SOC 2 CC6 and ISO 27001 still assume humans — agents break the evidence model
SOC 2 CC6 / CC7 and ISO 27001 Annex A access controls were designed around human users: provisioned accounts, predictable sessions, and admin actions you can attribute to a person. AI agents break those operating assumptions. A token can be valid at consent time, then an agent chains tools and produces side effects the quarterly user-access review never sees. OAuth still answers "can this client…
We haven't written up this one. Dev.to has the full story — the link below goes straight to it.