ISACA CEO says AI compliance will be like 'SOX on steroids'
Businesses will need to do far more work in far less time to meet stringent regulations
Compliance with AI regulations will present an enormous challenge for businesses, according to ISACA CEO Erik Prusch, describing the task as “Sarbanes-Oxley on steroids”.
Introduced in 2002 following the Enron and WorldCom accounting scandals, the Sarbanes-Oxley Act (commonly abbreviated to SOX) is a US federal law governing the reporting and verification of financial information by public companies.
Initial implementation of the necessary internal controls was notoriously costly and took several years to bed in, and compliance remains an annual exercise for US-listed companies.
Prusch, who was CFO of biometric authentication company Identix when the rules came into force, said the challenge of achieving compliance with incoming AI regulations dwarfs that work.
Prusch warned companies will need to do the same level of work five or even ten times faster thanks to the rapid pace of AI development – and all without a settled regulatory framework to guide them.
“It's the equivalent of SOX on steroids,” he told ITPro in an interview at the annual ISACA Europe conference in Munich. “It took us multiple years to get to a place where we actually knew what we were required to do from a Sarbanes-Oxley standpoint, and that was with the benefit of regulation that told us something to do.”
Dazed and confused over AI compliance
Part of the challenge with AI compliance, he explained, is that unlike SOX, the industry is still in the process of establishing the controls, accountability, and reporting lines that compliance will be based on.
Sign up today and you will receive a free copy of our Future Focus 2026 report - the leading resource for IT decision-maker insight on priorities and investment areas in AI, security and more.
“Who is responsible, who is ultimately going to be accountable, and how that is going to get communicated to the board, is brand new,” he said.
Further complicating matters, multiple countries and supranational bodies are butting heads over the best approach to regulating AI.
The EU's more cautious approach has favoured a comprehensive, risk-based rulebook – laid out in its AI Act – while the US federal government has prioritized development speed and innovation, resisting attempts to impose regulation at home and pressuring Brussels to scale back its own rules.
Combined with NIS2, DORA, and the Cyber Resilience Act, which govern cybersecurity for everything from critical infrastructure and banks to connected products, the AI Act makes the EU one of the more demanding regulatory environments for businesses.
Many organizations fall under several of these regimes at once, each with its own overlapping obligations.
"Over the last couple of years, we have seen a definite increase in the compliance burden," said Tara Wisniewski, senior vice president of advocacy at ISACA, citing complaints she’s heard from members.
"My DORA regulation says it has to look this way, NIS2 says it has to look this way, now CRA wants it this way… Why do I have to provide the same piece of information in six different colours? It gets ridiculous."
No light on the horizon
Prusch warned that the situation is likely to get worse before it gets better. He predicted that board members will be named in lawsuits when AI deployments go wrong, arguing that, as with SOX, regulation will arrive as a reaction to a string of high-profile failures.
"It's only going to take a couple of companies that frankly go out of business because they're exposed, and they haven't done the work necessary," he said. “Everybody’s going to have that ‘oh shit’ moment.”
"We're probably 12 months from panic," he added.
As part of efforts to address the gap, Wisniewski said ISACA is expanding its advocacy work, engaging with policymakers on the principles that should underpin AI regulation, and calling for greater consistency between different jurisdictions' rules.
This includes working with UK lawmakers on amendments to the Cyber Security and Resilience Bill.
At the same time, the association has also launched three AI-focused certification products, with a fourth on the way, and is building AI into established credentials such as CISA and CISM. Until regulation catches up, however, Prusch warned the onus is on businesses themselves.
“Every organization that is utilising AI without proper controls, without understanding risk, without governance policy principles, without cybersecurity awareness, is exposing that company to a traumatic amount of risk,” Prusch said.
FOLLOW US ON SOCIAL MEDIA
Follow ITPro on Google News and add us as a preferred source to keep tabs on all our latest news, analysis, views, and reviews.
You can also follow ITPro on LinkedIn, X, Facebook, and BlueSky.
Adam Shepherd has been a technology journalist since 2015, covering everything from cloud storage and security, to smartphones and servers. Over the course of his career, he’s seen the spread of 5G, the growing ubiquity of wireless devices, and the start of the connected revolution. He’s also been to more trade shows and technology conferences than he cares to count.
Adam is an avid follower of the latest hardware innovations, and he is never happier than when tinkering with complex network configurations, or exploring a new Linux distro. He was also previously a co-host on the ITPro Podcast, where he was often found ranting about his love of strange gadgets, his disdain for Windows Mobile, and everything in between.
You can find Adam tweeting about enterprise technology (or more often bad jokes) @AdamShepherUK.
-
‘The most useful thing a leader can do right now is admit the plan is unfinished’: Workers are being told to use AI, but not why to use it – here’s why that mattersNews A Culture Amp survey shows workers are eager for AI tools, but they'd like to know the business goal of the technology
-
AI skills investment could boost the UK economy by £80 billion – but there's still a long way to go before firms can capitalize on the technologyNews Researchers are calling for a Skills Tax Credit to incentivize employers
-
An AI kill switch ‘only solves half the problem’ with national security – British firms need to reduce reliance on foreign techNews Efforts to protect national security are welcomed, but bolstering sovereignty is also required
-
Poor business context is scuppering enterprise AI adoption – here’s why that mattersNews Research from Alteryx has found that more than half of organizations can't effectively operationalize the business knowledge AI needs
-
Manchester University: from AI initiators to AI integratorsCase Study The institution where Alan Turing first addressed the topic of artificial intelligence is rolling out Microsoft 365 Copilot access to 65,000 staff
-
‘Real-time data remains the voice that every leader must hear’: This one engineering role could be the key to building a truly data-driven enterpriseNews AI has increased the expectation for fast, or even instant, decisions. Data streaming engineers could help leaders keep pace
-
This new technique could improve AI output accuracy by 80% – and tackle hallucinations once and for allNews Researchers believe the new method will improve accuracy and help reduce costs
-
Reports: UK could consider regulation amidst growing 'rogue AI' concernsNews New AI minister said regulation is on the table, but only if public safety is at risk from AI

