🤖 AI Summary
This study addresses the lack of auditability in AI agent claims and the absence of compliance standards under the EU AI Act by proposing an auditability framework grounded in assurance engagement prerequisites. Methodologically, it defines four elements of auditable claims, extending policy inspectability to the claim level while establishing conditions for independent recording, authorization binding, and integrity. The approach employs explicit model derivation and formal proofs, anchoring a claim checklist to NIST, IETF, and OWASP standards. Furthermore, the research develops inspection mechanisms for six categories of common claims, provides five-state evidence exemplars, and offers practical guidelines tailored to multi-stakeholder contexts. Ultimately, this work effectively bridges the theoretical and standardization gaps in claim-level auditing for AI systems.
📝 Abstract
Organizations make claims about their AI agents: a person approves every external email, every action is logged, an evaluation shows the agent is safe to deploy. Article 12 of the EU AI Act requires high-risk systems to allow the automatic recording of events but does not say which records settle a given claim. The position is one sentence: to be checked, a claim about an agent must first name its policy, its scope, the records that would settle it, and who writes them. Adapting the preconditions of an assurance engagement, we call a claim auditable when these elements and a decision rule are fixed before any verdict and the records are obtainable. This extends the Policy Checkability dimension of our Auditable Agents framework from single actions to claims. Agents add three conditions: coverage by an independent record, authorization bound to each action's arguments, and completeness beyond integrity. Under an explicit model, we prove that support is impossible without each wherever its hypotheses hold. A claim-check table applies the method to six common claims, anchored in current NIST, IETF, and OWASP drafts. A worked case follows one claim through five evidence states. We close with a practice box and steps for operators, buyers, auditors, and standard setters.