W3C

VCWG Product and Wallet Vocabularies

13 July 2026

Attendees

Present
carsten_stöcker, fireflies.ai_notetaker_miguel, ivo_ladenius, m.-a._wolf, phil_archer, Phillip Long, ronald_koenig, susanne_guth-orlowski
Regrets
-
Chair
-
Scribe
transcriber

Meeting minutes

Introduction And Meeting Purpose

Carsten_Stöcker: Hello. Nice meeting you.

M.-A._Wolf: Hello. No,…

M.-A._Wolf: I'm popcorn.

Carsten_Stöcker: Poprn. foreign. Yeah.

M.-A._Wolf: Vocabul invited expert policy link.

Carsten_Stöcker: Mhm. Yeah.

M.-A._Wolf: project. …

Ronald_Koenig: Hello.

M.-A._Wolf: Verify credentials. Carsten Stöcker:

Carsten_Stöcker: I want to look in for Hi. Can you hear as hey Evo,…

M.-A._Wolf: No, Germans.

M.-A._Wolf: That comes from germs. They're everywhere. Hello.

Carsten_Stöcker: how are you doing?

Ivo_Ladenius: Hey, good afternoon.

Carsten_Stöcker: Good afternoon.

Ivo_Ladenius: Yeah, good.

Carsten_Stöcker: Hey Evo Ronard, is this today about DPPs or business wallets? Because we do this business wallets.

Ronald_Koenig: This is I think so…

Ronald_Koenig: because Nicole told us it right.

Carsten_Stöcker: Yes. Okay. Yeah. And…

Ronald_Koenig: She has sense that she cannot make it today and…

Carsten_Stöcker: then we do the business.

Ronald_Koenig: offer to you that you are organizing the meeting and discussing a little bit business wallet vocabularies and so on.

Carsten_Stöcker: Yeah. So we do the business models.

Knowledge Graphs And Trusted AI

Carsten_Stöcker: Maybe I share one thing. there's a lot of discussions now about knowledge graphs.

Carsten_Stöcker: And I need to share this. Where's my Knowledge graph.

Ronald_Koenig: by the way called it was Caroline.

Ronald_Koenig: I was mixing up the names. Sorry.

Carsten_Stöcker: But this is what I want to share. And then we go to the business wallet.

Carsten_Stöcker: Because Ronard did a lot of experiments in kind of feeding linked verifiable credentials into AI and we found out that AI can work very very efficiently when there's linked knowledge graph and then we ran some research to identify secondary research where people have done some benchmarking. Yeah. And this because in Germany the people would like to just copy paste what they've done in the last 20 years including the asset administration shell and they're not really interested in linked data at all.

Carsten_Stöcker: whatever the German industry for zero people and I think when it now comes to trusted AI there are a lot of benefits and this is what I want to share and I think the benefits are even bigger this is only the tip of the iceberg so we found some secondary research…

M.-A._Wolf: Yeah. Yeah.

Carsten_Stöcker: where people compared plain data with knowledge graph And then when we have verifiable credentials then knowledge graphs are even verifiable but here I'm only talking about the knowledge graphs and it's interesting because there is a factor of 3.5 to four fewer contradictions and factor of four fewer hallucinations and fewer token and massively fewer token usage. Yeah, this is what we found in our lab as well. But the fewer token usage in terms of compute environmental footprint and even in terms of edge computing, this is of course another big benefit. But I think even if you bring down the hard nations to some of these benchmarks and multiple benchmarks found those in terms of comparison but this is not good enough for regulated industries.

Carsten_Stöcker: But one thing is clear when you would like to use in regulated industries you need to feed it with knowledge graphs.

Carsten_Stöcker: And yeah.

M.-A._Wolf: I should have moved into AI a year ago longer.

M.-A._Wolf: We should build AI on knowledge graphs. I was thinking early last year but I don't want my background so I didn't do but now I see it it was exactly to be expected. I think our human language is disaster to work with as a computer. Carsten Stöcker:

Carsten_Stöcker: Yeah. And we see a lot of movement now where people are kind of let's say inventing the jaml for human whatever curated content but also for moving to knowledge graphs and fees in AI and it really looks when it needs to be explainable reliable or whatever trustable whatever your taxonomy is you need to have what knowledge graphs on the other hand there's also some confidentiality kind of things with the knowledge graphs when you make them verifiable but in regulated industries often it's more about transparency and risk and less about human privacy. But I think this is a kind of let's say you have to balance both targets confidentiality and knowledge graph type of benefits. so here's what we see and for the DPPS we clearly need this and I think it's a very nice research or also want to share this because with link data we're doing this.

Carsten_Stöcker: owners, do further can I hand over to you in terms of the business words?

Ronald_Koenig: Yeah, what I can do is I can let me a short introduction…

Ronald_Koenig: what we are doing currently in vuild with respect to the European business wallet vocabulary what's the ideas behind this what the current status is and…

Carsten_Stöcker: Yes. Ronald Koenig:

European Business Wallet Vocabulary

Ronald_Koenig: how it looks like using the WCC tooling young to vocab and what we try to achieve with this. So as a short survey about the activities we currently have in the semantic groups of the vill consortium. let me share my screen. Let's go forward. So you should see this document European business wallet vocabulary. Okay.

Carsten_Stöcker: Just yeah.

Ronald_Koenig: What are we doing in what is it 16 use cases which we build wants to address with the European business wallet. let me start with the Rebuild is a large scale pilot which should provide practical use cases for the European business wallet with respect to the USB wallet proposal and the AEDS 2 regulation. And inside this one we have as I already said And this 15 use cases define approximately 50 verifiable credentials it wants to exchange between wallet issuers verifier to host this use cases or to serve this use cases.

Ronald_Koenig: What we are doing in the semantic group is because we believe that we need semantic interoperability between all the different credentials because at the end we are discussing one ecosystem and not 50 separated credentials the way they are doing it in SDVC. indeed we define a vocabulary which is the base vocabulary to express or to describe all the different credential subjects inside this ecosystem. So this starts from

Ronald_Koenig: let me say the identity of the company itself. it goes farther with ownership control ultimate beneficiary owner structures and such thing like power of attorney and other things you want to express with verifiable credentials or for example a membership in the data space and so on. Because our understanding is that we are reusing all the vocabularies in the different credentials and not defining different properties for different credentials which then don't correlate each other and needs to be mapped manually or semianually let me say it this way. and therefore we are currently defining this European business wallet vocabulary. If you have any question please ask.

Ronald_Koenig: So what you are see here the basic for all this one is oops the basic the basis the foundation for this one is that we are using of course verifiable credential as they are specified by the W3C VCM data model 2.0 zero. We extend this one by only one additional attribute because the electronic atistations of attributes as specified in the European regulation have some at legal categories which says is it a qualified electronic attestation of attribute?

Ronald_Koenig: Is it a puppy coming from a pup issuer or is it let me say a normal electronic attestation of attributes with some limited level of assurance. In this vocabulary we are not defining anything except this one for verifiable credentials on the level of verifiable credentials. But what the kind we are adding is that we are defining a lot of credential subjects which are then more or less carried inside the verifiable credential and of course we are using all the functionality which verifiable credentials or W3C VCDM 2.0 verifiable credentials provide to us.

Ronald_Koenig: So at the end this means that every credential we are defining here for example the European business wallet owner credential is more or less a subclass of the credential subject. So if you go into the vocabulary and wants to know which kind of credentials we are providing, it's pretty easy. Go to the credential subject. I do it here on the left side. For example, I go here for this one. And what you see is then because it is not yet complete. We are currently in progress providing this one. You see all the different credentials or credential.

Ronald_Koenig: credial subjects of this credentials we have already defined and are providing. So that means this is more or less the root of the inheritance structure we have in our vocabulary and from here on you can go down and find then the different credential subjects which you really use in the different credentials. For example, if you go down go to a company, then we will see that the company has two subc The credential subject and economic operator and is subclass of and it is a zupa class of limited liability company and partnership. why we have this two?

Ronald_Koenig: because these two are defined in the European company law which will be mandatory I think next year so that everybody who is participating in the European Union needs the identity which can be expressed in the European company certificate and I think one or two years later this should then go through the European business wallet. How does it look then? So that means for example, let us take the limited liable company here. we can go to this jump into this one and we see okay this is a company. No surprise with this one. Let us go back.

Ronald_Koenig: What we are seeing here are the different terms which are required by the European business vocabulary by the European company The company law sets it that the activity needs to be asserted correspondence address date of registration and date jurisdiction. So that means which jurisdiction is responsible for this legal status, registered address and so on. And if we go to a limited liability company, additionally you have to list legal representatives on of course the sub subscribed capital. So that means the limitations the company has.

Ronald_Koenig: And if you look into then some examples we have already also in our description you will see all the data I have mentioned before the entier, legal name, legal form. But what is interesting also is that we have a completious list of legal representatives and for the legal representatives we are using explicitly JSON ID with links to other credentials. In this case, the link to the credential of the person which is in this case the CEO of this company and this enables this person to prove with the European business wallet two things. The first thing the identity of the company its own ident three things the identity of the company its own identity.

Ronald_Koenig: So that means the personal identity and also that he is authorized to act on behalf of this company because all these credentials are linked to each other and with this holder key. It is also possible that the legal representative is using this key to authenticate if he presents the credential or the presentation to a verifier. What we also have is that we can automatically verify that the structures are correct in the sense that JSON ID is canonizing correctly for proving and signatures because we can jump into the JSON ID playground directly canonize the data structure.

Ronald_Koenig: Okay, this is not working currently. because it's still wrong. Let me go to the other one. Take the partnership. go into the structure and what you can see here is that we are automatically canonize the example. In this case, this is the data structure of a partnership which is completely expressed with this is a membership credential. Okay, let me take another one. It's easier to explain partnership is company here. Yeah.

Ronald_Koenig: So what we have here is now not a limited liability company. It is a partnership with different partners limited partners, deterate partners and general partners. As explained before also here we have a partner ID which then referencing to the other credentials which are personal credential of the partner itself. so that we can build the complete structure of the company by using JSON ID and the references between all this one and what you can see here we have also the complete references I go into the table it's easier to read so in a subject predicard object data structure which is then directly linking into seed.

Ronald_Koenig: semantic definition of all the different terms we have defined in this vocabulary. And of course, for example, this one if I jump into the monetary amount, this is then defined as a semantic term. And inside the vocabulary what we have because I can jump directly from into the semantic definition of this one. It clearly defines where it is used.

Ronald_Koenig: For example, in this case, it is used by liability or contribution of the partners as well as subscribed capital inside limited liability or as a total payroll inside. Yes, I have to look in the social security contribution. and this is the way that we are building up this knowledge craft of the vocabulary or the ontology. we are using to describe the different credentials or the full set of credential in our domain. And this allows us then to give this model for example an agent.

Ronald_Koenig: In this case, I use it with clo and then give clo some statements or task based on this vocabulary so that he can for example generate new credentials or make statements about companies if there are some certain attributes known about this company and so this should be the first survey of what we are currently doing and what the semantic group are doing. This is work which is in progress. So that means it is currently started.

Ronald_Koenig: We still have 12 months to go forward inside the BBU consortium and with this vocabulary will support let me say the major credentials we have defined in feeble to support the different use cases. Yeah.

AI Agents And Power Of Attorney

Carsten_Stöcker: Maybe two comments. Maybe you can mention what I think we are also planning to extend this to power of attorney for AI agents. I think this is now very very big kind of hype to give AI agents a verifiable intent an authorization also so with manos bony of course this is now pretty much driven so we position as vocabulary we discussed a bit it's a black box we can position this in the

Carsten_Stöcker: and the work of our working group here. But with Manus Borne after the summer vacation break, we would like to identify some intersections. So what's in California is needed and then we tried kind of to build something with a minimum set of vocabulary items for US and for Europe using a shared vocabulary reusing it to demonstrate that multiple implementers but across jurisdictions. So there is value in kind of putting such vocabulary in place.

Carsten_Stöcker: Yeah. that's a bit also next steps. But maybe you can mention something about the AI piece and then we can discuss a bit next steps again I guess.

Ronald_Koenig: Maybe starting with the power of attorney…

Ronald_Koenig: which you have mentioned is we are using this vocabulary inside our business wallet ecosystem and what needs to be understand here is that our business wallet is not only supporting the identity or is not only holding the identity of the legal person. We are also holding the identities of all the natural person which are acting on behalf of this legal person and we are able to express as Ken explained with the power of attorney that someone who has for example signature rights in the company like a CEO or a protoarist or someone else who gets this rights from the registration in the business register.

Ronald_Koenig: He can delegate the rights or part of this rights to any employee inside the company and he can do it in a way that it is cryptographically verifiable by the verifier and this is what we are calling power of attorney. So for example, the CEO which I mentioned in this limited liability company can issue a credential and sign this credential with his identity and expressing that for example the head of human resources which is maybe not listed in the business register can act on behalf of the company with respect to anything which is related to human resources task something like that.

Ronald_Koenig: And we can do power of attorney not only to other employees. We can also do power of attorney to agents to processes and to machines because everything which has express identity anchor. So that means that whatever did method is behind this one, we can link the credential to this DID and then assigning or make them to the holder of See?

Ronald_Koenig: power of attorney credential so that he can prove against the verifier that it is the specific agent or machine and can also prove that it is authorized to act on behalf of the company on behalf of a person inside the company and this is also the way we are going forward now and putting it into some context of providing agentic AI agents so that we can prove that the EI agents are really acting on behalf of the company.

Ronald_Koenig: Any questions for this?

Benefits Of W3C Verifiable Credentials

Phil_Archer: Hi Ronald.

Phil_Archer: Thank you for that. first of all, I must apologize for having been so late to the call. I'm trying to understand from my perspective what you've done and where you're heading with this because It's obvious that you and the people you're working with, Ronald, know a great deal about this and have a lot of expertise in the business wallet area. What I'm trying to work out is the answer to the question, what can this group do? What benefit is there? what is the great outcome that comes from you doing this work here? the answer that the DPP group has come up with is essentially showing how DPPs can be expressed in a verifiable credential if that is so desired. it's different situation from you I know so I'm not expecting exactly the same kind of document there.

Phil_Archer: But I think it's …

Carsten_Stöcker: Why Phil?

Carsten_Stöcker: I think we can produce the same document as a starter. Yeah. Yeah.

Phil_Archer: if you can then great, by all means do. I mean, it's I mean, as you know, Caroline she hasn't answered yet, but that she's beginning to answer some of the questions. So why VC is useful for business?

Ronald_Koenig: Good.

Phil_Archer: I mean we think the answer is obvious but it may not be to some people.

Ronald_Koenig: Yeah, Phil, let me answer the question with really why we are doing it because we are not doing it doing it because we love the technology. on one side but on the other it should have some added value for the companies. The first thing where we are starting with is the EML anti-moneyary in Germany in Europe. and opening a bank account currently takes approximately 3 to four weeks if you want to open a corporate bank account in Europe because you have to verify the ownership control structure. the ultimate beneficiary owner, voting rights and everything, political exposed person and whatever. And if you want to get this information, it is a really burden for the financial institutes in Germany to fulfill the AML requirements.

Ronald_Koenig: And the AML requirements from year to year are more demanding with respect to the verifying process and also how often you have to go through this process to make sure that all your data are updated and what we are providing together with our strategic partners. This is a business register here in Germany. We are providing the complete information about a company including the ownership structure including ultimate beneficial owner everybody completely authenticated and everybody inside the structure can authenticate against the bank for example to open a bank account.

Ronald_Koenig: So the idea and it is already working but with the processor of this vocabulary is that you can use your wallet to open a bank account. You can prove the identity of your company. You can prove your own identity and you can prove your role inside the company and al and proof that you are authorized to open the bank account on behalf of the company and…

Ronald_Koenig: all this will be provided using credentials and these credentials allows then the bank to open a bank account more or less on one click and nothing else. Mhm.

Phil_Archer: In some ways only some…

Phil_Archer: what you just said is kind of a use case generally for What I think would be helpful is I suppose an expanded or a full description of that with examples and so on which I know you've done and I know I'm not asking you to do stuff you haven't done before but to show the world why and I think the actual vocabularies you've done within we build I don't think you're talking about developing that within this group because of it's the whole ecosystem around that which may also refer not just to BCDM but the competence methods and the render methods and the recognized entity methods and everything else that we're working on and show that ecosystem and…

Phil_Archer: that those use cases you have clearly if you can get a four-week process down to a 4-minute process everyone's happy and I think that's going to be a valuable description Yeah.

Ronald_Koenig: But let me see this is just the starting point on this one.

Ronald_Koenig: What we are also doing just to give you another example for this one is automatic onboarding and data spaces because currently it is that the authority has to collect all the data from the company and then doing a lot of background checks with clearing houses and so on to really onboard this company.

Ronald_Koenig: So what we are currently providing using the identity which is asserted by the business register officially with level of assurance at least substantial or even high and then do automatic onboarding in different data spaces more or less on a click because you don't have to go to a clearing house have to resolve the discrepancies between the different data you have and then you can go directly

Ronald_Koenig: And we are already doing it for some data spaces in Germany for the h data space as well as for x data space on a research basis because we want to replace the old x509 based infrastructure we currently have for defining for example if you go to a smart meter in Germany you have to get three x509 credentials to read the data out of a smart meter.

Ronald_Koenig: meter to get it for example for energy distribution or something like that. This is

Phil_Archer: So I think…

Phil_Archer: although it's a really useful case especially with the data spaces thing which is very politically active obviously working with Bundesan is obviously very important as well and being able to make sure that also works for other business registers not just the one in Germany and so all those things are valuable and showing that yeah this is why this technology works for this and showing these things that's what I hope we can do and as you have made clear and…

Phil_Archer: I understand it's very clear time is of the essence sorry…

Ronald_Koenig: and…

Ronald_Koenig: one thing what is more from the technology side is that we really want to prove that the W33 credentials that we have a long discussion in Europe using SDVC or W33 credentials as you may hear is that I'm completely in favor of W33 credentials…

Phil_Archer: why can't use both

Ronald_Koenig: because they are providing a lot of benefits with respect to holder multihoder binding, JSON as a link data and all the other stuff semantically interoperable interoperability because we are not writing vocabularies for one credential only.

Ronald_Koenig: We are writing for the whole ecosystem so that you can also on the fly create new credentials because the semantic of any term you are using inside the credentials and this is more or less something what we also want to achieve is this one proves that we have a technology already in place which can really address most of the questions we have and we don't have to reinvent the wheel and have to overcome some deficiency which are produced because we are using let me say a technology…

Ronald_Koenig: which was not from the beginning on design to solve the issues we currently address Yeah.

Phil_Archer: Yeah, if…

Phil_Archer: if some of what you just said isn't in my little document, it would be lovely if you could five minutes. That's all it takes just to jot down some notes, Ronald in that because that's my goodness me. I got to go to Geneva sometime and I'm going to have about 17 arrows pointing at me. and people are going to tell me how useless all your work is and how rubbish you all are and none of what you're talking about. And if you just use their thing, whatever that whether it's bc or MDO or something else they've already got, wouldn't life be easier? To which the answer is no. so I'm trying to make sure that I can answer those questions fully. I think you just said some things that are not in that doc. be really grateful even just notes bullet points that would be great please.

Phil_Archer: But yeah, I think that it's showing why the W3C VCDM has advantages, why this work is being done here, what the benefit is. and that would be I think appreciated by a lot of people. I would help move forward in that way that says look this is why this technology is good. this is what we can offer. this is why we think this is the right thing to do and here's how you can use them in these cases whether it's getting a new bank account setting up a data spaces thing. Sorry, Phil.

Phillip Long: Yeah, I just made a technical comment in the chat. Since you're introducing DIDs, you've got a relatively green field when it comes to the utilization of DIDs in your space. And it would be nice if in that process you promoted the use of DIDs that support key rotation which is a thing that will be increasingly important and for which we now have a couple models that will be potentially useful in the W3C space. And secondly, if you care about doing those links in a safe way, make them hash links so that the links themselves are verifiable.

Phillip Long: each of which introduces things that are sort of baked into the W3C architecture and which others I don't think quite have that capability with the exception of carry and carry is incredibly more heavyweight than I think is often useful particularly to midsize and…

Phillip Long: smaller businesses. Just to come it.

Ronald_Koenig: But I have not mentioned anything…

Ronald_Koenig: but what we are we have the code which is a rule books and in this rule books we also specify how we are using this and how we are addressing this one and this is I think one big benefits of W3 credentials because you can make a abstraction layer or you get automatically abstraction layer. between your trust infrastructure and the W33 credentials by just using the different methods we have for example, in data spaces they are using the web. We can long discuss about it. Is it or secure enough?

Ronald_Koenig: It seems to be enough for data spaces at least for the ecosystem I know and we can have the verifiable registry verifiable history the web vh or we go forward and putting a distributed ledger behind this one and using did either or epsy or other methods and this is what we are really promoting that we are saying we want to discuss the trust angel or the trust tree angel. We have on the upper layer between the issuer holder verifiers and we are based on a verifiable data registry which can be on completely different technologies like DNS, distributed ledger technology, like X509 because we have to use it in Europe. we cannot go around it unfortunately.

Ronald_Koenig: I would like to get rid of it or we can go to Epsy or something like that because we have an abstraction between this lower verifiable data registry where we get the trust anchor and on the other hand we can deal on top of it with our credential and of course key rotation is one of the topics. If you have seen in our examples did key and this is not with key rotation because the key information is inside the ds. This is just to make it easier and not to be in favor of a certain verifiable data registry we have be behind this.

Ronald_Koenig: So from my point of view this controlled identifiers and the abstraction of this one are controlled is a very important part of the whole suite which we are getting with W33 credential. I have also not mentioned data integrity and all the stuff so that we get very agile support of different cryptographic algorithms to support it. we get the selective disclosure and all the other things cast know it…

Ronald_Koenig: because we are currently fighting against MDOC SDJ VCs and therefore we summarized all the different benefits of W3C and the whole W3C stack we have including DS including data integrity and including all the other specifications also the diff presentation exchange and so

Ronald_Koenig: No

Recognized Entity Work

Phil_Archer: Have you seen the recognized entity work? Are you aware of what's going on there. I think that might be relevant to some of the use cases you're talking about. what I'm talking about. So, I think it's worth hang on a sec. Is it under VCL? Yeah, it is. So, one of the other task forces which unfortunately meets at a time that you will not like because it's 10 p.m. on a Tuesday night your time. is recognize entities. And that is it's okay. I've got this credential from Who the hell's John? I don't know. he's recognized by this organization over here. All right. Okay. John knows what he's talking about. We can do that. and so that's things like compliance certificates. They get accredited by organizations are able to do that. Phil Archer:

Phil_Archer: In our case, it's a chain of credentials from the barcode on the thing through to the JSON global office that issued all the prefixes and So there's a whole range of times where one credential on its own doesn't amount to a hill of beans.

Phil_Archer: You need to connect it to other things. And the recognized entity work which is going on very actively I think might be relevant to what you're saying. Then there's some

Ronald_Koenig: Yeah, it sounds interesting.

Ronald_Koenig: There's also as the problem what we are. I would definitely take a look on it because in this area we are currently moment where I'm with here we are. because we are currently working with GTC19 is it cast right where we have put that we need in Europe we have the problem that we will not get rid of the Etsy trust list because this is more or less where they have the trust anchor in.

Ronald_Koenig: So that means we have this trust list of list and it is still based on X509 certificates and what we need is how we get from this X509 infrastructure to some DS which more or less providing the abstract interfaces which are usually provided or created it retrieved it and gets the document and such stuff and this is what we need to combine with this X509 and it looks like I will look into it that there's something which goes into the same direction what we are currently dealing with. Yeah.

Phil_Archer: There are 26 mentions of Etsy in that document already.

Carsten_Stöcker: No. I think the recognized entities primarily started with the idea of having authorized trust list.

Phil_Archer: So, we are working on that. there's a couple of substantial PRs ready to be merged in are going to do it. So there's a whole bunch of stuff there. And I think from what you're saying, Ronald, I think that's going to be relevant. And yes, you can use an Etsy trust list because we recognize that times when it has to be or a list like that. but you don't have to

Carsten_Stöcker: They developed it in the direction of the recognized entities and I think what we are doing is adjacent because we have a recognized entity mechanism that an authorized whatever issuer issues identity credentials about an recognized entity and then we put some additional KC company structure Ubu information around this I think it's pretty much building on the recognized entities basic mechanisms from my perspective Yeah,…

Carsten_Stöcker: let's have a closer look and I think was this the recognized entity work kind of started one of the rebooting web of trust activities.

Carsten_Stöcker: one of our other colleagues also contributing to this and I think we can kind of put some scoping how it fits together and I think United Nations transparence protocol D capel is also working on this so there must be some yeah No,…

Phil_Archer: Yes, Steve's very involved in that group.

Phil_Archer: And so there's been, a lot of active work I think it's going to make a lot of progress in the near future. You'll see the shape of it, but some of the use cases you're talking about there are certainly relevant to Yeah.

Carsten_Stöcker: no. Good.

Phil_Archer: Then yes, as Phil Long is saying there, it isn't just about you're Recognized by who to do what? So you are recognized by this authority over here which may be an antitrust list that you are able to do that. So if you have a credential from those people that does that these people say it's okay.

Carsten_Stöcker: Yeah. Yeah.

Phil_Archer: It's that whole ecosystem that we are developing there and I think it's going to be important for what you're talking about.

Carsten_Stöcker: Absolutely. But I think it's pretty much adjacent. Yeah. It can be also a set tiff certificate trust ecosystem can be a market trust ecosystem…

Carsten_Stöcker: where people get market roles and they are recognized entity in a regulated market energy market role ecosystem and…

Carsten_Stöcker: I think that's what it's about. Yeah.

Ronald_Koenig: It's nice.

Phil_Archer: Doesn't m

Ronald_Koenig: It's nice I will look into it definitely because what we currently have is that we have this qualified trust service provider and of course what you say is how can I trust a qualified trust service provider only by it is in the trusted list which then needs to be in our case signed by the European Commission. The nationalists are signed by the European. And of course, we need a statement. What is this trust service provider allowed to do? And this is what we have this Etsy type. So that means for example you are a qualified electronic attestation provider for a certain type of credentials.

Carsten_Stöcker: Get this.

Ronald_Koenig: This is more or less what maps to this one. But it's nice to know that it is more formalized here because I have the other one I have every time the program that it is not really a formalized concept. It is more one idea…

Ronald_Koenig: how we can do it and then put it very pragmatic down to one solution. Nice.

Phil_Archer: There's another use case that you mentioned in passing…

Phil_Archer: but this is not directly relevant to today but I think is relevant to something you just said Ronald. so there's a workshop I'm organizing the week after GDC which is a pain. but that has a whole day looking at What authorization does an agent have to act on behalf of a person? when was it last All sorts of stuff there. speakers for talking about sort of that sort of stuff.

Phil_Archer: We got people from Pho talking various people Meridian Verity Skyfire Mike Jones SD Jot himself is going to be there and…

Phil_Archer: other people's that is

Carsten_Stöcker: in terms of this domain.

Carsten_Stöcker: So we work with lawyers to interpret the legal text in the European Union to identify when there is a delegation. So you have a legal person delegate something or an AI agent. what is the legal act requirements from compliance requirements but then also from basic legal requirements the authorization the delegation the power of attorney what RA mentioned plus how is a transaction intent being established from a legal perspective and as soon as this clear then the technology is there because we have our trust authorization provenence chaining whatever

Carsten_Stöcker: But this is what's going on here in Europe as well that kind of the legal discipline and the technologist are kind of coming together to come up with a legally compliant solution for this. Yeah.

Phil_Archer: Yeah. If your agent spends €1,000 on your behalf and…

Phil_Archer: you didn't authorize it, who owes the money? it's a simple question that that's the thing. So yeah, I'm one of the people organizing that. So that there. So I deflected a little bit there, but I think some of the kind of things that you're working on there as far will be relevant to some of that.

Carsten_Stöcker: Nope.

Ronald_Koenig: Whoops.

Phil_Archer: hasn't come up. as a topic. No, doesn't mean to say somebody won't mention it,…

Phil_Archer: but no one's put it in the position statements that I've read.

Phillip Long: Just in a minor context,…

Phillip Long: a university that I'm working with has an identity graph for all of the different subsystems of record within the institution, of which there are hundreds and there but unfortunately the top anchor node for that is a particular unique identifier which works inside their trust boundary but not beyond that. And so they're now adding a layer on top of that that is didbased and looking at Zcaps as the mechanism of delegated capabilities for the individuals in that larger trust graph.

Carsten_Stöcker: Mhm. Yeah,…

Phil_Archer: Interesting. …

Phil_Archer: have you got enough to be getting on with for another couple of weeks?

Carsten_Stöcker: absolutely. I think we can kind of let's say put a similar document that Carolyn is doing to justify WC credentials for legal person and as WA mentioned we have the same challenges here with regard to SD js and whatever people coming with all kind of different ideas but in the end we don't have task as Phil said it and this is what we need on the control plane and the data plane. Yeah.

Carsten_Stöcker: And for that reason I think we can put something similar together. Then we have the reference piece that's being done in vbuild and with manu we are trying to build something to have to have something very simple in place as an implementation for us and for Europe to demonstrate the two whatever implement implementations but also to justify the value and justify this That's fine.

Phil_Archer: And are you okay with GitHub and everything else? You need any support on that to get you started because we fine. Great.

Phil_Archer: That's Brent sharing this week and I've got next week. soon.

Carsten_Stöcker: And if…

Carsten_Stöcker: if you would like kind of if to do follow-up session on the AI stuff, the delegation, the AI service passports, third party risk management where when I interact for with an AI agent the first time, risk scoring, whatever, let us know because there's this very big ecosystems IPS AI where hundreds and thousands of companies are now spinning up an important project of come European interest for AI and they start to work on this based on European standards and we are pushing for verifiable credentials and this to be used as European standards for it's also universal because of WCC but to reuse the WCC standards for trust AI in

Carsten_Stöcker: this big European ecosystem and I think what's interesting because technology is there on the one hand side a legally compliant trust model needs to be there as well and in this project both is intersecting the European trust model plus the WCC technologies and you want to kind of follow up let us know yeah cool okay…

Ronald_Koenig: All right.

Phil_Archer: All right.

Carsten_Stöcker: then we proceed I guess Okay,…

Phil_Archer: right.

Carsten_Stöcker: guys. Speak to you soon.

Phil_Archer: Thank you.

Carsten_Stöcker: Bye-bye. Cheers.

M.-A._Wolf: Yeah. 58. Meeting ended after 00:53:34 👋 This editable transcript was computer generated and might contain errors. People can also change the text after it was created.

This transcription was generated by a large language model (LLM) and might contain errors. When in doubt, check the audio recording. This page was formatted by scribe.perl version 248 (Mon Oct 27 20:04:16 2025 UTC).