---
title: "When AI Agents Show Up At Your Next Audit"
description: "In February, I wrote about how AI agents could fit into SOC 2 Type II audits and concluded that the Trust Services Criteria could stretch to cover them. The framework is technology-neutral on purpose, and nothing in CC6 or CC8"
url: https://kaynemcgladrey.com/blog/when-ai-agents-show-up-at-your-next-audit/
date: 2026-10-09
modified: 2026-10-09
author: "Kayne"
image: https://kaynemcgladrey.com/wp-content/uploads/2026/10/agentsmith-2.webp
categories: ["Blog"]
type: post
lang: en-US
---

# When AI Agents Show Up At Your Next Audit

In February, I wrote about how AI agents could fit into SOC 2 Type II audits and concluded that the Trust Services Criteria could stretch to cover them. The framework is technology-neutral on purpose, and nothing in CC6 or CC8 says “human.” Seven months later, I’m revising my thinking because the criteria haven’t changed.

The trigger was a [CIO.com story](https://www.cio.com/article/4230240/your-employees-are-building-ai-agents-do-you-know-what-theyre-doing.html) about a [Howdy.com survey](https://www.howdy.com/blog/ai-agent-statistics) of 1,002 full-time US employees who use AI at work. Two-thirds have moved past chatbots and now run agents. 16% are building their own from scratch. If you’re planning a Q1 2027 Type II audit, your observation window has already started, and some of those agents may have been operating inside it. What follows is what to check and what to fix.

## The window is already open

Type II reports test controls over a period, typically six to twelve months. Your auditor isn’t assessing what your environment looks like on report day. They’re sampling evidence from the window, which for a Q1 2027 audit started sometime in 2026. Any agent that touched production during that window is already in scope, whether you catalogued it or not.

### Why mid-window rewrites backfire

If your change management policy says “human approval before merge” and an agent has been merging pull requests since July, quietly amending the policy now is the worst move available. Auditors test the control as written against the evidence in the window.

Some organizations have rewritten their policies to remove the human-review requirement before deploying AI approvers, which is permissible and even rational if the rewrite happened before the observation window opens rather than during it.

## Four assumptions that broke quietly

The Common Criteria were built on assumptions nobody wrote down because, over fifteen years since the American Institute of Certified Public Accountants (AICPA) introduced SOC 2 Type II in 2010, they held without effort. Agents break them the moment they act.

| Assumption | Criterion affected | What actually happens |
| --- | --- | --- |
| Every account has a named owner | CC6.1 access review | Ownership gets reconstructed after the fact from keys and repos. A guessed owner looks identical to a recorded one in the review spreadsheet. |
| The name in the log is the actor | CC6.1 logging | The agent borrowed a developer’s session or token, so fifty production queries land on someone who never touched a keyboard. |
| Permissions tell you purpose | CC6.1 least privilege | Access limits the blast radius, but says nothing about what the agent intends to do in any given moment. Intent lives in the prompt, not the identity and access management (IAM) policy. |
| Someone approves an account before it exists | CC6.2 registration | An agent spawns from an OAuth click, a pasted API key, or a JSON config. Nobody approved a thing. |

I mapped agent risks to the criteria [back in February](https://goteleport.com/blog/ai-agents-soc-2/) and argued the real challenge was evidentiary frequency, proving controls operate at machine speed. That’s still true for organizations that know their agents exist.

## Shadow agents are the default

Employees are building agents without waiting for permission because the barrier to entry keeps dropping. Frank Licea, Howdy’s founder, described the discovery order inside his own company. People came to the engineering team beaming about automations they’d shipped, and only then did someone from tech start asking questions.

> “What are the API keys here? Are you accessing encrypted data? What are the SOC 2 implications?”

[Andy Sen, CTO at AppDirect](https://www.cio.com/article/4230240/your-employees-are-building-ai-agents-do-you-know-what-theyre-doing.html), said, “Shadow IT has always existed, and shadow agents are just the latest version of it.” His company’s answer was a sanctioned sandbox with visibility into usage and costs rather than lockdown. If your instinct is to ban your way out, bans don’t last long when an engineer automates away hours of weekly busywork.

The Howdy.com survey found only 28% of workers say their workplace is extremely clear on who owns AI-generated outcomes. That ownership gap compounds the other problems.

### What the churn leaves behind

Howdy.com’s survey found that 71% of workers say fewer than half their department’s agents reach long-term production, and 25% have deactivated an agent entirely. Deactivation leaves behind abandoned OAuth grants with no expiry, API keys nobody remembers provisioning, service accounts tied to departed employees, and automation workflows with no surviving owner.

The churn manufactures orphaned access faster than most quarterly access reviews can catch. For 7% of surveyed workers, the deactivation happened because the agent went rogue, which in most cases means it did exactly what it was told and what it was told was wrong.

### The questions a SOC 2Type II report can’t answer

Because of the broken assumptions above, you can hold an unqualified Type II report and be unable to answer four basic questions about your own production environment on the day the report is issued.

- **Was it ever registered?** The registration control shows nothing missing, because the agent was never registered.
- **Who authorized it?** No better. The decision happened in a prompt, upstream of anything the evidence captures.
- **Whose credentials is it carrying?** A real employee’s, with a role that passed access review. The control checked the human, not the software acting as the human.
- **Who could switch it off?** Offboarding ran correctly and was never designed to flag agents in the first place.

There’s no HR system for agents, and most are tied to humans through OAuth grants or API keys. When a person leaves, whatever they built keeps running on their credentials unless you’ve planned for that specifically.

## Five things to do before Q1 2027

1. **Inventory every agent, now.** Spend the first month on discovery and nothing else. Search your identity provider (IdP), cloud IAM, and secrets managers for tokens tied to agent workloads. You cannot scope an audit around identities you don’t know exist, and you cannot secure them either.
2. **Kill the borrowed-credential pattern.** An agent running on a developer’s personal OAuth token is both your biggest audit exposure and your easiest fix. Migrate anything that survives the inventory to its own bot identity with scoped, ideally short-lived, credentials. This single change restores the attribution the CC6 controls depend on.
3. **Don’t rewrite policy mid-window.** You have two paths forward if agents have been operating against your written controls. Disclose it and take the observation, or negotiate amended language and compensating controls with your auditor for next period. Papering over the mismatch isn’t one of them.
4. **Define what “in scope” means.** Organizations should explicitly define which AI systems their SOC 2 covers, because that definition determines what evidence you retain. Companies that get ahead of this shape how their auditor interprets the criteria. Those that wait will answer hard questions with no evidence trail.
5. **Pressure-test the customer reaction.** A system description reading “AI agents build, test, and deploy code without human review” might be acceptable to your auditor and alarming to your customers. SOC 2 is a procurement signal before it’s anything else, and your buyers are more likely to read this than anyone else.

The pattern that passes audits is unglamorous. The agent runs under its own identity, holds permissions so narrow it physically can’t merge to protected paths, faces hard CI gates, and its merges get documented human review within a service level agreement (SLA), with proof the review happens.

## What auditors and courts might do

One caveat: the AICPA hasn’t issued agent-specific criteria or interpretations, and I don’t expect them soon.

### What your auditor will do

Test the controls you wrote, the way they’ve always tested them. The system description and the negotiated scope carry more weight than any think piece about frameworks becoming obsolete.

### What a court might do

Something less forgiving, but only if you get there. A SOC 2 Type II report enters the courtroom when a plaintiff’s attorney introduces it, which happens after an incident during litigation over the outcome. The report you’ll be questioned about was issued before the failure and describes a period that’s already closed. It can’t be improved once discovery starts.

Lawyers working through what happens when an agent approves a fraudulent payment or makes a discriminatory hiring recommendation have been coming to the same conclusions so far. Negligence and product liability doctrine were built around human decision-makers, and the business that deployed the agent holds the bag even when the decisions trace back through a model, a prompt, and a vendor. At that point, the gap between what your system description said and what was actually running isn’t an audit nuance. It’s something opposing counsel reads aloud, though if that goes to a juried trial, you’re probably in for a bad time.

Bhavna Bhatnagar, CTO at VigourSoft, framed it for Howdy’s CTO interview series. An agent needs “a scoped identity tied to an accountable human owner, because when something goes wrong an organization will not take the liability on its own.” You can delegate the work. Delegation doesn’t transfer liability.

## Start before the next window opens

Back in February, I believed the criteria would stretch to cover agents, and they still can. Now there’s survey data showing two-thirds of AI-using employees are already there and only 28% work somewhere with clear answerability for agent output. The revision comes down to discovery timelines.

If you’re heading into a Q1 2027 audit, the sequence is inventory first, then credential migration. Have the talk with your auditor before sampling begins. If your audit is later in the year, you have the luxury of amending policy language before your next window opens. Either way, the cheap day to learn what your agents are doing was yesterday. Today is second cheapest.

Want a second opinion about your upcoming SOC 2 type II audit? [Let’s chat.](https://calendar.proton.me/bookings#qL4TjjAGdaFuaqJv5pNriytK2-rH9U3DhUMQlEIr4ko=)
