Back to Blog
AI Compliance

SOC 2 Type II for LLM Deployments

How to close the evidence gap when your auditor asks about AI agent controls

SOC 2 was designed for deterministic software. LLM-powered agents create evidence gaps across five Trust Services Criteria that traditional controls don't address.

July 3, 202612 min read
SOC 2LLM ComplianceAudit EvidenceTrust AuditEnterprise AI
AgentTrust OS

SOC 2 Type II for LLM Deployments

How to close the evidence gap when your auditor asks how you control an AI agent's behavior

TL;DR
  • SOC 2 was designed for deterministic software. LLMs and agentic systems create evidence gaps that traditional controls don't address.
  • The five Trust Services Criteria most affected: CC6.1 (logical access), CC7.2 (monitoring), CC8.1 (change management), A1.2 (capacity), and PI1 (processing integrity).
  • The core auditor challenge: "How do you know the AI agent only accessed data it was authorized to access?"
  • AgentTrust OS produces continuous control evidence across the full audit period — not just point-in-time certifications.
  • Enterprise plans include pre-formatted SOC 2 audit pack exports your auditor can review directly.
Read the full breakdown →

SOC 2 Type II audits evaluate whether your controls operated effectively over a defined audit period — typically 6 or 12 months. For traditional software, this means sampling access logs, change records, and monitoring alerts across the period and verifying that controls were consistent and functioning.

LLM-powered applications break this model. An AI agent's behavior is not deterministic — it depends on inputs, context, and model state that vary at runtime. The tools it can invoke aren't a static access control list. Its "change events" include model updates that don't go through a traditional change management process. And "processing integrity" for a system that can hallucinate has no direct precedent in standard Trust Services Criteria.

This post covers the five Trust Services Criteria most affected by LLM deployments, the specific evidence gaps that auditors are increasingly flagging, and how to produce continuous control evidence that satisfies Type II requirements.

THE FIVE AFFECTED CRITERIA

Where traditional SOC 2 controls break down for AI agents

CC6.1

Logical and physical access controls

Traditional approach: RBAC configuration screenshots, access review records, user provisioning logs.

AI agent gap: The agent's access is not defined by a role in an RBAC system. It's defined by which tools the agent can call, which external systems those tools connect to, and what parameters the agent chooses at runtime. A traditional access review cannot capture this.

What auditors now ask: "How do you know the AI agent only accessed the data it was authorized to access? Can you show me a log of every data access decision it made over the audit period?"

CC7.2

System monitoring

Traditional approach: SIEM alerts, anomaly detection on access logs, performance monitoring dashboards.

AI agent gap: Standard SIEM rules are designed for deterministic access patterns. An AI agent that accesses a normally-accessed database via an unusual query path may not trigger any anomaly alert — because the access itself is authorized, even if the context suggests it shouldn't be.

What auditors now ask: "How do you detect when an agent is behaving outside its intended scope? What controls alert you to unusual agent behavior?"

CC8.1

Change management

Traditional approach: Change tickets, approval records, deployment logs, rollback procedures.

AI agent gap: Model providers update base models on their own schedules. A model update changes agent behavior without a change ticket in your system. An agent that passed behavioral testing on model version N may behave differently on version N+1 — and the change never went through your change management process.

What auditors now ask: "How do you manage changes to the AI model itself? What testing validates agent behavior after a model update?"

PI1

Processing integrity

Traditional approach: Input/output validation, data checksums, error rate monitoring.

AI agent gap: LLMs can produce confidently-stated incorrect outputs — hallucinations — that are structurally valid but factually wrong. Standard data validation catches malformed outputs; it cannot catch plausible-looking errors. Processing integrity for AI requires confidence scoring and behavioral consistency evidence.

What auditors now ask: "How do you ensure the AI agent's outputs are accurate? What evidence do you have that processing integrity controls are working?"

CONTINUOUS CONTROL EVIDENCE

What Type II audit evidence looks like for AI agents

SOC 2 Type II requires evidence that controls operated over the full audit period. For AI agents, this means producing records that are continuous, structured, and attributable — not point-in-time certifications.

CriterionRequired EvidenceAgentTrust OS SourceFrequency
CC6.1Per-session tool access log with permission contract referenceTrust Runtime + Trust AuditContinuous (every action)
CC7.2Behavioral anomaly records: escalated and blocked actionsTrust Runtime + Trust AuditContinuous (every escalation/block)
CC8.1Re-certification record after each model update or policy changeTrust CertifyEvent-triggered (on change)
CC8.1Change record linking deployment event to certification evidenceTrust Certify certification reportPer deployment
PI1Confidence score distribution over audit period; human review ratesTrust Audit analyticsAggregate + per-action
Audit Pack

AgentTrust OS enterprise plans include pre-formatted SOC 2 audit pack exports: a structured JSON + PDF report covering each Trust Services Criterion, with control references mapped to the relevant audit records. Your auditor receives a complete evidence package — not raw log files that require manual analysis.

FREQUENTLY ASKED QUESTIONS

Your questions, answered directly

If your AI agents process data in scope for your SOC 2 (i.e., customer data or systems that affect the security, availability, or integrity of your services), they should be in scope. Auditors are increasingly asking about AI systems in scoping discussions. If your agent is in scope, you'll need to address the relevant TSC criteria. Consult your auditor in advance of your next audit period start.
Third-party providers are complementary user entity controls (CUECs). Your SOC 2 scope includes your controls; the provider's controls are evidenced by their own SOC 2 Type II report. You should obtain and review the relevant provider SOC 2 reports and document the responsibilities split: what controls you rely on them for, and what controls you're responsible for on your side of the boundary. AgentTrust OS controls (access, monitoring, integrity) sit entirely on your side.
Trust Certify generates a certification report for every agent version — pre-deployment. When a model update occurs, the change management control includes a re-certification event: the updated agent is re-tested against the certification suite, and the certification report is attached to the change record. Auditors can trace every deployment event to its corresponding certification evidence.
AgentTrust OS generates evidence automatically for every governed agent — you don't produce records manually. The audit pack export aggregates across all agents for the audit period. The practical question is ensuring every agent that should be governed is registered with the runtime, which is a deployment configuration exercise rather than an ongoing manual task.
SOC 2 AUDIT EVIDENCE, AUTOMATED

Close the AI evidence gap before your auditor asks

Trust Certify, Trust Runtime, and Trust Audit generate continuous SOC 2 evidence across your full audit period. Enterprise plans include pre-formatted audit pack exports.

View Compliance Resources →

More from the blog

AI ComplianceJuly 22, 2026AI ComplianceJuly 22, 2026AI GovernanceJuly 22, 2026AI GovernanceJuly 22, 2026AI ArchitectureJuly 22, 2026AI SecurityJuly 16, 2026MLOpsJuly 10, 2026AI ImplementationJuly 8, 2026AI Agent ArchitectureJuly 5, 2026AI Agent ArchitectureJune 30, 2026EngineeringJune 23, 2026AI Agent ArchitectureJuly 2, 2026AI Agent ArchitectureJuly 1, 2026IntegrationsJuly 1, 2026IntegrationsJuly 1, 2026IntegrationsJuly 2, 2026AI SecurityJuly 3, 2026AI SecurityJuly 1, 2026AI ComplianceJuly 2, 2026AI StrategyJuly 2, 2026AI StrategyJuly 3, 2026AI StrategyJuly 3, 2026AI StrategyJuly 3, 2026AI GovernanceJuly 28, 2026Healthcare AIJuly 28, 2026ArchitectureJuly 29, 2026ArchitectureJuly 29, 2026AI StrategyJuly 29, 2026AI StrategyJuly 30, 2026AI SecurityJuly 30, 2026AI ComplianceJuly 30, 2026EngineeringJuly 30, 2026AI GovernanceAugust 4, 2026EngineeringAugust 4, 2026EngineeringAugust 4, 2026