RPA AI hero img

Govern every AI agent, model, and action on one trusted control plane

UiPath Platform™ Governance extends the identity, audit, and compliance infrastructure your enterprise already trusts across every agent, model, and action. Independently proven by AIUC-1 and ISO/IEC 42001.

Security & Governance

Govern every AI agent, model, and action on one trusted control plane

UiPath Platform™ Governance extends the identity, audit, and compliance infrastructure your enterprise already trusts across every agent, model, and action. Independently proven by AIUC-1 and ISO/IEC 42001.

UiPath Platform™ Governance: the trusted control plane for enterprise AI

One control plane governs every agent, every model, and every action across the platform.

1 in 5
companies currently have a mature governance model for autonomous AI agents, yet 74% plan to deploy agentic AIDeloitte, 2026
+40%
of agentic AI projects will be cancelled by 2027 due to inadequate risk controlsGartner, 2025
25%
of enterprise GenAI applications will experience at least 5 security incidents per year by 2028, a 300% increaseGartner, 2025

AI Trust: independently proven, not promised

What AI Trust means in practice.

Your data is safe

Your data never trains a model and never leaves approved boundaries. In-flight PII masking redacts personal identifiers before any prompt reaches an external model. Zero third-party retention across approved providers.

Every AI interaction governed

Every agent action, model invocation, prompt, response, and approver is logged in a tamper-evident audit trail. The same evidence regulators ask for and internal audit needs to sign off.

AI Agents you can trust

Schellman ran 2,000+ adversarial scenarios across UiPath IXP, Agents, and Autopilot under AIUC-1. Re-tested every quarter. Behavioral proof vs. evolving risks.

What independent certification of AI Agents looks like

The AIUC-1 standard, the adversarial scenarios behind it, and what they mean for an enterprise deploying agents.

Inside AIUC-1: real adversarial scenarios, quarterly re-tested.

AIUC-1

Inside AIUC-1: real adversarial scenarios, quarterly re-tested.

UiPath is the first enterprise automation platform certified to AIUC-1, audited by Schellman across 2,000+ adversarial scenarios. AIUC-1 maps to EU AI Act, NIST AI RMF, MITRE ATLAS, ISO/IEC 42001, OWASP LLM Top 10, and CSA AI Controls, re-tested every quarter.

Rajiv Dattani
UiPath is the first enterprise automation company to achieve AIUC-1 certification. To achieve this, they subjected their suite of agentic AI systems to 2,000+ technical evaluations, and a comprehensive audit of their AI policies and technical guardrails.

Rajiv Dattani

Co-founder, Artificial Intelligence Underwriting Company

Inside the AI Trust Layer

AI Trust Layer: model governance

AI Trust Layer: model governance

Manage the LLM lifecycle across the platform: validation, geo-residency, version control, and deprecation. Behavioral baselines validate every model before promotion, and affected workflows surface automatically when a model is deprecated.

AI Trust Layer: audit and PII

AI Trust Layer: audit and PII

Tamper-evident audit logs record every agent action with full TraceID across platform objects. In-flight PII masking redacts personal identifiers before prompts reach external models, on every interaction.

AI Trust Layer: model governance

AI Trust Layer: model governance

Manage the LLM lifecycle across the platform: validation, geo-residency, version control, and deprecation. Behavioral baselines validate every model before promotion, and affected workflows surface automatically when a model is deprecated.

AI Trust Layer: audit and PII

AI Trust Layer: audit and PII

Tamper-evident audit logs record every agent action with full TraceID across platform objects. In-flight PII masking redacts personal identifiers before prompts reach external models, on every interaction.

AI Trust Layer: BYOM

AI Trust Layer: BYOM

Bring your own model under one policy plane. OpenAI, Anthropic, Google, AWS Bedrock, Azure OpenAI, or customer-hosted. Vendor-agnostic governance for hybrid model strategies.

Observability and OpenTelemetry

Observability and OpenTelemetry

Define and remix governance dashboards using coding agents. Export to SIEM, Microsoft Agent365, and BI tools via OpenTelemetry. Governance data flows into the stacks you already operate.

AI Trust Layer: BYOM

AI Trust Layer: BYOM

Bring your own model under one policy plane. OpenAI, Anthropic, Google, AWS Bedrock, Azure OpenAI, or customer-hosted. Vendor-agnostic governance for hybrid model strategies.

Observability and OpenTelemetry

Observability and OpenTelemetry

Define and remix governance dashboards using coding agents. Export to SIEM, Microsoft Agent365, and BI tools via OpenTelemetry. Governance data flows into the stacks you already operate.

Silhouette of a businesswoman using a laptop by floor-to-ceiling windows overlooking a sunlit city skyline, representing executive productivity and analytics powered by UiPath agentic automation and AI agents.

UiPath Platform™ governance: the control plane governing every agent, model, and action

One policy framework, enforced at runtime, across the platform.

One policy framework, every agent, any platform

Author policies in code or low-code, version them in Git, and enforce them at runtime across access, guardrails, cost, geo, content, lifecycle, and audit. The same framework applies to every agent on every platform.

Security built in, not bolted on

Trust, velocity, and scale built into the platform that runs your agents and robots. No separate enforcement layer to procure, no overlay to integrate.

Independently certified, continuously re-tested

ISO/IEC 42001, AIUC-1, SOC 2 Type II, FedRAMP Moderate, and more. Certified by outside auditors and re-tested every quarter.

Inside UiPath Platform™ governance

Policy-as-code and the control plane

Policy-as-code and the control plane

Policies authored in VS Code or low-code, versioned in Git, enforced at runtime across access, guardrails, cost, geo, content and safety, lifecycle, and audit. One policy framework, every agent, any platform.

Centralized guardrails

Centralized guardrails

Jailbreak protection, prompt injection defense, tool restrictions, allow/deny lists, and PII masking enforced from a single policy surface. The same controls apply on every model invocation, every agent action.

Audit and observability

Audit and observability

Tamper-evident logs capture every agent action, prompt, response, tool call, model version, and human approver. Export audit and traces to your preferred SIEM, observability, and your GRC platforms.

Policy-as-code and the control plane

Policy-as-code and the control plane

Policies authored in VS Code or low-code, versioned in Git, enforced at runtime across access, guardrails, cost, geo, content and safety, lifecycle, and audit. One policy framework, every agent, any platform.

Centralized guardrails

Centralized guardrails

Jailbreak protection, prompt injection defense, tool restrictions, allow/deny lists, and PII masking enforced from a single policy surface. The same controls apply on every model invocation, every agent action.

Audit and observability

Audit and observability

Tamper-evident logs capture every agent action, prompt, response, tool call, model version, and human approver. Export audit and traces to your preferred SIEM, observability, and your GRC platforms.

Security and Governance - CERTIFICATIONS

Security certifications

ISO/IEC 42001, AIUC-1, SOC 2 Type II, ISO/IEC 27001, FedRAMP Moderate (Automation Cloud for Public Sector), HIPAA, IRAP, HITRUST, ISO 9001, Cyber Essentials Plus.

SECURITY INFRASTRUCTURE The foundation

The foundation

Run automation at enterprise scale without exposing your network. Relay bridges Automation Cloud to on-premises systems without inbound firewall rules. Azure Private Link keeps cloud traffic inside your Virtual Network. AES-256 encryption and customer-managed keys via Azure Key Vault ensure your data stays yours, in transit and at rest.

Security and Governance - CERTIFICATIONS

Security certifications

ISO/IEC 42001, AIUC-1, SOC 2 Type II, ISO/IEC 27001, FedRAMP Moderate (Automation Cloud for Public Sector), HIPAA, IRAP, HITRUST, ISO 9001, Cyber Essentials Plus.

SECURITY INFRASTRUCTURE The foundation

The foundation

Run automation at enterprise scale without exposing your network. Relay bridges Automation Cloud to on-premises systems without inbound firewall rules. Azure Private Link keeps cloud traffic inside your Virtual Network. AES-256 encryption and customer-managed keys via Azure Key Vault ensure your data stays yours, in transit and at rest.

One governance platform, four roles, the same source of truth

The same control plane looks different through each role, but every action is logged, every policy is enforced, and every decision is traceable.

ROLE

Org Admin

Set the standard, see the whole estate

Configure identity, RBAC, and tenant boundaries across the platform. Provision agents, robots, and people under one policy framework with SAML 2.0, OIDC, and SCIM. See every action across every agent in every tenant.

Org Admin

ROLE

AI Admin

Govern models, guardrails, and the AI Trust Layer

Approve models, set behavioral baselines before promotion, and enforce guardrails on every prompt and response. Manage the AI Trust Layer for UiPath and bring-your-own models alike, with deprecation workflows that flag affected automations.

AI Admin

ROLE

Developer

Build inside the guardrails, ship faster

Author Policy-as-Code in VS Code, version it in Git, and run against the same enforcement engine production uses. Build agents that inherit the right credentials, the right tools, and the right boundaries by default.

Developer

ROLE

Auditor

Regulator-ready evidence on demand

Pull the full record of every agent action, prompt, response, and human approval with cryptographic integrity. Map the platform to EU AI Act, NIST AI RMF, ISO/IEC 42001, and SOC 2 controls without rebuilding the trail.

Auditor

Go deeper on UiPath governance and security

Aerial view of a winding road curving through a dense green and autumn toned pine forest, symbolizing the guided journey and optimized routes that UiPath agentic automation and AI agents create for businesses.

SOLUTION ACCELERATOR

SOAR Solution Accelerator

File threat detection and response, ready to deploy from UiPath Marketplace.

Get the accelerator
A thoughtful businessman in an orange blazer rests his chin on his hand while working on a laptop in an open office, representing focused knowledge work supported by UiPath agentic automation and AI agents.

TRUST CENTER

trust.uipath.com

Every certification and security report in one place: ISO, SOC, FedRAMP, HIPAA, AIUC-1, and more.

Explore the Trust Center
Confident engineer in an orange sweater standing with arms crossed in front of glowing electrical schematic control screens, illustrating energy and utilities operations monitoring that UiPath agentic automation and AI agents strengthen.

SECURE AI

A CISO’s guide

UiPath CISO Scott Roberts on governing and securing AI agents.

Read the guide
Automation Cloud

Get it all SaaS

With Automation Cloud™, you get the full UiPath Platform™, the fastest updates—and the scalability and flexibility to automate any process, anywhere you do business.

Start here
Get the full platform

Need to self-host?

Run the platform yourself, with the world-class automation capabilities you expect and the performance, compliance, and security you require.

Start here

Common questions on AI agent governance

How AI agents are governed, audited, and certified on the UiPath Platform.

  • The AI Trust Layer governs any model. OpenAI, Anthropic, Google, Meta, AWS Bedrock, Azure OpenAI, or your own. Policy-as-Code enforcement, PII masking, and audit apply the same way, no matter who built the model.

  • AIUC-1 is an adversarial, behavioral standard. Schellman ran 2,000+ scenarios across prompt injection, data exfiltration, hallucination triggers, and tool misuse against UiPath IXP, Agents, and Autopilot. Re-tested every quarter. ISO/IEC 42001 validates governance; AIUC-1 validates behavior.

  • Tamper-evident, append-only logs capture every agent action, prompt, response, tool call, model version, and human approver. Cryptographic integrity via AWS CloudTrail or Azure Immutable Blob. Exportable to SIEM (Splunk, Microsoft Sentinel, Chronicle) and GRC platforms via OpenTelemetry.

  • ISO/IEC 42001, AIUC-1, ISO/IEC 27001, SOC 2 Type II, HIPAA, FedRAMP Moderate, IRAP, HITRUST, ISO 9001, Cyber Essentials Plus. AIUC-1 operationalizes the EU AI Act, NIST AI RMF, MITRE ATLAS, and OWASP LLM Top 10.

  • Bring-your-own-model is governed by the same AI Trust Layer that governs UiPath agents. Approved models, behavioral baselines, PII masking, and audit apply on every invocation. Unapproved model calls are blocked at the control plane.

  • Yes. UiPath Automation Cloud for Public Sector holds FedRAMP Moderate. Automation Suite supports air-gapped and on-premises deployments for sovereign and intelligence environments. Regional data residency is available across Automation Cloud regions.

Close Icon

Move AI agent governance into production

Ask AI about...Ask AI...