Digital Identity Needs a Legal Foundation - Phil Windley

KERICONF26 Day 2 · 43:10

0:00 Phil Windley | Digital Identity Needs a Legal Foundation | KERI Conference 2026

0:04 Okay, I'm going to start

0:07 since we're over time already. I'm

0:12 glad to be here today.

0:15 Title of my talk, as you can see, is

0:17 “Digital Identity Needs a Legal

0:19 Foundation”. So if you were at SEDI

0:22 summit

0:24 with the first two days of the week,

0:27 this is related to the things I said

0:29 there and just kind of goes into a

0:32 little bit more detail on how the legal

0:34 foundation actually helps us out. So we

0:37 spent a lot of time talking about

0:39 the cryptography and key

0:41 management and all of those things.

0:44 But I think the hardest part of digital

0:48 identity is actually

0:51 not the technical things but legal and

0:56 institutional. I spent a lot of

0:59 time talking about governance and

1:04 sometimes it's can be kind of

1:06 boring but ultimately I think it's what

1:08 gives us the foundation for making all

1:10 of this work. So, think about where

1:13 we're at. We've got decentralized key

1:16 management, authentic chained credentials,

1:19 Serialization formats,

1:23 some implementations, open- source code.

1:27 So, the technical foundations

1:30 are largely there. That doesn't mean

1:32 they're done. Doesn't mean they can't be

1:34 improved, but we've made real progress.

1:37 We also have things that we're still

1:40 working on like tooling and ecosystem

1:42 and developer experience and all of

1:45 those things that make it work.

1:48 But we need to get adoption. And in

1:50 order to get adoption,

1:52 we have to

1:56 get rid of some of the fundamental

1:57 blockers. Now, I'm going to talk about a

1:59 couple of them today. Not necessarily

2:02 all of them. I mean because

2:04 there's no end to blockers when you're

2:06 trying to do something this big. But

2:08 there's a couple of them that I think we

2:10 can help solve. So Sankarshan

2:16 How to say his name Mukhopadhyay I think

2:20 is how you say his last name. I haven't

2:22 heard it said so I'll say it that way.

2:24 Recently wrote a book about what he

2:26 called the a book a paper what he called

2:28 the proof gap. And for him, the proof https://thetrustgraph.substack.com/p/the-proof-gap

2:31 gap was the idea that we still rely

2:35 largely on centralized institutions to

2:39 be able to prove things about ourselves.

2:42 So, our education, employment, whatever

2:45 licenses we have benefits

2:47 we're entitled to, all of those things.

2:50 When proof is needed, we can't generally

2:53 present it directly, especially

2:55 digitally in a way that somebody else

2:58 can easily verify. So even worse, I

3:03 mean, if we lose that proof, we have to

3:05 essentially go back to those

3:07 institutions one at a time and confirm

3:10 something about ourselves, right? So

3:12 that could be a real problem.

3:16 Back 50 years ago when

3:18 everything was based on paper and kept

3:20 in filing cabinets, that might have made

3:22 sense because it was really all you

3:23 could do. But I think everybody in this

3:25 room acknowledges that we can do better

3:28 than that in a digital world and we

3:30 should do better than that, not just

3:32 take that old paper filing cabinet model

3:34 and move it forward.

3:36 So sometimes people think of the proof gap

3:40 as a technical problem and it certainly

3:43 is that. There are technical problems

3:45 with moving this centralized filing

3:48 cabinet model into the digital world and

3:51 trying to decentralize it and create

3:53 something that's better.

3:57 But I think we can ask

4:01 ourselves about the problem of

4:03 governance.

4:08 There are lots of ways that we have

4:09 worked out how to

4:13 transfer trust

4:16 in the physical world, right?

4:21 One of those is very familiar to

4:23 everybody and that is credit cards.

4:30 60 years ago,

4:33 we didn't have this problem because we

4:35 didn't have credit cards really at all,

4:37 right? There were bank cards and

4:41 maybe had a card from your department

4:43 store, right? I remember people had

4:44 Sears cards that you could use at Sears

4:47 and nowhere else, right? So they were

4:49 all centralized, single domain and Visa

4:53 first and then others followed came up

4:56 with this idea that we could have a

5:00 coalition of banks put together ways

5:03 that they can work together. So this

5:05 involved technology, how are we going to

5:08 technically transfer information? It

5:10 involved rules and processes. It

5:13 involved legal agreements. Involved all

5:16 of this. And collectively we call that

5:18 thing a trust framework, right? All of

5:21 those technical and legal and regulatory

5:24 rules that make all of that work. But

5:27 even today if you're a merchant,

5:31 you've got multiple ones of these that

5:33 you have to interact with. Now, it turns

5:35 out somebody saw that problem and there

5:37 are all kinds of companies. There's

5:39 actually between this guy and those

5:41 guys, there's like four layers of

5:43 companies that make this all work. In

5:46 order to make it easy for him and for

5:50 you when you go in, right? He doesn't

5:52 have to have six different terminals and

5:54 all of that because somebody's solved

5:56 that problem. But still, it's a problem.

5:59 Now, imagine what happens when we've got

6:01 not five different banking system or

6:05 credit card systems. We have thousands

6:08 of different credentials. Now we're

6:10 trying to navigate the sea

6:14 of islands where each of these is a

6:16 separate trust framework with their own

6:18 rules, their own governance. Maybe they

6:21 share some technical underpinnings

6:23 at least we could hope

6:25 for that. But it's still a problem. If

6:28 every category of credentials requires

6:30 its own private trust framework and

6:33 every verifier has to somehow be inside

6:37 each of those trust frameworks, it's a

6:39 nightmare, right? Instead of four layers

6:42 between the merchant and the credit card

6:43 companies, we'll have a hundred layers

6:45 between you and all of the

6:48 different things that you might need to

6:50 verify in your life. Now, private

6:53 governance can solve some of these

6:56 problems, right? And we've seen lots of

6:58 efforts over the years. IRA is one of

7:01 the most recent that tries to

7:04 create a coalition of

7:08 related or like-minded maybe

7:10 organizations who can come together and

7:13 create a trust framework that is

7:15 interoperable and I think

7:18 they all kind of have this vision of

7:20 we'll just get big enough that

7:22 we'll solve this problem. It won't be a

7:24 problem because we'll just get big

7:25 enough that everybody will be part of us

7:27 but Visa is not part of

7:30 Mastercard and they never will be.

7:32 And that's always going to be a problem.

7:35 So a different way to solve this problem

7:39 is to have something underneath all and

7:43 connect them. Okay, but that's just one

7:46 problem. There's another problem. I

7:47 talked about this in my talk on

7:50 Monday and that is an economic problem.

7:53 So in the mid 1990s,

7:56 Netscape had essentially solved the

7:59 digital identity problem for at least

8:01 the web. I mean, they had

8:04 pretty good ideas, right? We'll have

8:08 servers that will have certificates and

8:12 we'll put certificates in browsers

8:15 and your browser certificate will

8:18 identify you. We'll proof your identity

8:21 with these certificates. I mean, in

8:23 this day and age where you can

8:26 essentially get server certificates for

8:28 free, you may not remember, but back in

8:32 the day, certificates were really

8:34 expensive because they were all proofed.

8:37 Right now, they basically just link a

8:40 domain name to a key. That's all they

8:42 do. But if you want a real proofed

8:45 certificate, they cost money. Not only

8:47 because it costs money to proof you, but

8:49 because the company is putting

8:50 themselves out there and saying “this

8:53 information is correct”. So, they're

8:55 liable. So, they cost money.

8:58 Turns out, people were not

9:00 willing to pay money to shop and to bank

9:02 and all of those things. They wanted it

9:04 all to be free. So

9:08 we standardized on "Servers will have

9:11 certificates and people will have

9:13 passwords" and just kind of waved our

9:16 hands and hoped the problem would go

9:17 away because there was money to be made.

9:21 So here's the two problems. How

9:23 we scale trust. How do we create

9:25 trust frameworks that are more

9:28 universal? And second, who's going to

9:31 pay for this. Who's proofing the

9:33 person using what authority, what's the

9:36 legal standing, all of those questions.

9:43 This is where I think SEDI can help us

9:45 with both of these problems and

9:48 I'll talk about them in some detail.

9:51 As far as scaling trust, SEDI

9:56 doesn't provide any kind of universal

9:59 trust framework. That's not the answer.

10:01 What SEDI provides instead is a

10:04 foundation that trust frameworks can sit

10:07 on. So we have something that is

10:10 firm underneath, a firm legal foundation

10:13 for all of these other things that are

10:14 going to happen. The second help that

10:18 SEDI can provide is on the economic

10:20 problem because turns out that the state

10:26 already has lots of infrastructure

10:30 for doing this. They already

10:32 proof you, part of if

10:34 you look at your driver's license, we

10:36 have a couple of people from Europe here

10:38 so they may not be familiar with

10:40 this idea but if you look at your

10:41 driver's license which is the only thing

10:43 we have to prove who we are, there's a

10:45 little star on it. You know what that

10:46 star means?

10:49 “REAL ID”.

10:50 It means the state proofed your identity.

10:54 So this was started in 2005

10:59 when… earlier than that, maybe 2002…

11:03 It was right after 911.

11:06 It happened

11:08 before 911, because I remember I was CIO

11:10 when they started talking about this.

11:12 This was early 2000s, right? So,

11:15 proofing your identity. And at the time,

11:16 the motor vehicle division, the driver's

11:18 license division said, "We don't want

11:21 anything to do with identity. We're not

11:23 an identity

11:25 provider. This is not us." Well, let's

11:28 see how that worked out for them. So,

11:30 anyway, you have the old star. They

11:31 already proofed your identity.

11:34 So, let's talk for a minute. I think

11:36 most people at this point probably have

11:38 an idea of what SEDI is, but let's just

11:40 make sure that we're all on the same

11:41 page. SEDI doesn't give you

11:44 an identity. In fact, the SEDI

11:47 legislation specifically says:

11:50 "An individual possesses an identity innate

11:54 to the individual's existence and

11:56 independent of the state. Which identity

11:59 is fundamental and inalienable." SEDI

12:02 doesn't give you an identity. They're

12:04 not an identity provider, right? That's

12:06 a nice term. Instead, what it is, you

12:11 create your identifier or identifiers.

12:16 The state proofs specific attributes

12:19 about you,

12:21 then links those attributes to you

12:25 in a cryptographic way, not to you,

12:28 to this identifier (that you

12:30 control). In a cryptographic way.

12:32 So, you can kind of think of this like a

12:34 notary, right? The state is endorsing

12:37 your identity, not giving you an

12:41 identity. They're just saying, "Yeah,

12:44 this identifier, we looked at the person

12:47 who controls it, and that really is the

12:49 name and the birthday and the address

12:51 and whatever other attributes might be

12:54 part of your SEDI."

12:56 So SEDI not just one credential.

13:02 Like I said, you create an identifier

13:05 (or identifiers),

13:08 and then SEDI

13:11 is a credential which links those

13:17 attributes (that the state has proofed

13:20 and endorsed) to that identifier.

13:25 Now there could be other government

13:27 credentials that sit on top of that.

13:30 Things like driver's licenses. We heard

13:32 Joe talk about offhighway vehicle

13:35 operator licenses, fishing licenses.

13:39 States are veridible credential

13:41 factories. They just love giving

13:44 credentials to people for different

13:46 things, right? So, states have lots of

13:49 them. Now, some of these will involve

13:52 guardianship, things like birth

13:53 certificates and school records, and the

13:55 statute includes that idea.

13:58 Others will be just things that you get.

14:00 And, like I said, I've got six

14:02 up here, but there probably a thousand

14:04 of them that states have. Most of us

14:07 don't care about most of them.

14:09 But also, other institutions can give

14:12 you credentials. So, you could use your

14:15 SEDI to prove who you are when you go to

14:18 the bank to get a credential from your

14:21 bank. Or you could use your SEDI to

14:23 prove who you are when you're

14:25 registering for school and you would get

14:27 a school ID. So all of these other

14:29 credentials are essentially resting on

14:31 this foundation that SEDI has provided.

14:34 And you can even issue your own

14:36 credentials. You may not imagine why

14:40 that would be interesting now but I mean

14:42 with personal agents, AI agents

14:45 coming along this could be a lot more

14:47 interesting.

14:51 But it's not just people.

14:54 So there's also organizations. Now this

14:57 is not SEDI. This is different than SEDI

15:00 but it's related to SEDI and important

15:02 for what we're talking about. So,

15:05 organizations already have firm legal

15:07 foundations in the sense that

15:10 you can register a business and the

15:13 commerce department gives you a

15:15 registration number and the IRS gives

15:18 you an EIN and all of these things that

15:20 come along with being an organization.

15:22 We don't care as much about the

15:24 organizations creating and controlling

15:26 their own identifiers, but they

15:29 will, right?

15:33 State Department of Commerce generally

15:35 in the United States at least is who is

15:37 responsible for endorsing that

15:41 so you could imagine a SEDI-like

15:44 credential or it might just be their

15:46 business registration but anyway

15:50 it's analogous to the SEDI.

15:53 Organizations like GLEIF

15:56 are indispensable for businesses and

16:00 other organizations who need some sort

16:03 of global reach.

16:08 I got an LEI just because I wanted to

16:11 see how it worked. I've never ever used

16:13 it for anything, for my business.

16:16 But that's important.

16:18 Because there are some things like

16:20 government credentials and banking

16:21 credentials, business licenses that

16:24 would just depend on whatever

16:25 organizational identity you have,

16:27 whatever identity or credential

16:30 the organization has from the

16:32 Department of Commerce, but many might

16:35 require this global interaction.

16:38 Local restaurant might not ever need an

16:41 LEI and all of the things that go with

16:43 that, but a bank might.

16:47 Now,

16:49 let's talk for a second about the legal

16:53 underpinnings of SEDI because this is

16:55 important. I mean first of all SEDI

16:57 includes a bill of rights. I read you

16:59 the statement that it says about your

17:01 identity belonging to you and being

17:03 inalienable.

17:06 These are legal rights, not terms of

17:09 service. This is not a

17:10 click-through contract that you don't

17:12 read. And, if you want to

17:15 enforce whatever small rights they might

17:18 have left you in this 60page document,

17:20 you have to go to court. These are

17:22 things that are in

17:24 statute. They're in law. It also

17:27 includes selective disclosure. So the

17:29 idea that you don't have to disclose

17:33 everything in a credential

17:35 or in your SEDI credential in order to

17:38 use it. You can just disclose the parts

17:41 that is necessary. Requires that the

17:43 system be built on open standards.

17:46 That it's not a proprietary system MDL.

17:53 So, no vendor lock-in. Anyone can

17:57 build a conformant

17:59 wallet verifier, whatever. Speaking of

18:02 wallets, it mandates a choice of

18:04 wallets, right? So, there's not just one

18:06 app that the state gives you. And if you

18:09 don't have that state app, you don't

18:10 have a SEDI. You can choose different

18:13 wallet providers. You can put your SEDI

18:15 in any of those, move it between them,

18:18 whatever. It includes a

18:22 duty of loyalty which is like a

18:24 fiduciary requirement for identity

18:29 data which is a first. This is

18:32 revolutionary in the world of digital

18:34 identity.

18:36 And finally, like I mentioned earlier,

18:39 it supports the idea, recognizes that

18:42 many people are

18:46 wards of a guardian, and therefore the

18:50 guardian has to have the rights and the

18:52 abilities to carry out

18:58 functions,

19:00 operations on their behalf. I don't know

19:02 what the right word is. Carry out what?

19:04 What are they doing? Acting on their

19:06 behalf. There we go. Acting. That's the

19:08 word I was looking for. Nice simple

19:09 word, not carry out duties. Okay. So,

19:13 these are all part of the statute and

19:15 important to why SEDI creates this kind

19:19 of legal foundation.

19:23 Now,

19:25 as I mentioned earlier,

19:28 the problem in this proof gap is that

19:31 when institutions make errors,

19:34 you basically are left to navigate the

19:36 correction process all on your own. Now,

19:40 SEDI doesn't mandate that

19:43 every institution has to do things a

19:46 certain way, but it does provide you

19:48 with a legal foundation. And it does say

19:51 that you have enforcable rights

19:56 related to your SEDI. So you have the

19:58 right to obtain SEDI credentials. You

20:02 have the right to have its attributes

20:04 amended as they change, or need

20:08 correction. You have protections against

20:11 arbitrary revocation. There are only

20:13 certain circumstances where this can be

20:15 revoked.

20:18 There's a complaint, an

20:20 enforcement mechanism for how you can

20:23 deal with problems that come up and

20:26 that includes both the digital…

20:29 what's it called? A digital privacy

20:31 ombudsman and the attorney general. Yeah.

20:34 There are both of those that

20:37 give you the ability to seek redress if

20:40 something happens. So yeah…

20:42 – Just real quick, but it does not

20:44 include a private right of action. The

20:47 attorney general has to act on your

20:50 behalf.

20:50 –– Yeah, we tried to get that in there, but

20:52 they decided that was reach too far.

20:54 Reach too far. Yeah. So,

21:00 these aren't just like consent

21:03 form click-through consent forms and

21:05 support calls that you make.

21:08 These are legal remedies that

21:10 you have the right to …

21:13 They are legal remedies you have the right to

21:15 access if these things will happen.

21:18 Now…

21:20 like I said earlier this doesn't mean

21:22 SEDI doesn't

21:24 replace all of these trust frameworks

21:27 that exist. I spent my career largely

21:31 in academia.

21:34 Academics is going to have trust

21:36 frameworks about what an accredited

21:38 institution is for example.

21:42 Visa is still going to exist as a trust

21:44 framework for how

21:46 money gets transferred inside their

21:48 network. Those are all still going to

21:50 exist. But what does change is the idea

21:55 that they can sit on top of this

21:59 legal foundation. They can have

22:04 attributes that they know, someone they

22:07 trust, proofed.

22:11 Now along those lines, I want to talk

22:14 about two different ways of establishing

22:17 trust. This is a conversation I had with

22:19 Sam, at Smoking Apple six weeks ago,

22:24 or so, right? Because I had just

22:26 written a blog post about reputation for

22:29 agents. And how all that

22:32 can work. But it's equally important

22:34 here. So there are two different

22:35 ways of establishing trust.

22:40 One is by observation.

22:44 You look at someone's behavior

22:46 and you say, "Sam seems like a nice guy.

22:49 I guess I'll get to know him a

22:51 little better”, and then you have

22:53 more interactions and you build

22:56 up that trust. The second one, which I'm

22:58 going to talk about first, is

23:02 reputation by reference and the reason

23:04 I'm going to talk about it first is

23:05 because it's essentially how we

23:06 bootstrap things. So the top of

23:09 this have a diploma, so if you

23:12 want to know things about me related to

23:15 my education I can give you a diploma.

23:18 That is essentially reputation by

23:21 reference. Some institution is saying

23:25 that they did specific things and are

23:29 vouching for the fact that I met their

23:32 standards with respect to this course of

23:35 study. But who are they?

23:39 And does this really belong to me? And

23:43 what standards are they actually holding

23:46 me to? Now, if I tell you I have a PhD

23:50 from the University of California at

23:51 Davis, most people would say, "Oh,

23:53 University of California. I know that

23:56 school. I guess that's okay." But

23:58 if I tell you I have a bachelor's degree

24:01 from Norda,

24:03 whatever, what is that thing called?

24:05 Norda

24:06 Medical Thing. You guys know? Down in

24:09 Provo. Anyway,

24:12 are they good? Are they acceptable? Or

24:14 is that a good institution? I honestly

24:18 don't know. But who does? Well, the way

24:22 you do it, is this diploma can be a

24:26 credential

24:27 and it can be chained to my SEDI

24:31 credential which now means that I can

24:34 prove that this diploma was actually

24:37 linked to me or given to me. But

24:40 it also can be chained to the

24:43 university's credentials and

24:45 identifiers. So they probably have an

24:49 accreditation credential or should have

24:51 one that came from their accrediting

24:53 body. And there's not just one, right?

24:55 So there would be an accrediting body

24:57 for the university. There would be an

24:59 accrediting body for the specific degree

25:01 program I'm in. All of those… I mean

25:03 there might be dozens of these out here

25:05 that the university has.

25:08 You can also check to see is

25:11 this a legal business? Is it even

25:13 recognized as a business? So

25:17 that would be your commerce department

25:19 or GLEIF vLEI

25:22 credential.

25:23 And importantly when I present this

25:26 diploma as a credential

25:29 all of this can be checked automatically,

25:32 these chains can be followed. We

25:34 can check all of the credentials and

25:37 you can get a green light on your

25:38 system that tells you: yes

25:42 this credential is issued to

25:45 this person, it came from this

25:48 institution, that institution is

25:50 accredited by this body and this body

25:53 and this body and it's organized in the

25:55 state of Utah and all of the things that

25:58 you might want to know about it.

26:01 So that's reputation by reference

26:04 and

26:06 SEDI provides a nice foundation for

26:08 that, as do the organizational

26:10 credentials that we talked about.

26:13 There's another kind of reputation

26:16 that I mentioned and that's reputation

26:18 by behavior. Now, in the physical world,

26:20 we just interact with each other,

26:22 and that's kind of how we figure out

26:24 whether or not

26:27 we like this person. We trust them,

26:30 right? The fact that I'm going to let

26:32 you fix my plumbing doesn't mean I'm

26:34 going to let you babysit my kids, right?

26:36 So, there's different domains of

26:37 behavior that we that we look for.

26:40 We use reputation by reference to

26:43 essentially bootstrap this. I needed

26:45 someone to come in and fix an oven at a

26:48 at a rental property I have.

26:51 I didn't know anyone, so I just used

26:54 reputation by reference, right? I looked

26:56 at reviews online to see, okay, they've

26:59 got a pretty good thing. Yeah, Timothy…

27:02 – Isn't reputation by reference also an

27:05 accumulation of behaviors?

27:09 It is!, but it's at a distance.

27:13 So, we go back to this.

27:16 All of these could be many layers

27:19 away from the actual thing that I give

27:21 you. So there are accumulated

27:24 behaviors that lead to that diploma. But

27:27 it's not me who watched you

27:30 complete the degree. It's indirect. It's

27:33 the university who watched you complete

27:36 the degree and you're believing the

27:38 university. So there's an indirectness,

27:41 not a direct link. – But either way, the

27:44 quality of reputation

27:46 can't be separated from an

27:48 accumulation of behaviors over time.

27:50 Correct.

27:51 – That's true.

27:52 – And so if it's a good restaurant, it's

27:54 done well. It's had good behaviors

27:57 which got that reputation. And what

27:59 you're doing is you're collapsing the

28:00 history because it's so well known. I'm

28:02 going to collapse the history and just

28:04 say I just need to tell you the name

28:06 of the organization.

28:09 – In reputation you explicitly

28:11 trust the reputer. If you're observing

28:15 the direct behavior, the only person

28:17 you're trusting is yourself. So, the

28:19 verifier doesn't have to trust anybody.

28:22 If they truly do reputation by behavior,

28:24 they can verify all of…

28:27 Here's a different way of

28:29 thinking about it.

28:32 Trust always,

28:35 always requires vulnerability.

28:40 Trust requires vulnerability.

28:44 If you aren't vulnerable,

28:48 you don't have to trust.

28:50 So the question here is, am I trusting

28:55 me? I've eaten at that restaurant

28:57 before and it was pretty good. Or

28:59 am I trusting the reviewers, which is an

29:02 accumulation of behavior, but I'm

29:04 trusting someone else, in one case I'm

29:07 more vulnerable to mistakes than I

29:09 am any other right because it's indirect

29:12 rather than direct. That's the difference.

29:13 – You're trusting a third party's opinion

29:15 of the reputation versus your own.

29:17 – That's right. It's not whether

29:19 it's based on behavior, it's

29:21 whether it's indirect or direct,

29:24 so a different dimension, but yeah.

29:33 Right now, the way reputation by behavior

29:37 works, one example of that is credit

29:38 bureaus. So credit bureaus

29:41 accumulate

29:44 all of your transactions and whether you

29:46 pay your bills on time and whether you

29:48 were late and all of those things,

29:50 right?

29:51 And they use some algorithm to determine

29:56 a credit score which is then paid for. I

29:59 mean other places other banks or

30:02 credit card issuers or

30:05 employers and others can then pay for

30:07 that credit score and get that for you.

30:10 So that's one way that we do

30:14 behavior. Different way is, say every

30:19 time I have a transaction with company X

30:21 or company Y,

30:23 I get a receipt that I paid on time, all

30:28 of these things. Now, this may not

30:30 matter as much for individuals as it

30:31 does for organizations. I mean you can

30:33 see the organizations could really

30:35 benefit from something like this because

30:37 it's big, lots of money but anyway you

30:39 get these as credentials and now you can

30:41 prove to other people in combination or

30:44 apart whether or not you have behaved

30:48 properly. Now I have to say there's one

30:50 big problem here.

30:54 I can admit bad behavior. So, doesn't

30:58 mean that these things are ever

31:00 going to go away. I mean, I think

31:01 there's always room for things that

31:05 are looking for bad behavior. Yeah.

31:09 – One thing though that the

31:11 decentralized model allows is that the

31:15 verifier can pick their own algorithm.

31:18 If I go to get a credit score, there's

31:20 like five algorithms.

31:22 And I was

31:24 going to mention that this model allows

31:27 for a marketplace of algorithms.

31:29 And for transparency in algorithms.

31:32 Somebody might say, "Oh, yeah.

31:33 Well, we use this algorithm for how we

31:35 do how you do scoring." Yeah.

31:37 – I don't know if you were talking about

31:39 it, but you said at the bottom in

31:41 one case, you don't own your data. You

31:43 do own your data.

31:44 And I'm gonna say that this is

31:48 the sort of issue, legally, that is going

31:52 to slow us down dramatically because if

31:54 you look at what the Supreme Court has

31:57 always said, it's that no one owns

32:00 facts. Okay, data is facts. You might

32:03 own the database that the facts reside

32:05 in, but no one owns the underlying

32:07 facts. So the solution to that is to

32:11 treat those facts as an unownable

32:14 commons. Okay? And like all commons,

32:18 navigable waters or the air we breathe,

32:21 someone has to be responsible. So going

32:23 back to the fiduciary duty of loyalty

32:25 and other fiduciary duties, you are the

32:28 best candidate to be the trustee over

32:31 your facts because you're more

32:33 interested in their accuracy.

32:35 – I care about them.

32:36 – Right. And the government has

32:38 a secondary fiduciary duty to make

32:41 certain that your rights in those facts

32:45 aren't abused.

32:47 But the point there is I think that's

32:49 what's going to slow us down because if

32:50 you look at these 80page agreements

32:52 where you just click “I agree”, none of

32:55 them say “you own the data and you're

32:57 giving us ownership”. They all say “you

33:00 transfer whatever rights you have and we

33:02 accept whatever rights you have” and then

33:04 the company goes out and says “we

33:05 own this”. So it's a legal fiction.

33:07 – Yeah, I probably shouldn't say

33:10 “own” there. I mean control is a better

33:12 word.

33:13 Own is a problematic word in this word

33:16 for the reasons that you have

33:18 pointed out. And in fact,

33:23 if I'm in a transaction with someone, we

33:26 both are parties to that transaction

33:30 and we both could have a credential [inaudible]

33:33 to that transaction and we both control

33:37 that. And of course, that's just

33:39 two-party. It could be multi-party. So,

33:41 so yeah, it's about you have access

33:44 to and can control who you share it

33:47 with,

33:47 right? – And just to your point very

33:49 quickly about transactions we

33:51 always sort of say, well, the newspaper

33:54 costs a dollar. Well, if I'm buying the

33:57 newspaper, I value the newspaper more

34:00 than the dollar and the publisher values

34:04 the dollar more than the newspaper. So

34:06 otherwise, the transaction wouldn't

34:08 occur.

34:09 – Yeah.

34:11 There's cost, price, and value.

34:13 And they're not the same. Yeah.

34:16 – Even the word “your” implies ownership.

34:21 – “data about you”. Yeah.

34:26 Okay. This whole idea of

34:30 reputation has lots of implications or

34:36 ramifications for how we might

34:39 approach agentic AI and how agentic AI

34:44 works with us. I mean this talk is not

34:46 about agentic AI but I just wanted to

34:49 point out that this same foundation and

34:54 this idea of building reputation around

34:58 solid identifiers for organizations and

35:00 individuals

35:02 helps us in this space. If you want to

35:05 know details how I think about it like I

35:08 said there's a blog post.

35:15 One thing I thought of when I was doing

35:16 this actually is this idea of an

35:18 evaluator. You could imagine agents that

35:20 you employ that are evaluators. You

35:22 know, we talked about having a

35:24 marketplace of reputation evaluation

35:27 algorithms. You could imagine a

35:29 marketplace of reputation evaluation

35:31 agents who are working on your behalf

35:34 for various things. Things that

35:36 you care about and ones that you trust,

35:37 and “I'm going to use that

35:39 agent because I like the

35:41 restaurants it recommends”.

35:43 What's the technology opportunity

35:46 here? If you're building

35:50 decentralized identity infrastructure,

35:52 SEDI is an opportunity, but it's not a

35:54 guarantee.

35:59 SEDI sets out these requirements:

36:03 Open standards, decentralized

36:05 control,

36:07 that represent a high bar for how

36:10 this all has to work. And like I

36:15 said at the start of the talk,

36:18 there's the technical side of it,

36:20 which is not in any way a

36:24 small thing, but doing that at scale,

36:29 meeting the user experience requirements

36:32 that we might have, finding the right

36:34 economic models for the various parts

36:37 and pieces that have to work. Those are

36:39 all extremely difficult problems to

36:41 solve. So it's not a no-brainer

36:45 that “Oh SEDI came along good, it's all

36:48 solved” and we still have lots of work to

36:50 do. Timothy.

36:52 You've got whole talks about this.

36:54 – If you

36:56 in [inaudible]

37:01 have a legal basis in their giant

37:03 centralized digital system,

37:06 use a lot of cryptography as well

37:10 component missing

37:12 and that's the decentralized nature of

37:14 SEDI. It's trying to have [inaudible]

37:18 a legal verifiable basis but also

37:22 decentralization meaning that you can

37:24 have different vendors in different

37:26 states and different systems and they

37:29 can issue in one place and verify in

37:32 another because they're speaking a

37:33 common [inaudible]

37:34 We hope!

37:35 – Those systems that's

37:38 obviously the…

37:40 But that makes it

37:42 hard, right?

37:42 – In contrast with Aadhaar in India and in

37:45 contrast with what they're doing in

37:46 Estonia because they do not have that

37:48 property and they're not even trying.

37:50 It's a giant centralized system and

37:52 everybody phones home to the mother

37:53 ship.

37:54 – Yeah, absolutely.

37:55 – My point is just having those two

37:57 components up there describes Aadhaar.

38:01 That's my point.

38:04 – Okay.

38:06 – And it does…

38:08 going back to your point about control

38:11 because decentralization is about

38:14 autonomy and control ultimately.

38:23 – (Lawrence) Lessig famously said that “code is law”

38:27 and there's a lot of people who take

38:30 that to heart and it is true to the

38:32 extent that code controls what you can

38:35 do and what you can't do but I don't

38:38 think for identity that idea is quite

38:40 sufficient. That we need more than

38:44 code, we need this underlying legal

38:48 foundation that SEDI provides for

38:50 individuals.

38:57 SEDI answers questions about who has

39:00 authority to revoke, when can they

39:02 revoke? That's just one example.

39:05 Who has the right to get one of these?

39:09 Code doesn't solve those problems. Those

39:11 are all things that we need legal

39:13 infrastructure which is steady, at least

39:17 on the road to providing. I don't

39:20 think this will be the last SEDI

39:21 statute. I think there will be more but

39:23 but nevertheless we're on the

39:25 road to getting there. So

39:29 SEDI provides this legal foundation like

39:31 I've said.

39:33 We've got

39:36 code, we've got stacks that are maturing.

39:40 And what we have now starting in May

39:45 is a legal foundation for all of that.

39:49 So,

39:52 we've had some discussion going back.

39:53 I've got like two or three minutes I

39:55 think if there are questions. Two

39:56 minutes I'm told. So, is there

39:59 questions? Happy to answer them.

40:01 Otherwise, I will turn you over to the

40:03 next one. [Applause]