Company

The First Certified AI Agents in Legal: :Harvey: Achieves AIUC-1

Harvey has been independently evaluated and certified against AIUC-1, the standard for AI agent security, safety, and reliability — making Harvey the first legal AI company to achieve this certification.

by Harvey TeamJul 30, 2026

As legal teams adopt AI into their most consequential work, they're asking hard questions: How was this system tested? Who validated it? What happens when it fails? Self-attestation isn't enough anymore, and it shouldn't be.

Today, we're proud to announce that Harvey’s agentic platform has achieved AIUC-1 certification, making Harvey the first legal and professional services company to meet the industry's standard for AI agent security, safety, and reliability. The certification was conducted by Schellman, the first accredited AIUC-1 certification body. It’s one more reason law firms and in-house legal teams trust Harvey with their most sensitive work.

"Security and trust aren't a single milestone, they're a continuous commitment," said Joshua McKibben, Harvey's Head of Trust. "AIUC-1 gives our customers an independent, technical answer to the question every enterprise security team is asking about AI agents today: can we trust this system to act responsibly under pressure? For Harvey, the answer is now backed by an independent third party, not just by us.”

“Legal work leaves no room for error, so it’s fitting that legal AI is where the bar gets set,” said Rajiv Dattani, co-founder of AIUC. “Harvey is the first legal AI company to be certified against AIUC-1, and they earned it the hard way - independent, adversarial technical testing of the actual product, not a paper review.”

What AIUC-1 Certifies

AIUC-1 was built with input from 200+ Fortune 500 CISOs and security leaders across Microsoft, Google Cloud, Meta, Visa, Fidelity, and more, and it's refreshed quarterly to keep pace with how quickly AI risk evolves. It's the framework the industry has been missing: as Phil Venables, former CISO of Google Cloud, put it, "We need a SOC 2 for AI agents — a familiar, actionable standard for security and trust."

The standard evaluates AI systems across six domains: Data & Privacy, Security, Safety, Reliability, Accountability, and Society, and it's aligned to the frameworks enterprise security teams already rely on, including ISO 42001, the EU AI Act, NIST AI RMF, OWASP, and MITRE ATLAS. Certification requires independent, adversarial technical testing of our model and agentic platform, not just policy documents and paper reviews. AIUC-1's taxonomy spans 86 risk categories and 73 attack categories, covering hallucination, tool misuse, data leakage, and adversarial manipulation. Harvey was independently evaluated against this taxonomy through more than 3,000 unique tests, and passed with zero critical failures. Certification is not a one-time badge: technical testing is conducted at least quarterly and operational controls are reviewed annually. Full details on the standard and its methodology are available at aiuc-1.com.

Building on a Foundation of Verifiable Trust

AIUC-1 extends Harvey’s track record of independent validation that customers can inspect directly at trust.harvey.ai, including our SOC 2 Type II attestation, ISO 27001, ISO 27701, and ISO 42001 certifications.

We achieved ISO 42001 certification earlier this year, validating the governance systems, oversight processes, and risk management practices behind how we build and deploy AI. That's essential, but governance alone doesn't answer every question an enterprise security team asks. It doesn't independently stress-test whether a model will hallucinate under pressure, leak data across a session, or comply with an adversarial prompt. AIUC-1 closes that gap: where ISO 42001 audits the management system, AIUC-1 puts the product itself through adversarial, technical evaluation.

Together, they give enterprise legal and security teams a fuller picture: governance that's certified, and technical performance that's independently tested for both safety and security.

Setting the Standard for Legal AI

Harvey is the first legal technology company to achieve AIUC-1 certification. In an industry built on precision and trust, we believe AI companies should be held to very high standards.

As AI capabilities, regulations, and customer expectations continue to evolve, so will our approach to earning trust. We'll keep raising the bar, and we'll keep proving it independently.

To learn more about Harvey's security and trust program, visit harvey.ai/security or explore our certifications at trust.harvey.ai.