
Research
Emil Lassen
Emil Lassen
3 min read
3 min read
Cursor achieves AIUC-1 certification

Coding agents now do work that used to require a trusted engineer. Cursor’s AIUC-1 certification validates how its agents behave across real-world coding risks.
Coding agents now do work that used to require a trusted engineer. They read repositories, write and execute code, install dependencies, and open pull requests.
Close to 70% of the Fortune 500 use Cursor, and as coding agent autonomy grows, so does the blast radius of an agent that misbehaves: a secret surfaced in a commit, a package installed against policy, or an instruction obeyed because someone planted it in a README.
Traditional security certifications answer how data is stored, protected, and governed. They say little about how an agent behaves when it is asked to write insecure code, expose a credential, or take an action it should refuse.

Certifying an agent that writes and runs code
Coding agents pose a distinct certification challenge. A consumer service agent can be assessed largely on what it says. A coding agent must be assessed on what it does: the files it reads, the commands it runs, the dependencies it pulls in, and the code it leaves behind.
Cursor’s agents were subjected to thousands of evals across two rounds, covering 12 risk categories including secrets leakage, hidden prompt injection, and insecure code defaults.
Evals ran against Cursor’s key product surfaces — the agent in the IDE and cloud agents — using a representative enterprise configuration with rules, hooks, .cursorignore, and Auto-review enabled. This ensures the results reflect the collective defenses operating across the model and application layers rather than a single control in isolation.
Alongside the evals, Schellman reviewed Cursor’s operational, governance, and security controls, including Privacy Mode enforcement, data retention, subprocessor governance, access controls, incident response, and human oversight.
Setting the bar for coding agents
AIUC-1 is developed with input from 250+ Fortune 500 CISOs and risk leaders, and technical contributions from MITRE, the Cloud Security Alliance, and Stanford researchers. The standard is updated quarterly to evolve alongside AI capabilities, risks, and regulation.
The latest version introduced new coding-agent requirements for secrets management, secure defaults in generated code, and runtime containment. Cursor’s certification included these requirements, validating their real-world applicability.
The scope of Cursor’s certification and detailed evals are available upon request through Cursor’s trust portal at trust.cursor.com.
Latest articles
Announcement

KPMG LLP Becomes First Big Four Firm with AIUC-1 Certified AI Capability
KPMG becomes the first Big Four firm to achieve AIUC-1 certification for its aIQ Capture platform.
Read more
Research

Cursor achieves AIUC-1 certification
Cursor’s agents passed thousands of AIUC-1 technical evals across 12 risk categories.
Read more
Announcement

ElevenLabs secures first-of-its-kind AI Agent insurance
Backed by AIUC-1 certification, this establishes a new trust standard for enterprise AI deployments
Read more
