As AI agents move from assisting employees to taking actions on their behalf, security teams face a new accountability problem: It’s no longer enough to know what happened. As agents gain access to sensitive data, systems and business processes, organizations are likely to need evidence that establishes not only what an agent did but also why it was permitted to do it. That includes demonstrating that an agent had the right authority, was acting for the right purpose, and stayed within the boundaries established for that particular task.
Cybersecurity experts have warned that agentic systems complicate the traditional model, in which actions can be traced to an identifiable person with defined permissions and a clear audit trail. And at the moment, teams may need to work on solving the AI accountability conundrum on their own—while the issue is unquestionably on guiding agencies’ radars, NIST only began requesting input for a project on how identity standards and best practices can be applied to software agents in February 2026.
Among those with an eye on the security challenges that come with AI agents are the members of the Senior Executive Cybersecurity Think Tank. They bring deep experience in enterprise cybersecurity, risk management, security architecture and emerging technology to bear on the question. Below, two of them examine how organizations should rethink evidence and auditability for agent-driven workflows and what stronger, more trustworthy proof of authorization could look like in practice.
“A log saying ‘agent approved request’ is not enough.”
Capture the Full Decision Path
For Harikrishnan Muthukrishnan, Principal IT Developer for BCBS FLORIDA, auditability needs to extend well beyond a record of the action an agent ultimately took.
“For agent-driven workflows, evidence must prove the full decision path, not just the final action. A log saying ‘agent approved request’ is not enough,” he says. “Audit records should capture the input, prompt, retrieved data, tool calls, policy checks, approval context and final execution.”
Muthukrishnan also cautions against a “set it and forget it” approach to permissions.
“Agents should not carry broad standing authority; sensitive actions need scoped, time-limited authorization tied to a specific task,” he says.
That approach aligns with emerging guidance for securing AI agents, which calls for explicit approval of high-impact actions, clear audit trails and authorization tied to the precise action being performed. Muthukrishnan says those boundaries should be verifiable after the fact.
“Stronger proof would include a signed authorization token showing who approved the action, what the agent was allowed to do, which system it could access, and when permission expired,” he says. “Policies should be enforced as code so the record shows the exact policy version, attributes evaluated, access decision and any exception granted.”
“Leaders must rethink auditability as intent verification, not just action logging.”
Build Auditability for Agentic Risk
Kumar Ritesh, Founder, Chairman and CEO of CYFIRMA, sees a more fundamental mismatch between traditional audit practices and the way AI agents operate.
“AI agents make contextual decisions at machine speed, often invisibly,” he says. “Traditional audit trails were designed for human actions; they’re structurally inadequate for agentic workflows.
“Leaders must rethink auditability as intent verification, not just action logging,” he continues. “Stronger proof requires capturing the reasoning chain, what data the agent accessed, what it inferred, and whether that context was manipulated.”
That last concern introduces a cybersecurity dimension: The evidence itself must remain trustworthy even if an agent behaves unexpectedly or is compromised. OWASP’s Autonomous Penetration Testing Standard, which addresses auditability requirements for autonomous agentic systems, recommends isolating authoritative audit records from the agent runtime and using controls that preserve their evidentiary value.
Ritesh emphasizes that agent behavior must be treated as a threat surface. He details the checks and requirements that need to be in place.
“Real auditability means cryptographically anchored decision logs, real-time anomaly detection against known threat patterns, and continuous validation that agent outputs align with preauthorized intent boundaries,” he says. “In practice, this takes immutable reasoning transcripts, dynamic authorization tokens scoped per task, and adversarial simulation that tests whether your audit trail can detect a compromised agent, not just a compliant one.”
Strengthening the Evidence Behind Agent Actions
- Capture the full decision path, not just the outcome. Audit records should preserve the inputs, prompts, retrieved data, tool calls, policy checks, approval context and final execution surrounding sensitive actions.
- Limit agent authority to the task at hand. Use scoped, time-limited permissions rather than broad standing access, especially when agents interact with sensitive systems or data.
- Make authorization independently verifiable. Signed authorization tokens and policy-as-code records can help show who approved an action, what the agent was allowed to do, and which rules governed the decision.
- Treat auditability as a cybersecurity control. Evidence should help leaders determine not only what an agent did but also whether its behavior remained aligned with authorized intent.
- Protect the integrity of the audit trail itself. Immutable or cryptographically anchored records can make it harder for compromised systems or agents to alter the evidence used for review.
- Test audit controls against hostile behavior. Adversarial simulations can reveal whether monitoring and evidence mechanisms would detect a compromised agent rather than only documenting normal operations.
Building Trust in Agent-Driven Workflows
As AI agents take on more sensitive responsibilities, traditional logs and approval records may not provide enough context to establish that an action was properly authorized. Stronger auditability will require organizations to capture the full decision process, tightly control agent permissions and preserve evidence that can be trusted after an action occurs.
The challenge will only grow as agents become more autonomous and interconnected with critical business systems. Security and control leaders who build stronger evidence standards now will be better positioned to answer a question that’s likely to become increasingly important: not simply whether an agent took an action, but whether it had the right to take it in the first place.
MOST POPULAR
AI Is Commoditized—Here's What Sets Great Brands Apart
9 Ways to Measure the Success of Your DEI Strategy in 2023
Inspiring Ideas. Actionable Insights.
Senior Executive's Email Newsletters Deliver Fresh Solutions to Today's Leadership Challenges.
Subscribe Free
Where Marketing Teams Go Wrong With AI—and How to Fix It
The Human Side of AI: Building Better Customer Relationships
Top 5 Professional Associations for Marketing Professionals: Membership Benefits & Reviews
