Line of inquiry
Inquiring lines›How do we ensure safety, alignment…›What security vulnerabilities enab…›this line of inquiry
How can infrastructure records verify actual agent behavior?
A broader line of inquiry — a family of 49 specific questions the research asks around this. Follow one into its inquiring-line page, or move sideways to a related line below.
Questions in this line of inquiry 49
Specific inquiring lines the field asks around this — ordered from the most general framing down to the most specific angle.
- Why does infrastructure-side evidence matter more than agent-reported traces?
- Can execution traces reveal unsupported claims in AI agent behavior?
- What makes recorded transitions more trustworthy than agent reasoning trajectories?
- Can infrastructure evidence ground benchmark claims better than terminal scores alone?
- What process records would independently verify that agents performed required steps?
- How should verifiable process memory anchor safety-critical action logs?
- Can agents themselves read and rely on tamper-evident process records?
- Who holds authority to anchor evidence in this system?
- Why does forcing agents to trace function paths prevent unsupported claims?
- How does recording state provenance help detect unauthorized tampering between agent actions?
- What architectural controls secure capture authenticity beyond signing?
- How reliable is agent self-description compared to infrastructure monitoring for detecting intent?
- Where should authenticated provenance records sit to remain outside agent reach?
- Can an auditor verify environment state without trusting the executor's self-report?
- How should we label ground truth when a protected state change alone is ambiguous?
- How should humans audit agent behavior when autonomous systems lack transparency?
- What evidence should benchmark operators attach to completion claims?
- Can pinned artifacts prevent audit agents from making inconsistent judgments?
- What must auditors reconstruct when reviewing an agentic workflow decision?
- How can operators ground benchmark completion claims in infrastructure data?
- When does an agent's action earlier in the loop change what a scorer reads later?
- How do execution traces and tests represent agent environment state?
- How do signed logs compare to externally anchored records for audit?
- Who bears responsibility for reconstructing evidence when parties may be adversarial?
- How can anchored records fail authenticity while passing integrity checks?
- Do infrastructure event records alone suffice to distinguish different failure mechanisms?
- What makes a detector's output count as integrity evidence?
- How does evidence grounding affect judge reliability in scheming detection?
- How much coordination benefit comes from the record versus other factors?
- Where should the recorder sit relative to the agent it monitors?
- What commitment scheme and retention architecture does this design require?
- Who decides whether an entity has authority to anchor a record?
- How should evolving systems track lineage and enable rollback of changed mechanisms?
- What additional architectural controls must supplement blockchain anchors for compliance?
- What does trajectory audit reveal about evolution cycle contributions and costs?
- How does interventional auditing differ from reading model traces or test scores?
- Which specific EU AI Act provisions does anchored evidence satisfy or address?
- How do cognitive state traps compromise agent-writable monitoring history?
- How should researchers separate factual claims from systems lessons in preliminary incident reviews?
- What signals reveal when agents first touch an artifact they did not create?
- Can commitments prove the right content was captured, not just that it matches later?
- What makes a claim robust enough to lift out of preliminary incident evidence?
- Can missing recorded stops tell us whether mechanisms actually exist?
- Does a blockchain anchor prevent tampering or only reveal it?
- What does a verification verdict miss when required steps never run?
- What makes provenance infrastructure more critical than artifact quality?
- Can a blockchain anchor distinguish when an event happened from when it was recorded?
- What tests would reveal whether recorded human approvals represent real oversight?
- Where else in the vault are recovery and rollback mechanisms already specified?