The question arrives from an auditor, an enterprise customer, or your own GRC reviewer:
show me what your agents read from the internet last quarter. Most teams have the
model's outputs, and maybe an application log line saying that some URL was fetched.
What the model actually read is gone.
Audit trails cannot be retrofitted: a log you did not capture at the moment of retrieval
does not exist, and no later job can reconstruct what a page said when your agent read
it. Pages change, get taken down, and get rewritten.
The requirement set is dated and specific. The EU AI Act requires high-risk AI systems
to technically allow the automatic recording of events (Article 12), and requires
providers and deployers to keep those logs for at least six months, to the extent such
logs are under their control (Articles 19 and 26(6)).1
Those obligations were deferred. The Digital Omnibus that entered into force in July
2026 moved them to 2 December 2027 for Annex III systems and 2 August 2028 for Annex I
systems.2 Nothing was
cancelled, and the requirement text is unchanged with fixed dates further out. Most
agent deployments are not high-risk systems under the Act in the first place, and this
page will not tell you yours is.
The standards your customers already audit against do not wait for that timetable.
ISO/IEC 42001 Annex A carries a dedicated event-logging control (A.6.2.8) and
data-provenance controls that include retaining licensing records for third-party data
(A.7.5).3 SOC 2 evidence for
anomaly monitoring typically lands under CC7.2. ISO 42001 certification is still early,
in the range of a few hundred certified organisations, so an auditor may be working
through the AI-specific controls alongside you.
Today the pressure on most teams is contractual rather than regulatory. Vendor
questionnaires ask for provenance and subprocessor evidence now, and SOC 2 and ISO 42001
audits run on your customers' schedule.4