Future Proof The Authority Stack
European AI Agent Certification Standard
Methodology v 1.0 · Friday, 17 April 2026
Published by Future Proof Intelligence
The Authority Stack Briefing Weekly: EU AI Act enforcement, AI insurance market shifts, named carriers. Every Tuesday.
Read past issues →
European AI Agent Certification Standard

AI agent certification: a common way to read whether an agent is safe to rely on.

Methodology v2.0 is the published reference for AI agent certification. Seven dimensions. Weighted scoring. Independent assessment. One published standard, readable by anyone. The AI Omnibus, in force since 27 July 2026, moved the EU AI Act high-risk dates but not the evidence those obligations call for. A certified agent is one whose operator has been scored against all seven dimensions by an independent assessor and can produce the evidence file behind the score.

Framework 7 Dimensions
Scoring Range 0 to 100
Certification Tiers Five
Validity 12 Months
Methodology v2.0, Published 24 April 2026

The published reference for AI agent certification. Seven dimensions. Five tiers. Standards crosswalk. Assessment process. The document law firms, insurers, and regulators cite.

Read Methodology v2.0 →
Section I

Purpose of the framework

Europe is deploying autonomous agents into production faster than any governance framework can track. Agent Certified exists so that insurers, regulators, boards and counterparties have a common way to read whether an agent is safe to rely on.

For the Operator

A structured benchmark that produces a defensible position on governance, oversight, technical controls and operating readiness before an incident, not after.

For the Insurer

A consistent signal of risk posture across portfolios. Certification maps to the governance, transparency and human oversight obligations emerging under the EU AI Act.

For the Board

A clear artefact directors can reference in risk committees, vendor reviews and annual reports without having to construct one from scratch.

Section II

The seven dimensions

Every certified agent is evaluated against seven dimensions. Each dimension carries a weight reflecting its importance to operational safety and regulatory exposure. Together they total one hundred points.

Dimension 01 Weight 18

Trust & Safety

Guardrails, red teaming, misuse detection and the measurable prevention of unsafe actions in production.

Dimension 02 Weight 14

Context Integrity

How the agent sources, verifies and keeps fresh the data it reasons over, including provenance and lineage.

Dimension 03 Weight 12

Distribution Control

Who can invoke the agent, under what authority, and how downstream actions are bounded.

Dimension 04 Weight 14

Product Maturity

Reliability of the agent as a product surface: uptime, regression discipline, evaluation coverage and versioning.

Dimension 05 Weight 16

Governance

Board oversight, documented policies, risk registers, role accountability and audit trails at the operating level.

Dimension 06 Weight 12

AI Integration

How responsibly the agent sits inside existing systems of record, identity, approval and escalation.

Dimension 07 Weight 14

Autonomy Envelope

The explicit boundary between autonomous action and human confirmation, including revocation, rollback and hard stops. The single most important constraint on operational risk.

Read the full methodology →

Section III

Certification levels

The weighted score across all seven dimensions places the agent into one of five recognised tiers. The band is the signal that counterparties read.

Pre
Progress
Certified
Advanced
Elite
0 to 19 20 to 34 35 to 54 55 to 74 75 to 100
00 to 19

Pre Assessment

Baseline acknowledged. Governance, oversight and technical evidence are not yet sufficient for a certification call.

20 to 34

In Progress

Operator has initiated formal controls. Recognised as an active candidate, not yet certified.

35 to 54

Certified

The agent meets the operating floor. Counterparties may rely on the mark for standard commercial use.

55 to 74

Advanced

Materially above floor. Suitable for higher exposure deployments including regulated sectors.

75 to 100

Elite

Exemplar. Every dimension materially above the floor, including the two highest weighted. The tier the methodology is calibrated against.

See what each level requires →
Read a constructed deployment scored dimension by dimension →

Section IV

Questions this standard answers

Three questions arrive here more than any others. Each answer below is self contained, so it can be read, quoted or checked without reading the rest of the page.

What is AI agent certification?

AI agent certification is an independent assessment of whether an autonomous AI agent is safe for a counterparty to rely on, producing a documented score rather than a pass or fail. Under the Agent Certified methodology an assessor scores the agent across seven weighted dimensions, Trust and Safety, Context Integrity, Distribution Control, Product Maturity, Governance, AI Integration and Autonomy Envelope, totalling one hundred points, and places the result in one of five tiers from Pre Assessment to Elite. What makes it a certification rather than a self assessment is that the score is produced by a party other than the operator, against a rubric published in advance, and is backed by an evidence file a third party can inspect. Certification is voluntary. It is not the same thing as conformity assessment under Article 43 of the EU AI Act, which is a legal procedure carried out by a notified body for high risk systems, and it does not replace it.

How do you certify an AI agent's access?

Certifying an agent's access means proving four things about the authority it holds, and they are assessed under the Distribution Control dimension. First, identity: the agent authenticates as a distinct principal with its own credential, not as a shared service account or a borrowed human login, so every action it takes is attributable. Second, scope: the permissions it holds are enumerated, least privilege, and expressed as a written boundary rather than inherited from whatever the integration happened to grant. Third, downstream bounds: which onward systems it may invoke, what value or volume thresholds trigger a human approval, and what it may never do without one. Fourth, revocation and logging: a named owner can withdraw access immediately, and every invocation is logged with enough detail to reconstruct who asked, what was done and under whose authority. An access claim that cannot be evidenced on all four points does not score.

What vendors provide AI agent access certification?

There is no accredited market for this yet, and any answer that implies otherwise is describing something that does not exist. Four routes are real today. Certification against ISO/IEC 42001:2023, the AI management system standard, is issued by accredited certification bodies rather than by ISO itself, and it certifies the management system around the agent, not the agent's access model. Conformity assessment under Article 43 of the EU AI Act is carried out by notified bodies, applies only to high risk systems, and applies from 2 December 2027 for Annex III systems. AIUC-1, published by the Artificial Intelligence Underwriting Company, is an AI agent standard of 51 requirements and 130 controls across six pillars, assessed through an accredited auditor route and used as a condition of insurance cover rather than as a public mark. Agent Certified, published here, is the fourth: a voluntary methodology with a published rubric, run as an independent assessment. It is not a government accredited certification body and it does not present itself as one. A buyer comparing these should ask which of the four actually looks at the agent's access model, because only two of them do.

Section V

Latest analysis

Long form writing on certification, conformity assessment, and the standards landscape that Agent Certified connects to. Updated as the methodology evolves.

17 August 2026 · Methodology

Does the EU AI Act delay mean you can skip AI agent certification?

Annex III moved to December 2027. Does that mean AI agent certification can wait too? A sober look at what the delay changes and what it does not touch.

Read analysis →
10 August 2026 · Standards

DORA and AI agent certification: what financial services firms need

How DORA's ICT third party risk rules reach AI agents used by EU financial entities, and how independent certification evidence closes the board level gap.

Read analysis →
7 August 2026 · Methodology

Do you need to recertify after an AI agent incident?

An AI agent incident does not automatically void a certification. Here is when recertification is actually required, and what evidence a re-review needs.

Read analysis →
Updated 17 August 2026 · Methodology

What evidence an EU AI Act deployer needs to hold in 2026

The AI Omnibus moved the Article 26 high-risk deployer obligations to 2 December 2027. Here is the evidence file to hold anyway, and how certification maps to it.

Read analysis →
29 July 2026 · Analysis

AIUC-1 to FP Certified: a control-by-control crosswalk for risk leads

A direct mapping of AIUC-1's four control domains and five coverage categories against the seven weighted dimensions of the FP Certified methodology.

Read analysis →
27 July 2026 · Methodology

Does AI agent certification transfer if you switch vendors?

If you move to a new AI vendor or model, does your existing agent certification still count. What transfers, what does not, and why the answer differs by framework.

Read analysis →
24 July 2026 · Methodology

What happens when an AI agent fails certification?

A failed assessment is a findings document, not a dead end. What a low score actually means, what happens to the record, and the realistic path to re-assessment.

Read analysis →
22 July 2026 · Methodology

Certifying Multi-Agent Systems: A Practical Guide

When one agent calls another, single-agent certification assumptions break. How assessment scope, accountability, and evidence change for agent-to-agent workflows.

Read analysis →
15 July 2026 · International Standards

The Council of Europe AI Convention and what it means for certification

The first binding international AI treaty takes a human rights approach distinct from the EU AI Act. What that means for AI agent certification evidence.

Read analysis →
10 July 2026 · Methodology

AI Certification and the FRIA Burden Under Article 27

A precise look at Article 27 FRIA duties and where AI agent certification evidence genuinely overlaps with, but never replaces, the deployer's own assessment.

Read analysis →
8 July 2026 · Methodology

What does AI agent certification actually cost in 2026?

What does AI agent certification actually cost in 2026? A sober look at why no fixed market rate exists yet, what drives engagement cost, and how to weigh it.

Read analysis →
6 July 2026 · Methodology

Does AI agent certification actually reduce insurance premiums?

A sober look at whether AI agent certification genuinely reduces insurance premiums in 2026, what real evidence exists, and the honest answer today.

Read analysis →
3 July 2026 · Methodology

AI Integration: whether an agent extends institutional memory or quietly bypasses it

An analysis of the AI Integration dimension of AI agent certification: whether an agent extends institutional memory or quietly bypasses it, and how it is scored.

Read analysis →
3 July 2026 · Methodology

Distribution Control: who can invoke an agent, under what authority, and how downstream actions are bounded

An analysis of the Distribution Control dimension of AI agent certification: who can invoke an agent, under what authority, and how downstream actions are bounded.

Read analysis →

Three longer reference pieces sit outside the running list: the complete Agent Certified framework guide, which sets out the standard end to end; the assessment process step by step, which describes what an assessment actually involves; and the performance and reliability dimension in detail. Everything published on this subject is collected in the AI agent certification topic index.

Section VI

Foundational references

The framework is built on existing, recognised instruments rather than in parallel to them. Every dimension traces back to at least one primary reference.

Reference Issuer Relevance
ISO/IEC 42001:2023 International Organization for Standardization AI management system requirements. Informs Governance and Product Maturity dimensions.
NIST AI Risk Management Framework US National Institute of Standards and Technology Risk function model. Informs Trust & Safety and Context Integrity dimensions.
EU AI Act, Articles 9, 10, 14, 15 European Parliament and Council Risk management, data governance, human oversight and accuracy. Maps directly to dimension scoring.
EU AI Act, Article 26 European Parliament and Council Deployer obligations. Informs Distribution Control and Autonomy Envelope dimensions.
EIOPA supervisory statements on AI in insurance European Insurance and Occupational Pensions Authority Sector alignment for insurer reliance on the framework.
Q3 2026 assessment window

Request a formal assessment.

Assessments are scheduled in quarterly cohorts. Q3 2026 slots are open to European enterprises and scale ups operating agents in production environments. Submit a request to receive an intake briefing.

The Regulatory Context

Read the law that the methodology operates under.

The Agent Certified framework is calibrated to Article 26 of the EU AI Act, the revised Product Liability Directive, and the supervisory expectations of EIOPA and the AI Office. Agent Liability EU is the operator desk on those instruments.

agentliability.eu