{"slug":"an-ietf-draft-proposes-a-common-format-for-agent-audit-logs","citations":[{"url":"https://datatracker.ietf.org/doc/draft-sharif-agent-audit-trail/","committed_hash":"sha256:205d67530cf5f8dc2216156803005a6f0658b967f5e40d16d053cfe3a8c85333","committed_hash_short":"sha256:205d6753…a8c85333","mime_type":"text/html","committed_at":"2026-07-26T21:00:16.901432+00:00","content_snapshot":"\n<!DOCTYPE html>\n\n\n\n\n\n\n<html data-bs-theme=\"auto\" lang=\"en\" prefix=\"og: http://ogp.me/ns# article: http://ogp.me/ns/article#\">\n    <head>\n        \n        <meta charset=\"utf-8\">\n        <meta http-equiv=\"X-UA-Compatible\" content=\"IE=edge\">\n        <title>\n            \n    \n        draft-sharif-agent-audit-trail-00 - Agent Audit Trail: A Standard Logging Format for Autonomous AI Systems\n    \n\n        </title>\n        <meta name=\"viewport\" content=\"width=device-width, initial-scale=1\">\n        <meta name=\"traceparent\" content=\"\">\n        <link href=\"https://static.ietf.org/fonts/inter/import.css\" rel=\"stylesheet\">\n        <link href=\"https://static.ietf.org/fonts/noto-sans-mono/import.css\" rel=\"stylesheet\">\n        <link rel=\"stylesheet\" href=\"https://static.ietf.org/dt/12.69.0/ietf/css/ietf.css\">\n        <link rel=\"stylesheet\" href=\"https://static.ietf.org/dt/12.69.0/ietf/css/select2.css\">\n        \n        <script src=\"https://static.ietf.org/dt/12.69.0/ietf/js/theme.js\"></script>\n        <style>\n            .inline { display: inline; }\n        </style>\n        \n        \n    \n\n\n\n\n<meta property=\"og:title\" content=\"Agent Audit Trail: A Standard Logging Format for Autonomous AI Systems\">\n<meta property=\"og:url\" content=\"https://datatracker.ietf.org/doc/draft-sharif-agent-audit-trail/\">\n<link rel=\"canonical\" href=\"https://datatracker.ietf.org/doc/draft-sharif-agent-audit-trail/\">\n<meta property=\"og:site_name\" content=\"IETF Datatracker\">\n<meta property=\"og:description\" content=\"This document specifies a standard logging format for autonomous AI agent systems. The Agent Audit Trail (AAT) defines a JSON-based record structure with mandatory fields for agent identity, action classification, outcome tracking, and trust level reporting. Records are linked via tamper-evident hash chaining using SHA-256 per RFC 8785, with optional ECDSA signatures for non-repudiation. The format addresses requirements from the EU AI Act (Regulation 2024/1689), which mandates automatic recording of events for high-risk AI systems effective August 2026. It also maps to SOC 2 Trust Services Criteria, ISO/IEC 42001, and PCI DSS v4.0.1 logging requirements. The design is transport-agnostic and supports export to JSONL, Syslog (RFC 5424), and CSV while preserving chain integrity. Privacy is addressed through input/output hashing and tombstone- based deletion compatible with GDPR Article 17.\">\n<meta property=\"og:type\" content=\"article\">\n\n<meta property=\"article:section\" content=\"Individual Internet-Draft\">\n\n<meta property=\"article:author\" content=\"Raza Sharif\">\n\n\n\n    <link rel=\"alternate\"\n          type=\"application/atom+xml\"\n          title=\"Document changes\"\n          href=\"/feed/document-changes/draft-sharif-agent-audit-trail/\">\n    <meta name=\"description\"\n          content=\"Agent Audit Trail: A Standard Logging Format for Autonomous AI Systems \">\n\n        <script type=\"module\" crossorigin=\"\" src=\"https://static.ietf.org/dt/12.69.0/assets/embedded-f7f04c22.js\"></script>\n<link href=\"https://static.ietf.org/dt/12.69.0/assets/create-pinia-singleton-e1887cc7.js\" type=\"text/javascript\" crossorigin=\"anonymous\" rel=\"modulepreload\" as=\"script\" />\n<link href=\"https://static.ietf.org/dt/12.69.0/assets/Scrollbar-f0f599a2.js\" type=\"text/javascript\" crossorigin=\"anonymous\" rel=\"modulepreload\" as=\"script\" />\n        \n\n<link rel=\"apple-touch-icon\"\n      sizes=\"180x180\"\n      href=\"https://static.ietf.org/dt/12.69.0/ietf/images/ietf-logo-nor-180.png\">\n<link rel=\"icon\"\n      sizes=\"32x32\"\n      href=\"https://static.ietf.org/dt/12.69.0/ietf/images/ietf-logo-nor-32.png\">\n<link rel=\"icon\"\n      sizes=\"16x16\"\n      href=\"https://static.ietf.org/dt/12.69.0/ietf/images/ietf-logo-nor-16.png\">\n<link rel=\"manifest\" href=\"/site.webmanifest\">\n<link rel=\"mask-icon\"\n      href=\"https://static.ietf.org/dt/12.69.0/ietf/images/ietf-logo-nor-mask.svg\"\n      color=\"#ffffff\">\n<meta name=\"msapplication-TileColor\"\n      content=\"#ffffff\">\n<meta name=\"theme-color\"\n      content=\"#ffffff\">\n        <script src=\"https://static.ietf.org/dt/12.69.0/ietf/js/ietf.js\"></script>\n        \n    </head>\n    <body  class=\"navbar-offset position-relative\"\n          data-group-menu-data-url=\"/group/groupmenu.json\">\n        \n        <noscript><iframe class=\"status\" title=\"Site status\" src=\"/status/latest\"></iframe></noscript>\n<div class=\"vue-embed\" data-component=\"Status\"></div>\n        <a class=\"visually-hidden visually-hidden-focusable\" href=\"#content\">Skip to main content</a>\n        <nav class=\"navbar navbar-expand-lg fixed-top bg-secondary-subtle\">\n            <div class=\"container-fluid\">\n                <a class=\"navbar-brand\" href=\"/\">\n                    \n\n\n\n<img alt=\"IETF Logo\"\n     class=\"d-lm-none me-2\"\n     \n     \n        \n             src=\"https://static.ietf.org/dt/12.69.0/ietf/images/ietf-logo-nor-white.svg\"\n        \n     \n     >\n\n<img alt=\"IETF Logo\"\n     class=\"d-dm-none me-2\"\n     \n     \n        \n             src=\"https://static.ietf.org/dt/12.69.0/ietf/images/ietf-logo-nor.svg\"\n        \n     \n     >\n                    Datatracker\n                    \n                </a>\n                <div class=\"collapse navbar-collapse\" id=\"navbar-collapse\">\n                    <ul class=\"nav navbar-nav flex-nowrap\">\n                        \n\n\n\n\n<li class=\"nav-item dropdown\">\n    \n        <a href=\"#\"\n           class=\"nav-link dropdown-toggle\"\n           role=\"button\"\n           data-bs-toggle=\"dropdown\"\n           aria-expanded=\"false\">\n            Groups\n        </a>\n        <ul class=\"dropdown-menu mt-n1\">\n        \n    <li class=\"dropdown-header\">By area/parent</li>\n    \n\n\n\n    \n    <li class=\"dropend group-menu group-parent-2010\">\n        <a class=\"dropdown-item dropdown-toggle \"\n           href=\"/wg/#ART\">\n            Apps &amp; Realtime\n        </a>\n    </li>\n\n    \n    <li class=\"dropend group-menu group-parent-1008\">\n        <a class=\"dropdown-item dropdown-toggle \"\n           href=\"/wg/#GEN\">\n            General\n        </a>\n    </li>\n\n    \n    <li class=\"dropend group-menu group-parent-1052\">\n        <a class=\"dropdown-item dropdown-toggle \"\n           href=\"/wg/#INT\">\n            Internet\n        </a>\n    </li>\n\n    \n    <li class=\"dropend group-menu group-parent-1193\">\n        <a class=\"dropdown-item dropdown-toggle \"\n           href=\"/wg/#OPS\">\n            Ops &amp; Management\n        </a>\n    </li>\n\n    \n    <li class=\"dropend group-menu group-parent-1249\">\n        <a class=\"dropdown-item dropdown-toggle \"\n           href=\"/wg/#RTG\">\n            Routing\n        </a>\n    </li>\n\n    \n    <li class=\"dropend group-menu group-parent-1260\">\n        <a class=\"dropdown-item dropdown-toggle \"\n           href=\"/wg/#SEC\">\n            Security\n        </a>\n    </li>\n\n    \n    <li class=\"dropend group-menu group-parent-2412\">\n        <a class=\"dropdown-item dropdown-toggle \"\n           href=\"/wg/#WIT\">\n            Web and Internet Transport\n        </a>\n    </li>\n\n    \n        <li><a class=\"dropdown-item\" href=\"/group/iesg/about/\">IESG</a></li>\n    \n    <li class=\"dropend group-menu group-parent-7\">\n        <a class=\"dropdown-item dropdown-toggle \"\n           href=\"/program/\">\n            IAB\n        </a>\n    </li>\n\n    \n    <li class=\"dropend group-menu group-parent-3\">\n        <a class=\"dropdown-item dropdown-toggle \"\n           href=\"/rg/\">\n            IRTF\n        </a>\n    </li>\n\n    \n    <li class=\"dropend group-menu group-parent-2309\">\n        <a class=\"dropdown-item dropdown-toggle \"\n           href=\"/adm/\">\n            IETF LLC\n        </a>\n    </li>\n\n    \n    <li class=\"dropend group-menu group-parent-1876\">\n        <a class=\"dropdown-item dropdown-toggle \"\n           href=\"/rfcedtyp/\">\n            RFC Editor\n        </a>\n    </li>\n\n\n    <li class=\"dropend\">\n        <a class=\"dropdown-item dropdown-toggle \"\n           href=\"/group/\">\n            Other\n        </a>\n        \n\n\n<ul class=\"dropdown-menu ms-n1\">\n    \n        <li>\n            <a class=\"dropdown-item \"\n               href=\"/ag/\">Active AGs</a>\n        </li>\n    \n        <li>\n            <a class=\"dropdown-item \"\n               href=\"/area/\">Active Areas</a>\n        </li>\n    \n        <li>\n            <a class=\"dropdown-item \"\n               href=\"/dir/\">Active Directorates</a>\n        </li>\n    \n        <li>\n            <a class=\"dropdown-item \"\n               href=\"/iabworkshop/\">Active IAB Workshops</a>\n        </li>\n    \n        <li>\n            <a class=\"dropdown-item \"\n               href=\"/program/\">Active Programs</a>\n        </li>\n    \n        <li>\n            <a class=\"dropdown-item \"\n               href=\"/rag/\">Active RAGs</a>\n        </li>\n    \n        <li>\n            <a class=\"dropdown-item \"\n               href=\"/team/\">Active Teams</a>\n        </li>\n    \n    \n</ul>\n\n    </li>\n    <li><hr class=\"dropdown-divider\"></li>\n    <li class=\"dropdown-header\">New work</li>\n    <li>\n        <a class=\"dropdown-item\"\n           href=\"/group/chartering/\">\n            Chartering groups\n        </a>\n    </li>\n    <li>\n        <a class=\"dropdown-item\"\n           href=\"/wg/bofs/\">\n            BOFs\n        </a>\n    </li>\n    <li>\n        <a class=\"dropdown-item\"\n           href=\"/doc/bof-requests\">\n            BOF Requests\n        </a>\n    </li>\n    <li><hr class=\"dropdown-divider\"></li>\n    <li class=\"dropdown-header\">Other groups</li>\n    <li>\n        <a class=\"dropdown-item\"\n           href=\"/group/concluded/\">\n            Concluded groups\n        </a>\n    </li>\n    <li>\n        <a class=\"dropdown-item\"\n           href=\"/list/nonwg\">\n            Non-WG lists\n        </a>\n    </li>\n    \n    </ul>\n</li>\n\n<li class=\"nav-item dropdown\">\n    \n        <a href=\"#\"\n           class=\"nav-link dropdown-toggle\"\n           role=\"button\"\n           data-bs-toggle=\"dropdown\"\n           aria-expanded=\"false\">\n            Documents\n        </a>\n        <ul class=\"dropdown-menu mt-n1\">\n        \n    <li>\n        <a class=\"dropdown-item\"\n           href=\"/doc/search\">\n            Search\n        </a>\n    </li>\n    <li>\n        <a class=\"dropdown-item\"\n           href=\"/doc/recent\">\n            Recent I-Ds\n        </a>\n    </li>\n    <li>\n        <a class=\"dropdown-item\"\n           href=\"/submit/\">\n            Submit an Internet-Draft\n        </a>\n    </li>\n    \n    \n        <li><hr class=\"dropdown-divider\">\n        </li>\n    \n    <li class=\"dropdown-header\">\n        RFC streams\n    </li>\n    <li>\n        <a class=\"dropdown-item\"\n           href=\"/stream/iab/\">\n            IAB\n        </a>\n    </li>\n    <li>\n        <a class=\"dropdown-item\"\n           href=\"/stream/irtf/\">\n            IRTF\n        </a>\n    </li>\n    <li>\n        <a class=\"dropdown-item\"\n           href=\"/stream/ise/\">\n            ISE\n        </a>\n    </li>\n    <li>\n        <a class=\"dropdown-item\"\n           href=\"/stream/editorial/\">\n            Editorial\n        </a>\n    </li>\n    \n        <li><hr class=\"dropdown-divider\">\n        </li>\n    \n    <li class=\"dropdown-header\">\n        Subseries\n    </li>\n    <li>\n        <a class=\"dropdown-item\"\n           href=\"/doc/std\">\n            STD\n        </a>\n        <a class=\"dropdown-item\"\n           href=\"/doc/bcp\">\n            BCP\n        </a>\n        <a class=\"dropdown-item\"\n           href=\"/doc/fyi\">\n            FYI\n        </a>\n    </li>\n    \n    </ul>\n</li>\n\n<li class=\"nav-item dropdown\">\n    \n        <a href=\"#\"\n           class=\"nav-link dropdown-toggle\"\n           role=\"button\"\n           data-bs-toggle=\"dropdown\"\n           aria-expanded=\"false\">\n            Meetings\n        </a>\n        <ul class=\"dropdown-menu mt-n1\">\n        \n    <li>\n        <a class=\"dropdown-item\"\n           href=\"/meeting/agenda\">\n            Agenda\n        </a>\n    </li>\n    <li>\n        <a class=\"dropdown-item\"\n           href=\"/meeting/materials\">\n            Materials\n        </a>\n    </li>\n    <li>\n        <a class=\"dropdown-item\"\n           href=\"/meeting/floor-plan\">\n            Floor plan\n        </a>\n    </li>\n    <li>\n        <a class=\"dropdown-item\"\n           href=\"https://www.ietf.org/how/meetings/register/\">\n            Registration\n        </a>\n    </li>\n    <li>\n        <a class=\"dropdown-item\"\n           href=\"/meeting/important-dates/\">\n            Important dates\n        </a>\n    </li>\n    <li>\n        <a class=\"dropdown-item\"\n           href=\"/meeting/session/request/\">\n            Request a session\n        </a>\n    </li>\n    \n    <li>\n        <a class=\"dropdown-item\"\n           href=\"/meeting/requests\">\n            Session requests\n        </a>\n    </li>\n    \n    \n        \n            <li><hr class=\"dropdown-divider\">\n            </li>\n        \n        <li class=\"dropdown-header\">\n            Upcoming meetings\n        </li>\n    \n    <li>\n        <a class=\"dropdown-item\"\n           href=\"/meeting/upcoming\">\n            Upcoming meetings\n        </a>\n    </li>\n    \n        \n            <li><hr class=\"dropdown-divider\">\n            </li>\n        \n        <li class=\"dropdown-header\">\n            Past meetings\n        </li>\n    \n    <li>\n        <a class=\"dropdown-item\"\n           href=\"/meeting/past\">\n            Past meetings\n        </a>\n    </li>\n    <li>\n        <a class=\"dropdown-item\"\n           href=\"https://www.ietf.org/how/meetings/past/\">\n            Meeting proceedings\n        </a>\n    </li>\n    \n    </ul>\n</li>\n\n<li class=\"nav-item dropdown\">\n    \n        <a href=\"#\"\n           class=\"nav-link dropdown-toggle\"\n           role=\"button\"\n           data-bs-toggle=\"dropdown\"\n           aria-expanded=\"false\">\n            Other\n        </a>\n        <ul class=\"dropdown-menu mt-n1\">\n        \n    <li>\n        <a class=\"dropdown-item\"\n           href=\"/ipr/\">\n            IPR disclosures\n        </a>\n    </li>\n    <li>\n        <a class=\"dropdown-item\"\n           href=\"/liaison/\">\n            Liaison statements\n        </a>\n    </li>\n    \n    <li>\n        <a class=\"dropdown-item\"\n           href=\"/iesg/agenda/\">\n            IESG agenda\n        </a>\n    </li>\n    <li>\n        <a class=\"dropdown-item\"\n           href=\"/nomcom/\">\n            NomComs\n        </a>\n    </li>\n    <li>\n        <a class=\"dropdown-item\"\n           href=\"/doc/downref\">\n            Downref registry\n        </a>\n    </li>\n    <li class=\"dropend\">\n        <a class=\"dropdown-item dropdown-toggle\" href=\"#\">\n            Statistics\n        </a>\n        <ul class=\"dropdown-menu\">\n            <li>\n                <a class=\"dropdown-item\"\n                   href=\"/stats/document/\">\n                    I-Ds/RFCs\n                </a>\n            </li>\n            <li>\n                <a class=\"dropdown-item\"\n                   href=\"/stats/meeting/\">\n                    Meetings\n                </a>\n            </li>\n            \n            \n        </ul>\n    </li>\n    <li>\n        <a class=\"dropdown-item\"\n           href=\"/api/\">\n            API Help\n        </a>\n    </li>\n    <li>\n        <a class=\"dropdown-item\"\n           href=\"/release/\">\n            Release notes\n        </a>\n    </li>\n    <li>\n        <a class=\"dropdown-item\"\n           target=\"_blank\" href=\"https://status.ietf.org\">\n            System status\n        </a>\n    </li>\n    \n        <li><hr class=\"dropdown-divider\">\n        </li>\n    \n    <li>\n        <a class=\"dropdown-item text-danger \"\n           target=\"_blank\" href=\"https://github.com/ietf-tools/datatracker/issues/new/choose\">\n            <i class=\"bi bi-bug\">\n            </i>\n            Report a bug\n        </a>\n    </li>\n    \n    </ul>\n</li>\n\n\n    \n\n\n\n<li class=\"nav-item dropdown\">\n    \n        <a href=\"#\"\n           class=\"nav-link dropdown-toggle\"\n           role=\"button\"\n           data-bs-toggle=\"dropdown\"\n           aria-expanded=\"false\">\n            \n                User\n            \n        </a>\n        <ul class=\"dropdown-menu  mt-n1 \">\n        \n    \n    \n        \n            <li>\n                <a class=\"dropdown-item \"\n                   rel=\"nofollow\"\n                   href=\"/accounts/login/?next=/doc/draft-sharif-agent-audit-trail/\">\n                    Sign in\n                </a>\n            </li>\n            <li>\n                <a class=\"dropdown-item \"\n                   rel=\"nofollow\"\n                   href=\"/accounts/reset/\">\n                    Password reset\n                </a>\n            </li>\n            <li>\n                <a class=\"dropdown-item \"\n                   href=\"/accounts/settings/\"\n                   rel=\"nofollow\">\n                    Preferences\n                </a>\n            </li>\n        \n    \n    \n        <li>\n            <a class=\"dropdown-item \"\n               href=\"/accounts/create/\">\n                New account\n            </a>\n        </li>\n    \n    <li class=\"dropend\">\n      <a class=\"dropdown-item dropdown-toggle\" href=\"#\">\n        List subscriptions\n      </a>\n      <ul class=\"dropdown-menu\">\n            <li>\n                <a class=\"dropdown-item \"\n                href=\"https://mailman3.ietf.org/mailman3/lists/\">\n                    IETF Lists\n                </a>\n            </li>\n            <li>\n                <a class=\"dropdown-item \"\n                href=\"https://mailman3.irtf.org/mailman3/lists/\">\n                IRTF Lists\n                </a>\n            </li>\n            <li>\n                <a class=\"dropdown-item \"\n                href=\"https://mailman3.iab.org/mailman3/lists/\">\n                    IAB Lists\n                </a>\n            </li>\n            <li>\n                <a class=\"dropdown-item \"\n                href=\"https://mailman3.rfc-editor.org/mailman3/lists/\">\n                    RFC-Editor Lists\n                </a>\n            </li>\n        </ul>\n    </li>\n    \n    \n    \n    \n    \n    </ul></li>\n\n\n                    </ul>\n                </div>\n                <div class=\"d-flex align-items-center\">\n                    <a class=\"nav-link text-danger d-none d-xl-inline me-xl-4\"\n                       target=\"_blank\"\n                       href=\"https://github.com/ietf-tools/datatracker/issues/new/choose\">\n                        Report a bug\n                        <i class=\"bi bi-bug\"></i>\n                    </a>\n\n                    \n                        <a class=\"btn me-1  btn-warning  d-none d-sm-block\"\n                           rel=\"nofollow\"\n                           href=\"/accounts/login/?next=/doc/draft-sharif-agent-audit-trail/\">\n                            Sign in\n                        </a>\n                    \n\n                    <div class=\"d-none d-md-block dropdown\" id=\"navbar-doc-search-wrapper\">\n                        <input class=\"form-control\"\n                               id=\"navbar-doc-search\"\n                               type=\"text\"\n                               placeholder=\"Document search\"\n                               autocomplete=\"off\"\n                               data-ajax-url=\"/doc/select2search/document/all/\"\n                               aria-label=\"Document search\">\n                        <ul class=\"dropdown-menu\" id=\"navbar-doc-search-results\">\n                        </ul>\n                    </div>\n                </div>\n                <button class=\"navbar-toggler\"\n                        type=\"button\"\n                        data-bs-toggle=\"collapse\"\n                        data-bs-target=\"#navbar-collapse\"\n                        aria-controls=\"navbar-collapse\"\n                        aria-expanded=\"false\"\n                        aria-label=\"Toggle navigation\">\n                    <i class=\"navbar-toggler-icon\"></i>\n                </button>\n            </div>\n        </nav>\n        \n        <main class=\"pt-3 container-fluid\" id=\"main\">\n            <div class=\"row\">\n                \n                <div class=\"col mx-lg-3 ietf-auto-nav\" id=\"content\">\n                    <noscript data-nosnippet>\n                        <div class=\"alert alert-danger alert-ignore my-3\">\n                            <b>Javascript disabled?</b> Like other modern websites, the IETF Datatracker relies on Javascript.\n                            Please enable Javascript for full functionality.\n                        </div>\n                    </noscript>\n                    \n                    \n    \n    \n\n\n\n<h1>\n    Agent Audit Trail: A Standard Logging Format for Autonomous AI Systems\n    <br>\n    <small class=\"text-body-secondary\">draft-sharif-agent-audit-trail-00</small>\n</h1>\n<ul class=\"nav nav-tabs my-3\">\n    \n        <li  class=\"nav-item\">\n            <a class=\"nav-link active\"\n               href=\"/doc/draft-sharif-agent-audit-trail/\">\n                Status\n            </a>\n        </li>\n    \n        <li  class=\"nav-item\">\n            <a class=\"nav-link \"\n               href=\"/doc/draft-sharif-agent-audit-trail/email/\">\n                Email expansions\n            </a>\n        </li>\n    \n        <li  class=\"nav-item\">\n            <a class=\"nav-link \"\n               href=\"/doc/draft-sharif-agent-audit-trail/history/\">\n                History\n            </a>\n        </li>\n    \n</ul>\n\n    \n\n\n\n    <label class=\"my-1 fw-bold\">Versions:</label>\n    <nav class=\"mb-3\">\n\n    <ul class=\"revision-list pagination pagination-sm text-center flex-wrap\">\n        \n            \n                 \n                    <li class=\"page-item active\">\n                        <a class=\"page-link\"\n                        href=\"/doc/draft-sharif-agent-audit-trail/00/\"\n                        >\n                            00\n                        </a>\n                    </li>\n                \n            \n            \n        \n    </ul>\n\n    </nav>\n\n    \n\n\n\n\n    <div class=\"alert alert-warning \" role=\"alert\">\n        This document is an Internet-Draft (I-D).\n        Anyone may submit an I-D to the IETF.\n        This I-D is <strong>not endorsed by the IETF</strong> and has <strong>no formal standing</strong> in the\n        <a href=\"/doc/rfc2026/\">IETF standards process</a>.\n    </div>\n\n\n    <div id=\"doc-timeline\"></div>\n    \n        \n    \n    <table class=\"table table-sm table-borderless\">\n        \n\n\n\n\n\n\n\n<tbody class=\"meta align-top  border-top\">\n    <tr>\n        <th scope=\"row\">Document</th>\n        <th scope=\"row\">Type</th>\n        <td class=\"edit\"></td>\n        <td>\n            \n\n\n\n\n\n\n\n    <span class=\"text-success\">Active Internet-Draft</span>\n    (individual)\n    \n\n            \n            \n            \n        </td>\n    </tr>\n    \n    <tr>\n        <td></td>\n        <th scope=\"row\">Author</th>\n        <td class=\"edit\">\n            \n        </td>\n        <td>\n            \n            \n                <span ><a \n           title=\"Datatracker profile of Raza Sharif\"\n            href=\"/person/raza@cybersecai.co.uk\" >Raza Sharif</a> <a \n               href=\"mailto:raza%40cybersecai.co.uk\"\n               aria-label=\"Compose email to raza@cybersecai.co.uk\"\n               title=\"Compose email to raza@cybersecai.co.uk\">\n                <i class=\"bi bi-envelope\"></i></a></span>\n            \n            \n        </td>\n    </tr>\n    \n    \n    <tr>\n        <td></td>\n        <th scope=\"row\">Last updated</th>\n        <td class=\"edit\"></td>\n        <td>\n            2026-03-29\n            \n        </td>\n    </tr>\n    \n    \n        \n        \n        \n    \n    <tr>\n        <td></td>\n        <th scope=\"row\">\n            RFC stream\n        </th>\n        <td class=\"edit\">\n            \n        </td>\n        <td class=\"text-body-secondary\">\n            \n                (None)\n            \n        </td>\n    </tr>\n    \n        <tr>\n            <td></td>\n            <th scope=\"row\">\n                Intended RFC status\n            </th>\n            <td class=\"edit\">\n                \n            </td>\n            <td>\n                \n                    <span class=\"text-body-secondary\">\n                        (None)\n                    </span>\n                \n            </td>\n        </tr>\n    \n    <tr>\n        <td></td>\n        <th scope=\"row\">\n            Formats\n        </th>\n        <td class=\"edit\">\n        </td>\n        <td>\n            \n                \n    <div class=\"buttonlist\">\n    \n        \n        <a class=\"btn btn-primary btn-sm\"\n          \n          target=\"_blank\"\n          href=\"https://www.ietf.org/archive/id/draft-sharif-agent-audit-trail-00.txt\">\n            \n                <i class=\"bi bi-file-text\"></i> txt\n            \n        </a>\n        \n    \n        \n        <a class=\"btn btn-primary btn-sm\"\n          \n          \n          href=\"/doc/html/draft-sharif-agent-audit-trail-00\">\n            \n                <i class=\"bi bi-file-code\"></i> htmlized\n            \n        </a>\n        \n    \n        \n        <a class=\"btn btn-primary btn-sm\"\n          \n          target=\"_blank\"\n          href=\"/doc/draft-sharif-agent-audit-trail/00/bibtex/\">\n            \n                <i class=\"bi bi-file-ruled\"></i> bibtex\n            \n        </a>\n        \n    \n        \n        <a class=\"btn btn-primary btn-sm\"\n          \n          target=\"_blank\"\n          href=\"/doc/bibxml3/draft-sharif-agent-audit-trail-00.xml\">\n            \n                <i class=\"bi bi-file-code\"></i> bibxml\n            \n        </a>\n        \n    \n</div>\n\n            \n        </td>\n    </tr>\n    \n    \n        \n    \n        \n            \n            \n        \n    \n    \n        \n    \n</tbody>\n        <tbody class=\"meta border-top\">\n            <tr>\n                <th scope=\"row\">\n                    Stream\n                </th>\n                \n                    <th scope=\"row\">\n                        Stream state\n                    </th>\n                    <td class=\"edit\">\n                    </td>\n                    <td>\n                        <span class=\"text-body-secondary\">(No stream defined)</span>\n                    </td>\n                \n            </tr>\n            \n            \n                <tr>\n                    <td></td>\n                    <th scope=\"row\">\n                        Consensus boilerplate\n                    </th>\n                    <td class=\"edit\">\n                        \n                    </td>\n                    <td>\n                        <span class=\"text-danger\"\n                              title=\"Whether the document is the result of a community consensus process as defined in RFC 5741\">\n                            Unknown\n                        </span>\n                    </td>\n                </tr>\n            \n            \n            \n                <tr>\n                    <td></td>\n                    <th scope=\"row\">\n                        RFC Editor Note\n                    </th>\n                    <td class=\"edit\">\n                        \n                    </td>\n                    <td>\n                        \n                            <span class=\"text-body-secondary\">\n                                (None)\n                            </span>\n                        \n                    </td>\n                </tr>\n            \n            \n        </tbody>\n        \n            <tbody class=\"meta border-top\">\n                <tr>\n                    <th scope=\"row\">\n                        IESG\n                    </th>\n                    <th scope=\"row\">\n                        <a href=\"/doc/help/state/draft-iesg/\">\n                            IESG state\n                        </a>\n                    </th>\n                    <td class=\"edit\">\n                        \n                    </td>\n                    <td>\n                        <span class=\"\">\n                            \n                                I-D Exists\n                            \n                        </span>\n                    </td>\n                </tr>\n                \n                    \n                    <tr>\n                        <td></td>\n                        <th scope=\"row\">\n                            Telechat date\n                        </th>\n                        <td class=\"edit\">\n                            \n                        </td>\n                        <td>\n                            \n                                <span class=\"text-body-secondary\">\n                                    (None)\n                                </span>\n                            \n                            \n                        </td>\n                    </tr>\n                    <tr>\n                        <td></td>\n                        <th scope=\"row\">\n                            Responsible AD\n                        </th>\n                        <td class=\"edit\">\n                            \n                        </td>\n                        <td>\n                            \n                                <span class=\"text-body-secondary\">\n                                    (None)\n                                </span>\n                            \n                        </td>\n                    </tr>\n                    \n                    <tr>\n                        <td></td>\n                        <th scope=\"row\">\n                            Send notices to\n                        </th>\n                        <td class=\"edit\">\n                            \n                        </td>\n                        <td>\n                            \n                                <span class=\"text-body-secondary\">\n                                    (None)\n                                </span>\n                            \n                        </td>\n                    </tr>\n                </tbody>\n            \n            \n                \n            \n            \n        </table>\n        <div class=\"buttonlist\">\n            <a class=\"btn btn-primary btn-sm\"\n               href=\"mailto:draft-sharif-agent-audit-trail@ietf.org?subject=Mail%20regarding%20draft-sharif-agent-audit-trail\">\n                <i class=\"bi bi-envelope\">\n                </i>\n                Email authors\n            </a>\n            \n            <a class=\"btn btn-primary btn-sm\"\n               href=\"/ipr/search/?submit=draft&amp;id=draft-sharif-agent-audit-trail\"\n               rel=\"nofollow\">\n                <i class=\"bi bi-lightning\">\n                </i>\n                IPR\n                \n            </a>\n            <a class=\"btn btn-primary btn-sm\"\n               href=\"/doc/draft-sharif-agent-audit-trail/references/\"\n               rel=\"nofollow\">\n                <i class=\"bi bi-arrow-left\">\n                </i>\n                References\n            </a>\n            <a class=\"btn btn-primary btn-sm\"\n               href=\"/doc/draft-sharif-agent-audit-trail/referencedby/\"\n               rel=\"nofollow\">\n                <i class=\"bi bi-arrow-right\">\n                </i>\n                Referenced by\n            </a>\n            <a class=\"btn btn-primary btn-sm\"\n               href=\"https://author-tools.ietf.org/api/idnits?url=https://www.ietf.org/archive/id/draft-sharif-agent-audit-trail-00.txt\"\n               rel=\"nofollow\"\n               target=\"_blank\">\n                <i class=\"bi bi-exclamation\">\n                </i>\n                Nits\n            </a>\n             <a class=\"btn btn-primary btn-sm\"\n               href=\"https://author-tools.ietf.org/idnits3/results?url=https://www.ietf.org/archive/id/draft-sharif-agent-audit-trail-00.txt\"\n               rel=\"nofollow\"\n               target=\"_blank\">\n                <i class=\"bi bi-exclamation-diamond\">\n                </i>\n                Nits v3\n            </a>           \n            <a class=\"btn btn-primary btn-sm\"\n               href=\"https://mailarchive.ietf.org/arch/search/?q=%22draft-sharif-agent-audit-trail%22\"\n               rel=\"nofollow\"\n               target=\"_blank\">\n                <i class=\"bi bi-search\">\n                </i>\n                Search email archive\n            </a>\n            \n            \n            \n            \n        </div>\n        \n            <div class=\"card mt-5\">\n                <div class=\"card-header\">\n                    \n                        draft-sharif-agent-audit-trail-00\n                    \n                </div>\n                <div class=\"card-body\">\n                    <pre>Internet Engineering Task Force                               R. Sharif\nInternet-Draft                                            CyberSecAI Ltd\nIntended status: Standards Track                          March 29, 2026\nExpires: September 29, 2026\n\n   Agent Audit Trail: A Standard Logging Format for Autonomous AI\n                                Systems\n                  draft-sharif-agent-audit-trail-00\n\n<span>Abstract</span>\n\n   This document specifies a standard logging format for autonomous\n   AI agent systems.  The Agent Audit Trail (AAT) defines a\n   JSON-based record structure with mandatory fields for agent\n   identity, action classification, outcome tracking, and trust\n   level reporting.  Records are linked via tamper-evident hash\n   chaining using SHA-256 per RFC 8785, with optional ECDSA\n   signatures for non-repudiation.\n\n   The format addresses requirements from the EU AI Act\n   (Regulation 2024/1689), which mandates automatic recording of\n   events for high-risk AI systems effective August 2026.  It also\n   maps to SOC 2 Trust Services Criteria, ISO/IEC 42001, and\n   PCI DSS v4.0.1 logging requirements.\n\n   The design is transport-agnostic and supports export to JSONL,\n   Syslog (RFC 5424), and CSV while preserving chain integrity.\n   Privacy is addressed through input/output hashing and tombstone-\n   based deletion compatible with GDPR Article 17.\n\n<span>Status of This Memo</span>\n\n   This Internet-Draft is submitted in full conformance with the\n   provisions of BCP 78 and BCP 79.\n\n   Internet-Drafts are working documents of the Internet Engineering\n   Task Force (IETF).  Note that other groups may also distribute\n   working documents as Internet-Drafts.  The list of current\n   Internet-Drafts is at https://datatracker.ietf.org/drafts/current/.\n\n   Internet-Drafts are draft documents valid for a maximum of six\n   months and may be updated, replaced, or obsoleted by other\n   documents at any time.  It is inappropriate to use Internet-Drafts\n   as reference material or to cite them other than as &quot;work in\n   progress.&quot;\n\n   This Internet-Draft will expire on September 29, 2026.\n\n<span>Copyright Notice</span>\n\n   Copyright (c) 2026 IETF Trust and the persons identified as the\n   document authors.  All rights reserved.\n\n   This document is subject to BCP 78 and the IETF Trust&#x27;s Legal\n   Provisions Relating to IETF Documents\n   (https://trustee.ietf.org/license-info) in effect on the date of\n   publication of this document.  Please review these documents\n   carefully, as they describe your rights and restrictions with\n   respect to this document.  Code Components extracted from this\n   document must include Revised BSD License text as described in\n   Section 4.e of the Trust Legal Provisions and are provided\n   without warranty as described in the Revised BSD License.\n\n<span>Table of Contents</span>\n\n   1.  Introduction  . . . . . . . . . . . . . . . . . . . . . . .  3\n     1.1.  The Problem . . . . . . . . . . . . . . . . . . . . . .  3\n     1.2.  Design Goals  . . . . . . . . . . . . . . . . . . . . .  4\n   2.  Terminology . . . . . . . . . . . . . . . . . . . . . . . .  4\n   3.  Audit Record Format . . . . . . . . . . . . . . . . . . . .  5\n     3.1.  Mandatory Fields  . . . . . . . . . . . . . . . . . . .  5\n     3.2.  Optional Fields . . . . . . . . . . . . . . . . . . . .  8\n     3.3.  Field Constraints . . . . . . . . . . . . . . . . . . .  9\n   4.  Tamper-Evident Chaining . . . . . . . . . . . . . . . . . . 10\n     4.1.  Hash Computation  . . . . . . . . . . . . . . . . . . . 10\n     4.2.  Signature Envelope  . . . . . . . . . . . . . . . . . . 11\n     4.3.  Chain Verification  . . . . . . . . . . . . . . . . . . 11\n   5.  Action Type Definitions . . . . . . . . . . . . . . . . . . 12\n     5.1.  tool_call . . . . . . . . . . . . . . . . . . . . . . . 12\n     5.2.  tool_response . . . . . . . . . . . . . . . . . . . . . 13\n     5.3.  decision  . . . . . . . . . . . . . . . . . . . . . . . 13\n     5.4.  delegation  . . . . . . . . . . . . . . . . . . . . . . 13\n     5.5.  escalation  . . . . . . . . . . . . . . . . . . . . . . 14\n     5.6.  error . . . . . . . . . . . . . . . . . . . . . . . . . 14\n     5.7.  lifecycle . . . . . . . . . . . . . . . . . . . . . . . 14\n   6.  Session Structure . . . . . . . . . . . . . . . . . . . . . 15\n     6.1.  Genesis Record  . . . . . . . . . . . . . . . . . . . . 15\n     6.2.  Ordered Chain . . . . . . . . . . . . . . . . . . . . . 15\n     6.3.  Session Close . . . . . . . . . . . . . . . . . . . . . 16\n   7.  Retention Requirements  . . . . . . . . . . . . . . . . . . 16\n     7.1.  High-Risk Systems . . . . . . . . . . . . . . . . . . . 16\n     7.2.  General-Purpose Systems . . . . . . . . . . . . . . . . 17\n     7.3.  Tombstone Records . . . . . . . . . . . . . . . . . . . 17\n   8.  Export Formats  . . . . . . . . . . . . . . . . . . . . . . 17\n     8.1.  JSONL (Primary) . . . . . . . . . . . . . . . . . . . . 18\n     8.2.  Syslog (RFC 5424) . . . . . . . . . . . . . . . . . . . 18\n     8.3.  CSV . . . . . . . . . . . . . . . . . . . . . . . . . . 18\n   9.  Regulatory Mapping  . . . . . . . . . . . . . . . . . . . . 19\n     9.1.  EU AI Act . . . . . . . . . . . . . . . . . . . . . . . 19\n     9.2.  SOC 2 . . . . . . . . . . . . . . . . . . . . . . . . . 20\n     9.3.  ISO/IEC 42001 . . . . . . . . . . . . . . . . . . . . . 20\n     9.4.  PCI DSS v4.0.1 . . . . . . . . . . . . . . . . . . . . 20\n   10. Privacy Considerations  . . . . . . . . . . . . . . . . . . 21\n     10.1. Data Minimization . . . . . . . . . . . . . . . . . . . 21\n     10.2. Right to Erasure  . . . . . . . . . . . . . . . . . . . 21\n   11. Security Considerations . . . . . . . . . . . . . . . . . . 22\n     11.1. Log Tampering . . . . . . . . . . . . . . . . . . . . . 22\n     11.2. Log Injection . . . . . . . . . . . . . . . . . . . . . 22\n     11.3. Timing Attacks  . . . . . . . . . . . . . . . . . . . . 23\n     11.4. Chain Breaks  . . . . . . . . . . . . . . . . . . . . . 23\n   12. IANA Considerations . . . . . . . . . . . . . . . . . . . . 23\n     12.1. Action Type Registry  . . . . . . . . . . . . . . . . . 23\n     12.2. Outcome Registry  . . . . . . . . . . . . . . . . . . . 24\n   13. References  . . . . . . . . . . . . . . . . . . . . . . . . 24\n     13.1. Normative References  . . . . . . . . . . . . . . . . . 24\n     13.2. Informative References  . . . . . . . . . . . . . . . . 25\n   Appendix A.  Example Audit Trail  . . . . . . . . . . . . . . . 26\n   Appendix B.  EU AI Act Compliance Checklist . . . . . . . . . . 31\n   Appendix C.  Implementation Notes . . . . . . . . . . . . . . . 32\n   Author&#x27;s Address  . . . . . . . . . . . . . . . . . . . . . . . 34\n\n1.  Introduction\n\n1.1.  The Problem\n\n   The EU Artificial Intelligence Act (Regulation 2024/1689) enters\n   full application on 2 August 2026.  Article 12 requires that\n   high-risk AI systems &quot;shall technically allow for the automatic\n   recording of events (&#x27;logs&#x27;) over the lifetime of the system.&quot;\n   Article 12(2) further specifies that logging capabilities shall\n   conform to recognized standards or common specifications.\n\n   Despite this regulatory mandate, no standard exists for HOW\n   autonomous AI agents should log their activities.  Current\n   approaches suffer from several deficiencies:\n\n   o  Proprietary formats that vary across vendors, making cross-\n      system auditing impossible.\n\n   o  No tamper-evidence, allowing post-hoc modification of logs\n      without detection.\n\n   o  Inconsistent action taxonomies that prevent meaningful\n      comparison of agent behavior across implementations.\n\n   o  No linkage between agent identity and logged actions,\n      making attribution unreliable.\n\n   o  No session structure, making it impossible to reconstruct\n      the full sequence of an agent&#x27;s autonomous decision chain.\n\n   This document fills this gap by defining the Agent Audit Trail\n   (AAT), a standard JSON-based logging format with tamper-evident\n   chaining, a defined action taxonomy, and explicit regulatory\n   mapping.\n\n1.2.  Design Goals\n\n   The AAT format is designed with the following goals:\n\n   o  Regulatory compliance: Direct mapping to EU AI Act\n      Article 12 requirements and other frameworks.\n\n   o  Tamper evidence: Hash-chained records that make\n      unauthorized modification detectable.\n\n   o  Interoperability: A single format usable across different\n      agent frameworks, model providers, and orchestration\n      systems.\n\n   o  Privacy by design: No raw personal data in records;\n      cryptographic hashes of inputs and outputs instead.\n\n   o  Transport agnostic: Exportable to JSONL, Syslog, and CSV\n      without losing chain integrity.\n\n   o  Incremental adoption: Mandatory fields are minimal;\n      optional fields support progressive enhancement.\n\n2.  Terminology\n\n   The key words &quot;MUST&quot;, &quot;MUST NOT&quot;, &quot;REQUIRED&quot;, &quot;SHALL&quot;,\n   &quot;SHALL NOT&quot;, &quot;SHOULD&quot;, &quot;SHOULD NOT&quot;, &quot;RECOMMENDED&quot;, &quot;NOT\n   RECOMMENDED&quot;, &quot;MAY&quot;, and &quot;OPTIONAL&quot; in this document are to be\n   interpreted as described in BCP 14 [RFC2119] [RFC8174] when,\n   and only when, they appear in capitalized form, as shown here.\n\n   Agent:  An autonomous software system that uses one or more\n      large language models to make decisions and take actions\n      with limited or no human intervention per action.\n\n   Agent Audit Trail (AAT):  An ordered sequence of audit records\n      produced by an agent during a session, linked by hash\n      chaining.\n\n   Audit Record:  A single JSON object representing one logged\n      event in an agent&#x27;s operation.\n\n   Session:  A bounded sequence of agent operations that begins\n      with a genesis record and ends with a session close record.\n\n   Genesis Record:  The first record in a session, which has no\n      parent and establishes the chain root.\n\n   Tombstone Record:  A record that replaces a deleted record&#x27;s\n      content while preserving the hash chain.\n\n   Trust Level:  A classification from L0 (no verification) to\n      L4 (full mutual authentication with revocation checking)\n      as defined in [MCPS].\n\n   Action Type:  A controlled vocabulary value describing the\n      category of agent activity being logged.\n\n   Chain Hash:  The SHA-256 digest of the previous record&#x27;s\n      canonical JSON representation, linking records into a\n      tamper-evident sequence.\n\n3.  Audit Record Format\n\n   Each audit record is a JSON object.  Fields are divided into\n   mandatory (MUST be present in every record) and optional (MAY\n   be present based on the action type and deployment context).\n\n3.1.  Mandatory Fields\n\n   record_id:  String.  REQUIRED.  A UUID version 4 [RFC9562]\n      uniquely identifying this record.  Implementations MUST\n      generate a fresh UUIDv4 for each record.  Duplicate\n      record_id values within a session indicate a processing\n      error and MUST be flagged by validators.\n\n      Example: &quot;f47ac10b-58cc-4372-a567-0e02b2c3d479&quot;\n\n   timestamp:  String.  REQUIRED.  The time at which the event\n      occurred, formatted per RFC 3339 [RFC3339] with mandatory\n      UTC offset.  Implementations SHOULD use UTC (indicated by\n      &quot;Z&quot; suffix).  Millisecond precision is RECOMMENDED.\n      Microsecond precision is OPTIONAL.\n\n      Example: &quot;2026-03-29T14:30:00.123Z&quot;\n\n   agent_id:  String.  REQUIRED.  A URI [RFC3986] uniquely\n      identifying the agent instance.  This SHOULD be a\n      persistent identifier that survives agent restarts.  When\n      used with MCPS [MCPS], this MUST match the agent_id in the\n      Agent Passport.\n\n      Example: &quot;urn:agent:payment-bot.acme.example&quot;\n\n   agent_version:  String.  REQUIRED.  The semantic version\n      [SEMVER] of the agent software.  This allows correlation\n      of behavior changes with software updates.\n\n      Example: &quot;2.1.0&quot;\n\n   session_id:  String.  REQUIRED.  A UUID version 4 identifying\n      the current session.  All records within a single session\n      MUST share the same session_id.\n\n      Example: &quot;a1b2c3d4-e5f6-7890-abcd-ef1234567890&quot;\n\n   action_type:  String.  REQUIRED.  One of the registered\n      action type values defined in Section 5.  The initial\n      registry contains: &quot;tool_call&quot;, &quot;tool_response&quot;,\n      &quot;decision&quot;, &quot;delegation&quot;, &quot;escalation&quot;, &quot;error&quot;,\n      &quot;lifecycle&quot;.\n\n   action_detail:  Object.  REQUIRED.  A JSON object containing\n      action-type-specific fields as defined in Section 5.  The\n      structure of this object varies by action_type.  Unknown\n      fields within action_detail SHOULD be preserved by\n      processors.\n\n   outcome:  String.  REQUIRED.  The result of the action.  One\n      of the registered outcome values: &quot;success&quot;, &quot;failure&quot;,\n      &quot;timeout&quot;, &quot;denied&quot;, &quot;escalated&quot;.  See Section 12.2 for\n      the outcome registry.\n\n      o  &quot;success&quot;: The action completed as intended.\n\n      o  &quot;failure&quot;: The action did not complete due to an error.\n\n      o  &quot;timeout&quot;: The action exceeded its time budget.\n\n      o  &quot;denied&quot;: The action was blocked by a policy or\n         authorization check.\n\n      o  &quot;escalated&quot;: The action was redirected to a human or\n         higher-authority agent.\n\n   trust_level:  String.  REQUIRED.  The trust level at which\n      the agent was operating when this action occurred.  One of:\n      &quot;L0&quot;, &quot;L1&quot;, &quot;L2&quot;, &quot;L3&quot;, &quot;L4&quot;.\n\n      o  L0: No verification.  The agent has no cryptographic\n         identity.\n\n      o  L1: Self-signed identity.  The agent possesses a key\n         pair but no external attestation.\n\n      o  L2: Authority-signed identity.  A Trust Authority has\n         issued the agent&#x27;s passport.\n\n      o  L3: Mutual authentication.  Both parties have verified\n         each other&#x27;s identity.\n\n      o  L4: Full mutual authentication with revocation\n         checking and continuous monitoring.\n\n   parent_record_id:  String or null.  REQUIRED.  The record_id\n      of the immediately preceding record in the session chain.\n      For genesis records (the first record in a session), this\n      field MUST be null.  For all subsequent records, this MUST\n      contain the record_id of the previous record.\n\n   prev_hash:  String or null.  REQUIRED.  The SHA-256 hash of\n      the canonical JSON representation (per RFC 8785 [RFC8785])\n      of the previous record.  For genesis records, this field\n      MUST be null.  The hash MUST be encoded as a lowercase\n      hexadecimal string (64 characters).\n\n      Example: &quot;a7ffc6f8bf1ed76651c14756a061d662...&quot;\n\n3.2.  Optional Fields\n\n   The following fields are OPTIONAL and MAY be included in any\n   audit record:\n\n   human_override:  Object.  Present when a human intervened in\n      or overrode the agent&#x27;s action.  Contains:\n\n      o  &quot;operator_id&quot;: String.  An identifier for the human\n         operator (SHOULD be a pseudonym or role, not a real\n         name, for privacy).\n\n      o  &quot;reason&quot;: String.  Free-text explanation of the\n         override.\n\n      o  &quot;original_action&quot;: Object.  The action the agent would\n         have taken without intervention.\n\n   risk_score:  Number.  A value between 0.0 and 1.0 indicating\n      the agent&#x27;s assessed risk of the action.  0.0 indicates\n      minimal risk; 1.0 indicates maximum risk.\n\n   model_id:  String.  The identifier of the language model used\n      for the decision.  Example: &quot;gpt-4o-2025-03-01&quot; or\n      &quot;claude-sonnet-4-20250514&quot;.\n\n   input_hash:  String.  The SHA-256 hash of the input provided\n      to the agent for this action, encoded as lowercase\n      hexadecimal.  Used instead of raw input to preserve\n      privacy.\n\n   output_hash:  String.  The SHA-256 hash of the output\n      produced by the agent for this action, encoded as\n      lowercase hexadecimal.\n\n   latency_ms:  Number.  The wall-clock time in milliseconds\n      from action initiation to completion.\n\n   cost_estimate:  Object.  Estimated cost of the action:\n\n      o  &quot;amount&quot;: Number.  The monetary amount.\n\n      o  &quot;currency&quot;: String.  ISO 4217 currency code.\n\n      o  &quot;breakdown&quot;: Object.  Optional sub-costs (e.g.,\n         &quot;compute&quot;, &quot;api_calls&quot;, &quot;tokens&quot;).\n\n   sanctions_check:  Object.  Result of sanctions screening:\n\n      o  &quot;provider&quot;: String.  The screening provider.\n\n      o  &quot;checked_at&quot;: String.  RFC 3339 timestamp of check.\n\n      o  &quot;result&quot;: String.  One of &quot;clear&quot;, &quot;match&quot;, &quot;error&quot;.\n\n      o  &quot;list_version&quot;: String.  Version of the sanctions list.\n\n   jurisdiction:  String.  ISO 3166-1 alpha-2 country code\n      indicating the jurisdiction governing this action.\n\n   signature:  String.  An ECDSA P-256 signature over the\n      canonical JSON of this record (excluding the signature\n      field itself), encoded as Base64url per RFC 4648\n      Section 5.  See Section 4.2.\n\n3.3.  Field Constraints\n\n   The following constraints apply to all audit records:\n\n   o  All string fields MUST be valid UTF-8.\n\n   o  The total size of a single audit record SHOULD NOT exceed\n      64 KB when serialized as JSON.  Records exceeding 256 KB\n      MUST be rejected by validators.\n\n   o  Timestamps MUST NOT be backdated.  The timestamp of record\n      N+1 MUST be greater than or equal to the timestamp of\n      record N within the same session.\n\n   o  The action_detail object MUST contain at least one field\n      relevant to the action_type.\n\n   o  Implementations MUST NOT add fields with names beginning\n      with &quot;aat_&quot; to action_detail, as this prefix is reserved\n      for future extensions of this specification.\n\n4.  Tamper-Evident Chaining\n\n4.1.  Hash Computation\n\n   The prev_hash field creates a tamper-evident chain across all\n   records in a session.  The hash is computed as follows:\n\n   1.  Take the complete JSON object of the previous record,\n       INCLUDING all fields (mandatory and optional) that were\n       present in the record as stored.\n\n   2.  Serialize the JSON object using the JSON Canonicalization\n       Scheme (JCS) defined in RFC 8785 [RFC8785].  JCS\n       produces a deterministic byte sequence from any JSON\n       value.\n\n   3.  Compute the SHA-256 hash of the canonical byte sequence.\n\n   4.  Encode the resulting 32-byte hash as a 64-character\n       lowercase hexadecimal string.\n\n   The formula is:\n\n       prev_hash(N) = hex(SHA-256(JCS(record(N-1))))\n\n   For the genesis record (N=0), prev_hash MUST be null.\n\n   Implementations MUST use JCS (RFC 8785) for canonicalization.\n   Alternative canonicalization schemes MUST NOT be used, as they\n   would break chain verification across implementations.\n\n4.2.  Signature Envelope\n\n   When cryptographic non-repudiation is required, records MAY\n   include an ECDSA P-256 signature.  The signing procedure is:\n\n   1.  Construct the complete audit record with all fields\n       EXCEPT the &quot;signature&quot; field.\n\n   2.  Serialize using JCS (RFC 8785).\n\n   3.  Compute SHA-256 of the canonical bytes.\n\n   4.  Sign the hash using ECDSA P-256 with the agent&#x27;s private\n       key, per FIPS 186-5 [FIPS186-5].\n\n   5.  Encode the signature as Base64url (RFC 4648 Section 5)\n       using IEEE P1363 fixed-length r||s encoding (64 bytes\n       total: 32 bytes r, 32 bytes s).\n\n   6.  Add the &quot;signature&quot; field to the record.\n\n   When verifying, the verifier MUST remove the &quot;signature&quot; field\n   before computing the hash for comparison.\n\n   Note: When both prev_hash and signature are present, prev_hash\n   is computed over the COMPLETE previous record INCLUDING its\n   signature field.  Only the current record&#x27;s signature is\n   excluded during signing of the current record.\n\n   When used with MCPS [MCPS], the signing key SHOULD be the same\n   key used in the agent&#x27;s Agent Passport, providing a direct\n   binding between audit records and cryptographic identity.\n\n4.3.  Chain Verification\n\n   To verify a session&#x27;s audit trail integrity, a verifier MUST:\n\n   1.  Confirm the first record has parent_record_id = null and\n       prev_hash = null.\n\n   2.  For each subsequent record N (where N &gt; 0):\n\n       a.  Compute hex(SHA-256(JCS(record(N-1)))).\n\n       b.  Compare the computed hash with record(N).prev_hash.\n\n       c.  If the values differ, the chain is broken at\n           record N and the trail MUST be flagged as tampered.\n\n   3.  If signatures are present, verify each signature using\n       the agent&#x27;s public key.\n\n   4.  Verify that timestamps are monotonically non-decreasing.\n\n   5.  Verify that parent_record_id of record N equals the\n       record_id of record N-1.\n\n   A chain verification failure MUST be reported as a critical\n   integrity error.  Partial chain verification (e.g., verifying\n   only the last K records) is NOT RECOMMENDED but MAY be used\n   for performance reasons if the full chain has been previously\n   verified.\n\n5.  Action Type Definitions\n\n   Each action type defines a specific structure for the\n   action_detail object.\n\n5.1.  tool_call\n\n   Logged when the agent invokes an external tool or API.\n\n   action_detail fields:\n\n   o  &quot;tool_name&quot;: String.  REQUIRED.  The name of the tool\n      being called.\n\n   o  &quot;tool_server&quot;: String.  OPTIONAL.  URI of the MCP server\n      or API endpoint providing the tool.\n\n   o  &quot;parameters_hash&quot;: String.  REQUIRED.  SHA-256 hash of\n      the serialized parameters sent to the tool.\n\n   o  &quot;tool_version&quot;: String.  OPTIONAL.  Version of the tool\n      definition.\n\n   o  &quot;authorization&quot;: String.  OPTIONAL.  The authorization\n      mechanism used (e.g., &quot;bearer_token&quot;, &quot;api_key&quot;,\n      &quot;mutual_tls&quot;).\n\n5.2.  tool_response\n\n   Logged when the agent receives a response from a tool.\n\n   action_detail fields:\n\n   o  &quot;tool_name&quot;: String.  REQUIRED.  The name of the tool\n      that responded.\n\n   o  &quot;response_hash&quot;: String.  REQUIRED.  SHA-256 hash of\n      the response payload.\n\n   o  &quot;response_size&quot;: Number.  OPTIONAL.  Size of the response\n      in bytes.\n\n   o  &quot;parent_call_id&quot;: String.  REQUIRED.  The record_id of\n      the corresponding tool_call record.\n\n5.3.  decision\n\n   Logged when the agent makes an autonomous decision.\n\n   action_detail fields:\n\n   o  &quot;decision_type&quot;: String.  REQUIRED.  Category of decision\n      (e.g., &quot;route&quot;, &quot;approve&quot;, &quot;reject&quot;, &quot;classify&quot;,\n      &quot;generate&quot;).\n\n   o  &quot;reasoning_hash&quot;: String.  OPTIONAL.  SHA-256 hash of the\n      agent&#x27;s reasoning chain or chain-of-thought.\n\n   o  &quot;confidence&quot;: Number.  OPTIONAL.  Confidence score between\n      0.0 and 1.0.\n\n   o  &quot;alternatives_considered&quot;: Number.  OPTIONAL.  Count of\n      alternative actions the agent evaluated.\n\n   o  &quot;policy_ref&quot;: String.  OPTIONAL.  Identifier of the\n      policy or rule that governed this decision.\n\n5.4.  delegation\n\n   Logged when the agent delegates work to another agent.\n\n   action_detail fields:\n\n   o  &quot;delegate_agent_id&quot;: String.  REQUIRED.  URI of the agent\n      receiving the delegation.\n\n   o  &quot;delegate_trust_level&quot;: String.  REQUIRED.  Trust level\n      of the delegate agent.\n\n   o  &quot;task_description_hash&quot;: String.  REQUIRED.  SHA-256 hash\n      of the delegated task description.\n\n   o  &quot;constraints&quot;: Array of String.  OPTIONAL.  Constraints\n      imposed on the delegate.\n\n   o  &quot;timeout_ms&quot;: Number.  OPTIONAL.  Maximum time allowed\n      for the delegate to complete the task.\n\n5.5.  escalation\n\n   Logged when the agent escalates to a human operator or\n   higher-authority system.\n\n   action_detail fields:\n\n   o  &quot;escalation_reason&quot;: String.  REQUIRED.  Why the agent\n      escalated (e.g., &quot;confidence_below_threshold&quot;,\n      &quot;policy_requires_human&quot;, &quot;risk_score_exceeded&quot;,\n      &quot;error_recovery&quot;).\n\n   o  &quot;escalation_target&quot;: String.  REQUIRED.  Identifier of\n      the human or system receiving the escalation.\n\n   o  &quot;context_hash&quot;: String.  OPTIONAL.  SHA-256 hash of the\n      context provided to the escalation target.\n\n   o  &quot;urgency&quot;: String.  OPTIONAL.  One of &quot;low&quot;, &quot;medium&quot;,\n      &quot;high&quot;, &quot;critical&quot;.\n\n5.6.  error\n\n   Logged when the agent encounters an error condition.\n\n   action_detail fields:\n\n   o  &quot;error_code&quot;: String.  REQUIRED.  A machine-readable\n      error code.\n\n   o  &quot;error_message&quot;: String.  REQUIRED.  A human-readable\n      error description.\n\n   o  &quot;error_category&quot;: String.  REQUIRED.  One of &quot;transport&quot;,\n      &quot;authentication&quot;, &quot;authorization&quot;, &quot;validation&quot;,\n      &quot;timeout&quot;, &quot;internal&quot;, &quot;external&quot;.\n\n   o  &quot;recoverable&quot;: Boolean.  REQUIRED.  Whether the agent\n      can continue operating after this error.\n\n   o  &quot;stack_hash&quot;: String.  OPTIONAL.  SHA-256 hash of the\n      stack trace, for debugging without exposing internals.\n\n5.7.  lifecycle\n\n   Logged for agent lifecycle events (start, stop, pause,\n   configuration changes).\n\n   action_detail fields:\n\n   o  &quot;event&quot;: String.  REQUIRED.  One of &quot;session_start&quot;,\n      &quot;session_end&quot;, &quot;pause&quot;, &quot;resume&quot;,\n      &quot;configuration_change&quot;, &quot;key_rotation&quot;,\n      &quot;trust_level_change&quot;.\n\n   o  &quot;previous_state&quot;: String.  OPTIONAL.  The state before\n      this lifecycle event.\n\n   o  &quot;new_state&quot;: String.  OPTIONAL.  The state after this\n      lifecycle event.\n\n   o  &quot;trigger&quot;: String.  OPTIONAL.  What caused the lifecycle\n      event (e.g., &quot;scheduled&quot;, &quot;manual&quot;, &quot;policy&quot;,\n      &quot;error_recovery&quot;).\n\n6.  Session Structure\n\n6.1.  Genesis Record\n\n   Every session MUST begin with a genesis record.  The genesis\n   record has the following characteristics:\n\n   o  action_type MUST be &quot;lifecycle&quot;.\n\n   o  action_detail.event MUST be &quot;session_start&quot;.\n\n   o  parent_record_id MUST be null.\n\n   o  prev_hash MUST be null.\n\n   o  The action_detail SHOULD include the agent&#x27;s configuration\n      hash, enabled tools list, and operating parameters to\n      establish a baseline for the session.\n\n   Example genesis action_detail:\n\n       {\n         &quot;event&quot;: &quot;session_start&quot;,\n         &quot;new_state&quot;: &quot;active&quot;,\n         &quot;trigger&quot;: &quot;scheduled&quot;,\n         &quot;config_hash&quot;: &quot;b5bb9d8014a0f9b1d6...&quot;,\n         &quot;enabled_tools&quot;: [\n           &quot;payment_transfer&quot;,\n           &quot;sanctions_check&quot;,\n           &quot;balance_query&quot;\n         ]\n       }\n\n6.2.  Ordered Chain\n\n   After the genesis record, all records MUST form a strictly\n   ordered chain:\n\n   o  Each record&#x27;s parent_record_id MUST equal the previous\n      record&#x27;s record_id.\n\n   o  Each record&#x27;s prev_hash MUST equal\n      hex(SHA-256(JCS(previous_record))).\n\n   o  Timestamps MUST be monotonically non-decreasing.\n\n   o  No gaps in the chain are permitted.  If a record cannot\n      be produced (e.g., due to a crash), a recovery record\n      with action_type &quot;error&quot; MUST be inserted to document the\n      gap when the agent resumes.\n\n   Branching (multiple records claiming the same parent) is NOT\n   permitted within a single session.  If an agent forks into\n   parallel execution paths, each path MUST use a separate\n   session_id and the delegation record in the parent session\n   MUST reference the child session_id.\n\n6.3.  Session Close\n\n   Every session SHOULD end with a close record.  The close\n   record has the following characteristics:\n\n   o  action_type MUST be &quot;lifecycle&quot;.\n\n   o  action_detail.event MUST be &quot;session_end&quot;.\n\n   o  action_detail MUST include a &quot;session_hash&quot; field\n      containing the SHA-256 hash of the concatenation of all\n      record hashes in the session, in order:\n\n       session_hash = hex(SHA-256(\n         prev_hash(1) || prev_hash(2) || ... || prev_hash(N)\n       ))\n\n      where N is the close record itself and prev_hash values\n      are the raw 32-byte digests (not hex-encoded) prior to\n      concatenation.\n\n   o  action_detail SHOULD include &quot;record_count&quot; (integer)\n      and &quot;duration_ms&quot; (number) summarizing the session.\n\n   If an agent terminates abnormally without producing a close\n   record, the session is considered &quot;orphaned.&quot;  Monitoring\n   systems SHOULD detect orphaned sessions and produce a\n   synthetic close record with outcome &quot;failure&quot; and\n   action_detail.trigger &quot;crash_recovery&quot;.\n\n7.  Retention Requirements\n\n7.1.  High-Risk Systems\n\n   For AI systems classified as high-risk under the EU AI Act\n   (Annex III), audit trail records SHOULD be retained for a\n   minimum of 12 months from the session close timestamp.\n\n   This aligns with Article 12(1) which states that logging\n   capabilities shall be such that logs are kept for a period\n   appropriate to the intended purpose of the high-risk AI\n   system, of at least six months unless provided otherwise in\n   applicable Union or national law.\n\n   The 12-month RECOMMENDATION in this specification exceeds the\n   minimum 6-month requirement to account for audit cycles and\n   incident investigation timelines.\n\n7.2.  General-Purpose Systems\n\n   For AI systems not classified as high-risk, audit trail\n   records SHOULD be retained for a minimum of 6 months from\n   the session close timestamp.\n\n   Deployments subject to financial regulations (e.g., PCI DSS,\n   SOC 2) MAY require longer retention periods as specified by\n   those frameworks.\n\n7.3.  Tombstone Records\n\n   When individual records must be deleted (e.g., pursuant to\n   GDPR Article 17 right to erasure), the record MUST be\n   replaced with a tombstone record that preserves chain\n   integrity.  A tombstone record:\n\n   o  Retains the original record_id, timestamp,\n      parent_record_id, and prev_hash.\n\n   o  Sets action_type to &quot;lifecycle&quot;.\n\n   o  Sets action_detail to:\n\n       {\n         &quot;event&quot;: &quot;record_deleted&quot;,\n         &quot;deletion_reason&quot;: &quot;gdpr_art17&quot;,\n         &quot;deleted_at&quot;: &quot;2026-06-15T10:00:00Z&quot;,\n         &quot;original_action_type&quot;: &quot;tool_call&quot;\n       }\n\n   o  Sets outcome to &quot;success&quot;.\n\n   o  Retains the signature field if originally present.\n\n   The original record&#x27;s content is destroyed.  Because the\n   tombstone preserves the original record_id and prev_hash,\n   subsequent records in the chain remain verifiable.  However,\n   the prev_hash of the NEXT record will no longer match the\n   tombstone (since the content changed).  To handle this,\n   implementations MUST also store a &quot;tombstone_hash&quot; field in\n   the tombstone record containing the original record&#x27;s hash,\n   allowing validators to accept the chain break.\n\n8.  Export Formats\n\n   Implementations MUST support at least one export format.\n   JSONL is the RECOMMENDED primary format.\n\n8.1.  JSONL (Primary)\n\n   The primary export format is JSON Lines (JSONL), where each\n   line contains exactly one complete audit record serialized\n   as JSON.  Lines are separated by a single newline character\n   (U+000A).\n\n   o  Each line MUST be a valid JSON object.\n\n   o  The order of lines MUST match the chain order\n      (genesis first, close last).\n\n   o  The file SHOULD use UTF-8 encoding without a byte order\n      mark (BOM).\n\n   o  The file extension SHOULD be &quot;.jsonl&quot;.\n\n8.2.  Syslog (RFC 5424)\n\n   For integration with existing logging infrastructure, audit\n   records MAY be exported as Syslog messages per RFC 5424\n   [RFC5424].  The mapping is:\n\n   o  FACILITY: local0 (16).\n\n   o  SEVERITY: based on outcome -- success=6 (Informational),\n      failure=3 (Error), timeout=4 (Warning),\n      denied=5 (Notice), escalated=5 (Notice).\n\n   o  APP-NAME: the agent_id (truncated to 48 characters).\n\n   o  MSGID: the action_type.\n\n   o  STRUCTURED-DATA: SD-ID &quot;aat@IANA-PEN&quot; containing\n      record_id, session_id, trust_level, prev_hash.\n\n   o  MSG: JSON serialization of the full audit record.\n\n   The prev_hash and chain integrity MUST be preserved in the\n   structured data to enable reconstruction of the chain from\n   Syslog archives.\n\n8.3.  CSV\n\n   For human review and spreadsheet analysis, audit records MAY\n   be exported as CSV per RFC 4180 [RFC4180].  The mapping is:\n\n   o  Header row: record_id, timestamp, agent_id,\n      agent_version, session_id, action_type, outcome,\n      trust_level, parent_record_id, prev_hash, action_detail.\n\n   o  The action_detail column contains the JSON serialization\n      of the action_detail object.\n\n   o  CSV export is inherently lossy for optional fields.\n      Implementations SHOULD document which optional fields\n      are included.\n\n   CSV exports MUST NOT be used as the authoritative record.\n   The JSONL format MUST be retained as the source of truth.\n\n9.  Regulatory Mapping\n\n9.1.  EU AI Act\n\n   The following table maps AAT features to EU AI Act articles:\n\n   Article 12 (Record-Keeping):\n      AAT provides automatic recording via the mandatory audit\n      record format (Section 3).  Hash chaining (Section 4)\n      ensures records &quot;allow the tracing back of the AI system&#x27;s\n      operation.&quot;  The session structure (Section 6) provides the\n      &quot;period of each use&quot; required by Art 12(1)(c).\n\n   Article 13 (Transparency):\n      The action_type taxonomy (Section 5) and decision records\n      (Section 5.3) provide interpretability of agent behavior.\n      The model_id field documents which model was used.\n      The human_override field documents human interventions.\n\n   Article 14 (Human Oversight):\n      The escalation action type (Section 5.5) documents when\n      and why agents escalated to humans.  The human_override\n      optional field (Section 3.2) captures human interventions.\n      Trust levels document the degree of autonomous operation.\n\n   Article 72 (Reporting):\n      The export formats (Section 8) enable provision of logs\n      to national competent authorities.  The session_hash in\n      session close records (Section 6.3) provides a verifiable\n      summary for regulatory reporting.\n\n9.2.  SOC 2\n\n   SOC 2 Trust Services Criteria relevant to AAT:\n\n   o  CC6.1 (Logical Access): trust_level and authorization\n      fields document access controls.\n\n   o  CC7.2 (System Monitoring): Continuous audit trail with\n      tamper-evident chaining satisfies monitoring requirements.\n\n   o  CC8.1 (Change Management): lifecycle action type records\n      document configuration changes.\n\n9.3.  ISO/IEC 42001\n\n   ISO/IEC 42001 (AI Management System) clauses addressed:\n\n   o  Clause 6.1.2 (AI Risk Assessment): risk_score and\n      decision records support risk documentation.\n\n   o  Clause 8.4 (AI System Operation): Full session audit\n      trails document operational behavior.\n\n   o  Clause 9.1 (Monitoring): Continuous logging with chain\n      verification supports monitoring requirements.\n\n9.4.  PCI DSS v4.0.1\n\n   PCI DSS v4.0.1 requirements addressed by AAT:\n\n   o  Requirement 10.2: AAT provides audit logs for all agent\n      actions including tool calls, decisions, and errors.\n\n   o  Requirement 10.3: Record fields (timestamp, agent_id,\n      action_type, outcome) map directly to required audit\n      trail entries.\n\n   o  Requirement 10.5: Hash chaining and optional signatures\n      protect audit trail integrity.\n\n   o  Requirement 10.7: Retention requirements (Section 7)\n      align with PCI DSS retention periods.\n\n10.  Privacy Considerations\n\n10.1.  Data Minimization\n\n   AAT is designed with privacy by default:\n\n   o  Raw input and output data MUST NOT be stored in audit\n      records.  Implementations MUST use the input_hash and\n      output_hash fields instead.\n\n   o  The human_override.operator_id SHOULD be a pseudonymous\n      identifier or role name, not a natural person&#x27;s name.\n\n   o  The reasoning_hash field in decision records stores a hash\n      of the reasoning chain, not the reasoning itself.\n\n   o  Tool parameters are recorded via parameters_hash, not in\n      cleartext.\n\n   o  Sanctions check results record only &quot;clear&quot;, &quot;match&quot;, or\n      &quot;error&quot; -- not the details of what was screened.\n\n   Implementations that need to retain raw data for debugging\n   MUST store it in a separate system with appropriate access\n   controls, linked to the audit trail via record_id.\n\n10.2.  Right to Erasure\n\n   To support GDPR Article 17 (right to erasure) and similar\n   regulations, AAT uses tombstone records (Section 7.3) rather\n   than record deletion.  This approach:\n\n   o  Removes all personal data from the record.\n\n   o  Preserves chain integrity for regulatory compliance.\n\n   o  Documents the fact and reason for deletion.\n\n   o  Is compatible with the EU AI Act&#x27;s record-keeping\n      requirements, which do not require retention of personal\n      data but do require retention of operational logs.\n\n   Data controllers MUST implement a process to identify which\n   audit records contain personal data (even in hashed form) and\n   respond to erasure requests by creating tombstone records\n   within 30 days.\n\n11.  Security Considerations\n\n11.1.  Log Tampering\n\n   The primary threat to audit trails is unauthorized\n   modification.  AAT mitigates this through:\n\n   o  Hash chaining: Any modification to a record invalidates\n      all subsequent prev_hash values, making tampering\n      detectable.\n\n   o  Optional signatures: ECDSA P-256 signatures provide\n      non-repudiation and prevent even the log storage system\n      from undetectably modifying records.\n\n   o  Session hashes: The session_hash in close records provides\n      a single value that can be stored externally (e.g., on a\n      blockchain or with a timestamp authority) to anchor the\n      entire session.\n\n   Implementations SHOULD store session_hash values in a\n   separate, append-only system to provide an independent\n   verification point.\n\n11.2.  Log Injection\n\n   Attackers may attempt to inject false audit records into the\n   trail.  Mitigations include:\n\n   o  Signature verification: When signatures are present, only\n      records signed by the agent&#x27;s key are valid.\n\n   o  Chain continuity: Injected records would break the hash\n      chain unless the attacker can also modify all subsequent\n      records.\n\n   o  Timestamp monotonicity: Injected records with out-of-\n      order timestamps are detectable.\n\n   o  Record size limits: The 256 KB maximum prevents denial-of-\n      service through oversized records.\n\n   Implementations MUST validate all records against the schema\n   before accepting them into the audit trail.\n\n11.3.  Timing Attacks\n\n   Audit record timestamps may be manipulated if the agent\n   controls its own clock.  Mitigations include:\n\n   o  Using NTP-synchronized clocks with drift monitoring.\n\n   o  Cross-referencing timestamps with external systems (e.g.,\n      tool server response timestamps).\n\n   o  Flagging sessions where timestamps show suspicious\n      patterns (e.g., large jumps, regression).\n\n   Implementations SHOULD monitor for timestamp anomalies and\n   flag them for human review.\n\n11.4.  Chain Breaks\n\n   Chain breaks can occur due to:\n\n   o  System crashes during record writing.\n\n   o  Storage corruption.\n\n   o  Intentional tampering.\n\n   When a chain break is detected, implementations MUST:\n\n   1.  Flag the break with a severity of &quot;critical&quot;.\n\n   2.  Record the break location (which record pair failed\n       verification).\n\n   3.  Preserve both the broken chain and any recovered data.\n\n   4.  If the break is due to crash recovery, insert an error\n       record documenting the gap.\n\n   Chain breaks in high-risk systems MUST trigger an alert to\n   the system operator within 1 hour.\n\n12.  IANA Considerations\n\n12.1.  Action Type Registry\n\n   This document requests IANA to create the &quot;Agent Audit Trail\n   Action Types&quot; registry.  The registration policy is\n   &quot;Specification Required&quot; per RFC 8126 [RFC8126].\n\n   Initial registry contents:\n\n   +----------------+---------------------------+-----------+\n   | Value          | Description               | Reference |\n   +----------------+---------------------------+-----------+\n   | tool_call      | Agent invokes a tool      | Sec 5.1   |\n   | tool_response  | Agent receives tool reply  | Sec 5.2   |\n   | decision       | Agent makes a decision    | Sec 5.3   |\n   | delegation     | Agent delegates to agent  | Sec 5.4   |\n   | escalation     | Agent escalates to human  | Sec 5.5   |\n   | error          | Agent encounters error    | Sec 5.6   |\n   | lifecycle      | Agent lifecycle event     | Sec 5.7   |\n   +----------------+---------------------------+-----------+\n\n   New entries MUST include a value (lowercase ASCII string,\n   max 32 characters), description, and reference to a published\n   specification.\n\n12.2.  Outcome Registry\n\n   This document requests IANA to create the &quot;Agent Audit Trail\n   Outcomes&quot; registry.  The registration policy is &quot;Specification\n   Required&quot; per RFC 8126.\n\n   Initial registry contents:\n\n   +------------+-------------------------------+-----------+\n   | Value      | Description                   | Reference |\n   +------------+-------------------------------+-----------+\n   | success    | Action completed as intended  | Sec 3.1   |\n   | failure    | Action failed due to error    | Sec 3.1   |\n   | timeout    | Action exceeded time budget   | Sec 3.1   |\n   | denied     | Action blocked by policy      | Sec 3.1   |\n   | escalated  | Action redirected to human    | Sec 3.1   |\n   +------------+-------------------------------+-----------+\n\n13.  References\n\n13.1.  Normative References\n\n   [RFC2119]  Bradner, S., &quot;Key words for use in RFCs to Indicate\n              Requirement Levels&quot;, BCP 14, RFC 2119,\n              DOI 10.17487/RFC2119, March 1997,\n              &lt;https://www.rfc-editor.org/info/rfc2119&gt;.\n\n   [RFC3339]  Klyne, G. and C. Newman, &quot;Date and Time on the\n              Internet: Timestamps&quot;, RFC 3339,\n              DOI 10.17487/RFC3339, July 2002,\n              &lt;https://www.rfc-editor.org/info/rfc3339&gt;.\n\n   [RFC3986]  Berners-Lee, T., Fielding, R., and L. Masinter,\n              &quot;Uniform Resource Identifier (URI): Generic Syntax&quot;,\n              STD 66, RFC 3986, DOI 10.17487/RFC3986,\n              January 2005,\n              &lt;https://www.rfc-editor.org/info/rfc3986&gt;.\n\n   [RFC8174]  Leiba, B., &quot;Ambiguity of Uppercase vs Lowercase in\n              RFC 2119 Key Words&quot;, BCP 14, RFC 8174,\n              DOI 10.17487/RFC8174, May 2017,\n              &lt;https://www.rfc-editor.org/info/rfc8174&gt;.\n\n   [RFC8785]  Rundgren, A., Jordan, B., and S. Erdtman, &quot;JSON\n              Canonicalization Scheme (JCS)&quot;, RFC 8785,\n              DOI 10.17487/RFC8785, June 2020,\n              &lt;https://www.rfc-editor.org/info/rfc8785&gt;.\n\n   [RFC9562]  Davis, K., Peabody, B., and P. Leach, &quot;Universally\n              Unique IDentifiers (UUIDs)&quot;, RFC 9562,\n              DOI 10.17487/RFC9562, May 2024,\n              &lt;https://www.rfc-editor.org/info/rfc9562&gt;.\n\n   [FIPS186-5]\n              National Institute of Standards and Technology,\n              &quot;Digital Signature Standard (DSS)&quot;, FIPS PUB 186-5,\n              DOI 10.6028/NIST.FIPS.186-5, February 2023.\n\n   [RFC8126]  Cotton, M., Leiba, B., and T. Narten, &quot;Guidelines\n              for Writing an IANA Considerations Section in RFCs&quot;,\n              BCP 26, RFC 8126, DOI 10.17487/RFC8126, June 2017,\n              &lt;https://www.rfc-editor.org/info/rfc8126&gt;.\n\n13.2.  Informative References\n\n   [MCPS]     Sharif, R., &quot;MCPS: Cryptographic Security Layer for\n              the Model Context Protocol&quot;,\n              draft-sharif-mcps-secure-mcp-02, March 2026.\n\n   [EU-AI-ACT]\n              European Parliament and Council, &quot;Regulation (EU)\n              2024/1689 laying down harmonised rules on artificial\n              intelligence (Artificial Intelligence Act)&quot;,\n              Official Journal of the European Union, L series,\n              2024/1689, August 2024.\n\n   [RFC5424]  Gerhards, R., &quot;The Syslog Protocol&quot;, RFC 5424,\n              DOI 10.17487/RFC5424, March 2009,\n              &lt;https://www.rfc-editor.org/info/rfc5424&gt;.\n\n   [RFC4180]  Shafranovich, Y., &quot;Common Format and MIME Type for\n              Comma-Separated Values (CSV) Files&quot;, RFC 4180,\n              DOI 10.17487/RFC4180, October 2005,\n              &lt;https://www.rfc-editor.org/info/rfc4180&gt;.\n\n   [RFC4648]  Josefsson, S., &quot;The Base16, Base32, and Base64 Data\n              Encodings&quot;, RFC 4648, DOI 10.17487/RFC4648,\n              October 2006,\n              &lt;https://www.rfc-editor.org/info/rfc4648&gt;.\n\n   [ISO42001] International Organization for Standardization,\n              &quot;Information technology -- Artificial intelligence --\n              Management system&quot;, ISO/IEC 42001:2023, December\n              2023.\n\n   [PCI-DSS]  PCI Security Standards Council, &quot;Payment Card\n              Industry Data Security Standard Version 4.0.1&quot;,\n              June 2024.\n\n   [SOC2]     American Institute of Certified Public Accountants,\n              &quot;SOC 2 -- SOC for Service Organizations: Trust\n              Services Criteria&quot;, 2017.\n\n   [SEMVER]   Preston-Werner, T., &quot;Semantic Versioning 2.0.0&quot;,\n              &lt;https://semver.org/&gt;.\n\n<span>Appendix A.  Example Audit Trail</span>\n\n   The following example shows a complete audit trail for a\n   payment agent session that processes a GBP 500 transfer.\n   The session demonstrates tool calls, decisions, sanctions\n   screening, and successful completion.  prev_hash values are\n   truncated for readability (shown as first 16 hex characters).\n\n   Record 1: Genesis (session start)\n\n   {\n     &quot;record_id&quot;: &quot;a1000000-0000-4000-8000-000000000001&quot;,\n     &quot;timestamp&quot;: &quot;2026-03-29T14:00:00.000Z&quot;,\n     &quot;agent_id&quot;: &quot;urn:agent:payment-bot.acme.example&quot;,\n     &quot;agent_version&quot;: &quot;2.1.0&quot;,\n     &quot;session_id&quot;: &quot;sess-29mar-0001-4000-8000-abcdef123456&quot;,\n     &quot;action_type&quot;: &quot;lifecycle&quot;,\n     &quot;action_detail&quot;: {\n       &quot;event&quot;: &quot;session_start&quot;,\n       &quot;new_state&quot;: &quot;active&quot;,\n       &quot;trigger&quot;: &quot;api_request&quot;,\n       &quot;config_hash&quot;: &quot;b5bb9d8014a0f9b1...&quot;,\n       &quot;enabled_tools&quot;: [\n         &quot;payment_transfer&quot;,\n         &quot;sanctions_check&quot;,\n         &quot;balance_query&quot;\n       ]\n     },\n     &quot;outcome&quot;: &quot;success&quot;,\n     &quot;trust_level&quot;: &quot;L2&quot;,\n     &quot;parent_record_id&quot;: null,\n     &quot;prev_hash&quot;: null\n   }\n\n   Record 2: Sanctions screening tool call\n\n   {\n     &quot;record_id&quot;: &quot;a1000000-0000-4000-8000-000000000002&quot;,\n     &quot;timestamp&quot;: &quot;2026-03-29T14:00:00.150Z&quot;,\n     &quot;agent_id&quot;: &quot;urn:agent:payment-bot.acme.example&quot;,\n     &quot;agent_version&quot;: &quot;2.1.0&quot;,\n     &quot;session_id&quot;: &quot;sess-29mar-0001-4000-8000-abcdef123456&quot;,\n     &quot;action_type&quot;: &quot;tool_call&quot;,\n     &quot;action_detail&quot;: {\n       &quot;tool_name&quot;: &quot;sanctions_check&quot;,\n       &quot;tool_server&quot;: &quot;https://screening.acme.example/v2&quot;,\n       &quot;parameters_hash&quot;: &quot;e3b0c44298fc1c14...&quot;,\n       &quot;authorization&quot;: &quot;mutual_tls&quot;\n     },\n     &quot;outcome&quot;: &quot;success&quot;,\n     &quot;trust_level&quot;: &quot;L2&quot;,\n     &quot;parent_record_id&quot;:\n       &quot;a1000000-0000-4000-8000-000000000001&quot;,\n     &quot;prev_hash&quot;: &quot;7d865e959b2466918a...&quot;,\n     &quot;input_hash&quot;: &quot;9f86d081884c7d659a...&quot;,\n     &quot;latency_ms&quot;: 145\n   }\n\n   Record 3: Sanctions screening response\n\n   {\n     &quot;record_id&quot;: &quot;a1000000-0000-4000-8000-000000000003&quot;,\n     &quot;timestamp&quot;: &quot;2026-03-29T14:00:00.295Z&quot;,\n     &quot;agent_id&quot;: &quot;urn:agent:payment-bot.acme.example&quot;,\n     &quot;agent_version&quot;: &quot;2.1.0&quot;,\n     &quot;session_id&quot;: &quot;sess-29mar-0001-4000-8000-abcdef123456&quot;,\n     &quot;action_type&quot;: &quot;tool_response&quot;,\n     &quot;action_detail&quot;: {\n       &quot;tool_name&quot;: &quot;sanctions_check&quot;,\n       &quot;response_hash&quot;: &quot;2cf24dba5fb0a301...&quot;,\n       &quot;response_size&quot;: 256,\n       &quot;parent_call_id&quot;:\n         &quot;a1000000-0000-4000-8000-000000000002&quot;\n     },\n     &quot;outcome&quot;: &quot;success&quot;,\n     &quot;trust_level&quot;: &quot;L2&quot;,\n     &quot;parent_record_id&quot;:\n       &quot;a1000000-0000-4000-8000-000000000002&quot;,\n     &quot;prev_hash&quot;: &quot;4e07408562bedb8b6...&quot;,\n     &quot;sanctions_check&quot;: {\n       &quot;provider&quot;: &quot;acme_screening&quot;,\n       &quot;checked_at&quot;: &quot;2026-03-29T14:00:00.290Z&quot;,\n       &quot;result&quot;: &quot;clear&quot;,\n       &quot;list_version&quot;: &quot;2026-03-29&quot;\n     }\n   }\n\n   Record 4: Decision to approve transfer\n\n   {\n     &quot;record_id&quot;: &quot;a1000000-0000-4000-8000-000000000004&quot;,\n     &quot;timestamp&quot;: &quot;2026-03-29T14:00:00.310Z&quot;,\n     &quot;agent_id&quot;: &quot;urn:agent:payment-bot.acme.example&quot;,\n     &quot;agent_version&quot;: &quot;2.1.0&quot;,\n     &quot;session_id&quot;: &quot;sess-29mar-0001-4000-8000-abcdef123456&quot;,\n     &quot;action_type&quot;: &quot;decision&quot;,\n     &quot;action_detail&quot;: {\n       &quot;decision_type&quot;: &quot;approve&quot;,\n       &quot;reasoning_hash&quot;: &quot;6b86b273ff34fce1...&quot;,\n       &quot;confidence&quot;: 0.97,\n       &quot;alternatives_considered&quot;: 2,\n       &quot;policy_ref&quot;: &quot;payment-policy-v3.2&quot;\n     },\n     &quot;outcome&quot;: &quot;success&quot;,\n     &quot;trust_level&quot;: &quot;L2&quot;,\n     &quot;parent_record_id&quot;:\n       &quot;a1000000-0000-4000-8000-000000000003&quot;,\n     &quot;prev_hash&quot;: &quot;ef2d127de37b942ba...&quot;,\n     &quot;risk_score&quot;: 0.12,\n     &quot;model_id&quot;: &quot;claude-sonnet-4-20250514&quot;,\n     &quot;cost_estimate&quot;: {\n       &quot;amount&quot;: 500.00,\n       &quot;currency&quot;: &quot;GBP&quot;\n     }\n   }\n\n   Record 5: Payment execution tool call\n\n   {\n     &quot;record_id&quot;: &quot;a1000000-0000-4000-8000-000000000005&quot;,\n     &quot;timestamp&quot;: &quot;2026-03-29T14:00:00.320Z&quot;,\n     &quot;agent_id&quot;: &quot;urn:agent:payment-bot.acme.example&quot;,\n     &quot;agent_version&quot;: &quot;2.1.0&quot;,\n     &quot;session_id&quot;: &quot;sess-29mar-0001-4000-8000-abcdef123456&quot;,\n     &quot;action_type&quot;: &quot;tool_call&quot;,\n     &quot;action_detail&quot;: {\n       &quot;tool_name&quot;: &quot;payment_transfer&quot;,\n       &quot;tool_server&quot;: &quot;https://payments.acme.example/v1&quot;,\n       &quot;parameters_hash&quot;: &quot;d4735e3a265e16ee...&quot;,\n       &quot;authorization&quot;: &quot;bearer_token&quot;\n     },\n     &quot;outcome&quot;: &quot;success&quot;,\n     &quot;trust_level&quot;: &quot;L2&quot;,\n     &quot;parent_record_id&quot;:\n       &quot;a1000000-0000-4000-8000-000000000004&quot;,\n     &quot;prev_hash&quot;: &quot;e7f6c011776e8db7c...&quot;,\n     &quot;latency_ms&quot;: 890,\n     &quot;jurisdiction&quot;: &quot;GB&quot;\n   }\n\n   Record 6: Session close\n\n   {\n     &quot;record_id&quot;: &quot;a1000000-0000-4000-8000-000000000006&quot;,\n     &quot;timestamp&quot;: &quot;2026-03-29T14:00:01.210Z&quot;,\n     &quot;agent_id&quot;: &quot;urn:agent:payment-bot.acme.example&quot;,\n     &quot;agent_version&quot;: &quot;2.1.0&quot;,\n     &quot;session_id&quot;: &quot;sess-29mar-0001-4000-8000-abcdef123456&quot;,\n     &quot;action_type&quot;: &quot;lifecycle&quot;,\n     &quot;action_detail&quot;: {\n       &quot;event&quot;: &quot;session_end&quot;,\n       &quot;previous_state&quot;: &quot;active&quot;,\n       &quot;new_state&quot;: &quot;closed&quot;,\n       &quot;trigger&quot;: &quot;task_complete&quot;,\n       &quot;session_hash&quot;: &quot;9c22ff5f21f0b81b...&quot;,\n       &quot;record_count&quot;: 6,\n       &quot;duration_ms&quot;: 1210\n     },\n     &quot;outcome&quot;: &quot;success&quot;,\n     &quot;trust_level&quot;: &quot;L2&quot;,\n     &quot;parent_record_id&quot;:\n       &quot;a1000000-0000-4000-8000-000000000005&quot;,\n     &quot;prev_hash&quot;: &quot;a3a2e67ad1b8d57e2...&quot;\n   }\n\n<span>Appendix B.  EU AI Act Compliance Checklist</span>\n\n   The following table maps EU AI Act Article 12 sub-requirements\n   to specific AAT features:\n\n   +----------------------------+-------------------------------+\n   | Art 12 Requirement         | AAT Feature                   |\n   +----------------------------+-------------------------------+\n   | 12(1) Automatic recording  | Mandatory audit record format |\n   |                            | (Section 3)                   |\n   +----------------------------+-------------------------------+\n   | 12(1)(a) Recording of      | session_id + ordered chain    |\n   | period of each use         | (Section 6)                   |\n   +----------------------------+-------------------------------+\n   | 12(1)(b) Reference         | agent_id (URI) + agent_version|\n   | database against which     | + model_id (Section 3)        |\n   | input data has been        |                               |\n   | checked                    |                               |\n   +----------------------------+-------------------------------+\n   | 12(1)(c) Input data for    | input_hash field              |\n   | which search has led to    | (Section 3.2)                 |\n   | a match                    |                               |\n   +----------------------------+-------------------------------+\n   | 12(1)(d) Identification    | human_override field with     |\n   | of natural persons         | pseudonymous operator_id      |\n   | involved in verification   | (Section 3.2)                 |\n   +----------------------------+-------------------------------+\n   | 12(2) Conform to           | This specification            |\n   | recognised standards       |                               |\n   +----------------------------+-------------------------------+\n   | 12(3) Appropriate to       | Retention requirements        |\n   | intended purpose, at       | (Section 7): 12 months for    |\n   | least 6 months             | high-risk, 6 months general   |\n   +----------------------------+-------------------------------+\n   | 12(4) Providers of         | Export formats (Section 8)     |\n   | high-risk AI systems       | enable log provision to       |\n   | that are credit            | financial authorities         |\n   | institutions               |                               |\n   +----------------------------+-------------------------------+\n   | Art 13 Transparency        | action_type taxonomy +        |\n   |                            | decision records (Sec 5.3)    |\n   +----------------------------+-------------------------------+\n   | Art 14 Human oversight     | escalation type (Sec 5.5) +   |\n   |                            | human_override (Sec 3.2)      |\n   +----------------------------+-------------------------------+\n\n<span>Appendix C.  Implementation Notes</span>\n\nC.1.  Performance Considerations\n\n   Hash computation adds overhead to each record.  Benchmarks on\n   commodity hardware show:\n\n   o  JCS canonicalization: ~0.1 ms per record (typical size).\n\n   o  SHA-256 hash: ~0.01 ms per record.\n\n   o  ECDSA P-256 signing: ~1-2 ms per record.\n\n   o  Total overhead with signing: ~2 ms per record.\n\n   For high-throughput agents (&gt;1000 actions/second),\n   implementations MAY batch records and compute hashes\n   asynchronously, provided the chain order is preserved.  The\n   timestamp MUST reflect the actual event time, not the time\n   the hash was computed.\n\nC.2.  Storage Estimates\n\n   A typical audit record (mandatory fields only) is\n   approximately 500-800 bytes when serialized as JSON.  With\n   optional fields, records range from 800-2000 bytes.\n\n   For a high-activity agent producing 10,000 records per day:\n\n   o  Daily storage: ~10-20 MB (JSONL).\n\n   o  Monthly storage: ~300-600 MB.\n\n   o  12-month retention: ~3.6-7.2 GB.\n\n   Implementations SHOULD apply compression (e.g., gzip) to\n   archived sessions.  Typical compression ratios for JSON\n   audit data are 5:1 to 10:1.\n\nC.3.  Clock Synchronization\n\n   Accurate timestamps are critical for audit trail integrity.\n   Implementations MUST:\n\n   o  Use NTP or PTP for clock synchronization.\n\n   o  Monitor clock drift and alert if drift exceeds 100 ms.\n\n   o  Record the clock source in the genesis record&#x27;s\n      action_detail when available.\n\n   In distributed agent systems where multiple agents contribute\n   to a workflow, each agent maintains its own audit trail with\n   its own clock.  Cross-agent timestamp correlation SHOULD use\n   the delegation record timestamps as synchronization points.\n\nC.4.  Relationship to MCPS\n\n   AAT is designed to complement MCPS\n   [draft-sharif-mcps-secure-mcp].  The relationship is:\n\n   o  MCPS provides cryptographic identity (Agent Passports) and\n      per-message signing for MCP protocol traffic.\n\n   o  AAT provides the audit log format for recording what\n      agents did and why.\n\n   o  The agent_id in AAT records SHOULD match the agent_id in\n      the MCPS Agent Passport.\n\n   o  AAT signatures SHOULD use the same ECDSA P-256 key as the\n      MCPS Agent Passport, providing a single cryptographic\n      identity across both protocol security and audit logging.\n\n   o  MCPS trust levels (L0-L4) are directly referenced in AAT\n      records via the trust_level field.\n\n   Implementations that deploy both MCPS and AAT achieve both\n   real-time protocol security and comprehensive audit logging\n   under a unified cryptographic identity.\n\nC.5.  Validator Implementation\n\n   A conformant AAT validator MUST check:\n\n   1.  Schema validation: All mandatory fields present with\n       correct types.\n\n   2.  Chain integrity: prev_hash values match computed hashes.\n\n   3.  Temporal ordering: Timestamps are monotonically\n       non-decreasing.\n\n   4.  Session structure: Genesis record is first, close record\n       is last (if present).\n\n   5.  Referential integrity: parent_record_id values reference\n       existing records.\n\n   6.  Action type conformance: action_detail contains required\n       fields for the declared action_type.\n\n   A validator SHOULD produce a structured report indicating\n   pass/fail for each check, with the specific record_id where\n   failures occurred.\n\n<span>Author&#x27;s Address</span>\n\n   Raza Sharif\n   CyberSecAI Ltd\n\n   Email: contact@agentsign.dev\n</pre>\n                </div>\n            </div>\n            \n        \n    \n                    \n                </div>\n            </div>\n        </main>\n        \n            <footer class=\"col-md-12 col-sm-12 border-top mt-5 py-5 bg-light-subtle text-center position-sticky\">\n                <a href=\"https://www.ietf.org/\" class=\"p-3\">IETF</a>\n                <a href=\"https://www.ietf.org/iesg/\" class=\"p-3\">IESG</a>\n                <a href=\"https://www.iab.org/\" class=\"p-3\">IAB</a>\n                <a href=\"https://www.irtf.org/\" class=\"p-3\">IRTF</a>\n                <a href=\"https://www.ietf.org/llc/\" class=\"p-3 text-nowrap\">IETF LLC</a>\n                <a href=\"https://trustee.ietf.org/\" class=\"p-3 text-nowrap\">IETF Trust</a>\n                <a href=\"https://www.rfc-editor.org/\" class=\"p-3 text-nowrap\">RFC Editor</a>\n                <a href=\"https://www.iana.org/\" class=\"p-3\">IANA</a>\n                <a href=\"https://www.ietf.org/privacy-statement/\" class=\"p-3 text-nowrap\">Privacy Statement</a>\n                <div class=\"small text-body-secondary py-3\">\n                    \n                        <a class=\"mx-2\" href=\"/release/about\">About IETF Datatracker</a>\n                        <span class=\"mx-2\">\n                            \n                                <a href=\"https://github.com/ietf-tools/datatracker/releases/tag/12.69.0\">\n                            \n                            Version 12.69.0\n                            (release - 3cce873)\n                            \n                                </a>\n                            \n                        </span>\n                    \n                    <a class=\"mx-2\" href=\"https://status.ietf.org\" target=\"_blank\">System Status</a>\n                    <span class=\"mx-2 text-danger\">\n                        <i class=\"bi bi-bug\"></i>\n                        Report a bug:\n                        <a class=\"text-reset\" target=\"_blank\" href=\"https://github.com/ietf-tools/datatracker/issues/new/choose\">GitHub</a>\n                        \n                            <a class=\"text-reset\" href=\"mailto:tools-help@ietf.org\">Email</a>\n                        \n                    </span>\n                    \n                </div>\n            </footer>\n        \n        \n        <script src=\"https://static.ietf.org/dt/12.69.0/ietf/js/d3.js\">\n        </script>\n        <script src=\"https://static.ietf.org/dt/12.69.0/ietf/js/document_timeline.js\">\n        </script>\n    \n        <script src=\"https://static.ietf.org/dt/12.69.0/ietf/js/select2.js\"></script>\n        <script src=\"https://static.ietf.org/dt/12.69.0/ietf/js/navbar-doc-search.js\"></script>\n      \n<script>\n  var _paq = window._paq || [];\n  \n  _paq.push(['disableCookies']);\n  _paq.push(['trackPageView']);\n  _paq.push(['enableLinkTracking']);\n  (function() {\n    var u=\"//analytics.ietf.org/\";\n    _paq.push(['setTrackerUrl', u+'matomo.php']);\n    _paq.push(['setSiteId', 7]);\n    var d=document, g=d.createElement('script'), s=d.getElementsByTagName('script')[0];\n    g.type='text/javascript'; g.async=true; g.defer=true; g.src=u+'matomo.js'; s.parentNode.insertBefore(g,s);\n  })();\n</script>\n<noscript><p><img src=\"//analytics.ietf.org/matomo.php?idsite=7\" style=\"border:0;\" alt=\"\" /></p></noscript>\n\n    <script>(function(){function c(){var b=a.contentDocument||(a.contentWindow&&a.contentWindow.document);if(b){var d=b.createElement('script');d.innerHTML=\"window.__CF$cv$params={r:'a216553ce988a666',t:'MTc4NTA5OTYxNg=='};var a=document.createElement('script');a.src='/cdn-cgi/challenge-platform/scripts/jsd/main.js';document.getElementsByTagName('head')[0].appendChild(a);\";b.getElementsByTagName('head')[0].appendChild(d)}}if(document.body){var a=document.createElement('iframe');a.height=1;a.width=1;a.style.position='absolute';a.style.top=0;a.style.left=0;a.style.border='none';a.style.visibility='hidden';document.body.appendChild(a);if('loading'!==document.readyState)c();else if(window.addEventListener)document.addEventListener('DOMContentLoaded',c);else{var e=document.onreadystatechange||function(){};document.onreadystatechange=function(b){e(b);'loading'!==document.readyState&&(document.onreadystatechange=e,c())}}}})();</script></body>\n</html>\n","snapshot_chars":95944,"live_check":"changed"},{"url":"https://agenticrail.nz/blog/ietf-agent-audit-trail/","committed_hash":"sha256:d6a8b0b67ea0533db8ebea2db2509eb89d32f3d4bff01eab34437b77c407f479","committed_hash_short":"sha256:d6a8b0b6…c407f479","mime_type":"text/html","committed_at":"2026-07-26T21:00:17.090322+00:00","content_snapshot":"<!DOCTYPE html>\r\n<html lang=\"en\">\r\n<head>\r\n<meta charset=\"UTF-8\">\r\n<meta name=\"viewport\" content=\"width=device-width, initial-scale=1.0\">\r\n<title>IETF Agent Audit Trail: What the Draft Standard Requires — and What It Doesn't</title>\r\n<meta name=\"description\" content=\"The IETF draft standard for agent audit trails (draft-sharif-agent-audit-trail) defines hash-chained JSON records, trust levels L0–L4, and mandatory fields for AI agent sessions. It references EU AI Act Article 12 and ISO 42001. But the draft doesn't require pre-execution recording — here's what it covers, what it leaves open, and how AgenticRail aligns with and exceeds the draft specification.\">\r\n<link rel=\"canonical\" href=\"https://agenticrail.nz/blog/ietf-agent-audit-trail/\">\r\n<meta property=\"og:type\" content=\"article\">\r\n<meta property=\"og:url\" content=\"https://agenticrail.nz/blog/ietf-agent-audit-trail/\">\r\n<meta property=\"og:title\" content=\"IETF Agent Audit Trail: What the Draft Standard Requires — and What It Doesn't\">\r\n<meta property=\"og:description\" content=\"The IETF agent audit trail draft defines hash-chained JSON records with trust levels L0–L4. It cites EU AI Act Article 12 — but doesn't require pre-execution recording. Here's the full spec breakdown and where AgenticRail goes further.\">\r\n<meta property=\"og:image\" content=\"https://agenticrail.nz/og-image.png\">\r\n<meta property=\"article:published_time\" content=\"2026-05-12\">\r\n<meta property=\"article:author\" content=\"Kade Cowper\">\r\n<meta name=\"twitter:card\" content=\"summary_large_image\">\r\n<meta name=\"twitter:title\" content=\"IETF Agent Audit Trail: What the Draft Standard Requires — and What It Doesn't\">\r\n<meta name=\"twitter:description\" content=\"The IETF agent audit trail draft defines hash-chained JSON records with trust levels L0–L4. It cites EU AI Act Article 12 — but doesn't require pre-execution recording. Full spec breakdown and AgenticRail alignment.\">\r\n<meta name=\"twitter:image\" content=\"https://agenticrail.nz/og-image.png\">\r\n<link rel=\"icon\" type=\"image/svg+xml\" href=\"/favicon.svg\">\r\n<link rel=\"preconnect\" href=\"https://fonts.googleapis.com\">\r\n<link rel=\"preconnect\" href=\"https://fonts.gstatic.com\" crossorigin>\r\n<link rel=\"stylesheet\" href=\"https://fonts.googleapis.com/css2?family=Public+Sans:wght@400;500;600;700&family=IBM+Plex+Mono:wght@400;500&family=Syne:wght@700;800&display=swap\" media=\"print\" onload=\"this.media='all';this.onload=null\">\r\n<script type=\"application/ld+json\">\r\n{\r\n  \"@context\": \"https://schema.org\",\r\n  \"@type\": \"BlogPosting\",\r\n  \"headline\": \"IETF Agent Audit Trail: What the Draft Standard Requires — and What It Doesn't\",\r\n  \"description\": \"The IETF draft standard for agent audit trails (draft-sharif-agent-audit-trail) defines hash-chained JSON records, trust levels L0–L4, and mandatory fields for AI agent sessions. It references EU AI Act Article 12 and ISO 42001. But the draft doesn't require pre-execution recording — here's what it covers, what it leaves open, and how AgenticRail aligns with and exceeds the draft specification.\",\r\n  \"url\": \"https://agenticrail.nz/blog/ietf-agent-audit-trail/\",\r\n  \"datePublished\": \"2026-05-12\",\r\n  \"dateModified\": \"2026-07-18\",\r\n  \"author\": {\r\n    \"@type\": \"Person\",\r\n    \"name\": \"Kade Cowper\",\r\n    \"@id\": \"https://agenticrail.nz/#kade-cowper\"\r\n  },\r\n  \"publisher\": {\r\n    \"@type\": \"Organization\",\r\n    \"name\": \"AgenticRail\",\r\n    \"url\": \"https://agenticrail.nz\",\r\n    \"@id\": \"https://agenticrail.nz/#organization\"\r\n  },\r\n  \"image\": \"https://agenticrail.nz/og-image.png\",\r\n  \"keywords\": [\"ietf agent audit trail\", \"agent audit trail ietf\", \"draft-sharif-agent-audit-trail\", \"AI agent audit trail standard\", \"hash chained audit log\", \"AI agent compliance\", \"ISO 42001\", \"agentic AI governance\"],\r\n  \"isPartOf\": {\r\n    \"@type\": \"Blog\",\r\n    \"url\": \"https://agenticrail.nz/blog/\"\r\n  },\r\n  \"breadcrumb\": {\r\n    \"@type\": \"BreadcrumbList\",\r\n    \"itemListElement\": [\r\n      { \"@type\": \"ListItem\", \"position\": 1, \"name\": \"AgenticRail\", \"item\": \"https://agenticrail.nz\" },\r\n      { \"@type\": \"ListItem\", \"position\": 2, \"name\": \"Blog\", \"item\": \"https://agenticrail.nz/blog/\" },\r\n      { \"@type\": \"ListItem\", \"position\": 3, \"name\": \"IETF Agent Audit Trail\", \"item\": \"https://agenticrail.nz/blog/ietf-agent-audit-trail/\" }\r\n    ]\r\n  }\r\n}\r\n</script>\r\n<script type=\"application/ld+json\">\r\n{\r\n  \"@context\": \"https://schema.org\",\r\n  \"@type\": \"FAQPage\",\r\n  \"mainEntity\": [\r\n    {\r\n      \"@type\": \"Question\",\r\n      \"name\": \"What is the IETF agent audit trail draft?\",\r\n      \"acceptedAnswer\": {\r\n        \"@type\": \"Answer\",\r\n        \"text\": \"The IETF agent audit trail draft (draft-sharif-agent-audit-trail) is an Internet-Draft that defines a standardised JSON format for AI agent audit records. It specifies mandatory fields including record_id, timestamp, agent_id, agent_version, session_id, action_type, action_detail, outcome, trust_level, parent_record_id, and prev_hash. Records are hash-chained using SHA-256 over JSON Canonicalization Scheme (RFC 8785) output, forming a tamper-evident linked list. The draft defines five trust levels (L0–L4) and special record types for session start (genesis) and GDPR-compliant deletion (tombstone). It references EU AI Act Article 12, ISO/IEC 42001, SOC 2, and PCI DSS as regulatory contexts where the standard applies. The draft expires September 29, 2026.\"\r\n      }\r\n    },\r\n    {\r\n      \"@type\": \"Question\",\r\n      \"name\": \"What hash algorithm does the IETF agent audit trail standard use?\",\r\n      \"acceptedAnswer\": {\r\n        \"@type\": \"Answer\",\r\n        \"text\": \"The IETF agent audit trail draft uses SHA-256 over JSON Canonicalization Scheme (JCS, RFC 8785) output. The hash formula is: prev_hash(N) = hex(SHA-256(JCS(record(N-1)))). JCS produces a deterministic, canonicalised representation of the JSON record — alphabetically sorted keys, no insignificant whitespace — before the hash is computed. This means any tampering with field order, whitespace, or content in a prior record will break the chain at the next record. The genesis record (session start) has a null prev_hash. AgenticRail uses the same approach for its receipt chain: prev_receipt_hash is SHA-256 over the canonical JSON of the prior receipt, with Ed25519 signatures over the same canonicalisation.\"\r\n      }\r\n    },\r\n    {\r\n      \"@type\": \"Question\",\r\n      \"name\": \"What are the IETF agent audit trail trust levels?\",\r\n      \"acceptedAnswer\": {\r\n        \"@type\": \"Answer\",\r\n        \"text\": \"The IETF agent audit trail draft defines five trust levels: L0 (no verification — agent claims identity, no external check); L1 (self-signed — agent signs its own records but no external authority verifies the signing key); L2 (authority-signed — a trusted third party signs or countersigns records); L3 (mutual authentication — both the agent and a counterparty verify each other's identity); L4 (full mutual authentication with revocation checking and continuous monitoring). Higher trust levels provide stronger assurance that records cannot be forged or disavowed. The trust_level field is mandatory in every record.\"\r\n      }\r\n    },\r\n    {\r\n      \"@type\": \"Question\",\r\n      \"name\": \"Does the IETF agent audit trail draft require pre-execution recording?\",\r\n      \"acceptedAnswer\": {\r\n        \"@type\": \"Answer\",\r\n        \"text\": \"No. The IETF agent audit trail draft defines records of events that occurred — it records outcomes (success, failure, timeout, denied, escalated) after actions complete. The draft does not require a gate to fire before execution, nor does it mandate that a record be written at the moment of authorisation rather than at the moment of completion. This is a significant gap: a compliant implementation could write all records after the fact. AgenticRail goes beyond the draft by writing a signed receipt before the action executes — at the moment the gate decision is made, before execution begins. This means the receipt proves what was enforced, not merely what was observed to have happened.\"\r\n      }\r\n    },\r\n    {\r\n      \"@type\": \"Question\",\r\n      \"name\": \"How does AgenticRail align with the IETF agent audit trail draft?\",\r\n      \"acceptedAnswer\": {\r\n        \"@type\": \"Answer\",\r\n        \"text\": \"AgenticRail aligns with the IETF agent audit trail draft on cryptographic structure (SHA-256 over canonical JSON), the 'denied' outcome value, and the session-scoped record chain (sequence_id maps to session_id). AgenticRail goes beyond the draft in three material ways: (1) receipts are written pre-execution — at gate decision time, before the action runs — whereas the draft only requires post-event records; (2) AgenticRail enforces strict step-order across the session (SEQUENCE_VIOLATION, SEALED_SEQUENCE), which the draft does not require; (3) AgenticRail provides specific DENY reason codes (REPLAY_NONCE, ACTION_NOT_ALLOWED, UNKNOWN_STEP, STALE_TIMESTAMP) rather than a single 'denied' outcome. The effect: AgenticRail receipts satisfy the draft's structural requirements and add the pre-execution enforcement evidence that EU AI Act Article 12's reconstruction requirement demands.\"\r\n      }\r\n    },\r\n    {\r\n      \"@type\": \"Question\",\r\n      \"name\": \"Does the IETF agent audit trail draft satisfy EU AI Act Article 12?\",\r\n      \"acceptedAnswer\": {\r\n        \"@type\": \"Answer\",\r\n        \"text\": \"The IETF agent audit trail draft is explicitly designed with EU AI Act Article 12 in mind — it cites Article 12 as one of the primary regulatory drivers. The draft's hash-chained, tamper-evident record structure addresses Article 12's requirement that AI systems 'technically allow for the automatic recording of events (logs)' with sufficient fidelity to enable reconstruction of the sequence of events. However, the draft alone does not guarantee Article 12 compliance: compliance depends on what is recorded (mandatory fields must cover the right events), how records are stored (Article 26 requires at least 6 months retention), and whether the records support reconstruction of the full decision chain. A post-hoc audit log built to the draft spec is a necessary starting point — pre-execution enforcement evidence, as provided by AgenticRail, is what makes reconstruction conclusive.\"\r\n      }\r\n    }\r\n  ]\r\n}\r\n</script>\r\n<link rel=\"stylesheet\" href=\"/styles.css\">\r\n<style>\r\n*,*::before,*::after{box-sizing:border-box;margin:0;padding:0}\r\n:root{--bg:#f6f1e7;--fg:#161210;--accent:#8f6300;--muted:#6b6358;--border:#e7ddc9;--card:#fbf7ee}\r\nhtml{font-size:16px;scroll-behavior:smooth}\r\nbody{background:var(--bg);color:var(--fg);font-family:'Public Sans',system-ui,-apple-system,'Segoe UI',sans-serif;line-height:1.6;min-height:100vh}\r\na{color:var(--accent);text-decoration:none}\r\na:hover{text-decoration:underline}\r\n\r\n/* NAV */\r\nnav{display:flex;align-items:center;justify-content:space-between;padding:1rem 2rem;border-bottom:1px solid var(--border);position:sticky;top:0;background:var(--bg);z-index:100}\r\n.logo{font-family:'Public Sans',sans-serif;font-weight:800;font-size:1.35rem;letter-spacing:-0.02em;color:var(--fg);text-decoration:none;flex-shrink:0}\r\n.logo span{color:var(--accent)}\r\nnav .nav-links{display:flex;gap:22px;align-items:center}\r\nnav a{color:#2b2620;font-size:0.75rem;letter-spacing:0.08em;text-transform:uppercase;text-decoration:none}\r\nnav a:hover{color:var(--fg)}\r\n\r\n/* LAYOUT */\r\n.post-wrap{max-width:760px;margin:0 auto;padding:4rem 2rem 6rem}\r\n\r\n/* BREADCRUMB */\r\n.breadcrumb{font-size:0.75rem;color:var(--muted);margin-bottom:2.5rem;display:flex;gap:0.5rem;align-items:center}\r\n.breadcrumb a{color:var(--muted)}\r\n.breadcrumb a:hover{color:var(--fg)}\r\n.breadcrumb span{color:var(--border)}\r\n\r\n/* HEADER */\r\n.post-meta{font-size:0.75rem;color:var(--muted);margin-bottom:1rem;display:flex;gap:1.5rem;flex-wrap:wrap}\r\n.post-tag{background:var(--accent);color:#000;padding:0.2rem 0.6rem;font-size:0.7rem;font-weight:500;letter-spacing:0.05em;text-transform:uppercase}\r\nh1{font-family:'Public Sans',sans-serif;font-size:clamp(1.6rem,4vw,2.4rem);font-weight:800;line-height:1.15;letter-spacing:-0.02em;margin-bottom:1.5rem}\r\n.post-lede{font-size:1.05rem;color:#6b6358;line-height:1.7;margin-bottom:2.5rem;border-left:3px solid var(--accent);padding-left:1.25rem}\r\n\r\n/* BODY */\r\nh2{font-family:'Public Sans',sans-serif;font-size:1.35rem;font-weight:700;margin:3rem 0 1rem;letter-spacing:-0.01em}\r\nh3{font-family:'Public Sans',sans-serif;font-size:1.05rem;font-weight:700;margin:2rem 0 0.75rem;color:var(--accent)}\r\np{margin-bottom:1.25rem;color:#2b2620;line-height:1.75}\r\nul,ol{margin:0 0 1.25rem 1.5rem;color:#2b2620}\r\nli{margin-bottom:0.4rem;line-height:1.7}\r\nstrong{color:var(--fg);font-weight:500}\r\n\r\n/* CALLOUTS */\r\n.callout{border:1px solid var(--border);padding:1.25rem 1.5rem;margin:2rem 0;background:var(--card)}\r\n.callout-label{font-size:0.7rem;text-transform:uppercase;letter-spacing:0.1em;color:var(--accent);margin-bottom:0.6rem;font-weight:500}\r\n.callout p{margin:0;font-size:0.9rem}\r\n.callout.warn{border-color:#a8401f}\r\n.callout.warn .callout-label{color:#a8401f}\r\n.callout.info{border-color:#005dbb}\r\n.callout.info .callout-label{color:#005dbb}\r\n\r\n/* CODE BLOCKS */\r\n.code-block{background:#fbf7ee;border:1px solid var(--border);padding:1.25rem 1.5rem;margin:1.5rem 0;overflow-x:auto;font-size:0.82rem;line-height:1.6}\r\n.code-label{font-size:0.7rem;text-transform:uppercase;letter-spacing:0.1em;color:var(--muted);margin-bottom:0.75rem}\r\npre{white-space:pre;font-family:'IBM Plex Mono',monospace}\r\n.kv{color:#2b2620}\r\n.kv .key{color:#005dbb}\r\n.kv .val-str{color:#8f6300}\r\n.kv .val-num{color:#d99a07}\r\n.kv .val-null{color:#888}\r\n.kv .val-ok{color:#8f6300}\r\n.kv .val-deny{color:#a8401f}\r\n.kv .comment{color:#444;font-style:italic}\r\n\r\n/* TABLES */\r\n.table-wrap{overflow-x:auto;margin:1.5rem 0}\r\ntable{width:100%;border-collapse:collapse;font-size:0.85rem}\r\nth{text-align:left;padding:0.6rem 1rem;border-bottom:2px solid var(--border);color:var(--muted);font-weight:500;font-size:0.75rem;text-transform:uppercase;letter-spacing:0.05em;white-space:nowrap}\r\ntd{padding:0.65rem 1rem;border-bottom:1px solid var(--border);color:#2b2620;vertical-align:top}\r\ntr:last-child td{border-bottom:none}\r\n.tag-align{color:var(--accent)}\r\n.tag-partial{color:#d99a07}\r\n.tag-gap{color:#a8401f}\r\n.tag-ok{background:rgba(200,255,0,0.08);color:var(--accent);padding:0.15rem 0.5rem;font-size:0.75rem}\r\n.tag-warn{background:rgba(255,107,53,0.08);color:#a8401f;padding:0.15rem 0.5rem;font-size:0.75rem}\r\n.tag-note{background:rgba(74,158,255,0.08);color:#005dbb;padding:0.15rem 0.5rem;font-size:0.75rem}\r\n\r\n/* TRUST LEVELS */\r\n.trust-grid{display:grid;grid-template-columns:auto 1fr;gap:0;margin:1.5rem 0;border:1px solid var(--border)}\r\n.trust-row{display:contents}\r\n.trust-level{padding:0.75rem 1rem;border-bottom:1px solid var(--border);border-right:1px solid var(--border);font-size:0.9rem;font-weight:500;white-space:nowrap}\r\n.trust-desc{padding:0.75rem 1rem;border-bottom:1px solid var(--border);font-size:0.85rem;color:#2b2620}\r\n.trust-row:last-child .trust-level,\r\n.trust-row:last-child .trust-desc{border-bottom:none}\r\n.l0{color:#888}\r\n.l1{color:#d99a07}\r\n.l2{color:#005dbb}\r\n.l3{color:#8f6300}\r\n.l4{color:#8f6300;font-weight:600}\r\n\r\n/* FIELD TABLE */\r\n.field-table table{font-size:0.82rem}\r\n.req{color:var(--accent)}\r\n.opt{color:var(--muted)}\r\n\r\n/* DIAGRAM */\r\n.diagram{background:#fbf7ee;border:1px solid var(--border);padding:1.5rem;margin:1.5rem 0;font-size:0.8rem;overflow-x:auto}\r\n.diagram pre{color:#888;line-height:1.8}\r\n.diagram .hi{color:var(--accent)}\r\n.diagram .lo{color:#444}\r\n.diagram .ok{color:#8f6300}\r\n.diagram .deny{color:#a8401f}\r\n.diagram .neutral{color:#005dbb}\r\n\r\n/* STATS */\r\n.stat-row{display:flex;gap:1.5rem;margin:1.5rem 0;flex-wrap:wrap}\r\n.stat-box{border:1px solid var(--border);padding:1.25rem 1.5rem;flex:1;min-width:140px}\r\n.stat-val{font-family:'Public Sans',sans-serif;font-size:2rem;font-weight:800;color:var(--accent);display:block;letter-spacing:-0.02em;line-height:1}\r\n.stat-label{font-size:0.75rem;color:var(--muted);margin-top:0.4rem;display:block}\r\n\r\n/* CTA */\r\n.cta-block{border:1px solid var(--accent);padding:2rem;margin:3rem 0;text-align:center}\r\n.cta-block h3{font-family:'Public Sans',sans-serif;font-size:1.1rem;font-weight:700;margin:0 0 0.75rem;color:var(--fg)}\r\n.cta-block p{font-size:0.9rem;margin:0 0 1.25rem;color:var(--muted)}\r\n.btn{display:inline-block;background:var(--accent);color:#000;padding:0.65rem 1.5rem;font-size:0.85rem;font-weight:500;font-family:'IBM Plex Mono',monospace;cursor:pointer;border:none;letter-spacing:0.03em}\r\n.btn:hover{background:#d99a07;text-decoration:none;color:#000}\r\n.btn-ghost{background:transparent;border:1px solid var(--accent);color:var(--accent);margin-left:1rem}\r\n.btn-ghost:hover{background:var(--accent);color:#000}\r\n\r\n/* BACK LINK */\r\n.back-link{display:inline-flex;align-items:center;gap:0.5rem;font-size:0.8rem;color:var(--muted);margin-top:3rem}\r\n.back-link:hover{color:var(--fg)}\r\n\r\n/* FOOTER */\r\nfooter{border-top:1px solid var(--border);padding:2rem 0;display:flex;justify-content:space-between;align-items:center;flex-wrap:wrap;gap:16px}\r\n.footer-left{font-size:0.7rem;color:#6b6358;letter-spacing:0.04em}\r\n.footer-right{display:flex;gap:24px}\r\n.footer-right a{font-size:0.7rem;color:#6b6358;text-decoration:underline;text-underline-offset:3px;letter-spacing:0.06em;text-transform:uppercase}\r\n.footer-right a:hover{color:var(--fg)}\r\n\r\n@media(max-width:640px){\r\n  nav{padding:1rem}\r\n  .nav-links{display:none}\r\n  .post-wrap{padding:2rem 1rem 4rem}\r\n  .stat-row{flex-direction:column}\r\n  .trust-grid{grid-template-columns:1fr}\r\n  .trust-level{border-right:none}\r\n}\r\n</style>\r\n</head>\r\n<body>\r\n<canvas id=\"ekg-canvas\"></canvas>\r\n<div id=\"bg-kk\"></div>\r\n\r\n<nav>\r\n  <a href=\"/\" class=\"logo\">Agentic<span>Rail</span></a>\r\n      <div class=\"nav-links\">\r\n      <a href=\"/docs/\">Docs</a>\r\n      <a href=\"https://report.agenticrail.nz/report\">Verify</a>\r\n      <a href=\"/about/\">About</a>\r\n    </div>\r\n</nav>\r\n\r\n<div class=\"post-wrap\">\r\n\r\n  <div class=\"breadcrumb\">\r\n    <a href=\"/\">AgenticRail</a>\r\n    <span>›</span>\r\n    <a href=\"/blog/\">Blog</a>\r\n    <span>›</span>\r\n    IETF Agent Audit Trail\r\n  </div>\r\n\r\n  <div class=\"post-meta\">\r\n    <span class=\"post-tag\">Standards</span>\r\n    <span>2026-05-12 · reviewed 2026-07-18</span>\r\n    <span>Kade Cowper</span>\r\n  </div>\r\n\r\n  <h1>IETF Agent Audit Trail: What the Draft Standard Requires — and What It Doesn't</h1>\r\n\r\n  <p class=\"post-lede\">There is a live IETF Internet-Draft that defines a JSON standard for AI agent audit records with hash chaining, trust levels, and mandatory fields. It cites EU AI Act Article 12 and ISO/IEC 42001. Here is what the draft requires, where it leaves gaps, and how AgenticRail aligns with — and goes beyond — it.</p>\r\n\r\n  <h2>The Draft</h2>\r\n\r\n  <p><code>draft-sharif-agent-audit-trail</code> is an IETF Internet-Draft defining a standardised format for audit records produced by AI agent systems. It was published to address the absence of a common structure for agent audit logs — the gap that makes compliance attestation difficult when every deployment invents its own schema.</p>\r\n\r\n  <p>The draft expires September 29, 2026. At that point it either advances toward RFC status, is revised, or lapses. For now it represents the closest thing to an emerging standard that developers, auditors, and compliance teams can reference when building or evaluating agent audit infrastructure.</p>\r\n\r\n  <div class=\"callout info\">\r\n    <div class=\"callout-label\">Draft Reference</div>\r\n    <p><strong>draft-sharif-agent-audit-trail</strong> — IETF Internet-Draft, version -00 (status re-verified 18 July 2026). Expires 2026-09-29. Regulatory references: EU AI Act Article 12, ISO/IEC 42001, SOC 2, PCI DSS.</p>\r\n  </div>\r\n\r\n  <h2>Mandatory Fields</h2>\r\n\r\n  <p>Every audit record under the draft must include the following fields. Optional fields can be added, but omitting any mandatory field renders the record non-conformant.</p>\r\n\r\n  <div class=\"field-table\">\r\n  <div class=\"table-wrap\">\r\n  <table>\r\n    <thead>\r\n      <tr>\r\n        <th>Field</th>\r\n        <th>Required</th>\r\n        <th>Description</th>\r\n      </tr>\r\n    </thead>\r\n    <tbody>\r\n      <tr><td><code>record_id</code></td><td><span class=\"req\">Required</span></td><td>Unique identifier for this record</td></tr>\r\n      <tr><td><code>timestamp</code></td><td><span class=\"req\">Required</span></td><td>ISO 8601 timestamp of the event</td></tr>\r\n      <tr><td><code>agent_id</code></td><td><span class=\"req\">Required</span></td><td>Identifier of the agent that produced the record</td></tr>\r\n      <tr><td><code>agent_version</code></td><td><span class=\"req\">Required</span></td><td>Version string for the agent</td></tr>\r\n      <tr><td><code>session_id</code></td><td><span class=\"req\">Required</span></td><td>Groups all records from one agent session</td></tr>\r\n      <tr><td><code>action_type</code></td><td><span class=\"req\">Required</span></td><td>Categorises the action (e.g. tool_call, lifecycle)</td></tr>\r\n      <tr><td><code>action_detail</code></td><td><span class=\"req\">Required</span></td><td>Structured object describing the specific action</td></tr>\r\n      <tr><td><code>outcome</code></td><td><span class=\"req\">Required</span></td><td>Result: success / failure / timeout / denied / escalated</td></tr>\r\n      <tr><td><code>trust_level</code></td><td><span class=\"req\">Required</span></td><td>L0–L4 verification assurance level</td></tr>\r\n      <tr><td><code>parent_record_id</code></td><td><span class=\"req\">Required</span></td><td>Record that triggered this one (null for genesis)</td></tr>\r\n      <tr><td><code>prev_hash</code></td><td><span class=\"req\">Required</span></td><td>Hash of the prior record; null for genesis</td></tr>\r\n    </tbody>\r\n  </table>\r\n  </div>\r\n  </div>\r\n\r\n  <p>The <code>session_id</code> + <code>prev_hash</code> combination is what turns individual records into a chain. Every record knows what session it belongs to and cryptographically commits to the content of the record before it. This means you cannot insert, delete, or alter any record in the chain without invalidating all subsequent <code>prev_hash</code> values.</p>\r\n\r\n  <h2>The Hash Formula</h2>\r\n\r\n  <p>The draft specifies SHA-256 over <strong>JSON Canonicalization Scheme</strong> output (RFC 8785):</p>\r\n\r\n  <div class=\"code-block\">\r\n    <div class=\"code-label\">Hash chain formula</div>\r\n    <pre>prev_hash(N) = hex(SHA-256(JCS(record(N-1))))</pre>\r\n  </div>\r\n\r\n  <p>JCS (RFC 8785) produces a deterministic, canonicalised JSON encoding: alphabetically sorted keys, no insignificant whitespace, Unicode normalisation. The key property: two representations of the same logical record produce identical JCS output, and therefore identical hashes. Conversely, any change to field content, field order, or encoding in a prior record will produce a different hash, breaking the chain at the next record.</p>\r\n\r\n  <p>The genesis record — the session start record — has <code>prev_hash: null</code> and <code>parent_record_id: null</code>. It uses <code>action_type: \"lifecycle\"</code> and <code>action_detail.event: \"session_start\"</code>. All subsequent records in the session chain back to it.</p>\r\n\r\n  <div class=\"callout\">\r\n    <div class=\"callout-label\">AgenticRail alignment</div>\r\n    <p>AgenticRail signs receipts with Ed25519 over canonical JSON (alphabetically sorted keys), and chains them with SHA-256 over the same canonicalisation via <code>prev_receipt_hash</code> (the draft's <code>prev_hash</code>) — the same structure the draft mandates. The <code>sequence_id</code> field maps directly to the draft's <code>session_id</code>.</p>\r\n  </div>\r\n\r\n  <h2>Trust Levels</h2>\r\n\r\n  <p>The <code>trust_level</code> field is mandatory on every record. The draft defines five levels:</p>\r\n\r\n  <div class=\"trust-grid\">\r\n    <div class=\"trust-row\">\r\n      <div class=\"trust-level l0\">L0</div>\r\n      <div class=\"trust-desc\">No verification. The agent asserts its identity and produces records with no external check. Records can be self-reported and cannot be independently verified.</div>\r\n    </div>\r\n    <div class=\"trust-row\">\r\n      <div class=\"trust-level l1\">L1</div>\r\n      <div class=\"trust-desc\">Self-signed. The agent signs its own records using a key it controls. The signature proves record integrity but doesn't verify the signing key itself came from a trusted authority.</div>\r\n    </div>\r\n    <div class=\"trust-row\">\r\n      <div class=\"trust-level l2\">L2</div>\r\n      <div class=\"trust-desc\">Authority-signed. A trusted third party countersigns or issues records. The signing key is externally verifiable.</div>\r\n    </div>\r\n    <div class=\"trust-row\">\r\n      <div class=\"trust-level l3\">L3</div>\r\n      <div class=\"trust-desc\">Mutual authentication. Both the agent and its counterparty verify each other's identity before records are produced.</div>\r\n    </div>\r\n    <div class=\"trust-row\">\r\n      <div class=\"trust-level l4\">L4</div>\r\n      <div class=\"trust-desc\">Full mutual auth with certificate revocation checking and continuous monitoring. The highest assurance level — every verification is checked against live revocation data.</div>\r\n    </div>\r\n  </div>\r\n\r\n  <p>Most production deployments today operate at L0 or L1. Compliance contexts targeting EU AI Act or ISO 42001 should aim for L2 minimum — authority-signed records that an auditor can verify without trusting the agent itself.</p>\r\n\r\n  <h2>Special Record Types</h2>\r\n\r\n  <h3>Genesis Record</h3>\r\n  <p>The first record in every session. Marks session initialisation. <code>parent_record_id</code> and <code>prev_hash</code> are both null. All records in the session chain back to this one.</p>\r\n\r\n  <div class=\"code-block\">\r\n    <div class=\"code-label\">Genesis record structure</div>\r\n    <pre><span class=\"kv\">{\r\n  <span class=\"key\">\"record_id\"</span>: <span class=\"val-str\">\"rec_0001\"</span>,\r\n  <span class=\"key\">\"timestamp\"</span>: <span class=\"val-str\">\"2026-05-12T09:00:00Z\"</span>,\r\n  <span class=\"key\">\"session_id\"</span>: <span class=\"val-str\">\"sess_abc123\"</span>,\r\n  <span class=\"key\">\"agent_id\"</span>: <span class=\"val-str\">\"credit-approval-agent\"</span>,\r\n  <span class=\"key\">\"agent_version\"</span>: <span class=\"val-str\">\"1.4.2\"</span>,\r\n  <span class=\"key\">\"action_type\"</span>: <span class=\"val-str\">\"lifecycle\"</span>,\r\n  <span class=\"key\">\"action_detail\"</span>: { <span class=\"key\">\"event\"</span>: <span class=\"val-str\">\"session_start\"</span> },\r\n  <span class=\"key\">\"outcome\"</span>: <span class=\"val-str\">\"success\"</span>,\r\n  <span class=\"key\">\"trust_level\"</span>: <span class=\"val-str\">\"L2\"</span>,\r\n  <span class=\"key\">\"parent_record_id\"</span>: <span class=\"val-null\">null</span>,\r\n  <span class=\"key\">\"prev_hash\"</span>: <span class=\"val-null\">null</span>\r\n}</span></pre>\r\n  </div>\r\n\r\n  <h3>Tombstone Record</h3>\r\n  <p>Used for GDPR-compliant deletion. When personal data in a record must be erased, a tombstone replaces the original record. The tombstone preserves the <code>record_id</code>, <code>timestamp</code>, and chain linkage fields (<code>prev_hash</code>, <code>parent_record_id</code>) so chain integrity is maintained, while removing the personal data. This lets you honour right-to-erasure requests without destroying audit chain continuity.</p>\r\n\r\n  <h2>What the Draft Requires</h2>\r\n\r\n  <p>The draft is explicit about structure. It requires:</p>\r\n  <ul>\r\n    <li>All mandatory fields present on every record</li>\r\n    <li>Hash chaining using the JCS+SHA-256 formula</li>\r\n    <li>Trust level declared per record</li>\r\n    <li>Genesis record at session start</li>\r\n    <li>Outcome value from the specified set</li>\r\n  </ul>\r\n\r\n  <p>What it does not specify: how long records must be retained, which storage backend to use, whether the recording system must be independent of the agent, or when in the action lifecycle the record must be written.</p>\r\n\r\n  <h2>The Gap: Pre-Execution Recording</h2>\r\n\r\n  <p>The most significant gap in the draft is timing. The draft defines records of events that <em>occurred</em> — it records outcomes after actions complete. The outcome values reflect completion states: success, failure, timeout, denied, escalated.</p>\r\n\r\n  <p>This means a fully conformant implementation could write all records after execution. An agent could complete every action in a session and then produce a conformant, hash-chained audit log retroactively. The chain would be internally consistent. The hashes would verify. But the records would not prove that any enforcement gate fired before execution — they would only record what the agent reported about itself.</p>\r\n\r\n  <div class=\"callout warn\">\r\n    <div class=\"callout-label\">Critical gap</div>\r\n    <p>The draft does not require that a record be written at the moment of authorisation rather than at the moment of completion. A post-execution log can be fully draft-conformant. That is not the same as pre-execution evidence.</p>\r\n  </div>\r\n\r\n  <p>This matters for EU AI Act Article 12. Article 12 requires logs enabling <em>reconstruction of the sequence of events</em> — which implies the log must be a faithful record of what was enforced, not a summary written after the fact by the system being audited.</p>\r\n\r\n  <h2>How AgenticRail Aligns With the Draft</h2>\r\n\r\n  <div class=\"table-wrap\">\r\n  <table>\r\n    <thead>\r\n      <tr>\r\n        <th>Draft Requirement</th>\r\n        <th>AgenticRail</th>\r\n        <th>Status</th>\r\n      </tr>\r\n    </thead>\r\n    <tbody>\r\n      <tr>\r\n        <td>SHA-256 over canonical JSON</td>\r\n        <td>SHA-256 over canonical JSON for the receipt chain (<code>prev_receipt_hash</code>); Ed25519 signatures over the same canonicalisation</td>\r\n        <td><span class=\"tag-ok\">Aligned</span></td>\r\n      </tr>\r\n      <tr>\r\n        <td><code>session_id</code> groups records</td>\r\n        <td><code>sequence_id</code> groups all receipts in a session chain</td>\r\n        <td><span class=\"tag-ok\">Aligned</span></td>\r\n      </tr>\r\n      <tr>\r\n        <td><code>denied</code> outcome value</td>\r\n        <td>DENY decisions map to <code>denied</code> outcome; specific reason codes also provided</td>\r\n        <td><span class=\"tag-ok\">Aligned</span></td>\r\n      </tr>\r\n      <tr>\r\n        <td>Tamper-evident record storage</td>\r\n        <td>Receipts written to tamper-evident storage, Ed25519-signed at write time; sealed sequences copied to an independently held archive</td>\r\n        <td><span class=\"tag-ok\">Aligned</span></td>\r\n      </tr>\r\n      <tr>\r\n        <td>Trust level per record</td>\r\n        <td>Gate enforces key verification on all requests; receipts are signed by the gate — an authority independent of the agent (L2 characteristics)</td>\r\n        <td><span class=\"tag-ok\">Aligned</span></td>\r\n      </tr>\r\n    </tbody>\r\n  </table>\r\n  </div>\r\n\r\n  <h2>Where AgenticRail Goes Further</h2>\r\n\r\n  <div class=\"table-wrap\">\r\n  <table>\r\n    <thead>\r\n      <tr>\r\n        <th>Capability</th>\r\n        <th>Draft standard</th>\r\n        <th>AgenticRail</th>\r\n      </tr>\r\n    </thead>\r\n    <tbody>\r\n      <tr>\r\n        <td>Record timing</td>\r\n        <td>Post-event (outcome recorded after action completes)</td>\r\n        <td><strong>Pre-execution</strong> — receipt written at gate decision time, before action runs</td>\r\n      </tr>\r\n      <tr>\r\n        <td>Step order enforcement</td>\r\n        <td>Not specified — records are individual events, no sequence enforcement</td>\r\n        <td>Strict step-order enforced across session; SEQUENCE_VIOLATION returned for out-of-order steps</td>\r\n      </tr>\r\n      <tr>\r\n        <td>Replay protection</td>\r\n        <td>Not specified</td>\r\n        <td>Nonce ledger per session; REPLAY_NONCE for any reused nonce</td>\r\n      </tr>\r\n      <tr>\r\n        <td>Sequence sealing</td>\r\n        <td>Not specified</td>\r\n        <td>Session sealed at final step; SEALED_SEQUENCE for any subsequent request</td>\r\n      </tr>\r\n      <tr>\r\n        <td>DENY reason codes</td>\r\n        <td>Single <code>denied</code> outcome value</td>\r\n        <td>SEQUENCE_VIOLATION / REPLAY_NONCE / ACTION_NOT_ALLOWED / UNKNOWN_STEP / SEALED_SEQUENCE / STALE_TIMESTAMP / ARTIFACT_UNBOUND</td>\r\n      </tr>\r\n      <tr>\r\n        <td>Timestamp freshness</td>\r\n        <td>Timestamp field required; no freshness check defined</td>\r\n        <td>|ts_ms − now| &gt; 300s → STALE_TIMESTAMP — closes replay-with-fresh-nonce-after-delay</td>\r\n      </tr>\r\n    </tbody>\r\n  </table>\r\n  </div>\r\n\r\n  <h2>An AgenticRail Receipt Mapped to Draft Fields</h2>\r\n\r\n  <p>Here is an AgenticRail ALLOW receipt with the IETF draft fields mapped:</p>\r\n\r\n  <div class=\"code-block\">\r\n    <div class=\"code-label\">AgenticRail receipt — IETF field mapping</div>\r\n    <pre><span class=\"kv\">{\r\n  <span class=\"comment\">// draft: record_id (SHA-256, 64 hex chars)</span>\r\n  <span class=\"key\">\"pack_id\"</span>: <span class=\"val-str\">\"24449424694a3f...e020\"</span>,\r\n\r\n  <span class=\"comment\">// draft: outcome (\"success\" / \"denied\")</span>\r\n  <span class=\"key\">\"decision\"</span>: <span class=\"val-ok\">\"ALLOW\"</span>,\r\n  <span class=\"key\">\"reasons\"</span>: [],\r\n  <span class=\"key\">\"executed\"</span>: <span class=\"val-ok\">true</span>, <span class=\"comment\">// permitted — not proof the downstream action performed</span>\r\n\r\n  <span class=\"comment\">// draft: session_id, agent identity, action_type, action_detail — carried in meta</span>\r\n  <span class=\"key\">\"meta\"</span>: {\r\n    <span class=\"key\">\"model_id\"</span>: <span class=\"val-str\">\"client:acme-bank\"</span>,\r\n    <span class=\"key\">\"sequence_id\"</span>: <span class=\"val-str\">\"credit-approval-20260512-001\"</span>,\r\n    <span class=\"key\">\"step\"</span>: <span class=\"val-str\">\"intake\"</span>,\r\n    <span class=\"key\">\"function\"</span>: <span class=\"val-str\">\"intake\"</span>,\r\n    <span class=\"key\">\"action_type\"</span>: <span class=\"val-str\">\"CHECK_STATE\"</span>\r\n  },\r\n\r\n  <span class=\"comment\">// binds the full request — nonce, inputs, labels — into the record</span>\r\n  <span class=\"key\">\"payload_hash\"</span>: <span class=\"val-str\">\"9080bd2ac4da...86cb\"</span>,\r\n\r\n  <span class=\"comment\">// draft: prev_hash — SHA-256 of the prior receipt's canonical JSON</span>\r\n  <span class=\"key\">\"prev_receipt_id\"</span>: <span class=\"val-str\">\"a7f3c91b22e0...54da\"</span>,\r\n  <span class=\"key\">\"prev_receipt_hash\"</span>: <span class=\"val-str\">\"b6a18d234e38...338d\"</span>,\r\n\r\n  <span class=\"comment\">// draft: timestamp</span>\r\n  <span class=\"key\">\"ts_ms\"</span>: <span class=\"val-num\">1715507244154</span>,\r\n\r\n  <span class=\"key\">\"key_id\"</span>: <span class=\"val-str\">\"k2_2026-06-07_ed25519\"</span>,\r\n  <span class=\"key\">\"signature_alg\"</span>: <span class=\"val-str\">\"Ed25519\"</span>,\r\n  <span class=\"key\">\"signature\"</span>: <span class=\"val-str\">\"TpQr8f3aXz9c2b1d...\"</span>, <span class=\"comment\">// base64, over the canonical receipt</span>\r\n  <span class=\"key\">\"version\"</span>: <span class=\"val-str\">\"slp8_pack_1.0\"</span>\r\n}</span></pre>\r\n  </div>\r\n\r\n  <p>The structural alignment is clear. And the pre-execution property needs no special field: the receipt <em>is</em> the gate decision, written at the moment of authorisation, before the action runs. The <code>executed</code> field records that the step was permitted — deliberately not a claim that the downstream action performed.</p>\r\n\r\n  <h2>DENY Receipt: The <code>denied</code> Outcome</h2>\r\n\r\n  <div class=\"code-block\">\r\n    <div class=\"code-label\">AgenticRail DENY — maps to draft outcome: \"denied\"</div>\r\n    <pre><span class=\"kv\">{\r\n  <span class=\"key\">\"pack_id\"</span>: <span class=\"val-str\">\"0098a55bab90...823e\"</span>,\r\n\r\n  <span class=\"comment\">// draft outcome: \"denied\"</span>\r\n  <span class=\"key\">\"decision\"</span>: <span class=\"val-deny\">\"DENY\"</span>,\r\n\r\n  <span class=\"comment\">// AgenticRail extension: specific reason codes, as an array</span>\r\n  <span class=\"key\">\"reasons\"</span>: [<span class=\"val-deny\">\"SEQUENCE_VIOLATION\"</span>],\r\n  <span class=\"key\">\"executed\"</span>: <span class=\"val-deny\">false</span>,\r\n\r\n  <span class=\"key\">\"meta\"</span>: {\r\n    <span class=\"key\">\"model_id\"</span>: <span class=\"val-str\">\"client:acme-bank\"</span>,\r\n    <span class=\"key\">\"sequence_id\"</span>: <span class=\"val-str\">\"credit-approval-20260512-001\"</span>,\r\n    <span class=\"key\">\"step\"</span>: <span class=\"val-str\">\"execution\"</span>,\r\n    <span class=\"key\">\"function\"</span>: <span class=\"val-str\">\"execution\"</span>,\r\n    <span class=\"key\">\"action_type\"</span>: <span class=\"val-str\">\"SELECT_NEXT_STEP\"</span>\r\n  },\r\n\r\n  <span class=\"key\">\"payload_hash\"</span>: <span class=\"val-str\">\"b6a18d234e38...338d\"</span>,\r\n  <span class=\"key\">\"prev_receipt_hash\"</span>: <span class=\"val-str\">\"b1d8e27c9a04...61f2\"</span>,\r\n  <span class=\"key\">\"ts_ms\"</span>: <span class=\"val-num\">1715507311208</span>,\r\n  <span class=\"key\">\"key_id\"</span>: <span class=\"val-str\">\"k2_2026-06-07_ed25519\"</span>,\r\n  <span class=\"key\">\"signature_alg\"</span>: <span class=\"val-str\">\"Ed25519\"</span>,\r\n  <span class=\"key\">\"signature\"</span>: <span class=\"val-str\">\"Nq4wRz1c8f3aXz9c...\"</span>\r\n}</span></pre>\r\n  </div>\r\n\r\n  <p>The draft records <code>denied</code>. AgenticRail records <code>DENY</code> with <code>SEQUENCE_VIOLATION</code> in its <code>reasons</code> array — a step was submitted out of order. An auditor reading this receipt knows not just that something was denied, but exactly which policy rule fired and what the agent attempted.</p>\r\n\r\n  <h2>Regulatory Context</h2>\r\n\r\n  <p>The draft explicitly references the following regulatory frameworks:</p>\r\n\r\n  <div class=\"table-wrap\">\r\n  <table>\r\n    <thead>\r\n      <tr>\r\n        <th>Framework</th>\r\n        <th>Relevant Requirement</th>\r\n        <th>Draft coverage</th>\r\n      </tr>\r\n    </thead>\r\n    <tbody>\r\n      <tr>\r\n        <td>EU AI Act Article 12</td>\r\n        <td>Automatic recording of events enabling reconstruction of the sequence</td>\r\n        <td><span class=\"tag-partial\">Structural — no pre-execution mandate</span></td>\r\n      </tr>\r\n      <tr>\r\n        <td>EU AI Act Article 26</td>\r\n        <td>Deployers retain logs at least 6 months</td>\r\n        <td><span class=\"tag-note\">Not specified — retention policy outside draft scope</span></td>\r\n      </tr>\r\n      <tr>\r\n        <td>ISO/IEC 42001</td>\r\n        <td>AI management system risk controls and evidence</td>\r\n        <td><span class=\"tag-partial\">Structure aligns; enforcement controls outside draft scope</span></td>\r\n      </tr>\r\n      <tr>\r\n        <td>SOC 2</td>\r\n        <td>Availability, confidentiality, integrity controls</td>\r\n        <td><span class=\"tag-partial\">Hash chain satisfies integrity; storage controls outside draft scope</span></td>\r\n      </tr>\r\n      <tr>\r\n        <td>PCI DSS</td>\r\n        <td>Audit log completeness and tamper evidence</td>\r\n        <td><span class=\"tag-partial\">Chain tamper evidence aligns; field completeness depends on implementation</span></td>\r\n      </tr>\r\n    </tbody>\r\n  </table>\r\n  </div>\r\n\r\n  <p>The draft is a structural foundation. It defines how records relate to each other and what fields every record must carry. It does not specify the enforcement architecture that produces those records — that is left to implementors. For EU AI Act purposes, the draft alone gets you a well-formed log. Pre-execution enforcement is what makes that log admissible as evidence of control rather than observation.</p>\r\n\r\n  <h2>What This Means in Practice</h2>\r\n\r\n  <p>If you are evaluating agent audit infrastructure against the IETF draft, the questions to ask are:</p>\r\n\r\n  <ol>\r\n    <li><strong>When is the record written?</strong> At action completion, or at gate decision time before execution? The draft allows both. Only pre-execution records provide enforcement evidence.</li>\r\n    <li><strong>Who writes the record?</strong> The agent itself (L0/L1), or an independent gate (L2+)? The draft requires trust level to be declared — it does not require independence. Auditors will ask.</li>\r\n    <li><strong>Are all 11 mandatory fields present?</strong> Missing any one — including <code>trust_level</code> or <code>prev_hash</code> — makes the record non-conformant.</li>\r\n    <li><strong>Is the chain verifiable independently?</strong> JCS canonicalisation must be reproducible without the original system. Verify hashes offline before claiming chain integrity.</li>\r\n    <li><strong>What does <code>denied</code> mean in your implementation?</strong> The draft has one denied outcome. What rule fired? Which step was out of order? Reason codes are not required by the draft — but they are what compliance teams and auditors actually need.</li>\r\n  </ol>\r\n\r\n  <div class=\"stat-row\">\r\n    <div class=\"stat-box\">\r\n      <span class=\"stat-val\">11</span>\r\n      <span class=\"stat-label\">Mandatory fields per record</span>\r\n    </div>\r\n    <div class=\"stat-box\">\r\n      <span class=\"stat-val\">L0–L4</span>\r\n      <span class=\"stat-label\">Trust verification levels</span>\r\n    </div>\r\n    <div class=\"stat-box\">\r\n      <span class=\"stat-val\">RFC 8785</span>\r\n      <span class=\"stat-label\">Canonicalisation standard (JCS)</span>\r\n    </div>\r\n    <div class=\"stat-box\">\r\n      <span class=\"stat-val\">2026-09-29</span>\r\n      <span class=\"stat-label\">Draft expiry date</span>\r\n    </div>\r\n  </div>\r\n\r\n  <h2>Summary</h2>\r\n\r\n  <p>The IETF agent audit trail draft is the right structural starting point. It defines a hash-chained, tamper-evident record format with trust levels and mandatory fields that map cleanly onto EU AI Act, ISO 42001, and other compliance frameworks. If you are building agent audit infrastructure, building to the draft gives you a schema that regulators and auditors will recognise.</p>\r\n\r\n  <p>The gap the draft leaves open is enforcement. A conformant log can be written post-hoc by the agent itself. For compliance contexts where the question is not just \"what happened?\" but \"what was the agent permitted to do, and was that permission granted before execution?\" — you need a gate that fires before execution and signs a receipt at the moment of decision. That is what AgenticRail provides, on top of the structural alignment the draft defines.</p>\r\n\r\n  <div class=\"cta-block\">\r\n    <h3>See IETF-aligned receipts in the live demo</h3>\r\n    <p>Run a sequence through AgenticRail and inspect the hash-chained receipts — canonical JSON, Ed25519-signed, hash-chained, written pre-execution.</p>\r\n    <a href=\"/demo/\" class=\"btn\">Open Demo</a>\r\n    <a href=\"/docs/\" class=\"btn btn-ghost\">Read Docs</a>\r\n  </div>\r\n\r\n  <a href=\"/blog/\" class=\"back-link\">← All posts</a>\r\n\r\n</div>\r\n\r\n<div class=\"pare-band\"></div>\r\n\r\n<footer>\r\n  <div class=\"footer-left\">© 2026 TUARA KURI LIMITED — trading as AgenticRail. Hokianga, New Zealand.</div>\r\n  <div class=\"footer-right\">\r\n    <a href=\"/docs/\">Docs</a>\r\n    <a href=\"https://report.agenticrail.nz/report\">Verify</a>\r\n    <a href=\"mailto:hello@agenticrail.nz\">hello@agenticrail.nz</a>\r\n  </div>\r\n  <p style=\"margin-top:16px;text-align:center;font-style:italic;opacity:0.6;font-size:0.72rem;letter-spacing:0.03em\">He toi whakairo, he mana tangata</p>\r\n</footer>\r\n\r\n<script defer src=\"/site-ekg.js\"></script>\r\n<!-- Cloudflare Pages Analytics --><script defer src='https://static.cloudflareinsights.com/beacon.min.js' data-cf-beacon='{\"token\": \"13ab256aaf5b46478c927041639b10c9\"}'></script><!-- Cloudflare Pages Analytics --><script>(function(){function c(){var b=a.contentDocument||(a.contentWindow&&a.contentWindow.document);if(b){var d=b.createElement('script');d.innerHTML=\"window.__CF$cv$params={r:'a216553e0ff45bc0',t:'MTc4NTA5OTYxNg=='};var a=document.createElement('script');a.src='/cdn-cgi/challenge-platform/scripts/jsd/main.js';document.getElementsByTagName('head')[0].appendChild(a);\";b.getElementsByTagName('head')[0].appendChild(d)}}if(document.body){var a=document.createElement('iframe');a.height=1;a.width=1;a.style.position='absolute';a.style.top=0;a.style.left=0;a.style.border='none';a.style.visibility='hidden';document.body.appendChild(a);if('loading'!==document.readyState)c();else if(window.addEventListener)document.addEventListener('DOMContentLoaded',c);else{var e=document.onreadystatechange||function(){};document.onreadystatechange=function(b){e(b);'loading'!==document.readyState&&(document.onreadystatechange=e,c())}}}})();</script></body>\r\n</html>\r\n","snapshot_chars":44189,"live_check":"changed"}]}