“Monitor the AI” sounds straightforward.
Observability is not the same as assurance
This analysis forms part of the same operational picture as Why Healthcare AI Cannot Be “Approved Once and Trusted Forever” and AI Agents Need Identity, Authority, Boundaries and a Kill Switch.
In practice, it raises a series of questions.
What exactly should be monitored?
For traditional software, organisations frequently monitor uptime, errors, access and security events.
Autonomous AI introduces another layer: behaviour.
An effective assurance environment may need to capture the identity of an AI system or agent, its permissions, the resources it accessed, significant actions attempted, controls triggered, human interventions and changes in risk status.
The evidence chain organisations need
The important distinction is between observability and assurance.
Observability tells an organisation what happened.
Assurance asks whether what happened was permitted, expected and adequately controlled.
For agentic systems, that can require an evidence chain such as:
agent identity → authority → proposed action → policy check → execution → result → evidence → escalation where required.
This also enables a more meaningful audit trail.
Making controls proportionate to AI risk
Instead of asking whether an organisation has an AI policy, an auditor or buyer can ask whether a specific high-risk action was authorised and what evidence proves it.
As AI systems become increasingly embedded in operational workflows, this capability may become fundamental to enterprise trust.
The objective is not to create bureaucracy around every automated action.
It is to make assurance proportionate to risk.
Low-risk actions can proceed with lightweight controls. Higher-risk actions may require stronger validation, human authority or escalation.
That is what operational AI governance increasingly looks like.
SOS perspective
This issue sits within our work on AI governance and assurance: practical systems should preserve evidence, human accountability and proportionate control while delivering useful automation.
Apply this analysis to a practical, accountable AI decision.
Discuss AI monitoring with SOS