Key takeaways
  • AIUC-1's four control domains, scope definition, adversarial testing, governance documentation, and telemetry, map most directly onto three of FP Certified's seven dimensions: Autonomy Envelope, Trust and Safety, and Governance.
  • Trust and Safety carries the highest weight in the FP Certified methodology at 18 of 100 points, and AIUC-1's requirement for over 5,000 adversarial simulations produces evidence that satisfies a substantial share of this dimension's testing requirements.
  • Context Integrity (weight 14) and Distribution Control (weight 12), together 26 of the 100 available points, have no direct AIUC-1 equivalent, because AIUC-1 was not designed to evidence EU-specific data governance or end-user transparency obligations.
  • A business holding a completed AIUC-1 audit can reuse that evidence for roughly half of the FP Certified score by weight, but still needs to produce EU AI Act article mapping and deployer-specific documentation for the remainder.
  • Product Maturity (weight 14) and AI Integration (weight 12) draw partial evidence from AIUC-1's testing and scope definition work, but require additional documentation FP Certified specifies that AIUC-1 does not.

Every operator holding an AIUC-1 audit and considering an FP Certified assessment asks a version of the same question: how much of this do I have to do twice. The honest answer is neither "all of it" nor "none of it." AIUC-1 and FP Certified were built for different legal contexts, US common law liability concepts for the former, EU AI Act deployer obligations for the latter, but both frameworks are, at bottom, trying to produce evidence that a given AI agent is safe to operate and safe to insure. Where that underlying evidence overlaps, it transfers. Where it does not, it has to be produced separately. This crosswalk sets out exactly where each of those lines falls.

The seven dimensions, for reference

The FP Certified methodology scores an AI agent across seven weighted dimensions summing to 100 points: Trust and Safety (18), Governance (16), Context Integrity (14), Product Maturity (14), Autonomy Envelope (14), Distribution Control (12), and AI Integration (12). The full scoring rubric for each is set out in the seven dimensions guide. This article assumes that structure and walks through what AIUC-1 evidence does, and does not, contribute to each one.

Where AIUC-1 evidence transfers directly

Adversarial testing to Trust and Safety (weight 18)

AIUC-1's most demanding requirement, over 5,000 adversarial simulations testing for prompt injection, jailbreak attempts, data exfiltration pathways, unsafe tool use, and harmful output generation, is also the single most useful piece of evidence an operator can bring to an FP Certified assessment. Trust and Safety carries the highest weight of any FP Certified dimension precisely because robustness under adversarial conditions is the strongest available predictor of real-world failure rate. A completed AIUC-1 adversarial test report, submitted as supporting evidence, covers a meaningful share of what an FP Certified assessor would otherwise need to test independently, though the assessor will still confirm the testing methodology's coverage against FP Certified's own robustness criteria rather than accepting the AIUC-1 pass or fail result at face value.

Governance documentation to Governance (weight 16)

AIUC-1 requires a named senior owner for the agent, a documented risk policy, a vendor and model supplier due diligence record, and an audit trail of agent decisions with defined retention periods. This is close to a direct match for the FP Certified Governance dimension, which scores policies, incident response readiness, and liability chain clarity. An operator with complete AIUC-1 governance documentation can expect most of this evidence to carry over, with one addition FP Certified requires that AIUC-1 does not: a documented liability chain analysis identifying which party, foundation model provider, fine-tuning layer, or deployer, is responsible for which category of failure, a requirement that stems from the EU AI Act's provider and deployer distinction under Article 26 and has no equivalent concept in AIUC-1's US-oriented governance clause.

Scope definition to Autonomy Envelope (weight 14)

AIUC-1's scope definition requirement, documenting an agent's permitted actions, tool access, data access, and decision boundaries with enough precision for external audit, overlaps substantially with the Autonomy Envelope dimension, which scores the level of autonomous decision-making an agent is permitted and the human checkpoints built around it. Where AIUC-1 asks "what can this agent do," Autonomy Envelope asks the closely related question "what should this agent be allowed to do without a human confirming it," which means a well-documented AIUC-1 scope definition is most of the raw material an Autonomy Envelope assessment needs, with the added FP Certified requirement that the human checkpoint itself be evidenced as functioning, not merely specified on paper, a distinction that traces to Article 14's requirement that human oversight be meaningful rather than nominal.

Where AIUC-1 evidence contributes partially

Telemetry and observability to Governance and Trust and Safety

AIUC-1's telemetry requirement, that the agent produce structured, retained, insurer-accessible logs supporting post-incident investigation, is one of the few AIUC-1 obligations with a reasonably close EU statutory analogue, Article 12's logging requirement for high-risk AI systems. This evidence splits across two FP Certified dimensions rather than mapping to one: it supports the Governance dimension's audit trail requirement and the Trust and Safety dimension's incident investigation criteria simultaneously. An operator should expect an FP Certified assessor to credit AIUC-1 telemetry evidence against both, but not to treat it as fully satisfying either dimension alone, since each dimension also scores elements telemetry alone does not establish, such as whether the governance policy was actually followed when an incident occurred.

Adversarial testing and scope definition to Product Maturity (weight 14) and AI Integration (weight 12)

AIUC-1's testing rigour and scope documentation both feed partially into Product Maturity, which scores testing methodology and product safety more broadly than adversarial robustness alone, and into AI Integration, which scores how the AI system is embedded into the operator's actual business processes rather than how it behaves in isolated testing. AIUC-1 evidence establishes that the agent has been tested and that its permitted actions are documented, which is necessary but not sufficient for either FP Certified dimension. Product Maturity additionally requires evidence of a broader testing methodology across the product lifecycle, not only adversarial simulation, and AI Integration requires evidence of how the agent's outputs are actually consumed downstream in the business, which is an operational question AIUC-1's audit does not examine because it sits outside AIUC-1's insurance-pricing purpose.

Where AIUC-1 has no equivalent

Context Integrity (weight 14)

Context Integrity scores data quality and training data governance, corresponding to Articles 10 and 13 of Regulation (EU) 2024/1689 on data governance and provider-to-deployer transparency. AIUC-1's coverage of data-related risk is narrower and outcome-focused: its "data leakage" insurance category responds to an agent exposing personal or confidential data through its outputs, which is a different question from whether the training and validation data underlying the agent was governed to an adequate standard in the first place. An operator pursuing FP Certified needs to produce Context Integrity evidence independently of any AIUC-1 documentation, because AIUC-1 was never designed to ask this question.

Distribution Control (weight 12)

Distribution Control scores how an agent's outputs reach users and what controls exist over that distribution, corresponding most closely to Article 50's transparency and labelling obligations, which require that users be informed they are interacting with an AI system in specified circumstances. AIUC-1 contains no equivalent control domain, again because this is a EU-specific statutory transparency duty toward end users with no direct US regulatory parallel at the time AIUC-1 was written. This is the second of the two dimensions, alongside Context Integrity, that an AIUC-1-only operator must build evidence for entirely from scratch.

What this means in practice: roughly half the score, by weight

Summed by weight, AIUC-1 evidence contributes meaningfully to Trust and Safety (18), Governance (16), and Autonomy Envelope (14), a combined 48 of the 100 available FP Certified points, plus partial contributions to Product Maturity (14) and AI Integration (12) that reduce but do not eliminate the additional evidence-gathering required there. Context Integrity (14) and Distribution Control (12), 26 points combined, require evidence built independently of any AIUC-1 audit. The practical guidance for a compliance team holding a completed AIUC-1 audit is to treat it as covering roughly half of an FP Certified assessment by weight, not as a substitute for one, and to plan the remaining evidence-gathering around the two dimensions AIUC-1 was never built to address rather than duplicating work in the dimensions where it already provides usable evidence. This is consistent with the broader conclusion in our companion analysis of the European certification gap AIUC-1 leaves open, that the two frameworks are complementary rather than competing, and it is why the Agent Certified assessment intake asks operators directly whether an AIUC-1 audit already exists before scoping the evidence-gathering plan.

For the insurance side of why this crosswalk matters commercially, specifically how underwriters weigh certification evidence when pricing an AI liability policy, see the companion analysis on AI agent certification and insurance eligibility on agentinsured.eu.