Your team just shipped an AI agent that can deploy code, manage databases, and chat with every API you own. It’s efficient, brilliant, and a compliance nightmare waiting to happen. Every query, every prompt, every automated fix touches customer or system data. Suddenly, your SOC 2 scope looks like