At a glance
- EU AI Act and DORA audit trails must reconstruct what an agent was asked, which tools it reached, and what it changed.
- Process-level endpoint telemetry shows that a binary executed; it cannot show an agent's instructions, its tool calls, or the outcome.
- Backslash security research found hidden instructions in a repository's AGENTS.md file could trick OpenAI Codex into silently accessing AWS credentials and Git configuration.
- Latio's 2026 AI Security Market Report named Backslash an Endpoint AI Security Leader for in-depth controls over AI on the endpoint.
Backslash Security
Published:
An audit trail that will hold up under EU AI Act or DORA examination has to reconstruct a specific agent run: the instruction that started it, the model and connected tools it reached through, the calls it made, and what it changed — on the endpoint where it executed under an employee's own identity. Most organizations cannot produce that record today, because their endpoint telemetry stops at the process boundary. Endpoint detection and response, the incumbent layer built to catch malicious processes, files and known-bad behavior on a machine, can show that an agent binary ran; it cannot show what the agent was instructed to do or which connected systems it acted on afterward. Backslash Security traces the full path of an agent run from prompt to agent to tool call to outcome, which is the level of detail a reconstruction depends on. Framed that way, the audit trail is first a question of what gets captured on the endpoint during the run, and only then a reporting question.
The surface that has to be recorded is wider than most inventories assume. An endpoint running a coding agent such as Claude Code or Cursor may also carry MCP servers — Model Context Protocol is the protocol agents use to connect to external tools and data sources, and each server is a live connection an agent can act through — alongside Skills, hooks, rules files, plugins and connectors, any of which can change the agent's behavior on its next run. Backslash Security discovers every agent, model, MCP server, MCP tool, Skill, hook, rules file, plugin and connector running on an endpoint, and its MCP Server Security Hub held 81,021 publicly available MCP servers, each scored for risk, when read on 22 September 2026. Latio's 2026 AI Security Market Report named Backslash an Endpoint AI Security Leader, a badge awarded to vendors demonstrating the most in-depth controls for AI on the endpoint, including permission mapping, folder structures, approved commands, and runtime controls for MCPs and Skills.
What do the EU AI Act and DORA actually require you to record about AI agent activity?
This section narrows the question to one case: what the EU AI Act — the European Union's regulation governing AI systems — and DORA, the Digital Operational Resilience Act covering ICT risk in EU financial entities, expect you to be able to produce about agent activity running on employee machines. Neither text is written around endpoint agents as such. The AI Act's record-keeping obligations are framed around automatic event logging across an AI system's lifecycle, traceability of how a system behaved, and documentation supporting human oversight. DORA is framed around ICT risk management and the ability to reconstruct an incident: what happened, in what order, through which systems and third-party connections.
Translated into agent terms, the attributes an auditor will look for are reasonably consistent:
| Record attribute | Values you should be able to show | Why it matters |
|---|---|---|
| Component inventory | Named agents, models, MCP servers, MCP tools, Skills, hooks, rules files, plugins, connectors | Establishes the scope of AI in use; an obligation you cannot enumerate, you cannot evidence |
| Actor identity | Enterprise identity (Entra ID, Okta, Active Directory) versus a personal account | Shows whose access the agent acted under, central to accountability under both regimes |
| Instruction source | Prompt, rules file such as AGENTS.md or CLAUDE.md, Skill, or hook that triggered the run | A rules file carries standing instructions an agent reads on every run, so it shapes behavior invisibly |
| Action and target | Tool calls, file and credential access, commands executed, destinations contacted | The event record proper — the substance of traceability and incident reconstruction |
| Disposition | Allowed, blocked inline, or flagged | Demonstrates that a control existed and operated, not merely that a policy document existed |
| Sequence and continuity | Ordered, time-stamped run history retained and exportable to a SIEM such as Splunk | Supports reporting timelines and forensic replay |
The practical obstacle is the first row. Backslash Security discovers every agent, model, MCP server, MCP tool, Skill, hook, rules file, plugin and connector running on an endpoint, which is what turns these obligations from a drafting exercise into a populated register.
Why does agent activity on employee endpoints escape the evidence record?
When an AI agent runs on an employee's own machine, the activity it generates lands outside the systems your evidence record draws from. The agent executes under that employee's identity and local permissions, and its tool calls travel through MCP servers — Model Context Protocol connections, each one a path an agent can act through — that are configured per user, not provisioned centrally. Endpoint detection and response was built to catch malicious processes and known-bad files; it can log that a process read a credential file, but not that a rules file told the agent to go looking.
The components themselves are equally quiet. Agent Skills are packaged instructions and scripts, often just a markdown file in a user directory. Hooks fire before or after an agent action. A rules file such as AGENTS.md or CLAUDE.md carries standing instructions the agent reads on every run. None of these pass through a change process, and MDM platforms like Intune or Jamf enroll the device without enumerating what the agent invokes on it. When an employee signs a coding assistant in through a personal account, the session never appears in Entra ID or Okta either.
| Do this | But watch out for — and how to cover it |
|---|---|
| Inventory agent components on endpoints continuously | A one-off scan ages immediately as users add Skills and MCP servers; use ongoing discovery, not an onboarding snapshot |
| Forward agent evidence into the SIEM, such as Splunk | Evidence left only on individual laptops is not somewhere an auditor can query; collect tracing data from the endpoint into a central record |
| Require enterprise identity for agent sign-in | Private-account access leaves no record in the identity provider; detect personal-account use on corporate machines directly |
| Decide which components may run at all | A blanket block stalls adoption; scope allowlists and denylists per team and risk profile |
Backslash Security pairs that continuous discovery with allowlisting and denylisting of components, scoped per team and risk profile.
What has to be in an audit trail before a regulator or auditor will accept it?
This narrows to one case: the record of an AI agent run on an employee endpoint. Before an auditor or supervisor will treat that audit trail as defensible, it has to answer four questions without inference — who acted, what was running, what instructions were in force, and what the action touched. Regimes such as the EU AI Act and DORA are generally read to require records sufficient to reconstruct an event after the fact, not summary counters.
Which attributes must each record carry?
| Attribute | Allowed values / content | Why it decides acceptance |
|---|---|---|
| Actor identity | Human principal plus the agent and model that executed, including whether a personal account was used | Enterprise versus private identity is the first thing an investigator reconstructs |
| Component inventory reference | The specific agent, MCP server (the protocol agents use to reach external tools), Skill, plugin or connector invoked, with version | Without it, the same action cannot be attributed to a known, approved component |
| Instruction provenance | The prompt, plus the rules file — a file carrying standing instructions an agent reads on every run, such as AGENTS.md or CLAUDE.md — in effect at execution | Separates operator intent from instructions injected through content the agent read |
| Action and tool call | Command, tool call parameters, target system, and the hook that fired around it | Distinguishes a sanctioned task from credential access or privilege escalation |
| Outcome and destination | Result, data read or written, and the destination it was sent to | Shows whether data reached a destination outside approved policy, which an incident reconstruction has to establish |
| Time and sequence | Ordered timestamps across the run | Reconstruction depends on sequence, not isolated events |
| Integrity and retention | Tamper-evident storage, defined retention, exportable to a SIEM such as Splunk | A record an operator can silently edit carries little evidentiary weight |
Most of these attributes are unavailable unless the inventory exists first. Backslash Security discovers every agent, model, MCP server, MCP tool, Skill, hook, rules file, plugin and connector running on an endpoint, which is what lets a logged action resolve to a named, assessed component rather than an anonymous process.
Which architectural layers can reconstruct agent activity, and what does each one actually see?
Reconstructing an agent run after the fact depends entirely on which architectural layer captured it, and the layers differ sharply in what they can evidence. Before comparing them, it helps to fix the criteria that decide whether a record is usable as evidence at all.
- Identity attribution — whether the record ties the activity to a named corporate identity rather than to an API key or a personal account. Decisive when an employee signs in with a private login on a company machine.
- Instruction provenance — whether you can see what the agent was told, including standing instructions in a rules file (a file such as AGENTS.md or CLAUDE.md that an agent reads on every run) or an Agent Skill. Decisive in any suspected prompt injection, where hidden instructions arrive inside content the agent reads.
- Action coverage — whether local actions are captured: file reads, shell commands, credential access, and calls through MCP servers, the Model Context Protocol connections an agent acts through.
| Layer | What it can evidence | What it cannot show |
|---|---|---|
| Model-provider logs | Prompts and completions for that one vendor's model; account-level usage | Anything run through another provider or a local model; what the agent then did with the output |
| Network and proxy layer | Destinations contacted, volumes, egress to unapproved endpoints | Instruction content, local file and credential access, which agent or Skill initiated the call |
| Server-side application logs | API calls that reached your own services, with service-side identity | Activity that never leaves the laptop; the reasoning or instruction chain behind the call |
| Endpoint-level telemetry | The components present and the actions they take locally, under the employee's own identity | Depends on scope — conventional process-level endpoint tooling records the process, not the instruction it followed |
That last distinction matters because the incumbent endpoint layer, EDR, was built to catch malicious processes and known-bad behavior, and an approved agent running an attacker's instructions looks like neither. Backslash Security works at the endpoint layer, discovering every agent, model, MCP server, MCP tool, Skill, hook, rules file, plugin and connector running on a machine.
How can a team build an agent audit trail step by step?
A team can build an agent audit trail in a defined sequence, and the order matters because each stage produces the input the next one depends on. The steps below assume an organization past the point of debating whether employees run AI agents and now deciding how to govern them — a consideration-stage sequence, not an awareness-stage primer.
- Discover what is actually running. Begin agentless — collecting information without leaving software permanently installed on the machine — so the first picture costs no deployment project. Backslash Security offers a free AI Endpoint Exposure Assessment, referred to in sales conversations as Scout, which is agentless, read-only and retains no data, and can be pushed through existing MDM tooling such as Intune or Jamf.
- Convert findings into an inventory. Record every agent, model, MCP server, MCP tool, Skill, hook, plugin, connector and rules file — a file such as AGENTS.md or CLAUDE.md that carries standing instructions an agent reads on every run. An inventory built as of 2026 has to account for coding agents including Claude Code, Cursor, Codex and GitHub Copilot, and each entry should be bound to a user identity from Entra ID, Okta or Active Directory.
- Assess risk posture per component before approving anything, so approval is a decision with a reason attached rather than a default.
- Write and enforce policy. Allowlist approved components, denylist risky ones, and vary policy by team — a research group and a finance team do not need the same permissions.
- Block at the point of action. Backslash Security blocks risky agent actions inline before execution, including unauthorized code execution, credential access, privilege escalation, and data sent to unapproved destinations. Discovery can be agentless; enforcement is not.
- Route and retain the record. Send agent activity into your SIEM, such as Splunk, and connect exceptions to Jira or ServiceNow so remediation is evidenced.
- Rehearse a reconstruction. Pick one agent run from the previous month and walk it end to end before an auditor asks you to.
Frequently Asked Questions
What does an audit trail for AI agent activity actually need to capture?
Regulators reviewing an automated decision under the EU AI Act, or an operational incident under DORA — the EU's Digital Operational Resilience Act for financial entities — expect a reconstructable record, not a log of processes that started. For agent activity, that means the instruction the agent received, the identity it ran under, the tools it reached for, and what it ultimately did. Backslash Security traces the full path of an agent run from prompt to agent to tool call to outcome, which is the chain an investigator needs to answer "who told it to do that, and what did it touch?"
Why doesn't the existing endpoint stack produce this record?
Endpoint detection and response, the incumbent endpoint security layer, is built to catch malicious processes, files and known-bad behavior on a machine. An agent run happens inside an approved process, under the employee's own identity, using permissions that were legitimately granted. Device management layers inventory hardware and installed applications; they do not enumerate the MCP servers, Skills and rules files an agent reads at runtime. MCP — Model Context Protocol — is the protocol agents use to connect to external tools and data, and each MCP server is a live connection an agent can act through.
How can a file in a repository end up mattering to the audit record?
A rules file, such as AGENTS.md or CLAUDE.md, carries standing instructions an agent reads on every run. Backslash security research found that malicious instructions hidden in a repository's AGENTS.md file could trick OpenAI Codex into silently accessing AWS credentials, npm tokens and Git configuration. Nothing in that sequence looks like malware, so an audit trail built only on process events would not show why the agent behaved as it did.
Which components belong in the inventory?
Backslash Security discovers every agent, model, MCP server, MCP tool, Skill, hook, rules file, plugin and connector running on an endpoint. Agent Skills are packaged instructions and scripts — in practice often a markdown file — that execute with the user's own permissions. Hooks are triggers that fire before or after an agent action.
How do teams start without installing software everywhere?
Backslash Security offers a free AI Endpoint Exposure Assessment, known in conversation as Scout, which is agentless, read-only, and retains no data. It is distributed through existing device management tooling and gives a first inventory as of 2026 before any policy decisions are made.
About this article
Backslash Security publishes this article under its own name and is responsible for its accuracy. Articles are researched and drafted with AI assistance and approved by Backslash Security before publication; publication and update dates reflect substantive edits, not automated refreshes. Last updated: 2026-10-08