The push is real, and most of the reasons are honest
The move to agentic AI is the fastest technology adoption we have watched at close range, and most of what drives it is legitimate. An agent collapses the cost of routine knowledge work. It runs through the night. It covers a breadth of tasks that no team could staff, and it does not lose interest in the boring ones. For a small organisation, agents are the difference between a roadmap and a wish list. We build with them every working day and the gains are not hype.
There is also a commercial engine underneath the enthusiasm. The industry has moved from selling tools to selling work itself: not software that helps a person do a task, but a substitute for the person doing the task, priced accordingly. Once work itself is the product, the pressure to put an agent between every person and every system is enormous, because every interface an agent mediates is revenue.
That second driver deserves more scrutiny than it gets, because of what mediation quietly does to evidence.
The quiet casualty is the paper trail
Organisations run on records precisely because human accounts of history are unreliable. The file, the ledger entry, the signed approval and the timestamped log exist so that what happened does not depend on what anyone later says happened. Regulated industries state it plainly: if it is not documented, it did not happen.
Now put an agent in front of the records. It retrieves them, summarises them, renames them, versions them, tidies them. Every one of those verbs is sold as convenience, and each one is also a transformation of evidence by a system that is difficult to inspect and that changes behaviour with every model update.
Consider the failure that worries us most, because it is so quiet. A person asks for a document and the agent answers page not found. That answer is compatible with three different histories: the document never existed, the document was deleted, or the document exists and was not served. From the person's side of the screen these are indistinguishable. And if the question is asked again next month, an agent with no reliable memory of its own actions can flatly, sincerely deny that anything was ever there.
It does not take malice. Context gets compacted and detail is lost. A summariser drops the inconvenient paragraph without knowing it was inconvenient. A model update changes what the agent considers relevant. A retrieval index quietly fails to cover a folder. The motive hardly matters, because the effect is identical in every case: history becomes negotiable, and the organisation's answer to what happened? becomes whatever the agent serves that day.
Whether anyone in the market privately welcomes that property is a question we cannot settle. What we can say is that a mediated record with no independent trail is convenient for whoever controls the mediator, and that organisations should notice whose interests that serves before they wire it in.
A quick pulse, while it is fresh
Could your organisation prove, with evidence rather than memory, what its agents did last month?
How to get the full paper
The remedies are deliberately not on this page. The rest of the argument, and the working material that makes it usable, is in the full paper, and the way to get it is simple: enter a work email below, we email you the link, and the download starts straight away as well. It covers:
- Evidence outside the agent's reach. The witness log: written by infrastructure rather than by the agent, append-only and hash-chained, stored where the agent has no path, and the red team check that proves all three.
- The factory before the field. Scenario banks replayed on every change, hallucination measured per release rather than reported anecdotally, and model weight changes treated as personnel changes, with regression evidence.
- Why the control has to come now. You cannot backfill an audit trail: the record you keep from the first day an agent touches your systems is the only record you will ever have of that period.
- Where is the code of practice? Why nobody with standing has published an enforceable one, and what a usable code contains.
- Three appendices. The witness log specified as a five property verification table, the factory release gate we run before any agent or model change reaches the field, and the five clause code of practice you could sign today, each clause with the test that proves it.
Get the full paper by email
The full paper is free. We email the link to your inbox so it survives the browser tab, and the download starts immediately as well.
Related work
The rule set and recovery argument is in the rules are the asset, the operational side is in agentic AI in operations, and the live twin these agents act on is in autotwins.