SOC 2 with AI-Specific Controls

SOC 2 examinations extend to AI by evaluating AI-specific risks — model governance, data handling, and monitoring — under the existing trust services criteria. There is no separate AI audit: AICPA guidance folds AI considerations into the standard SOC 2 examination, which enterprise buyers increasingly expect from AI vendors during due diligence.

Updated 2026-09-06 · 162 tracked updates

SOC 2 + AI extends the traditional SOC 2 trust services criteria to address AI-specific risks. It covers security, availability, processing integrity, confidentiality, and privacy as they apply to AI systems, including model governance, bias monitoring, and AI transparency.

162
Regulations Tracked
11
Jurisdictions
10
Upcoming Milestones
2026-09-06
Last Updated

Who Needs to Comply?

SaaS companies, AI vendors, and technology service providers that need to demonstrate trust and compliance to enterprise customers. Essential for B2B AI companies undergoing customer due diligence.

Key Dates & Timeline

AICPA's guidance on AI considerations in SOC examinations published 2024. SOC 2 with AI-specific controls gaining traction through 2024-2025. AICPA AI-related point of focus updates ongoing.

Upcoming Milestones

2026-12-02

Article 5 prohibitions on realistic intimate synthetic content and CSAM-related AI practices apply

Digital Omnibus on AI amends the EU AI Act
2026-12-02

Providers of AI systems generating synthetic audio, image, video or text must comply with Article 50(2) marking steps if placed on market before 2 Aug 2026

Digital Omnibus on AI amends the EU AI Act
2027-08-01

Commission deadline to publish AI Act guidance on complementarity and proportionality for Annex I-sector AI systems

Digital Omnibus on AI amends the EU AI Act
2027-08-02

General application date for Chapter III Sections 1-3 high-risk AI rules under the amended timetable

Digital Omnibus on AI amends the EU AI Act
2027-08-02

High-risk AI embedded in regulated products has extended transition period end

AI Act and European AI Office implementation and enforcement

Latest SOC 2 + AI Updates

guidancemedium2026-09-06

FCA confirms no new AI-specific rules for financial services

The FCA says it is not planning AI-specific regulation and will rely on existing frameworks such as Consumer Duty and SM&CR, so firms should focus on fitting AI governance into current control regimes rather than waiting for a new rulebook.

guidancelow2026-09-06

SEC announces internal AI task force

The SEC announced an internal AI task force on 1 August 2025 to coordinate responsible AI adoption across the agency; the announcement does not introduce a new external compliance obligation.

enforcementhigh2026-09-06

FTC AI enforcement actions on deceptive claims and substantiation

These records cover separate FTC proceedings concerning AI claims, an AI companion chatbot inquiry, and the later setting aside of the Rytr order; they do not establish a common new compliance deadline.

guidancemedium2026-09-06

AICPA SOC 2 resources reaffirm current Trust Services Criteria for AI-enabled services

AICPA’s SOC resources confirm the current Trust Services Criteria baseline and do not create AI-specific rules, but they reinforce that AI-enabled services must still satisfy existing security, privacy, and processing integrity controls in audits.

enforcementmedium2026-08-30

FTC AI enforcement posture remains active across deceptive claims and AI investments

The FTC’s AI hub and related matters, including Rytr, Workado, and DoNotPay, show that the agency continues to police deceptive AI claims and conduct, so AI product and marketing teams should assume ongoing enforcement scrutiny now.

guidancemedium2026-08-30

ISO AI management-system and adjacent AI standards pipeline expands

ISO’s AI standards pages and draft items show an active pipeline around AI management systems, audit/certification, societal concerns, and privacy protection, so organizations pursuing ISO-based assurance should update their standards watchlist now.

guidancemedium2026-08-30

NIST signals revision of AI RMF and new critical-infrastructure profile work

NIST’s AI RMF materials state that the framework is being revised and that a new critical-infrastructure trustworthy-AI profile was launched on 2026-04-07, so organizations relying on the RMF should track the revision now for shifting implementation guidance.

enforcementhigh2026-08-30

FTC finalizes orders against Cox Media Group and two other firms over deceptive AI-powered marketing claims

On 2026-08-27, the FTC finalized orders and $930,000 in settlements after alleging the firms falsely claimed an AI-powered “active listening” ad service and deceptive customer consent, creating immediate enforcement risk for any AI marketing claims that are not fully substantiated.

enforcementhigh2026-08-23

DoNotPay final order on deceptive AI lawyer claims

The FTC finalized its DoNotPay order in February 2025, prohibiting deceptive AI lawyer claims and requiring monetary relief and notice, which raises the bar for substantiation of legal-assistance AI products.

enforcementhigh2026-08-23

MindSift LLC matter

The FTC matter against MindSift alleges deceptive AI-powered active-listening and opt-in claims, underscoring immediate enforcement risk where AI functionality or data-collection claims are overstated.

Jurisdiction Coverage

Related Frameworks

Key Topics

Frequently Asked Questions

How does SOC 2 apply to AI systems?

SOC 2 examinations extend to AI by evaluating AI-specific risks — model governance, data handling, and monitoring — under the existing trust services criteria. There is no separate AI audit: AICPA guidance folds AI considerations into the standard SOC 2 examination, which enterprise buyers increasingly expect from AI vendors during due diligence.

What is SOC 2 + AI?

SOC 2 + AI refers to SOC 2 examinations that include additional criteria and controls specific to AI systems. It extends the five trust services criteria (security, availability, processing integrity, confidentiality, privacy) to cover AI-specific risks like model governance, bias, and transparency.

Do I need a separate SOC 2 audit for AI?

No. AI-specific controls are incorporated into your existing SOC 2 examination. Your auditor evaluates AI risks as part of the standard trust services criteria assessment, with additional focus areas for AI governance, model management, and ethical AI practices.

How does SOC 2 + AI relate to ISO 42001?

SOC 2 + AI focuses on third-party attestation of controls for service organizations, while ISO 42001 is a management system certification. SOC 2 + AI is typically customer-driven (enterprise buyers require it), while ISO 42001 is more proactive governance. Many organizations pursue both.

Keep exploring

This hub tracks published activity relevant to SOC 2 and AI; examination scoping is set by your auditor, and this page is not attestation advice.