BlueprintBlueprint

Making sense of AI Agent certifications and compliance

Buying an AI Agent means sorting through a long list of certifications. Here's how to tell which ones actually matter.

Thibault Candebat
CredentialWhat it coversHow much is AI-specificWhat it applies to
SOC 2Independent attestation covering security, availability, and confidentiality controlsNone – the same baseline review any vendor goes through, AI or notA defined system/service, not the whole company by default
ISO 27001A documented, audited system of security policies and controlsNone – the same underlying security program regardless of AIThe organization’s security program
ISO 27701Previously an extension of ISO 27001, now a standalone system for managing personal dataMostly unchanged – plus a new requirement to assess the privacy risks that AI processing poses to the people whose personal data is involvedThe organization’s privacy program
ISO 27018Protection of personally identifiable information (PII) handled by a cloud provider on your behalfNone – standard cloud-data protection still appliesThe organization, but only in its role as the data processor for your company
ISO 42001Governance and lifecycle management of AI systems across how an organization develops, provides, and uses AIEntirely – it only exists because AI systems needed a governance standard of their ownThe organization’s AI program
AIUC-1Tested resistance to jailbreak and prompt injection, with mandatory quarterly adversarial testingEntirely – there’s no non-AI version of this certification to compare it toA specific AI product or Agent configuration
Fin's Procedures

Related articles

Stay up to date with us on LinkedIn

Follow Fin for the latest research, guides, and product updates on AI customer service.

Follow us on LinkedIn