{"id":137312,"date":"2026-08-12T13:49:13","date_gmt":"2026-08-12T13:49:13","guid":{"rendered":"https:\/\/www.europesays.com\/ai\/137312\/"},"modified":"2026-08-12T13:49:13","modified_gmt":"2026-08-12T13:49:13","slug":"why-ai-agents-cant-certify-their-own-compliance-work","status":"publish","type":"post","link":"https:\/\/www.europesays.com\/ai\/137312\/","title":{"rendered":"Why AI Agents Can&#8217;t Certify Their Own Compliance Work"},"content":{"rendered":"<p>                    BLodgic&#8217;s Brennan Lodge on Segregation of Duties Between AI and Auditors<\/p>\n<p>                                                <a class=\"author-link\" href=\"https:\/\/www.bankinfosecurity.com\/authors\/michael-novinson-i-4923\" rel=\"nofollow noopener\" target=\"_blank\">Michael Novinson<\/a> (<a href=\"https:\/\/www.twitter.com\/MichaelNovinson\" rel=\"nofollow noopener\" target=\"_blank\">MichaelNovinson<\/a>)                                                    \u2022<br \/>\n                        August 12, 2026 \u00a0 \u00a0 <a href=\"https:\/\/www.bankinfosecurity.com\/ai-agents-cant-certify-their-own-compliance-work-a-32489#disqus_thread\" rel=\"nofollow noopener\" target=\"_blank\"><\/p>\n<p>                <img decoding=\"async\" src=\"https:\/\/www.europesays.com\/ai\/wp-content\/uploads\/2026\/08\/ai-agents-cant-certify-their-own-compliance-work-image_large-8-a-32489.jpg\" alt=\"Why AI Agents Can't Certify Their Own Compliance Work\" class=\"img-responsive hidden\"\/><\/p>\n<p>Brennan Lodge, founder and CEO, BLodgic<\/p>\n<p>Artificial intelligence agents can reduce the manual burden of cybersecurity compliance, but organizations still need human judgment to validate evidence and authorize outcomes, said Brennan Lodge, founder and CEO of BLodgic.<\/p>\n<p>See Also: <a href=\"https:\/\/www.bankinfosecurity.com\/open-weight-model-antares-delivers-stronger-code-security-a-32429?rf=RAM_SeeAlso\" rel=\"nofollow noopener\" target=\"_blank\">Open-Weight Model Antares Delivers Stronger Code Security<\/a><\/p>\n<p>Lodge said AI can analyze screenshots, policy documents and security tool evidence, then map that material to controls under frameworks such as NIST RMF, ISO 42001 and CMMC. The same system, however, shouldn&#8217;t perform the work, validate its output and certify compliance without independent review. &#8220;There still needs to be the human,&#8221; Lodge said.<\/p>\n<p>That oversight becomes even more important in regulated, sensitive and air-gapped environments, where agents require strict boundaries, logging and continuous observation. &#8220;You can&#8217;t just like set it and forget it. You&#8217;ve got to review the logs. You&#8217;ve got to check out what it&#8217;s doing and observe,&#8221; Lodge said.<\/p>\n<p>In this video interview with ISMG at <a href=\"https:\/\/www.bankinfosecurity.com\/black-hat-c-372\" rel=\"nofollow noopener\" target=\"_blank\">Black Hat USA 2026<\/a>, Lodge also discussed:<\/p>\n<p>Why specialized agents can improve validation without replacing human sign-off;<br \/>\nWhy agentic systems&#8217; non-deterministic nature demands more scrutiny than traditional model testing;<br \/>\nHow preparation, validation and authorization must stay distinct steps in the audit process. <\/p>\n<p>Lodge is a cybersecurity executive, data scientist, professor and researcher focused on applying AI to security operations, compliance, audit readiness and threat defense. He is the creator of Audit CADDIE, an AI-powered governance, risk and compliance platform.<\/p>\n<p>            <script async src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script><\/p>\n","protected":false},"excerpt":{"rendered":"BLodgic&#8217;s Brennan Lodge on Segregation of Duties Between AI and Auditors Michael Novinson (MichaelNovinson) \u2022 August 12, 2026&hellip;\n","protected":false},"author":2,"featured_media":137313,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[6],"tags":[405,20044,1798,7537,67955,67954,7428,4766,6975,32898,67956,67957],"class_list":["post-137312","post","type-post","status-publish","format-standard","has-post-thumbnail","category-agentic-ai","tag-ai-agents","tag-ai-compliance","tag-ai-governance","tag-artificial-intelligence-agents","tag-blodgic","tag-brennan-lodge","tag-cmmc","tag-cybersecurity-compliance","tag-human-in-the-loop","tag-iso-42001","tag-nist-rmf","tag-segregation-of-duties"],"_links":{"self":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts\/137312","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/comments?post=137312"}],"version-history":[{"count":0,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts\/137312\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/media\/137313"}],"wp:attachment":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/media?parent=137312"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/categories?post=137312"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/tags?post=137312"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}