The Memory of Record
For Artificial Intelligence

They were not fined for what they did. They were fined for what they could not produce.

More than two billion dollars in penalties. More than a hundred firms. Not for misconduct — for gaps in the records they were required to keep. Every one of those was a record of what a person did.

The work is now being handed to AI agents. The record is still being asked for, but with greater oversight and increased fines.

$2B+
in recordkeeping penalties, SEC tally
100+
firms, since December 2021
2026
and firms are still being fined for it
See the three clocks →
01The precedent

What a missing record costs

The firms in that number were not accused of lying to customers. They were penalized because, when regulators asked, the record was incomplete — conversations held where nobody was keeping the book.

The sweep that produced those penalties has wound down. The enforcement has not: examinations continue, and firms were still being fined for the same failure in 2026.

A record you cannot produce is treated as a record that is against you.
02What changed

That was people, using the wrong app.

Companies are now handing real work to AI agents — service, sales, claims, underwriting, operations — and the machines that follow will act in the physical world.

When one of them is challenged, the question is the same question it has always been, and it is historical:

What did the system know then?
What did it do?
And what can you prove now?
03Three clocks

Three clocks are running, and their dates are fixed.

Today
16 Sep 2026
14 JAN 2027
EU Machinery Regulation — AI-driven machine behaviour explicitly in scope
2 DEC 2027
EU AI Act — record-keeping binds high-risk systems
ALREADY RUNNING
Six US state chatbot-disclosure laws, Nov 2025 through Jul 2027. Two of them let the customer sue.
The dates, the texts, and what each one requires →
04The void

Read what the law asks for. Then read what it does not say.

“the automatic recording of events (logs) over the lifetime of the system”
EU AI ACT, ARTICLE 12
It does not say
tamper-evident
It does not say
complete
It does not say
verifiable
It does not say
scoped

Every one of these rules creates a duty to hold a record. None of them defines what makes a record believable.

On a date that is already set, someone — a regulator, an auditor, an insurer, a customer’s lawyer — will ask your company what your AI knew and what it did.

You will answer with something.

The question is whether they have to take your word for it.

05The test

Logging is not proof.

A log says what it contains. A provable record can show what happened to it. Most systems can claim the first. Almost none can demonstrate the other three.

01
Recorded
02
Complete
03
Unchanged
04
Independently verifiable
06The answers

Each one, demonstrated.

Not asserted. Measured on the engine, and enforced by the test suite on every build — so a claim that stopped being true would fail the build before it reached a customer.

01
Recorded
Ten million events a day holds as under two terabytes a year. When a page fills, nothing is dropped silently — the system says so, seals the page, and continues on the next.
02
Complete
What is in scope is declared in advance and sealed. A declared channel that goes quiet has produced a recorded fact, with a timestamp and an owner.
03
Unchanged
The record restores byte-identical and every seal still verifies. Changing history is not against policy — it is arithmetic, and anyone holding the record can detect it.
04
Independently verifiable
Two files a stranger can run, importing nothing of ours. Four independently written implementations, sharing no code, agree on every value.
07What TIE is

TIE is the memory of record for artificial intelligence.

A permanent, tamper-evident record of what AI systems knew and what they did — built to answer two questions that regulated industries already ask about people, and nobody can yet answer about machines.

Did it know?
Did it comply?
Who it is for
Software agents

The first market. Financial-services agent channels, customer-facing AI that makes binding representations, healthcare administration, insurance claims — any enterprise that must answer a regulator about what its AI did.

Robotics

The physical wave. A robot is an agent whose acts are physical, and TIE needs no new machinery to serve one — manufacturing, surgery, security, wherever a machine’s act applies knowledge an expert or regulator would examine afterward.

Knowledge owners

Standards bodies, equipment makers and expert firms licensing their knowledge to fleets as sealed artifacts, with use accounting that doubles as the royalty basis.

08One technology, three engines
KnowledgeConductProof
TIE 3
Wellspring

The knowledge a machine consults before it acts — a profession’s rules and standards, versioned and citable, so what the system held on any past date stays answerable.

TIE 1
Fortress

The record of what the machine declared it did — sealed page by page, added to but never rewritten, holding what it was told, what it did, and what it left out.

TIE 2
Attest

Proof that works on strangers. A customer, an insurer or a court can verify the record against the interest of whoever handed it over.

09What it costs to keep

A record that never deletes has an obvious question waiting for it.

If nothing is ever thrown away, does the bill grow forever? It is the right question, and the answer is measured rather than promised.

~60%
all-in reduction on the structured record, measured on the engine
~1.8 TB
one year at ten million events a day, held compressed
1,000
entries — the only hard limit in the system, and a deliberate one

The compression is lossless and deterministic: nothing is summarised, sampled or thinned with age, the record restores byte-identical, and every seal still verifies afterward — proven on every build, over every record.

The single limit is at the working edge, on the page still being written, so that nothing accumulates where the record is still forming. Everything sealed leaves for the permanent store, and the permanent store has no practical ceiling. How much one customer’s memory can hold is a storage bill, never a system limit.

What does not compress is the proof itself. A record whose audit material squeezed down nicely would be a record carrying less proof.

Scope: the figures describe the structured record. Prose-heavy records land at the low end. Attachments — images, PDFs, audio — are already compressed and do not shrink further, so a media-heavy deployment is quoted a blended figure. Measured on the real engine, September 2026; re-measured on real records as deployments begin.

10Design law

TIE never judges, ranks, recommends, gates or prevents.

It cannot block what an AI does and never sits in its control loop. TIE witnesses; it never gates. We do not judge the conduct — we make it examinable, by a regulator, an auditor, an insurer or a court. That refusal is exactly why the record can be believed.

It contains no AI. No model, nothing to hallucinate, drift or go down. It does not retell the record — it returns it, so the same question produces the identical answer today, next year, and in front of a tribunal. AI systems are its customers, never its components.

11Proof

You do not have to take our word for it. That is the whole design.

A record you have to trust the vendor about is the failure this exists to end. So the proof is built to work on a stranger — and against us.

Custody
You hold the key

TIE holds none. The root of the record’s signatures lives inside your own cloud’s hardware boundary — the key service your security team already audits. It can sign. It can never be exported. And every signature it makes lands on your audit trail, not ours.

Threat model
We are inside it

Every touch of your record is itself a sealed record, and you hold its chain. An operator who alters or deletes an access entry is caught by your own verification tooling — with nothing in the detection path that the operator controls. That operator includes us.

Verification
It leaves our hands

Two single files — one in Node, one in Python — importing nothing of ours, run on your machine, offline. Four independently written implementations, sharing no code, agree on every value. The chain closes to its root by the root’s signature, not by its name.

What TIE does not protect

A security page that lists no limits has limits you have not found yet.

These are ours, stated here rather than discovered later. Each is a boundary of the design, not a defect in it.

Confidentiality at rest is your cloud’s, not ours
The record and payload stores rest on your account’s encryption and access controls. That is not something TIE supplies.
The payload store holds your bytes in clear
Clear to whoever holds the bucket. The sealed record carries commitments; the payload beside it does not.
Index encryption is designed, not built
The design exists and is not yet implemented. It is named here because it is not yet true.
No uptime commitment is offered
Operations stand early. We do not publish an availability figure we cannot yet stand behind.
The custody ceremony is the next step
The first root exists inside the boundary. The ceremony that puts it into service is not claimed today.

TIE’s property is integrity, not secrecy — a record that can be shared with whoever is approved and still proven by anyone who holds it. On legal compulsion the answer is architectural: we hold nothing.

Every AI company is racing to make machines act.

We are building the record that proves what they knew — and what they did.

And the record outlives everything. Including us.

Request a briefing

briefing@memoryofrecord.ai