AI security is becoming increasingly important as AI agents begin to use tools, call APIs, modify data, and take actions in real-world systems.
But I keep coming back to a simpler question.
Before we can secure AI agents, shouldn’t we first be able to know what they actually did?
When did the AI act?
What did it try to do?
What system or tool did it act on?
What governance conditions were checked?
Why was the action allowed or blocked?
I think one of the first foundations of AI security may be a verifiable governance record of important AI actions.
If something goes wrong, that record could help us understand, investigate, reproduce, and improve what happened.
This is one of the ideas I have been exploring through EGA V9.
But I am more interested in the broader question than in promoting a particular implementation:
Do you think verifiable governance records should become a basic requirement for important AI-agent actions?