Summary
Agentic AI systems perform tasks by communicating, making decisions, and changing shared information. However, it can be tricky to know if their records and messages truly prove what happened or who approved what. The paper by the authors proposes a detailed model that explains different kinds of evidence claims an AI can make, like showing a message’s integrity or proving authorization. This model helps people understand what AI systems can reliably prove, what they cannot, and what rules or checks are needed to trust them. It doesn't guarantee perfect security or legal compliance but provides a clear way to talk about evidence and trust in these AI processes.
Agentic AIEvidence claimsArtifact integrityProvenanceAuthorizationApproval evidenceTrust assumptionsPolicy assessmentDeliberation traceabilityManagement response loop
Abstract
Agentic AI systems increasingly exchange messages, invoke tools, request approvals, hold structured decision sessions, and modify shared artifacts. Logs and anchors can make selected records tamper-evident, but they can also mislead if their evidentiary meaning is implicit: a hash does not establish semantic truth, a signature does not establish authorization, and an external anchor does not establish capture completeness. This paper proposes an evidence claim model for agentic processes. It distinguishes artifact integrity, temporal existence, provenance, approval evidence, declared ordering, capture claim, relevance claim, deliberation traceability, monitoring claim, anchoring authorization claim, policy assessment claim, risk treatment claim, mitigation implementation claim, and management response claim. Semantic validity is treated as a recurring limitation. The model maps these claims to mechanisms, assumptions, limitations, and threats, and situates them in an agent organization with functional CEO agent, executive, operational, evidence, and audit roles, plus a plan-do-check-act-inspired management response loop. The contribution is conceptual: it does not validate a particular implementation, prevent all failures, or automate legal compliance. It provides a vocabulary for stating which claims an agentic black box can support, which claims it cannot establish, and which controls are required around it.