Blog

Agent accountability, written down.

Verifiable receipts, ground-truth verification, and the regulation arriving for AI agents.

11 August 2026

AI agent audit trails: what to record, and what your records can prove

The fields an agent audit trail needs, the EU AI Act's six-month log retention floor in Articles 12, 19 and 26, and the gap between a record that is complete and one a third party can believe.

4 August 2026

How to sandbox an AI coding agent (and what a sandbox cannot prove)

A working bubblewrap profile, the DNS leak we found when we actually ran it, and the point at which a containment boundary stops being something you can demonstrate to anyone else.

30 July 2026

Alibi: grade coding agents on what actually happened on disk

A small open-source harness that runs the same missions through agentic CLIs and grades every run against ground truth on disk, never the transcript — with runs sealed by signed receipts a witness can cosign.

28 July 2026

Signed execution receipts: a primer on why logs are not evidence

What evidence actually demands, where centralised logging, WORM storage and hash chains each stop, and what a canonical signature over an execution record adds.

21 July 2026

How to verify what an AI agent actually did

A practical walkthrough of traceseal-verify and the anatomy of a signed execution receipt: what the signature covers, what an [OK] proves, and what it honestly does not.

19 July 2026

EU AI Act Article 50: what it means for teams running AI agents

Transparency obligations apply from 2 August 2026. What Article 50 requires, who it covers, and why signed execution receipts turn compliance into a one-command check.