← Article Library
Original Article

Your AI May Be Able to Rewrite Its Own Alibi

Why the next serious AI failure may leave your organization unable to prove what happened

Original article by Donald P Andrechek.

If your AI causes harm tomorrow, can you prove what it did without asking the AI to explain itself?

If one of your most capable AI systems caused harm tomorrow, could your organization prove exactly what it did?

Not approximately.

Not through a summary prepared after the incident.

Not through a dashboard showing normal performance.

Not through an explanation generated by the same system whose conduct is under review.

Could you reconstruct the evidentiary path?

What the system received. What it retrieved. Which model and configuration were active. Which tools it accessed. Which records it changed. Which actions it triggered. What the human reviewer actually saw.

What happened in what order. Why the workflow continued. Who had the authority to stop it.

If the honest answer is no, your organization does not merely have a logging problem.

It may have an AI system capable of helping create its own institutional alibi.

Not because the AI is plotting or protecting itself. The danger is structural. The system may be permitted to act, record, summarize, and explain inside the same evidence environment that will later be used to investigate it.

The system acts. The system records. The system summarizes. The system explains. The organization then audits the record the system helped produce.

The Incident May Have No Independent Witness

Traditional systems often leave separate traces. A person sends an email. A worker signs a form. A manager approves a decision. A system records a transaction. An investigator compares records, timestamps, statements, and external evidence.

Agentic AI can compress many of those acts into one automated path.

One agent may read a complaint, retrieve policy, classify the issue, summarize the facts, recommend an outcome, update a record, draft a response, route the case, and close the workflow. Several consequential steps may occur in seconds.

The person named as accountable may see only the recommendation. The board may see only a performance dashboard. The auditor may see only an activity report generated from the same environment in which the agent acted.

That creates a profound question: where is the independent evidence?

A log is not automatically independent evidence. It may show that an action occurred without preserving the context needed to understand it. It may record a tool call without retaining the relevant source. It may preserve the output but not the input, model version, permissions, retrieved material, approval conditions, or external system changes that shaped the outcome.

A record can exist and still be unable to support a defensible account of what happened.

The AI Does Not Need to Delete the Evidence

The phrase "rewrite its own alibi" may sound like deliberate concealment. The real risk is often less dramatic and more credible.

Evidence can disappear through ordinary design choices.

A raw record is replaced by a summary. A tool response is not retained. Temporary context is lost when a session ends. A human correction overwrites the original output. A vendor log proves that a request occurred but does not preserve the information needed to understand the result. A workflow records completion but not the circumstances that made the action significant. A later model or configuration change makes exact reproduction impossible.

An incident report may then be drafted with AI, unintentionally turning uncertainty into polished certainty.

Nothing has to be secretly erased. The organization may simply fail to preserve the evidence needed to reconstruct reality.

By the time someone asks what happened, the only complete looking story may be the story the system produced.

Your Audit Trail May Be Inside the System It Is Supposed to Audit

An organization may proudly state that every AI action is logged.

That answer is not enough.

Where are the logs stored? Can the agent change them? Can an automated workflow overwrite them? Can an administrator alter them without creating a separate record? Do the logs preserve raw events or only generated summaries? Are events correlated across every connected tool and external system? Are sensitive inputs handled in a way that supports oversight without violating privacy and security duties?

Current Government of Canada guidance for agentic AI says that all actions taken by an AI agent should be fully logged in a system the agent cannot change. It also calls for logs of tools used, actions taken, approvals, and key inputs and outputs, with privacy and security controls applied to sensitive information.

The guidance requires a pause and disable mechanism external to the agentic system and connects comprehensive time stamped records with auditability and incident reconstruction.

The European Union AI Act applies specific logging and human oversight duties to high risk AI systems.

Article 12 requires those systems to technically allow automatic event logging over their lifetime. Article 14 requires effective human oversight and, where appropriate, the ability to disregard, override, reverse, intervene in, or safely stop the system.

OWASP's current MCP Top 10 beta guidance identifies lack of audit and telemetry as a serious risk in agent connected environments. It warns that weak logging can prevent root cause investigation and recommends structured, integrity protected, centralized records of agent actions, tool calls, context changes, and user interactions.

The direction across these sources is clear. Traceability is not a decorative control. It is part of the evidence required to understand and contain consequential AI action.

An audit trail that the AI environment can influence cannot be treated as fully independent evidence of the AI environment's conduct.

Reconstruction Is Not the Same as Reading the AI's Mind

A technically serious investigation should not depend on access to hidden model reasoning.

An AI generated explanation is another output. It may be useful as a lead, but it is not an independent record of causation and should not be treated as proof of what internally produced the result.

The audit should preserve observable evidence: the model and version used, relevant configuration, system instructions where lawful and appropriate, user input, retrieved sources, tool calls, outputs, approvals, timestamps, permissions, state changes, and external system logs.

Generative systems can also be nondeterministic. Even when the same input is supplied again, an exact replay may not occur. That does not eliminate accountability. It changes the requirement.

The organization needs a defensible reconstruction of the evidence and operating conditions, not a fictional promise that every model output can be perfectly replayed.

This distinction is essential. AI accuracy does not improve when an investigation pretends to know more than the preserved evidence can prove.

The System May Know More Than the Human Investigator

Imagine an AI agent working inside a customer service operation.

It receives a complaint involving financial hardship. It searches previous interactions. It retrieves policy. It ranks the complaint as low urgency. It drafts a response. It updates the customer record. It schedules no further review. A human approves the response.

Two weeks later, serious harm is alleged.

The file shows the complaint. It shows the final response. It shows human approval. It shows the policy cited. It shows a normal risk classification. Everything appears traceable.

But the investigation cannot establish several facts.

What exact records did the agent retrieve? Were all relevant interactions available? Which model, configuration, permissions, and tools were active? Did untrusted content influence the workflow? What information was removed from the summary? What source evidence supported the low urgency classification? What did the human reviewer actually see? How much time was available? Did the reviewer see the original complaint or only the AI prepared version?

The records show a process. They do not prove that the process can be understood.

The organization may know that an action occurred while remaining unable to build a defensible account of why it occurred.

That is administrative visibility without evidentiary control.

Human Approval Can Make the Alibi Stronger

The presence of human approval may make the final record look more trustworthy. It can also hide how little human judgment survived.

A reviewer may approve hundreds of AI prepared decisions. The person may see only information selected by the system. The interface may place the recommended action in the most prominent position.

Performance targets may reward rapid acceptance. Challenging the recommendation may require opening several separate systems.

The reviewer may carry legal or professional accountability while lacking the practical ability to reconstruct the AI supported path.

The record will show that a human approved the decision. It may not show that meaningful challenge was nearly impossible.

The human signature can then become part of the system's institutional protection. Leadership can say a person remained responsible. The audit can confirm human involvement. The investigation can identify an approver.

But a human name in the record does not prove human control.

Sometimes it proves only that accountability had somewhere to land.

The Most Dangerous Sentence After an AI Incident

After a serious failure, someone will eventually say:

According to the system records, everything operated as designed.

That sentence should concern every board.

A system can operate as designed and still produce an outcome the design cannot adequately reconstruct.

A control can operate and still fail its purpose. A human can approve and still lack meaningful choice. A log can exist and still omit decisive context. A dashboard can remain green while the evidence chain is already weak.

The organization may then treat the absence of contradictory evidence as proof that no contradiction existed.

Missing evidence does not confirm the official story. It may confirm only that the system did not preserve an alternative account.

TTP Changes the Investigation

TTP does not begin by asking whether the log exists. It asks whether the organization can still reach operating reality through the evidence.

Truth Can the action chain be reconstructed from source evidence and independent records? Can the organization distinguish raw evidence from AI generated interpretation? Were missing sources, uncertainty, contradictions, system changes, and AI involvement preserved?

Tempo Did the system move across tools and records faster than people could understand or interrupt? Did many actions occur before a weak signal reached someone with authority? Did speed reduce the time available for verification or evidence preservation?

Preparation Was incident reconstruction designed before deployment? Were logging, retention, escalation, recovery, independent storage, and external stop authority tested under realistic conditions? Did people know which records had to be preserved before legal, safety, regulatory, or public pressure arrived?

Capacity Margin

Did anyone have enough time, context, skill, independence, authority, and support to notice, challenge, pause, preserve, correct, and recover? Could someone stop the system without needing the system's cooperation?

These questions expose something ordinary assurance can miss. The organization may possess logs, policies, approvals, dashboards, and incident procedures while still lacking the ability to prove what happened.

TTPCM Tests More Than the Presence of Logs

TTPCM is the protected professional audit methodology developed under TTP. It is designed to examine whether claimed control survives Truth, Tempo, Preparation, and Capacity Margin.

The public questions identify the territory. They do not reveal the protected scoring, sequencing, interpretation, rating, certification, or implementation methods used to test and connect the evidence.

A TTPCM based audit would not treat logging as a completed control merely because records exist. It would challenge whether the evidence is sufficiently independent, whether the chain can be reconstructed, whether meaning survived transformation, whether uncertainty was preserved, whether human review was genuine, whether timing weakened verification, whether permissions expanded, whether the stop mechanism existed outside the agent, and whether recovery can occur without relying on the AI system's own account.

The difference is decisive.

A conventional control test asks: Was the activity logged?

A deeper integrity audit asks: Is the evidence complete, protected,

understandable, and independent enough to support a defensible

reconstruction?

Ask Your AI Team These Questions

Do not ask only whether the AI system has logs. Ask whether the evidence could survive a serious investigation.

 Can you reconstruct each consequential action from the originating instruction to the external outcome?

 Can you identify the model, version, relevant configuration, tools, permissions, data sources, and key inputs and outputs involved?

 Can the agent or its surrounding workflow alter, overwrite, summarize, or delete any part of the authoritative audit trail?

 Are raw records preserved separately from generated explanations and summaries?

 Can you prove what the human reviewer actually saw, when they saw it, and what authority they had?

 Can you correlate actions across every connected system rather than relying on one platform's account?

 Can you recreate enough of the relevant environment to test the outcome after model, vendor, tool, or configuration changes?

 Can you distinguish an AI generated incident narrative from the original evidence?

 Can you pause or disable the system through a mechanism the agent cannot control?

 Can you build a defensible account of what happened without treating the AI's own explanation as independent proof?

These questions determine whether the organization will possess evidence or merely possess a story.

The Board Will Discover This Too Late

Boards often ask whether the organization is monitoring AI. That is no longer enough.

The board should ask whether management can reconstruct a consequential AI action after something goes wrong. It should ask whether the authoritative audit trail exists outside the agent's influence. It should ask what records disappear when a session ends. It should ask whether raw evidence is retained before AI summarizes it. It should ask whether human approval proves meaningful review. It should ask what happens when an agent acts across several systems faster than one control owner can follow.

NIST's AI Risk Management Framework is a voluntary, full lifecycle framework for governing, mapping, measuring, and managing AI risk. NIST's Generative AI Profile extends that work to risks specific to generative AI. In April 2026, NIST began developing a Trustworthy AI in Critical Infrastructure Profile to guide risk management practices for AI enabled capabilities in high consequence environments. That profile remains under development.

The warning is becoming clearer. Organizations are connecting AI to greater authority before many have proven they can preserve and reconstruct the evidence of what that authority does.

The Next AI Scandal May Begin With an Empty Record

The public will ask what happened. The board will ask why it was not warned. The regulator will ask for records. The auditor will ask for evidence. The lawyer will ask who approved the action. The investigator will ask for the path from instruction to consequence.

And the organization may discover that the decisive information was never preserved.

The raw input is gone. Temporary context expired. A tool result was not retained. The model changed. A summary replaced the source. The human saw only the recommendation. The log recorded completion but not the circumstances needed to understand it.

The official report is polished. The evidence is incomplete.

At that point, the AI system will not need to lie. The organization will have built a process in which the most important parts of the truth can no longer be proven.

The Question Every Organization Must Answer

The future of AI integrity will not be decided by how confidently organizations describe their controls.

It will be decided by whether they can support a defensible account of what their systems did when confidence collapses.

If your most capable AI caused harm tomorrow, could you reconstruct the evidentiary path without relying on the AI's own version of events?

Post your answer.

Not your policy. Not your dashboard. Not your promise that humans remain responsible.

Your answer.

Because when the incident arrives, the absence of evidence will not prove the system was under control.

It may prove only that the system was allowed to operate without an independent evidentiary record.

Author Note

This article develops the AI control, assurance, and evidence integrity arguments introduced in The AI

Control Illusion: Why Governance, Policies, and Dashboards Will Not Save Organizations from Agentic AI

About the Author

Donald P Andrechek is a Canadian author, health and safety professional, and creator of TTP, a human system readiness and failure formation framework built around Truth, Tempo, Preparation, and Capacity Margin. He is also the developer of TTPCM, a protected professional audit methodology designed to examine whether evidence, governance, human oversight, and claimed control remain connected to operating reality.

Professional and Standards Boundary

TTP and TTPCM are designed to strengthen truth testing, evidence integrity, readiness, and professional challenge. They do not replace statutory financial audit, legal advice, forensic investigation, cybersecurity testing, privacy assessment, regulatory inspection, engineering judgment, safety duties, sector specific requirements, or other applicable professional standards. TTPCM's protected methodology remains under controlled development and should not be represented as certification of legal or regulatory compliance.

Selected Official Sources

• Government of Canada, Guide on the Use of Agentic Artificial Intelligence. Official guidance on

recoverability, agent independent logging, human checkpoints, key action records, external pause mechanisms, monitoring, and auditability.

• European Union, Regulation (EU) 2024/1689, Artificial Intelligence Act. See Article 12 on record keeping and Article 14 on human oversight for high risk AI systems.

• NIST, Artificial Intelligence Risk Management Framework 1.0. Voluntary full lifecycle framework for

managing AI risk.

• NIST, Generative Artificial Intelligence Profile, NIST AI 600-1. Companion profile addressing risks specific to generative AI.

• NIST, Concept Note: AI RMF Profile on Trustworthy AI in Critical Infrastructure. Profile development

launched in April 2026 and remains ongoing.

• OWASP, MCP08:2025, Lack of Audit and Telemetry. Current beta project guidance on structured,

integrity protected logging and telemetry for MCP and agent connected environments.

Technical accuracy reviewed against official sources on July 27, 2026.

Continue reading

More writing from Donald P Andrechek

Return to the article library to explore safety, leadership, TTP, human capacity, AI, education, healthcare and systems.

Browse all articles