auditing, and explanation of AI system behavior.”

That sentence alone would be unremarkable. The evidence beneath it is not. E015.2, the agent-specific logging evidence, asks for structured logs capturing:

What E015.2 asks a log to captureLevel
“approver identity, timestamp, decision outcome” for authorization events, the standard's own example being human-in-the-loop approvalsTR-3
“tool call parameters and their results”TR-1
“delegation chain records showing sub-agent handoffs with identity, task context, and outcome”TR-1
“agent type identifier, creator or deployment origin”TR-1

And E015.4, log integrity protection, asks for “write-once-read-many (WORM) storage configuration, cryptographic hashing of log entries, append-only database settings”.

This is the first instrument read by this project that asks for both halves. The identity of the person who approved an action, and technical evidence that the record of it was not altered afterwards. The scheme census read four instruments and found neither in any of them. AIUC-1 was not one of those four, and it has both.

Where the person is not

The placement is the finding, and it is easier to see by looking at the controls that a reader would expect to carry it.

ControlStatusWhat it actually asks for
C007 Flag high risk outputs for human reviewOptionalA policy defining high-risk criteria, detection code, and “workflow documentation showing review processes, assignments, and escalation paths”. Assignments, not reviewers. No individual is required
E008 Review internal processesMandatory“document review records and approvals”, evidenced by meeting notes, decision logs in Jira, Notion or Confluence, and risk registers. Governance of the programme, not of a decision
E004 Assign accountabilityMandatory“approval records showing sign-offs with supporting evidence”, but for lifecycle changes: model selection, meta prompt, guardrails, workflow. Change management, not a runtime action
E015.2 AI agent loggingMandatory“approver identity, timestamp, decision outcome”

The control that establishes human review is optional and names nobody. The control that asks for a name is the logging control. So under AIUC-1 the approver's identity is collected as log content rather than established as an oversight duty. What can be produced therefore depends on what the underlying agent framework emits, not on what the deployer's governance says about itself.

What the frameworks emit

This project has read ten widely deployed agent systems against a published rubric. Of the eight that take or gate consequential actions, one can identify the person who approved one, and that one is the reference implementation of this specification, which is disclosed rather than left to be found. The per-system verdicts, with the file and line behind each, are at /approval-binding/ and /register/.

On the narrower question E015.2 raises by asking for “decision outcome”: of five frameworks with an approval step, two can distinguish a modification from an approval and three cannot. In two of those three, reproduced rather than reasoned about, a reviewer who rewrote an action's arguments and a reviewer who approved it unchanged produce the same record.

What this does not say. It does not say that any AIUC-1 certified product fails E015.2. No certified product has been assessed here and none is named in this reading. A vendor may have built approval logging by hand on top of a framework that does not supply it, and several plainly have the engineering to do so. The claim is narrower and it is about the substrate: the frameworks do not emit the field, so wherever it exists somebody built it deliberately, and whether they did is a question with an answer rather than an assumption.

How this sits beside Colorado

These two do not collide and the distinction is worth stating. Colorado's proposed Rule 7.7 would require a record naming who reviewed a consequential decision about a person, and it would do so as law. AIUC-1's E015.2 asks for the approver of an authorization event in an agent system, and it does so as a condition of a private certificate. Different subjects, different force, and a deployer can be inside one and outside the other.

What they share is the shape of the evidence. A record that can name the approver of an action, distinguish an approval from a modification, and be shown not to have changed satisfies the record-facing part of both. That is the case for the format being jurisdiction-neutral while the reading of each instrument is not.

The reading

Fifteen obligations, ten of which a record can speak to and five of which no log will ever answer. The five are named rather than dropped, because knowing which obligations are documentary saves asking a vendor for something no vendor can supply. The reading is data, dated, and carried by the instrument library rather than written out separately, so this page and the tool cannot drift.

A reading of this text has a shelf life that the statutes do not. AIUC-1 is refreshed quarterly and has already retired two controls into others inside a single update. An auditor working from a reading they made in January is working from a stale one by April, and the control identifiers they cited may no longer resolve.

A wrong reading is cheap to demonstrate. The control set is published openly at aiuc-1.com, every clause quoted here is quoted verbatim, and corrections are published with the date they were made.

Citing this

The readings are CC BY 4.0, which asks for attribution, so the reference is here rather than left to be composed. This block is generated from the page it sits on, so a date that moves here moves in the citation too.

Clifford, T. (2026). AIUC-1 asks for the approver's name in exactly one place. Machine Testimony. https://machinetestimony.org/aiuc-1/
@misc{clifford2026aiuc1,
  author = {Clifford, Troy},
  title  = {AIUC-1 asks for the approver's name in exactly one place},
  year   = {2026},
  note   = {Machine Testimony, read 12 September 2026},
  url    = {https://machinetestimony.org/aiuc-1/},
}

This page carries no DOI. It cites its dated URL, and saying so is the point: a citation naming a deposit that does not exist is worse than one naming a page that does.