[{"data":1,"prerenderedAt":20},["ShallowReactive",2],{"blog-post-en-ai-agent-audit-trail-eu-ai-act":3},{"slug":4,"lang":5,"title":6,"description":7,"heading":6,"translationKey":8,"date":9,"keywords":10,"readingMinutes":16,"html":17,"alternates":18},"ai-agent-audit-trail-eu-ai-act","en","AI agent audit trail: what to log under the EU AI Act","What an audit trail for AI agents should record, why the AI vendor's own log is not independent evidence, and how the EU AI Act and GDPR frame it.","audit-trail","2026-09-18",[11,12,13,14,15],"AI agent audit trail","EU AI Act logging","AI agent audit log","EU AI Act record-keeping","AI governance audit",8,"\u003Cp>AI agents in software teams no longer only answer questions. They create Jira issues, comment on\npull requests, query tables in Databricks and post messages in Slack. Each of these actions is a\ncall against a real system, made with real credentials. When something goes wrong, or when an\nauditor or a customer asks what an agent did, the team needs a record that answers the question\nprecisely. In many organisations that record does not exist, or it exists only in the logs of the\nAI vendor.\u003C\u002Fp>\n\u003Cp>This post describes what an audit trail for AI agents should contain, why the location of the log\nmatters as much as its content, and how the EU AI Act and the GDPR frame the topic. It is part of\nour series on \u003Ca href=\"\u002Fblog\u002Fai-agents-software-development-lifecycle\">AI agents in the software development lifecycle\u003C\u002Fa>.\u003C\u002Fp>\n\u003Ch2>Why the question comes up now\u003C\u002Fh2>\n\u003Cp>Two developments meet here. First, agents act on more systems than before. With the Model Context\nProtocol (MCP), a client such as Claude Code, Cursor or VS Code can call tools in Jira, GitHub or\nConfluence directly. Second, regulation has started to ask for evidence. The\n\u003Ca href=\"https:\u002F\u002Feur-lex.europa.eu\u002Feli\u002Freg\u002F2024\u002F1689\u002Foj\">EU AI Act (Regulation (EU) 2024\u002F1689)\u003C\u002Fa> contains\nexplicit record-keeping duties, and the GDPR has required accountability for any processing of\npersonal data since 2018.\u003C\u002Fp>\n\u003Cp>The timeline is often misread, so it is worth stating it carefully. Prohibited practices apply\nsince 2 February 2025, and obligations for general-purpose AI models since 2 August 2025. The\ntransparency obligations of Article 50 apply from 2 August 2026. The obligations for high-risk\nsystems were postponed by the Digital Omnibus (Regulation (EU) 2026\u002F1744, in force since 27 July\n2026): stand-alone high-risk systems listed in Annex III follow from 2 December 2027, and AI\nembedded in regulated products under Annex I from 2 August 2028.\u003C\u002Fp>\n\u003Cp>It is also important to be honest about scope. Most agents that plan sprints, review code or\nupdate documentation are not high-risk systems in the sense of the AI Act. The strict logging\nduties of Article 12 therefore do not apply to them directly. However, this does not make the\nquestion irrelevant. As soon as an agent reads or passes on personal data, the GDPR applies, and\nthe controller must be able to demonstrate what happened (Art. 5(2) GDPR). In addition, security\nteams and customers increasingly ask the same question an auditor would ask: which agent did what,\nwith whose authority, and was it allowed?\u003C\u002Fp>\n\u003Ch2>What an audit trail for AI agents should contain\u003C\u002Fh2>\n\u003Cp>A useful audit trail answers five questions for every single call. The following fields are a\nreasonable minimum.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Who acted.\u003C\u002Fstrong> The identity behind the call: which agent or person, with which API key, in which\nproject or workspace. &quot;The AI did it&quot; is not an answer an auditor accepts. The record has to name\nthe accountable identity.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>What was requested.\u003C\u002Fstrong> The target system, the operation (for example \u003Ccode>jira_create_issue\u003C\u002Fcode> or\n\u003Ccode>github_merge_pr\u003C\u002Fcode>) and the parameters, such as the project key or the repository. Parameters can\ncontain personal or secret data, so they should be redacted before they are written. The log must\nnot become a second copy of the sensitive data it is meant to protect.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>What was decided, and why.\u003C\u002Fstrong> This is the part most logs miss. It is not enough to record\nsuccessful calls. A complete trail also records calls that were denied, together with the reason\n(for example &quot;operation not enabled for this workspace&quot; or &quot;repository not in allowlist&quot;), calls\nthat were held for human approval, calls that hit a rate limit and calls that failed with an\nerror. Denied calls are often the most informative entries, because they show what an agent tried\nto do outside its scope.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>When.\u003C\u002Fstrong> A precise timestamp, in a consistent time zone, so that entries can be correlated with\nevents in other systems.\u003C\u002Fp>\n\u003Cp>\u003Cstrong>Whether the record is intact.\u003C\u002Fstrong> An audit trail is only evidence if nobody can quietly change it\nafterwards. This requires technical protection, not only a policy that says &quot;do not edit&quot;.\u003C\u002Fp>\n\u003Cp>A good test is to take one real incident and try to reconstruct it from the log alone. If the\nreconstruction needs screenshots, chat histories or somebody&#39;s memory, the log is incomplete.\u003C\u002Fp>\n\u003Ch2>Why the vendor&#39;s log is not independent evidence\u003C\u002Fh2>\n\u003Cp>Several AI vendors now offer audit logs for their own tools and connectors. These logs are useful\nfor operating the tool, and there is no reason to ignore them. However, as evidence they have a\nstructural weakness: the party that is being evaluated also keeps the record.\u003C\u002Fp>\n\u003Cp>This matters for three reasons. First, independence: an auditor treats a log kept by the operator\nof the system under review differently from a log kept by a separate control. The situation is\ncomparable to financial accounting, where the bookkeeping and the audit are separated on purpose.\nSecond, coverage: a vendor log only covers that vendor&#39;s tools. A team that uses Claude Code for\ncode, Cursor in the IDE and an internal chatbot for support has three partial logs with three\nformats, and none of them shows the complete picture. Third, control over retention and access:\nthe retention period, the export format and the access rights are set by the vendor, not by the\norganisation that has to answer for the data.\u003C\u002Fp>\n\u003Cfigure class=\"post-figure\">\n\u003Csvg viewBox=\"0 0 760 300\" xmlns=\"http:\u002F\u002Fwww.w3.org\u002F2000\u002Fsvg\" role=\"img\" aria-labelledby=\"audit-where-title\">\n  \u003Ctitle id=\"audit-where-title\">Vendor logs cover only each vendor's own tool; a self-hosted gateway keeps one log for every agent call and forwards it.\u003C\u002Ftitle>\n  \u003Ctext class=\"fig-h fig-c-deny\" x=\"20\" y=\"32\">VENDOR LOGS\u003C\u002Ftext>\n  \u003Ctext class=\"fig-h fig-c-primary\" x=\"392\" y=\"32\">YOUR OWN GATEWAY\u003C\u002Ftext>\n  \u003Cpath class=\"fig-edge fig-edge--faint\" d=\"M370 20 V290\"\u002F>\n  \u003Crect class=\"fig-box fig-box--ai\" x=\"20\" y=\"60\" width=\"112\" height=\"44\" rx=\"8\"\u002F>\n  \u003Ctext class=\"fig-t\" x=\"76\" y=\"87\" text-anchor=\"middle\">Claude Code\u003C\u002Ftext>\n  \u003Cpath class=\"fig-edge\" d=\"M132 82 H196\"\u002F>\n  \u003Cpath class=\"fig-head--muted\" d=\"M196 82 l-7 -4 v8 z\"\u002F>\n  \u003Crect class=\"fig-box fig-box--muted fig-box--dashed\" x=\"196\" y=\"60\" width=\"152\" height=\"44\" rx=\"8\"\u002F>\n  \u003Ctext class=\"fig-t\" x=\"272\" y=\"79\" text-anchor=\"middle\">Log A\u003C\u002Ftext>\n  \u003Ctext class=\"fig-s\" x=\"272\" y=\"95\" text-anchor=\"middle\">vendor's retention\u003C\u002Ftext>\n  \u003Crect class=\"fig-box fig-box--ai\" x=\"20\" y=\"130\" width=\"112\" height=\"44\" rx=\"8\"\u002F>\n  \u003Ctext class=\"fig-t\" x=\"76\" y=\"157\" text-anchor=\"middle\">Cursor\u003C\u002Ftext>\n  \u003Cpath class=\"fig-edge\" d=\"M132 152 H196\"\u002F>\n  \u003Cpath class=\"fig-head--muted\" d=\"M196 152 l-7 -4 v8 z\"\u002F>\n  \u003Crect class=\"fig-box fig-box--muted fig-box--dashed\" x=\"196\" y=\"130\" width=\"152\" height=\"44\" rx=\"8\"\u002F>\n  \u003Ctext class=\"fig-t\" x=\"272\" y=\"149\" text-anchor=\"middle\">Log B\u003C\u002Ftext>\n  \u003Ctext class=\"fig-s\" x=\"272\" y=\"165\" text-anchor=\"middle\">vendor's retention\u003C\u002Ftext>\n  \u003Crect class=\"fig-box fig-box--ai\" x=\"20\" y=\"200\" width=\"112\" height=\"44\" rx=\"8\"\u002F>\n  \u003Ctext class=\"fig-t\" x=\"76\" y=\"227\" text-anchor=\"middle\">Chatbot\u003C\u002Ftext>\n  \u003Cpath class=\"fig-edge\" d=\"M132 222 H196\"\u002F>\n  \u003Cpath class=\"fig-head--muted\" d=\"M196 222 l-7 -4 v8 z\"\u002F>\n  \u003Crect class=\"fig-box fig-box--muted fig-box--dashed\" x=\"196\" y=\"200\" width=\"152\" height=\"44\" rx=\"8\"\u002F>\n  \u003Ctext class=\"fig-t\" x=\"272\" y=\"219\" text-anchor=\"middle\">Log C\u003C\u002Ftext>\n  \u003Ctext class=\"fig-s\" x=\"272\" y=\"235\" text-anchor=\"middle\">vendor's retention\u003C\u002Ftext>\n  \u003Crect class=\"fig-box fig-box--ai\" x=\"392\" y=\"60\" width=\"104\" height=\"44\" rx=\"8\"\u002F>\n  \u003Ctext class=\"fig-t\" x=\"444\" y=\"87\" text-anchor=\"middle\">Claude Code\u003C\u002Ftext>\n  \u003Cpath class=\"fig-flow fig-flow--ai\" d=\"M496 82 C508 82 508 152 520 152\"\u002F>\n  \u003Crect class=\"fig-box fig-box--ai\" x=\"392\" y=\"130\" width=\"104\" height=\"44\" rx=\"8\"\u002F>\n  \u003Ctext class=\"fig-t\" x=\"444\" y=\"157\" text-anchor=\"middle\">Cursor\u003C\u002Ftext>\n  \u003Cpath class=\"fig-flow fig-flow--ai\" d=\"M496 152 C508 152 508 152 520 152\"\u002F>\n  \u003Crect class=\"fig-box fig-box--ai\" x=\"392\" y=\"200\" width=\"104\" height=\"44\" rx=\"8\"\u002F>\n  \u003Ctext class=\"fig-t\" x=\"444\" y=\"227\" text-anchor=\"middle\">Chatbot\u003C\u002Ftext>\n  \u003Cpath class=\"fig-flow fig-flow--ai\" d=\"M496 222 C508 222 508 152 520 152\"\u002F>\n  \u003Cpath class=\"fig-flow fig-flow--ok\" d=\"M624 152 C638 152 638 82 652 82\"\u002F>\n  \u003Crect class=\"fig-box fig-box--ok\" x=\"652\" y=\"60\" width=\"96\" height=\"44\" rx=\"8\"\u002F>\n  \u003Ctext class=\"fig-t\" x=\"700\" y=\"87\" text-anchor=\"middle\">Audit log\u003C\u002Ftext>\n  \u003Cpath class=\"fig-flow fig-flow--ok\" d=\"M624 152 C638 152 638 152 652 152\"\u002F>\n  \u003Crect class=\"fig-box\" x=\"652\" y=\"130\" width=\"96\" height=\"44\" rx=\"8\"\u002F>\n  \u003Ctext class=\"fig-t\" x=\"700\" y=\"157\" text-anchor=\"middle\">CSV · JSON\u003C\u002Ftext>\n  \u003Cpath class=\"fig-flow fig-flow--ok\" d=\"M624 152 C638 152 638 222 652 222\"\u002F>\n  \u003Crect class=\"fig-box\" x=\"652\" y=\"200\" width=\"96\" height=\"44\" rx=\"8\"\u002F>\n  \u003Ctext class=\"fig-t\" x=\"700\" y=\"227\" text-anchor=\"middle\">SIEM\u003C\u002Ftext>\n  \u003Crect class=\"fig-box fig-box--primary\" x=\"520\" y=\"60\" width=\"104\" height=\"184\" rx=\"12\"\u002F>\n  \u003Ctext class=\"fig-t fig-c-primary\" x=\"572\" y=\"148\" text-anchor=\"middle\">Vordix\u003C\u002Ftext>\n  \u003Ctext class=\"fig-s\" x=\"572\" y=\"166\" text-anchor=\"middle\">self-hosted\u003C\u002Ftext>\n  \u003Ctext class=\"fig-s\" x=\"20\" y=\"272\">× 3 partial logs, 3 formats\u003C\u002Ftext>\n  \u003Ctext class=\"fig-s\" x=\"20\" y=\"288\">× kept by the party under review\u003C\u002Ftext>\n  \u003Ctext class=\"fig-s fig-c-ok\" x=\"392\" y=\"272\">✓ one complete log across vendors\u003C\u002Ftext>\n  \u003Ctext class=\"fig-s fig-c-ok\" x=\"392\" y=\"288\">✓ owned by the accountable org\u003C\u002Ftext>\n\u003C\u002Fsvg>\n\u003Cfigcaption>Left: each AI client writes to its own vendor log, with the vendor's format and retention. Right: every call passes one self-hosted gateway, which keeps one audit log and forwards it.\u003C\u002Ffigcaption>\n\u003C\u002Ffigure>\n\n\u003Cp>An independent control point avoids these problems by design. If every agent call passes through\none gateway operated by the organisation itself, the log is complete across vendors, and it\nbelongs to the organisation that is accountable. The article\n\u003Ca href=\"\u002Fblog\u002Fwhat-is-an-mcp-gateway\">What is an MCP gateway?\u003C\u002Fa> explains this architecture in more detail.\u003C\u002Fp>\n\u003Ch2>How Vordix records agent activity\u003C\u002Fh2>\n\u003Cp>Vordix is a self-hosted gateway between AI agents and tools such as Jira, GitHub, Confluence,\nSlack and Databricks. Every request passes through it, so every request is recorded in one place.\nThe audit log is designed along the questions above:\u003C\u002Fp>\n\u003Cul>\n\u003Cli>\u003Cstrong>Every outcome is recorded:\u003C\u002Fstrong> allowed, denied with the reason, held for approval, rate-limited\nand error. Each entry contains the decision trace, which shows which rule led to the decision.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Parameters are redacted before they are written\u003C\u002Fstrong>, so personal data from a request does not\nend up in the log in clear text.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>The log is append-only and hash-chained with an HMAC.\u003C\u002Fstrong> No role, including the administrator,\ncan edit entries, and the integrity of the chain can be verified on demand. A changed or removed\nentry breaks the chain.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Retention has a floor of 180 days\u003C\u002Fstrong>, and a legal hold can keep records beyond that.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Export and forwarding:\u003C\u002Fstrong> entries can be exported as CSV or JSON, followed as a live stream or\nsent to a SIEM (security information and event management system) through a signed webhook.\u003C\u002Fli>\n\u003Cli>\u003Cstrong>Regulatory tags:\u003C\u002Fstrong> audit entries carry tags for Articles 10 and 12 of the AI Act, and the\ncompliance page of the documentation maps the controls to Articles 10, 12 and 14 of the AI Act\nand to ISO 27001 Annex A.\u003C\u002Fli>\n\u003C\u002Ful>\n\u003Cfigure class=\"post-figure\">\n\u003Csvg viewBox=\"0 0 760 290\" xmlns=\"http:\u002F\u002Fwww.w3.org\u002F2000\u002Fsvg\" role=\"img\" aria-labelledby=\"audit-chain-title\">\n  \u003Ctitle id=\"audit-chain-title\">An append-only audit log: every entry, including a denied call with its reason, carries an HMAC over the previous hash, and the chain is exported or sent to a SIEM.\u003C\u002Ftitle>\n  \u003Ctext class=\"fig-h fig-c-primary\" x=\"16\" y=\"28\">AUDIT LOG · APPEND-ONLY\u003C\u002Ftext>\n  \u003Cg>\n    \u003Crect class=\"fig-box\" x=\"16\" y=\"44\" width=\"164\" height=\"178\" rx=\"10\"\u002F>\n    \u003Ctext class=\"fig-s\" x=\"28\" y=\"66\">#1041 · 09:14:02\u003C\u002Ftext>\n    \u003Ctext class=\"fig-t fig-c-ok\" x=\"28\" y=\"102\">ALLOWED\u003C\u002Ftext>\n    \u003Ctext class=\"fig-s\" x=\"28\" y=\"122\">jira_create_issue\u003C\u002Ftext>\n    \u003Ctext class=\"fig-s\" x=\"28\" y=\"158\">agent: sprint-bot\u003C\u002Ftext>\n    \u003Cpath class=\"fig-edge fig-edge--faint\" d=\"M28 170 H168\"\u002F>\n    \u003Ctext class=\"fig-s\" x=\"28\" y=\"188\">prev 3f9a…c21e\u003C\u002Ftext>\n    \u003Ctext class=\"fig-s fig-c-primary\" x=\"28\" y=\"206\">hash 9c1e…07b4\u003C\u002Ftext>\n  \u003C\u002Fg>\n  \u003Cg>\n    \u003Crect class=\"fig-box\" x=\"206\" y=\"44\" width=\"164\" height=\"178\" rx=\"10\"\u002F>\n    \u003Ctext class=\"fig-s\" x=\"218\" y=\"66\">#1042 · 09:14:07\u003C\u002Ftext>\n    \u003Ctext class=\"fig-t fig-c-deny\" x=\"218\" y=\"102\">DENIED\u003C\u002Ftext>\n    \u003Ctext class=\"fig-s\" x=\"218\" y=\"122\">github_merge_pr\u003C\u002Ftext>\n    \u003Ctext class=\"fig-s fig-c-deny\" x=\"218\" y=\"140\">not in allowlist\u003C\u002Ftext>\n    \u003Ctext class=\"fig-s\" x=\"218\" y=\"158\">agent: review-bot\u003C\u002Ftext>\n    \u003Cpath class=\"fig-edge fig-edge--faint\" d=\"M218 170 H358\"\u002F>\n    \u003Ctext class=\"fig-s\" x=\"218\" y=\"188\">prev 9c1e…07b4\u003C\u002Ftext>\n    \u003Ctext class=\"fig-s fig-c-primary\" x=\"218\" y=\"206\">hash 4b7a…e913\u003C\u002Ftext>\n  \u003C\u002Fg>\n  \u003Cg>\n    \u003Crect class=\"fig-box\" x=\"396\" y=\"44\" width=\"164\" height=\"178\" rx=\"10\"\u002F>\n    \u003Ctext class=\"fig-s\" x=\"408\" y=\"66\">#1043 · 09:15:31\u003C\u002Ftext>\n    \u003Ctext class=\"fig-t fig-c-primary\" x=\"408\" y=\"102\">HELD\u003C\u002Ftext>\n    \u003Ctext class=\"fig-s\" x=\"408\" y=\"122\">confluence_update_page\u003C\u002Ftext>\n    \u003Ctext class=\"fig-s fig-c-primary\" x=\"408\" y=\"140\">awaiting approval\u003C\u002Ftext>\n    \u003Ctext class=\"fig-s\" x=\"408\" y=\"158\">agent: docs-bot\u003C\u002Ftext>\n    \u003Cpath class=\"fig-edge fig-edge--faint\" d=\"M408 170 H548\"\u002F>\n    \u003Ctext class=\"fig-s\" x=\"408\" y=\"188\">prev 4b7a…e913\u003C\u002Ftext>\n    \u003Ctext class=\"fig-s fig-c-primary\" x=\"408\" y=\"206\">hash d25f…6a08\u003C\u002Ftext>\n  \u003C\u002Fg>\n  \u003Cg>\n    \u003Crect class=\"fig-box fig-box--dashed\" x=\"586\" y=\"44\" width=\"164\" height=\"178\" rx=\"10\"\u002F>\n    \u003Ctext class=\"fig-s\" x=\"598\" y=\"80\">#1044 · 09:15:40\u003C\u002Ftext>\n    \u003Ctext class=\"fig-s fig-c-primary\" x=\"738\" y=\"62\" text-anchor=\"end\">appending\u003C\u002Ftext>\n    \u003Ctext class=\"fig-t fig-c-ok\" x=\"598\" y=\"102\">ALLOWED\u003C\u002Ftext>\n    \u003Ctext class=\"fig-s\" x=\"598\" y=\"122\">slack_post_message\u003C\u002Ftext>\n    \u003Ctext class=\"fig-s\" x=\"598\" y=\"158\">agent: sprint-bot\u003C\u002Ftext>\n    \u003Cpath class=\"fig-edge fig-edge--faint\" d=\"M598 170 H738\"\u002F>\n    \u003Ctext class=\"fig-s\" x=\"598\" y=\"188\">prev d25f…6a08\u003C\u002Ftext>\n    \u003Ctext class=\"fig-s fig-c-primary\" x=\"598\" y=\"206\">hash 71c0…b3d2\u003C\u002Ftext>\n  \u003C\u002Fg>\n  \u003Cpath class=\"fig-flow\" d=\"M176 202 C194 202 192 184 206 184\"\u002F>\n  \u003Cpath class=\"fig-head\" d=\"M206 184 l-7 -4 v8 z\"\u002F>\n  \u003Cpath class=\"fig-flow\" d=\"M366 202 C384 202 382 184 396 184\"\u002F>\n  \u003Cpath class=\"fig-head\" d=\"M396 184 l-7 -4 v8 z\"\u002F>\n  \u003Cpath class=\"fig-flow\" d=\"M556 202 C574 202 572 184 586 184\"\u002F>\n  \u003Cpath class=\"fig-head\" d=\"M586 184 l-7 -4 v8 z\"\u002F>\n  \u003Ctext class=\"fig-s\" x=\"16\" y=\"256\">hash = HMAC(prev hash, entry)\u003C\u002Ftext>\n  \u003Ctext class=\"fig-s\" x=\"16\" y=\"274\">no role can edit an entry\u003C\u002Ftext>\n  \u003Cpath class=\"fig-flow fig-flow--ok\" d=\"M478 222 V244\"\u002F>\n  \u003Cpath class=\"fig-flow fig-flow--ok\" d=\"M668 222 V244\"\u002F>\n  \u003Crect class=\"fig-box fig-box--ok\" x=\"396\" y=\"244\" width=\"164\" height=\"36\" rx=\"8\"\u002F>\n  \u003Ctext class=\"fig-t\" x=\"478\" y=\"267\" text-anchor=\"middle\">Export CSV · JSON\u003C\u002Ftext>\n  \u003Crect class=\"fig-box fig-box--ok\" x=\"586\" y=\"244\" width=\"164\" height=\"36\" rx=\"8\"\u002F>\n  \u003Ctext class=\"fig-t\" x=\"668\" y=\"267\" text-anchor=\"middle\">SIEM webhook\u003C\u002Ftext>\n\u003C\u002Fsvg>\n\u003Cfigcaption>Four audit entries in an append-only chain: each stores the previous hash and an HMAC over itself, so a denied call with its reason is as fixed as an allowed one. The chain can be exported or sent to a SIEM.\u003C\u002Ffigcaption>\n\u003C\u002Ffigure>\n\n\u003Cp>Because Vordix runs on the organisation&#39;s own infrastructure, the log is stored where the\norganisation decides, and the Vordix company is not in the request path.\u003C\u002Fp>\n\u003Cp>For write operations that need a second pair of eyes, for example merging a pull request (see\n\u003Ca href=\"\u002Fblog\u002Fai-code-review-permissions-github-azure-devops\">AI code review permissions on GitHub and Azure DevOps\u003C\u002Fa>),\nan administrator can configure an approval policy. Held calls then appear in the log as well, with\nthe approval or rejection that followed. For data access, the same trail shows which tables and\ncolumns an agent read, as described in\n\u003Ca href=\"\u002Fblog\u002Fai-agents-databricks-data-access\">AI agents and Databricks data access\u003C\u002Fa>.\u003C\u002Fp>\n\u003Ch2>Limitations and trade-offs\u003C\u002Fh2>\n\u003Cp>An audit trail is a necessary part of governance, but it is not sufficient on its own, and a few\nlimitations should be stated clearly.\u003C\u002Fp>\n\u003Cp>First, a log documents; it does not prevent. The value comes from combining it with enforcement:\nscoped permissions, allowlists and approvals decide what an agent may do, and the log proves what\nit actually did. A log without enforcement mainly documents the damage.\u003C\u002Fp>\n\u003Cp>Second, a gateway can only record what passes through it. If an agent still holds a direct API\ntoken for GitHub, calls made with that token bypass the gateway and are not in its log. Removing\ndirect credentials is therefore part of the setup, not an optional step.\u003C\u002Fp>\n\u003Cp>Third, Vordix holds no certification, and using it does not make an organisation compliant with\nthe AI Act, the GDPR or ISO 27001. The controls and the mapping help to produce evidence; the\nassessment of whether a specific use case is high-risk, and whether the overall setup is\nsufficient, remains with the organisation and its advisers.\u003C\u002Fp>\n\u003Cp>Finally, redaction is a trade-off. The more parameters are masked before writing, the less\npersonal data the log contains, but the harder some investigations become. The right balance\ndepends on the data the agents handle and should be decided together with the data protection\nofficer.\u003C\u002Fp>\n\u003Ch2>Conclusion\u003C\u002Fh2>\n\u003Cp>An audit trail for AI agents should record who acted, what was requested, what was decided and\nwhy, and when, for denied calls as well as successful ones, and it should be protected against\nlater changes. For most development-tool agents the AI Act&#39;s high-risk logging duties do not\napply directly, but GDPR accountability and customer expectations lead to the same requirement.\nKeeping that record in an independent, self-hosted control point, instead of in each vendor&#39;s\ntool, gives one complete log that belongs to the organisation that has to answer for it.\u003C\u002Fp>\n\u003Cp>The Vordix documentation describes the audit log in detail, and a demo shows it with real agent\ncalls.\u003C\u002Fp>\n",{"de":19,"en":4},"audit-log-ki-agenten-eu-ai-act",1790588073004]