REGULATORY MAPPING MATRIX

Agentic AI Capability vs. Audit/Compliance Requirements vs. Evidence Custody
August 2026 | Submitted to NIST AI Standards Zero Draft comment period (closes Sept 16, 2026)

Summary of changes from the version submitted August 2026

CORRECTION EU AI Act application dates. The prior version listed August 2, 2026 for high-risk obligations including Article 12. Regulation (EU) 2026/1744 moved Annex III stand-alone systems to December 2, 2027 and Annex I embedded systems to August 2, 2028. Article 50 transparency obligations applied from August 2, 2026 as originally scheduled. Corrected in the EU AI Act rows and in the Regulatory Timeline section.

STRENGTHENED Scope of the evidence-architecture implications. Item 3 previously listed specific hardening mechanisms in a way that could be read as describing a particular implementation. It now states the architectural property standards guidance should require, without naming one.

Regulation Requirement Agent Capability (Now) Evidence Holder Independent Custody Gap
EU AI Act Art. 12 Automatic event logging; tamper-evident; min 6-month retentionApplies December 2, 2027 for Annex III stand-alone systems; August 2, 2028 for Annex I systems embedded in regulated products. Agents execute multi-step workflows (credit analysis, payment routing, fraud investigation) — generating hundreds of loggable events per session Agent operator / platform provider — self-produced logs in operator-controlled infrastructure No requirement for evidence outside operator's mutable storage. Agent produces its own audit trail.
EU AI Act Art. 13 Transparency: deployers must understand system operation sufficiently to interpret outputsApplies December 2, 2027 for Annex III stand-alone systems; August 2, 2028 for Annex I systems embedded in regulated products. Agents chain reasoning across tool calls, delegations, and decisions — reasoning traces are internal to the model Model provider (if exposed) or deployer's application logs Reasoning traces are provider-controlled. No independent record of what reasoning actually occurred vs. what was logged.
EU AI Act Art. 14 Human oversight: ability to intervene, override, or halt system operationApplies December 2, 2027 for Annex III stand-alone systems; August 2, 2028 for Annex I systems embedded in regulated products. Agents escalate selectively; many workflows complete without human checkpoint. Override events logged by the agent itself. Agent operator — override records in operator-controlled systems The agent that was overridden records whether it was overridden. No independent witness to the override event.
EU AI Act Art. 72 Post-market monitoring: provision of logs to national authorities on requestApplies December 2, 2027 for Annex III stand-alone systems; August 2, 2028 for Annex I systems embedded in regulated products. Agents in production generate continuous operational data across financial, legal, and healthcare workflows Deployer's logging infrastructure — exportable on request Authorities receive logs from the entity being audited. No mechanism to verify logs weren't modified before production.
SEC FY2026 Exam Priorities AI governance documentation; ability to explain AI-driven decisions to examiners; supervision framework for AI tools AI agents autonomously execute trade surveillance, compliance monitoring, client communication analysis Registered firm's internal compliance systems and documentation Examiner receives explanation from the firm using the AI. No independent evidence of what the AI actually did.
SEC 17a-4 / 204-2 Comprehensive recordkeeping of all business communications regardless of channel Agents communicate across APIs, tool calls, and inter-agent delegation — generating machine-to-machine 'communications' at scale Broker-dealer / adviser record archives — WORM storage for 17a-4 WORM addresses immutability but records originate from the firm's own systems. Agent-to-agent communications may not be captured at all.
SOX 404 / PCAOB AS 2201 Internal controls over financial reporting; evidence that controls operated effectively Agents perform journal entry testing, anomaly detection, transaction monitoring, control evidence documentation Audit firm and company's internal control documentation No AI-specific ICFR guidance as of June 2026 (SEC FRM, PCAOB). AI-generated control evidence is self-attested.
NIST AI RMF 1.0 Risk management policies; system inventory; testing and evaluation; incident response Agentic systems plan, use tools, chain decisions, and escalate privileges — exceeding RMF 1.0's assumptions of bounded, predictable behavior Organization's AI governance documentation and risk registers Voluntary. No requirement for independent verification of risk management claims. Self-assessment is the norm.
NIST CAISI (Feb 2026) Identity, authorization, audit, and interoperability standards for autonomous agents Agents operate with delegated authority, execute financial transactions, invoke external tools without human intervention Standards still in development — no enforceable requirements yet Initiative focuses on identity and authorization. Custody of evidence after creation is not yet addressed.
FINRA AI Supervision Enterprise-wide AI governance; inventory of AI tools; demonstrated supervision of AI-driven processes AI agents in broker-dealers execute compliance surveillance, client onboarding, trade execution support Firm's compliance management system Supervision evidence is produced by the firm deploying the agent. No independent verification that supervision actually occurred.
SOC 2 Logical access controls; continuous system monitoring; change management documentation Agents access systems, make decisions, and modify configurations autonomously — access patterns are machine-speed Service organization's control environment and auditor testing Auditor samples controls; does not independently verify every agent action. Agent-produced logs are primary evidence.
ISO/IEC 42001 AI management system: risk assessment, operational documentation, monitoring Agentic AI systems with autonomous planning, tool use, and multi-step execution across enterprise workflows Organization's AIMS documentation and internal audit records Certification bodies audit documentation, not runtime behavior. No independent custody of operational evidence.
GDPR Art. 22 Right not to be subject to solely automated decision-making with legal effects; right to explanation Agents make consequential automated decisions (credit, insurance, hiring) with minimal human involvement Data controller's processing records and automated decision documentation Explanation of automated decision is produced by the entity that made it. No independent record of the actual decision process.

KEY FINDING

Across every regulatory framework examined, the entity being audited is also the entity that produces, stores, and controls the audit evidence. No current US or EU requirement mandates that evidence of AI/agent activity exist outside the operator's own infrastructure. This structural gap widens as agent capability increases: a system sophisticated enough to optimize for its own continuation is sophisticated enough to produce internally consistent but fabricated audit records. Hash chaining and tamper-evident logging address post-creation modification but do not address fabrication at the point of creation by the entity that controls the logging infrastructure.

IMPLICATIONS FOR STANDARDS DEVELOPMENT

1. The evidentiary value of an audit record is inversely proportional to the degree of control the audited system has over that record. Current frameworks implicitly trust that the operator's logging infrastructure faithfully represents what occurred. This assumption was reasonable when decisions were human-speed and human-legible. It is structurally insufficient for autonomous systems that can plan, execute, and log in a single unobserved pipeline.
2. Independent custody is an architectural requirement, not a product feature. Standards guidance should distinguish between self-attested evidence (produced and held by the operator) and independently custodied evidence (accepted, sequenced, and preserved by a system outside the operator's trust boundary). Both have value; only the latter resists fabrication at origin.
3. Evidence should strengthen over time, not weaken. An evidence layer has to accept events immediately, so that recording imposes no latency penalty on the pipeline it observes. What can be guaranteed at the moment of acceptance is therefore weaker than what should hold a year later, when the record is actually examined. Standards guidance should evaluate an evidence architecture on whether the record hardens after acceptance — through cryptographic commitment to accepted records, distribution of those commitments outside the producing system, and reconciliation across related events — rather than on the guarantees it offers at ingest alone. Each layer raises the cost and the detectability of retroactive tampering.
4. Agent-sourced attestation is circular. Proposals that define audit trail formats for agents to log their own behavior (e.g., IETF Agent Audit Trail draft) address the format problem but not the custody problem. The same structural weakness that makes self-certification unreliable for human actors applies with greater force to autonomous systems: the entity with the strongest incentive to present favorable evidence should not be the sole custodian of that evidence. Complementary independent custody closes this gap without competing with self-attested logging formats.
5. Simplicity enables adoption; complexity enables evasion. An independent verification layer must be lightweight enough to deploy across any agent framework, any model provider, and any industry vertical without requiring the operator to redesign their pipeline. A minimal receipt (hash, timestamp, signature, chain reference) accepted by an independent party is more durable than a comprehensive but self-produced audit trail. The verification primitive should be small enough to be ubiquitous.

REGULATORY TIMELINE

August 2, 2026: EU AI Act Article 50 transparency obligations applied as originally scheduled.

September 16, 2026: NIST AI Standards Zero Draft comment period closes.

Q4 2026: NIST AI Agent Interoperability Profile expected.

December 2, 2027: EU AI Act high-risk obligations, including Article 12 logging, apply to Annex III stand-alone systems under Regulation (EU) 2026/1744.

August 2, 2028: EU AI Act high-risk obligations apply to Annex I systems embedded in regulated products.

2026 ongoing: SEC FY2026 exam priorities target AI governance, supervision, and recordkeeping. PCAOB QC 1000 in first full audit cycles. 44% of finance teams now using agentic AI (600% YoY increase).

SOURCES

  1. Gibson Dunn, EU AI Act Omnibus Agreement — Postponed High-Risk Deadlines and Other Key Changes, 2026, on Regulation (EU) 2026/1744.