A field guide to AI positions

Observability & runtime monitoring

Publication dates and source age

Sources counted: 6

Newest dated source: 2026-08-20

At least one source was published within the 18-month window.

Assessed at this edition's evidence cutoff: 2026-09-15. 18-month boundary: 2025-03-15.

Some publication dates are unknown; the newest dated source may not be the newest source overall.

Publication age does not tell us whether a claim is still valid. Reading an old source again does not make its publication date newer. An update date does not establish that the passage we used was updated.

Open in the glossary Reading notes · Structured record

In plain language

Using recorded system events to investigate what an application is doing and where problems occur. [1]

Reference this explanation or suggest a correction

Link to this explanation · Suggest a correction · How corrections work

Limits & distinctions

Recorded actions do not fully explain learned mechanisms. Reasoning traces can add useful monitoring signals, but may omit relevant information; a clean log is not proof of safety. [4] [5] [6]

Reference this explanation or suggest a correction

Link to this explanation · Suggest a correction · How corrections work

A fuller explanation

Software observability uses signals such as logs, metrics and traces. For AI applications, useful records can include inputs, outputs, tool activity and network events, with appropriate privacy protections. [1] [2] [3]

Reference this explanation or suggest a correction

Link to this explanation · Suggest a correction · How corrections work

How it relates to the map

Operational evidence can inform a deployment assessment. It is not a measure of someone's development preference or catastrophic-risk concern. [2]

Reference this explanation or suggest a correction

Link to this explanation · Suggest a correction · How corrections work

Share this page

https://theaiatlas.org/ideas/observability/

Download a share image · Vector image

Image previews are summaries. Keep the page link so readers can check the evidence.

Sources and what we read

  1. 1. Observability primer

    Publication dates and source age

    Sources counted: 1

    Publication dates are unavailable.

    Assessed at this edition's evidence cutoff: 2026-09-15. 18-month boundary: 2025-03-15.

    Some publication dates are unknown; the newest dated source may not be the newest source overall.

    Publication age does not tell us whether a claim is still valid. Reading an old source again does not make its publication date newer. An update date does not establish that the passage we used was updated.

    Read observability, telemetry, logs and distributed-trace definitions. Updated date follows the displayed documentation modification, which references a spelling-related commit rather than a new research result. Used for software terminology, not complete access to model internals.

  2. 2. Guidelines for secure AI system development: Secure operation and maintenance

    Source is over 18 months old.

    Publication dates and source age

    Sources counted: 1

    Newest dated source: 2023-11-27

    Assessed at this edition's evidence cutoff: 2026-09-15. 18-month boundary: 2025-03-15.

    Publication age does not tell us whether a claim is still valid. Reading an old source again does not make its publication date newer. An update date does not establish that the passage we used was updated.

    Read monitoring of behavior and inputs, privacy-aware logging, update evaluation and lessons learned. Date follows the containing guideline publication. Describes operational monitoring, not complete explanation of learned weights.

  3. 3. Managing the cyber risk of agentic AI

    Publication dates and source age

    Sources counted: 1

    Newest dated source: 2026-08-20

    At least one source was published within the 18-month window.

    Assessed at this edition's evidence cutoff: 2026-09-15. 18-month boundary: 2025-03-15.

    Publication age does not tell us whether a claim is still valid. Reading an old source again does not make its publication date newer. An update date does not establish that the passage we used was updated.

    Read autonomy, model safeguards, oversight, sandbox boundaries, network and credential restrictions, observability and emergency response. The publisher labels this interim practical advice based on its research; formal guidance may supersede it.

  4. 4. Circuit Tracing: Revealing Computational Graphs in Language Models

    Publication dates and source age

    Sources counted: 1

    Newest dated source: 2025-03-27

    At least one source was published within the 18-month window.

    Assessed at this edition's evidence cutoff: 2026-09-15. 18-month boundary: 2025-03-15.

    Publication age does not tell us whether a claim is still valid. Reading an old source again does not make its publication date newer. An update date does not establish that the passage we used was updated.

    Read introduction, method overview and limitations including reconstruction errors, graph complexity, global circuits and mechanistic faithfulness. The authors' replacement-model analyses reveal selected mechanisms; they do not provide a complete explanation of all behavior. Later attention-tracing work is cited alongside this paper to avoid treating its missing-attention limitation as a permanent field-wide result.

  5. 5. Chain of Thought Monitorability: A New and Fragile Opportunity for AI Safety

    Publication dates and source age

    Sources counted: 1

    Newest dated source: 2025-07-15

    At least one source was published within the 18-month window.

    Assessed at this edition's evidence cutoff: 2026-09-15. 18-month boundary: 2025-03-15.

    Publication age does not tell us whether a claim is still valid. Reading an old source again does not make its publication date newer. An update date does not establish that the passage we used was updated.

    Read abstract, rationale, research questions, limitations and conclusion. A research position paper: reasoning traces may add monitoring value while remaining incomplete and potentially fragile. Authors' views are not necessarily their institutions' positions; cited experiments were not all independently reviewed.

  6. 6. How we monitor internal coding agents for misalignment

    Publication dates and source age

    Sources counted: 1

    Newest dated source: 2026-03-19

    At least one source was published within the 18-month window.

    Assessed at this edition's evidence cutoff: 2026-09-15. 18-month boundary: 2025-03-15.

    Publication age does not tell us whether a claim is still valid. Reading an old source again does not make its publication date newer. An update date does not establish that the passage we used was updated.

    Read deployment approach, reasoning/tool-trace monitoring, asynchronous alerts, limitations and proposed control evaluations. A dated first-party account, not an independent audit or a claim about current coverage. The authors explicitly cannot establish a real-world missed-event rate from employee escalations alone.

Edition and machine-readable evidence

Content version 0.20.0. Evidence cutoff 2026-09-15; this does not mean every source was read on that day.

Pinned complete dataset · Complete evidence page · Agent consumption guide