SOC 2 with AI-Specific Controls
SOC 2 examinations extend to AI by evaluating AI-specific risks — model governance, data handling, and monitoring — under the existing trust services criteria. There is no separate AI audit: AICPA guidance folds AI considerations into the standard SOC 2 examination, which enterprise buyers increasingly expect from AI vendors during due diligence.
Updated 2026-09-06 · 162 tracked updates
SOC 2 + AI extends the traditional SOC 2 trust services criteria to address AI-specific risks. It covers security, availability, processing integrity, confidentiality, and privacy as they apply to AI systems, including model governance, bias monitoring, and AI transparency.
Who Needs to Comply?
SaaS companies, AI vendors, and technology service providers that need to demonstrate trust and compliance to enterprise customers. Essential for B2B AI companies undergoing customer due diligence.
Key Dates & Timeline
AICPA's guidance on AI considerations in SOC examinations published 2024. SOC 2 with AI-specific controls gaining traction through 2024-2025. AICPA AI-related point of focus updates ongoing.
Upcoming Milestones
Article 5 prohibitions on realistic intimate synthetic content and CSAM-related AI practices apply
Digital Omnibus on AI amends the EU AI ActProviders of AI systems generating synthetic audio, image, video or text must comply with Article 50(2) marking steps if placed on market before 2 Aug 2026
Digital Omnibus on AI amends the EU AI ActCommission deadline to publish AI Act guidance on complementarity and proportionality for Annex I-sector AI systems
Digital Omnibus on AI amends the EU AI ActGeneral application date for Chapter III Sections 1-3 high-risk AI rules under the amended timetable
Digital Omnibus on AI amends the EU AI ActHigh-risk AI embedded in regulated products has extended transition period end
AI Act and European AI Office implementation and enforcementLatest SOC 2 + AI Updates
FCA confirms no new AI-specific rules for financial services
The FCA says it is not planning AI-specific regulation and will rely on existing frameworks such as Consumer Duty and SM&CR, so firms should focus on fitting AI governance into current control regimes rather than waiting for a new rulebook.
SEC announces internal AI task force
The SEC announced an internal AI task force on 1 August 2025 to coordinate responsible AI adoption across the agency; the announcement does not introduce a new external compliance obligation.
FTC AI enforcement actions on deceptive claims and substantiation
These records cover separate FTC proceedings concerning AI claims, an AI companion chatbot inquiry, and the later setting aside of the Rytr order; they do not establish a common new compliance deadline.
AICPA SOC 2 resources reaffirm current Trust Services Criteria for AI-enabled services
AICPA’s SOC resources confirm the current Trust Services Criteria baseline and do not create AI-specific rules, but they reinforce that AI-enabled services must still satisfy existing security, privacy, and processing integrity controls in audits.
FTC AI enforcement posture remains active across deceptive claims and AI investments
The FTC’s AI hub and related matters, including Rytr, Workado, and DoNotPay, show that the agency continues to police deceptive AI claims and conduct, so AI product and marketing teams should assume ongoing enforcement scrutiny now.
ISO AI management-system and adjacent AI standards pipeline expands
ISO’s AI standards pages and draft items show an active pipeline around AI management systems, audit/certification, societal concerns, and privacy protection, so organizations pursuing ISO-based assurance should update their standards watchlist now.
NIST signals revision of AI RMF and new critical-infrastructure profile work
NIST’s AI RMF materials state that the framework is being revised and that a new critical-infrastructure trustworthy-AI profile was launched on 2026-04-07, so organizations relying on the RMF should track the revision now for shifting implementation guidance.
FTC finalizes orders against Cox Media Group and two other firms over deceptive AI-powered marketing claims
On 2026-08-27, the FTC finalized orders and $930,000 in settlements after alleging the firms falsely claimed an AI-powered “active listening” ad service and deceptive customer consent, creating immediate enforcement risk for any AI marketing claims that are not fully substantiated.
DoNotPay final order on deceptive AI lawyer claims
The FTC finalized its DoNotPay order in February 2025, prohibiting deceptive AI lawyer claims and requiring monetary relief and notice, which raises the bar for substantiation of legal-assistance AI products.
MindSift LLC matter
The FTC matter against MindSift alleges deceptive AI-powered active-listening and opt-in claims, underscoring immediate enforcement risk where AI functionality or data-collection claims are overstated.
Jurisdiction Coverage
Related Frameworks
Key Topics
Frequently Asked Questions
How does SOC 2 apply to AI systems?
SOC 2 examinations extend to AI by evaluating AI-specific risks — model governance, data handling, and monitoring — under the existing trust services criteria. There is no separate AI audit: AICPA guidance folds AI considerations into the standard SOC 2 examination, which enterprise buyers increasingly expect from AI vendors during due diligence.
What is SOC 2 + AI?
SOC 2 + AI refers to SOC 2 examinations that include additional criteria and controls specific to AI systems. It extends the five trust services criteria (security, availability, processing integrity, confidentiality, privacy) to cover AI-specific risks like model governance, bias, and transparency.
Do I need a separate SOC 2 audit for AI?
No. AI-specific controls are incorporated into your existing SOC 2 examination. Your auditor evaluates AI risks as part of the standard trust services criteria assessment, with additional focus areas for AI governance, model management, and ethical AI practices.
How does SOC 2 + AI relate to ISO 42001?
SOC 2 + AI focuses on third-party attestation of controls for service organizations, while ISO 42001 is a management system certification. SOC 2 + AI is typically customer-driven (enterprise buyers require it), while ISO 42001 is more proactive governance. Many organizations pursue both.
Keep exploring
This hub tracks published activity relevant to SOC 2 and AI; examination scoping is set by your auditor, and this page is not attestation advice.