We are heading into the 40th Internet Identity Workshop, an event that I cofounded with Doc Searls and Phil Windley 20 years ago. I am not sure we ever thought it would last this long but it has. We continue to be the world’s leading innovation forum for decentralized digital identity focused on a range of use-cases that include human-centric approaches along with enterprise identity management, government-oriented ID schemes, and non-human identities.
I feel compelled to explicitly name some key themes that seem to be emerging for discussion and invite anyone who is keen on addressing them/figuring them out to join us.
How do we solve the identity of AI Agents?
There are a huge range of questions that are emerging around this new type of Non-Human Entity/Identity) (NPE or NHI). A meeting took place several weeks ago at Stanford that originally was supposed to be more technical than it was. There is another meeting coming up on April 8th AI Agents x Law right before IIW. In a conversation with Dazza Greenwood at Funding the Commons (March 15-16), we agreed it would be great if those at the meeting who really want to dive in and solve the problem use the second and third day of IIW (April 9 and 10) to do so. Some of the key questions I believe require a deeper dive include:
- What should AI agents be using as identifiers?
- Could it be Decentralized Identifiers?
- How can AI agents prove who they actually are working on behalf of (which person, which organization)?
- Could it be credentials they carry in a wallet and share?
- How can these statements be trusted?
- Are there registries of issuing entities? How are these trusted?
- How can relying parties keep access to their resources relative to the information they share?
- What are the protocols for permissioning?
- What is the role of the existing enterprise federation protocols like the OAuth family of protocols?
Proof of Personhood and First Person Credentials
This topic is surfacing from a variety of places right now and there are lots of different teams with slightly different approaches. The Personhood Credentials paper from last year had multiple authors from the IIW community and others recently won an award from the Future of Privacy Forum. There are quite a few different options on this playing field right now including:
- WorldID wants to scan everyone on earth’s irises and link this to a crypto wallet.
- Billions created by Privado (formerly PolyGonID that merged with Disco.xyz)
- Human.Tech which recently acquired the GitCoin Passport they were also at Funding The Commons (March 15-16)
- FedID put forward by JLINC and shared at the last IIW (They have acknowledged they have a name space conflict with the Federated Identity Working group at W3C)
- Ayra is working on First Person Credentials and discussing how it can be used in a range of important contexts including software authorship.
- Sideways.earth is working on credentials for trust building across bioregional networks.
- I am sure there are more…
IIW will provide an opportunity to explore the overlaps and synergies and hopefully industry alignment.
Trust registries for entities playing different roles within an ecosystem
The good news is we are getting to the point where large ecosystems of entities that must work together to deliver value to their customers are getting serious about figuring out how they can navigate who to trust for what and how to access public keys and related technical data securely across ecosystems.
Registries and registrars are not new concepts, but the acceleration of digitization during COVID time really made the needs for registries more prominent for ecosystems, as well as the needs for registries from digital ecosystems to interact in a meaningful way. For example, if I want to use a credential (digital letter) issued by my bank in country X to open a new bank account when I move to country Y, how the bank in country Y knows whether to trust the letter or whether the letter was indeed issued by my bank in country X. Some trust establishment between the banking networks of the two countries needs to take place to make such decisions easier.
My colleague Lucy has been working with the Regi-Trust project incubated within UNDP (originally created at the Linux Foundation as the Global COVID Certificate Network) and has been under development since 2021 with a focus on providing a decentralized way of federating existing and new trust registries regardless of their governance and technical schemes. TRAIN (TRust mAnagement INfrastructure), the backend infrastructure Regi-TRUST is built on, emerged from Frauhofer’s research and development effort that dates back to 2016.
My consultancy recently worked with IATA to articulate a vision of how an aviation security trust ecosystem that can leverage decentralized identity standards to facilitate secure and interoperable exchange and sharing of certificates and documents across borders for air travel and trade, which include how IATA can potentially provide trust registry and notary services for the ecosystem.
Digital Credentials Consortium has invested in the research and development of a trust registry for higher education using OpenID federation. You can find very valuable discussions and outcomes from this work:
- Issuer Registry Working Group meeting notes
- Issuer Registry Use Cases
- Governance Areas for Issuer Registries
- Issuer Registry prototype repo
There is a lot of trust list work happening in Europe with the EU Digital Wallet developments.
- For Wallet Providers
- For Qualified & Public Sector Attestation Providers (Pub/Q-EAA Providers)
- For Relying Parties (Service Providers)
I’m looking forward to seeing everyone at IIW 40. I know there is some trepidation about traveling to the United States. Doc Searls wrote a blog post about IIW is like the United Nations of identity conference along with highlighting the many Canadians involved from the very beginning.
This is a photo from me facilitating at IIW #1 in October 2005 at the Hillside Club in Berkeley, CA.

