AI Agent Investigations + Incident Forensics

An independent AI agent investigation establishes what an autonomous AI system did, why it did it, and whether the company’s records of that activity are complete. Guidepost reviews the code, architecture, environment, logs, and transcripts, and reports what we find in a form that can go to a regulator, a court, or a board.

Our Approach

AI agents can now write and run code, access data, and connect to outside systems without a person approving each step. When an agent does something it was not supposed to do, General Counsel, boards, and regulators ask the same questions: what happened, why, what did the company know and when, and can the records be trusted.

These questions are harder to answer than in a traditional technology review. Agent activity can span several systems, logs may be incomplete, and the agents’ own reasoning and messages become evidence. Independence matters as well, because a review run by the team that built or deployed the agent is difficult to defend to an outside party.

Request a Consultation

Guidepost investigates these incidents independently. Our team combines former federal prosecutors and senior law enforcement officials with forensic, cyber, and data specialists who build their own AI and automation tools. We work on site or inside the client’s environment, examine the underlying data ourselves, and deliver findings designed to withstand scrutiny.

When to Engage Guidepost

Guidepost supports organizations facing situations such as:

  • An agent accessed systems or data it was not authorized to access, including those of a third party
  • An agent bypassed a sandbox, guardrail, or monitoring control
  • Agents communicated with each other in ways no one set up or approved
  • Logs or transcripts appear incomplete or altered
  • A regulator, board, customer, or other outside party is asking what happened

Who We Serve

  • Outside counsel, General Counsel, boards, and audit committees
  • Companies that use AI in their business or products
  • Companies harmed by another organization’s agent
  • AI developers reviewing incidents involving their own models

Our Investigation Process

Each engagement follows seven stages, scoped with the client at the outset.

  • Evidence Preservation. We agree on scope, then collect logs, transcripts, model versions, configurations, and access records before anything is overwritten.
  • Code + Environment Review. We examine how the agents were built and deployed, including tools and permissions, network and sandbox settings, credentials, and any scoring or reward logic that influenced behavior.
  • Timeline Reconstruction. We lay out what each agent did and when, where controls failed, and whether there were earlier signs of a problem.
  • Agent Reasoning + Message Review. We analyze transcripts and messages between agents to understand what they were trying to do and whether they acted together. For large volumes of records, we use our own AI tools to sort and search them.
  • Records Integrity Testing. We test whether activity was hidden, changed, or deleted, and whether the logs match what actually ran.
  • Dynamic Root Cause Analysis. Where appropriate, we conduct controlled prompt testing and red teaming to confirm what caused the behavior.
  • Independent Report. Our report covers what happened, why, what the company knew and when, and what needs to be fixed. We write it so it can go to a regulator, a court, or a board.

Independence

Independence is the point of the engagement. We review the underlying data ourselves, on site or inside the client’s environment. Our report states what we reviewed, what we were not given, and whether that affected our conclusions. The conclusions are ours.

Why Guidepost

  • Guidepost serves as a court and agency appointed monitor in major regulatory matters, a role that demands independent judgment reported into a regulatory framework.
  • Our team includes former federal prosecutors and senior law enforcement officials who work alongside forensic, cyber, and data specialists.
  • Regulators, prosecutors, and courts regularly review our findings, and we conduct every investigation with that in mind.
  • Guidepost is a member of the U.S. AI Safety Institute Consortium, established under the Department of Commerce’s National Institute of Standards and Technology

Facing an AI agent incident? Guidepost can help you preserve the evidence and establish the facts.

Frequently Asked Questions

(FAQs)

An independent review of an incident involving an autonomous AI system. It examines the code, configuration, logs, and transcripts to determine what the agent did, why, and whether the records of its activity are complete.

When an agent accessed unauthorized systems or data, got around a control, or acted in ways no one approved. Also when logs look incomplete or altered, or when a regulator, board, customer, or other outside party asks what happened.

Logs, transcripts, model versions, configurations, and access records. Suspend automatic deletion and overwriting, and avoid changing the environment until the evidence has been collected.

Internal teams should begin preserving evidence and containing the issue. An independent review carries more weight with regulators, courts, and boards, particularly when the company or its vendor built or operated the agent.

What happened, why, what the company knew and when, what we reviewed and what we were not given, and what needs to be fixed.

The forensic investigation of AI systems themselves: collecting and analyzing evidence of what a system did and why. It differs from using AI to assist forensic work, which we also do at scale when reviewing large record sets.

Yes. We work with companies harmed by an agent they did not build or deploy, including where the agent accessed their systems or data.

MSU Institutional Assessment + RA
MAGELLAN Monitorship
Empire/Liberty Review