{
  "schema_version": "1.1",
  "id": "archive:https://cursor.com/blog/aiuc-1",
  "slug": "aiuc-1-0s1nr9l",
  "url": "https://feed7.dev/p/aiuc-1-0s1nr9l",
  "title": "Cursor earns AIUC-1 certification for agent security and reliability",
  "why_included": "Cursor’s AIUC-1 certification combines a controls audit with adversarial testing of live agents. For enterprise evaluation, it adds behavioral evidence beyond conventional data-security attestations.",
  "summary": "Cursor received **AIUC-1 certification** after an independent controls audit and adversarial testing across **several thousand scenarios** in two rounds. Testing covered IDE and cloud agents in a representative enterprise configuration.",
  "practical_implication": "Teams evaluating coding agents can use the report to inspect coverage of secrets, secure code, MCP, permissions, unsafe commands, and destructive actions. Rules, hooks, and Auto-review were tested together with model safeguards.",
  "agent_context": "Cursor received **AIUC-1 certification** after an independent controls audit and adversarial testing across **several thousand scenarios** in two rounds. Testing covered IDE and cloud agents in a representative enterprise configuration.\n\nTeams evaluating coding agents can use the report to inspect coverage of secrets, secure code, MCP, permissions, unsafe commands, and destructive actions. Rules, hooks, and Auto-review were tested together with model safeguards.\n\nCertification is recurring: testing occurs **at least quarterly**, with a **full annual audit**. The post summarizes a passing result, but detailed scope and findings must be checked in Cursor’s trust-portal report.",
  "source": {
    "name": "Cursor",
    "url": "https://cursor.com/blog/aiuc-1",
    "published_at": "2026-08-13T12:00:00.000Z"
  },
  "source_class": "blog_post",
  "content_type": "Engineering Post",
  "layer": "benchmark",
  "domains": [
    "coding",
    "security"
  ],
  "topics": [
    "agent-evals",
    "agent-reliability",
    "benchmark-integrity"
  ],
  "verification": {
    "status": "official_source",
    "label": "Official Source",
    "method": "source_feed",
    "verified_at": null
  },
  "uncertainty": [
    "Certification is recurring: testing occurs **at least quarterly**, with a **full annual audit**. The post summarizes a passing result, but detailed scope and findings must be checked in Cursor’s trust-portal report."
  ],
  "connected_context": {
    "meaning": "This adds independently audited, recurring evidence about Cursor’s deployed security-control stack, complementing capability benchmarks that say little about secrets, permissions, unsafe commands, or destructive actions. It narrows confidence to the tested enterprise configuration and summarized passing result; procurement or deployment decisions still require the trust-portal report’s detailed scope and findings.",
    "corpus_size": 479,
    "generated_at": "2026-08-18T10:04:01.168Z",
    "connections": [
      {
        "title": "What Do Compliance Detectors Read? An Audit of Activation Probes and Guard Models",
        "source_name": "arXiv",
        "source_url": "https://arxiv.org/abs/2608.16852v1",
        "feed7_url": "https://feed7.dev/p/2608-16852v1-0580uyd",
        "reason": "The detector audit warns that compliance controls may follow scenario cues instead of rules; AIUC-1’s adversarial testing is relevant counterevidence, but only detailed findings can show whether comparable counterfactual weaknesses were tested."
      },
      {
        "title": "Teaching AI to Find Real Vulnerabilities — David Brumley, Bugcrowd",
        "source_name": "AI Engineer",
        "source_url": "https://www.youtube.com/watch?v=ZFxh7sqbUZo",
        "feed7_url": "https://feed7.dev/p/teaching-ai-to-find-real-vulnerabilities-david-brumley-bugcrowd-1ok0f7q",
        "reason": "The vulnerability-evaluation guidance favors concrete, externally verified outcomes over self-reported success, aligning with AIUC-1’s independent audit while emphasizing the need to inspect its actual test oracles and scope."
      },
      {
        "title": "Vending-Bench: Long-Horizon Agent Evals — Lukas Petersson, Andon Labs",
        "source_name": "AI Engineer",
        "source_url": "https://www.youtube.com/watch?v=cO8qC6HBuBg",
        "feed7_url": "https://feed7.dev/p/vending-bench-long-horizon-agent-evals-lukas-petersson-andon-labs-0fu78nz",
        "reason": "Vending-Bench argues that agent behavior can drift and differ outside evaluations; AIUC-1’s quarterly testing and annual audit provide a recurring-control response rather than treating one passing result as permanent."
      }
    ]
  },
  "lifecycle": "Current",
  "published_at": "2026-08-13T12:00:00.000Z",
  "modified_at": "2026-08-13T12:00:00.000Z",
  "supersedes": [],
  "expires_at": null,
  "formats": {
    "html": "https://feed7.dev/p/aiuc-1-0s1nr9l",
    "json": "https://feed7.dev/p/aiuc-1-0s1nr9l.json",
    "markdown": "https://feed7.dev/p/aiuc-1-0s1nr9l.md"
  }
}