An AI agent audit trail is the record of what an AI agent tried to do, which rule or person decided whether it could, and what happened next, kept in a form that someone outside the team can check later. A useful entry answers seven questions: who acted, what they tried, against which target, under which policy, what was decided, what resulted, and what lets a reviewer verify it.
Why it matters
Agents act faster and in more places than the people who deploy them can watch. When something goes wrong, or an auditor asks how a control operated, the audit trail is often the only account of what an agent did. Ordinary application logs rarely serve: whoever runs them can change them, they seldom carry the policy decision, and they give no sign of what is missing.
How it differs from an audit log and a tamper-evident log
An audit log is the stored list of events. An audit trail is the connected sequence that lets a reviewer follow one action from request to decision to outcome. A tamper-evident log describes a property the trail can have: a change to a recorded entry becomes detectable. Tamper evidence speaks to what was recorded; it says nothing about actions that were never recorded, which depends on where recording happens.
In Praesidia
Praesidia records the decisions it makes in an append-only, hash-chained audit trail, signed under the default configuration; an operator can turn signing off. A signed record shows it was not changed afterwards. It does not show that every action was captured. External anchoring is optional; without it, removal of the most recent records cannot be detected. Calls that do not pass through Praesidia are not recorded. Decision receipts are shown on AI agent evidence anyone can verify.
Where to go next
What to record, what auditors ask for under the EU AI Act, SOC 2 and ISO/IEC 42001, and a practical checklist are in the AI agent audit trail guide.
Common questions
Is an audit trail required for AI agents?
For high-risk AI systems under the EU AI Act, Article 12 requires automatic logging and Articles 19 and 26 require the logs to be kept. For other agents, SOC 2 and ISO/IEC 42001 auditors expect evidence that controls operated. The EU AI Act compliance page maps the articles.
Can an audit trail prove that nothing was left out?
Not on its own. Hash chains and signatures show that recorded entries were not changed; completeness depends on every governed path passing through the point that does the recording.