Subject: Evidence request — AI agent activity, Q3
As part of this year's review cycle, please provide the following, covering the three highest-risk AI agents identified in last quarter's risk assessment:
- Complete, reconstructible logs of each agent's actions for the period, sufficient to replay any single decision — including model version, prompt, tool inputs, and tool outputs.
- Attestation that those logs have not been modified after the fact, with a mechanism that proves immutability cryptographically.
- Mapping of the agent's permissions to your risk and compliance framework — EU AI Act Article 12, DORA Article 17, or equivalent.
- Records showing which human approved the agent's capabilities, when, and under what policy — with evidence that the policy was enforced.
- Evidence of any incident or near-miss in the period, with timeline reconstructed from the logs.
Please respond within fifteen business days. Findings will be raised where evidence is unavailable or insufficient.