That's what I'm going to talk about. Authenticity. Authenticity in the Age of AI.
Like, that's why nobody came. They're like, yeah, right. So I'm Grace. I'm from the Decentralized Identity Foundation, which is a standards org like the OpenID Foundation. We're a little smaller and more focused on certain things. And so this is a standard that we're working on that doesn't compete with any of the OpenID standards. Next. And so why are you here? Next.
Oh, I have a no clicker. Oh, I have next. I have this. I press this button. I have the magic button.
OK, so what's in it for you? Right. So we've been talking about the wallets and what are some of the opportunities in wallets. And one of the big missing pieces today, whether it's through wallets or other apps, is if I'm creating content, whether I'm creating Instagram or video or music content, how do I assert that this is really mine? And that's going to be another type of credential that's going to go in our wallets. It's another type of use case that really people aren't talking about.
It's still early days, but this is something that actually is implemented and I think is a big opportunity for the people here today. Great. So I don't need to tell you about fake news or AI slop, but the business cases around this and where it's really hot is where creators are concerned that their material is being ingested by the LLMs. And once it's in the LLM, you can't get it out. You can't say, hey, forget about that novel that I wrote that you just ingested.
There's no way for people to signify, don't ingest this to your LLM, and there's certainly no way to get it out once it's been done. And then the other area is royalties. So if you think about something like music, you've got the musicians, you've got the writers of the music, the lyricists, you've got the recording companies, and they all want to be able to have the right split of their royalties. So these are real business cases, and they're very interesting to a very large industry, the entertainment and news industries.
Oh, yeah, and it's the law. So both in the EU, in California, and in India, we're seeing some preliminary laws that are saying if you produce content and it's from AI, you're going to have to label it. We need to know whether this is real or not real content, and this is just the beginning of legislation. So people are taking it seriously. So what do you want to know about this piece of content?
Obviously, where did it come from? Did it actually come from a camera, or was it produced by AI? Has it been modified? Even if it was produced from a camera, you probably put it through some filters or Photoshop or whatever else you did to it. If you had a video, it's gone through a video editor. So what is the history of modifications, and in what way was it modified?
I mean, it was just a filter, fine, but if you've moved the heads around, who has the rights to it, who has the royalties to it, and then the consent about it. One of the people who's on the standards body who's talking about that is an actor. One day his friend called him up and said, hey, my son just shot you in a video game. He had acted in an action film, and his character must have been the bad guy or whatever, and he was somebody you're supposed to kill.
He's like, I never agreed that my face would be used in a violent game for children. So consent is really a big topic as well, and did I consent to allow this into an LLM? That's just the tip of the iceberg. What did I consent to having my content used for? And then authenticity and vouching. So if I'm a news agency and this article appeared in my news, whatever it was, newspaper on my website, and I validate that this is a real journalist, or I validate that this is something that appeared in my newspaper, that's also a question of who vouched for this authenticity of this news item. Great.
So those are some of the things that you're going to need to attach to your piece of content. And this coalition has already come together, been working for about two years, and already we have a lot of progress.
So C2PA, again, like DIFF, is under the Linux Foundation, and the C2PA is just working about content provenance and what they've created as a framework for a manifest that comes with your content. And already many of the phone manufacturers and many of the camera manufacturers and a few video camera manufacturers will put this stamp in there. So they have a C2PA stamp that says this camera that's owned by this person, they signed in with their biometrics, actually took this picture. And so this is already implemented in a lot of the hardware today.
Not all of the hardware, but a lot of the hardware is already implementing it. Two days ago, Gemini announced, Google announced that Gemini will be recognizing this, so that their AI can recognize that this was an actual piece of content taken from a camera, and they'll be putting stamps in Gemini-generated content saying this was generated by AI. So this is picking up. OpenAI also does recognize this content and create these types of things. This is already being picked up.
The next part is COG, which is where I come in and our working group, and our working group is working specifically on creator assertions. As the creator of this content, what do I assert about it? Can it be used by LLMs for input? Can it be used in violent games? Can it be used for, you know, reused copyright use? What are the royalties attached to it? I can assert all kinds of things about my content, and that's what's under discussion right now.
And so right now, as we're establishing the standards, we're looking for people who want to put in input about what types of assertions need to be done, and how do you do delegation, and how do you do royalties, and what types of certification authorities are we going to have. So again, this is a real opportunity for people to step in and establish these standards on behalf of the users or on behalf of themselves if they're a particular type of organization.
The Content Authenticity Initiative is an advocacy alliance, and as you can hear from the type of organizations that have already implemented this, they're doing a good job with the advocacy. The International Press and Telecommunications Council, obviously extremely concerned about the authenticity of the news media, and they're also part of this coalition, and JPEG Trust Foundation, which has trust in media stuff, so familiar to a lot of you. This is what a manifest looks like.
Of course, the assertions, like I said, that's what I'm emphasizing today because we're still in deliberation. That's a very open working group where you can have a lot of say in it. But basically, it says all the things you said. This is the piece of media. This is what I claim about it. It went through this type of software, applied these filters, all of the claims. What you're going to see on a piece of content is a chain, as I mentioned, with music.
The chain might be the lyrics were produced by this person, the music was produced by this person, this studio did the production work on top of the music, it was remixed in this type of machine. You have a manifest that has all of these chain of events that happened to this.
Obviously, things can be stripped, but as this becomes more and more of a standard, when, let's say it's an LLM or social media or any type of authority gets content that has been stripped of this type of manifest, there's something suspicious here because it doesn't have its manifest. Just like today, that's why they're calling it a manifest. If you pull in with your ship to a port and you don't have a manifest of where these goods came from and what they are, it's like, I'm sorry, you can't unload it here. This is the same structure that we're looking at for content.
You can imagine a world in which you could either filter by yourself, like, I don't want to see anything that doesn't have this type of manifest, or where social media says, listen, we're not going to put anything on our platform that doesn't have at least these types of manifests. It's not here now, that's one of the gaps, but you can start to see it. A lot of you remember that we used to get a lot of spam and now we don't. It's not because there isn't spam in the world. 50% of the emails sent out there are spam, but you don't get them because now we can identify it.
That's the direction that we're going with this AI slop. Right now, it looks impossible.
Like, oh my goodness, somebody can impersonate me and make it seem like I said something, but these types of manifests will be able to handle that. Again, there's some other pieces. Where are we today? As I mentioned, we already do have major camera manufacturers, video manufacturers. We have Adobe, so you can use the Adobe Suite or something called the Adobe Content Authenticity App, and you can put content assertions on there.
For now, the assertions that are implemented are just whether you can or can't use it for LLM ingestion, but as I said, a lot of other things are being discussed in the working group. One of the guys was like, I don't want my likeness to be used for hate speech, but is that implemented in the law? That's another question, right? So that's a gap. You can say, I don't want this implemented, and I don't want CLUD to ingest this, but Anthropic hasn't implemented that, and OpenAI and Gemini have implemented that.
So these are happening in real time that these different types of softwares are able to recognize these manifests. In development, again, there's a bunch of different types of identity credentials. So do you want to signify that you're an authorized journalist, or do you want to signify that you are an actual production studio? We're still working together to figure out what types of identity credentials we want, what types of rights frameworks, what types of assertions. All of those things are under discussion, and where are the trust registries going to be?
Obviously, they're going to be different trust registries. You can imagine the different types of news outlets. There might be the conspiracy theorists unite news authenticity outlet, and that's legitimate in a free speech world, but you and I might not want to subscribe to those credentials. And there's some really big gaps. So right now, as you can imagine, it's a standards body. We don't have TikTokers who've come to DIFF to be on a standards body about creator assertions.
We're counting on wallet providers and other organizations like that to come into here and represent those creators, because there is a market need. Those people are using their software to make transactions around their content more often than they're doing financial transactions. So if you think about the size of this market, we really want to have organizations that can represent those creators. And like I said, the wallet providers seem to be potential. We're going to need acceptance networks. That's going to take time. We're going to need the regulation and the enforcement coming along.
That's going to take time. And there's always going to be certain kinds of attacks that you can make. So you can take a screenshot of something, and you can strip things of their assertions. Whether technically we'll be able to actually stop all of that kind of copying, I don't know.
I mean, you can type in somebody's novel into your Word document, and then you are the original writer. I mean, that's not going to stop. But we're still working on what are some of the security things that we can put in here. So where is my assertion wallet? These are the organizations that are now participating in COG. And like I said, COG is a working group of the Decentralized Identity Foundation. And the Decentralized Identity Foundation is a proto-standards body. And our standards tend to start with us and then move into W3C, move into IETF, move into ISO.
But we're working together now because this is moving fast. And so that's why these organizations have come to DIF, because they can't spend two years inside of ISO until this comes out. They need at least a proto-standard that they can use today. And as you can hear, it is being used today. We have some large enterprises. Adobe is heading up this thing. We have some AI organizations, large AI organizations like Kindral, who have joined DIF to participate in this effort. We have some professional coalitions.
So some of the people coming from the recording industry, from the newspaper industry, from the music industry. And these represent some of those artists. But those are the labeled artists, right? We're not talking about podcasters. We're not talking about the individual TikTokers. We're talking about enterprises. And of course, Android, Adobe, OpenAI are using this. IPTC on behalf of the broadcasters. For some reason, we do have some individual actors. I don't know why. There's a couple of actors who came in who are individuals who are representing themselves as actors.
But we don't have any of the major studios. Bollywood or Hollywood studios are not there. So that's a gap. We're looking for more representation. We don't have any wallet providers. We don't have universities.
I mean, when we're talking about content and the validity of content, research content is really important. So we don't have universities yet that are on there. Although one wrote to me this week. And some of these independent media people. So these are the opportunities and the people that we're looking to join the coalition so that we can make sure that as we provide these content assertions, they're going to serve everybody. And here's some of the things that might be your role. If you're a wallet provider, you might join.
You might start developing this stuff on your wallet for creators to use. If you're in the regulatory organization, one of the gaps that I didn't put on there is this is not part of Apple. And a lot of creators are using Apple.
However, when they start to have to comply with these European regulations, they may need to put something on there. Now, you could put an app on your Apple. You could put an app on your Apple phone on your iOS, but it's not the same as if the hardware were to assert this. So pressure from regulators, pressure from anybody who can from the creators about making sure that their content is going to be marked as their content. That something needs to be done. Certification is a major issue. The recording labels have told us that they do need certifying agencies and we're a standards body.
We're not a certifying agency. So there's definitely an opportunity here for people who do certification. And trust anchors, which maybe they'll be government trust anchors.
Like, how do you know where the registries are? That's another thing that has been developing. There's a coalition called IRA coming together around being trust registries for this.
And again, that's a business opportunity. And this is myself. This is Eric from Adobe, who's one of the co-chairs of the working group. We're happy to have you. Yeah. So thank you very much. So the big question is, have you got any questions? We've got time. I always leave time. One.
Okay, well, I'll ask a question. Okay, good. So clearly, the standards are important. But of course, there's another dimension, which is a legal dimension. And how does this relate to copyright? And what is your comments on the legal enforcement?
Yeah, so this is, of course, standards don't don't just because there's a standard just because you say you can't use my content doesn't mean somebody doesn't use your content. So enforcement is a really huge, important thing. And as I said, we're starting to see at least legislation. I call it legislation because regulation would imply enforcement as well. So we're seeing the legislation around this. And I think that one of the things that's going to happen is that there's a lot of pressure on these organizations.
I mean, there isn't a person in the world today who doesn't feel the stress about, is this true? What do I see on the internet? Is this true? And so this coalition has come together even before there's real legislation or enforcement on this, because it's a problem for everyone. And despite the fact that these large AI companies, in some ways, don't have a business interest in this, because people are just using this stuff like bonkers. It's great. And it's bringing a lot of traffic. I think even for them, it starts to be beyond what they want to handle.
And that's why we're starting to see a lot of legislation. So we're seeing OpenAI and Google taking the lead in this. And once they've started to say, we're not going to put up with it, even before the legislation and the enforcement is in place, we are seeing that as a real issue. So there's a real, like a real need, a real desire for people to do this. Okay. Any more questions?
Well, so I'll ask another one. So I'm sure that as a security geek, I've always turned off all the metadata on my phone, because I don't want anyone to know where I took that picture that I took it. So how do you deal with the conflict between privacy and publication and signing of things?
Well, I mean, this is a question, right? But it's also one of the reasons why there's been this tension with Apple. It's not that Apple is the bad guys, and they don't want C2PA assertions on their phones. It's because they say the user has privacy, and we're not going to create a situation where every single thing that they create is known to us. So it's a real tension. I don't know that there's any simple answer to how do you do that. But obviously, for the people who are the creators, they want that.
So me, as somebody who sends a message to my mom or a cute picture of my, I don't have babies at this point, they're kind of big, but a picture of my baby or whatever it is to my mom, I don't need a creator assertion. I mean, maybe I will. That's the scary part, right? Maybe I will need a creator assertion just to send a signal message to my mom that this really is me. But generally, I won't care. But the people who are making a living from music and from video or whatever, they're not turning off the metadata. It's by choice.
I brought that up because in the UK at the moment, there is a concern that school photographs of children are being manipulated by Gen AI for child pornography. And this is the kind of problem.
Now, I don't know whether having a provenance on that would help to find and prevent or whether, in a sense, you really want to be able to totally prevent certain kinds of things for being used for certain ways. To some extent, you've got that. But it depends upon consent. This is a specific application. But I mean, the truth is that pornography and that type of thing will be reduced by punishing the perpetrators, the actual people who watch the pornography. And we're doing it the backwards way.
I won't make a comment about why it is that we punish the people who are publishing pornography and not the people who are consuming it. But I think we all know the reason for that. If you are in a struggling country, maybe you don't want the content you produce to be trustable to you. And that's Apple's privacy position. A journalist wants the photo he takes to be his own photo because he wants to be credited for that. And in some struggling countries, we know very well, they don't want to be traced to the fact that because they play their life in taking some photos.
And I think there's a lot of questions about also about freedom of speech, like where do you draw the line between art and pornography? And I don't think that our current framework of thinking is adequate for a digital world.
And, you know, it used to be that stories were meant to be told over and over again and passed on and you didn't, you know, like there's there's sort of a financial incentive. It used to be, you know, you'd pass on a story from generation to generation. There isn't a copyright on the Bible. And so we're living, there's a very deep conversation to be had here, which we're not going to have today. Thank you very much.
Yes, thank you very much.