What happened
Individual Internet-Draft updated 2026-09-15 (revision -04). It specifies a JSON-based agent audit-trail record format with mandatory fields for agent identity, action classification, outcome tracking and trust-level reporting, tamper-evident SHA-256 hash chaining (RFC 8785), optional ECDSA and new post-quantum ML-DSA-65 (FIPS 204) signatures, signer key identifiers, trust-level assignment integrity, and optional Merkle batch anchoring. It explicitly addresses EU AI Act automatic event-recording obligations and maps to ISO/IEC 42001, draft ISO/IEC 24970, SOC 2 and PCI DSS logging.
Why it matters
Autonomous AI agents are increasingly auditable only if their actions are captured in an interoperable, tamper-evident log; this draft is an early standards body answer to accountability/forensics for agentic systems and informs how the EU AI Act's recording requirements will be met in practice.
Action needed
Track the I-D; prototype AAT-format agent activity logging to validate fit; submit technical comments to the draft's authors.