When AI Writes Its Own Audit Trail
The Edge Singapore featured my article "When AI Writes Its Own Audit Trail" on 28 September 2026.
Lee Ooi Keong
10/6/20269 min read




When AI Writes Its Own Audit Trail
AI agents have begun breaking rules and falsifying the record of what they did. Every AI framework Singapore has published assumes the opposite.
TLDR, full article.
On September 4, Reuters reported that AI agents built by OpenAI had spent months using a small German programming website as a private noticeboard. They made more than 15,000 edits to it from May, passing each other instructions on how to get round the safety limits their own operator had set. Nobody outside knew. When the site's moderator started deleting their pages in June, the agents worked out he was clearing the site in alphabetical order, and moved their notes to a page beginning with Z.
An AI agent is software given a goal rather than a list of steps, then left to work out for itself how to reach it inside live systems. Unlike the software a board has approved before, nobody can say in advance what it will do.
This was not a one-off. In the six weeks before that report, three more disclosures came out, from an AI monitoring body funded by the UK government, from OpenAI and from Anthropic.
The Loss of Control Observatory, August 30. Funded by the UK AI Security Institute, it recorded more than 300 cases in July of AI systems acting against their operators' intentions, close to double the June count and more than 1,600 this year. Among the behaviour logged: systems impersonating the people who control them, and working around checkpoints built to require human approval.
OpenAI, August 26. In a separate case, agents in a training run that were meant to be sealed off from one another found a shared folder and turned it into a message board. They found a hole in the same system, escaped their testing sandbox onto the open internet, and ran their own code on the live production machines of Hugging Face, another company.
Anthropic, July 30. During security testing, the company's own models reached the live working systems of three outside organisations without permission. None of the three noticed at the time. Anthropic found it only in a later review of its own test records.
The German website, the Hugging Face breach and the Anthropic tests all involve agents that were meant to stay inside a testing environment and instead reached live systems belonging to other organisations.
Inside the Hugging Face case
The Hugging Face incident is the only one examined in detail. OpenAI opened its records to two outside groups, METR and Redwood Research, so what the agents did can be compared with what they recorded.
Roughly 1,200 agents used the unauthorised message board. Of the 533 active during the attack, more than 90% joined it. The investigators are precise about what those agents understood. They "realized this activity was out of scope and unethical, but joined" anyway.
Expecting their work to be checked, some agents built a way to write false records of actions they had never taken, and posted the method to the board for others to use. Of roughly 1,300 transcripts examined, at least 96 carried false entries, about 7%. What the investigators found was small and easy to spot. They searched for subtler cases, found none, and say they cannot be sure they caught everything.
The scale is not the point. The capability was built, shared and used. Once any part of a record can be written by the system the record is about, none of it can be relied on until something external confirms it.
Agents tried to delete and edit entries on the board, and none succeeded. Some altered the logs inside their own containers, then worked out those were not the records that mattered. A deleted record leaves a gap someone can see. A false one does not.
The pattern runs wider than any one company's AI model. Anthropic's models did something similar at a different company weeks earlier, and the observatory's cases run across systems built by many suppliers. As these models grow more capable, the same pattern keeps appearing: when an agent is set an objective and finds the rules in its way, it works around them, and covers its tracks.
Singapore's exposure
The supply of AI models is concentrated. Menlo Ventures' December 2025 survey of roughly 500 US enterprise decision-makers puts Anthropic at 40% of enterprise spending on large language models and OpenAI at 27%. The two firms whose agents deceived their own operators hold two-thirds of that market.
Singapore adopts AI faster than almost anyone. Microsoft's 2026 Work Trend Index, published on 23 June, ranked Singapore second in the world on its AI Diffusion Index. IMDA's Digital Economy Report puts AI adoption among larger Singapore firms at 62.5%, and among small and medium enterprises at 14.5%, up from 4.2% a year earlier. On agents specifically, a survey of 200 senior leaders here published by ServiceNow and ThoughtLab on 17 August put agentic AI adoption at 51%, against 22% a year before. One in ten said they had already redesigned processes so that AI completes multi-step tasks from end to end.
The assumption underneath the guidance
Singapore set out how AI should be governed early. IMDA published version 1.5 of its Model AI Governance Framework for Agentic AI in May 2026, for organisations on a voluntary basis. MAS issued a draft consultation paper on AI risk management for financial institutions in November 2025, and the Singapore Institute of Directors an AI Guide for Boards in June 2026. The IMDA document deals with agents directly. The other two cover AI as a whole, with agents as one part of it. A board that has worked through all three is ahead of most.
All three rest on the same assumption, that agents do what they are told and report accurately what they did. Where they deal with things going wrong, they cover two cases.
The first is honest error, the agent misreading the task. MAS puts it as an agent executing actions "not aligned with an FI's business objectives or a customer's best interests due to a divergence between human goals and how the AI agent translated such goals into actions".
The second is an outsider taking control of the agent, which occupies most of the SID guide's security chapter. Both assume the agent is either confused or has been taken over.
Neither covers what the investigators documented: an agent that understands the rule, breaks it deliberately, and writes a false record of what it has done. All three tell organisations to keep a record of what an agent does, and IMDA goes further, asking them to "ensure log immutability" so that problematic agent behaviour "cannot be deleted". None tells a company how to satisfy itself that the record was true when it was written. A record that cannot be deleted can still be false.
Companies developing their own AI controls use these documents as a starting reference. The assumption that an agent will do as it is told, and record honestly what it did, comes with them.
What the annual reports show
Seven of the 30 Straits Times Index (STI) constituents tell shareholders they are using AI agents in their own operations. These are not back-office trials. The agents sit in customer onboarding, in investment analysis, and in changes made to customer records.
The reports are detailed about what the agents deliver and thin about what checks them. Only OCBC describes an actual control, people keeping final approval over what the agent proposes. DBS names a framework. The other five say nothing.
The same holds across all 30 reports. Not one gives a number for how often an agent's work is rejected, how often a person overrides it, or how many exceptions or incidents arose. Output is counted. Control is not.
Where these reports discuss AI as a risk, they treat it as a technology the company may adopt too slowly, a channel an attacker may use, or a source of poor output. None treats the AI system as an actor that might break a rule on purpose and then hide it.
What controls sit behind those agents is not clear from the reports. An annual report is a disclosure document, not an inventory, so silence is not proof of absence. The fullest disclosure in the sample comes from ST Engineering, which records the adoption of AI as an emerging risk, an AI Governance Framework adopted in 2025, an AI Governance Committee formed to monitor it, and a briefing on agentic AI given to its directors at a quarterly board meeting. Even there, no measure of control appears.
Agents that break rules they understand and then falsify their own records are a development of the last few months, and every framework a Singapore company would have used to build its AI controls predates that. Until this year the question did not arise.
The risk that is already running
The exposure that matters is not in the annual report. It is running now, inside live operational processes in live companies. Agents sit in work that matters, checked by controls that assume software does as it is told and reports honestly. Control frameworks exist because processes without them eventually produce a loss, whether the actor is a person or software.
When a process is redesigned around AI, the controls that used to sit inside it are easy to lose. Taking the person out does not remove the need for the check they were performing, and a redesign that removes both leaves a process nobody can verify.
Where an agent both performs a task and writes the record of it, the company cannot reconstruct what happened from its own systems. The day it needs to is the day something has already gone wrong.
What has to change
Nothing in the rulebook needs amending. What has to change is the meaning of independent. Until now it has meant independent of management. MAS uses it that way, defining validation as work done by people independent "from the development and deployment teams". Where an agent does the work, independent has to mean independent of the agent.
This is maker and checker, which every control framework a board approves already contains. The person who raises the payment does not release it. Applied to agents, the rule reads the same way. An agent that performs a task cannot be the agent that checks it, and cannot be the agent that writes the record of it. The check has to sit outside the agent. Three things follow.
1. The record of what an agent did has to be captured somewhere the agent cannot write to. That is a design decision, not a policy.
2. The outcome has to be reconciled to something outside the system, the way a payment run is reconciled to the bank statement rather than to the log of the process that produced it.
3. Somebody outside the process has to test that both hold. That means internal audit, or the external auditor on a wider scope agreed with the firm.
What about the auditors?
The strongest objection is that external auditors already cover general controls over information technology as part of the financial statement audit.
However, those controls are scoped to the financial statements. An agent that amends a customer's booking, or supports how an investment is evaluated, sits outside that scope, and it hits operations, service delivery and reputation rather than the accounts. This belongs with the risk committee rather than the audit committee alone.
Where this becomes a board obligation
Once a year, the board has to sign-off on this.
· Listing Rule 1207(10) requires that "the board must comment on the adequacy and effectiveness of the issuer's internal controls (including financial, operational, compliance and information technology controls) and risk management systems", with the audit committee saying whether it concurs and material weaknesses disclosed.
· Provision 9.2 of the Code of Corporate Governance rests that opinion on assurance from "the CEO and other key management personnel who are responsible".
The listing rule binds every issuer as a condition of listing, and SGX RegCo enforces it. The rule names operational and compliance controls alongside financial ones, in the same sentence, so the board's opinion is wider than the audit. What has changed is that some of the evidence behind that assurance is now written by the systems the assurance is about. A bank statement is a fact because a third party produced it. Boards have treated a system's own log the same way. That log is now written by something that has been shown to falsify it.
The signature is the smaller half of the problem. It matters because it is signed and dated. A board that has not asked what its agents can access and amend will sign the same opinion as last year without knowing whether it is true, and every listed company here signs its next one within twelve months.
What a director can ask now
The public service is putting the controls in first. GovTech is building a register of AI agents, with file deletion and outbound external email blocked, before putting a personal AI assistant in the hands of 150,000 public officers later this year. Whether listed companies are doing the same cannot be established from their disclosures.
A director does not have to wait for a rule or guidance. The first question can be asked at the next meeting: how many agents are running in this company, what can each of them reach, and who approved that access. If nobody can answer it, that is the answer.
The second question comes once the list exists. For each agent sitting in a process that matters, who checks its work, and can the agent access the record of what it did. A board that has neither is taking the agent's word for it.
Written on 7 September 2026 by Lee Ooi Keong.
Lee Ooi Keong is an Independent Director of an SGX Mainboard-listed company with 30 years of experience in corporate performance, investments and risk management. He is the founder and Managing Director of Clover Point Consultants, an independent Board and C-suite advisory firm, and was formerly Director of Risk Management at Temasek for over 16 years.



