AI & Trust

What every AI action needs to prove

If AI takes action, the company needs proof: who acted, what authority allowed it, which policy applied, what evidence was used, and where the audit record lives.

Effective
Last updated
Reading time
6 min

On February 14, 2024, Air Canada was ordered to compensate a passenger after its chatbot gave the wrong refund guidance. The customer had asked about bereavement fares. The chatbot told him he could buy a regular ticket and claim a refund later. The actual policy said the opposite.

Air Canada argued the chatbot was a separate legal entity. The tribunal rejected that argument.

The damages were small: C$650.88. The precedent was larger: the company was responsible for what its AI system told a customer.

The lesson is not "train the chatbot better." The lesson is that AI systems need proof around their actions.

The wrong question

Most AI safety conversations start with the model:

  • Is the model aligned?
  • Is the prompt good?
  • Are the guardrails strong?
  • Did the model hallucinate?

Those questions matter, but they are not enough for business software.

If an AI system issues a refund, sends an email, changes a campaign budget, rejects an applicant, writes to a customer record, or deploys code, the company has to answer a different set of questions:

  • Who or what acted?
  • Was it allowed to act?
  • Which policy applied?
  • Was approval required?
  • What evidence did it use?
  • Where is the permanent record?

If the answer is "we have logs," the system is probably not ready for high-stakes action.

Why the company cannot outsource responsibility

AI makes it tempting to blame the tool.

The model answered. The agent clicked. The automation sent the message. The vendor hosted the system. In a real dispute, those explanations do not remove company responsibility. A customer does not have a contract with the model. A regulator does not audit the prompt alone. A court will ask what the company allowed its system to do.

This is why the action record matters more than the model brand. Models will change. Vendors will change. Prompts will change. The business still needs a durable answer to the same questions: who acted, what was allowed, what evidence was used, what rule applied, and what record was written.

For low-stakes drafting, that may be too heavy. For refunds, hiring, finance, pricing, customer promises, data exports, campaign budget, or regulated advice, it is the cost of using AI inside company work.

The six fields

Every AI action should carry six fields at the moment it happens.

Identity. A specific human, service, workflow, or agent. Not "the system."

Authority. The role or permission that allowed the action.

Policy. The rule that governed the decision, with a version.

Approval. The human or rule that approved it. If no human approval was needed, the system should say why.

Evidence. The ticket, document, customer record, prior message, metric, or policy section used to justify the action.

Audit event. A permanent event that ties the action to the other five fields.

Together, these fields turn "the AI did it" into a record the company can defend.

The difference between a tool call and a business action

Many AI demos stop at the tool call.

The agent calls a refund API. The agent updates a CRM field. The agent sends an email. The agent changes a budget. From a demo point of view, the action worked.

Inside a company, the tool call is only one part of the action. The business also needs to know whether the action was allowed, whether it was reviewed, whether it used the right facts, whether the customer record was correct, whether the policy had changed, and whether someone can inspect the record later.

That is the gap between automation and accountable automation. The first proves the system can do the thing. The second proves the company can stand behind the thing.

Why logs are not enough

Logs are useful for debugging. They are not the same as an action record.

A log may be incomplete. It may be written after the action. It may not include the policy version. It may not link to the evidence. It may be hard to query six months later. It may show text but not authority.

A business action should not depend on a forensic reconstruction. The proof should be written with the action.

The EU AI Act points in this direction. Article 12 requires high-risk AI systems to technically allow automatic event recording. NIST's AI Risk Management Framework also names traceability, explainability, and accountability as core requirements. The regulatory trend is not subtle: if AI takes action, the company needs records.

A simple example

An AI support agent issues a $150 refund.

A weak implementation stores: customer ID, amount, timestamp, and a log line.

A stronger implementation stores:

  • identity: support-agent-v3 acting in the customer support workspace
  • authority: refund role up to $200
  • policy: refund-policy version 2026-03-01
  • approval: auto-approved because the amount was below threshold
  • evidence: original ticket, order, policy section, and customer history
  • audit event: append-only event tied to the refund

The first version creates a support action. The second creates a defensible business action.

What Lyberty does

Lyberty treats AI work as company work. That means AI actions follow the same approval, evidence, policy, and audit flow as human work.

An agent cannot simply write a consequential action because a prompt said so. It resolves identity, checks authority, attaches evidence, records the policy, and either writes the audit event or refuses the action.

Where the evidence is too thin, the system can abstain. That matters. A system that refuses to act when it cannot prove the action is safer than a system that always returns a polished answer.

What to require before deploying AI agents

  1. Make identity and authority mandatory on every write.
  2. Attach policy and evidence references before the action is saved.
  3. Store approvals as records, not comments.
  4. Write audit events to append-only storage.
  5. Make "do not act" a valid output.

The model will keep changing. The proof around the action should not.

Sources

  1. Moffatt v. Air Canada, 2024 BCCRT 149. ABA Business Law Today, February 2024. https://www.americanbar.org/groups/business_law/resources/business-law-today/2024-february/bc-tribunal-confirms-companies-remain-liable-information-provided-ai-chatbot/
  2. Artificial Intelligence Risk Management Framework (AI RMF 1.0). NIST, January 2023. https://nvlpubs.nist.gov/nistpubs/ai/nist.ai.100-1.pdf
  3. Regulation (EU) 2024/1689 - Article 12: Record-Keeping. Official Journal of the European Union. https://artificialintelligenceact.eu/article/12/
  4. AI Act Implementation Timeline. European Commission. https://artificialintelligenceact.eu/implementation-timeline/
  5. SEC Charges Knight Capital With Violations of Market Access Rule. SEC, October 16, 2013. https://www.sec.gov/newsroom/press-releases/2013-222
  6. iTutorGroup to Pay $365,000 to Settle EEOC Discriminatory Hiring Suit. EEOC, August 9, 2023. https://www.eeoc.gov/newsroom/itutorgroup-pay-365000-settle-eeoc-discriminatory-hiring-suit
  7. Cost of a Data Breach Report 2024. IBM Security, July 2024. https://newsroom.ibm.com/2024-07-30-ibm-report-escalating-data-breach-disruption-pushes-costs-to-new-highs
  8. Gartner Predicts Over 40% of Agentic AI Projects Will Be Canceled by End of 2027. Gartner, June 25, 2025. https://www.gartner.com/en/newsroom/press-releases/2025-06-25-gartner-predicts-over-40-percent-of-agentic-ai-projects-will-be-canceled-by-end-of-2027
  9. Gartner Unveils Top Predictions for IT Organizations and Users in 2025 and Beyond. Gartner, October 22, 2024. https://www.gartner.com/en/newsroom/press-releases/2024-10-22-gartner-unveils-top-predictions-for-it-organizations-and-users-in-2025-and-beyond
  10. DPD AI chatbot goes off the rails at suggestion of customer. The Register, January 23, 2024. https://www.theregister.com/2024/01/23/dpd_chatbot_goes_rogue/