AI adoption in organizations is running ahead of its assurance, and the distance is growing. A recent global survey of internal audit leaders confirms it: auditing AI systems remains a relatively low priority in audit plans, precisely as corporate adoption accelerates — something the study itself expects to change as organizations need more assurance over these new risks.
Meanwhile, two things have happened that make that gap unsustainable.
Shadow AI: the adoption that never went through the committee
The first is shadow AI: the use of AI tools and agents by employees and business areas without the technology function's sanction. The study already warned about it — many employees are likely using AI independently, raising data security and privacy risks and bringing unreliable information into the organization — and called for stronger governance and guardrails in response.
With agentic AI the problem changes category: an agent does not just generate text, it acts — sends emails, queries systems, chains operations with valid credentials. A shadow agent with excessive permissions is a privileged user with no owner, no inventory and no log.
The regulatory calendar: delayed, not gone
The second is regulatory — with a recent twist. On 29 June 2026 the Council of the EU approved the Digital Omnibus package, postponing the EU AI Act obligations for stand-alone high-risk systems from 2 August 2026 to 2 December 2027 (August 2028 for AI embedded in products). What does not move: the Article 50 transparency obligations — informing people when they interact with an AI and labelling generated content — still apply from 2 August 2026. And in financial services, DORA has required since January 2025 an ICT risk management regime that reaches AI systems: risk classification, access controls, audit logs and third-party assessment.
The question "do we need to audit AI?" still has a calendar answer. The delay buys compliance time — it does not reduce the risk, which is being deployed today.
Criteria that already exist: from principles to work program
There is no need to invent the framework from scratch. The trusted AI principles used by reference frameworks — fairness, transparency, explainability, accountability, data integrity, reliability, security, privacy — are audit criteria in waiting: each translates into verifiable control questions. And the NIST AI RMF organizes AI risk management into four functions — govern, map, measure, manage — that map naturally onto the internal audit work cycle.
Agents are not audited with screenshots. They are audited with an inventory, verifiable limits and a record of every run: context, instructions, tools invoked and actions taken.
The auditor's agenda for the next two quarters
- Inventory of agents and AI usage — including the unauthorized. Without a census there is no auditable universe; shadow AI is governed first by making it visible.
- Risk classification aligned with the AI Act: which systems touch decisions about people, money or critical infrastructure.
- Verifiable limits: action budgets, allowed tools, human approval for irreversible operations — enforced technically, not just written in a policy.
- Audit-proof records of every run, retained and protected like any other critical record.
The underlying risk map is already known: effective versus formal authorization, traceability of reasoning, behavioural drift and the cognitive supply chain. What separates prepared teams from the rest is having turned it into a work program — and the room the new calendar grants is exactly for that, not for postponing it.