The AI audit trail problem: what regulators actually want to see

The AI audit trail problem: what regulators actually want to see

Cyril Treacy

COO and Co-Founder

This post explains what a defensible AI audit trail has to capture in 2026, how supervisors read it against the EU AI Act, FCA, and NIST AI RMF, and where most enterprises are still confusing system logs with AI Evidence.

This post explains what a defensible AI audit trail has to capture in 2026, how supervisors read it against the EU AI Act, FCA, and NIST AI RMF, and where most enterprises are still confusing system logs with AI Evidence.

Key Takeaways

  • System logs and an AI audit trail are not the same artefact. Logs record events. An audit trail records decisions, context, and accountability.

  • The EU AI Act becomes fully applicable for high-risk systems in August 2026, with named obligations a document repository cannot satisfy.

  • The FCA reads AI governance through its existing principles-based regime, with SMCR and PRA model risk principles already applying. NIST AI RMF organises the same expectation into GOVERN, MEASURE, MANAGE.

  • A defensible AI audit trail captures four things: decision inputs, action log, policy state, and human oversight record.

  • Audit trails are a Prove & Comply capability inside the AI Assurance Lifecycle. The record has to be generated in real time, not reconstructed after the fact.

Key Takeaways

  • System logs and an AI audit trail are not the same artefact. Logs record events. An audit trail records decisions, context, and accountability.

  • The EU AI Act becomes fully applicable for high-risk systems in August 2026, with named obligations a document repository cannot satisfy.

  • The FCA reads AI governance through its existing principles-based regime, with SMCR and PRA model risk principles already applying. NIST AI RMF organises the same expectation into GOVERN, MEASURE, MANAGE.

  • A defensible AI audit trail captures four things: decision inputs, action log, policy state, and human oversight record.

  • Audit trails are a Prove & Comply capability inside the AI Assurance Lifecycle. The record has to be generated in real time, not reconstructed after the fact.

Why "we have logs" is not the same as "we have an audit trail"

System logs are not an audit trail. The two answer different questions, and supervisors read them as different categories.

A system log captures events. Timestamps, error codes, request and response payloads, infrastructure traces. The operational record an engineering team uses to debug.

An audit trail captures decisions. What the system was asked to do. What it actually did. Under which policy. With what human oversight. A structured record built to be read by a supervisor, not by the engineer who shipped the agent.

For AI agents the gap widens. An AI audit trail has to record the data the agent saw, the instruction it was operating under, the action it took, and the reason that action was permitted by the policies in force at the time.

The failure mode worth naming is PowerPoint Governance. A policy deck, a committee minute, a risk register in SharePoint, all costed as the AI compliance answer. None of it produces the AI Evidence a supervisor reads after an incident.

What regulators actually expect: EU AI Act, FCA, and NIST AI RMF

Three regimes converge on one demand: a continuous, structured record of how the system behaved against named obligations.

The EU AI Act becomes fully applicable for high-risk systems in August 2026. Article 9 requires a continuous, lifecycle-wide risk management system. Article 13 requires transparency to deployers. Article 26 sets deployer obligations: monitoring in operation, retaining logs, assigning human oversight to a named natural person, reporting serious incidents. Article 72 requires providers to collect and analyse performance data across the system's lifetime.

The FCA reads AI governance through its principles-based regime, not a dedicated AI rulebook. Not a softer test. A more demanding one. Firms must demonstrate model governance, explainability, and ongoing monitoring. The FCA's DP5/22 and the PRA's model risk principles in SS1/23 already apply. SMF24, SMF4, and SMF16 are the named accountabilities.

For US and multinational firms the NIST AI Risk Management Framework is the de facto benchmark. GOVERN, MEASURE, MANAGE. Documentation is a continuous output, not a one-time artefact.

The four things every AI audit trail must capture

A defensible AI audit trail captures four categories of record, each mapped to a named obligation, each existing in real time.

  1. Decision inputs. The data and context the agent acted on. The prompt, the retrieval calls and what they returned, the user or upstream agent that initiated the action. The factual base of the decision.

  1. Action log. Every action the agent took, with timestamp, system context, and downstream effect. Each intermediate tool call, each external system touched. For agentic systems the action log carries most of the audit weight.

  1. Policy state. Which policies were active at the time of the decision, which guardrails were in force, which thresholds applied. Without versioned policy state, an audit trail cannot answer whether the action was permitted under the rules that applied that day.

  1. Human oversight record. When humans were in the loop and what they approved. Article 26 makes oversight a named obligation; the FCA reads it against SMCR. The trail has to identify the natural person, their competence, and the record they reviewed.

A trail that captures all four in real time is Continuous AI Governance. One or two is the document repository pattern in a new format.

How the AI Assurance Lifecycle generates the record

Disseqt is the only assurance layer in the industry built for the full enterprise AI lifecycle, unified in one platform. Test & Detect. Protect & Enforce. Prove & Comply. One spine, three pillars, every stage of the AI Assurance Lifecycle covered.

  1. Test & Detect. Generates the pre-deployment record. Continuous testing, vulnerability detection, threshold-based sign-off. The evidence pack feeds the Article 9 file.

  1. Protect & Enforce. Generates policy state, human oversight, and the action log at the inference layer. Run-time protection, policy enforcement, continuous monitoring, the named approver and the record they reviewed.

  1. Prove & Comply. Generates the audit-ready evidence. Automated compliance reporting, enterprise-grade auditability, SOC2, SSO/SCIM, RBAC. Structured reports mapped to obligations across the EU AI Act, FCA, and NIST AI RMF.

One Window for the Full AI Assurance Lifecycle. Three pillars, one AI Evidence trail, end-to-end in one platform.

Bottom Line

Regulators are not asking for more documentation. They are asking for a different category of record. Decisions rather than events. Policy state rather than policy intent. Human oversight rather than committee attendance.

Disseqt is the only assurance layer in the industry built for the full enterprise AI lifecycle, covering testing, monitoring, policy enforcement, audit trails, and compliance reporting, unified in one platform. Firms producing AI Evidence in real time will have a clean answer when the supervisor calls. Firms producing PowerPoint Governance will be reconstructing a record that was never captured.

FAQs

01

What is an AI audit trail?

An AI audit trail is a structured, continuous record of how an AI system or agent made decisions, what data it acted on, which policies were in force, and what humans approved. It is distinct from a system log, which records events for operational debugging.

02

What does the EU AI Act require for AI documentation?

The EU AI Act requires high-risk systems to maintain a documented risk management system (Article 9), automatic logging (Article 12), transparency (Article 13), deployer monitoring and human oversight (Article 26), and continuous post-market monitoring (Article 72). Full applicability begins August 2026.

03

What does the FCA expect from AI governance in financial services?

The FCA reads AI governance through its principles-based framework, including SMCR and the PRA's SS1/23. Firms must demonstrate model governance, explainability, and ongoing monitoring on demand, with SMF24, SMF4, and SMF16 as the named accountabilities.

04

How do you demonstrate AI compliance to regulators?

By producing a continuous AI audit trail that captures four categories of record in real time: decision inputs, action log, policy state, and human oversight. Each maps to obligations under the EU AI Act, FCA, or NIST AI RMF.

AUTHOR

Cyril Treacy

COO and Co-Founder

Cyril is Co-Founder and COO at Disseqt, leading go-to-market, partnerships, and customer success. He brings 20+ years of enterprise sales, pre-sales leadership, and scaling expertise from Salesforce and the Irish startup ecosystem.

See Disseqt in action
Book a 30-minute walkthrough

Our team will walk you through a live workflow using your own AI environment. No slides. No generic demo. A real walkthrough of how Disseqt fits into your stack.

See Disseqt in action
Book a 30-minute walkthrough

Our team will walk you through a live workflow using your own AI environment. No slides. No generic demo. A real walkthrough of how Disseqt fits into your stack.

See Disseqt in action
Book a 30-minute walkthrough

Our team will walk you through a live workflow using your own AI environment. No slides. No generic demo. A real walkthrough of how Disseqt fits into your stack.