SOC 2 has long been a baseline for evaluating the security of service providers, but the rise of AI agents is straining its assumptions. According to a BleepingComputer article, these agents can operate through human credentials and take actions that existing SOC 2 controls are not designed to differentiate from ordinary human behavior.
That limitation creates a blind spot: if an AI agent can authenticate as a person, standard access reviews and monitoring may miss anomalous or unauthorized activity. Token Security, which provided the analysis, contends that SOC 2 risks becoming irrelevant unless it explicitly accounts for agent-driven actions rather than assuming every authenticated session belongs to a human.
The suggested direction is to adapt SOC 2 so it recognizes agent identities as distinct actors, with their own permissions and boundaries. That would require new controls around how agents are provisioned, scoped, and monitored. The article offers this as a recommendation rather than a concrete proposal, but it highlights a growing tension between established compliance regimes and the way automated agents are beginning to move through enterprise systems.