AI governance

Provable, not claimed: a tamper-evident log for AI agents

In testingPublished:

Starting questionHow can we prove after the fact what an autonomous AI agent did, in a way that nobody can change the log unnoticed?

Result

Open

Design in testing: a signed chain of events with a hardware-bound key. How strong the guarantee is depends on the device.

By storing every relevant event as a signed link in a chain, with a reference to its predecessor and a key bound to the hardware. If the chain is altered, it shows, and the device is isolated. The design is in testing.

What we tested

Every relevant event is stored as a link in a chain, with a reference to its predecessor and a signature. Such events include a tool call, a policy decision, or a key rotation.

The signing key is bound to the hardware. If the chain is altered, that shows, and the device is isolated.

What it means for business architecture

Autonomy needs tamper-evident records. Only a complete trail makes AI agents acceptable to auditors, internal audit, and supervisors.

Lessons learned

  1. An encrypted connection protects the transport, not the stored log.
  2. Security depends on the hardware. Weaker devices mean weaker guarantees, and that has to be said openly.
  3. The format of log entries has to be frozen early. Every later change breaks compatibility.
  • audit trail
  • AI agents
  • tamper-evident records
  • signature

More reports on AI governance

Consulting by SIMO GmbH

From the Lab to consulting.

This report shows what works technically. Whether it works in your company is a question of architecture. SIMO GmbH answers it with you, independent of vendors.

Decision Readiness Check: 12 questions, about 3 minutes, result at once. Initial call: 45 minutes, free of charge, by video. Entry with BISA 1 or BEIA. All on simo-online.com.