Guidelines  ·  2026-09-28

Agent Audit Trail (AAT) — draft-sharif-agent-audit-trail-05, standard logging format for autonomous AI systems

GuidelinesMedium impactGlobal
On 2026-09-25 the individual Internet-Draft was updated to revision -05 (expires 2026-03-29), continuing the AAT series that defines a JSON-based, tamper-evident (SHA-256 hash-chained, RFC 8785) audit-record format for autonomous AI agents with mandatory agent-identity, action-classification and trust-level fields. Prior revisions added pre-execution recording, recording independence, decision-reproducibility attestation closure (-03), and post-quantum signature agility (ML-DSA-65/FIPS 204), signer key identifiers, trust-level integrity and optional Merkle batch anchoring (-04); the -05 update advances that draft in-window. It maps to EU AI Act logging obligations, ISO/IEC 42001, draft ISO/IEC 24970 and prEN 18229-1. (This is a genuine new revision beyond the -04 draft covered 2026-09-21.)
Agent audit trails are the practical substrate most AI-security frameworks reference for accountability and incident reconstruction. A fresh IETF draft revision gives implementers and vendors an updated de-facto-consensus format for agent evidence, aligned to the EU AI Act's high-risk logging duty (application dates staged to 2027-2028) and to PCI DSS/SOC2 mapping.
Platform and agent-security engineers should review -05 for changes to record fields, signing and export requirements and align their agent logging designs; submit IETF comments/implementation feedback before expiry.
IETF Datatracker — draft-sharif-agent-audit-trailAgent Audit Trail standard site
See this in the live feed Explore related AI security and governance findings — updated every morning.
Open the feed →