Skip to content
Menu ▾
Patent pending

Enterprise licensing

Five properties an enterprise AI audit trail needs to withstand scrutiny

Most trails are never tested. The ones that are get read by someone independent of the operator: a regulator, an insurer, an opposing party. Five properties decide whether a trail holds up in that room. For the plain-English definition of the term itself, see what an AI audit trail is.

The standard the five properties are measured against

A record of events and decisions in an AI system, created as those events occur, that can later be shown to someone who does not trust the operator.

Three words in that sentence carry the weight. Record, because a summary written afterwards is a report, not a record. As those events occur, because contemporaneity is the one property a reconstructed log cannot fake. And someone who does not trust the operator, because an audit trail is stronger when an independent reviewer can verify it. Everything below is what it takes to meet that third clause.

Five properties decide whether one withstands scrutiny

Contemporaneous

Written at the moment of the decision, as a byproduct of it. Any trail compiled later can be shaped later, and every examiner knows it.

Tamper-evident

Signed and chained, so a change or a deletion shows. The claim is never that change is impossible. The claim is that the seam is visible to anyone who looks.

Content-free

The fact of the decision, the fingerprint of the material, the identity of the person. Not the material. A trail that stores content becomes a liability of its own and cannot be shown to an outsider without betraying an insider.

Independently verifiable

Checkable by the party you answer to, with public mathematics, without your servers, your account or your permission. A trail that needs you present to verify is evidence about yourself, graded by yourself.

Attributable to a person

Human oversight is a named duty in regulation, including Article 14 of the EU AI Act. A trail of machine events with no person in it answers a question nobody asked. The question is what the system did and what a person decided about it.

Where independent evidence adds something different

Application logs are essential operational records. Depending on their architecture, however, they may not independently establish integrity, contemporaneous creation, chain completeness or external verifiability.

Regulayer adds separate evidence designed to preserve those properties around governed AI decisions: The Witness for sealed decision memory, Drift for behavioral change per person, HumanMark for authorship, and the record format that makes any of it checkable by anyone, permanently, without us.

Licensing begins with the problem, not the product.

Describe the system, what it decides, and what it would cost you to be unable to prove it. A written scope follows before any call.

Ways to begin:

hello@regulayer.com