An AI audit trail is a record of how AI was used in a piece of work: which tools, for what purpose, who reviewed the output, and when. A defensible one has two properties an ordinary log does not: each entry is attributable to a named person under their own signature, and any later change to an entry shows.
The record format behind each entry is documented field by field at what is a Regulayer Receipt.
What a defensible AI audit trail shows
Whoever asks for the trail, a bank examiner, a judge, an auditor, a client, they are asking the same six questions. A trail that cannot answer one of them is a gap, not a trail.
| Question | What the entry must carry |
|---|---|
| what was used | Which AI tools were used and for what purpose, declared in the words of the person who used them. A statement, not an inference. |
| who reviewed | A named person, attributable. An entry nobody signed is an entry nobody owns. |
| what was checked | The specific checks the reviewer carried out, reported, never scored. |
| when | The time of the entry, and where that time came from: the device clock, marked self-asserted, or an independent time authority's countersignature (RFC 3161), marked witnessed. |
| which work | Fingerprints of the exact file delivered, so the entry binds to one deliverable. Not the file; you cannot read the document back out of them. |
| unchanged since | A seal over the whole entry, so any later edit shows, and a chain to the previous entry, so a missing or altered entry shows. |
Why ordinary logs fall short
Most organisations answering an AI audit request today reach for one of three records. Each answers a different question than the one being asked.
A chat history
Records prompts and outputs, not review. It lives in the vendor's systems, it can be edited or deleted without a trace, and it shows what the machine said, never what a person checked. Producing it also hands over the work itself, which for privileged or confidential matters is the one move you cannot make.
An access log
Records that a system was touched: who logged in, when, from where. It cannot say what the AI was used for, which deliverable it touched, or whether any person reviewed the output. It is infrastructure telemetry wearing the name of an audit trail.
A typed memo
A typed declaration is your word in a document, and it is what most people file today. But it is undated beyond the filing, unverifiable by the person reading it, and editable after the fact without a trace.
An audit trail that seals itself, one record at a time
A Regulayer Receipt is a signed, tamper-evident record of what AI tools were used in a piece of work, for what, and what a named person personally checked. It is sealed at the moment of creation on the signer's own machine, and anyone can verify it free, independently, without an account, without contacting us, and without ever seeing the work itself.
Each receipt carries a sequence number and the fingerprint of the previous record, so the receipts form a chain: a missing or altered entry shows. That chain is the audit trail, built one deliverable at a time, held on your own machine rather than in anyone's cloud.
The record holds fingerprints of the file, not the file, so the trail can be produced to a judge, a regulator, or an auditor without handing over the work. Make a real one in your browser at the demos, then try to alter it and watch the seal break.
Who asks for an AI audit trail
The request arrives under different names in different rooms:
- Bank examiners. Model risk management under SR 26-2 and OCC Bulletin 2026-13, which superseded SR 11-7 and OCC 2011-12 in April 2026, expects documented oversight of models. It is non-enforceable guidance and reaches traditional statistical models rather than generative or agentic AI, so the generative tools your people open sit outside the inventory it describes, and outside any record it produces.
- EU financial supervisors. DORA, Regulation 2022/2554, asks financial entities to evidence operational resilience across their ICT, and AI tooling sits inside that perimeter.
- NYC employers. Local Law 144 requires a bias audit of automated hiring tools, and an audit needs a record of use to audit.
- Federal judges. The Ropes & Gray AI court order tracker records more than 550 standing orders, local rules and decisions on AI in court filings. Ours are read one by one against the court's own document: 21 verified orders, 17 of them in force, requiring disclosure or certification of AI use in filings.
- Everyone else with a questionnaire. The catalogue maps the 143 laws that ask for evidence of how AI touched the work.
The limits
Tamper-evident, not tamper-proof. Nothing is unalterable. The guarantee is narrower and stronger: any change after sealing breaks the signature, and the break shows on verification.
It records evidence. It does not certify compliance. The trail certifies nothing by itself. What weight a court or examiner gives it is their decision; the format is built to support self-authentication under FRE 902(13) and 902(14), and the evidence-law analysis is on a page of its own.
Attested, not proved. The signature makes each declaration permanent and attributable. It does not make it true. An entry says a named person declared this review, at this time, and the record has not changed since. That is what it shows, and it is all it shows.
Questions people ask
Is a chat history an AI audit trail?
A chat history records prompts and outputs, not review. It lives in the vendor's systems, it can be edited or deleted without a trace, and it records what the machine said rather than what a person checked. It is raw material for an audit trail, not the trail itself.
Does the trail contain my work or my prompts?
No. The record carries fingerprints of the file, not the file, and nothing of the prompts. That is what lets you send it to a judge, a client, or an auditor without handing over privileged work. The desktop app works offline; nothing leaves the machine.
Who can verify it, and what does that cost?
Anyone, free. The verifier runs in any browser with no account, checks the Ed25519 signature over the canonical record and the file fingerprints, and contacts no server. It needs only the receipt file, never the underlying work.
Can an entry be backdated or edited after sealing?
Editing any field after sealing breaks the signature, and verification reports the record as tampered. A private seal asserts its own time; if the time itself may be questioned, witnessed mode carries an independent authority's countersignature, and the record says which it carries.
Start the trail with the next deliverable.
The live demos sign a real record in your browser and let you alter it: change one character and the verification flips to tampered. Then generate your own. Seven days free, then $349 a month: unlimited receipts, the Sealer, HumanMark creation facts, and the free verifier. Cancel at any time; existing signed records remain independently verifiable.
Category description as of 14 August 2026. The seal is tamper-evident, not tamper-proof. A receipt attests what the signer declared; it does not certify the work, and admissibility is decided by the court.
