A new paper lays out exactly what it takes to prove, not just assert, that an AI agent behaves the way its operator says it does.
The researchers propose a framework for what they call auditable claims about AI agents. Their argument: a statement like a person approves every external email or every action is logged can't actually be checked unless someone first names the policy being claimed, its scope, the specific records that would settle it, and who writes those records. For agents, they add three more requirements: an independent record of each action, authorization tied to that action's exact arguments rather than a generic human sign-off, and completeness that goes beyond basic data integrity. The paper proves that, under its model, a claim can't be supported if any of these pieces are missing, then applies the method to six common claims in a reference table and walks one claim through five stages of evidence in a worked example.
This matters because Article 12 of the EU AI Act already requires high-risk systems to support automatic logging, but it never says what counts as sufficient proof that a given claim holds. That gap is exactly where vague compliance claims live. This framework gives regulators, auditors, and buyers a concrete checklist for telling a verifiable claim from a reassuring sentence.
In other words: a company saying every agent action is logged and reviewed is not a safety feature. It's a marketing line until someone can name the record that would prove it wrong.