IT Governance — AI assurance and compliance

AI Log Analyzer

Runtime governance, drift detection, and compliance telemetry for AI and agentic systems

Executive summary

Deploying AI is easy. Proving that it stayed within policy — across thousands of prompts, tool calls, and multi-turn agent sessions — is hard.

The AI Log Analyzer is a production-ready governance telemetry sink and operational control plane for AI quality and governance programmes. It ingests structured events from LLM gateways, agent harnesses, and MCP tool servers; evaluates drift, policy violations, and agentic risk signals; routes high-severity cases to a human oversight queue; and feeds alerts, post-market monitoring events, and auditor evidence packs.

One service. One ingest contract. One dashboard. Full traceability back to your AI System Register.

Why organisations choose the AI Log Analyzer

Need How the analyzer delivers
Close the agent governance gap Pre-execution gates, shadow-agent detection, Lethal Trifecta assessment, MCP allowlist enforcement
Detect drift before harm Rule engine, content patterns, orchestration heuristics, and behavioural indicators of compromise (bIOCs)
Human oversight that counts Review queue with persisted decisions, justification, and automation-bias metrics
Regulatory evidence on demand Four-layer evidence packs, integrity metadata, and control-mapping export
Prompt-level visibility Full turn capture, content rules, norm divergence, append-only event store
Article 50 transparency checks Multi-modal watermark detection API that feeds watermark governance workflows
Loose coupling HTTP API and webhooks — integrate without hard dependencies on QMS internal models

Unlike a generic log aggregator, the analyzer understands AI-specific semantics: agent identity, trajectory, action ontology, MCP tools, runtime state snapshots, and linkage to your AI system register.

Runtime ingestion and governance actions

Every agent turn or LLM call can be recorded via a single ingest endpoint. The analyzer returns a governance action the harness must honour:

Optional webhooks notify external runtimes on drift, MCP violations, and reassessment triggers.

Agentic risks — pre-execution governance

Aligned with agentic AI governance practice: shift from policy documents alone to machine-enforceable boundaries.

Recommended flow: authorize → execute (if allowed) → ingest for audit.

Drift, anomaly, and content detection

Human oversight and automation-bias metrics

Prompt-level monitoring

QMS, post-market, and evidence integration

When ingest includes AI system identifiers:

Evidence packs return a structured four-layer bundle:

  1. Decision record — rules triggered, governance action, review status
  2. Input / context — prompt/response (with retention and redaction), ontology, trajectory, state snapshot
  3. Governance evidence — MCP policy, bIOCs, norm divergence, agentic governance detail
  4. Integrity links — hashes and cross-references to watermark and QMS records

Control-mapping export supports alignment with prEN 18286 / 18282 / 18229, the EU AI Act, OWASP Agentic categories, agentic-risk frameworks, and Article 50 watermark controls.

Watermark and transparency detection

Built-in multi-modal watermark detection (image, text, PDF with OCR) for diagnostic checks — the same class of capability that supports our Watermark (Art. 50) Management System. Generation-time watermark embedding remains an upstream producer responsibility.

How it fits in the architecture

LLM Gateway / Agent Harness / MCP Server
           │
           ▼  authorize (pre-execution)
           ▼  ingest (audit)
    ┌──────────────────┐
    │  AI Log Analyzer │◄── agent-registry sync (inventory)
    │  Rules + store   │
    └────────┬─────────┘
             │
   ┌─────────┼──────────────┐
   ▼         ▼              ▼
 QMS      Webhooks     Evidence packs
 alerts   (halt /      & control mapping
 + PMS     escalate)
 events

The analyzer is intentionally decoupled from application internals — integrate via HTTP, environment configuration, and shared AI system identifiers.

Standards and frameworks supported

Standard / framework Analyzer role
EU AI Act Arts. 12–15, 72–73 Logging, oversight signals, post-market event feed
prEN 18229 Trustworthiness logging, trajectory, immutable review records
prEN 18282 MCP / tool privilege, actor provenance
prEN 18286 §9.4.4(b) Continuous monitoring telemetry
Agentic AI governance practice Pre-execution boundaries, registry, Trifecta-style checks
OWASP Agentic themes Tool misuse, injection, excessive agency rule categories
Art. 50 / transparency CoP Watermark detect API and control-mapping section

Who it is for

Transparent limitations

The analyzer is a governance and diagnostic service, not a replacement for:

These boundaries keep procurement and audit conversations accurate.

Getting started

  1. Deploy the analyzer in your environment
  2. Connect QMS credentials and optional fail-closed governance
  3. Register agents in inventory; sync the registry
  4. Point gateway or harness at authorize, then ingest
  5. Open the oversight queue; tune rules to risk appetite
  6. Export an evidence pack from the first drift alert to validate the audit trail

Pair with watermark governance

Organisations pursuing full EU AI Act transparency coverage typically deploy:

Both share the AI System Inventory spine and integrity conventions — one QMS, one audit story.

Ready to operationalise runtime AI governance?

Contact us to discuss how the AI Log Analyzer can sit in front of your gateways and agent harnesses, and how it links to your existing risk, monitoring, and QMS stack.