The risk is not that an agent is sometimes wrong. It is that when an agent acts, the record of what it did is editable, scattered, and silent on who allowed it. That is the exposure a receipt closes.
When the record is editable and incomplete, “trust us” is all that is left. “We have never had a wrongful action” is not a safety record. It is the absence of a place to look.
The pressure is a deadline, not a preference. EU AI Act transparency obligations came into application Aug 2, 2025, and DORA is already live for financial firms. Both ask, in different words: if a system acts, can you show what it did and why, to someone who does not have to take your word for it?