Resources
Handed out after the talk, kept here because a slide URL outlives the slide.
Recovering Authenticity
The standards and organisations behind the talk, and behind the essay it became. Provenance is the part of authenticity that can be built; the rest is argument.
Provenance travels with the file, or it does not travel at all.
Data provenance and content authenticity
- C2PA — the Coalition for Content Provenance and Authenticity, and the specification itself.
- Content Authenticity Initiative — the implementation side, and the open-source tooling.
- IPTC Media Provenance — the news industry's programme, where this meets working newsrooms.
Sigillo is my own attempt at the practical end of this: an iOS camera that signs a photograph at the moment of capture, so the credential is embedded before the image is ever seen.
Combating disinformation
- DISARM Foundation — a shared framework for describing influence operations, so defenders can name the same thing the same way.
On behalf of: delegated authority for AI
Ongoing work, and the part most likely to have moved since you read this.
- Identity Management for Agentic AI (OpenID Foundation, October 2025) — a survey of where agent authorisation stands and what it still cannot do. Not my paper; the clearest statement of the problem I know.
- The Unfinished Digital Estate (OpenID Foundation, March 2026) — what becomes of an account after its owner dies. I co-edited this one with Heather Flanagan and Dean H. Saxe.
Where the work happens
- Shared Signals — the working group behind SSF, CAEP and RISC.
- Death and the Digital Estate — the community group behind the paper above.
I co-chair both. This page gets updated as the standards work moves, at OpenID and at the IETF. Last touched 6 March 2026. If something here has gone stale or a link has rotted, tell me.