The topics below examine how SEC staff are approaching AI oversight, when an AI application may become relevant to Internal Control over Financial Reporting, how non-human identities affect access governance, and how the audit profession is beginning to operationalize AI.
This Week's Key Topics
SEC Staff Signal Reminders Rather Than Prescriptive AI Rules
The SEC's Office of the Chief Accountant has indicated that near-term communication concerning AI in financial reporting is more likely to take the form of practical reminders and questions than detailed, technology-specific rules.
The areas receiving attention include management's reliance on third-party AI providers, the quality and reliability of data used by AI systems, and how AI-related risks are incorporated into management's existing risk-assessment process.
For SOX and compliance teams, the practical implication is that organizations should not wait for a dedicated AI rulebook before evaluating financially relevant uses of the technology. Existing ICFR principles remain the starting point.
At the same time, the SEC staff discussion should not be characterized as a new mandate requiring every financial AI application to be treated as a key control. The appropriate treatment depends on how the technology is used and whether it materially affects financial reporting.
Read the Thomson Reuters report
Determining When AI Becomes Part of ICFR
Not every AI tool used by finance automatically falls within ICFR scope. The more useful question is whether the system performs, supports, or materially affects a control over financial reporting.
An AI application that directly performs reconciliations, evaluates journal entries, approves financially relevant transactions, or generates information relied upon in a key control may require formal consideration within the organization's risk-and-control framework. A drafting assistant used only to improve wording may present a different level of control relevance, particularly when its output is independently reviewed and is not relied upon as control evidence.
AI-enabled controls may also fail differently from traditional manual controls. A missing signature or incomplete approval is usually visible. An automated system, however, may continue generating plausible results even when its data, configuration, or processing logic has deteriorated.
Organizations evaluating these applications may therefore consider whether their existing control design adequately addresses input reliability, output review, authorized changes, exception handling, and evidence retention. Practices such as model validation or drift monitoring may be helpful in certain environments, but the source materials do not establish them as universal regulatory mandates.
Non-Human Identities Expand the Access-Governance Discussion
AI agents and automated service identities can interact with ERP, HCM, and financial applications in ways that were previously limited to human users. Depending on their permissions, these identities may route approvals, initiate transactions, modify master data, or retrieve information used in financial controls.
This creates an important ITGC consideration. An automated identity capable of affecting financial reporting should not be treated as an informal technical account merely because it is not assigned to an employee. Its access may need identifiable ownership, documented business purpose, appropriate authorization, monitoring, and consideration within segregation-of-duties processes.
The linked SafePaaS article presents this issue as market and practitioner commentary rather than authoritative regulatory guidance. Its broader governance message is nevertheless relevant: non-human identities with financially significant access should be managed as auditable access subjects.
The article's EU AI Act timing also requires qualification. The attached accuracy review concludes that August 2026 should not be described as a universal deadline for high-risk AI systems. Transparency requirements reach an important milestone in August 2026, while obligations for certain high-risk systems begin later, including dates in 2027 and 2028.
PCAOB Modernization Focuses on the Audit Ecosystem
On July 9, the PCAOB announced 12 members of its new Inspections Modernization Council. The council is expected to help inform potential improvements to inspection reporting, the use of automation and AI, and the PCAOB's evaluation of audit firms' systems of quality control.
This is a meaningful indication that technology and data-enabled oversight are becoming part of the PCAOB's modernization agenda. However, the development is directed primarily toward audit-firm inspections and the broader audit ecosystem. It should not be interpreted as a new issuer requirement concerning digital verification, immutable logging, or AI-specific control documentation.
A separate Cato Institute opinion essay criticizes the PCAOB's governance and technology-related standard-setting. That article represents a policy viewpoint, not evidence that the PCAOB has imposed new digital-data mandates. Together, the two sources illustrate an ongoing tension: the profession is adopting advanced technology while stakeholders continue to debate whether auditing standards and inspection practices are evolving at the appropriate pace.
Read the Cato Institute commentary
Audit Technology and Lean-Team Practices Continue to Evolve
Technology providers, audit firms, and compliance practitioners are already integrating AI and automation into their operating models.
Deloitte's June 24 announcement describes AI agents embedded within its Omnia audit and assurance platform. The agents are intended to assist with activities such as identifying potential risk factors, analyzing evidence, drafting documentation, and supporting preliminary evaluations subject to professional review. This is not a regulatory development, but it demonstrates how AI is entering audit workflows where governance, validation, and human oversight are essential.
The ACS Live SOX & Internal Controls Update 2026, scheduled for July 14-15, includes sessions addressing ITGC scoping, Information Used in Controls, cloud environments, dynamic control testing, AI and automation, and SOX operating models for lean teams. Because the event had not yet occurred when the source newsletter was dated, its agenda should be treated as an indicator of practitioner priorities rather than a record of conclusions reached at the conference.
Related commentary on SOX return on investment emphasizes sustainable execution, stronger evidence, reduced manual effort, and clearer control ownership. These observations suggest that technology investments should be evaluated not only by whether an audit is completed, but also by whether the underlying compliance process becomes more reliable and maintainable.
Read the Deloitte Omnia announcement
Read "What Real SOX Compliance ROI Looks Like"
Key Takeaways
- AI-related SOX decisions should be based on function and financial-reporting impact, not simply on whether a tool uses artificial intelligence.
- Existing ICFR and ITGC principles remain applicable, particularly where AI performs a control, produces information relied upon in a control, or holds access capable of affecting financial data.
- Regulatory announcements, practitioner commentary, vendor publications, and conference agendas provide different levels of authority. Clear source labeling is essential to avoid presenting emerging practices as established requirements.
- Audit firms and compliance teams are already operationalizing AI. As adoption increases, documented ownership, dependable evidence, controlled access, reliable data, and meaningful human review will remain central to audit readiness.
Thank you for reading. We hope this digest supports informed conversations among compliance, finance, internal audit, technology, and risk-management stakeholders.