AI Agent Audit Trail: Unaltered vs Attributable
A record can be unaltered and still silent about which agent wrote it and under whose authority. What the EU AI Act asks of logs, and the questions that separate the two.
By Harinderpal Hanspal on July 2026. Updated October 2026
An AI agent audit trail needs two properties that are easy to confuse: records nobody altered, and records that say which agent acted under whose authority. EU AI Act Article 12 requires automatic event logging for high-risk systems. It does not say tamper-evident.
A valve setting changes at 2 a.m. in a plant where four agents have access to the same system. The next morning someone opens the log to learn what happened and who allowed it.
What the EU AI Act asks of an agent's log
Article 12 says high-risk AI systems must technically allow automatic recording of events over the lifetime of the system, and that the logging must support traceability of events relevant to risk situations and to monitoring (Article 12). Article 19 has providers keep those logs for a period suited to the purpose, at least six months unless other law says otherwise (Article 19). Both texts are as published on artificialintelligenceact.eu, because the official EUR-Lex pages could not be read.
Read what is absent. Neither article says tamper-evident, immutable or cryptographically chained. We found no regulator that requires it. Both also apply to high-risk systems only, not to every agent, and the Digital Omnibus (Regulation 2026/1744, in force 27 July 2026) moved the Annex III high-risk obligations to 2 December 2027, according to Hunton. Anyone who says the logging duty starts this August is quoting the old schedule.
Industrial buyers have a softer source. CISA and eight partner agencies told critical-infrastructure owners in December 2025 to log and monitor the inputs and outputs of AI components in operational technology (CISA, 3 December 2025). That is guidance, not a regulation.
Three claims a log can make
Vendors say "full audit trail" and mean one of three things.
The record is unaltered. Hash chaining does this: each entry carries a fingerprint of the one before, so editing or deleting an old entry breaks every entry after it. It is a design choice, and a good one for an investigation.
The record was written by the system it names. A digital signature does this, and only while the signing key is itself protected.
The record says which agent acted, who authorized it, and why it was allowed. Neither of the first two touches this. A perfectly chained log can show that entry 4,112 is intact and that it came from "the agent service account", shared by all four agents. The reviewer's question stays open.
Three things have to be written at the moment of the action. A distinct identity for each agent, not a shared login. The decision that let it proceed: allowed by policy, approved by a named person, or refused. And, when agents start other agents, which run started which. Skip the lineage and a sub-agent's call cannot be traced to the instruction that created it.
Governance data suggests buyers are not well covered here. Deloitte's 2026 survey of 3,235 senior leaders in 24 countries, fielded August to September 2025, found that only one in five companies has a mature model for governing autonomous agents (Deloitte).
A test you can run on any agent log
Choose one action an agent took last week. Ask the vendor to answer these from the log alone, without opening the source code or asking an engineer.
- Which agent did it, and is that identity unique to that agent?
- Who or what authorized it: a policy, a named approver, a schedule?
- Was the decision recorded when it was made, or reconstructed afterward?
- If another agent started this one, can you see the parent run?
- Can the vendor show you an edited entry being caught?
- How long are records kept, and who can export them?
A vendor who answers the fifth question and goes quiet on the second has sold you an unaltered record of something nobody can attribute.
Drawn from EU AI Act Articles 12 and 19 as published on artificialintelligenceact.eu (the EUR-Lex text was not readable), Hunton's note on the Digital Omnibus (2026), CISA and eight partners' AI-in-OT principles (3 December 2025) and Deloitte's State of AI in the Enterprise 2026, all read on 6 October 2026. No figure here is a measurement.
Related notes
- Before an AI agent writes to equipment: what the joint CISA guidance asks for
- Where to put the human in an AI agent's work: approve the write, not the draft
Related insights
Related paper: Governing agents in production: what to ask before an agent acts