---
title: "Provable, not claimed: a tamper-evident log for AI agents"
description: "How to prove after the fact what an autonomous AI agent did, without anyone being able to change the log unnoticed."
canonical: "https://simosphereai.com/en/field-reports/tamper-evident-agent-log"
lang: en
---

# Provable, not claimed: a tamper-evident log for AI agents

How to prove after the fact what an autonomous AI agent did, without anyone being able to change the log unnoticed.

- Published: 2026-10-06
- Updated: 2026-10-06
- Status: erprobung
- Publisher: SIMO GmbH

## Starting question

How can we prove after the fact what an autonomous AI agent did, in a way that nobody can change the log unnoticed?

## Result: open

Design in testing: a signed chain of events with a hardware-bound key. How strong the guarantee is depends on the device.

By storing every relevant event as a signed link in a chain, with a reference to its predecessor and a key bound to the hardware. If the chain is altered, it shows, and the device is isolated. The design is in testing.

## What we tested

Every relevant event is stored as a link in a chain, with a reference to its predecessor and a signature. Such events include a tool call, a policy decision, or a key rotation.

The signing key is bound to the hardware. If the chain is altered, that shows, and the device is isolated.

## What it means for business architecture

Autonomy needs tamper-evident records. Only a complete trail makes AI agents acceptable to auditors, internal audit, and supervisors.

## Lessons learned

- An encrypted connection protects the transport, not the stored log.
- Security depends on the hardware. Weaker devices mean weaker guarantees, and that has to be said openly.
- The format of log entries has to be frozen early. Every later change breaks compatibility.

Rendered version: https://simosphereai.com/en/field-reports/tamper-evident-agent-log
