An audit trail is the record of what an agent did, on whose authority, and when — enough to reconstruct decisions and attribute them.
Why it matters
Accountability needs evidence. Without an audit trail you cannot answer “which agent, authorised by whom, did this?” after the fact — and you cannot investigate an incident, prove compliance, or improve policy.
It builds on established logging and governance practice:
- Log management (NIST SP 800-92) defines how to collect, protect, and analyse security logs; an agent audit trail is a specialised, identity-rich log.
- EU AI Act Article 12 requires high-risk AI systems to technically allow automatic recording of events (logs) over the system’s lifetime — a regulatory floor for record-keeping.
- AI risk frameworks (NIST AI RMF) and management systems (ISO/IEC 42001) place accountability and monitoring in governance structures, which log evidence supports.
What an agent audit record should capture
- The agent’s verifiable identity and its principal.
- The authority or mandate under which it acted.
- The action, target, and parameters (including amount, where relevant).
- Timestamp, outcome, and any human approval or step-up.
- A tamper-evident link so records cannot be silently altered.
Caution
Logging agent inputs and outputs can capture sensitive personal data. Apply data-minimisation and retention rules, and keep secrets out of logs.
Related
Sources
- NIST, SP 800-92, Guide to Computer Security Log Management — https://csrc.nist.gov/pubs/sp/800/92/final (accessed 2026-10-03)
- European Commission, EU AI Act, Article 12 — https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-12 (accessed 2026-10-03)
- NIST, AI 100-1, AI RMF 1.0 — https://nvlpubs.nist.gov/nistpubs/ai/nist.ai.100-1.pdf (accessed 2026-10-03)
- ISO, ISO/IEC 42001:2023 — https://www.iso.org/standard/42001 (accessed 2026-10-03)