Evidence checklist // what to capture and preserve
Three proposed categories, adapted from Ezell et al. (2025) and the EC's Article 73 guidance. This is a first proposal, and it will be revised as investigative practice develops. Working checklist with investigative cautions in the repository.
1. Activity logs: prompts (user + system), reasoning traces / chain-of-thought, retrieved external content, per-step outputs, executed tool calls, guardrail outputs, timestamps and version identifiers.
2. System documentation: model/system cards, the exact version at incident time, runtime settings enabling reconstruction, change logs, persona/configuration files.
3. Tool records: every tool the agent used or attempted: what it grants access to, what the agent did with it, errors encountered.
Three cautions that recur in the case files: the agent's statements about itself are artifacts, not testimony; establish whether the agent could write to its own record (CF-2025-001); and ask what context compaction silently destroyed (CF-2026-002).
At present, open incident databases contain little of this evidence. In most cases it was never captured in the first place, remains internal to the provider, or is limited to what the operator retained. Investigations should plan around this constraint, and its occurrence should itself be recorded as a finding.