Research and perspectives
Technology risk, AI agents and audit methodology, written from practice.
July 2026
Kiyoshi Omaza
AI agents introduce a category of risk that current control frameworks do not contemplate: systems that decide and act. A first map for auditors.
Agentic AI is being deployed faster than audit plans incorporate it, employees already use AI on their own, and the EU AI Act activates its high-risk obligations in August 2026. The practical agenda.
The teams that audit technology barely use it themselves: 33% apply data analytics in half their audits, 13% use generative AI and 9% intelligent automation. Where the real value is.
Only 1 in 10 audit functions dedicates half its team to technology, and in AI the gap is extreme: 11% skilled today, 89% planning to invest. Upskilling, co-sourcing and tooling.
Cybersecurity, data governance and IT general controls still dominate the audit plan, while AI, cloud and DevOps push from outside. Only 42% of teams feel prepared.