cd /news/ai-agents/soc-2-cc6-and-iso-27001-still-assume… · home › topics › ai-agents › article
[ARTICLE · art-143090] src=dev.to ↗ pub= topic=ai-agents verified=true sentiment=· neutral

SOC 2 CC6 and ISO 27001 still assume humans — agents break the evidence model

Permit.io published a practical checklist mapping SOC 2 CC6/CC7 and ISO 27001 Annex A access controls to AI agents, arguing that existing compliance evidence models assume human users with provisioned accounts and attributable sessions. The company notes that OAuth answers whether a client can use a token but not whether a specific agent should call a given tool on a given resource for a given user at that moment.

read1 min views1 publishedOct 1, 2026

SOC 2 CC6 / CC7 and ISO 27001 Annex A access controls were designed around human users: provisioned accounts, predictable sessions, and admin actions you can attribute to a person.

AI agents break those operating assumptions. A token can be valid at consent time, then an agent chains tools and produces side effects the quarterly user-access review never sees. OAuth still answers "can this client use this token?" — it does not fully answer "should this agent, for this user, call this tool on this resource right now?"

Useful evidence for agentic systems usually needs:

We published a practical CC6 / ISO 27001 checklist for AI agents (I'm with Permit.io):

── more in #ai-agents 4 stories · sorted by recency
── more on @permit.io 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
→ Live at https://your-agent.zahid.host ✓
Get free account → Pricing
from €0/mo · no card required
LIVE [news/soc-2-cc6-and-iso-27…] indexed:0 read:1min 2026-10-01 · —