Evidence note · Agentic AI evidence

Provenance Overreach: When an Artifact Proves Less Than It Appears To

A forensic examination of why agent, account, and token records do not automatically establish human authorship, intent, authorization, or control.

Published
August 14, 2026
Author
Kevin V. Watson
Reading time
6 min
Format
Evidence note

Share this analysis

No social platform widgets are loaded.
LinkedInEmail

Every investigation begins with artifacts. A log entry. An IP address. A set of credentials. A file on a device. Each one may record that something happened. None of them, on its own, establishes who performed, directed, or authorized the action.

That is a longstanding problem in digital forensics. A login establishes that an account was used. It does not establish who was sitting behind the keyboard. An IP address associates an action with a connection. It does not identify the person who took it. Possession of credentials indicates access. It does not establish legitimate control.

Investigators are trained to hold that line. The artifact tells you what the system recorded. Attribution to a person is a separate question, and it requires separate evidence.

The failure mode has a name. I call it provenance overreach: an attribution conclusion that exceeds what the provenance evidence can establish.

Provenance overreach is not new. Agent systems increase both the distance between artifact and actor and the consequence of reasoning across that distance too quickly.

The artifact trail and the attribution trail are separating

In many conventional investigations, fewer intermediary systems separated human input from system action. Attribution still required corroboration. Shared accounts, compromised credentials, remote access, scheduled tasks, and automated processes have always limited what a log can prove. But the execution chain was often shorter.

AI agents change that distance.

When a person delegates a task to an agent, the agent acts. It queries systems, calls services, and produces output. When that agent calls another agent, the chain of action extends again. Each step may generate artifacts identifying an agent, service account, token, or process. Those records do not necessarily capture human intent. They may not establish whether a person foresaw the specific action, authorized it, or would have permitted it had they seen it in advance.

The artifact trail documents what executed. The attribution trail runs back toward the decisions, authority, and control that placed the system in a position to act. The relevant artifacts may never have captured all of those elements.

In agent systems, those two trails can diverge sharply. The point where they diverge is where attribution can fail.

Naming the boundary

At Zemi North, we treat that point as a discontinuity, not a gap to be reasoned across casually. We developed the Human–Agent Attribution Discontinuity (HAAD), Version 0.4, as a forensic and assurance methodology for locating that boundary and examining what the available evidence can carry across it. The current release is a public-review and structured-testing draft.

The core idea is direct. Between a human and the actions taken by an agent on that human's behalf, there is a boundary. Attribution does not automatically carry across it. Evidence of delegation may establish that a person set something in motion. It does not, by itself, establish that the person authored, intended, or authorized each downstream act.

HAAD exists to make that boundary visible and to require the analyst to establish, rather than assume, what carries across it.

HAAD does not determine legal liability or organizational accountability. It identifies where the evidence no longer supports carrying attribution from an agent's action to human authorship, intent, authorization, or control. Those are distinct findings. They may depend on different evidence and may not point to the same person.

Attribution is not a single finding

An agent action can raise several attribution questions at once. Who initiated the task? Who defined its objective? Who authorized the capabilities it used? Who controlled the infrastructure and credentials? Who intervened, or had the ability to intervene? Who remains accountable under law, policy, contract, or organizational role?

These questions are related, but they are not interchangeable. A person may have deployed a system without authoring a particular action. Another person may control the credentials without defining the objective. An organization may remain accountable for an outcome even when the evidence does not establish that a particular employee intended it.

The forensic task is to state which relationship the evidence supports. It is not enough to identify the nearest human and treat proximity as proof.

The standards community is beginning to frame the same operational problem. In February 2026, NIST's National Cybersecurity Center of Excellence published a draft concept paper asking how delegation should be handled in "on behalf of" scenarios, how agent identity should be bound to human identity for authorization, and how agent actions can support auditing and non-repudiation. The paper was open for public comment through April 2, 2026. These remain active identity, control, preservation, and attribution questions.

The discipline the boundary demands

Sound attribution in agent systems requires the same discipline as any other forensic conclusion, applied to a harder problem.

First, separate what is known from what is assumed and what is undetermined. A validated record may establish that an identified agent or process executed an action. That a particular human intended the action remains an assumption until separate evidence establishes the connection.

Second, treat the absence of an artifact carefully. Evidence can be absent because it was never created, because it exists but cannot be accessed, or because its existence cannot be determined. These are different states with different weight. Collapsing them into a single "no evidence" produces false confidence in both directions.

Third, keep delegation and authorship distinct. Granting an agent broad latitude may indicate acceptance of certain operational risks, depending on the terms and context of the delegation. That evidence must be examined. It is not an admission that the person authored or intended every act the agent later takes. Voluntariness, scope, foreseeability, and retained control are questions to be established, not defaults to be assumed.

None of this is exotic. It is the standard forensic requirement that a finding must be bounded to what the evidence supports. Agent systems raise the stakes because the artifacts can look complete. A log that names an agent and a timestamp may appear to settle the question. If the record is reliable, it may establish what the agent executed. It does not, without more, establish the human relationship to that action.

Why this matters now

These artifacts will appear in matters where the conclusion carries weight. Employment decisions. Regulatory findings. Litigation. Internal investigations. In each setting, a clean-looking artifact that names an agent, account, or token invites a fast attribution to the person most visibly associated with the system.

That is provenance overreach at scale. The artifact is real. The processing is real. The error enters when technical association is treated as proof of human authorship, intent, authority, or control. It is easy to miss because the evidence looks complete.

The remedy is not to distrust artifacts. Artifacts are the foundation of the work. The remedy is method. State what the artifact establishes. State what it does not. Mark the boundary where human attribution stops being carried by the evidence and starts being carried by assumption. Then examine whether identity, authorization, configuration, session, communication, and control records close that distance or leave it open.

An artifact may establish what happened inside a system. Connecting that action to human authorship, intent, authorization, or control requires additional evidence. The discontinuity cannot be crossed by assumption.

The question is never only what the system recorded. It is what that record actually proves.

Reference

National Cybersecurity Center of Excellence. Accelerating the Adoption of Software and AI Agent Identity and Authorization. Draft concept paper. National Institute of Standards and Technology, February 2026.

Watson, K. V. (2026). Human–Agent Attribution Discontinuity: A Forensic and Assurance Methodology, Version 0.4 [Public-review and structured-testing draft]. Zenodo.

Related Zemi North practice: AI assurance.