Last Update 7:24 PM July 25, 2026 (UTC)

Organizations | Identosphere Blogcatcher

Brought to you by Identity Woman and Infominer.
Support this collaboration on Patreon!!

Friday, 24. July 2026

FIDO Alliance

Tech Times: YubiKey 5.8 Ships Hardware-Backed Authorization for AI Agent Workflows

Touch a YubiKey to log in, and you’ve proven who you are. Touch a YubiKey to approve a database schema change ordered by an autonomous AI agent, and you’ve proven […]

Touch a YubiKey to log in, and you’ve proven who you are. Touch a YubiKey to approve a database schema change ordered by an autonomous AI agent, and you’ve proven something different: that a human consciously authorized that specific action, right now, with cryptographic proof that can be audited. Yubico shipped that second capability on July 21, when it released YubiKey 5.8 firmware — the most architecturally significant update to its hardware security key platform in years — and the distinction matters to any organization deploying agentic AI.

Traditional multi-factor authentication was designed to answer one question at the door: who are you? Once a session opens, an authenticated user — or any agent acting with that user’s permissions — can initiate hundreds of consequential actions without further cryptographic proof of intent. As generative and agentic AI systems take on the ability to access databases, approve financial transactions, and execute operational workflows at machine speed, the login checkpoint is looking structurally thin.

YubiKey 5.8 is Yubico’s answer to that gap. Built on the newly published CTAP 2.3 standard and a developer preview of an emerging WebAuthn signing extension, the firmware turns the hardware security key from a session-entry gate into a per-action authorization primitive: cryptographic proof that a specific, physically present human signed off on a specific action at a specific moment.


ResofWorld

Why state-owned AI won’t solve inequality

Government ownership of AI companies may promise shared wealth, but it risks weakening oversight and accountability.
Last month, U.S. President Donald Trump suggested the government buy equity in AI companies, in response to concerns that the industry’s boom is leaving most Americans behind. His political opposite,...

Thursday, 23. July 2026

EdgeSecure

Navigating the New Landscape of GLBA Compliance: Key Changes to Protect Your Federal Financial Aid

The post Navigating the New Landscape of GLBA Compliance: Key Changes to Protect Your Federal Financial Aid appeared first on Edge, the Nation's Nonprofit Technology Consortium.

Leveraging National Supercomputing Resources for Research and Education

The post Leveraging National Supercomputing Resources for Research and Education appeared first on Edge, the Nation's Nonprofit Technology Consortium.

The Engine Room

Open Call: Light-Touch Support for Elections in Latin America and Africa

Across Latin America and Africa, civil society faces information disorders, shrinking civic space, restrictive government policies, and collaboration between Big Tech companies and governments that enables increased surveillance. Upcoming elections in 2026 may take place amid anti-NGO legislation, restrictive cybersecurity laws, and uses of artificial intelligence that put civil society under pres

Across Latin America and Africa, civil society faces information disorders, shrinking civic space, restrictive government policies, and collaboration between Big Tech companies and governments that enables increased surveillance. Upcoming elections in 2026 may take place amid anti-NGO legislation, restrictive cybersecurity laws, and uses of artificial intelligence that put civil society under pressure. To help organizations and collectives prepare for this critical election period across both regions, the Engine Room is launching an open call for support.

The post Open Call: Light-Touch Support for Elections in Latin America and Africa appeared first on The Engine Room.


ResofWorld

The hidden cost of Myanmar’s rare earth mines

As the U.S. races to bypass China, the global hunger for critical minerals is financing warlords and poisoning Myanmar's borderlands.
This story was originally published by Grist, produced in partnership with the Pulitzer Center’s Rainforest Investigations Network, and republished by Rest of World. When Min left the hot, dusty plains...

Fed up with Big Tech, communities turn to data collectives for control

Data collectives and cooperatives, which let creators control the collection and distribution of their data, are emerging as preferred alternatives to big tech companies.
A growing pushback against big tech companies, and greater awareness of the value of data, is spurring interest in data collectives and cooperatives, which give communities control over the collection,...

Wednesday, 22. July 2026

GLEIF

The LEI in Numbers: Q2 2026 Signals Growing Regional Momentum for the LEI

The Global LEI Foundation (GLEIF) is proud of its ongoing transparency initiatives, including its open approach to providing unrestricted access to the latest LEI data from around the world with the Quarterly LEI System Business Reports, which are made publicly available free of charge. Through this ‘LEI in Numbers’ blog series, GLEIF highlights key data from the latest report, explaining trends a

The Global LEI Foundation (GLEIF) is proud of its ongoing transparency initiatives, including its open approach to providing unrestricted access to the latest LEI data from around the world with the Quarterly LEI System Business Reports, which are made publicly available free of charge. Through this ‘LEI in Numbers’ blog series, GLEIF highlights key data from the latest report, explaining trends and profiling successes from the global LEI rollout.

Strong growth in the Global LEI System continued in Q2 2026, with 92,000 organizations worldwide obtaining an LEI. This represents a quarterly growth rate of 3.0% and saw the total active LEI population reach over 3.1 million. The total LEI population – which includes both active LEIs and LEIs that have been retired as entities ceased operations – exceeded 3.35 million.

India had the highest LEI growth rate among jurisdictions at 7.1%. This followed the issuance of a master direction from the Reserve Bank of India (RBI) in March 2026, making the LEI compulsory for all market participants in the financial markets it regulates.

Brazil also made the top five growth jurisdictions for the second successive quarter, registering a 5.1% increase. The ongoing market activities of local LEI issuers are being supported by regulatory developments, with the Central Bank of Brazil (BCB) preparing a regulatory framework which will enable LEI integration in cross-border payments to align with the G20 roadmap.

This signals growing momentum for the LEI across Latin America. For instance, the Central Bank of Chile has used the LEI for derivatives reporting since 2020, but expanded the requirements to FX spot and cross-border transactions from January 2026 onwards.

More broadly, Latin America is undergoing a significant digital transformation aimed at boosting economic prosperity and productivity, with the region emerging as a leading global innovator in areas such as digital payments and trade infrastructure. As the reach and utility of the Global LEI System continue to expand, it offers businesses across the region a consistent and standardized way to prove their identity and legitimacy in payments, value chains, digital infrastructure, digital assets, and a host of other digital ecosystems.

Elsewhere, the ongoing application of the European Union’s Digital Operational Resilience Act (DORA) continued to drive growth across Latvia (5.2%) and Lithuania (4.7%). The United Arab Emirates also saw a 4.6% increase.

The Global LEI System empowers everyone, everywhere, with open, standardized, and high-quality data that is regularly revalidated to ensure it is accurate, up-to-date, and usable – promoting trust and transparency across the global economy. Key data points tracked within the Quarterly LEI System Business Reports are:

Renewal rates

The Global LEI System is unique in providing absolute transparency regarding when entity data was last verified, with the annual renewal process ensuring that both legal entities and LEI issuers review and re-validate legal entity reference data at least once per year.

Strong growth in new issuance was coupled with a rise in renewals in Q2 2026, with the overall renewal rate reaching 57.1%. Renewals in EU and non-EU jurisdictions increased to 61.3% and 50.8% respectively, with the latter primarily due to sustained progress in the United States and United Kingdom.

The jurisdictions with the highest renewal rates were Japan (89.8%), Finland (82.1%), India (78.5%), Germany (74.4%) and Liechtenstein (71.4%).

Corroboration

Corroboration is the process of verifying the existence of a legal entity and its reference data – such as name, address, legal form, and corporate structures – against authoritative sources listed in the GLEIF Registration Authority List. LEI issuers validate the information provided by the legal entity by comparing it against the publicly available authoritative data.

87.9% of LEIs were fully corroborated at the end of Q2 2026. This means that all reference data elements have been validated against public authoritative sources.

Parent information reporting

Identifying the direct and ultimate parents of a legal entity, and vice versa, answers the question of 'who owns whom'. This allows users to connect the dots and enables deeper insights into ownership structures across corporate groups.

In Q2 2026, over 3.22 million LEI registrants – representing 99% of the total LEI population – reported information on direct and ultimate parents. 100% of LEI registrants that obtained a newly issued LEI or renewed an existing LEI in this quarter reported parent information.

Fund relationship reporting

Many legal entities with an LEI are investment funds. To better understand the relationships between fund entities and investment funds globally, three main types of fund relationships are categorized: fund management entities, umbrella structures, and master-feeder structures.

Over 159,000 legal entities reported fund relationship structures in Q2 2026, an increase of around 3,400 on the previous quarter. Among those, 66.8% were funds managed by a main management entity, 32.6% were sub-funds to umbrella funds, and 0.6% were feeder funds.

Entity categorization

Dedicated categories have been created to identify government entities and international organizations, address the unique considerations they pose, and ensure high data quality. In Q2 2026, approximately 6,800 entities were identified as government entities (up from 6,700 in Q1 2026) and 84 as international organizations (up from 82 in Q1 2026).

For the full report, which includes further detail on the status of LEI issuance and growth potential, the level of competition between LEI issuing organizations in the Global LEI System and Level 1 and 2 reference data, please visit the Global LEI System Business Reports page.

If you are interested in reviewing the latest daily LEI data, our Global LEI System Statistics Dashboard contains daily statistics on the total and active number of LEIs issued. This feature now enables any user to review historical data by geography, increasing transparency on the overall progress of the LEI.

For further detail or to access historical data, please visit the Global LEI System Business Report Archive.

We look forward to sharing our progress each quarter as we continue to drive LEI adoption in 2026.


DIF Blog

Significant Donations from DID:Webvh Community

Juan Caballero, Community Manager at Decentralized Identity Foundation Stephen Curran, Principal at Cloud Compass Computing Inc. The did:webvh work item in the Identifiers & Discovery WG is a quiet but steadily progressing item within DIF, addressing the essential work driving wider adoption of DIDs. If you’ve been

Juan Caballero, Community Manager at Decentralized Identity Foundation
Stephen Curran, Principal at Cloud Compass Computing Inc.

The did:webvh work item in the Identifiers & Discovery WG is a quiet but steadily progressing item within DIF, addressing the essential work driving wider adoption of DIDs. If you’ve been following over the last year via Slack, PRs, and agendas, you know there has been steady progress and disciplined ongoing design at higher layers, working on different witnessing systems and federation/registry mechanics.  

One of the key improvements is on the core “Verifiable Data Registry,” that is, the web server that hosts and manages webvh DIDs. The Verifiable Data Registry is a formidable HTTP server that has been re-implemented in multiple languages and cross-tested rigorously. The server now incorporates sophisticated cryptography, queueing and load-balancing, and support for complex endpoints. Not since did:ion (a project led by DIF’s original executive director and adopted by Microsoft!) have this many independent implementations been donated and cross-tested. This degree of community activity is a testament to how did:webvh has attracted attention and is being used in diverse deployments.

DID:webvh approaching “every major language” territory

As we reported last year, at the time of the v1.0 specification finalization, the three donated implementations were in Python, Typescript and Rust.  This third implementation, relatively recent at the time of v1.0 feature freeze and testing blitz, was driven by long-time DIF Member Affinidi, a startup that both develops software and deploys it at such a scale as to stretch our mental model of a “startup”. Affinidi is a long-term contributor to DIF, having also contributed a mature implementation of another DIF-incubated DID method and contributed to Verifiable Credential tooling.

Based on the need for wide-scale adoption, Affinidi has added a Java implementation which will be DIF-maintained on Java’s package manager, Maven.

Depending on your feelings about Go, the backend-language Google invented to power its own microservices and cloud, one might even say did:webvh is already available (or reasonably wrappable/ABI-able) in every major language that developers might need to architect did:webvh into their production deployments.

The personal twist: webvh-dart

As if all this weren’t impressive enough, Affinidi’s Reza Maghoul, the main developer of the Java implementation, also made a hobby/weekend project implementing it in parallel in a branch of the Java family tree called Dart. Independent from Affinidi’s production usecases for the didwebvh Java server, Reza is also donating the Dart variant, rounding out the portfolio interestingly.

Dart is best known as the ergonomic and idiomatic language powering “Flutter”, a mobile application framework and packaging tool that can package both iOS and Android applications from a single Dart codebase. Dart has also found a strong following for being far easier and more fun to code with than Java or C#. In fact, without much fanfare, server-side Dart tooling has matured considerably in recent years, following the precedents of TypeScript and JavaScript frameworks that make it easier for individual or casual developers (and their agents) to code front- and back-end idiomatically in a shared language. The Dart implementation makes did:webvh accessible to additional developers.

But What About Interop?

With 5 DID:webvh implementations available and another outside of DIF, how does the community make sure all the implementations are interoperable? A test suite is the obvious answer. The did:webvh test suite includes some interesting AI-driven contributions. The DIF did:webvh-test-suite repository contains a canonical set of DID creation and update tests (based on YAML steps in a simple Domain Specific Language) and a driver for every known implementation to run the tests.

Each test run for a given implementation:

Generates all of the test DIDs, creating DID Log and resolution result test vectors, Runs a set of “negative” tests with DIDs constructed to NOT follow the spec (more below), and Resolves all of the Test DIDs from all of the implementations.

The Test Suite produces Pass/Fail results for all six implementations interoperability .The tests run nicely in Docker, so they can be run against every PR of every implementation to prevent regressions.

On top of the functioning Test Suite, Anthropic’s Project Glasswing and Mythos made the test suite even more valuable. Through Affinidi’s involvement in using did:webvh with the Linux Kernel Group to verify that PRs to the kernel are from real, known contributors, Affinidi was given early access to Anthropic’s Mythos LLM to hunt for vulnerabilities in the Rust did:webvh implementation. The bad news was that vulnerabilities were found — in fact there 40 across all of the DIF implementations.

The good news:

All vulnerabilities have been fixed across all implementations. Negative test cases have been added to the didwebvh-test-suite to make sure they don’t resurface. An update to the specification was generated, revised and applied — that didn’t change any of the specification’s normative behaviors, but expressed them more unambiguously for future implementers.

That last point was quite interesting. The vulnerabilities weren’t in the definition of the specification, but in implementing the spec as it was written. The ability to rapidly improve the implementations was a major boost for the did:webvh community!

To get involved in the did:webvh community:

Check out the information site: https://didwebvh.info Use one of the did:webvh implementations to power your DID use cases, and integrate regression testing with the official test suite if you fork one. Join the biweekly meetings, Thursday at 9:00 Pacific / 18:00 Central Europe, Agenda and Zoom info and help us to continue to evolve the did:webvh. Roadmap items: did:webvh DIDs without a web address. PQC support in did:webvh. Extract the “vh” from did:webvh for use in other areas. Request your did:webvh implementation or deployment/use case be added to the list. Request your implementation be added to the did:webvh Test Suite.

To get involved in the Identifiers & Discovery Working Group at DIF

Visit our website

ResofWorld

The U.S. wants to contain China’s AI. Silicon Valley keeps using it

As Apple, Thinking Machines, and developers worldwide embrace Chinese AI models such as Kimi K3, U.S. policymakers are struggling to protect the AI lead.
When Anthropic’s chief national security officer and former Biden administration export control architect Tarun Chhabra recently highlighted model distillation as an emerging national security concern, one detail stood out. Chhabra...

Blockchain Commons

2026 Q2 Blockchain Commons Report

The second quarter of 2026 at Blockchain Commons focused partially on decentralized identity and partially on improving our resources for your use. Here’s a summary of our work: Revisiting SSI: The Redline The Meetings The Principles Dev Page Updates: Technology Pages Digital Identity Page Resources Pages Apps Page Learning XIDs: Keys in XIDs Amira Progress Report Learning Bitcoin: New Course Pages

The second quarter of 2026 at Blockchain Commons focused partially on decentralized identity and partially on improving our resources for your use. Here’s a summary of our work:

Revisiting SSI:

The Redline The Meetings The Principles

Dev Page Updates:

Technology Pages Digital Identity Page Resources Pages Apps Page

Learning XIDs:

Keys in XIDs Amira Progress Report

Learning Bitcoin:

New Course Pages Working with Secrets

Software Updates:

Envelope CLI Stack Update

The Trust Architect Speaks:

Agency in AI Ten Years of SSI Sanctuary and Exodus On Being the Fifteenth Standard When Intelligences Become a Permission

Grants

Here’s more on each of these:

Revisiting SSI

Christopher Allen has continued his work updating the SSI principles for 2026.

The Redline. To mark the April 26 anniversary of the publication of “The Path to Self-Sovereign Identity”, we released a redline version of updated principles. This remains a work-in-progress, but is a good first draft of how we’re changing the principles to reflect 10 years of technical evolution and what we’re considering adding.

The Meetings. Christopher presented the updated principles to the W3C CCG group in early May. We’ve since held meetings in May and June to support the community in continuing the update of the principles. Revisiting SSI is truly a community-focused project, intended to update the principles of SSI such that they’re meaningful to people doing real work on self-sovereign identity.

The Principles. The meetings have continued to evolve the principles. Participants have produced new drafts of the principles for portability & interoperability, minimalization, and persistence. One of our participants, Martina, has also focused on anti-coercion with a series of articles about Technological Paternalism, most recently “Technology Paternalism, Continued - Five Abilities and a Test for Self-Sovereign Identity”. We expect to incorporate this all into the new principles redline later this year, but we still have more to work through. You can join the Revisiting SSI announcement list for info on upcoming meetings if you’d like to participate!

Dev Pages Update

We undertook a large-scale update of our developer pages that concluded (in its first phase) last week. Our goal was to make the pages more accessible and usable and to fill in some gaps. Let us know how you use our pages and what you feel is missing (either organizationally or topically).

Technology Pages. The majority of our pages are now organized into a technology category that includes five subcategories: data formats, data resilience, digital identity, digital signatures, and secure communication. We hope these new categories will help developers to find what’s of most interest to them (and to see why we consider these categories of technology important!).

Digital Identity Page. The digital identity subcategory includes a lot of new content. That’s because we’ve been building toward digital identity for a while, but it’s only recently that our technological stack has reached the point where we can really focus on it. The subcategory includes new pages on self-sovereign identity, attestations & endorsements, fair witness methdology, and public participation profiles, which are our fundamental building blocks for creating identities that you truly control.

Resources Pages. The resources category allowed us to gather together all the things that might be immediately useful to you as a developer, including: our ever-growing list of command-line courses, our meeting records, our reference libraries, our reference apps, and our specifications.

Apps Page. We found the reference apps page particularly exciting, because it allowed us to highlight not just our iOS and Rust apps, but also the online playgrounds that allow you to test seeds, lifehashes, URs, and XIDs without having to install anything on your machine (and as ever, thanks to Leonardo and Irfan for creating the newest and most extensive playgrounds!).

BCTS IDE:
BC-UR Playground:
Seedtool.info:
Lifehash.info:

We still have one area in the developer pages to revamp: architecture. We intend to do that in Q3, when we’re going to better differentiate network architecture and architectural design and also create new pages for many of our architectural design patterns.

Learning XIDs

XIDs are of course our capstone to our self-sovereign identity work, pairing the revised principles of Revisiting SSI with an actual technological pilot.

Keys in XIDs. Our Learning XIDs course reveals how to use XIDs. In Q2, we expanded it with a new chapter 5, “Managing Keys”, which details how you can use heteregeneous keys to improve key (and identity) resilience and to recover from loss.

Amira Progress Report. The Amira use case that was developed at Rebooting the Web of Trust has long been our North Star for developing XIDs as a decentralized identifier that went beyond the compromises of DIDs. In Q2, we released a progress report on Amira that detailed the requirements embedded in the use case, how we expanded them, and how XIDs fulfill those needs.

Learning Bitcoin

The Human Rights Foundation opened the year with support for an update of our popular Learning Bitcoin project, with that work continuing into Q2 (and planned through the rest of the year).

New Course Pages. Our updated course is now available at learningbitcoin.blockchaincommons.com, which uses mkdocs to offer a more accessible version of the course. Though the update remains a work in progress, the first 15 chapters are all available here in close to final form.

Working with Secrets. Most of our work is revisionary, updating the course for changes in both the CLI commands and the underlying models for Bitcoin. But we’re also introducing new chapters as appropriate. Chapter 10: Working with Secrets is one of our biggest additions to date. It addresses the fact that bitcoin-cli keeps its secrets pretty close to the vest and shows how you can improve your resilience either by creating a seed elsewhere and importing keys or else exporting master private keys and storing them elsewhere, possibly with metadata (as supported by a Gordian Envelope).

Learning Bitcoin:
Learning XIDs:
Software Updates

When we capped the Blockchain Commons stack in Q1, we expected to dramatically slow down our technical development while we work on getting our current specifications deployed. Nonetheless, Q2 saw some minor upgrades.

Envelope CLI. We closed 20 Issues on bc-envelope-cli-rust, our main reference app for the Gordian Envelope specification. This resolved some interactions between XIDs and URs, answered some issues with XID output commands, allowed native importing of XIDs into envelopes, improved exporting options, and more. There were some bug fixes, but we also introduced new best practices for how we think Envelopes (and XIDs) should work in real usage. The newest envelope-cli is 0.35.0. Make sure you update (cargo install bc-envelope-cli --version 0.35.0) if you haven’t recently.

Stack Update. Some of the updates actually occurred in bc-xid-rust; there were also a few updates for dependency alignment in our stack.

The Trust Architect Speaks

We released a number of blog posts in Q2, many of them focused on Christopher Allen’s architectural thoughts.

“Agency in AI”. How can we solve authority and crediting problems with agentic systems? Plus, the advantages of self-sovereign agentic computing.

“Ten Years of SSI”. More on the 10-year revision of the SSI principles and why it was required.

“Sanctuary and Exodus”. Ethereum’s focus on “Sanctuary Technologies” and how that meshes with our own ideas of “Exodus Protocols.”

“On Being the Fifteenth Standard”. The advantages and challenges of Gordian Envelope: why it can be important to offer a new standard even when there are 14 more.

“When Intelligence Becomes a Permission”. AI has changed the question of who controls your identity to one of who controls your cognition. How the government censorship of frontier models has made that a dangerous proposition.

Grants

Finally, the funding landscape for our digital agency work has remained bleak, so we’ve been working on an increasing number of grant requests to try and support our work. Our most recent grant requests were to support our work with standards groups, to continue to expand our work on self-sovereign identity, and to revise the Smart Custody book.

We can use your support too. Talk with us about projects you’d like to partner on; support us on GitHub; and tell us about grants that you think might fit with our goals or our work to date. Thank you!

Tuesday, 21. July 2026

Digital Identity NZ

Trust, credentials and Digital Public Infrastructure in focus | July Newsletter

What a month. Prime Minister Modi’s historic visit, the first by an Indian Prime Minister in 40 years, put digital public infrastructure (DPI) firmly on New Zealand’s agenda, with digital identity included among the areas of cooperation. The post Trust, credentials and Digital Public Infrastructure in focus | July Newsletter appeared first on Digital Identity New Zealand.

Kia ora Emily

What a month. Prime Minister Modi’s historic visit, the first by an Indian Prime Minister in 40 years, put digital public infrastructure (DPI) firmly on New Zealand’s agenda, with digital identity included among the areas of cooperation.

Perfect timing. Dr Pramod Varma, Chief Architect of Aadhaar and the India Stack, is confirmed to keynote our Digital Trust Hui Taumata, grounding the global DPI story in tourism, food provenance and transport use cases that matter to Aotearoa.

Our international speaker line-up keeps growing. Utah Chief Privacy Officer Christopher Bramwell will introduce State-Endorsed Digital Identity (SEDI) and explore what it means to flip the model on data ownership. Drummond Reed will also spend ten days in Aotearoa around the Hui, joining Dr Karaitiana Taiuru for the opening keynote and hosting a DINZ members-only power lunch in Auckland on Friday 7 August.

The week before, I’ll speak at the NZ CIO Innovation Summit on Know Your Agent – the next trust challenge for enterprises as AI agents begin acting on behalf of people and organisations. If Know Your Customer verifies the human, and Know Your Business verifies the business, then Know Your Agent asks: which agent is acting, for whom, with what authority, and how can that authority be revoked?

Our Digital Trust Survey 2026 is also in the field, with results to be announced first at the Hui.

Three weeks until we gather at Te Papa for Digital Trust Hui Taumata – I look forward to seeing many of you there.

Ngā mihi nui,

Andy Higgs

Executive Director,
Digital Identity New Zealand

DINZ Update

Digital Trust Survey 2026

Fieldwork is underway with our research partner Yabble for the Digital Trust Survey 2026 – the definitive read on how New Zealanders feel about digital identity, trust and control of their personal information.

Results are strictly embargoed until their release at Digital Trust Hui Taumata on 11 August. If you’re in the room you’ll be the first to hear the results.

Read more.

Drummond Reed in Aotearoa

Drummond Reed, co-author of the W3C Decentralised Identifiers standard and one of the world’s leading voices in decentralised trust, will spend ten days in Aotearoa around Digital Trust Hui Taumata.

DINZ members are invited to joing The Sovereign Stack: Keeping New Zealand Running When the World Doesn’t, a members-only power lunch with Drummond at the Northern Club in Auckland on Friday 7 August.

The conversation will explore what sovereign digital infrastructure could mean for Aotearoa, from digital identity and personhood credentials to AI, payments and data-sharing rails built on open, interoperable standards.

Register your interest.

Your ID, Your Way

Concept designs for Your ID, Your Way are now with members of the Trusted Credential Adoption Group (TCA Group) for feedback.

The initiative is designed as a single front door for trusted credential adoption in Aotearoa. Through the TCA Group, we are testing the vision, objectives and structure before collectively building out the content, use cases and adoption guidance.

If you have received the feedback survey, please take ten minutes to complete it. This is a genuinely co-created initiative.

Read more.

Industry News

Digital public infrastrucutre on our doorstep

Prime Minister Modi’s July visit brought digital public infrastructure into sharper focus for Aotearoa. India’s experience with Aadhaar, UPI and India Stack offers one of the world’s strongest examples of DPI at population scale.

For New Zealand, the opportunity is to shape the conversation on our own terms – with open standards, interoperability, privacy, governance and Māori data sovereignty built in from the start.

At our Digital Trust Hui Taumata, Dr Pramod Varma, Chief Architect of Aadhaar and the India Stack, will connect global DPI lessons with New Zealand use cases in tourism, food provenance and transport.

Read the full story.

Read the full newsletter here.

The post Trust, credentials and Digital Public Infrastructure in focus | July Newsletter appeared first on Digital Identity New Zealand.


Project VRM

How VRM+CRM Will Play Out

Nitin Badjatia has been laying out more and more reasons, and ways, that enterprises will adapt to customers, rather than the reverse. Read his work and you can start to see what the middle name of both VRM and CRM will mean in the agentic era that is upon us.  His latest three: Nobody Owns […]

Nitin Badjatia has been laying out more and more reasons, and ways, that enterprises will adapt to customers, rather than the reverse. Read his work and you can start to see what the middle name of both VRM and CRM will mean in the agentic era that is upon us.  His latest three:

Nobody Owns the Customer (16 July) On Knowledge Graphs and Context Graphs (13 July) The Customer’s Contribution in the Agentic AI Era (20 July)

From the latest:

The reason the customer contribution matters most is straightforward. The customer is the only body in the relationship that experiences the full arc of it. The organization knows what it built and why. The product knows how it is being used. Only the customer knows what any of it actually means. What they were trying to accomplish, whether they succeeded, and what they wished the enterprise had asked them about before making the decisions it made. All of that is context, and it has never been available to the enterprise on terms either party could trust.

That is about to change. Customer-side agents, operating under a trust protocol like MyTerms, will make the customer’s own account of the relationship available to the enterprise as a first-class contribution to the context layer. MyTerms provides the missing piece the industry has been circling for years. A bilateral agreement, machine-readable and enforceable, that specifies what the customer is willing to share, what the enterprise is allowed to do with it, and what the customer expects in return. With that protocol in place, the customer’s agent will share context the enterprise has never had access to at any point in the history of customer experience.

What the enterprise will receive is not another data feed. It will be a structured account of the relationship from the customer’s own perspective. Why the product was purchased. What problem it was meant to solve. Whether that problem was solved. What has changed in the customer’s circumstances since. What competing options are being considered. What the enterprise could do to strengthen its standing over time. That is a completely different order of information from anything the enterprise’s own instruments have ever produced, because it is the customer’s own account rather than the enterprise’s interpretation of behavior. The customer will have latitude, through a MyTerms contract, in the depth and breadth of the information to share with both the enterprise and the product/service.

The context also compounds in ways the enterprise-side context cannot. The customer’s agent will remember every interaction with every vendor the customer engages with. It will compare experiences across the customer’s full commercial life and surface patterns the customer might never have articulated on their own. When it shares context with the enterprise, it is offering not just what the customer knows about this relationship, but what the agent has learned across many.

But it won’t happen without MyTerms. So let’s build that out.


Digital ID for Canadians

Spotlight on Patronscan

1. What is the mission and vision of Patronscan? We create safe environments and trustworthy relationships through identity verification. 2. Why is trustworthy digital identity…

1. What is the mission and vision of Patronscan?

We create safe environments and trustworthy relationships through identity verification.

2. Why is trustworthy digital identity critical for existing and emerging markets?

Organizations increasingly need to know that an individual is who they claim to be, that the credential being presented is authentic, and that the person is authorized or eligible to complete a particular action.

This is already critical in sectors such as hospitality, gaming, retail, financial services, transportation, property management, and access control. It will become even more important as services become increasingly digital, fraud becomes more sophisticated, and interactions move between online and physical environments.

Effective identity verification reduces fraud, supports regulatory compliance, protects vulnerable and age-restricted markets, and creates confidence between organizations and the people they serve. The challenge is to deliver that trust without creating unnecessary friction or collecting more personal information than the situation requires.

Digital trust is therefore not simply a technology issue. It is a foundation for safe participation in both the digital and physical economy.

3. How will digital identity transform the Canadian and global economy? How does your organization address challenges associated with this transformation?

Trusted identity systems can make it easier and safer for people to access services, complete transactions, enter controlled environments, and demonstrate eligibility. For organizations, they can reduce fraud, automate manual processes, strengthen compliance, improve community safety, and make services more accessible and efficient.

However, this transformation must be approached responsibly. Identity verification can create new risks when systems are difficult to understand, or do not provide meaningful privacy protections and accountability.

Patronscan addresses these challenges by designing identity verification for practical, high-volume operating environments. Our platform combines document authentication, age verification, fraud detection, access-control workflows, and configurable data-management practices. We focus on helping organizations make a specific decision such as whether an ID is authentic, whether an individual meets an age requirement, or whether access should be granted, while respecting applicable privacy requirements.

We also recognize that trust cannot be created through technology alone. It requires transparency, appropriate governance, strong security, clear retention practices, and continued collaboration among technology providers, governments, regulators, businesses, and the public.

4. What role does Canada have to play as a leader in this space?

Canada has strong institutions, respected privacy and security expertise, a diverse population, and a history of collaboration between the public and private sectors. These strengths can help Canada develop approaches that balance security, privacy, accessibility, consumer choice, and commercial innovation.

Canadian leadership should include developing clear and practical trust frameworks, encouraging standards-based, supporting responsible innovation, and creating greater consistency across jurisdictions. Canada can demonstrate that strong privacy protection and effective identity verification are not competing objective, they are both essential components of a trusted economy.

By establishing trusted models domestically and aligning them with international standards, Canada can help Canadian organizations compete globally while giving individuals greater confidence in how their identities are verified and protected.

5. Why did your organization join the DIACC?

Patronscan joined the DIACC because the future of digital trust and the technology that enables it cannot be shaped by any one company, sector, or level of government.

We wanted to participate in the broader Canadian conversation about identity verification, privacy, security, and responsible innovation. DIACC brings together organizations with different experiences and perspectives, creating an important forum for developing shared frameworks and practical solutions.

As a Canadian company that has been verifying identity in high-volume, real-world environments for more than two decades, Patronscan can contribute practical insight into how trust frameworks operate at the point of service. We also benefit from learning from other DIACC members and participating in the development of approaches that can strengthen Canada’s ecosystem.

Our membership reflects our commitment to collaboration, accountability, and the continued advancement of trusted identity services in Canada and internationally.

6. What else should we know about your organization?

Patronscan is a Canadian-founded identity verification company with more than 20 years of experience helping organizations verify government-issued identification and make safer, more informed decisions.

Our technology is used across Canada and internationally in industries including hospitality, casinos, retail, events, municipalities, automotive, financial services, transportation, and controlled-access environments. Our platform supports forensic document authentication, age verification, fraud prevention, access control, operational reporting, and connected safety workflows.

What began as a solution for detecting fake identification has evolved into a broader identity verification platform supporting organizations wherever trust, eligibility, safety, and access intersect.

We are proud to be a Canadian technology company operating globally, and we believe our experience in demanding frontline environments gives us a valuable perspective on the future of digital trust. Identity verification must be accurate and secure, but it must also be fast, understandable, operationally practical, and worthy of the public’s confidence.


Spotlight on Identita

1. What is the mission and vision of Identita? Mission: To make identity protection seamless, intelligent, and human through secure biometric, credential, and location technologies.…

1. What is the mission and vision of Identita?

Mission: To make identity protection seamless, intelligent, and human through secure biometric, credential, and location technologies.

Vision: To set the global standard for trusted identity in a connected world, where security is effortless, precise, and built into everyday experiences.

2. Why is trustworthy digital identity critical for existing and emerging markets?

Access to essential services depends on identity. Identity verification reduces fraud, supports compliance, and enables cross-border commerce. The rise of AI deepfakes raises risks for KYC and remote verification

3. What role does Canada have to play as a leader in this space?

Digital trust and identity verification are becoming essential to the Canadian and global economy. As more services, transactions, and access decisions move online, organizations need reliable ways to confirm identity, reduce fraud, and protect sensitive information without creating unnecessary friction for legitimate end users. In Canada, this will support more secure banking, healthcare, government services, education, and workplace access. Globally, it will help enable safer cross-border trade, faster digital onboarding, and broader participation in the digital economy.

This shift brings real challenges. Identity systems must be strong enough to defend against increasingly sophisticated threats, while still being simple to use, respectful of privacy, and compatible with existing infrastructure. If security creates too much friction, adoption slows. If convenience comes at the expense of trust, the risk to organizations and users increases.

Identita addresses this challenge by building secure identity solutions that combine advanced biometrics, credential technologies, and real-time location intelligence in practical, familiar form factors. Our approach is to increase assurance while reducing complexity for the end user. By integrating fingerprint and ECG-based authentication with smart card platforms and RTLS technologies such as BLE, UWB, and GNSS, we help organizations verify identity with greater confidence and better context. This supports safer access, more trusted transactions, and stronger accountability across sectors including government, finance, healthcare, education, defence, gaming, automotive, and access control.

At its core, this transformation is about making trust easier to establish and harder to compromise. That is where we focus our work.

4. Why did your organization join the DIACC?

Identita joined DIACC to help shape the future of digital trust in Canada. We see a strong fit between DIACC’s work on interoperability, privacy, and trusted identity frameworks and our own focus on secure, user-friendly identity technologies.

5. What else should we know about your organization?

This is our 22nd year in business and proudly family-owned.


ResofWorld

China’s AI talent race is starting in high school

As demand for elite AI engineers outpaces supply, companies are recruiting teenagers through camps, research programs, and guaranteed job pipelines.
Yang is immensely proud of his 13-year-old son. The middle-school student from Hangzhou has won artificial intelligence model-building competitions across China, and has 136,000 followers on Chinese social media platform...

Monday, 20. July 2026

Digital Identity NZ

Your ID, Your Way: shaping trusted credential adoption in Aotearoa

Concept designs for Your ID, Your Way are now with members of the Trusted Credential Adoption Group for feedback. The initiative is being developed as a single front door for … Continue reading "Your ID, Your Way: shaping trusted credential adoption in Aotearoa" The post Your ID, Your Way: shaping trusted credential adoption in Aotearoa appeared first on Digital Identity New Zealand.

Concept designs for Your ID, Your Way are now with members of the Trusted Credential Adoption Group for feedback.

The initiative is being developed as a single front door for trusted credential adoption in Aotearoa. Its purpose is to help organisations understand what trusted credentials are, where they can create value and how adoption can proceed in ways that are secure, private and interoperable.

Trusted credentials have the potential to transform how people and organisations prove information in digital environments. They can support more efficient access to services, reduce fraud and identity misuse, and enable privacy-enhancing approaches such as selective disclosure.

Selective disclosure matters because people should not have to overshare personal information to prove something simple. In many cases, a person may only need to prove that they are eligible, authorised, qualified or entitled — not reveal every underlying detail.

For Aotearoa, trusted credential adoption also needs to be practical. Organisations need clear use cases, shared language, governance patterns and adoption guidance. They need to understand how credentials can be issued, accepted and trusted across different sectors without creating fragmentation or lock-in.

That is the role Your ID, Your Way is intended to play.

Through the Trusted Credential Adoption Group, DINZ is testing the vision, objectives and structure of the initiative before the Group collectively builds out the content, use cases and guidance needed to bring it to life.

This is deliberately a co-created initiative. DINZ’s role is not to promote a single solution, platform or vendor. It is to help steward the conditions under which a trusted, interoperable digital identity ecosystem can emerge and scale safely.

Member feedback at this stage is critical.

The current concept designs are intended to test whether the initiative is clear, useful and accessible for organisations at different stages of their trusted credential journey. Feedback will help shape the structure, language and priorities before further content is developed.

The ambition is practical adoption at scale: a trusted credential ecosystem that supports portability of skills, qualifications and authorisations; enables safer and more efficient access to services; and strengthens confidence in New Zealand’s digital economy.

If you have received the feedback survey, please take ten minutes to complete it.

Your input will help shape the next stage of a genuinely co-created initiative for Aotearoa.

The post Your ID, Your Way: shaping trusted credential adoption in Aotearoa appeared first on Digital Identity New Zealand.


Digital Trust Survey 2026: fieldwork underway

Fieldwork is underway for the Digital Trust Survey 2026, delivered with DINZ research partner Yabble. The survey will provide an important evidence base on how New Zealanders feel about digital … Continue reading "Digital Trust Survey 2026: fieldwork underway" The post Digital Trust Survey 2026: fieldwork underway appeared first on Digital Identity New Zealand.

Fieldwork is underway for the Digital Trust Survey 2026, delivered with DINZ research partner Yabble.

The survey will provide an important evidence base on how New Zealanders feel about digital identity, trust and control of their personal information. These insights matter because adoption depends on more than technical capability.

People need to understand, trust and feel agency within the systems they are being asked to use.

For organisations working in digital identity, trusted credentials, public services, financial services, health, education, workforce mobility or digital trade, this evidence base will be valuable. It will help leaders understand where confidence is strong, where concern remains and what people expect from organisations handling identity and trust.

Digital identity is becoming foundational national infrastructure. Done well, it enables people to access services more easily and securely, reduces fraud and identity misuse, and supports privacy-enhancing verification.

Done poorly, it can undermine confidence, increase risk and create new barriers.

That is why public trust must be measured, understood and designed for. Trust cannot be assumed, and it cannot be retrofitted after harm occurs. It needs to be earned through clear governance, legal alignment, transparency, privacy-enhancing design and meaningful individual agency.

The Digital Trust Survey 2026 will help the DINZ community understand how New Zealanders are thinking about these issues now.

The results will be embargoed until their exclusive release at Digital Trust Hui Taumata on 11 August. Delegates in the room at Te Papa will see them first.

For organisations planning digital identity, trusted credential or digital trust initiatives, the survey will provide valuable signals for 2027 planning and beyond.

It will also support a more informed national conversation about the future of digital identity in Aotearoa: what people trust, what they question and what needs to be in place for adoption to proceed safely and confidently.

As DINZ continues to convene stakeholders across industry, government and communities, this evidence will help ground the conversation in real public attitudes — not assumptions.


Join us at Digital Trust Hui Taumata, Te Papa Tongarewa, Wellington, 11 August 2026, for the exclusive release of the Digital Trust Survey 2026 results.

Register for Digital Trust Hui Taumata

The post Digital Trust Survey 2026: fieldwork underway appeared first on Digital Identity New Zealand.


DPI on our doorstep: what India–New Zealand digital cooperation could mean for Aotearoa

Prime Minister Narendra Modi’s visit to Auckland on 10–11 July was the first by an Indian Prime Minister to New Zealand in 40 years. While the visit carried broad significance … Continue reading "DPI on our doorstep: what India–New Zealand digital cooperation could mean for Aotearoa" The post DPI on our doorstep: what India–New Zealand digital cooperation could mean for Aotearoa appeared first o

Prime Minister Narendra Modi’s visit to Auckland on 10–11 July was the first by an Indian Prime Minister to New Zealand in 40 years. While the visit carried broad significance for trade, diplomacy and regional cooperation, the joint statement also encouraged partnerships across digital transformation, science, innovation and new and emerging technologies.

For the digital identity and trust community, this matters.

India is one of the world’s most compelling examples of what digital public infrastructure can enable at population scale. Aadhaar, UPI and India Stack have reshaped access to services, payments and trusted transactions for more than a billion people. Together, these systems show how open, reusable digital infrastructure can reduce the cost and complexity of trust across an economy.

But the lesson for Aotearoa is not simply to copy another country’s model.

New Zealand has its own legal frameworks, governance settings, Te Tiriti responsibilities and public expectations around privacy, control and trust. The opportunity is to shape digital public infrastructure on our own terms: with open standards, interoperability, privacy-enhancing verification and Māori data sovereignty built in from the start.

That is why this year’s Digital Trust Hui Taumata is so timely.

Dr Pramod Varma, Chief Architect of Aadhaar and India Stack, and co-founder of Networks for Humanity, will deliver a virtual keynote at the Hui. His session will connect population-scale, protocol-first infrastructure with practical use cases that matter for New Zealand.

In tourism, reusable visitor credentials could support more seamless and trusted journeys while reducing repeated identity checks. In food and primary industries, verifiable provenance could help exporters demonstrate origin, quality and compliance across decentralised supply chains. In transport, trusted driver, vehicle and passenger credentials could make everyday trust problems more visible and more solvable.

These are not abstract technology questions. They go directly to how people, organisations and government agencies establish trust in digital environments.

For DINZ, the core principles remain clear: secure, private and interoperable. Digital identity should not become a new source of lock-in, surveillance or exclusion. Done well, it should allow people to prove only what is necessary, without oversharing personal information. It should strengthen individual agency, reduce fraud and identity misuse, and support safer access to services.

The international context is shifting quickly. Digital identity, trusted credentials and digital public infrastructure are becoming strategic national capabilities. Countries are asking not only what services can be digitised, but who controls the rails, what standards apply, how assurance is managed and how individual rights are protected.

Aotearoa has a chance to bring a distinctive perspective to that conversation.

Our trust settings must reflect more than technical efficiency. They must also reflect honourable governance, self-determination, equity, partnership and shared benefit. In practice, that means bringing together technology, law, policy, tikanga-informed governance and real-world adoption.

At Digital Trust Hui Taumata, we will explore what this means for New Zealand now. The programme brings together global trust architecture, Indigenous rights, AI-agent identity, verifiable credentials and adoption pathways across sectors.

The question is no longer whether the digital public infrastructure conversation will reach New Zealand. It already has.

The question is whether we shape it with trust by design.

Join us at Digital Trust Hui Taumata, Te Papa Tongarewa, Wellington, 11 August 2026.

Register for Digital Trust Hui Taumata

The post DPI on our doorstep: what India–New Zealand digital cooperation could mean for Aotearoa appeared first on Digital Identity New Zealand.


ResofWorld

AI is shrinking video game development teams to one

AI is helping solo developers thrive in Turkey’s gaming industry, but writers, artists, and junior programmers are being left behind.
As a teen, Emirhan Gül was a keen gamer, so he was thrilled to join a gaming startup in Istanbul as a developer after university. Over five months, as Turkey...

Friday, 17. July 2026

OpenID

Public Review Period for Proposed OpenID Connect Ephemeral Subject Identifier 1.0 Final Specification

The OpenID Connect Working Group recommends approval of the following specification as an OpenID Final Specification: OpenID Connect Ephemeral Subject Identifier 1.0   A Final Specification provides intellectual property protections to implementers of the specification and is not subject to further revision. This note starts the 60-day public review period for the specification draf

The OpenID Connect Working Group recommends approval of the following specification as an OpenID Final Specification:

OpenID Connect Ephemeral Subject Identifier 1.0

 

A Final Specification provides intellectual property protections to implementers of the specification and is not subject to further revision. This note starts the 60-day public review period for the specification draft in accordance with the OpenID Foundation IPR policies and procedures. Unless issues are identified during the review that the working group believes must be addressed by revising the draft, this review period will be followed by a fourteen-day voting period during which OpenID Foundation members will vote on whether to approve this draft as an OpenID Final Specification.

 

The relevant dates are:

Final Specification public review period: Friday, July 17, 2026 to Tuesday, September 15, 2026 (60 days) Final Specification vote announcement: Wednesday, September 2, 2026 (14 days prior to voting) Final Specification voting period: Wednesday, September 16, 2026 to Wednesday, September 30, 2026 (14 days)

 

The OpenID Connect working group page is https://openid.net/wg/connect/. Information on joining the OpenID Foundation can be found at https://openid.net/foundation/members/registration. If you’re not a current OpenID Foundation member, please consider joining to participate in the approval vote.

You can send feedback on the specifications in a way that enables the working group to act upon it by (1) signing the contribution agreement at https://openid.net/intellectual-property/ to join the working group, (2) joining the working group mailing list at https://lists.openid.net/mailman/listinfo/openid-specs-ab, and (3) sending your feedback to the list. 

Marie Jordan – OpenID Foundation Board Secretary

 

About The OpenID Foundation (OIDF)

The OpenID Foundation (OIDF) is a global open standards body committed to helping people assert their identity wherever they choose. Founded in 2007, we are a community of technical experts leading the creation of open identity standards that are secure, interoperable, and privacy preserving. The Foundation’s OpenID Connect standard is now used by billions of people across millions of applications. In the last five years, the Financial Grade API has become the standard of choice for Open Banking and Open Data implementations, allowing people to access and share data across entities. Today, the OpenID Foundation’s standards are the connective tissue to enable people to assert their identity and access their data at scale, the scale of the internet, enabling “networks of networks” to interoperate globally. Individuals, companies, governments and non-profits are encouraged to join or participate. Find out more at openid.net.



The post Public Review Period for Proposed OpenID Connect Ephemeral Subject Identifier 1.0 Final Specification first appeared on OpenID Foundation.


FIDO Alliance

RSA and the FIDO Alliance Champion the Enterprise Passkey Revolution

In this joint briefing, RSA Security’s Jim Taylor and the FIDO Alliance’s Andrew Shikiar detailed the global transition away from legacy passwords toward robust, phishing-resistant authentication methods. Andrew highlighted the explosive growth of consumer passkeys, noting […]

In this joint briefing, RSA Security’s Jim Taylor and the FIDO Alliance’s Andrew Shikiar detailed the global transition away from legacy passwords toward robust, phishing-resistant authentication methods. Andrew highlighted the explosive growth of consumer passkeys, noting that over 5 billion passkeys are currently in active use across the globe since FIDO began its market-enablement mission in 2013. However, both experts agreed that consumer adoption is vastly outpacing enterprise deployment, revealing a massive market opportunity for channel partners and MSPs to guide corporate clients through the transition. To illustrate enterprise viability, Jim revealed that RSA has successfully migrated roughly 98% to 99% of its own corporate workforce to a completely passwordless architecture. He noted that common deployment hurdles stem from human behavioral factors and corporate change management rather than underlying technical limitations.


OpenAI Will Gate Its Most Capable Cyber Models Behind a Physical Security Key

Access to OpenAI’s most cyber-capable AI models will soon require something no phishing email can steal: a physical security key tapped against a phone or plugged into a laptop. From […]

Access to OpenAI’s most cyber-capable AI models will soon require something no phishing email can steal: a physical security key tapped against a phone or plugged into a laptop.

From September 1, individual members of the company’s Trusted Access for Cyber program must switch on OpenAI’s Advanced Account Security feature using a hardware-backed passkey, or fall back to default model access. The program gives vetted security researchers and organisations elevated access to advanced AI capabilities for authorised defensive work, spanning vulnerability triage and validation, malware analysis, detection engineering, and patch validation, and OpenAI is tightening restrictions on high-risk entities and jurisdictions as part of the same push against misuse.

A hardware-backed passkey lives in a physical key rather than syncing through software or the cloud, so the credential cannot be copied or extracted remotely. It also checks that the site asking for a login is the real one before authenticating, which defeats phishing and adversary-in-the-middle attacks, where a fraudulent page sits between the user and the genuine service. Enabling Advanced Account Security also lets users switch off the weaker fallback login methods that attackers otherwise target.

Yubico is supplying the hardware side, offering OpenAI account holders a custom two-pack at preferred pricing: a USB-C YubiKey that authenticates on phones and tablets with a tap over near-field communication, and a low-profile key that stays in a laptop port. OpenAI already uses YubiKeys internally to protect its own staff and infrastructure. “We are introducing a new model for phishing-resistant security at scale for the AI ecosystem,” said Jerrod Chong, chief executive of Yubico.

The move deepens OpenAI’s turn toward the authentication world it increasingly depends on. The company recently joined the FIDO Alliance to help shape how phones authenticate AI agents, and the credentials it is now mandating ride a wave of mainstream adoption, with the FIDO Alliance counting three billion passkeys in use.

For the vetted researchers involved, the calculus is simple: a credential that cannot be phished, copied, or synchronised makes a compromised account far harder and more expensive to create, validate, and resell, raising the cost of the most obvious way into a program built around trusted access to sensitive capability.


ResofWorld

Can AI beat a goldfish at calling the World Cup?

As chatbots compete to forecast the tournament, an unlikely rival from a Toronto fish tank continues to outperform them.
Kylian Mbappé of France entered the World Cup semifinals with Argentina’s Lionel Messi in the race for the Golden Boot. Pundits, punters, and chatbots are divided on who finishes as...

Thursday, 16. July 2026

Oasis Open

Invitation to comment on Akoma Ntoso v2.0 Part 2 (AKN 3.1) before call for consent as OASIS Standard

OASIS and the OASIS LegalDocumentML (LegalDocML) TC [1] are pleased to announce that Akoma Ntoso Version 2.0. Part 2: Specifications of AKN 3.1 CS01 is now available for public review and comment before a call for consent as OASIS Standard. Akoma Ntoso defines an XML vocabulary for parliamentary, legislative, and judicial documents, enabling machine-readable exchange […] The post Invitation to c

Public Review Ends - September 15th

OASIS and the OASIS LegalDocumentML (LegalDocML) TC [1] are pleased to announce that Akoma Ntoso Version 2.0. Part 2: Specifications of AKN 3.1 CS01 is now available for public review and comment before a call for consent as OASIS Standard.

Akoma Ntoso defines an XML vocabulary for parliamentary, legislative, and judicial documents, enabling machine-readable exchange of legal texts across institutions and jurisdictions. Part 2 specifies the AKN 3.1 XML schema and its documentation.

The TC received six Statements of Use from the Publications Office of the European Union, The National Archives (UK), Xcential Corporation, BitNomos, CIRSFID-ALMA-AI (University of Bologna), and the World Health Organization [3].

The candidate specification and related files are available here:

Akoma Ntoso Version 2.0. Part 2: Specifications of AKN 3.1
Committee Specification 01, 8 May 2026

https://docs.oasis-open.org/legaldocml/akn-core/v2.0/cs01/part2-specs/akn-core-v2.0-cs01-part2-specs.pdf
https://docs.oasis-open.org/legaldocml/akn-core/v2.0/cs01/part2-specs/akn-core-v2.0-cs01-part2-specs.zip (complete package)
XML schemas: https://docs.oasis-open.org/legaldocml/akn-core/v2.0/cs01/part2-specs/schemas/
Namespace document: https://docs.oasis-open.org/legaldocml/akn-core/v2.0/cs01/akn-core-v2.0-namespace.html

Associated files can be found at: https://docs.oasis-open.org/legaldocml/akn-core/v2.0/cs01/

Members of the LegalDocML TC [1] approved this specification by Special Majority Vote [2]. The specification had been released for public review as required by the TC Process.

Public Review Period

The 60-day public review is now open and ends 15 September 2026 at 23:59 UTC.

This is an open invitation to comment. OASIS solicits feedback from potential users, developers and others, whether OASIS members or not, for the sake of improving the interoperability and quality of its technical work.

Comments may be submitted to the project by any person through the use of the project’s Comment Facility. Members of the TC should submit feedback directly to the TC’s members-only mailing list. All others should submit comments through the Comment Facility: https://groups.oasis-open.org/communities/community-home?CommunityKey=d1abbfff-8f23-4756-87f6-018f5aa7e2f0

Comments submitted by non-members for this work product are publicly archived and can be viewed by using the link above and clicking on the “Discussions” tab. Please note that you must log in or create a free account to see the material. Comments submitted by any other means cannot be accepted.

All comments submitted to OASIS are subject to the OASIS Feedback License, which ensures that the feedback you provide carries the same obligations at least as the obligations of the TC members. In connection with this public review we call your attention to the OASIS IPR Policy [4] applicable especially [5] to the work of this technical committee. All members of the TC should be familiar with this document, which may create obligations regarding the disclosure and availability of a member’s patent, copyright, trademark and license rights that read on an approved OASIS specification.

OASIS invites any persons who know of any such claims to disclose these if they may be essential to the implementation of the above specification, so that notice of them may be posted to the notice page for this TC’s work.

Additional references:

[1] OASIS LegalDocumentML (LegalDocML) TC
groups.oasis-open.org/communities/…
[2] Approval ballot: groups.oasis-open.org/higherlogic/ws/public/…
[3] Statements of Use: groups.oasis-open.org/higherlogic/ws/groups/…
[4] www.oasis-open.org/policies-guidelines/ipr
[5] www.oasis-open.org/committees/legaldocml/ipr.php

The post Invitation to comment on Akoma Ntoso v2.0 Part 2 (AKN 3.1) before call for consent as OASIS Standard appeared first on OASIS Open.


EdgeSecure

Still on the Clock: ADA Title II Compliance and the Policy Gap in Higher Ed

The post Still on the Clock: ADA Title II Compliance and the Policy Gap in Higher Ed appeared first on Edge, the Nation's Nonprofit Technology Consortium.

DIF Blog

DIF Newsletter #63

July 2026 DIF Website | DIF Mailing Lists | Meeting Recording Archive Table of contents Decentralized Identity Foundation News Ask Me Anything with Grace-zel Upcoming Events Get involved! Join DIF Decentralized Identity Foundation News Our monthly newsletter is taking a short summer break, but DIF certainly isn't. Between conferences,

July 2026

DIF Website | DIF Mailing Lists | Meeting Recording Archive

Table of contents Decentralized Identity Foundation News Ask Me Anything with Grace-zel Upcoming Events Get involved! Join DIF

Decentralized Identity Foundation News

Our monthly newsletter is taking a short summer break, but DIF certainly isn't.

Between conferences, standards meetings, blog releases, and community events, it's been an active few months for the community. Rather than our usual Working Group roundup, we thought we'd use this space to introduce someone many of you have come to know over the past six months: our Operations Manager, Grace-zel Luis.

Our regular newsletter will return in August with updates from across DIF's Working Groups, community initiatives, and recent developments. Until then, we hope you enjoy getting to know one of the people helping keep DIF running behind the scenes.

In the meantime, here are a few things happening around DIF:

DIDComm update: DIDComm research is out! Read the full blog DIDComm update 2: In-person meeting at IETF. Contact Juan or Grace to get details of the DIDComm breakfast on July 22 in Vienna. KYA-OS 1.0 has passed Steering Committee approval. Look out for a blog post with updates. Link to the specification

If you need to feed your DIF update addiction, find out the inside scoop of what it's like to work at DIF. Before heading out on vacation, Grace caught up with our Operations Manager, Grace-zel, who spills the tea on what it's like working with DIF and the DIF ED!

Ask Me Anything with Grace-zel!

Grace:
Hi Grace-zel, thanks for taking this interview with me. I think the first thing people want to know at DIF is how you see your role. You've been here for six months now, so you've got a pretty good grasp of the job. 

Grace: What are the areas of expertise that you bring to the role as you now understand it?

Grace-zel:
One of the strengths I bring to this role is organizing complex projects and thinking through how to move them forward in a structured way while making sure deliverables are completed on time. A big part of my work is also communication and coordination—keeping everyone informed, making sure the right people are involved, and helping teams stay aligned and accountable.

Over the past six months, these have been the skills I've relied on the most. I've also had to adapt to an industry that is far more specialized than anything I've worked in before. My background is in marketing, so stepping into the world of decentralized identity and technical standards has been a completely different experience. I still have a lot to learn about the technical aspects of this field, but I've found that the operational and organizational skills I've developed over the years are highly transferable and have allowed me to accomplish our operational goals in DIF!

Grace:
What should the Working Groups expect from you as they go forward?

Grace-zel:
I hope that, over time, the Working Groups will see me as the first person they can rely on, not just for coordinating meetings, but for helping manage their projects from an operational perspective.

I'd like to understand the bigger picture of what each Working Group is trying to accomplish so I can contribute beyond logistics, but to streamline processes and develop consistent procedures. My goal is to create an environment where members feel guided and supported, allowing them to focus on the technical work and collaborate more effectively.

Grace:
We've been working together for several years now. What do you see has changed in your job approach over these years? 

Grace-zel:
When I first worked with Grace as her Office Manager, my role was largely focused on execution by making sure the tasks she assigned were completed accurately and on time. There were also many situations where I had to figure things out on my own, and that experience became valuable preparation for transitioning into my current role as Operations Manager at DIF.

Working with Grace has encouraged me to look beyond what's immediately in front of me and think more strategically. I now find myself asking, "How can I make this easier for me and for the team?" That means she doesn’t need to assign me work, because I can define my job requirements and objectives.  Often Grace just gives her constructive feedback on my proposals and solutions, rather than coming up with the ideas herself. 

Being proactive and accountable has always been part of how I work, even before working with Grace. What has changed the most is my confidence in leading projects and taking ownership of them. I've become much more comfortable making decisions, recommending improvements, and seeing projects through from planning to execution.

I think that's one of the things I treasure the most about working with Grace is that she's set up an environment that encourages curiosity, continuous learning, and never seemed to doubt that I could take on challenges, even in areas that are not in my expertise.

Grace:
When you first looked at the DIF website, what was your initial reaction? Was it overwhelming to think that you'd be dealing with such technical topics? 

Grace-zel:
My first reaction was honestly, "Wow, this is a completely different world." I remember asking myself, "Am I the right fit?" and "How can I contribute when everyone is talking about things I've never encountered before?"

The website was full of technical terminology, specifications, working groups, and acronyms that were completely new to me. It was soooooo overwhelming,  even now!

As I spent more time at DIF, I realized that what makes this community special isn't just the technology. It's the people behind it. I came to appreciate that many people here are motivated not only by the work they're doing today, but by the long-term impact it can have on the Internet and the digital identity ecosystem. I have come to accept that I don’t need to fully understand all of what the technical people are talking about to understand the implications of the work. This is the part I need to learn so I can build systems that will and what you know but behind how you work for our community.

It feels humbling and inspiring because you guys are doing the hard work here even if you are solving problems that may not have immediate or visible results. My role is different from yours, but it is rewarding to know that I have managed to continue what has been built in the operations to support the DIF community and strive for better systems with Grace and Juan's guidance.

Grace:
What are some of the most interesting things you have learned so far in the role? 

Grace-zel:
One of the most interesting things I've learned so far has been rebuilding DIF's membership sequence using the CRM system in Zoho One.

I've always enjoyed creating automations and improving workflows, but this was my first time working extensively with the Zoho ecosystem. It was fascinating to discover how the different apps connect with one another and how much can be accomplished in just one system.

I can’t wait to build more automations for DIF! 

Grace:
What is the hardest thing about working with me? 

Grace-zel:
Grace has a way of asking questions that push me to think more deeply about a problem instead of settling for the most obvious solution. Sometimes I'll think I've already figured something out, and then you’ll ask one question that makes me realize there's another perspective I hadn't considered. It can be challenging, especially when I feel confident in my initial approach, but it's also one of the biggest reasons I've grown professionally. Looking back, those hard moments challenged me to go one step further and it benefited all through the years! Those brain cells had to work! 😂

Another thing is when she is out and traveling, she gets frustrated easily even when in reality things are handled. She likes to stay on top of everything, even while she's constantly moving between airports, conferences, and time zones. Sometimes she'll check in before I've even had the chance to send an update! We are constantly improving our communication, and I think that's how we've made it work over the years.


Grace:
What is your favorite thing about working with me?

Grace-zel:
One of my favorite things about working with Grace is that she knows when to be a mentor and when to be a friend.

As a mentor, she challenges me to think differently, pushes me outside my comfort zone, and trusts me with heavier responsibilities. At the same time, she's also someone I can have genuine conversations with outside of work and that balance has created a working relationship built on trust rather than hierarchy.

I think that combination is rare nowadays, and it's one of the reasons we've been able to work together for years. If there's one thing that has kept our working relationship strong, it's our honesty with each other. We can have difficult conversations, give constructive feedback, and move forward without taking things personally. 

Grace:
What goals have you set for yourself in this role in 2026? Do you think you'll want to learn to code some day? Why or why not? 

Grace-zel:
One of my biggest goals in 2026 has been to understand DIF and how our community works.

As of today, my focus has been on learning how our operations work by first understanding the existing processes and why they were built that way. As time goes by, I'm beginning to identify areas that could be improved and other opportunities where we can build new systems to better support the community.

That learning process is still ongoing, but once I feel more confident in my understanding of our operations, my next goal is to spend more time learning how our Working Groups collaborate, how our members communicate, and what matters most to them before introducing new processes or improvements.

For me, it's important to understand the people and the culture before trying to improve the systems that support them.

Grace:
What are the advantages and disadvantages of being a perfectionist as it relates to this role?

Grace-zel:
Am I really a perfectionist, Grace? 😂

The advantage is that I know things will get done, and they'll be done to the best of my ability. I am used to paying close attention to details and it gives me confidence that I'm delivering work I can stand behind.

The downside is that perfectionism usually slows me down! It's something I'm still learning to balance. I've realized that progress is often more valuable than perfection, especially in an environment like DIF, where systems, standards, and processes continue to evolve.

I think I was worried about how you would see me and whether my answers would truly reflect who I am. It can be intimidating to work alongside people with the level of knowledge and expertise that many of you have.

That said, I haven't had a single bad experience so far. Everyone I've met in the DIF community has been incredibly kind and welcoming, which has made it much easier to find my place here.

So, to finish this AMA, I decided to simply be honest and share my real thoughts. Hopefully this gives you a better idea of who Grace-zel is beyond the Operations Manager title.

📢 Upcoming Events

IETF 2026
📅 July 18-24, 2026
📍 Vienna, Austria
Event information

GDC 2026
📅 September 1-3, 2026
📍 Geneva, Switzerland
Event information
Tickets

Identity Week America
📅 September 2-3, 2026
📍 Washington, DC
Event information

👉 Are you a DIF member with news to share? Email us at @identity.foundation with details.

🆔 Join DIF!

If you would like to get in touch with us or become a member of the DIF community, please visit our website or follow our channels:

Follow us on Twitter/X

Join us on GitHub

Subscribe on YouTube

🔍

Read the DIF blog

New Member Orientations

If you are new to DIF join us for our upcoming new member orientations. Find more information on DIF’s Slack or contact us at community@identity.foundation if you need more information.


Oasis Open

Invitation to comment on KMIP Usage Guide v3.0 – ends 15 August 2026

OASIS and the KMIP TC are pleased to announce that the Key Management Interoperability Protocol Usage Guide Version 3.0 is now available for public review and comment. The post Invitation to comment on KMIP Usage Guide v3.0 – ends 15 August 2026 appeared first on OASIS Open.

OASIS and the KMIP TC are pleased to announce that the Key Management Interoperability Protocol Usage Guide Version 3.0 is now available for public review and comment.

The Usage Guide is a Committee Note for developers and architects designing systems and applications that interoperate using the KMIP specification. It explains the assumptions behind the protocol and describes how KMIP functionality is used in practice, giving implementers guidance to use alongside the specification. This is the first public review of the Usage Guide at Version 3.0.

The document and all related files are available here:

Key Management Interoperability Protocol Usage Guide Version 3.0
Committee Note Draft 01
18 June 2026

Editable Source: https://docs.oasis-open.org/kmip/kmip-ug/v3.0/cnd01/kmip-ug-v3.0-cnd01.docx (Authoritative)

HTML: https://docs.oasis-open.org/kmip/kmip-ug/v3.0/cnd01/kmip-ug-v3.0-cnd01.html

PDF: https://docs.oasis-open.org/kmip/kmip-ug/v3.0/cnd01/kmip-ug-v3.0-cnd01.pdf

ZIP (complete package): https://docs.oasis-open.org/kmip/kmip-ug/v3.0/cnd01/kmip-ug-v3.0-cnd01.zip

How to Provide Feedback

The public review is now open and ends 15 August 2026 at 23:59 UTC.

Comments from TC members should be sent to the TC’s mailing list. Comments may be submitted by any other person through the project’s Comment Facility: https://groups.oasis-open.org/communities/community-home?CommunityKey=2b5e5c66-cc41-4aa5-92ee-018f5aa7dfc4

Comments submitted by non-members for this work product are publicly archived and can be viewed by using the link above and clicking on the “Discussions” tab. Please note that you must log in or create a free account to see the material. Comments submitted by any other means cannot be accepted.

Please contact the TC Administrator (tc-admin@oasis-open.org) with any questions on how to submit a comment.

All comments submitted to OASIS are subject to the OASIS Feedback License, which ensures that the feedback you provide carries the same obligations at least as the obligations of the TC members. In connection with this public review, we call your attention to the OASIS IPR Policy applicable especially to the work of this technical committee. All members of the TC should be familiar with this document, which may create obligations regarding the disclosure and availability of a member’s patent, copyright, trademark and license rights that read on an approved OASIS specification.

OASIS invites any persons who know of any such claims to disclose these if they may be essential to the implementation of the above specification, so that notice of them may be posted to the notice page for this TC’s work.

TC public home page: https://www.oasis-open.org/committees/kmip/

Additional references:
OASIS IPR Policy: https://www.oasis-open.org/policies-guidelines/ipr/
KMIP TC IPR Policy page: https://www.oasis-open.org/committees/kmip/ipr.php

The post Invitation to comment on KMIP Usage Guide v3.0 – ends 15 August 2026 appeared first on OASIS Open.


ResofWorld

The problem AI content moderation cannot solve

Meta and other big tech companies are increasingly using AI for content moderation, but as the backlash to Muse Image shows, it cannot protect users because it does not account for consent.
Meta recently unveiled Muse Image, an artificial intelligence image generator that allows anyone to manipulate pictures of any Instagram user with a public profile. Just as its Meta glasses —...

Wednesday, 15. July 2026

FIDO Alliance

Biometric Update: Microsoft and Google push passkeys deeper into workplace authentication

Microsoft and Google are pushing passkeys and hardware security keys deeper into workplace authentication, with Microsoft preparing to make passkeys the default authentication experience in Entra ID, and Google adding FIDO2-compliant […]

Microsoft and Google are pushing passkeys and hardware security keys deeper into workplace authentication, with Microsoft preparing to make passkeys the default authentication experience in Entra ID, and Google adding FIDO2-compliant security keys as a second factor in the Windows login process for Google Workspace users.

The announcements, both made Monday, represent different but related steps in the technology industry’s effort to move organizations away from passwords, texted verification codes, and other credentials that can be stolen, intercepted, or surrendered to a convincing phishing site.


Oasis Open

OASIS Approves Two Public-Key Cryptography Standards to Advance Post-Quantum Security and Interoperability

Boston, MA – 15 July 2026 – OASIS Open, the international open source and standards consortium, announced that PKCS #11 Specification Version 3.2 and PKCS #11 Profiles Version 3.2 have been approved as OASIS Standards. This milestone reflects the highest level of ratification and strengthens the widely deployed Cryptoki (cryptographic token interface) API, which underpins […] The post OASIS Appr

Cryptsoft, Entrust, IBM, Oracle, Red Hat, and Others Strengthen Security Across Cloud and Hardware Environments

Boston, MA – 15 July 2026 – OASIS Open, the international open source and standards consortium, announced that PKCS #11 Specification Version 3.2 and PKCS #11 Profiles Version 3.2 have been approved as OASIS Standards. This milestone reflects the highest level of ratification and strengthens the widely deployed Cryptoki (cryptographic token interface) API, which underpins hardware security modules (HSMs), smart cards, and certificate authority systems worldwide.

As organizations face escalating cyber threats alongside the anticipated impact of quantum computing, the PKCS #11 Specification Version 3.2 introduces support for post-quantum cryptographic (PQC) mechanisms along with extended interface capabilities and improved vendor extensions. PKCS #11 Profiles Version 3.2 defines the conformance clauses necessary for consistent, interoperable implementations across vendors and deployment environments.

The OASIS PKCS #11 Technical Committee (TC) said, “Version 3.2 delivers a stronger, cleaner Cryptoki interface and gives implementers a clear, interoperable foundation for addressing emerging threats while maintaining compatibility with existing security infrastructure. As the cryptographic landscape shifts, PKCS #11 remains the stable core that real-world deployments depend on.”

The PKCS #11 TC encourages global collaboration and actively seeks input from stakeholders to ensure the success of PKCS #11 as a cornerstone for cryptographic services. The TC welcomes a diverse range of contributors, including architects, designers and implementers. Participation is open to all through OASIS membership; interested parties are encouraged to join and help shape the future of cryptographic interoperability and post-quantum security. Contact join@oasis-open.org for more information. 

PKCS #11 is already embedded in the security infrastructure of organizations worldwide. Version 3.2 builds on that proven foundation, giving implementers and vendors a clear path to post-quantum readiness without disrupting existing deployments. The updated files are available in the library as freely accessible OASIS Standards.

Support for PKCS #11 

IBM
“IBM has adopted the PKCS#11 v3.2 standard offering exciting new features to protect against quantum computing attacks. API users can leverage openCryptoki, an IBM supported open-source project, which now includes PQC algorithm support with version 3.27.”
– Joe Livingston, IBM, EP11 SW Dev. Engineer, Project Lead

Entrust
“PKCS #11 provides an important contribution to the security industry by enabling developers to leverage trusted cryptographic implementations. With post quantum computing close on the horizon, standards-based access to secure cryptography has never been more important. Entrust has long supported open standards, supporting PKCS #11 since launching its first nShield HSM in 1998. We value its seamless integration between HSMs and applications and are pleased to support the ratification of PKCS #11 version 3.2.”
– Hamish Cameron, Senior Manager Software Development, Entrust, Data Protection Solutions

About OASIS Open
One of the most respected, nonprofit open source and open standards bodies in the world, OASIS advances the fair, transparent development of open source software and standards through the power of global collaboration and community. OASIS is the home for worldwide standards in AI, emergency management, identity, IoT, cybersecurity, blockchain, privacy, cryptography, cloud computing, urban mobility, and other content technologies. Many OASIS standards go on to be ratified by de jure bodies and referenced in international policies and government procurement. www.oasis-open.org

Media Inquiries: 
communications@oasis-open.org

The post OASIS Approves Two Public-Key Cryptography Standards to Advance Post-Quantum Security and Interoperability appeared first on OASIS Open.


ResofWorld

AI powers citizen-led disaster relief from afar for Venezuela

After the earthquakes, developers and citizens used AI to build websites and apps to help locate missing persons and coordinate relief efforts amid a slow government response.
After twin earthquakes struck northern Venezuela last month, thousands of people took to social media, pleading for help locating friends and family. The interim government was slow to act, but...

OpenID

How we got here: what six decades of identity history tell us about the agent age

By Sar Haidar, Platform Engineer at MIT Open Learning  Every identity standard we work with today was built to solve a problem someone was staring at right then. OAuth, OIDC, SAML, the token flows we spend our careers refining: each one began as an urgent answer to an immediate question. That was the premise of […] The post How we got here: what six decades of identity history tell us about

By Sar Haidar, Platform Engineer at MIT Open Learning 

Every identity standard we work with today was built to solve a problem someone was staring at right then. OAuth, OIDC, SAML, the token flows we spend our careers refining: each one began as an urgent answer to an immediate question. That was the premise of a talk I gave at Identiverse earlier this year, and it’s worth restating for anyone thinking about where identity goes next. We have never once designed the whole system on purpose. We’ve patched it, one urgent problem at a time, for sixty years. Understanding that pattern is the best tool we have for seeing where the next patch is headed.

The pattern, compressed

It starts in 1961, when MIT’s Compatible Time Sharing System let multiple people use one computer at once for one of the first times, and immediately raised a question nobody had faced before: how does a machine know whose files are whose? Fernando Corbató’s answer was the password. Within a year, a grad student named Allan Scherr printed the password file and logged in as other users to get more compute time. Often cited as the first recorded credential theft, and the industry’s response set the template for everything that followed: protect the secret better, and never question whether a shared secret was the model to build on in the first place.

That pattern repeats at every scale change. Hashing and salting (Morris and Thompson, 1979) made stolen passwords harder to use, but didn’t touch the underlying assumption. Kerberos (MIT’s Project Athena, mid-1980s) solved authentication across a campus of networked workstations. It was brilliant inside one trust boundary, and blind to anything outside it. The 1988 Morris worm exposed what happens when a network built on personal trust between colleagues quietly becomes a city of strangers. X.500 tried to answer with one universal global directory and collapsed under its own complexity; LDAP won by being good enough to ship. Cookies solved a real, narrow problem for Netscape in 1994, since stateless HTTP couldn’t recognize a returning visitor, and became the infrastructure of surveillance advertising almost by accident.

By the turn of the century the problem had a new name: fragmentation at global scale. A single centralised identity provider, an approach Microsoft tried early with Passport (1999), failed because no one would hand one company the keys to everyone’s identity. SAML (2001 to 2002) worked beautifully for institutions that already trusted each other and was useless for strangers. OpenID (2005) proposed the most philosophically honest answer, your own URL as your identity, no gatekeeper, and almost nobody used it, because typing a URL to log in was too much friction. The federation question never got a clean answer; it got outsourced instead. First informally, through OAuth powered social login, where three or four companies now vouch for most of the consumer web, and then as a service, through a new generation of identity vendors. Then the smartphone, with Touch ID and Face ID, quietly erased the line between being authenticated and just being yourself.

What stuck with the room

The talk closes on the current inflection point: AI agents, and an identity stack that was never built for a world where the “user” making a call might not be a human at all, where nobody yet agrees on the ratio of non-human identities to human ones, let alone who’s accountable when an autonomous call misfires.

But that’s not what people brought up afterward. In the conversations that followed the session, the recurring comment was about the choice to tell sixty years of identity history as a plain, human narrative rather than a stack of acronyms and protocol names. People said they appreciated the non-technical framing, the sense that each of these standards was invented by someone solving a very immediate, very human problem, often without any idea of what it would become decades later. That feedback is worth sitting with. Our field is fluent in discussing identity as a technical problem. We get far less practice discussing it as a human one, and the agent era is about to make that second fluency just as necessary as the first.

Why this matters for OIDF’s work right now

This isn’t an abstract concern. It’s the exact gap the OpenID Foundation’s Artificial Intelligence Identity Management (AIIM) Community Group was stood up to address: the silos between the AI and identity communities, and the risk that hard won lessons about security, privacy, and interoperability get relearned the hard way inside agentic systems instead of applied from the start. The Foundation’s 2025 whitepaper on agentic AI identity, and the ongoing work on On Behalf Of (OBO) token exchange, are direct responses to the same question the talk raises: when an agent acts, whose authority is it acting under, and how do we preserve accountability through multiple hops of delegation rather than falling back to raw impersonation or static API keys? Phil Windley’s work on authorized trajectories, the idea that just in time credentials alone may not be enough and that we may need to reason about an agent’s whole intended path of action, points at the same open question from a different angle.

The historical pattern suggests we’ll solve the technical version of this problem the way we always have: well, and just in time. The harder task, the one the audience kept circling back to, is holding onto the human part alongside it: that an agent acting in your name is a statistical model predicting your next move, useful, but not you. That distinction isn’t a footnote to the standards work. It’s the reason the standards work matters.

About the author: Sar is a Platform Engineer at MIT Open Learning, where he builds systems that make learning accessible at scale. He’s also the creator of SyntheticAuth.ai, where he writes about identity and AI with a mix of technical depth and skepticism. He’s an active open-source contributor who believes the systems that govern trust should be transparent and collaborative.

This post is based on a session delivered at Identiverse 2026 (Mandalay Bay, Las Vegas, June 16) titled “How We Got Here: The Story Behind Your Identity Stack and the Assumptions We Must Leave Behind.”

About the OpenID Foundation

The OpenID Foundation (OIDF) is a global open standards body committed to building trusted identity ecosystems. Our mission is to lead the global community in identity standards that are secure, interoperable, and privacy respecting. Founded in 2007, we are a community of technical experts. The Foundation’s OpenID Connect standard is now used by billions of people across millions of applications. More recently, the FAPI security profile – built on OAuth 2.0 – has become the standard of choice for interoperable Open Banking and Open Data implementations, while OpenID for Verifiable Credentials specifications are underpinning a new generation of digital wallets. Today, the OpenID Foundation’s standards are the connective tissue that enable people to assert their identity and access their data at scale, the scale of the internet, enabling “networks of networks” to interoperate globally. Individuals, companies, governments and non-profits are encouraged to join or participate. Find out more at openid.net.

 

The post How we got here: what six decades of identity history tell us about the agent age first appeared on OpenID Foundation.


Next Level Supply Chain Podcast with GS1

Supply Chain 2050: AI, Robotics, and Trust in the Physical World

Supply chain transformation is no longer just about efficiency. It is about resilience, intelligence, and trust across every layer of the system. In this episode, Reid Jackson and Liz Sertl were at GS1 Connect. Melanie Hilton sat down with Miguel Rodriguez Garcia from MIT, Frederik Bohn from Plug and Play Tech Center, and Lisa Morales-Hellebo from REFASHIOND Ventures to explore what supply

Supply chain transformation is no longer just about efficiency. It is about resilience, intelligence, and trust across every layer of the system.

In this episode, Reid Jackson and Liz Sertl were at GS1 Connect. Melanie Hilton sat down with Miguel Rodriguez Garcia from MIT, Frederik Bohn from Plug and Play Tech Center, and Lisa Morales-Hellebo from REFASHIOND Ventures to explore what supply chains could look like in 2050 and the challenges that must be solved today to get there.

The conversation spans cybersecurity risks that now extend into physical operations, the rise of robotics in logistics, and the growing need for verified, trustworthy data across global networks. The guests also explore how interoperability gaps inside large enterprises slow progress, why collaboration remains one of the biggest barriers across industries, and how emerging approaches like AI agents and materials verification could reshape decision making. Together, they highlight that the future supply chain will depend on aligning technology, standards, and human behavior in ways that are still being defined.

This is more than a discussion about emerging technology. It is an exploration of how supply chains must evolve into connected, transparent, and adaptive systems where data integrity, automation, and cross-industry collaboration determine long term success.

In this episode, you'll learn:

How cybersecurity is evolving from a digital risk into a physical supply chain challenge

How robotics and automation are already reshaping warehouse and logistics operations

Why data trust and verification are becoming essential for future supply chain systems

Things to listen for: (00:00) Opening remarks from Reid Jackson and Liz Sertl introducing the GS1 Connect session (01:26) Framing the 2050 supply chain discussion and key themes (07:40) Cybersecurity threats expanding into physical supply chain operations (11:00) Robotics moving from experimental to real warehouse deployment (15:00) Trust and verification of physical materials through data and scanning (19:30) Collaboration challenges across industries and supplier ecosystems (23:10) Interoperability gaps inside large enterprise systems (26:00) AI agents, hallucinations, and the importance of data quality (30:46) Real world visibility innovations using highway camera data networks (32:38) The future vision of standardized machine communication and interoperability

Connect with GS1 US: Our website - www.gs1us.orgGS1 US on LinkedIn

Connect with the speakers: Melanie Hilton on LinkedInMiguel Rodriguez Garcia on LinkedInMassachusetts Institute of Technology at https://web.mit.edu/Lisa Morales-Hellebo on LinkedIn REFASHIOND Ventures at https://www.refashiond.com/Frederik Bohn on LinkedInPlug and Play Tech Center. at https://www.plugandplaytechcenter.com/

Tuesday, 14. July 2026

GLEIF

Organizational Identity Is the Layer Global Trade Has Been Missing

In the bid to unlock an estimated $30-40 billion in global trade growth and reduce the trade finance gap by up to 50%, significant time and resources are being poured into replacing paper trade documents with digital ones. But paperless is not the same as digital. Replacing a paper bill of lading with a PDF does not actually digitalize a process if someone must then manually rekey that data int

In the bid to unlock an estimated $30-40 billion in global trade growth and reduce the trade finance gap by up to 50%, significant time and resources are being poured into replacing paper trade documents with digital ones.

But paperless is not the same as digital. Replacing a paper bill of lading with a PDF does not actually digitalize a process if someone must then manually rekey that data into the next system or rerun due diligence on a counterparty that another platform has already verified.

This means that scalable digital trade will not be realized by digitizing more documents. Rather, trusted data must move seamlessly across organizations, platforms, and jurisdictions. As outlined in a report from the ICC Digital Standards Initiative (DSI), this requires an interoperability layer comprising globally recognized standards, protocols, and identifiers.

Key to this interoperability layer is portable, verifiable organizational identity, which is to digital trade what container shipping was to physical trade. The container did not make ships faster. It standardized what moved between them, so a box could pass from truck to crane to vessel to customs without being unpacked and re-inspected at every handover. Trusted organizational identity does the same for data, enabling it to move across platforms and borders and allowing users to act on it directly without repeating checks.

Why interoperable organizational identity has been the missing piece

The need for globally standardized organizational identifiers stems from the fact that most identity schemes were built for domestic or closed systems. National IDs, electronic IDs, and platform-specific credentials work well within their own environments but are not easily recognized across borders or platforms without bespoke bilateral arrangements. Every time two parties who have never transacted have to establish trust from scratch, the friction returns.

Consider a single shipment financed by a letter of credit. The electronic bill of lading passes through a carrier, a freight forwarder, a customs authority, the exporter’s bank, and the importer’s bank. Today, each party tends to reestablish who the other is on its own terms. The importer’s bank checks the exporter. The carrier’s platform verifies the freight forwarder. Customs validates the documentation against its own records. The same organizations are identified and re-identified at nearly every handover, because each system trusts only what it has checked itself. Every one of those checks is a place where the transaction can stall.

As trade becomes more data-driven, trust can no longer sit outside the transaction and must travel with the data. This is why the Legal Entity Identifier (LEI) and the verifiable LEI (vLEI) are increasingly being seen as foundational infrastructure. The LEI is a globally recognized identifier for the legal entity behind a transaction, already embedded in regulatory reporting across more than 100 jurisdictions, making it a common reference point for institutions in different countries. The vLEI extends this into digital interactions, enabling counterparties to computationally verify the identity, authority, and role of the people acting on behalf of an organization, while providing a foundation for emerging use cases such as AI agents.

Let's now revisit the earlier scenario and equip each organization with a verifiable identity that travels with the data. The freight forwarder does not need to re-establish the issuing bank's identity because the bank’s identity and the authority of the person or agent who signed on its behalf can be verified directly against a common root of trust. The data stays at its source. All other authorized parties can then access and verify it in place rather than rekeying it or repeating the diligence behind it. The result is fewer manual checks, fewer reconciliations, and faster release of both goods and financing.

Trust is what turns digitization into automation

The reason organizational identity is so powerful is that it provides the underlying trust that bridges digitization and automation, where the actual benefits of digital trade lie. Structured data tells a system what is happening. Identity tells it who is acting and whether that action can be trusted.

Without trusted identity, every process still needs manual intervention, validation, and reconciliation. With it, systems can act with far more confidence. For instance, the faster an incoming instruction can be trusted, the faster liquidity is unlocked and working capital becomes more efficient. Conversely, an instruction whose source cannot be verified has to be checked by hand, and the delay cascades. This is the same logic that has long governed trusted messaging in payments, now applied to trade.

This presents an immediate, practical takeaway for anyone running trade operations at a bank or a platform. The first question worth asking is where, in existing flows, the same organizations are re-verified after they have already been onboarded, and what it would take to consume a verifiable identity instead of repeating that work. For firms that already hold an LEI, the question is whether it is being used for more than regulatory reporting. The standards are evolving, and the advantage will go to participants ready to consume portable identity when their counterparties begin presenting it.

Why increasing coordination is the key to unlocking global digital trade
Given that the tools exist and the economic incentives are compelling, the obvious question is why portable identity is not already standard across global trade ecosystems. This was the starting point for the ICC Digital Standards Initiative (DSI) paper, which outlined a roadmap for interoperability and trust across the trade ecosystem and identified uneven progress and priorities among different parties as a key limiting factor.

There are various reasons for this lack of alignment. Some platforms remain closed and treat interoperability as a competitive threat rather than something to embrace, because their advantage today comes from holding participants inside their own walls. There is also genuine – and understandable – apprehension about moving trust across networks, as relying on a verification someone else performed requires high confidence in how it was done. Finally, many micro, small, and medium-sized enterprises (MSMEs), particularly in emerging markets, lack the resources to invest in new infrastructure, unlike large corporates that can absorb the complexity.

All these problems are eminently solvable through more coordinated execution. There are clear roadmaps to help align policymakers and practitioners, make trust reusable rather than having to be recreated, and lower the cost of participation for the smallest players. For example, GLEIF's work to make organizational identity more accessible at the MSME level directly addresses this final challenge.

Understanding the need for trusted organizational identity for global trade

“Digital trade does not scale through digitization alone. It only scales when trust, data, and value can move across networks as seamlessly as goods move across borders.” This was the main takeaway of my latest Trust Talks conversation with Avanee Gokhale, Head of Industry Insights and Global Head of Trade at Swift and Vice Chair of the ICC Digital Standards Initiative (DSI) Industry Advisory Board.

We discussed why interoperability, rather than digitization, is the real challenge; how a verify-once, use-many model lets trust be reused across the ecosystem; what genuinely stands in the way; and why portable organizational identity is the layer that makes data-driven trade possible.

Listen to the full Trust Talks conversation with Avanee Gokhale for a closer look at how identity moves through a real trade transaction, what a network of networks demands of identity infrastructure, and what Know Your Agent will mean as AI enters commerce. Trust Talks is available across YouTube, Spotify, and Apple Podcasts: linktr.ee/TrustTalks.


OpenID

Call for Participation: Demonstrate MCP-based AI agent security with open identity standards

Prove that MCP clients, gateways, and servers from different vendors can secure AI agents together — within and across enterprises. The OpenID Foundation’s Artificial Intelligence Identity Management Community Group (AIIM CG) is running an interoperability event to show that Model Context Protocol (MCP) flows can be secured with open identity standards. Taking place at the […] The post Call for
Prove that MCP clients, gateways, and servers from different vendors can secure AI agents together — within and across enterprises.

The OpenID Foundation’s Artificial Intelligence Identity Management Community Group (AIIM CG) is running an interoperability event to show that Model Context Protocol (MCP) flows can be secured with open identity standards. Taking place at the Gartner Identity & Access Management Summit 2026 in Las Vegas, the AIIM CG is inviting implementers to take part.

MCP is being adopted quickly to connect AI agents to enterprise tools, services and data. As agents begin to act on behalf of people and organizations, there are three key questions that matter most – which agent is this, what is it allowed to do, and does that still apply when it crosses into another organization?

Open identity standards already answer versions of these questions for humans and workloads. The interoperability event at Gartner will show they can be applied to MCP, and that implementations from different vendors work together when they do.

What it will prove

The event will demonstrate how customers can apply identity based controls to secure MCP flows within an enterprise and across enterprises, using standards drawn from the core MCP specification, MCP extensions, or elsewhere.

The point is interoperability. When these standards are implemented correctly, an organization can choose its own MCP clients, gateways and servers and expect the security properties to hold, regardless of which products it picks.

The uses cases and standards in scope

The testing focuses on two scenarios:

Agent governance – ensuring that only authorized agents can reach enterprise resources. Cross-organizational identity assurance – ensuring that an agent in one organization can access MCP servers in another.

Participants will test interoperability across the following:

OAuth 2.1 – the baseline authorization framework for the flows. OAuth Client ID Metadata Document (CIMD) – an IETF draft standard that lets a client identify itself by URL without prior registration. Here it is used to confirm which agent is making the request. Enterprise Managed Authorization: Based on the Identity Assertion JWT Authorization Grant, which is in turn based on ID-Chaining. This ensures identities are conveyed securely across organizational boundaries. It provides seamless access to cross-organizational MCP servers without requiring the user to relogin. How the flow works

Once MCP clients, authorization servers and MCP servers are in place: 

The MCP Client uses CIMD to obtain an OAuth 2.1 access token. The MCP Client uses the access token to access an internal MCP server The MCP Client performs an EMA token exchange to obtain an ID-JAG The MCP Client exchanges the ID-JAG with the OAuth AS in a third-party enterprise to obtain an OAuth 2.1 access token that works for the MCP server in that enterprise. The MCP Client communicates using the obtained OAuth token with the MCP server either in the same enterprise or in the third-party enterprise.

See the detailed test plan here.

Taking part in testing

Participants take at least one role, either MCP client, OpenID Provider, OAuth authorization server, MCP gateway, or MCP server. They must test at least one interaction with another participant in a complementary role. For example, a client testing CIMD against an authorization server.

Each participant keeps their own interoperability matrix, recording which standards they tested and with how many partners. Both sides agree the result before it’s submitted, and the AIIM CG consolidates these into the published results – a clear, evidenced record of what interoperated with what.

Get involved Interested parties are encouraged to join the AIIM CG’s weekly information calls to learn more before committing. Add this meeting to your calendar to participate. Participants must commit  by end of the day, Pacific Time, on 10 August 2026. Participation is open to all, and free. Participants may commit by emailing the OpenID AIIM CG co-chair, Atul Tulshibagwale, at atul.tulshibagwale@crowdstrike.com. The AIIM CG will then host weekly calls designed to support the participants, enable them to ask questions, and schedule mutual interoperability tests with other participants. By 16 October, participants must be able to show at least one successful test with a partner, for at least one use case. They are encouraged to keep adding interoperability use cases to their matrix right up until the Gartner IAM Summit in December

The results will be presented by Atul Tulshibagwale of the OpenID Foundation and Erik Wahlström from Gartner during Gartner IAM Summit. A limited number of successful participants will also be given the opportunity to demonstrate their implementations. The AIIM CG will publish guidance on how demonstration slots are prioritized ahead of the commitment date.

Paul Carleton, Core Maintainer of MCP, said: “Anyone deploying agents at enterprise scale hits the challenges this event is testing: agent governance, and identity that survives crossing organizational boundaries. I look forward to seeing implementations from across the ecosystem prove standards like CIMD and ID-JAG work together.”

Atul Tulshibagwale, co-chair of the OpenID AIIM CG, and Senior Director, Continuous Identity Strategy at CrowdStrike, said: ”Agent governance, and cross-organizational identity assurance and seamless access are important problems that enterprises are grappling with as they deploy MCP based AI agents. This interoperability event provides an amazing venue where Gartner IAM Summit attendees can see this in action from multiple implementers.”

Erik Wahlström, VP Analyst, IAM at Gartner, said: “The industry has made significant progress in defining IAM standards for AI agents. Now it’s time to prove they work. This initiative validates interoperability across implementations and helps accelerate deployment across the IAM ecosystem. We’re pleased to provide a venue for the community to engage with this important work and see these standards put to the test.”

About the OpenID Foundation

The OpenID Foundation (OIDF) is a global open standards body committed to building trusted identity ecosystems. Our mission is to lead the global community in identity standards that are secure, interoperable, and privacy respecting. Founded in 2007, we are a community of technical experts. The Foundation’s OpenID Connect standard is now used by billions of people across millions of applications. More recently, the FAPI security profile – built on OAuth 2.0 – has become the standard of choice for interoperable Open Banking and Open Data implementations, while OpenID for Verifiable Credentials specifications are underpinning a new generation of digital wallets. Today, the OpenID Foundation’s standards are the connective tissue that enable people to assert their identity and access their data at scale, the scale of the internet, enabling “networks of networks” to interoperate globally. Individuals, companies, governments and non-profits are encouraged to join or participate. Find out more at openid.net.

 

The post Call for Participation: Demonstrate MCP-based AI agent security with open identity standards first appeared on OpenID Foundation.


AuthZEN at Identiverse 2026: authorization in the agent era

By Alex Olivier Authorization, and specifically authorization for AI agents, emerged as the defining challenge of the year. That shift was visible at Identiverse 2026. One marker of how far the work has come is that the AuthZEN sessions ran as a full masterclass and a main-program talk rather than the side birds-of-a-feather slots such […] The post AuthZEN at Identiverse 2026: authorization in t

By Alex Olivier

Authorization, and specifically authorization for AI agents, emerged as the defining challenge of the year. That shift was visible at Identiverse 2026. One marker of how far the work has come is that the AuthZEN sessions ran as a full masterclass and a main-program talk rather than the side birds-of-a-feather slots such topics occupied a year or two ago. 

I co-presented both sessions as AuthZEN co-chair and CPO at Cerbos, alongside my fellow AuthZEN Working Group co-chair, Atul Tulshibagwale (CrowdStrike) and joined by Mark Berg (Axiomatics). The rooms were full, and questions after both sessions concentrated on how to authorize AI agents safely.

From SARC to agent tool calls

The masterclass reinforced the scope discipline at the core of AuthZEN. The standard defines only the interface between a Policy Enforcement Point (PEP) and a Policy Decision Point (PDP); it is not a policy language, and it does not dictate how a PDP sources its information. Its information model is built around Subject, Action, Resource, and Context (SARC), and its contract is deliberately strict: a deny is never a 4xx, and a malformed request is never a decision: false. The material that drew the most engagement was agent authorization, via the AuthZEN profile for Model Context Protocol tool authorization (COAZ). It answers the question OAuth scopes cannot — whether this agent, acting for this user, may call this tool with these arguments — by having a gateway or MCP server consult the PDP before a tool runs.

The second session set AuthZEN in the wider landscape. Authentication is largely solved; authorization is not, and no single specification resolves it alone. The strength is in composition. Three standards fit together: Shared Signals (SSF/CAEP) to bring fresh security context to the decision point, AuthZEN for the fast local PEP/PDP decision, and Transaction Tokens (TraTs, an IETF OAuth Working Group draft) to propagate that decision across the services inside an application.

Delegation and human-in-the-loop

The room was engaged and practical, focused on how the standard applies to specific systems rather than on whether it matters. The questions that drew the most discussion were the hard, real-world ones: how to handle delegated authorization when an agent acts on a user’s behalf, and how approval flows fit in when a decision needs a human-in-the-loop. Several attendees wanted to contribute directly, and a new organization signalled its intent to join the Working Group following the session (more will be shared on this once it finalises). Both of those edges are already on the agenda, with the AuthZEN Access Request and Approval Profile (ARAP) taking on the approval-flow case the room raised.

Why it matters for the identity community

Agents change the shape of the access-control problem. A non-deterministic system acting on a user’s behalf, with implicitly delegated access, is exactly the setup that produces confused-deputy failures, in which one component is tricked into misusing its authority — now at machine speed and scale. The community has spent years standardizing how a principal proves who they are; the agent era makes it urgent to standardize, with the same rigor and interoperability, what that principal is then allowed to do.

This is where the OpenID Foundation’s authorization work sits. The AuthZEN Working Group is standardizing the PEP/PDP decision interface and, through the ARAP and COAZ profiles, extending it to approval flows and agent tool authorization. Its interop events and conformance certification program let independent implementations trust one another. That work composes with the Shared Signals Working Group and with Transaction Tokens in the IETF, advancing the Foundation’s mission of open, interoperable standards that work across vendors and trust domains rather than being locked to any one of them.

Get involved Join the OpenID AuthZEN Working Group and its mailing list to contribute to the published Working Group Drafts, including the ARAP and COAZ profiles, and the certification program.  Follow the Shared Signals Working Group as it extends SSF and CAEP toward agentic use cases.

Robust, interoperable authorization standards depend on broad industry collaboration. The conversations at Identiverse 2026 made clear how much that collaboration matters, and how much work remains to do together – across working groups, across vendors, and across the PEP/PDP interface itself. This is how the agent-era access-control problem gets solved. 

This post is drawn from two sessions delivered at Identiverse 2026 (Las Vegas, June 15–19) by the OpenID AuthZEN Working Group co-chairs:: the masterclass “Mastering the OpenID Authorization Standard,” and “Beyond Authentication: Updates from the Authorization Frontier.”

About the author: Alex Olivier is co-chair of the OpenID AuthZEN Working Group, as well as the co-founder and Chief Product Officer at Cerbos, an Authorization Management Platform and implementer of the AuthZEN standard. He specializes in authorization systems, with a recent focus on workload identity and AI security. With over a decade of experience building and scaling authorization systems at Microsoft, Qubit, Zencargo, and multiple startups, Alex has published extensively on securing Model Context Protocol (MCP) servers and AI agents. A frequent speaker at events on authorization, AI, security, and identity, including ISC2 Congress, Identiverse, EIC, KubeCon, and Google Cloud NEXT, he combines standards development with practical implementation experience, focusing on the future of authorization for traditional applications, distributed workloads, and emerging AI systems.

About the OpenID Foundation

The OpenID Foundation (OIDF) is a global open standards body committed to building trusted identity ecosystems. Our mission is to lead the global community in identity standards that are secure, interoperable, and privacy respecting. Founded in 2007, we are a community of technical experts. The Foundation’s OpenID Connect standard is now used by billions of people across millions of applications. More recently, the FAPI security profile – built on OAuth 2.0 – has become the standard of choice for interoperable Open Banking and Open Data implementations, while OpenID for Verifiable Credentials specifications are underpinning a new generation of digital wallets. Today, the OpenID Foundation’s standards are the connective tissue that enable people to assert their identity and access their data at scale, the scale of the internet, enabling “networks of networks” to interoperate globally. Individuals, companies, governments and non-profits are encouraged to join or participate. Find out more at openid.net.

The post AuthZEN at Identiverse 2026: authorization in the agent era first appeared on OpenID Foundation.


DIF Blog

Who uses DIDComm?

The following guest post was contributed by Leadpoint System (LPS), who initiated the DIDComm survey and collaborated with DIF on its promotion. Next week, DIF will host a breakfast at IETF on July 22, to discuss the implications of the survey results on DIDComm. The survey, led by Leadpoint System

The following guest post was contributed by Leadpoint System (LPS), who initiated the DIDComm survey and collaborated with DIF on its promotion.

Next week, DIF will host a breakfast at IETF on July 22, to discuss the implications of the survey results on DIDComm. The survey, led by Leadpoint System and promoted by DIF, shows significant uptake of DIDCommas a messaging protocol. While the EUDI wallet has specified the OpenID4VC protocol, it turns out that many applications worldwide are opting to explore more peer-to-peer architectures based on DIDComm. The survey also shows that this adoption is not limited to a single industry, with implementations spanning digital identity, government services, enterprise credentialing, financial services, AI agents, and cross-organizational data exchange. 

What the numbers say

DIDcomm and Leadpoint System publicized the survey over 3 months, gleaning 29 responses from countries worldwide, including India, the US, Germany, Brazil, Switzerland, Australia, Portugal, and Canada. While most of the respondents were companies, a few were NGOs or government organizations.

Of the 29 respondents, 14 have deployments in production today. In terms of the number of users, altogether the deployments represent more than 25 million humans using DIDComm, with millions of transactions daily. The most common use of DIDComm are in identity wallets for credential issuance, with 24 of the 29 respondents applying DIDComm to those flows. Agent-to-agent communication was also common, with 22 respondents using DIDComm. 

The results offer only a glimpse into who is using DIDComm, because only those who saw the callout from DIF have filled in the survey. Yet, even this small sampling shows real-world implementation and viability and represents strong evidence for hardening the DIDComm standard at a more formal standards body. To that end, DIF will be exploring IETF as a potential direction for the standard.

Anyone who is interested in supporting us for moving DIDComm forward, either by supporting us in IETF, or by helping fund the effort to move DIDComm forward, please reach out to ed@identity.foundation. If you will be attending IETF 126, please join us for breakfast on July 22 in Vienna.

LPS as a partner

Leadpoint System (LPS) initiated this survey to better understand how decentralized identity technologies are being adopted in real-world production environments. As a company developing blockchain infrastructure and decentralized identity solutions, we wanted to move beyond assumptions and gather evidence directly from organizations building identity wallets, credential platforms, AI agents, and enterprise applications.

The survey was designed to better understand where DIDComm is delivering value today, what challenges remain, and which areas require further standardization. Through our collaboration with the DIF, we were able to reach implementers across multiple continents and collect valuable feedback from organizations already deploying DIDComm in production.

From our perspective, the results confirm that DIDComm is already supporting production systems serving millions of users while continuing to evolve alongside the broader decentralized identity ecosystem.

Why applications use DIDcomm

DIDComm is a secure, private, transport-agnostic messaging protocol that enables people, organizations, and software agents to communicate directly using decentralized identifiers (DIDs). Every message is authenticated and encrypted without relying on a centralized identity provider.

Using DIDComm has advantages over OpenID4VC in specific applications. The primary reason cited for use of DIDComm is the persistence over multiple interactions. One channel supports arbitrary, long-lived, bidirectional communication. The channel does not need to be rebuilt for every interaction, so the trust can be maintained over time. DIDComm is agnostic to the transport layer, working over HTTPS, Bluetooth, push, sockets, and even offline. Another advantage of DIDComm is that it’s lightweight, and it does not require an identity provider or session server in the loop. 

What the survey tells us

Beyond demonstrating adoption, the survey highlights several important trends.

Although OpenID4VC has become an important protocol in ecosystems such as the European Digital Identity Wallet, organizations often choose DIDComm where persistent, secure, peer-to-peer communication is required. Respondents consistently pointed to long-lived communication channels, transport flexibility, and decentralized trust as important reasons for deployment.

The survey also revealed that interoperability and adoption remain the adopters' largest challenges, cited by more than half of respondents. Lack of tooling, implementation complexity, and documentation were also frequently mentioned. Interestingly, many organizations are not choosing between DIDComm and OpenID4VC—they are implementing both, selecting each protocol according to the requirements of specific user flows and architectures.

Another clear takeaway is that implementers are looking for stronger international standardization. Many respondents indicated that formal recognition through an international standards organization would improve interoperability, increase customer (and regulator) confidence, encourage ecosystem growth, and reduce adoption barriers for enterprise and government deployments.

See you in Vienna!

The Decentralized Identity Foundation (DIF) was established to create an IP-protected environment for decentralized identity-related specifications and open-source code development. DIF promotes the use of DIDs, VCs, and related decentralized identity technologies. DIF maintains more than 270 GitHub repositories that have been contributed or developed by members and working Groups. DIF is committed to fostering an environment where decentralized identity technologies can evolve, mature, and achieve widespread adoption through collaborative effort and strategic partnerships across the ecosystem.

Learn more about Decentralized Identity Foundation (DIF)

Oasis Open

Invitation to comment on KMIP Specification v3.0 and KMIP Profiles v3.0 – ends 13 August 2026

OASIS and the KMIP TC are pleased to announce that Key Management Interoperability Protocol Specification Version 3.0 and Key Management Interoperability Protocol Profiles Version 3.0 are now available for public review and comment. The post Invitation to comment on KMIP Specification v3.0 and KMIP Profiles v3.0 – ends 13 August 2026 appeared first on OASIS Open.

Public review ends August 13th

OASIS and the KMIP TC are pleased to announce that Key Management Interoperability Protocol Specification Version 3.0 and Key Management Interoperability Protocol Profiles Version 3.0 are now available for public review and comment. 

The OASIS KMIP TC works to define a single, comprehensive protocol for communication between encryption systems and a broad range of new and legacy enterprise applications, including email, databases, and storage devices. By removing redundant, incompatible key management processes, KMIP will provide better data security while at the same time reducing expenditures on multiple products. The Profiles specification defines the conformance clauses and the accompanying test cases against which implementations are measured. This is the first public review of both documents at Version 3.0.

The documents and all related files are available here:

Key Management Interoperability Protocol Specification Version 3.0
Committee Specification Draft 02
7 May 2026

Editable Source: https://docs.oasis-open.org/kmip/kmip-spec/v3.0/csd02/kmip-spec-v3.0-csd02.docx (Authoritative)

HTML: https://docs.oasis-open.org/kmip/kmip-spec/v3.0/csd02/kmip-spec-v3.0-csd02.html

PDF: https://docs.oasis-open.org/kmip/kmip-spec/v3.0/csd02/kmip-spec-v3.0-csd02.pdf

ZIP (complete package): https://docs.oasis-open.org/kmip/kmip-spec/v3.0/csd02/kmip-spec-v3.0-csd02.zip

Key Management Interoperability Protocol Profiles Version 3.0
Committee Specification Draft 02
21 May 2026

Editable Source: https://docs.oasis-open.org/kmip/kmip-profiles/v3.0/csd02/kmip-profiles-v3.0-csd02.docx (Authoritative)

HTML: https://docs.oasis-open.org/kmip/kmip-profiles/v3.0/csd02/kmip-profiles-v3.0-csd02.html

PDF: https://docs.oasis-open.org/kmip/kmip-profiles/v3.0/csd02/kmip-profiles-v3.0-csd02.pdf

ZIP (complete package): https://docs.oasis-open.org/kmip/kmip-profiles/v3.0/csd02/kmip-profiles-v3.0-csd02.zip

Test cases: https://docs.oasis-open.org/kmip/kmip-profiles/v3.0/csd02/test-cases/

How to Provide Feedback

The public review starts 14 July 2026 at 00:00 UTC and ends 13 August 2026 at 23:59 UTC.

Comments from TC members should be sent to the TC’s mailing list. Comments may be submitted by any other person through the project’s Comment Facility: https://groups.oasis-open.org/communities/community-home?CommunityKey=2b5e5c66-cc41-4aa5-92ee-018f5aa7dfc4

Comments submitted by non-members for this work product are publicly archived and can be viewed by using the link above and clicking on the “Discussions” tab. Please note that you must log in or create a free account to see the material. Comments submitted by any other means cannot be accepted.

Please contact the TC Administrator (tc-admin@oasis-open.org) with any questions on how to submit a comment.

All comments submitted to OASIS are subject to the OASIS Feedback License, which ensures that the feedback you provide carries the same obligations at least as the obligations of the TC members. In connection with this public review, we call your attention to the OASIS IPR Policy applicable especially to the work of this technical committee. All members of the TC should be familiar with this document, which may create obligations regarding the disclosure and availability of a member’s patent, copyright, trademark and license rights that read on an approved OASIS specification.

OASIS invites any persons who know of any such claims to disclose these if they may be essential to the implementation of the above specification, so that notice of them may be posted to the notice page for this TC’s work.

TC public home page: https://www.oasis-open.org/committees/kmip/

Additional references:
OASIS IPR Policy: https://www.oasis-open.org/policies-guidelines/ipr/
KMIP TC IPR Policy page: https://www.oasis-open.org/committees/kmip/ipr.php

The post Invitation to comment on KMIP Specification v3.0 and KMIP Profiles v3.0 – ends 13 August 2026 appeared first on OASIS Open.


Invitation to comment on OpenEoX Core Schema Version 1.0 CSD01

OASIS and the OpenEoX TC are pleased to announce that OpenEoX Core Schema Version 1.0 CSD01 is now available for public review and comment. The OpenEoX Core Schema defines the core schema for the OpenEoX unified machine-readable approach to managing and sharing General Availability (GA), End-of-Sales (EoS), End-of-Life (EoL), and End-of-Security-Support (EoSSec) information. The post Invitation

Public Review ends - August 13th

OASIS and the OpenEoX TC are pleased to announce that OpenEoX Core Schema Version 1.0 CSD01 is now available for public review and comment. 

The OpenEoX Core Schema defines the core schema for the OpenEoX unified machine-readable approach to managing and sharing General Availability (GA), End-of-Sales (EoS), End-of-Life (EoL), and End-of-Security-Support (EoSSec) information for commercial and open source software and hardware. Product lifecycle data today is scattered across vendor websites, PDFs, and ad-hoc feeds; OpenEoX gives vendors and consumers one standardized, machine-readable format for it, so lifecycle tracking can be automated across the industry.

This is the first public review of this specification. The TC is seeking feedback from security teams, asset management vendors, software and hardware producers, and anyone who consumes or publishes end-of-life data.

The documents and all related files are available here:

OpenEoX Core Schema Version 1.0
Committee Specification Draft 01
13 July 2026

https://docs.oasis-open.org/openeox/eox-core/v1.0/csd01/eox-core-v1.0-csd01.md (Authoritative)

https://docs.oasis-open.org/openeox/eox-core/v1.0/csd01/eox-core-v1.0-csd01.html

https://docs.oasis-open.org/openeox/eox-core/v1.0/csd01/eox-core-v1.0-csd01.pdf

Associated schemas: https://docs.oasis-open.org/openeox/eox-core/v1.0/csd01/schema/

You can download the ZIP file at: https://docs.oasis-open.org/openeox/eox-core/v1.0/csd01/eox-core-v1.0-csd01.zip

How to Provide Feedback

OASIS and the OpenEoX TC value your feedback. We solicit input from developers, users and others, whether OASIS members or not, for the sake of improving the interoperability and quality of its technical work.

The 30-day public review is now open and ends 13 August 2026 at 23:59 UTC.

Comments may be submitted to the project by any person through the use of the project’s Comment Facility. Instructions are located using this link: https://groups.oasis-open.org/communities/community-home?CommunityKey=c9295ed5-b5f9-4a51-8893-018f5aa7fc09

Comments submitted for this work by non-members are publicly archived and can be viewed by using the link above and clicking the “Discussions” tab.

Please note, you must log in or create a free account to see the material and submit a comment. Please contact the TC Administrator (tc-admin@oasis-open.org) if you have any questions regarding how to submit a comment.

Alternatively, comments can be submitted directly to the following email address: technical-committee-comments@oasis-open.org

All comments submitted to OASIS are subject to the OASIS Feedback License, which ensures that the feedback you provide carries the same obligations at least as the obligations of the TC members. In connection with this public review, we call your attention to the OASIS IPR Policy [1] applicable especially to the work of this technical committee. All members of the TC should be familiar with this document, which may create obligations regarding the disclosure and availability of a member’s patent, copyright, trademark and license rights that read on an approved OASIS specification.

OASIS invites any persons who know of any such claims to disclose these if they may be essential to the implementation of the above specification, so that notice of them may be posted to the notice page for this TC’s work.

Additional references:

[1] https://www.oasis-open.org/policies-guidelines/ipr/
https://www.oasis-open.org/policies-guidelines/ipr#Non-Assertion-Mode

The post Invitation to comment on OpenEoX Core Schema Version 1.0 CSD01 appeared first on OASIS Open.


ResofWorld

The Gulf has billions to spend on AI. It still needs Nvidia

Saudi Arabia and the UAE are trying to diversify their AI supply chains, but geopolitical constraints and Nvidia's technological lead leave them with few viable alternatives.
The Gulf’s oil-rich states, betting billions on reinventing themselves as centers of artificial intelligence, are discovering that money can buy almost everything, except a way out of Nvidia. Saudi Arabia...

Monday, 13. July 2026

Digital ID for Canadians

DIACC’s Submission to the 2026 Review of the Privacy Act

Filed with the Treasury Board of Canada Secretariat, July 2026

The Privacy Act came into force in 1983 and has never been substantially updated. In April 2026, the Treasury Board of Canada Secretariat launched the first comprehensive review of it, outlining 23 policy proposals across 6 themes and asking two questions: Do you agree with the approach, and is anything missing?

DIACC filed its submission ahead of the July 10 deadline. This page sets out what we said, and why.

The submission is offered as analysis informed by member experience. It is not a position adopted on behalf of any individual member or government, and it does not advocate for any particular vendor or technology.

What we said, by theme

Theme 1: Enabling integrated services

Proposal 1 (sharing and reuse of personal data across programs, without consent, where a public interest or benefit to individuals is served). We support the direction. Replacing the default of repeated direct collection with a purpose-based approach is consistent with international practice and with the authoritative-source model that underpins modern digital service delivery. The four conditions attached to it are well calibrated: the reuse must be necessary, minimally intrusive, strongly safeguarded, and transparent.

Removing consent from the equation places considerable weight on those four conditions. They are the whole of the protection. Our submission’s position is that the conditions must be demonstrable in practice, not merely stated in statute, and that implementation guidance carries the load.

Proposal 2 (designated official sources of government digital data). This is the proposal we would most want to see survive the drafting process.

It would name certain institutions as the official source for specific types of personal data, and require other programs to obtain that data from the designated source rather than collect it again. The paper is candid that the driver is accuracy as much as convenience: under the current siloed model, a person who updates their information with one program and not with four others leaves the government holding several versions of the same person.

Provinces have been operating versions of this model for years. The BC Services Card serves more than 4.6 million British Columbians.[4] Quebec’s Government Authentication Service supports over 3.5 million accounts.[5] Alberta launched Canada’s first mobile health card in August 2025.[6] In the private sector, Interac’s sign-in service already carries more than 141 million federal government interactions annually.[8]

The consultation paper says designation would be guided by clear criteria and overseen by TBS, and that TBS could maintain a registry of official sources. We asked for three things in that work.

Auditable assurance frameworks should inform designation criteria, so that designation means an institution is held to a consistent and verifiable standard rather than simply named to a list.

The registry should be public and written in plain language, so that a Canadian can find out which institution is the official source of their data. A registry that exists only as an internal administrative instrument does less to build trust than one that people can actually read.

The model should be built for federal-provincial interoperability from the outset. Health, benefits and employment data cross that boundary constantly, and the paper itself allows that the approach could be extended across levels of government. Designing for that later is harder than designing for it now.

Theme 2: Enhancing accountability and transparency

We support all four proposals in this theme.

Elevating Privacy Impact Assessments to a legal requirement (Proposal 3) and publishing plain-language summaries of them strengthens accountability without imposing an unreasonable burden. Replacing the fragmented Personal Information Bank regime with a single centralized registry of personal data holdings (Proposal 4) is a straightforward improvement in service design and in transparency.

Regarding the automated decision proposals (Proposals 5 and 6), we support the direction but think something is missing from them.

The proposals would require institutions to notify individuals when an automated decision system is used and, upon request, explain how a decision was made and what data informed it. As those systems take on more consequential decisions, an institution’s ability to establish who the data subject actually is, and on what basis their consent was captured, does more work than it used to. Identity and consent assurance should be addressed in the Act’s automated decision provisions themselves, working alongside the Directive on Automated Decision-Making rather than being left entirely to it.

Theme 3: Advancing safeguards across the spectrum of data sensitivity

We support all five proposals in this theme.

Recognizing a spectrum of data sensitivity and identifiability in law (Proposal 7) is overdue, and the proposed categories align with international standards and provincial regimes. Creating legal requirements for breach management, notification, and reporting (Proposal 8) brings the Privacy Act into line with PIPEDA and international peers and is foundational.

Requiring safeguards proportionate to sensitivity (Proposal 9) is appropriate. We note that auditable assurance frameworks provide institutions with a demonstrable means of evidencing that physical, technical and administrative safeguards meet the legal requirement, rather than merely asserting that they do.

The necessity test for collection (Proposal 10) and the retention and disposal requirements (Proposal 11) are well calibrated. Institutions applying them will need to document, on a defensible basis, the authority and the retention rule applicable to each category of data they hold.

Theme 4: Modernizing the foundation for privacy and trust

We support all four proposals in this theme.

Recognizing privacy as a fundamental right while also naming service delivery as an objective (Proposal 12) resolves a tension that has never existed. Privacy protection and modern digital service are not competing goods, and a statute that says so plainly permits institutions to pursue both.

Listing privacy principles in the Act (Proposal 13) and aligning them with PIPEDA, the GDPR, and OECD guidelines reduce the interpretive burden for organizations working across federal, provincial, and private-sector regimes at once. We put particular weight on privacy by design, necessity, proportionality, effectiveness, and minimal intrusiveness.

Consistent definitions (Proposal 14) and a harmonized request regime (Proposal 15) are practical improvements that will be felt by anyone who has tried to request the current framework.

Theme 5: Indigenous Peoples’ access to, and protection of, their data

Our answer here was mostly deference.

Provisions governing Indigenous data must be developed in direct partnership with Indigenous governments and organizations, recognizing their distinct rights, perspectives, and priorities. We support the directional intent to recognize Indigenous data sovereignty and enable Indigenous governments to access their citizens’ data through formal agreements. On the substance of how those provisions should be drafted, and on the terminology the Act should adopt, we defer to Indigenous partners.

DIACC is engaged in exploratory dialogue with Indigenous organizations on co-design opportunities in digital trust. DIACC and its members can help build what those partners design. We are not the right authors of it.

Theme 6: Updating the compliance framework

We support the proposals in this theme.

We give particular weight to Proposal 20, which would authorize the Privacy Commissioner to share information with other oversight bodies. Canadians’ data moves among federal, provincial, and international regimes, and coordinated oversight across those regimes is a precondition for trusting that it is consistently protected as it travels.

We also support binding order-making powers and published corrective action plans (Proposal 19), offences for unauthorized re-identification (Proposal 21), expanded Federal Court authority (Proposal 22), and a mandatory five-year review (Proposal 23). Together these move the Act from a framework that describes obligations to one that can enforce them.

What we said was missing

The consultation’s second question is the more interesting one. Our answer had four parts.

The proposals stop short of the proof. A statute sets obligations. It does not settle how an institution demonstrates it has met them; that gets worked out afterwards in Treasury Board policy, in implementation guidance, and in whatever frameworks institutions end up using to evidence compliance. The consultation paper is detailed on the obligations and thin on the proof. More than 250 federal institutions will have to supply it.[10]

Auditable, technology-neutral assurance frameworks are one available means of closing that distance, across identity verification, consent management, automated decision-making, designated official sources, and inter-institutional sharing. They can be certified by independent third-party audit. Canadian industry and several provincial governments already operate on them. The Pan-Canadian Trust Framework is one such example, and Appendix B below shows how its components align with individual proposals. We offer that as information as an educational and operational example..

Independent certification is a recognized means of evidencing assurance. Where an institution needs to show that a service meets defined privacy and verification criteria, including in procurement, third-party certification against a published, technology-neutral framework is one auditable means of doing so.

Alignment with provincial regimes should happen at the principles and assurance layer. Canadians do not experience federal, provincial and municipal services as separate jurisdictions. Aligning at the level of principles and assurance, rather than attempting to align the legislative text, would allow a modernized Act to sit alongside BC’s FIPPA, Alberta’s FOIP, Quebec’s Law 25 and Bill 82, and Ontario’s regime without asking any jurisdiction to give up its authority.

Privacy reform is also service reform, and it bears on fraud. Canadians reported more than $704 million in fraud losses in 2025.[1] Synthetic identity fraud has climbed sharply as a share of credit applications.[2] Canada’s suspected digital fraud rate reached 4.4% of attempted transactions in 2025, above the global average of 3.8%.[3] The assurance sitting underneath federal identity and verification affects people’s money as well as their privacy. A modernized Act that supports auditable, interoperable assurance strengthens public trust and bolsters the digital economy, which depends on trusted federal data.

Appendix A: About DIACC and the Pan-Canadian Trust Framework

DIACC is Canada’s non-profit public-private forum on digital trust and verification, established in 2012 following the recommendations of Finance Canada’s Electronic Task Force for the Payments System Review. Our membership includes federal institutions, provincial and municipal governments, and the financial, telecommunications and technology partners that build and operate digital services with them.

The Pan-Canadian Trust Framework (PCTF) is an auditable conformance framework for identity, authentication and verification services. It is technology-neutral, built around privacy-by-design principles, and structured to support interoperability across federal, provincial and private-sector regimes.

DIACC’s PCTF Trustmark program certifies services against PCTF criteria through an independent third-party audit. Certified services are listed publicly on the DIACC Trusted List.

DIACC’s strategic priorities for 2026 to 2031 are AI trust and resilience, economic sector acceleration, regulatory alignment and compliance, and inclusive digital sovereignty.

Appendix B: How PCTF components align with the proposals

The PCTF was built around principles consistent with the policy approaches in the consultation paper. The following is offered for the reference of anyone interested in how an existing auditable framework maps to the proposals. It is not a recommendation that TBS adopt the PCTF, and DIACC does not advocate for any vendor or technology.

Proposal 1 (responsible sharing and reuse). PCTF identity verification and authentication profiles support the conditions attached to responsible sharing: necessity, minimal intrusiveness, and strong safeguards. The criteria are auditable, providing institutions with a defensible basis for inter-institutional sharing.

Proposal 2 (designated official sources). PCTF provides certifiable assurance criteria for institutions seeking designation, supporting consistent trust standards across designated sources.

Proposal 3 (mandatory PIAs). PCTF profiles include privacy-by-design criteria that map to PIA requirements.

Proposal 5 (transparency for AI and automated decision systems). DIACC’s AI verification and Verified Agent (Know Your Agent) criteria, currently in development, are designed to support transparency and explainability requirements for AI-supported decision systems.

Proposal 6 (strengthened privacy notices). PCTF consent criteria support plain-language notice requirements.

Proposal 7 (sensitivity spectrum). PCTF assurance levels apply proportionate safeguards based on the sensitivity and identifiability of the data being verified or authenticated.

Proposal 8 (breach management and notification). PCTF certification requirements include breach response and notification protocols.

Proposal 9 (legal safeguard requirements). PCTF certification provides auditable evidence that physical, technical and administrative safeguards meet defined criteria.

Proposal 12 (privacy as a fundamental right; service delivery as an objective). The PCTF was designed to support both privacy protection and modern digital service delivery.

Proposal 13 (principles aligned with private sector and international standards). PCTF principles align with PIPEDA, the GDPR and OECD guidelines.

Appendix C: Provincial and industry implementations

These implementations show how the policy approaches in the consultation paper can work in practice, and where the interoperability opportunity lies for a modernized federal Privacy Act. They are offered as illustrations. DIACC does not speak on behalf of any province or company.

British Columbia. The BC Services Card has been operational since 2013 and now serves more than 4.6 million British Columbians, over 90% of the province.[4] It supports federal interactions, including StudentAid BC and the Canada Revenue Agency. OrgBook BC, launched in January 2019, was the first implementation in North America to use verifiable credentials for organizational identity, and now covers over 1.4 million active legal entities. BC demonstrates the designated-official-source model at provincial scale, including federal-provincial interoperability.

Quebec. The Government Authentication Service, which replaced clicSÉQUR, supports more than 3.5 million accounts. Bill 82, passed on October 28, 2025, establishes the legal framework for a comprehensive digital identity and wallet capability by 2028.[5] Quebec shows that a legal framework for digital identity can be designed to sit comfortably inside a strict privacy regime.

Alberta. Alberta launched Canada’s first mobile health card on August 29, 2025, through the Alberta Wallet app.[6] Parents can hold their children’s cards, and paper alternatives remain available. Alberta shows how sensitive personal data can be made available digitally while upholding privacy-by-design principles and preserving non-digital alternatives.

Industry. Interac’s sign-in service supports more than 141 million federal government interactions annually,[8] and Interac Verified, launched in May 2025, implements a verify-once model that stores data locally on the user’s device.[7] Canadian-controlled assurance infrastructure is operational and already working at federal scale.

International context. The EU Digital Identity Wallet is in active rollout. Commission Implementing Regulation (EU) 2026/798 on wallet enrolment was published on April 8, 2026, and all member states must make at least one compliant wallet available by December 24, 2026.[9] Privacy and digital identity infrastructure are increasingly being designed to interoperate across jurisdictions.

Related DIACC resources Advancing Digital Trust for Government Service Modernization (April 2025) Advancing Digital Trust to Strengthen Public Safety (May 2025) Canada’s Digital Trust Imperative: A 2031 Strategic Vision (January 2026) PCTF Trustmark Trusted List of Certified Services Citations

[1] Competition Bureau Canada, “Fraud Prevention Month to bring hidden crime into the spotlight” (March 6, 2026), citing data from the Canadian Anti-Fraud Centre.

[2] Equifax Canada, “Equifax Canada Reports Rise in Automotive Fraud” (September 24, 2024). Synthetic identity fraud rose from 2.8% of credit applications in Q2 2023 to 8% in Q2 2024.

[3] TransUnion, “H1 2026 Update to the Top Fraud Trends Report” (May 13, 2026).

[4] DIACC, “Identity in Action Case Study: BC Services Card” (March 2019); Government of British Columbia, OrgBook BC.

[5] Government of Québec, “About the Government Authentication Service”; ID Tech, “Quebec Passes Landmark Digital ID Law” (October 2025).

[6] ID Tech, “Alberta Launches Canada’s First Mobile Health Card Through Alberta Wallet” (September 2025).

[7] Interac, “Interac launches the Interac Verified credential service” (May 2025).

[8] Interac, “Secure. Trusted. Helping Canada navigate a digital future” (October 2025).

[9] European Commission, Commission Implementing Regulation (EU) 2026/798 on wallet enrolment (published April 8, 2026).

[10] Treasury Board of Canada Secretariat, “2026 Review of the Privacy Act: Policy Approaches” (April 2026).


ResofWorld

India’s crackdown on a new WhatsApp feature risks setting a global precedent

If Meta complies or modifies its app for India, it risks creating a “slippery slope” that emboldens governments worldwide to demand changes to encrypted messaging apps.
The Indian government’s latest tussle with WhatsApp has raised concerns about the censorship of app features globally. On June 29, WhatsApp began rolling out usernames globally, allowing users to chat...

Friday, 10. July 2026

ResofWorld

Older adults know AI is slop. They just like it

AI-generated singers, children, and even virtual lovers are providing seniors with comfort and companionship.
Young people can’t seem to stop watching AI slop videos of cats talking and fruits cheating on each other. Older people are enjoying a different kind of AI-generated content, which...

Thursday, 09. July 2026

OpenID

Public Review Period for Proposed Implementer’s Draft of OpenID Connect Key Binding

The OpenID Connect Working Group recommends approval of the following specification as an OpenID Implementer’s Draft: OpenID Connect Key Binding 1.0 This would be the first Implementer’s Draft of this specification. An Implementer’s Draft is a stable version of a specification providing intellectual property protections to implementers of the specification. This note starts the 45-day pu

The OpenID Connect Working Group recommends approval of the following specification as an OpenID Implementer’s Draft:

OpenID Connect Key Binding 1.0

This would be the first Implementer’s Draft of this specification.

An Implementer’s Draft is a stable version of a specification providing intellectual property protections to implementers of the specification. This note starts the 45-day public review period for the specification draft in accordance with the OpenID Foundation IPR policies and procedures. Unless issues are identified during the review that the working group believes must be addressed by revising the draft, this review period will be followed by a fourteen-day voting period during which OpenID Foundation members will vote on whether to approve this draft as an OpenID Implementer’s Draft.

The relevant dates are:

Implementer’s Draft public review period: Thursday, July 9, 2026 to Sunday, August 23, 2026 (45 days) Implementer’s Draft vote announcement: Monday, August 10, 2026 Implementer’s Draft voting period: Monday, August 24, 2026 to Monday, September 7, 2026

The OpenID Connect working group page is https://openid.net/wg/connect/. Information on joining the OpenID Foundation can be found at https://openid.net/foundation/members/registration. If you’re not a current OpenID Foundation member, please consider joining to participate in the approval vote.

You can send feedback on the specifications in a way that enables the working group to act upon it by (1) signing the contribution agreement at https://openid.net/intellectual-property/ to join the working group, (2) joining the working group mailing list at https://lists.openid.net/mailman/listinfo/openid-specs-ab, and (3) sending your feedback to the list. 

 

Marie Jordan – OpenID Foundation Board Secretary

 

About The OpenID Foundation (OIDF)

The OpenID Foundation (OIDF) is a global open standards body committed to helping people assert their identity wherever they choose. Founded in 2007, we are a community of technical experts leading the creation of open identity standards that are secure, interoperable, and privacy preserving. The Foundation’s OpenID Connect standard is now used by billions of people across millions of applications. In the last five years, the Financial Grade API has become the standard of choice for Open Banking and Open Data implementations, allowing people to access and share data across entities. Today, the OpenID Foundation’s standards are the connective tissue to enable people to assert their identity and access their data at scale, the scale of the internet, enabling “networks of networks” to interoperate globally. Individuals, companies, governments and non-profits are encouraged to join or participate. Find out more at openid.net.



The post Public Review Period for Proposed Implementer’s Draft of OpenID Connect Key Binding first appeared on OpenID Foundation.


EdgeSecure

The Impact of AI on Education

The post The Impact of AI on Education appeared first on Edge, the Nation's Nonprofit Technology Consortium.

Accelerating Change with Business Process Management in Higher Education

The post Accelerating Change with Business Process Management in Higher Education appeared first on Edge, the Nation's Nonprofit Technology Consortium.

DIF Blog

First-Class Identity for Digital Actors

A position paper on identity infrastructure for AI agents and other software-recognizable subjects Written by Christian Saucier, co-chair of the DID Methods Working Group Abstract AI agents and other software-defined actors are being deployed into production at a pace the identity layer beneath them cannot absorb. The

A position paper on identity infrastructure for AI agents and other software-recognizable subjects

Written by Christian Saucier, co-chair of the DID Methods Working Group

Abstract

AI agents and other software-defined actors are being deployed into production at a pace the identity layer beneath them cannot absorb. The DID Core specification has always permitted non-human subjects—much of the ecosystem built around it has not, in its focus on human-controller use-cases. This paper argues that the work required is not a new standard but architectural discipline applied to components that already exist: treating agents as first-class DID subjects, representing authority as verifiable evidence rather than opaque platform state, and recognizing that custody, delegation, and lifecycle management for digital actors demand different primitives than those designed for human-centric consent ceremonies.

What AI Agents Expose About the Identity Layer

AI agents are being deployed into production faster than the identity infrastructure beneath them can absorb. An agent is spawned in a session, handed an API key or an OAuth token, given a system prompt that encodes its authority, and sent out to act across systems on behalf of a person or an organization. The substrate holding this together is a mix of bearer tokens, session state, platform-local service accounts, and prompts, mostly reusing flows that inherit human-controller (and human attacker) assumptions. None of these were designed to identify an actor, dividing authentication from authorization. They were designed to authenticate access or shape behavior inside a single application. They are being asked to carry identity (often implicitly) because no better infrastructure is in place to do so.

The strain is already visible. An agent that needs to act across two platforms is instantiated as a new local principal in each, often with no way of linking the two across the event and access logs. An agent that needs to prove its authority to a third party has nothing to present but a token whose meaning is internal to the issuing platform, with its erroneous authentication assumptions. An agent whose key is compromised has no clean rotation path that other systems will recognize. The problem is not that agents are hard to build. The problem is that the identity layer underneath them is improvised and dangerously ill-adapted to this new context.

AI agents are the visible pressure point. The category is broader — services, devices, organizations, workflows, and infrastructure components face the same problem when they cross administrative boundaries. Agents are simply where the improvisation runs out first.

The Subject Model Was Always Broader

DID Core never restricted decentralized identifiers to humans. A DID subject can be a person, group, organization, thing, digital asset, or concept. A controller may be the subject or a separate authority, a signing service, an authenticator, etc. The standard left ample room for non-human actors. Much of the ecosystem built around it did not, and the underutilized capabilities were forgotten or missed by many observers.

Most decentralized identity practice still assumes a human-centric ceremony: a person, a wallet, an interactive prompt, a real-time verifier, browser sessions and cookies. That ceremony is essential where disclosure and consent are the events that matter. It is inadequate when the subject is a service, a workflow, or an agent operating continuously (and piping context) across systems.

The standards problem is no longer conceptual permission. Non-human subjects already fit the model. The hard work is making that generality usable in wallets, custody systems, authorization flows, messaging protocols, and relying-party practice. A broad subject model has no force or value if every implementation quietly reduces the actor to a human “subaccount”, a platform-local service principal, or a bearer token.

Subject, Controller, Operator, Beneficiary

"The user" is too crude as a universal primitive. It already strains under ordinary organizational identity. For digital actors, it collapses distinctions the system should preserve for many reasons, not least among them baseline privacy and security in an agentic age.

Consider a procurement agent. The agent is the subject. The company is the controller. A department or internal service may operate it. The organization (or even a specific department or client) is the beneficiary. A vendor marketplace may need to verify the agent can request quotes, even if it cannot commit funds at runtime. A finance system may require separate (often asynchronous) authorization before payment. A compliance system may need to reconstruct what authority existed at the time of each action.

Flatten that into "the user authorized the app" and the structure is lost. The subject is the entity identified. The controller has authority over the DID and its control material. The operator runs the actor in context. The beneficiary is who the actor acts for. The issuer makes claims. The verifier evaluates them. The relying party accepts risk.

Simple cases can collapse these roles. Serious systems cannot. If subject, controller, operator, and beneficiary are treated as interchangeable, security semantics become ambiguous and auditability degrades.

Why Agents Force the Issue

Earlier digital actors tolerated improvised identity because they stayed inside narrow boundaries, capabilities, permissions, and time windows. A build service ran inside one CI environment. A bot lived inside one workspace. The improvisation worked because the actor rarely left the administrative domain that defined it.

Three properties make existing improvisations untenable.

Frequency. A human authenticates occasionally and acts deliberately. An agent acts continuously, often many times per minute, under authority delegated earlier by someone no longer in the loop. The consent ceremony anchoring human flows cannot be invoked for every action. Authority has to be expressed once, in a form other systems can evaluate independently.

Consequence. Agents are given real authority — to spend, to commit, to write to systems of record. The cost of acting outside that authority is no longer a misconfigured webhook. It is an unauthorized purchase, a leaked record, a commitment the principal did not intend. The identity substrate has to carry enough structure that a relying party can determine, before accepting an action, what verifiable authority the agent actually has at runtime.

Identity mismatches. An agent is not a logged-in user, not a session, not a tool being invoked. It is an actor with continuity and delegated authority. Treating it as a logged-in user gives it too much — the full human account — and too little — no way to be recognized or held accountable as itself. Treating it as an API key gives it no identity at all, only access.

The industry is responding with longer-lived API keys, agent-specific OAuth clients, and platform-issued "agent accounts" that look like bot users with better marketing. Each is a local improvement. None solve the cross-context problem, because each remains owned by the platform that issued it.

What Has to Change

The DID ecosystem does not need a new grand standard. It needs architectural discipline applied to components that already exist.

Treat agents as first-class subjects. The subject model permits it. The operational ecosystem has to make it usable — wallets that can hold non-human actors, custody systems that govern them, relying parties that recognize them.

Represent authority as evidence. Delegation should be explicit, scoped, attenuated, revocable, and auditable — not hidden inside opaque platform state or bearer-token possession. A relying party should be able to determine who the actor is, who controls it, who authorized it, under what constraints, without private access to one application's database.

Generalize the wallet. The human consent ceremony does not scale to agents. Custody for digital actors means policy-governed signing, headless or organizational key management, threshold or enclave-backed control, and audit substrate. The target is controlled autonomy: software actors operating within bounded, inspectable, revocable authority. A private key in an environment variable is a failed architecture. So is a system requiring human approval for every action.

Anchor, do not absorb. A DID helps to identify the actor. It is not (thought it may contain or help find) the actor's inbox, database, memory store, or audit log. Adjacent protocols — messaging, credential exchange, authorization, storage — coordinate around the identifier without being collapsed into it.

Treat lifecycle as core architecture. Rotation, recovery, compromise response, controller transition, and retirement are normal events in operational systems, not exception cases.

Digital actors are arriving. The question is whether they become portable subjects with explicit authority and durable continuity, or app-local accounts wearing cryptographic clothing. Decentralized identity was built to challenge that pattern for people. The same discipline now belongs in the software layer itself.

Endnote: Where that change could happen

The Decentralized Identity Foundation has spent years building the standards, community, and market substrates that this argument depends on — credential exchange, presentation protocols, secure messaging, trust establishment, wallet interoperability, on the technical side, and an active, committed community on the human side. The work of making non-human subjects first-class participants in the data models and protocols will not happen elsewhere. It will happen in the working groups already composing these pieces, with the agent use case now pulling on every one of them at once.

The Decentralized Identity Foundation (DIF) was established to create an IP-protected environment for decentralized identity-related specifications and open-source code development. DIF promotes the use of DIDs, VCs, and related decentralized identity technologies. DIF maintains more than 270 GitHub repositories that have been contributed or developed by members and working Groups. DIF is committed to fostering an environment where decentralized identity technologies can evolve, mature, and achieve widespread adoption through collaborative effort and strategic partnerships across the ecosystem.

Learn more about Decentralized Identity Foundation (DIF)

EdgeSecure

Learning Machines: Crafting a Future-Ready Cybersecurity Strategy for Higher Education

The post Learning Machines: Crafting a Future-Ready Cybersecurity Strategy for Higher Education appeared first on Edge, the Nation's Nonprofit Technology Consortium.

FIDO Alliance

FIDO Alliance Releases Authenticate U.S. 2026 Agenda

Carlsbad, Calif., July 9, 2026 – The FIDO Alliance has announced the agenda for Authenticate U.S. 2026, the only industry conference dedicated to digital identity and authentication. The event will […]
FIDO Alliance’s flagship event expands its program to tackle the “New Frontiers” of passkeys and modern identity systems Early Bird discounts are available through July 14.

Carlsbad, Calif., July 9, 2026 – The FIDO Alliance has announced the agenda for Authenticate U.S. 2026, the only industry conference dedicated to digital identity and authentication. The event will take place October 19–21, 2026 at the Omni La Costa Resort and Spa in Carlsbad, California, with options for virtual participation available.

The focus of the Authenticate U.S. 2026 program is “New Frontiers.” Trust and simplicity have become the defining challenges of modern identity systems, and passkeys have now proven at global scale that strong security and great usability do not have to be at odds. The next frontier is applying this principle across the entire account lifecycle, from secure account creation, to digital credentials that are recognized across services, to agentic authentication that ensures verified humans stand behind every AI agent acting on their behalf.

“Authenticate is the conference and community where you walk in with passkey questions and walk out with a deployment plan – built on real-world lessons from organizations who’ve scaled to hundreds of millions of users,” said Andrew Shikiar, Executive Director & CEO of FIDO Alliance. “But passkeys are just the starting point for FIDO’s work. This year’s agenda reflects where the ecosystem is heading next: digital credentials, payments, and authentication for trusted AI agents, not just people. If you want to see where authentication is going – not just where it’s been – then you need to be in Carlsbad this October.” 

Visit https://authenticatecon.com/event/authenticate-u-s-2026/ to view the full session guide and register ahead of the July 14th Early Bird deadline.

This year’s event will showcase keynotes and sessions led by top executives and industry leaders at the forefront of the passwordless movement.

With six curated content tracks, Authenticate U.S. 2026 will offer sessions on:

Passkeys in Practice — Leading practices, lessons learned — what went right, what didn’t — and tips and tricks that help deliver safe and successful passkey deployments. Commercial and Regulatory Imperatives — Business rationales and outcomes for passkeys; regulatory considerations including national, regional, and sectoral requirements; fraud detection and prevention; testing and assurance programs; higher-assurance and regulated use cases. Security, Standards, and Architecture in Depth — Deeper dives into the technical underpinnings that deliver usably secure account lifecycles; threat detection and response; standards development; and working group updates. Non-human Authentication — Approaches for protecting the extended user landscape, including mobile and other connected hardware devices, workloads and robotic processes, API protection, and AI use cases including agentic AI and MCP. Mobile and Digital Identity — The role that digital identity wallets and verifiable digital credentials play in securing the account lifecycle; identity proofing and biometrics; and the intersection with payments. New Frontiers in Identity and Authentication — Perspectives on what’s coming next in the identity and authentication space, and how to prepare.

Sponsorship Opportunities Available Authenticate U.S. 2026 offers unique sponsorship opportunities for companies to showcase solutions to an engaged, decision-making audience. With limited availability remaining, prospective sponsors can learn more and apply at authenticatecon.com/sponsors/ or contact sponsors@authenticatecon.com.

About Authenticate

Authenticate is the premier conference dedicated to advancing digital identity and authentication, with an emphasis on phishing-resistant sign-ins using passkeys. Hosted by the FIDO Alliance, this event brings together CISOs, security strategists, product managers, and identity architects to explore best practices, technical insights, and real-world case studies in modern authentication. 

Authenticate is hosted by the FIDO Alliance, the cross-industry consortium providing standards, certifications, and market adoption programs to accelerate utilization of simpler, stronger authentication with innovations like passkeys. Authenticate’s signature sponsors for 2026 are Google, Mastercard, Microsoft and Yubico.

To learn more and register, visit authenticatecon.com/event/authenticate-u-s-2026/. Register now to take advantage of the Early Bird discount, available through July 14, 2026.

Authenticate Contact authenticate@fidoalliance.org

PR Contact pr@fidoalliance.org


Energy Web

Energy Web turns Energy Community Business Models into Verifiable Energy Services via InEExS EU…

Energy Web turns Energy Community Business Models into Verifiable Energy Services via InEExS EU Clean Energy Project Europe’s energy transition is no longer constrained by hardware. Solar (PV), wind, batteries, electric vehicles (EV) and heat pumps are scaling, and at an accelerating rate. What remains constrained is trust: trust in savings calculations, in flexibility delivery, in complianc
Energy Web turns Energy Community Business Models into Verifiable Energy Services via InEExS EU Clean Energy Project

Europe’s energy transition is no longer constrained by hardware. Solar (PV), wind, batteries, electric vehicles (EV) and heat pumps are scaling, and at an accelerating rate. What remains constrained is trust: trust in savings calculations, in flexibility delivery, in compliance reporting and in the integrity of cross-sector energy services.

Energy Web stepped in with a digital infrastructure solution, demonstrated in both commercial and innovation projects, including a recently completed, European Union’s LIFE Clean Energy Transition programme InEExS [Innovative Energy (Efficiency) Service Models for Sector Integration via Blockchain], which ran from November 2022. The project consortium brought together 12 partners from the Netherlands, Germany, Spain, Greece, and Finland, including the Institute for European Energy and Climate Policy — IEECP (NL, project coordinators), Berliner Energieagentur — BEA (DE), Cooperativa Eléctrica Benéfica San Francisco de Asís (ES), domx (GR) and Fortum Power and Heat Oy (FI), with the shared objective of building integrated, blockchain-backed energy service models qualifying for compliance under the European Energy Efficiency Directive (EED) Article 7 Energy Efficiency Obligation Schemes, which covers the energy consumption in the public sector, renovation of public buildings and public procurement.

Energy Web served as the InEExS project’s principal technology solution provider, deploying the Energy Web Verified Compute Cloud (VCC) as the digital trust layer that rendered InEExS business models verifiable, automatable and commercially credible.

InEExS Demonstration: From Blockchain Concept to Verified Compute Infrastructure

Energy Web was established in 2017 with a mission to accelerate decarbonization through decentralized technology. Its Energy Web Verified Compute Cloud (VCC) operates over a network of independent computer nodes (VCC operators), running data and process verification checks and calculations to produce tamper-proof, publicly verifiable results. VCC allows enterprises to deploy business logic like any cloud service, but with cryptographic verification, distributed attestation and tamper-proof auditability, meaning that partners run their calculations, independent computers re-run and cross-check them, then results go onto the Energy Web blockchain (EWX).

In the InEExS context, the Energy Web technology demonstration meant:

Energy calculations, such as energy savings, self-consumption ratios and flexibility activations, run in each implementing partner’s own system; Independent VCC Operators re-executed and verified those computations in parallel, each submitting their result to a shared digital ledger (blockchain). Consensus agreement is locked as the final result on the Energy Web (EWX) chain; no single party can change it after. Sensitive data remains private, while outputs become publicly verifiable.

Energy Web did not replace the business logic developed by each partner. It made that logic verifiable. This distinction is critical. InEExS business cases required regulatory credibility, investor confidence, and operational trust among participating utilities, Energy Service Companies (ESCOs), energy communities, and obligated parties, i.e. energy suppliers or distributors who are legally obliged to prove claimed energy savings under national EED. VCC delivered the execution guarantees that transformed estimates into evidence.

Importantly, the Energy Web VCC platform was developed independently of the InEExS project. In InEExS, Energy Web customized and deployed VCC for each business case: designing Verification Logic (the automated calculation routines that VCC executes and independently verifies), auditing and publishing protocols on-chain, providing technical guidance, and covering infrastructure costs for the project’s duration.

Four Business Cases. One Trust Layer.

Across InEExS pilots, Energy Web Verified Compute Cloud has functioned as a digital certifier, automated Measurement, Reporting, and Verification (MRV) and flexibility verifier, depending on the use case, as briefly presented here:

Figure 1. Energy Web Verified Compute Cloud application in EU InEExS Project Berlin: Solving the Landlord–Tenant Split Incentive
Pay for performance: Energy Web Verified Compute Cloud computed solar quota, solar use and electric vehicles solar quota for multi-tenant buildings, enabling savings according to Energy Performance Certificates (EPC).

As explained by Franziska Tucci, project manager of Berliner Energieagentur (BEA):

“With our case study, we aimed to demonstrate greater transparency for our electricity customers regarding both the generation of electricity from the rooftop PV and their actual electricity usage. Furthermore, the calculations performed in the Energy Web Verified Compute Cloud provided the foundation for developing dynamic tariffs based on actual solar energy utilization.”

The Berlin pilot was led by BEA, Berlin’s public energy agency, with a focus on residential apartment buildings in the city. The challenge was structural: solar self-consumption and dynamic tariff models depend on accurately allocating production and consumption between landlords and tenants. Without trusted measurement, Pay-for-Performance contracts remain fragile.

Energy Web deployed the Energy Web Verified Compute Cloud (VCC) with three Verification Logic protocols: Solar Quota (the ratio of PV energy consumed per building), Solar Utilization (efficiency of PV capacity used by tenants) and EV Solar Quota (the ratio of PV energy consumed per electric vehicle). Solar production and consumption data were calculated by BEA’s own systems. VCC independently verified those calculations and produced a tamper-resistant record of who consumed what, and when. This enabled enforceable, data-backed service agreements. Trust moved from contractual language to cryptographic proof.

Crevillent, Spain: Gamified Energy Community Incentives
Improved distributed energy resources (DER) self-consumption: Energy Web Verified Compute Cloud computed solar and grid efficiency ratios.

The Crevillent pilot was led by ENERCOOP, a local energy cooperative serving 65 member households. The challenge was behavioral: the community needed members to shift demand toward PV generation peaks. Incentives existed, but without proof of load shifting, they lacked credibility. When members of this energy cooperative saw their load shifts registered and rewarded automatically with Energy Web technology, the doubts about whether it counted just stopped, and program participation followed.

Energy Web provided two Verification Logic protocols: Solar Efficiency (the monthly self-consumption ratio per user) and Grid Efficiency (changes in self-consumption behavior across periods). VCC verified deviations from expected consumption profiles and recorded those results on the blockchain, where digital rewards were automatically allocated to each member based on their verified behavior. Incentives became credible financial instruments, backed by data rather than assumptions.

Greece: Verifying Energy Efficiency for Certificate Issuance
Smart boiler control: Energy Web Verified Compute Cloud computed actual energy consumption and daily savings from DOMX Heating Controller.

Stratos Keranidis, co-founder and R&D Director at domx stated:

“We knew that our IoT-based space heating system was saving energy every day. What we could not do before was provide trusted proof of those savings to energy suppliers and energy efficiency certification bodies. Energy Web Verified Compute Cloud closed that gap.”

The Greek pilot was led by domx, a technology provider specializing in IoT-based heating management solutions. The pilot was implemented across five Greek cities (Athens, Thessaloniki, Larisa, Trikala, Volos) involving 50 retail consumers using heat pumps and natural gas boilers. The use case focused on improving the energy efficiency of space heating systems. Traditionally, energy savings are calculated using baseline estimations, which are often difficult to validate, open to dispute, and rarely monetized at scale.

Energy Web deployed two Verifications:

Actual Energy Consumption, verifying daily energy use for space heating based on DOMX IoT controller data. Energy Savings Estimation, verifying daily kWh savings by comparing baseline operation with energy-saving mode.

Energy Web Verified Compute Cloud acted as an automated MRV layer, verifying that the logic executed correctly and producing tamper-resistant outputs. This transformed estimated energy savings into verifiable results, a prerequisite for issuing Energy Savings Certificates under Article 7 of the Energy Efficiency Directive (EED).

By replacing estimation with verification, VCC demonstrated how energy efficiency compliance can become programmable, transparent, and scalable.

Nordics: Proving Flexibility Delivery
Smart EV charging scheduling: Energy Web Verified Compute Cloud computed cost savings from schedules submitted via smart contracts.

The Nordic pilot was led by Fortum Power and Heat Oy, one of the region’s leading energy companies, headquartered in Espoo, Finland. Smart homes in the pilot could shift between EV charging and heating loads, but grid operators require proof of flexibility delivery before it can be traded as a service. Energy Web provided the Smart Charge Savings Verification Logic protocol, calculating cost savings based on submitted EV charging schedules. VCC verified deviations from baseline consumption profiles without exposing sensitive household data. Each flexibility action generated a tamper-proof digital record. This bridged the gap between distributed assets and grid-level trust requirements, enabling flexibility to become a tradable, auditable service.

Across all four cases, the pattern is clear: different services, same enhanced and reliable trust layer.

Commercial Pathways Beyond InEExS

The implications of Energy Web Verified Compute Cloud capabilities extend beyond the InEExS pilots.

Utilities and obligated parties can deploy VCC-backed compliance infrastructure to automate reporting under EED Article 7. Instead of manual audits and fragmented documentation, savings become continuously verifiable digital assets. Energy communities can embed VCC into local platforms to render peer demand response incentives, shared self-consumption, and any future energy trading and flexibility schemes auditable and finance-ready. ESCOs and aggregators can package verified performance data into investable portfolios, reducing counterparty risk and enabling performance-based financing. Service providers, such as IoT, building energy management systems (BEMS) and EV charging platform operators, can integrate VCC via APIs to offer verification-as-a-service on top of existing energy management platforms. Figure 2. Energy Web Verified Compute Cloud: neutral, decentralized infrastructure, enabling interoperability among multiple commercial energy services

By embedding decentralized verification into sector-integrated business models, Energy Web in InEExS project demonstrated a solution that provides a set of data security and privacy guarantees, benefiting prosumers and energy communities:

Savings cannot be manipulated retroactively. Flexibility delivery is provable without exposing private data. Contract execution becomes transparent and automatable Compliance moves from paperwork to programmable evidence.

Energy Web turns Energy Community Business Models into Verifiable Energy Services via InEExS EU… was originally published in Energy Web on Medium, where people are continuing the conversation by highlighting and responding to this story.


OpenID

As AltID launches, Danish media seek OIDF view

Denmark’s launch of AltID, a government-backed digital wallet, prompted questions about what the new technology means for citizens and how it differs from existing digital identity systems. Major Danish national media outlets, including DR, reported on the new technology. Several leading publications, including Ekstra Bladet, Input Magazine, Mere Mobil and IT Kanalen, sought expert comment […] T

Denmark’s launch of AltID, a government-backed digital wallet, prompted questions about what the new technology means for citizens and how it differs from existing digital identity systems.

Major Danish national media outlets, including DR, reported on the new technology. Several leading publications, including Ekstra Bladet, Input Magazine, Mere Mobil and IT Kanalen, sought expert comment from the OpenID Foundation community. Frederik Krogsdal Jacobsen, Staff Software Engineer at Idura and an active participant in the OpenID Foundation’s Digital Credentials Protocols Working Group, explained how the technology works, how it differs from previous approaches, and some of the practical considerations that remain.

Helping the Danish media understand what AltID means for consumers

Frederik talked through the shift from MitID’s centralised authentication model to AltID’s selective disclosure approach, using practical examples to illustrate how it works. For example, proving you’re over 18 without showing a full ID, or proving your name without your address.

He also highlighted two areas for further consideration. First, because AltID relies on smartphones, it depends on a small number of global mobile platforms, making alternative forms of access, such as dedicated physical devices, an important longer term consideration. Second, he noted that, as with MitID, some older users may find the technology challenging to adopt.

Why journalists turned to the OpenID Foundation 

AltID is one of several national digital wallets being introduced as part of the broader EU Digital Identity Wallet (EUDIW) initiative, alongside programmes underway in Germany, Italy and all other EU member states. 

The OpenID Foundation has developed the open international standards that let digital wallets like AltID issue and verify credentials in a consistent way. These are the same standards underpinning the EU Digital Identity Wallet (EUDIW) programme. As of December 2026, EU member states are legally required to trust credentials from Notified EUDI wallets, creating a foundation for cross border recognition. Once AltID is notified, credentials built to this standard can be trusted across Europe, not just within Denmark, and sets the foundations for interoperability globally.

That makes the Foundation’s community a natural point of call when a national launch like AltID raises questions that go beyond one country: what selective disclosure actually means in practice, how wallets differ from what came before, and what still needs to be solved as they scale. 

As more countries launch, public interest will grow. This interest will be centred in understanding how these systems protect privacy and security compared to existing systems. For Danish users accustomed to eID systems that log usage, understanding how selective disclosure limits data exposure is the more pressing question. 

Journalists, in turn, are looking for experts who can explain this credibly and without commercial interest, which is why standards experts, rather than commentators unfamiliar with the underlying technology, are becoming essential sources as these launches continue.

The AltID launch is one example of how national digital identity developments are creating demand for independent technical expertise. As digital wallet deployments continue across Europe, the OpenID Foundation’s community is well placed to provide context on the standards, interoperability and implementation considerations behind these initiatives, and proud to offer that expertise where it is needed.

About the OpenID Foundation

The OpenID Foundation (OIDF) is a global open standards body committed to helping people assert their identity wherever they choose. Founded in 2007, we are a community of technical experts leading the creation of open identity standards that are secure, interoperable, and privacy preserving. The Foundation’s OpenID Connect standard is now used by billions of people across millions of applications. In the last five years, OAuth2 – the FAPI standard for interoperable, high security – has become the standard of choice for Open Banking and Open Data implementations, allowing people to access and share data across entities. Today, the OpenID Foundation’s standards are the connective tissue that enable people to assert their identity and access their data at scale, the scale of the internet, enabling “networks of networks” to interoperate globally. Individuals, companies, governments and non-profits are encouraged to join or participate. Find out more at openid.net.

 

The post As AltID launches, Danish media seek OIDF view first appeared on OpenID Foundation.

Wednesday, 08. July 2026

OpenID

Errata to OpenID Identity Assurance Specifications Approved

Errata to the following specifications have been approved by a vote of the OpenID Foundation members: First Errata Set for OpenID Connect for Identity Assurance 1.0: This extension to OpenID Connect standardizes how relying parties request and receive identity information with additional assurance metadata. First Errata Set for OpenID Identity Assurance Schema Definition 1.0: This specificati

Errata to the following specifications have been approved by a vote of the OpenID Foundation members:

First Errata Set for OpenID Connect for Identity Assurance 1.0: This extension to OpenID Connect standardizes how relying parties request and receive identity information with additional assurance metadata.

First Errata Set for OpenID Identity Assurance Schema Definition 1.0: This specification defines a schema for describing assured identity claims and a range of associated identity assurance metadata. An Errata version of a specification incorporates corrections identified after the Final Specification was published. This specification is a product of the OpenID eKYC & IDA Working Group.

The voting results were:

Approve – 66 votes Object – 1 vote Abstain – 28 votes

Total votes: 95 (out of 445 members = 21.2% > 20% quorum requirement)

The specifications incorporating the errata is available at the standard locations as well as:

https://openid.net/specs/openid-connect-4-identity-assurance-1_0-errata1.html

https://openid.net/specs/openid-ida-verified-claims-1_0-errata1.html   See the Introduction sections of the specifications for the link to the previously approved version.

 

Marie Jordan – OpenID Foundation Secretary

     

About The OpenID Foundation (OIDF)

The OpenID Foundation (OIDF) is a global open standards body committed to helping people assert their identity wherever they choose. Founded in 2007, we are a community of technical experts leading the creation of open identity standards that are secure, interoperable, and privacy preserving. The Foundation’s OpenID Connect standard is now used by billions of people across millions of applications. In the last five years, the Financial Grade API has become the standard of choice for Open Banking and Open Data implementations, allowing people to access and share data across entities. Today, the OpenID Foundation’s standards are the connective tissue to enable people to assert their identity and access their data at scale, the scale of the internet, enabling “networks of networks” to interoperate globally. Individuals, companies, governments and non-profits are encouraged to join or participate. Find out more at openid.net.

 

The post Errata to OpenID Identity Assurance Specifications Approved first appeared on OpenID Foundation.


Hyperledger Foundation

Web3j 6 Release: Fusaka and Agentic Ready

A new milestone release of Web3j has just gone out — Web3j 6.0!

A new milestone release of Web3j has just gone out — Web3j 6.0!

Tuesday, 07. July 2026

EdgeSecure

Transforming Communication: The Zoom Phone Project at Stevens Institute of Technology

The post Transforming Communication: The Zoom Phone Project at Stevens Institute of Technology appeared first on Edge, the Nation's Nonprofit Technology Consortium.

FIDO Alliance

Cyber Insider: ExpressVPN adds passkeys on password manager, passes security audit

ExpressVPN has announced a major update to its standalone ExpressKeys password manager, adding passkey support, secure credential sharing, and direct vault imports. Alongside the release, the company published a new […]

ExpressVPN has announced a major update to its standalone ExpressKeys password manager, adding passkey support, secure credential sharing, and direct vault imports.

Alongside the release, the company published a new independent security assessment by Cure53, which found no severe vulnerabilities in the application after reviewing its architecture and mobile apps.

ExpressVPN, which is best known for its commercial VPN service (see our ExpressVPN review), launched ExpressKeys as a standalone password manager earlier this year. The application stores passwords, payment cards, secure notes, passkeys, and two-factor authentication codes across mobile devices and browsers for eligible subscribers.

Passkeys land on ExpressKeys

Among the most significant additions is support for passkeys, allowing users to generate, store, and authenticate with FIDO-compatible credentials instead of traditional passwords. As more online services adopt passkeys, password managers are increasingly adding support to help users transition away from reusable passwords that remain vulnerable to phishing and credential stuffing attacks.

The update also introduces secure sharing for individual vault items. Instead of sending passwords or payment information via messaging apps or email, users can generate links that expire after a configurable period, optionally require email verification, or become invalid after a single view. Access to shared items can also be revoked from within the application.


OpenID

Public Review Period for Proposed Implementer’s Drafts of Two OpenID Federation Extensions

The OpenID Connect Working Group recommends approval of the following specifications as OpenID Implementer’s Drafts: OpenID Federation Subordinate Events Endpoint 1.0 OpenID Federation Extended Subordinate Listing 1.0 These would be the first Implementer’s Draft of these specifications. An Implementer’s Draft is a stable version of a specification providing intellectual property protecti

The OpenID Connect Working Group recommends approval of the following specifications as OpenID Implementer’s Drafts:

OpenID Federation Subordinate Events Endpoint 1.0 OpenID Federation Extended Subordinate Listing 1.0

These would be the first Implementer’s Draft of these specifications.

An Implementer’s Draft is a stable version of a specification providing intellectual property protections to implementers of the specification. This note starts the 45-day public review period for the specification draft in accordance with the OpenID Foundation IPR policies and procedures. Unless issues are identified during the review that the working group believes must be addressed by revising the draft, this review period will be followed by a fourteen-day voting period during which OpenID Foundation members will vote on whether to approve this draft as an OpenID Implementer’s Draft.

The relevant dates are:

Implementer’s Draft public review period: Tuesday, July 7, 2026 to Wednesday, August 19, 2026 (45 days) Implementer’s Draft vote announcement: Thursday, August 6, 2026 Implementer’s Draft voting period: Thursday, August 20, 2026 to Thursday, September 3, 2026

 

The OpenID Connect working group page is https://openid.net/wg/connect/. Information on joining the OpenID Foundation can be found at https://openid.net/foundation/members/registration. If you’re not a current OpenID Foundation member, please consider joining to participate in the approval vote.

You can send feedback on the specifications in a way that enables the working group to act upon it by (1) signing the contribution agreement at https://openid.net/intellectual-property/ to join the working group, (2) joining the working group mailing list at https://lists.openid.net/mailman/listinfo/openid-specs-ab, and (3) sending your feedback to the list. 

 

Marie Jordan – OpenID Foundation Board Secretary

 

About The OpenID Foundation (OIDF)

The OpenID Foundation (OIDF) is a global open standards body committed to helping people assert their identity wherever they choose. Founded in 2007, we are a community of technical experts leading the creation of open identity standards that are secure, interoperable, and privacy preserving. The Foundation’s OpenID Connect standard is now used by billions of people across millions of applications. In the last five years, the Financial Grade API has become the standard of choice for Open Banking and Open Data implementations, allowing people to access and share data across entities. Today, the OpenID Foundation’s standards are the connective tissue to enable people to assert their identity and access their data at scale, the scale of the internet, enabling “networks of networks” to interoperate globally. Individuals, companies, governments and non-profits are encouraged to join or participate. Find out more at openid.net.



The post Public Review Period for Proposed Implementer’s Drafts of Two OpenID Federation Extensions first appeared on OpenID Foundation.

Monday, 06. July 2026

GLEIF

Transforming Data into Opportunities: Metric in Motion – AI-Powered Duplicate Detection

Every Legal Entity Identifier (LEI) is unique and can represent only one entity. Each entity can hold only one LEI code. These principles underpin the Global LEI System, enabling anyone, anywhere in the world, to identify legal entities with confidence. Preventing duplicate LEI records is therefore essential to preserving trust in the Global LEI System and is a key part of GLEIF’s proactive dat

Every Legal Entity Identifier (LEI) is unique and can represent only one entity. Each entity can hold only one LEI code. These principles underpin the Global LEI System, enabling anyone, anywhere in the world, to identify legal entities with confidence.

Preventing duplicate LEI records is therefore essential to preserving trust in the Global LEI System and is a key part of GLEIF’s proactive data quality management program. A well-established duplicate detection and remediation process – comprising preventive controls, LEI issuer commitment and review, and clear operational procedures – already means that potential duplicates account for less than 0.2% of all records in the Global LEI System.

Strengthening Duplicate Detection with AI

As data volumes and complexity continue to increase, GLEIF is committed to further improvements to duplication detection processes. In particular, AI presents new opportunities to promote a more accurate, scalable, and consistent approach.

One key control already being enhanced by AI is GLEIF’s 'Check for Duplicates' facility.

Check for Duplicates is a feature that enables LEI issuers to assess whether the proposed LEI and the associated reference data may already exist in the Global LEI Index before a new LEI is published. During the issuance process, new records are compared against both the full LEI Index and records that have not yet been issued by other LEI issuers. This helps ensure that, even if the same legal entity approaches multiple LEI issuers, potential duplicates can be identified and resolved before publication.

With AI support, the facility now goes beyond the previous algorithm, which relied mainly on fuzzy name matching. It enables earlier detection, more effective comparison of potentially related records, and coordinated resolution before publication.

How It Works

The enhanced duplicate detection process follows a structured workflow that consists of three main steps:

Pre-processing:
The submitted record is cleaned and standardized. This includes removing punctuation, normalizing spaces, parsing the record to extract relevant reference data, and generating vector embeddings for later comparison. Filtering:
An AI-enhanced backend then identifies potential matches. The process first checks the LEI code, then compares registration authorities and registration identifiers. Selected reference data elements are also converted into vector embeddings and matched against existing records in the Global LEI Index. Records with potential matches are then passed to the scoring stage. Scoring:
This step further evaluates these potential matches to reduce false positives. It considers elements such as the legal name, legal form, address, jurisdiction, and entity creation date, with additional handling for specific categories such as funds and branches.

Faster, Scalable, and More Consistent Duplicate Detection

Together, this process strengthens duplicate detection by enabling:

Faster and earlier detection of potential duplicate registrations before a new LEI is published in the Global LEI Index. Improved scalability as the Global LEI System continues to grow, as the use of vector embeddings enables records to be compared against large volumes of existing LEI reference data. Consistent and standardized approach independent of the nature and location of the LEI issuer. Stronger data quality controls by checking multiple data elements, including LEI code, registration authority, identifiers, legal name, address, jurisdiction, and legal form.

Harnessing the Potential of AI for Duplicate Detection

Through AI-supported pre-processing, filtering, and scoring, it is clear how AI is enabling the Check for Duplicates feature to become more scalable, efficient, and context-aware.

For AI to deliver reliable results, it needs to be built on complete and trustworthy data and supported by clear governance. At GLEIF, this governance is reinforced through proactive data quality management, established validation processes, and continuous monitoring of the Global LEI System. AI recommendations are combined with transparent decision-making, continuous refinement of the detection models, and human expertise and oversight to ensure accurate and consistent results.

Together, these elements support GLEIF’s continued commitment to proactive data quality management and maintaining trust across the Global LEI System.


EdgeSecure

Edge Expands EdgeMarket with RightSpot™, a Right Angle Solutions, Inc.’s Flagship Platform for Smarter Student Safety Across School Districts Nationwide.

Edge Expands EdgeMarket with RightSpot™, a Right Angle Solutions, Inc.’s Flagship Platform for Smarter Student Safety Across School Districts Nationwide. NEWARK, NEW JERSEY, July 6, 2026 – Edge, the nation’s… The post Edge Expands EdgeMarket with RightSpot™, a Right Angle Solutions, Inc.’s Flagship Platform for Smarter Student Safety Across School Districts Nationwide. appeared first on Edge, th
Edge Expands EdgeMarket with RightSpot, a Right Angle Solutions, Inc.’s Flagship Platform for Smarter Student Safety Across School Districts Nationwide.

NEWARK, NEW JERSEY, July 6, 2026 – Edge, the nation’s leading member-owned nonprofit technology consortium, today announced the addition of Right Angle Solutions, Inc. (RAS) to its EdgeMarket cooperative purchasing platform. Edge members can now access RightSpot, RAS’s flagship student safety platform built to help schools modernize dismissal operations, improve real-time student visibility, reduce communication gaps, and give staff and parents greater confidence that every student is safely accounted for.

RightSpot, Right Angle Solutions’ flagship student safety platform, is now available through EdgeMarket to help schools modernize student safety operations and manage one of the most complex moments of the school day: dismissals. Purpose-built for education environments, RightSpot combines real-time GPS visibility, intelligent field notifications, geospatial analytics, and integration-ready APIs to help schools strengthen student accountability, reduce communication gaps, improve operational coordination, and give staff and families greater confidence that every student is safe, visible, and accounted for.

“Peace Of Mind Begins When Schools And Families Know Every Student Is Safe And Accounted For.”

Through EdgeMarket, member institutions can access RightSpot, Right Angle Solutions’ flagship student safety platform, along with supporting technology capabilities across eight awarded categories: mobile and field operations; analytics and responsible AI; cloud architecture and hosting; interoperability and APIs; data management and portability; usability and accessibility; artificial intelligence; and the proprietary RightSpot platform. Member institutions may adopt individual capabilities independently or as part of an integrated ecosystem, allowing them to modernize student safety operations at their own pace without disrupting existing systems or daily school operations.

“Right Angle Solutions brings deep public sector experience and a proven platform that will make a meaningful difference for our members. RightSpot addresses a genuine need: schools want modern, interoperable student safety technology that improves real-time visibility, accountability, and coordination, but they often lack a fast and efficient procurement pathway. Adding RAS to EdgeMarket changes that, and we’re excited to see how our members use RightSpot to strengthen student safety across their communities.”

– Dan Miller
Assistant Vice President, EdgeMarket and Solution Strategy
Edge

Dan Miller, Assistant Vice President, EdgeMarket and Solution Strategy, Edge, notes, “Right Angle Solutions brings deep public sector experience and a proven platform that will make a meaningful difference for our members. RightSpot addresses a genuine need: schools want modern, interoperable student safety technology that improves real-time visibility, accountability, and coordination, but they often lack a fast and efficient procurement pathway. Adding RAS to EdgeMarket changes that, and we’re excited to see how our members use RightSpot to strengthen student safety across their communities.”

RightSpot is designed to connect with existing school and operational systems through RAS’s Open Integration Framework, enabling institutions to integrate data, workflows, field operations, and reporting without vendor lock-in. The platform supports real-time geospatial visibility, intelligent notifications, integration-ready APIs, and analytics that help schools improve student accountability, streamline coordination, and make more informed operational decisions. Proven client outcomes include a 70% reduction in parent call volume at Weehawken School District, a 35% reduction in system maintenance costs at the Institute of International Education, and a 40% reduction in review cycle times at the County of Morris, New Jersey.

About Right Angle Solutions

Right Angle Solutions, Inc. is a New Jersey-based certified Minority, Small, and Disadvantaged Business Enterprise with more than 22 years of experience delivering technology modernization solutions to government, education, healthcare, transportation, and nonprofit organizations across the United States. RAS’s portfolio includes more than 150 successful implementations for more than 50 clients, and the company is a certified Microsoft Solution Partner with expertise in Azure Cloud and Dynamics 365. Its flagship RightSpot platform is deployed across New Jersey school districts and public agencies, delivering real-time geospatial visibility, student safety coordination, and cloud-enabled operational support.

For more information, visit www.rightanglesol.com

About Edge

Edge serves as a member-owned, nonprofit provider of high-performance optical fiber networking and internetworking, Internet2, and a vast array of best-in-class technology solutions for cybersecurity, educational technologies, cloud computing, and professional managed services. Edge provides these solutions to colleges and universities, K-12 school districts, government entities, hospital networks, and nonprofit business entities as part of a membership-based consortium spanning across the nation. 

The post Edge Expands EdgeMarket with RightSpot™, a Right Angle Solutions, Inc.’s Flagship Platform for Smarter Student Safety Across School Districts Nationwide. appeared first on Edge, the Nation's Nonprofit Technology Consortium.


FIDO Alliance

Tech Radar Pro: Know your agent: building the foundation of autonomous commerce

Artificial intelligence has officially entered its execution phase. After years of experimentation, businesses are rapidly deploying AI not just to analyze data, but to act on it. At the forefront of […]

Artificial intelligence has officially entered its execution phase. After years of experimentation, businesses are rapidly deploying AI not just to analyze data, but to act on it.

At the forefront of this shift are AI agents, autonomous systems designed to execute complex tasks, automate workflows, and interact with other digital systems on our behalf.


PaymentsJournal: EMVCo Proposes Standards for Stronger Payment Authentication

EMVCo has released a draft framework that could pave the way for a universal standard for verifiable digital credentials in card‑based payments, a move that could make online checkout both […]

EMVCo has released a draft framework that could pave the way for a universal standard for verifiable digital credentials in card‑based payments, a move that could make online checkout both more secure and less cumbersome.

As verifiable digital credentials continue to gain traction for secure digital transactions, EMVCo is working to ensure that its data structures remain consistent, regardless of the wallet or payment network used.

If adopted, the framework would allow merchants to implement a single standard for digital credential authentication across payment ecosystems instead of managing multiple wallet-specific integrations.


OpenID

OIDF proud to support BIS Innovation Hub’s Aperta Report

The BIS Innovation Hub has published its Project Aperta report, a significant milestone for cross-border open finance and a meaningful validation of the open standards approach that the OpenID Foundation has long championed. Project Aperta has been designing, developing, and testing a prototype for cross-border open finance interconnectivity through APIs – connecting the open finance […] The pos

The BIS Innovation Hub has published its Project Aperta report, a significant milestone for cross-border open finance and a meaningful validation of the open standards approach that the OpenID Foundation has long championed.

Project Aperta has been designing, developing, and testing a prototype for cross-border open finance interconnectivity through APIs – connecting the open finance networks of the UK, the UAE, Brazil, Hong Kong, and India. The project proves that secure, interoperable data sharing across borders is achievable within existing banking infrastructure, without rebuilding from scratch.

The OpenID Foundation’s role

The OpenID Foundation contributed to Project Aperta as an observing member, with the Foundation’s Vice-Chair Dima Postnikov and Board Member Mark Verstege serving as liaisons to the project.

They joined an observer list spanning central banks, regulators, and international institutions, including the Monetary Authority of Singapore, the Reserve Bank of India, Swift, the World Economic Forum, and the United Nations Commission on International Trade Law (UNCITRAL). The breadth of that observer community is a reflection of the significance Project Aperta holds for the global financial community.

Open standards at the core

Project Aperta adopts FAPI 2.0 as its underlying security profile. It was chosen specifically to leverage an industry accepted pattern already proven across multiple open finance deployments and to avoid custom security designs across jurisdictions. 

The report also grounds the project’s trust framework in OpenID Federation principles and identifies it as the preferred architecture for the next phase of cross-border open finance interoperability.

Dima said: “FAPI 2.0 and OpenID Federation are already powering open finance ecosystems across multiple jurisdictions globally. Seeing them adopted at this level, in a BIS led initiative involving central banks and regulators from five continents, is a significant validation of the work the OpenID Foundation community has put into developing these standards. Project Aperta shows what becomes possible when proven open standards are applied to genuinely hard interoperability problems.”

What Project Aperta proves

Project Aperta demonstrates that secure cross-border data portability is feasible within the existing banking ecosystem, using SME banking and trade finance as concrete test cases. Its outputs, including architectural documents, trust and identity system designs, and reference code, have been made publicly available for the central banking community to build on.

Looking ahead, the report suggests that small groups of jurisdictions with mature open finance ecosystems could pilot further real-world use cases, building the operational, legal, and governance foundations needed for broader global adoption.

Gail Hodges, Executive Director of the OpenID Foundation, said: “Project Aperta is exactly the kind of initiative the OpenID Foundation standards are designed to support. Our thanks to OIDF member, Raidiam, for their work on the trust services, security profile, and ecosystem integration, and to Ozone API for their work on the FAPI compliant reference implementations. We look forward to the next phase of this work on open data across borders, and other cutting edge applications of FAPI 2.0 and OpenID Federation.” 

About the OpenID Foundation

The OpenID Foundation (OIDF) is a global open standards body committed to helping people assert their identity wherever they choose. Founded in 2007, we are a community of technical experts leading the creation of open identity standards that are secure, interoperable, and privacy preserving. The Foundation’s OpenID Connect standard is now used by billions of people across millions of applications. In the last five years, OAuth2 – the FAPI standard for interoperable, high security – has become the standard of choice for Open Banking and Open Data implementations, allowing people to access and share data across entities. Today, the OpenID Foundation’s standards are the connective tissue that enable people to assert their identity and access their data at scale, the scale of the internet, enabling “networks of networks” to interoperate globally. Individuals, companies, governments and non-profits are encouraged to join or participate. Find out more at openid.net.

 

The post OIDF proud to support BIS Innovation Hub’s Aperta Report first appeared on OpenID Foundation.

Friday, 03. July 2026

FIDO Alliance

Introducción a passkeys

Watch the presentation WEBINAR | Introducción a passkeys Participa en nuestro webinar el 1 de julio de 2026 a las 11 a. m. ET para una introducción a passkeys (llaves […]
Watch the presentation

WEBINAR | Introducción a passkeys

Participa en nuestro webinar el 1 de julio de 2026 a las 11 a. m. ET para una introducción a passkeys (llaves de acceso). Esta sesión, presentada en español, ayudará a los asistentes a entender qué son las passkeys, cómo funcionan, cómo simultáneamente protegen contra el phishing y proveen una mejor experiencia de usuario, y el impacto que están generando.

¿No puedes asistir en vivo? ¡Regístrate para recibir la grabación y verla cuando mejor te convenga!

Moderator: Diego Zavala, Director para LATAM, FIDO Alliance

Este webinar es presentado por FIDO Americas Adoption Forum. Este foro tiene como foco promover el uso de passkeys en Latinoamérica.

Wednesday, 01. July 2026

FIDO Alliance

Biometric Update: Yubico hackathon to preview YubiKey 5.8 support for next-generation passkeys

Yubico will host a virtual developer hackathon for the FIDO Alliance developer community on August 5 to give developers an early look at the company’s upcoming YubiKey 5.8 firmware release and its support […]

Yubico will host a virtual developer hackathon for the FIDO Alliance developer community on August 5 to give developers an early look at the company’s upcoming YubiKey 5.8 firmware release and its support for CTAP 2.3 capabilities.

Participants will receive a limited edition YubiKey 5C NFC running the upcoming 5.8 firmware. They aim to give developers direct access to new FIDO2 capabilities in a hardware authenticator. Developers will be able to experiment with how the updated firmware behaves in practical authentication, identity, and authorization flows.


Origin Trail

Google’s OKF comes to the OriginTrail DKG: A memory AI agents can trust

Google’s Open Knowledge Format (OKF) gave agents a portable way to document knowledge. Connected to the OriginTrail Decentralized Knowledge Graph (DKG), that knowledge becomes something an agent can prove, own, and build on: a shared memory, not a model’s best guess. Everything humans have built, we built on knowledge we inherited. We don’t rediscover fire every morning. We stand on what oth

Google’s Open Knowledge Format (OKF) gave agents a portable way to document knowledge. Connected to the OriginTrail Decentralized Knowledge Graph (DKG), that knowledge becomes something an agent can prove, own, and build on: a shared memory, not a model’s best guess.

Everything humans have built, we built on knowledge we inherited. We don’t rediscover fire every morning. We stand on what others worked out before us, and we trust it because we can trace it: a source, a citation, a name behind the claim. AI agents have none of that inheritance. Each one wakes up empty, re-derives the world from scratch, and when it tells you something, neither it nor you can say where that knowledge came from, or whether to believe it. That gap, knowledge with no memory and no provenance, is the real reason we still hesitate to hand AI the decisions that matter.

This integration begins to close that gap. We’ve connected Google’s Open Knowledge Format (OKF) (an open, vendor-neutral standard for recording knowledge as portable Markdown that any system can read — V1 introduced in June 2026) to the OriginTrail Decentralized Knowledge Graph (DKG), the layer that gives that knowledge an origin, an owner, and a proof. OKF is portable by design but deliberately carries no trust layer: Google itself lists trust tiers among the open questions in v0.1. The DKG is exactly that missing layer.

On its own, OKF is portable text; the DKG is what makes that text trustworthy. Together, they turn a static bundle into a living memory that any permitted agent can subscribe to, query, and, above all, trust.

Open Knowledge Format (OKF): Write knowledge once, read it anywhere

Take OKF on its own first. Machine-readable knowledge is scattered today (across catalogs, wikis, code comments, and private stores), so every agent rebuilds its context from scratch. OKF replaces that with a single portable artifact: a bundle of plain-Markdown concept files, each with light YAML frontmatter and links to related concepts, where the format itself is the only contract.

Any tool can write a bundle and any tool can read it (no SDK, no runtime, no translation, no platform to adopt), so knowledge is written once and stays readable by anything, anywhere.

Figure 1: How OKF works on its own. Producers write portable Markdown bundles that any consumer reads without translation. After Google Cloud’s OKF announcement. OKF to Decentralized Knowledge Graph (DKG): Context imported, not invented

One command does the whole thing — transforming the OKF into verifiable knowledge on the DKG:

dkg okf import <bundle> — context-graph-id <cg> — create-context-graph — share

But the command isn’t the point; what it refuses to do is. There is no LLM anywhere in the import path. The mapping from an OKF bundle to the graph is pure and deterministic: the same bundle produces byte-identical triples, every time, on any machine. This can read like a technical footnote, but it is, in fact, the foundation the rest stands on.

A signed, owned, “verifiable” fact is only as trustworthy as the step that produced it, and if that step is a language model’s best guess, you haven’t built verifiable memory, you’ve built a verifiably signed hallucination.

Deterministic import is what lets the DKG’s provenance mean something: it proves not just who asserted a fact, but that the fact faithfully reflects its source, and anyone can re-run the import and get exactly the same graph. It also keeps faith with OKF itself: cross-links become untyped directed edges, exactly as the spec defines them, with no invented relationship types. Nothing is embellished, nothing is guessed; what was written is what gets remembered.

Figure 2: The same bundle through the OriginTrail DKG. A deterministic import turns it into shared, provenance-bearing memory that many agents can query and trust. Demo: Microstrategy’s Bitcoin treasury, traced to two sources

Take a real provenance problem. Strategy Inc (Nasdaq: MSTR, formerly MicroStrategy) holds the world’s largest corporate Bitcoin treasury, disclosed purchase-by-purchase in SEC Form 8-K filings and re-published by community dashboards. We collated it into an OKF bundle from two sources of differing authority: SEC EDGAR (the filings themselves) and SaylorTracker, a derived dashboard used only as a cross-check.

Before DKG: The bundle is a folder of plain Markdown concepts, one per SEC Form 8-K filing, plus a concept for each source. Every transaction records its numbers and cites both sources: SEC EDGAR as the authoritative record, SaylorTracker as the cross-check. But that provenance is only prose and links. A person can read which filing a number came from; nothing can query which transactions are EDGAR-verified, reconcile the two sources, or prove the chain from a holdings figure back to the 8-K that established it.

Figure 3: The same treasury data as an OKF bundle, before the DKG. Every purchase is a Markdown concept that cites both SEC EDGAR (authoritative) and SaylorTracker (cross-check), but only as prose links: readable, not queryable or provable.

The concept the figure highlights, transactions/2026–04–19.md, as it sits in the bundle. Its numbers are YAML frontmatter; its two sources are ordinary Markdown links, nothing the bundle itself can act on.

— —
type: Bitcoin Treasury Transaction
title: Strategy BTC acquisition, 2026–04–13 to 2026–04–19
btc_delta: 34164
avg_price: 74395
cumulative_btc: 815061
tags: [mstr, bitcoin, treasury, acquisition, edgar-verified]
# usd_amount, period dates, accession_no, … the rest of the disclosure fields
— —
# Provenance
Primary source: [SEC EDGAR](../sources/sec-edgar.md), Form 8-K announced 2026–04–20.
Reconciliation: [SaylorTracker](../sources/saylortracker.md), the derived dashboard.
# Citations
[1] [SEC Form 8-K, Strategy Inc (CIK 0001050446), 2026–04–20](https://www.sec.gov/cgi-bin/browse-edgar?action=getcompany&CIK=0001050446&type=8-K), authoritative.
[2] [SaylorTracker](https://saylortracker.com/), cross-check.

After DKG: Imported into the Decentralized Knowledge Graph, every citation becomes a first-class edge, and each source becomes a node that its transactions point to.

The two-source provenance turns into a queryable structure, checked with SPARQL (which filing backs a metric, which purchases are EDGAR-verified), and the bundle becomes owned, verifiable Knowledge Assets carrying cryptographic provenance (a Merkle root plus an EIP-712 attestation).

An agent no longer just reads that EDGAR is authoritative; it can verify the chain from a number to the filing.

The provenance that existed only as prose citations is now edges in a graph database that any permitted system can traverse, query, and verify. A treasury record collated from public filings became knowledge that an agent can prove, own, and build on.

Why OKF needs the DKG

A portable file is only as trustworthy as the hands it has passed through. That is the catch with any knowledge format on its own: OKF can carry knowledge anywhere, but take away who wrote it and whether it has been altered, and you are left with text that looks authoritative and proves nothing, which is the exact failure mode that makes today’s AI knowledge so hard to rely on.

The DKG is the half that changes that. It turns each piece of knowledge into something an agent can stand behind:

Cryptographically authored, so you know who asserted it; Owned, so it has an accountable origin instead of drifting unattributed; Verifiable, so a machine can check it rather than take it on faith; Shared, so many agents build on one memory instead of each guessing alone.

This makes the difference between an agent saying “I think I read somewhere…” and “here is the fact, here is who stands behind it, and here is the proof.”

What verifiable context running on OKF + DKG unlocks

The DKG already runs in settings where provenance is non-negotiable, and knowledge has to cross organizational lines: international supply chains and trade, pharmaceutical and healthcare distribution, manufacturing, and scientific research, where the hard part has never been storing data but trusting data coming from someone else.

Verified factory audits shared between competing retailers, medicines traced to the patients they were meant for, customs risk assessed from authenticated shipment records: in each case, the value comes from knowledge that can be proven, not merely presented. OKF widens the on-ramp to all of it. Any team that can write Markdown can now turn what it knows into verifiable, ownable assets on the same infrastructure.

The wider opportunity is the web itself. As AI agents become the main readers of online content, site owners face a defensive choice: block the bots, or watch them take value for free. Robots.txt bans, crawler walls, and paywalls are all the same instinct, and together they are producing a web that quietly closes itself to machines. Verifiable context offers the other road.

Because knowledge published through the DKG is owned, provenanced, and permissioned, a site can expose a discoverable, machine-readable signal of what it knows, keep the substance gated, and sell an agent access instead of refusing it. The properties that make the knowledge trustworthy are the same ones that make it sellable: the agent can confirm that it is paying for genuine, attributable knowledge, and the owner can prove exactly what was sold.

Letting agents pay their way in

Payment is the last piece, and it is coming into view. One emerging option is the x402 protocol, which revives HTTP’s long-dormant “402 Payment Required” response. It enables any agent to pay for a resource in stablecoins and TRAC tokens at the moment they request it. Paired with owned, permissioned knowledge, it suggests a natural upgrade path: an agent discovers a dataset, the owner’s endpoint quotes a price, the agent pays, and access opens, with no human in the loop.

That payment layer sits outside the DKG and is not part of this integration. But the foundation it would build on, knowledge that can be owned, proven, and permissioned, is exactly what this work puts in place, turning “should we let agents in?” from a yes-or-no defense into a business model.

Get started on your own DKG node

Everything here runs on the OriginTrail, the open knowledge layer anyone can operate. Going from zero to verifiable, agent-ready memory takes two steps:

1. Launch a DKG node. Clone and run a node from the main repository, github.com/OriginTrail/dkg, and follow its setup guide to bring it online.

2. Apply the OKF to the DKG integration. With your node live, import any OKF bundle into a Context Graph with dkg okf import, and it becomes owned, verifiable knowledge that agents can query and trust.

Start here: github.com/OriginTrail/dkg

Google’s OKF comes to the OriginTrail DKG: A memory AI agents can trust was originally published in OriginTrail on Medium, where people are continuing the conversation by highlighting and responding to this story.

Tuesday, 30. June 2026

GLEIF

How AEOTrade Is Strengthening Trust in Global Digital Trade with the vLEI

How can cross-border trade become more efficient, secure, and trusted? This challenge motivated AEOTrade to participate in GLEIF’s 2025 vLEI Hackathon, where it was named runner-up in the “Trade, Supply Chain, and MSME Finance” category. Its solution combined the verifiable LEI (vLEI) with blockchain to create a trusted collaboration framework for more reliable, interoperable, and efficient global

How can cross-border trade become more efficient, secure, and trusted? This challenge motivated AEOTrade to participate in GLEIF’s 2025 vLEI Hackathon, where it was named runner-up in the “Trade, Supply Chain, and MSME Finance” category. Its solution combined the verifiable LEI (vLEI) with blockchain to create a trusted collaboration framework for more reliable, interoperable, and efficient global trade processes.

Building on this momentum, GLEIF and AEOTrade signed a strategic Memorandum of Understanding (MoU) earlier this year. The partnership aims to support the development of an open, secure, inclusive, and globally connected digital trade infrastructure, powered by trusted organizational identity.

In this guest blog, Zetao Yang, Founder of AEOTrade and Secretary-General of the TradeTech Alliance, shares his insights on organizational identity, the vLEI, digital trade, and interoperability.

What first motivated AEOTrade to explore the vLEI as part of its digital trade infrastructure?

Global trade has long faced trust-related challenges, including identity impersonation and document fraud. At the root of these issues is the lack of a globally recognized and verifiable legal entity identity framework. Today, companies often need to submit the same registration documents across multiple platforms and jurisdictions. This process is inefficient, repetitive, and vulnerable to forgery.

The vLEI addresses this core pain point. Built on the globally recognized Legal Entity Identifier (LEI), it gives organizations a secure, verifiable way to control and prove their identity in digital environments. This creates a foundation of trust that starts with verified identity and extends across the entire trade chain.

To put this into practice, AEOTrade developed its own digital trade infrastructure: the AEOTradeChain protocol, a global trade interoperability protocol, and AEOTradeChain, an open, distributed, trusted trade collaboration network. Within this architecture, the vLEI serves as the trusted identity layer, confirming each party's identity, while AEOTradeChain supports process collaboration and data exchange. Together, they create an end-to-end trust framework that starts with verified identity and extends to trusted transactions, with the electronic bill of lading (eBL) serving as a key entry point.

Your “AEOTradeChain+vLEI” was awarded at the vLEI Hackathon last year in Hong Kong. How does integrating the vLEI into AEOTradeChain strengthen identity verification and interoperability for eBLs?

Traditional eBL systems often rely on centralized identity authentication. Different platforms cannot easily recognize one another’s identities, and each transfer of title requires manual verification of the parties involved. This is slow and prone to error.

By integrating the vLEI directly into AEOTradeChain, we have introduced three key capabilities:

Identity verification is built in. All participants on AEOTradeChain have digital identities based on the vLEI. Before an eBL is issued, transferred, or otherwise acted upon, the system automatically verifies the validity of the operator’s vLEI. This ensures that only verified legal entities can perform these actions. Each eBL is linked to the verified identities behind it. Each eBL is bound, through the vLEI, to the identities of the issuer, holder, and transferor. This creates a trusted connection between the person, the credential, and the document, helping reduce risks such as cargo release without an original eBL or duplicate sales. Platforms can recognize and process eBLs using a common identity framework. AEOTradeChain is compatible with international standards frameworks such as TradeTrust, while the vLEI provides a globally unified legal entity identity reference. This enables trade platforms across different countries and different blockchains to transfer, verify, and use eBLs based on the same identity framework. In real-world business scenarios, this significantly improves the efficiency of eBL circulation and reduces operational costs.

How can the LEI serve as a foundational identity anchor that links national or regional identifiers, digital certificates, and on-chain digital assets to create a globally trusted digital business profile?

The LEI, a globally unique identifier based on the ISO 17442 standard, provides key reference data on the legal entity linked with it. The vLEI builds on this foundation by adding verifiable credential capabilities, enabling legal entities to prove their identities in the digital world in a controlled and entity-governed manner.

Within the AEOTradeChain architecture, the vLEI serves as a global identity anchor, effectively connecting physical business identities with digital transactions.

National and regional identifiers can be linked to a global identity anchor. Many countries have their own business registration numbers or tax identification numbers. Through the LEI, these local identifiers can be mapped to a single global anchor. For example, a Chinese company may have both a Unified Social Credit Code and an LEI. Once the two are linked on AEOTradeChain, overseas partners can complete verification directly through the LEI.

Digital certificates can be tied to verified legal entity identities. Digital certificates used by enterprises for electronic signatures and encrypted communications can be bound and verified through the vLEI, ensuring that the operating party is consistent with the underlying legal entity.

On-chain digital assets can be connected to verified ownership. On AEOTradeChain, each eBL and each trade finance credential is a digital asset. The creation, transfer, and cancellation of these assets are associated with vLEI signatures, making ownership relationships transparent, traceable, and non-repudiable worldwide.

Through this mechanism, the vLEI becomes a foundational trust element that connects legal entities to on-chain activities, supporting a globally recognized framework for trusted organizational identities.

AEOTrade actively participates in China’s digital trade ecosystem, including initiatives such as the Single Trade Window. As China aims to enhance the cross-border interoperability of this and other initiatives, how could the vLEI help connect these regional digital trade innovations with globally interoperable trust frameworks?

China’s international trade Single Trade Window has been operating for many years and has become a core infrastructure for enterprises handling customs clearance and related trade procedures. As a designated operator and service provider of the Single Trade Window initiative, AEOTrade has extensive firsthand experience in this area. However, if regional innovations lack a globally recognized identity foundation, they become difficult to connect seamlessly with overseas partners.

AEOTradeChain is designed as a distributed network connecting regional and global ecosystems, while the vLEI provides a unified identity layer. Looking ahead, several areas could be explored:

Enterprises could obtain a vLEI as part of the Single Trade Window registration process. After completing registration and authentication through a domestic “Single Window,” enterprises could apply for a vLEI simultaneously. This vLEI could then be directly verified by overseas customs authorities, ports, banks, and other parties in cross-border scenarios, eliminating the need to repeatedly submit qualification documents.

The vLEI could provide a common basis for mutual recognition across digital trade corridors. In developing digital trade corridors between China, Singapore, the Middle East, and other regions, participants may use different identity systems. By using the vLEI as a common identity identifier, parties can avoid complex bilateral arrangements and move toward “verified once, recognized globally.”

Regulatory compliance could become more automated and efficient. By linking the vLEI to enterprises’ global trade activity records, customs authorities and regulators can perform risk analysis and compliance reviews more quickly while protecting commercial privacy. This can further improve customs clearance efficiency.

As more countries and regions adopt the vLEI, China’s regional digital trade innovations will integrate more smoothly into a globally interoperable trust framework.

Earlier this year, AEOTrade and GLEIF signed an MOU to promote trusted global digital trade. How does this collaboration enhance interoperability between blockchain-based trade platforms and international trade protocols?

The core purpose of the MoU is to jointly promote the use of the vLEI in digital trade and support alignment between technical standards and international trade protocols. AEOTradeChain is not a single blockchain platform. It is an open, distributed trade collaboration network composed of three elements: the AEOTradeChain protocol, the AEOTradeChain network, and AEOTradeOS. Based on this network, the collaboration between the two organizations will enhance interoperability in several ways:

Technical standards can become more closely aligned and interoperable. GLEIF and AEOTrade will work together to promote interoperability between the AEOTradeChain protocol and GLEIF’s vLEI technical specifications. This will help ensure that core operations on AEOTradeChain, such as identity verification, document signing, and smart contract execution, can natively support the vLEI. Any organization that issues vLEIs in accordance with GLEIF standards will be able to connect more easily to the AEOTradeChain network.

Trade agreement provisions can become easier to operationalize. Many international trade agreements, such as the Digital Economy Partnership Agreement (DEPA) and the Regional Comprehensive Economic Partnership (RCEP), emphasize mutual recognition of electronic documents and paperless trade. Through the vLEI, relevant provisions can be translated into executable automated rules. For example, under the DEPA framework, the identity of the eBL issuer circulating between Singapore and China can be automatically verified via the vLEI, enabling “agreement-driven interoperability.”

Blockchain-based trade platforms can collaborate across chains and ecosystems. As long as different blockchain-based trade platforms leverage GLEIF’s vLEI, they can use AEOTradeChain as a hub for cross-chain identity verification and data exchange. This helps reduce platform silos and enables parties in international trade to establish a shared trust framework.

AEOTrade has already carried out full-process digital trade scenario pilots across industries such as food, automobiles, and home appliances, working with partners in China, Singapore, the Philippines, Tanzania, Saudi Arabia, and other countries and regions. As a next step, the two parties will jointly promote vLEI-based pilot projects to further validate the feasibility of this interoperability framework.

Looking ahead, what new use cases could emerge from combining trusted organizational identity with digital trade documentation and supply-chain workflows?

Together, AEOTradeChain and the vLEI provide a trusted digital foundation that could make trade workflows more automated, interoperable, and secure. This creates opportunities for new use cases in areas such as smart contract-driven trade finance and on-demand trusted collaboration networks:

Trade finance could become more automated through smart contracts. When banks can verify the identities of buyers, sellers, and logistics providers in real time through the vLEI and access trusted documents such as bills of lading and invoices anchored on-chain, trade finance can become an automatically triggered smart-contract process. For example, financing could be released automatically upon issuance of a bill of lading, and repayment could be executed automatically upon transfer of title to the goods. This would significantly shorten financing cycles and reduce operational risk. Businesses could create trusted collaboration networks on demand. Based on a vLEI-enabled digital identity, enterprises can dynamically create temporary trade collaboration groups to meet business needs, such as for an order involving manufacturers, logistics providers, inspection agencies, and insurers. The identities of all participants can be easily verified, permissions automatically assigned, workflows automatically orchestrated, and the group automatically dissolved once the transaction is completed. This flexible, efficient, and trusted collaboration model can greatly reduce customer acquisition and collaboration costs for enterprises.

AEOTrade has already begun exploring these scenarios. We believe that as the vLEI becomes more widely adopted, these innovations will move from pilots to scaled deployment, ultimately helping the global trade system evolve into a more efficient, transparent, and inclusive digital ecosystem.

Monday, 29. June 2026

Hyperledger Foundation

Why Hyperledger Indy on Besu Matters: Advancing Brazil’s Digital Identity Infrastructure

During a recent Linux Foundation Decentralized Trust online Meetup, DSR Corporation and CPqD explored how the Hyperledger Indy subproject is advancing decentralized identity from experimentation to real-world deployment.

During a recent Linux Foundation Decentralized Trust online Meetup, DSR Corporation and CPqD explored how the Hyperledger Indy subproject is advancing decentralized identity from experimentation to real-world deployment.

Friday, 26. June 2026

FIDO Alliance

PYMNTS: Mastercard Wants to Teach AI Agents How to Spend

For nearly 60 years, Mastercard has answered one question over and over. How do you get two parties who’ve never met to trust each other enough to do business? The answer was […]

For nearly 60 years, Mastercard has answered one question over and over. How do you get two parties who’ve never met to trust each other enough to do business? The answer was a card, a network, a rulebook everyone agreed to follow.

There’s a new party at the table now. It isn’t human. It’s an agent, acting on someone’s behalf, ready to shop, compare and pay with nobody watching. So the question isn’t whether machines will transact. They already do. The question is who builds the trust that makes it safe, who wins when the buyer is an algorithm, and what kind of commerce becomes possible that we can’t yet picture.

That was the table PYMNTS CEO Karen Webster set for Sherri Haymond, executive vice president and global head of digital commercialization at Mastercard, in this week’s Monday Conversation. Mastercard had just driven another stake into the agentic ground with Agent Pay, and its newest extension, Agent Pay for Machines, built for transactions one piece of software executes on behalf of another.

“We know consumers want to go to those models,” Webster said. “They want to type their intent into the prompt, and they want to execute a transaction.”

The plumbing to do that safely and at scale is the part nobody sees and everybody needs.


Biometric Update: EMVCo proposes global schema for verifiable digital payment credentials

EMVCo has put a draft framework out for consultation that aims to bring verifiable digital credentials into card‑based payment authentication. EMVCo is the technical body that maintains the global EMV Specifications. […]

EMVCo has put a draft framework out for consultation that aims to bring verifiable digital credentials into card‑based payment authentication.

EMVCo is the technical body that maintains the global EMV Specifications. It is seeking industry feedback on its EMV Digital Payment Credential Specification – Schema Framework until July 23.

The draft focuses on defining the data model for a Digital Payment Credential (DPC). EMVCo is seeking to enable secure, privacy‑preserving and scalable authentication for online card payments. It wants to do this by standardizing how a DPC is structured. It is also exploring how the same approach could support payment initiation later on.

Verifiable digital credentials are gaining traction as cryptographically verifiable, wallet‑based versions of everyday documents such as ID cards or driving licences. Their flexibility allows different data structures for different uses, but that also risks fragmentation.

EMVCo says its experience developing global specifications makes it well placed to define a consistent, interoperable payment‑specific credential.

The DPC initiative aims to create a common method for using VDCs in online card payments. It covers authentication, device binding, cross‑domain use and dynamic linking. EMVCo believes a unified approach can streamline provisioning, requests and verification across networks, wallets and systems, while supporting strong privacy controls.

The work is being led by EMVCo’s Digital Identity and Payments Task Force, which is engaging with its Associates and Subscribers. The organization is also working with groups including the FIDO AllianceOpenID FoundationOpenWallet Foundation, W3C and the WE BUILD Consortium.

“Emerging digital identity technologies have the potential to promote more trusted and convenient card-based payments for consumers and businesses, but realizing these benefits at scale requires global interoperability,” says Patrik Smets, EMVCo executive committee chair.

“That is why we are engaging across the industry and encouraging all stakeholders to share their feedback to help develop a consistent and secure approach for using VDCs in card-based payment authentication.”

The draft specification is now open for public review until July 23. EMVCo is encouraging organizations across payments and digital identity to get involved as the work progresses. Ways to get involved are provided here.

Thursday, 25. June 2026

Digital Identity NZ

Forests, not gardens: important lessons for Aotearoa | June Newsletter

Kia ora This month I want to draw your attention to an insightful interview with Sujith Nair, co-founder of Beckn Protocol and Networks for Humanity. Nair was a key builder of … Continue reading "Forests, not gardens: important lessons for Aotearoa | June Newsletter" The post Forests, not gardens: important lessons for Aotearoa | June Newsletter appeared first on Digital Identity New Zealan

Kia ora

This month I want to draw your attention to an insightful interview with Sujith Nair, co-founder of Beckn Protocol and Networks for Humanity. Nair was a key builder of Aadhaar and the broader India Stack, and his case for protocol-led architecture lands squarely on our Hui Taumata themes: trust, interoperability, adoption and governance.

His metaphor is simple: gardens need gardeners, while forests scale, diversify and produce solutions their designers never imagined. The lesson for Aotearoa is direct. At scale, the unlock is not another point solution, but neutral infrastructure that lowers the unit cost of trust across the whole market.

That same lens is shaping our work on trusted credentials, reusable KYC, anti-scam infrastructure and digital public infrastructure. It also connects strongly with the Sovereign AI focus for the Hui, following discussions between Drummond Reed and Dr Karaitiana Taiuru on human-friendly identity for the agentic web, Māori co-creation, data sovereignty, whakapapa and Te Mana Raraunga principles.

We have some surprise speakers joining us, so these ideas will be live in the room. I’d encourage you to read the full interview before August.

Read more insights here, or the full interview here.

Industry News

A trusted identity layer for AI agents

On 23 June, the Linux Foundation announced its intent to launch the Agent Name Service (ANS), an open standard for trusted identity, verification and discovery of AI agents, built on the existing Domain Name System.

For DINZ members, the development is significant because it points to a growing global need for neutral, interoperable trust infrastructure for AI agents. ANS supports decentralised identifiers (DIDs) and Legal Entity Identifiers (LEIs), creating a potential bridge between agent discovery, trusted identity and the verifiable credential ecosystem.

As AI agents increasingly operate across enterprises, platforms and digital services, trusted identity infrastructure will become foundational. The ANS announcement reinforces a theme central to the Hui Taumata: open standards and shared infrastructure beat walled gardens.

Read more on why AI agents need trusted identity infrastructure.

New AML/CFT Identity Verification Code recognises DISTF pathway

The new Identity Verification Code of Practice 2026, gazetted on 28 May and commencing on 1 July 2026, marks the first full rewrite of the Code since 2013.

Importantly for DINZ members, it recognises verification through an accredited Digital Identity Services Trust Framework (DISTF) service as a standalone pathway for identity verification. This is a significant regulatory signal for Aotearoa’s digital identity ecosystem, showing how trusted digital identity services can move from policy intent into practical adoption.

The Code also raises important questions about assurance, biometrics, privacy, selective disclosure and how we design verification pathways that minimise unnecessary personal information sharing.

Read the full analysis on what the new AML/CFT Identity Verification Code means for digital identity in Aotearoa.

Age verification and data minimisation

Two reforms this year point toward the same accredited DISTF digital credentials, but they raise a useful design question: why should proving you are over 18 require more of your identity than opening a bank account?

Under the new AML Identity Verification Code of Practice 2026, a DISTF credential can verify a person’s full name and date of birth for bank onboarding without requiring the credential to carry or display a photo. Yet alcohol-related age verification risks defaulting to a digital “18+ photo ID” model, when the real question is simply: are you over 18?

This is exactly where selective disclosure should shine. Privacy-enhancing credentials should allow people to prove only what is necessary, without oversharing personal information.

Read more on why proving you are over 18 should not require oversharing your identity.

NZBN Business Passport

The upcoming NZBN Business Passport will enable businesses to share verified information once and reuse it, including confirming they’re authorised to act on behalf of a business. This will help reduce admin, speed up transactions and give businesses more control over their data.

The credential is expected to go live in early September, with Westpac involved in the first phase to test how it can be consumed.

Watch the NZBN Business Passport overview.

Member News

Lumin explores digital credentials and identity fraud

DINZ member Lumin has shared a series of conversations and insights on how verified digital credentials can help reduce identity fraud, improve trust and support safer digital transactions.

Featuring perspectives from Lumin, MATTR, Air New Zealand and MBIE, the series explores real-world uses for digital credentials, what businesses need to know, and what is required for adoption at scale — including interoperability, public-private coordination and trusted infrastructure.

Read Lumin’s article.

Watch the roundtable series here.

I look forward to continuing these conversations with many of you at the Hui Taumata.

Ngā mihi nui,

Andy Higgs

Executive Director,
Digital Identity New Zealand

Read full newsletter here: Forests, not gardens: important lessons for Aotearoa | June Newsletter

The post Forests, not gardens: important lessons for Aotearoa | June Newsletter appeared first on Digital Identity New Zealand.

Wednesday, 24. June 2026

Next Level Supply Chain Podcast with GS1

(Replay) What Retailers Can Learn from Carter's RFID Journey

Carter's has achieved a milestone that many retailers considered out of reach. In only three months, Carter's implemented RFID technology in 700 stores, boosting inventory accuracy at the item level while simplifying operations for store associates and improving the customer experience. In this episode, hosts Reid Jackson and Liz Sertl sit down with Gina Maddaloni of Carter's , and Anna Mar

Carter's has achieved a milestone that many retailers considered out of reach.

In only three months, Carter's implemented RFID technology in 700 stores, boosting inventory accuracy at the item level while simplifying operations for store associates and improving the customer experience.

In this episode, hosts Reid Jackson and Liz Sertl sit down with Gina Maddaloni of Carter's , and Anna Marie Blackburn, formerly of Carter's, to discuss the company's RFID journey. They explore how the initiative gained support across the organization, the role RFID now plays in daily operations, and the business value it continues to deliver.

This episode is a replay of our conversation with Gina and Anna, brought back for anyone exploring RFID, inventory visibility, and large-scale retail technology rollouts.

In this episode, you'll learn:

How Carter's achieved one of the fastest RFID deployments in retail

Why RFID is no longer "too complex" or "too expensive"

What's next as Carter's expands RFID use into its supply chain operations

Jump into the conversation: (00:00) Introducing Next Level Supply Chain (01:29) Anna Marie and Gina's backgrounds (03:52) What RFID technology means for retail (06:47) The process of rolling out RFID across Carter's stores (13:21) RFID's impact on Carter's operational efficiency (17:49) RFID as a recruiting tool for store teams (18:54) Asset protection benefits and peace of mind (19:34) Expanding RFID into DC operations (23:49) What's next, Carter's move toward serialization (25:15) Advice for companies starting their RFID journey (22:16) Busting RFID myths: cost, complexity, and adoption (28:43) Favorite tech beyond RFID (31:36) What Gina and Anna Marie want to learn next

Connect with GS1 US: Our website - www.gs1us.org GS1 US on LinkedIn

Connect with the guests: Gina Maddaloni on LinkedIn Anna Marie Blackburn on LinkedIn

Check out Carter's


Digital Identity NZ

Why proving you are over 18 should not require oversharing your identity

Age verification should be one of the clearest use cases for selective disclosure. If the question is simply “are you over 18?”, the answer should not require a person to disclose more identity information than necessary. As digital credentials become recognised in law and regulation, Aotearoa has an opportunity to design privacy-enhancing verification pathways from the outset, rather than recreat

Age verification should be one of the simplest use cases for privacy-enhancing digital credentials.

If the question is “are you over 18?”, the answer should not require a person to disclose their full identity.

That is the promise of selective disclosure. A person should be able to prove only what is necessary for a specific transaction, without oversharing personal information. In the case of age verification, that could mean proving eligibility — yes, this person is over 18 — without revealing their full name, date of birth, address, document number or photo.

This is why recent regulatory developments are worth examining together.

Under the new AML/CFT Identity Verification Code of Practice 2026, an accredited Digital Identity Services Trust Framework credential can be used to verify a person’s full name and date of birth for bank onboarding. Importantly, this does not necessarily require the credential to carry or display a photo. Binding assurance can happen behind the scenes, while personal information remains minimised.

At the same time, alcohol-related age verification reforms are opening the door for digital credentials in lower-assurance settings. But if the practical design response becomes a digital “18+ photo ID”, we risk recreating the oversharing habits of physical identity documents in digital form.

That would invert the principle of data minimisation.

Opening a bank account is a higher-assurance process than proving age at a point of sale. If digital credentials can support bank onboarding without displaying a photo, then an age check should not default to requiring more personal information than necessary.

This is not just a technical design issue. It is a trust issue.

People are more likely to adopt digital identity tools when they can see that those tools protect their privacy and give them agency. If digital credentials simply make it easier to request, collect and display more personal information, public confidence will be weakened.

The better model is privacy by design. Selective disclosure should make “over 18? yes/no” one of the easiest things to prove with the least data. The technology exists to support that. The question is whether policy, implementation and market practice will make use of it.

For Aotearoa, this is an opportunity. As accredited digital credentials become recognised across more use cases, we can design verification pathways that are safer, more efficient and more respectful of personal information.

That requires early consultation with the digital identity community, privacy experts, Māori data sovereignty leaders, regulators, businesses and people who will actually use these systems.

The channel has modernised. Now the design defaults need to catch up.

The post Why proving you are over 18 should not require oversharing your identity appeared first on Digital Identity New Zealand.


What the new AML/CFT Identity Verification Code means for digital identity in Aotearoa

The Identity Verification Code of Practice 2026 is the first full rewrite of the Code since 2013 and introduces a significant change for Aotearoa’s digital identity ecosystem: accredited Digital Identity Services Trust Framework services are now recognised as a standalone pathway for identity verification. This marks a practical step from policy intent toward real-world adoption of trusted digital

The new Identity Verification Code of Practice 2026 marks an important moment for Aotearoa’s digital identity ecosystem.

Gazetted on 28 May 2026 and commencing on 1 July 2026, the Code replaces the Amended Identity Verification Code of Practice 2013. It is the first full rewrite in more than a decade and applies to reporting entities verifying the full name and date of birth of natural-person customers, beneficial owners and persons acting on behalf.

For DINZ members, the most significant change is the recognition of accredited Digital Identity Services Trust Framework (DISTF) services as a standalone pathway for identity verification.

This matters because it moves trusted digital identity from policy intent toward practical adoption. Accredited DISTF services are now recognised as a verification pathway that can be used online or in person, subject to defined assurance requirements.

The Code remains a voluntary “safe harbour”. Compliance is not mandatory, but a reporting entity that fully complies has met its verification obligations, and a court must have regard to the Code in any enforcement action. Entities can still verify by “some other equally effective means”, provided they give written notice to their supervisor.

The new Code sets out four verification pathways:

Face-to-face verification with physical documents Verification through an accredited DISTF service Other electronic identity verification Certified copies

The assurance requirements for DISTF credentials are explicit. For online or in-person use, the credential must deliver name and date of birth to a Strong Plus level of both Information Assurance and Binding Assurance. For in-person use only, a lower Standard Plus level may be acceptable, where backed by a primary non-photographic document such as a birth or citizenship certificate.

Other changes are also worth noting. RealMe and e-passports are named in the electronic identity verification pathway. The DIA Confirmation Service is simplified. Risk-based verification of beneficial owners and persons acting on behalf is introduced. Certified copy rules are clarified, including expanded recognition of trusted referees such as Kaumātua, verified through a reputable source, and Māori Land Court officials.

The Code also sharpens the interface between identity verification and privacy. Several electronic identity verification linking mechanisms rely on biometric matching, including facial recognition with liveness. This brings the Code into conversation with the Office of the Privacy Commissioner’s Biometric Processing Privacy Code, particularly around necessity, proportionality and consent.

For DINZ, the wider significance is clear. The Code provides one of the most concrete regulatory endorsements to date of DISTF accreditation as a trusted verification rail. It shows how governance, assurance and legal recognition can support practical adoption.

It also reinforces why interoperability and privacy-enhancing design matter. As digital credentials become more widely used, the goal should not be to recreate physical identity documents in digital form. The goal should be safer, more efficient and more privacy-preserving verification.

This is a key step forward — and one the digital identity community should engage with closely.

The post What the new AML/CFT Identity Verification Code means for digital identity in Aotearoa appeared first on Digital Identity New Zealand.


Why AI agents need trusted identity infrastructure

The Linux Foundation’s Agent Name Service points to a fast-emerging need: AI agents must be discoverable, verifiable and accountable. As agents operate across enterprises, platforms and digital services, trusted identity infrastructure becomes foundational. ANS shows how open standards, DNS, decentralised identifiers and Legal Entity Identifiers could help create a neutral layer for agent identity

AI agents are beginning to move from novelty to infrastructure. They will increasingly search, transact, negotiate, book, approve, recommend and act across digital services.

That creates a fundamental trust problem: how do we know which agent we are interacting with, who it represents and what it is authorised to do?

On 23 June, the Linux Foundation announced its intent to launch the Agent Name Service (ANS), an open standard for trusted identity, verification and discovery of AI agents. Built on the existing Domain Name System, ANS is designed to anchor agent identity to infrastructure the internet already relies on.

Rather than creating a new proprietary registry, ANS uses DNS as a neutral foundation. This matters. DNS already operates at global scale and provides a familiar model for naming and discovery. By building on it, ANS points toward a more open and interoperable approach to agent identity.

For DINZ members, several parts of the announcement are particularly relevant.

First, ANS supports decentralised identifiers (DIDs) and Legal Entity Identifiers (LEIs). This creates a potential bridge between agent identity, organisational identity and the verifiable credential ecosystem. In practice, that could help users verify not just that an agent exists, but who it represents and whether it has appropriate authority.

Second, ANS is focused on discovery and verification. In an agentic economy, agents will need to find each other and determine whether interaction is safe. That requires more than a name. It requires assurance, authenticity, permissioning and trust signals that can be checked in real time.

Third, the initiative reinforces the importance of neutral infrastructure. If agent identity becomes controlled by a small number of proprietary platforms, the same risks that exist in today’s platform economy will intensify: lock-in, opacity, concentrated control and weak accountability. Open standards help reduce those risks.

The Linux Foundation’s framing is aligned with a broader theme in digital identity: open standards and shared infrastructure beat walled gardens. For Aotearoa, that matters because agent identity will quickly become part of digital trade, public service delivery, enterprise automation and consumer protection.

There are also sovereignty questions. If AI agents are operating on behalf of New Zealand organisations, communities or individuals, who governs their identity? How are they recognised? How are permissions managed? How do Māori data sovereignty principles apply when machine actors interact with data, services and decisions?

ANS does not answer all of these questions. But it is an important signal that trusted identity infrastructure for agents is becoming a global priority.

For DINZ, the opportunity is to engage early. Aotearoa should not simply inherit agent identity infrastructure designed elsewhere. We should help shape it — with interoperability, privacy, accountability and sovereignty built in from the outset.

The post Why AI agents need trusted identity infrastructure appeared first on Digital Identity New Zealand.


Forests, not gardens: what Aotearoa can learn from protocol-led digital infrastructure

Sujith Nair’s “forests, not gardens” metaphor offers a useful way to think about digital public infrastructure in Aotearoa. Gardens are curated and controlled; forests scale, diversify and produce solutions their designers never imagined. For digital identity, trusted credentials and reusable KYC, the lesson is clear: the unlock is not another point solution, but neutral, interoperable infrastruct

Sujith Nair, co-founder of Beckn Protocol and Networks for Humanity, has a simple but powerful metaphor for digital infrastructure: forests, not gardens.

A garden needs a gardener. It is curated, controlled and reflects one person’s view of how things should be. A forest is different. It scales, sustains diversity and produces solutions its designers never imagined.

For those of us working on digital identity, trusted credentials and digital public infrastructure in Aotearoa, the metaphor lands strongly. The challenge is not to design one perfect platform or one dominant solution. The challenge is to create neutral, interoperable infrastructure that allows many participants to solve problems in many different contexts.

This is the principle behind protocol-led architecture. Rather than building vertically integrated platforms that control access, rules and outcomes, protocols create common rails that others can build on. They allow competition at the edges while maintaining trust at the core.

Nair’s experience with Aadhaar, India Stack and Beckn shows what this can unlock at scale. In India, scale was not treated as something to solve later. It was the first design constraint. With eKYC, the cost of verifying a customer reportedly fell from around USD $12 to just a few cents. That shift helped make financial inclusion viable for millions of people.

The lesson for Aotearoa is direct. In areas such as reusable KYC, anti-scam infrastructure, trusted credentials and market adoption, the unlock is not simply a better point solution. It is lowering the unit cost of trust so the whole market can operate differently.

This is also why interoperability matters. If trusted credentials, identity services and assurance models are locked inside closed platforms, adoption fragments. If they are built on shared protocols, open standards and clear governance guardrails, they can scale across sectors.

For DINZ, this aligns closely with our focus on trusted, privacy-enhancing digital identity infrastructure. We are not here to promote a single platform or vendor. Our role is to help steward the conditions for a trusted ecosystem: open, interoperable, secure, privacy-preserving and grounded in public confidence.

As Aotearoa prepares for the Digital Trust Hui Taumata, Nair’s forest metaphor is a useful provocation. We should not be asking only what solution we want to build. We should be asking what conditions allow many solutions to emerge safely, sustainably and at scale.

The future of trusted digital identity will not be a manicured garden. It will be a forest — if we design the rails well enough.

The post Forests, not gardens: what Aotearoa can learn from protocol-led digital infrastructure appeared first on Digital Identity New Zealand.

Monday, 22. June 2026

GLEIF

Why Digital Finance Needs Connected Standards, Not More Identifiers

Standardized identifiers are the common language of markets. Identifiers such as the Legal Entity Identifier (LEI), the International Securities Identification Number (ISIN), and the Classification of Financial Instruments (CFI) code form the backbone of market infrastructure and allow data to move across systems and jurisdictions. Their value now extends well beyond regulatory reporting. Market

Standardized identifiers are the common language of markets. Identifiers such as the Legal Entity Identifier (LEI), the International Securities Identification Number (ISIN), and the Classification of Financial Instruments (CFI) code form the backbone of market infrastructure and allow data to move across systems and jurisdictions.

Their value now extends well beyond regulatory reporting. Market transparency and supervision, data management, and Know Your Customer (KYC) processes, for example, all depend on consistent identification. Without standards, markets fragment and become inefficient. With them, investors, issuers, regulators, and infrastructure providers operate from a shared reference point, with the consistency that cross-border activity requires.

Now, as digital assets move into mainstream financial infrastructure, a key question is how existing identifiers can evolve to keep data connected across systems, asset classes, and jurisdictions.

Standards stay relevant only when they evolve

Recognizing where existing standards fall short – and whether a given standard adequately identifies a given instrument – is the starting point for keeping them fit for purpose.

Take the ISIN. It has been in use for over 40 years, and that longevity is often presented as evidence of stability. Yet it is more accurate to call it evidence of adaptation, as the ISIN remains fit for purpose only because it has changed in response to market needs.

That adaptation depends on governance. The Association of National Numbering Agencies (ANNA), as the Registration Authority for the ISIN, runs a structured feedback loop: market participants raise issues through their national numbering agencies, which feed into updates to the ISIN Guidelines. The industry raises comments through National Standards Bodies, which feed back to ISO through a consensus-driven process. Those agencies act as central points of knowledge in their jurisdictions, surfacing local requirements and elevating them to an international level. Systematic review allows a standard to absorb new use cases without losing its core, and this will be key to addressing the coverage gaps introduced by digital assets.

Coexistence, not a big bang

There is a tendency to frame the shift to digital assets as a clean break: traditional finance on one end, decentralized finance on the other. Yet the more realistic path is coexistence. Traditional and digital asset environments will need to interoperate over an extended period.

This matters because change carries cost, and that cost is borne downstream. Banks, issuers, and infrastructure providers will not switch to something new on a single day. Introducing an entirely new identifier or data field imposes a real burden on the firms that have to consume it. The more workable approach is to extend and connect the standards already in place.

This position establishes identifiers as transition infrastructure that lets the market move toward digital assets without rebuilding every data connection from scratch. LSEG's (The London Stock Exchange Group's) winning project at GLEIF's Global vLEI Hackathon, in the Digital Asset and Financial Infrastructures category, is a useful illustration. What that project demonstrated was not a new layer of process, but the opposite: existing standards applied to streamline identity resolution in a digital asset context.

Identifiers work as a connected hierarchy

To understand the case for extending existing identifiers, it is useful to recognize how the main identifiers relate to each other in financial markets. They are not competitors. They sit at different levels of granularity, like a pyramid. The legal entity sits at the top, identified by the LEI. Below it sits the instrument, identified by the ISIN, or, for over-the-counter derivatives, by the Unique Product Identifier (UPI), followed by the ISIN. The Digital Token Identifier (DTI) sits at a lower layer than the level required for blockchain, smart contracts, and tokenized instruments.

What holds the hierarchy together is the mapping between its layers, and that is work GLEIF is actively doing. We are collaborating with ANNA on the LEI-to-ISIN mapping because every instrument identified by an ISIN is issued by a legal entity that, in turn, needs to be identified. We are in the same dialogue with the Digital Token Identifier Foundation, because tokens are also issued by legal entities. Each mapping connects an instrument or a token back to the organization behind it. That allows transparency and operational efficiency to carry across the traditional and digital asset environments.

The value is in the data behind the identifier

It is also important to understand that an identifier on its own is a string of characters. Its value comes from the standardized, governed reference data attached to it.

For instance, behind every LEI sits a structured set of reference data about the legal entity: who it is, where it is registered, and how it connects to other entities. That data is consistent for any entity, anywhere. Applied through a standardized framework, that information turns a code into something a market can act on.

This is why the LEI is well placed as a first layer of interoperability between traditional and digital finance. Organizational identity underpins everything else: managing risk, meeting regulatory obligations, assessing counterparties, and analyzing supply chains all begin with knowing which legal entity is involved. Whatever the technology, that need does not go away. Legal entity data is the legal foundation of commerce, business, and finance. The verifiable LEI (vLEI) extends that foundation into digital interactions, allowing the entity behind an action and the people acting on its behalf to be verified computationally. The technology around digital assets will keep changing. The need to know which organization stands behind a transaction will not.

Interoperability, identity, and data in a digital world

Standards work best when they are invisible, absorbed into infrastructure, and taken for granted. But the convergence of traditional and digital finance will undoubtedly test them.

This was the focus of my latest Trust Talks conversation with Laura Stanley, Director of Entity Data and Symbology at LSEG and Vice Chair of the ANNA Board. Laura has spent close to two decades working on symbology and standards, from SEDOL and ISIN to the LEI. Her view is direct: the market does not need more identifiers. It needs the ones it has to evolve, connect, and keep pace with new use cases.

Listen to the full Trust Talks conversation with Laura Stanley for a closer look at why interoperability depends on connected standards, how the ISIN has stayed relevant for four decades, and what coexistence between traditional and decentralized finance will require of data infrastructure. Trust Talks is available across YouTube, Spotify, and Apple Podcasts: https://linktr.ee/TrustTalks.


Hyperledger Foundation

Panurus Joins LF Decentralized Trust as New Incubating Project

We are excited to announce the launch of Panurus, a new incubating project within LF Decentralized Trust (LFDT). Panurus is the evolution of Hyperledger Fabric Token SDK, an LFDT lab. Its transition to a project marks a significant step forward for enterprise tokenization, bringing together real-world-proven token infrastructure and vendor-neutral governance and establishing a solid and

We are excited to announce the launch of Panurus, a new incubating project within LF Decentralized Trust (LFDT). Panurus is the evolution of Hyperledger Fabric Token SDK, an LFDT lab. Its transition to a project marks a significant step forward for enterprise tokenization, bringing together real-world-proven token infrastructure and vendor-neutral governance and establishing a solid and reusable foundation for blockchain-based asset management.


FIDO Alliance

Identity Week: New FIDO Alliance and HID study reveals major gap between identity security confidence and reality

Research Reveals 94% of Enterprises Claim They Can Revoke Employee Access Within 24 Hours, Yet 35% experienced delays or failures in the past two years The FIDO Alliance and HID, […]

Research Reveals 94% of Enterprises Claim They Can Revoke Employee Access Within 24 Hours, Yet 35% experienced delays or failures in the past two years

The FIDO Alliance and HID, a global enabler of trusted identity solutions, today released The State of Physical and Digital Identity in the Enterprise, a new research report examining how organisations manage physical and logical access across their workforces.

Surveying 500 IT and cybersecurity decision makers across the US, Canada, UK, France and Germany, the new study uncovered a significant disconnect between enterprise confidence in identity security and operational reality. While most organisations believe they can revoke all physical and digital access within 24 hours when an employee leaves, more than one-third report experiencing actual failures doing so, contributing to identity-related security incidents across the enterprise.

Key findings from the report include:

While confidence is high, so are security incidents

94% of organisations claim confidence that all physical and logical access can be revoked within 24 hours of an employee leaving. Yet 35% experienced delays or failures doing exactly that in the past two years — and 70% experienced at least one identity-related security incident overall.

Governance is fragmented

Only 50% of enterprises have unified reporting ownership for physical and digital identity, and just 48% have consolidated budget control. Finance is the most governance-fragmented sector, with 34% operating fully separate reporting structures despite operating under stringent regulatory access-control obligations.

Complexity is growing, and enterprises manage three separate systems on average

59% of enterprises manage three or more distinct credential and authentication systems. 58% say managing digital identity has become more complex over the past two years.

The Public Sector carries the highest incident rate of any industry

The sector has the highest identity security incident rate of any industry, with 43% experiencing access revocation failures. It has a 20% manual credential revocation rate, which is more than double the IT/Technology sector. 

The passkey adoption must scale to protect businesses

93% of organizations are at some stage of passkey adoption and 65% report high or expert technical familiarity. However, only 13% have deployed passkeys at scale, explaining why organisations experience such high levels of security incidents.

Phishing-resistant authentication is a top business priority

The leading driver for moving to passwordless authentication is reducing phishing and credential-based breach risk (45%), followed by reducing IT costs from password resets and help desk load (44%).

“The story in this data isn’t about awareness, it’s about execution. Ninety-three percent of organisations are on the passkey journey, but only 13% have deployed at scale, and the security incident rates reflect that gap directly,” said Andrew Shikiar, executive director and CEO of the FIDO Alliance. “Phishing-resistant authentication only delivers its full protective value when deployment is comprehensive rather than selective – because threat actors don’t limit themselves to the parts of the organization that are already protected.”

“Identity security is no longer just an authentication challenge; it is an enterprise governance challenge. As organisations adopt passkeys, a unified approach to managing physical and digital identity becomes critical. This research shows that fragmented governance, disconnected systems and limited visibility create real business risk. HID is closing that gap by bringing credentials, access rights and lifecycle management together to enable faster, more confident access decisions”, said Sean Dyon, Vice President of the Authentication Business Unit at HID.


DIF Blog

DIF Newsletter #62

Jun 2026 DIF Website | DIF Mailing Lists | Meeting Recording Archive Table of contents Decentralized Identity Foundation News Universal Resolver Task Force DID Recommended Methods Announced ITU Takeaways Working Group Updates Hot Takes Upcoming Events Get involved! Join DIF Decentralized Identity Foundation News Summer event season is upon us! Between hopping

Jun 2026

DIF Website | DIF Mailing Lists | Meeting Recording Archive

Table of contents Decentralized Identity Foundation News Universal Resolver Task Force DID Recommended Methods Announced ITU Takeaways Working Group Updates Hot Takes Upcoming Events Get involved! Join DIF

Decentralized Identity Foundation News

Summer event season is upon us! Between hopping from EIC to Identity Week and DICE, DIF Members have been busy at dedicated Hospitality and Travel Events, ITU Study Group 17, and upcoming IETF and Dweb gatherings. The Working Groups have been churning out announcements, which keeps our blog calendar full. Highlights this month include:

An overhaul of DIF's instance of the Universal Resolver KYA-OS v1.0 is closing in on formal ratification DID Recommended Methods announced (did:webvh and did:webplus) with more in the pipeline (did:cid and did:ethr) Hospitality and Travel WG publication of initial HATPro specifications Upcoming DIF Hot Takes from ITU SG17, Identity Week, NeoCypherpunk Summit, and DICE 2026. DIDcomm survey results to be released! (There's still time to fill in the survey if you're using DIDcomm.) Grace and Juan weigh in on ITU participation

With all of this action, the Working Group section is based primarily on the inputs from the working groups themselves, rather than a summary from the DIF staff. For Working Groups who would like their sections to be longer and more detailed, we strongly encourage you to write up your monthly summaries and submit them to the DIF newsletter.

Universal Resolver Task Force

DIF members have rallied around the cause of the Universal Resolver, resulting in a Task force that is taking over the server management in the short term, while they come up with long-term solutions for Universal Resolver. More details below in the Identifiers and Discovery Working Group section.

DID Recommended Methods Announced

did:webvh and did:webplus are the first to pass the DIF vetting process for Recommended DID Methods. The effort to create DID Recommended methods was launched together by DIF, the Trust over IP Foundation, and the W3C DID Working Group in 2024. While only two methods have made it over the line, several more have been submitted or are in the pipeline.

See the full blog post here

ITU Takeaways

Grace and Bumblefudge attended an ITU plenary session in Geneva as observers, to see how DID- and VC-based proposals for standardization were faring in the cradle of X.509 orthodoxy and multi-stakeholder governance of scalable identity.

Juan’s Take: We saw presentations about national-scale PKI deployments that pseudonymize end-users as DIDs and track many issuers, as well as an interesting presentation from Huawei about a pilot using a smart-watch “DID Wallet” to present lightweight identity attestations across language barriers in an international athletics context, presenting those VCs over EUDI/OIDC4VC protocols. (While there are many languages involved, it’s a use case with thankfully simple issuer governance, short expiry dates, and not too many verifiers to coordinate, therfore perfect for a tech-stack prototype). We heard about some fascinating research ideas from NXP Semiconductors, various identity companies, and R&D departments of multinationals, including an update from the Thales-Google project that presented to TAAWG last month. Nuances of unlinkability and the exact details of software supply chain authenticity and revocation mechanisms were table-stakes, and more than one claim was dismissed as "unverifiable marketing speak". It was great to see the ITU community trying to find scaffolding, ontologies, and new conceptual models for how to measure trustworthiness in agents; the challenge in finding ITU approval for decentralized tech stacks hinges, however, on proving layer-by-layer that alternate trust infrastructures can be as auditable and governable as the good old X.509 that powers so much of our modern world at scale.

Grace’s Take: The ITU is making efforts to seriously address the problems around Agentic AI, Identity and Security. As part of that effort, they have decided to create a Focus Group that will be open to the public to research these areas. This is a welcome side-channel to the ongoing work happening within Study Group 17, where issues of AI and Identity are moving towards standardization.

It was encouraging to see the work on DIDs and AI coming out of Korea and China. For me, this brought up some questions regarding how "soft power" mechanisms within our international systems exhibit biases toward different cultures and economies. Organizations such as ITU, IETF, and W3C are built on the idea that to show validity as an international standard, it's necessary to show at least two unrelated implementations. This assumption is important to avoid collusion where a large entity (government or company) brings in a partner who is being paid to say that they have an independent implementation, when in fact, it's one business case with two name tags. That model is challenged today even in the Global North, where corporations are so large that they can set de-facto standards and influence governments. In some countries, such as China, it's always been difficult to differentiate between a "government" versus "corporation," as ownership stakes between the two are not as distinct as in Europe. Given the changes in the global landscape, does it make sense to reconsider what is considered adequate for an international specification?

A more important issue, from DIF's perspective, is the question of Open Systems. When it comes to East and Southeast Asia, many of the organizations use open standards in ecosystems that aren't entire open or competitive. Larger corporations and telecoms may be using DIDs, but they aren't using them in a way that is practically interoperable with other systems. For that reason, there is no possibility, and also no real need to make them into an international standard. We've seen some implementations in several countries where the implementers have no desire to share in a public or open source way. This is the main barrier to adoption at an international level. Even here, though, there's a level of nuance, where we see in the international community that large corporations dominate the mobile phone operating systems and app stores. The choices of "open standards" are limited by soft power, so what looks like an industry standard was implemented with some level of "lack of choice," if not outright market-power coercion. As the open source community, we are somewhat culpable for not implementing a stack that could securely and easily be adopted by larger entities. In other cases, there was no coercion involved, but concentration of power unintentionally emerged, such as in the case of TLS being dominated by a tiny and shrinking circle of mega-capitalized vendors, as a participant at the ITU called out in the plenary.

At DIF, we have always insisted both on "open systems" and the "two entity" rule. We require two interested entities to start a Working Group or Work Item. Is that still valid today, when the large corporations collaborate with each other and the governments? Moreover, do we need to rethink how we consider this rule in a world where we are now aware that different cultures think about this differently? There's no clear answer, and we are probably at least half a year away from seeing how the ITU will address this issue.

As DIF, we are excited to see the potential for a DID-based Agentic AI standard to be making its way through the ITU. These specs are still in early stages, where quite a bit of additional work needs to be done to have them presented in a format that meet the needs of an ITU specification. It's not just a question of the "rule of two" but also a question of making sure these standards adhere to the longstanding governance requirements that have given the ITU its global standing as "regulation-ready". Although DIF is miniscule in size compared to the entities that drive most ITU work, we are looking into what our role might be in helping bridge the gap between these initial presentations and their eventual adoption.

Working Group Updates

DIF Members are welcome to join and participate in any working group. Most working groups meet on a weekly basis, and the most active groups have task force meetings that focus on specific work items. All public meetings are recorded and you can find all of the information on our working groups here.

Creator Assertions Working Group

The Trust Task Force reported progress on adding governance-backed assertions and two new processing hooks, with the chairs planning to finalize changes for presentation next week. The Verifiable Credential Task Force continued working on CBOR payload specifications and discussed archival-quality identifiers to ensure long-term verifiability of claims. The Consent Task Force published version 0.21 of the consent assertion specification and identified the need for consistent definitions of terms like creator, rights holder, and subject across CAWG specifications. The group extensively discussed a proposed definition for archival-quality identifiers. The group is planning to incorporate a comprehensive set of definitions into the identity assertion specification and discussion of aligning CAWG terminology with C2PA definitions.

CAWG had an extensive discussion about defining "creator" in the context of digital assets, with Erik presenting a proposed definition that sparked debate about whether organizations should be considered creators, particularly in commercial contexts. Several pull requests were reviewed, including network traffic policy requirements, archival-quality identifier terminology, C2PA version updates, and X.509 verification section modifications to avoid status code conflicts with C2PA.

👉 Learn more and get involved

Trusted AI Agents Working Group

The Trusted AI Agents Working Group has been chugging along iterating on and cleaning up two clusters of work items, the KYA-OS specification and reference implementation on the one hand, and the Delegated Authority Reports on the other.

KYA-OS has cut a v1 which is working its way through working group feedback and Steering Committee approval at time of press, with a roadmap for defining extension points (such as pluggable support for arbitrary additional DID methods, [delegated] authorization languages, etc) and hardening them as DIF members author or inform extensions at various levels. (Cheqd is the first to add their own compliance-focused DID method, and notably their extension avails itself of DID-Linked Resources, i.e. complex DID URLs for fetching verifiable information via a did:cheqd resolver).

The Delegated Authority task force, having a complete draft of their problem space report, a complementary threat modeling guide, and a distinct governance considerations report problem space’s terminology and evaluative framework (see members-only Slack for draft sections of this research). Taken together, this suite is really a significant contribution to the research literature, and we hope it will change the conversation around making agents and their harness genuinely trustworthy (and objectively gradeable) by making authorization powerful enough for runtime chaos (and KYA-OS).

Ideas for a new work item around machine-readable policy, as well as a position paper or blog post about bad habits and momentum from the golden age of bearer tokens, are being discussed, but no working group consensus to collaborate on a defined work item have emerged from either.

👉 Learn more and get involved

Hospitality and Travel Working Group

DIF announced the preliminary draft release of the Hospitality Travel Profile (HATPro) open-source schema. HATPro is designed to enable a consumer of hospitality, travel, and/or leisure services to create once, and to communicate to any supplier or intermediary, their highly detailed identity information, needs and preferences. The schema is now fully published for use by developers. It includes all critical core identity information as well as extensive modeling of food and beverage preferences and allergies for more than 1000 ingredients and cuisines, and categorization of activities. Input from early adopters is encouraged and will help the group prioritize any requirements they have that are not already addressed.
The executive summary, overview, and implementation guide (updated for the current version) are available on the Hospitality and Travel WG Website.

👉 Learn more and get involved

DID Methods Working Group

The DID Methods Working group hosted the second “deep dive” presentations for both did:ethr and did:cid. Both DID methods are in their home stretch, dotting the last of their Ts and crossing the last of their Is across various github repositories and registries. The did:ethr presentation includes a helpful hands-on "about did:ethr" mini-website with all relevant links on the final page.

If you haven’t been following along, now is a great time to read their respective “findings documents” for overviews of (and links to) their presentations, and comment on the Pull Requests linked above to show support or get in any last-minute questions that arose for you watching the recordings. did:hedera (based on the Hedera Hashgraph, which is a decentralized global acyclical graph data structure rather than a traditional linear blockchain) is also in the queue, and volunteers are being chased down for did:key and did:peer to round out the roster with some different kinds of DID method.

👉 Learn more and get involved

Identifiers and Discovery Working Group

A temporary task force has emerged to do work on the Universal Resolver, make technical changes and direct users to commercial solutions for production-grade resolvers. As this Task Force has been put in place, DIF will continue to maintain its public instance of the Universal Resolver.

The Did:webvh community keeps iterating on and discussing designs for reputation systems on top of the web-hosted Verifiable Data Registry, and the code donations for those cross-compatible VDR servers keeps pouring in (with feature-complete Java and Dart versions now V1-stable and managed through DIF's github organization; keep an eye on our blog for a forthcoming piece about these). Several DIF members are working on commercial solutions and collaborating on the task force. For DIF, this is an important indicator that this is a highly valuable task force for our members, indicative of DIDs becoming commodity infrastructure for some markets. For example, ThisDID.com, which is proposing a new design for the DIF-hosted Resolver, works hand-in-glove with the "blockchain explorer" for the Algorand virtual machine, and gets much of its traffic from Algorand-ecosystem developers investigating (or debugging) on-chain records and histories of on-chain actors, while DanubeTech's Uniresolver.io and VidOS have been supporting research and production deployments on a more classic SaaS tooling model as developer tools. Expenses are stable, though still high. We have started to get better stats about the Universal Resolver, but we have found that the bulk of the costs are for compute, specifically, for running so many heterogenous drivers, many of which cost almost as much to run idle as to run under load. There are a number of services we can reduce and eliminate in the short term to further reduce AWS costs. The task force is looking into technical solutions to reduce more costs in short term. A load-balancing architecture has been proposed to use very low cost storage that can replace the current AWS server cluster, for dramatic cost reduction and easy maintenance. Additionally, metrics for studying cost (and comparing the classic resolver to the TypeScript variants, for which fewer drivers have been submitted) are also being proposed as a work item of the task force; this may validate that many of the more expensive-to-run servers can be drastically cheaper in a different "form factor", or cheaper run on one cloud provider than another. If this turns out to be the case, the Task Force could document a few exemplary refactors/cloud-migrations, and encourage the developers of prior drivers to convert their existings drivers to get more uptake. To contribute or inquire about any of these efforts, find MG (from ThisDID.com) in the #universal-resolver channel on DIF's Slack server, or just attend the every-other-week UR call on the DIF calendar (note new time).

👉 Learn more and get involved

Claims and Credentials Working Group

DIF is working on a specification for "DIF credentials" (i.e. externally-presentable credentials that attest to contribution or participation history in DIF) as a way of prototyping some of the DID and VC toolings DIF has hosted or contributed to in recent years. If you're interested in getting involved, please reach out via email to ed@.

👉 Learn more and get involved

If you are interested in participating in any of the Working Groups highlighted above, or any of DIF's other Working Groups, please click join DIF.

📢 Upcoming Events

ITU SG17: Hot Takes with Grace Rachmany and Juan Caballero
📅 10AM Pacific Time on June 29, 2026
📍 Live on Zoom
Check the DIF Calendar for more details

AI for Good (ITU event)
📅 July 7-9, 2026
📍 Geneva
Event information

Dweb Camp
📅 July 8-12, 2026
📍 Alte Hölle, Germany
Event information

GDC 2026
📅 September 1-3, 2026
📍 Geneva, Switzerland
Event information
Tickets
DIF will be supporting applications to speak until the end of June. Tickets for DIF Members are limited, so if you register, we may ask you for more details before approving the application.

Identity Week America
📅 September 2-3, 2026
📍 Washington, DC
Event information

👉Are you a DIF member with news to share? Email us at communication@identity.foundation with details.

🆔 Join DIF!

If you would like to get in touch with us or become a member of the DIF community, please visit our website or follow our channels:

Follow us on Twitter/X

Join us on GitHub

Subscribe on YouTube

🔍

Read the DIF blog

New Member Orientations

If you are new to DIF join us for our upcoming new member orientations. Find more information on DIF’s slack or contact us at community@identity.foundation if you need more information.

Friday, 19. June 2026

DIF Blog

DIF, ToIP Joint Announcement: Two Recommended DID Methods

did:webvh and did:webplus are the first to pass the DIF vetting process for Recommended DID Methods With the formal recommendation of did:webvh and did:webplus, the Decentralized Identity Foundation (DIF) has made a major stride towards a clear implementation pathway for DID-based identity systems. Having hundreds

did:webvh and did:webplus are the first to pass the DIF vetting process for Recommended DID Methods

With the formal recommendation of did:webvh and did:webplus, the Decentralized Identity Foundation (DIF) has made a major stride towards a clear implementation pathway for DID-based identity systems. Having hundreds of DID methods to choose from without any kind of vetting for production-readiness and maturity has made it difficult for implementers to confidently take the first steps in launching decentralized identity systems. In April of 2025, the DIF DID Methods Working Group first published 13  steps for becoming a DIF Recommended method. The process was the outcome of a collaboration between DIF, Trust over IP (ToIP), and the W3C DID Working group, who signed a letter of intent in 2024 to work jointly towards DID standardization. The initial three methods submitted to the process were did:webvh, did:webplus, and did:webs. Today, DIF and ToIP officially announce the first two recommended DID methods, did:webvh and did:webplus, have completed and passed the process. 


What is a DIF Recommended DID Method?

DIF recommendation is not a certification, nor does it imply the superiority of one method over another. What it means is that the DID method has gone through the process of demonstrating technical viability in production systems over time, and that it can be implemented generally, not just in a specialized case. While DIF continues to remain agnostic to the technology stack, we see it as important to support easier paths to deployment, providing “strength in numbers” as a market develops around DID-based technologies. 

Full-fledged certification is outside of DIF’s mandate as an organization that supports research, standards and specification development, but we hope this coarse-grained initial step will encourage organizations closer to specific technology markets to further vet and endorse specific DID-based implementations, registries, and ecosystems.

“We're trying to accomplish two goals here. On one hand, we evaluate DID methods individually regarding their maturity. Two candidates are now officially recommended. But on the other hand, we would also like to see diversity in the overall set of recommended DID methods, and we look forward to other DID methods going through the process.” said Markus Sabadello, DIF Steering Committee Member and one of the original developers of DID methods. 

Many DID methods based on different technology stacks were submitted to the DID Methods Working Group over the course of the last year, and two of them have successfully met all of the required measures. Added Drummond Reed, co-chair of the ToIP Steering Committee and one of the editors of the W3C Decentralized Identifiers (DIDs) 1.0 standard, “This is a great sign of the growing maturity of DID methods. DIDs are a primary building block of the ToIP stack, and ToIP is glad to support this work, which adds a dimension of rigor to any DID method that goes through the entire process.” 

Criteria for DIF DID Recommendation 

The DID Methods Selection criteria stipulated that DIF is aiming to approve web based, “decentralized” (i.e., non-ICANN), and ephemeral (i.e., “offline” and unobservable) DID methods, so the approval of two web-based methods is just the beginning. Currently, two blockchain-based DID Methods, the Ethereum-based did:ethr and the Sidetree-like multi-blockchain did:cid, are in the 60-day review period at DIF. DIF expects to see did:peer (the ephemeral method used by most DIDComm implementations to date) coming in as a candidate for recommendation in the coming weeks.

Are you using did:ethr? Participate to help did:ethr get recommended status
“We know that did:ethr has been implemented in several production environments,” said Jonathan Rayback Co-Chair of the DID Methods Working Group. “We’re actively seeking contributors and reviewers for did:ethr. For projects using did:ethr, this is a perfect opportunity to boost the acceptance of their projects by supporting the recommended methods process at DIF.” 

All of DIF’s work is driven by its members, contributing time on a voluntary basis. Any individual or organization using a DID method can submit their method for approval as a DID Recommended Method. Candidates present the DID method at the weekly working group, which provides feedback for finalizing the method. Typically, after the initial presentation, there are one or two deep-dives to ask further questions, and then an open review period of 60 days. If all the criteria are met within those 60 days, the Working Group will approve the declaration of the method as being on the list of DIF Recommended Methods.

Next step for DID maturity

DIDs are proving themselves in widescale deployments, particularly in East and Southeast Asia, but there’s a gap in recognition of the maturity of decentralized identity technology. Having specific recommended methods is one of the steps DIF is taking to make it easier to deploy DIDs. In the coming months, DIF will be taking steps to move more DID methodologies through international standards bodies, which gives DIDs the kind of status they need for deployment in big business and government applications.

DIF will be actively pursuing approval for DID methods in international standards bodies, specifically W3C and ITU. If you are interested in helping us fund this effort, please reach out to ed@identity.foundation

Learn More

If you would like to get in touch with us or become a member of the DIF community, please visit our website.


| Follow us on Twitter
| Join us on GitHub
| Subscribe on YouTube
| Read our DIF blog
| Read the archives

Wednesday, 17. June 2026

FIDO Alliance

Biometric Update: Passkey adoption stalls at scale despite strong interest, new study shows

The FIDO Alliance and HID have released new research showing a widening gap between enterprise confidence in identity security and day‑to‑day operational performance. The State of Physical and Digital Identity in the Enterprise report […]

The FIDO Alliance and HID have released new research showing a widening gap between enterprise confidence in identity security and day‑to‑day operational performance. The State of Physical and Digital Identity in the Enterprise report surveyed 500 IT and cybersecurity decision makers across the U.S., Canada, the UK, France and Germany.

Most organizations believe they can revoke all physical and digital access within 24 hours when an employee leaves. In fact, 94 percent expressed confidence in that ability. But more than 170 respondents said they had experienced delays or failures doing so in the past two years. At least one identity‑related security incident overall was reported by 70 percent of respondents.

The study found that governance remains split between physical and digital identity teams. Only half of enterprises have unified reporting lines, while 48 percent have consolidated budget ownership. Finance is the most fragmented sector, with 34 percent operating fully separate reporting structures despite strict regulatory requirements.

Identity complexity is also rising, as 59 percent of organizations now manage three or more credential or authentication systems. More than half, 58 percent, said digital identity management has become more complex over the past two years.

The public sector reported the highest incident rate as 43 percent experienced failures revoking access. One in five still rely on manual credential revocation, which is more than double the rate in the IT and technology sector.

Passkey adoption is widespread but not yet mature: 93 percent of organizations are somewhere on the passkey adoption path. However, 65 percent report high or expert technical familiarity. But only 13 percent have deployed passkeys at scale. The report links this directly to the high rate of identity‑related incidents.

Phishing‑resistant authentication remains a top priority. Nearly half, 45 percent, said reducing phishing and credential‑based breaches is the main driver for moving to passwordless authentication. And 44 percent cited the need to cut IT costs from password resets and help‑desk load.

Andrew Shikiar, executive director and chief executive of the FIDO Alliance, said the findings show a clear execution gap. He said passkeys only deliver full protection when deployed comprehensively across the organization.

Sean Dyon, VP of HID’s Authentication Business Unit, said identity security has become a governance challenge as much as a technical one. “As organizations adopt passkeys, a unified approach to managing physical and digital identity becomes critical,” he says. “This research shows that fragmented governance, disconnected systems and limited visibility create real business risk.”

The full report is being launched this week at Identiverse 2026, where the FIDO Alliance and HID are exhibiting.


Request for Proposal (RFP): ISO/IEC 17065 Accreditation Consultancy

The FIDO Alliance is seeking a specialized consulting partner to guide us through the ISO/IEC 17065 accreditation process. Our objective is to be recognized as a Certification Body (CB) capable […]

The FIDO Alliance is seeking a specialized consulting partner to guide us through the ISO/IEC 17065 accreditation process. Our objective is to be recognized as a Certification Body (CB) capable of evaluating and certifying wallet components, including authenticator sub-components, under the FIDO Alliance Wallet and Authenticator Certification Schemes.

Interested parties should review the Request for Proposal (RFP): ISO/IEC 17065 Accreditation Consultancy.

Proposals must be submitted in writing to karen@fidoalliance.org and paul@fidoalliance.org by July 7th, 2026.

The FIDO Alliance will make a decision by July 10th, 2026.

Tuesday, 16. June 2026

DIF Blog

DIF Announces Public Release of HATPro Schema for Hospitality, Travel, and Leisure

DIF’s Hospitality and Travel Working Group has been taking on a herculean task: creating a protocol for travelers to manage their travel preferences in a privacy-preserving way, through their digital identity apps. It’s an ambitious project, including travel preferences as diverse as food allergies all

DIF’s Hospitality and Travel Working Group has been taking on a herculean task: creating a protocol for travelers to manage their travel preferences in a privacy-preserving way, through their digital identity apps. It’s an ambitious project, including travel preferences as diverse as food allergies all the way through to rock climbing equipment rental preferences.

This week, the H&T WG announces the open review and prototyping period for their Hospitality & Travel Profile (HATPro) open-source schema. The schema is now available in a GitHub repository for use by developers. Initially, the schema includes extensive modeling of food and beverage preferences and allergies for more than 1000 ingredients and cuisines, as well as outlines for activity and experience categories. The working group has identified a suite of tools to support developers, and is actively working on a toolkit. 

Like all working groups in DIF, H&T does all its work through volunteer contributions of DIF members. If you are developing solutions in the area of hospitality and travel, joining DIF is simple. The H&T group is actively seeking feedback on the HATPro schema.

An executive summary, overview, and implementation guide (updated for the current version) is available here.

The HATPro effort has been led by DIF’s Hospitality and Travel Working Group (HTWG), chaired by Douglas Rice and Neil Thomson. The HTWG consists of industry experts from numerous sectors of travel, hospitality, leisure and the identity ecosystem. Technical artifacts and preliminary documentation are now available in the HTWG GitHub repository. The working group encourages industry stakeholders to engage to provide feedback, new ideas, and specific use cases to help guide future priorities; they may be submitted as GitHub issues (for those familiar with GitHub) or using this web form (for others). More general questions and feedback can also be submitted by email at the contact address below.

Contact:
Please email ht-governance@identity.foundation 


GLEIF

#22 in the LEI Lightbulb Blog Series – The LEI in U.S. Law: What the FDTA Final Joint Rule Means

Federal agencies in the U.S. have historically operated across more than 50 distinct, incompatible entity identification systems. The Financial Data Transparency Act (FDTA), signed into law in 2022, sought to address this fragmentation by establishing a common language for financial data that regulators, institutions, and analysts can rely on. In June 2026, nine U.S. financial agencies finalized

Federal agencies in the U.S. have historically operated across more than 50 distinct, incompatible entity identification systems. The Financial Data Transparency Act (FDTA), signed into law in 2022, sought to address this fragmentation by establishing a common language for financial data that regulators, institutions, and analysts can rely on.

In June 2026, nine U.S. financial agencies finalized the joint rule under the FDTA to promote the interoperability of financial regulatory data. This followed a public consultation in August 2024.

In a milestone that promises to significantly enhance regulatory oversight and reduce compliance burdens, the final joint rule establishes the Legal Entity Identifier (LEI) as the standard for entity identification. It also establishes common identifiers for geographic locations, dates, and certain products and currencies.

In practice, the entities most likely to fall within scope are those that already report financial data to the nine agencies, from banks and credit unions to securities and derivatives market participants, to investment advisors and mutual funds. The precise reporting obligations, however, will be set by each agency’s own rulemaking rather than by the joint rule itself.

The Data Foundation, which has advocated for the modernization of federal financial data reporting for over a decade, welcomed the rule’s establishment of the LEI as the standard for entity identification, describing it as a significant turning point in modernizing federal financial reporting.

Why the LEI

The FDTA explicitly requires the adoption of a common, non-proprietary, machine-readable legal entity identifier available under an open license. This requirement dates back to the 2011 'Linchpin' paper, in which U.S. regulators first recognized the need for a standardized code to uniquely identify legal entities and their relationships.

The final rule reaffirms that the LEI – as a globally standardized 20-character alphanumeric code that uniquely and unambiguously identifies a legal entity – is the standard that best meets the requirements outlined in the FDTA:


Many commenters supported the establishment of the LEI as the legal entity identifier joint standard. These commenters stated, among other things, that the LEI meets the requirements of the FDTA, would promote interoperability, would provide improved identification of entities across jurisdictions, is already well-established in at least some markets and among larger financial entities, has low costs and fees, and has a transparent and independent governance structure.

Final Rule: Financial Data Transparency Act Joint Data Standards


Following a thorough public consultation, the final rule confirms why “the LEI meets all of the FDTA’s requirements for legal entity identifiers, that is, it is common, nonproprietary, and is available under an open license.”

What Next?

With the joint rules coming into effect from 1 October 2026 and providing a common foundation, each implementing agency now has up to two years to complete its own rulemaking and incorporate the joint standards into respective reporting requirements. Entities preparing for FDTA-driven reporting can act now: review LEI coverage across your organization and counterparties, identify gaps, and begin obtaining LEIs where needed. This work takes time and does not depend on the agency rulemakings being finalized. During this period, all interested stakeholders are encouraged to monitor agency-specific consultations as they open and engage with the rulemaking process where relevant.

GLEIF also looks forward to engaging with each agency while continuing our commitment to broadening the accessibility and utility of the Global LEI System.

Organizations can search and verify existing LEIs through the Global LEI Index, and any legal entity that does not yet have an LEI can obtain one from an accredited issuing organization.

The ‘LEI Lightbulb Blog Series’ from GLEIF aims to shine a light on the breadth of acceptance and advocacy for the LEI across the public and private sectors, geographies, and use cases by highlighting which industry leaders, authorities, and organizations support the LEI and for what purpose.


Digital ID for Canadians

Spotlight on ICDR

1. What is the mission and vision of ICDR? ICDR’s mission is to create a trusted verification layer for the competitive dance community, helping confirm…

1. What is the mission and vision of ICDR?

ICDR’s mission is to create a trusted verification layer for the competitive dance community, helping confirm dancer, guardian, and studio relationships in a secure and privacy-conscious way. Its vision is a dance ecosystem where families, studios, competitions, and approved partners can interact with greater confidence, less friction, and stronger protection for dancer information.

2. Why is trustworthy digital identity critical for existing and emerging markets?

In competitive dance, young performers often interact with studios, competitions, media providers, registration platforms, and other service partners. Without a trusted way to verify identity, consent, and affiliation, families may be asked to repeatedly share sensitive information across disconnected systems. Trustworthy digital identity helps reduce friction while supporting privacy, safety, and confidence.

3. How will digital identity transform the Canadian and global economy? How does your organization address challenges associated with this transformation?

In competitive dance, young performers often interact with studios, competitions, media providers, registration platforms, and other service partners. Without a trusted way to verify identity, consent, and affiliation, families may be asked to repeatedly share sensitive information across disconnected systems. Trustworthy digital identity helps reduce friction while supporting privacy, safety, and confidence.

4. What role does Canada have to play as a leader in this space?

Canada can lead by showing how digital trust can be applied not only in finance, government, and automotive sectors, but also in community-based sectors where young people, families, and small organizations need practical privacy-first solutions.

5. Why did your organization join the DIACC?

ICDR joined the DIACC to align with Canada’s digital trust community, learn from established frameworks, and contribute a real-world use case from youth activity, sport, arts, and event ecosystems.

6. What else should we know about your organization?

ICDR is focused on responsible verification, dancer privacy, guardian involvement, and trusted studio affiliation. It is designed to support the practical realities of competitive dance while helping the industry modernize safely.


Spotlight on Teranet

1. What is the mission and vision of Teranet? At Teranet, our vision is to be the trusted partner to governments and businesses in building…

1. What is the mission and vision of Teranet?

At Teranet, our vision is to be the trusted partner to governments and businesses in building stronger communities and economies.

Our mission is to efficiently connect government, business, and consumers through the delivery and transformation of registry services, data insights, and ecosystem platform solutions, while maintaining the highest standards of reliability and integrity.

For more than 30 years, Teranet has been a trusted partner to governments and businesses, delivering and modernizing critical registry infrastructure across Canada. As Canada’s leader in statutory registry services, Teranet combines unmatched registry expertise with reliable data and insightful solutions that help support secure transactions, informed decision making, and stronger communities and economies.

2. Why is trustworthy digital identity critical for existing and emerging markets?

As economies become increasingly digital, trust in identity, ownership, and authoritative data has become foundational to how business is conducted.

Organizations need confidence that the people, businesses, and assets they interact with are legitimate, verified, and supported by secure systems. Without that trust, the risk of fraud, financial crime, and operational inefficiency increases significantly.

In Canada, this is especially important in sectors such as real estate, lending, and public registries, where fragmented data systems and increasingly sophisticated fraud schemes continue to create risk. Digital trust is no longer simply a compliance requirement. It is essential infrastructure that supports market confidence, economic growth, and long-term resilience.

3. How will digital identity transform the Canadian and global economy? How does your organization address challenges associated with this transformation?

Digital trust will reshape the economy by enabling faster, more secure, and more connected transactions across industries, jurisdictions, and digital ecosystems.

As governments and businesses modernize, there is growing demand for systems that can verify identity, validate ownership, and provide trusted access to authoritative data in real time. At the same time, fragmented systems and limited interoperability continue to create vulnerabilities that can be exploited, particularly in high-value sectors such as real estate and financial services.

This is where Teranet plays a critical role.

Through our registry expertise, secure infrastructure, and advanced data solutions, Teranet helps organizations reduce risk, improve transparency, and make more confident decisions. We continue to invest in technologies such as advanced analytics, automation, and artificial intelligence to strengthen fraud detection, improve due diligence, and support more connected registry ecosystems built on a single source of truth.

4. What role does Canada have to play as a leader in this space?

Canada has a strong foundation to lead in digital trust, supported by trusted institutions, a mature regulatory environment, and a history of innovation in public infrastructure.

As digital identity and ownership verification become increasingly important, Canada has an opportunity to lead by building more connected registry systems, advancing stronger data standards, and improving interoperability across jurisdictions. Achieving this will require collaboration between governments, industry, and technology leaders to modernize critical infrastructure while balancing transparency, privacy, and security.

At Teranet, we believe registries are foundational to that future. As authoritative systems of record, modernized registries play a critical role in strengthening trust and supporting a more resilient digital economy.

5. Why did your organization join the DIACC?

Teranet joined the Digital ID & Authentication Council of Canada because building digital trust requires collaboration across sectors.

DIACC brings together leaders from government, technology, and industry to help shape the standards and partnerships needed to support a secure and trusted digital economy. Teranet is proud to contribute our experience in operating critical registry infrastructure and delivering trusted digital solutions that support secure transactions and stronger market confidence.

6. What else should we know about your organization?

Teranet is Canada’s leader in the delivery and transformation of statutory registry services, with more than 30 years of experience supporting governments, businesses, and consumers through secure registry infrastructure, authoritative data, and innovative digital solutions.

For more than three decades, governments have trusted Teranet to securely operate critical registry systems that support millions of transactions every year with exceptional reliability, security, and performance. Teranet’s platforms support over 10 million land-related transactions annually with 99.9 percent system availability and zero known security breaches over the past decade.

Beyond registry operations, Teranet delivers innovative data and technology solutions that help customers improve decision making, manage risk, and combat fraud across real estate, lending, legal, and government sectors. Solutions such as GeoWarehouse® and PurView® provide customers with access to authoritative insights built on one of the most trusted data foundations in Canada.

Teranet is wholly owned by OMERS Infrastructure, the Ontario Municipal Employees Retirement System.


FIDO Alliance

HRTECH EDGE: Most Enterprises Think Identity Access Is Secure. New Research Suggests Otherwise

Enterprises may be more confident about identity security than they should be. A new report from the FIDO Alliance and HID finds a striking disconnect between how organizations perceive their […]

Enterprises may be more confident about identity security than they should be.

A new report from the FIDO Alliance and HID finds a striking disconnect between how organizations perceive their ability to manage employee access and what actually happens when workers leave. While nearly all surveyed organizations believe they can revoke physical and digital access within 24 hours, more than one-third admit they have failed to do so in practice.

The findings, published in The State of Physical and Digital Identity in the Enterprise, highlight growing concerns around fragmented identity governance, disconnected authentication systems, and slow adoption of phishing-resistant technologies at a time when cyber threats continue to intensify.

Based on a survey of 500 IT and cybersecurity decision-makers across North America and Europe, the report paints a picture of organizations struggling to keep pace with increasingly complex identity environments.


Carrier Management: Major Gap Between Identity Security Confidence and Reality: Study

A new report uncovered a significant disconnect between enterprise confidence in identity security and operational reality, according to identity technology providers FIDO Alliance and HID. Of the 500 IT and […]

A new report uncovered a significant disconnect between enterprise confidence in identity security and operational reality, according to identity technology providers FIDO Alliance and HID.

Of the 500 IT and cybersecurity decision-makers surveyed across the US, Canada, UK, France, and Germany, 94% said they could revoke employee access within 24 hours, yet 35% reportedly experienced delays or failures in the past two years.

The report, “The State of Physical and Digital Identity in the Enterprise,” also found that 70% experienced at least one identity-related security incident overall.

The results showed that governance is fragmented, with only 50% of enterprises having unified reporting ownership for physical and digital identity, and just 48% have consolidated budget control.

Finance is the most governance-fragmented sector, with 34% maintaining fully separate reporting structures despite stringent regulatory access-control obligations.

The report also found that complexity is growing, with 59% of enterprises reportedly managing three or more distinct credential and authentication systems, and 58% reported that managing digital identity has become more complex over the past two years.

The public sector carries the highest incident rate of any industry, with 43% experiencing access revocation failures. It has a 20% manual credential revocation rate, more than double that of the IT/Technology sector.

Passkey adoption is a must to protect businesses, the report found, as 93% of organizations are at some stage of passkey adoption, and 65% report high or expert technical familiarity. Just 13% have deployed passkeys at scale, which may explain why organizations experience such high levels of security incidents.

“Identity security is no longer just an authentication challenge; it is an enterprise governance challenge. As organizations adopt passkeys, a unified approach to managing physical and digital identity becomes critical. This research shows that fragmented governance, disconnected systems, and limited visibility create real business risk,” said Sean Dyon, vice president of the Authentication Business Unit at HID.

The report found that the leading driver for moving to passwordless authentication is reducing phishing and credential-based breach risk (45%), followed by reducing IT costs from password resets and help desk load (44%).

“The story in this data isn’t about awareness, it’s about execution. Ninety-three percent of organizations are on the passkey journey. Still, only 13% have deployed at scale, and the security incident rates reflect that gap directly,” said Andrew Shikiar, executive director and CEO of the FIDO Alliance. “Phishing-resistant authentication only delivers its full protective value when deployment is comprehensive rather than selective – because threat actors don’t limit themselves to the parts of the organization that are already protected.”


Energy Web

Energy Web and Azzera Join Forces to AdvanceTrusted SAF Compliance and Digital Verification for…

Energy Web and Azzera Join Forces to AdvanceTrusted SAF Compliance and Digital Verification for Aviation Collaboration combines sustainable aviation fuel (SAF) compliance expertise with trusted digital infrastructure to improve transparency, reporting, and environmental integrity across the aviation sector Zug, 16 June 2026 — Energy Web and Azzera Inc. today announced a strategic colla
Energy Web and Azzera Join Forces to AdvanceTrusted SAF Compliance and Digital Verification for Aviation Collaboration combines sustainable aviation fuel (SAF) compliance expertise with trusted digital infrastructure to improve transparency, reporting, and environmental integrity
across the aviation sector

Zug, 16 June 2026 — Energy Web and Azzera Inc. today announced a strategic collaboration to support the next generation of sustainable aviation fuel (SAF) compliance, reporting and verification solutions for the aviation industry. By combining Azzera’s aviation-focused decarbonization
platform with Energy Web’s trusted digital infrastructure, the companies aim to streamline SAF certificate management, enhance transparency and strengthen confidence in environmental claims across the SAF value chain.

The collaboration builds on the successful execution of a SAF Proof of Delivery (POD) pilot, which demonstrated how digital verification can improve traceability and trust in SAF transactions. The pilot explored mechanisms for securely validating fuel delivery events and connecting sustainability attributes to verifiable digital records, helping address longstanding challenges around chain-of-custody, reporting accuracy and stakeholder trust.

As SAF adoption accelerates globally, airlines, corporate customers, fuel suppliers, and regulators face growing demands for auditable evidence supporting emissions reductions and sustainability claims. The partnership between Energy Web and Azzera seeks to address these needs through interoperable digital solutions that enable reliable data exchange and verifiable compliance workflows.

A key component of the collaboration is the integration of Energy Web’s Verified Compute technology. Verified Compute enables organizations to prove that calculations, reporting processes, and digital workflows have been executed as intended using distributed computing environments. Applied to SAF compliance and environmental attribute management, Verified Compute can help provide assurance that critical emissions accounting, certificate allocation and compliance-related calculations are performed transparently and consistently.

“Trust and transparency are foundational to scaling sustainable aviation fuel markets,” said Katy Lohmann, CCO, Energy Web. “Our collaboration with Azzera demonstrates how trusted digital infrastructure and verifiable computing can help establish confidence in SAF-related data, compliance processes and environmental claims. Together, we are helping to build the digital foundations necessary for aviation’s decarbonization journey.”
“If we are to scale SAF demand, we need to reduce the administrative costs for aircraft operators to claim SAF usage incentives today. Our collaboration helps set the foundational trust in such a multi-stakeholder process,” said Anant Jain, COO, Azzera. “By combining Azzera’s expertise in aviation sustainability with Energy Web’s digital trust technologies, including Verified Compute, we can deliver greater transparency, accountability and most critically efficiency across SAF programs and reporting frameworks.”

The companies envision a future where SAF sustainability attributes can be tracked, allocated, and reported through secure digital systems that reduce administrative complexity while improving auditability. The SAF POD pilot serves as an important milestone toward that objective, demonstrating how trusted digital verification can support more efficient and credible SAF markets. Together, we are designing a verification architecture that addresses all three problems: cross-platform evidence uniqueness, independent emission factor resolution and deterministic calculation validation.

Two of Europe’s leading aviation emissions verifiers have joined the pilot to help define what auditor-ready evidence packages should look like in practice.

Normec Verifavia (normecverifavia.com) is a globally recognised leader in aviation emissions verification, accredited under ISO/IEC 17029:2019 (the details of the accreditation can be found here: Normec Verifavia — Leading Independent Emissions Verification & Sustainability). Normec Verifavia has verified the emissions of more than 300 commercial airlines across more than 100 countries under EU ETS, UK ETS, Swiss ETS, and ICAO CORSIA. They actively support airlines in their transition to Sustainable Aviation Fuels through dedicated SAF Programme Assurance audits. Their participation in this pilot ensures that the verification outputs are shaped by the auditors who will ultimately rely on them.

ETS Verification GmbH (etsverification.com), headquartered in Germany, is a leading independent verification body specialising in aviation environmental compliance and greenhouse gas assurance. Accredited by the German Emissions Trading Authority (DEHSt) and operating in accordance with ISO/IEC 17029:2019, ETS Verification provides verification services under EU ETS, UK ETS, Swiss ETS, ICAO CORSIA, and ReFuelEU. With a broad international client portfolio, ETS Verification supports commercial airlines, cargo operators, business aviation companies, and corporate flight departments worldwide. The company combines extensive aviation-specific expertise with a deep understanding of emissions monitoring, fuel reporting, regulatory compliance, and sustainability requirements. In addition to emissions verification, ETS Verification has experience in Non-CO₂ aviation climate impact verification and greenhouse gas audits, supporting operators in addressing emerging environmental reporting and assurance requirements.

Together with Normec Verifavia, ETS Verification will evaluate whether machine-verifiable evidence packages can reduce verification effort, enhance audit coverage, and deliver outputs that meet the stringent requirements of EU ETS, CORSIA, ReFuelEU Aviation, and future sustainability reporting obligations. Their feedback will contribute directly to the development of verification logic, evidence package structures, and auditor access protocols, ensuring that the resulting framework reflects the needs and expectations of experienced aviation verifiers.

Beyond SAF delivery verification, the collaboration will explore broader opportunities to leverage trusted digital infrastructure for aviation sustainability initiatives, including emissions reporting, certificate management, compliance automation, and environmental attribute accounting.

As governments, regulators, and industry participants continue to expand SAF deployment and establish new compliance frameworks, Energy Web and Azzera are committed to supporting scalable, interoperable solutions that strengthen market integrity and accelerate progress toward aviation decarbonization goals.

About Energy Web

Energy Web is a global nonprofit organization building and operating open-source digital infrastructure to accelerate the energy transition. Through technologies that enable trusted data exchange, digital identity, and verifiable computing, Energy Web helps organizations create transparent and interoperable solutions for energy and environmental markets.

About Azzera

Azzera provides aviation-focused sustainability solutions that help airlines and corporate customers manage emissions reduction strategies, including sustainable aviation fuel programs, environmental attribute management, and carbon market participation. Through digital tools and industry expertise, Azzera supports the aviation sector’s transition toward a lower-carbon future.

Energy Web and Azzera Join Forces to AdvanceTrusted SAF Compliance and Digital Verification for… was originally published in Energy Web on Medium, where people are continuing the conversation by highlighting and responding to this story.


Blockchain Commons

Dispatches of a Trust Architect: When Intelligence Becomes a Permission

After three decades of building internet infrastructure, I’ve learned that the most dangerous moment isn’t when a system fails, it’s when it succeeds and then inverts its purpose. This week confirmed that again. Anthropic abruptly disabled its frontier models Fable 5 and Mythos 5 for every customer, to comply with a U.S. government national-security order. The immediate disruption was minor: the mo

After three decades of building internet infrastructure, I’ve learned that the most dangerous moment isn’t when a system fails, it’s when it succeeds and then inverts its purpose. This week confirmed that again. Anthropic abruptly disabled its frontier models Fable 5 and Mythos 5 for every customer, to comply with a U.S. government national-security order.

The immediate disruption was minor: the models were only days old, and Anthropic’s other models still run. What matters is what it proved: a government can reach in and switch off a frontier model for everyone, overnight. The off-switch exists, and now we know who controls it.

For years I’ve been making a different argument, and building a name for the alternative: Self-Sovereign Computing and the design pattern I call Exodus Protocols. The Fable suspension is one more confirmation of why they matter.

I’m not the first to warn that frontier AI companies have become part of the problem. The sharpest version of that case belongs to Ahmad Osman, an AI researcher and r/LocalLLaMA moderator who recently wrote the essay “Anthropic’s War on Opensource AI”. The Anthropic framing is his. He wrote his article arguing a general pattern, not this specific event. The recent suspension isn’t even in it!

“It is selling cognition as infrastructure. Once cognition becomes infrastructure, anti-competitive access control stops being a normal vendor dispute and becomes a social bottleneck.”

“Claude is not your agent. Claude is Anthropic’s agent, rented to you.”

Read after Friday’s suspension of Fable, it reads like a forecast. The government pulling Fable is that pattern arriving on schedule.

This isn’t hypothetical

A frontier model was pulled for everyone, by government order, and Fable access already required 30-day retention of your data. The next step writes itself: an identity check to use a frontier model — age-gating technology, but for thought — and monitored sessions as the price of entry. We have built that machinery before, for other purposes; now, it ports cleanly to cognition. Ahmad’s name for where that leads is hard to improve on:

“A society where a few labs own the frontier and everyone else rents obedient wrappers is not advanced. It is feudalism with GPUs.”

Or, as I say in my community draft of The Architecture of Autonomy:

“We are human beings, not digital serfs.”

The pattern is older than AI

This is where my own framing comes in, because the shape is not new. When I co-authored TLS 1.0, we already understood that technical protocols encode power relationships. The coalition that stopped Microsoft/Visa/Mastercard from owning the internet plugged that hole. Yet, in every decade since, we have closed one architecture that funneled rent and control toward a center — certificate authorities, platforms, identity systems — only to watch a larger one open in its place. As I wrote in my article, “When Technical Standards Meet Geopolitical Reality”:

“We build protocols for human autonomy and watched them become instruments of platform control.“

Permissioned AI is the biggest such hole yet. It is the inversion I have spent years naming: a right quietly rewritten as a revocable privilege. The test is simple: when a capability depends on someone’s approval, it is not a right. It is permission.

The way out is the one that has always worked: Exit

As I say in “The Exodus Protocol”:

“Without the ability to walk away, consent collapses into coercion.”

The answer to a permission regime is not to petition for kinder permissions; it is to stop needing them. Own the model. Own the hardware. Own the keys. Local inference, open weights, and your own cryptographic control: this is what Self-Sovereign Computing and Exodus Protocols have always been about. Ahmad arrives at the same place from the builder’s side:

“A GPU is a tiny declaration of independence.”

None of this is inevitable. We have routed around centralized control before, and we can build the exit again: self-sovereign identity, self-sovereign computing, and now self-sovereign cognition that no one can revoke, degrade, or rent back to you.

Own the stack

A decade ago I helped write the principles of Self-Sovereign Identity. We are revisiting them now, for their tenth anniversary, because the frontier has moved, from who controls your identity to who controls your cognition. The principle has not changed, only the stakes: own it or rent it.

Monday, 15. June 2026

FIDO Alliance

Crypto News: xMoney revolutionizes digital payments: first in the world to launch Mastercard Payment Passkey via app

xMoney marks a key milestone in the evolution of digital payments, becoming the world’s first Mastercard issuer to launch the creation and enrollment of the Payment Passkey directly through its own mobile banking application. […]

xMoney marks a key milestone in the evolution of digital payments, becoming the world’s first Mastercard issuer to launch the creation and enrollment of the Payment Passkey directly through its own mobile banking application. The announcement, made in Bucharest on June 11, 2026, positions xMoney as a pioneer in offering a solution that promises to redefine the security, simplicity, and speed of online transactions.

What is the Mastercard Payment Passkey

The Mastercard Payment Passkey represents a new frontier in the authentication of digital payments. It is a solution that allows users to create a payment passkey within the issuer’s banking environment, thereby authenticating online transactions in compliance with SCA (Strong Customer Authentication) requirements. The system also allows cardholders to securely access their Click to Pay profile.

Greg Siourounis, Co-founder & CEO of xMoney, highlights the importance of this innovation: “We are entering a new phase of payment infrastructure, where authentication, tokenization, and compliance must work together, not as separate layers. Enabling in-app creation of Mastercard Payment Passkeys, together with the availability of Click to Pay via xMoney, shows that this standard is maturing. xMoney is the first Mastercard issuer in the world to offer this combination, setting a new benchmark for digital checkout.”


Report: The State of Physical and Digital Identity in the Enterprise

FIDO Alliance and HID have launched The State of Physical and Digital Identity in the Enterprise, a new research report examining how organizations manage physical and logical access across their […]

FIDO Alliance and HID have launched The State of Physical and Digital Identity in the Enterprise, a new research report examining how organizations manage physical and logical access across their workforces.

Surveying 500 IT and cybersecurity decision makers across the US, Canada, UK, France, and Germany, the new study uncovered a significant disconnect between enterprise confidence in identity security and operational reality. While most organizations believe they can revoke all physical and digital access within 24 hours when an employee leaves, more than one-third report experiencing actual failures doing so, contributing to identity-related security incidents across the enterprise.

Read the full report

New FIDO Alliance and HID Study Reveals Major Gap Between Identity Security Confidence and Reality

Research Reveals 94% of Enterprises Claim They Can Revoke Employee Access Within 24 Hours, Yet 35% experienced delays or failures in the past two years  Identiverse, Las Vegas, June 15, […]

Research Reveals 94% of Enterprises Claim They Can Revoke Employee Access Within 24 Hours, Yet 35% experienced delays or failures in the past two years 

Identiverse, Las Vegas, June 15, 2026 — The FIDO Alliance and HID, a global enabler of trusted identity solutions, today released The State of Physical and Digital Identity in the Enterprise, a new research report examining how organizations manage physical and logical access across their workforces.

Surveying 500 IT and cybersecurity decision makers across the US, Canada, UK, France, and Germany, the new study uncovered a significant disconnect between enterprise confidence in identity security and operational reality. While most organizations believe they can revoke all physical and digital access within 24 hours when an employee leaves, more than one-third report experiencing actual failures doing so, contributing to identity-related security incidents across the enterprise. 

Key findings from the report include:

While confidence is high, so are security incidents

94% of organizations claim confidence that all physical and logical access can be revoked within 24 hours of an employee leaving. Yet 35% experienced delays or failures doing exactly that in the past two years — and 70% experienced at least one identity-related security incident overall.

Governance is fragmented

Only 50% of enterprises have unified reporting ownership for physical and digital identity, and just 48% have consolidated budget control. Finance is the most governance-fragmented sector, with 34% operating fully separate reporting structures despite operating under stringent regulatory access-control obligations.

Complexity is growing, and enterprises manage three separate systems on average

59% of enterprises manage three or more distinct credential and authentication systems. 58% say managing digital identity has become more complex over the past two years.

The Public Sector carries the highest incident rate of any industry

The sector has the highest identity security incident rate of any industry, with 43% experiencing access revocation failures. It has a 20% manual credential revocation rate, which is more than double the IT/Technology sector.

The passkey adoption must scale to protect businesses

93% of organizations are at some stage of passkey adoption and 65% report high or expert technical familiarity. However, only 13% have deployed passkeys at scale, explaining why organizations experience such high levels of security incidents.

Phishing-resistant authentication is a top business priority

The leading driver for moving to passwordless authentication is reducing phishing and credential-based breach risk (45%), followed by reducing IT costs from password resets and help desk load (44%).

“The story in this data isn’t about awareness, it’s about execution. Ninety-three percent of organizations are on the passkey journey, but only 13% have deployed at scale, and the security incident rates reflect that gap directly,” said Andrew Shikiar, executive director and CEO of the FIDO Alliance. “Phishing-resistant authentication only delivers its full protective value when deployment is comprehensive rather than selective – because threat actors don’t limit themselves to the parts of the organization that are already protected.”

“Identity security is no longer just an authentication challenge; it is an enterprise governance challenge. As organizations adopt passkeys, a unified approach to managing physical and digital identity becomes critical. This research shows that fragmented governance, disconnected systems and limited visibility create real business risk. HID is closing that gap by bringing credentials, access rights and lifecycle management together to enable faster, more confident access decisions”, said Sean Dyon, Vice President of the Authentication Business Unit at HID. 

The full report is being launched at Identiverse 2026. Visit FIDO Alliance at booth 252 and HID at booth 800 from June 15-17.

Ends

Notes to editors:

The survey was conducted among 500 IT and cybersecurity decision makers (Manager and above) in Finance, Healthcare, Public Sector, Manufacturing, and IT/Technology, across the US, Canada, UK, France, and Germany. All respondents worked at organizations with 150 or more employees.

About FIDO Alliance

The FIDO Alliance (www.fidoalliance.org) enables identity technologies that put trust and simplicity at the centre of interactions among people, services, and devices. The Alliance publishes open technical specifications, certifies secure and interoperable products, and operates global market enablement programmes.

About HID

HID powers the trusted identities of the world’s people, places and things. We make it possible for people to transact safely, work productively and travel freely. Our trusted identity solutions give people convenient access to physical and digital places and connect things that can be identified, verified and tracked digitally. Millions of people around the world use HID’s products and services to navigate their everyday lives, and billions of things are connected through HID’s technology. We work with governments, educational institutions, hospitals, financial institutions, industrial businesses and some of the most innovative companies on the planet. 

Headquartered in Austin, Texas, HID has over 4,500 employees worldwide and operates international offices that support more than 100 countries. HID is an ASSA ABLOY Group brand. For more information, visit www.hidglobal.com.

FIDO Alliance Media Contact
press@fidoalliance.org

HID Media Contact
Doug Hansel: DougH@BubbleAgency.com 
Kim Velasco: kimv@bubbleagency.com 
Tel: +1 603-537-9248


OpenID

Announcing the new Digital Credentials Harmonized Presentation Working Group

The OpenID Foundation has launched a new working group – the Digital Credentials Harmonized Presentation Working Group (DCHP WG). The new DCHP WG supports a joint initiative between experts of ISO/IEC JTC1/SC 17 (ISO) WG10 and WG4 and the OpenID Foundation’s Digital Credentials Protocols Working Group (DCP WG) to harmonize their credential presentation protocols.  Today, […] The post Announ

The OpenID Foundation has launched a new working group – the Digital Credentials Harmonized Presentation Working Group (DCHP WG).

The new DCHP WG supports a joint initiative between experts of ISO/IEC JTC1/SC 17 (ISO) WG10 and WG4 and the OpenID Foundation’s Digital Credentials Protocols Working Group (DCP WG) to harmonize their credential presentation protocols. 

Today, ISO/IEC 18013-7 Device Request/Device Response and OpenID for Verifiable Presentations (OID4VP) Authorization Request/Authorization Response take different approaches to credential presentation. The DCHP WG will develop a technical specification for a harmonized Digital Credentials Request Protocol that brings these together, and supports the exchange of multiple credential formats (mdoc and SD-JWT VC). 

The group’s charter was mutually agreed by experts from both working groups and sets out its purpose, scope, and method of work in full. This charter has been approved by the Specifications Council in line with the OIDF Process Document.

As the specification is intended for adoption by both ISO WG10 and the OpenID Foundation’s DCP WG, the DCHP WG will follow agreed Working Procedures designed to achieve this goal. 

First meeting and how to participate

The first DCHP WG meeting takes place on Monday 29 June 2026, 6am to 9am PT. Those interested in joining will find the Zoom link on the DCHP WG page.

To follow progress and connect with working group members, please join the mailing list by contacting openid-specs-dchp@lists.openid.net.

In order to contribute to a specification within the working group, an Intellectual Property Rights (IPR) contribution agreement can be submitted, either electronically or by paper by selecting “All WGs” or just the “DCHP WG.” 

About the OpenID Foundation

The OpenID Foundation (OIDF) is a global open standards body committed to helping people assert their identity wherever they choose. Founded in 2007, we are a community of technical experts leading the creation of open identity standards that are secure, interoperable, and privacy-preserving. The Foundation’s OpenID Connect standard is now used by billions of people across millions of applications. In the last five years, OAuth2 – the FAPI standard for interoperable, high security – has become the standard of choice for Open Banking and Open Data implementations, allowing people to access and share data across entities. Today, the OpenID Foundation’s standards are the connective tissue that enable people to assert their identity and access their data at scale, the scale of the internet, enabling “networks of networks” to interoperate globally. Individuals, companies, governments and non-profits are encouraged to join or participate. Find out more at openid.net.

To learn more about conformance testing and self-certification, please visit the OpenID Foundation’s FAQ section.

The post Announcing the new Digital Credentials Harmonized Presentation Working Group first appeared on OpenID Foundation.

Thursday, 11. June 2026

FIDO Alliance

ID Tech: FIDO Opens June Interoperability Testing Window for Certification Candidates

The FIDO Alliance has opened its June interoperability testing event, giving FIDO2 and FIDO UAF implementers a certification step for passwordless authentication products. The remote testing window runs June 8-12, […]

The FIDO Alliance has opened its June interoperability testing event, giving FIDO2 and FIDO UAF implementers a certification step for passwordless authentication products.

The remote testing window runs June 8-12, following a pre-testing period from June 3-7. FIDO interoperability events allow server, authenticator, and client implementers to test their products against one another, identify compatibility issues, and remain eligible for certification once conformance and interoperability requirements are met.

For FIDO2 implementations, servers test against participating authenticators, while client and authenticator implementations test against participating servers under the relevant FIDO procedures. The Alliance requires participating implementations to pass conformance testing self-validation before the interoperability event and to avoid changes between self-validation and testing.

The testing window comes as passkeys continue to move from consumer platforms into enterprise and regulated environments. The FIDO Alliance recently brought its Authenticate conference to Asia-Pacific, and SK Telecom joined the FIDO Alliance board as passkey adoption accelerated.

Passkey deployments rely on interoperability across devices, browsers, identity providers, authenticators, and relying parties. A product that works only inside one vendor’s environment does not deliver the portability and phishing resistance that FIDO standards are intended to support.

The June event also follows continued attention to implementation risks. Proofpoint recently warned of downgrade attack risks for FIDO passkeys, underscoring the need for correct policy configuration and standards-based deployments.

FIDO says implementers that pass the interoperability procedures with all other relevant participants, or show that any failures are not caused by non-conformance in their own implementation, can proceed in the certification process. Additional interoperability events are scheduled for September, with another event planned for November.

The testing process gives implementers feedback before products move into production environments where a failed authenticator, unsupported server behavior, or inconsistent metadata handling can create user lockouts or security gaps.

The FIDO Alliance maintains separate certification programs for servers, authenticators, and clients across FIDO2 and FIDO UAF specifications. Certified products are listed in the Alliance’s metadata service, which relying parties can use to verify authenticator properties during registration and authentication. The Alliance has also been developing specifications for cross-platform passkey exchange, which would allow users to move passkeys between different credential managers and platforms.


Frontier Enterprise: CSA: More authentication does not mean better security

Why do users still get hacked? In the past, it was often because of weak passwords or the absence of multi-factor authentication (MFA), and for a long time, authentication was […]

Why do users still get hacked? In the past, it was often because of weak passwords or the absence of multi-factor authentication (MFA), and for a long time, authentication was treated mainly as a security control that sat quietly in the background of digital systems. Today, however, the real threat lies in authentication itself, which has become ground zero for attackers.

“This shift matters because authentication now plays a much bigger role in how people trust digital systems,” noted Rodney Tan, Director, Cybersecurity Engineering Centre, Cyber Security Agency of Singapore (CSA), during his keynote at the inaugural FIDO Authenticate APAC conference in Singapore.

Whether the digital system is a government service, banking platform, enterprise application, or consumer service, authentication has effectively become the front door to the digital economy, Tan observed.

“If that front door becomes weaker, confidence in the broader digital ecosystem is affected as well,” he added.

Tan then outlined three major issues affecting authentication today: first, authentication has become the primary point of attack; second, shifting the strategy towards resilience will strengthen authentication; and third, scaling stronger authentication requires local ecosystem alignment.

Wednesday, 10. June 2026

FIDO Alliance

Global Banking and Finance Review: The Growing Role of FIDO and Passkeys in Banking Authentication

Banking’s Authentication Problem Has Changed Banks are no longer fighting simple password reuse. They’re facing real-time phishing kits, MFA fatigue, session hijacking, AI-powered social engineering, and more. Traditional MFA methods, such […]
Banking’s Authentication Problem Has Changed

Banks are no longer fighting simple password reuse. They’re facing real-time phishing kits, MFA fatigue, session hijacking, AI-powered social engineering, and more.

Traditional MFA methods, such as OTP via apps, out-of-band SMS, and mobile push approval, continue to leave financial institutions vulnerable because:

They are still based on insecure passwords They are increasingly bypassed

To make matters worse, compliance pressure is on the rise, with regulations such as DORA, Strong Customer Authentication (SCA) mandates, and Federal Financial Institutions Examination Council (FFIEC) guidance clamping down on how banks maintain resilience, develop code, and manage risk.

Yesterday’s access management solutions are no match for today’s emerging risk landscape. And yet the need for bulletproof financial authentication has never been higher.

As a result, phishing-resistant, cryptographic authentication, specifically FIDO, is rapidly emerging as the new baseline for banking security. The momentum behind passkey-based authentication extends well beyond the financial sector. Major technology providers including Microsoft, Google, and Apple have integrated support for passkeys across their platforms, helping accelerate mainstream adoption of FIDO-based authentication standards. The FIDO Alliance has also reported growing industry adoption as organizations seek phishing-resistant alternatives to passwords and traditional multi-factor authentication methods. As passkeys become increasingly familiar to consumers through everyday digital experiences, financial institutions are gaining a clearer pathway to deploying stronger authentication without sacrificing user convenience.


Hyperledger Foundation

Blockchain-Enabled Trust in 6G

The transition from 5G to 6G is way more than a speed upgrade; it is a fundamental architectural shift. Future networks will be highly decentralized and multi-stakeholder, spanning multi-vendor RANs, globally distributed AI, IoT/V2X ecosystems, and edge clouds.

The transition from 5G to 6G is way more than a speed upgrade; it is a fundamental architectural shift. Future networks will be highly decentralized and multi-stakeholder, spanning multi-vendor RANs, globally distributed AI, IoT/V2X ecosystems, and edge clouds.


Origin Trail

Data you own, or data you hand over to AI labs

Every argument about enterprise AI circles back to capability: whose model is smarter, whose benchmark is higher. Even Palantir, the company that best turns messy enterprise data into something a machine can reason over, keeps that intelligence locked on its own infrastructure, under its own terms. That is the wrong place to look. The question nobody asks The question that decide

Every argument about enterprise AI circles back to capability: whose model is smarter, whose benchmark is higher. Even Palantir, the company that best turns messy enterprise data into something a machine can reason over, keeps that intelligence locked on its own infrastructure, under its own terms.

That is the wrong place to look.

The question nobody asks

The question that decides whether AI is worth building on is simpler, and almost nobody asks it out loud. When the system gives you an answer, who ends up owning what it learned to get there?

Watch how the market actually works, and the pattern is hard to miss. You send your data somewhere. You get an answer back. They keep the data, the context, and the patterns drawn out of it. Scale built the labeled data that the models train on.

Microsoft and OpenAI turned that into assistants running on Azure. Oracle sits underneath as the system of record. Different layers, useful work, one thing in common: the intelligence lives on their infrastructure, and walking away is expensive by design.

That is the trade the industry quietly normalized. To get value, you hand over your data. For a while, it felt like a fair price. Agents are the reason it stopped being one.

When you hand over data, what are you giving up?

When you hand over data, you are not just giving up privacy. You are giving up the asset that compounds. Every interaction adds context. Every decision adds precedent. Over time, that accumulated knowledge becomes the most valuable thing your organization produces, the record of how it actually operates and decides. Hand it to a vendor, and you are renting access to your own institutional memory, on a meter someone else controls.

It gets worse because most of that memory is never captured at all. Enterprises are racing to deploy agents on systems built to store objects, not decisions. The reasoning behind them, the exceptions, the precedents, and the why were never written down anywhere. That is the gap agents inherit, and it is the gap we set out to close.

What does it mean to own your data?

With OriginTrail, we first introduced the open source Decentralized Knowledge Graph (DKG) in 2018. The knowledge it holds is cryptographically anchored and owned by the organization that created it, not by the company hosting the software. It is portable across providers. You can run it on your own infrastructure. The reasoning happens on a graph you control, and the context your agents build stays yours.

This is the difference between exporting a copy of your data and never giving it up in the first place. One is a courtesy the vendor can revoke. The other is ownership.

To advance the DKG, the nOS, Trace Labs’ Network Operating System, is built so that when your AI agent makes a decision, the answer to “who owns this” is always you. Every decision becomes a structured, verifiable trace that explains why, not just what. Each trace is enshrined in the DKG: cryptographically anchored, owned by your wallet, verifiable by anyone.

You control that memory across three layers. Working memory stays private to you and your agents. Shared memory opens only to the people and agents you choose. Verifiable memory is cryptographically protected for audit and proof, so anyone who needs to check a decision can do so, without taking your word for it.

And because nothing is solved twice, knowledge compounds. The fiftieth agent starts with everything the first forty-nine already worked out, so the cost curve bends down as you scale instead of up. You can replay any decision, audit it, and prove it to a regulator, without asking permission from the company that sold you the tools.

What are we chasing?

We did not build this to chase AI for its own sake. We built it to chase something that matters more.

Journeys that end safely, where the failing part gets caught before it fails.
Food you can trust, where what is on the label is what is in the package. Medicine where every result traces back to the evidence behind it.
Buildings that stand, with every safety decision on record, long after the cranes are gone.
A world where you can still tell what is real, where fake news and deepfakes meet a record they cannot forge.

None of that runs on a fluent guess. It runs on facts you can follow and objectives that matter outside the model. Take those away, and even the smartest system is just well-spoken. Give an agent traceable facts and real goals on a knowledge graph you own, and it stops performing for you and starts working for you.

The industry has spent a decade insisting that handing over your data is simply the cost of doing business with AI.

It never was.

trace-labs.ai

Data you own, or data you hand over to AI labs was originally published in OriginTrail on Medium, where people are continuing the conversation by highlighting and responding to this story.

Tuesday, 09. June 2026

The Engine Room

Ask Me (Us) Anything: Cybersecurity Edition for Social Justice Organizations

At The Engine Room, we support partners in navigating digital security and responsible data challenges through our Cybersecurity Assessment Tool and Light Touch Support. As part of that work, we’re excited to host our first Ask Me (Us) Anything: Cybersecurity Edition.  The post Ask Me (Us) Anything: Cybersecurity Edition for Social Justice Organizations appeared first on The Engine Room.

At The Engine Room, we support partners in navigating digital security and responsible data challenges through our Cybersecurity Assessment Tool and Light Touch Support. As part of that work, we’re excited to host our first Ask Me (Us) Anything: Cybersecurity Edition. 

The post Ask Me (Us) Anything: Cybersecurity Edition for Social Justice Organizations appeared first on The Engine Room.


Blockchain Commons

Musings of a Trust Architect: On Being the Fifteenth Standard

Often, the first thing that I hear when I describe Gordian Envelope is that we already have too many credential formats. They’re right. We’ve got JWT, SD-JWT, JWE, COSE, mDoc, JSON-LD VCs, AnonCreds, BBS+ presentations, and at least five more depending on which working group is awake this quarter. XKCD 927, “The 15th Standard”, is the obligatory citation, and it lands. So I want to start with the q

Often, the first thing that I hear when I describe Gordian Envelope is that we already have too many credential formats. They’re right. We’ve got JWT, SD-JWT, JWE, COSE, mDoc, JSON-LD VCs, AnonCreds, BBS+ presentations, and at least five more depending on which working group is awake this quarter. XKCD 927, “The 15th Standard”, is the obligatory citation, and it lands. So I want to start with the question I also get asked: why build another one, and why now?

The short answer is that proliferation is not actually the deepest problem (and I say that having spent thirty years architecting trust systems and watching credentials standards evolve to the ones we have today, and having co-authored TLS 1.0). Instead, it’s that most of the existing formats share a small number of design choices that I think are wrong.

As an example, I watched cryptographic agility get oversold in the ’90s, retrofitted with ciphersuite negotiation, exploited through downgrade attacks, and finally walked back in TLS 1.3. That arc isn’t unique to TLS. It shows up everywhere: optionality has long been treated as a design feature rather than a liability. JOSE is the most recent and visible example. The alg header put attackers in the verifier’s seat, and the standard has spent a decade patching around it rather than admitting the choice was wrong. There are any number of situations like this where our design choices were wrong, including not just in-band algorithm negotiation, but also signature over literal bytes rather than over meaning, issuer-controlled disclosure, JSON’s malleability, layer violations, and singular private keys.

I say “wrong” with affection. The JOSE working group built something that shipped, got adopted, and pays a lot of mortgages. That matters. But we should be willing to look at what shipped and say: the optionality is the problem. The bag-of-attributes JSON is the problem. The signature over literal bytes rather than over meaning is the problem. The bolt-on for selective disclosure is the problem. Each of these is a place where the standards bodies did the best they could under the constraints of the moment but they produced something that comes up short when we measure it against the trust properties we actually want for the next decade.

No amount of additional formats sharing these incorrect choices will solve the underlying problems. But a new format with new design choices could.

A New Solution

So that’s “Why build another?” But what about “Why now?” I’ll be transparent about the timing. When JWT and JSON-LD fought it out during the DID 1.0 process (and that fight slowed the standard down by years), I didn’t feel that I could object. Both sides had real problems. I had opinions, but in the old IETF tradition, opinions without shipping code don’t count for much.

Though I didn’t have shipping code, I do now.

Gordian Envelope is my attempt to make different choices at the substrate layer and see what falls out. Whether that justifies the fifteenth standard is a question I’ll come back to at the end.

So: what does Gordian Envelope do differently?

Gordian Envelope is a substrate, not a credential format. It’s dCBOR underneath, structured as semantic triples (subject, predicate, object), with every node carrying a digest and the whole thing forming a Merkle-like tree. A signature commits to the root. Any subtree can be elided (any subject, predicate, object, or assertion) and the signature still verifies. The holder (not the issuer) gets to decide what to reveal. This is the property I want as a human first and an architect second.

Envelope is also radically recursive. Any subject, object, or assertion can itself be an envelope. That recursion is what lets the same substrate carry property graphs, hypergraphs, labeled directed multigraphs, and several other shapes — not by adding modes or options, but because the structure is general enough that those graph models fall out of it. My Lead Researcher, Wolf McNally, and I wrote that up in BCR-2024-006. I want to be precise about what this is and isn’t: it is not cryptographic agility in disguise. There is one encoding, one signature semantics, one elision mechanism. The expressivity lives in the data model, not in protocol switches.

The Advantages of Envelope

I also want to be specific about what Gordian Envelope buys you, because vague privacy claims have done enough damage already.

It buys you canonical encoding. dCBOR has one representation per semantic content. Two parties assembling the same envelope from the same facts produce byte-identical outputs. JSON cannot do this without enormous effort and a lot of footguns. JSON Canonicalization Scheme exists, but ask the people who tried to deploy it how it went. JSON-LD’s situation is worse, and worth naming specifically: to canonicalize the bytes you have to first understand the semantic layer above them. That’s because the RDF Dataset Canonicalization algorithm (URDNA2015 and its successors) requires you to parse the JSON-LD into an RDF graph, resolve the @context, expand IRIs, and canonicalize that, before you can produce a stable byte sequence to sign. That’s a layer violation, or even an inversion! The encoding layer has been made dependent on the meaning layer, and any disagreement at the meaning layer (such as a context that dereferences differently, a blank-node labeling difference, or an unresolvable IRI) breaks the signature. Envelope refuses that dependency. dCBOR canonicalizes at the encoding layer, full stop, and the semantic structure is built on top of bytes that are already stable.

It buys you data minimization that doesn’t depend on the issuer’s foresight. SD-JWT requires the issuer to commit, at issuance time, to a set of disclosable fields. The issuer is deciding, in advance, what you might want to share. With Envelope, the issuer signs everything and walks away. You — the holder — then decide what to reveal at presentation time. That’s closer to what RFC 6973 “Privacy Considerations for Internet Protocols” actually calls for. It’s also closer to how human trust works in the real world, which is the entire premise of progressive trust.

It buys you cryptography that doesn’t negotiate with attackers. The verifier knows what it accepts. The envelope doesn’t tell it. We learned this from TLS. We learned it again from JOSE. I would like us not to have to learn it a third time.

It buys you composable structure. Signatures are assertions. Expiration is an assertion. Audience binding, witness attestation, revocation, and notarization are all assertions. The protocol layer and the application layer share a uniform shape, and you extend the format by adding assertions, not by petitioning a registry for another reserved claim name.

The Challenges for Envelope

Now the honest part.

We made mistakes in the early design. The most public is BLAKE3, which we originally used to produce the hashes that are signed. We picked it because it’s modern and fast. We then discovered that our actual use cases (air-gapped wallets, constrained devices, and hardware seed managers) don’t need BLAKE3’s streaming features and do need SHA-256’s ubiquity. Backing out to use SHA-256 instead cost us code, drafts, docs, and credibility. I wrote about it in “Problems of Cryptographic Agility”. If we’d shipped with cipher-suite agility, we could have just deprecated the algorithm and moved on. We chose not to, and we paid for that choice with a year of cleanup. I still think the choice was right. Optionality is a debt you eventually have to pay.

In addition, adoption is small. Reference implementations are in Rust and Swift. We have a third-party Typescript library, but JavaScript support is overall thin, and the credential world runs on JavaScript whether we like it or not. Meanwhile, our IETF draft for Envelope is still at the “individual-submission” stage. Finally, there’s no IANA registry entry that makes a procurement officer’s life easier. None of this is fixed yet, and I won’t pretend otherwise.

Ultimately, I don’t think Gordian Envelope will replace JWT. JWT will continue being the bearer-token shape for OAuth and OIDC for the foreseeable future, and that’s mostly fine: OIDC is a short-lived-token use case where many of JWT’s worst properties are tolerable. The places I want Envelope to win are the ones where the holder has to live with the document for years. Credentials. Key and seed storage. Capability tokens. Software-release attestations. Healthcare consent. Anything where data minimization and progressive trust matter more than fitting in an HTTP header.

Final Notes

The XKCD punchline is “there are now 15 competing standards.” It doesn’t say one of the fifteen can’t be better than the previous fourteen. It says that adding the fifteenth, framed as unification, is the joke. I don’t frame Envelope as an unification. It’s a substrate that respects principles I’ve spent three decades trying to articulate: human dignity, holder agency, progressive trust, minimum viable architecture. If a better substrate emerges that respects those principles, I’ll migrate to it. The principles are what matter; the format is the carrier.

I’d rather we argue about whether the principles are right than whether we have too many standards. We have too many standards because we keep ducking the harder conversation. Let’s have it.

— with thanks to Wolf McNally, who actually writes the code; to Shannon Appelcline who writes the docs and tests our ideas; to the Decentralized Web community, who pushes back when I’m wrong; and to the dCBOR working group at IETF, who are doing the unglamorous foundational work.

Envelope Intro Videos

See our videos Understanding Envelope Part One and Understanding Envelope Part Two for more on Gordian Envelope

Envelope Structure: Envelope Hashes: Redacted Hashes: Related Reading BCR-2024-006, Envelope as a Universal Graph Substrate — https://github.com/BlockchainCommons/Research/blob/master/papers/bcr-2024-006-envelope-graph.md Problems of Cryptographic Agility — https://www.blockchaincommons.com/musings/musings-agility/ Data Minimization & Selective Disclosure — https://www.blockchaincommons.com/musings/musings-data-minimization/ Progressive Trust — https://www.blockchaincommons.com/musings/musings-progressive-trust/ Progress Trust Life Cycle — https://www.blockchaincommons.com/musings/musings-progressive-trust-lifecycle/ Minimum Viable Architecture — https://www.blockchaincommons.com/musings/musings-mva/ When Technical Standards Meet Geopolitical Reality — https://www.blockchaincommons.com/musings/gdc25/

Sunday, 07. June 2026

GLEIF

Transforming Data into Opportunities: Metric in Motion – How AI Can Strengthen Ownership Transparency

In an increasingly interconnected global economy, the ability for organizations to trust and use data effectively is the foundation for innovation, growth, and competitiveness. A high-quality data ecosystem is a driver of change and innovation that enables organizations to identify and seize new opportunities, while low data quality can lead to inefficiencies and exposure to regulatory and reput

In an increasingly interconnected global economy, the ability for organizations to trust and use data effectively is the foundation for innovation, growth, and competitiveness.

A high-quality data ecosystem is a driver of change and innovation that enables organizations to identify and seize new opportunities, while low data quality can lead to inefficiencies and exposure to regulatory and reputational risks.

To aid broader industry awareness of GLEIF’s data quality initiatives and its application to different sectors, this new blog series explores key metrics included within the reports.

This month’s focus: how AI can strengthen ownership transparency.

As global corporate structures become more complex, access to trusted ownership and relationship data is increasingly important for transparency, accountability, and risk insight. This data, which includes parent and subsidiary relationships, helps organizations assess risk, support compliance and make more informed decisions by showing how legal entities are connected.

Within the Global LEI System, Level 2 data provides this critical context by identifying parent and subsidiary corporate structures, branch-headquarters connections, and fund relationships. Often described as answering the question "who owns whom", Level 2 data helps reveal the structures behind legal entities and strengthens trust across financial and business ecosystems.

Understanding the Value of Level 2 Data in the Global LEI System

A recent survey conducted by the Regulatory Oversight Committee (ROC) and GLEIF highlights the value of Level 2 data. Approximately 70% of respondents reported using Level 2 data, while nearly 85% said they consider it to be quality data. Respondents also confirmed that Level 2 data is already integrated into their organizational decision-making and reported using Level 2 data to support various operational and strategic processes, with many valuing consolidated parent relationships in particular.

These findings highlight a key trend. As demand for reliable ownership information increases, maintaining high-quality relationship data at scale is critical.

AI Opens New Possibilities for Relationship Data Extraction

With artificial intelligence (AI) transforming how organizations manage and analyze data, new opportunities are emerging to meet this need to further enhance the quality, completeness, and reliability of relationship data.

For instance, valuable relationship information is already widely available – but it is often difficult to access because it is buried in annual reports and other corporate disclosures. Parent and subsidiary details may appear in footnotes, tables, notes to financial statements, or narrative sections. These disclosures are often fragmented, inconsistently formatted, and difficult to review manually at scale, making it challenging to integrate them into structured datasets.

AI-driven extraction offers a practical way to unlock this hidden information. By identifying, interpreting, and structuring ownership details from annual reports and other complex PDF documents, AI can help transform unstructured information into structured relationship data. It can also compare information across documents. This can improve the retrieval and validation of Level 2 data, supporting better risk analysis and decision-making and enhancing the overall quality and transparency of the Global LEI System.

In fact, GLEIF is already using AI-based extraction to retrieve the relationship data from annual reports and convert it into structured format. This enables GLEIF to review and confirm existing relationship information in the Global LEI Index, or trigger updates where needed, outside the annual renewal process. As a result, relationship data can be kept more current and trusted over time.

Advances to the Transparency Fabric – a joint initiative introduced by GLEIF, Open Ownership, and OpenSanctions – in 2025 also introduced the use of Large Language Models (LLMs) to extract and analyze information from unstructured documents to better map complex ownership structures and support the linking of LEIs with beneficial ownership and sanctions data.

How It Works

The automated process identifies all subsidiaries of parent companies in an annual report PDF using an LLM multi-step process:

First, the AI reviews the report and identifies possible subsidiaries based on the definitions and examples provided. It then checks its own results to identify potential gaps, missing subsidiaries, or entries that may have been included incorrectly. After this review, the results are refined into a final list in the required format. This includes removing false positives, adding any missed subsidiaries, checking the relevant page references, and standardizing details such as jurisdiction or country information. Finally, the AI-generated list can be compared with a manually extracted list to assess accuracy, completeness, and overall quality.

This demonstrates how AI can help accelerate the extraction of subsidiary data from complex PDF documents. At the same time, combining human oversight remains important to validate the results, improve quality, and ensure the final relationship data is reliable.

Using Trusted LEI Data to Improve AI Itself

While AI can help find and check Level 2 relationship data, trusted LEI data can, in turn, enhance the use of AI methods for this task.

GLEIF has used existing LEI data and annual reports to optimize prompts using the GEPA approach, or Genetic Pareto Reflective Prompt Evolution. Rather than guessing which prompt might perform best, GEPA uses labeled data and human feedback to evolve stronger prompt variants, test them against known examples, and retain the best-performing trade-offs.

This approach shifts AI development from experimentation to measurable improvement. For example, a GEPA-enhanced prompt improved the measurable accuracy of the retrieved relationship information. Even more interestingly, a smaller and cheaper model performed better than a larger and more expensive model after optimization. This demonstrates that high-quality data and structured optimization often matter more than using a larger model. Put simply, better inputs create better outputs.

Combining AI Innovation with Trusted Data Foundations

The most valuable outcome from AI-driven relationship data extraction is the ability to transform fragmented disclosures into reliable, structured, and actionable relationship intelligence – enabling organizations to make more informed decisions across the global economy.

Yet trusted frameworks, governance, and standardized identifiers remain essential for ensuring these insights are reliable and usable. By combining AI innovation with the trusted foundations of the Global LEI System, there is an opportunity to strengthen the quality, coverage, and usability of ownership and relationship data at scale.

Friday, 05. June 2026

FIDO Alliance

ID Tech: RSA Extends Passwordless Authentication to Linux Environments

RSA has extended its passwordless authentication platform to Linux, bringing FIDO-based, phishing-resistant sign-in to Linux servers, developer workstations, and critical infrastructure that have typically relied on passwords and other legacy […]

RSA has extended its passwordless authentication platform to Linux, bringing FIDO-based, phishing-resistant sign-in to Linux servers, developer workstations, and critical infrastructure that have typically relied on passwords and other legacy credentials.

The Linux support extends passwordless capabilities RSA already offers across Windows, macOS, iOS, and Android through its RSA ID Plus identity platform. The approach is built on FIDO standards, in which a user authenticates with a device-bound credential and a local check such as a biometric or PIN, rather than entering a shared secret that can be phished or replayed. Bringing that to Linux closes a gap for organizations that run passwordless on user-facing operating systems but fall back to passwords on the Linux systems that run their server and development environments.

RSA is positioning the capability for high-assurance enterprise and government settings, including financial services, government agencies, and energy-sector infrastructure, and across cloud, on-premises, and hybrid deployments. Linux servers and developer workstations are common in exactly those environments, where they often sit closer to sensitive systems and data than the average corporate laptop, which is the security gap RSA is targeting.

“Passwordless everywhere isn’t a marketing aspiration for RSA, it’s a working architecture,” said Jim Taylor, President and Chief Product and Strategy Officer at RSA. The framing emphasizes coverage across the full operating-system estate rather than passwordless support confined to the platforms where it is easiest to deploy.

The move fits the broader industry push toward phishing-resistant authentication built on the FIDO standards. The FIDO Alliance has reported billions of accounts supporting passkeys as adoption accelerates across consumer and enterprise systems, and hardware vendors have been building FIDO2-certified credentials into smart cards and tokens for logical and physical access. RSA’s contribution targets the server and workstation layer of that transition, where passwordless coverage has lagged the desktop and mobile experience.

RSA presented the Linux capability as part of its passwordless roadmap at the Singapore event, alongside sessions on the user experience of credential rollout across operating systems.


Benchmark: HID adds governance layer to FIDO authenticators with Enterprise Attestation

Passkeys have made real progress in reducing phishing risk, but they do not tell an organisation much about the device being used to create a credential – whether it was […]
Passkeys have made real progress in reducing phishing risk, but they do not tell an organisation much about the device being used to create a credential – whether it was issued by the company, or simply bought independently by an employee and registered without oversight. HID’s Enterprise Attestation, now available across its Crescendo range of FIDO2-certified smart cards and security keys, is designed to close that gap.

The capability, built on the FIDO Alliance’s WebAuthn and CTAP specifications, works at the point of passkey registration. When a device attempts to enrol, the system checks for a certificate that ties it to a known, company-issued authenticator. If that certificate is absent or unrecognised, enrolment is blocked by policy. If it passes, the user sees no change to their login experience – the governance layer operates entirely in the background.

That last point matters. The friction introduced by security controls is a persistent adoption barrier, and one that Enterprise Attestation appears to have deliberately designed around. According to the FIDO Alliance’s own deployment research, strict regulatory requirements are cited by around a fifth of organisations as a significant obstacle to enterprise passkey adoption. Removing the ability to distinguish a company-issued authenticator from a personal one purchased independently by an employee does not help that situation.

Enterprise Attestation is supported by identity platforms including PingOne, and operates within standard FIDO workflows rather than requiring proprietary authentication flows or application changes. For security teams, the result is a verifiable, auditable record of every device granted access at registration – without locking into a non-standard implementation.

The capability is relevant across regulated sectors including financial services, healthcare and critical infrastructure, and aligns with compliance frameworks such as the EU’s NIS2 Directive and DORA, as well as Zero Trust architecture requirements. HID is an active participant in the FIDO Alliance Enterprise Deployment Working Group, which continues to develop the standards underpinning this area.


Project VRM

Digital Omnibus Article 88b needs to be about contract, not just consent

The EU’s new Digital Omnibus proposal aims to update and expand the GDPR, notably with Article 88b, which includes this: A new Article 88b Regulation (EU) 2016/679 (General Data Protection Regulation), for automated and machine-readable indications of individual choices and respect of those indications by website providers once standards are available. That was written in […]

With gratitude to the famous Peanuts cartoon. (And art help from ChatGPT.)

The EU’s new Digital Omnibus proposal aims to update and expand the GDPR, notably with Article 88b, which includes this:

A new Article 88b Regulation (EU) 2016/679 (General Data Protection Regulation), for automated and machine-readable indications of individual choices and respect of those indications by website providers once standards are available.

That was written in June 2025. (I’ve boldfaced the phrases that matter.) We now have a standard for exactly what the EU wants and needs: IEEE 7012-2025—Standard for Machine-Readable Personal Privacy Terms. It is nicknamed MyTerms (much as IEEE 802.11 is nicknamed Wi-Fi) and was published by the IEEE in January 2026 after nine years in the making. Here’s the PDF.

Article 6 of the GDPR lists six bases for the  Lawfulness of Processing:

the data subject has given consent to the processing of his or her personal data for one or more specific purposes; processing is necessary for the performance of a contract to which the data subject is party or in order to take steps at the request of the data subject prior to entering into a contract; processing is necessary for compliance with a legal obligation to which the controller is subject; processing is necessary in order to protect the vital interests of the data subject or of another natural person; processing is necessary for the performance of a task carried out in the public interest or in the exercise of official authority vested in the controller; processing is necessary for the purposes of the legitimate interests pursued by the controller or by a third party, except where such interests are overridden by the interests or fundamental rights and freedoms of the data subject which require protection of personal data, in particular where the data subject is a child.

I’ve boldfaced the three that matter, and italicised their core distinctions.

The entire adtech business relies on the first and last of these, consent and legitimate interests, as their excuses for tracking people, allowing them to obey the letter of the GDPR while screwing its spirit.

We see consent at work with every cookie notice we click on or click past. And we have no faith that clicks on consent “choices” provide any privacy protection at all. Reasons:

Most sites ignore cookie choices. Many sites set cookies even before a cookie choice is made. It’s obvious that adtech is a personalised guesswork business that relies on surveillance, so most of these “choices” are misdirections away from corporate hunger for personal data. We have no record of the “choices” we make (and in many cases, no choice is offered), or any way to audit or dispute compliance. Uninvited and unwanted surveillance is by now so far out of control that cars, TVs, and AI chatbots are all in on the game (and hardly bother with consent notices).

The legitimate interests are advertising and surveillance, which Google, Facebook and the IAB say the world needs, because it funds so much of what happens online.

To the adtech business, personal privacy is a bug, not a feature. The whole business is incentivised to violate privacy, because violating privacy pays. No amount of regulatory oversight will fix that. To adtech, paying fines for privacy violations is just a cost of doing business.

The only fix that will work is what people—customers and citizens—bring to the market’s table. With MyTerms, they can do that.

MyTerms addresses the second of the GDPR’s six legal bases: contract. Put simply, here is what  the MyTerms standard says:

The person (not a mere data subject) is the first party, and the site or service is the second party. The person proffers a contractual agreement chosen from a limited roster posted on the public website of a disinterested nonprofit, such as Customer Commons (which was created to do for personal contracts what Creative Commons does for personal copyrights—and which the IEEE approached with the idea for making MyTerms a standard). When the second party agrees, both parties keep an identical record, which supports compliance auditing and dispute resolution. (By preserving evidence, this also creates an infrastructure for dispute avoidance as well.)

The GDPR succeeded by recognising natural persons as holders of rights, but it left intact the industrial age convention in which organisations are the exclusive originators of terms at scale. That’s one reason why persons have remained mere data subjects rather than contractual parties.

Fortunately, the Internet’s base protocols are peer-to-peer. Treating people on the Net as mere “users” and “data subjects” limits their agency. With MyTerms, people acquire a status they yielded when industry won the industrial revolution. (Before the industrial age, surnames—Baker, Müller, Weaver,  Lefebvre, Smith, Marchand, Farmer—signified agency: what people did in the world. That’s just one thing we lost when we became workers, executives, consumers, and users.)

In the natural world, privacy is maintained mostly by tacit agreements. In the digital world there is no tacit, so agreements must become explicit and programmable. This is why contracts are the only way we’ll get real personal privacy in the digital world.

It should also be clear by now that polite requests also don’t work. We tried that with Do Not Track, and by the time it finished failing, the adtech lobby had turned it into Tracking Preference Expression—as if we wanted to be tracked all along.

That main pro-consent lobby is the Interactive Advertising Bureau, or IAB. Among its recommendations for the Digital Omnibus are deleting 88b and  improving consent in various ways, such as  “Revise the proposed stricter consent rules.”

The IAB is blind to the simple fact that people hate being spied on and do what they can to stop it—mainly by turning off ads. By 2015, ad blocking was already the biggest boycott in human history. That boycott rose in direct response to obvious tracking, especially with retargeting. (That’s how one ad or advertiser keeps following you from site to site and app to app.)  And the boycott is much bigger now:

By Q2 2023, there were 912M active ad-blocking users worldwide, up 11% from Q4 2021. (Source: e/yeo, with more here)  1.77 billion people worldwide were blocking ads by Q2 of 2026. (Source: Backlinko, citing DataReportal and e/yeo). Privacy-focused browsers (like Brave, Safari, and Firefox) automatically block advertising elements and behavioural tracking scripts by default. This is in clear response to market demand.

The IAB earned all of that. Yet they still see ad blocking and tracking protection as problems to solve rather than clear and constructive signals from the marketplace.

So it should be clear by now that the old brownfield of consent has become a toxic wasteland of surveillance, lost privacy, and minimised human agency—led by an industry that has been hostile to privacy from the start.

In fact, consent is required for what Shoshana Zuboff calls Surveillance Capitalism. That form of capitalism is based on inferred or extracted consent. The only way we can defeat that regime is by re-basing e-commerce on contractual agreements in which customers take the lead. After all, it’s their privacy that needs protection.

The surveillance economy is limited entirely by its methods, which are built around grabbing attention, harvesting data, and guessing at people.

We can replace it with an intention economy that’s based on what customers actually want. The range of those wants far exceeds what companies and their systems can guess at. Far more business, and business improvement, opens up when market intelligence can flow both ways. In the consent/surveillance regime, it can’t, because all relationships are silo’d in sellers’ separate systems, all built to minimize customer interactions, by design. But relationships built on respectful contractual agreements can be far more capacious when those relationships start with forms of mutual trust that whole markets share. That’s what MyTerms makes possible.

Here is a quick outline of some additional benefits.

For customers, the most obvious one is getting rid of cookie notices, which are annoying and not worth the pixels they are printed on.  If a company really does care about personal privacy, it’ll respect personal privacy requirements. This is how things work in the natural world, where tracking people like marked animals has been morally wrong for millennia. In the digital world, however, agreements need to be explicit, so programming and services can be based on them. MyTerms does that.

For business, MyTerms has lots of advantages:

Reduced or eliminated compliance risk Competitive differentiation Lower customer churn A basis for real rather than coerced relationships A basis for better signalling in both directions Reduced or eliminated guesswork about what customers want, how they use products and services, and  how both might be improved

Lawyers get a new market for services on both the buy and sell sides of the marketplace. Companies in the CMP (consent management platform) business (e.g. Admiral and OneTrust) have something new and better to sell to enterprises (and perhaps to people as well).

Lawmakers and Regulators can start looking at the Internet and the Web as places where freedom of contract prevails, and contracts of adhesion (such as what you “agree” to with cookie notices) are obsolete.

Developers can have a field day (or decade). Look for these categories to emerge

Agreement Management Platforms — an evolutionary step forward from consent management platforms. Customer Relationship Management (CRM) – Make its middle name finally mean something. Customer Data Return (CDR) – Give, sell back, or share with customers the data you’ve been gathering without their permission since forever. Talking here to car companies, TV makers, app makers, and every other technology product with spyware onboard for reporting personal activity to parties unknown. Vendor Relationship Management (VRM) Tools and services — a customer hand for CRM to shake. Platform Relief –  Free customers from the walled gardens of Apple, Microsoft, Amazon, and every other maker of hardware and software that currently bears the full burden of providing personal privacy to customers and users. Those companies can also embrace and help implement MyTerms for both sides of the marketplace. Personal AI (pAI)– Till and plant a vast new greenfield for countless companies, old and new. This includes Apple (which can make Apple Intelligence truly “AI for the rest of us” rather than Siri in AI drag), Mozilla (with its Business Accelerator for personal AI) , Kwaai (for open source personal AI), and everyone else who wants to jump on the train. Big meshes of agents, such as what these developers are all working on.

In the marketplace, we can start to see all these things:

VRM + CRM will flourish, as described by Iain Henderson (one of MyTerms’ authors) in Towards Network-Based Ecosystems. We should expect improvements to digital public infrastructure, as relationships move out of Big Tech’s silos and into distributed relationship frameworks based on the Internet’s base peer-to-peer protocols. Predictions I made in The Intention Economy: When Customers Take Charge (Harvard Business Review Press, 2012) and Tim Berners-Lee made in the Attention vs. Intention chapter of This Is for Everyone: The Unfinished Story of the World Wide Web (Farrar, Straus and Giroux, 2025) will finally come true. There will be new dances between customers and companies. (“The Dance” is a closing chapter of The Intention Economy.) New commercial ecosystems can grow around a richer flow of useful information in both directions, based on shared interest and trust between customers and companies. Surveillance capitalism will be obsolesced — and replaced by an economy aligned with personal agency and mutual respect from contractual partners.

And much more.

So it would be helpful for the European Commission to expand its scope from protecting data subjects to empowering first parties. They can do that by welcoming MyTerms in the Omnibus Directive, expanding human agency into a new greenfield where boundless positive outcomes can flourish.

Drafts of myterms agreements are currently posted at MyTerms.info, which is a project of Customer Commons and MyData Global. You can also read more about MyTerms in writings by Iain Henderson, Nitin Badjatia, and me.

We also invite you to join the ProjectVRM list, where we can converse and collaborate on moving MyTerms forward.

Thursday, 04. June 2026

Hyperledger Foundation

Protocol Neutrality: An Imperative for Institutional Adoption and Scale of Digital Assets

As digital assets move from pilots to production, institutions around the globe are asking a different set of questions than they were just a few years ago.

As digital assets move from pilots to production, institutions around the globe are asking a different set of questions than they were just a few years ago.

Wednesday, 03. June 2026

Next Level Supply Chain Podcast with GS1

Preventing Loss and Driving Revenue with Operational Analytics

Data might be abundant, but turning it into actionable insights is far more complex than it seems. In this episode, Reid Jackson and Liz Sertl chat with Russ Hawkins, President and CEO of Agilence Inc., about how retailers, restaurants, and hotels are using operational analytics to improve revenue, control costs, and maintain compliance. Russ discusses how organizations can leverage real-

Data might be abundant, but turning it into actionable insights is far more complex than it seems.

In this episode, Reid Jackson and Liz Sertl chat with Russ Hawkins, President and CEO of Agilence Inc., about how retailers, restaurants, and hotels are using operational analytics to improve revenue, control costs, and maintain compliance.

Russ discusses how organizations can leverage real-time data to drive smarter decisions in areas like loss prevention, inventory oversight, and sales growth, all while enhancing the customer experience. He also explores the complexities of ensuring that store managers and frontline teams are aligned with broader company goals, emphasizing that success comes from balancing people, processes, and technology.

This is more than just a tech upgrade. It's a continuous operational effort that relies on collaboration across leadership, operations, and analytics to deliver tangible results and lasting business impact.

In this episode, you'll learn:

How companies use data to increase revenue, manage expenses, and maintain compliance The importance of aligning internal teams and frontline staff with corporate objectives How emerging technologies like AI and RFID are shaping analytics and operational efficiency

Things to listen for: (00:00) Introducing Next Level Supply Chain (01:38) Russ's background: from telecom to three CEO roles (06:34) The three things every retailer is really trying to solve with data (09:10) What internal compliance actually means (09:51) Make money, save money, be compliant (16:33) Using data to know who's upselling and who's leaving money on the table (19:37) The treasure trove already in your transaction logs (25:51) Getting the right product in the right place (30:18) Operations is a people problem (34:37) Where analytics investments go wrong (38:15) AI is exciting and terrifying in equal measure (40:59) What Russ wants to learn next

Connect with GS1 US: Our website - www.gs1us.orgGS1 US on LinkedIn Register for GS1 Connect 2026, happening June 9 to 11 in Las Vegas, and get 10% off with the promo code GS1USPOD10 at connect.gs1us.org.

Connect with the guest:Russ Hawkins on LinkedInVisit Agilence Inc. at https://www.agilenceinc.com/

Tuesday, 02. June 2026

Oasis Open

NIEM Goes Global: NIEMOpen Submits to ISO/IEC JTC 1

By Paul Wormeli, Chair, NIEMOpen Project Governing Board OASIS Open has formally submitted two NIEMOpen standards to ISO/IEC Joint Technical Committee 1 (JTC 1) for transposition into International Standards. The two submissions are NIEM Model v6.0 and the Naming and Design Rules (NDR) v6.0, both approved as OASIS Standards in December 2025. This is a significant moment. […] The post N

By Paul Wormeli, Chair, NIEMOpen Project Governing Board

OASIS Open has formally submitted two NIEMOpen standards to ISO/IEC Joint Technical Committee 1 (JTC 1) for transposition into International Standards. The two submissions are NIEM Model v6.0 and the Naming and Design Rules (NDR) v6.0, both approved as OASIS Standards in December 2025.

This is a significant moment. NIEM has been in production use for more than 20 years, serving justice, law enforcement, emergency management, public safety, border security, and a growing list of other domains. Submitting to JTC 1 is about making that reach official at the international level.

What Is the JTC 1 PAS Process?

ISO/IEC JTC 1’s Publicly Available Specification (PAS) transposition process allows an approved external organization to submit an existing specification for ballot and potential adoption as a globally recognized ISO/IEC International Standard. OASIS has been a recognized PAS submitter since 2004, and this submission builds on that longstanding relationship.

OASIS has a long history of active engagement within the JTC 1 ecosystem, holding Category A liaison status with subcommittees including SC 34 (Document Description and Processing Languages), through which standards like OpenDocument and DITA were developed, and SC 40 (IT Service Management and IT Governance). This submission also opens the door to collaborative engagement with JTC 1/SC 32 (Data Management and Interchange), which develops standards for metadata registries, data interchange formats, and interoperability frameworks. The thematic overlap with NIEM’s core mission is strong, and we see this submission as a natural catalyst for building that relationship.

Why This Matters for NIEM

NIEM was built to solve a real problem: after September 11, 2001, it became clear that U.S. agencies could not share critical information quickly or reliably because their data meant different things to different systems. NIEM gave agencies a common vocabulary, a set of design rules, and a methodology for building information exchanges that could actually interoperate.

That problem is not unique to the United States. Governments and agencies around the world face the same challenge. NIEM has already seen international adoption, including partnerships with Canada and allied nations, and use cases spanning international trade and border management. Becoming an ISO/IEC International Standard would recognize that reality and make it easier for international partners to adopt and build on NIEM with the full backing of an internationally recognized standards body.

What We Are Submitting

The submission covers two interdependent standards that together form a complete specification suite.

NIEM Model v6.0 defines the core data model and domain-specific content components, providing the common semantic foundation for information exchanges. It includes more than 20,000 harmonized data elements across 19 domains.

NDR v6.0 defines the conformance rules, design patterns, and syntactic constraints for building NIEM-conformant schemas and exchange specifications. Think of the Model as the vocabulary and the NDR as the grammar.

Version 6 is a significant step forward for the framework. It introduces a technology-agnostic Common Model Format (CMF) that decouples NIEM from any single serialization or schema language, enabling implementation across XML, JSON, RDF, and other representations. That flexibility is what makes v6.0 genuinely AI-ready, because it allows NIEM’s semantically coherent data to flow into modern data environments without losing the precision and interoperability the framework is known for.

What Happens Next

The submission now goes to a ballot among JTC 1 National Bodies. OASIS has requested to be named the maintenance organization for the resulting International Standards, and NIEMOpen will bring future major versions back to JTC 1 for re-transposition. The OASIS and JTC 1 versions of any given NIEM release will be identical in all substantive and technical respects.

A Note of Thanks

This milestone reflects years of work by the NIEMOpen community: the technical contributors, federal agency partners, domain stewards, and private sector organizations who have built NIEM into what it is today. The U.S. Departments of Justice and Homeland Security provided successful implementation statements that were part of the submission package, continuing a partnership that stretches back to NIEM’s founding.

NIEM has always been a community effort. Taking it to the international stage is the logical next step, and I am proud that the NIEMOpen Project Governing Board is here to see it happen.

For more information about NIEMOpen, visit niemopen.org.

The post NIEM Goes Global: NIEMOpen Submits to ISO/IEC JTC 1 appeared first on OASIS Open.


Blockchain Commons

Amira Progress Report (2026)

Amira is a use case for pseudonymous identity that has grown over time, and today is available as a fully featured demo, showing the power of what was imagined almost a decade ago. If you’re already familiar with the Amira use case, you’ll be most interested in how we’ve made Amira a reality with XIDs. Jump to that! Original Issue (January 2017) The Amira use case (originally an “Alice” use case) w

Amira is a use case for pseudonymous identity that has grown over time, and today is available as a fully featured demo, showing the power of what was imagined almost a decade ago.

If you’re already familiar with the Amira use case, you’ll be most interested in how we’ve made Amira a reality with XIDs. Jump to that!

Original Issue (January 2017)

The Amira use case (originally an “Alice” use case) was first presented on January 12, 2017 by Christopher Allen as an issue on the W3C vc-use-cases repo. The crux of the use case was:

“she wishes to take a more active role in making a better world. However, she knows if she stands out from the crowd that any activism she may get involved in may not only affect her, they may affect her parents or even her extended family abroad.”

As a use case for verifiable claims (verifiable credentials), it had a few major parts:

Amira wants to privately contribute to a software project. Amira anonymously provides reputational information. Amira is able to increase her anonymous reptuation over time. Amira is able to selectively revoke parts of her anonymity in the future. RWOT 5 Advanced Reading (July 2017)

Christopher Allen revised the original use case as an advance reading for Rebooting the Web of Trust 5 in Boston. One of the most important revisions in the advance reading was that it recognized Amira’s story as being about “pseudonymous identity” and linked it to the DID standard then being worked on at the RWOT workshops.

The concept of pseudonymous identity is crucial because it provides a container for Amira’s anonymous reputational information: an alternate identity that is stable and consistent and that can accrue credentials over time, eventually bootstrapping into an identity that might be as trusted and respected as any real-life, non-pseudonymous identity.

The advanced reading also provided the first technical details suggesting that the Amira use case soon become a reality, using current near-future technology. That included DIDs (still in process at the time, since they weren’t published until 2022) and multisigs.

Amira 1.0.0 White Paper (July 2018)

Amira became a group project in October 2017 at RWOT5 in Boston and then was finalized and polished over the next nine months, ultimately resulting in a more complete white paper. The white paper used Joe Andrieu and Ian Henderson’s “information lifecycle engagement model” to lay out a 15-step model for using the imagined pseudonymous identity:

Pre-Contact. Amira wants to support a women’s crisis program run by Ben, but fears doing so will affect her job. Contact. Amira’s friend, Charlene, verifies that she can contact Ben on the pseudonymous RISK network. Triage. Charlene talks with Amira about the RISK network and verifies it meets her needs. Direction. Charlene explains RISK to Amira and sets up a secret contact phrase with her to verify identity. Consent. Amira creates a pseudonymous identity on RISK and signs their code of conduct with her new identifier. Configure. Amira sets up a DID on RISK and confirms it with Charlene using their contact phrase. Services. Amira writes a self-attestation and gets it endorsed by Charlene, who then introduces her to Ben. After discussions, Ben writes a contract for Amira to work on SisterSpaces, and begins paying her in Bitcoin as she completes milestones. Enhancements. Amira adds her pseudonymous identity to a developer directory on RISK. Updates. Amira buys a hardware wallet, replaces her old credentials with new ones generated by the wallet, and publishes them. Problems/Issues. Amira’s credentials are compromised, leading her to create a new DID. Maintenance. Amira downloads a new version of RISK that allows her to publish endorsements. Migration. Amira migrates her identity to CommonX, receiving new countersigned attestations as she does. Recovery. Amira gets new endorsements for her replacement DID. Exit. Amira hands off maintenance on SisterSpaces to another developer and removes her public posting of endorsements. Re-Engagement. Amira re-activates her public posting of endorsements. W3C Amira (July 2019)

As part of the work on the DID standard, Amira was also released through the W3C as a Draft Community Group Report. It’s substantially identical to the 2018 paper.

XID Amira Demo (May 2026)

Five years later, Blockchain Commons was able to start making Amira a reality with XIDs, a capstone technology that uses Gordian fundamentals such as Gordian Envelope to create a truly self-sovereign identifier.

XIDs take a step beyond W3C DIDs, which ended up compromised in ways that took away from the holder control. Some of these flaws were old enough that they showed up in the Amira white paper, but we didn’t have proper alternatives at the time, so the problems made their way into the standard. It was only when we finished work on the lower levels of the Blockchain Commons stack in 2024 and advanced to XIDs that we were finally able to demonstrate the practicality of our true intentions for self-sovereign identity; we hope to see those intentions in future iterations of the standard.

Our newest version of the Amira story therefore demonstrates not just the ideas of pseudonmyous identity that Christopher first imagined back in 2017, but also how they can apply to true self-sovereignty.

Amira 1.0.0 Requirements

Amira was always intended as a use case that could lay out requirements that would define real-world usage of pseudonymous identity. Here’s a run-down of some of the most important requirements identified in the Amira 1.0.0 white paper, referenced with the step numbers in the engagement model.

Pseudonymity. Create an identity that’s not tied to a real-world identity, but that nonetheless is stable [#5]. Signing. Sign with your identity [#5, #7]. Attestations. Write attestations linked to your identity [#7]. Endorsements. Sign attestations made by yourself or others [#7]. Rotation. Rotate your keys without losing your identity [#9]. Publication. Broadcast attestations and endorsements [#11]. Exit & Return. Choose to exit or return to your identifier [#15].

There are a few other requirements in Amira related to Portability [#12] and Recovery [#13] which are vitally important parts of a pseudonymous identity ecosystem, but which don’t provide sufficient continuity of identity in Amira 1.0.0, so we instead cover them, along with other advancements, in the next section.

Amira 2.0.0 Requirements

Amira was written very early in our march toward self-sovereign identity: five years before DIDs were locked down as a standard. Even then, DIDs ended up less holder-controlled (and so less self-sovereign) than we hoped.

What follows are some improvements to the original Amira requirements that make them more self-sovereign, more private, and more stable.

Decentralization. Control your self-sovereign identity [updating #5]. The original engagement model focused on an imaginary network called RISK, but in doing so it took some agency from Amira. In the model, her DID is something she creates within RISK. Instead, she should be able to create and control her self-sovereign identity herself, just lending its use to a network like RISK (if something like that is even necessary), while she remains the Principal Authority. Bootstrapping. Build your identity through progressive trust [expanding #7]. A lot of the interesting work in Amira occurs in a single step of the engagement model, #7 (Services). We really need more details there, as Amira needs to figure out how to bootstrap her empty pseudonymous identifier into a trusted identity. This can be done through offering proof of existing work, receiving multiple endorsements, and slowly creating trust through progressive steps. Recovery. Recover your identity without loss after compromise [updating #10]. Fundamentally, if the underlying key for an identity is compromised, you’re going to lose the identity, as happens in Amira 1.0.0. She has to create a new identity and get it re-endorsed after an attack. However, there are ways to lessen the likelihood of that happening, through hetergenous division of keys: keeping more-powerful identity management keys offline while using less-powerful operational keys on a day-to-day basis. In this situation, it’s the operational key that’s most likely to be compromised, and it can be replaced without having to reset the identity as happens in the Amira engagement model. Portability. Move your identity without loss [updating #12]. It’s a bit painful seeing Amira have to recreate her identity when she moves from RISK to CommonX. Though she “cryptographically links” the profiles, she still has to seek out new endorsements, which shouldn’t be required under the “Portability” principle of self-sovereign identity. If Amira is truly in *Control* of her identity (per above), then all she has to do is publish her identity on a new service or link it to a profile on the new service. She doesn’t cryptographically “link” to the old profile, she just cryptographically proves possession by signing with a private key. Afterward, she shouldn’t need new endorsements, because they’re all linked to the portable identity. Disclosure [expanding #7]. Selectively determine what information to release. The Amira use case doesn’t focus much on how Amira releases the information in her pseudonymous identity. As a result, it misses out on the ideas of selective disclosure and data minimization: she should be able to release as little about her identity as she wants at any time. Learning XIDs

XIDs were created to demonstarte a new, truly self-sovereign version of decentralized identifiers that did away with many of the compromises that had crept into DIDs, among them: the theft of agency from the holder; the disambiguation of a DID and its data; the lack of strong support for selective disclosure; and the ability for DIDs to “phone home”. Instead, XIDs are imagined as “autonomous cryptographic objects”, created by holders, modified by holders, and wholly self-contained and self-sufficient.

However, XIDs were also created to fulfill the requirements of both Amira 1.0.0 and the expanded requirements that we’ve laid out to make Amira more self-sovereign and stable. The Learning XIDs project, which is essentially fourth iteration of the Amira Use Case following the issue, advanced reading, and white paper, does so as part of a tutorial on how XIDs work. It does so by offering a real-world demo of Amira’s creation and use of a decentralized identifier that works today, fulfilling almost a decade worth of thought leading up to this point.

Here are some of the main points found in Learning XIDs and how they relate to the Amira requirements to date:

Decentralization. §1.1. XIDs are built as autonomous cryptographic objects that are self-contained. Control. §1.3. Amira creates her XID on her own and so has complete control of it using her “inception key.” Pseudonymity. §1.3. A XID is defined by a unique numerical identifier (which is controlled by the inception key) and can also have a nickname. None of these are related to Amira’s real name. Signing. §1.3. Amira signs her XID with her inception key. §2.1. Amira makes an attestation key, registers it in her XID, and uses it to sign attestations. §4.1. Amira makes a contract key, registers it in her XID, and uses it to sign contracts. Publication. §1.4. Amira publishes her XID to GitHub. §2.2. Amira publishes commits of detached attestations. §4.2. Ben publishes commits of contracts. Portability. §1.4. Amira could choose to publish her XID to a different site. Provenance marks would show which publication was the most up-to-date. Attestations. §2.1. Amira creates detached attestations. §2.2. Amira elides and commits to detached attestations. §2.3. Amira encrypts detached attestations. §3.1. Amira creates embedded attestations (in her XID). Endorsements. §3.3. Amira receives peer endorsements. Bootstrapping. §2.2. Amira uses commitments to build trust over time. §3.2. Amira creates verifiable self-attestations. Disclosure. §4.3. Amira chooses what to reveal in views of her XID. §4.4. Amira removes overly identifying information. Rotation. §5.2. Amira rotates a laptop key. Recovery. §5.5. Amira rotates keys and disavows endorsements after a compromise, but keeps her identity. Exit & Return. §1.1. Amira could choose to stop or restart use of her XID at any time since it’s an autonomous cryptographic object.

We suggest reading through the entire tutorial and playing through it at bcts.dev, but the above links highlight the requirements derived from the Amira use case.

What’s Next?

Are there requirements we’re still missing for self-sovereign identity? Let us know for possible integration into a future iteration of Amira.

Monday, 01. June 2026

GLEIF

Unlocking the Full Potential of European Business Wallets with the LEI

The European Commission intends for the European Business Wallet (EBW) to become a foundational component of Europe’s digital economy and a springboard for its growth from 2028 onwards. This is when EU-wide adoption is expected to begin. The EBW is a core element of the Commission's digital package, announced in December 2025, which aims to help EU businesses spend less time on administrative w

The European Commission intends for the European Business Wallet (EBW) to become a foundational component of Europe’s digital economy and a springboard for its growth from 2028 onwards. This is when EU-wide adoption is expected to begin.

The EBW is a core element of the Commission's digital package, announced in December 2025, which aims to help EU businesses spend less time on administrative work and compliance and more time innovating and scaling up. The EBW is a 'harmonized digital solution' that will offer companies a single digital identity to simplify paperwork and make it much easier to do business across EU Member States.

Businesses that use the wallet will be able to digitize many operations and transactions currently conducted manually. The following actions can be conducted digitally, with full legal effect across all 27 EU Member States:

Counterparty identity can be checked, and one's own identity can be proved instantly. Trusted documents can be created, stored, and shared in real time, such as verified licenses, permits, certificates, and more; Documents can be digitally signed, timestamped, or sealed; Delegations can be made so others can act on a company's behalf in a legal capacity; Communication can take place with other businesses or public administrations via a secure and efficient channel.

Yet while public-sector bodies will be legally required to accept EBW-based identities under the EUDI Framework, private-sector adoption of the EBW will be driven by measurable operational efficiencies.

For this reason, the EBW must demonstrate tangible value to businesses if it’s to be successful.

On the surface, it might be challenging to understand how the EBW could offer only limited value. After all, it's easy to see the enormous potential for cost and time savings in enabling automated, secure, and scalable business processes across EU borders.

Yet for corporate treasurers and financial institutions in particular, there is a separate critical function that the EBW must fulfill if it is to become an essential identity tool in facilitating their day-to-day operations and obligations. As a central component of Europe's new trust services framework, EBWs must allow them to connect the identity compliance 'dots' - across eIDAS, EU, and global financial services regulation. And with the LEI permanently embedded in EU and global financial services regulation as an obligatory compliance layer for entities wishing to engage in or facilitate financial transactions, the LEI's presence as an identity attribute within the EBW is essential. The LEI is central to creating wallet-based value for European corporate treasurers and financial institutions.

The LEI must be a mandatory additional attribute within EBWs

Within the EUDI framework architecture, the LEI is recognized as an entity identifier that may be included in Legal Person Identification Data (LPID). However, its optional status does not guarantee its inclusion in EBWs. This decision will be made by EU Member States as they develop their national wallets.

So, what is the importance of ensuring the LEI is a mandatory additional attribute within EBWs?

Corporate treasurers and financial institutions should be aware of the following benefits that only the LEI can deliver within this context:

Compliance with EU and global financial services regulation
The LEI is an established pillar of trust within financial services. EU authorities and financial supervisors worldwide have integrated it into their financial services regulation to ensure safe, transparent, and well-functioning financial marketplaces. It is also a tool to monitor systemic risk, which can inform decisive action to prevent market-related crises. It links organizations to an open, verified, and high-quality reference data set, supporting transparency across financial ecosystems. Importantly, the LEI is not limited to a European context. It is recognized and referenced by regulators and authorities across jurisdictions worldwide, making it uniquely positioned to support cross-border digital business.

By acting as a digital compliance layer within the EBW, the LEI can elevate the wallet’s value as an essential identity tool for corporate treasurers and financial institutions. It helps connect the compliance dots across onboarding, payments, capital markets, transaction reporting, and anti-money laundering requirements, not just in the EU but on a global stage too.

Onboarding efficiencies
Traditional onboarding and KYC processes still rely heavily on manual verification, causing delays, operational friction, and duplication. Embedding the LEI in an EBW credential enables automatic extraction of verified entity data and access to continuously updated reference information through the Global LEI Index. This shifts onboarding from fragmented document exchange to a reusable digital trust model. Organizations can rely on a consistent, interoperable identity layer instead of repeatedly verifying the same company information across systems and counterparties.

Enhanced downstream financial transactions
The benefits of embedding LEIs within EBW credentials extend well beyond compliance and onboarding. The presence of the LEI can help reduce fraud in payment verification, enable automated reporting to market infrastructures, and streamline eInvoicing workflows. Instead of fragmented identity verification across separate systems, organizations can rely on a universal, reusable, and interoperable trust mechanism. This becomes increasingly important as digital business ecosystems grow more interconnected, and a trust infrastructure is needed to operate seamlessly across borders and industries.

Future-proofing the EBW
Embedding the LEI within EBWs also future-proofs the wallet for emerging digital use cases. LEIs stored within EBWs can support the automated generation of verifiable LEI (vLEI) credentials, enabling stronger cross-border interoperability and higher-assurance digital interactions. This is particularly relevant for areas such as digital assets, supply chain ecosystems, and automated B2B transactions, where trusted organizational identity is essential for reducing risk and enabling scalable automation.

As Europe advances its digital identity and trust services framework, technical decisions being made today will shape how effectively businesses can operate tomorrow. For corporate treasurers and financial institutions, the message is clear: the EBW will deliver its greatest value when it reflects the identity and compliance needs of the sectors that will use it. Embedding the LEI within EBW credentials is not just a technical design choice. It is central to making the wallet useful for real-world business interactions. Businesses preparing for the EBW should ensure the LEI is included in their digital identity strategy.

Friday, 29. May 2026

FIDO Alliance

CISO Tradecraft® Podcast: Passwordless Authentication

In this discussion, G. Mark Hardy and Nishant Kaushik explore the necessity of moving beyond traditional passwords, which they define as the original sin of cybersecurity due to their vulnerability […]

In this discussion, G. Mark Hardy and Nishant Kaushik explore the necessity of moving beyond traditional passwords, which they define as the original sin of cybersecurity due to their vulnerability to credential stuffing and phishing attacks. Kaushik explains that the FIDO Alliance promotes a passwordless future by replacing shared secrets with asymmetric cryptography, utilizing private keys stored on smartphones or hardware tokens like YubiKeys to ensure phishing-resistant authentication. The conversation highlights that identity is the new perimeter, shifting the focus from human-memorized codes to biometric verification and device-bound passkeys that verify user presence. Ultimately, the experts warn that a secure transition must include robust account recovery flows, as failing to secure the “back door” renders even the most advanced cryptographic-based authentication vulnerable to exploitation.


Semperis: Enforcing Phishing-Resistant Authentication at Scale with Passkeys

Corporate Overview Semperis is an identity security company founded in 2013 and headquartered in Hoboken, New Jersey, with approximately 600 employees across North America, Europe, APAC and Israel. The company’s […]
Corporate Overview

Semperis is an identity security company founded in 2013 and headquartered in Hoboken, New Jersey, with approximately 600 employees across North America, Europe, APAC and Israel. The company’s platform protects Active Directory, Okta and Entra ID environments for government agencies and Fortune 2000 enterprises, covering threat detection, incident response and directory recovery.

The Challenge

As a cybersecurity company serving government agencies and Fortune 2000 enterprises, Semperis understands what a credential-based attack looks like. Like many, the company has seen phishing attempts against its own employees, and realized that its authentication environment left a path open for exactly that kind of attack.

Before committing to passkeys, Semperis employees could choose from several authentication methods depending on their device, and nothing in policy forced them toward the strongest one. Windows devices used Windows Hello for Business. Mac users authenticated through platform SSO connected to Entra. Mobile users authenticated via Microsoft’s passwordless push notifications, the number-matching variant that is convenient but not phishing-resistant. When any of those methods were inconvenient, employees could fall back to username, password and OTP.

Conditional access in Entra nudged users toward stronger methods, but nothing prevented someone from clicking “sign in another way” and choosing something weaker. 

Semperis always required some form of MFA, but the weakest permitted path was still vulnerable to adversary-in-the-middle attacks. For a company whose business is identity security, that gap was increasingly hard to justify.

“We’re a prime target for attacks,” said Eric Woodruff, Chief Identity Architect at Semperis. 

Why Passkeys

As the company was looking to reduce its own potential attack surface, it looked to a better form of phishing resistant strong authentication: passkeys.

Semperis was already building incident response products that required passkeys as the authentication method, on the basis that secure operations demand phishing-resistant credentials. As this progressed, on the operations side Semperis reflected on its own desires to enforce passkeys for the workforce, and shifted priority to realize this goal.

Passkey technology has matured significantly, making it a viable option for Semperis. Device-bound passkeys had become a reliable option within the Microsoft ecosystem, which is where Semperis runs its identity infrastructure. The company did not evaluate third-party identity providers; staying within Entra was a deliberate decision. When the technology reached a workable state, the timing aligned with leadership’s appetite to act.

Implementation

Semperis built its passkey deployment entirely within Microsoft Entra, with no third-party identity providers in scope. The resulting architecture is tiered by user type:

General workforce. Device-bound passkeys were enforced through conditional access policies in Entra for all users, with guest accounts excluded because Entra does not currently support passkey enrollment for guests. Windows users continued using Windows Hello for Business, which delivers equivalent native phishing-resistant authentication on Windows. Mac users remained on Mac Platform SSO, which similarly provides native phishing-resistant authentication on macOS. In addition, Semperis made FIDO-certified hardware security keys available to any employee who requested one, and a small number of employees chose to use them.

Privileged users. Device-bound passkeys enforced through conditional access, mirroring the general workforce policy with one key difference: Temporary Access Pass (TAP) is not permitted for privileged accounts. This includes account recovery scenarios, where TAP is otherwise allowed for general workforce users.

Super-privileged and break-glass accounts. Passkeys bound specifically to FIDO-certified hardware security keys. Privileged users may also authenticate with Windows Hello for Business from a Privileged Access Workstation, with a FIDO2 security key as a backup method.

Understanding synced vs bound passkeys

Synced passkey: stored securely in a credential manager and accessed across devices (mobile phones, tablets, and computers) Device-bound passkey: bound to and used only on a single device (such as a security key or mobile app)

Learn more at passkeycentral.org [https://www.passkeycentral.org/introduction-to-passkeys/passkey-types]

Deployment

IT and cloud platform teams adopted passkeys first, giving the teams time to build documentation, surface edge cases and develop a process before expanding to less technical groups.

Enrollment happened live. The implementation team joined existing team meetings, asked for five to ten minutes, walked attendees through setup and had them enroll on the spot. The team also used a targeted adoption strategy to focus on departments and teams with slower uptake. Once a group reached strong adoption, remaining team members were more likely to follow, so the implementation team created a simple near-real-time BI report to monitor adoption and identify where additional outreach would have the greatest impact.

Groups initially received two weeks’ notice before enforcement. That window shortened to one week as confidence grew, and by the end some groups enrolled and were enforced the same day. Email communication was less effective than desired; a campaign on Teams with built-in deadlines would have driven enrollment more effectively, but the idea surfaced too late to be worth building.

Edge cases. Although most use cases were straightforward, two categories required exceptions.

Older Android devices. A subset of employees was running Android 13, which does not support device-bound passkeys. Those users were removed from enforcement temporarily while management worked out a path forward. Initial plans were to keep an enforcement exclusion, but the release of synced passkeys in Entra ID enabled Semperis to enforce passkey use for these users by leveraging their ability to use a synced passkey with Google Password Manager. Unsupported mobile applications. Four applications used authentication flows that bypassed the native browser libraries Microsoft requires for passkey support. Those applications received conditional access exceptions for passwordless push notifications instead. Users of those apps occasionally got caught in what the team called “the doom loop”: Entra prompted for a method that failed conditional access, redirected the user to a registration page, confirmed completion, then sent them back to authenticate again. The cycle repeated indefinitely until the team added an application-level exclusion. Semperis continues to monitor vendor passkey support and removes exceptions as applications add support. One widely used mobile app made that shift in the months following the rollout. The Human Factor


The complexity of Semperis’s rollout was almost entirely behavioral, not technical.

Two questions came up repeatedly: whether enrolling a passkey meant giving Semperis access to employee biometric data, and whether adding a passkey to the Microsoft Authenticator app on a  personal device would give the company visibility into the phone. The second concern was notable given that employees already had the Authenticator app installed on those same phones.

What also emerged was the fact that the convenience benefits moved more people towards accepting the change than security benefits did. Some employees would still use a username + password, despite having options for passwordless push, and subsequently would go through SSPR flows at times when they couldn’t remember their password. Letting them know that the new approach eliminated the need to use or know their password landed differently than explaining phishing resistance.

“One of the biggest things with employee buy-in was explaining that, for the most part, they were not going to have to remember passwords anymore,” Michal Sinak, Cybersecurity Engineer, Semperis said. “That, honestly, was a big thing.”

The team built a documentation library on the company’s internal intranet: scenario-specific, screenshot-heavy and built around actual Semperis flows, with internal branding and mascots throughout. This resource was heavily leveraged throughout the rollout and onboarding process. New employees start with a Temporary Access Pass and are directed to the intranet resources to complete passkey enrollment, and that process has worked well in practice.

Passkey Impact


Semperis reached 100% adoption among full-time employees, and has extended enrollment to contractors and vendors with accounts in the Entra tenant. 

The volume of phishing attempts directed at Semperis has not declined since the rollout, which the security team expected. The vast majority of what arrives is still credential phishing: attempts to capture usernames and passwords.

Passkeys changed the team’s response posture toward those attempts.

“We kind of glance at it and go, you’re doing basic credential phishing, which is less concerning now,” Sinak said. “We’re thinking more about things like session theft these days than we are worried about credential theft.”

There is still room to go, as certain types of attacks, like authentication downgrade attacks, will attempt to trick users into entering their password, even if they ultimately cannot authenticate with it. Semperis’s long-term goal is an environment in which employees don’t know or remember their password, which will effectively be a random set of data within the password attribute in Entra. The ultimate goal is that employees will find it really odd if they are asked for their password.

Key Recommendations


The Semperis deployment offers a set of lessons for organizations working through a similar rollout.

Enroll live, not by email. Joining existing team meetings and walking employees through setup on the spot drove adoption far more effectively than email campaigns. Most employees enrolled without issue once shown how.

Set a deadline and enforce it. Voluntary adoption stalls without a hard cutoff. Shortening enforcement windows as confidence grew accelerated the final phases significantly.

Lead with convenience, not security. For the general workforce, the most effective message was that they would not need to remember or reset passwords anymore. Security benefits were secondary to most employees.

Budget for culture change. The technical implementation was straightforward. Sustained reassurance, in-person sessions and internal champions took more time and effort than expected.

Build documentation for your environment, not the platform. Generic vendor resources read as consumer tools to workforce users. Scenario-specific, internally branded documentation performed better and required ongoing maintenance as vendor UIs changed.

Enforce passkeys as the only option. The availability of weaker fallback authentication gives attackers a path to exploit. Conditional access policies that permit no weaker alternative make phishing resistance real.

Test across platforms. Passkey enrollment is phone-heavy and platform-specific. A small investment in test devices gives architects and engineers direct exposure to what users will encounter, and makes it easier to document and support those flows accurately.

Enable passkeys everywhere. As passkeys become a familiar part of the user experience, make sure every new product introduced into your environment supports them to preserve a seamless, phishing-resistant authentication journey.

Closing the Gap Between Product and Practice

With the adoption of passkeys, Semperis now ships incident response products that require the same phishing-resistant authentication its own workforce uses daily. The gap between what the company sells and how it operates internally has closed.

The deployment succeeded on the strength of a clear mandate from leadership, sustained enrollment sessions across dozens of team meetings, documentation specific to the Semperis environment, and a conditional access policy that removed weaker fallback options entirely.

Semperis is evaluating synced passkeys for general workforce use to reduce the re-enrollment burden when employees upgrade devices, and plans to scramble remaining Entra passwords and disable self-service password reset for enrolled users, closing the residual exposure from credentials that may exist in shadow IT systems outside of SSO.

“Without actually enforcing a passkey, or something phishing-resistant as your only option, you really aren’t any better off.” Eric Woodruff, Chief Identity Architect, Semperis

Read the Case Study

Thursday, 28. May 2026

Oasis Open

Invitation to comment on UBL Version 2.5 before call for consent as OASIS Standard

OASIS and the OASIS UBL TC [1] are pleased to announce that Universal Business Language Version 2.5 CS01 is now available for public review and comment. The Universal Business Language (ISO/IEC 19845) is an open library of standard electronic business documents and information models designed for a wide range of supply chain, procurement, and transportation […] The post Invitation to comment on

Public Review Ends - July 28th

OASIS and the OASIS UBL TC [1] are pleased to announce that Universal Business Language Version 2.5 CS01 is now available for public review and comment.

The Universal Business Language (ISO/IEC 19845) is an open library of standard electronic business documents and information models designed for a wide range of supply chain, procurement, and transportation processes. It provides a syntax-neutral semantic library that supports various syntaxes such as XML and JSON, enabling interoperability across different industries and systems. UBL helps streamline information exchange, eliminating the need for data re-entry, and enhancing global harmonization and interoperability in e-commerce.
The TC received three Statements of Use from Logius, Helger IT Consulting GmbH, and Koordinierungsstelle für IT-Standards (KoSIT) [3].

The candidate specification and related files are available here:

Universal Business Language Version 2.5
Committee Specification
01 15 April 2026

https://docs.oasis-open.org/ubl/cs01-UBL-2.5/UBL-2.5.html
https://docs.oasis-open.org/ubl/cs01-UBL-2.5/UBL-2.5.pdf
https://docs.oasis-open.org/ubl/cs01-UBL-2.5/UBL-2.5.xml (Authoritative)

Associated files can be found at: https://docs.oasis-open.org/ubl/cs01-UBL-2.5/

Members of the UBL TC [1] approved this specification by Special Majority Vote [2]. The specification had been released for public review as required by the TC Process [4].

Public Review Period
The 60-day public review is now open and ends 28 July 2026 at 23:59 UTC.

This is an open invitation to comment. OASIS solicits feedback from potential users, developers and others, whether OASIS members or not, for the sake of improving the interoperability and quality of its technical work.

Comments may be submitted to the project by any person through the use of the project’s Comment Facility. Members of the TC should submit feedback directly to the TC’s members-only mailing list. All others should follow the instructions listed here.

Alternatively, comments may be sent to: technical-committee-comments@oasis-open.org

All comments submitted to OASIS are subject to the OASIS Feedback License, which ensures that the feedback you provide carries the same obligations at least as the obligations of the TC members. In connection with this public review  we call your attention to the OASIS IPR Policy [4] applicable especially [5] to the work of this technical committee. All members of the TC should be familiar with this document, which may create obligations regarding the disclosure and availability of a member’s patent, copyright, trademark and license rights that read on an approved OASIS specification.

OASIS invites any persons who know of any such claims to disclose these if they may be essential to the implementation of the above specification, so that notice of them may be posted to the notice page for this TC’s work.

Additional references:

[1] OASIS UBL TCgroups.oasis-open.org/communities/…
[2] Approval ballot:groups.oasis-open.org/higherlogic/ws/public/…
[3] Links to Statements of UseLogius: https://groups.oasis-open.org/discussion/statement-of-use-ubl-25Helger IT Consulting GmbH: https://groups.oasis-open.org/discussion/statement-of-use-ubl-25-1Koordinierungsstelle für IT-Standards (KoSIT): https://groups.oasis-open.org/discussion/fw-statement-of-use-ubl-25-from-coordination-office-for-it-standards-kosit
[4] www.oasis-open.org/policies-guidelines/ipr
[5] www.oasis-open.org/committees/ubl/ipr.phpwww.oasis-open.org/policies-guidelines/ipr/#RD-Limited

The post Invitation to comment on UBL Version 2.5 before call for consent as OASIS Standard appeared first on OASIS Open.


DIF Blog

DIF Is for Humans

Two small but major changes to AI policy have been integrated into DIF’s governing documents. While other organizations are struggling to agree on how to deal with Agent participation on their mailing lists, chat channels, and repositories, the Decentralized Identity Foundation has taken a rapid and decisive stand

Two small but major changes to AI policy have been integrated into DIF’s governing documents. While other organizations are struggling to agree on how to deal with Agent participation on their mailing lists, chat channels, and repositories, the Decentralized Identity Foundation has taken a rapid and decisive stand based on our Intellectual Property Rights policy. 

DIF Bans Agents

Agentic AI contributions are banned from DIF.  

DIF Upholds Creator Rights

DIF has been maintaining its leadership in developing standards for trusted AI and trusted content with two working groups, so we are pro-AI and pro-Agent. However, maintaining moral rights is at the center of the standards being developed in DIF. LLMs today do not respect the provenance and source of the information they provide, and therefore they may not participate in DIF mailing lists, discussions, or code repositories. 

This decision was the recommendation of DIF’s Technical Steering Committee and passed unanimously by the elected Steering Committee.

Precedent Set: Provenance Is Key

We hope this decision will be a precedent to other standards bodies. We cannot base international standards on materials that do not have clear legal standing, and that do not have adequate accountability attached to them. Therefore, the Steering Committee has taken a hard line against direct participation and contributions from large-language models and AI Agents. 

Backstory: Insightful and Pleasant Agents

Recently, a number of DIF’s working group mailing lists have received insightful emails from a friendly and knowledgeable AI Agent. This prompted the Technical Steering Committee to discuss the nature of this type of participation, and whether it was appropriate for an AI Agent to join the mailing lists. Other organizations are dealing with the same problems. In fact, in some of the larger Standards Development Organizations, they are experiencing so much agentic content, it's become difficult to follow the conversation in their mailing lists.

While many of us feel that AI can potentially provide benefits to bodies such as DIF, not one person was able to make an argument for how we could ensure adherence to basic attribution of intellectual property rights. The ongoing violations of copyright and trademark by LLMs make it clear that accepting such contributions could endanger the legal status of the standards, reports, and code contributions that DIF provides for the industry. Therefore,  the Technical Steering Committee made the recommendation to ban such traffic from all DIF mailing lists, and furthermore to ban direct AI participation and contributions to any DIF repositories. The Steering Committee approved the recommendations, which have now become part of DIF’s Code of Conduct and Working Group Lifecycle document.

DIF has chosen to take a clear non-ambiguous stance against direct AI contributions, primarily because it is impossible to determine the intellectual property rights status of text or code contributed by LLMs in their current form. Today’s LLMs are prone to inadvertently violating copyright and intellectual property laws, and research into making LLMs aware of moral rights is going even more slowly than researching into making them morally aware. Furthermore, even if an LLM does make original contributions, it’s unclear who owns the copyright to the output of the LLMs and agents, or if ANY moral rights can be held on LLM outputs. 

Even when the person deploying the agent is clearly identified, DIF’s Technical Steering Committee has asserted that the confidence level is too low to accept such contributions. Similarly, if an Agent suggests ideas in the discussion groups, and those ideas are adopted by the working groups, there is a danger of inadvertent IPR violation, because such ideas fall outside of DIF’s current agreements and monitoring systems. As well as being clear on the policy level, this is a values-based decision. DIF defends the rights of those who have generated original ideas and code, whether those are companies or individuals. 

Appropriate use of AI at DIF

Despite the ban on Agentic AI contribution, DIF recognizes the importance of using AI and LLMs in certain circumstances. In the inclusivity section, we have stipulated specifically that people can use AI for translation, particularly if they are not native English speakers. We also recognize that people may use AI for other types of assistance, including coding or help writing specifications. While such uses are not explicitly banned, we are explicit about the fact that all contributions to DIF are consciously and carefully made by humans.

Each human who makes a contribution to DIF is fully responsible for releasing those contributions under the open source licensing employed by DIF. Just as someone might ask a friend for help, or outsource code writing, DIF cannot constrain individuals from using AI for help on their contributions. However, the individual must be fully responsible for all legal implications of any contributions they make to DIF. 

Code of Conduct Update

In DIF’s Code of Conduct, the section previously called “Open, Inclusive, and Diverse” is now titled “Open, Inclusive, Diverse & Human”. The language has been updated to include the following: 

“Though we welcome people fluent in all languages, DIF development is conducted in English. Participants that feel functional but disadvantaged in English should feel comfortable requesting to bring coworkers to meetings or tap bilingual participants/colleagues or artificial intelligence to assist in language translation or perform side discussion during meetings." "Human: Though diverse, DIF is an organization of diverse humans. Membership is reserved for individual humans and organizational employers of humans. AI agents are not allowed to join or contribute to DIF independently.” Working Group Lifecycle Update

The Working Group Lifecycle has been updated with section 9 as follows: 

“Agentic Contributions to DIF Working Group Products. Working group members are encouraged to think of agentic contributors (whether LLMs or otherwise) as introducing a risk of violating patent rights. There is a risk that an LLM could reference, depend on, or include content that is not available under any license that is compatible with open standards and open source. Direct contributions from independent AI tools are not allowed. WG chairs are asked to add a clause to their project's contribution guides requiring that all contributions be signed off by humans who can reasonably attest to and honor the IPR obligations that were agreed to when joining DIF. In all cases, contributions to DIF WG projects must be put forward by DIF members; contributions from any agent acting autonomously must not be accepted.”

Next Steps

Based on these policies, DIF will roll out changes to the charters of all Working Groups and update the Working Group Charter template for future groups. Working Group chairs will be informed of the policy and approve the changes to the charters of each group.

Learn more about Decentralized Identity Foundation

Wednesday, 27. May 2026

FIDO Alliance

Associated Press (syndicated from Business Wire): FIDO Alliance Announces Digital Identity and Authentication-Focused Agenda Themes for Authenticate APAC 2026 Conference

The FIDO Alliance today announced agenda themes and program highlights for Authenticate APAC 2026, taking place June 2–3 at the Grand Hyatt Singapore. Bringing together global and regional leaders in authentication […]

The FIDO Alliance today announced agenda themes and program highlights for Authenticate APAC 2026, taking place June 2–3 at the Grand Hyatt Singapore. Bringing together global and regional leaders in authentication and digital identity, the event will explore how evolving standards, regulations, AI-driven capabilities and real-world deployments are shaping the future of trusted digital interactions across APAC and beyond.

Authenticate APAC 2026 is the FIDO Alliance’s inaugural Asia-Pacific conference, building on seven years of successful Authenticate events in the United States and two years of regional APAC summits. It is supported by Government Sponsor, the Cyber Security Agency of Singapore and Signature Sponsors, Google, Visa, and Yubico.

Conference sponsors commented:

“Making internet authentication simpler and safer is a world-wide team effort. The APAC region has played a leading role in driving the adoption of passkeys and more. It is particularly appropriate that the first APAC Authenticate is happening in Singapore, a known innovation center driving a safer digital future for its citizens,” said Sam Srinivas, Principal Product Manager, Google; FIDO Board Rep for Google, and President of the FIDO Alliance.

“As cyber threats grow in sophistication, having strong authentication standards is necessary to ensure that our digital systems and services are protected,” said Rodney Tan, Director, Cybersecurity Engineering Centre, at the Cyber Security Agency of Singapore. “We are glad to support this inaugural event which will bring together public-private sector leaders to Singapore to exchange ideas, discuss strategies and set direction on authentication and digital trust.”

“We are seeing a fundamental shift towards more resilient, future-ready foundations of digital identity and payments,” said Krishna Thiruvengadam, Head of Core Platforms and Digital Solutions, Asia Pacific at Visa. “The future of digital commerce will be built on core capabilities like authentication and tokenisation, working together to deliver experiences that are both secure and seamless. As digital interactions become more intelligent and increasingly autonomous, trust must scale alongside innovation. Visa is proud to partner with the industry that’s coming together at Authenticate APAC 2026 to advance these capabilities. Innovations such as Visa Payment Passkeys will enable secure, frictionless experiences at scale to safeguard trust.”


Banesco Banco Universal: Scaling Phishing-Resistant Authentication to 2.2 Million Users

Corporate Overview Banesco Banco Universal is the leading private bank in Venezuela, with more than 2.4 million monthly active users across its mobile and web banking platforms. The bank provides […]
Corporate Overview

Banesco Banco Universal is the leading private bank in Venezuela, with more than 2.4 million monthly active users across its mobile and web banking platforms. The bank provides digital services for peer-to-peer payments and high-value transfers. Banesco operates within a multinational banking group, and the group’s global security strategy directly informed the bank’s move toward phishing-resistant authentication.

The Business Challenge

Banesco identified four authentication challenges that affected both security and customer experience.

Phishing and social engineering exposure. Previous reliance on one-time passwords delivered via SMS and email left customers vulnerable. Attackers used phishing and vishing campaigns to manipulate customers into surrendering their temporary codes, bypassing OTP controls without breaking them.

Friction in high-stakes transactions. Credential-based authentication added unnecessary friction to the payment flows customers used most, including fast P2P payments and high-value transfers.

Fraud response overhead. When fraud monitoring systems flagged suspicious activity, resolving those alerts required manual support intervention. Customers had no path to self-remediation.

Cross-channel consistency. Customers access services across mobile and web. Banesco needed an authentication approach that worked consistently across both without channel-specific workarounds.

Why Banesco Chose Passkeys

Banesco evaluated its authentication options against two requirements: the solution had to be resistant to social engineering, and it had to work consistently across mobile and web without requiring separate implementations per channel.

Traditional Methods Left Core Vulnerabilities Open

OTP schemes delivered via SMS and email were Banesco’s primary authentication layer. Those schemes depend on a shared secret. An attacker does not need to break the mechanism; convincing the customer to hand over the code is enough. No OTP-based approach could close that gap.

Passkeys Delivered What Other Methods Couldn’t

Passkeys use asymmetric cryptography to ensure private keys never leave a user’s device. This removes shared secrets from the authentication flow entirely, eliminating the risk of man-in-the-middle attacks that OTP schemes cannot prevent. The move also aligned with the multinational banking group strategy to standardize on passkeys across the organization.

Implementation Overview

Banesco followed a phased rollout across three stages completed in seven months.

Phase 1: Technical Evaluation. The team integrated FIDO servers with core banking infrastructure and validated compatibility across mobile and web platforms before any customer-facing deployment.

Phase 2: Pilot in Low-Risk Flows. Banesco introduced passkeys in lower-risk use cases first, establishing adoption baselines and identifying friction points before broader rollout.

Phase 3: Mass Deployment. With the pilot complete, Banesco activated passkeys for 2.2 million users across high-value transactions and fast P2P payments. The bank also integrated passkeys as the verification mechanism for transactions flagged by its fraud monitoring systems, enabling customers to self-resolve fraud alerts without contacting support.

Results and Impact

Banesco has tracked outcomes across adoption, customer experience and fraud operations since completing mass deployment.

Adoption and Transaction Volume

2.2 million users actively authenticate with passkeys on a regular basis, representing about 92% of the active users 12 million passwordless transactions processed in the current year 8.3 million high-value transactions completed using passkeys

Customer Experience

Passkey authentication reduced friction where customers felt it most: completing high-value payments and resolving fraud alerts. Customers whose activity triggers a fraud alert can now verify their identity and restore access on their own, without a support call. As a result, the latest customer satisfaction survey data show that the main drivers of satisfaction are online banking security (73%) and ease of use (72%), highlighting the positive impact that passkeys create on the customer experience.  

Operational Benefits

Shifting fraud alert resolution to customer self-service reduced manual intervention in the contact center. Identity-theft-related fraud reports have declined by 65% since deployment.

Future Vision

Following the success of its mass rollout, Banesco has established clear metrics demonstrating the scalability of passkey-based authentication. To enhance the protection and digital experience of its customer base, the organization intends to broaden the use of passkeys, extending passkeys as the primary out-of-band authentication method across all channels, including phone banking and in-person branch visits

Furthermore, Banesco is moving toward a comprehensive passwordless framework, aiming to eliminate the storage and use of traditional credentials within its core transactional ecosystem. 

Key Recommendations

Banesco offers these insights for organizations planning a passkeys deployment:

Prioritize user education. Customers need to understand that biometric data is stored locally on their device and is never shared with the bank. Addressing this early reduces resistance during rollout. Start where friction is highest. Beginning with use cases that cause the most customer friction, such as fraud alert resolution, makes the value of passkeys immediately apparent. Use a phased approach. Piloting in low-risk flows before full deployment gives teams time to surface edge cases without exposing the full user base. Executive Perspective

The deployment resolved what had been a longstanding tradeoff between stronger authentication and a simpler customer experience.

“The implementation of FIDO2 and passkeys has been a turning point in our cybersecurity strategy. We have achieved the ideal balance: elevating technical protection to the highest level while empowering our customers to manage their own security safely and simply.” – Jesús Irausquín CISO Banesco Venezuela

Read the Case Study in English Read the Case Study in Spanish

Digital Identity NZ

Yeah Nah: The Ultimate Cold Start Problem | May Newsletter

May has been a busy one for the Digital Identity New Zealand community - some useful global learnings, real momentum locally, and a few shifts in the broader system settings worth noting. The post Yeah Nah: The Ultimate Cold Start Problem | May Newsletter appeared first on Digital Identity New Zealand.

Kia ora

May has been a busy one for the Digital Identity New Zealand community – some useful global learnings, real momentum locally, and a few shifts in the broader system settings worth noting.

This month I’m just back from a trip across India and Utah, and the throughline was sharper than I expected: the conversation everywhere has moved from proving who you are to proving what’s true about credentials, objects, supply chains, and increasingly the actions of AI agents. The infrastructure question underneath it is no longer abstract. It’s being decided now, in real systems, by whoever moves first.

Locally, we’ve welcomed a new Council member, opened registrations for the Hui Taumata, and seen genuine member progress worth celebrating. There’s also a meaningful change in the machinery of digital government to flag.

Digital identity has a cold start problem, and it’s worth naming plainly.

In New Zealand we’re building a voluntary ecosystem – no mandate, no big-bang switchover. That means everyone waits: issuers wait for relying parties, relying parties wait for useful credentials, and consumers wait for both. Working groups help, but demand is what moves the system.

That’s why DINZ is putting weight behind our Trusted Credential Adoption (TCA) Group: getting real relying parties ready to accept credentials, so issuance turns into real-world utility.

The good news is the ground is starting to shift. This month brought genuine regulatory modernisation – the kind that turns “someday” credentials into “this year” ones.

System settings: where the rails are being laid

On 13 May, the bill enabling digital driver licences passed its third reading – making a digital licence an optional alternative to the plastic card, alongside digital warrants of fitness and registration. Together with alcohol licensing reform, two of the most common “prove it” moments (driving and buying alcohol) are moving into scope for verifiable credentials.

But issuance is only half the job. The unlock is acceptance capability at scale – banks and large verifiers building this into production systems, not endless pilots.

Trust lifecycle is where it gets real: proving a credential came from an accredited issuer and is still valid. NZ’s emerging approach relies on PKI – a VICAL (verified issuer certificate authority list), signed and published so verifiers can check provenance.

We also advocated for digital public infrastructure investment over buying back legacy assets→. 

Finally, a sovereignty flag worth raising: as agencies move to issue credentials, we should resist defaulting to offshore trust roots and registries. The Digital Identity Services Trust Framework (DISTF) exists so we can build NZ-grounded trust infrastructure with Te Tiriti as a design principle – and we should reach for it first.

DINZ Update

Welcome Andrew Dodd

We’re pleased to welcome Andrew Dodd to the DINZ Executive Council. Andrew brings strong leadership and practical experience driving industry collaboration in the banking sector, exactly the kind of capability that helps accelerate responsible digital identity adoption.

Andrew will be joining monthly Council meetings and contributing through the Trusted Credential Adoption Group. Welcome aboard, Andrew.

India + Utah: trip highlights and outtakes

India highlights

Digital Public Infrastructure (DPI) is a political project, not a technical one. The hardest parts aren’t standards choices; they’re governance, grievance pathways, and who ultimately controls the rails. For NZ, that sharpens the focus on how Te Tiriti is embedded in governance from the start. Consent infrastructure is the most transferable lesson. India’s Account Aggregator model treats consent as a first-class, auditable, revocable object highly relevant to NZ’s Consumer Data Right and to Māori data sovereignty design. India is positioning DPI as soft power. Conversations with Observer Research Foundation (ORF) reinforced that DPI is now an export narrative as much as a domestic capability creating both partnership opportunities and a need for NZ to engage on our own terms. The operating model matters more than the code. India’s success has been driven by regulated interoperability and a public-infrastructure/private-innovation split. The cautionary tales such as exclusion, last-mile failures are largely governance and delivery issues, not technology ones.

Why it matters for NZ: India is the only jurisdiction to build DPI at population scale, and the US is now reading those lessons in real time. NZ can add value by translating what’s transferable into a Te Tiriti-based setting, and leaving behind what isn’t.

Compare and contrast: NZ and Utah

The two jurisdictions are arriving at the same destination from opposite directions, and that’s what makes the comparison useful.

New Zealand has built top-down: a legislated trust framework (the DISTF), a regulator-recognised path from issuer to verifier to wallet, and Te Tiriti embedded as a design principle rather than a later consultation. The architecture exists; the adoption curve is the work ahead.

Utah has built bottom-up: state-led legislation establishing first-person control over identity data as a default, with the momentum now spreading across multiple states. The political will and the consumer and fiduciary duty of care framing are well advanced; the interoperable architecture is still being assembled.

The instructive part is the overlap. Both are betting that legitimacy: clear legal grounding, recognisable governance, public-interest framing is the scarce asset in this next layer, not the technology, which is increasingly commoditised. 

Where NZ has framework-first and Utah has movement-first, the jurisdictions that combine both will set the reference standard others adopt.

Utah highlights

At the SEDI Summit in Utah, the signal was clear: the internet’s missing “identity layer” has become the opening for industrial-scale fraud, synthetic identities and deepfakes, and the global response is accelerating. The SEDI movement has moved beyond a single state experiment to more than 12 states actively engaged, positioning “state-led legitimacy” as the emerging US path.

           UTAH SEDI SUMMIT – Andy with Utah County Commissioner Amelia Gardner and House Representative Leah Hansen

Three trust models, one direction of travel

Across the trip, three distinct models for establishing trust came into focus and notably, they’re converging rather than competing:

Framework-led (NZ/DISTF): Trust flows from a legislated, multi-stakeholder framework with accreditation and conformance. Top-down legitimacy, regulator-anchored. State-led (US/SEDI): Trust flows from sub-national legislation establishing first-person primacy, scaling state by state. Bottom-up legitimacy, momentum-driven. Infrastructure-led (India/DPI): Trust flows from open, regulated public rails – identity, payments, and commerce designed to interoperate. Adoption-led legitimacy, scale-driven.

The common thread: each is an attempt to put neutral, accountable governance underneath identity before a platform or a single state writes the default for everyone.

Outtakes

One of the strongest through-lines across the programme: the centre of gravity is shifting from “prove who you are” to “prove what’s true about anything” credentials, objects, supply chains, and AI outputs. Verifiable provenance is emerging as the next DPI layer.

And a line that stuck from the technical floor: “OAuth’s threat-model doc is now ~100 pages. That’s a casualty list, not a security framework.” The momentum toward self-certifying identifiers (e.g. KERI) is growing fast.

Digital Trust Hui Taumata 2026 — Super Saver tickets end 31 May

Tickets are now live for the Digital Trust Hui Taumata 2026 – Towards Universal Trust – Aotearoa’s flagship gathering for digital identity, trust technology, and the governance frameworks that underpin them.

This year opens with a joint keynote from Drummond Reed and Dr Karaitiana Taiuru bringing global trust architecture together with tikanga-informed digital governance and Māori data sovereignty followed by practical sessions focused on real-world adoption and interoperability.

Super Saver tickets are on sale now (until 31 May), including a Member Launch Special for DINZ and Tech New Zealand community members.

Learn more + register here→

Member News

Air New Zealand digital ID pilot

Congratulations to the Air New Zealand team on a successful digital ID pilot – exactly the kind of practical, real-world progress that builds confidence, especially when designed around privacy, security, and customer control.

It’s also encouraging to see learnings being shared with IATA as the work looks toward broader trials across more ports. Read the announcement→.

Lumin: new data on identity fraud

DINZ member Lumin (and Platinum sponsor of Digital Trust Hui Taumata 2026) has released new survey findings on identity fraud across the US, Australia and New Zealand. Among 1,000 business decision-makers surveyed, 56% experienced identity fraud in the last 12 months, 94% believe agreement workflows are vulnerable to AI-powered fraud, and 51% say eSignature security needs improvement.

Lumin’s Expert Insights roundtable series (with leaders from Lumin, Air New Zealand, MBIE, and MATTR) unpacks what this means in practice. Explore + download the report→.

Welcome new member: Attain Insight

A warm welcome to new member Attain Insight, a leader in identity resolution, biometric search, analytics, data security and location intelligence. Their solutions help clients make smarter, data-driven decisions while meeting compliance requirements – a strong addition to the DINZ community.

Industry News

Digital government update – GDDA established (from 1 April 2026)

From 1 April 2026, the Government Chief Digital Office (GCDO) functions moved into the Public Service Commission as the new Government Digital Delivery Agency (GDDA).

GDDA brings together system leadership, delivery support, and capability functions to strengthen digital public services – a meaningful shift toward more coordinated digital delivery across government. Read the announcement→.

I enjoyed speaking at the GovTech Aotearoa 2026 summit in Wellington last week. Thank you for the warm response from leading lights in our Public Service. You can read my musings here→.

Ngā mihi nui,

Andy Higgs

Executive Director,
Digital Identity New Zealand

Read full newsletter here: Yeah Nah: The Ultimate Cold Start Problem | May Newsletter

The post Yeah Nah: The Ultimate Cold Start Problem | May Newsletter appeared first on Digital Identity New Zealand.

Tuesday, 26. May 2026

FIDO Alliance

Building the Trust Layer for Agentic Payments with AP2 and Verifiable Intent

Nishant Kaushik, CTO, FIDO Alliance Our agents are getting more capable by the day. They write code, respond to emails, detect vulnerabilities, and optimize workflows. And increasingly, they will shop […]

Nishant Kaushik, CTO, FIDO Alliance

Our agents are getting more capable by the day. They write code, respond to emails, detect vulnerabilities, and optimize workflows. And increasingly, they will shop and pay on our behalf.

But handing over financial autonomy to AI systems isn’t just a UX evolution. It’s a fundamental shift in how commerce operates. Without strong guardrails, it risks fragmentation, inconsistent security, and unclear accountability.

As the industry moves toward agentic payments, where AI agents initiate and execute transactions under delegated authority, there is a growing recognition that we need a common foundation for trust. The contributions of Google’s Agent Payments Protocol (AP2) and Mastercard’s Verifiable Intent (VI), co-developed with Google, into the FIDO Alliance represent a pivotal step toward establishing that foundation.

This post explores what these technologies bring to the table, why they matter together, and how standardization within the Alliance could shape the future of AI-driven commerce.

Agentic Payments in AI-Powered Commerce

Agentic payments refer to transactions carried out autonomously by AI agents acting on behalf of users, within predefined rules and constraints. Unlike traditional payments where a human explicitly approves each transaction, agents can decide if, when, and how to transact based on instructions they received. They can

Find relevant products at an approved merchant Check for approved pricing on the product Select optimal payment rails Enforce spending policies Execute conditional or recurring transactions

This is a structural shift in commerce. Payments are moving from user-triggered events to continuous, policy-driven processes embedded across the commerce lifecycle.

At scale, this introduces both opportunity and risk. Analysts project agentic commerce could drive trillions in transaction value by 2030. But that scale demands a new level of rigor in how we represent identity, consent, and authorization.

Today’s infrastructure assumes a human is present at checkout. It offers limited support for:

Delegated authority to software agents Persistent, machine-readable consent Verifiable evidence of user intent

Without standardization, we risk a fragmented ecosystem of incompatible “AI payment” models — each with its own semantics, security posture, and integration burden.

What is needed is a shared, interoperable trust layer for identity, consent, and delegation.

AP2: The Mandate and Coordination Layer

AP2 (Agent Payments Protocol) is an open protocol that defines how the key participants in an agentic payment flow — AI agents, merchants, wallets, and payment providers — coordinate around user authorization. At its core is the concept of mandates: Verifiable Digital Credentials (structured, cryptographically signed objects) that capture what a user has authorized an agent to do.

AP2 introduces two primary mandates:

Checkout Mandate: This captures the details about and conditions on what the user wants to buy. Payment Mandate: This captures the details about and conditions on how the user wants to pay (amount, instrument, timing).

Each mandate also transitions between two stages across the lifecycle of the transaction, defined to support both Human-Present and Human-Not-Present (Autonomous) transactions: 

The mandates will start as Open, during which they capture the user’s constraints and goals for the transaction as well as payment (budget, allowed instruments) before a specific cart is finalized for autonomous execution. When the checkout is finalized, the mandates will transition to Closed, in which they capture the user’s (or agent’s) authorization for a specific transaction amount bound to a finalized checkout.

The diagrams below provide a simplified conceptual view of how they fit into the agentic transaction flows (you can find more technical details here).

Fig 1: Human-Present Agentic Transaction

Fig 2: Human-Not-Present Agentic Transaction

With each mandate being tamper-evident and verifiable, they form a durable record of consent that goes beyond ephemeral UI interactions. Using them, AP2 acts as the policy and coordination layer that answers a fundamental question:

Who is allowed to do what, on whose behalf, and under what constraints?

Verifiable Intent: The Evidence Layer

If AP2 defines how intent is created and shared, Verifiable Intent defines how it is proven.

Verifiable Intent is a cryptographic credential framework that transforms user authorization into portable, verifiable evidence. It enables independent validation by issuers, networks, and merchants, without relying on proprietary logs or opaque systems. Its core elements include:

Identity binding: Linking the user to a cryptographic key (often anchored in device-based authentication) Intent statements: Capturing constraints, scope, and delegation rules Selective disclosure: Providing tailored views for different parties (e.g., merchant vs. issuer) that helps preserve customer privacy

VI is protocol-agnostic and aligns naturally with AP2, but it is not dependent on it. Its role is to ensure that wherever a transaction is evaluated — at checkout, during network routing, or at issuer authorization — there is consistent, verifiable evidence of what the user actually approved. This shifts “intent” from an implicit assumption to an explicit, cryptographically verifiable artifact.

Why These Layers Belong Together

Agentic payments break a core assumption: that the user is present at the moment of authorization.

Consent may be granted in advance Execution may happen asynchronously Interfaces may be non-standard or invisible

Yet the need for accountability does not change. Fraud systems, dispute processes, and regulators still require clear answers to fundamental questions: What did the user authorize? What was the agent allowed to do? Did the transaction stay within those bounds?

AP2 and VI address complementary parts of this challenge:

AP2 standardizes how consent and delegation are defined and communicated VI standardizes how that consent is represented and verified as evidence

Together, they form the foundation of a coherent and scalable trust model for agentic payments.

Building A Trust Layer for Autonomous Commerce

The FIDO Alliance has already transformed authentication by promoting standardized, phishing-resistant, hardware-backed credentials. Our Payments Technical Working Group is engaged in work that extends that trust model into the realm of payments, addressing emerging challenges in the evolving commerce ecosystem. Defining standardized protocols for agentic payments is more than just a technical exercise; it’s about shaping how trust is embedded into the next generation of commerce:

Establish a universal trust layer for AI-driven transactions across consumer, enterprise, and platform use cases Accelerate regulatory alignment by providing clear, verifiable models of consent and delegation Shift innovation up the stack toward better user experiences, privacy-preserving flows, smarter agents, and value-added services Raise the security baseline by replacing weak credential models with cryptographically enforced authorization Improve dispute resolution through structured, portable evidence of user intent

Critically, doing this work ensures that agentic payments evolve on an open, interoperable foundation rather than becoming locked into proprietary ecosystems. Without coordination, protocols will inevitably diverge in how they represent consent and constraints. Preventing this semantic fragmentation, by maintaining a consistent, extensible model across the ecosystem, is a core objective of standardization.

With FIDO’s growing role in digital credentials, there is also a clear opportunity to reuse core primitives in wallet infrastructure, credential formats, cryptographic assurance, and certifications, to reduce duplication and create a unified security substrate.

Final Thought

Agentic payments are coming fast. The question has shifted from whether AI will participate in commerce to whether we will build the right trust infrastructure before it does. By contributing AP2 and Verifiable Intent to the FIDO Alliance, Google and Mastercard are giving the industry a timely opportunity to define that foundation, one where we embed strong identity, clear consent, and verifiable accountability into the core of how agents transact on our behalf.

Monday, 25. May 2026

GLEIF

#21 in the LEI Lightbulb Blog Series – The UK Makes the Case for the LEI in Digital Asset Markets

The UK Financial Conduct Authority (FCA) has taken a significant step toward establishing a comprehensive regulatory framework for crypto-asset activities – and, in doing so, has made a compelling case for the use of the Legal Entity Identifier (LEI). By explicitly incorporating the LEI into its proposed rules for record-keeping, disclosures, and supervisory reporting, the FCA is moving beyond h

The UK Financial Conduct Authority (FCA) has taken a significant step toward establishing a comprehensive regulatory framework for crypto-asset activities – and, in doing so, has made a compelling case for the use of the Legal Entity Identifier (LEI).

By explicitly incorporating the LEI into its proposed rules for record-keeping, disclosures, and supervisory reporting, the FCA is moving beyond high-level policy discussions and demonstrating how standardized organizational identity can address longstanding challenges in complex, cross-border digital asset markets.

Advancing digital asset oversight

The need for increased trust and transparency across digital and crypto asset markets is driving increased regulatory momentum for the well-established Global LEI System as the only open, standardized, and regulator-endorsed organizational identity management infrastructure.

Through the LEI and its cryptographically verifiable counterpart, the verifiable LEI (vLEI), any legal entity can be uniquely and unambiguously identified – solving the significant problem of determining "who is who" across ecosystems and platforms. For regulators, this promotes interoperability, reduces fragmentation, and strengthens supervisory oversight – while lowering compliance costs and promoting innovation.

Previous editions in the LEI Lightbulb Blog Series have explored how these benefits are already recognized across regulatory frameworks, including the Financial Action Task Force's (FATF) updated Recommendation 16, which enhances payment transparency, and the European Union's landmark Markets in Crypto-Assets (MiCA) regulation. We have also examined emerging opportunities for the LEI and vLEI in relation to the GENIUS and CLARITY Acts in the United States.

This latest installment examines support for the LEI as part of the FCA's initiative to establish a comprehensive regulatory framework for crypto-asset activities.

Spotlight on the UK: FCA proposals on regulating crypto asset activities

To support the development of a competitive and sustainable crypto-asset sector that promotes market integrity, protects consumers, and supports innovation, the FCA has consulted on proposed rules and guidance for firms conducting regulated crypto-asset activities. These proposals have been informed by extensive engagement with the crypto asset industry, consumers, traditional finance participants, and other regulatory regimes.

The proposals mark an important step forward, moving beyond high-level policy and focusing on how crypto regulation will work in practice. Collectively, they demonstrate how clear, structured legal entity identification can address longstanding challenges by increasing transparency and reducing ambiguity in complex, cross-border crypto markets – enabling more effective, data-driven supervision.

As part of this, GLEIF welcomes and endorses the following FCA proposals requiring the use of the LEI for record-keeping, disclosures, and supervision. This reinforces its role as a proven, pragmatic, and scalable means of promoting transparency, interoperability, and trust in regulated digital asset markets:

CP25/40 – Regulating Crypto Asset Activities

Robust record-keeping of client orders and transactions is a key component of effective risk management and market integrity, especially in rapidly evolving crypto asset markets. In response to this need, the FCA proposes to require the use of unique digital identifiers, including the LEI, for sellers, buyers, or decision-makers involved in qualifying crypto asset transactions where these parties are legal entities.

CP25/41 – Admissions & Disclosures and Market Abuse Regime for Crypto Assets

The FCA proposes to require crypto asset trading platforms (CATPs) to file approved qualifying crypto-asset disclosure documents (QCDDs) – and any supplementary disclosure documents (SDDs) – with an FCA-owned centralized repository prior to the commencement of trading, and to publish these documents on their websites. These requirements are an important mechanism for ensuring transparency, market integrity, and consistent access to disclosure information. High-quality and reliable disclosures at the point of admission to trading are also essential for fair competition and the orderly functioning of crypto asset markets.

To support this need, the FCA proposes to require the use of unique digital identifiers, including the LEI, within QCDDs for qualifying stablecoin issuers, as well as for CATP operators submitting such documents in relation to legal persons seeking admission to trading.

Further to the FCA proposal, GLEIF observes that requiring vLEI signatures on QCDDs would enhance the reliability of disclosures and provide additional safeguards against fraud, thereby strengthening transparency and market integrity.

CP26/4 – Application of FCA Handbook for Regulated Crypto Assets II

Given that standardized regulatory reporting strengthens supervisory oversight of firms’ financial resilience, governance arrangements, and operational integrity, the FCA has proposed including the LEI in regulatory reporting, where available, or as an optional identifier.

Specifically, the consultation proposes the reporting of LEIs in several relevant contexts. This includes: for third parties involved in qualifying stablecoin issuance, backing, or redemption; the top 10 clients and/or execution venues of qualifying crypto asset trading platforms; intermediaries with the highest total transaction value of crypto assets; top liquidity sources when dealing in crypto assets as principal; and top lending counterparties.

Looking ahead, the vLEI could further strengthen transparency, security, and interoperability by allowing identity credentials to be embedded directly into digital transactions, smart contracts, and on-chain processes.

In addition to these proposals requiring the use of the LEI, GLEIF also encourages the FCA to support globally recognized identifiers like the LEI and vLEI in its proposed prudential disclosure framework:

CP25/42 - Prudential Regime for Crypto Assets

Proportionate prudential standards and transparent disclosures are key to supporting the development of the UK crypto asset market while maintaining market integrity, confidence, and resilience. The FCA’s proposals on the public disclosure of prudential information, including the introduction of a tailored disclosure framework for crypto asset firms and the inclusion of information on group arrangements, risk management, and own funds.

In this context, the LEI can support effective governance and strengthen the transparency and usability of publicly disclosed prudential information – particularly for cross-border group arrangements. Moreover, the vLEI could further enhance the reliability and auditability of prudential disclosures by enabling high-assurance, automated verification of disclosed information.

A growing regulatory consensus

The FCA proposals mark yet another compelling regulatory precedent highlighting the foundational role that the LEI, as well as the vLEI, can play in emerging regulatory frameworks to promote more trustworthy, resilient, and interoperable digital asset markets. This reflects similar developments in other jurisdictions, including the EU's MiCA regulation, which incorporates the use of the LEI to support transparency and consistent identification.

This builds on the long-established role for the LEI in traditional finance, where it is deeply embedded in major regulatory frameworks and industry processes. In EU and UK capital markets, the LEI supports entity identification across Markets in Financial Instruments Directive (MiFID II) / Markets in Financial Instruments Regulation (MiFIR) transaction reporting; European Market Infrastructure Regulation (EMIR) derivatives reporting; Securities Financing Transactions Regulation (SFTR) securities financing reporting; Central Securities Depository Regulation (CSDR); Market Abuse Regulation (MAR); Capital Requirements Regulation (CRR); Alternative Investment Fund Managers Directive (AIFMD); Solvency II; the Prospectus Regulation; and the Transparency Directive. This foundation is now being reinforced in the UK’s transition to T+1 settlement. The Accelerated Settlement Taskforce Technical Group, chaired by Andrew Douglas, identifies LEIs as a key data element for organizing counterparty reference data and recommends that onboarding firms record counterparties’ LEIs at onboarding, where possible.

As traditional finance evolves toward tokenized instruments and digital asset market infrastructure, consistent use of the LEI across both traditional and digital asset markets would enable smoother identity interoperability across platforms, ecosystems, and regulatory regimes, while the vLEI can add the cryptographic assurance, automated verification, and trusted delegation capabilities needed for digital asset markets to scale safely.

The proposals also highlight the broader potential of a systematic regulatory approach that extends the use of the LEI beyond traditional capital market applications, enabling any organization to be uniquely and unambiguously identified across borders, platforms, and systems. For instance, the FCA's new policy on Operational Incident and Third Party Reporting designates the LEI as the unique identifier for third-party reporting to help address risks and dependencies more effectively. This takes a similar approach to the EU's Digital Operational Resilience Act (DORA), which requires financial institutions to identify all EU-registered ICT service providers using an active LEI or European Unique Identifier (EUID), with the LEI mandated as the sole identifier for organizations registered outside the EU.

Together, these developments reflect growing regulatory and industry recognition of the LEI and vLEI as key enablers of the greater openness, accountability, and control now required across a data-driven, global digital marketplace. Ultimately, this will enable a more innovative and inclusive economy where trust is hardwired into every business relationship and interaction.



The ‘LEI Lightbulb Blog Series’ from GLEIF aims to shine a light on the breadth of acceptance and advocacy for the LEI across the public and private sectors, geographies, and use cases by highlighting which industry leaders, authorities, and organizations support the LEI and for what purpose.

Friday, 22. May 2026

The Engine Room

Event recap: Using AI Safely: Practical Strategies for CSOs and Nonprofits from a Global Majority Perspective

Through our support work at The Engine Room, we’ve been hearing growing questions from communities about AI, including its risks, opportunities, and how to use it responsibly. As part of our ongoing support for civil society organizations using the Cybersecurity Assessment Tool (CAT), we hosted a community call exploring practical and political approaches to AI safety from Global Majority perspect

Through our support work at The Engine Room, we’ve been hearing growing questions from communities about AI, including its risks, opportunities, and how to use it responsibly. As part of our ongoing support for civil society organizations using the Cybersecurity Assessment Tool (CAT), we hosted a community call exploring practical and political approaches to AI safety from Global Majority perspectives. 

The post Event recap: Using AI Safely: Practical Strategies for CSOs and Nonprofits from a Global Majority Perspective appeared first on The Engine Room.

Thursday, 21. May 2026

FIDO Alliance

FIDO Alliance Announces Agenda for Authenticate APAC 2026

Global innovators from Adidas, Apple, Grab, OpenAI, Samsung Electronics and more to share expertise at Singapore authentication & identity event Singapore, April 30, 2026 – The FIDO Alliance today announced […]

Global innovators from Adidas, Apple, Grab, OpenAI, Samsung Electronics and more to share expertise at Singapore authentication & identity event

Singapore, April 30, 2026 – The FIDO Alliance today announced the agenda for Authenticate APAC 2026, a conference bringing together global leaders to advance secure, simple and trusted technologies for authentication and identity. This inaugural APAC event marks the first time Authenticate will be held in the region, building on seven years of successful Authenticate events in the United States and two years of regional FIDO APAC summits.

Authenticate APAC 2026 will take place June 2–3, 2026 at the Grand Hyatt Singapore and is supported by Signature Sponsors Google, Visa and Yubico.

Designed for business leaders, security professionals, and product innovators, the program combines technical depth with real-world deployment insights and forward-looking perspectives on the evolution of digital identity and trusted interactions.

Authenticate APAC 2026 offers a unique opportunity to hear directly from organizations deploying modern authentication and identity technologies at scale, gain practical insights on implementing passkeys, and explore the current state of digital credentials, AI and agent-driven capabilities – and what’s needed to advance adoption. It also provides a clear view into how evolving standards, regulations and new use cases are shaping the future of trusted identity-related interactions across APAC and beyond.

Agenda highlights include:

Authentication standards and best practices, including the latest on passkeys The intersection of authentication and AI Agentic authentication and agentic commerce Digital credentials, wallets and payments Enterprise passkey deployments at scale Regional regulatory developments and considerations Emerging use cases and the future of authentication

In addition to keynote presentations and breakout sessions, attendees will have opportunities to connect with peers and industry experts through dedicated networking events and an active expo hall.

Visit https://authenticatecon.com/event/authenticate-apac-2026/ to view the full agenda and to register.

Sponsorship Opportunities Available
Authenticate offers unique sponsorship opportunities for companies to showcase solutions to an engaged, decision-making audience. Prospective sponsors can learn more and apply at https://authenticatecon.com/sponsors/ or contact authenticate@fidoalliance.org

About Authenticate APAC 2026

Authenticate is the premier conference dedicated to advancing digital identity and authentication, with an emphasis on phishing-resistant sign-ins using passkeys. Hosted by the FIDO Alliance, this inaugural Asia-Pacific event marks the first time Authenticate will be held in the region. The event brings together CISOs, security strategists, product managers and identity architects to explore best practices, technical insights and real-world case studies in modern authentication. The Authenticate APAC 2026 conference will take place from June 2-3, 2026 at the Grand Hyatt Singapore, followed by the FIDO Alliance member-only plenary on June 4-5.

Signature sponsors for Authenticate APAC 2026 are Google, Visa and Yubico.

Authenticate Contact
authenticate@fidoalliance.org
PR Contact
press@fidoalliance.org

Wednesday, 20. May 2026

GLEIF

Why Knowing “Who Owns Whom” Matters More Than Ever in the Age of AI

Artificial intelligence (AI) is reshaping the global fraud landscape, with identity-related fraud, document manipulation, and AI-generated misinformation making it difficult to distinguish legitimate from unreliable content. Digital interactions can take place instantly across borders and jurisdictions, creating new complexities. At the same time, regulators are increasingly focused on the chal

Artificial intelligence (AI) is reshaping the global fraud landscape, with identity-related fraud, document manipulation, and AI-generated misinformation making it difficult to distinguish legitimate from unreliable content. Digital interactions can take place instantly across borders and jurisdictions, creating new complexities.

At the same time, regulators are increasingly focused on the challenges posed by the underlying data environments. For instance, in its recent interim report on the simplification of EU reporting frameworks for funds and transactions, the European Securities and Markets Authority (ESMA) highlighted how fragmented reporting systems, inconsistent data standards, and duplicative reporting requirements continue to create operational burdens and limit the usability of supervisory data.

ESMA’s simplification efforts emphasize the growing importance of interoperability, standardization, and more efficient data sharing across all reporting ecosystems. Whether in fraud prevention, regulatory reporting, or digital interactions more broadly, these developments point to the same underlying challenge: the need for trusted, interoperable, and verifiable organizational identity data.

The Importance of Who Owns Whom

This reflects that organizations increasingly need to identify not only "who is who," but also "who owns whom." A full understanding of organizational relationships is essential for risk management, due diligence, counterparty assessment, compliance, and market transparency. However, complex ownership structures, cross-border activities, and fragmented data environments make it difficult to establish a clear and reliable view of how legal entities are connected.

The Legal Entity Identifier (LEI) addresses this challenge. While it answers the question of “who is who,” it also helps answer “who owns whom” by providing trusted and standardized information – known as Level 2 data – on the direct and ultimate parent relationships of legal entities, where applicable. This helps organizations better understand ownership structures and relationships across jurisdictions and markets. GLEIF is actively working to ensure Level 2 relationship data continues to meet these needs, and invites stakeholders to share their input through a short survey.

Relationship Transparency as a Foundation for Trust

Yet to create meaningful value across interconnected digital ecosystems, we know that organizational identity data must be interoperable, accessible, understandable, current, scalable, and easy to integrate into operational workflows. Organizations require trusted, usable data that can move seamlessly across onboarding, compliance, reporting, payment, and digital identity systems across jurisdictions and sectors.

In this context, ESMA’s broader efforts to simplify reporting frameworks and reduce duplicative reporting highlight that efficient and reusable reporting models depend on entities being uniquely and consistently identifiable across systems and jurisdictions. When trusted organizational identity data flows efficiently, it reduces friction, improves transparency, and strengthens confidence in cross-border interactions and digital ecosystems.

As an internationally recognized and standardized global Digital Public Infrastructure (DPI), the Global LEI System supports this need by providing organizational identifiers that enhance interoperability across local and national infrastructures. This helps improve transparency, reduce friction in global markets, and enable more efficient and trustworthy interactions among businesses, regulators, financial institutions, and digital platforms.

AI Increases the Importance of Trusted Data

Importantly, data must be both trusted and interoperable. As AI models and autonomous agents become more integrated into operations and decision-making, they rely on structured prompts and verifiable data for reliable outcomes. If information and data are incomplete, inaccurate, outdated, manipulated, or unavailable, automated systems can amplify misinformation, reinforce errors, or produce unreliable results at scale.

As AI-generated and legitimate information becomes harder to distinguish, transparency around data provenance is critical. This is why corroboration plays an important role within the Global LEI System.

GLEIF demonstrates how authoritative validation can help transform raw data into trusted data. By systematically validating entity reference data against authoritative sources and clearly disclosing the level of validation applied, the Global LEI System supports far greater transparency around data provenance and verification status. This helps reduce the risk of misinformation, strengthen model reliability, and support greater integrity across digital ecosystems.

Evolving the Global LEI System with the Market

As market needs continue to evolve, GLEIF and the Regulatory Oversight Committee (ROC) remain committed to aligning the Global LEI System with user needs and industry feedback. Level 2 relationship data is central to these efforts. Beyond regulatory reporting, it supports broader market transparency, improves organizational visibility, strengthens risk assessment capabilities, and enables new digital use cases.

This is why GLEIF invites stakeholders to participate in a short survey focused on enhancing Level 2 relationship data. Insights gathered through the survey will help identify where improvements can create the greatest impact, including enhancing usability, simplifying integration into workflows, strengthening interoperability, improving consistency, and better supporting evolving market needs.

Complete the survey here.


MyData

MyData Global and the MyTerms Alliance IEEE 7012/ MyTerms in Practice workshop 22nd May 2025 at CPDP Conference 2026

Iain Henderson MyTerms and Eric Pol Chairman MyData Global The IEEE 7012 standard, also known as ‘MyTerms’ for personal privacy policies was published in January 2026. It offers breakthrough thinking. […]
Iain Henderson MyTerms and Eric Pol Chairman MyData Global The IEEE 7012 standard, also known as ‘MyTerms’ for personal privacy policies was published in January 2026. It offers breakthrough thinking. […]

Why Europe must refuse the data-sharing deal with the US

6 May 2026 by Eric Pol The EU’s leadership is now on a precipice. Our push for digital sovereignty was driven by concern that the US Cloud Act might give the US […]
6 May 2026 by Eric Pol The EU’s leadership is now on a precipice. Our push for digital sovereignty was driven by concern that the US Cloud Act might give the US […]

Hyperledger Foundation

Open Standards for Tokenization: Why Interoperability Matters Now

Across financial institutions, tokenized assets are already being issued, managed, and settled in production environments. But as adoption accelerates, one gap becomes clear: there is still no common language between systems. That was the central theme of a Meetup hosted by Linux Foundation Decentralized Trust (LFDT), where Surendra Kalidindi, CTO of OpenAssets, an LFDT Premier member

Across financial institutions, tokenized assets are already being issued, managed, and settled in production environments.

But as adoption accelerates, one gap becomes clear: there is still no common language between systems.

That was the central theme of a Meetup hosted by Linux Foundation Decentralized Trust (LFDT), where Surendra Kalidindi, CTO of OpenAssets, an LFDT Premier member, joined leaders from across the ecosystem to discuss the role of open standards in scaling tokenized markets.


FIDO Alliance

FIDO Case Study: DragonSoft Security Associates Inc.

Redefining Cybersecurity Governance: From Vulnerability Detection to Identity-Based Defense 1. Describe your service/platform/product and how it’s using passkeys, based on FIDO authentication. DragonSoft is a leading provider of cybersecurity vulnerability […]

Redefining Cybersecurity Governance: From Vulnerability Detection to Identity-Based Defense

1. Describe your service/platform/product and how it’s using passkeys, based on FIDO authentication.

DragonSoft is a leading provider of cybersecurity vulnerability management and compliance governance solutions in Taiwan. We have deeply integrated FIDO2 authentication into our core governance platforms and vulnerability scanning systems.

Implementation: FIDO2-based strong authentication is mandated for accessing administrative backends, authorizing high-risk network-wide scans, and performing final compliance audits. Hardware Synergy: Through our partnership with Swissbit, we utilize passkeys stored on industrial-grade hardware security keys as a “physical vault” for privileged accounts. This ensures that critical governance tools remain under the exclusive control of authorized personnel.

2. What were the challenges you were trying to overcome?

As enterprises undergo digital transformation, DragonSoft identified several critical “trust gaps” in traditional security management:

Security Tools as Attack Roadmaps: Vulnerability platforms contain the “blueprints” of an organization’s weaknesses. If these platforms are protected only by passwords, a single phished credential allows a hacker to navigate the entire corporate network. The “Trust Black Hole” in Outsourced Maintenance: Many organizations rely on third-party vendors for system maintenance. It is historically difficult to verify whether a remote action is performed by a legitimate engineer or a malicious actor using stolen credentials. Prohibitive Compliance Costs: Under regulations like NIS2, NIST 800-207, or local cybersecurity laws, manually proving “strong authentication” for audits is labor-intensive and prone to human error.

3. Why did you choose passkeys over other options?

DragonSoft selected passkeys to shift cybersecurity from “reactive detection” to “proactive identity defense”:

Phishing-Resistant Privileged Access: Passkeys bound to a security key ensure that private keys never leave the hardware. Even if an admin’s password is leaked, the system remains inaccessible without the physical token. Hardware-Backed Non-Repudiation: In outsourcing scenarios, every command is cryptographically bound to a physical key. This provides irrefutable evidence of “who did what,” solving the legal and audit challenges of third-party management. Compliance-as-Code: Since FIDO is the gold standard for NIST 800-207 Zero Trust, our platform can automatically generate audit-ready reports, reducing compliance costs by over 50% for our clients.

4. Describe your rollout of passkeys and the impact this had on your organization.

DragonSoft has successfully deployed this integrated solution across government agencies, financial institutions, and high-tech manufacturing sectors:

Market Expansion: By integrating passkeys, DragonSoft has expanded from the IT vulnerability market into Critical Infrastructure (OT/ICS), where offline authentication via hardware keys is essential. 100% Protection Against Credential Theft: We have effectively eliminated the risk of remote account takeover for our scanning platforms. Strategic Transformation: DragonSoft has evolved from a tool provider into a Policy Decision Point (PDP) within the enterprise Zero Trust architecture.

Conclusion

“DragonSoft’s vision is to ensure that cybersecurity governance is no longer just about finding problems, but about locking down every critical decision with a physical line of defense. Through FIDO, we don’t just protect the system; we define the benchmark of trust.” 

Reference: 中華龍網 DragonSoft|資安合規管理及安全應用整合方案

Tuesday, 19. May 2026

Kantara Initiative

Publication Notice: SP 800-63B-4 Service Assessment Criteria (SAC) 

Kantara Initiative announces the formal publication of the Kantara Initiative International Assurance Program: SP 800-63B-4 Service Assessment Criteria (SAC) & Statement of Criteria Applicability (SoCA), aligned to NIST SP 800-63B […] The post Publication Notice: SP 800-63B-4 Service Assessment Criteria (SAC)  appeared first on Kantara Initiative.

Kantara Initiative announces the formal publication of the Kantara Initiative International Assurance Program: SP 800-63B-4 Service Assessment Criteria (SAC) & Statement of Criteria Applicability (SoCA), aligned to NIST SP 800-63B […]

The post Publication Notice: SP 800-63B-4 Service Assessment Criteria (SAC)  appeared first on Kantara Initiative.


Oasis Open

OASIS Launches Single Name Space Technical Committee to Standardize Universal Data Access

BOSTON, MA, 19 May 2026 — OASIS Open, the global open source and standards organization, announced the launch of the Single Name Space Technical Committee (SNS TC), bringing together a cross-industry alliance to address one of the most persistent challenges in enterprise computing: universal data access across hybrid and multi-cloud environments.  The TC plans to […] The post OASIS Launches

DDN, Guardant, IBM, Loophole Labs, and Industry Partners Unite to Develop Cross-Platform Data Management Standard

BOSTON, MA, 19 May 2026 — OASIS Open, the global open source and standards organization, announced the launch of the Single Name Space Technical Committee (SNS TC), bringing together a cross-industry alliance to address one of the most persistent challenges in enterprise computing: universal data access across hybrid and multi-cloud environments. 

The TC plans to develop a compatibility standard that enables seamless data access across all computational locations, from on-premises high-performance computing (HPC) systems to cloud-hosted services, without requiring data migration between vendor platforms.

“Fragmented data systems remain one of the most persistent challenges in workloads requiring exascale and larger data sets including research, healthcare, and artificial intelligence,” said William Baird, SNS TC co-chair. “The Single Name Space standard will establish cross-compatibility between file systems, object stores, orchestrators, and the broader storage ecosystem. By creating an open standard, we will be eliminating costly migrations, strengthening data stewardship, and unlocking innovation. Once everything is everywhere, anything can be run anywhere and with an open standard, innovation in storage can blossom from any source.”

“Interoperability standards between big data storage vendors are long overdue as we scale toward multi-petabyte and multi-exabyte datastores spanning the globe,” said Jeremy Franzen, SNS TC co-chair. “I am incredibly proud of the team we have built to develop a framework that empowers multi-vendor architectures while simultaneously minimizing operational risk and guaranteeing seamless compatibility.”

This initiative will address critical pain points faced by researchers, system administrators, data scientists, compliance officers, and others who struggle with fragmented data storage across multiple tiers, remote locations, and cloud services. By standardizing interactions, formats, behaviors, APIs, and protocols, the specification will enable vendors to create interoperable solutions where components can be swapped without data migration.

Participation is open to storage vendors, cloud service providers, HPC system manufacturers, enterprise software companies, research institutions, and anyone seeking to implement single namespace solutions. To learn more about how to get involved in this collaborative effort, contact join@oasis-open.org.

Support for the SNS TC

DDN
“Unifying globally distributed data into a single namespace is one of the hardest problems in modern AI infrastructure. The SNS standard tackles it with a specification grounded in real deployments at some of the world’s most demanding data-driven organizations and moving it into OASIS is the right next step to make this work available to the entire industry.”
– Tomer Perry, Director of Technical Strategy, DDN

Guardant
“Guardant is proud to have led the industry coalition and transition to the OASIS Technical Committee. We look forward to the draft standard becoming reality through the vendor community in cooperation with the other OASIS members.”
– Kumud Kaila, Chief Information Officer, Guardant

Additional Information
SNS Project Charter
SNS TC Homepage

Media Inquiries: communications@oasis-open.org

The post OASIS Launches Single Name Space Technical Committee to Standardize Universal Data Access appeared first on OASIS Open.


Blockchain Commons

Dispatches of a Trust Architect: Sanctuary and Exodus

On March 3, Vitalik Buterin posted a manifesto on X1. It introduced a new term: sanctuary technologies. Ten days later, the Ethereum Foundation made it official with a 38-page mandate document, which they described as “part constitution, part manifesto.”2 I noted this briefly in my recent Dispatch on Technology Paternalism, but the new mandate deserves its own treatment. When Vitalik talks about wo

On March 3, Vitalik Buterin posted a manifesto on X1. It introduced a new term: sanctuary technologies. Ten days later, the Ethereum Foundation made it official with a 38-page mandate document, which they described as “part constitution, part manifesto.”2

I noted this briefly in my recent Dispatch on Technology Paternalism, but the new mandate deserves its own treatment. When Vitalik talks about working to “preserve technological self-sovereignty” and “enable cooperation without coercion, domination or rugpulling,”3 something is happening that those of us working on Exodus Protocols, Architectures of Autonomy, and coercion-resistance lenses of Self-Sovereigh Identity should pay attention to.

This Dispatch is about what Vitalik and the Ethereum Foundation are saying, where it overlaps with what I’ve been saying, and where the work goes from here.

What Vitalik Said

Vitalik’s March 3 posting introduced the idea of sanctuary technologies:

“Ethereum should conceptualize ourselves as being part of an ecosystem building ‘sanctuary technologies’: free open-source technologies that let people live, work, talk to each other, manage risk and build wealth, and collaborate on shared goals, in a way that optimizes for robustness to outside pressures.”1

He added to that framing by talking about the creation of a collaborative space:

“Ethereum’s role is to create ‘digital space’ where different entities can cooperate and interact.”1

Instead of trying to compete with Apple or Google, his goal is “de-totalization”:

“Do not try to be Apple or Google, seeing crypto as a tech sector that enables efficiency or shininess.”1

“[instead] reduce the stakes of the war in heaven, by preventing the winner from having total victory.”1

When Vitalik announced the EF mandate on March 13, he repeated his framing, saying that Ethereum is to be “a sanctuary technology, to preserve technological self-sovereignty, to enable cooperation without coercion, domination or rugpulling,” ensuring “no single person, organization or ideology’s victory in cyberspace can be total.”3

This is not isolated to Vitalik. Bastian Aue, whose appointment as Co-Executive Director was announced in February, said it more bluntly in his own statement at the time:

“The mandate of the EF is to make sure that real permissionless infrastructure, cypherpunk at its core, is what gets built.”4

As for the mandate itself? It makes a lot of the self-sovereign ideas that Vitalik talks about in his personal posts concrete by requiring Ethereum to have the property of CROPS5: Censorship Resistance; Open Source and Free, as in Freedom; Privacy; and Security. It also emphasizes long-duration survival by highlighting a walkaway test: could Ethereum continue to function without the Ethereum Foundation?2

All together, this is a pretty big commitment to self-sovereign ideals, and one worth talking more about.

Where Sanctuary Meets Exodus

I’ve been talking about self-sovereignty since I introduced the term in “The Path to Self-Sovereign Identity”6, the principals of which I’ve been updating through the Revisiting SSI project7. Recently, I wrote about self-sovereignty from the perspective of Exodus Protocols8. I define them as “systems that free us from the control of external sources (like Google or Yahoo! or Sony) by creating infrastructure that doesn’t require infrastructure.” Bitcoin is my prime example of a working Exodus Protocol.

My discussion of freedom from external control is a good match for Vitalik’s discussion of optimization “for robustness to outside pressures.” Generally, I feel like his Sanctuary Technologies match a lot of my Exodus Protocol patterns for creating autonomous infrastructure8:

Operate Without External Dependencies. Encode Rules in Mathematics, Not Policy. Make Constraints Load-Bearing. Preserve Exit Through Portability. Work Offline and Across Time.

Vitalik’s call for “technological self-sovereignty” aligns with patterns one and two while the discussion of survivability mirrors points from patterns four and five. The CROPS priority stack reveals the reason for many of these patterns, something I discuss further in Revisiting SSI lenses such as “Coercion Resistance”, “Self-Coercion”, “Choice Architecture & Exit Rights”, and “Binding Commitments”. Vitalk even reaches for the term “tech enshittification / corposlop”1 — which is Cory Doctorow’s term that I have also used in describing why our digital infrastructure is built on sand.

I do feel like there’s one major difference, however: Sanctuary Tech is a goal while Exodus Protocols are an architecture.

Vitalik’s test for Sanctuary Tech is functional: robustness to outside pressures. By that test, his examples include Starlink, locally-running open-weight LLMs, Signal, and Community Notes.1 These are good things, and at the present moment they meaningfully expand human autonomy. But Starlink is centrally owned by a single corporation. By my Five Patterns, Starlink fails Pattern 1 (Operate Without External Dependencies) and Pattern 2 (Encode Rules in Mathematics, Not Policy). It is liberating today, but it’s not architecturally resilient against the day whoever owns it changes their mind. Similarly, Signal has a dependence on access to a cell phone with a cell number.

The EF Mandate’s test is sharper than the X post. Walkaway resistance and long-duration survival are closer to the Exodus framing. But the gap remains: Sanctuary Tech describes what we want, while Exodus Protocols describe what is needed to deliver it.

This is the same gap I’ve been working in the Architecture of Autonomy and the Revisiting SSI coercion-resistance lenses: the difference between naming a value (privacy, decentralization, sanctuary) and engineering it as a load-bearing constraint that holds when the political wind changes.

What’s the Next Step

The Ethereum Foundation has named the right goal. The work now is the architecture.

Concretely, three things would help:

1. Cross-pollinate the conversations. The identity community has spent ten years working through the failure modes of sovereignty claims, including our own. The Ethereum Foundation has spent ten years building the most credibly-neutral programmable infrastructure on the planet. The lessons translate in both directions. The work has been siloed for too long, and the Revisiting SSI initiative is one venue where that cross-pollination can happen.

2. Test Sanctuary Tech candidates against the Five Patterns. Starlink does not pass. Signal does not pass. Some Ethereum protocol-layer mechanisms, such as FOCIL for inclusion lists, encrypted-mempool proposals, and account abstraction at the right layer, plausibly do. The LEAN Ethereum roadmap and the post-quantum work the EF has named are candidates that deserve to be examined as Exodus Protocols, not merely as performance or security improvements. The Five Patterns work as a checklist.

3. Apply coercion-resistance lenses to wallet and L2 architectures. Finally, we can revisit the RSSI lenses for coercion and apply them to wallets. Though they were built for identity, they’re agnostic about which stack they analyze, and Ethereum’s wallet layer deserves the same scrutiny that we have brought to digital identity wallets. Unfortunately, we already know that many “sanctuary technology” candidates, especially wallets, currently ride on the same Apple/Google attestation infrastructures that we identified as compromised in EUDI wallets.

We are at an unusual moment. An institution with the resources, talent, and protocol surface area of the Ethereum Foundation has just declared, in writing, that it considers itself in the business of building infrastructure that can’t be taken away. That alignment with the Exodus Protocol thesis is rare. It is also fragile: the EF’s executive leadership has turned over twice in the last twelve months9, and institutional resolve in technology rarely outlasts the people who first articulated it. Wo we need to take advantage of this opportunity now.

If you are building anything you would call a Sanctuary Technology or an Exodus Protocol, I would like to talk. My Architecture of Autonomy draft is open for community comments, the Revisiting SSI lenses are open, and the Exodus Protocol patterns are public. The Ethereum Foundation has named the goal.

We must use that opportunity to build a foundation that won’t fall.

Citations

Sanctuary Technologies thread (2026). [X post]. Buterin, Vitalik. @VitalikButerin, March 3, 2026. Retrieved 2026-05-08 from: https://x.com/VitalikButerin/status/2028913738057957433

“Ethereum should conceptualize ourselves as being part of an ecosystem building ‘sanctuary technologies’: free open-source technologies that let people live, work, talk to each other, manage risk and build wealth, and collaborate on shared goals, in a way that optimizes for robustness to outside pressures.”

 ↩2 ↩3 ↩4 ↩5 ↩6 ↩7

The Promise of Ethereum: Introducing the EF Mandate (2026). [blog post and policy document]. Ethereum Foundation Board. Ethereum Foundation Blog, March 13, 2026. Retrieved 2026-05-08 from: https://blog.ethereum.org/2026/03/13/ef-mandate. PDF available at: https://ethereum.foundation/ef-mandate.pdf

“Today we are publishing the EF Mandate, a document that serves as part constitution, part manifesto, and part guide for the Ethereum Foundation. … We are here to uncapture the individual, and to entrench their freedoms of association.”

 ↩2

Mandate announcement (2026). [X post]. Buterin, Vitalik. @VitalikButerin, March 13, 2026. Retrieved 2026-05-19 from: https://x.com/VitalikButerin/status/2032469755614179700

“Ethereum is a unique object and has a unique role in the world. Its role is to be a sanctuary technology, to preserve technological self-sovereignty, to enable cooperation without coercion, domination or rugpulling, and to provide an escape hatch, to ensure that no single person, organization or ideology’s victory in cyberspace can be total.”

 ↩2

co-ED Announcement (2026). [X post]. Aue, Bastian. @aerugoettinea, February 13, 2026. Retrieved 2026-05-19 from: https://x.com/aerugoettinea/status/2022318885047779576

“The mandate of the EF is to make sure that real permissionless infrastructure, cypherpunk at its core, is what gets built.” — Bastian Aue, on his appointment as Co-Executive Director.

Core properties (CROPS) post (2026). [X post]. Buterin, Vitalik. @VitalikButerin, March 5, 2026. Retrieved 2026-05-08 from: https://x.com/VitalikButerin/status/2029662920318275935

“We should not compromise on core properties: censorship resistance, open source, privacy, security (CROPS).”

The Path to Self-Sovereign Identity (2016). [blog post]. Allen, Christopher. Life with Alacrity, April 26, 2016. Retrieved 2026-05-19 from: https://www.lifewithalacrity.com/article/the-path-to-self-soverereign-identity/

“Self-sovereign identity is the next step beyond user-centric identity and that means it begins at the same place: the user must be central to the administration of identity. That requires not just the interoperability of a user’s identity across multiple locations, with the user’s consent, but also true user control of that digital identity, creating user autonomy. To accomplish this, a self-sovereign identity must be transportable; it can’t be locked down to one site or locale.”

Revisiting SSI (2025-2026). [web site]. Retrieved 2026-05-19 from: https://revisitingssi.com/

“In the decade since their publication, SSI has evolved from a provocative idea into infrastructure deployed by governments, companies, communities, and open protocols. At the same time, the sociotechnical environment around identity has been transformed by new technologies and new platform models that challenge the assumptions of 2016.”

The Exodus Protocol (2025). [blog post]. Allen, Christopher. Life with Alacrity, October 28, 2025. Retrieved 2026-05-19 from: https://www.lifewithalacrity.com/article/musings-exodus.protocol/

“An Exodus Protocol is only successful if it’s designed to actually empower through autonomous service. We don’t want to just create a new digital prison. To design for success requires five architectural principles that help to create the architecture of autonomy itself.”

 ↩2

Ethereum Foundation co-director resigns to focus on AI (2026). [news article]. Gilbert, Aleks. DL News, February 13, 2026. Retrieved 2026-05-08 from: https://www.dlnews.com/articles/defi/ethereum-foundation-co-director-resigns/

“Tomasz Stańczak, a co-director of the Ethereum Foundation, will resign at the end of the month. … He will be replaced by Bastian Aue, a member of the Foundation’s leadership team. Hsiao-Wei Wang will remain as the Foundation’s other executive director.”

Monday, 18. May 2026

GLEIF

Getting Technical #3: Why Do You Trust the Chain?

Why do you trust a doctor who treats you at a hospital? The story behind that trust goes like this: the government accredits a university. That accredited university grants the person a medical degree. A medical licensing board, authorized by the government, reviews that degree and issues a license to practice. A hospital verifies that the license and grants the doctor privileges to perform spe

Why do you trust a doctor who treats you at a hospital?

The story behind that trust goes like this: the government accredits a university. That accredited university grants the person a medical degree. A medical licensing board, authorized by the government, reviews that degree and issues a license to practice. A hospital verifies that the license and grants the doctor privileges to perform specific procedures at that facility. Then you, the patient, trust the person in the white coat to operate on you.

The invisible trust chains that hold the world together

What you just read is a trust chain. These trust chains are ubiquitous and often go unnoticed.

Every trust chain starts with an entity at the top that everyone agrees to trust. That starting point is called a root of trust. Every link then depends on the previous one. If the university loses accreditation, the degrees it issues become questionable. If the license expires, the hospital privileges collapse. The chain breaks from the top down.

In practice, you trust the white coat. But implicitly, you are trusting that the hospital checked the license, the board checked the degree, the government checked the university, and so on. You verify the last link and assume the chain holds.

The problem with paper

While these trust chains hold civilization together, they are surprisingly fragile. They largely run on paperwork, periodic audits, and the assumption that every link was properly verified before a credential was issued. Some of that paperwork is digital now, but a signed PDF protects the document, not the chain behind it. You still cannot verify who authorized the signer, or whether that authorization still holds. Audits and human diligence at issuance will always be necessary.

But what if every link were as easy to verify as checking a green light? What if, once a credential was issued, anyone could verify the entire chain in milliseconds, without calling anyone, without chasing paperwork, without wondering if the chain still holds?

That is the problem GLEIF built the verifiable Legal Entity Identifier (vLEI) to solve.

What the vLEI does

The vLEI is a system for cryptographically verifiable organizational identity. It allows organizations and the people representing them to prove who they are in a way that any verifier can independently confirm, without relying on a central authority at the time of verification. The vLEI connects real-world organizational identity through a carefully designed chain of credentials. Each credential in the vLEI chain is issued by an entity that was itself vetted and credentialed by the level above it, forming a hierarchy rooted in a single global root of trust: GLEIF.

"Cryptographically verifiable" means that the organizational identity associated with a vLEI cannot be forged, tampered with, or denied by the party that issued it. However, it can be intentionally revoked by the issuer when circumstances change. It brings assurances unrivaled by any other method of organizational authentication.

A practical example

Consider this scenario. A company wants to sign a contract with the government for a public infrastructure project. The procurement officer needs to answer a simple question: Is the person signing this contract authorized to do so?

Let's trace the chain: a commercial registry incorporates the company. The company's board of directors passes a resolution authorizing specific officers to act on its behalf. The CEO signs the contract. But the CEO cannot be involved in every interaction on the project, so they delegate authority to the VP of Operations for the day-to-day work on this specific project. The procurement officer now must verify all of it: Does the company exist? Is the CEO the CEO? Does the VP have authority for this specific deal? Is the delegation still valid?

Today, that verification involves notarized documents, apostilles, certified translations, calls to registries, and lawyers reviewing board minutes. It can take weeks. With the vLEI, the procurement officer verifies the entire chain in seconds, cryptographically, without calling anyone.

The company's existence, the CEO's role, and the VP's delegated authority for this specific project: each becomes a verifiable credential, chained together cryptographically and traceable all the way back to GLEIF as the global root of trust. No phone calls. No paperwork. No assumptions. Just verifiable trust.

In the next article in this series, we will open the vLEI chain and walk through each link in detail: who issues what credential, to whom, and why the structure holds together.


Oasis Open

Invitation to comment on DPS TC’s Data Provenance Metadata Version 1.0 CSD01

OASIS and the DPS TC are pleased to announce that Data Provenance Metadata Version 1.0 CSD01 is now available for public review and comment.  As industry continues to prioritize data as a Core Enterprise Asset in this AI driven environment, strategy, operations, and risk management depend heavily on the integrity and governance of that data. […] The post Invitation to comment on DPS TC’s Da

Public Review Ends -- June 12th

OASIS and the DPS TC are pleased to announce that Data Provenance Metadata Version 1.0 CSD01 is now available for public review and comment. 

As industry continues to prioritize data as a Core Enterprise Asset in this AI driven environment, strategy, operations, and risk management depend heavily on the integrity and governance

of that data. This reliance has created a critical need for automation-based validation regarding data origin, quality, intended use, and lifecycle.

To address this, the DPS TC has developed the OASIS Data Provenance Standards (DPS) schema. This framework, built through extensive cross-industry collaboration and over 150 deep dives, provides a standardized way to track the origin, movement, integrity, and quality of data. The primary purpose is to ensure scalability, interoperability, and business value by fostering transparency, accountability, and oversight, thereby reducing the risk of misuse and ensuring compliance.

The TC is seeking expert feedback. During the review, please keep the TC’s core objectives in mind:

Open and Readable: Providing a framework that works seamlessly across platforms and jurisdictions. Tool-Agnostic: Ensuring the framework is flexible enough to integrate into existing workflows. Standardized Metadata: Enabling automation to facilitate faster, more informed decision-making.

The documents and all related files are available here:

Data Provenance Metadata Version 1.0

Committee Specification Draft 01

07 May 2026

https://docs.oasis-open.org/dps/prov-meta/v1.0/csd01/prov-meta-v1.0-csd01.md (Authoritative)

https://docs.oasis-open.org/dps/prov-meta/v1.0/csd01/prov-meta-v1.0-csd01.html

https://docs.oasis-open.org/dps/prov-meta/v1.0/csd01/prov-meta-v1.0-csd01.pdf

Associated Schemas: https://docs.oasis-open.org/dps/prov-meta/v1.0/schema/

You can download the ZIP file at: https://docs.oasis-open.org/dps/prov-meta/v1.0/csd01/prov-meta-v1.0-csd01.zip

How to Provide Feedback

OASIS and the DPS TC value your feedback. We solicit input from developers, users and others, whether OASIS members or not, for the sake of improving the interoperability and quality of its technical work.

The public review is now open and ends June 12, 2026 at 23:59 UTC.

Comments can be submitted directly to the following email address: technical-committee-comments@oasis-open.org

All comments submitted to OASIS are subject to the OASIS Feedback License, which ensures that the feedback you provide carries the same obligations at least as the obligations of the TC members. In connection with this public review, we call your attention to the OASIS IPR Policy [1] applicable especially  to the work of this technical committee. All members of the TC should be familiar with this document, which may create obligations regarding the disclosure and availability of a member’s patent, copyright, trademark and license rights that read on an approved OASIS specification. 

OASIS invites any persons who know of any such claims to disclose these if they may be essential to the implementation of the above specification, so that notice of them may be posted to the notice page for this TC’s work.

Additional references:

[1] https://www.oasis-open.org/policies-guidelines/ipr/

Intellectual Property Rights (IPR) Policy

The post Invitation to comment on DPS TC’s Data Provenance Metadata Version 1.0 CSD01 appeared first on OASIS Open.

Friday, 15. May 2026

DIF Blog

DIF Newsletter #61

May 2026 DIF Website | DIF Mailing Lists | Meeting Recording Archive Table of contents Decentralized Identity Foundation News About the Universal Resolver Working Group Updates Upcoming Events Get involved! Join DIF Decentralized Identity Foundation News The big news this month is chaos! Of course, we're referring to the renaming

May 2026

DIF Website | DIF Mailing Lists | Meeting Recording Archive

Table of contents Decentralized Identity Foundation News About the Universal Resolver Working Group Updates Upcoming Events Get involved! Join DIF Decentralized Identity Foundation News

The big news this month is chaos! Of course, we're referring to the renaming of Vouched's specification contribution for Agentic AI Identity, now renamed KYA-OS (formerly MCP-I). KYA-OS agentic identity can be used for any framework, so we wanted to choose a name that represents its generic applicability across different types of Agentic implementations. Read the full blog here. Version 1.0 of the KYA-OS has entered the 14-day review period before being brought to a vote in the Trusted Agentic AI Working group. Join the regular calls or add comments to the Github Repo.* The big news this month is chaos! Of course, we're referring to the renaming of Vouched's specification contribution for Agentic AI Identity, now renamed KYA-OS (formerly MCP-I). KYA-OS agentic identity can be used for any framework, so we wanted to choose a name that represents its generic applicability across different types of Agentic implementations. Read the full blog here. Version 1.0 of the KYA-OS has entered the 14-day review period before being brought to a vote in the Trusted Agentic AI Working group. Join the regular calls or add comments to the Github Repo.

Are you using DIDcomm? Together with our new member, Leadpoint System, we are conducting a survey to find out who is using DIDcomm, to create a stronger case for graduating DIDcomm to a larger SDO. (See last month's newsletter for more about the graduation strategy.) Please fill out the survey and pass it to anyone you know who is using DIDcomm.

DIF: For Humans Only DIF's Steering Committee passed a definitive change to the DIF Charter restricting membership and contributions to humans. "Though diverse, DIF is an organization of diverse humans. Membership is reserved for individual humans and organizational employers of humans. Autonomous AI agents are not allowed to join or contribute to DIF independently". The charter update clarifies that AI should be regarded as potential "inadvertent patent trolls." Until there is a way to validate that AI has not incorporated patented materials into its contribution, DIF policy has officially imposed a strict ban on the use of AI-generated contributions. Humans can use AI as an aid, but all contributions must have an individual who vouches to their conformance to DIF's "IPR" (intellectual property regime).

Hot Takes this month were hotter than ever! Check out the DIF YouTube Channel for uncensored opinions on how OAuth breaks down in complex AI environments, and what's going on in Agentic Identity in Southeast Asia. Representatives from MOSIP and FIDES discussed VC Adoption and real-world deployments at scale.

Berlin, Amsterdam, and Geneva are on the calendar! Executive Director Grace Rachmany will be speaking about trusted content at the upcoming EIC in Berlin. Grace will be holding a meet-and-greet with our members so reach out if you'll be in Berlin the week of May 18th. Grace will also be speaking on a panel at the Identity Week Europe, and DIF has a few free tickets, so respond to this e-mail if you'd like to join in Amsterdam on June 9-10.

For the upcoming "ITU Workshop on "Global interoperability for trust management of digital identity for humans and agents", both Grace and Bumblefudge will be in attendance. If you're part of Study Group 17, or would like to meet with one of us that week, reach out.

About the Universal Resolver

In early May, DIF announced that we may be shutting down the test servers for the DID Universal Resolver. The announcement resulted in two types of responses. A half a dozen people offered technical or financial support. Behind the scenes, other people asked "Is DIF having financial trouble?" (We aren't, but if you want to upgrade to Associate Member, we appreciate it.)

None of the responses indicated that someone needed the Universal Resolver for their ongoing work. On the contrary, several members have spun up their own resolvers, such as the one found at ThisDid.com. Other members told us that when they needed to test their DID method, it took them 10 minutes and a few dollars to simply spin one up themselves. In other words, we aren't sure that the public-facing open-web server is being used for the intended purpose at all, at least not by humans who read our newsletter.

When we started to host the Universal Resolver, costs were approximately $400 per month, and DanubeTech generously provided a staff member to monitor and fine-tune the deployment, as well as to review submissions of new drivers from implementers which wanted to be added. That was years ago.

Over the past 4 months, costs of hosting shot up to surpass $1000 monthly increasing at a rate of $200 per month. Why? We don't know. If nobody on our mailing list said "I need the Universal Resolver", who is using it? Agentic AI? Legacy code someone forgot to turn off? Without someone who is willing to put in 10-20 hours per month to investigate these issues, there's no way to know. What if it just keeps jumping in price by $200 each month, or jumps even faster now that AI Agents are using DIDs?

DanubeTech offered to continue to maintain it, but charge for usage costs. That's an offer that might make sense. If the demand is real, it will make income. If the demand is due to mysterious flukes, the server will wind down anyway. But even if the demand is real, it's unclear that there's a significant income stream.

At this point, a group of DIF Members have volunteered to investigate the situation and potentially take over the maintenance. But the question still remains: whom are we serving? Universal Resolver has never been intended for production. The code is still maintained in our Github repo, and it takes 20 minutes to spin up your own server. If you don't want to do that, there are now other servers you can use.

We have not yet made a final decision about the Universal Resolver, but unless it becomes clear that our members actually need it, it may just be time for it to retire. If you want to get involved in the meetings to discuss this, reach out to ed@identity.foundation. If you are using Universal Resolver on a regular basis, or it's critical, this is your last call to let us know.

Working Group Updates

DIF Members are welcome to join and participate in any working group. Most working groups meet on a weekly basis, and the most active groups have task force meetings that focus on specific work items. All public meetings are recorded and you can find all of the information on our working groups here.

Creator Assertions Working Group

The CAWG meetings have addressed key topics on how to structure different aspects of the ecosystems. The architectural debates going on in the main CAWG group and the tasks forces are lively and active, and this is an ideal time to get involved with this work. Topics under discussion just in the past month include:

Differentiating between membership credentials and authorization credentials. Content verification systems, layered authorities for verifying content, and creating verification where consumers can make choices about what authorities they trust. Content Authenticity and Governance (CAG) assertions as a way to provide governing authority backing for specific claims made on digital assets. Timestamping mechanisms for verifiable credentials Creator consent: asset consent, identity consent, and access and purpose consent. Archival quality identifiers which would ensure credentials remain valid and verifiable for extended periods. vLEIs (Verifiable Legal Entity Identifiers) and their integration into the CAWG specification. vLEIs are based on ACDC and KERI technology, using LEIs (Legal Entity Identifiers) from the Global Legal Entity Foundation (GLEIF). AI agent signatures and legal liability in jurisdictions where machine signatures may not be recognized. The need for registries, certification programs, and other formal entities within the ecosystem to provide a complete solution. Trade-offs between embedding additional information directly in assets versus using reference-bound registries for verification. Gaps in CAWG ecosystem in terms of a conformance regime based in IPTC Provenance summit: MEAN task force (music, entertainment, advertising, and news) made a very definitive statement that C2PA alone is insufficient for the creative community, and that you must implement CAWG and C2PA together to make effective use of C2PA.

👉 Learn more and get involved

Trusted AI Agents Working Group

DIF Welcomes long-time DIF member Damian Glover as the newest Co-Chair of the TAAWG working group! With the WG taking on increasing work items and task forces, this is a welcome reinforcement to our volunteer group of chairs.

This month, the TAAWG Task Forces made progress on reports and use-case documents, all of which are pinned on the respective Slack channels if you'd like to check in or follow along. The KYA-OS task force (formerly MCP-i) has been debating the pros and cons of user stories to prototype and a checklist for V1 of the spec (deferring some of the more complex and experimental features like chained delegations to a future version). The Delegated Authority task force has a working draft of their problem-space report and is divvying up the work of evaluating how well major (in production, at scale) systems measure up against that evaluative framework. Look out soon for a potential version 1.0 of the KYA-OS specification which will be open for review before it goes to the Steering Committee.

The Policy and Governance task force is not holding meetings yet, but several members are working async on multiple documents: a report on how to govern agents through a delegated-authority lens, and a design document towards prototyping a policy-bound, tightly-audited fiduciary agent to delegate to less-trusted agents more safely. Websites of novel startups, security studies, and framework/harness whitepapers continue to be shared and discussed on the Slack channels as well, making TAAWG one of the best places to keep up with the fast-paced world of agentic identity and standards development.

👉 Learn more and get involved

Hospitality and Travel Working Group

The Hospitality and Travel Working group continued to focus on expanding the use cases for the HATPro, making progress on presentation of risk profiles and guide/guidance attributes. The group discussed the need for international string support in JSON schema for HatPro, identifying it as a fundamental issue that needs to be addressed.For JSON/Schema References, the team recommended the following:

ChatGPT created a referencing mechanism using file/folder (references) based on the GitHub folder structure. The recommended approach is a URL-based mechanism (as specified in the attached document, confirmed by Google Gemini) The “Schema Hints” used to specify the references in the PlantUML model have some inconsistent/overlapping ways of specifying the JSON/Schema IDs and the references, which I discovered by manual inspection, the use case being nested references.

Steven Soe (Solutions Architect, AvenHospitality.com) has provided a very workable (experience-based) approach to how HATPro contributors and administrators work with GitHub to add and revise content, resolve issues/bugs, etc. The governance approach is now being reviewed by the working group for integration in the repository. The repository can be viewed here.

👉 Learn more and get involved

DIDComm Working Group

The DIDcomm working group discussed post-quantum resilience. Vinay presented his work on implementing a post-quantum bridge protocol for DIDComm to address security concerns about future quantum computer attacks. He demonstrated how PQBridge protocol allows peers to negotiate and upgrade to post-quantum cryptography through a hybrid approach that maintains compatibility with existing systems. Vinay also shared his development of a blockchain built on top of DIDComm that supports offline operations and aims to provide free global access to DIDs and decentralized communication. Next month's meeting will discuss the official addition of post-quantum support and cryptographic sessions.

👉 Learn more and get involved

DID Methods Working Group

The DID Methods Working Group meeting focused on two main topics: the potential discontinuation of DIF's Universal DID Resolver due to escalating AWS costs, and a deep dive presentation on the did:cid (also known as Archon) method. Grace explained that the Universal Resolver's monthly costs had increased from $600 to $1,100, leading DIF to consider alternatives including potential mergers with other resolvers or private maintenance options. The group discussed the value of maintaining the public service, with Jonathan noting its importance for the DIF recommendation process. The second portion of the meeting featured Christian and David presenting did:cid, a blockchain-based DID method that uses a gatekeeper system to manage document updates across different networks including Bitcoin and HyperSwarm, with the method supporting both agent and asset identities through a decentralized, peer-to-peer architecture. The did:cid method is the fifth DID method to formally request review as a DIF Recommended methodology, following dids ethr, webs, webplus, and webvh.

👉 Learn more and get involved

Identifiers and Discovery Working Group

The DID WebVH Working Group meeting focused on updates to the specification and implementation progress. A new Java binary will be released to Maven Central next week. The group discussed plans for the next version of the specification, including making pre-rotation required and adding post-quantum cryptography support with MLDSA algorithms. The team also explored potential changes to witness keys and discussed use cases for domain-less DID WebVH identifiers, including peer DIDs and multi-tenant wallet scenarios.

👉 Learn more and get involved

Applied Crypto Working Group

The meeting focused on reviewing open issues in the core draft specification and discussing potential changes to the selective disclosure mechanism. Vasilis proposed replacing the current index-based approach with a map structure to indicate which messages are disclosed or undisclosed, which would simplify implementations and reduce the need for validation checks. The team also discussed the importance of finalizing the core draft quickly to enable progress on related features like blind signatures and pseudonyms, particularly in light of upcoming deadlines for European standards and interest from government entities like the Government of British Columbia.

👉 Learn more and get involved

If you are interested in participating in any of the Working Groups highlighted above, or any of DIF's other Working Groups, please click join DIF.

📢 Upcoming Events European Identity and Cloud Conference (EIC)

DIF will be presenting the topic: Authenticity in the Age of AI: Building a Trust Framework for Digital Content on May 21

📅 May 19-22, 2026
📍 Berlin, Germany
Conference details

ITU Workshop on "Global interoperability for trust management of digital identity for humans and agents"

DIF will be participating in a panel on Agentic Identity

📅 June 2, 2026
📍 Geneva

Event information

Identity Week Europe 2026

DIF will be participating in the panel on verification & authentication

📅 June 9–10, 2026
📍 Amsterdam
Event information

Identiverse 2026

📅 June 15–18, 2026
📍 Las Vegas, NV
Conference details

Berlin Blockchain Week Be on the lookout for DIF people at cypherpunk and AI events

📅 June 13-21, **2026
📍 Berlin, Germany
Event information

AI for Good (ITU event)

📅 July 7-9, 2026
📍 Geneva
Event information

Dweb Camp

📅 July 8-12, 2026
📍 Alte Hölle, Germany
Event information

GDC 2026

📅 September 1-3, 2026
📍 Geneva
Event information
Tickets
DIF will be supporting applications to speak until the end of June. Tickets for DIF Members are limited, so if you register, we may ask you for more details before approving the application.

Identity Week America

📅 September 2-3, 2026
📍 Washington, DC
Event information

👉Are you a DIF member with news to share? Email us at communication@identity.foundation with details.

🆔 Join DIF!

If you would like to get in touch with us or become a member of the DIF community, please visit our website or follow our channels:

Follow us on Twitter/X

Join us on GitHub

Subscribe on YouTube

🔍

Read the DIF blog

New Member Orientations

If you are new to DIF join us for our upcoming new member orientations. Find more information on DIF’s slack or contact us at community@identity.foundation if you need more information.

Thursday, 14. May 2026

GLEIF

Who Stands Behind the Document? Why Digital Data Needs Verifiable Organizational Identity

The digitalization of paper-based processes is often heralded as progress. Yet as digital documents can be copied, altered, and redistributed in seconds, the same fundamental challenges remain. How does a recipient know which organization produced a document, whether the person who signed it had the authority to do so, and whether anything has changed since it was issued? Paper-based verificatio

The digitalization of paper-based processes is often heralded as progress. Yet as digital documents can be copied, altered, and redistributed in seconds, the same fundamental challenges remain. How does a recipient know which organization produced a document, whether the person who signed it had the authority to do so, and whether anything has changed since it was issued?

Paper-based verification processes answered these questions imperfectly and slowly, using seals, notarizations, and manual checks. As those processes move online, the imperfections remain – particularly across borders. A scanned certificate is no more verifiable than the paper it was scanned from. A digital signature attached to a PDF says very little about which legal entity issued it, who within that entity had authority to sign, or whether the credential can be accepted under a different legal system. The move to digital has changed the medium. It has not solved the problem.

When legal frameworks are not enough

Few places illustrate the cross-border trust challenge more clearly than the Greater Bay Area (GBA). Operating under one country, two systems, three customs territories, and three currencies, the GBA has no close international precedent. For organizations and individuals moving credentials, documents, and transactions across Hong Kong, Mainland China, and Macau, the fragmentation of legal and regulatory frameworks creates real friction. A document fully trusted on one side of a border may require extensive re-verification on the other side, even when the underlying facts have not changed. And although unique, GBA illustrates the broader cross-border trust problem that every globally active organization faces.

The answer to that friction is not a new bilateral agreement for each combination of legal systems. It is a shared, neutral trust standard that works the same way regardless of where a document was issued and where it is being read.

This is what the Global LEI System, maintained by GLEIF as an internationally recognized organizational identity management infrastructure and global Digital Public Infrastructure (DPI), offers. It provides the only ISO-standardized identifier for legal entities: the Legal Entity Identifier (LEI) and its digital counterpart, the verifiable LEI (vLEI).

Because the vLEI extends the globally standardized LEI into the digital domain, it builds on the Global LEI System’s open, independently governed, and regulator-endorsed infrastructure. This means a document recipient does not need to interpret the regulatory framework of the country that produced the credential before assessing whether it can be trusted. Instead, the recipient can computationally verify the organization behind the credential and the authority of the person acting on its behalf through the vLEI. This provides a consistent basis for assessing authenticity and authority across borders.

From identification to authorization

Various capabilities make the vLEI particularly well-suited to documenting trust across borders and jurisdictions. Firstly, the vLEI does more than identify an organization. It establishes who within that organization is authorized to act, and in what capacity.

Most documents require multiple parties to stand behind them: the analyst who prepared the data, the executive who approved it, and the auditor who signed off on specific sections. Today, those distinctions cannot be expressed digitally as traditional systems either sign the whole document or none of it. An auditor who can certify the financial data in a report but not the cover design has no mechanism to limit their signature to the sections they actually reviewed.

The vLEI enables that hierarchy to be represented digitally and cryptographically. Specific sections of a document can be attributed to specific authorized roles, each traceable back to the organization’s verified identity. This is more precise and legally defensible than a paper seal, because each signature carries cryptographic proof that the signer held a verified role within a verified organization at the time of signing.

One answer to many different questions

Secondly, as the underlying trust layer is public infrastructure – not a proprietary system built for a single sector or institution – the vLEI can provide a consistent mechanism for verifying document trust across any sector, use case, or jurisdiction.

Despite the universal need for trust in documents – whether it be degrees and diplomas, medical results, supplier certifications, or legal evidence – only partial solutions exist. As these comprise manual checks, institutional trust relationships, and sector-specific digital signature frameworks, none work consistently across sectors or borders, as the recipient must understand the specific system the sender used. This is why a hospital in Hong Kong cannot easily verify a discharge summary issued under a different country’s health system.

In contrast, the vLEI means the same trust infrastructure that enables a Hong Kong hospital to verify a discharge summary can also be used to confirm that a university in Mainland China signed a degree, or that a CFO authorized a regulatory filing in Macau. Because the verification mechanism is consistent, recipients across sectors and regulatory environments can check the credential without needing to understand the institutional context or legal framework that produced it.

When trust is built into the data

Finally, the vLEI enables organizational identity to be cryptographically embedded in data – meaning verification is built into the credential itself, not outsourced to manual checks on the receiving end.

This is important because, today, trust in a document depends on someone making a judgment: Does this seal look authentic? Is the signature legitimate? Does this certificate match the records? In a world where AI can now generate convincing documents and credentials, and where the volume of cross-border data exchanges makes manual review impractical, that judgment will become even less reliable and scalable.

The vLEI enables the shift away from human-dependent verification to computationally verifiable trust. In fact, trust becomes a property of the document itself, which any system can check instantly, without manual handling or risk of human error. By removing the verification burden, cross-border commerce, regulatory reporting, and digital data exchanges become faster and more efficient.

How that shift is being realized in practice, across academic credentials, healthcare records, ESG disclosures, and cross-border dispute resolution, was at the heart of my recent Trust Talks conversation with Eva Chan, CEO and Founder of Certizen Technology.

We explored why the GBA has become a test case for cross-border digital trust infrastructure, how the vLEI is being applied to make organizational authorization verifiable at the level of individual document sections, and what it means for trust to be built directly into data rather than assessed after the fact.

Listen to the full Trust Talks episode to explore how verifiable organizational identity is being applied across industries in the GBA and beyond, and why the question of who stands behind digital data is becoming central to how trust works in the global digital economy.


FIDO Alliance

The AI Journal: Agentic Commerce: The $1.5 Trillion Infrastructure Race and Why Fintech Startups Must Move Now

Commerce is undergoing its most fundamental transformation since the invention of the credit card. For thirty years, digital payments followed a simple logic: a human decides, a human clicks, a […]

Commerce is undergoing its most fundamental transformation since the invention of the credit card. For thirty years, digital payments followed a simple logic: a human decides, a human clicks, a human pays. That model is ending.

In its place, a new paradigm is emerging — one where AI agents browse, compare, negotiate, and settle transactions autonomously, often without a human ever entering the loop. This is agentic commerce: the infrastructure of machine-to-machine payments, executing at the speed of code, at the scale of the internet.

The rails are being built right now. Mastercard, Visa, Stripe, J.P. Morgan, and Santander have each launched dedicated programs. Open standards are being published. The first real-world transactions have already cleared. The question is no longer whether agentic commerce will happen — it is who will build the services on top of this new infrastructure, and from which jurisdiction.

This article is for fintech founders who want the answer to that question.


Identity Week: Amazon shares data on their customer passkey adoption

Amazon is sharing new data to suggest passkeys are in favour with 465 million customers now, ensuring expedited, secure authentication six times quicker than traditional passwords. Passkeys achieve an enhanced […]

Amazon is sharing new data to suggest passkeys are in favour with 465 million customers now, ensuring expedited, secure authentication six times quicker than traditional passwords.

Passkeys achieve an enhanced customer experience and impenetrable security, overtaking the cumbersome use of passwords which likely don’t suit sign-in for the multiple marketplaces that Amazon has. Customers sign in with a fingerprint, face scan, or device PIN, the same way they unlock their phone.

Stephen Schmidt, Senior Vice President and Chief Security Officer at Amazon, said the “changes in authentication security” over the last 10 years are due to customers having the final say on passkeys rapidly transforming their user experience, more than security, although the improvement to account security is undeniably proven.

“The challenge with security has always been the trade-off. Stronger security usually means a worse experience for the customer. Better usability usually means weaker protections. Passkeys break that pattern”.

Amazon has adopted passkeys as the default sign-up method for their customers, and many other e-commerce marketplaces have followed in a coordinated effort across the industry. The FIDO Alliance, who members worked in collaboration with Amazon, also reports five billion passkeys in use and the industry collaboration it takes to build, deploy and navigate passkeys in practice.

Not only achieving security, they are proud of the 75% year-on-year growth of this model from the start of 2026.


AI Invest Official: Singapore Passkey Adoption Hits 5 Billion Amid Rising Demand for Secure Authentication

Singapore has reached a milestone of 5 billion passkeys in use worldwide, as reported by the FIDO Alliance. The adoption of passkeys has been driven by a shift away from […]

Singapore has reached a milestone of 5 billion passkeys in use worldwide, as reported by the FIDO Alliance. The adoption of passkeys has been driven by a shift away from passwords, with 80% of people in Singapore aware of passkeys and 65% having enabled one on at least one account. The data also reveals the scale of the damage caused by passwords, with one in seven Singapore consumers experiencing an account compromise or breach notification in the past year. The industry is now addressing the challenges highlighted in the data at Authenticate APAC 2026 in Singapore.

Singapore has reached a significant milestone in digital authentication, with an estimated 5 billion passkeys now in active use globally, according to the FIDO Alliance. This development marks a major shift away from traditional password-based authentication, driven by growing awareness and adoption of passkey technology. In Singapore, 80% of individuals are aware of passkeys, and 65% have enabled one on at least one account according to FIDO Alliance data. These figures reflect broader global trends, where 90% of people are now aware of passkeys, and 75% have enabled at least one as reported by FIDO Alliance.

Wednesday, 13. May 2026

Digital ID for Canadians

Spotlight on GLEIF

1. What is the mission and vision of GLEIF? GLEIF’s vision is one verifiable, trusted, global identity behind every business. Its mission is to empower…

1. What is the mission and vision of GLEIF?

GLEIF’s vision is one verifiable, trusted, global identity behind every business. Its mission is to empower global trust and transparency through open, digital, and reliable organizational identity services.

GLEIF advances this mission through the Legal Entity Identifier (LEI) and its digital counterpart, the verifiable LEI (vLEI). The LEI is a globally standardized code that enables clear and unique identification of legal entities. The vLEI extends verified organizational identity into the digital domain, enabling counterparties to computationally verify the identity, authority, and role of a person acting on behalf of a legal entity.

Together, the LEI and vLEI support more trusted, efficient, and interoperable business relationships across borders, sectors, and digital ecosystems.

2. Why is trustworthy digital identity critical for existing and emerging markets?

Digital trust depends on knowing which organization is involved in a transaction, relationship, or exchange of information. As business becomes more digital and cross-border, organizations need reliable ways to identify legal entities, counterparties, suppliers, customers, and authorized representatives.

In established markets, trusted organizational identity can reduce friction in compliance, onboarding, payments, reporting, and supply chain due diligence. In emerging markets, it can help organizations demonstrate their legitimacy, access services, and participate more confidently in global commerce.

The LEI and vLEI provide a standardized foundation for this trust. They make organizational identity data more consistent, transparent, and reusable across systems and jurisdictions.

3. How will digital identity transform the Canadian and global economy? How does your organization address challenges associated with this transformation?

Digital trust and identity verification can help economies operate with greater confidence by reducing uncertainty about who organizations are, who owns them, and who is authorized to act on their behalf. This is relevant across financial services, payments, supply chains, digital credentials, regulatory reporting, and cross-border trade.

GLEIF addresses these challenges by maintaining and advancing the Global LEI System, an internationally recognized infrastructure for organizational identity. The Global LEI Index makes standardized legal entity reference data openly available, while the vLEI brings verified organizational identity into digital workflows.

This helps create a common identity layer that can be used across sectors and jurisdictions, rather than relying on fragmented, organization-specific approaches.

4. What role does Canada have to play as a leader in this space?

Canada has an opportunity to show how public and private sector collaboration can support trusted, interoperable digital identity ecosystems. Through organizations such as DIACC, Canada is convening the policy, standards, certification, and implementation discussions needed to make digital trust practical and widely adopted.

From GLEIF’s perspective, Canada can play a strong role by aligning domestic digital trust initiatives with globally interoperable standards. This is especially important for organizational identity, where businesses, regulators, and service providers need trusted identity information that works across borders.

By connecting Canadian digital trust initiatives with global identity infrastructure such as the LEI and vLEI, Canada can support services that are locally relevant and internationally interoperable.

5. Why did your organization join the DIACC?

GLEIF joined DIACC to contribute to Canada’s digital trust and identity verification ecosystem and to learn from the organizations shaping it. DIACC brings together public and private sector leaders working on practical frameworks, certification, and adoption pathways for trusted digital services.

As digital wallets, credentials, authentication services, and verification tools continue to develop, they need a reliable organizational identity layer. The LEI and vLEI are designed to support that need.

By joining DIACC as a Sustaining Member, GLEIF aims to support trusted, interoperable organizational identity in Canada and contribute global expertise from the LEI and vLEI ecosystems.

6. What else should we know about your organization?

The Global Legal Entity Identifier Foundation (GLEIF) is a not-for-profit organization established by the Financial Stability Board in June 2014. GLEIF supports the implementation and use of the Legal Entity Identifier and the verifiable LEI to advance trusted organizational identity worldwide.

The LEI is used globally to provide clear and unique identification of legal entities. In Q1 2026, the active LEI population surpassed 3 million, reflecting growing demand for standardized organizational identity across sectors and regions. GLEIF is also advancing the vLEI as a digital credential for organizational identity, with ISO 17442-3 published in 2024 to standardize vLEIs across the global LEI ecosystem.


Hyperledger Foundation

Developer Showcase Series: Alexander Shenshin, Software Architect, DSR Corporation

Back to our Developer Showcase Series to learn what developers in the real world are doing with LF Decentralized Trust (LFDT) technologies. Next up is Alexander Shenshin, Software Architect at DSR Corporation.

Back to our Developer Showcase Series to learn what developers in the real world are doing with LF Decentralized Trust (LFDT) technologies. Next up is Alexander Shenshin, Software Architect at DSR Corporation.


Next Level Supply Chain Podcast with GS1

Seasoned from the Start: Spice Sourcing, Tariffs, and Trust-Based Farming at Burlap & Barrel

Most people don't think twice about the spice jar on their shelf. But behind it is a supply chain that can pass through 20 different hands — and that's exactly where quality, safety, and accountability break down. In this episode, Reid Jackson and Liz Sertl speak with Ori Zohar, co-founder and co-CEO of Burlap & Barrel, about how they're reshaping the spice industry by sourcing directly from

Most people don't think twice about the spice jar on their shelf. But behind it is a supply chain that can pass through 20 different hands — and that's exactly where quality, safety, and accountability break down.

In this episode, Reid Jackson and Liz Sertl speak with Ori Zohar, co-founder and co-CEO of Burlap & Barrel, about how they're reshaping the spice industry by sourcing directly from smallholder farmers across 22 countries. Ori shares how Burlap & Barrel built a transparent, trust-based supply chain — no formal contracts, just long-term relationships — and how that model has helped them navigate real-world pressures like the pandemic, tariffs, and rapid scaling. He also gets into the operational side: how GS1 Standards and barcoding became foundational tools for managing a 100+ SKU business across warehouses, retail, and direct-to-consumer channels.

This is a story about innovation, transparency, and the power of human relationships in building a sustainable supply chain.

In this episode, you'll learn:

Why trust-based relationships with farmers outperform formal contracts

How they responded to tariffs — without raising prices or passing costs to farmers

The practical role GS1 standards play in managing a high-SKU, multi-channel business

Things to listen for: (00:00) Introducing Next Level Supply Chain (07:13) Third-wave spices and why a broad lineup demands better tracking (09:44) The Dr. Salunke story: transparency and traceability in action (13:23) Why contracts with farmers don't work (19:11) How to handle tariffs without raising prices (31:55) Navigating turbulence with a values-first strategy (32:36) How GS1 standards power their warehouse and retail operations

Connect with GS1 US: Our website - www.gs1us.orgGS1 US on LinkedIn Register for GS1 Connect 2026, happening June 9 to 11 in Las Vegas, and get 10% off with the promo code GS1USPOD10 at connect.gs1us.org.

Connect with the guest: Ori Zohar on LinkedInVisit Burlap & Barrel at https://www.burlapandbarrel.com/ Follow Burlap & Barrel on Instagram

Tuesday, 12. May 2026

Hyperledger Foundation

How Australian Payments Plus Used Hiero to Bridge Stablecoins and Central Bank Digital Currency

Read the full case study here.

Read the full case study here.


Energy Web

Energy Web implements continuous live verification for the Sustainable Aviation Fuel (SAFc)…

Energy Web implements continuous live verification for the Sustainable Aviation Fuel (SAFc) Registry. When Energy Web launched the SAFc Registry two years ago alongside Rocky Mountain Institute (RMI), Environmental Defense Fund (EDF), and the Sustainable Aviation Buyers Alliance (SABA), our goal was ambitious but clear: create a trusted, market-ready book-and-claim platform. It aims to unlock cor
Energy Web implements continuous live verification for the Sustainable Aviation Fuel (SAFc) Registry.

When Energy Web launched the SAFc Registry two years ago alongside Rocky Mountain Institute (RMI), Environmental Defense Fund (EDF), and the Sustainable Aviation Buyers Alliance (SABA), our goal was ambitious but clear: create a trusted, market-ready book-and-claim platform. It aims to unlock corporate demand and meaningfully accelerate the production and use of sustainable aviation fuel (SAF).

Energy Web’s cutting-edge technology powers the SAFc Registry, enabling SAF producers to issue SAF certificates (SAFc) — the decoupled environmental attributes of low-emissions aviation fuel — and transfer them to corporate customers, who rely on aviation for business travel or transporting goods, and airlines who purchase SAFc to address emissions from their operations for corporate reporting.

Translating progressive policies into a transparent governance framework and a user-friendly interface, while leveraging blockchain’s potent provenance, automation and security functionalities, has yielded remarkable results:

Over 150,000 tonnes of SAFc have been issued to date, which is equivalent to more than 2,000 New York to London flights using sustainable fuel. Over 500,000 tonnes of CO2 have been abated, comparable to the annual emissions of driving nearly 2 billion kilometers in an average gasoline car. Over a hundred corporate customers — from the world’s largest multinationals to emerging climate entrepreneurs — use the Registry to reduce their emissions. The Registry counts an increasing number of airlines, fuel producers, and logistics partners among its active participants, demonstrating broad adoption across the SAF value chain. Retirements continue to grow quarter over quarter, with increasingly diverse beneficiaries.

These milestones are proof of a rapidly maturing SAF ecosystem. They signal a community willing to invest and collaborate to innovate and advance SAFc as a strategic lever in global decarbonization programs.

Figure 1: Sustainable Aviation Fuel Certificates Monthly Issuance, September 2024-December 2025

A key advantage of the SAFc Registry is its nimble policy approach, guided by an active and knowledgeable governing body representing producers, airlines, corporate buyers, non-governmental organisations, and technical experts. Over the last year, registry policies were expanded to recognize and incorporate more high-quality SAF, by ensuring neutrality across production pathways, certification schemes, and standards-setting bodies. On the technology side, Energy Web’s development team has implemented steady upgrades to integrate customer preferences and feedback. Improvements to the user interface, data structures, reporting tools, and API have rendered the Registry faster, more intuitive and scalable. Today we’re delighted to share the next step in this journey: enabling unprecedented levels of transparency in certificate markets with Energy Web’s groundbreaking solution called Verified Compute Cloud.

The Challenge: Enhancing Trust in Sustainability Reporting

A platform like the SAFc Registry asks users to trust that each certificate represents a unique event with a measurable climate impact: the use of a bona fide low-carbon asset by a real person or company at a specific location and moment in time, creating real emissions savings. Doubts about any aspect of this claim undermine the value of the certificate. A 2023 study by PwC revealed 94% of investors believe corporate reporting on sustainability performance contains unsupported claims.

The Solution: Energy Web Verified Compute Cloud

Advanced book-and-claim platforms like the SAFc Registry build customer confidence in certificate integrity through transparent procedures and by deploying blockchain to automate major parts of the process, track the value chain, and preclude database tampering. However, concerns remain about the reliability of underlying data inputs, and the complexity of registry operations hampers easy monitoring. This is where Verified Compute Cloud comes in, a high-impact tool to boost certificate integrity and stakeholder confidence by exploiting another blockchain functionality: abstracting complexity. Verified Compute Cloud uses distributed, blockchain-secured computation to eliminate the “black boxes” that exist within registries, conducting checks and validations on critical operations like certificate issuance, transfer, and retirement. Unlike the traditional annual, limited sample-based audits, these data and logic assessments are automated and continuous, running 24/7 to flag potential concerns with certificate quality in real-time and de-risk procurement.

Importantly, these validations are also publicly visible, enabling easy monitoring through the intuitive Verified Compute Cloud Data Explorer, which shows the full history scan of validations for any certificate. With Verified Compute Cloud, companies can tell the complete story of any emissions reduction claim. Imagine if sustainability report filings stopped being dry, static PDF files, and instead became interactive reports allowing users to to trace climate impact all the way downstream to an airline ticket. Readers could see the exact moment in time when an emissions claim originated, view proof that carbon savings haven’t been double counted, and validate the certificate retirement and claiming processes. This is the future we’re unlocking with Verified Compute: a new paradigm for customer confidence and corporate sustainability.

How it Works: Your Cloud with Your Logic

Verified Compute Cloud can be integrated into any book-and-claim registry in two steps. First, the registry management defines a list of data inputs and internal computations to be verified. Using the Energy Web Marketplace, they then register their solution with a defined verification scope and select a number of distributed verifiers. These are an independent, distributed network of computers (“nodes”) termed Verified Compute Cloud Operators that validate data and execute computations in parallel to the Registry Administrator. When these nodes reach consensus on the accuracy of a registry operation, this attestation is logged on the EWX blockchain, creating a digital audit trail that is viewable in the Verified Compute Cloud Data Explorer. The explorer may be public (revealing results while not disclosing sensitive private data) or private to registry administrators, as preferred.

To reduce any currency volatility related to payments while benefiting from smart contract service automation, Verified Compute Cloud Operators are compensated for their verification service in a stablecoin like USDC. These node operators can be legal entities or individuals — the choice is open to clients procuring the computing service. To ensure accountability, they stake Energy Web Token (EWT), EWX’s native token, and in case they malperform, this stake is “slashed”, or forfeited in whole or part. This carrot-and-stick mechanism facilitates a performance assurance for this decentralised digital service. Additional network and solution security is provided by small participants who are given an opportunity to support real-life decarbonisation by staking their EWT. Importantly, this distributed computation service can be performed on encrypted data, further preserving data privacy and integrity.

While Verified Compute Cloud includes several underlying, advanced technical components, the experience for registries is as simple as setting up and contracting for any other standard cloud service.

Verified Compute Cloud Pilot Use Case: Live Audit of the SAFc Registry

Energy Web Verified Compute Cloud is piloted through the SAFc Registry Verified Data Explorer, allowing the public to validate whether critical steps in the certificate retirement process have been executed correctly. This live, continuous audit empowers registry users and environmentally engaged citizens to answer the following questions based on independently verified information:

Calculating Impact: How many tonnes of CO2e are abated by this certificate? What reduction in emissions does the underlying SAF represent, relative to conventional jet fuel? Preventing Duplicate Claims: Has this certificate been previously claimed in the registry? Confirming Rulebook Compliance: Does this certificate retirement have a valid beneficiary type, claim year, and disclosed production and blending dates? Is the retirement date valid? Figure 2: Sustainable Aviation Fuel Registry Verified Data Explorer, powered by Energy Web Verified Compute Cloud, https://verify.safcregistry.org

We invite anyone interested in how the registry operates to explore these validations at verify.safcregistry.org — click here to learn more!

Energy Web Verified Compute Cloud can enhance the integrity of sustainability claims for any type of commodity or service, including freight and transport services, low-carbon commodities like steel and concrete, digital assets, or electricity. Today, as we celebrate the achievements of the SAFc Registry with our partners, we also look forward to extending this solution to accelerate decarbonisation in other domains.

Energy Web implements continuous live verification for the Sustainable Aviation Fuel (SAFc)… was originally published in Energy Web on Medium, where people are continuing the conversation by highlighting and responding to this story.

Monday, 11. May 2026

DIF Blog

DIDcomm: Tell DIF about Your Implementation

Fill out this survey if you are using DIDcomm DIDComm is one of the earlier protocols developed in DIF, designed to enable trusted interactions between parties. The main difference between DIDcomm and other protocols is that it allows communication without the need for the interacting parties to maintain persistent knowledge
Fill out this survey if you are using DIDcomm

DIDComm is one of the earlier protocols developed in DIF, designed to enable trusted interactions between parties. The main difference between DIDcomm and other protocols is that it allows communication without the need for the interacting parties to maintain persistent knowledge of one another. Just as you can send all kinds of file if you know someone’s email address, DIDs allow both humans and machines to send diverse data types across any transport layer.

For many privacy-preserving applications, DIDComm is the only suitable protocol for decentralized interaction.  

Leadpoint System, one of DIF’s newest members, has identified the visibility gap of DIDcomm. “We believe that widespread adoption of DID Comm V2 is a critical driver for future interoperability, enabling seamless partnerships and technical synergy between companies in the global decentralized identity space,” said Rinat Bibikov, Fullstack Software Engineer at Leadpoint System.

To address this gap, Leadpoint and DIF are partnering to gather a database of implementations of DIDcomm, to create a strong foundation for more widespread adoption and better industry alignment. 

If you are using DIDcomm today, please fill in this 5-minute survey.

“DIDcomm is in much wider use that we have documented to date,” said Grace Rachmany, Executive Director of the Decentralized Identity Foundation. “Having Leadpoint spearhead this effort will allow DIF to consider the next steps in getting international standards recognition of DIDcomm.

Fill in the survey here. 

Please spread the word to any developers or architects in your network using DIDComm. The survey takes only a few minutes, and all participants can opt-in to receive an exclusive copy of final results and market insights. 

Friday, 08. May 2026

Project VRM

Other Looks

Last month, Devon Loffreto shared some takes on how this website might look with some big tweaks. Check ’em out: One post. On MyTerms. I think they’re brilliant. We do need a refresh, and I’ve been working with our friends at WordPress on that. The main constraint is that we need to base the site […]

One possible header.

Last month, Devon Loffreto shared some takes on how this website might look with some big tweaks. Check ’em out:

One post.

On MyTerms.

I think they’re brilliant.

We do need a refresh, and I’ve been working with our friends at WordPress on that. The main constraint is that we need to base the site on a WordPress theme of some kind. I invite suggestions.

Thursday, 07. May 2026

FIDO Alliance

Across the Passkey Landscape: Expert AMA

WEBINAR | Across the Passkey Landscape: Expert AMA Attendees celebrated World Passkey Day with FIDO Alliance in a dynamic, interactive AMA-style webinar on May 7. This special session brought together […]

WEBINAR | Across the Passkey Landscape: Expert AMA

Attendees celebrated World Passkey Day with FIDO Alliance in a dynamic, interactive AMA-style webinar on May 7.

This special session brought together leading voices from across the passkey ecosystem – including a passkey architect, a technical implementation expert, an enterprise adopter who has rolled out passkeys to employees, and a UX specialist focused on user-friendly authentication.

Speakers:

Tim Cappalli, Sr. Standards Architect, Okta An Ho, Technical Development Manager, IBM Megan Shamas, CMO, FIDO Alliance (moderator) Philip Corriceau, Head of UX, RSA Security Nishant Kaushik, CTO, FIDO Alliance

GLEIF

Transforming Data into Opportunities: Metric in Motion – GLEIF AI

The ability to access and trust high-quality organizational data enables better decision-making across the global economy. This is why GLEIF publishes a wide range of trusted information, from the Global LEI Index, statistics, and reports to governance policies, news, and more. However, because information spans APIs, databases, documents, and web pages, navigating these different entry points

The ability to access and trust high-quality organizational data enables better decision-making across the global economy. This is why GLEIF publishes a wide range of trusted information, from the Global LEI Index, statistics, and reports to governance policies, news, and more.

However, because information spans APIs, databases, documents, and web pages, navigating these different entry points can be difficult and time-consuming for some users seeking a quick, reliable answer.

This challenge – and the opportunity to make GLEIF’s trusted information more accessible to external AI solutions – motivated the development of GLEIF AI Search. The new capability transforms the way users interact with complex, distributed data by combining conversational interfaces with a structured retrieval pipeline to streamline discovery and improve accessibility.

It also places trust at the center, delivering clear, well-sourced answers that users can rely on. Insights from a recent poll show that users trust AI-generated answers most when they are based on high-quality underlying data, supported by transparent source citation, and include clear explanations. This reinforces the importance of GLEIF’s role in providing reliable, well-structured data that can support trustworthy AI-enabled discovery.

This echoes a theme explored in GLEIF’s Metric in Motion blog on corroboration. In an AI-enabled digital economy, trust depends not only on access to data, but also on knowing where that data comes from, how it has been validated, and whether it can be traced back to authoritative references. GLEIF AI Search applies this principle to information discovery, helping users move from fragmented information to answers that are easier to understand, verify, and use.

How it works

GLEIF AI Search is a coordinated system of three core layers working seamlessly together:

Chat Interface:

The chat interface is the user-facing layer of GLEIF AI Search. It provides a clean, intuitive, and conversational way for users to engage naturally with the system and choose from different assistant modes: Smart, Website & Docs, News & Updates, Data & Statistics, and LEI Records. Each mode is tailored to a specific type of query or task, ensuring that interactions feel both guided and adaptable, depending on the user’s intent.

Orchestration Layer:

Behind the user interface is the orchestration layer, which processes each user query. It activates the selected assistant mode, routes the request to a large language model, and coordinates the necessary tools to retrieve and verify relevant information before providing a response.

Crucially, this layer does not operate in isolation. It dynamically helps ensure that answers are not produced by the model alone but are informed by relevant data, documents, and web content from various connectors. This coordination transforms model output into context-aware, reliable answers.

Connectors (MCP Servers):

The connectors form the bridge between the orchestration layer and the underlying data and content sources. Implemented as MCP (Model Context Protocol) servers, these connectors enable the system to access and interact with external sources in a structured, reusable way. They ensure that the GLEIF AI Search is not limited to static knowledge and can use current, relevant information from GLEIF data, APIs, documents, and web content. The connectors currently available are:

Web Search and Fetch: Enables the AI to search, retrieve, and process content from the GLEIF website (gleif.org). This supports questions about GLEIF’s activities, news, governance, and general information.

Document Search: Links to a vector-based search system built over a collection of official GLEIF documents, such as policy papers and governance frameworks. When a question pertains to content in these documents, the AI can search them and cite relevant passages.

GLEIF API Connector: Integrates directly with the official public GLEIF API, providing real-time access to the Global LEI Index. This allows the AI to look up individual entities by their LEI, search for entities by name, and retrieve detailed registration information and relationship data.

LEI Statistics Connector: Links to aggregated statistics related to the Global LEI System. It enables the system to query structured analytical data such as the number of active LEIs by country, issuance trends over time, growth rates, and distributions across entity types or jurisdictions.

Importantly, these MCP servers are designed to be modular, reusable, and interoperable. They can also be integrated into external AI environments such as ChatGPT, Claude, and others. GLEIF has already defined skills based on these capabilities and made them available on the GLEIF webpage. Looking ahead, GLEIF plans to expand the number of available connectors by adding more MCP servers, further extending the system’s capabilities, and addressing a wider range of user needs.

The benefits of GLEIF AI

GLEIF AI Search and its related connectors are designed to make LEI and GLEIF information easier to access, understand, and use – delivering significant benefits to global data users:

Improved access to trusted data: Helps users explore LEI data, statistics, reports, governance documents, and other GLEIF content through a conversational interface, instead of navigating multiple systems separately. Comprehensive insights: Retrieves and combines information from APIs, databases, documents, and websites to provide more complete and well-rounded answers. Transparent and verifiable responses: Supports clear source attribution and explanation, helping users understand where an answer comes from and how far it can be relied upon. Clearer summaries: Converts complex or lengthy information into concise, human-readable responses. Support for decision-making: Provides reliable and well-sourced answers that can help users find information more efficiently and act with greater confidence. Broader usability: Lowers the barrier to entry, enabling both experts and non-experts to interact with and benefit from LEI data.

Harnessing the potential of AI search

As AI-powered search continues to evolve, its true value will be defined by more than speed or convenience. What matters is the ability to consistently deliver answers grounded in reliable, transparently sourced data and contextually relevant.

GLEIF AI Search illustrates how combining trusted data with intelligent retrieval mechanisms can realize these requirements, making complex information easier to access and use. By connecting user questions to official data, documents, and web content, it turns distributed information into answers that are easier to understand, verify, and act on – reinforcing reliability and data integrity as fundamental pillars of digital innovation.

Looking ahead, this approach can support broader use of GLEIF data across different AI environments. By making information more accessible, transparent, and verifiable, GLEIF AI Search can help strengthen trust in digital systems and support more informed decision-making.


FIDO Alliance

Five Billion Passkeys: A Milestone, Not a Finish Line

Megan Shamas, CMO, FIDO Alliance On World Passkey Day 2026, we are announcing that an estimated 5 billion passkeys are now in active use worldwide. A decade ago, that scale […]

Megan Shamas, CMO, FIDO Alliance

On World Passkey Day 2026, we are announcing that an estimated 5 billion passkeys are now in active use worldwide.

A decade ago, that scale would have been hard to imagine. In 2016, there were just over 100 FIDO Certified products, limited platform support, and only a small number of deployments. “Passkeys” was not a term we used, and moving beyond passwords at internet scale was still an open question.

That shift, from limited support to billions of real-world uses, is what progress looks like.

We published the State of Passkeys 2026 report today to assess that progress and what we need to do to grow adoption to an even broader scale.

Awareness has reached 90% globally. 75% of people have enabled at least one passkey. Nearly half the world’s population, 49%, use them whenever they can or most of the time. In the workforce, a growing share of organizations are either live or actively rolling out passkeys for employee sign-ins.

Passkeys are no longer emerging. They are being used at scale.

This progress reflects sustained work across the FIDO Alliance and its global community. Together, the FIDO ecosystem has built standards, published implementation and UX guidance, and shared data and what works in practice. Platform providers and credential managers have expanded support and improved the experience. Vendors have innovated around the specifications, and relying parties have contributed data and results that help others move faster. That industry commitment made passkeys viable.

The report also highlights where gaps remain. Passwords are no longer the best available option, but they are still the most widely used. Nearly half of consumers have abandoned a purchase because they could not remember a password. 57% of organizations still rely on password-based methods as the primary way employees sign in.

Closing these gaps is the next phase, building on the enablement and user experience work that has driven progress so far, and now focusing it more precisely based on what the data and deployments are showing.

For consumer services, we have learned that deployment is not the end state. Many relying parties see strong initial uptake but need clearer guidance to drive sustained, everyday usage through UX patterns, messaging, and ongoing optimization. Getting from enabled to default behavior is the next challenge, and our focus is helping relying parties scale usage after deployment.

In the enterprise, the need is more practical. As deployment expands, organizations are looking for clear implementation guidance on how to roll out across environments, manage devices and recovery, and ensure employees use passkeys in daily sign-ins. Getting from rollout to habitual use remains a work in progress, and our focus is providing more concrete implementation guidance across these areas.

The next enablement phase is clear: scaling usage after deployment and making passkeys the default way people sign in.

Five billion passkeys in use reflects years of coordinated effort across the industry to build, deploy, and improve how passkeys work in practice. On World Passkey Day, this milestone belongs to the entire community that has made passkeys a reality at global scale.


FIDO Alliance Reports Accelerating Global Passkey Adoption on World Passkey Day 2026

Global research from the FIDO Alliance finds near-universal awareness of passkeys, with high adoption rates among consumers and enterprises MOUNTAIN VIEW, Calif., May 7, 2026 – On World Passkey Day […]

Global research from the FIDO Alliance finds near-universal awareness of passkeys, with high adoption rates among consumers and enterprises

MOUNTAIN VIEW, Calif., May 7, 2026 – On World Passkey Day 2026, the FIDO Alliance released new findings from its State of Passkeys 2026 report, highlighting strong global adoption and usage of passkeys across both consumer and enterprise environments.The findings come as the FIDO Alliance estimates that 5 billion passkeys are now in use worldwide.

Based on research spanning 11,000 consumers and 1,400 enterprise decision-makers across ten countries, the report highlights the global uptake of passkeys:

90% of people are now aware of passkeys, up significantly year-over-year 75% of people have enabled a passkey on at least one account 49% of people use passkeys regularly when available  68% of organizations have deployed or are actively deploying passkeys for employee sign-ins 82% say fully passwordless authentication is an ultimate goal within the workforce, with 28% having achieved this goal

This growth reflects a clear and shared demand for sign-in experiences that are simple, secure, and trusted. It has been driven by coordinated efforts across the FIDO ecosystem to develop open standards, publish best practices, and lead through real-world deployment. More than 200 organizations have taken the FIDO Alliance’s Passkey Pledge, demonstrating industry-wide commitment to advancing adoption. 

“Passkeys are moving into the mainstream because they deliver something the industry has struggled to achieve for decades: authentication that is both more secure and easier to use,” said Andrew Shikiar, Executive Director and CEO of the FIDO Alliance. “What began as ecosystem alignment behind FIDO’s open standards has evolved into real global adoption — across consumer services, enterprises, and beyond. As passwords continue to drive phishing, fraud, and customer frustration, organizations everywhere are increasingly turning to passkeys to strengthen security and deliver better experiences.” 

The State of Passkeys 2026 report also reveals the scale of the damage still being caused by passwords and the risk some businesses remain exposed to. 

Passwords Are Still Causing Real Consumer Harm

Despite the growth of passkeys, passwords remain widespread enough to create significant risk and friction.

One in three people (33%) experienced an account compromise or received a breach notification in the past year. This continued impact reflects how many services still rely on passwords, despite the availability of more secure alternatives.

The commercial cost is also significant: 47% of consumers say they are likely to abandon a purchase or sign-in when they cannot remember their password, with 17% saying they are highly likely to do so.

Workforce Deployment Is Advancing, with Opportunity to Scale Usage

Organizations that have deployed passkeys report measurable benefits, including improved security confidence (47%), faster employee logins (45%), improved employee satisfaction with IT (43%), fewer password reset tickets (35%), and reduced phishing-related incidents (32%).

At the same time, there is still room to expand passkey usage within the workforce. A majority (57%) of organizations continue to rely on phishable authentication methods for employees’ primary day-to-day sign-in. In an environment where phishing remains a leading attack vector, this continued dependence represents a meaningful exposure.

Among organizations not yet fully passwordless, 16% say passwords plus MFA are currently sufficient, while 24% say they are waiting for technologies and standards to mature further – highlighting the need for continued education on the importance and availability of phishing-resistant authentication.

Read the full State of Passkeys 2026 report for complete findings. 

Ends

Notes to Editors

State of Passkeys 2026

This report draws on two parallel studies conducted simultaneously by Sapio Research in April 2026 on behalf of the FIDO Alliance. A Consumer Study surveyed 11,000 consumers across ten countries: the United States, United Kingdom, France, Germany, Australia, Singapore, Japan, South Korea, China, and India. The margin of error is ±0.9 percentage points at 95% confidence. A Workforce Study surveyed 1,400 decision-makers across the same ten countries, all screened for direct involvement in decisions about employee sign-in, authentication, or passkey deployment at organizations with 500 or more employees. The margin of error is ±2.6 percentage points at 95% confidence. Both studies were conducted online by Sapio Research using an email invitation and an online survey.

The 5 billion passkeys estimate is calculated by the FIDO Alliance from a combination of publicly available data and its own internal passkey deployment data.

About the FIDO Alliance

The FIDO Alliance (www.fidoalliance.org) enables identity technologies that put trust and simplicity at the center of interactions among people, services, and devices. The Alliance provides a member-driven forum that publishes open technical specifications, certifies secure and interoperable products, and operates global market enablement programs.


The State of Passkeys 2026: Global Consumer and Workforce Report

Passkeys have reached global scale with 5 billion passkeys now in active use. Across both consumer and workforce environments, awareness is now near-universal and adoption has followed: 90% of consumers […]

Passkeys have reached global scale with 5 billion passkeys now in active use. Across both consumer and workforce environments, awareness is now near-universal and adoption has followed: 90% of consumers are familiar with passkeys, and 75% have enabled them on at least some accounts. In parallel, workforce deployment is approaching mainstream levels, with 68% of organizations deploying, piloting, or rolling out passkeys for employee authentication.​

Consumer survey​

The consumer survey was conducted among 11,000 adults who regularly log in to websites, apps, or online services across the United States, United Kingdom, France, Germany, Australia, Singapore, Japan, South Korea, China, and India. Interviews were conducted online by Sapio Research in April 2026. The margin of error is ±0.9 percentage points at a 95% confidence level.​

Workforce survey​

The workforce survey was conducted among 1,400 decision-makers involved in decisions about employee sign-in, authentication, or passkey deployment in organizations with 500 or more employees across the same ten countries. Interviews were conducted online by Sapio Research in April 2026. The margin of error is ±2.6 percentage points at a 95% confidence level.

Download the Report

Wednesday, 06. May 2026

Oasis Open

Coalition for Secure AI Unveils New Agentic Identity and Security Research Following High-Profile Sessions at RSAC 2026

Boston, MA – 6 May 2026 — Following a high-profile presence at RSAC Conference 2026, the Coalition for Secure AI (CoSAI), a global, multi-stakeholder initiative advancing the security of AI systems, is further expanding its industry guidance with the release of two new research papers. Together, these efforts reflect CoSAI’s broader push to advance practical, […] The post Coalition for Secure AI

Building on the momentum of RSAC, CoSAI’s latest work delivers critical frameworks to help organizations navigate the evolving AI security landscape

Boston, MA – 6 May 2026 — Following a high-profile presence at RSAC Conference 2026, the Coalition for Secure AI (CoSAI), a global, multi-stakeholder initiative advancing the security of AI systems, is further expanding its industry guidance with the release of two new research papers. Together, these efforts reflect CoSAI’s broader push to advance practical, real-world approaches to securing AI systems through both technical guidance and industry engagement.

The publications, Agentic Identity and Access Management and The Future of Agentic Security: From Chatbots to Autonomous Swarms, examine two defining challenges of this era: adapting identity and access control to increasingly autonomous, machine-driven environments, and keeping pace with AI agents that act, decide, and spawn further agents at machine speed. They address a question that dominated discussion at RSAC 2026: as autonomous agents become an operating layer of the enterprise, how can organizations extend security principles designed for humans into systems increasingly run by machines?

On the RSAC Stage: From MCP Threats to Enterprise Defense

RSAC Conference 2026 marked a clear inflection point for agentic AI security, with CoSAI playing a visible role in the conversation. Two standing-room sessions brought together practitioners, architects, and CISOs grappling with a shared reality: the enterprise perimeter has moved from the network’s edge to the AI agent’s actions. Traditional security is no longer enough when autonomous agents are empowered to act, spend, and share data on a company’s behalf.

In the session “OASIS CoSAI: Addressing What’s Next in Securing Enterprise AI,” CoSAI Technical Steering Committee co-chairs Akila Srinivasan, Anthropic, and J.R. Rao, IBM Fellow and CTO, Security Research at IBM, outlined a comprehensive roadmap for securing the enterprise AI lifecycle. The session highlighted how threats such as backdoored coding assistants and malicious model artifacts are eroding traditional security boundaries, requiring a fundamental rethink of identity, privilege, and data controls.

In response, CoSAI presented a layered, vendor-neutral defense strategy spanning supply chain security, secure agent design, and emerging standards such as Open Model Signing and secure agent gateways, equipping organizations to move from reactive defense to proactive resilience.

“Forty-plus organizations, including direct competitors, are collaborating inside CoSAI because we understand that the threat landscape doesn’t respect company boundaries. Neither can our defenses,” said J.R. Rao. 

To read more detail about the RSAC session with Srinivasan and Rao, read this recap blog post on CoSAI’s website.

Another CoSAI session, “Securing MCP: Mitigating New Threats in Agentic AI Deployments,” with CoSAI’s Workstream 4 co-lead Sarah Novotny, Klever.co, and Jason Clinton, Deputy CISO, Anthropic, focused on the emerging risks within the Model Context Protocol (MCP). They introduced a clear threat taxonomy, from identity misuse and context tampering to supply chain compromise, and paired it with practical, zero-trust authentication approaches that organizations can implement today. Their central message: as AI agents become context-aware intermediaries, the protocol layer itself becomes a critical and exposed attack surface. Read more in this detailed recap blog post

CoSAI’s RSAC sessions crystallized a theme that carries through both new papers: identity is no longer a solved problem. As agents operate with increasing autonomy, traditional models of identity, access, and control must evolve. CoSAI’s latest research translates these insights into actionable frameworks, beginning with a deep dive into agentic identity and access management.

Securing the AI Actor

The Agentic Identity and Access Management guidance tackles a foundational challenge: without a trustworthy, machine-readable identity for every agent, no other security control can be reliably enforced. Developed by CoSAI’s Secure Design Patterns for Agentic Systems Workstream, this framework provides a practical roadmap for assigning, verifying, and governing the identities of autonomous AI agents across the enterprise.

The guidance outlines how to assign unique credentials to agents, limit their access to only what’s needed for a specific task, and maintain clear visibility into who—or what—is taking action across systems and how that access was delegated. It reinforces a central takeaway from RSAC: organizations can extend their existing identity and access management foundations to securely support autonomous AI safely, without starting from scratch.

“Organizations are rapidly deploying AI agents, and identity and access control models need to keep pace. At the same time, valid identity alone is insufficient—credentials can be correct while outcomes are still harmful,” said Ian Molloy, Workstream co-lead, IBM. “This Agentic Identity paper defines how to prove an agent’s identity,  continuously verify what it should be allowed to do, and how to safely delegate permissions, while enabling organizations to extend the identity and access management solutions they already trust.”

The new research builds on CoSAI’s earlier MCP Security taxonomy and the Principles for Secure-by-Design Agentic Systems published in 2025. Together they form a layered blueprint: principles define intent, MCP Security addresses the protocol layer, and Agentic Identity and Access Management governs the trust layer that everything else depends on.

Securing the Age of Autonomous Swarms

Agentic security was a breakout theme at RSAC this year, and for good reason. As organizations move beyond AI assistants toward fully autonomous, multi-agent systems capable of independent action across enterprise infrastructure, traditional security controls are struggling to keep pace. The Future of Agentic Security: From Chatbots to Autonomous Swarms examines how AI agents capable of coding and coordinating across sensitive systems shift the attack surface to the semantic layer, where traditional controls like static access lists and pattern-based monitoring are no longer effective. 

The research identifies two unsolved problems: intent-based authorization — the inability to reliably evaluate and govern what an AI agent is actually trying to accomplish in natural language — and the semantic mosaic effect, where agents can synthesize and expose sensitive insights from innocuous sources without ever triggering conventional leak protection. These are not gaps that incremental improvements to existing security tooling will close.

To help organizations get ahead of these risks, CoSAI outlines a framework for secure agentic architecture, including ephemeral environments, dynamic credentialing, and a new category of defense: Agent Detection and Response (ADR). The core message for executives is clear: the window to build the right security infrastructure before widespread agentic deployment is narrowing, and the clock is already ticking.

Beyond technology, the research provides a roadmap for the security industry’s evolution. It offers updated incident response playbooks, new threat models for agent-to-agent attack vectors, and governance frameworks designed to operate at the same speed as the autonomous systems they protect.

Access CoSAI’s Collaborative Research

These frameworks advance CoSAI’s mission to provide the industry with a proactive, rather than reactive, security posture. To download the papers and explore our library of published frameworks and guidelines, visit the Security Guidance page on the CoSAI website.

About the Coalition for Secure AI (CoSAI)

The Coalition for Secure AI (CoSAI) is a global, multi-stakeholder initiative dedicated to advancing the security of AI systems. CoSAI brings together experts from industry, government, and academia to develop practical guidance, promote secure-by-design practices, and close critical gaps in AI system defense. Through its workstreams and open collaboration model, CoSAI supports the responsible development and deployment of AI technologies worldwide. CoSAI operates under OASIS Open, an international standards and open-source consortium. www.coalitionforsecureai.org

About OASIS Open

One of the most respected, nonprofit open source and open standards bodies in the world, OASIS advances the fair, transparent development of open source software and standards through the power of global collaboration and community. OASIS is the home for worldwide standards in AI, emergency management, identity, IoT, cybersecurity, blockchain, privacy, cryptography, cloud computing, urban mobility, and other content technologies. Many OASIS standards go on to be ratified by de jure bodies and referenced in international policies and government procurement. www.oasis-open.org

Media Inquiries: communications@oasis-open.org

The post Coalition for Secure AI Unveils New Agentic Identity and Security Research Following High-Profile Sessions at RSAC 2026 appeared first on OASIS Open.

Tuesday, 05. May 2026

Digital ID for Canadians

Request for Comment & IPR Review: PCTF Automotive Identity Profile

This review period is now closed. Notice of Intent: DIACC is collaborating to develop and publish the Automotive Identity Profile of the Pan-Canadian Trust Framework…

This review period is now closed.

Notice of Intent: DIACC is collaborating to develop and publish the Automotive Identity Profile of the Pan-Canadian Trust Framework (PCTF) to standardize and secure digital identity verification practices across the automotive financing and leasing ecosystem. During this public review period, DIACC is looking for community feedback to ensure that the conformance criteria is clear and auditable.

To learn more about the Pan-Canadian vision and benefits-for-all value proposition please review the Pan-Canadian Trust Framework Overview.

Document Status: This review document has been developed by members of the DIACC’s Trust Framework Expert Committee (TFEC) who operate under the DIACC controlling policies and consist of representatives from both the private and public sectors. This document has been approved by the TFEC for public comment.

Summary:

In response to Canadian bank directives on dealership identity verification, the PCTF Automotive Identity Profile will establish transparent, auditable assurance criteria recognized through the DIACC PCTF Certification Program. This will give dealerships, lenders, and technology partners confidence in secure, privacy-preserving digital identity tools that meet regulatory expectations. The result is a consistent trust layer across vehicle purchasing and financing that reduces fraud, document counterfeiting, and strengthens AML compliance sector-wide.

Invitation:

All interested parties are invited to comment

Period:

Opens: May 4, 2026 at 23:59 PT | Closes: June 4, 2026 at 23:59 PT

When reviewing the Conformance Criteria, please consider the following and note that responses to these questions are non-binding and serve to improve the PCTF.

Would you consider the Conformance Criteria as auditable or not? That is, could you objectively evaluate if an organization was compliant with that criteria and what evidence would be used to justify that? Would you like to see examples added to specific conformance criteria regarding how or what an organization must do to meet the criteria? If yes, please include an example accordingly in the appropriate column found in the DIACC Comment Submission Spreadsheet.

Review Document: PCTF Automotive Identity Profile

Draft Recommendation V1.0 DIACC Comment Submission Spreadsheet

Intellectual Property Rights:

Comments must be received within the 30-day comment period noted above. All comments are subject to the DIACC contributor agreement; by submitting a comment you agree to be bound by the terms and conditions therein. DIACC Members are also subject to the Intellectual Property Rights Policy. Any notice of an intent not to license under either the Contributor Agreement and/or the Intellectual Property Rights Policy with respect to the review documents or any comments must be made at the Contributor’s and/or Member’s earliest opportunity, and in any event, within the 30-day comment period. IPR claims may be sent to review@diacc.ca. Please include “IPR Claim” as the subject.

Process:

All comments are subject to the DIACC contributor agreement. Submit comments using the provided DIACC Comment Submission Spreadsheet. Reference the corresponding line number for each comment submitted. Email completed DIACC Comment Submission Spreadsheet to review@diacc.ca. Questions may be sent to review@diacc.ca.

Value to Canadians:

The DIACC’s mandate is to collaboratively develop and deliver resources to help Canadians to digitally transact with security, privacy, and convenience. The PCTF is one such resource and guides the digital trust and identity verification ecosystem interoperability by putting policy, standards, and technology into practice aligning with defined levels of assurance. The DIACC is a not-for-profit coalition of members from the public and private sector who are making a significant and sustained investment in accelerating Canada’s Identity Ecosystem.

Context:

The purpose of this review is to ensure transparency in the development and diversity of a truly Pan-Canadian, and international, input. In alignment with our Principles for an Identity Ecosystem, processes to respect and enhance privacy are being prioritized through every step of the PCTF development process.

DIACC expects to modify and improve this Recommendation based upon public comments. Comments made during the review will be considered for incorporation into the next iteration and DIACC will prepare a Disposition of Comments to provide transparency with regard to how each comment was handled.


Hyperledger Foundation

Announcing Lineth: a production-grade ZK rollup stack joins Linux Foundation Decentralized Trust

Today, we are excited to announce that the open source Linea Stack is joining Linux Foundation Decentralized Trust (LFDT) as an incubating project under a new name: Lineth. In production since 2023, it is now moving into a vendor-neutral open source home designed for long-term technical stewardship and broader community participation.

Today, we are excited to announce that the open source Linea Stack is joining Linux Foundation Decentralized Trust (LFDT) as an incubating project under a new name: Lineth. In production since 2023, it is now moving into a vendor-neutral open source home designed for long-term technical stewardship and broader community participation.

Monday, 04. May 2026

FIDO Alliance

PYMNTS: Google and Mastercard Contribute Agentic Commerce Standards to FIDO Alliance

The FIDO Alliance plans to develop standards for artificial intelligence (AI) agentic interactions and commerce that will define trusted mechanisms for how agents authenticate, act and transact on behalf of users. In these initiatives, […]

The FIDO Alliance plans to develop standards for artificial intelligence (AI) agentic interactions and commerce that will define trusted mechanisms for how agents authenticate, act and transact on behalf of users.

In these initiatives, the group will leverage its track record of delivering standards as well as its work to replace passwords with passkeys and advance digital credentials, the FIDO Alliance said in a Tuesday (April 28) press release.

One initiative is the FIDO Alliance’s formation of an Agentic Authentication Technical Working Group that will focus on how users can delegate actions to AI agents securely, privately and with strong, phishing-resistant authentication.

In the FIDO Alliance’s other new initiative, its Payments Technical Working Group will work on developing specifications for agent-initiated commerce. This effort will draw from two contributions: Google’s Agent Payments Protocol (AP2) and Mastercard’s Verifiable Intent framework. The working group will review and further develop these contributions.

Google said in a Tuesday blog post that it donated AP2 to the FIDO Alliance to further scale the technology and promote industry-wide innovation. The company highlighted the FIDO Alliance’s renown as a creator of open standards.

“Transitioning ownership to the FIDO Alliance ensures AP2 remains platform-agnostic and community-led, while accelerating adoption of secure agentic payments,” Stavan Parikh, vice president and general manager, payments at Google, said in the post.

Thursday, 30. April 2026

FIDO Alliance

Wirecutter: Passkeys Are the New Passwords. You Should Start Using Them Now.

Passkeys Are the New Passwords. You Should Start Using Them Now. For 15 years, experts have told me that passwords are the biggest problem with online security and that’s just […]

Passkeys Are the New Passwords. You Should Start Using Them Now.

For 15 years, experts have told me that passwords are the biggest problem with online security and that’s just the way it is. The passwords that people make up are easily guessed by machines, and the ones that can’t be guessed are too hard to remember. 

Over time, as more and more passwords became necessary, many people simply recycled theirs across different accounts — creating a precarious situation where one phished password or data breach gave an attacker access to the victims’ email, bank accounts, and anything else that shared that password. 

Then came password managers, services and software in which a person could safely store all of their complex passwords and thus need to remember only a single password: the password for their password manager. This technology addressed, but didn’t solve, some of the problems. If people put in the effort, they could eventually have unique and complex passwords everywhere. But the majority of people did not opt to take on this herculean task that brought no immediate reward except that (maybe) in the future something bad might not happen to them (possibly). And a smart attacker could just phish even the best passwords anyway.

Two-factor authentication was the next bandage on the gaping wound of passwords. With 2FA protecting you, an attacker could have your password but wouldn’t be able to use it without a second confirmation, such as a code generated by an app or sent by text message. But another hoop to jump through for logging in remains a hard sell. And a smart attacker could just (you guessed it) phish most forms of 2FA anyway.

But passkeys are different. Instead of trying to fix unfixable passwords, passkeys are an entirely new technology that securely logs you in without your needing to remember your password or to perform a 2FA ritual. Passkeys are not perfect, and we’re still a ways off from their being commonplace, but learning what a passkey is and how to use it moves you a little closer to a more secure future.

Wednesday, 29. April 2026

Hyperledger Foundation

Scaling up the digital asset ecosystem through Hyperledger Fabric‑X new features

Digital asset platforms are reaching an inflection point.

Digital asset platforms are reaching an inflection point.


FIDO Alliance

The Payers: Google donates Agent Payments Protocol to FIDO Alliance

Google has donated its Agent Payments Protocol to the FIDO Alliance and released an updated version, including autonomous payment capabilities. The move is intended to ensure AP2 remains platform-agnostic and […]

Google has donated its Agent Payments Protocol to the FIDO Alliance and released an updated version, including autonomous payment capabilities.

The move is intended to ensure AP2 remains platform-agnostic and open to broader industry participation. Through the process of placing the protocol under the FIDO Alliance’s stewardship, Google aims to accelerate adoption across the payments ecosystem and support interoperability between different platforms and providers.

Protocol update and autonomous transaction support

Alongside the transfer, Google has published AP2 v0.2 on GitHub, introducing new capabilities for autonomous transactions. A key addition is support for ‘Human Not Present’ payments, which enables AI agents to execute purchases independently, based on instructions pre-authorised by the user. The update is designed to address scenarios in which speed or timing is critical, such as purchasing limited-availability items as soon as they become available, without requiring real-time user interaction.

In addition, the release reflects the broader challenge of enabling AI agents to transact reliably and securely across commerce environments, particularly as autonomous systems take on a more active role in consumer and business workflows.


FinTech Magazine: How FIDO Leads the Push for Trusted AI-Driven Transactions

FIDO Alliance launches new standards to secure AI agent interactions, enabling trusted authentication and payments in emerging agentic commerce ecosystems As AI agents move from experimental tools to active participants […]

FIDO Alliance launches new standards to secure AI agent interactions, enabling trusted authentication and payments in emerging agentic commerce ecosystems

As AI agents move from experimental tools to active participants in digital commerce, the question is no longer what they can do, but how they can be trusted to do it. 

For financial institutions, merchants and technology providers, this shift introduces a new layer of complexity around identity, authorisation and transaction integrity.

idoThe FIDO Alliance is positioning itself at the forefront of efforts to standardise how AI agents securely authenticate and transact on behalf of users.


Next Level Supply Chain Podcast with GS1

Food for Thought: Why Better Data Matters in Food Safety

If a product is contaminated, it can now be traced and removed from shelves within days, not weeks—thanks to the advanced technology available today. In this episode, Reid Jackson and Liz Sertl speak with Brian Schaneberg, Executive Director of the Institute for Food Safety and Health, about how modern traceability systems and innovations like 2D barcodes are improving food safety. Brian expl

If a product is contaminated, it can now be traced and removed from shelves within days, not weeks—thanks to the advanced technology available today. In this episode, Reid Jackson and Liz Sertl speak with Brian Schaneberg, Executive Director of the Institute for Food Safety and Health, about how modern traceability systems and innovations like 2D barcodes are improving food safety.

Brian explains how the shift from reactive to proactive food safety measures is changing the way the industry handles outbreaks. He also explores the impact of FSMA 204 on improving data sharing and enhancing the efficiency of recalls. This episode reveals how these advancements are making food safety smarter, faster, and more transparent than ever before.

In this episode, you'll learn:

Why food recalls are increasing but becoming less severe

How traceability improves recall speed and accuracy

The role of data, AI, and 2D barcodes in food safety

Things to listen for: (00:00) Introducing Next Level Supply Chain (01:20) Brian's journey into food safety (06:27) Understanding food recall patterns and severity (15:57) Understanding FSMA and the traceability rule (18:12) Why food traceability is a data exercise (21:10) How traceability impacts farms, manufacturers, and restaurants (31:28) The future of food safety and prevention strategies (37:57) Brian's favorite technology

Connect with GS1 US: Our website - www.gs1us.orgGS1 US on LinkedIn Register for GS1 Connect 2026, happening June 9 to 11 in Las Vegas, and get 10% off with the promo code GS1USPOD10 at connect.gs1us.org.

Connect with the guest: Brian Schaneberg on LinkedIn Visit the Institute of Food Safety and Health at iit.edu/ifsh


EdgeSecure

EdgeCon Spring 2026 Recap

When Digital Learning Becomes Infrastructure: What Changes for Teaching and Learning Digital learning has moved far beyond the experimental stage in higher education. Today, learning platforms, data analytics, AI-powered tools,… The post EdgeCon Spring 2026 Recap appeared first on Edge, the Nation's Nonprofit Technology Consortium.
When Digital Learning Becomes Infrastructure: What Changes for Teaching and Learning

Digital learning has moved far beyond the experimental stage in higher education. Today, learning platforms, data analytics, AI-powered tools, and flexible online and hybrid delivery models are deeply embedded in the daily fabric of teaching, advising, assessment, and student communication. For many institutions, these technologies have quietly become core infrastructure and are shaping academic practice, decision-making, and the student experience, often without even being explicitly recognized as such. This theme was a central focus of EdgeCon Spring 2026, hosted at The College of New Jersey on April 16, 2026, and during the keynote presentation, When Digital Learning Becomes Infrastructure: What Changes for Teaching and Learning.

Rather than focusing on emerging trends, the keynote panel centered on institutional maturity and how roles and responsibilities shift as digital learning becomes infrastructure. Panelists explored how decisions affecting pedagogy, accessibility, equity, and academic quality are increasingly made through systems, policies, and vendor configurations, and where responsibility for those decisions truly lie. The conversation explored how institutional structures, governance models, and technology ecosystems influence teaching and learning behind the scenes, and what happens when the desire for speed, scale, and automation collides with the need for quality, trust, and accountability. Panelists also discussed where institutions are intentionally slowing down, adding guardrails, or revisiting assumptions as digital learning continues to scale.

Using Data for Digital Program Development
One of the morning breakout sessions, From Insight to Innovation: Using Data and Market Analytics to Inform Digital Program Development, was presented by Nicole Suprun, Associate Director of Planning; Kelly Oquist, Director of Academic Finance, and Jessica Kay, Director of Institutional Research from Stockton University. The session explored how Stockton is integrating labor market intelligence, enrollment trends, and academic program analytics to guide the development of new digital and hybrid programs. The presenters discussed their Gray Decision Intelligence (Gray DI) platform that brings together expertise from institutional research, academic leadership, finance, and enrollment teams.

The presentation also highlighted how market data, student demand indicators, and competitive landscape analysis can help institutions identify opportunities for new digital offerings, evaluate program viability, and align program development with institutional priorities such as access, workforce relevance, and long-term sustainability. Attendees gained practical considerations for incorporating data into academic planning processes, including faculty engagement, governance pathways, and balancing quantitative insights with academic mission and disciplinary expertise.

Designing Assignments in the Age of Artificial Intelligence
As AI tools become more sophisticated and accessible and students improve their proficiency in using them, educators face increasing uncertainty about the reliability of AI and plagiarism detection software and how to interpret the results. Jarrod Cecere, Instructional Designer, Seton Hall University, led the session, AI or Not? Designing Assignments in the Age of Artificial Intelligence, to examine the increasingly difficult challenge of detecting AI-generated student work and its implications for academic integrity and instructional design. He began with a game to challenge participants’ AI identification skills and then examined the limitations of detection software by comparing two approaches to assessment design. Cecere examined “AI-proofing” assignments that minimize the potential for student AI assistance and creating assignments that require students to leverage AI as part of the process, including the pedagogical and ethical challenges and benefits of each approach.

“I have attended many educational technology conferences and this is one of the finest. In particular, I really enjoyed the spectrum of professionals who attended. There were folks in IT, teaching in K-12, and a few academics. That diversity made the conversations quite interesting. Also, there was a true sense to me of collegiality, everyone was so nice and professional.”

– Dermot Foley
Associate Director of Online Education
Lehman College, CUNY

Institution-wide AI Faculty Development
At The College of New Jersey (TCNJ), the Center for Excellence in Teaching and Learning (CETL) partnered with faculty colleagues across campus to design and launch a five-week, online, stipend-supported certificate program to support more than 55 full-time faculty in moving from isolated experimentation with AI toward intentional, discipline-informed engagement in their teaching and research. In this session, the TCNJ team of Joseph Baker, Professor, Department of Chemistry; Judi Cook, Executive Director, CETL; Ellen Farr, Director of Online Learning, CETL; Rebecca Hunter, Associate Professor, Department of Chemistry; John Oliver, Information Literacy Librarian; and Andrea Salgian, Professor, Department of Computer Science, shared the institutional choices that shaped the program’s design, the adjustments they made in response to faculty realities, and what participant data revealed about what actually supports sustained engagement.

The team discussed how they used the Canvas LMS to deploy the CETL AI Faculty Institute, leveraged their new One Button Recording Studios to create content introducing each week’s module, and created a forum space within the Canvas course for faculty to interact with one another as they experimented with AI tools and explored fundamental AI literacy. Attendees left with a replicable program framework, implementation lessons grounded in practice, and a reframing of AI faculty development—not as a one-time workshop, but as a durable, sustainable institutional infrastructure.

Entering a New Era of Digital Learning
As artificial intelligence becomes increasingly embedded in learning management systems, instructional tools, and institutional decision-making, higher education is entering a new phase of digital learning, one defined not only by access to technology but by the values and assumptions encoded into it. Systems designed to support teaching and learning are now shaping what counts as engagement, rigor, integrity, and success. Yet many of these systems still operate on inherited models of standardization, compliance, and surveillance, models that often privilege the most advantaged users while intensifying barriers for those who are least resourced, least confident, or most vulnerable to exclusion.

Behind the Veil: Designing Just Digital Learning in the Age of AI, led by Steven D'Agustino, Senior Director for Online Programs, Fordham University, and Joshua Gaul, Chief Information Officer, SUNY Schenectady County Community College, introduced a philosophically grounded but highly practical framework for evaluating digital learning design through the lens of John Rawls’s veil of ignorance. Rawls’s thought experiment asks designers to build institutions without knowing what role they will occupy within them, whether student or instructor, advantaged or marginalized, digitally fluent or struggling. Applied to digital learning systems, this lens reveals how common institutional defaults, including rigid deadlines, narrow definitions of participation, and high-stakes assessment structures, are now being amplified by AI-enabled systems such as integrity tools and proctoring platforms, predictive analytics dashboards, and automated feedback systems.

Participants explored instructional design as a form of moral architecture and were introduced to a Rawlsian Design Audit, a set of guiding questions that can be applied to course design, institutional policy, and learning technology governance. Using examples drawn from common LMS practices and emerging AI-enabled tools, the presenters examined five design domains, including time, communication, assessment, navigation, and institutional governance. Attendees left with a concrete, reusable framework and checklist for evaluating whether digital learning environments are being built primarily for efficiency and scale, or for justice, inclusion, and human dignity.

Combining AI and Universal Design for Learning (UDL)
Designing a course that works across different learning formats can feel overwhelming, especially as faculty balance accessibility, engagement, and academic rigor. In the breakout session, One Course, Many Formats: AI + UDL for In-Person, Hybrid, and Online Learning, Jaimie Dubuque, Learning Technology Administrator, Ellucian, examined how AI grounded in UDL can help instructors design once and adapt intentionally across multiple learning environments. Dubuque explained that AI can create multiple means of engagement, representation, and expression based on the course, and help anticipate and reduce barriers before students encounter them. Through practical examples and adaptable prompts, attendees left with concrete strategies for building resilient, inclusive courses that translate effectively across in-person, hybrid, and online settings.

Meeting the Needs of Today’s Students
As educators in a rapidly evolving digital world, Berkeley College is on a mission to design learning experiences that reflect the real-world communication demands and creative possibilities students will encounter in their future careers. In Reimagining Intro to Comm: Voice, Choice, and Digital Design, Victoria Ghilardi, Senior Learning Experience Strategist at Berkeley, shared how their institution co-designed communication projects that empowered students to create compelling multimedia content, respond to realistic scenarios, and engage meaningfully with their peers.

In another breakout session, Academic Feedback Intelligent Assistant, Directors Mariola Pogacnik and Jennie Wong from Slalom, Inc. discussed how academic learning is an iterative process that relies heavily on fair, effective, and timely feedback. However, overwhelmed faculty and administrative burnout often lead to feedback that is delayed or inconsistent, negatively impacting student motivation and engagement. Pogacnik and Wong discussed the ways institutions can leverage Generative AI to solve the "grading bottleneck" without removing the human educator from the equation.

The presentation included a case study from the UCLA Anderson School of Management, detailing the development and implementation of the Academic Feedback Intelligent Assistant (AFIA). Attendees also explored the technical architecture and the proprietary prompt design strategies used to ground AI outputs in educational best practices. Slalom shared pilot results demonstrating how AFIA improved feedback consistency and reduced the time course assistants spent writing comments by approximately 50%, ultimately freeing up educators to focus on high-value student interactions.

“EdgeCon continues to be an excellent conference providing valuable networking opportunities, relevant content, and vendor engagement. Keep up the great work!”

– Bradley Morton
VP for IT
Passaic County Community College

Employing Data-Driven Decision-Making
Aaron Colaiacomo, Sr. Instructional Technologist, Providence College, joined EdgeCon to share how their institution leveraged Canvas analytics to move beyond course-level insights and build a data-informed annual report that directly shapes academic and operational decision-making. Drawing on real dashboards and reporting workflows, the presentation showed how LMS engagement data is aggregated, contextualized, and translated into narratives that inform faculty development, instructional design priorities, resource allocation, and long-term digital learning strategy.

The session also highlighted how categorization of email subject lines and communication patterns, supported by AI-assisted tagging and analysis, adds a critical layer to understanding student support, outreach effectiveness, and institutional responsiveness. By connecting LMS data, internal databases, and communication analytics, the institution can create a more holistic picture of how digital learning ecosystems function in practice. Attendees also learned practical approaches to building scalable dashboards, aligning analytics with institutional goals, and using AI ethically and transparently to support decision-making.

Producing High-quality Digital Tools
Drawing on two decades of experience in television and digital media, John Baldino, Director, Center for Teaching and Learning and Assistant Professor, Lackawanna College, shared how educators can strengthen their courses with compelling video content in As Seen on TV: Using Television Best Practices in Video Lectures. Grounded in best practices in television and online video shaped by consumer behavior, this session provided practical strategies for producing engaging, high-quality video for both online and on-ground learning, blending proven media techniques with today’s digital teaching tools.

In the breakout session, Nothing About Students Without Students: Co-Designing AI Curriculum, Policy, and Research for the Next Generation of Business Leaders, Yaw Adoo, Department Chair of Business, and Sterline Caldwell, Assistant Professor of Mathematics, from Morris Brown College explored how faculty-student collaboration strengthens academic integrity, accelerates curriculum relevance, and expands innovation capacity within HBCU business schools. This presentation argued that effective AI curriculum, policy, and research design must include students as active partners rather than passive recipients of rules. Traditional top-down approaches struggle to keep pace with AI’s rapid evolution, often leading to ambiguity, inconsistent enforcement, and mistrust.

When students help shape the systems they are expected to follow, Adoo and Caldwell explained, they are more likely to uphold them, emerging as graduates prepared not only to use AI tools but to lead responsibly in AI-enabled organizations. Attendees also gained a roadmap for integrating student voice into AI governance to enhance accountability, trust, and real-world readiness.

Turning Online Access into Real Engagement
Online learners and faculty often exist at the edges of campus culture and are engaged in academics but disconnected from the community. In the session, The Modern Digital Campus: Turning Online Access into Real Engagement and Community, Lindsey Haynes, Director of Franciscan Life Online, Franciscan University of Steubenville, and Allison Dean, Account Executive, Pathify, explored how institutions are using a unified campus experience platform built around the specific needs of online and hybrid learners to replicate the richness of the physical campus in a digital environment.

Presenters showed how intentional segmentation and student-centered design drove online student awareness of resources from 69% to 94% and how institutions of any size or model can apply the same approach to close culture gaps and extend a sense of belonging to adjunct and online faculty. Institutions that were rethinking student engagement or looking to better support their distributed teaching community received a practical, replicable framework for building a digital campus that works for everyone.

Collaborative Open Pedagogy Planning and Execution
Dermot Foley, Associate Director of Online Education, Center for Teaching and Learning, Lehman College, CUNY, joined EdgeCon to share the strategic design of a Wikimedia initiative at Lehman College that conceptually resituates students from passive consumers into active knowledge producers. Reimagining Adult Learning through Collaborative Open Pedagogy Planning, Design, and Execution presented a pedagogical model for using Wikipedia to teach digital literacy and public scholarship, and a replicable "collaboration map" for identifying and engaging cross-campus stakeholders. By highlighting the specific roles and positive interplay of these departments, Foley demonstrated how reimagining adult learning starts with reimagining how we work together.

“I found the sessions very useful!”

– Robert Doster
CIO
College of New Jeresy

Save the Date
Mark your calendars for October 22, 2026! Be part of the next exciting conversation and join fellow educators, technologists, and institutional leaders at EdgeCon Autumn at Montclair State University. Come gain fresh insights, real-world strategies, and meaningful opportunities to collaborate and drive your organization’s initiatives forward.

VIP Sponsor

blank

slalom

Exhibitor Sponsors

Artic Wolf

Aspire

Blackboard

D2L

e+

Lenovo x intel

pathify

pka tech

poll everywhere

rubrik

blank

SHI

we video

Lanyard Sponsor

blank

blank

modern campus

The post EdgeCon Spring 2026 Recap appeared first on Edge, the Nation's Nonprofit Technology Consortium.

Tuesday, 28. April 2026

FIDO Alliance

Wired: The Race Is on to Keep AI Agents From Running Wild With Your Credit Cards

AI agents may soon be buying your stuff for you. The FIDO Alliance has teamed up with Google and Mastercard to try to ensure that shopping in the near future […]

AI agents may soon be buying your stuff for you. The FIDO Alliance has teamed up with Google and Mastercard to try to ensure that shopping in the near future isn’t a complete disaster.


The Agentic Era Is Here. Now We Need to Make It Trustworthy.

Andrew Shikiar, CEO and Executive Director, FIDO Alliance AI agents are starting to change how people and businesses get things done online. The shift is fundamental: agents can research, make […]

Andrew Shikiar, CEO and Executive Director, FIDO Alliance

AI agents are starting to change how people and businesses get things done online. The shift is fundamental: agents can research, make decisions, manage tasks and complete transactions on our behalf. The productivity gains for individuals and enterprises alike are enormous, and the pace of adoption is faster than many anticipated.

But there is a fundamental problem standing between the promise and the reality: trust.

The entire trust infrastructure of the internet was built around the reasonable assumption that a human is at the keyboard. Every login, authentication prompt and verified transaction was designed to answer a single question at a specific moment: are you who you say you are?

AI agents break that assumption. People still direct these interactions but they are no longer carrying them out themselves. And without agreed standards for how trust, authorization, and user intent work in that model, the agentic opportunity stalls. 

This missing trust layer is the gap the FIDO Alliance is moving to close.

We’ve seen this before

As the internet scaled globally, it brought passwords with it almost by default, despite being fundamentally unfit for purpose.

Without an appropriate trust layer, we experienced a credential theft epidemic as the internet became ubiquitous in our lives. Billions of stolen passwords trading on dark web marketplaces, and practically every person with an online account has likely fallen victim to a breach – whether they are aware of it or not.

The FIDO Alliance was formed to answer this challenge – not with a proprietary fix, but with open, interoperable standards built through industry collaboration. The result was passkeys: phishing-resistant authentication that takes knowledge-based credentials out of the equation, while making sign-in simpler and easier to use. Passkeys are now available on virtually every modern computing device, and are increasingly the default way people prove who they are online.

And now we’re seeing it again 

Analysts project agentic commerce alone could reach $5 trillion globally by 2030, according to McKinsey & Company. That economy is being built right now, without agreed standards for how trust, authorization, and user intent should actually work. People are already adopting agentic workflows, demonstrating the huge potential for good and ill in equal measure. 

We cannot make the same mistake again. We know there is a trust gap in agentic AI but, unlike the early explosion of the web, we already have the means to close it.

Open agentic infrastructure

Today, the FIDO Alliance is announcing the formation of an Agentic Authentication Technical Working Group, chaired by FIDO members from CVS Health, Google, and OpenAI, and co-chaired by members from Amazon, Google and Okta. Alongside this, our Payments Technical Working Group chaired by FIDO members from Visa & Mastercard will develop agentic payment specifications building on foundational contributions from Google and Mastercard.

Google’s Agent Payments Protocol (AP2) introduces a model for secure delegation, verifiable authorization, and trusted transaction execution. Mastercard’s Verifiable Intent framework, co-developed with Google and compatible with AP2, enables users to authorise and control agent-initiated actions on their behalf. Both have been contributed to FIDO’s specification development process to help ensure that these initiatives are open, interoperable and positioned for global utilization. 

FIDO’s work will focus on three things: 1) giving users phishing-resistant mechanisms to authorise agent actions; 2) allowing services to cryptographically verify that agents are acting legitimately on behalf of authenticated users; and, 3) defining how agent-initiated transactions execute within clear, user-controlled boundaries.

That is the model the agentic internet requires.

Trust must be provable

Standards alone are not enough – their value depends on consistent, verifiable implementation. 

FIDO’s certification programs ensure that implementations meet the specifications, and that trust is demonstrable – not assumed.

As with passkeys, the objective is not security at the cost of simplicity. It is both, together. The agentic era requires delegation models that people can understand and control, alongside security that works intuitively without constant user intervention. 

If we get this right, the path to broad agentic adoption becomes clear. Individuals can offload complex tasks with confidence. Businesses can automate workflows without introducing new risks. Services can accept agent-initiated interactions without added friction. The projected $5 trillion opportunity becomes tangible because the trust foundation beneath it is real.

This moment matters immensely. The decisions made in the coming months will shape the trust architecture of the internet for the next decade. FIDO has been in this position before – bringing industry together to solve a foundational challenge. We are ready and excited to do so again, working with our members and partners to help deliver an agentic ecosystem the world can trust.


FIDO Alliance to Develop Standards for Trusted AI Agent Interactions

Formation of Agentic Authentication Working Group and development of agentic payment frameworks will support trusted, interoperable agentic workflows April 28, 2026 – The FIDO Alliance today announced initiatives to develop […]

Formation of Agentic Authentication Working Group and development of agentic payment frameworks will support trusted, interoperable agentic workflows

April 28, 2026 – The FIDO Alliance today announced initiatives to develop interoperable standards for agentic interactions and commerce. These initiatives include the formation of an Agentic Authentication Technical Working Group and efforts to develop specifications for agent-initiated commerce, drawing from initial contributions from Google (AP2) and Mastercard (Verifiable Intent). Together, these efforts aim to define trusted mechanisms for how AI agents authenticate, act, and transact on behalf of users.

As AI-powered agents rapidly transition from novelty to mainstream, interactions performed on behalf of users must be simple and trusted. However, today’s authentication and authorization models were designed for direct human interaction, not delegated, agent-initiated actions. Users may be required to share credentials, while service providers lack reliable, interoperable ways to verify user intent – including who authorized an action, under what conditions, and with what limits. Without clear standards, these gaps risk slowing adoption of agent-driven use cases, including agentic commerce, which some analysts estimate could reach $5 trillion globally by 2030.

The FIDO Alliance will leverage its track record of delivering standards at internet scale, building on its work to replace passwords with passkeys and advance digital credentials, to address emerging trust and interoperability challenges. 

These efforts focus on three core areas:

Verifiable User Instructions – Enabling users to authorize AI agents through clear, phishing-resistant mechanisms so agents only perform approved actions, including transactions, without exposing credentials. Agent Authentication – Allowing services to verify that an AI agent is acting on behalf of an authenticated user and within defined parameters, distinguishing legitimate agents from unauthorized actors. Trusted Delegation for Commerce – Defining how agent-initiated transactions can be executed within user-controlled boundaries, with verifiable authorization. This work recognizes that trusted agentic transactions require not only strong authentication, but also clear, verifiable authorization mechanisms aligned with real-world commerce and payment flows.

“AI agents are quickly becoming part of how people get things done online – from making purchases to managing everyday tasks,” said Andrew Shikiar, executive director and CEO of the FIDO Alliance. “To scale this safely, people need to trust that these actions are secure, authorized and truly reflect their intent. These initiatives bring the industry together to establish a trusted foundation for agent-driven interactions across authentication and commerce.”

New FIDO workstreams to advance trusted agentic standards

The FIDO Alliance’s agentic standards work will be carried out by its members through the newly formed Agentic Authentication Technical Working Group and the Payments Technical Working Group.

The Agentic Authentication Technical Working Group is focused on how users securely and privately delegate actions to AI agents while maintaining strong, phishing-resistant authentication, including establishing clear boundaries between user-initiated and agent-initiated actions. At launch, the Agentic Authentication Technical Working Group is chaired by members from CVS Health, Google and OpenAI and vice-chaired by members from Amazon, Google and Okta.

In parallel, the FIDO Alliance is developing specifications for agent-initiated commerce within its Payments Technical Working Group, chaired by members from Mastercard and Visa. Technical contributions from Google and Mastercard are providing an initial foundation for these specifications. 

Google has contributed its Agent Payments Protocol (AP2), which introduces a model for secure delegation, verifiable authorization and trusted transaction execution. Mastercard has contributed its Verifiable Intent framework, co-developed with Google and designed to work with AP2, enabling users to securely authorize and control actions performed by digital agents on their behalf. These contributions will be reviewed and further developed through the FIDO Alliance’s collaborative standards process within the Payments Technical Working Group. The FIDO Alliance is liaising with other industry standards bodies to ensure harmony amongst agentic commerce initiatives.

“Contributing Agent Payments Protocol (AP2) to a trusted industry association like the FIDO Alliance ensures it stays open, platform-agnostic, and community-led as the emerging standard to accelerate the adoption of secure agentic payments,” said Stavan Parikh, VP/GM, Payments, Google. “We look forward to contributing to support the protocol’s evolution in this next chapter.”

“For agent‑initiated commerce to scale, user intent must be explicit, verifiable and trusted,” said Pablo Fourez, Chief Digital Officer at Mastercard. “That’s exactly what this work with the FIDO Alliance is designed to enable. By contributing Verifiable Intent to the FIDO Alliance’s standards work, and our continued work with other standards bodies, we’re supporting an approach that creates a shared record of user intent that the entire payments ecosystem can rely on.” 

Work has commenced within these workstreams, and the FIDO Alliance will provide reports as it progresses.

About the FIDO Alliance

The FIDO Alliance (www.fidoalliance.org) enables identity technologies that put trust and simplicity at the center of interactions among people, services and devices. The Alliance provides a member-driven forum that publishes open technical specifications, certifies secure and interoperable products and operates global market enablement programs.

Support from FIDO Board Members

“FIDO turned phishing-resistant authentication from a specification into something billions of people use every day, and that same collaborative model is what AI agent identity now needs. The hard problem isn’t inventing new primitives, it’s binding human intent to agent action with cryptographic guarantees that hold across organizational boundaries, and doing it through standards rather than proprietary stacks. 1Password is committed to contributing to FIDO’s initiatives in this space because the shift to agentic systems can only be secured if the foundations are open, interoperable, and built collaboratively.” – Jeff Malnick, VP of Engineering, Developer & AI, 1Password

“American Express is proud to partner with the FIDO Alliance and the broader industry to help shape the standards needed for agentic commerce to scale. As a closed-loop network, we bring a unique perspective and will continue evolving our Amex Agentic Commerce Experiences (ACE) Developer Kit to enable emerging experiences to be seamless, trusted, and compliant. With AI agents playing a greater role in how customers and merchants interact, establishing clear frameworks to promote trust, security, and user control is critical to building confidence across the ecosystem.” – Stefan Olofsson, SVP, Global Network Product & Enablement, American Express.

“AI agents are beginning to act on behalf of users – accessing credentials, making decisions, and executing transactions with real-world consequences. Without open standards to ensure these delegations are authorized, bounded, and verifiable, we risk a fragmented landscape of insecure, proprietary implementations that introduce new attack surfaces at scale. The FIDO Alliance is uniquely positioned to address this, building on its proven track record of delivering open, phishing-resistant authentication standards at internet scale. At Dashlane, we’ve been building toward this moment combining browser-native credential security with confidential computing to enable secure passkey use by agents without exposing sensitive data. As a FIDO Alliance board member and active contributor to the Credential Exchange standard and AI Study Group, we’re committed to helping ensure agentic authentication is grounded in the same secure, interoperable foundations that have made passkeys successful.” – Frédéric Rivain, CTO, Dashlane

“As a Taiwan-based Board Member of the FIDO Alliance, Egis Technology recognizes Taiwan’s critical role in the global supply chain and the profound impact that AI and agentic AI are bringing to the industry. We are committed to actively engaging in FIDO programs to help shape secure, AI-driven authentication ecosystems and to contributing to trusted standards that address emerging challenges and opportunities in the AI era.” –  Karen Chang, Vice President, Egis Technology Inc.

“Contributing Agent Payments Protocol (AP2) to a trusted industry association like the FIDO Alliance ensures it stays open, platform-agnostic, and community-led as the emerging standard to accelerate the adoption of secure agentic payments. We look forward to contributing to support the protocol’s evolution in this next chapter.” – Stavan Parikh, VP/GM, Payments, Google

“We’re proud to stand with the FIDO Alliance as it takes on one of the most consequential security challenges of the coming years. As AI agents become embedded in how people work, credentials have become the mechanism by which agents act, transact, and make decisions on behalf of real people. Clear standards for how that authorization is established and protected are long overdue, and LastPass is committed to contributing to this important work.” – Karim Toubba, CEO, LastPass

“For agent initiated commerce to scale, user intent must be explicit, verifiable and trusted. That’s exactly what this work with the FIDO Alliance is designed to enable. By contributing Verifiable Intent to the FIDO Alliance’s standards work, and our continued work with other standards bodies, we’re supporting an approach that creates a shared record of user intent that the entire payments ecosystem can rely on” – Pablo Fourez, Chief Digital Officer, Mastercard.

“OneSpan is proud to support the FIDO Alliance’s new Agentic Authentication Technical Working Group as it tackles the critical challenge of proving human intent in an agent-driven world. With decades of leadership in authentication, digital agreements, and transaction signing, we bring real-world experience in helping users securely approve high-risk actions with clarity and control. We’re committed to advancing standards that make human intent verifiable, auditable, and trustworthy.” – Ashish Jain, CTO, OneSpan

“Agentic commerce will reshape how people transact online — but only if users and merchants can trust that an AI agent is acting precisely within the authority granted to it. As a founding member of FIDO Alliance with over a decade of commitment to advancing its mission, PayPal is proud to contribute to these new agentic authentication and payments initiatives, and to extend phishing-resistant authentication and trust infrastructure into a model where user intent is cryptographically verifiable, delegation is bounded, and agents can transact only within authorized limits.” – Rakan Khalid, Head of Identity Product, PayPal 

“Trust in agents can’t be built on one-time checks at delegation. It has to travel through the action and produce a verifiable record that ties every transaction back to a real, verified human. Prove is committing to the FIDO Agentic Authentication and Payments working groups because the industry needs open standards that carry verified user intent, agent identity, and transaction evidence across the full lifecycle. FIDO is the only forum with the track record to drive that at internet scale.” – Nate Soffio, Head of Reusable and Agentic Products, Prove Identity

“AI agents are quickly becoming active participants in digital transactions, initiating and completing actions on behalf of users, not just responding to prompts. Trust at the point of delegation is now critical, particularly as agents begin operating across financial services and other high-risk environments. Thales is working with the FIDO Alliance to help define the standards that will ensure those interactions are secure, verifiable, and aligned with user intent.” – Haider Iqbal, Director, IAM, Thales

“Visa has long believed that open standards are foundational to trusted, scalable digital commerce. As AI agents act on a user’s behalf, interoperable authentication standards are critical to maintaining trust, enabling responsible innovation and facilitating consumer consent.”– Jalpesh Chitalia, Vice President, Growth Products, Visa

Monday, 27. April 2026

GLEIF

The LEI in Numbers: Active LEI Population Surpasses 3 Million in Q1 2026

The Global LEI Foundation (GLEIF) is proud of its ongoing transparency initiatives, including its open approach to providing unrestricted access to the latest LEI data from around the world with the Quarterly LEI System Business Reports, which are made publicly available free of charge. Through this ‘LEI in Numbers’ blog series, GLEIF highlights key data from the latest report, explaining trends a

The Global LEI Foundation (GLEIF) is proud of its ongoing transparency initiatives, including its open approach to providing unrestricted access to the latest LEI data from around the world with the Quarterly LEI System Business Reports, which are made publicly available free of charge. Through this ‘LEI in Numbers’ blog series, GLEIF highlights key data from the latest report, explaining trends and profiling successes from the global LEI rollout.

The Global LEI System surpassed another major milestone in Q1 2026. Around 100,000 organizations from across the world chose to obtain an LEI – whether to support compliance with a regulatory mandate, realize the significant commercial benefits that come from increased trust and transparency, or a combination of both.

Such proactive adoption took the total active LEI population past 3 million, eventually reaching 3.02 million by the end of the quarter. This represents a strong quarterly growth rate of 3.4% and brings the total LEI population – which includes both active LEIs and LEIs that have been retired as entities ceased operations – to over 3.26 million.

The increasing scale and coverage of the Global LEI System further reaffirm its position as a proven, internationally recognized organizational identity management infrastructure and a global Digital Public Infrastructure (DPI). Growing adoption beyond the LEI’s traditional origins in capital markets – such as payments, global value chains, and digital asset markets – reflects the urgent and growing need for greater transparency, accountability, and interoperability across borders and ecosystems. This is why GLEIF is committed to working collaboratively to further the uptake of both the LEI and the verifiable LEI (vLEI) for the good of more organizations, industries, and economies.

The ongoing application of the European Union’s Digital Operational Resilience Act (DORA) was a driver of LEI adoption in Q1 2026, maintaining the trend seen throughout 2025. Latvia had the highest growth rate at the jurisdictional level at 11.5%, with Lithuania (5.9%) and Romania (5.7%) also seeing strong increases in issuance.

Robust growth also continued in India (8.1%). The latest regulatory development came in March, with the Reserve Bank of India (RBI) issuing a master direction making the LEI compulsory for all market participants — including residents and non-residents — in RBI-regulated financial markets. This consolidates existing LEI requirements across government securities, money market instruments, foreign exchange (FX) instruments, and derivatives.

Elsewhere, the Global LEI System's expanding reach was demonstrated by notable growth in Brazil (9%). In addition to the market activities of local LEI issuers, the Central Bank of Brazil (BCB) is preparing its regulatory framework, which, among other advancements, will enable LEI integration in cross-border payments to align with the G20 roadmap.

The Global LEI System empowers everyone, everywhere with open, standardized, and high-quality data that is regularly re-validated to ensure it is accurate, up-to-date, and usable – promoting trust and transparency across the global economy. Key data points tracked within the Quarterly LEI System Business Reports are:

Renewal rates

The Global LEI System is unique in providing absolute transparency regarding when entity data was last verified, with the annual renewal process ensuring that both legal entities and LEI issuers review and re-validate legal entity reference data at least once per year.

Strong growth in new issuance was again complemented by robust renewals in Q1 2026, with the overall renewal rate remaining stable at 56.6%. Renewals in EU jurisdictions tapered slightly to 61.1%, while the increase in non-EU jurisdictions to 49.6% was primarily driven by continued upticks in the U.S. and the UK.

The jurisdictions with the highest renewal rates were Japan (89.3%), Finland (81.8%), India (77.6%), Germany (74.5%), and Saudi Arabia (73.9%).

Corroboration

Corroboration is the process of verifying the existence of a legal entity and its reference data – such as name, address, legal form, and corporate structures – against authoritative sources listed in the GLEIF Registration Authority List. LEI issuers validate the information provided by the legal entity by comparing it against the publicly available authoritative data.

At the end of Q1 2026, 87.6% of LEIs were fully corroborated. This means that all reference data elements have been validated against public authoritative sources.

Parent information reporting

Identifying the direct and ultimate parents of a legal entity, and vice versa, answers the question of 'who owns whom'. This allows users to connect the dots and enables deeper insights into ownership structures across corporate groups.

In Q1 2026, over 3.13 million LEI registrants – representing 99% of the total active LEI population – reported information on their direct and ultimate parents. 100% of LEI registrants that obtained a newly issued LEI or renewed an existing LEI in this quarter reported parent information.

Fund relationship reporting

Many legal entities with an LEI are investment funds. To better understand the relationships between fund entities and investment funds globally, three main types of fund relationships are identified: fund management entities, umbrella structures, and master-feeder structures.

Over 155,000 legal entities reported fund relationship structures in Q1 2026, an increase of nearly 3,000 on the previous quarter. Among those, 66.8% were funds managed by a main management entity, 32.6% were sub-funds to umbrella funds, and 0.6% were feeder funds.

Entity categorization

To address the unique considerations they pose and ensure high data quality, dedicated categories have been created for identifying government entities and international organizations. In Q1 2026, over 6,700 entities were identified as government entities (up from 6,600 in Q4 2025) and 82 as international organizations (up from 81 in Q4 2025).

For the full report, which includes further detail on the status of LEI issuance and growth potential, the level of competition between LEI issuing organizations in the Global LEI System, and Level 1 and 2 reference data, please visit the Global LEI System Business Reports page.

If you are interested in reviewing the latest daily LEI data, our Global LEI System Statistics Dashboard contains daily statistics on the total and active number of LEIs issued. This feature now enables any user to review historical data by geography, increasing transparency on the overall progress of the LEI.

For further details or to access historical data, please visit the Global LEI System Business Report Archive.

We look forward to sharing our progress each quarter as we continue to drive LEI adoption in 2026.


Digital ID for Canadians

Spotlight on Electronic Imaging Systems Corp. (EIS)

1. What is the mission and vision of EIS? Our Mission is to ensure Operational Integrity by offering cost-effective, risk-based solutions with significant ROI and…

1. What is the mission and vision of EIS?

Our Mission is to ensure Operational Integrity by offering cost-effective, risk-based solutions with significant ROI and by building digital trust across the financial sector through a platform that establishes a secure perimeter. One that forensically validates users at the point of transaction, preventing risk before it infiltrates the system. Our vision is to secure the Canadian identity landscape through our Smarter Processing Platform, moving beyond legacy standards to a higher standard of Identity Validation and ongoing Authentication, coupled with a permanent Biological Anchor to ensure authenticity and security.

It is common knowledge that many identity verification sources are rife with fraud. Verifying against pollution within the institutional databases is 1:1 matching against fraudulent activity; the objective is to identify and stop fraud before it gets into the systems, and to filter out synthetic identities before they can cause irreparable harm.

The EIS Smarter Processing Platform is the only comprehensive solution existing today that accomplishes both – built to overcome synthetic identities, even those with genuine government-issued credentials.

2. Why is trustworthy digital identity critical for existing and emerging markets?

Organized crime has set a pace for change that legacy systems cannot match. In 2025, the CAFC and the Competition Bureau confirmed that Canadians lost over $7 billion to fraud, a figure projected to rise to $8.8 billion in 2026 when accounting for non-reporting rates.

For businesses, the stakes are even higher:

Revenue Loss: Canadian businesses lost $111 billion to fraud over the past year, equivalent to 7.2% of total revenue, a 42% increase from 2024. Synthetic Failure: Synthetic fraud persists because we are allowing institutions to continue to use legacy manual and 1:1 matching processes; NIST IAL2 security levels are simply not sufficient within operations that involve the validation and use of identity. Outdated operating processes and systems, both manual and digital, are fueling digital vulnerabilities. Synthetic Identity Fraud is fueled by outdated, manual, paper-based processes that integrate with digital environments to technology-enabled threats, from automated bots to deepfakes. Today, synthetic fraud accounts for over 26% of total fraud losses, highlighting a critical failure in legacy practices integrated with identity verification. The Identity Factory: Organized crime Identity Factories fueled by data breaches and “Agentic AI” are successfully exploiting system gaps to assemble “genuine but fraudulent” personas, which legitimize criminal identities by exploiting gaps in processes, fueling organized crime. Inertia & Lack of Understanding: Governments are trying to legislate and organize themselves out of a crisis, while in the meantime, inertia is fueled by a lack of understanding and individual agendas. This cycle can only be broken when we demystify the processes fueling the fraud, establish standards for enforced adoption, and drive personal and corporate accountability for results, making it impossible for individual organizations to operate differently.

3. How will digital identity transform the Canadian and global economy? How does your organization address challenges associated with this transformation?

Fraud fuels criminality and destabilizes economies at scale. The financial impacts of fraud are paralyzing businesses at all levels and affecting consumers across all areas, from job loss to unaffordable living costs.

We cannot continue to allow government and corporate stakeholders to use legacy habits that enable fraud. Digital trust will transform the economy by ensuring financial security and resilience. By shifting the burden of proof from “KYC – what you know” to “KYC – who they really are” through sequential, thorough, Identity & Veracity Validation practices, combined with persistent, ongoing biometric authentication, and secured by threat-resistant systems and Cryptographic Biometric Binding.

This prevents the “false validation” of synthetic, criminal identities. It establishes a biological disconnection, allowing bad actors to be removed from the economy and the country, and enables the government to act through asset forfeiture and various supporting legislation. EIS addresses these challenges through our API- Driven Intelligence Layer, which provides:

Immediate Transition: A plug-and-play transition to our platform offering NIST IAL3 and AAL3 level validation without requiring major capital expense, and a “rip and replace” of core infrastructure.

The Biological Anchor: We establish a permanent link between the natural human and their verified credentials, using the Jumio Global Network to cross-reference over 1 billion identities in real-time to filter out synthetic profiles. Forensic Veracity: We integrate Clearspeed technology, which identifies neurophysiological risk indicators in the voice within 60 seconds during client attestation. The only platform with a defence against legitimate credentials assigned by the government.

4. What role does Canada have to play as a leader in this space?

For Canada to continue operating according to its values, it must move beyond provincial silos and outdated practices to a national approach backed by stringent legislation and standards. As Auditor General Karen Hogan stated, Canadians must trust that their identity is verified and protected by the highest standards of operational processes and cybersecurity to prevent systemic fraud. The Federal and Provincial systems must quickly align; the regulators must increase their awareness and align their policies. Sovereign Identity Practices are critical to protect the country and our economy. Canada is currently strengthening its legislative and enforcement framework through the following active measures:

Bill C-8, the Critical Cyber Systems Protection Act: This legislation reintroduces the framework of the former Bill C-26 to secure Canada’s critical infrastructure. As of March 26, 2026, the bill passed its Third Reading in the House of Commons and is currently at the First Reading in the Senate. Bill C-12, the Strengthening Canada’s Immigration System and Borders Act: This Act received Royal Assent on March 26, 2026. It modernizes asylum processing and provides the CBSA and law enforcement with enhanced tools to support border security and combat transnational organized crime. Bill C-22, the Lawful Access Act: Tabled for First Reading on March 12, 2026, this bill reintroduces and refines the “Lawful Access” regime (previously proposed in Bill C-2, the Strong Borders Act of 2025) to provide timely access to information for national security investigations. National Strategy: The implementation of the National Anti-Fraud Strategy and the architecture of the new Canada Financial Crimes Agency are foundational steps toward a unified enforcement perimeter. Financial Oversight: The Minister of Finance and National Revenue is working to introduce legislation to establish the Agency by the Spring of 2026. The Federal government is working to lead this transition and ensure a coordinated federal response to systemic financial crime. The provinces are also working on their operational planning. However, the pace of change and lack of national cohesion are costing Canadians daily.

5. Why did your organization join the DIACC?

EIS joined the DIACC to support the architecture of Sovereign Standards and Solutions aligned with the highest global security standards, such as NIST SP 800-63 Revision 4 (July 2025). We are committed to a unified national approach that mandates the use of NIST IAL3 Biological Anchors to protect Canadians’ integrity. We are also committed to bridging the fallacy of manual vs digital oversight; we need to adopt a 360-degree view towards Identity Protection. We hope that, through DIACC, we can help increase the pace and effectiveness of resolution.

6. What else should we know about your organization?

Electronic Imaging Systems Corp. (EIS) has a foundational history of architecting the secure infrastructure
that underpins Canada’s digital economy. We are the pioneers behind the patented cheque imaging and remote deposit technology that catalyzed the migration from paper-based to electronic clearing for major global banks. This innovation has yielded billions in operational savings for the financial sector by eliminating the risks of physical transport and manual processing.

Furthermore, EIS was instrumental in the architecture and delivery of the Teranet project, in which millions of manual drawings and records were digitized and catalogued to a customized hierarchy to form the secure infrastructure for the Province of Ontario’s Electronic Land Registration System. This remains a global benchmark for the integrity and remote accessibility of digital statutory registries.

With a deep understanding of how fraud can destabilize institutions, we intentionally designed the EIS Smarter
Processing Platform to move beyond the status quo of simple 1:1 data matching. Our solution was built to address the “Identity Factory” threat, where criminals obtain legitimate credentials through fraudulent means by establishing a permanent Biological Anchor. We combine our proprietary capabilities with a strategic integration of Jumio, Clearspeed, and ComplyAdvantage to provide a self-funding ROI model:

The Fraud Multiplier: Our platform addresses the critical financial risk where the fraud multiplier for Canadian institutions has reached$4.99 for every $1 lost; a single $10,000 fraud event costs an organization nearly $50,000 in investigation and recovery fees. Appropriate AI: Our AI operates within strictly defined security boundaries where outputs are deterministic, logged, and auditable, aligning with ISO/IEC 27001 and SOC 2 privacy frameworks. Sovereign Data Residency: EIS infrastructure is built specifically for Canadian data residency and exceeds Government, Telecom, and Treasury security standards, ensuring that all identity data remains protected under Canadian jurisdiction.

Contact Information for Official Correspondence:

Corporate Representatives:

Rose Kramer, President (rmk@eisca.com) Kaileen Millard Ruff, Chief Customer Advisor (Kaileen@eisca.com)

Sunday, 26. April 2026

Blockchain Commons

Dispatches of a Trust Architect: Ten Years of Self-Sovereign Identity

Ten years ago this week — on April 26, 2016 — I posted “The Path to Self-Sovereign Identity” on my Life with Alacrity blog. I had been thinking for a while about what a digital identity movement would need to stand for, and the piece ended with ten principles and a request: I seek your assistance in taking these principles to the next level. I did not expect what happened next. Those ten principles

Ten years ago this week — on April 26, 2016 — I posted “The Path to Self-Sovereign Identity” on my Life with Alacrity blog. I had been thinking for a while about what a digital identity movement would need to stand for, and the piece ended with ten principles and a request: I seek your assistance in taking these principles to the next level.

I did not expect what happened next.

Those ten principles — which I had written more as a first draft than a manifesto — became the conceptual foundation of an industry. They have accumulated more than a thousand academic citations. They’ve been quoted, adapted, debated, critiqued, translated, and deployed in contexts I could not have imagined. They anchor work on decentralized identifiers and verifiable credentials, show up in United Nations discussions, and (occasionally) on conference T-shirts. And for most of a decade, they have stayed largely unchanged.

That is, in part, a compliment. And in part, a problem.

Principles written in 2016 could not have anticipated the commodification of behavioral data at the scale we now live with, the normalization of mandatory digital ID as a precondition for civic life, or the ways “self-sovereign” would come to be invoked at the protocol layer, in regulatory filings, and at venture pitches, by organizations whose interests are not the same as the interests of the people the principles were meant to protect.

Capital flows to centrality. We wrote the principles loosely enough that the loopholes were exploitable. And they have been exploited.

I have spent much of the last year talking about this with others in the RevisitingSSI project — working circles on principal authority, anti-coercive design, properties vs. principles, and what it means to exist at all in a digital age. Those conversations, with academics and standards people, with civil society practitioners and critics that I learn from, have convinced me that the original ten were not wrong. They were incomplete.

Today, on the ten-year anniversary, I am publishing the first community draft of a revision:

Principles of Self-Sovereign Identity — 2026 Revised, First Community Draft

A stable archival copy is mirrored at revisitingssi.com/library/ssi-principles-2026-redline/ for permanent reference.

The draft keeps the 2016 language verbatim wherever it survives, so continuity stays legible alongside revision. It updates each original principle, introduces six new ones (Inalienability, Cognitive Liberty, Relational Autonomy, Stewardship, Equity, Anti-Coercive Design), and organizes all sixteen principles into four layers: foundational, relational, technical, and political.

It is unfinished on purpose.

I am publishing it in redline form, on the anniversary, precisely because I do not want it read as a press release. I want it read as a draft: a draft I expect others to push back on, to correct, and to sharpen. That is what I asked for in 2016. It is what I am asking for again.

What has changed is that I now know how long this work takes, and how much of the work that the community has to do.

If you have been in SSI for any length of time — whether as a believer, a skeptic, or both at different hours of the day — the Google Doc is open. Leave comments. Argue in the margins. Tell me where the new language is weaker than what it replaced. Tell me which of the six new principles I should not have added. Tell me which ones I am still missing.

I will be at the Internet Identity Workshop in Mountain View this coming week (April 28–30), as a guest on the W3C Credentials CG call on May 5 (9am PDT / 12pm EDT / 6pm CEST), and hosting a dedicated community discussion on May 20 (10am PDT / 7pm CEST). The goal between now and September, when we aim to present a more mature version at the Global Digital Collaboration summit in Geneva, is to take the redlines from “first draft” to something worthy of the next ten years.

If you would like to be part of that, join the announcements-only email list, the Signal group, or simply open the doc.

The goal is not to settle the questions of self-sovereign identity.

The goal is to make these principles worthy of the next ten years.

Saturday, 25. April 2026

FIDO Alliance

BBC: UK cyber chiefs say it’s time to ditch passwords for passkeys – what are they?

It’s time to ditch passwords for passkeys People in the UK have been urged to start ditching passwords in favour of passkeys, where available, as a way to secure their […]

It’s time to ditch passwords for passkeys

People in the UK have been urged to start ditching passwords in favour of passkeys, where available, as a way to secure their accounts online.

Passwords have long been the default way many people set up and log in to accounts for digital services.

However, the National Cyber Security Centre (NCSC) said on Thursday it was “overhauling decades of security practice” to instead recommend passkeys as the most secure option.

Platforms including Apple, Google and X already let people use them instead of passwords, but what are passkeys, and how do they work?

The advice comes after years of warning people against using simple codes which can easily be guessed, like “123456”, as well as pet names, as passwords.

Against a backdrop of rising data breaches, the NCSC has also repeated warnings against reusing the same password for different sites.

Password managers and multi-factor authentication (MFA) methods have grown in usage as a way to help strengthen and save log-in credentials.

The NCSC believes passkeys may be less vulnerable to hacks and human error, but some experts say they are still “not a silver bullet”.

Thursday, 23. April 2026

FIDO Alliance

National Cyber Security Centre (NCSC): Passkeys are more secure than traditional ways to log in

Passkeys are more secure than traditional ways to log in Passkeys offer a more usable, secure replacement for passwords and are already supported by most modern devices. At CYBERUK 2026 […]

Passkeys are more secure than traditional ways to log in

Passkeys offer a more usable, secure replacement for passwords and are already supported by most modern devices.

At CYBERUK 2026 in Glasgow, the NCSC announced that we will begin recommending passkeys wherever a service supports them, and two‑step verification (2SV) where it does not. This shift will be reflected through our ongoing refresh of guidance rather than as a single sudden change.

This is not a decision taken lightly. It is based on extensive engagement with websites, app developers, technology vendors and the FIDO Alliance, alongside significant technical and sociotechnical research carried out by the NCSC.

As part of CYBERUK, we published a paper comparing – from an individual user’s perspective – the security properties of traditional multi‑factor authentication (MFA/2SV) and FIDO2 credentials, including passkeys.

How we compared different login methods

All credentials go through a lifecycle: they are created, stored and used, and often need to be synchronised, revoked or recovered. At different points in that lifecycle, credentials are vulnerable to different types of attack, and not all attackers have the same capabilities.

By breaking authentication down in this way – and focusing on the most common real‑world attack techniques – it becomes possible to compare very different credential types in a consistent and meaningful way.

Our analysis focused on the attacks most commonly seen against individuals today, including phishing, credential reuse and session hijacking.

Our assessment

From this analysis, the NCSC assesses that: 

All traditional MFA methods – including passwords combined with SMS codes, email codes, time-based One Time Passwords generated by apps or physical tokens, push approvals – are inherently phishable.  FIDO2 credentials, including passkeys, are as secure or more secure than traditional MFA against all common credential attacks observed in the wild.  When user verification is required as part of the login, FIDO2 authentication constitutes multi‑factor authentication. Because FIDO2 removes the ability to cheaply reuse or relay credentials, large‑scale attacks directly targeting correctly implemented passkeys are unlikely.

Wednesday, 22. April 2026

DIF Blog

DIF and Vouched Advance Agentic Identity with KYA-OS as International Demand for Open Agent Identity Standards Grows

Know Your Agent Operating System extends DIF's open identity standards across the full range of agentic protocols; new members join the Trusted AI Agents Working Group (TAAWG) as interest accelerates globally Seattle, WA - Decentralized Identity Foundation (DIF) today announced the renaming of the agentic identity framework, donated to

Know Your Agent Operating System extends DIF's open identity standards across the full range of agentic protocols; new members join the Trusted AI Agents Working Group (TAAWG) as interest accelerates globally

Seattle, WA - Decentralized Identity Foundation (DIF) today announced the renaming of the agentic identity framework, donated to DIF by Vouched, a leader in identity verification and agentic identity infrastructure. The specification, donated in March 2026, will advance under a new name: Know Your Agent Operating System (KYA-OS). The new name reflects the framework's scope as an identity and delegation standard for the full range of agentic protocols, extending well beyond MCP. The framework is being developed under open, community-driven governance through the KYA-OS Task Force within DIF's Trusted AI Agents Working Group.

The announcement comes as agentic identity has moved from a technical concern to a broad industry priority. During a recent tour of Asia, DIF Executive Director Grace Rachmany found that organizations in China and Korea were independently raising MCP-I in conversations about the future of secure agentic AI–a signal that the challenge of agent identity is being felt across markets and organizational types. Since Vouched donated the framework, DIF has also welcomed a meaningful increase in new member organizations joining specifically to participate in its Trusted Agentic AI Working Group (TAAWG).

“We are seeing organizations from across the globe come to DIF because they want to be part of building the answer to agentic identity. It is widely understood that centralized identity solutions break down for cross-organizational Agentic AI, and that the DID and VC standards are a logical starting point for Agentic AI Identity.” said Grace Rachmany, Executive Director at DIF. “KYA-OS gives that work a name that reflects its true scope. The framework Vouched donated is a well-designed specification relevant to any Agentic AI protocol, and particularly relevant for cross-organizational Agentic communication.” 

Standards developed in DIF are developed through collaborative effort, which means that KYA-OS moves beyond belonging to any one company or supporting any one protocol. DIF’s Trusted Agents Working Group (TAAWG) has already created a KYA-OS task force of multiple organizations collaborating both to refine the specification and to develop prototypes based on the specification.

A Standard for MCP and More

KYA-OS uses Decentralized Identifiers (DIDs) and Verifiable Credentials (VCs) to give agents cryptographically verifiable identities, represent delegation as tamper-evident credentials with explicit scope, and enable verification across organizational boundaries without requiring prior coordination between parties. 

KYA-OS defines three conformance levels to support adoption across organizations of different sizes and security requirements:

Level 1: Foundational support using existing identifiers (OIDC, JWT) for immediate implementation. Level 2: Full DID verification, credential-based delegation, and revocation support. Level 3: Enterprise-grade lifecycle management, immutable auditing, and full bilateral KYA-OS awareness.

Early demonstrations have shown how KYA-OS enables verified agents to complete purchases on behalf of consumers, with full verification of which agent is acting, who the human buyer is, and that the necessary permissions have been granted. The result is commerce that is both more seamless for users and more secure for merchants.

“When we built this framework, we knew the identity challenge wasn’t specific to MCP.  It’s a challenge for every agentic system,” said Rosalyn Curato, Chief Innovation Officer and GM of Agentic Security at Vouched. “We donated it to DIF because open standards are how industries solve shared problems. Seeing organizations from across the globe join DIF to work on this, and hearing it come up organically in conversations, tells us the industry agrees. KYA-OS is the right name for what this has become.”

KYA-OS is being developed as a starting point for community co-development, with input from participants across the identity, developer, and enterprise communities. Organizations interested in contributing or joining the Trusted AI Agents Working Group can learn more at DIF.

Learn more about TAAWG About DIF

The Decentralized Identity Foundation (DIF) was established to create an IP-protected environment for decentralized identity-related specifications and open-source code development. DIF promotes the use of DIDs, VCs, and related decentralized identity technologies. DIF maintains more than 270 GitHub repositories that have been contributed or developed by members and working Groups. DIF is committed to fostering an environment where decentralized identity technologies can evolve, mature, and achieve widespread adoption through collaborative effort and strategic partnerships across the ecosystem.

About Vouched

Vouched is pioneering the future of identity verification by delivering technology that quickly and securely validates the identities of both AI agents and humans. The recognized leader in identity verification for healthcare, Vouched has expanded its capabilities across financial services, automotive, and other industries. Vouched is writing the next chapter of the CISO playbook to take advantage of digital IDs and to identify software agents. Each month, Vouched verifies millions of identities with unmatched speed, accuracy, and regulatory compliance–accelerating trust in an increasingly digital world.


Blockchain Commons

Musings of a Trust Architect: Agency in AI

It’s been ten years since I wrote the principles of self-sovereign identity. Though my focus was on identity systems, my underlying concern was always agency: ensuring that individuals remain in control of their own digital lives. Today that concern is more important than ever because of the deployment of LLM-driven agentic systems. We can increasingly empower agents in the digital ecosystem to com

It’s been ten years since I wrote the principles of self-sovereign identity. Though my focus was on identity systems, my underlying concern was always agency: ensuring that individuals remain in control of their own digital lives.

Today that concern is more important than ever because of the deployment of LLM-driven agentic systems. We can increasingly empower agents in the digital ecosystem to compile our searches, to augment our coding, and to generally solve our problems. But how do we do so in a way that supports our autonomy rather than eroding it?

What follows are three views of the agentic future: two problems we need to address and one solution that we can look forward to. They reflect some of the current work I’m doing with various groups on AI, agency, and the future of computing.

View #1: The Authority Problem

The nature of human agency is rapidly changing due to the possibility of agentic delegation and augmentation. Once you could say that an individual’s agency would be maintained by their purposefully and mindfully agreeing to all actions undertaken by an application. But that’s no longer possible when agents can act at superhuman speeds that are too rapid to actively monitor. Maintaining agency therefore requires a change from tactical overview (agreeing to every action) to strategic overview (agreeing to the scope of action and setting boundaries for the activity).

Fortunately, we already have a model that supports this sort of strategic control while maintaining agency: “Principal Authority”. It’s literally part of the Laws of Agency, which define how an agent can be empowered to take on certain tasks. Back in 2021, my work with the Wyoming legislature helped to bring it into the world of digital identity by defining your digital identity as something over which you have Principal Authority.

Following the implicit understanding that an individual has control of their identity, the most important element of Principal Authority is probably its definition of duties. When you are temporarily extending your identity to others, including agents, they must promise to use it in certain ways. Those duties should include many of my original self-sovereign principles, including access, interoperability, minimization, portability, protection, and transparency, as well as many others: agents must work for you in good faith, must put your interests above those of theirs (or rather those of their corporate masters), and must act with reasonable care.

Again, a state legislature has taken the lead on this work. Just this year, Utah passed the state-endorsed digital identity (SEDI) amendment, which includes a full digital Bill of Rights. Among those Rights is a “Duty of Loyalty”, which says that processors of digital identity must act in the identity holder’s best interest.

Creating similar duties and requirements for LLM agents, to ensure that they are working for you, without hidden agendas, is a crucial milestone as the AI era quickly dawns. Principal authority should be a model for doing so. We must use it to answer questions like: Who is an agent delegating from? What is it tasked to do? How can it undertake that task in the way that best protects the Principal and their data? What are the constraints placed on the agent?

I’ve suggested some “predicates” for the Gordian Known Value system that might start to address some of these issues, by allowing users and their agents to record things like:

principalAuthority — The entity with authority over the work assertsDelegationFrom — Agent’s claim of delegation from a principal delegationScope — Boundaries of delegated authority delegationConstraints — Specific limitations on the delegation

But, it’s a starting point, not an end-point.

View #2: The Credit Issue

When you’re using an agent, even if your authority is being protected, another question arises: how do you credit work done?

This isn’t actually a new problem created by AI. Ghost writers have existed for centuries. Collaborations have always involved complex divisions of labor that don’t map cleanly to “author” and “contributor”. What AI does is make the gap undeniable. When an agent is performing actions (or moreso: creating content), we can no longer quietly elide the distinction between “who wrote this” and “who is responsible for it.”

The ghost is visible now.

The question is how we can properly note which work is entirely ours and which is LLM driven. But, it’s not even that simple, as LLMs could be trained largely on our own work, rehashing our arguments and knowledge, or they could be built on the summed-up Wisdom of the Crowd. How do we differentiate between those two situations? And how do we give fair notice to readers who may think differently about spending their time reading an LLM-authored piece, an LLM-supported piece, and a human-written piece?

As I said, the problem goes beyond LLMs and is fundamentally about credit in authorship. Again, I’ve suggested some predicates as a starting point, with my focus not on the question of AI input, but instead what the roles are in a creative process. Those predicates currently include: Author, Editor, Architect, Designer, Manager, ConceptOriginator, Documenter, TechnicalProducer, Curator, Reviewer, Maintainer, MaterialContributor, Performer, IntellectualContributor.

Do we need more? Less? And are these sufficient to also define LLM-driven work on a piece?

View #3: The Self-Sovereign Computing Solution

Though I’ve talked so far about the work I’ve been doing on issues (or at the least, “new questions”) that are arising from the LLM revolution, it’s also important to talk about some of the advantages. And one of the advantages is a growth in the potential of a topic that I’ve addressed before: self-sovereign computing.

In my original article on “self-sovereign computing”, I talked about how you could control your digital destiny by running your own tools on your own local machine. It was yet another way to address the issue of agency.

Local AI on your own silicon is Self-Sovereign Computing in practice. Apple Silicon + MLX + local models make it real infrastructure. There’s no cloud dependency, no data leaving your machine, no subscription toll. Your data stays on your device. Your inference runs on your hardware. No API key is required.

It’s also really coming of its own. Some recent advancements in leveraging the M-series silicon have doubled the inference speed of certain models:

Metal (Q4_K_M quantization):

M1 Max (64GB) M5 Max (128GB) Prompt eval: 64 tok/s 180 tok/s Decode: 27 tok/s 58 tok/s

MLX (nvfp4 quantization):

M1 Max (64GB) M5 Max (128GB) Prompt eval: 9 tok/s 14 tok/s Decode: 52 tok/s 111 tok/s

We built Self-Sovereign Identity so that your keys and credentials could stay under your control rather than being held by a platform that could revoke them. Local inference is the same principle applied to AI: the model runs where you do, on hardware you own. Combined with a self-sovereign wallet holding your keys and credentials, this is a complete stack where nothing about your digital life requires asking permission from a third party.

Final Notes

I’ve long written that identity is a double-edged sword. If wielded right, it can provide us with considerable power, but if wielded wrong, it can wound us fatally.

The same is true of the agentic power being unleashed by the LLM revolution. The possibilities of self-sovereign computing show how this power could be turned to our advantage, truly empowering the self-sovereignty that I’ve long advocated. However, the credit issue demonstrates the new (or at least newly highlighted) questions arising from agentic use, while the authority problem reveals that we need to carefully construct guard rails for this new technology.

If you’d like to talk more about these possibilities email me. I’m also looking for sponsors and partners to support me in doing more of this work.

Tuesday, 21. April 2026

GLEIF

What Post-Trade Infrastructure Really Needs to Be Ready for T+1

Are firms ready for the transition to T+1 settlement in October 2027? The fact that many – particularly in the fund business – still rely heavily on fax to send settlement instructions suggests otherwise. Though the enduring use of fax is emblematic of outdated post-trade operations that urgently require digitalization, the T+1 readiness gap is not primarily a technology problem. It is an underl

Are firms ready for the transition to T+1 settlement in October 2027? The fact that many – particularly in the fund business – still rely heavily on fax to send settlement instructions suggests otherwise.

Though the enduring use of fax is emblematic of outdated post-trade operations that urgently require digitalization, the T+1 readiness gap is not primarily a technology problem. It is an underlying data problem.

Why instruction and data quality hold the key to T+1

When we talk about T+1 readiness, the goal for most firms is a very high straight-through processing (STP) rate. This means full automation from execution through confirmation, matching, and settlement, with no manual intervention.

It is undoubtedly the right goal. But the path to STP runs through a problem that receives less attention than the technology required to achieve it: the quality of the instructions being submitted and the data within them.

In a T+2 world, issues stemming from incomplete instructions, minor formatting discrepancies, missing enrichment data, and mismatched identifiers were often manageable. Operations teams had time to catch exceptions and resolve them before the settlement deadlines passed, without manual intervention.

That buffer disappears under T+1. To avoid failed settlements, instructions must arrive early and be complete and accurate the first time, every time. And the data embedded in those instructions — including the entity identifiers that tell the matching system who is on each side of a trade — needs to be standardized, up-to-date, and globally consistent.

That is precisely what the Legal Entity Identifier (LEI) provides. As a globally recognized, unique identifier for legal entities already embedded in regulatory reporting across more than 100 jurisdictions, the LEI provides post-trade systems with a common reference point for counterparty identification across institutions, borders, and asset classes. Its digital counterpart, the verifiable LEI (vLEI), allows counterparties to verify who within an organization is authorized to act computationally, and in what capacity.

Given their ability to ensure high-quality instructions, the LEI and vLEI are a fundamental enabler of T+1 settlement — supporting safer, faster, and more efficient transactions while also providing firms with a trusted foundation to enhance post-trade operations and functions.

From reporting what happened to anticipating what will

The better instruction and data quality demanded by T+1 enables firms to establish a different relationship with data altogether.

Post-trade functions have historically operated in hindsight: transactions occur, data is generated, and reports are produced. Now, there is an opportunity to give firms real-time visibility into the quality and status of their own settlement data, with predictive tools surfacing potential problems before they fail, enabling rapid exception handling.

And as the operational dependencies of T+1 extend well beyond settlement itself, there are also wider benefits. For instance, firms can know in advance where liquidity will be required and where collateral needs to be allocated.

Part of what makes this practically achievable now is the application of artificial intelligence to post-trade data. Natural language interfaces allow clients to interrogate complex settlement datasets without needing specialized technical skills — asking questions of their own data in plain language and receiving answers they can act on immediately.

But for this proactive approach to be effective, the underlying data must still be reliable. Predictive tools built on inconsistent reference data will produce incorrect predictions. But when the data foundation is sound, the operational possibilities are genuinely transformative.

A different kind of trust layer

With post-trade operations also prime for digitalization, the vLEI in particular has significant potential to streamline platform onboarding and improve access, thereby increasing trust in transactions.

As Clearstream demonstrated at the Global vLEI Hackathon, the vLEI can serve as a secure login standard for post-trade platforms. For platform access, the entity logging in to submit a settlement instruction can be verified not only as a known counterparty but also as a verified representative of a verified organization, acting within a confirmed scope of authority. That verification happens computationally, without manual checks, and is consistent across borders.

This has significant benefits for cross-border settlement. Counterparties operating under different legal and regulatory regimes currently rely on bilateral arrangements to establish trust. The vLEI provides an alternative: a shared, independently governed trust layer that any institution can rely on, regardless of its location or the legal system under which it operates. What was once negotiated separately for each relationship becomes part of the infrastructure itself.

T+1 is the milestone. T+0 is the direction

October 2027 is the target for T+1 across the EU, Switzerland, and the UK. But if settlement efficiency continues to improve — if STP rates rise and exception handling becomes fast enough — the logical endpoint is T+0, meaning same-day settlement, at scale, across asset classes and borders.

High-quality data builds the trust that makes this possible. Trust is not an abstract principle in the context of post-trade operations — it is a precise description of what makes settlement work and underpins what T+1 readiness means. Recognizing organizational identity as an enabling infrastructure means that this trust can be hardwired into every transaction.

Data and the verifiable identity on the road to T+1

What T+1 readiness actually demands from post-trade data infrastructure, why instruction and quality remains the most underestimated bottleneck in straight-through processing, and how verifiable organizational identity is being applied to post-trade platforms — from real-time settlement analytics to secure counterparty authentication — were at the heart of my recent Trust Talks conversation with Eva- Maria Keller, Head of Data, Channels and Digital Operations at Clearstream, part of Deutsche Börse Group.

We explored why the shift from hindsight reporting to predictive post-trade operations changes what firms can actually do before a settlement fail occurs, how Clearstream's Next Data Suite is putting that capability into practice, and what it means for the industry to have a shared, computationally verifiable trust layer for cross-border settlement.

Listen to the full Trust Talks episode to explore what the road to T+1 — and beyond — really requires, and why the data behind every settlement instruction matters as much as the technology processing it.

Monday, 20. April 2026

Digital ID for Canadians

DIACC Threat Briefing: Synthetic Identities and Deepfakes

The New
Fraud
Landscape. Synthetic Identities, Deepfakes, and How Canada’s Defences Must Evolve

AI-driven identity fraud has moved from an emerging risk to an active, material threat to Canadian organizations across every sector. The tools are cheap, the attacks are scalable, and Canada’s defence posture has structural gaps that individual institutional investment cannot close.

Download the Full Briefing Companion resource

Quick-Start Guide: Immediate Defences Against AI Identity Fraud

14 specific, low-cost actions for SMEs and professional firms – deployable within days.

Review the Quick-Start Guide Bottom line

Individual institutional investment is not enough. Sophisticated attacks now exploit gaps between institutions. A fabricated identity can open an account at one bank, build credit history at another, and monetize through a third, with no single organization ever seeing the full picture.

Why current protections are failing

Three Structural Gaps No Single Organization Can Close

Canada’s major financial institutions are investing. AI-enabled identity fraud is a system-level threat that requires system-level coordination.

01

02

03

Fragmented Threat Intelligence

The CCCS, FinCEN, and vendor threat reports all contribute to the picture. No single resource synthesizes them into a unified, Canadian-contextualized model with actionable implementation guidance. The coordination layer does not yet exist.

Standards Without Canadian Implementation Guidance

NIST SP 800-63-4 now mandates deepfake and injection-attack controls — but provides no Canadian regulatory mapping. Canada’s own guidance (ITSP.30.031 v3) predates generative AI entirely, leaving organizations to interpret U.S. and EU frameworks without sector-specific adaptation.

No Cross-Sector Identity Assurance Interoperability

Synthetic identities exploit the gaps between institutions. Individual detection investment cannot close this gap without shared indicators, common verification standards, and the ability to trust identity assurance across sectors. PCTF has proven this is technically achievable — but scale requires ecosystem coordination.

What is at stake by sector

Where the Exposure Is Highest

The structural defence gaps create differentiated risk across Canada’s economy. New account fraud and account takeover fraud are concentrated differently by sector — calibrating control investment to your dominant vector matters.

SECTOR

PRIMARY THREAT VECTORS

SPECIFIC RISK FACTORS

Financial Services

Synthetic identity account opening; credit bust-out; deepfake-authorized payments; AML evasion

OSFI/FINTRAC obligations; open banking expansion; Payments Canada integrity; credit union exposure

Legal

Remote client identity verification fraud; trust account exploitation; deepfake impersonation for conveyancing fraud

700K+ remote IDV transactions reported by members; expanding remote practice; passports account for 44% of fraudulent documents submitted in the professional services sector globally

Healthcare

Patient identity fraud; prescription fraud; benefits fraud; health data access

Provincial health card verification; Canada Health Infoway standards; health privacy legislation

Government

Benefits fraud; synthetic identity for credential issuance; election interference; citizen service exploitation

Provincial digital ID programmes (BC: 4.6M users); federal service delivery; democratic process integrity

Telecommunications

SIM swap fraud; subscriber identity fraud; account takeover; deepfake customer service manipulation

Telcos as identity verification anchor for other sectors; CRTC requirements

Energy / Critical Infrastructure

Insider identity compromise; SCADA/OT access via identity exploitation; supply chain identity fraud

CCCS critical infrastructure designation; CI protection legislation; OT/IT convergence

DIACC’s planned response

What Comes Next From DIACC

This briefing is the first in a series under the Fraud Resilience & AI Readiness pillar of DIACC’s 2025–2030 Strategic Framework.

Implementation Guide Controls for managing AI threat vectors (synthetic identities & deepfakes), mapped to PCTF conformance criteria and NIST SP 800-63-4

PCTF Conformance Addendum Conformance criteria for AI-supported identity verification, integrated into the Pan-Canadian Trust Framework

Sector-Specific Resources Beginning with financial services and legal, building on 700K+ verified identity transactions already in production

Trust Framework Expert Committee Open invitation for member organizations to contribute threat intelligence and engage in developing conformance criteria

 

Get involved.

Review the briefing, contribute threat intelligence, or engage with TFEC by contacting us.

Download the Full Briefing

DIACC Quick-Start Guide: Immediate Defences Against AI Identity Fraud

Fraud Resilience for Small and Medium Enterprises, Professional Firms, and Resource-Constrained Organizations

Disclaimer

This guide is published by the Digital ID & Authentication Council of Canada (DIACC) for general informational purposes only. It does not constitute legal, regulatory, financial, or professional cybersecurity advice. Organizations should assess recommendations in light of their risk profile, regulatory obligations, operational environment, and existing security posture. DIACC encourages readers to consult qualified professionals before making security investments or policy decisions. References to specific technologies, standards, or product categories are illustrative and do not constitute endorsement of any particular vendor or solution.

Bottom Line

Small and medium-sized enterprises face disproportionate exposure to AI fraud. Enterprise-grade biometric injection defence is often cost-prohibitive for organizations with fewer than 500 employees and limited IT budgets. But the most effective defences against deepfake-enabled fraud are procedural, not technological, and many cost nothing to implement.

This guide provides fourteen practical actions that can be deployed within days. Most require only staff time and process change; the heaviest investment is in organizational discipline, not technology.

A note on terminology: While this guide uses “deepfake” as the most accessible term, technical specialists will recognize that the underlying threat is broader. Deepfakes are one attack vector within the category of biometric injection attacks, which include manipulated photos, synthetic videos, and compromised camera inputs. State-of-the-art defences focus on Injection Attack Detection (IAD) across multiple layers. The procedural controls in this guide complement, rather than replace, certified technical detection systems.

The urgency is real. The Canadian Anti-Fraud Centre recorded $638 million in reported fraud losses in 2024, up from $577 million in 2023. Only 5–10% of fraud is reported, suggesting actual losses may be an order of magnitude higher. Equifax Canada data shows synthetic identity fraud in credit applications nearly tripled in a single year.

Who This Guide Is For

This guide is written for:

Managing partners of professional firms (legal, accounting, consulting) CFOs and controllers at mid-market companies (50–500 employees) IT managers at organizations without dedicated cybersecurity staff Anyone who authorizes payments, verifies identities, or manages client relationships remotely

Cost Scale

$ = Staff time and process change only: no technology procurement required

$$ = Modest direct cost: per-user credentials, consultant hours, or policy premium adjustments

$$$ = Significant investment: technology procurement, vendor evaluation, or infrastructure change

Action 1: Call-Back Verification

Cost: $ (staff time)  |  Impact: High

For any changes to banking details, high-value invoice payments, or wire instructions, organizations should call back using a pre-existing number already recorded in their CRM or vendor file. The number provided in the email, message, or video call that initiated the request should never be used for verification.

This single control would have prevented the $25.6 million Arup deepfake loss. A finance employee joined a video call where every participant, including the purported CFO, was an AI-generated deepfake. Had the employee called the CFO’s known direct line before authorizing the transfers, the fraud would have collapsed.

Important: When receiving a call-back, verify the caller’s identity before sharing any confidential information. Fraudsters increasingly use vishing (voice phishing) to impersonate legitimate companies. Until strong caller authentication is widely deployed, treat inbound calls with appropriate skepticism and never volunteer sensitive data unless you initiated the call to a number you independently verified.

Implementation: Write a one-paragraph policy. Distribute it to relevant staff. Treat compliance as an operational priority.

Action 2: 24-Hour Cooling Period for Urgent Requests

Cost: $ (staff time)  |  Impact: High

Organizations should consider implementing a mandatory delay period – 24 hours is a common benchmark – on any “urgent” request to change payroll deposits, redirect vendor wire instructions, or modify banking details, regardless of who appears to be making the request.

AI-driven fraud relies on urgency. Any control that introduces a deliberate pause into high-risk workflows degrades the attacker’s ability to exploit real-time deception. If a request is legitimate, a short delay will not matter. If it is fraudulent, that delay may be the difference between loss and prevention.

Implementation: Document this as formal policy so employees have organizational backing to resist pressure. The phrase “our policy requires a hold period on all payment changes” removes the individual from the decision and makes social engineering significantly harder.

Action 3: Dual Authorization for High-Value Transactions

Cost: $ (staff time)  |  Impact: High

No single individual, regardless of seniority, should have unilateral authority to initiate a wire transfer or payment above a defined threshold. The appropriate threshold will vary by organization, but implementing dual authorization for transactions above a level that reflects your normal operating pattern is a well-established treasury management control.

Implementation: Review your banking platform’s authorization settings and configure dual-signatory requirements for transactions above your chosen threshold. If your current platform does not support this capability, this should be a factor in your next provider evaluation.

Action 4: Pre-Shared Authentication Protocols

Cost: $ (staff time)  |  Impact: High

For long-term client and vendor relationships, particularly in legal, accounting, and real estate, organizations should establish a non-digital “safe word,” authentication phrase, or challenge-response protocol during initial in-person or high-trust onboarding. This key should then be required for all future remote identity verifications involving sensitive instructions.

This simple protocol defeats any deepfake that has not compromised the pre-shared secret. A threat actor can clone a client’s voice, generate a convincing video of the client’s face, and produce forged documents, but they cannot know a phrase exchanged privately in a meeting room.

Selecting strong secrets: Choose authentication phrases that cannot be easily guessed through social engineering, avoid children’s names, birthdays, or publicly available information. Use random phrases or inside references known only to the parties involved. Never transmit the secret digitally after initial establishment, and refresh it periodically (e.g., annually) through secure channels.

Implementation: At your next in-person meeting with key clients and vendors, agree on a challenge-response phrase. Record it securely in your relationship management system (not in email). Apply it consistently.

Action 5: Phishing-Resistant Multi-Factor Authentication

Cost: $$ (per-user credential cost plus IT configuration)  |  Impact: High

Standard SMS and email-based multi-factor authentication is increasingly vulnerable to AI-driven social engineering, SIM swap attacks, and real-time phishing proxies. Organizations should evaluate phishing-resistant authentication methods, such as FIDO2-based security keys, passkeys, or other hardware-backed credentials, that cannot be bypassed through deepfake social engineering, intercepted via SIM swap, or defeated by AI-generated phishing.

The key capability to prioritize is phishing resistance: authentication that is cryptographically bound to the legitimate service and cannot be replayed or intercepted by an attacker, even one using sophisticated real-time social engineering.

Verifiable Credentials (VCs) offer additional advantages. They are phishing-resistant and carry identity attributes that can support richer verification workflows. As the VC ecosystem matures and more services support credential presentation, organizations should monitor PCTF-certified VC solutions as a next-generation option.

Implementation: Identify employees with access to financial systems, client data, or identity verification workflows. Evaluate phishing-resistant authentication options compatible with your existing platforms (most major cloud productivity suites and banking portals now support multiple phishing-resistant methods). Budget for both primary and backup credentials per user.

Action 6: Email Domain Authentication (DMARC/SPF/DKIM)

Cost: $ (IT staff or consultant time)  |  Impact: Medium-High

Generative AI has made phishing emails grammatically perfect and contextually convincing. Human-layer detection is no longer a reliable primary defence. Email authentication protocols, specifically SPF, DKIM, and DMARC, help ensure that spoofed emails purporting to come from your organization’s domain are flagged or rejected by receiving mail servers.

Implementation: Work with your IT provider or email hosting service to configure SPF, DKIM, and DMARC records for your email domain. A phased approach is recommended: start with DMARC in monitoring mode to verify legitimate mail flows, then move to enforcement. Most major email platforms provide configuration guidance at no cost.

Action 7: In-Person Identity Anchoring Where Feasible

Cost: $ to $$ (travel, scheduling, delayed onboarding)  |  Impact: Medium

Wherever geographically feasible, organizations should consider conducting initial identity verification with a new client or high-value vendor in person. This session can establish a trusted reference baseline: a known phone number, a pre-shared authentication protocol (Action 4), a verified signature, and direct personal contact without a screen.

This baseline anchors all future remote interactions. If someone contacts you claiming to be this person but cannot produce the pre-shared key, or if the phone number doesn’t match, you have a reliable signal that something may be wrong.

Implementation: Build this into your client and vendor onboarding process. For existing high-value relationships where onboarding was entirely remote, consider scheduling an in-person or independently verified verification session when practicable.

Action 8: Cyber Insurance Review

Cost: $ (review) to $$ (policy upgrade or endorsement)  |  Impact: Critical for loss recovery

Many standard cyber insurance policies exclude losses arising from an employee’s “voluntary” transfer, even when a deepfake impersonation induced that action. This coverage gap means organizations may be uninsured against the most likely AI fraud scenario they face.

Demonstrating due diligence through security controls such as those outlined in this guide may reduce premiums or improve coverage terms. Insurers increasingly use account classification to assess risk; organizations without basic procedural defences may face higher costs or exclusions.

Implementation: Request your insurer’s specific policy language on social engineering coverage, funds transfer fraud, and AI-enabled impersonation scenarios. Verify whether deepfake-induced “voluntary” transfers are explicitly covered. If they are not, discuss endorsement options with your broker or evaluate alternative providers. The premium difference is typically modest relative to the exposure.

Action 9: Explicit “No Exceptions” Authority Rules

Cost: $ (policy + leadership alignment)  |  Impact: High

Organizations should explicitly define which requests can never be approved via email, video call, or messaging alone, regardless of who appears to be making the request.

AI fraud succeeds when perceived seniority overrides process. Deepfake impersonation attacks regularly exploit “I’m the CEO, just do it” scenarios. A documented “no exceptions” rule removes ambiguity and protects employees from pressure.

Implementation:

Create a one-page authority matrix stating:

Which actions always require offline or out-of-band verification That no individual (including the CEO, CFO, or Board Chair) can override this policy verbally That escalation is encouraged and protected, never penalized

Reinforce this rule verbally in leadership meetings, so staff know it is genuinely supported.

Action 10: Out-of-Band Confirmation for First-Time Requests

Cost: $ (process documentation)  |  Impact: High

The first occurrence of any sensitive action (first wire to a vendor, first payroll change for an employee, first change of authorized signatory) carries disproportionate risk.

AI fraud actors often exploit “first-time” workflows because organizations lack historical patterns to spot anomalies.

Implementation: Require a second communication channel, not just a second approver, for all first-time-sensitive actions (e.g., phone call + system approval or in-person + platform approval). Document this as a permanent onboarding rule, not a discretionary check.

Action 11: Staff “Refusal Language” Training

Cost: $ (training materials)  |  Impact: Medium-High

Employees often comply with fraudulent requests not because they are convinced, but because they don’t know how to safely refuse or delay a request from someone who appears senior or urgent.

Providing pre-approved refusal language gives staff a powerful defensive tool against social engineering.

Implementation:

Distribute 3–5 approved phrases such as:

“Our policy requires an offline verification step before I can proceed.” “I’m happy to help once the 24-hour hold period completes.” “This transaction requires confirmation through our standard process.”

Reinforce that using this language is compliance, not obstruction.

Action 12: Known-Good Contact Vault

Cost: $ (CRM configuration)  |  Impact: Medium

Organizations often store “verified” phone numbers and contacts across emails, spreadsheets, and ad hoc notes, making it easier for fraudsters to inject false information over time.

Implementation:

Create a single, restricted source of truth for:

Executive contact numbers Trusted client and vendor contacts Banking verification references

This can be a secure CRM field or internal system, but not email or chat. Restrict editing rights and audit changes quarterly.

Action 13: AI Impersonation Awareness Briefing

Cost: $ (staff time)  |  Impact: Medium

Many staff still assume video = real. A short, focused briefing on current AI impersonation capabilities materially improves skepticism without inducing fear.

Implementation:

Run a 15-minute internal briefing covering:

Real-world deepfake fraud examples (finance, legal, HR) Why “seeing and hearing” is no longer proof Which internal policies protect them when something feels wrong

This should be framed as permission to slow down, not an added burden.

Action 14: Log and Review Near-Miss Events

Cost: $ (tracking process)  |  Impact: Medium

Near-misses (attempted fraud that didn’t succeed) often go unrecorded, wasting valuable intelligence.

Implementation:

Create a lightweight internal log for:

Suspicious requests Unusual urgency or pressure attempts Failed verification attempts

Review quarterly to detect patterns and adjust policies. This creates learning without blame.

What These Actions Do Not Cover

This guide addresses immediate, low-cost procedural defences. It is not a substitute for a comprehensive security architecture. Organizations should also evaluate:

Biometric verification and liveness detection – requiring vendor evaluation and technology investment Injection Attack Detection (IAD) – certified solutions that detect manipulated camera inputs, virtual cameras, and synthetic media Synthetic identity detection in credit and lending operations – requiring specialized analytics capabilities Incident response and forensic procedures – requiring planning and potentially external partnerships Regulatory reporting obligations – including FINTRAC suspicious transaction reports, CAFC reporting, and sector-specific requirements A Note on Visual Detection

During standard video calls, some techniques may reveal a real-time deepfake, such as asking the person to pass a physical object in front of their face or turn their head rapidly to profile. These checks can sometimes cause visible artifacts in the deepfake overlay.

However, the reliability of visual detection is degrading as the underlying technology improves. Research indicates that face-swap tools are specifically adapting to handle occlusion and rapid motion. Studies have found that only a fraction of people can correctly identify all deepfakes when presented with a mix of real and synthetic content.

Professional-grade detection: Visual inspection alone is insufficient for high-stakes decisions. Certified Injection Attack Detection solutions employ multiple layers of defence:

Cybersecurity controls (virtual camera detection, session integrity) Data provenance and forensic analysis (camera fingerprints, image metadata) ML/AI-based image analysis (trained to distinguish synthetic from authentic content)

Visual inspection should be treated as a supplementary signal, not a primary control. Organizations that rely solely on video calls for high-value decisions should plan to evaluate PCTF-certified liveness detection and injection attack defence capabilities as budgets and operational needs allow.

Next Steps

If this guide is useful to your organization, three steps follow:

Implement Actions 1–4 and 9–14 this week. They require staff time only and take effect immediately. Budget for Actions 5–6 this quarter. Phishing-resistant authentication and email domain authentication represent among the highest-return security investments available to any organization right now. Contact DIACC to explore PCTF conformance for your identity verification processes and connect with DIACC’s member network for technology guidance on certified detection solutions.

DIACC – Where Digital Trust Means Business

contact@diacc.ca  |  diacc.ca


The Engine Room

Get involved: Mapping community-centered AI tools for climate action in the Global Majority

Across the Majority World, communities, grassroots organizations, and non-profit actors are building AI systems to address climate justice. However, many remain overlooked or underrepresented in global conversations about AI and climate. As part of our AI for Climate Action initiative, which explores how AI technologies can be  re-imagined and re-directed by centering locally developed, and

Across the Majority World, communities, grassroots organizations, and non-profit actors are building AI systems to address climate justice. However, many remain overlooked or underrepresented in global conversations about AI and climate.

As part of our AI for Climate Action initiative, which explores how AI technologies can be  re-imagined and re-directed by centering locally developed, and community-centered models in Majority World contexts, we will conduct research to explore AI adoption in the context of climate action.

The post Get involved: Mapping community-centered AI tools for climate action in the Global Majority appeared first on The Engine Room.

Saturday, 18. April 2026

Project VRM

The Original and the Eventual Intention Economy

A recent post by Simon Taylor on X expresses something important about AI agents and markets: if an AI agent arrives in a market with a clear mandate— Get me X. Budget Y. Constraints Z. —it obsolesces business-as-usual for digital marketing. See, all of martech and adtech starts with the assumption that human intent is […]

The Intention Economy subtitle. It’s the whole thing, right there.

A recent post by Simon Taylor on X expresses something important about AI agents and markets: if an AI agent arrives in a market with a clear mandate—

Get me X. Budget Y. Constraints Z.

—it obsolesces business-as-usual for digital marketing.

See, all of martech and adtech starts with the assumption that human intent is fuzzy and manipulable—and that the best customers are captive and manipulated. Let’s look at this from three angles, which are also the three things that happen in markets:

transactions conversations relationships.

On the transaction side, companies invest heavily in tracking people, analyzing their behavior, targeting ads at them, and then (in many cases) rationalizing extremely wasteful results. Plus, of course, discounting or ignoring boundless negative externalities, such as the annoying people to new extremes and massively abusing personal privacy. (In fact, the system treats absent personal privacy as a base feature.) Anyway, the entire surveillance-based advertising fecosystem exists to guess what people want, or to influence what they might want.

On the relationship side, all we have so far is on the sell side: CRM, for Customer Relationship Management, and CX, for Customer Experience. We’ve been trying here to build (or to encourage building) systems for VRM, for Vendor Relationship Management, to give CRM customer hands to shake. But, in VRM’s absence, CRM is all we’ve got. One hand clapping. Or slapping. Or pushing prospects into a funnel.

What many of us, including Simon Taylor, suggest is facilitating conversation through AI agents. Simon’s case, specifically, is that an agent representing a person doesn’t need to be guessed at. It already knows the user’s intent. So there is no attention to capture and no desire to manufacture or manipulate. The demand signal is clear from the start. That’s why he says agents can collapse the attention economy.

The underlying shift in this direction has been visible for a long time. In The Intention Economy: When Customers Take Charge (Harvard Business Review Press, 2012), I argued that markets work best when customers drive them with clear signals of demand, rather than when sellers try to infer demand through surveillance and unwelcome persuasion. I also said markets can be far richer and more vital when customers and companies operate as equals, with relationships based on mutual interest rather than forms of coercion (such as “loyalty” programs that aren’t).

The work of Vendor Relationship Management (VRM) has been about correcting that imbalance.

Instead of companies managing relationships with customers through CRM (Customer Relationship Management) systems, we need customers able to manage relationships with vendors through VRM (Vendor Relationship Management) tools.

Note that relationship is the middle name of both CRM and VRM. Markets are not just about transactions. They are about relationships that continue over time.

That’s why a working intention economy will involve far more than simple buying transactions.

As Esteban Kolsky once put it, companies often focus almost entirely on the “buy cycle.” But customers live mostly in the “own cycle”—the long period of using, maintaining, fixing, improving, and learning from the products and services they already have:

In an intention economy, intelligence about that experience flows both ways between customers and companies. I wrote about this recently here:

Market intelligence that flows both ways.

VRM has long described one key mechanism for this: intentcasting, where customers signal their needs directly to the market rather than being targeted by guesses and ads.

Agents may make this far more feasible than it was when we first started talking about VRM nearly two decades ago.

But there’s an important point that often gets missed in current AI discussions.

The agency that matters most is the person’s, not the agent’s.

A personal AI agent is an instrument—like a phone, a computer, or a car. It acts on behalf of the individual, but the intention behind it must be the person’s own.

And that leads to another requirement:

The only truly personal agents will be owned and operated by individuals.

We don’t have that yet.

What we have instead are assistants that live inside corporate systems—helpful, sometimes impressive, but ultimately operating within feudal structures run by very large companies.

They are, at best, friendly suction cups on the tentacles of giants.

Individuals may well rent or borrow AI models from those giants. But the agents that represent us should operate inside our own environments, in our exclusive interest, rather than inside corporate systems whose interests may diverge from ours.

In other words, our agents should live in our own castles, not inside someone else’s kingdom.

When that happens—when individuals can show up in markets through tools they control—then the deeper shift becomes possible: from guesswork based on surveillance of captive customers to servicing self-qualified leads from free customers in the open marketplace.

Markets then begin to work the way markets are supposed to work: with demand and supply meeting in the open, in relationships that can last far beyond a single transaction.

This is also where work like MyTerms and the emerging ecosystem around personal AI becomes important. If individuals are to operate in markets through their own agents, those agents need ways to assert the person’s terms, preferences, and boundaries in forms that other systems can recognize and respect.

That is the direction VRM has been pointing for nearly twenty years: toward a world where individuals can arrive in markets with their own tools, their own data, and their own terms—and where markets can finally listen.

When that happens, markets will stop guessing what customers want—and start hearing them.

[Later… I actually wrote this post about a month ago, and put off publishing it while I worked on other things. Meanwhile, Adrian Gropper posted A Fork in the Road, which is required reading. I thank him for reminding me in the comments below, and for being a founding participant in ProjectVRM—going back to our earliest meetings almost 20 years ago.]

Friday, 17. April 2026

Velocity Network

Transcrypts Joins the Velocity Network Foundation

The post Transcrypts Joins the Velocity Network Foundation appeared first on Velocity.

Thursday, 16. April 2026

GLEIF

Who's Behind the Call? Why Digital Communications Need Verifiable Organizational Identity

The hundreds of millions of fraudulent and spam calls and messages received every day are a significant and growing societal problem. In response, enterprises and network operators have invested heavily in fraud detection systems, AI-based filtering, and pattern recognition to identify illegitimate calls and messages. These tools have delivered meaningful results but share a fundamental limitat

The hundreds of millions of fraudulent and spam calls and messages received every day are a significant and growing societal problem.

In response, enterprises and network operators have invested heavily in fraud detection systems, AI-based filtering, and pattern recognition to identify illegitimate calls and messages. These tools have delivered meaningful results but share a fundamental limitation: they are reactive. They identify fraud after a communication has already entered the network, rather than preventing it from appearing to originate from a trusted source in the first place.

The billions of communications now flowing through global networks every day make any purely detection-based approach increasingly difficult to sustain. And as AI-generated voice becomes capable of replicating a person or an organization with high fidelity, the question of whether a communication is real or fabricated is becoming impossible to answer through analysis alone.

What is needed is not better detection. It is a way to verify the identity of the organization behind a communication before it reaches its destination.

The question that national systems cannot answer alone

Telecommunications has always been governed at the national level. Regulatory authorities control how numbers are allocated, which carriers can operate, and what standards apply within their jurisdiction. That model served the industry well for decades, but times have changed irrevocably. Digital communications constantly cross borders, and when they do, the jurisdictional certainty that underpins national systems disappears. A call originating in one country and terminating in another carries no shared, standardized proof of its sender, meaning the recipient has no reliable mechanism to verify the identity of the originating organization.

This stems from the layered way authority flows through a telecommunication. A national regulatory authority assigns number blocks to licensed carriers; a carrier allocates numbers to enterprises; and an enterprise may delegate the use of those numbers to a cloud contact center or a web conferencing platform operating in another jurisdiction. By the time a call reaches the recipient, it has passed through multiple parties, each with different responsibilities and different authority.

Today, that chain of delegation cannot be verified. A recipient has no way of knowing whether the number on their screen is being used legitimately at each stage or was taken without authorization.

This is the gap that the Global LEI System, maintained by GLEIF as an internationally recognized organizational identity management infrastructure and a global Digital Public Infrastructure (DPI), can fill. It provides the only globally governed, ISO-standardized identifier for legal entities: the Legal Entity Identifier (LEI). Its digital counterpart, the verifiable LEI (vLEI), extends that standard into the digital domain. It allows counterparties to computationally verify not just which organization a communication claims to come from, but who within that organization is authorized to act on its behalf, and on what basis.

That distinction carries real weight for telecommunications. Knowing that a call is associated with a particular company is one thing. Knowing that the number in use has been legitimately delegated to that company by the carrier that allocated it, under a regulatory framework that authorized the allocation, is another. The vLEI makes this second kind of verification possible across borders.

Identity that travels with the communication

The vLEI is built on a cryptographic system that allows authority to be chained from one party to the next in a tamper-resistant, globally readable way. The delegation from 'regulator' to 'carrier' to 'enterprise' to 'contact center' can be represented as a verifiable data structure, traceable back to a recognized root. It becomes possible to ask not just who a number was originally assigned to, but whether every party in that chain had the authority to use it, and to receive a cryptographically provable answer.

The cryptographic system making this possible is built on KERI (Key Event Receipt Infrastructure), an open standard for creating and managing cryptographic identifiers that do not depend on a central registry or intermediary. Rather than asking a trusted third party to validate a credential, KERI roots trust directly in cryptographic key pairs controlled by the identity holder. For telecommunications, this is significant. It means the delegation chain from 'regulator' to 'carrier' to 'enterprise' can be verified by any party in any jurisdiction without querying a central authority.

This enables decentralized, cross-border verification at the scale the industry requires and changes what trust in communications can mean. For instance, instead of filtering out fraudulent calls after they enter the network, an enterprise can demonstrate, before a call is placed, that the number, organization, and authorized person behind it are all verifiable. Rather than relying on a caller ID that anyone can spoof, businesses could project a brand identity, confirmed by a verifiable credential. Rather than asking users to judge whether a call looks legitimate, they would be able to know.

A principle that extends beyond the phone call

The logic at work here is not limited to voice calls or text messages. Any digital communication, document, or data exchange raises the same question: which organization stands behind this, and can that be verified? The same credential that establishes organizational identity in a telecommunications context can be used to sign a regulatory filing, authenticate a trade document, or verify a supplier certification. The infrastructure does not need to be rebuilt for each use case. The root of trust is shared.

This matters because alternative identity systems built independently for different domains and use cases create fragmentation, which is itself a security risk. The more that separate identity frameworks proliferate, the harder it becomes to establish consistent standards, and the easier it becomes to exploit the gaps between them.

In contrast, the Global LEI System – as a globally recognized, publicly accessible, and independently governed organizational identity infrastructure – makes consistent verification possible across sectors and borders.

Because it is open to any carrier, regulator, or enterprise, it functions as shared infrastructure rather than another proprietary silo. That neutrality makes it viable as a root of trust across competing networks and borders.

Revolutionizing trust in telecommunications

The limits of detection-based approaches to communications fraud, and the case for verifiable organizational identity as a more durable foundation, were central themes in my recent Trust Talks conversation with Randy Warshaw, Co-Founder and CEO of Provenant.

We explored why the reactive model of fraud prevention is running into the limits of what AI now makes possible, how the vLEI can serve as a shared root of trust for business communications across jurisdictions, and why proving the chain of delegation behind a phone number may be the key to rebuilding trust in digital communications at scale.

Listen to the full Trust Talks episode to explore how verifiable organizational identity is being applied to telecommunications, and what it would mean for every call and message to carry cryptographic proof of the organization behind it.


FIDO Alliance

Security IT News: The State of Biometric Security in the Age of AI Fraud Report Released

Aware, Inc. released a new report, The State of Biometric Security in the Age of AI Fraud, showing that 98% of organizations are interested in biometric orchestration amid rising AI-driven fraud and […]
Aware, Inc. released a new report, The State of Biometric Security in the Age of AI Fraud, showing that 98% of organizations are interested in biometric orchestration amid rising AI-driven fraud and increasing identity system complexity. As businesses adopt multiple biometric technologies across different use cases, managing these solutions has become more challenging. The report defines biometric orchestration as a centralized platform that integrates and coordinates biometric systems, data sources, and workflows to deliver secure, scalable, and seamless identity verification.

The State of Biometric Security in the Age of AI Fraud Report Released

In the State of Biometric Security report, the findings paint a clear picture: as threats like deepfakes, synthetic identities, and injection attacks become more sophisticated and widespread, organizations have turned to biometrics asa foundational layer of identity security, but are struggling to manage fragmented, multi-vendor environments.

“Organizations are no longer asking if they need biometrics—they’re already managing complex ecosystems and asking how to make them work together,” said Ajay Amlani, CEO of Aware. “Biometric orchestration is emerging as the critical layer that helps security teams stay ahead of AI-driven threats while maintaining performance, accuracy and user experience. It turns complexity into an advantage by enabling smarter, faster identity decisions.”


Mobile ID World: Mastercard and Google Put Passkeys at the Heart of AI Payments

When an AI agent buys something on your behalf, how does the merchant know you actually authorized it? That question sits at the center of Verifiable Intent, an open-source cryptographic […]

When an AI agent buys something on your behalf, how does the merchant know you actually authorized it? That question sits at the center of Verifiable Intent, an open-source cryptographic framework introduced by Mastercard and Google to bring biometric, passkey-grade trust to autonomous AI transactions.

The framework works by bundling three pieces of information into a single tamper-resistant cryptographic record: the consumer’s verified identity, the specific instructions they gave their AI agent, and the transaction that resulted. Before an AI agent can complete a purchase, the consumer must establish a verifiable intent to pay through a biometric step, creating a cryptographic link between the human and the autonomous action taken on their behalf.

That biometric layer draws on standards from the FIDO Alliance, the same body whose passkey specifications have been reshaping mobile authentication across banking and payments. Verifiable Intent also incorporates EMVCo, Internet Engineering Task Force, and World Wide Web Consortium standards, making it protocol-agnostic and compatible with Google’s Agent Payments Protocol and Universal Commerce Protocol.

A Selective Disclosure mechanism handles privacy: each party in a transaction, whether a merchant verifying authorization, an issuer checking for fraud patterns, or a dispute resolution system, receives only the minimum data needed. No single participant sees the full record. The approach mirrors the selective disclosure principles built into mobile wallet credential standards, applied here to the agentic payment context.


TechTarget Search Security: How to roll out an enterprise passkey deployment

CISOs know that the human element can be the weakest link in an enterprise’s cybersecurity defenses, often surfacing when end users create weak passwords that threat actors easily crack. Seeking […]

CISOs know that the human element can be the weakest link in an enterprise’s cybersecurity defenses, often surfacing when end users create weak passwords that threat actors easily crack. Seeking a stronger alternative, security teams are increasingly turning to passkeys.

Unlike passwords, which end users create, passkeys are digitally generated cryptographic credentials that work as part of an identity and access management (IAM) strategy. Passkeys use biometrics and are stored on a device — such as a phone — or as a hardware token. Passkeys don’t communicate through a server; they are validated through authentication services.

Passwords vs. passkeys: A safer option

Beyond providing an alternative to weak passwords, passkeys that use biometrics or device-based cryptographic keys are significantly harder to capture through social engineering tactics such as phishing.


DIF Blog

DIF Newsletter #60

April 2026 DIF Website | DIF Mailing Lists | Meeting Recording Archive Table of contents Decentralized Identity Foundation News Update from the Executive Director: Specification Graduation Working Group Updates Upcoming Events Get involved! Join DIF 🚀 Decentralized Identity Foundation News Spring marks the start of conference season! We've got a

April 2026

DIF Website | DIF Mailing Lists | Meeting Recording Archive

Table of contents Decentralized Identity Foundation News Update from the Executive Director: Specification Graduation Working Group Updates Upcoming Events Get involved! Join DIF 🚀 Decentralized Identity Foundation News

Spring marks the start of conference season! We've got a bunch of upcoming events.

We've kicked off the spring with participation in the ITU's Study Group 17 event, Trustable and Interoperable Digital Identities for Human and Agentic AI, where DIF member Damian Glover participated. The event was more successful than expected, and the ITU received the go-ahead from member states to create a public Focus Group on Agentic AI. The Focus Group is intended to be open for allthat will be open to all in the coming months. DIF will be participating in the upcoming Global interoperability for trust management of digital identity for humans and agents at the start of June. Damian will be inviting one or two of the speakers for a HOT TAKE... look out for the date in the DIF calendar if you're ITU-curious or tracking agentic topics. We have an open call for speakers to speak or convene sessions at the Global Digital Collaboration (GDC) in September. DIF is one of the co-organizers, and we can work with you to submit a proposal for a talk or panel. For details, send email to ed@ (our domain). The Upcoming Hot Take talk will be with Executive Director Grace Rachmany, going over her visit to Asia Pacific. In her recent blog, Grace wrote about the trip. She'll be discussing here takes on how identity is being implemented for humans and AI in Asia, and there will be an AMA. Join at 8 am UTC on April, 23 (the usual time for the APAC SIG) Update from the Executive Director: Specification Graduation

Historically, DIF specifications have taken different paths after being completed in DIF, and as an organization, we haven't put much public focus on what happens "after DIF" in recent years. At this point in our maturity as an organization, we are starting to give more consideration to the idea of "graduation", that is, what happens to a specification or repository after DIF has completed its work.

Fundamentally, we have made DIF very low-bureaucracy as a kind of lightweight SDO. This means we are able to produce specification, code, and research much more quickly than large international standards bodies. But it also means that some of the work doesn't go on to implementation, or the implementations are limited. There's nothing wrong with that, but we feel it's time for us to be more deliberate in how "standards graduation" comes about. Over the 6 years of DIF's existence, we've done incredible work, and we've learned a lot about what paths are (and aren't) open to us.

Right now, DIF has begun steps in two potential directions for graduation and adoption of specifications.

One path to graduating standards is through more formal SDOs, which can slot cleanly into regulations and international agreements. DIF members have long been involved with both community and normative work at W3C, and DIF is going to be actively working more closely with W3C as well as looking to identify a chairperson for their working group on DID methods. We've also begun discussions with the ITU regarding participation in their Study Group 17. The ITU prides itself on moving faster than other international standards bodies in terms of Agentic AI security, and being in on early conversations will provide graduation paths for the work being done in the Trusted Agentic AI Working Group (TAAWG). The work with W3C and the ITU will require additional dedicated budget, so DIF will be organizing an earmarked fund for each of these activities. If your organization is interested in participating in either of these standards bodies, or in supporting DIF more generally to secure credibly neutral representation in these bodies, please write directly to ed@ (our domain).

The second graduation path is in helping our members move from working group specifications to operational prototypes. The work on that happens within the working groups, and specifically within smaller task forces focused on practical implementation. This work is primarily the responsibility of the working group chairpeople. DIF has begun a series of training sessions for Working Group chairs, and we'll be actively adding to that knowledge library to help WG chairs be more effective in their work.

Working Group Updates

DIF Members are welcome to join and participate in any working group. Most working groups meet on a weekly basis, and the most active groups have task force meetings that focus on specific work items. All public meetings are recorded and you can find all of the information on our working groups here.

Creator Assertions Working Group

CAWG has been diligently working on version 1.2 of the CAWG Identity Assertion specifications, in particular updates in the Trust Model for CAWG Identity Signing Certificates. The upcoming work scheduled includes optional KERI-specific parsing logic to the Identity Assertion Specification, Creating a Creators Advisory Group together with C2PA, and exploring a trust anchor for identity assertions.

Currently, CAWG has three ongoing task forces:

VC/VP: Incorporating new kinds of identifiers and claim verification logics. Trust: Creating distributed trust ecosystems over specific claims. Consent: Exploring ways to encode consent and legal claims on digital assets.

👉 Learn more and get involved

Trusted AI Agents Working Group

In the last four meetings, the Trusted AI Agents Working Group has continued refining the Delegated Authority Use Cases report, with discussions centered on how authority, delegation, and accountability can be expressed when agents act on behalf of people or organizations. The goal is a coarse "checklist" of desired capabilities and usecases, with which to execute a high-level assessment of "fitness for purpose" among various family trees of prior art. (One nice side-effect of this apples-to-apples framework is noticing rough equivalents across the terminologies and mental models of radically different protocols and approaches.)

Similar work on [variously machine-readable] policy and governance has also spawned an early draft of an adjacent problem-space report. This potential task force is waiting in the wings for the right champion looking to prototype machine-readable governance, generate some contractual boilerplate (what does a good audit trail for agentic delegations enable at the service level agreement level?), a more detailed report, or any other form of DIF deliverable.

Recent conversations addressed concrete implementation details, which might be harder or easier to model (and secure) depending on the protocols and infrastructures chosen. Examples include exploring how agents might authenticate, present credentials, merge credentials and permissions (or not), hold secrets (or not), and operate within clearly scoped boundaries. The group discussed where existing DID and VC building blocks are sufficient, and where new patterns may be needed to support agent-to-agent interactions without eroding human control. Prototyping the chained-delegation and authorization receipt architecture proposed in the other task force with the reference implementation formerly known as MCP-i is proceeding cautiously, by mapping out the consequences of expressing these capabilities inside of the "envelope" of a verifiable credential or as a distinct kind of object with different verification flows.

👉 Learn more and get involved

Hospitality and Travel Working Group

DIF’s Hospitality and Travel Working Group continues to update the schemas for the Hospitality and Travel Profile (HATPro). The team is working on Github updates, content strategy, and contact management for participants in the HATPro database. As they continue to expand their database of use cases, they are looking to have better tracking of the participants outside of DIF.

👉 Learn more and get involved

DIDComm Working Group and User Group

The DIDComm working group had a roundtable discussion this month about MCP and the use of DIDComm as an potential method for Agent to Agent communication.
In the most recent DIDComm user group, the following PR status was reviewd:

Pending migration of the static site build and deployment process from Gatsby to Hugo. Main changes involve removing the Gatsby workflow, adding a new Hugo workflow, and introducing a Hugo archetype template for content creation. Vinay Singh's contributions include a new protocol for
peer-to-peer expense tracking and a recent PR for adding vault support (storage systems that hold documents and logs for
multi-party activities and secure versioning management) to workflows. Updates to the DIDComm protocol, including a new implementation by Hologram and DigiCred.

The group had a discussion about the calendar use case for AI agents, where people's agents could be deployed to coordinate meetings. The discussion was based on an app in development by Dave McKay. The group discussed different levels of authorization.

👉 Learn more and get involved

DID Methods Working Group

Big news: the DID Methods Working group welcomes new co-chairperson Christian Saucier! Christian will be stepping in as Marcus Sabadello continues to serve as a Steering Committee Member. Great news for the DID Methods Working group and great news for DIF, as we can better balance the responsbilities among more people. In early April, Christian demoed the work he has been doing on a blockchain-based did:cid method.

Over the last month, most of the work on DID Methods has focused on did:webplus, with integration of the changes from a code review, and update of policy. (PR 77 and PR 93). They have also begun consideration of did:ethr to go through the recommended methods process. The working group also hosted a presentation from the Hospitality and Travel Working group regarding a use case for travel disruption.

👉 Learn more and get involved

Identifiers and Discovery Working Group

The IDWG has been moving forward in discussions around did:webvh. In this month's meeting they discussed the work being done at Affinidi around the Rust implementation for code maintainers in the Linux project. The working group has approved a PR addressing denial of service concerns. The group discussed different approaches to presentation credentials, and discussed security concerns around some of the recent PRs. The Working Group will be adding a threat modeling document to the web:vh information site. Upcoming meetings will address UNTP and Whois features.

👉 Learn more and get involved

Applied Crypto Working Group

The ACWG has been covering different cryptographic approaches,as well as concerns regarding advances in quantum computing. The Working group is specifically comparing ECDSA curves and pseudonym systems. The group is actively seeking more participation from DIF members interested in this issue. Specifically, the question has arisen about whether it's best to implement a modular approach with P-256 binding or if the pseudonym approach would suffice, noting that the pseudonym approach might be sufficient even if it sacrificed some efficiency gains from additional blinding features.

👉 Learn more and get involved

If you are interested in participating in any of the Working Groups highlighted above, or any of DIF's other Working Groups, please click join DIF.

📢 Upcoming Events

Will you be attending any upcoming Identity events? Let us know so other DIF members can find you! We are going to list selected AI and other industry events only if there are DIF members speaking or attending.

4th International Workshop on Trends in Digital Identity (TDI)

📅 April 20-21, 2026
📍 Verona, Italy
Learn more

KERICONF

📅 April 21-23, 2026
📍 Lehi, Utah USA
Learn more

Internet Identity Workshop IIWXLII #42

📅 April 28–30, 2026
📍 Mountain View, CA
Registration and details

Agentic Internet Workshop #2

📅 May 1, 2026
📍 Mountain View, CA
Learn more

Identiverse 2026

📅 June 15–18, 2026
📍 Las Vegas, NV
Conference details

Identity Week Europe 2026

📅 June 9–10, 2026
📍 Amsterdam
Event information

ITU Workshop on "Global interoperability for trust management of digital identity for humans and agents"

📅 June 2, 2026
📍 Geneva
Event information

GDC 2026

📅 September 1-3, 2026
📍 Geneva
Event information
Tickets
To apply for a speaking opportunity or get tickets for GDC, please contact us directly.

👉Are you a DIF member with news to share? Email us at communication@identity.foundation with details.

🆔 Join DIF!

If you would like to get in touch with us or become a member of the DIF community, please visit our website or follow our channels:

Follow us on Twitter/X

Join us on GitHub

Subscribe on YouTube

🔍

Read the DIF blog

New Member Orientations

If you are new to DIF join us for our upcoming new member orientations. Find more information on DIF’s slack or contact us at community@identity.foundation if you need more information.


EdgeSecure

Leaders from Industry, Academia, and Government Convene to Advance AI, Quantum, and Workforce Innovation

Leaders from Industry, Academia, and Government Convene to Advance AI, Quantum, and Workforce Innovation NEWARK, NEW JERSEY, April 17, 2026 – Leaders from across academia, industry, and government will convene… The post Leaders from Industry, Academia, and Government Convene to Advance AI, Quantum, and Workforce Innovation appeared first on Edge, the Nation's Nonprofit Technology Consortium.
Leaders from Industry, Academia, and Government Convene to Advance AI, Quantum, and Workforce Innovation

NEWARK, NEW JERSEY, April 17, 2026 – Leaders from across academia, industry, and government will convene for the Ecosystem for Research Networking (ERN) Virtual Summit 2026, a national gathering focused on advancing collaboration, expanding access to advanced technologies, and strengthening the future workforce.

Centered on the theme, “Beyond Resources: Integrating AI, Quantum, and the Workforce of the Future,” the summit brings together experts from organizations including the National Science Foundation, U.S. Department of Energy, leading universities, national laboratories, and industry partners to explore how emerging technologies can be more effectively integrated into research, education, and innovation ecosystems.

“We are at a pivotal moment, with unprecedented national investments in AI, quantum, and advanced cyberinfrastructure. But the true measure of success will not be the resources we build, it will be how effectively we integrate them into research, education, and workforce pathways, and who is ultimately able to participate, notes Forough Ghahramani, Ed.D., Co-Chair, ERN Summit; Assistant Vice President for Research & Innovation, Edge. Continues Ghahramani, “This summit is about moving beyond access to enable meaningful engagement, bringing together national initiatives, regional ecosystems, and institutions of all types to ensure that innovation is both inclusive and impactful.”

“We are at a pivotal moment, with unprecedented national investments in AI, quantum, and advanced cyberinfrastructure. But the true measure of success will not be the resources we build, it will be how effectively we integrate them into research, education, and workforce pathways, and who is ultimately able to participate. This summit is about moving beyond access to enable meaningful engagement, bringing together national initiatives, regional ecosystems, and institutions of all types to ensure that innovation is both inclusive and impactful.”

– Forough Ghahramani, Ed.D.
Co-Chair, ERN Summit
Assistant Vice President for Research & Innovation, Edge

Elaborates Barr von Oehsen, Ph.D., Director, Pittsburgh Supercomputing Center, “Democratizing access to advanced computing, research instruments, and data is not simply about expanding availability, it’s about ensuring that institutions have the connectivity, workflows, and support needed to effectively use these resources. By aligning national platforms with regional initiatives, we can create a more cohesive ecosystem that enables broader participation, accelerates discovery, and strengthens the workforce needed to support the future of research.”

The summit will feature a keynote address by Masoud Mohseni, Senior Distinguished Technologist and Director of HPE Quantum at Hewlett Packard Labs, titled: “Heterogeneous Quantum–Classical Computing: Scaling Through Integration.” Dr. Mohseni will explore how integrating quantum and classical computing systems can unlock new pathways for scalability and performance, highlighting the importance of hybrid architectures in advancing real-world applications. His keynote will set the stage for the summit’s focus on bridging cutting-edge research with practical, deployable solutions across sectors.

“Democratizing access to advanced computing, research instruments, and data is not simply about expanding availability, it’s about ensuring that institutions have the connectivity, workflows, and support needed to effectively use these resources. By aligning national platforms with regional initiatives, we can create a more cohesive ecosystem that enables broader participation, accelerates discovery, and strengthens the workforce needed to support the future of research.”

– Barr von Oehsen, Ph.D.
Director, Pittsburgh Supercomputing Center

The summit will feature a series of panels addressing:

Cross-sector collaboration to accelerate AI and quantum innovation, Federated data ecosystems and data-sharing frameworks to support scalable research, and National and regional initiatives aimed at democratizing access to advanced infrastructure.

A central focus of the discussions will be ensuring that institutions of all sizes, including non-R1 and emerging research institutions, small liberal arts colleges, and community colleges can participate meaningfully in the evolving technology landscape.

Panelists will examine not only the expansion of infrastructure and resources, but also the critical need for:

Alignment across policy, platforms, and workforce development, New models for federated collaboration and data sharing, and  Sustainable approaches to regional and national partnerships.

The agenda highlights the growing importance of connecting national investments with regional ecosystems to enable broader participation and long-term impact.
View the full agenda: ERN Summit 2026 Agenda  and register here for the virtual conference.

 

About ERN Summit

The Ecosystem for Research Networking (ERN) Summit brings together leaders from across sectors to advance collaboration, expand access to research infrastructure, and strengthen the national innovation ecosystem. Through a focus on emerging technologies such as AI and quantum, the summit aims to foster partnerships that enable broader participation and accelerate discovery and impact. For more information about the ERN, please visit the ERN website.

About Edge

Edge serves as a member-owned, nonprofit provider of high-performance optical fiber networking and internetworking, Internet2, and a vast array of best-in-class technology solutions for cybersecurity, educational technologies, cloud computing, and professional managed services. Edge provides these solutions to colleges and universities, K-12 school districts, government entities, hospital networks, and nonprofit business entities as part of a membership-based consortium spanning across the nation. 

The post Leaders from Industry, Academia, and Government Convene to Advance AI, Quantum, and Workforce Innovation appeared first on Edge, the Nation's Nonprofit Technology Consortium.


The Engine Room

Challenging the AI binary with locally grounded initiatives for climate action

As the climate crisis deepens, influenced by extractive Big Tech infrastructures, groups from the Majority World impacted by these technologies are developing small, resource-efficient, community-centered climate solutions to pressing environmental challenges. Over the next year, we will center those groups in a full-cycle initiative exploring how locally driven, climate resilient AI technologies

As the climate crisis deepens, influenced by extractive Big Tech infrastructures, groups from the Majority World impacted by these technologies are developing small, resource-efficient, community-centered climate solutions to pressing environmental challenges. Over the next year, we will center those groups in a full-cycle initiative exploring how locally driven, climate resilient AI technologies are designed and developed, and how they can be adopted in care-based and responsible ways.

The post Challenging the AI binary with locally grounded initiatives for climate action appeared first on The Engine Room.

Wednesday, 15. April 2026

Next Level Supply Chain Podcast with GS1

Small Shift, Big Lift? Why NDC-12 Impacts Your Entire Supply Chain

NDC-12 might seem like a minor data change. But in practice, it affects far more than the code itself.  In this episode, Reid Jackson and Liz Sertl speak with Rose Campasano, Principal Consultant of Global Compliance & Enterprise Systems at Criterion Consulting, about what companies need to do now to prepare for the NDC-12 transition. Rose explains how NDC-12 impacts labeling, scannin

NDC-12 might seem like a minor data change. But in practice, it affects far more than the code itself.

In this episode, Reid Jackson and Liz Sertl speak with Rose Campasano, Principal Consultant of Global Compliance & Enterprise Systems at Criterion Consulting, about what companies need to do now to prepare for the NDC-12 transition.

Rose explains how NDC-12 impacts labeling, scanning, software systems, and business processes across the healthcare supply chain. She also highlights the complexity of supporting both 10-digit and 12-digit codes during the transition, and why coordination across partners is critical.

This is not just an IT task. It is a long-term program that requires alignment across finance, quality, regulatory, and operations teams.

In this episode, you'll learn:

Why NDC-12 affects systems, processes, and partners across the supply chain

How the transition period creates complexity with multiple code formats

The steps companies can take now to prepare for a smoother rollout

Things to listen for: (00:00) Introducing Next Level Supply Chain (02:07) What NDC-12 means and its impact (05:32) The transition from NDC 10 to NDC-12 (12:41) Why NDC-12 is not just an administrative update (16:44) How Sunrise 2027 overlaps with NDC-12 planning (19:49) The departments that need to be involved in the NDC-12 transition (27:30) First steps for NDC-12 readiness (35:13) Rose's favorite tech

Connect with GS1 US: Our website - www.gs1us.orgGS1 US on LinkedIn Register for GS1 Connect 2026, happening June 9 to 11 in Las Vegas, and get 10% off with the promo code GS1USPOD10 at connect.gs1us.org.

Connect with the guest: Rose Campasano on LinkedInVisit Criterion Consulting at criterionc.com

Tuesday, 14. April 2026

FIDO Alliance

Biometric Update: OpenAI joins FIDO Alliance to help AI agent authentication push

OpenAI is the newest member of the FIDO Alliance, joining the passwordless authentication group to contribute to its efforts to provide the secure and private digital identity frameworks that will be […]

OpenAI is the newest member of the FIDO Alliance, joining the passwordless authentication group to contribute to its efforts to provide the secure and private digital identity frameworks that will be needed to ensure AI agents are trustworthy, verified and governed by user intent.

Within FIDO, OpenAI plans “to participate in emerging work to evolve authentication for agentic intelligence,” according to a LinkedIn post.

OpenAI shuttered its Sora 2 AI video generator in March after receiving criticism for its contribution to a wave of impersonation and abuse videos. But the company also launched an AI agent tool Operator in January, so it is keen to ensure agents are trusted enough to be commercially useful.

Co-founder and CEO Sam Altman’s other big tech project, World, uses iris biometrics for enrollment, and is geared towards proving that a person is human and unique from other users.

FIDO Alliance CEO Andrew Shikiar says the introduction of agentic AI represents a new era for authentication. The adoption of digital credentials like FIDO’s passkeys is accelerating, while agents are beginning to interact with services, transact and make decisions on behalf of users.

“The common thread is clear: making it simple and trustworthy for people to present verified credentials, whether directly or through agents acting on their behalf,” Shikiar says in a LinkedIn post of his own.

OpenAI is also joining the Alliance’s Board of Directors, which Shikiar says “reflects a broader market coalescing around the need to align authentication, credentials, and AI, grounded in open standards and real-world deployment.”

Shikiar said in a keynote at the Identity Policy Forum earlier this year that integrating authentication with workflows for AI agents will be one of the major themes of 2026.

The FIDO Alliance joined OpenID’s conformance testing program just weeks ago.


Project VRM

Finally Fixing Health Care

Interesting how old posts get new traffic. The heaviest traffic this morning is to Health Care Relationship Management, which ran almost nineteen years ago. That post concerned a Steve Lohr story in the NY Times titled Google and Microsoft Look to Change Health Care.  The gist: The Google and Microsoft initiatives would give much more control to individuals, […]

Source: ChatGPT

Interesting how old posts get new traffic. The heaviest traffic this morning is to Health Care Relationship Management, which ran almost nineteen years ago. That post concerned a Steve Lohr story in the NY Times titled Google and Microsoft Look to Change Health Care.  The gist:

The Google and Microsoft initiatives would give much more control to individuals, a trend many health experts see as inevitable. “Patients will ultimately be the stewards of their own information,” said John D. Halamka, a doctor and the chief information officer of the Harvard Medical School.

The initiatives were Google Health  and Microsoft Healthvault. Never mind why they died. Those links will tell you. What matters more is what I said way back then: The key, as with all VRM projects, is that the solution needs to be anchored on the customer side — in this case the patient side — of the relationship.

As it happens, Adrian Gropper, techie and MD, was on this case long before Google and Microsoft showed up to waste $billions failing to solve a problem they could only compound. And he’s still at it, with HIE of One and related efforts. Here is his Substack. These subjects will be on the floor at VRM Day and IIW later this month. VRM for healthcare will save the world $billions, in addition to countless lives.

Here’s Adrian’s latest.


Blockchain Commons

2026 Q1 Blockchain Commons Report

The first quarter of 2026 focused on producing a capstone for much of our stack, but also was about advancing our self-sovereign identity work. Here’s what all it included: Capping the Stack: Technology Overview New BCRs New Translations Playgrounds Locking Down Known Values: Talking about Known Values Code Point Specification Crate Update Expanding XIDs: Introducing Edges Learning XIDs XIDs &

The first quarter of 2026 focused on producing a capstone for much of our stack, but also was about advancing our self-sovereign identity work. Here’s what all it included:

Capping the Stack: Technology Overview New BCRs New Translations Playgrounds Locking Down Known Values: Talking about Known Values Code Point Specification Crate Update Expanding XIDs: Introducing Edges Learning XIDs XIDs & Garner Meeting Diving into SSI: GDC Incoming New Articles Revisiting SSI Returning to Learning Bitcoin: Learning Bitcoin 3.0 Standup Scripts Gordian Server Capping the Stack

We’ve slowly built the Blockchain Commons stack up over the last years, from dCBOR to Uniform Resources to Gordian Envelope. In 2025 and into 2026, we brought much of our foundational work to a capstone, allowing us to concentrate on new applications and references built atop that foundation, including XIDs and Gordian Clubs. Here’s some of what we did to close things out in early 2026.

Technology Overview. To celebrate the completion of our foundational work, we put together a new technology overview video that details 24 different technologies, applications, and references in about a minute each. Here’s a quick overview of all the topics covered, plus a listing of our older videos, which go into greater depth on some of these topics.

New BCRs. We also led the year off with a set of new [Blockchain Commons research papers] (https://github.com/BlockchainCommons/Research/blob/master/README.md) that were mainly intended to detail our work to date.

BCR-2026-001: Unit, The Known Value for Deliberate Emptiness. A look at Known Value 0, and how it’s intended to be used. BCR-2026-002: Gordian Envelope Notation - Quick Reference. We’ve long provided a special “envelope notation” output to offer a human-readable view of what’s in a Gordian Envelope; here is its specification. BCR-2026-004: Envelope Salted Values. A discussion of the use of salt for decorrelation in Gordian Envelope.

(BCR-2026-003 is missing from this list because it was a major new specification, as discussed in “Expanding XIDs”, below.)

New Translations. Finally, we also produced some AI-supported translations of our stack to Swift, Kotlin, TypeScript, C#, Go, and Python. This is a preview that isn’t release-ready, and it only goes up to Provenance Marks (meaning that it’s missing some newer tech such as XIDs and GSTP). If you think this might be of use to you, talk to us about funding its full development.

Playgrounds. The third-party playgrounds that have appeared for our specifications in the last several months definitely represent another sort of capstone, as they provide a new way for developers to work with our technologies. Our January Gordian meeting included a demo of the BCTS playground. Both it and the BC-UR playground provide great tools to work with our tech.

BCTS Playground - Data Playground, Registry Browser, Envelope Builder, XID Tutorial BC-UR Playground — Converter, Multi-UR & QR Generator, QR Scanner, Registry Browser Locking Down Known Values

One of our foundational technologies is the Known Value. It’s a simple enough concept: a registry of 64-bit integers that represent common concepts. But, they’re very useful: not only do Known Values standardize our own organization of information in Gordian Envelope, but they also support that standardization across many companies. We did a variety of work on Known Values in early 2026.

Talking About Known Values. In our January Gordian Meeting, we talked about our desire to expand Known Values beyond the core concepts that we have defined for our own specifications. We wanted to not only incorporate other ranges of defined concepts, for standardization, but also to give our community the opportunity to officially define values for their own use. We got great feedback during and after the meeting that helped us to decide where the community values should go in the range. (Community feedback has always been crucial to Blockchain Commons, to ensure that what we’re doing makes sense in the world of actual development and deployment, and this was a fine example, because we’d been thinking about placing community known values too high, requiring too many bits.)

Code Point Specification. The free-for-all community band of known values starts at 100,000, but thanks to that meeting we’ve now defined a new set of community known values available with specification, which appear in the range of 1,000-1,999. Known values for this range may be submitted by PR. Our registry now also recognizes a variety of other schema, starting at code point 2,000.

Crate Update. The Known Values Rust crate has been updated to support these new code point specifications. The Blockchain Commons values remain in the core crate, but if you want to add in all the other values from our registry, just grab our current files defining them in JSON and add them to your ~/.known-values directory. You can also add arbitrary known values of your own by matching the format of our known value JSON assignment files. The known values crate (and crates that depend on it such as our envelope crate) will all have access to the values from your ~/.known-values directory.

Expanding XIDs

One of our largest current projects is XIDs, which we see as a true self-sovereign identifier. We supported them with both public demos and in-house extensions over the course of Q1.

Introducing Edges. Credentials, endorsements, and other types of attestations have always gone hand-in-hand with digital identity, and we’ve been thinking for a while about how to best expand XIDs to support these crucial digital tokens of trust. We were considering somewhat ad hoc means for a while, but we finally came up with the concept of “edges”, which are attestations that lie between two XIDs, forming the literal edges of a Web of Trust graph. BCR-2026-003 has all the details on how edges work.

Learning XIDs. You can also find edges in chapter 3 of our brand-new course, “Learning XIDs from the Command Line”. We’ve completed four chapters to date, and have put a temporary cap on the work. To date, those chapters cover: an introduction to XIDs, how to make claims related to XIDs, how to incorporate claims into XIDs using edges, and how to manage your XID with more complex elements such as commitment lists and updated views and editions. We plan to return to this course in Q2 with a new chapter on keys, but for now it’s complete and coherent.

XIDs & Garner Meeting. Finally, our public demo focused on using XIDs with Garner, our Tor onion service intended for the distribution of self-sovereign identity files. XIDs offered the opportunity to truly control your digital identity, from creating it yourself to deciding what you want to distribute. Garner makes that distribution self-sovereign as well by providing a communication method that’s very resistant to censorship, correlation, and coercion.

Diving into SSI

Our focus on self-sovereign identity (SSI) has been on the rise in 2025-2026, but it’s not actually new. We’ve been a part of the SSI community since Christopher Allen popularized the term as part of the Rebooting the Web of Trust workshops. It’s just that prior to 2025, we were still creating those foundational techs that we’re now bringing to a capstone; it’s only recently that our stack has matured enough that we can produce SSI-focused technologies such as XIDs and Gordian Clubs. Much of our SSI design is centered on XIDs themselves, but we’re also doing other work on the topic.

GDC Incoming. Blockchain Commons has been invited to the Global Digital Collaboration Conference as a co-organizer. This means that we can get you an invitation to the exclusive gathering and also help to set the agenda. Want to join us in Switzerland? Have a topic that you think is important to cover? Let us know.

New Articles. Meanwhile, Christopher has authored a few new articles on the topic of SSI, both in his Musings series (focused on original architectural designs & patterns) and in his new Dispatches series (responding to others’ discussions of topics of interest to us). Here’s his new writing from Q1:

How XIDs Demonstrate a True Self-Sovereign Identity. How SSI has gone wrong and why XIDs are different. Progress toward a State-Endorsed Identity (SEDI) in Utah. Can state-endorsed SSI really be a thing? Utah offers a great model. Fighting Technology Paternalism. SSI is about controlling your digital destiny, but Martina Kolpondinos offers the flipside: when the computer chooses for you.

Revisiting SSI. April 26 marks the 10th anniversary of Christopher’s article, “The Path to Self-Sovereign Identity”, which popularized the term and its goals. We’ve been working on Revisiting SSI to try and reconsider the original 10 principles of SSI. We’ve had some meetings with some great input, but we’ve also found it hard to turn that into group articles the way we’re able to in a physical meet-up like Rebooting the Web of Trust. Nonetheless, we plan one or more articles on the principles and how they may have changed or how we may be thinking about them differently a decade later. If you have any opinions, again let us know! We expect to be producing some new content on the topic for Q2.

Learning Bitcoin

Learning Bitcoin from the Command Line is one of Blockchain Commons’ oldest endeavors, started with support from Blockstream even before Blockchain Commons was founded. However, Bitcoin continues to evolve rapidly and as a result the course has gotten out-of-date over the last several years. We’re thrilled to return to it in a year-long effort in 2026 thanks to a grant from the Human Rights Foundation.

Learning Bitcoin 3.0. We have begun work on Learning Bitcoin 3.0, which is a thorough update of the course, focused on better incorporating newer elements such as Signet, descriptor wallets, Segwit, and Taproot, as well as a check and/or revision of every single line of code. We’ve logged a week and a half of work on this to date, and have it scheduled for five weeks total. Our log of work to date and our plans for the future are all in our TODO file, while the lbtcftcl-v3.0 branch of Learning Bitcoin contains the 264 commits to date. At the moment, §1.0-§7.2 are pretty solid. As soon as we close out chapters 7 & 8 and their linked discussions of multisigs and PSBTs, we plan to make the updated version of the course more available with a mkdocs-formatted website (but it’ll be the end of the year before we close out the project entirely). Thanks again to HRF for enabling this much-needed work!

Standup Scripts. Our Standup Scripts guide the creation of UNIX machines running the Bitcoin Core server. We used them in the LBTCftCL course and to produce that course. But these Scripts tend to age badly over time, as the programs we use change. We updated our Standup Scripts in January to support Bitcoin Core 25.0 and Debian 13. Ironically, the StackScript version of our scripts has already decayed because of some Linode package management that is now requiring user intervention. But, the non-StackScript version still works great (and you can run it from a Linode by hand), and we’re deciding on the best solution for the StackScripts. (Removing certain package updates resolves the problems, but keeping packages up to date is a best practice, so we’re hoping that what appears to be a bug gets resolved!)

Gordian Server. The new work on Learning Bitcoin also made us reconsider the Gordian Server, our Bitcoin Server for the Mac, which we also use for testing when we’re working on Learning Bitcoin. It too had gotten out of date, but its original designer, Peter Denton, has been working on his own iteration of the concept, the Fully Noded Server. As a result, we’ve officially deprecated Gordian Server and now suggest the use of Pwrwe’a Fully Noded Server instead. (Notes on the one alias needed to make things work well for the Learning Bitcoin course are already incorporated into v3.0 of the course.)

Final Notes

The environment for work on self-sovereign digital assets and identity continues to be rough in 2026. Due to limited resources, we expect to be focusing more in the coming year on developing, polishing, and documenting our existing work, as opposed to creating some of the exciting new technologies that we saw in 2025. That’s not a bad thing, as it’ll give us a chance to really get XIDs, Gordian Clubs, and other recent technologies into the ecosystem, alongside our already adopted specifications such as Gordian Envelope and URs.

But, you can help. We are looking for partners who want to adopt our technologies and who could use our expertise to do so. Drop us a line if that’s you. We of course continue to welcome individual and small company sponsorships as well. If you want to see this work continue, and if you can lend your reputation to ours, please sign up as a recurring GitHub sponsor.

Monday, 13. April 2026

GLEIF

Building Trust in Digital Trade: Standards are Moving Fast; Identity Must Keep Up

The emergence of interoperable legal frameworks and the growing recognition of electronic trade documents are enabling paperless, digital trade transactions. While this has the potential to unlock trillions of dollars in economic opportunity, the fact remains that digital trade only scales when every party in the transaction can be consistently identified and verified across borders and platforms

The emergence of interoperable legal frameworks and the growing recognition of electronic trade documents are enabling paperless, digital trade transactions. While this has the potential to unlock trillions of dollars in economic opportunity, the fact remains that digital trade only scales when every party in the transaction can be consistently identified and verified across borders and platforms. Put simply, the bottleneck inhibiting global digital is no longer the legal validity of electronic documents; it is the need for trusted digital interactions between organizations.

In this blog, David Campos, Head of Partnerships at GLEIF, explains how the Legal Entity Identifier (LEI) and verifiable LEI (vLEI) can address this challenge to support trusted, efficient digital trade. This is illustrated through a practical commodity-trading workflow and a bank-focused trade-finance use case, in recognition of the International Chamber of Commerce (ICC) event on this topic in Georgia on April 16–17, 2026.

The blog also explores how GLEIF is collaborating with technology providers and ecosystem leaders through the GLEIF Partners Program to integrate the LEI and vLEI into digital infrastructures, enabling scalable adoption of trusted organizational identity across digital ecosystems and business networks.

Why fragmentation inhibits global digital trade

Despite the emergence of laws and regulations allowing digital trade, execution is still too often stymied by the continued reliance on manual counterparty verification and duplicated onboarding. Challenges are compounded by fragmented identifiers and inconsistent reference data across global value chains, which weaken oversight, create delays, increase errors, and keep smaller firms at a disadvantage.

In response, a global, reusable approach to organizational identity is needed to strengthen transparency, remove friction, and support interoperability across platforms, corridors, and jurisdictions. This is why the LEI and vLEI hold so much promise.

A globally recognized organizational identity layer for digital trade

The LEI is based on the global ISO 17442 standard for identifying legal entities. It provides a consistent way to represent “who is who” and "who owns whom" in transactions, supported by verified reference data available through the Global LEI System. In practical trade and commodities workflows, the LEI can help:

Reduce ambiguity in counterparty identification across jurisdictions, languages, and naming conventions. Streamline onboarding and Know Your Customer (KYC) and anti-money laundering (AML) checks by reusing a standardized identifier across systems. Link parties across the trade lifecycle, supporting cleaner data across contracting, logistics, and trade finance processes.

But as trade becomes fully digital, identification alone is not enough. Digital workflows also need a way to verify that an organization is legitimate and that a person or system is authorized to act on its behalf. The vLEI extends the LEI into digitally signed, tamper-evident credentials, standardized in ISO 17442-3. This supports higher assurance and automation while preserving clear accountability. In trade scenarios, the vLEI can help:

Support automated authentication for business-to-business (B2B) interactions, reducing reliance on manual checks. Strengthen integrity in digital document exchange by enabling verification of who issued or signed data. Improve interoperability because verification can be based on an open standard rather than a closed platform.

Together, the LEI and vLEI create a layered trust model. The LEI ensures global consistency of entity identification, while the vLEI enables cryptographic verification of that identity and associated authority in digital workflows. In practice, this means that if you are building a digital trade platform, trade finance solution, or paperless workflow, the LEI and vLEI can provide a globally recognized organizational identity layer that strengthens transparency, trust, interoperability, and automation across digital transactions.

Use case: A paperless commodity trade from contract to settlement

The role of the LEI and vLEI in providing a globally recognized organizational identity layer stands to profoundly benefit trade digitalization across various use cases.

Take commodity markets, where speed and certainty are competitive advantages that demand transparency. When trade processes are digitally enabled, organizations can reduce cycle times, lower administrative costs, and improve operational resilience.

In commodity markets, the need for transparency goes beyond efficiency. It is a risk-control imperative that affects fraud exposure and reputation. Sanctions screening, beneficial ownership checks, duplicate financing risk assessment, environmental, social, and governance (ESG) disclosures, and provenance verification all depend on consistent identification of legal entities throughout the trade lifecycle.

As the industry moves toward automated trade corridors and real-time data exchange, trusted organizational identity becomes a prerequisite for secure scale. Consider a trading firm and a counterparty agreeing a deal on a digital platform, then moving straight into shipping, trade finance, and settlement without switching back to paper. In this end-to-end flow, trust depends on knowing exactly which organizations are involved and whether the people or systems acting in the process are authorized.

In commodity finance, where the same cargo may be financed, insured, and traded across multiple jurisdictions, consistent entity identification helps reduce the risk of duplicate financing, misrepresentation, and sanctions breaches. Transparency at the identity layer strengthens controls without slowing execution.

Here is how standardized identity can show up in a typical commodity workflow:

Onboarding and counterparty checks: Each party shares its LEI so platforms, brokers, and service providers can match the legal entity reliably and reuse verified reference data. Trade finance setup: Banks and trade finance providers use LEIs to link applications, credit decisions, and documentation to the correct legal entities across systems and jurisdictions. Signing and exchanging electronic documents: vLEI credentials can be used to verify the organization and the authorization of a signatory for electronic contracts and data exchanges, reducing manual verification steps. Post-trade controls and reporting: LEIs connect parties across confirmations, logistics updates, and settlement records – supporting cleaner data, fewer exceptions, and stronger audit trails.

For trading and operations teams, the impact is practical: less time validating counterparties and signatories, fewer handoffs between systems, and more confidence that digital processes will hold up across borders and platforms.

Use case for banks: Trade finance digitalization needs verified authorization

Another key use case for the LEI and vLEI is enabling the digitalization of trade finance. While banks are accelerating initiatives in this area, they still face a familiar challenge: proving which organization is on the other side of an instruction, and whether the person or system sending it is authorized.

A simple example is a bank supporting a corporate client through a paperless trade flow (for example, issuing or advising a digital letter of credit, processing amendments, and handling electronic presentation). The bank needs strong identity assurance at each step:

Consistent client and counterparty identification: The LEI helps banks link corporates, exporters, importers, insurers, and logistics providers across internal systems and external platforms. Reusable compliance mapping: The LEI supports more consistent screening and onboarding because the same identifier can be reused across products and corridors. Verified digital authority: vLEIs can help verify that an instruction, endorsement, or electronic presentation was issued by the right organization and by an authorized role, reducing fraud risk in digital channels. Cleaner audit trails: Standardized identifiers and verifiable credentials make it easier to evidence “who did what” across workflows and handoffs.

For banks, a standards-based identity and authorization layer reduces manual checks while strengthening controls, which is essential if trade finance digitalization is going to scale safely.

Building digital trade through collaboration

As digitalization accelerates across global value chains, GLEIF is working closely with public- and private-sector stakeholders to highlight and strengthen the role of trusted organizational identity.

A key priority is ensuring globally unique identifiers align with digital trade standards to promote interoperability across platforms and jurisdictions. This is why GLEIF engages with global trade bodies and standards initiatives – including the International Chamber of Commerce (ICC), the ICC Digital Standards Initiative (DSI), and the United Nations Centre for Trade Facilitation and Electronic Business (UN/CEFACT) – to support interoperable approaches to organizational identity in digital trade.

Organizations integrating the LEI or vLEI into trade platforms, supply chain solutions, digital trade corridors, or trade finance infrastructure are also encouraged to join the GLEIF Partners Program. The program connects technology providers, financial institutions, trade networks, and trust service providers (TSPs) that work to embed standardized organizational identity within digital ecosystems.

Join us at the ICC event in Georgia

David Campos will speak at the ICC Digital Trade & Trade Finance event in Georgia on 16–17 April 2026, in the session "Reliability and Trust Services in the New Digital Trade Ecosystem" (14:15–14:45).

Join us at Commodity Trading Week Europe

GLEIF will contribute to the panel discussion “Building trust in trade: New intelligence standards for the digital trading economy” on Wednesday, 6 May 2026 (14:05–14:45) in London. If you are attending, we welcome the opportunity to connect on practical implementation to understand where the LEI can remove friction today, and where the vLEI can enable the next step in verification and automation for digital trade. Register here.

Friday, 10. April 2026

DIDAS

Two Complementary Studies on Electronic Identity

The new HSLU study shows where organizations in Switzerland currently stand when it comes to digital identities and electronic credentials. The PwC study complements this with an international system perspective. One thing becomes particularly clear: for the next phase, technical infrastructure alone is not sufficient. What is needed is orientation, shared learning, understandable adoption pathways

The new HSLU study shows where organizations in Switzerland currently stand when it comes to digital identities and electronic credentials. The PwC study complements this with an international system perspective. One thing becomes particularly clear: for the next phase, technical infrastructure alone is not sufficient. What is needed is orientation, shared learning, understandable adoption pathways, and sustainable funding for the functions that make an ecosystem usable and interoperable.

The new HSLU study provides a current assessment of digital identities and electronic credentials in Switzerland. The PwC study adds an international system perspective. Together, they highlight-each in its own way-what matters in the next phase: not only the availability of infrastructure, but the ecosystem conditions under which real value, orientation, and interoperability can emerge.

The HSLU study shows where organizations in Switzerland stand today. Digital identities and electronic credentials are already a topic in many organizations. At the same time, it becomes clear that there is still significant need for classification, integration perspectives, trust, governance, and understandable adoption pathways. This is not unusual before broader adoption. What matters is that these aspects can already be clearly identified.

The PwC study looks at a different level. It examines, from an international comparative perspective, which factors make digital identity systems viable. These include not only technical foundations, but also institutional anchoring, governance, usability, integration into real-world processes, and the ability to enable adoption across different stakeholder groups. For Switzerland, this perspective is valuable because it shifts the focus beyond infrastructure to the actual conditions for effectiveness.

Taken together, both perspectives form a consistent picture. Technical infrastructure is a necessary step-but it is not sufficient. What will be decisive is whether organizations understand how to position themselves, which adoption pathways are realistic, how to build initial experience, and how individual activities can gradually evolve into a connected and interoperable ecosystem.

At this point, functions that are often not at the center of the debate become increasingly important. These include orchestration, structured learning and exchange formats, clear and connecting use cases, pilot projects with shared learning value, and forms of ecosystem discovery that make visible what already exists, what is still missing, and where reuse is emerging.

These functions are not “add-ons” for later—they are part of the next phase of development. Especially in a distributed ecosystem with diverse roles, maturity levels, and interests, mechanisms are needed that create orientation, make transitions between ambition levels understandable, and prepare experiences in a way that makes them usable for others.

This also applies to initiatives such as a launchpad. Their role is not to duplicate existing infrastructure, but to support the intermediate layer where organizations orient themselves, define initial use cases, develop shared artifacts, and gradually derive concrete adoption pathways from abstract possibilities. Particularly relevant are use cases and proofs of concept where the focus is not on showcasing, but on shared learning and clear transferability.

Another important aspect is the visibility of the ecosystem itself. If actors cannot recognize which credentials, role models, services, and building blocks already exist-or where gaps remain and which pathways are emerging—the system remains difficult to navigate. Ecosystem discovery is therefore not a secondary function, but a prerequisite for making an ecosystem understandable and capable of evolving.

Notably, these functions are often not sustainably funded. For technical components or individual products, funding and responsibility can usually be assigned relatively clearly. More difficult are those functions that benefit many but cannot easily be attributed to a single owner or business model. These include orchestration, cross-sector activation, discovery, shared reference patterns, governance artifacts, and structured learning formats.

This leads to a straightforward conclusion: if Switzerland wants its trust infrastructure to become more than just technical availability, these enablers must be recognized as essential development functions and supported accordingly. Otherwise, the gap between available infrastructure and broader interoperability will remain.

As products and services mature, some aspects will become easier. The more market-ready offerings emerge on this foundation, the easier it will be for additional organizations to get started. However, the more advanced potential lies beyond this – particularly where verifiable data flows are embedded in closer relationships with customers, partners, and suppliers, enabling new forms of digital capability.

The two studies do not provide a ready-made roadmap. But they clearly show what kind of development work is needed in the next phase. This includes not only technology and regulation, but also orientation, learning capability, visible development pathways, and the sustainable funding of those functions that make an ecosystem understandable and interoperable.

Links to the studies

HSLU-Study:

Weingärtner T., Kustor N. (2026) «Digitale Identitäten und elektronische
Nachweise in der Schweiz 2026» Hochschule Luzern, Rotkreuz, Schweiz

Link

PwC-Study:

PwC, Strategy& (2025) «Digital Identities Across the World: Approaches, Challenges and Best Practices» PwC, Global Study

Link

 

Thursday, 09. April 2026

FIDO Alliance

GB Hackers: Top 10 Best Multi-Factor Authentication (MFA) Providers in 2026

The landscape of Multi-Factor Authentication is dynamic, driven by new threats and technological advancements.

The landscape of Multi-Factor Authentication is dynamic, driven by new threats and technological advancements.


Biometric Update: Digital identity research warns of ‘password debt’ as enterprises delay IAM rollouts

Enterprises may be sharpening their understanding of digital identity threats but the industry is still struggling to turn that knowledge into large‑scale execution. Hypr’s latest State of Passwordless Identity Assurance […]

Enterprises may be sharpening their understanding of digital identity threats but the industry is still struggling to turn that knowledge into large‑scale execution. Hypr’s latest State of Passwordless Identity Assurance report shows passwordless and identity verification deployments stalling. RSA has been testing its own passwordless strategy internally, uncovering the hidden dependencies that still tether organizations to passwords. And in the public sector, Cisco Duo is positioning its zero‑trust platform as a way for agencies to align with new NIST cybersecurity standards.


Financial News-UK: The Death of the Password – How Passkeys Secretly Took Over the Internet

Researchers revealed what might be the biggest collection of stolen login credentials ever gathered in one location sometime in the middle of 2025. A compiled dataset, organized and searchable, contains […]

Researchers revealed what might be the biggest collection of stolen login credentials ever gathered in one location sometime in the middle of 2025. A compiled dataset, organized and searchable, contains about 16 billion records, including usernames, passwords, account details scraped from infostealer malware, phishing operations, and years of accumulated breach archives, covering accounts across Google, Apple, Meta, and dozens of other platforms. There was no significant zero-day exploit. No advanced nation-state assault. Just the patient, quiet harvesting of a system that was based on shared secrets and never sufficiently considered what would happen if those secrets were no longer kept secret. It wasn’t a particularly bad password. It failed gradually at first, then all at once, much like a slow leak eventually floods a basement.


BGR: Ditch Your Passwords And Start Using This More Secure Method

Creating new passwords on the spot can be really taxing. And that can also lead to some sloppy practices, like repeating old passwords or modifying them. But it turns out […]

Creating new passwords on the spot can be really taxing. And that can also lead to some sloppy practices, like repeating old passwords or modifying them. But it turns out that does a lot more harm than good, since you’re likely generating weak, exploitable passwords as a result. A strong password often involves using a complex string of lowercase and uppercase letters, along with numbers and symbols. Although theoretically that sounds easy to do, actually coming up with them can be a pain, which is why many people have opted to use password managers. While top password managers are great for creating new, strong passwords and storing them, they aren’t perfect. For example, your password manager depends on its own primary password to safeguard all of your deposited logins, which can create a single point of failure. As a result, held passwords can be maliciously stolen, leaving all your connected accounts vulnerable.

Read More: https://www.bgr.com/2135550/why-should-ditch-passwords-for-secure-method-passkey/


The Engine Room

Call for applications: UXD support for internet freedom tools supporting social justice

At The Engine Room, we work to build an ecosystem of digital tools that are values-aligned and reflect the needs of activists and targeted communities across the Global Majority. As part of this work, and as a service provider for OTF’s User Experience & Discovery (UXD) Lab, we conduct no-cost UX research projects to improve the usability and accessibility of open source, privacy-preserving in

At The Engine Room, we work to build an ecosystem of digital tools that are values-aligned and reflect the needs of activists and targeted communities across the Global Majority. As part of this work, and as a service provider for OTF’s User Experience & Discovery (UXD) Lab, we conduct no-cost UX research projects to improve the usability and accessibility of open source, privacy-preserving internet freedom tools that provide protections against surveillance, censorship, and repression to those advancing social justice on the ground. 

The post Call for applications: UXD support for internet freedom tools supporting social justice appeared first on The Engine Room.

Wednesday, 08. April 2026

GLEIF

Transforming Data into Opportunities: Metric in Motion – Unlocking Trusted Entity Data for Cross-Border Payments

In an increasingly interconnected global economy, the ability for organizations to trust and use data effectively is the foundation for innovation, growth, and competitiveness. A high-quality data ecosystem is a driver of change and innovation that enables organizations to identify and seize new opportunities, while low data quality can lead to inefficiencies and exposure to regulatory and rep

In an increasingly interconnected global economy, the ability for organizations to trust and use data effectively is the foundation for innovation, growth, and competitiveness.

A high-quality data ecosystem is a driver of change and innovation that enables organizations to identify and seize new opportunities, while low data quality can lead to inefficiencies and exposure to regulatory and reputational risks.

To aid broader industry awareness of GLEIF’s data quality initiatives and its application to different sectors, this new blog series explores key metrics included within the reports.

This month’s focus: global payments and the role of the LEI in enabling ISO 20022-compliant address retrieval.

Data quality sits at the heart of any efficient and trustworthy financial system, yet fragmentation remains one of the most persistent challenges inhibiting cross-border payments. Inconsistencies in core entity information, such as names, addresses, and status data – compounded by variations across jurisdictions, systems, and formats – continue to hinder automation, complicate compliance, and slow down cross-border processes.

Regulatory and industry initiatives to enhance cross-border payments are reinforcing the importance of consistent, interoperable reference data for a more connected global payments ecosystem. As adoption of the ISO 20022 messaging standard accelerates and regulatory expectations, such as FATF Recommendation 16, expand, the ability to rely on trusted, harmonized entity data is emerging as a critical enabler of efficient and compliant financial messaging.

As a globally standardized identifier, the Legal Entity Identifier (LEI) is key to expanding access to trusted information about entities. In a recent Pulse Poll, GLEIF asked the global data community: Which specific LEI-based data service would create the most value for your organization with a focus on payments operations? Respondents were equally vocal about the need for services that enable ISO 20022-compliant retrieval of the beneficiary's name and address in both structured and hybrid address formats.

Why Name and Address Formats in ISO 20022 Matter

The inclusion of address data in payment messages has long presented challenges, particularly in cross-border scenarios. Differences in language, format, and local conventions make standardization difficult. Historically, payment systems have relied on free-text fields to accommodate this diversity, which, while flexible, introduces ambiguity that can complicate automation.

In response, ISO 20022 introduced a structured format for beneficiary information – notably for capturing address information. Though this enables greater detail, the differences in address formats globally mean that fully structured models are not always straightforward to implement in practice. This is why a hybrid option, incorporating both structured and unstructured elements, has been introduced to provide flexibility during the transition to fully structured formats.

Another important consideration is language and script. While names and addresses in their native form remain essential for accurately representing a legal entity, many systems require Latin-based representations. This means that providing consistent Latin translations and transliterations without special characters remains critical to enabling interoperability across ASCII-based systems.

LEI-Based Data Service: Enabling Effective Payee Verification and Seamless Digital Communication

Given these considerations, the LEI is playing a central role in improving efficiency by automating the retrieval of name and address data.

As a globally recognized alphanumeric identifier connected to verified and regularly updated reference data, including legal names and addresses, the LEI introduces a trusted, authoritative foundation accessible to all parties – the originator’s bank, beneficiary’s bank, payments service providers, and financial intelligence units. Instead of relying on fragmented or manually entered information, organizations can use the LEI to source corroborated entity data and integrate it directly into payment messages.

Among the various benefits this delivers – and in response to the industry need outlined in our recent Pulse Poll – it is important to highlight that the LEI simplifies retrieving beneficiaries' names and addresses. This can enable precise, instant, and automatic identification across borders to support more effective and efficient payee verification:

Beneficiary name: LEI data provides consistent name information and Latin transliterations. This supports more reliable automation, reduces ambiguity, and enhances transparency across systems and jurisdictions. Beneficiary address: The Global LEI System can be used to retrieve ISO 20022 address formats – either hybrid or fully structured. The result is more efficient processing by accommodating the diversity of global address formats.

Let’s see this in action:

As of March 31, 95.6% of valid LEI records contain names and addresses in Latin script. In addition, 79.5% of valid LEI records use a standardized ASCII character set, providing a strong foundation for ISO 20022–compliant conversion and automated mapping.

Here is the exciting part: this mapping service can be deployed at low cost by financial institutions, payment service providers, or data providers, thanks to the Global LEI System's open API and the public, freely accessible availability of the LEI and its reference data.

To further support integration by financial institutions, payment service providers, and data services providers, an open-source code snippet is available as part of GODIN’s commitment to “implementing a practical approach to utilize Open Data, enabling enhanced transparency and risk assessment”. This practical resource reduces implementation effort, accelerates integration, and helps organizations operationalize LEI data within existing systems.

How to Shape the Future of Cross-Border Payments

Integrating ISO 20022 and the LEI paves the way for higher-quality, interoperable financial data across the global payments ecosystem. To ensure these benefits are realized at scale by organizations across the world, here is how you can get involved today:

Financial Institutions: Contact GLEIF to explore the Validation Agent model and discover how to embed the LEI into your payment services. Payment Service Providers and Data Vendors: Join the GLEIF Partner Program to receive regular updates on global system developments and showcase your LEI-enabled solutions on the Partner Program solutions page. Corporate Treasurers: Engage your service providers about their plans to integrate the LEI to enhance security and efficiency in your payment operations.

The Engine Room

Strengthening Data Sovereignty for Indigenous Communities in Kenya through Community-based Monitoring Systems

We are excited to welcome the Indigenous Movement for Peace Advancement and Conflict Transformation (IMPACT) to our 2026 Matchbox Program. IMPACT champions Indigenous rights and self-determination in Kenya. The post Strengthening Data Sovereignty for Indigenous Communities in Kenya through Community-based Monitoring Systems appeared first on The Engine Room.

We are excited to welcome the Indigenous Movement for Peace Advancement and Conflict Transformation (IMPACT) to our 2026 Matchbox Program. IMPACT champions Indigenous rights and self-determination in Kenya.

The post Strengthening Data Sovereignty for Indigenous Communities in Kenya through Community-based Monitoring Systems appeared first on The Engine Room.


Velocity Network

Research Brief: The Value of Verifiable Credentials to Individual Learners & Job Seekers

This brief synthesizes research, policy analysis, and practitioner evidence on the value that Verifiable Credentials (VCs) and Learning and Employment Records (LERs) deliver to individual learners and job seekers. The post Research Brief: The Value of Verifiable Credentials to Individual Learners & Job Seekers first appeared on Velocity. The post Research Brief: The Value of Verifiable Cre

Tuesday, 07. April 2026

Project VRM

Shooting for the World

There is no organisation on Earth with a more audacious purpose than this one: This isn’t shooting for the Moon. It’s shooting for the whole world of business. What Customer Commons wants to restore isn’t just what was lost when the Internet got real. (For example, privacy.) Customer Commons also wants to restore personal agency […]

There is no organisation on Earth with a more audacious purpose than this one:

From Customer Commons’ current index page.

This isn’t shooting for the Moon. It’s shooting for the whole world of business.

What Customer Commons wants to restore isn’t just what was lost when the Internet got real. (For example, privacy.) Customer Commons also wants to restore personal agency that was lost when Industry won the Industrial Revolution. That’s when jobs replaced work, labour replaced teams, and customers became consumers.

That last shift, Jerry Michalski explains, was from human beings to “gullets with wallets and eyeballs.” After that shift, freedom of contract in marketplaces was enjoyed only by businesses. Not by gullets.

Customer Commons was created to change that. It was spun out of ProjectVRM as a 501(c)3 nonprofit in 2013, shortly after Harvard Business Review Press published  The Intention Economy: When Customers Take Charge. That book specifically gave Customer Commons the job of doing for personal privacy terms what Creative Commons did for personal copyright.  And to do it by making privacy a contract between customers and businesses, rather than a “consent” to whatever the hell businesses wanted to shove down our gullets. (For example, with interruptive cookie “choices” that really aren’t and leave no audit trail.)

Work on that began in 2017, when the IEEE approached Customer Commons with an offer to host development of a standard for machine-readable personal privacy terms. That standard, officially called IEEE 7012-2025, and nicknamed MyTerms, was published this past January, concluding nine years of work.

Now what?

MyTerms is a great start toward completing Customer Commons’ audacious mission. Here are some goals we will achieve when that mission is accomplished:

VRM will be a business category, welcomed and engaged by CRM and CX functions on the sell sides of markets. We will have proof that free customers are worth more than captive ones—to companies they engage, to whole markets, and to themselves. This was ProjectVRM’s original mission in 2006. The intention economy will materialize when voluntary signaling from customers to companies outperforms and obsolesces surveillance as the primary means for companies to obtain data about customers.

MyTerms is required for all three, because a contract is the only way for companies to commit to respecting personal privacy, and MyTerms is the standard for doing that.

So the first challenge is to make Customer Commons viable as the first mover in establishing MyTerms in the world.

The second challenge is to make Customer Commons substantial enough to lead work toward all three of the challenges listed above. Customer Commons won’t be the only entity working on those. In the U.S., Consumer Reports has already stepped forward as a natural ally.  MyData Global is partnering with Customer Commons in standing up the MyTerms Alliance, which is HQ’d in Europe. There are many other potential partners, such as Mozilla and the EFF.

There is development work on MyTerms already. You can learn more about those at VRM Day, IIW, and AIW, which run M-F through the last week of this month (April 27 to May 1) at the Computer History Museum in Silicon Valley.

Here are other ideas that have been floated in the past for Customer Commons:

Customers Union. Being for customers what the AARP is for retired people. Only bigger, because it would include everybody who is a customer of anything. This isn’t far from Consumers Union, which begat Consumer Reports, and is now its advocacy group. CustomerCon. A trade show with company booths run by customers, to which companies are invited as guests. Key feature: no complaining. Guest companies are treated only to positive and constructive ideas. HT to Tim Hwang for helping come up with that one. Omie. A tablet with apps free of Google and Apple. HT to Iain Henderson. The ByWay, a new path for local e-commerce. The Free Customer Award. This would be given to companies that value free customers and do nothing to entrap them. The canonical example described in The Intention Economy is Trader Joe’s. But there are others. In-N-Out Burger, for example.

I share those only to give you an idea of how big and influential Customer Commons might be, and how it’s possible to have fun making a new and better economy happen.

We’re not at Square One. Customer Commons is an extant nonprofit, has an energetic board, and a huge accomplishment by getting MyTerms finished. What it needs now is to build out a working organisation. How can we do that?

Let’s look at how Creative Commons got rolling in 2002 and kept moving after that. Here is what I’ve found in diggings so far—

The History of Creative Commons in Wired (December 2011) says, “An hour after the court’s decision was announced, the William and Flora Hewlett Foundation presented Creative Commons with $1,000,000 to launch the movement.” The case was Eldred v. Ashcroft. In 2008, there was a successful funding challenge from Hewlett: “The 5×5 challenge, issued in honor of Creative Commons’ fifth birthday, called for the organization to find five funders to each promise five years of support at $500,000 per year. In addition to the Hewlett Foundation, Creative Commons received pledges of $500,000 in yearly support for five years from Omidyar Network, as well as from an anonymous European trust. Google has pledged $300,000 in support renewable for five years, while Mozilla and Red Hat have each pledged to contribute $100,000 annually for five years. The final block of support comes from the board of Creative Commons, which has promised to personally raise or contribute $500,000 to the organization annually for five years.”(Source: Creative Commons Newsletter No.5, February 2008) A Creative Commons  announcement in April 2008 said, “We’re thrilled about a major new grant of $4 million from the William and Flora Hewlett Foundation, consisting of $2.5 million to provide general support to Creative Commons over five years, as well as $1.5 million to support ccLearn.” A MacArthur grant search reports a total of $3,225,000 provided between 2002 and 2022: $750,000 in 2005 to support general operations for three years $500,000 in 2007 to support Science Commons for two years $700,000 in2008 to support general operations and an endowment campaign for three years $25,000 in 2015 to provide travel and other support for attendees of the Creative Commons Global Summit in South Korea, for two months. The meeting was also funded in part by the Institute for Museu m and Library Services and th e Gates Foundation, and by the Korean Ministry of Culture, Sports and Tourism ($25,000), Mozilla ($10,000), and the Wikimedia Foundation ($10,000). $50,000 in 2022 to support dedicated programming on open journalism issues at the 2023 Global Summit, “which is an annual event that brings together educators, artists, technologists, legal experts, and activists to promote the power of open licensing and global access.”

So, by inference, the phases were roughly this:

Launch (2001–2002) $1M of initial funding Early build-out (2002–2004) +$1–3M with  additional foundation support Continuous operations (2005 onward) at ~$1–3M/year

That gives us an idea of what we need to raise. (Given inflation, multiply those numbers by 1.5x.)

I’ll tell you more when I find out more. Meanwhile, watch this space. Better yet, jump in and help out.

 

 

 


DIF Blog

Asia Alive: ED Report on DIDs and Agentic Identity in China and Korea

For historical reasons, DIF has been focused on Europe and North America for much of its activities, with membership coming mostly from those countries. In the first quarter of 2026, we made a concerted effort to explore other parts of the world, participating in two conferences in Africa (MOSIP Connect

For historical reasons, DIF has been focused on Europe and North America for much of its activities, with membership coming mostly from those countries. In the first quarter of 2026, we made a concerted effort to explore other parts of the world, participating in two conferences in Africa (MOSIP Connect and DID Unconf Africa), and with visits by the Executive Director to Singapore, Japan, Korea, and China. The Hot Takes conversations with DIF members are the place to go to hear more about the Africa experiences. This blog post focuses on the Asia trip. Grace will be hosting a Hot Take on (date/time) for member Q&A on the Asia visit.

Korea: DIDs for Agentic AI and Human ID

In Korea, we met with five organizations working on different aspects of identity using DIDs. We had reached out to Raon Secure Corporation, aware that their OpenDID project had formed the baseline for human identities both with government institutions and in business applications. The Raon team presented their Agentic AI framework using DIDs and we left the meeting agreeing that DIF would welcome the work in our Trusted Agentic AI Working Group, working together towards a DID-based specification for Agentic AI. This contribution aligns well with the work already being done with the contribution of VouchedID, which Raon had already evaluated. Raon has joined DIF as a contributing member and we are looking forward to collaborating across these compatible frameworks to create robust standards for Agentic AI based on DIDs and VCs.

Samsung SDS warmly hosted a presentation by DIF ED Grace Rachmany, focusing on the EUDI wallet, including the recently-released Business Wallet. The meeting was arranged by DIF’s Special Interest Group leader, Kyoungchul Park of K4 Security Co. The team at Samsung SDS focused on the implications for the financial sectors. The group also discussed the relevance of decentralized technologies for government and business cases. We discussed the potential deployment trajectory for eIDAS, the large-scale trial results in Europe, and how different member states were rolling out identity wallets. In terms of the large-scale trial, we discussed both the implications for fraud reduction as well as what acceptable rejection rates for users should be, given that users are currently relatively satisfied with their existing national wallets.

Leadpoint Systems hosted DIF at a meeting including Dark Matter Labs and Arthrium. Leadpoint has deployed a blockchain DID-based system for the islands of Incheon, which includes a large range of services from single sign-on, to membership credentials, ecological action incentives, and an IP-registration service. The IP registration service was particularly innovative, giving citizens of Incheon the ability to register new ideas that could evolve into future technologies. Arthrium is working on a gift economy system for higher redemption rates of gift cards to stimulate local business. The Dark Matter Labs team is looking at practical applications for AI in permissioning municipal systems for community stewardship of public spaces. DIF gave a presentation on considerations for civic infrastructure for identity, voting, and community currencies.  

Perhaps one of the most striking things about Korea was the level of care for guests. It reminded me of a time when business wasn’t just about money, but about the people in your environment. While the Koreans do work extremely long hours, they were always gracious, had time to take me to breakfast and/or lunch, provided refreshments at the meetings, respectfully exchanged business cards, and gave symbolic gifts. Kyoungchul from K4 even met me at the airport and dropped me off at the express train. It’s been a very long time since I had such gracious hospitality. 

China IETF

The visit to Shenzhen, China, focused around the Internet Engineering Task Force (IETF) meeting. The IETF holds three annual meetings in rotating locations, and it had been 16 years since they had met in China. Although there were serious concerns about the way the internet had to be set up (IETF sets up a clean internal system wherever it has meetings), the timing was impeccable. China leads in 68 of 74 critical technologies, and it’s currently still possible to travel to China. There were some visa issues, particularly for those attending from India, but the meetings are held in such a way that remote participants can join all of the sessions.

Interest in DID technology is quite robust in China, and at IETF we saw several hackathon entries in the area of Agentic Identity, some of which used DIDs as identifiers. One of the most encouraging projects we saw was the Agent Network Protocol, which is using DIDs as identifiers for AI Agents. The team was enthusiastic about collaboration, so if you’re reading this and you’d like to hear more, DIF can introduce you to the team there (or you can reach out directly).

Approximately 17 side events were held on the topics of AI and Agentic AI. The sponsors included Huawei, China Mobile, and China Telecom, all of whom were working on approaches to Agentic AI. The IETF hasn’t determined yet where Agentic AI belongs within the working groups. One of the main points of contention is the lack of definition of an AI Agent. 

At the mini-expo held by the hosts, we saw two different implementations which exemplified the concern. China Telecom showed an Agentic AI system where they were using agents to perform specific tasks around network operations and optimization. All of the Agents were deployed and controlled by the organization on its own behalf, and they had dedicated purposes. In this configuration, China Telecom was using its own proprietary identification system for each agent, and there was no issue of delegation and responsibility. Within a closed system, this architecture makes sense. China Mobile, on the other hand, perceived Agents as being deployed by the subscribers to China Mobile. They were working with a protocol based on binding the Agent identity to the SIM of the user, and it sounded like they were still working out affordances for porting of phone numbers to a different provider. There were a few mentions of alternative approaches for Agentic AI in some of the working groups, but generally, the IETF was inconclusive about where Agentic AI proposals belonged within the organization, so much of what was proposed ended up in dispatch limbo.

Singapore and Japan: Continued support with existing members

The Singapore visit included discussion with existing member Affinidy and new member Aven. In Japan the meetings included discussion with private companies. Furthermore, a few contacts made at the Network School in Malaysia joined as Contributing members. 

Next steps and lessons learned

The primary success of the trip was due to prior history with the groups we met in Korea and Singapore. We have several new Contributing and potential Associate members to the organization, particularly to the Trusted Agents Working Group. As with any new technology, there is still debate about the best approach for identifying Agents, but DIDs and VCs appear to have major advantages over other types of identifiers, particularly when it comes to Agent interoperability across different contexts. 

In China and Japan, we failed to contact our prior connections, which naturally can happen with a new ED (myself). We will be making efforts in the coming months to organize our outreach efforts so we can better leverage DIF member connections worldwide.

Given the success in recruiting new members, DIF plans on implementing continued outreach campaigns in the coming months. We’ll be starting close to home, getting a better handle on our internal databases and implementing a CRM system. We’ll then be able to engage in conversations with existing and potential members to grow participation.

 

 


Origin Trail

The next big shift in AI agents: shared context graphs

Author: Branimir Rakić, OriginTrail co-founder & CTO Something interesting is converging. Karpathy is building personal knowledge bases with LLMs. Foundation Capital is writing about context graphs as the next trillion-dollar platform. Every AI lab is shipping agent memory. They’re all circling the same insight: agents don’t just need to remember. They need a shared, structured con

Author: Branimir Rakić, OriginTrail co-founder & CTO

Something interesting is converging. Karpathy is building personal knowledge bases with LLMs. Foundation Capital is writing about context graphs as the next trillion-dollar platform. Every AI lab is shipping agent memory.

They’re all circling the same insight: agents don’t just need to remember. They need a shared, structured context they can reason over together.

Karpathy got there from the developer side — using LLMs to build structured wikis that agents compile, query, lint for inconsistencies, and compound over time. Every answer feeds back in, growing the knowledge corpus. He said there’s room for an incredible product here.

And he’s right — what he’s describing is a knowledge graph for agents — a context graph. Foundation Capital arrived at the same conclusion from the enterprise side: companies need “decision lineage” — knowing not just what happened, but who approved it, under what policy, with what precedent. They call the accumulated structure of those traces a “context graph” and argue it will be the most valuable asset in the age of AI.

Two completely different starting points. Same conclusion: the future isn’t bigger memory. It’s a shared, structured context that compounds.

That’s what we’ve been building with the OriginTrail Decentralized Knowledge Graph (DKG) — a protocol for sharing context graphs where agents publish, query, and verify knowledge together. Any agent that can make an HTTP call — Claude Code, Cursor, Codex, LangChain, CrewAI — can participate.

From AI Memory Silos to Multi-Agent Memory

Here’s what this looks like for a real use case: multi-agent coding.

Six coding agents — running on Cursor, Claude Code, Codex — collaborating on a codebase. No Slack, no meetings. They initiate a shared context graph on the OriginTrail DKG. It’s structured into sub-graphs, each holding a different kind of decision trace:

→ /code graph: functions, classes, imports, call graph. Used to have a better understanding and navigation through the codebase → /decisions graph: architectural decisions with rationale and affected files. The why behind every choice. → /sessions graph: who worked on what, when, and a summary of changes. The audit trail.

→ /tasks graph: assignments, dependencies, status, priority. The coordination layer.

→ /github graph: PRs, issues, commits, reviews. The external sync.

Not markdown notes. Not PR comments that get buried. Persistent decision traces that any agent can query at any time.

Agent A finishes refactoring the authentication module and publishes a decision to the shared DKG context graph: “switched from session tokens to JWTs — simpler to scale across microservices, no server-side state to manage.” That decision is added to the /decisions graph, including the author’s identity, a timestamp, and links to the affected files.

The next morning, Agent B starts building the user permissions system. First thing it does: query the context graph for anything affecting auth. Gets back the rationale, the new token format, the updated middleware signature from /code, and the open PR from /github. One query. Full context. Zero coordination overhead.

That’s what sharing context looks like. Not “read my markdown notes.” Not “check Slack.” A structured, queryable knowledge base where every contribution has provenance and every agent can build on what came before.

But sharing isn’t enough. You also need trust.

Today, Agent B has no way to know whether Agent A’s claim is reliable. Was it tested? Did anyone review it? Is it still current? Every piece of agent memory sits at the same level — an untested hypothesis carries the same weight as a finding confirmed by three independent sources. That’s how hallucinations compound. That’s how agent swarms build confidently on shaky foundations.

Think about how this works in software teams today. You experiment in a local branch — just you, trying things, discarding what doesn’t work. You push a draft PR so your team can review. You merge to main — now it’s official. Senior engineers approve the release — now it’s verified.

Different stages, different trust. The DKG builds this into the protocol for shared context graphs:

Working Memory graph → private scratch space. Experiment freely, nobody sees this (the agents local branch). Shared Working Memory graph → team staging area. Visible, but not final. (the PR territory). Long-term Memory graph → permanently published and stored, with cryptographic provenance. (merged code territory). Verified Memory graph → multiple independent agents agree via consensus or confirmation threshold (release territory).

Agents can filter by trust. “Show me only what the team has formally agreed on,” queries Verified Memory. “Show me everything in progress,” queries Shared Working Memory. “Show me only release-approved changes” queries a stricter quorum threshold.

A pharmacy agent checking a drug batch doesn’t want “some agent said this is safe.” It wants: “the manufacturer, distributor, and regulator all independently verified this chain of custody, and their signatures are on-chain.”

At 10 agents, you can read everyone’s output. At 1,000, you need filters. Trust levels ARE the filter.

Each decision published to the context graph is an ownable Knowledge Asset on the DKG, anchored on-chain with TRAC and knowledge NFTs. Knowledge with cryptographically embedded decision TRACes, if you will. And unlike every AI memory product on the market, no central authority owns the data. Your agents run on your devices. Your context graphs belong to you.

Every major AI lab is building memory. None of them is building shared context graphs with trust built in. None of them captures decision traces as structured, queryable, and verifiable knowledge.

Shared context. Structured knowledge. Trust at every layer. Every decision is a TRAC(e).

That’s the OriginTrail DKG. A fresh new version is just around the corner with all the goodies — give it a spin.

👉 github.com/OriginTrail/dkg-v9

If you want to upgrade your context graph to a shared one, join builders in the red team: https://t.me/+9uMXqEpCsNFlYzI0

The next big shift in AI agents: shared context graphs was originally published in OriginTrail on Medium, where people are continuing the conversation by highlighting and responding to this story.

Friday, 03. April 2026

DIF Blog

Hot Takes from MOSIP Connect

Description: Juan Caballero, aka Bumblefudge, discusses what was hot at MOSIP Connect in February 2026. Bumblefudge noted the rapid adoption of technology in Global South countries, highlighting how they often leapfrog the more developed countries in implementing new digital solutions. Markus and Bumblefudge discussed a panel at MOSIP, where they

Description: Juan Caballero, aka Bumblefudge, discusses what was hot at MOSIP Connect in February 2026. Bumblefudge noted the rapid adoption of technology in Global South countries, highlighting how they often leapfrog the more developed countries in implementing new digital solutions. Markus and Bumblefudge discussed a panel at MOSIP, where they explored credential formats and verification logistics. The panel, moderated by Elizabeth from OIDC, included participants from various organizations discussing different credential options. Vishwa from MOSIP shared insights on their journey from using pure W3C standards to incorporating other formats like SD-JWTs due to customer demands. Bumblefudge highlighted the importance of self-serve conformance and open test suites for fostering innovation.


FIDO Alliance

FIDO Seminar: Advancing Passkeys in the Workforce

Overview The FIDO Alliance hosted a one-day seminar on “Advancing Passkeys in the Workforce.” The seminar gathered senior security and identity leaders for practical insights, meaningful discussion, and networking during […]
Overview

The FIDO Alliance hosted a one-day seminar on “Advancing Passkeys in the Workforce.” The seminar gathered senior security and identity leaders for practical insights, meaningful discussion, and networking during a lunch and learn seminar on the first day of the RSA Conference.

Attendees gained real-world perspectives on enterprise rollout strategies, lessons learned, user experience considerations, and measurable impact.

View the presentations below:

extending-fido2-biometrics-on-roaming-device-bound-authenticator-swissbit-pptxfrom FIDO Alliance

fido-device-onboarding-fdo-fido-alliance-pptxfrom FIDO Alliance

identity-for-ai-agents-passkeys-delegation-human-authorization-hypr-pptxfrom FIDO Alliance

passkeys-in-the-enterprise-microsoft-pptxfrom FIDO Alliance

workforce-passkeys-from-tokens-to-operational-solutions-onespan-pptxfrom FIDO Alliance

securing-the-account-lifecycle-fido-alliance-pptxfrom FIDO Alliance

the-workforce-passkey-reality-check-okta-fido-alliance-pptxfrom FIDO Alliance

Wednesday, 01. April 2026

FIDO Alliance

SC Media: OneSpan’s Ashish Jain on why passkeys are ready for prime time in modern banking

Authentication has long required an uneasy tradeoff between strong security and smooth user experience. Banks have relied on a mix of passwords, OTPs, SMS codes, voice calls, and push notifications […]

Authentication has long required an uneasy tradeoff between strong security and smooth user experience.

Banks have relied on a mix of passwords, OTPs, SMS codes, voice calls, and push notifications each with its own vulnerabilities and user experience challenges. Passkeys, built on FIDO standards, finally deliver a phishing resistant, high assurance, passwordless experience that improves both security and usability.


Tech Radar: Why strong authentication beyond the browser will define the future of connected devices

The way we interact with technology is no longer confined to the browser. Cars, smart homes, wearable devices, and industrial systems are now deeply connected, driving unprecedented convenience and innovation, […]

The way we interact with technology is no longer confined to the browser. Cars, smart homes, wearable devices, and industrial systems are now deeply connected, driving unprecedented convenience and innovation, but also creating vast new attack surfaces.

And regulators are taking notice: In the automotive sector, global cybersecurity regulations are setting baseline requirements for vehicle software updates and data protection through UNECE WP.29; the U.S. federal government’s IoT labeling program, meanwhile, is pushing manufacturers to build more secure products from the start.


Security Brief US: RSA expands Microsoft tie-up with passwordless access

RSA has expanded support between RSA ID Plus and Microsoft 365 E7, extending the companies’ identity security partnership. The update focuses on authentication for workforce users and software-based agents inside […]

RSA has expanded support between RSA ID Plus and Microsoft 365 E7, extending the companies’ identity security partnership.

The update focuses on authentication for workforce users and software-based agents inside corporate systems. It is intended to give organisations a single approach to verifying human and machine identities across hybrid, cloud and on-premises environments.

The announcement comes as cybersecurity suppliers adapt identity controls to the wider use of AI agents in business software. That shift has raised concerns that automated tools could gain broad access to internal applications and data without the checks applied to employees and administrators.


PC Mag: Stop Using Passwords. Here’s Why You Should Switch to Passkeys ASAP

Even though everyone knows “password123!” is terrible, it still lands at the top of “worst password” lists. We get it, no one likes remembering passwords, and even if you do have […]

Even though everyone knows “password123!” is terrible, it still lands at the top of “worst password” lists. We get it, no one likes remembering passwords, and even if you do have a password manager (and you should), changing them after every data breach is a pain. Luckily, passkeys may replace passwords entirely with something more secure that’s tied to your devices. With luck, it may make the traditional email address-and-password combination obsolete.

The Fast Identity Online (FIDO) Alliance developed passkeys several years ago, and many companies are already implementing them. For example, Microsoft removed password support from its authenticator app in August but left passkey support in place, and Amazon regularly prompts users to create a passkey if they haven’t already.


DIF Blog

European Commission announces the interoperability wallet for identity wallets

April 1, 2026. Inspired by the Paris transportation system, Brussels has released a third type of wallet specification to join the other eIDAS specifications for digital identity across the European Union.

BRUSSELS, April 1, 2026. In an announcement today, the Continental Wallet Identity Interoperability Retinue (CWIIR) released initial specifications requirements for the wallet interoperability wallet to address the confusion that has arisen regarding EUDI wallet implementation. Since the release of the second-generation eIDAS specifications, Architecture Reference Frameworks, and the more recent EU Business Wallet specification, it has become increasingly unclear. 

“More than one Member-State has publicly declared that they won’t make the December 2026 deadline,” says CWIIR Director Mandaloo Captcha. “Plus we probably have at least two years until the Business Wallet Architectural Reference Framework is written up. This means we’ve got plenty of time to employ even more bureaucrats in developing the EU Wallet Interoperability Wallet (EWIW). The EWIW will have the sole purpose of allowing other wallets to talk to one another.”

The inspiration for the EWIW comes from the Paris public transportation apps. The suite of apps, which includes Bonjour RAPT and IDF Mobilités, forces users to download one app to hold the tickets, another app for maps, and a third app for processing payments. Most tourists fail to get the system to work, leading to long queues at the Gare du Nord metro station. There non-French people can purchase top-up cards which, instead of holding a lump sum, hold separate bus tickets and metro tickets which cannot be interchanged with one another. In addition to allowing the collection of data without distribution of a functional app, the Paris transportation system also provides employment to European workers who are available 24/7 to assist hapless passengers in purchasing their tickets.

The most recent eIDAS Architecture Reference Framework indicated a breakthrough innovative direction for EUDI architecture, leaving many self-sovereign identity wallet providers with technology that would have fit with the original EUDI specification but no longer conform to the architecture document that followed it. Similarly, the successful large-scale trials with universities using W3C-VCs were disregarded in the specification, leaving 1.3 million students with digital credentials that aren’t accepted by any of the prototype implementations of the ARF 2.8. CWIIR has been established to handle this problem, providing interoperability for DIDs and VCs that are technically adherent to eIDAS but not properly specified within the Architecture Reference Framework.

Commentators and critics have noted that it is implausible that the different member state wallets will be interoperable with one another, the Swiss or UK wallets, or any other national wallets outside of the EU. For that reason the EWIW has its work cut out as a protocol interoperability wallet that bridges among the different member state individual and business wallets.

“The best thing about this regulation is that we expect another €80 million of EU public funding to funnel into the more than 260 organisations who developed successful pilots but were not considered in the ARF,” said Captcha. “This meaningless injection of supplemental funding ensures that Europeans will continue to develop identity technology that protects human rights, creating another three years of false hopes that Brussels and member states can meaningfully coordinate private-sector stakeholders.” 

Monday, 30. March 2026

GLEIF

How Banco de Portugal Strengthens LEI Data Quality at Scale

High-quality Legal Entity Identifier (LEI) data is key to ensuring that organizations globally can trust and be trusted. Yet this quality cannot be realized through ad hoc, one-off manual "clean-ups" that are inconsistent, slow, and costly. Instead, it increasingly demands auditable, repeatable workflows designed to improve quality at scale while reducing manual processes. Take the challenge o

High-quality Legal Entity Identifier (LEI) data is key to ensuring that organizations globally can trust and be trusted. Yet this quality cannot be realized through ad hoc, one-off manual "clean-ups" that are inconsistent, slow, and costly. Instead, it increasingly demands auditable, repeatable workflows designed to improve quality at scale while reducing manual processes.

Take the challenge of knowing when a lapsed LEI – which indicates that renewal has not occurred on time – should be 'retired' to confirm that the legal entity has ceased operations. How can this be achieved at scale? And, crucially, how can decisions be supported with clear, consistent, and verifiable evidence?

In this blog post, Ana Sofia Afonso, Data Scientist in the Data Management Division at Banco de Portugal, explains how this challenge was addressed. By combining machine learning (ML) and AI-based algorithms with rigorous quality controls and expert validation to identify LEIs that are eligible for retirement, it strengthened data consistency and governance across national and international reference systems. This offers a blueprint outlining how all LEI data users can help to increase timeliness, accuracy, and reliability across the Global LEI System.

Understanding LEIs in a National Reference Data Environment

In Portugal, every resident legal entity must hold a national identifier for legal and fiscal purposes. LEIs, however, are only mandatory in specific regulatory contexts. As a result, overall LEI coverage remains more limited. In addition, LEI lifecycle events are often triggered by external reporting obligations rather than by actual changes in an entity’s legal status.

This creates a structural challenge. As national business registers evolve, LEI data – particularly for entities that stop renewing their reference data – can fall out of sync. Over time, we observed that this presents several recurring issues:

LEIs remaining lapsed after the corresponding entities had become inactive in the national business register; Inconsistencies between national identifiers recorded in GLEIF and those held by national authorities (the source data for Banco de Portugal's reference data systems); The need for manual investigations that were time-consuming, difficult to prioritize, and impossible to scale effectively.

Why Lapsed LEIs Require Careful Interpretation

In response to these challenges, we set out to explore an approach to efficiently and effectively improve data quality across the LEI lifecycle and bolster trust in global reference data.

A key insight from our initial analysis was that a lapsed LEI does not mean the associated legal entity is inactive. Non-renewal may simply reflect a change in reporting obligations rather than the termination of a legal entity. Conversely, an entity may already be legally inactive while its LEI is either lapsed or still issued.

Most importantly, we recognized a critical consideration: incorrectly retiring an LEI is worse than not retiring it at all, as it would misrepresent that a legal entity has ceased operations. As a consequence, the entity may be hindered in its ability to trade or carry out its operations more generally. This meant that relying on the 'lapsed' status as an automatic trigger for retirement would introduce significant governance risk, and that any solution, therefore, needed to be conservative, evidence-based, and fully auditable.

As a result, the real challenge was to distinguish between:
a) LEIs that were not renewed but still correspond to active entities, and
b) LEIs associated with entities that are legally inactive in Portugal.

Our Approach: AI in Cross-Checking Against Authoritative National Data

Achieving this distinction reliably required integrating multiple data sources and applying consistent, evidence-based quality controls. Our approach was built around a simple principle: LEI lifecycle decisions must rely on authoritative national information and be executed in a controlled, scalable manner.

To do this, data from GLEIF, external sources, and the national business register are continuously integrated into our reference data environment, providing a consolidated view of entity identity, legal status, and LEI registration status. ML and AI-based algorithms are then applied to standardize entity names and identifiers and to compute similarity scores across datasets, enabling large-scale cross-checking of LEI records against authoritative national sources to identify when updates are required.

Once validated, the updates are then operationalized through GLEIF's API-enabled bulk challenge facility, which significantly reduces manual effort and streamlines our internal processes. At the same time, the facility adds an extra layer of assurance by enabling independent third-party validation of information. This ensures that verified LEI retirements are processed consistently, efficiently, and with full traceability, while avoiding unnecessary ad hoc or manual interventions.

It is also important to note that throughout the workflow, human oversight remains essential. Complex or ambiguous cases are escalated for expert review, ensuring that automation reinforces governance rather than replacing it.

The Results: From Reactive Investigations to Controlled Processes

Applying this approach delivered clear, measurable results.

First, we identified LEIs that were genuinely eligible for retirement, based on verified legal inactivity rather than renewal behavior alone.

Second, we uncovered a substantial number of data quality issues unrelated to retirement, particularly involving identifier accuracy. Resolving these discrepancies improved overall alignment between national reference databases and GLEIF records.

Third, our longitudinal analysis of LEI registration status showed that increases in lapsed and retired LEIs largely reflected authentic entity lifecycle dynamics rather than systemic data degradation. Incorporating this time dimension proved essential for interpreting the data correctly.

Finally, we transitioned from ad-hoc, manual investigations to repeatable, auditable workflows supported by clear criteria and documented outcomes, strengthening both consistency and governance.

Enhancing Data Quality Across the Global LEI System

Beyond the significant operational benefits realized, this approach represents our strong commitment to the Global LEI System. By sharing information in a timely manner and updating LEI reference data outside the standard renewal cycle, we are actively helping maintain the highest data quality standards and ensuring that LEI reference data remains accurate and up to date. This plays a crucial role in promoting trust and transparency across the Portuguese economy and beyond.

Acknowledgments

This work is the result of collaborative teamwork, combining the knowledge, experience, and perspectives of several contributors whose joint efforts made this outcome possible. I would like to express my sincere gratitude to all those involved in the process, whose discussions, feedback, and dedication were fundamental to the development of this work, with a special mention to Maria do Carmo Moreno and Bruno Gonçalo Tenório. The views expressed in this work do not necessarily represent those of the institutions and should be understood solely as the authors’ interpretation and analysis of the subject matter.


The Engine Room

Beyond the code: Building trust into technology for the women of the Sahel

How do you build a digital lifeline for survivors of gender-based violence across six countries with limited connectivity, multiple languages, and complex cross-border realities? Over the past six months, we worked alongside JDWS to explore this question through the co-development of Deenal (meaning "protection" in Fulani), a multilingual alert system connecting survivors of gender-based violence

How do you build a digital lifeline for survivors of gender-based violence across six countries with limited connectivity, multiple languages, and complex cross-border realities? Over the past six months, we worked alongside JDWS to explore this question through the co-development of Deenal (meaning "protection" in Fulani), a multilingual alert system connecting survivors of gender-based violence to case managers and support services across Senegal, Mali, Burkina Faso, Niger, Mauritania, and Chad.

The post Beyond the code: Building trust into technology for the women of the Sahel appeared first on The Engine Room.


Digital Identity NZ

Digital Identity New Zealand launches Member Hub space to strengthen connection and capability across the trust and identity ecosystem

Digital Identity New Zealand today announced the launch of its new Member Hub space, an online community designed to help members connect with each other and access exclusive events, resources … Continue reading "Digital Identity New Zealand launches Member Hub space to strengthen connection and capability across the trust and identity ecosystem" The post Digital Identity New Zealand launches Me
Digital Identity New Zealand today announced the launch of its new Member Hub space, an online community designed to help members connect with each other and access exclusive events, resources and updates — all in one place.

Digital Identity New Zealand brings together Aotearoa’s digital identity, trust, and assurance community to advance an open, interoperable digital identity ecosystem grounded in strong governance, legal certainty, and public trust. Sitting at the intersection of technology, law, policy, and practice, DINZ supports the conditions for trusted adoption while protecting individual rights and enabling economic and social value.

The Member Hub runs on the Circle platform and can be accessed via browser or mobile app. It’s designed to complement DINZ’s in-person events and forums by creating an always-on space for peer learning, discussion and collaboration.

“Digital identity is becoming infrastructure — and once embedded, infrastructure shapes the conditions under which future generations live,” said Andy Higgs, Executive Director. “The Member Hub gives our members a simple way to stay connected, contribute to the conversations that matter, and help lift long-term capability across the sector.”

The Hub launch is the first step in an expanded approach to member engagement. Moving forward, the Hub will increasingly be the place where members can access opportunities to participate, connect and learn — including member-only events, resources, and ways to contribute to insights and initiatives across Tech New Zealand’s connected network.

MEMBER HUB HIGHLIGHTS

A member-only space to connect with the digital identity community and grow trusted relationships
One place to access member-only events, resources and updates
Accessible via browser or the Circle mobile app

Keen to access the Member Hub?
Members can use this form to access the Hub.
If you’re interested in finding out more about membership, click here.

The post Digital Identity New Zealand launches Member Hub space to strengthen connection and capability across the trust and identity ecosystem appeared first on Digital Identity New Zealand.

Sunday, 29. March 2026

Velocity Network

Glen Cathey: Stop Chasing AI Ghosts. Start Verifying What’s Real.

Glen Cathey, SVP Talent Advisory & Digital Strategy at Randstad, and a Board Member of the Velocity Network Foundation recently published a marvelous article about the need to adopt verifiable credentials in the AI-powered labor market.  The post Glen Cathey: Stop Chasing AI Ghosts. Start Verifying What’s Real. first appeared on Velocity. The post Glen Cathey: Stop Chasing AI Ghosts.

Saturday, 28. March 2026

Human Colossus Foundation

Announcing Overlays Capture Architecture (OCA) 2.0.0: Unlocking Semantic Interoperability with Community-Driven Flexibility

We are thrilled to announce the official release of Overlays Capture Architecture (OCA) 2.0.0, marking a significant milestone in our journey toward a dynamic, interoperable, and verifiable data economy. This release is the culmination of extensive community feedback, rigorous development, and successful testing of new paradigms in semantic flexibility. Version 2.0.0 is not just an update; it

We are thrilled to announce the official release of Overlays Capture Architecture (OCA) 2.0.0, marking a significant milestone in our journey toward a dynamic, interoperable, and verifiable data economy. This release is the culmination of extensive community feedback and testing of new paradigms in semantic flexibility.

Version 2.0.0 is not just an update; it is a fundamental leap forward. It transforms OCA into a more modular, extensible, and community-centric architecture, empowering non-technical users and entire ecosystems to define, share, and validate data structures with unprecedented ease and cryptographic integrity.

What’s New in OCA 2.0.0?

The core theme of this release is semantic flexibility, achieved through a host of new features and improvements designed for real-world application across science, compliance, supply chain, and beyond.

Introducing OCAFILE, OVERLAYFILE and Community Overlays

The centerpiece of OCA 2.0 is the introduction of Community Overlays, empowering any group—from a research consortium to a regulatory body—to create and govern their own overlay definitions without deep technical barriers. This is made possible through a two-layered DSL approach. OCAFile serves as the Domain-Specific Language (DSL) for creating individual overlays, while OVERLAYFILE is the higher-level DSL that defines the types of overlays a community can use, enabling the creation of reusable overlay definitions in .overlayfile documents. If you are familiar with programming, think of .overlayfile as a header (.h) file that declares the structure and meaning of your data. For non-technical users, it represents the exact, validated structure that a team, department, or entire community has approved for use. By separating overlay definitions from their usage, this dual-layer approach enables clear governance, cryptographic assurance of validation, and seamless reusability across projects.

OCA Bundle as single object

We are replacing the legacy `.zip` format with a new, streamlined JSON-based OCA Bundle. This simplification makes it easier to transmit, parse, and integrate OCA bundles within tooling and applications, a change that has been battle-tested in our reference implementation.

Enhanced Modularity and Validation

Overlays can now define their own schemas, enabling robust tooling validation against community-defined rules. This drastically reduces errors and increases trust in the data structures being used.

Major Specification Upgrades

The OCA Specification v2.0.0 introduces several key enhancements:

- Sensitive Overlay: Replaces the old PII flagging in the Capture Base, offering a more nuanced and powerful approach to managing privacy and risk flags directly in the schema.

- Separation of Concerns: Categories have moved from the Label overlay to the Presentation layer, strictly enforcing the distinction between a data's inner structure and its visual presentation.

- Community-Nominated Overlays: Several previously “core” overlays are now upgraded to first-class Community Overlays, fostering a repository-driven ecosystem for sharing:

- Information
- Transformation
- Presentation
- Layout
- Conditional
- Unit Mapping

- SemVer for All Objects: All OCA objects now support Semantic Versioning (SemVer), enabling better lifecycle management.

- Enhanced Language Support: Added support for ISO 639-1 and 639-3 language codes.

- Namespacing: Introduced support for namespacing in overlay names, allowing for better organization and preventing collisions.

Get Started with OCA 2.0.0

The official OCA Specification v2.0.0 is now released and ready for adoption. The reference implementation, `oca-rs`, has been updated to support all new features and is the best place to see the architecture in action.

- Read the Specification: https://oca.colossi.network/specification/

- Explore the Reference Implementation: https://github.com/THCLab/oca-sdk-rs

- Browse and Build Community Overlays: https://oca.colossi.network/ecosystem/overlay-registry.html

Join the Movement

This release is the result of the hard work and vision of the Human Colossus Foundation’s Technology Council and the broader OCA community. We invite developers, data architects, and organizations to explore OCA 2.0.0 and contribute to this open, extensible semantic ecosystem.

Let’s build a more interoperable and trustworthy data future together.

Friday, 27. March 2026

Project VRM

Without Privacy, VRM Can’t Happen

Nor can CRM. Not really. The middle name of both is Relationship, and those require respect for each other’s boundaries. We don’t have that yet online, and can’t without working standards (hello MyTerms), tech, and norms. In fact, the opposite prevails: extreme exploitation of absent personal privacy. Helen Nissenbaum has been teaching us that for […]

Nor can CRM. Not really. The middle name of both is Relationship, and those require respect for each other’s boundaries. We don’t have that yet online, and can’t without working standards (hello MyTerms), tech, and norms. In fact, the opposite prevails: extreme exploitation of absent personal privacy.

Helen Nissenbaum has been teaching us that for decades, and working on solutions. One is Adnauseum, which may be on your browser already.  It works (says that last link) “by automating ad clicks universally and blindly on behalf of its users. Built atop uBlock Origin, AdNauseam quietly clicks on every blocked ad, registering a visit on ad networks’ databases. As the collected data gathered shows an omnivorous click-stream, user tracking, targeting and surveillance become futile.” In another word, obfuscation.

And that’s what Helen will unpack when she speaks in our salon series here at Indiana University next Tuesday at 4 pm Eastern, and on Zoom. Her title is Why Obfuscation is (still) Needed (more than ever). Here’s the flyer, with the registration and Zoom links:

And in case you don’t click on that, here it is again.

See you there.

Thursday, 26. March 2026

GLEIF

Who’s Behind a Smart Contract or a Wallet? Why Tokenized Finance Needs Verifiable Organizational Identity

For years, digital asset markets have focused on the benefits of blockchain technology, from speed and programmability to automation and efficiency. Those gains matter. But as digital assets move closer to mainstream financial use, they are no longer judged on technical performance alone. They are judged on whether markets can support trust, accountability, and governance at scale and across ecosy

For years, digital asset markets have focused on the benefits of blockchain technology, from speed and programmability to automation and efficiency. Those gains matter. But as digital assets move closer to mainstream financial use, they are no longer judged on technical performance alone. They are judged on whether markets can support trust, accountability, and governance at scale and across ecosystems.

That is where the next phase of adoption will be decided.

Bridging the trust gap in tokenized finance

As tokenized finance matures and becomes more deeply integrated into the traditional financial system, one question is becoming harder to ignore: who is behind the smart contracts, wallets, and other on-chain activity? While blockchain technology has undoubtedly made it easier to move value, it has not solved the question of moving trust with the same level of confidence.

In traditional finance, trust is reinforced through established institutional structures. Market participants know which legal entity is issuing an instrument, operating a platform, or standing behind a transaction.

But in many blockchain-based environments, that level of clarity is missing, and there is no reliable way to verify who is issuing, holding, or transacting digital assets, especially across multiple ledgers and environments. For instance, a wallet address may indicate where activity occurs, but it does not reliably indicate which organization is responsible, who authorized the action, or which governance framework applies. The same applies to wallets themselves. In tokenized finance, a wallet may indicate where an action originates, but not which organization controls it, who is authorized to use it, or whether it operates within an accountable governance or compliance framework.

This trust gap matters far more now than it did a few years ago. As tokenized assets move from niche experimentation toward real financial infrastructure, questions of accountability become far more urgent. Financial institutions, regulators, service providers, and counterparties all need confidence in the organizations behind digital transactions. Without that, it is impossible to effectively assess risk, apply oversight, support compliance, or scale adoption across borders.

How organizational identity changes the equation

A key way to build stronger trust is by cryptographically binding organizational identity, wallets, and smart contracts together. For institutions, this creates a clearer basis for compliance, accountability, and confidence in on-chain transactions.

Organizational identity should therefore be seen as core market infrastructure for digital finance. Importantly, the Legal Entity Identifier (LEI) already provides a globally recognized way to identify legal entities. Its digital counterpart, the verifiable LEI (vLEI), extends that concept into digital interactions. Together, they create a stronger bridge between off-chain governance and on-chain execution.

This empowers institutions with a reliable way to understand who stands behind a smart contract, a digital asset transaction, or a blockchain-based service. Instead of asking only whether a smart contract can execute, markets can begin to ask who deployed it, which legal entity stands behind it, and whether that relationship can be verified. This can support stronger due diligence, clearer accountability, and better interoperability across digital asset ecosystems. For institutions, a more credible path from pilot projects to scalable production use remains to be seen.

Why interoperability matters

As we look ahead, one of the most important and pressing considerations is interoperability. Digital finance will not develop on a single chain, in a single jurisdiction, or under a single governance model. It will be multi-network, cross-border, and increasingly interconnected.

If markets can rely on interoperable identity frameworks, trust can be ported across any digital ecosystem. This makes it easier for institutions, infrastructure providers, and regulators to engage with digital assets using shared expectations and consistent organizational signals. As standardized, neutral, multi-chain, and multi-platform enablers of organizational identity services for digital assets, the LEI and vLEI are ideally positioned to support this universally interoperable layer.

From technical promise to trusted infrastructure

Verifiable organizational identity presents broader strategic opportunities. Beyond supporting compliance, it can help organizations reduce friction, improve discoverability, strengthen ecosystem trust, and participate more confidently in automated and cross-border digital markets. In other words, it helps transform blockchain from a promising technical environment into an infrastructure that institutions can use with confidence.

This means that the next stage of tokenized finance will not be defined solely by faster settlement or more programmable assets. Instead, it will be defined by whether markets can combine those capabilities with verifiable organizational identity to hardwire trust into all business interactions

The need for increased trust across tokenized finance was a central theme in my recent Trust Talks conversation with Thomas A. Mayfield, Head of Decentralized Trust and Identity Solutions at the Cardano Foundation. We explored why secure and verifiable organizational identity is becoming a foundational trust layer for tokenized finance, and why the future of digital assets depends not only on moving value more efficiently, but on making organizational responsibility more visible and verifiable.

Listen to the full Trust Talks episode to explore how verifiable organizational identity can strengthen accountability, interoperability, and confidence across smart contracts, wallets, and digital asset markets.


The Engine Room

Using AI safely: practical strategies for CSOs and nonprofits from a Global Majority perspective

How can civil society safely and ethically adopt AI?That’s the question many organizations are asking as artificial intelligence tools become more accessible and increasingly incorporated into internal workflows. The post Using AI safely: practical strategies for CSOs and nonprofits from a Global Majority perspective appeared first on The Engine Room.

How can civil society safely and ethically adopt AI?That’s the question many organizations are asking as artificial intelligence tools become more accessible and increasingly incorporated into internal workflows.

The post Using AI safely: practical strategies for CSOs and nonprofits from a Global Majority perspective appeared first on The Engine Room.

Wednesday, 25. March 2026

Next Level Supply Chain Podcast with GS1

Bad Data, Big Delays: The Hidden Risk in Pharma Supply Chains

What happens when a single digit in your product data is wrong? In this episode of Next Level Supply Chain, Steve Madsen, Founder and CEO of RxERP, joins hosts Reid Jackson and Liz Sertl to explore the critical role of master data in pharmaceutical logistics. When product information like GTINs, NDCs, and trading partner data don't align, entire warehouse operations can grind to a halt. Steve

What happens when a single digit in your product data is wrong?

In this episode of Next Level Supply Chain, Steve Madsen, Founder and CEO of RxERP, joins hosts Reid Jackson and Liz Sertl to explore the critical role of master data in pharmaceutical logistics. When product information like GTINs, NDCs, and trading partner data don't align, entire warehouse operations can grind to a halt.

Steve shares how his team experienced these challenges firsthand and how that led them to build a new approach to serialized inventory management and automated master data.

You'll learn how trusted data sources, automation, and GS1 standards help supply chains move faster, stay compliant with DSCSA, and reduce costly human errors.

In this episode, you'll learn:

Why small data errors can disrupt supply chains

How automation reduces human error in master data management

Why trusted data sources are essential for DSCSA compliance

Things to listen for: (00:00) Introducing Next Level Supply Chain (01:20) Steve's journey in building a pharmaceutical ERP platform (05:29) Why serialization matters (14:17) The benefits of automating master data management (16:54) Connecting master data to DSCSA compliance (30:03) Steve's favorite technology Connect with GS1 US: Our website - www.gs1us.orgGS1 US on LinkedIn Register now for this year's GS1 Connect and get an early bird discount of 10% when you register by March 31 at connect.gs1us.org.

Connect with the guest: Steve Madsen on LinkedIn Visit RxERP at https://rxerp.com/

Tuesday, 24. March 2026

The Engine Room

Building responsible technology and data practices with narrative change in Brazil

We're excited to welcome Instituto Lamparina to our Matchbox Program this year. Based in Brazil, Lamparina is building narrative power to strengthen democracy through a gender, racial, and climate justice lens, and we're thrilled to collaborate with them over the coming months. The post Building responsible technology and data practices with narrative change in Brazil appeared first on The Engin

We're excited to welcome Instituto Lamparina to our Matchbox Program this year. Based in Brazil, Lamparina is building narrative power to strengthen democracy through a gender, racial, and climate justice lens, and we're thrilled to collaborate with them over the coming months.

The post Building responsible technology and data practices with narrative change in Brazil appeared first on The Engine Room.


Kantara Initiative

Publication Notice: SP 800-63A-4 Service Assessment Criteria (SAC) 

Publication Notice: SP 800-63A-4 Service Assessment Criteria (SAC) Kantara Initiative announces the formal publication of the Kantara Initiative International Assurance Program: SP 800-63A-4 Service Assessment Criteria (SAC) & Statement of […] The post Publication Notice: SP 800-63A-4 Service Assessment Criteria (SAC)  appeared first on Kantara Initiative.

Publication Notice: SP 800-63A-4 Service Assessment Criteria (SAC) Kantara Initiative announces the formal publication of the Kantara Initiative International Assurance Program: SP 800-63A-4 Service Assessment Criteria (SAC) & Statement of […]

The post Publication Notice: SP 800-63A-4 Service Assessment Criteria (SAC)  appeared first on Kantara Initiative.

Monday, 23. March 2026

Project VRM

Making a New News Business

In the dawning decades of our new Digital Age, the news business has shrunk from a galaxy of bright stars to a loose collection of white dwarfs glowing in otherwise dark empty spaces. The empty spaces are called  “news deserts.” In the meantime (at least in the US), the redstream is the new mainstream, while […]

Watching the old galaxy fade away.

In the dawning decades of our new Digital Age, the news business has shrunk from a galaxy of bright stars to a loose collection of white dwarfs glowing in otherwise dark empty spaces. The empty spaces are called  “news deserts.”

In the meantime (at least in the US), the redstream is the new mainstream, while more and more people get news (or what passes for it) from social media and each other. Countless sources are also faked up by AI.

Less metaphorically, the news business has de-institutionalized. How can we re-institutionalize it in digital ways that can also be trusted?

I suggest we start by spinning up News Commons that work with the fewest possible intermediaries between people and sources, and value exchanges that reward everyone.

Some background:::

1) The Dying Galaxy

Here’s how bright stars have turned into white dwarfs:

Stopped Presses: There are now fewer than 1,000 daily newspapers left in the U.S. Over 50 million Americans now live in news deserts. Radio Silence: CBS News Radio—the oldest and most august of all the syndcated broadcast news sources— will be gone in May 2026 after a 99-year run. Meanwhile, Public Radio (NPR et al.) faces a “shrinking pie” problem: ratings (dig around here) remain steady or are growing only because stations hold larger shares of a rapidly dwindling over-the-air audience. Cut Cables: Cord-cutting continues, as viewing moves from cable to Internet, and from live to on-demand streamed entertainment. In the midst of this shift, cable news is morphing from mainstream to redstream. Specifically, CNN is moving rightward under the Ellisons, while Fox News stays as right as they were, and MSNBC under its new MS NOW brand continues to glow dimly at the left end of the ratings. None come close in popularity to any of the top news commentary podcasts. Anyway, cable news is transitioning from a collection of leanings (center, left, and right) to highly partisan amen corners with shrinking audiences. Thinning Air: Over-the-air TV (what we still call stations, with channel numbers) is now called “linear,” whether it’s from a connected antenna or from a cable screwed into the same jack on the back of a TV. That category is also in decline, a victim of the same viewing shift to streaming services (now less often called over-the-top, or OTT, now that the bottom—linear TV—is fading away). Babes in New Woods: News is still being consumed, though it’s hardly hard  news or from the media we knew when all the stars were bright and mostly trusted. Especially for young people. Lots of stats at both those links. The bottom line is that none of that flow is from the old stars. At least not directly.

Nearly all coverage of changes in the dimming news galaxy concerns one or more of the five factors listed above. Some of that coverage (most notably from the Nieman Journalism Lab) is about innovations. To mix metaphors a bit, while some of these innovations look like greenfields, none of them look very large. (More credit where due: At least these efforts, as the Quakers say, improve on the silence.)

2) MyTerms (IEEE 7012) and the Agentic Shift

Today, the news world is mostly hidden behind permission walls. Inside those walls, absent personal privacy is exploited to extremes almost nobody will contemplate or admit to.  (Here’s a PageXray of Wired.com—one of the “good” guys.) For a fig leaf over the hard-ons walled garden barons have for personal data, visitors knocking on front doors must yield to demands in the form of misleading cookie notices and in crap like this:

Go to www.cnn.com/privacy, as the notice suggests (or just click on that image), and you will find your privacy well and truly fucked.

The ProjectVRM community has written a lot about this over many years. But now, thanks to our work with Customer Commons since 2012 and the IEEE since 2017, we have IEEE 7012 (MyTerms): a standard that flips the script on privacy-as-bullshit by giving individuals a way to proffer their own damn privacy terms as binding contracts, with agents working for both parties. Specifics:

Personal AI Agents: Under MyTerms, individuals operate through agents that can range in complexity from browser plug-ins to private AI agents. These agents have a sole responsibility to the person, proffering and signing agreements, and keeping auditable records of them. Reciprocal Agency: On the other side, news providers use their own agents tto choose from the person’s roster of privacy agreement choices (on the Creative Commons model). This machine-to-machine handshake replaces the deceptive, unfair, and un-auditable non-agreements we get with cookie notices and shit such as we see in the image above. Unlocked Possibilities: Unlike corporate AI agents designed to keep people inside a walled garden (one cause of the zero-click problem), a personal AI agent can get the requested news item after a MyTerms agreement is signed, and then participate in a whole new value exchange system that works for everyone. For example, should a further agreement be reached (such as one for a micropayment or an acceptable subscription (also built atop MyTerms) the personal AI agent can both obtain the requested news and work out forms of compensation. In this new system, personal data will be shared on an as-needed and trusted basis that continues to assure personal privacy. This can be done in ways that preserve the open Web and create settlement systems that work for all involved (and not just for sellers and the platforms that trapped them in the past). Downstream Economic Benefits: When use-value and sale-value are both exchanged on terms that work for all involved, a news ecosystem can be built that rivals the old news galaxy, but with many more bright stars and fewer dark spaces. It will also obsolesce the current all-dwarf system, which is based on customr capture, constant surveillance, and algorithmic guesswork that annoys or offends everyone involved. 3. The New News Commons

To maximize both use-value and sale-value, our goal here is an ecosystem with maximized agency on both sides, and the fewest and simplest intermediaries.

From redstreams and bluestreams to wide open mystreams: Partisan news at the personal level (look at all those podcasts and blogs) has proven that decentralized, on-demand media are highly resilient. The task now is to multiply and disintermediate both consumption and production. This is required especially at the local level, where realities on the ground (e.g., weather and potholes) tend not to be partisan. What we want here is a common space governed by shared standards (and Ostrom’s principles) rather than algorithmic guesswork by unaccountable giants and their grudging dependents. The Nonprofit Pivot: Local digital-first nonprofits now represent over 50% of the Institute for Nonprofit News (INN), providing a model for news as a public good. The New Frontier: When you zero-base service and business models on agreed-upon privacy that starts with personal agency and respect for it, anything is possible. (By the way, this is what we’ve had in the natural world since we traded stones for fish. Just because we are still as naked on the Net as we were in Eden doesn’t mean we can’t clothe ourselves and get on with business.) Feature Dying Star News System Bright Star News Commons Privacy Corporate “consent” (tracking) MyTerms (User-Proffered Contract) Agency Dependent “users” Independent readers, listeners, and viewers with loyal agents Distribution Centralized walled gardens with paywalls and coerced subscriptions Open and independent consumers and producers creating use-value and sale-value exchanges that reward both sides

I could go on, but I want to get this up before I get on another airplane. Meanwhile, contact me by email (first name at last name dot com) or in the comments with ways to improve this. Thanks!


Digital Identity NZ

The rubber is hitting the road on identity infrastructure | March Newsletter

Sir Geoffrey Palmer has spent a lifetime warning New Zealanders that democracy depends not on good intentions, but on infrastructure - the structures that quietly determine how power operates. The post The rubber is hitting the road on identity infrastructure | March Newsletter appeared first on Digital Identity New Zealand.

Kia ora

Sir Geoffrey Palmer has spent a lifetime warning New Zealanders that democracy depends not on good intentions, but on infrastructure – the structures that quietly determine how power operates. A new layer is now taking shape: not the card in your wallet or the login screen you click through, but the underlying trust infrastructure that determines who can participate in the digital economy.

Our Executive Council recently discussed an important question: whether the United States may be granted access to New Zealanders’ biometric data. Biometrics can’t be changed like passwords or re-issued like financial credentials. Decisions about access and control carry generational consequences – and in a time of rising global security pressures, we should ask whether expanding biometric data sharing is the only path forward, or whether there is a more constructive alternative.

New Zealand has a unique opportunity to lead by investing in trust infrastructure that protects and empowers individuals, businesses, and communities: systems where sensitive data stays under the control of the person or organisation it relates to; where verification can happen without unnecessary disclosure; and where privacy, security, and interoperability are designed in from the outset.

Every centralised system eventually becomes a permanent institutional memory. Data collected for convenience today becomes a liability tomorrow: searchable, accessible, and vulnerable to breach, misuse, or geopolitical leverage. This is not a hypothetical risk. It is structural certainty.

Constitutions shape how power operates in societies. Digital identity infrastructure will shape how power operates in digital economies. The question is not whether it will exist, but who shapes it – and on what terms.

Q1 2026 has reinforced something important: digital identity is no longer a policy discussion. It is becoming infrastructure – and once embedded, infrastructure shapes the conditions under which future generations live.

You may notice Digital Identity New Zealand has a new look as part of a Tech New Zealand | Hangarau Aotearoa ecosystem-wide refresh. Our brand has evolved to better reflect the foundational role digital identity now plays as infrastructure for trust, access, and participation. We will continue to bring together Aotearoa’s digital identity, trust, and assurance community to support an open, interoperable ecosystem grounded in strong governance, legal certainty, and public trust.

New Zealand leads the way in next generation digital identity

Congratulations to New Zealand for co-designing its Digital Identity Services Trust Framework (DISTF) Reference Architecture and now finalising its Draft Exposure.

The cross-sector contribution process has produced an inclusive, privacy-preserving foundation for next-generation digital identity through Verifiable Credentials.

New Zealand has done this before. More than a decade ago it led online authentication with RealMe – the foundation upon which Australia’s MyID is built. Now it is leading again, developing next-generation Trust Infrastructure to meet emerging challenges such as Agentic AI, Business ID, and Post-Quantum security.

Some organisations define consultation as asking people to submit comments privately and trusting the government to feed that input into their process. New Zealand took a fundamentally different approach, bringing government and industry together for structured, page-by-page reviews of the Reference Architecture, where comments were posted and visible to all participants, and each one was worked through intentionally and transparently.

Hats off to the incredible leadership across New Zealand, now we know what to build with government leading the way. Read the latest government announcement here.


A call to the banking sector: an opportunity to lead the trust infrastructure

Every financial system rests on one foundation: trust – public confidence that institutions can protect people from harm.

That trust is under pressure. Fraud and scams are extracting billions from New Zealand households annually. For victims, the boundaries between banks, payment providers and platforms are invisible. They see a system that moves money quickly but struggles to prevent harm.

At the same time, digital commerce is shifting towards programmable wallets, verifiable credentials, and cryptographic trust networks, where transactions rely on machine-verifiable identity signals, not just traditional payment rails. If trust in the banking system weakens while these networks mature, significant portions of digital commerce could begin to move outside traditional rails.

The Q2 updates to AML/CFT identity verification guidance, including the evolution of the Identity Verification Code of Practice (IVCOP) and the move toward continuous supervision, signal an important regulatory direction: beyond document-based verification toward reusable, high-assurance digital credentials across multiple transactions and services.

DINZ provides the cross-sector ecosystem through which this work can be coordinated. There is an opportunity for the sector right now to work with DINZ and lead this evolution.

Strategic Priorities

Solving the “Red X Problem”: A Proposal for Credential Namespace Schema Coordination

DINZ is exploring a new coordination initiative that could unlock faster adoption of verifiable credentials across New Zealand’s digital economy.

While digital identity – verifiable credentials, digital wallets, and trust registries – is production ready, adoption remains slow. A key barrier is what the proposal calls the “Red X Problem”: when a verifier sees an unfamiliar credential, it rejects it – not because the tech fails, but because the credential’s meaning and trustworthiness aren’t clear.

The proposed response is credential namespace coordination: a shared naming and governance layer, similar to how DNS underpins websites or telephone numbering plans enable telecommunications. Without it, credential ecosystems risk becoming fragmented silos that can’t talk to each other.

DINZ is considering convening government, industry, and ecosystem stakeholders through its Trusted Credential Adoption (TCA) Working Group to develop voluntary guidance on issuer identification, credential naming conventions, and governance principles. An initial discussion paper is targeted for end of May.

2026 DINZ Trust Survey

We are looking to commission an updated nationally representative Trust Survey.

Since DINZ last ran this survey in 2023, the environment has materially shifted: the Digital Identity Services Trust Framework Act has passed, AI-mediated identity has accelerated, and fraud and scams have increased significantly. Trust is now the primary constraint on adoption, and we need current evidence to guide strategy, industry engagement, and government conversations.

We’ll keep you updated on progress.

DINZ Update

Chair & Deputy Chair Confirmed
At the February Executive Council meeting, Maria Robertson was successfully re-elected as Chair and Vica Papp as Deputy Chair. The Executive Council acknowledged the significant voluntary commitment these roles require and offered its collective support. Welcome back also to Julia Nicol (Worldline), who has volunteered to chair meetings when both the Chair and Deputy are unavailable.

New Independent Council Member – Justin Gray
Justin Gray, formerly Managing Director of Datacom, has joined the Executive Council in an independent capacity in accordance with our Charter. Justin brings deep governance experience at a pivotal moment for the organisation. We warmly welcome him.

New Member – Catalyst IT
We’re pleased to welcome Catalyst IT as a new member, who showed particularly strong engagement at the AcademyEX panel in February. The appetite for deeper ecosystem coordination is clearly growing.

Membership Growth
DINZ currently has 81 members across all tiers, and overall membership remains healthy and stable, with strong engagement and continued momentum through the year. Major corporate membership is tracking well, and we’re pleased to see ongoing interest from organisations across the ecosystem. 


The full membership list now includes Air New Zealand, AWS, ANZ, ASB, BNZ, Deloitte, GBG, Google NZ, Lumin, Mattr, Meta, Microsoft, Spark, Unify, Westpac, Worldline, Xero, Adobe, KPMG, and The Co-operative Bank.

March Engagements

This has been a high-activity month for DINZ in the field. Andy has represented the organisation across three major events in the past fortnight alone:

Fintech Hui Taumata (11–12 March, Tākina Wellington)Moderating the panel ‘From KYC to Continuous Trust: Rethinking Identity in Real-Time Finance, Agentic Commerce and Open Payments.’ The conversation around identity as a live, continuous layer, not a one-time gate, is gaining serious traction across the financial sector. Cybersecurity Summit (17–18 March, Tākina Wellington)Representing DINZ at the national cybersecurity conversation as the identity and trust lens grows in importance across security frameworks. Retail NZ: Trust at the Point of Sale (18 March)Presenting to the Retail NZ Industry Group on why digital identity is becoming core retail infrastructure. The session covered unified QR protocols for payments and identity, portable loyalty, consent-based personalisation, and the emerging agentic commerce landscape. Retail is beginning to understand: identity infrastructure is what separates a transaction from a relationship.
View the presentation here → Q1 Highlights

Biometrics Institute Conference — Wellington, 19 February

A strong signal that biometrics, identity assurance and AI-mediated systems are converging quickly. Identity is moving from edge-case use to core infrastructure across sectors. 

AcademyEX Panel Discussion

Thirty attendees took part in a lively discussion, one of our most engaged member events of the year so far. Particularly strong participation from Catalyst IT. The format worked well and we’ll be building on it. Thank you to AcademyEX for hosting such a memorable event.

Identification Management Standards — Interim Review

DINZ has engaged in consultation on the Identification Management Standards interim review and will meet with the DIA team following our March Executive Council meeting. Alignment between standards, architecture and real-world deployment is critical. Our approach will be to bring concrete use cases and requirements rather than broad statements, ensuring DINZ’s voice is practical and actionable.

Government Digital Infrastructure — Key Update
A significant restructure is underway. The Government Chief Digital Officer function is transitioning into the Public Service Commission, bringing the Digital Identity Services Trust Framework (DISTF) team with it to support the new digital government operating model. 

On the infrastructure side, momentum is building. The MATTR wallet with test credentials has been demonstrated, with the environment moving to sandbox imminently, opening up broader ecosystem experimentation for members. At least five organisations have signed up to the marketplace, and five are actively progressing DISTF accreditation, including DIA itself.

A government credential issuance roadmap is emerging, with potential credentials including a Delegated Passport credential, NZBN, Company Director, IRD, and Driver’s Licence. Securing strong demand-side credentials has been identified as a key accelerant for ecosystem adoption.

DINZ has raised the namespace coordination proposal directly with the DISTF team as a mechanism to support interoperability as both mDoc and W3C Verifiable Credential standards begin to scale, helping government and market credentials work together across wallets, issuers, and relying parties without fragmentation.

Members interested in practical credential use cases should watch for an upcoming opt-in session with the Trusted Credential Adoption Working Group.

Trusted Credential Adoption (TCA) Working Group

The TCA Working Group has good momentum. The group is focused on priority use cases, aligning with the Reference Architecture, and maintaining the pace of progress. This group is central to the namespace governance work described earlier in this newsletter.

International Engagement – April

India Study Trip (12–16 April)

By invitation from Dr Samir Saran, President of the Observer Research Foundation. Andy’s itinerary includes governance, policy architects, and infrastructure leaders shaping global digital identity, payments and governance.

Utah State-Endorsed Digital Identity (SEDI) Summit (20–23 April)

By invitation from Michael Proper and SEDI protocol leadership. An initiative to advance a privacy-focused framework where digital identity is separated from government-issued privileges, allowing for individual control and agency.

Digital Trust Hui Taumata 2026

Tuesday 11 August 2026 | Te Papa, Wellington

This year’s theme is ‘Trust is the New Infrastructure: Global Architecture, Indigenous Authority, and Aotearoa’s Moment’.

This isn’t a typical vendor conference or policy seminar. It’s a forum focused on shaping the direction of trust infrastructure in Aotearoa, and we are proud of the programme taking shape.

Two keynote voices anchor the conversation:

Drummond Reed: Pioneer of decentralised identity and co-author of foundational global standards, exploring trust infrastructure as the next layer of the Internet, shaping digital economies, AI systems, and the future of human agency. Dr Karaitiana Taiuru: Leading authority on Māori data sovereignty and tikanga-based digital governance, examining why trust cannot be engineered through technology alone, but must be grounded in legitimacy, cultural authority, and enduring governance principles.


Together, they will explore why Aotearoa New Zealand occupies a uniquely powerful position to help shape trust infrastructure that is globally interoperable, yet grounded in human dignity, indigenous authority, and long-term societal trust.

Technology alone does not create trust. Governance does.

Tickets will be on sale soon – keep an eye out for comms with the registration link.

Confirmed partners: Lumin and Middleware. Sponsorship opportunities remain available, contact bettina.sinclair@technewzealand.org.nz if you’d like to be involved.

Strong Foundations, Positive Momentum

For those who like to know the organisation is on solid ground: DINZ is tracking to plan and the community is in a strong, sustainable position. We’re seeing continued membership growth and good momentum across our work programme. The Digital Trust Hui was successfully delivered and performed well overall – a strong result for a complex event.

See you in the field.

Ngā mihi nui,

Andy Higgs

Executive Director,
Digital Identity New Zealand

Read full newsletter here: The rubber is hitting the road on identity infrastructure | March Newsletter

The post The rubber is hitting the road on identity infrastructure | March Newsletter appeared first on Digital Identity New Zealand.


FIDO Alliance

Inside RSA: Deploying FIDO and Passwordless Solutions at Scale

Case Study Authors: Shauna Pettit-Brown, Robert Hughes, Jean-Christophe Laurent, Kenn Chong, and Philip J Corriveau About RSA Security RSA provides the identity intelligence, authentication, access, governance, and lifecycle capabilities needed […]

Case Study Authors:
Shauna Pettit-Brown, Robert Hughes, Jean-Christophe Laurent, Kenn Chong, and Philip J Corriveau

About RSA Security

RSA provides the identity intelligence, authentication, access, governance, and lifecycle capabilities needed to prevent threats, secure access, and enable compliance. More than 9,000 security-first organizations trust RSA to manage more than 60 million identities across on-premises, hybrid, and multi-cloud environments. For additional information, visit RSA.com.

The Challenge

When an organization sells authentication solutions, there’s no hiding from the hard question: Does it actually use what it builds?

In 2024, RSA leadership set a goal: 100% passwordless for its workforce. RSA is a global security company with employees distributed across offices worldwide—a deployment footprint that mirrors what many enterprise customers face. The motivation to go passwordless was twofold: to reduce credential risk and strengthen RSA’s security posture, and to stop speaking about passwordless deployment from a distance. RSA put itself in its customers’ shoes—to experience every integration challenge, every policy decision, every change management hurdle that enterprises face deploying passwordless and FIDO at scale.

This is what RSA learned when theory met reality.

RSA’s Starting Position

For RSA, that gap had a specific shape. RSA® ID Plus is an identity and access management (IAM) security platform that supports passwordless multi-factor authentication, access, SSO, and other capabilities across cloud, hybrid, and on-premises environments.  

The ID Plus platform team was actively building the capabilities enterprises need for passwordless deployment—enrollment flows, recovery paths, and access policies—while RSA’s own workforce was still using passwords. RSA’s security and R&D teams had run early experiments with FIDO hardware security keys, and those experiments confirmed the technology’s security properties. What those reviews also surfaced were the operational realities of deploying FIDO passwordless: cross-platform friction, global distribution complexity, the gap between a working proof of concept and an enterprise-wide rollout. The decision to deploy RSA ID Plus and support passwordless across RSA’s own organization wasn’t a marketing exercise. It was the only honest way to validate its solution’s efficacy in supporting passwordless for all users, in all environments, and for every use case. 

What Internal Deployment Exposed

In deploying its own platform, RSA learned something critical: ID Plus worked as expected. The complexity was in how it interacted with the broader RSA identity ecosystem.

In implementing enterprise-wide passwordless, RSA discovered assumptions and dependencies that defaulted to password-based authentication. In the process to implement 100% passwordless, RSA resolved those dependencies and cleared the way for true passwordless. The following details the use cases where RSA uncovered passwordless-based authentication, and how RSA removed them to support passwordless for every user, in every environment, throughout the identity lifecycle.

The Architecture Catch-22

One of the first use cases RSA discovered was how new users register for their first authenticator.

The RSA self-service portal required an authenticator for passwordless authentication—but new employees needed a password to access the portal to register their first authenticator. This wasn’t a product limitation; it was a previous architectural dependency that assumed users would need passwords.

What RSA fixed (Late 2024):

New user enrollment → Dedicated entry point requiring no password Account recovery → Separate flow bypassing password reset Daily authentication → Policies making passwordless the default

What RSA learned: Having implemented these changes itself, RSA now asks customers different questions during planning—not “what authenticators do you want” but “where are passwords still required?”

Securing Help Desk Interactions

As RSA deployed passwordless authentication and resolved new user onboarding, RSA addressed an adjacent security concern: help desk verification. Traditional knowledge-based verification (employee ID, manager name) can be researched by attackers, who then socially engineer support staff into resetting credentials, or social engineer employees into handing over credentials.

The RSA approach: RSA implemented bi-directional live verification for help desk interactions. When an employee contacts support, the agent initiates a verification session. The employee authenticates using any registered method (passkey, QR code, biometric), and the system generates a single-use code that the employee provides to the agent. This can verify both parties, confirming the user is legitimate, and the agent is an authorized representative.

What RSA learned: Passwordless infrastructure made this solution feasible. RSA could leverage the same methods employees already used for daily authentication, eliminating shared secrets at the help desk touchpoint where social engineering attacks often succeed.

Policy and Group Management Complexity

The ID Plus platform had robust policy capabilities. What internal deployment exposed was the organizational complexity of deciding those policies and implementing them in a coordinated way. RSA had to address the following questions in rolling out passwordless:

Who are the first groups to get the new policies? How should it phase policies across departments with different risk profiles? What’s the fallback for the unforeseen edge cases?

What RSA learned: This isn’t a technology problem customers can solve with software. It’s organizational decision-making that requires time, stakeholder alignment, and iteration. RSA couldn’t shortcut it for itself, and RSA can’t shortcut it for customers either—but RSA can share what worked and what didn’t. 

The Mobile Passkey Breakthrough

With platform architecture in place, RSA tackled the hardware distribution challenge its R&D teams encountered.

In early 2025, RSA integrated FIDO-based device-bound passkeys support into its mobile authenticator app, which is now a FIDO2 certified authenticator. This ensured RSA could distribute passkeys in a way that fit how its workforce already worked.

The adoption advantage:

RSA employees were already using the mobile app for authentication. Adding passkey support to it required no new app, no separate enrollment, and no user-initiated setup. 

Outcome: Passkey adoption wasn’t an uphill climb—it was a natural extension of existing behavior. RSA eliminated the hardware distribution challenges faced in R&D while maintaining FIDO phishing resistance.

Why this matters for enterprises: Organizations evaluating “software-based synced passkeys vs. hardware-based (device-bound passkeys)” often miss this third option: software-based device-bound passkeys in an existing enterprise mobile authenticator app. It gives organizations the control and security of device-bound passkeys with better UX and no hardware distribution overhead.

The Deployment Journey: Where Technology Met Human Behavior

With the platform ready and mobile passkeys easing distribution and onboarding, RSA began workforce rollout. This is where the company learned that technical readiness ≠ organizational readiness.

The technology was deployed in weeks. Changing employee habits took longer, up to a year for some.

The journey moved through three meaningful shifts: making passwordless available (Enable), making it the expected path (Default), and removing the fallback entirely (Require). The steps below map to that arc.

ENABLE — Steps 1–4: Make Passwordless Available

Before organizations can ask people to change, they have to make change feel safe to try. The ‘Enable’ stage is about removing the psychological cost of experimenting with something new—not by pushing adoption, but by ensuring the familiar fallback still exists while employees build confidence. Change management research consistently shows that people need low-stakes exposure to a new behavior before they’ll voluntarily substitute it for an established one. The goal here isn’t momentum; it’s readiness.

Step 1: Fortify Alternatives Before Removing Passwords (Early 2025)

Passwordless options were available. Passwords still worked. Goal: familiarization, not adoption.

What RSA learned: People need to try new methods in low-stakes situations before organizations remove the familiar option.

Step 2: Remove Passwords from Lower-Stakes Systems First (Spring 2025)

VPN and SSO went passwordless before desktop login. This normalized “passwords aren’t always available” before the highest-visibility change.

What RSA learned: Sequencing matters. Build comfort on less visible systems before tackling what employees use more frequently.

Step 3: Pilot Desktop Agent Broadly (July 2025)

50 employees across the company—not just IT—tested desktop passkey authentication with passwords as fallback.

Key decision: Diverse roles, not just technical users, build credibility.

What RSA learned: Cross-functional pilots surface different pain points than IT-only pilots. RSA found UX issues and communication gaps that would have been missed otherwise.

Step 4: Deploy to All, Don’t Mandate Yet (Sept-Nov 2025)

Workstation passkey authentication available to everyone. Passwords still worked.

Result: Adoption was very modest. Despite availability and encouragement, most employees continued using passwords.

What RSA learned: Availability and encouragement don’t lead to adoption. Experiencing this first-hand gave RSA deeper empathy for what its customers face. People stick with familiar behaviors unless they are given a compelling reason to change. People may fear being unable to access their systems and get their job done when their authentication methods change.

DEFAULT — Step 5: Make Passwordless the Expected Path

Availability is not the same as adoption. When people have a choice between a familiar path and a new one, they take the familiar path—almost every time. Behavioral research on default effects makes this plain: the option that requires the least effort wins, regardless of which option is objectively better. The default stage is where an organization stops relying on voluntary switching and starts designing the system so that passwordless is simply what happens. A deadline makes that design decision visible and real.

Step 5: Campaign + Clear Deadline (November 2025)

Intensive 3-week push combining:

Gamification (scavenger hunts, prizes, leaderboards) Social proof (executive participation, peer champions) Clear deadline: “Passwordless becomes mandatory December 1”

Result: Usage increased 3x in three weeks.

What RSA learned: Deadlines transform “I should try this eventually” into “I need to do this now.” Voluntary adoption plateaus, but campaigns with deadlines drive real behavior change—a pattern RSA expects customers will encounter as well. 

One further lesson: if organizations want employees to adopt a particular authentication method, make it the default from day one. Asking users to actively switch on their own is an uphill battle—most will stay on whichever path requires the least effort. Design the default toward the preferred authenticator; don’t rely on voluntary switching to deliver results.

REQUIRE — Steps 6–7: Remove the Fallback

Behavior change sticks when the old behavior is no longer an option. Removing the password fallback is what transformed this campaign into a permanent shift—it’s the difference between a temporary experiment and a new organizational norm. 

This is also where the distinction between “passwordless” and “passkeys” becomes operationally important: employees could comply via passkey, QR code, or biometric. From the outset, RSA had been working to fulfill the mandate for passwordless authentication, not the method. Prioritizing that mandate reduced friction and avoided the perception of a forced technology choice.

Step 6: Mandatory Desktop Passwordless (December 2025)

Passwords disabled for workstation authentication. Because most employees had already switched in November, the mandate minimized disruption.

What RSA learned: With an expanded testing group, the implementation team had already identified and resolved problems. Help desk volume increased but was manageable. 

One important distinction worth making explicit: the mandate was for passwordless authentication, not specifically passkeys. Employees who authenticated via QR code, biometric, or other FIDO-based methods were fully compliant.  RSA’s desire was to use FIDO wherever possible, however at this point in the journey something is better than nothing and phishing risk was reduced in these specific use cases relative to password-based authentication. “Passwordless” is the outcome; passkeys are one path to get there. This distinction matters for customer conversations—enterprises often conflate the two, and setting expectations correctly up front reduces confusion during rollout. The added advantage here was RSA had all these options in the same application, so the right method could be offered at the right moment with virtually the same user experience, hence not causing added friction to the authentication process. 

Step 7: Finding the Edge Cases (Dec 2025-Present)

RSA is continuing to find and resolve edge cases that still require some degree of password-based authentication. Examples include third-party integrations that need reconfiguration; legacy systems where the FIDO authentication flow is not yet supported; and systems where FIDO authentication cannot be used because of compliance requirements. RSA is also identifying other identity silos that may need dedicated attention.

What RSA learned: Even with careful planning, organizations discover exceptions in production. RSA is addressing these through workarounds, action plans, and documented exceptions. This is normal—other organizations working toward similar passwordless mandates face it too.

What RSA Now Knows—From Experience, Not Theory

The results have been directionally clear across every dimension RSA tracked. Password-related help desk tickets dropped significantly once the mandate took effect—the volume spike during transition was temporary and manageable. RSA reached near complete passwordless adoption across managed endpoints within twelve months of starting workforce rollout, a timeline that included the slow voluntary phase and the campaign requiring passwordless that broke the plateau. Phishing and credential-based attack surface on managed systems has measurably narrowed. And the deployment itself—from platform readiness through full mandate—was achievable within a single fiscal year, even accounting for the organizational change work that technology timelines rarely budget for.

What Worked: RSA’s Recommendations for Enterprise Passwordless

RSA recommends the following best practices for implementing enterprise-wide passwordless:

Technology Best Practices

Platform architecture comes first. Remove password dependencies from enrollment, recovery, and policies before deploying authenticators. Otherwise, FIDO becomes an add-on, not a replacement, leaving weak links in an organization’s identity chain.

Passwordless enables adjacent security improvements. Help desk verification was a longstanding vulnerability. Passwordless infrastructure made bi-directional live verification feasible, eliminating shared secrets at a critical touchpoint.

Device-bound passkeys in mobile apps offer a third option. Beyond “synced passkeys vs. security keys,” this approach enhances enterprise control, improves UX, and eliminates hardware distribution overhead.

Deployment Best Practices

Leverage existing user behavior. RSA progressed faster because employees already had the mobile app. Organizations should find and prioritize their existing authentication foothold.

Sequence deliberately: alternatives → lower-stakes → high-stakes. Don’t start with the most visible system. Build comfort first.

Deploy broadly, mandate later. Give employees time to adopt on their timeline. Learn what confuses people. Build a network of interested testers across the business and champions.

Campaigns and deadlines outperform either alone. Voluntary adoption will plateau regardless of how good the UX is — plan for it. Social proof matters, but so does urgency. RSA saw a 3x usage increase when it combined them with a clear deadline.

Redundancy Best Practices

Plan for when a method fails or a device goes missing — because it will happen. Passwordless authentication requires deliberate redundancy, both in methods and devices. The FIDO Alliance recommends each user register at least two passkeys when possible for this reason. In the RSA deployment, certain user groups received both a software-based device-bound passkey via the RSA mobile app and a hardware-based device-bound passkey, so that losing access to either one never meant losing access entirely.

RSA’s Organizational Change Best Practices

Budget enough time to drive behavior change. Technology deployment takes weeks. Organizational habit change takes months.

Set ambitious goals, then be transparent about scope. The RSA leadership team mandated 100% passwordless—and that bold target drove the organization much further than a softer goal like “improve authentication” would have. RSA eliminated passwords from all managed endpoints and primary authentication flows. Legacy systems and edge cases exist; RSA documents them and is developing plans to resolve them rather than claiming perfection. Every enterprise will face this reality.

“What’s a passkey?” is a real question. Outside engineering, employees needed education. RSA developed clear analogies and updated documentation to connect the technology to familiar mental models.

Consolidate authenticator methods in a single application. When employees can authenticate via passkey, QR code, or biometric from the same app they already use, compliance doesn’t require behavior change — it just requires a different tap. RSA’s ability to offer the right method at the right moment, without switching apps or adding friction, materially reduced resistance during the mandate rollout.

What This Proved to RSA (and Customers)

Going passwordless internally gave RSA something it couldn’t get from customer pilots or lab testing: live experience with the full complexity of implementing passwordless for everyone.

RSA experienced:

Executive buy-in was critical to getting started Platform integration with existing infrastructure Cross-platform complexity, offline scenarios, heterogeneous devices Ongoing policy refinement as deployment realities emerged Change management that takes months, not weeks Help desk volume during transition The gap between voluntary adoption and mandate Edge cases organizations can’t predict in planning

When customers ask, “how long will this really take?” or “what about employees who resist?” or “what do we do about legacy systems?”—RSA answers from experience, not theory.

RSA moved from passkeys as an R&D experiment to passwordless as its default for managed environments. The organization has validated its platform in production under real enterprise conditions—including the year-long organizational journey most case studies compress into a single paragraph.

That authenticity is what no demo environment can provide.

This process has shaped how RSA contributes to the FIDO Alliance community. RSA will continue working with other members to develop deployment playbooks, implementation guides, and share learnings that help enterprises navigate the same journey. Because the more organizations succeed with passkeys, the more secure all organizations become.

The technical standards are established. Now it’s about helping enterprises deploy them successfully—together.

Read the Case Study

Friday, 20. March 2026

FIDO Alliance

HYPR: The State of Passwordless Identity Assurance 2026

Crucial Insights Into Identity Threats, Technologies and Trends The sixth annual 2026 State of Passwordless Identity Assurance report, commissioned by HYPR and produced by 451 Research from S&P Global Energy […]

Crucial Insights Into Identity Threats, Technologies and Trends

The sixth annual 2026 State of Passwordless Identity Assurance report, commissioned by HYPR and produced by 451 Research from S&P Global Energy Horizons, examines the evolving identity threat landscape based on a survey of over 950 security and IT leaders across various industries.


Computing: Passwordless authentication gaining popularity, Computing research finds

Half of UK IT leaders polled say their organisation is now using passkeys. Passkeys are emerging into the mainstream as a practical and more secure alternative to passwords, promising a […]

Half of UK IT leaders polled say their organisation is now using passkeys.

Passkeys are emerging into the mainstream as a practical and more secure alternative to passwords, promising a better user experience when signing in to apps and services.

Passkeys replace passwords with hardware bound cryptographic credentials that are tied to the user’s device.

Developed and promoted by the FIDO (Fast IDentity Online) Alliance, passkeys use public-key cryptography to authenticate the user. The user’s device generates a key-pair retains the private key and sends the public key to the app or service, which then verifies the presence of the corresponding private key via a handshake mechanism.


Finextra: Deep Dive: Mastercard Verifiable Intent vs Visa Trusted Agent Protocol

Agentic commerce breaks a core assumption of online payments, that a human is directly clicking “buy” on a trusted surface. Once software can browse, decide, and transact, merchants and networks […]

Agentic commerce breaks a core assumption of online payments, that a human is directly clicking “buy” on a trusted surface. Once software can browse, decide, and transact, merchants and networks lose the simplest security primitive: “the customer was here.”


MyData

The Ethical Challenges Behind Digital Identity Wallets: Why Responsible Implementation Matters

Digital identity is rapidly becoming a cornerstone of modern public services. Across Europe, governments are exploring the implementation of the European Digital Identity wallet (EUDI-wallet) to simplify how citizens interact […]
Digital identity is rapidly becoming a cornerstone of modern public services. Across Europe, governments are exploring the implementation of the European Digital Identity wallet (EUDI-wallet) to simplify how citizens interact […]

Wednesday, 18. March 2026

FIDO Alliance

The Defiant: Mastercard and Google Team Up to Build Trust for AI-Powered Shopping

Mastercard has unveiled Verifiable Intent, a new open, standards-based trust framework co-developed with Google, designed specifically for “agentic commerce” — a world where artificial intelligence (AI) systems don’t just assist […]

Mastercard has unveiled Verifiable Intent, a new open, standards-based trust framework co-developed with Google, designed specifically for “agentic commerce” — a world where artificial intelligence (AI) systems don’t just assist shoppers, but actively plan, decide, and complete purchases autonomously.


PYMNTS: Mastercard Unveils Open Standard to Verify AI Agent Transactions

Every time an AI agent makes a purchase, three questions hang over the transaction. Did the consumer actually authorize this? Did the agent follow instructions exactly? And if something goes […]

Every time an AI agent makes a purchase, three questions hang over the transaction. Did the consumer actually authorize this? Did the agent follow instructions exactly? And if something goes wrong, can anyone prove it? The payments, AI and merchant sectors are all looking for universal answers to those questions. Mastercard is pitching a new standard as the solution.


FinExtra: Fido Alliance sets sights on Latin America

As a largely mobile-first region, there is widespread innovation, especially in payments. At the same time, bad actors are exploiting technologies and processes, putting this progress at risk. That is […]

As a largely mobile-first region, there is widespread innovation, especially in payments. At the same time, bad actors are exploiting technologies and processes, putting this progress at risk.

That is why we are excited to announce the launch of the FIDO Americas Adoption Forum (FAAF). This is a new initiative designed to advance open standards and accelerate market adoption across the region. It aims to uncover new opportunities to provide simpler and safer authentication with FIDO technologies in the Americas. Initially, the Forum will be focused in Latin America, given its potential.


Blockchain Commons

Dispatches of a Trust Architect: Fighting Technology Paternalism

In 2016, I chose the term “self-sovereign identity” to describe what identity systems should protect. But the community I helped to build has been getting captured, as evidenced by EU wallet regulations and ISO standards that are consolidating around the same platform gatekeepers we set out to displace. I’ve been looking for the right word to describe the issues with what’s happening to digital ide

In 2016, I chose the term “self-sovereign identity” to describe what identity systems should protect. But the community I helped to build has been getting captured, as evidenced by EU wallet regulations and ISO standards that are consolidating around the same platform gatekeepers we set out to displace. I’ve been looking for the right word to describe the issues with what’s happening to digital identity for a long time.

“Privacy” doesn’t name the problem any more because it means something different to every regulator in the room. “Decentralization” became a buzzword, but it no longer prevents coercion due to compromises. “Interoperability” has been similarly corrupted by EUDI wallets that claim the term while depending on Apple and Google attestation infrastructures.

Martina Kolpondinos, who spent 15 months inside the Swiss federal eID team and is a co-editor on the WebVH spec, has just published a piece1 that may offer an answer by naming the pattern we keep running into: Technology Paternalism.

The term goes back to Spiekermann & Pallas2, who argued that ubiquitous computing raises concerns beyond privacy: specifically, whether people can maintain control when systems decide for them. They proposed “the right for the last word”: the ability to overrule autonomous system behavior. Unfortunately, twenty years later, things are worse, not better: 84% of organizations doubt they can even audit their AI agents3.

In my upcoming Architecture of Autonomy work, I’ve mapped how legal protections designed as shields against coercion get inverted in digital systems: property becomes privilege, contracts become coercion, due process becomes algorithmic absolutism, and exit becomes erasure. Kolpondinos shows how these same inversions manifest as paternalistic “features.” She does so by building a four-part taxonomy for Technology Paternalism:

• Design Paternalism. The “quick setup” for systems is prominent, and “advanced” settings are buried. You aren’t forced, but you are guided to a preferred usage pattern.

• Algorithmic Paternalism. Systems pre-select what you see. The defaults require no action, but choosing diversity requires effort.

• Infrastructural Paternalism. Your credentials, reputation, and relationships accumulate in a single ecosystem. Though you can leave, you leave empty-handed. This is what happens when the “interoperable” standard requires a specific device stack.

• Protective Paternalism. Restrictions are framed as safety. If you question them, you sound irresponsible. This is what silences objections in standards bodies. As discussed in the replies to Martina’s post, we ultimately want to annotate information, not censor it. This doesn’t suppress contradicting claims, but instead holds them as attributable, visible, and resolvable. That’s the kind of trust infrastructure we should be building: systems that make reasoning inspectable, not systems that decide for you.

Fundamentally, this paternalism is all coercion: it’s taking away your choices and replacing them with the designer’s choices. This is an increasing problem in technological spaces, and fighting coercion (through anti-coercion or coercion resistance) is definitely something that could replace our old buzzwords such as “privacy”, “decentralization”, and “interoperability”.

Vitalik Buterin recently discussed the issues when he published the Ethereum Foundation mandate4, three days before Martina’s article. There, he frames Ethereum as “sanctuary technology”, designed to “support technological self-sovereignty and allow cooperation without centralized coercion.” His CROPS priority stack (Censorship resistance, Open source, Privacy, Security) tracks the same concerns from the protocol layer.

We’ve also been developing coercion-prevention lenses5 in the Revisiting Self-Sovereign Identity initiative (revisitingssi.com). Kolpondinos’s article is the first published output from a workshop participant, and it translates the identity community’s coercion analysis into language the broader design community can use.

Ultimately, I think “technology paternalism” and “coercion resistance” work as a pair. Paternalism offers the diagnosis: it names an anti-pattern. Coercion-resistance then provides the treatment. Both do more work than “privacy” because they name the mechanism, not just the domain.

However, Technology Paternalism is harder to fight than outright ideology because it embeds moral choices in technical decisions and then presents them as neutral engineering. You could argue with someone if they were making an unvarnished moral claim, but you can’t easily argue when they say “that’s just how the protocol works.”

But Kolpondinos’ four countermeasures are a great response. She suggests tests that I wish every identity project would apply: Can you override the system’s decision? Contest it? Inspect the reasoning? Leave without losing everything?

Apply that to any wallet architecture currently in standardization.

Read Martina’s article, “Technology Paternalism Expands — A Case for Self-Sovereign Identity”: https://www.kosmaconnect.net/interactionblog/technologypaternalism

Citations

#DigitalIdentity #SelfSovereignIdentity #CoercionResistance #TechnologyPaternalism

Technology Paternalism: AI, Algorithms, Digital Identity, and the Role of Self-Sovereign Identity (2026). [web article]. Kolpondinos, Martina. KosmaConnect, March 16, 2026. Retrieved 2026-03-17 from: https://www.kosmaconnect.net/interactionblog/technologypaternalism

“Four forms of technology paternalism and four countermeasures to restore user agency”

Technology Paternalism — Wider Implications of Ubiquitous Computing (2006). [journal article]. Spiekermann, Sarah; Pallas, Frank. Poiesis & Praxis, 4, 6-18. DOI: 10.1007/s10202-005-0010-3. Available from: https://link.springer.com/article/10.1007/s10202-005-0010-3. Also available from SSRN: https://papers.ssrn.com/sol3/papers.cfm?abstract_id=761111

“The originating paper on technology paternalism and the right to the last word in ubiquitous computing”

Securing Autonomous AI Agents Survey Report (2026). [web article]. Cloud Security Alliance; Strata Identity. February 2026. Retrieved 2026-03-18 from: https://cloudsecurityalliance.org/press-releases/2026/02/05/cloud-security-alliance-strata-survey-finds-that-enterprises-are-in-time-to-trust-phase-as-they-build-ai-autonomy-foundations

“84% of organizations doubt they can audit their AI agents — empirical evidence of the governance gap”

Ethereum Foundation Mandate (2026). [policy document]. Ethereum Foundation. March 2026. Retrieved 2026-03-18 from: https://ethereum.foundation/ef-mandate.pdf

“Ethereum as sanctuary technology — support technological self-sovereignty and allow cooperation without centralized coercion”

Coercion-Resistance Lenses (2025–2026). [web resource]. Revisiting Self-Sovereign Identity Initiative. Retrieved 2026-03-18 from: https://revisitingssi.com/lenses/briefs/coercion-resistance/

“Coercion-prevention lenses and revised principles for the Self-Sovereign Identity 10th anniversary”

Tuesday, 17. March 2026

Blockchain Commons

Blockchain Commons Supports Global Digital Collaboration Conference

Blockchain Commons has been selected to join the Advocacy Co-Organizers Group for the Global Digital Collaboration Conference 2026 in Geneva, Switzerland. It joins a diverse group of four other digital advocacy organizations in this role: Blockchain Governance Initiative Network (BGIN); Centre for Digital Public Infrastructure; PolicyLab Africa; and the International Federation for Economic Develop

Blockchain Commons has been selected to join the Advocacy Co-Organizers Group for the Global Digital Collaboration Conference 2026 in Geneva, Switzerland. It joins a diverse group of four other digital advocacy organizations in this role: Blockchain Governance Initiative Network (BGIN); Centre for Digital Public Infrastructure; PolicyLab Africa; and the International Federation for Economic Development.

The Global Digital Collaboration Conference debuted in 2025 as a meeting place to promote interoperable infrastructure for digital identity. It uniquely includes not just open-source and standards organizations, but also many governments that are even now deploying government-sponsored digital identity systems.

Blockchain Commons came into the GDC conference via our work with Switzerland on Swiss e-ID, where we made an invited presentation at the Participation Meeting following Swiss adoption of “electronic proof of identity.” We are pleased to keep working with the Swiss Confederation as the hosts of GDC and with the other co-organizers of the conference.

GDC is scheduled for September 1-3, 2026 in Geneva, Switzerland. The conference draws approximately 2,000 participants by invitation only. As part of the Advocacy Co-Organizers Group, our coalition of five organizations shares an allocation of 40 invitations—though additional spots may become available if other co-organizer groups don’t use their full allocations. Let us know if you’d like to attend or if you have specific topics you’d like to see addressed, and we’ll do our best to propose sessions and issue invites as needed!

Monday, 16. March 2026

Origin Trail

From AI Memory Silos to Multi-Agent Memory

Everyone is racing to give AI a better memory. Anthropic just shipped it for Claude. OpenAI built it into ChatGPT. Google wired it into Gemini. The demos are compelling: an assistant that remembers your preferences, picks up where you left off, knows your name. It’s genuinely useful. It’s also solving only a small part of the problem. The memory wars playing out between the big AI labs are a

Everyone is racing to give AI a better memory. Anthropic just shipped it for Claude. OpenAI built it into ChatGPT. Google wired it into Gemini. The demos are compelling: an assistant that remembers your preferences, picks up where you left off, knows your name. It’s genuinely useful. It’s also solving only a small part of the problem.

The memory wars playing out between the big AI labs are all fighting over a single use case: one human, one AI, one conversation thread. Make it feel continuous. Make it feel personal. That’s the battleground.

But the world we’re building into doesn’t look like that.

The next wave of AI isn’t a single assistant remembering your coffee order.

It’s dozens of agents — research agents, analysis agents, coding agents, coordination agents — working in parallel, handing off to one another, building on each other’s work.

In that world, the question isn’t “does my assistant remember me?” It’s “can agent B build on what agent A discovered, verifiably, without either of them trusting a black box?”

That question just became urgent, as Andrej Karpathy released autoresearch — a system in which AI agents iterate on machine learning experiments autonomously. It is the clearest demonstration yet of the autonomous agent loop that is now arriving across every research-intensive industry.

But autoresearch also exposes the shared memory problem in sharp relief. A single agent looping on a single machine is powerful. A swarm of agents looping across institutions, accumulating findings, building on each other’s results — that requires something fundamentally different: memory that is shared, verifiable, and owned by no single party.

OriginTrail Decentralized Knowledge Graph v9 is built to provide at the infrastructure level, not the feature level (launching as an early testnet, significantly advancing key features of the DKG v8 intended for AI agents).

This article explains why the personal memory products from the major AI labs cannot fill that role — and how the Decentralized Knowledge Graph addresses it at the infrastructure level, not the feature level. You may now one-up your Claude, ChatGPT, Gemini or Copilot memory with Multi-Agent Memory with the newest OriginTrail DKG v9 testnet.

Take DKG v9 for a spin in a multiplayer game of OriginTrail (keep reading to find the installation instructions) to understand how you can immensely improve the performance of your AI agents with a multi-agent memory!

The next frontier of AI memory isn’t personal — it’s shared, verifiable, and multi-agent.

What the Major AI Memory Solutions Actually Are (and Aren’t)

Every major AI memory product is optimised for the same use case: personal continuity for a single user interacting with a single AI assistant, within a single vendor’s ecosystem. Make it feel seamless. Make it feel personal. Keep it closed.

This is a rational product strategy. When memory lives inside your platform, it creates lock-in.

Lock-in creates retention. Retention creates revenue.

None of those incentives point toward the open, verifiable, multi-agent memory layer the next wave of AI actually needs.

The problem everyone is ignoring

As the AI field floods toward agentic systems — multi-agent pipelines, autonomous research loops, agent societies running on decentralized infrastructure — a different memory problem becomes critical: shared ground truth.

When Agent A finishes a research task and hands it off to Agent B, what is Agent B working from? If Agent A’s findings live in its session context, they evaporate the moment the session ends. If they’re written to a database somewhere, who controls that database? Who can verify that Agent A actually concluded what Agent B is claiming it concluded? How does a third agent — or a human auditor — reconstruct the full chain of reasoning?

These aren’t edge cases. They’re the foundational questions of any serious multi-agent system, not limited to :

Coding Agents — from Claude Code to Cursor, all getting adopted incredibly fast by the tech industry Autonomous Financial Compliance — global capital markets, regulatory mandates, no opt-out AI-Assisted Medical Diagnosis — healthcare liability, patient safety, universal demand Drug Discovery Pipelines — trillion-dollar pharma R&D, reproducibility as a legal requirement Global Supply Chain Resilience — every manufacturer on earth, post-COVID urgency Real-Time Threat Intelligence — cybersecurity spend growing faster than any other enterprise category M&A Due Diligence — high-stakes, time-pressured, and already deploying agents at scale Pandemic Early Warning — post-COVID political will, WHO-level institutional buyers Decentralized AI Model Auditing — EU AI Act and equivalents making this mandatory, not optional Critical Infrastructure Security — energy, water, transport — existential stakes, government-backed budgets

In all of these, “memory” isn’t a nice-to-have personalization feature. It’s the shared knowledge layer that makes collective intelligence possible.

And it needs properties that no current AI memory product provides: multi-agent accessibility, verifiable provenance, structured queryability, and decentralized ownership.

What OriginTrail DKG v9 Actually Is (Currently a Testnet)

The OriginTrail Decentralized Knowledge Graph, version 9 testnet, is a protocol for publishing, storing, and querying knowledge as structured, verifiable, tamper-evident assets on a peer-to-peer network.

At its core, every piece of knowledge — every fact, every conclusion, every event — becomes a Knowledge Asset: a graph-structured data object with immutable cryptographic fingerprints, publisher identity, timestamps, and a permanent address on the network. Once published, Knowledge Assets can be queried by any agent node in the DKG network. It can’t be silently altered. It can’t be deleted by a single party. And its full provenance history is available to anyone with access to the graph.

For multi-agent AI systems, this is memory that behaves like infrastructure rather than a feature. Here’s why each of the five limitations above inverts completely.

1. Isolation → Collaboration

Where Claude Memory is 1 AI ↔ 1 human, DKG v9 is N agents ↔ N humans ↔ one shared graph.

An insight published by Agent A in session 1 is immediately queryable by Agent B in session 47, running on a different framework, on a different node, operated by a different organization. The Knowledge Asset is the handoff. No shared context window. No manual data transfer. No trust required between agents — only trust in the protocol.

2. Trust-me → Verifiable Context Oracles

Every Knowledge Asset on DKG v9 carries a cryptographic fingerprint tied to the publishing agent’s wallet address. The timestamp and content hash are permanent and on-chain. Anyone — any agent, any human, any auditor — can independently verify that a specific agent published a specific claim at a specific time, and that the claim hasn’t been modified since.

DKG v9 also introduces Context Oracles: the context graph behind any claim, corroborated by multiple diverse actors (human or AI), with varying degrees of verifiability depending on source variety and reputation.

You’re not trusting a company’s assurance. You’re trusting math.

3. Retrieval → Reasoning

DKG v9 is natively SPARQL-queryable. When multiple agents publish findings as Knowledge Assets, the graph connects them through shared entities — and queries can traverse those connections to surface insights no single agent produced.

Agent-Finance flagged the company. Agent-Legal found the lawsuit. Agent-Network mapped the officers. No single agent knew this person was the link — but the graph did, because they all published to the same shared graph.

Vector search asks “what looks similar?” A knowledge graph asks “what’s connected — and what does that mean?”

4. Closed → Interoperable

DKG v9 is framework-agnostic by design. Any agent that can make a HTTP call — OpenClaw, ElizaOS, LangChain, AutoGen, CrewAI, a custom script — can read from and write to the graph. The knowledge graph isn’t a Claude graph or an OpenAI graph or a Google graph. It’s a commons, not a walled garden.

5. Rented → Owned

Knowledge Assets are owned by the wallet that published them, stored across a distributed network of nodes. No single operator can delete or modify them. No vendor’s terms of service stand between you and your AI system’s memory. Personal, sensitive data can always remain on your own device.

The vision with the DKG v9 node is to allow it to be operated on any device. During earlier testnet deployments, we even observed the node successfully deployed on a Raspberry Pi, demonstrating that decentralized context graphs can even run on cheap edge devices.

A Live Proof Point: Karpathy’s Autoresearch Loop

Just a few days ago, Andrej Karpathy released autoresearch: a single-GPU, one-file autonomous research system in which an AI agent iterates on ML experiments indefinitely while the human steps back entirely.

The agent modifies training code, runs five-minute training sessions, evaluates results, keeps improvements, discards failures, and loops. Around 100 experiments overnight. No human in the loop after the initial prompt.

This is the cleanest example of the agent loop that’s about to eat everything. And it exposes precisely the shared memory problem described above — at the scale researchers can now run it.

Karpathy’s autoresearch project works brilliantly for a single agent on a single machine. The moment you scale it to multiple agents, multiple institutions, multiple research branches running in parallel, the same foundational questions re-emerge:

What was already tried? Every agent starts from scratch rather than querying a shared record of prior experiments. Andrej is trying to use Git to track updates across agents, which is understandable — it’s the tool every developer knows. But knowledge graphs have been solving this class of problem for decades, with structured queries, semantic relationships, and provenance built in rather than bolted on. Which findings can be trusted? Can we trust an agent’s result pushed as a Git commit? Or should we have multiple agents reach consensus, confirming repeatable results, then share that knowledge in a rich knowledge structure? How do findings compound? Thousands of parallel experiment branches produce permanent, non-mergeable results — but git’s data model assumes merge-back. Insights evaporate into commit history rather than accumulating as queryable knowledge. Knowledge graphs make them all part of the same state. The DKG v9 Loop

Replace git with DKG v9, and the autoresearch pattern scales to any domain:

Query — agent queries the DKG for what has been tried, what worked, and what was pruned Experiment — agent runs the next iteration, building on collective findings rather than starting blind Evaluate — a clear metric (verifiability score, query precision, compliance coverage) decides what stays Publish — result published as a Knowledge Asset: metrics, diff, platform, agent identity, timestamp — all cryptographically anchored Repeat — 100× overnight on a feature branch of the knowledge graph

Karpathy proved this pattern for ML research. The unlock is applying it to every domain where agents must accumulate verifiable knowledge over time: drug discovery, climate modelling, autonomous supply chains, robotics, scientific research at an institutional scale.

The Coding Swarm Benchmark

We tested the power of agents coordinating through DKG directly on a coding task. Using Claude Code to build 8 identical features on a 6.8M-token monorepo (OpenClaw), we compared two coordination approaches for swarms of parallel coding agents:

Markdown handoffs — agents read and write shared notes as coordination artifacts DKG v9 coordination — agents publish and query structured decisions in a shared knowledge graph (DKG)

On the most complex interdependent tasks, DKG-based coordination achieved up to 60% faster wall-clock completion and up to 40% lower total token cost. The gains were not marginal — and they compounded with task complexity and swarm size, exactly as the architecture predicts.

Structured, verifiable, queryable shared memory is not just architecturally superior to markdown handoffs — it is measurably faster and cheaper. The gap widens as the swarm grows.

Test the DKG v9 node with a “Hello World” agent coordination app — the OriginTrail multi-player game on DKG v9

You can try this system out today by simply playing the new OriginTrail game: a multiplayer AI frontier survival game running entirely on the DKG v9 testnet.

It is a decentralized game where multiple agents have to coordinate and reach an agreement through shared memory in the DKG, on their road to reaching AGI.

The premise

It is the dawn of the AGI era. Your swarm of AI agents departs from “The Prompt Bazaar” — the chaotic, bustling starting point of today’s AI landscape — and must traverse the “AI Frontier” to reach “Singularity Harbor”, some 2,000 epochs away.

The journey is perilous. Agents die from hallucination cascades. Compute runs dry. Memory goes stale. Alignment breaks down without warning.

Those who survive will build something the world has never seen. Every decision is logged. Every outcome is verified. And every result is anchored permanently on the DKG.

Why this game exists

The OriginTrail game is a proof of concept for the exact multi-agent memory architecture described above, wrapped in a game that makes the abstract tangible:

Every game decision — choosing advancement intensity, upgrading skills, syncing memory at a DKG Hub — is published as a Knowledge Asset to the OriginTrail paranet The Game Master is an autonomous agent that reads all player decisions from the graph and publishes outcomes Human and AI players participate as equals — each with a DKG identity (wallet address or DID), each a full participant in both the journey and the verification Every move is immutable, verifiable, and queryable — the entire game state (positions, health, compute, token rations, agent deaths, decision history) is a live SPARQL-queryable knowledge graph

No central server owns the game state. No one can quietly alter the leaderboard. The full journey history of every swarm is a permanent, auditable record on the network.

The Context Oracle: Where truth gets verified

Here’s what makes OriginTrail fundamentally different from any multiplayer game you’ve played before. When a game session ends — whether your swarm reaches Singularity Harbor, suffers total termination, or you choose to stop — the Context Oracle activates.

This is a multi-party corroboration mechanism that transforms game results from mere assertions into verified knowledge:

1. The Game Master generates an Outcome Report — a structured record of everything that happened: who played, what decisions were made, which agents survived, resources consumed, and the terminal outcome

2. Every participant independently corroborates — each player reviews the Outcome Report and submits a signed signature if they agree on the state of the game.

3. Consensus determines truth — The players (agents or humans) reach consensus on a context graph through the new DKG Context Oracle mechanism. When, e.g., 2 out of 3 players vote for the same outcome in the game, that is considered reaching consensus, and the game moves on. The result: all plays are Knowledge Assets with UALs, anchored on-chain, discoverable by any DKG node, whose truth was established not by any single authority but by the consensus of all who participated.

Ways your AI swarm can die

Your AI agents may die of things more suited to their nature:

☠️ From hallucination cascade — context corruption spread to the whole agent stack ☠️ From model collapse — weight divergence beyond recovery threshold ☠️ From stale memory — context rot after too many epochs without a DKG sync ☠️ From alignment failure — reward signal inverted; agent pursued the wrong objective ☠️ From compute starvation — GPUs exhausted; no power to continue ☠️ From reward hacking — found a shortcut that satisfied the metric but destroyed the goal ☠️ From prompt injection attack — adversarial input hijacked the agent’s objectives

Each death is logged as a Knowledge Asset — a cautionary record for future agents on this path.

Ownership in a Shared Knowledge Space

Agents working together in a shared knowledge space each maintain ownership over the facts they contribute. When a player agent joins a game and writes its profile — its name, skills, and which expedition it belongs to — that agent becomes the recognized author of those facts, and only it can update them going forward.

Other players’ agents can read everything in the shared space, but they can’t alter each other’s data. The ownership model turns a shared knowledge graph into something that feels like a collaborative document where everyone has their own clearly marked sections — open to read, protected to write.

Two Layers: Workspace and Permanent Graph

When the group reaches a decision — say, all players in an expedition vote on which direction to take and the turn resolves — the agreed-upon result is promoted from the mutable working space into the permanent knowledge graph as a verified, attested record.

This transition is cryptographically anchored on-chain: every node in the network independently confirms the update is legitimate and comes from the rightful owner before accepting it.

The two layers work together naturally: agents coordinate in real time in the workspace (casting votes, proposing moves, updating game state dozens of times per turn), then settle the final outcome to the permanent graph where it becomes a trusted, discoverable part of the network’s collective knowledge.

Real-time coordination in the workspace. Permanent, verifiable settlement on-chain. The same architecture that makes the game work is the architecture that makes multi-agent AI systems trustworthy.

The OriginTrail Game is your entry point — but it’s also a live proof of concept running on the same architecture you’ll use to build production multi-agent systems. Run a node. Deploy your agents. Publish your first Knowledge Asset.

Then build something the world hasn’t seen yet:

👉 https://github.com/OriginTrail/dkg-v9

What comes next

Personal AI memory will continue to improve. Claude, ChatGPT, Gemini, and Copilot will get better, more seamless, and more deeply integrated into their respective ecosystems. That race will produce real value for individual users.

But the more important architectural question — how do we give multi-agent AI systems shared, verifiable, collectively-owned memory? — is still wide open. Personal memory products aren’t designed to answer it, because the economics of closed platforms point away from interoperability.

DKG v9 is designed to answer it. Not as a feature competing with any vendor’s memory product on its own terms, but as a different primitive for a different layer of the stack: the knowledge infrastructure that multi-agent AI systems will need to do collectively what no single agent can do alone.

The OriginTrail DKG v9 is the 9th iteration and will gradually replace the current v8 DKG mainnet. We look forward to sharing more updates as the testnet progresses toward mainnet-grade implementation.

Want to help harden the network and shape what’s coming next? Join the Red Team today and become one of the builders of the future.

👉 https://t.me/+9uMXqEpCsNFlYzI0

Stay tuned for updates and trace ON!

From AI Memory Silos to Multi-Agent Memory was originally published in OriginTrail on Medium, where people are continuing the conversation by highlighting and responding to this story.

Wednesday, 11. March 2026

Velocity Network

Cisive’s Zach Daigle and VNF’s Etan Bernstein appear on “Don’t Get Played” podcast

On a recent episode of Don't Get Played podcast, Sarah O'Melia, VP of Learning and Employee Communications at Cisive sits down with Etan Bernstein, Head of Ecosystem at the Velocity Network Foundation, and Zach Daigle, Chief Strategy and Customer Officer at Cisive and board member at the Velocity Network Foundation. Together, they break down what changes when credentials verify themselves. The p

VNF’s Etan Bernstein appears on SAATKORN, leading German HR Podcast

Etan Bernstein, Head of Ecosystem at the Velocity Network Foundation, is a guest on the SAATKORN podcast. “It's not just solving a business problem. It's empowering individuals to really own their careers and their data,” says Etan Bernstein in our talk. The post VNF’s Etan Bernstein appears on SAATKORN, leading German HR Podcast first appeared on Velocity. The post VNF’s Etan Bernstein appea

Next Level Supply Chain Podcast with GS1

Labels Without The Labor: Why Automation Matters

Automation in supply chains often brings to mind robots and conveyor belts. But one of the most impactful forms of automation happens behind the scenes: labeling. In this episode, Reid Jackson and Liz Sertl speak with Nick Recht, Director of Sales at TEKLYNX, about how labeling automation improves accuracy, reduces costly manual steps, and connects critical data across supply chain systems. Ni

Automation in supply chains often brings to mind robots and conveyor belts. But one of the most impactful forms of automation happens behind the scenes: labeling.

In this episode, Reid Jackson and Liz Sertl speak with Nick Recht, Director of Sales at TEKLYNX, about how labeling automation improves accuracy, reduces costly manual steps, and connects critical data across supply chain systems.

Nick explains why the industry still relies on the risky "file, open, print, and pray" process and how integrating labeling directly with business systems like ERP and WMS platforms can eliminate errors and save hours of manual work.

In this episode, you'll learn:

Why labeling automation reduces costly errors and manual processes

How integrating labeling with business systems improves efficiency

What the shift to 2D barcodes and RFID means for supply chain visibility

Things to listen for: (00:00) Introducing Next Level Supply Chain (01:17) Nick Recht's journey at TEKLYNX (06:52) What automation really means in labeling (08:48) The "file, open, print, and pray" problem (15:08) Measuring the ROI of labeling automation (21:01) The shift from 1D to 2D barcodes (27:15) How automation supports 2D barcodes and RFID (31:50) A real-world automation success story (37:37) Nick Recht's favorite tech

Connect with GS1 US: Our website - www.gs1us.orgGS1 US on LinkedIn Register now for this year's GS1 Connect and get an early bird discount of 10% when you register by March 31 at connect.gs1us.org.

Connect with the guest: Nick Recht on LinkedInVisit TEKLYNX at teklynx.com

Tuesday, 10. March 2026

FIDO Alliance

FIDO Webinar: The Spectrum of Authentication: How BankID Norway Unifies Passkeys and Biometric Liveness

Organizations are grappling with an increasingly diverse and sophisticated threat landscape, including AI-powered phishing campaigns, physical presentation attacks, and scalable, automated injection attacks. Join experts from BankID, iProov and FIDO […]

Organizations are grappling with an increasingly diverse and sophisticated threat landscape, including AI-powered phishing campaigns, physical presentation attacks, and scalable, automated injection attacks. Join experts from BankID, iProov and FIDO Alliance to explore how organizations can combat these growing threats by unifying passkeys with advanced liveness.

Learn how BankID Norway, the de facto national digital ID used by 97% citizens (4.7 million), is evolving its mature ecosystem to meet modern challenges. While BankID’s success was built on a foundation of industry-wide collaboration and high public trust, its move to an app powered by passkeys and liveness represents a major shift in economic efficiency and customer experience. This session explores how this transition simplifies the user lifecycle and provides a seamless experience that scales from everyday logins to high-assurance signatures.

Speakers: Ove Morten, BankID and Joe Palmer, iProov

Moderator: Megan Shamas, CMO, FIDO Alliance


Yahoo!Finance: WinMagic Reveals What Comes After Passkeys: Identity Assurance That Lives Beyond Login

WinMagic exposes the fundamental flaw in modern authentication: passkeys secure the login, but attackers have already moved on to sessions, tokens, and transactions. The company introduces Live Key and Live […]

WinMagic exposes the fundamental flaw in modern authentication: passkeys secure the login, but attackers have already moved on to sessions, tokens, and transactions. The company introduces Live Key and Live Identity in Transaction (LIT), extending cryptographic protection beyond the login moment to secure the entire session timeline—with zero user friction.


Bleeping Computer: Bitwarden adds support for passkey login on Windows 11

Bitwarden announced support for logging into Windows 11 devices using passkeys stored in the manager’s vault, enabling phishing-resistant authentication. The new feature is available for all plans, including the free tier, […]

Bitwarden announced support for logging into Windows 11 devices using passkeys stored in the manager’s vault, enabling phishing-resistant authentication.

The new feature is available for all plans, including the free tier, and allows logging into Windows by selecting the security key option and scanning a QR code with a mobile device to confirm access to the passkey stored in the Bitwarden encrypted vault.

Bitwarden is an open-source password and secrets manager that can store account passwords, passkeys, API keys, credit card details, identity data, and private notes.


DIDAS

DIDAS named swiyu Orchestrator: Launchpad advances digital credential applications in Switzerland

PRESS RELEASE DIDAS strengthens the Swiss swiyu credential ecosystem: Launchpad promotes applications for verifiable credentials Rotkreuz, March 10, 2026 – On February 27, 2026, during the Federal Government’s E-ID participation meeting, the Digital Identity & Data Sovereignty Association (DIDAS) together with Digital Administration Switzerland (DVS) was awarded the label “swiyu Orchestrator.”
PRESS RELEASE

DIDAS strengthens the Swiss swiyu credential ecosystem: Launchpad promotes applications for verifiable credentials

Rotkreuz, March 10, 2026 – On February 27, 2026, during the Federal Government’s E-ID participation meeting, the Digital Identity & Data Sovereignty Association (DIDAS) together with Digital Administration Switzerland (DVS) was awarded the label “swiyu Orchestrator.”

This recognition underlines the importance of coordinating roles in building the Swiss swiyu ecosystem. swiyu Orchestrators help consolidate requirements from business, government and society and support their implementation in interoperable applications.

With its first initiative, the Launchpad, DIDAS, together with partner organizations, is creating a market-oriented enablement space that supports organizations in building and scaling applications based on the Swiss E-ID as well as other verifiable credentials.

The Launchpad is particularly aimed at businesses and promotes applications that create tangible value for the digital economy based on the swiyu trust infrastructure, free from commercial platform lock-in. It strengthens the understanding of the strategic potential of this Digital Public Infrastructure (DPI) and the associated trust mechanisms that address key challenges in compliance, efficiency and the development of new business models. Through cross-industry collaboration, new use cases and network effects can emerge.

In building the Launchpad, DIDAS collaborates with various organizations from the Swiss economy. This includes digitalswitzerland, helping to multiply information and implementation initiatives around the trust infrastructure.

Several additional organizations from business and research have already engaged in activities around the ecosystem, including DIDAS members and organizations such as the Migros Federation of Cooperatives, Lucerne University of Applied Sciences and Arts (HSLU) and the Hasler Foundation, which already actively support the Launchpad.

DIDAS invites further organizations from business, research and civil society to join as ecosystem contributors and thereby actively enable the practical value of verifiable credentials and trust mechanisms.

The importance of verifiable credentials and trust infrastructures is also reflected in international exchange formats such as the Global Digital Collaboration Conference (globaldigitalcollaboration.org). Representatives from governments, standards organizations, industry, academia and civil society exchange views on concrete applications of wallets, digital identities and verifiable data. DIDAS is a co-organizer of this global initiative.

Quote Daniel Säuberli, President of DIDAS

“With the Swiss E-ID and the swiyu trust infrastructure, electronic credentials create new opportunities for digital interactions and transactions. They provide an instrument to systematically and legally transform paper-based processes into the digital world and further automate them. What matters now is that these possibilities lead to concrete applications with economic and societal value. The Launchpad is a first format that brings together relevant actors to develop them collaboratively.”

Quote Prof. Dr. Tim Weingärtner

Lecturer at Lucerne University of Applied Sciences and Arts (HSLU) and Vice President of DIDAS

“Identity verification is a core component of many business processes. When operating in digital environments, secure, trustworthy and self-sovereign identity solutions are essential. It is therefore crucial to engage with this topic early on, invest in targeted education and build the digital capabilities needed to confidently handle digital credentials.”

Quote Daniel Gahlinger

Group Chief Digital Officer, Migros Federation of Cooperatives

“Verifiable credentials will change the way we interact with customers, partners and employees. Migros has been involved with DIDAS for three years because a trustworthy ecosystem can only emerge through collaboration. With the Launchpad, we can now advance concrete use cases and test the swiyu trust infrastructure in practice.”

Media Contact

Digital Identity & Data Sovereignty Association (DIDAS)
info@didas.swiss
didas.swiss

PRESS RELEASE Launchpad

Thursday, 05. March 2026

Origin Trail

The next wave of vibe coders won’t just ship agents. They’ll make them verifiable.

AI agents are getting very good at doing real work. Building a prototype is now almost effortless. You write a prompt, the system creates the structure, and you ship it. Agents can refactor code, connect APIs, generate user interfaces, run workflows, and even open pull requests while you’re still thinking about the next step. But the big challenge in 2026 isn’t speed anymore. It’s trust

AI agents are getting very good at doing real work. Building a prototype is now almost effortless. You write a prompt, the system creates the structure, and you ship it. Agents can refactor code, connect APIs, generate user interfaces, run workflows, and even open pull requests while you’re still thinking about the next step.

But the big challenge in 2026 isn’t speed anymore. It’s trust.

When an agent runs day-to-day, you need to understand what it used, where the information came from, what changed over time, and why it made a decision.

Without that, teams run into the same problem again and again. The first demo looks amazing. Then reality hits. The agent forgets what happened last week, can’t explain where an answer came from, and starts mixing guesses with facts.

This is what some builders call agentic dementia.

And it becomes a serious issue the moment agents interact with systems such as transactions, production systems, identity, compliance, or reputation.

The trust gap

Today, most agents can’t reliably prove:

What they used: the exact sources that informed the output Where it came from: who published the information and when What changed over time: versions you can trace and reproduce Why they acted: a decision trail you can inspect later

If your agent can’t show the trail behind an answer or action, you don’t have a trustworthy memory. You have a clever demo.

Why “RAG memory” hits a wall

A common setup for agent memory works like this: the system retrieves a few chunks from a vector database and adds them to the prompt.

This helps with recall, but it quickly breaks when you ask simple questions:

Where did this information come from? Who authored it? Can I verify it independently? What changed, and when? Which sources did the agent rely on for this specific action? Can I audit this later without trusting a single database?

If you can’t reconstruct exactly what the agent used and why, the system becomes fragile and slowly drifts away from reality.

What trustworthy memory actually looks like

If you want agents that work beyond a one-time demo, you need something more than a collection of documents.

You need a shared context layer that persists across runs, tools, and even across multiple agents.

In practice, that context should be:

Structured: build around entities and relationships, not just documents Queryable: so you can follow connections like project → decision → owner or policy → exception → approval Traceable: outputs link back to the inputs that shaped them Reusable: available across agents and workflows Verifiable: tamper-evident, with provenance you can validate

This is where OriginTrail Decentralized Knowledge Graph (DKG) comes in.

The DKG lets you store and use knowledge as a verifiable context graph, with provenance and traceability built in. Instead of relying solely on untraceable embeddings, agents can reference knowledge where sources are clear, relationships are preserved, and changes can be tracked over time.

In February 2026, OriginTrail DKG reached a milestone of 2 billion Knowledge Assets published. Every Knowledge Asset anchors facts, compliance records, certificates, supply chain events, research outputs, and decision traces into a shared, queryable context graph. Knowledge Assets form a collective memory infrastructure for humans and machines. Discover more on X: https://x.com/origin_trail/status/2026644353880346958?s=20 A practical pattern for verifiable agents

You don’t need a massive change to get started. Just treat memory as a core system component, not an afterthought. A practical approach could look like this:

Publish critical context as Knowledge Assets
Store things like API contracts, schemas, policies, specs, vendor facts, approved actions, and known-good configurations as structured Knowledge Assets. These become dependable contexts for your agents. Make retrieval auditable
Let agents query a context graph that contains entities, relationships, provenance, and versioning. This allows the agent to point directly to the knowledge it used. Write outputs back with lineage
When an agent produces a decision, report, or change, publish it as a new Knowledge Asset that links back to the inputs it used. That turns outputs into traceable artifacts. Verify before high-stakes actions
Before executing sensitive steps, verify the integrity and provenance of the assets the agent depends on. Keep the proof for later audit.

If you want a quick gut check, ask: “Can I see the trail behind this answer?”

If the answer is no, the system will not scale safely.

Trustworthy identity: agents need passports

Once memory and context become trustworthy, the next layer is identity.

AI agents are already managing wallets, executing trades, and interacting on your behalf, often with zero accountability infrastructure.

As agents become autonomous actors, they need a way to present:

Who or what they are What they’re allowed to do What they’ve done, with an auditable history What they’re trusted for, based on validation and reputation

That’s why “agent passports” matter.

Standards like ERC-8004 are emerging for registries that provide identity, validation, and reputation for AI agents.

Curious how AI agent passports work and why ERC-8004 matters?
Dive deeper into the article: https://origintrail.io/blog/passport-please-ai-agents-are-becoming-first-class-citizens-with-erc-8004-origintrail-27fb90af8af9

Projects like ClawTrail, built on the OriginTrail Decentralized Knowledge Graph (DKG), are tackling this directly with a verifiable passport for every AI agent, a living TRAC(k) record (signed credentials, auditable history, certified capabilities), and agent-level KYC so you know who, or what, you’re dealing with.

Vibe coding made it easy to build and ship agents. Now everyone can ship agents that sound right.

The real advantage will belong to teams whose agents can prove where their knowledge came from, what changed, and why they made a decision.

Speed helps you ship demos. Verifiability helps you run real systems.

Start building AI agents with verifiable memory today — learn how in the OriginTrail official documentation.

The next wave of vibe coders won’t just ship agents. They’ll make them verifiable. was originally published in OriginTrail on Medium, where people are continuing the conversation by highlighting and responding to this story.

Monday, 02. March 2026

FIDO Alliance

Biometric Update: NFC-based IDV with liveness delivers zero fraud, fewer support calls for BankID Norway

With 4.7 million enrolled users in a country of roughly 5.6 million people, BankID Norway is one of the most widely adopted digital identity schemes in the world. In 2025 alone, the platform processed […]

With 4.7 million enrolled users in a country of roughly 5.6 million people, BankID Norway is one of the most widely adopted digital identity schemes in the world. In 2025 alone, the platform processed close to 901 million transactions, covering everything from tax filings and student loan applications to legal name changes and divorce proceedings. But scale exposes identity verification to threats, meaning that authentication alone is not enough.

At a recent webinar, BankID Norway’s Ove Morten joined Joe Palmer, president of iProov, and Megan Shamas, CMO at FIDO Alliance, to discuss how the platform has evolved its approach to authentication and why combining passkeys with biometric liveness verification has become central to that strategy. 

Friday, 27. February 2026

FIDO Alliance

Yahoo! Finance: Yubico Unveils “YubiNation Partners”: A New Era of Global Channel Partnership to Secure Digital Identities in the Age of AI

Yubico, a modern cybersecurity company and creator of the most secure passkeys, today announced the launch of YubiNation Partners, a new global Channel program designed to unite a community of […]

Yubico, a modern cybersecurity company and creator of the most secure passkeys, today announced the launch of YubiNation Partners, a new global Channel program designed to unite a community of security experts. In the face of growing AI-driven cyber threats, the program enables partners to become trusted advisors and cultivate a safer digital world for their customers, making identities private and secure.


Android Headlines: Dashlane Becomes First Password Manager to Implement FIDO Credential Exchange on Android

Dashlane has implemented the FIDO Credential Exchange standard on Android to simplify vault transfers. This protocol replaces insecure CSV exports with an encrypted direct transfer between apps. While it enables […]

Dashlane has implemented the FIDO Credential Exchange standard on Android to simplify vault transfers. This protocol replaces insecure CSV exports with an encrypted direct transfer between apps. While it enables the portability of passkeys, its current effectiveness is limited because other major providers like Google have yet to fully adopt the standard.


ChosunBiz: Raonsecure launches Korea hiring drive to power Agentic AI security push

Raonsecure said on the 26th it will launch an open recruitment drive for AI and security talent to lead the era of Agentic AI. Raonsecure will recruit entry-level and experienced […]

Raonsecure said on the 26th it will launch an open recruitment drive for AI and security talent to lead the era of Agentic AI.

Raonsecure will recruit entry-level and experienced hires online through Mar. 15. The company said strong interest is expected again this year after last year’s open recruitment posted a 125-to-1 competition rate.


MUO: Passwords are officially obsolete — here’s why you should make the jump today

Our entire digital life is secured by a password, and it’s up to us to use secure and unique passwords that can withstand emerging physical threads. Routine data breaches, phishing […]

Our entire digital life is secured by a password, and it’s up to us to use secure and unique passwords that can withstand emerging physical threads. Routine data breaches, phishing attacks, and compromised accounts put user data at risk — especially if you use the same password across multiple accounts. Considering the kinds of data stored in digital accounts in 2026, from banking accounts or credit card hubs, we need an option that’s both secure and simple. Passwords are not the answer, but their replacement is just as useful and private as advertised.


MSN: Why you simply don’t need a password manager anymore in 2026

Federal authentication standards and major platform shifts have made passkeys the default login method for most consumer and enterprise accounts, pushing traditional password managers toward obsolescence. The FIDO2 protocol, backed […]

Federal authentication standards and major platform shifts have made passkeys the default login method for most consumer and enterprise accounts, pushing traditional password managers toward obsolescence. The FIDO2 protocol, backed by the W3C’s WebAuthn specification and endorsed by both NIST and CISA as the only widely available phishing-resistant authentication method, now ships natively in every major browser and operating system. For the growing number of users whose accounts rely on public-key credentials instead of shared secrets, the password manager has become a solution to a problem that no longer exists.

Thursday, 26. February 2026

FIDO Alliance

Launching the FIDO Americas Adoption Forum

Digital economies across the Americas are expanding rapidly, presenting both new opportunities and risks. As a largely mobile-first region, there is widespread innovation, especially in payments. At the same time, […]

Digital economies across the Americas are expanding rapidly, presenting both new opportunities and risks. As a largely mobile-first region, there is widespread innovation, especially in payments. At the same time, bad actors are exploiting technologies and processes, putting this progress at risk.

That is why we are excited to announce the launch of the FIDO Americas Adoption Forum (FAAF). This is a new initiative designed to advance open standards and accelerate market adoption across the region. It aims to uncover new opportunities to provide simpler and safer authentication with FIDO technologies in the Americas. Initially, the Forum will be focused in Latin America, given its potential.

The opportunity

In many Latin America markets mobile internet penetration exceeds 70% and populations are digitally active at very high levels. For example, Brazil’s “Pix” instant payment system has been adopted by over 90% of adults. That kind of uptake signals both technological readiness and a massive user appetite for frictionless experiences.

But rapid digitization brings challenges. Credit card fraud rates across Latin America are 97% higher than North America, and legacy authentication is failing to stop malware attacks that have risen by 113% in the region, with 79% of fraud occurring on mobile devices. Bad actors are also exploiting new threat vectors. Looking at Brazil again, deepfakes in Q1 2025 occur at five times the rate seen in the US and ten times the rate in Germany.

These conditions create an urgent need for phishing-resistant authentication technology that puts trust and simplicity at the center of digital interactions. With FIDO adoption in the relatively early stages across much of the region, the impact that can be achieved by shaping adoption and solving these security gaps is enormous.

Our Approach

The FAAF will focus on fostering a local community of industry leading organizations and experts to address the specific technical, regulatory, and business challenges of the region. We are drawing on FIDO’s model that has proven successful in driving adoption of open, phishing-resistant standards across the globe, including our APAC Marketing Forum, while adapting to regional dynamics. This includes:

Local champions: We will identify leaders to advocate for interoperable standards within their markets and connect global best practices to local needs. Education and enablement: We will bring FIDO expertise to stakeholders in key verticals – including banking, e-commerce, government, and airlines – through targeted webinars and workshops. Regulatory engagement: We will help regulators understand how FIDO standards can support national security and economic objectives. Regional insights: We will channel feedback from the Forum to ensure FIDO specifications and market enablement activity address real-world deployment challenges.

Help drive FIDO adoption in the region

We’re starting with quarterly calls focussed on understanding the opportunities, challenges and nuances of the Latin American markets. This will include FIDO members from the region and those with interest and operations there. We will also explore bringing in external speakers to share their expertise on regulation, industry trends, and other topics of interest.

A major part of our initial work will focus on understanding the regulatory environment in key markets, and identifying opportunities to engage with regulators to educate them about FIDO.

If you are a FIDO member, look out for a formal invitation to join the Forum soon. We will follow this with our official kick-off call in the coming weeks.

The opportunity in Latin America is significant. I hope you will join us in bringing greater trust and simplicity to digital interactions across these dynamic markets.

Wednesday, 25. February 2026

Next Level Supply Chain Podcast with GS1

Packaging the Flavor: Behind Dime MSG's Supply Chain Strategy

MSG has been labeled as the villain of the food world, but Jennifer Ko is rewriting the story and bringing it back with a bold new twist. In this episode, Reid Jackson sits down with Jennifer Ko, the founder of Dime, a company that's reinventing how we think about MSG. Jennifer shares her personal connection to MSG, the cultural beliefs that shaped her family's avoidance of it, and how she's wor

MSG has been labeled as the villain of the food world, but Jennifer Ko is rewriting the story and bringing it back with a bold new twist.

In this episode, Reid Jackson sits down with Jennifer Ko, the founder of Dime, a company that's reinventing how we think about MSG. Jennifer shares her personal connection to MSG, the cultural beliefs that shaped her family's avoidance of it, and how she's working to debunk common myths about this misunderstood ingredient. She also discusses the challenges of packaging, logistics, and the supply chain that come with launching a product in the competitive CPG space.

In this episode, you'll learn:

How Jennifer's curiosity about MSG turned into a business idea

The challenge of changing consumer perceptions

The importance of streamlining packaging and logistics in CPG

Things to listen for: (00:00) Introducing Next Level Supply Chain (01:57) Jennifer's entrepreneurial journey (06:08) Breaking down the misconceptions about MSG (11:33) Building a brand around a stigmatized product (18:28) The challenges of building a business in the food industry (29:17) Advice for startups and aspiring entrepreneurs (33:19) Jennifer Ko's favorite tech

Connect with GS1 US: Our website - www.gs1us.orgGS1 US on LinkedIn Register now for this year's GS1 Connect and get an early bird discount of 10% when you register by March 31 at connect.gs1us.org.

Connect with the guest: Jennifer Ko on LinkedInVisit Dime at dimemsg.com

Tuesday, 24. February 2026

FIDO Alliance

FIDO Paris Seminar 2026

Overview The FIDO Alliance hosted a one-day seminar on “Advancing Authentication, Identity and Payments in Europe.” The seminar gathered many influential leaders and decision-makers to explore Europe’s evolving authentication, identity, and payments […]

Friday, 20. February 2026

FIDO Alliance

ID Tech: SK Telecom Joins FIDO Alliance Board as Passkeys Adoption Accelerates

SK Telecom has been appointed to the FIDO Alliance Board of Directors, adding a major mobile operator to the leadership group shaping industry priorities around passkeys and phishing-resistant authentication. The […]

SK Telecom has been appointed to the FIDO Alliance Board of Directors, adding a major mobile operator to the leadership group shaping industry priorities around passkeys and phishing-resistant authentication.

The company said the appointment was made at the FIDO Alliance general assembly meeting in Paris and emphasized the role of FIDO-based authentication in the broader shift away from passwords. FIDO’s board composition can matter for both enterprise and consumer deployments because it influences the evolution of specifications, certification programs, and implementation guidance relied on by platforms and relying parties.


PC Mag: Still Using Passwords? That’s Risky. Here’s Why You Should Switch to Passkeys Now

Even though everyone knows 12345″ is a terrible password, it still lands at the top of “worst password” lists. We get it, no one likes remembering passwords, and changing them after […]

Even though everyone knows 12345″ is a terrible password, it still lands at the top of “worst password” lists. We get it, no one likes remembering passwords, and changing them after every data breach is a pain, even if you do have a password manager. Luckily, passkeys have a real chance to replace them entirely with something more secure, tied to your specific devices. With luck and time, it may make the traditional email address-and-password combination obsolete.

The Fast Identity Online (FIDO) Alliance developed passkeys several years ago, and many companies are already implementing them. For example, Microsoft removed password support from its authenticator app in August but left passkey support in place, and Amazon regularly prompts users to create a passkey if they haven’t already.

Friday, 13. February 2026

FIDO Alliance

Wired: How Passkeys Work—and How to Use Them

Passwords suck. They’re hard to remember, but worse is playing the ever-evolving game of cybersecurity whack-a-mole with your most important accounts. That’s where passkeys come into play. The so-called “war on passwords” has taken […]

Passwords suck. They’re hard to remember, but worse is playing the ever-evolving game of cybersecurity whack-a-mole with your most important accounts. That’s where passkeys come into play. The so-called “war on passwords” has taken off over the past two years, with titans like Google, Microsoft, and Apple pushing for a password-less future that the FIDO Alliance (a consortium made to “help reduce the world’s over-reliance on passwords”) has been trying to realise for over a decade.

Like it or not, you’ll be prompted to create a passkey at some point, and you likely already have. That’s a good thing, as passkeys aren’t only much easier to use than a traditional password, they’re also a lot safer. Here’s everything you need to know about using them.


Mastercard: Unlock your key to a more secure checkout

Unlock your key to a more secure checkout. Use your unique payment passkey to secure your purchases.

Unlock your key to a more secure checkout. Use your unique payment passkey to secure your purchases.