VIAS
The evidence plane for autonomous agents
VIAS captures and seals execution events outside the agent runtime, creating tamper-evident evidence that can be verified independently of the platform that acted.
Control planes determine what agents may do. Evidence planes preserve what agents did do. VIAS is the evidence plane.
What VIAS Is
VIAS is an execution-evidence layer that operates separately from the agent runtime and decision environment. At the platform boundary, execution events are routed to VIAS, evaluated against defined governance policy and sealed into a tamper-evident evidence chain. Where an outcome falls outside policy, the original record remains unchanged and any correction, reversal or reconciliation is cryptographically linked as a new event.
VIAS combines established cryptographic, policy and evidence-management primitives at the point where accountability must live: between autonomous action and the durable evidentiary record. Because the evidence function is separated from the model, planner, runtime, orchestration system and tool caller, auditors and counterparties do not have to rely exclusively on records produced by the system that made the decision. Evidence is captured separately from the system that acted. The owner may be the same.
How It Works
A three-stage evidence system.
Agent & Tool Boundary
VIAS Governance Boundary
01
RECORD
Captured outside the agent runtime
02
ATTEST
Evaluated against policy and authority grant
03
SEAL
Append-only evidence chain commitment
Auditor / Regulator / Counterparty
01
RECORD — Platform Boundary Routes
The platform boundary routes a normalised execution event to VIAS. The evidence package identifies the relevant authority, requested action, execution payload, executor assertion and reported result. Deployments claiming comprehensive coverage must ensure that applicable actions cannot bypass the configured evidence boundary.
02
ATTEST — Policy Evaluation
The VIAS Governance Gate evaluates the captured evidence against the applicable policy and authority grant. The evidence record distinguishes between evidence directly observed by VIAS, assertions supplied by upstream systems, policy comparisons derived by VIAS, and external attestations supplied by trusted issuers. This distinction preserves the chain of responsibility — VIAS protects the integrity of the record, while the originator of each upstream assertion remains responsible for its reliability.
03
SEAL — Ledger Committed
VIAS cryptographically seals the record into an append-only evidence chain. The original event is never silently rewritten — corrections, reversals and reconciliations are recorded as separately sealed events linked to the original evidence. Where a verdict falls outside policy, VIAS records the non-compliant event and any governed response in the same chain. VIAS does not silently replace the original event or imply that the underlying external effect has necessarily been reversed.
Verification scope: A valid seal establishes that the sealed record has not subsequently changed. It does not, by itself, prove that every upstream assertion was factually correct or that every applicable action was captured.
Six complementary attestation vectors
Each captured action can be sealed across six complementary dimensions, preserving evidence of input, origin, response, handoff, scope and authorisation outside the host platform.
Input Attestation
Binds declared inputs to the inputs presented for execution.
Origin Attestation
Records declared model identity, version or hash, origin and relevant jurisdictional metadata.
Response Attestation
Seals the canonical execution record and resulting output hash.
Handoff Attestation
Links captured events across multi-agent execution chains.
Scope Attestation
Records declared authority and observed system-access events within the integration boundary.
Authorisation Attestation
Seals the policy grant, approval event and associated authorisation evidence.
Note: The trust assumptions, verification rules and evidence sources for each vector are defined in the VIAS technical architecture.
What It's Built For
As autonomous agents begin making purchases, changing records, operating enterprise systems and exercising delegated authority, the evidence question becomes an operational and liability question. The same evidence problem appears whenever AI actions create legal or financial consequences — security incidents, claims and underwriting, payments, administrative decisions, audit and governance.
Organisations need to establish: what authority existed; what action was requested; what payload was executed; which executor was involved; what result was reported; whether the evidenced action remained within policy.
VIAS provides evidentiary custody for those questions without inspecting private reasoning or asking one model to judge another.
Proof of integrity, not interpretation. Evidence, not introspection. Custody, not trust.
EU AI Act
The EU AI Act applies progressively. The European Commission’s implementation timeline states that Article 50 transparency rules are scheduled to apply from 2 August 2026, while rules for Annex III high-risk systems are scheduled for 2 December 2027. VIAS is designed to support evidence and record-keeping programmes, but applicability depends on the system’s classification and the organisation’s role.
DORA
DORA establishes digital-operational-resilience requirements for the financial sector. Article 30 requires ICT contracts to address matters including data availability, authenticity, integrity and confidentiality, alongside access, recovery and cooperation obligations. VIAS evidence can support relevant controls and assurance activities. VIAS should not be presented as automatically satisfying Article 30.
ISO 42001
ISO/IEC 42001:2023 specifies requirements for establishing, implementing, maintaining and continually improving an AI management system. It addresses responsible AI use, risk management, traceability, transparency and reliability. VIAS is designed to provide evidence that can support an organisation’s wider AI management system.
NIST AI RMF
The NIST AI Risk Management Framework is a voluntary, non-sector-specific framework designed to help organisations manage risks associated with AI and incorporate trustworthiness into the design, development, use and evaluation of AI systems. VIAS evidence can support governance, measurement and accountability practices within an organisation’s implementation of the framework.
UK ICO
The ICO Tech Futures: Agentic AI report examines emerging agentic-AI capabilities and related data-protection questions, including accountability, complex automated decision-making, transparency and cybersecurity. The ICO explicitly describes the report as early thinking rather than formal guidance or regulatory expectations. VIAS is designed to support accountable evidence capture where agentic systems process information and perform consequential actions.
Important qualification: Specific obligations, implementation dates and applicability depend upon the organisation, autonomous system, deployment role and jurisdiction. VIAS provides evidence infrastructure, not automatic legal compliance.
VIAS connects at the governance layer through reference architectures designed to connect to major agent platforms, with no re-architecture of the agent platform required. Evidentiary independence reduces platform lock-in and avoids dependence on a specific model or agent runtime. Platform-side configuration is needed to route execution records to VIAS.
