What makes an AI log usable

When firms compare AI vendors, the demo looks the same everywhere. A clean screen, a task that finishes in seconds, a promise that the tool learns your files. The part that decides whether the thing survives a review almost never comes up: the log.
A log is the record of what the system did. Done well, it answers a question a partner may have to answer months later. Done badly, it is a screen of timestamps that proves nothing.
Logs get skipped for an understandable reason. They are dull to look at, and every vendor claims to have one. The difference is in the design, and it comes out only when you ask a specific question and listen to the answer.
Here is a vendor-neutral checklist for judging one, with the weak answer spelled out beside each question.
What is recorded for each action
The unit that matters is the action, not the session. For every action, the log should show what was asked, what was done, and when.
Weak answer: “We keep a full activity history.” Ask to see a single entry. If they cannot show one action with its input and its result, there is nothing to inspect.
Who can read it, and who can export it
A log helps only if the right people can reach it. Ask who can view it, whether viewing is itself recorded, and whether you can export the whole thing without filing a request.
Weak answer: “We will pull a report for you.” That means the log lives on someone else’s desk. When a client or a regulator asks, you want the file in your own hands.
How long it is kept
Retention should be a number, not a mood. Ask how long actions are stored, what gets deleted and when, and whether the deletion happens on its own or waits for someone to do it.
One concrete answer: recordings deleted after 90 days, transcripts after 365, automatically. Weak answer: “As long as you need it.” That is not a policy, and it will not survive contact with a records request.
Whether a named person approved the action
This is what separates a log from evidence. A record that a change happened is not the same as a record of who allowed it. For any write to a client system, the log should name the person who approved it.
Weak answer: “The system follows your rules.” Rules are not people. If no human is named on the write, you cannot show that anyone signed off on it.
Why the order matters
Most vendors lead with the model. The model is the easy part to swap and the hard part to judge. The log is the opposite: boring to demo and decisive later. Put the log questions before the model questions in your next evaluation, and the shortlist tends to sort itself.
Four questions for the next vendor
- Show me one log entry for one action, with its input and its result.
- Who can read and export this, and is reading recorded?
- How long is it retained, and who or what deletes it?
- Which named person approved the last write to a system of mine?
One more note. Log expectations are not only a vendor question. What your firm is required to keep, and for how long, depends on your own recordkeeping obligations and the rules you work under. Check your answers against those with your compliance advisor before you sign anything.
The vendor can tell you what their log does. Only your own advice can tell you whether it is enough.
