Skip to content
Transformation Agenda

Briefing · 18 September 2026

Audit trail is not the same as control

Enterprises are getting better at seeing what AI does. Logs, traces and dashboards can tell us in more detail what an AI agent did. But there is a risk in treating better visibility as better control.

An audit trail can tell us that an AI agent crossed a boundary. Governance should also define whether that boundary could be crossed in the first place. I think this difference will become more important as AI moves from experiments into everyday business processes.

For years, many organisations have used a familiar model of control: record the activity, keep an approval trail, monitor access and make sure actions can be checked afterwards. That is still important, but AI changes how fast and widely actions can happen. An agent can use information, make a decision, call another system and start a workflow much faster and at a much larger scale than a human-operated process. Knowing afterwards exactly what the agent did is useful, but it is not the same as controlling what it was able to do.

We may be asking the wrong question

A lot of enterprise governance has focused on whether access is monitored and whether activity can be traced. With AI, an even more important question may be whether the access, permission or action should have been available in the first place.

An agent that needs enough customer information to recommend the next step in a service process does not necessarily need access to the whole customer record. An agent that needs to create a case does not automatically need permission to change the underlying data. In the same way, an agent that can run a workflow on its own should have clear limits instead of broad permissions simply because they are available.

This moves the discussion from monitoring towards how the system is designed. Governance becomes part of how data access, permissions, process limits and approval points are built into the environment.

There is also a natural tendency to answer governance concerns with more visibility: more logging, more telemetry and more dashboards. These are useful, but they are not always the strongest control. In some situations, the better control is that the data is not available, the permission does not exist or the action cannot happen without approval. Sometimes the most effective control is not another monitoring layer. It is a boundary.

AI makes weak boundaries more costly

Traditional enterprise processes have friction built into them. A person opens a system, reviews information, makes a decision and performs an action. That friction can be inefficient, but it also limits how quickly a mistake can spread.

AI removes some of that friction, and that is one of the reasons it is valuable. It is also why weak control boundaries matter more. If an autonomous system has too much access or too many permissions, the problem is no longer that one person can make one poor decision. The same design problem can be repeated across processes and at machine speed.

This is why I think AI governance will become more of a system design question, not only a compliance question. The important issue is not just whether an organisation can prove what happened afterwards. It is also what was technically possible in the first place. That brings governance closer to identity, permissions, process design, data access and the systems where the work actually happens.

Visibility still matters

None of this makes audit trails less important. Enterprises need traceability for accountability, investigations, regulation and learning. If an AI system behaves in an unexpected way, organisations need to understand what happened and why.

The risk is confusing evidence of control with control itself. A complete record of a badly designed permission model is still a badly designed permission model. A dashboard showing an agent doing something it should never have been able to do is useful evidence, but the control came too late.

The strongest environments will probably use both approaches. They will have good visibility, but they will also have clear limits. Data access will be limited to what is actually needed, permissions will match the task, autonomy will stop at defined points and some actions will require human approval. Just as importantly, some capabilities will simply not be available.

Audit trails will remain essential, but as AI becomes a bigger part of everyday enterprise operations, I think the balance will change. Good governance will be defined less by how completely we can observe AI, and more by how clearly we define what it is allowed to do.

Visibility matters. Boundaries matter more.