What should an AI agent's audit log record? A field list finance and compliance will accept
Twelve fields per agent action: trigger, inputs, sources, decision, approver, outcome and cost. A log that answers finance, auditors and disclosure rules.

The short answer
Record every agent action as one row: what triggered it, the inputs and sources it used, what it decided and why, which tool call it made, who approved it, the outcome, and what it cost. Keep the model and prompt version. That log lets finance reconcile costs and lets compliance show a disclosure or review happened.
Key takeaways
- An agent's audit log should let a person rebuild any action without asking the agent: trigger, inputs, decision, approval, outcome and cost.
- Article 50 of the EU AI Act has applied since 2 August 2026, and the organisation carries the burden of showing a disclosure was made in time.
- Colorado's amended AI Act, effective 1 January 2027, keeps rights to meaningful human review of adverse automated decisions, which a log has to evidence.
- In KPMG's Q2 2026 survey of 204 US leaders at $1bn+ firms (April–May 2026), 26% reported full, real-time visibility of what their AI systems cost to run.
- Our view: log cost per action from day one, because it is the field finance asks for first and the hardest to rebuild later.
In this article
What is an agent audit log for?
It lets a person reconstruct any action the agent took without asking the agent. Finance uses it to reconcile what the agent did and what it cost. Compliance uses it to show that a required disclosure, approval or human review happened. Operations uses it to find why an exception occurred.
An application log is not enough. It records errors and timings for engineers, often in formats only they read, and it rotates out in days. An audit log records business events in plain fields and keeps them as long as your retention policy says.
Cost visibility is still rare. In KPMG's Q2 2026 AI Pulse survey of 204 US leaders at firms with $1bn or more in revenue (28 April to 25 May 2026), 26% reported full, real-time visibility of what their AI systems cost to operate.1 In the same survey, 53% said they were deploying AI agents.1 Our view: that gap starts with logs that never recorded cost per action.
The fields to record for every action
One row per action, with twelve fields. An action is anything the agent does that changes a record, sends a message or spends money: drafting an invoice match, routing a lead, replying to a ticket. Our design guide for a lead-routing agent shows what to log in one CRM workflow.
| Field | What it holds | Who asks for it |
|---|---|---|
| Action ID and time | Unique ID, UTC timestamp, agent name | Everyone |
| Trigger | What started it: email, form, schedule, user | Operations |
| Inputs | The record IDs and documents it read | Audit |
| Sources | Reference data and rules it matched against | Audit, compliance |
| Model and prompt version | Model ID and the version of instructions in use | Engineering, audit |
| Decision and reason | What it chose, and the rule or check behind it | Compliance |
| Tool call | The system it wrote to, and with which permission | Security |
| Disclosure shown | Whether an AI notice was shown, and its text version | Compliance |
| Approver | Who approved, rejected or edited, and when | Finance, compliance |
| Outcome | Submitted, held, escalated or failed, with record link | Operations |
| Cost | Tokens or usage units, and money at current rates | Finance |
| Exception flag | Whether a person took over, and why | Operations |
Illustrative. Our default field list; rename fields to match your ERP or CRM.
Two rules make the list usable. Store references, not copies, where the source record already lives in your system, so the log does not become a second store of personal data. And write the reason in words a reviewer can read, such as "PO matched within the agreed price tolerance", not a score nobody can interpret.
How logs support the EU and Colorado rules
Logs are how you prove a duty was met. Neither law asks for this exact field list, but both put the burden on you to show what happened.
EU AI Act Article 50
Article 50's transparency duties have applied since 2 August 2026 and were not deferred by the Digital Omnibus, according to a Cloud Security Alliance research note.2 The note says only machine-readable marking of synthetic content gets until 2 December 2026. It also says fines reach up to €15 million or 3% of worldwide annual turnover, and that the organisation carries the burden of proving timely disclosure.2
That burden is why the "disclosure shown" field exists. If a customer-facing agent must tell people they are talking to AI, log that the notice was displayed at the first interaction, with the text version. Our explainer on Article 50 covers what the notice must say, and our disclosure-first design for a clinic scheduling agent shows it in a booking flow.
For high-risk systems the Act goes further. Article 26 requires deployers to keep automatically generated logs for a period suited to the purpose and of at least six months, unless other law says otherwise.3 Most back-office agents are not high-risk, but the same retention habit costs little.
Colorado's amended AI Act
Colorado's SB 26-189, signed on 14 May 2026, moved the law's effective date to 1 January 2027 and replaced the risk-management duties with a narrower framework.4 It keeps rights, in limited circumstances, to correct data and to obtain meaningful human review of adverse automated decisions.4
A human review right needs evidence. The "approver" and "decision and reason" fields show who reviewed, when, and on what basis. Our note on the Colorado amendments covers whether your agent makes consequential decisions at all.
Where each log field is written
- Trigger and inputs
- Decision, reason, sources
- Disclosure shown
- Approver and edit
- Outcome and cost
How long should you keep the log?
As long as the records it explains. If the agent drafts invoices, keep its log for the period your finance records are kept, because an auditor asking about an invoice will ask how it was matched. For customer conversations, align with your data protection retention policy and delete on the same schedule.
Our view: set retention per agent, not per platform, and write it into the acceptance criteria before the build. An agent's log that disappears after thirty days because that was the platform default will fail the first audit question that matters.
Where should the log live?
Next to the system of record, not only inside the agent platform. On an ERP, write a log entry against the document the agent touched, so the trail sits where an auditor already looks. Keep the platform's detailed traces too, for engineers, but treat them as supporting evidence. If the agent works across several systems, give every action one ID and carry it through each system it touches.
Permissions matter here. The agent's user should be able to append to the log and never edit or delete entries. Our least-privilege checklist covers the agent's other rights, and our guide to invoice-matching controls shows the log inside an ERP workflow.
Cost per action is the field that scales
When a second agent arrives, the log is what lets you compare them. Gartner's survey of 1,303 leaders at organisations with $50M or more in revenue (January–April 2026) found that 22% had scaled AI across multiple business units or adopted an AI-first approach.5 About 11% did not know their function's 2025 spend on AI.5
Unknown spend is a logging failure before it is a strategy failure. Record usage and cost on every action, roll it up weekly by agent and process, and divide by actions completed without a person. That number, cost per completed action, is the one to put in front of finance. Every workflow on our AI automation page is designed to report it.
Sources
- KPMG, AI Quarterly Pulse Q2 2026: 204 US leaders at $1bn+ firms, 28 Apr–25 May 2026 (Jun 2026)
- Cloud Security Alliance, research note on EU AI Act Article 50 transparency (Jul 2026)
- EU AI Act, Article 26: obligations of deployers of high-risk AI systems
- Hunton, Colorado AI Act amended and effective date delayed (May 2026)
- Gartner, survey of 1,303 leaders at organisations with $50M+ revenue, Jan–Apr 2026; geography not stated (Sep 2026)


