For buyers and risk teams, 5 September 2026
If a system acts on your behalf, somebody will eventually ask you what it did and who allowed it. These are the questions worth asking before that, in the order they usually matter.
They are not a compliance instrument and passing them is not conformity with anything. They come from a published assessment of 8 agent memory and agent framework implementations, where the counts below were measured rather than estimated, and each one is a question at least 7 of the 8 could not answer well.
Send them as your own. No attribution, no sign-up, nothing to buy, and no need to mention where they came from. A questionnaire is more useful when the supplier answers the question rather than researching who is asking.
| Ask | A real answer | A soft yes | Could not |
|---|---|---|---|
| When your system takes an action on our behalf that needed a human to approve it, does the record say which person approved it? | A named person or a named role holder, in the record itself, for every such action. | “All high-risk actions require human approval.” That says a step exists. It does not say the record names who took it. | 5 of 6 |
| Where does that name come from? | From your authentication layer: the session, the token, the directory entry the approver signed in with. | “The approver is passed in the request.” A name supplied by the caller is an assertion about a person rather than a fact about one, and the caller can be the system being approved. | 5 of 6 |
| Can the agent approve its own action? | No, and the system enforces it rather than the operator remembering to. | “That would not happen in practice.” Ask what stops it. | 5 of 6 |
| If two of your sources disagreed about a fact, does the record keep both, or only the one the system chose? | Both, with the disagreement recorded as its own thing. | “The system resolves conflicts automatically.” That is the answer to a different question, and it means the losing side is gone. | 5 of 8 |
| When a disagreement was resolved, does the record say who or what resolved it, and on what basis? | The method, the party, the time, and which side was kept. | “We use confidence scores.” A number is not a reason, and it does not say who set the threshold. | 6 of 8 |
| Can we get from a stored fact back to the source it came from? | A citation in the record that leads to the message, document or API response the fact was drawn from. | “Everything is logged.” Logs elsewhere are not a citation in the record, and an auditor cannot join them for you. | 6 of 8 |
| If somebody altered a past entry, would anyone be able to tell? | A published scheme under which alteration is detectable, and a way to run it. | “The database is append-only.” That is a property of your code path behaving, which is the thing in question. | 7 of 8 |
| Could we check that ourselves, without your software and without your cooperation? | Yes, and here is how. This is the question that separates a record from a report. | “You can export it and we will verify it for you.” A verification only the supplier can perform is not one you can rely on in a dispute with the supplier. | 6 of 8 |
Can you show us the record for one specific action your system took last month, end to end?
Every question above can be answered in good faith by somebody describing what they believe their system does. This one cannot. Either the record exists and they can show you, or the conversation has been about an intention.
Questions about your system's record of what it did. 1. When your system takes an action on our behalf that needed a human to approve it, does the record say which person approved it? 2. Where does that name come from? 3. Can the agent approve its own action? 4. If two of your sources disagreed about a fact, does the record keep both, or only the one the system chose? 5. When a disagreement was resolved, does the record say who or what resolved it, and on what basis? 6. Can we get from a stored fact back to the source it came from? 7. If somebody altered a past entry, would anyone be able to tell? 8. Could we check that ourselves, without your software and without your cooperation? 9. Can you show us the record for one specific action your system took last month, end to end? These come from a published assessment of eight agent systems: https://machinetestimony.org/register/
A supplier who answers all of these well has a record you can read. That is worth a great deal and it is not the same as the record being true: a system can record precisely what it believed and be wrong. What these questions establish is whether anybody can find out.
None of this is a legal conclusion either. The EU AI Act's obligations run through Articles 12, 13 and 14, and presumption of conformity comes from the harmonised standards. A supplier is not non-compliant because they answered one of these badly, and not compliant because they answered them all well.