CISO
CTO
Enterprise Architect
Compliance Officer
Industry relevance
Financial Services
Healthcare
Government
MAY 24, 2026
CISA's agentic AI guidance answers accountability with logging. Logging cannot attribute, authorize, or remediate if the underlying system never could. Assess the substrate first.
On April 30, 2026, six national cyber agencies published joint guidance on adopting agentic AI. It names accountability as one of five core risks and is candid about why tracing agent action is hard: opaque decisions, attribution that fragments across separate logs, reasoning chains that resist reconstruction. Then it prescribes the remedy almost entirely as logging. Comprehensive artefact logs by default, unified inter-agent audit trails, interpretability tooling. Logging answers a question that comes second. It assumes the system of record underneath can already attribute a write to an agent, express authorization at the level of a business operation, and reconstruct the business state at the moment of action. Many enterprise systems cannot. An audit log that records modified by integration user has captured the event perfectly and identified no one. The accountability the guidance asks for has to be supported by the substrate before any log can establish it.
GOVERNANCE IMPLICATION
CISA's joint agentic AI guidance treats accountability as a logging problem and prescribes comprehensive audit trails, unified inter-agent logs, and interpretability tooling. Logging is downstream of a prior question the guidance never asks. Can the system of record attribute a write to an agent, express operation-level authorization, reconstruct the business state at the time of action, and remediate an incorrect write. If the substrate cannot do these, no volume of logs produces accountability. Regulated enterprises should assess substrate readiness before treating logging as their accountability control. The Agent Substrate Readiness Model Tier Two provides the five-question test that sits above the logging layer the guidance recommends.
SCENARIO
A procurement agent updates a status field it was permitted to touch. Six weeks later a vendor is flagged incorrectly, because that field was a compliance hold a human would have recognized on sight. The audit log shows the agent ran. It does not show who sanctioned that specific state transition, or whether the system can even separate the agent's write from the human who invoked it. The event can be logged in four different tools and still not answer the only question an examiner asks first. Who authorized this write, and can the system prove an agent made it.
THE GOVERNANCE QUESTION
Before logging becomes the accountability control, can your system of record attribute a write to an agent rather than a human, authorize a business operation rather than table access, and reconstruct the business state at the moment the agent acted?
CONTROL GAP
The guidance's accountability controls are observability measures: artifact logging, unified audit logs, interpretability tools. None establishes whether the system of record can attribute agent identity, authorize at the operation level, or reconstruct business state. Those substrate properties sit upstream of logging and are not addressed.
REGULATORY RELEVANCE
NIST Ai RMF
OCC
FINRA
PRIMARY SOURCE
Careful Adoption of Agentic AI Services
CISA, NSA, ASD's ACSC, CCCS, NCSC-UK, NCSC-NZ
April 30, 2026
Read the primary source ->(opens in new tab)CONTINUE READING
MAY 21, 2026
AccountabilityOn May 21, 2026, Microsoft Digital published its primary internal agent-governance guide on the Inside Track Blog, authored by Alex Fleck, the third in a connected series following the Frontier Firm guide (April 16, 2026) and the Copilot governance guide (May 7, 2026). The guide describes six governance principles, a matrixed review model spanning SharePoint Agent Builder through Microsoft Foundry, agent lifecycles tied to user identity or to attestation and accountability confirmations for team-owned agents, and Microsoft Agent 365 as the observability and tracking layer. Its closing principles state that effective governance must be human-led, because accountability and judgment remain essential.
MAY 7, 2026
AccountabilityMicrosoft Digital's internal Copilot governance guide, published May 7, 2026 and updated June 8, 2026 by Alex Fleck on the Inside Track Blog, requires every full-time employee with a shared SharePoint container to re-attest its compliance every six months. Attestation confirms the container is correctly labeled, that the owner still wants it to exist, and that its access roster remains accurate. Containers without attestation are treated as orphaned and scheduled for deletion. The guide also cites Microsoft Entra's inactive-group expiration policy as a parallel renewal mechanism.
MAY 5, 2026
AccountabilityThe 2026 Work Trend Index, published May 5, 2026 by Microsoft WorkLab, reports that only 26% of AI users say their leadership is consistently aligned on AI strategy. A companion finding shows that only 13% of workers say their employer rewards reinventing work with AI when results fall short. The survey covered 20,000 knowledge workers across 10 countries, conducted by Edelman Data x Intelligence between February 18 and April 7, 2026.