bickford

How to verify an AI decision log, and prove nobody edited it

The question behind every AI records request is "show me the decisions, and prove nobody edited them." A hash chain answers the second half with a plain file and a script anyone can read.

The problem with ordinary audit logs

A database audit log is kept by the same people who run the model. When an examiner asks whether the decision records are complete and unaltered, "we have an audit table" asks them to trust the system under review. The NAIC's 2026 examiner draft asks for a model's "last date of model testing" and whether "there is a human in the loop"; both are claims about records, and records are only evidence if a third party can check them.

How a hash chain works

Each decision is written as one line of JSON with four parts: the hash of the previous line, the timestamp, the decision itself, and a SHA-256 hash of those three. Because every hash covers the previous hash, changing, deleting or reordering any record changes every hash after it. The first record points at sixty-four zeros.

{"prev_hash":"000…000","timestamp":"2026-01-01T09:00:00Z","entry":{"decision_id":"D-0001","model_version":"2.3.0","output":"approve","score":0.37},"hash":"652014cf…"}
{"prev_hash":"652014cf…","timestamp":"2026-01-02T09:01:00Z","entry":{"decision_id":"D-0002",…},"hash":"9b24eccd…"}

The export is a text file. Anyone holding a copy, an examiner, an auditor, a reinsurer, can recompute the chain and compare the final hash ("the head") with the one they were given. If the two match, the file is the file. No access to the insurer's systems is needed.

Verifying one yourself

Two verifiers, about forty lines each, with no dependencies, are published at github.com/bickfordd-bit/decision-ledger under the MIT license:

node verify.mjs ledger.jsonl      # OK: 1231 records, head 04441e32…
python verify.py ledger.jsonl     # same answer, standard library only

Both report the first record that fails and why: prev_hash does not match the previous record (a record was removed, inserted or reordered) or hash does not match the record content (a record was edited). The repository includes a 50-record sample ledger and the tests that show both verifiers agree byte for byte.

What it proves, and what it does not

Which framework controls a verified log evidences

The same repository maps a decision log's fields to the controls they can evidence: ISO/IEC 42001 A.6.2.8 (event logging) and 7.5 (documented information), NIST AI RMF MEASURE 2.8 and MAP 3.5, and EU AI Act Articles 12 (record-keeping), 14 (human oversight) and 26 (deployer obligations). Only control IDs and one-line paraphrases are given; standard text is licensed.

The Evidence Pack replays your exported log into exactly this kind of chain and returns it to you, with the head hash printed in the report, so the report and the records can be checked by someone who did not buy it.

Related