Mysten Labs and Google Cloud are jointly developing a decentralized verification infrastructure called Verifiable Agent Arbiter (VAA).
It aims to address an increasingly real problem:
As AI agents begin handling funds, data, and account permissions on our behalf, how can we prove they haven’t gone beyond the scope of their authorization?
Until now, we’ve mostly relied on “trusting the agent.” But once agents enter enterprise and financial settings, simply trusting the model clearly isn’t enough.
VAA’s approach is to separate out the verification layer.
What an agent does, and whether it operates strictly within its authorized scope, can be checked by independent verification infrastructure.
More importantly, detailed records of sensitive operations remain stored in a Google Cloud environment controlled by the customer.
In other words:
The verification layer provides proof; the customer retains the original records.
One addresses “Can it be verified?” while the other addresses “Do the data have to be handed over?”
This gets to a challenge that AI agents must face to become commercially viable.
When an agent handles funds, permissions, and data on your behalf, what really matters isn’t just what it can do, but whether, when something goes wrong, we can answer:
What did it do?
Did it exceed its authority?
Where does responsibility lie?
What the agent economy may truly be missing isn’t a smarter model, but a verifiable, auditable ledger of actions.
It aims to address an increasingly real problem:
As AI agents begin handling funds, data, and account permissions on our behalf, how can we prove they haven’t gone beyond the scope of their authorization?
Until now, we’ve mostly relied on “trusting the agent.” But once agents enter enterprise and financial settings, simply trusting the model clearly isn’t enough.
VAA’s approach is to separate out the verification layer.
What an agent does, and whether it operates strictly within its authorized scope, can be checked by independent verification infrastructure.
More importantly, detailed records of sensitive operations remain stored in a Google Cloud environment controlled by the customer.
In other words:
The verification layer provides proof; the customer retains the original records.
One addresses “Can it be verified?” while the other addresses “Do the data have to be handed over?”
This gets to a challenge that AI agents must face to become commercially viable.
When an agent handles funds, permissions, and data on your behalf, what really matters isn’t just what it can do, but whether, when something goes wrong, we can answer:
What did it do?
Did it exceed its authority?
Where does responsibility lie?
What the agent economy may truly be missing isn’t a smarter model, but a verifiable, auditable ledger of actions.