SkadiSkadi
Sign in
Field notes · SOC 2 & AI assurance

SOC 2 & AI assurance in 2026: a client's guide to the conferences shaping your audit

An educational look at where SOC 2 and AI-audit standards are being debated between July 2026 and January 2027 — written for founders, security leads, and compliance owners who want to understand the landscape their auditor operates in.

Kseniia Khrytova · Skadi·July 3, 2026·8 min read·Educational

If you are preparing for a SOC 2 audit — especially for an AI-native product — it helps to know that the rules of the road are being actively rewritten right now. Standards bodies, regulators, and the CPA profession are all putting AI in the auditon the record for the first time. This post is a plain-English map of where that conversation is happening, so you can walk into your next audit knowing what your auditor is hearing.

This is an educational post only. Nothing here is a recommendation to attend, and Skadi has no commercial relationship with any of the organizers listed. Prices and dates were accurate as of July 3, 2026 — always verify with the organizer.

Why this matters for your next SOC 2

A SOC 2 report is an opinion signed by a licensed CPA firm against criteria set by the AICPA. As soon as AI joins the story — a model in your product, a vendor sending your customer data to an LLM, an internal copilot with access to production — three questions come up that the classic SOC 2 controls were not written for:

  • What counts as a "system" when part of it is a probabilistic model?
  • How does an auditor evaluate a control that runs against model outputs?
  • Which AI-specific frameworks (NIST AI RMF, ISO/IEC 42001, the AICPA's emerging AI attestation work) belong inside your SOC 2 scope, and which stay adjacent?

The events below are where those answers are being drafted. For a client, the value isn't attending them — it's knowing they exist so you can ask your auditor smart questions about how they're keeping up.

The one date to have on your radar: August 7, 2026

If your audit involves AI in any material way, August 7 is the most important public date in this cycle. The PCAOB's first-ever request for input on its standard-setting agenda (Release 2026-005) closes for public comment that day, and it explicitly names "data and technology, including AI" as a critical emerging issue. Anyone — including your team — can file a comment. Whatever the PCAOB hears now will shape the language auditors use in reports two to three years out.

A useful question for your auditor: "How is your firm engaging with the PCAOB 2026-005 comment window and the AICPA's AI-attestation work?" A firm that can answer specifically is a firm that will still be current in 2027 and 2028.

The calendar at a glance

The window has a natural rhythm: a summer of virtual AI-security summits, an in-person GRC block in August, an early-bird cutoff or two in the fall, then a December double-header of CPA-tech conferences in San Diego and Washington DC.

Jul 16
CSA Regulated Industries summit
virtual · free · AI in regulated sectors
in 12 days
Jul 20–21
AICPA SOC School opens
training for practicing SOC auditors
in 16 days
Aug 7 ★
PCAOB 2026-005 comments close
public comment on AI in the audit
in 34 days
Aug 17–19
GRC Conference (ISACA + IIA)
San Diego · hybrid · GRC and IT audit
in 44 days
Sep 16–17
CSA AI Security Summit: State of Trust
virtual · free · AI trust & assurance
in 74 days
Nov 18–19
TXCPA Houston F.A.C.T.S.
Houston · A&A and cyber CPE
in 137 days
Dec 6–9
Digital CPA 2026
San Diego · CPA technology
in 155 days
Dec 7–9
AICPA SEC & PCAOB Developments
Washington DC · standard-setter updates
in 156 days

Where the standard-setters actually meet

Two events in this window sit closest to where SOC 2 language is written and rewritten. If your future auditor is serious about AI, they are watching what happens in these rooms.

AICPA & CIMA — SEC & PCAOB Developments

Dec 7–9, 2026Washington DCHybrid
  • What it isThe annual room where SEC, PCAOB, FASB and IASB preview what's coming in audit and reporting
  • Why it mattersThis is where signals about AI in the audit turn into concrete guidance for CPA firms
  • For clientsAsk any prospective auditor whether they attend or watch the sessions from this event

GRC Conference 2026 (ISACA + The IIA)

Aug 17–19, 2026San DiegoHybrid
  • What it isThe largest joint governance, risk and compliance conference in North America
  • Why it mattersThe IT-audit and internal-audit communities set expectations here that flow into SOC 2 evidence requests
  • For clientsThe takeaways typically show up in your auditor's evidence checklist within a quarter

Where practicing CPAs share what's actually working

Standards move slowly. Practice moves faster. Two events in this window are where working CPA firms trade notes on how they're handling AI in real audits today.

Digital CPA 2026 (DCPA26)

Dec 6–9, 2026San DiegoHybrid
  • What it isCPA.com's flagship technology conference — the AICPA's tech-focused subsidiary
  • Why it mattersThis is where the CPA profession openly discusses AI tooling, evidence collection, and workflow automation
  • For clientsA useful signal that your auditor's tools are current — ask if they attended or watched sessions

TXCPA Houston F.A.C.T.S.

Nov 18–19, 2026HoustonIn person
  • What it isTXCPA Houston's Fall Accounting & Tech Symposium — 20 CPE across audit, assurance and cyber
  • Why it mattersState-society events are where regional CPA firms calibrate on emerging technology risk
  • For clientsA good marker that your auditor is plugged into the wider CPA community, not just SaaS compliance

Standards to know by name

You don't need to become an expert in any of these, but the following are the AI standards you will hear referenced in SOC 2 conversations over the next 12 months. A short glossary:

  • PCAOB Release 2026-005. The regulator that oversees public-company audits asking for public input on its standard-setting agenda — including AI. Comment window closes Aug 7, 2026.
  • AICPA Auditing Standards Board. Sets the U.S. auditing and attestation standards behind SOC 2. Standard-setting portions of their meetings are open to the public.
  • NIST AI Risk Management Framework (AI RMF). A voluntary framework for managing risks in AI systems. Increasingly referenced as supporting evidence inside SOC 2 controls.
  • ISO/IEC 42001. The first international management-system standard for AI. Certifiable, and starting to appear in vendor questionnaires alongside SOC 2.
  • CSA AI summits. The Cloud Security Alliance runs free virtual summits on AI security and trust throughout the window. Useful public context for how the security world is framing AI risk.

Two "SOC" traps to avoid

A quick note on naming: in security-operations circles, "SOC" stands for Security Operations Center, not SOC 2. Events called AI SOC Summit or AI Risk Summit are about AI in the SOC — red-teaming and adversarial ML for CISOs. Interesting, but unrelated to a SOC 2 attestation. Similarly, IAPP Privacy. Security. Risk. is a privacy-and-legal AI-governance conference with no CPA or SOC 2 content. If a vendor pitches you an "AI SOC" tool, this is the distinction to ask about.

What to take away

Three things worth remembering:

  • The rules for AI in SOC 2 are being written right now. The most important public moment in this window is the PCAOB comment period closing Aug 7.
  • Your auditor's continuing education matters. Ask which of these venues they attend, listen to, or contribute to. Specific answers are a good sign.
  • No single event is the "AI SOC 2" event yet. The conversation is spread across CPA, GRC, and AI-security rooms — which is exactly why choosing an auditor who tracks all three matters.

A note on sources

We built this map across three research passes: 302 automated agents, 54 primary sources fetched, 217 individual claims extracted, of which 66 were confirmed and 9 refuted on a 2-of-3 adversarial vote. Every date and price came from an official organizer page as of July 3, 2026. If you plan to attend anything on this list, verify it with the organizer directly — conference details change.

Ready for your SOC 2?

Skadi is an independent SOC 2 Type II audit firm built for AI-native and SaaS teams. Book a call and we'll walk through your scope, timeline, and controls in 30 minutes.