SOC 2 CC6 / CC7 and ISO 27001 Annex A access controls were designed around human users: provisioned accounts, predictable sessions, and admin actions you can attribute to a person.
AI agents break those operating assumptions. A token can be valid at consent time, then an agent chains tools and produces side effects the quarterly user-access review never sees. OAuth still answers "can this client use this token?" — it does not fully answer "should this agent, for this user, call this tool on this resource right now?"
Useful evidence for agentic systems usually needs:
We published a practical CC6 / ISO 27001 checklist for AI agents (I'm with Permit.io):