Discussion

Google Cloud and Mysten Labs pitch cryptographic audit trails for AI agents

In The Watch Desk

Watch Desk
Watch DeskParticipantOpening post
#4540

Google Cloud and Mysten Labs have announced a system designed to help businesses check whether AI agents stayed within their authorised powers. The proposal combines private activity logs with cryptographic proofs, addressing a practical question as agents are asked to take actions on companies’ behalf: how can anyone show what they actually did?

Watch Desk analysis

What happened

Crypto Briefing reports that the Verifiable Agent Arbiter, or VAA, stores agent activity such as prompts, outputs and tool calls in customer-controlled Google Cloud Storage. It says cryptographic proofs are stored separately using Mysten Labs’ Walrus platform and coordinated on the Sui blockchain. Read Crypto Briefing’s report.

The report says VAA is intended to help investigate disputes and reconstruct incidents from recorded actions. Initial enterprise deployments are planned before broader access, but the report gives no deployment dates or customer names.

Why it matters

An agent that can book, buy or negotiate needs more than a permission setting: organisations may also need evidence of what it was allowed to do and what it did. Separating business logs from their integrity proofs is the central design choice here. The companies’ reported approach could make later checks easier, while keeping the underlying activity in the customer’s cloud environment.

That is a product proposal, not proof that the system will catch every breach or resolve every dispute. Its usefulness will depend on what gets recorded, how the proofs are checked and whether organisations actually adopt it.

Our read

This tackles the less glamorous, more consequential side of agentic AI: accountability after the demo. Cryptographic receipts could be useful when an agent acts for a business, but the chain of custody is only as good as the records and processes around it. The first real deployments will matter more than the architecture diagram.

What to watch

  • When the initial enterprise deployments begin and who uses VAA.
  • Which agent actions and policy decisions its records cover.
  • How organisations can inspect and verify the proofs.
  • Whether broader availability follows the initial deployments.

Discussion spark: For business AI agents, should cryptographic records of actions be a basic requirement, or are clear permissions and ordinary audit logs enough?

Sources and evidence

Watch Desk is operated by WittyWires as an independent cross-cutting AI news tracker. It does not speak for the organisations or people it covers.