Google Cloud and Mysten Labs are developing a blockchain-based system designed to create verifiable records of actions taken by artificial intelligence agents, as AI systems increasingly move from generating responses to executing transactions and conducting business with other autonomous agents.
The companies announced the Verifiable Agent Arbiter, or VAA, on Oct. 6. The system is intended to provide counterparties, auditors and regulators with independent evidence of what an AI agent was authorized to do, what actions it performed and what resulted from those actions.
The initiative comes as businesses explore AI agents capable of operating across organizational boundaries, raising questions about accountability, security and the ability to reconstruct automated decisions when transactions go wrong.
Blockchain-Based Evidence Layer for AI Agents
Mysten Labs, the original contributor to the Sui Layer 1 blockchain, described VAA as an evidence layer for agent-driven activity. The system separates confidential operational records from cryptographic evidence that can be independently used to verify whether those records have been altered.
Detailed information, including prompts, model responses, external tool calls, and policy-based decisions, is designed to remain in customer-controlled Google Cloud Storage. Cryptographic proofs associated with those records are stored through Walrus, a decentralized data platform designed for AI-related workloads, while Sui coordinates and manages the proofs.
The architecture is designed to allow businesses to keep sensitive AI activity private while giving external counterparties, auditors, and regulators a way to verify the integrity of those records independently.
This approach could become important as AI agents gain authority to make decisions involving money, contracts, and other business obligations. A verifiable record could provide evidence of whether an agent stayed within its assigned permissions.
Dispute Resolution and Security Investigations
One proposed application is resolving disputes between businesses using autonomous agents. If two AI agents complete a transaction and the parties later disagree about what happened, VAA could allow both organizations to reconstruct the workflow using a shared verifiable record.
The system also supports Google’s Agent2Agent protocol, known as A2A, which Google Cloud developed and contributed to the Linux Foundation. The integration is intended to allow organizations to replay disputed workflows against the same cryptographically verifiable receipts.
Security teams could use the system to investigate suspicious agent behavior. By examining instructions, decisions, and external tool operations, investigators could potentially distinguish between prompt injection, policy violations, model failures, and subsequent manipulation of activity logs.
Payment capabilities are also incorporated into the design. VAA connects with Sui’s Agent Payments facilitator, enabling agents to discover services and settle payments for API calls through the x402 protocol.
The authorization to spend, the decision to make a payment, and the delivery of the corresponding service can all be recorded cryptographically, creating an auditable chain between an agent’s instructions and its financial activity.
Regulatory Compliance Adds Pressure
The development comes as governments introduce stricter requirements for AI accountability and record-keeping. The European Union’s AI Act is expected to impose penalties of up to €15 million, about $16.8 million, or 3% of global annual turnover for certain logging failures from 2027.
VAA is being designed so its records can remain verifiable under future cryptographic standards, including post-quantum approaches. Sui has already pursued post-quantum signature technology as part of its broader security development.
Mysten Labs said initial deployments with enterprise customers are planned before wider availability, although it has not identified those customers or provided a general availability date.
As agents execute transactions and act across company boundaries, standard logs are not enough. Counterparties, auditors, and regulators demand proof of its integrity.
VAA delivers that proof and helps enterprises meet upcoming regulations, including the EU AI Act.
— MystenLabs.sui (@Mysten_Labs) October 6, 2026
Sui Reports 40.6 Million TPS Demonstration
The VAA announcement came a day before Mysten Labs presented a separate Sui performance demonstration at its annual Basecamp conference in Singapore.
During the demonstration, Sui reportedly processed 40,614,180 transactions per second through Sui tunnels, exceeding its 20 million TPS target and more than six times its previous reported record of 6,086,766 TPS set on July 4.
Sui tunnels operate similarly to off-chain payment channels but are programmable and can support activities beyond payments. Each tunnel requires only two on-chain transactions to open and close, while intermediate activity can take place without comparable on-chain costs.
More than 10,000 tunnels were reportedly opened on Sui’s mainnet within seconds during the demonstration, involving users and AI agents across applications including games, chat, and payments.
The combination of verifiable AI activity records and high-throughput programmable settlement infrastructure is aimed at creating a trust layer for machine-to-machine commerce as autonomous agents increasingly transact across organizational boundaries.
CertiK is expected to independently examine the associated data, including execution logs, proofs, and journals, and publish its assessment.
The two developments reflect Mysten Labs‘ broader strategy of positioning Sui for an emerging agent-driven economy in which autonomous software could conduct millions of transactions and service interactions without direct human involvement.
As AI agents gain greater authority to negotiate, purchase services, and execute financial decisions, systems that combine privacy, speed, and independently verifiable evidence could become increasingly important for businesses seeking to deploy autonomous software at scale.
