Audit Trail — KYA Glossary

An audit trail is the record of what an agent did, on whose authority, and when — enough to reconstruct decisions and attribute them.

Why it matters

Accountability needs evidence. Without an audit trail you cannot answer “which agent, authorised by whom, did this?” after the fact — and you cannot investigate an incident, prove compliance, or improve policy.

It builds on established logging and governance practice:

  • Log management (NIST SP 800-92) defines how to collect, protect, and analyse security logs; an agent audit trail is a specialised, identity-rich log.
  • EU AI Act Article 12 requires high-risk AI systems to technically allow automatic recording of events (logs) over the system’s lifetime — a regulatory floor for record-keeping.
  • AI risk frameworks (NIST AI RMF) and management systems (ISO/IEC 42001) place accountability and monitoring in governance structures, which log evidence supports.

What an agent audit record should capture

  • The agent’s verifiable identity and its principal.
  • The authority or mandate under which it acted.
  • The action, target, and parameters (including amount, where relevant).
  • Timestamp, outcome, and any human approval or step-up.
  • A tamper-evident link so records cannot be silently altered.

Caution

Logging agent inputs and outputs can capture sensitive personal data. Apply data-minimisation and retention rules, and keep secrets out of logs.

Related

Sources

  1. NIST, SP 800-92, Guide to Computer Security Log Management — https://csrc.nist.gov/pubs/sp/800/92/final (accessed 2026-10-03)
  2. European Commission, EU AI Act, Article 12 — https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-12 (accessed 2026-10-03)
  3. NIST, AI 100-1, AI RMF 1.0 — https://nvlpubs.nist.gov/nistpubs/ai/nist.ai.100-1.pdf (accessed 2026-10-03)
  4. ISO, ISO/IEC 42001:2023 — https://www.iso.org/standard/42001 (accessed 2026-10-03)