NeFut Logo NeFut
中 Admin Login

[CS.AI] Auditable Claims about AI Agents

Published at: 2026-10-07 22:00 Last updated: 2026-10-08 01:25
#algorithm #AI #Machine Learning

Organizations often make statements about their AI agents, such as “every external email requires human approval”, “all actions are logged”, or “an evaluation shows the agent is safe to deploy”. Article 12 of the EU AI Act obliges high‑risk systems to record events automatically, yet it does not specify which records satisfy a given claim. This paper argues that a claim can be checked only after naming four elements: the governing policy, the claim’s scope, the records that would settle it, and who writes those records. Adapting assurance engagement preconditions, we call a claim auditable when these elements and a decision rule are fixed before any verdict and the records are obtainable. This extends the Policy Checkability dimension of our Auditable Agents framework from single actions to full claims. For AI agents we add three conditions: coverage by an independent record, authorization bound to each action’s arguments, and completeness beyond mere integrity. An explicit model proves that support is impossible without each condition wherever its hypotheses hold. We then present a claim‑check table applying the method to six common claims anchored in current NIST, IETF and OWASP drafts. A worked example follows one claim through five evidence states. The paper closes with a practice box and concrete steps for operators, buyers, auditors, and standard setters.

Review

Original Source: https://arxiv.org/abs/2610.07459

[h] Back to Home