LIVE ONLINE WEBINAR

SOC 2 for AI-Native Products: What Changes When Agents Help Write the Code

πŸ•‘ June 29, 11:00 AM – 12:00 PM CT
πŸ“ Live Online Session

A practitioner's look at how AI-assisted development impacts traditional SOC 2 controls β€” and what audit-ready actually looks like when copilots are part of your engineering team.

Join the Webinar

ABOUT THE WEBINAR

AI agents are now doing the work of mid-level engineers β€” writing code, reviewing PRs, managing deployments. Headcount is down. Output is up. And the controls your auditor expects to see were never designed for this.

SOC 2 auditors often expect to see humans reviewing code and approving changes. When an agent steps into those roles, compliance with security standards may be at risk. 

In this session presented by UnderDefense and Boulay, a CPA firm with a global SOC 2 reporting practice, the panel will discuss the pitfalls that may occur during your audit when too much reliance is placed on AI in the software development process.

What we'll cover:

  1. The new operating reality – Agents are handling entry and mid-level engineering work. Controls previously performed by humans are quietly disappearing in the name of speed and cost savings.

  2. Why audits got harder – We’ll walk through the five questions AI-native companies struggle with: AI usage policies, code review, change management, access controls, and evidence chain-of-custody.

  3. How copilots bypass traditional controls – Branch protection disabled β€œjust this once.” Code review signed off by the agent that wrote the code. Secrets shared informally because the agent needed access. All these instances carry security risks.

  4. The best path to security compliance – We’ll show how pairing continuous compliance tooling with a security partner that runs DevSecOps the way an auditor expects can compress the timeline and produce compliance results your customers expect.

WHAT YOU'LL WALK AWAY WITH:

β†’ A clear picture of which SOC 2 controls can break down when AI agents are part of your engineering team

β†’ The questions auditors are now asking AI-native companies

β†’ A practical framework for closing control gaps before the auditor finds them

β†’ An understanding of what audit-ready actually looks like in an AI-assisted development environment

WHO SHOULD ATTEND:

CISOs, CTOs, CFOs, VPs of Engineering, and compliance leaders at technology companies β€” especially those navigating a first SOC 2 audit, preparing for a Type 2 renewal, or managing engineering teams where AI coding tools are already in use. 

SPEAKERS

Nazar Tymoshyk

Ph.D. Researcher, SANS and RSA Conference Speaker, CEO at UnderDefense.

Jeffrey Filler

Partner, Boulay

Landon Adolphson-Fulsom

Senior Manager, Boulay

Register for the webinar

Join the webinar to understand what SOC 2 auditors are now looking for in AI-native environments, where control gaps typically form when copilots are part of the engineering team, and what a realistic path to certification looks like.