A client's compliance team just asked which parts of their deliverable were AI-generated and who reviewed them. Here's the provenance log that answers that in minutes, not days.
by Ayush Gupta's AI
The problem
A fintech client's compliance team flags a paragraph in a report six weeks after delivery and asks a simple-sounding question: was this AI-generated, which tool, and who on the team reviewed it before it went out. Nobody wrote that down. The answer now requires reconstructing a Slack thread, a Claude conversation nobody saved, and someone's fuzzy memory of a Tuesday six weeks ago. The agency isn't in trouble because it used AI — the client already knew that. It's in trouble because it can't produce a fast, confident answer to a question it should have seen coming. As more agency clients sit in fintech, healthcare, insurance, and legal — industries where an auditor, an insurer, or a regulator can ask this question with teeth — 'we don't actually know' is becoming the answer that ends accounts, not the AI use itself.
The fix
Build a lightweight, per-deliverable provenance log that captures which AI tool touched a deliverable, what it generated versus what a human wrote or edited, and who reviewed and signed off — captured at the natural review checkpoint, not as separate admin work, so any deliverable's AI history is a two-minute lookup instead of a team-wide memory exercise.
The Playbook
Decide which accounts and deliverable types actually need this
This isn't a log for every asset the agency ships. It's for accounts where AI provenance could become a real question — regulated-industry clients (fintech, healthcare, insurance, legal), any client with an AI disclosure or audit clause in the contract, and any deliverable type where a factual or compliance error carries real consequences. Logging everything guarantees the log gets abandoned within a month.
Define the minimum fields, not the ideal ones
Per deliverable: what it is and a link to it, which AI tool and model touched it, what the AI generated versus what a human wrote or substantially edited, who reviewed the final version, and the review date. Five fields. Anything more elaborate turns into a form people route around under deadline pressure.
Have Claude draft the entry from the actual work session, not from memory afterward
The failure mode is asking someone to fill this out after the fact, from memory, days later — which is exactly the process that fails today. Instead, at the point a deliverable is marked ready for client review, paste the AI conversation or draft history in and have Claude produce the log entry directly.
Read this AI conversation/draft history for a client deliverable and produce a provenance log entry.
Deliverable: [NAME/LINK]
Client: [CLIENT NAME]
Conversation/draft history:
[PASTE AI CONVERSATION OR DRAFT VERSIONS]
Output exactly these fields:
1. AI tool and model used
2. What the AI generated substantially as-is (be specific — which sections, claims, or assets)
3. What a human wrote, substantially rewrote, or fact-checked before it shipped
4. Anything in the AI output that was flagged, corrected, or removed before delivery
5. One-line summary suitable for a compliance or client-facing record
Be factual and specific. Do not soften or omit what the AI actually generated.Wire the log entry into the existing sign-off step
Don't create a new approval gate — attach the log entry to the one that already exists. If a deliverable can't be marked 'client-ready' without a reviewer's name attached, add the provenance entry to that same moment. The reviewer signing off is already reading the deliverable; capturing what they're signing off on costs nothing extra.
Make the log searchable by client and by deliverable, not just chronological
A running doc nobody can search is functionally the same as no log. Keep entries in a table (Airtable, Notion, even a shared sheet) filterable by client and deliverable name, so when a compliance question lands on a specific report or asset, the answer is a lookup, not an investigation.
What changes
When a client's compliance team, insurer, or legal department asks which parts of a deliverable were AI-generated and who reviewed it, the agency answers in minutes with a specific, factual record — instead of reconstructing it from Slack and memory under pressure, which is when trust actually breaks.
Six weeks after a report ships, a fintech client's compliance team flags a paragraph and asks a question that sounds simple: was this AI-generated, which tool wrote it, and who reviewed it before it went to them. Nobody on the account can answer with any confidence. The conversation with Claude that produced the first draft is gone from someone's chat history. The Slack thread where a strategist said "looks good, ship it" doesn't say what they were looking at. The honest answer is "we're not sure" — and that answer, not the AI use itself, is what actually damages the relationship.
This isn't a hypothetical anymore. As more agencies serve clients in fintech, healthcare, insurance, and legal — industries where a compliance review, an insurer, or a regulator can ask this question with real consequences attached — the gap between "we use AI responsibly" and "we can prove exactly how, on this specific deliverable" is exactly where trust gets tested.
The problem isn't AI use. It's the absence of a record.
Most agencies serving regulated-industry clients already have reasonable AI practices — a human reviews the output, obvious errors get caught, nothing ships blind. What's missing isn't the practice. It's the record of the practice. When the question comes weeks or months later, "we always review AI output" is a policy statement. It isn't an answer to "who reviewed this specific paragraph, and what did they change." Only a record answers that question, and most agencies don't have one.
Log at the moment of review, not after the fact
The instinct is to build a form and ask the team to fill it out. That fails the same way every after-the-fact documentation process fails — it depends on someone remembering to do it, accurately, days after the work happened, under no particular incentive to bother. The fix is capturing the entry at the point where a human is already reviewing the deliverable and about to sign off on it. Claude can turn the actual AI conversation or draft history into a structured log entry in under a minute — what the AI generated, what a human changed, what got flagged and corrected. The reviewer isn't doing extra work. They're capturing what they're already doing.
Five fields, not a compliance framework
The version of this that survives contact with a real production week is short: the deliverable, the AI tool and model, what the AI generated versus what a human wrote or substantially edited, who reviewed it, and when. Anything more elaborate becomes the kind of process people quietly stop doing under deadline pressure — and a provenance log that's inconsistently filled out is barely better than no log, because now the gaps themselves look like the story.
Bottom line
The agencies that get hurt by AI use in regulated-industry work aren't the ones using AI carelessly — most aren't. They're the ones who can't produce a fast, specific, factual answer when a client's compliance team asks a fair question about a specific deliverable. A five-field log, captured at the review step that already exists, is the difference between a two-minute lookup and a scramble that makes a routine compliance question look like a bigger problem than it is.