Share with your CISO
ISACA CEO Erik Prusch is warning that AI compliance will hit organizations with the structural weight of Sarbanes-Oxley but at five to ten times the speed, before the rulebook is even written. SOX, which followed the Enron and WorldCom scandals, took years of costly internal-controls work and arrived with a clear legal mandate. AI compliance has neither advantage. Prusch puts the timeline to widespread corporate panic at roughly 12 months, and predicts board members will face personal legal liability when AI deployments fail publicly.
What this means for your business
The organizations most exposed here aren’t the ones moving slowest on AI. They’re the ones moving fastest without building the governance layer underneath it. If your company is already operating AI in customer-facing or high-stakes internal processes, the absence of a settled regulatory framework isn’t a reason to wait. It’s the condition under which the first lawsuits will be filed, against companies that assumed they could formalize controls after the fact. Prusch’s SOX analogy is apt precisely because SOX didn’t punish companies for being early adopters of bad accounting software. It punished the executives who couldn’t demonstrate they knew what was happening inside their own systems.
The deeper problem is jurisdictional fragmentation. A multinational operating under the EU AI Act, NIS2, DORA, and the Cyber Resilience Act simultaneously isn’t facing four compliance programs. It’s facing four overlapping documentation demands, often for the same underlying control, formatted differently. ISACA, whose certification business grows when compliance complexity grows, has a structural incentive to frame the burden as larger rather than smaller, but that tilt doesn’t make Wisniewski’s complaint wrong. “The same piece of information in six different colours” is a real operational cost that falls hardest on companies with lean compliance teams and broad geographic footprints.
The who-wins-who-loses call here is straightforward. Large enterprises with mature GRC (governance, risk, and compliance) functions, the audit trails, the internal controls documentation, the board-level reporting cadence built for SOX, will absorb AI compliance faster than their mid-market competitors. The compliance-as-moat dynamic that followed SOX in financial services is likely to repeat. If you’re in a renewal cycle for your GRC platform or currently staffing a risk function, the relevant question isn’t whether AI regulation arrives. It’s whether your current architecture can produce the accountability documentation that regulators and plaintiffs’ attorneys will eventually demand.
Concept deep-dive: Sarbanes-Oxley (SOX)
SOX is a 2002 US federal law requiring public companies to formally document, test, and certify their internal financial controls every year, with executives signing off personally. Think of it as mandatory proof that a company’s financial reporting isn’t just accurate but that someone with a name and title is legally responsible for verifying it. The relevance to AI is structural: regulators and courts will eventually demand the same named accountability for how AI systems are built, monitored, and corrected.
Based on reporting from ISACA CEO says AI compliance will be like ‘SOX on steroids’, originally published 2026-10-07 19:05:00.

