ISACA CEO says AI compliance will be like 'SOX on steroids'

Businesses will need to do far more work in far less time to meet stringent regulations

Regulatory AI compliance concept image showing scale symbol in a digital interface, with multiple other symbols including legislative building and legal documents.
(Image credit: Getty Images)

Compliance with AI regulations will present an enormous challenge for businesses, according to ISACA CEO Erik Prusch, describing the task as “Sarbanes-Oxley on steroids”.

Introduced in 2002 following the Enron and WorldCom accounting scandals, the Sarbanes-Oxley Act (commonly abbreviated to SOX) is a US federal law governing the reporting and verification of financial information by public companies.

Initial implementation of the necessary internal controls was notoriously costly and took several years to bed in, and compliance remains an annual exercise for US-listed companies.

Prusch, who was CFO of biometric authentication company Identix when the rules came into force, said the challenge of achieving compliance with incoming AI regulations dwarfs that work.

Latest Videos FromIT Pro

Prusch warned companies will need to do the same level of work five or even ten times faster thanks to the rapid pace of AI development – and all without a settled regulatory framework to guide them.

“It's the equivalent of SOX on steroids,” he told ITPro in an interview at the annual ISACA Europe conference in Munich. “It took us multiple years to get to a place where we actually knew what we were required to do from a Sarbanes-Oxley standpoint, and that was with the benefit of regulation that told us something to do.”

Dazed and confused over AI compliance

Part of the challenge with AI compliance, he explained, is that unlike SOX, the industry is still in the process of establishing the controls, accountability, and reporting lines that compliance will be based on.

“Who is responsible, who is ultimately going to be accountable, and how that is going to get communicated to the board, is brand new,” he said.

Further complicating matters, multiple countries and supranational bodies are butting heads over the best approach to regulating AI.

The EU's more cautious approach has favoured a comprehensive, risk-based rulebook – laid out in its AI Act – while the US federal government has prioritized development speed and innovation, resisting attempts to impose regulation at home and pressuring Brussels to scale back its own rules.

Combined with NIS2, DORA, and the Cyber Resilience Act, which govern cybersecurity for everything from critical infrastructure and banks to connected products, the AI Act makes the EU one of the more demanding regulatory environments for businesses.

Many organizations fall under several of these regimes at once, each with its own overlapping obligations.

"Over the last couple of years, we have seen a definite increase in the compliance burden," said Tara Wisniewski, senior vice president of advocacy at ISACA, citing complaints she’s heard from members.

"My DORA regulation says it has to look this way, NIS2 says it has to look this way, now CRA wants it this way… Why do I have to provide the same piece of information in six different colours? It gets ridiculous."

No light on the horizon

Prusch warned that the situation is likely to get worse before it gets better. He predicted that board members will be named in lawsuits when AI deployments go wrong, arguing that, as with SOX, regulation will arrive as a reaction to a string of high-profile failures.

"It's only going to take a couple of companies that frankly go out of business because they're exposed, and they haven't done the work necessary," he said. “Everybody’s going to have that ‘oh shit’ moment.”

"We're probably 12 months from panic," he added.

As part of efforts to address the gap, Wisniewski said ISACA is expanding its advocacy work, engaging with policymakers on the principles that should underpin AI regulation, and calling for greater consistency between different jurisdictions' rules.

This includes working with UK lawmakers on amendments to the Cyber Security and Resilience Bill.

At the same time, the association has also launched three AI-focused certification products, with a fourth on the way, and is building AI into established credentials such as CISA and CISM. Until regulation catches up, however, Prusch warned the onus is on businesses themselves.

“Every organization that is utilising AI without proper controls, without understanding risk, without governance policy principles, without cybersecurity awareness, is exposing that company to a traumatic amount of risk,” Prusch said.

FOLLOW US ON SOCIAL MEDIA

Follow ITPro on Google News and add us as a preferred source to keep tabs on all our latest news, analysis, views, and reviews.

You can also follow ITPro on LinkedIn, X, Facebook, and BlueSky.

Adam Shepherd

Adam Shepherd has been a technology journalist since 2015, covering everything from cloud storage and security, to smartphones and servers. Over the course of his career, he’s seen the spread of 5G, the growing ubiquity of wireless devices, and the start of the connected revolution. He’s also been to more trade shows and technology conferences than he cares to count.

Adam is an avid follower of the latest hardware innovations, and he is never happier than when tinkering with complex network configurations, or exploring a new Linux distro. He was also previously a co-host on the ITPro Podcast, where he was often found ranting about his love of strange gadgets, his disdain for Windows Mobile, and everything in between.

You can find Adam tweeting about enterprise technology (or more often bad jokes) @AdamShepherUK.