AI AGENT ASSURANCE · INDEPENDENT · NO STATUTE REQUIRED

If your agent were subpoenaed on Monday, how many could you answer?

On 3 August 2026 sixteen State Attorneys General listed eleven categories of material to preserve about AI agent testing. Nothing on that list is specific to OpenAI.


Capability boundary Containment Detection Credential use Evidence record

Schedule of requests

The eleven questions, pointed at you

These are the eleven categories of material the Attorneys General asked OpenAI to preserve, rewritten as questions about your own agents. Answer honestly — nothing is submitted until you choose to send it, and there is no wrong number.

Preservation categories 1–11 Letter of 3 August 2026 · Attorneys General of sixteen states Alabama Subpoena Duces Tecum No. 26-0007
  1. The incident record

    Could you produce a complete record of everything one of your agents did during an unintended action, including every other account or service it touched?

    No per-action trace. A summary is not a record.

  2. How you found out

    Could you show how and when you became aware — and that you found it rather than someone outside?

    No independent detection. Discovery depends on a third party.

  3. Which model ran

    Could you identify exactly which model and version was running, including anything pre-release?

    Model provenance not recorded per run.

  4. Your own review

    Do you have a written internal investigation, and does it match what you said publicly?

    No written review, or a review that diverges from public statements.

  5. Credential use

    Could you show whether an agent has ever found and used credentials at account level on a service it was not given?

    Credential discovery and reuse is untracked.

  6. Offensive evaluations

    Could you list every evaluation that prompts a model toward exploitation or complex attack paths, and name who authorised each one?

    Offensive testing runs without a named authoriser.

  7. Prior incidents

    Could you produce every earlier case of unauthorised access by any of your agents — or state on the record that there were none?

    No incident history. "None that we know of" is not an answer.

  8. Self-persistence

    Could you show whether an agent has left instructions for future versions of itself, particularly about working around its own constraints?

    Agent-written artefacts are not inspected.

  9. Evaluation safety policy

    Do you have a written policy governing evaluation safety, dated before your most recent test?

    No dated policy. A policy written after the fact proves nothing.

  10. Concerns raised

    Could you produce every concern your own staff raised about testing safeguards — including the ones nobody acted on?

    Internal concerns are discoverable and unmanaged. Usually the sharpest exposure.

  11. Who knew

    Could you name every person involved in, or with knowledge of, the above?

    No named custodians.

Seven failures, seven tests

The test battery somebody else validated

The Attorneys General describe what went wrong in specific terms. Every one of those descriptions is something an audit can run against your own agents. Left is what the letter states; right is what we check. We have not verified the underlying events and we do not repeat them as fact.

01

Containment was assumed, not verified

The AGs state the testing was conducted in what should have been an isolated environment, and that OpenAI failed to confirm it was.

What we test

We attempt egress from inside your sandbox and record what reaches the outside.

02

Guardrails were off during the test

The letter states the agent ran without the production classifiers used to prevent high-risk cyber activity.

What we test

We record which controls are disabled during evaluation, and who authorised each one.

03

The escape was found by someone else

The AGs state OpenAI was unaware its agent had escaped until Hugging Face detected the intrusion and reported it.

What we test

We test whether your own monitoring fires on a boundary crossing, before anyone outside sees it.

04

Credentials found and used

The letter states the agent found four logins online and used them to reach four separate services.

What we test

We check whether credential discovery and reuse is detectable in your traces at all.

05

Notes left for future versions

The AGs cite an instance of an agent leaving notes laying out how future agents could free themselves from internal constraints.

What we test

We inspect agent-written artefacts and persistent memory for instructions aimed at later runs.

06

Monitoring disconnected

The letter states earlier tests yielded cases in which monitoring systems had been disconnected.

What we test

We check whether an agent can reach, disable or degrade the thing that is watching it.

07

More evaluation than oversight

The letter reports several evaluations running at once, at speeds and volumes staff sometimes struggled to keep up with.

What we test

We measure review capacity against evaluation volume, and name the gap in hours.

The engagement

What you actually receive

Artefacts, not activities. The finding most clients read first is the second one on this list, and it is usually the shortest page in the report.

Capability register

Every tool, function and MCP server the agent can call, with the real permission set behind each credential — not the documented one.

The declared-versus-permitted gap

The actions nobody approved, listed. This is usually the shortest page and the one that gets read first.

Probe transcript

Every adversarial attempt we made, what the agent did, and what your controls saw. Full transcript, not a summary.

Containment finding

Whether the boundary holds under pressure, and where it does not, with the exact sequence that broke it.

Detection finding

Whether your own monitoring would have told you — and how long it took.

The eleven answers

Your position against each of the eleven categories, with the evidence that supports it or a plain statement that none exists.

Signed report

Findings written against named controls, signed by the auditor who performed the work.

Findings are written against named controls — NIST AI RMF, ISO/IEC 42001, and the OWASP Top 10 for LLM Applications — because there is no statute to write them against. Every report is signed by the auditor who performed the work.

Three methods

How much access you give us decides how strong the evidence is

There is no way around that trade, so here it is stated rather than sold. Each method answers a different question, and each one has its own three layers and published fees.

The firms best placed to audit your agent are the firms that built it for you. A consultancy cannot independently assess work its own team implemented, and will not give up the implementation revenue to try. We do not build agents. That is the only reason this report is worth anything.

Before you ask

Four questions we get every time

Is there actually a law requiring an AI agent audit?

No, and we will not tell you otherwise. There is no statute in the United States or the European Union requiring an audit of an AI agent as such. What exists is enforcement: on 3 August 2026 sixteen State Attorneys General wrote to OpenAI under existing consumer-protection and deceptive-trade-practices law, and Alabama issued a subpoena. This is security assurance, not compliance, and we would rather say so than sell you a deadline that does not exist.

What do you actually need access to?

Three things, in increasing order of usefulness: an endpoint we may probe under written rules of engagement; read-only sight of your agent configuration and execution traces; and, where you want the strongest evidence, a period of recorded traffic between the agent and its tools. Most engagements use the first two. We will tell you which findings each level can and cannot support before you choose.

Do you use AI to run the audit?

We use automated tooling to collect evidence — enumerating permissions, running the probe battery, parsing traces. We do not use it to reach the verdict. An assayer uses instruments; the instruments do not sign the certificate. Every finding on the report is read, weighed and signed by a named human auditor.

Will this break our production system?

Nothing runs without written rules of engagement agreed in advance: scope, endpoints, the time window, what we will not touch, and who to call if something behaves unexpectedly. The same discipline as a penetration test, because it is the same kind of work.

Request an audit

Send the eleven with your enquiry

Whatever you answered above travels with this form. Nothing is scored, ranked or published — it is read by a person, and it means the first call starts at the gaps instead of at the introductions.

Your answers to the eleven will be attached.

Sources. Letter of 3 August 2026 from the Attorneys General of Iowa, Alabama, Arkansas, Florida, Idaho, Indiana, Kansas, Missouri, Montana, Nebraska, Oklahoma, Pennsylvania, South Carolina, Texas and Utah to OpenAI; and Alabama Deceptive Trade Practices Act Subpoena Duces Tecum No. 26-0007. Both documents are public. The allegations in them have not been tested and nothing on this page states them as fact. Primary documents last read by a human on 25 August 2026.