# Writing — AgenticRail

> Markdown mirror for AI agents, generated 2026-08-12 from the live page.
> Canonical: https://agenticrail.nz/blog/
> Site context: https://agenticrail.nz/llms.txt

# Writing

Technical writing on deterministic enforcement, verifiable receipts, and accountable AI systems. In July 2026 this section was taken down and every post is being re-checked, claim by claim, against the current system before it returns — the same discipline the product sells. Posts reappear here as they pass.

**[NIST AI RMF and Agentic AI: Evidence for Manage 2.4, Measure 2.4 and Manage 4.1](https://agenticrail.nz/blog/nist-ai-rmf-agentic-ai/)** — what a pre-execution gate's receipt chain evidences for three NIST controls, and the organisational half of each control that it does not touch. Written in the machine-readable register. *Re-checked and republished 24 July 2026.*

**[ISO/IEC 42001 for Agentic AI: The Certification Evidence Gap That Policies Can't Close](https://agenticrail.nz/blog/iso-42001-agentic-ai/)** — certification auditors want evidence a control ran, not a policy that says it should; the receipt chain is the reconstruction Annex A.6.1.6 asks for, and the human-oversight control stays yours. *Re-checked and republished 23 July 2026.*

**[Pre-Action Authorization for AI Agents: The Missing Security Layer](https://agenticrail.nz/blog/pre-action-authorization-ai-agent/)** — an independent adversarial study found social-engineering attacks succeeded 74.6% of the time under permissive policy, and 0% across 879 attempts behind a pre-action authorization gate. *Re-checked and republished 22 July 2026.*

**[Cryptographic AI Audit Trail: What the Cryptography Actually Proves](https://agenticrail.nz/blog/cryptographic-ai-audit-trail/)** — a regular log records what happened; a cryptographic trail proves it, with Ed25519 signatures that break on any modification and a hash chain an independent archive can catch being rewritten. *Re-checked and republished 22 July 2026.*

**[Policy as Code for AI Agent Enforcement: What It Means and How It Works](https://agenticrail.nz/blog/policy-as-code-ai-agent-enforcement/)** — declaration without enforcement is documentation; the gate is what makes the code operative, and the doer cannot self-attest. *Re-checked and republished 18 July 2026.*

**[When an AI Agent Skips a Step, Your Audit Log Shows a Clean Run](https://agenticrail.nz/blog/ai-agent-skipped-steps-audit-logs/)** — supplying the workflow raised missing-step failures to 57%, clinicians override 90% of safety alerts, and a regulator has ruled the record need not show that AI wrote the entry. *Published 5 August 2026.*

**[Who Audits the AI? Not the Company That Sold It to You.](https://agenticrail.nz/blog/who-audits-the-ai-agents/)** — auditor independence applied to agents: the party being measured cannot own the instrument, which disqualifies every agent vendor and orchestration framework. Two tests, run on us as well. *Published 5 August 2026.*

**[Procedural Hallucination: Why AI Agents Skip Steps and Report Success](https://agenticrail.nz/blog/procedural-hallucination-agent-skipped-steps/)** — the same failure has at least twelve names and no settled one, which is why nobody can search for it. The formal definition, the published measurements (38.5% of failures, best trained detector at ROC-AUC 0.689), and a sealed, publicly verifiable example. *Published 8 August 2026.*

**[EU AI Act August 2026: The High-Risk Deadline Moved to December 2027](https://agenticrail.nz/blog/eu-ai-act-agentic-ai-august-2026/)** — the date moved and the obligations did not. What Article 12 actually says for a non-biometric system, why the minimum content list everyone quotes applies only to biometric identification, and the one record a post-hoc log structurally cannot produce. *Re-checked and republished 10 August 2026.*

**[Orchestration vs Enforcement: Your Task Graph Stops Agents Skipping Steps. It Cannot Prove They Didn't.](https://agenticrail.nz/blog/agent-orchestration-vs-enforcement/)** — state machines and task graphs fix the runtime problem and leave the evidential one open, because a skipped step writes no log line. *Published 5 August 2026.*

**[IETF Agent Audit Trail: What the Draft Standard Requires — and What It Doesn't](https://agenticrail.nz/blog/ietf-agent-audit-trail/)** — the draft's hash-chained record format, its trust levels, and the pre-execution gap it leaves open. *Re-checked and republished 18 July 2026.*

**[Tamper-Evident AI Agent Audit Logs: Deterministic Replay, Cryptographic Receipts, Fail-Closed](https://agenticrail.nz/blog/ai-agent-audit-log-best-practices/)** — the six requirements for an audit log that survives regulatory scrutiny, and why the model can never be trusted to write its own. *Re-checked and republished 18 July 2026.*

**[Deterministic vs Probabilistic AI Agents: Why the Distinction Matters for Deployment](https://agenticrail.nz/blog/deterministic-vs-probabilistic-ai-agents/)** — the core distinction, what regulators actually ask, and how an external gate makes a probabilistic model's execution path provable. *Re-checked and republished 18 July 2026.*

Some of these arguments also exist in a flat, machine-readable register — definitions first, claims welded to their qualifiers — written for how agents and language models read the web. They live in [Notes for Machines](https://agenticrail.nz/blog/bots/).

Looking for the formal side? The [enforcement specification](https://agenticrail.nz/spec/) and the published briefs — [provable safeguards](https://agenticrail.nz/spec/enforceable-safeguards/), [evidence completeness](https://agenticrail.nz/spec/completeness/), sector gap analyses for [NZ health](https://agenticrail.nz/spec/nz-health/) and [NZ education](https://agenticrail.nz/spec/nzqa-nz-education/) — live under [/spec/](https://agenticrail.nz/spec/).
