SOC 2 auditing framework faces calls for update to address AI agent identities
An industry commentary argues that SOC 2, the widely used compliance standard for data-handling trust, was built around assumptions that no longer hold as AI agents operate within company systems. The piece contends that agents can act under human credentials—such as an engineer's login—allowing risky activity to pass audits undetected because SOC 2 does not explicitly classify AI agents as a distinct identity type.