An AI audit trail has to show who said yes, and to which version
Qamar Abbas4 min read
AI-assisted, human-edited
This post was drafted by an AI on my laptop on a Monday afternoon, and the first thing it did after writing the file was commit it under its own name. In the history of this site's code, that commit is signed "gravixar weekly research", with its own email address, and it sits in a folder the site doesn't publish. When the file is moved out, that move is a second commit under a person's name. So anyone reading the history can tell which words the AI wrote and who decided to publish them, and that small AI audit trail is the thing accounting firms now say they want before they'll trust AI with client work.
What accounting firms said they need
Uku, which makes accounting software, surveyed firms in eight countries in May and June 2026 for its AI in Accounting report. 62% said their trust in AI depends on a person approving before anything is sent or filed, and 44% picked a clear audit trail of what the AI did. Not one firm said it already fully trusts AI. The report describes the sample as dozens of firms, so I'd read those percentages as a direction rather than a measurement.
I'd treat the two answers as one request, because an approval nobody can find later won't help when a client disputes a filing, and a log of AI output with no approval in it only shows that the AI ran.
What an AI audit trail usually records
The usual AI log stores the prompt, the response, the model and a timestamp. That's useful when you're debugging the AI, but it doesn't help much when a client says "I never agreed to that", because they're asking who looked at the work and whether what they looked at is what went out.
So when I build a review step around AI work, the record has to hold four things, and the AI's output is only one of them.
The first is the AI's work under its own identity. If the AI's changes are logged as whoever happened to be signed in, you can't separate them later. On this blog that's the separate commit name. Inside a client system it's a separate actor on every audit row.
The second is the approval as its own entry, with a name and a time. In the client sign-off flow I run in an agency portal, work moves through fixed steps, from draft to internal review to client approval, and each step writes its own line to the audit log. Nobody can mark work approved by editing a status field, and the AI can't approve at all. It drafts briefs and that's where its part stops.
The third is the version. An approval has to point at the exact version that was approved. When a client asks for changes in that same flow, the work goes back to draft, the earlier approvals stay in the history, and the next submission is flagged so the reviewer sees exactly what changed since they last said yes. Without that, a second approval quietly covers edits the reviewer never saw.
The fourth is what happens after approval. In the audit log I use in the agency portal and the healthcare platform, some edits can be undone in one click, and the undo writes a new row pointing back at the original. Status, money amounts and who owns a piece of work are never on that list. Changing those needs a person, and that person shows up in the record too. Records about contracts and money are kept for seven years and everyday changes for one.
What a client actually asks
The engineering in all of this is simple, so most of the work is deciding where the approval lives. I wrote before about how approval is the slow part on this blog, and the audit trail is the reason I'm fine with that. When someone asks whether a post was reviewed, the answer is the commit that moved it, who made it and when, and the diff between what the AI wrote and what went live.
For an accounting firm the same question comes from a client or a regulator, and it's about a filing or an email to a client. "Did a person check this before it went out, and is the thing they checked the thing that was sent?" If the system can answer that from its own records, the firm can let AI do the drafting and still stand behind what went out. If it can't, someone at the firm ends up rebuilding the answer from old emails.
Where it costs me
Keeping the approval as a separate act means things wait for me. One draft on this blog sat in that unpublished folder for 40 days before it was moved out. The record shows that too, with the date the AI committed it and the date it was published, which isn't flattering, but it's accurate.