Guide

What to record about an AI agent

Recording an AI agent is the first governance step, not the last. What to record about each agent, why each field matters and how the record earns its keep.

What should you record about an AI agent?

Recording an AI agent is the first governance step, not the last. You cannot assess an agent, oversee it or answer for it if you do not know it exists and cannot describe what it can do. This guide sets out what to record about each agent, why each field matters and how the record earns its keep, anchored to Australia's Voluntary AI Safety Standard.

Guardrail 9 of the standard asks you to keep and maintain records that let a third party assess your work against the guardrails. For an agent, a record that only names the tool is not enough. The record has to describe what the agent can do and who answers for it, and it has to stay current as the agent changes.

What a good agent record contains

An agent record covers more than a system record, because an agent acts. Cover the following.

Record the agent and its purpose, which is what the agent is, the goal it is set and the scenarios it runs in. Record enough that someone who has never seen it can tell what it is for.

Record the human owner, the named person accountable for the agent. Guardrail 1 of the Voluntary AI Safety Standard is direct that accountability for AI cannot be delegated or outsourced, so every agent has a person, not a team, answerable for it.

Record the permissions and reach, meaning the systems the agent can read from and write to, the credentials it holds and the other agents, tools or services it can call. This is the part a system record usually skips and the part that matters most for an agent, because it is the surface area of everything the agent could do.

Record the autonomy. This is which actions the agent may take on its own and which actions stop for a person to approve. Record the line, because the line is the thing you are governing.

Record the risk position, which is whether the agent has been assessed, what the assessment found and where the full assessment lives, wherever your organisation keeps that work.

Record the oversight in place, meaning how a person can see what the agent is doing, how they can stop or override it and who watches it in operation.

Record the lifecycle dates, which are when the agent went into use, when it was last reviewed and when it is next due. Agents change as their prompts, tools and permissions change, so a record without a review date drifts out of date without anyone noticing.

Why the record has to stay current

An agent is not static. Its prompt is tuned, a tool is added, its permissions are widened to cover a new task. Each change can move the agent’s risk without anyone re-opening the paperwork. A record that described the agent accurately at launch can quietly stop describing the agent that is running now.

That is why the record is versioned and reviewed rather than written once. When the agent changes, the record changes with it, and the earlier versions stay as the account of what the agent was and when. ISO/IEC 42001 frames AI governance as a management system for exactly this reason, so that the record of a system reflects it across its life and not only on the day it was signed off.

What the record is for

A current agent record does real work. The accountable owner can oversee the agent because they can see what it can do. You can assess and reassess it because the assessment starts from an accurate picture of its reach and autonomy. And when a third party asks, a board, an auditor, an enterprise customer running due diligence or a regulator, you can show what the agent is, what it can do and who answers for it, with the history to back it.

Where Aicura fits

Aicura is your AI Register, and your agents live in it as their own kind of entry alongside your systems. It surfaces each agent’s purpose, permissions, autonomy and owner, carries the agent’s disclosure and model card, and versions the record as the agent changes so the history is there, prompting you when a review is due. Incidents record when an agent does something it should not have, so the record stays true to how the agent behaves and not only to how it was set up. When you need to show the record to someone outside the organisation, the Evidence Vault holds a snapshot that is cryptographically anchored and externally verifiable, evidence you don’t have to trust us for.

People keep the record’s contents current, deciding what an agent is for and what it may do. Aicura is the system of record that holds it, surfaces it and prompts the review. It does not certify the agent or sign off its use.

Sources

  • Voluntary AI Safety Standard, Department of Industry, Science and Resources, industry.gov.au/publications/voluntary-ai-safety-standard
  • ISO/IEC 42001:2023, Information technology, Artificial intelligence, Management system

A note on this page

This guide is general information on what to record about an AI agent under current Australian and allied guidance. It is not legal advice and it does not tell you whether your records meet a particular obligation. For how the guidance applies to your organisation, read the primary source above and take your own professional advice.

When you need to show your work

Aicura is your AI Register, and Pro adds the assurance layer, meaning impact assessments, incident records, attestation and the Evidence Vault, which seals each record so it can be verified without taking anyone's word for it, ours included. Pro is sales-led, so the best next step is a conversation and a walkthrough.