Just came from a very, very interesting AI conference in Paris, goes in. I don't know if any of you have been to Station F. There's a lot of very exciting work, I think, going on in terms of how do you produce open AI models, how do you produce open source version of DeepSeq, for example. And one area that I talked about in that conference is how do we give trust to AI agents. So I'm going to maybe do a version of that, but it's slightly less technical, and I hope, I know we only have 20 minutes, so I'm trying to see if I could quickly get the point across.
What I will say may not help your, I think, current business or your current job, but I hope what I say have some meaning to what the future of that business may be. So with that, I want to basically introduce myself. I'm a technologist, I think, by training engineer. My work has been on AI and human trust for last six or seven years now, and the part of work I'm going to introduce today are open innovations that we've been working with open source projects. I'm going to mention two of them. One's called OpenWallet, you may hear that.
I'm a board member at the OpenWallet Foundation, and also a, it's called Innisfoundation Decentralized Trust, A-O-F-D-T, and I work in the group that chairs the AI and human trust working group. So we want to give these agents an ability that we will eventually be able to manage and make, adopt the technology in a way that help our business and our society. So my talk really involves sort of trying to think about in a new language or a new vocabulary, and if you are a developer or engineer, a new primitives. I think those are required.
Whenever you are in today's keynote, there's so-called paradigm shift, right? Tom's cone, which I studied in undergrad, but this is at the moment that we need to use this new language to have a shift. And the way to start with that shift, I think is probably take a peek at some of the new capabilities these agents are able to do. So this one is from Visa.
It's, you know, this is not going to cover it, but basically it's a Visa's way to enable your AI agents be able to do spending for you. Okay, so you are delegating or you're giving your credit card to this AI agent, and for example, the agent will be able to go to shopping for you or book a trip, et cetera, right? So that's a very common example. The next example is from Entropic, and this one is also, I think earlier mentioned, NVIDIA is also saying the same thing.
Basically, you are thinking about some kind of a virtual employee. The employee can do quite amazing work, hopefully, but then, you know, this is, I'm not going to go into the details, but there's going to be a lot of issues, questions will pop up in your mind. I imagine that this employee, this virtual employee is going to be super powerful, know a lot of things.
And to me, I get excited, but also, I think we should all be a little afraid what this is going to do. So I think that just raised the question, and I'm going to use, again, you know, this is the last week in ISA, I don't know if any of you have been there, but Bruce Schneier gave a very nice talk about the security and trust, and so that's come to finally come to my main topic. I think my view is that we need to start from, back away from thinking about security to think about trust.
Okay, so this is his definition. Security is something not being hacked by a third party, while trust is really about the alignment in value. Value alignment is a big AI topic. So alignment in value with the primary parties. If you are talking to an AI agent, it's a question of how much you can tell the agent how much you trust the agent. So that you may be thinking about your doctors, your lawyer, your real estate agents, and some of them are actually called agents, and you have the same kind of issues with those agents.
So to get away, really far away from sort of technology, I like to use this example of Roman emperors. They need security. So what they have is Praetorian guards, so basically the elite military units to protect themselves as, you know, for any threat to their safety and power, presumably. And so the issue is like security, right? People know how to do it, et cetera. But also there's a question, once you have this kind of empowerment or delegation of authority, you immediately create a risk, and that's about alignment of value or trust, what we typically say.
And apparently Roman emperors are not very good at managing trust, because in the next picture, this is the Praetorian guard, in some way, complicated story, but they killed the emperor Caligula, I think, and then this painting is portraying that they eventually picked Claudius as their next emperor. So you can see this power dynamics change, because they have misalignment in value, right?
And so when we think about giving agents more and more things to do, or more knowledge, or more capability or power, we need to know where that risk is, and realign and develop relatively efficient and capable means to manage or control. And so those are fundamental, I think, to the success of any business, especially in our business, which is providing tools so that businesses can do this. So the rest of it is a little bit slide technical. I'm gonna go very quick. I want to see what existing technology architecture look like. I thought the best place to start will be this so-called open API.
This is really, when we say API, we say web services, all of that. Underneath of it is really this architecture, where you have a API gateway, which as an enforcement point, and there are many ways, right? You will know about ORs, you'll know about OIDC, et cetera, that give you the so-called type of vocabulary we can say about how do you provide security. And I'm gonna define that as our security.
Now, the security have a big assumption. The assumption usually is never quite explicitly said, but the assumption is that you will have some kind of a control system, and that's the yellow circle, and also a monitoring system, that's the red circle, typically, okay? And so there are probably a lot more features that in this conference we'll talk about are basically those features, which allow the previous picture to exist and provide some kind of security. And so you can see this is your protecting glass. This is the secret behind it that make the system work. Now you introduce agents.
What are the defining feature of agents? They are autonomous. They don't absolutely listen to you. They are autonomous decision-makers. We can try to limit them, we can try to quantify them, we can try to do all kinds of things, but these are autonomous decision-makers. So the way I think about it is like you work in an environment that you know all your co-workers very well, all of a sudden there's a new boss coming or a new co-worker even coming. What do you do?
You try and be friendly, but you also are a little bit guarded in the beginning because you don't have enough time and reputation to know about this new entity. If the new entity is extremely powerful and knows everything, that's even, I think we wouldn't naturally, intuitively be very cautious. And I think that's the problem here is that the security mechanism does not allow us to think about anything about trust.
And when I mean trust, I know some people, or we commonly use security and trust sometimes in the same sentence as if they are the same, but I'm trying to say we should separate them. If trust is about liability, responsibility, delegations, reputation, those are what we decide do we trust. And security is the mechanism to enforce things.
Okay, so I hope I in some way convinced you to think about that we need a new set of basic primitives that we can use to build these mechanisms so that we can trust AI agents in a way. And for that, I would point to, so this is the Google's agent framework. So you can think of it to like how today we will build agents, right? The MCP is a model contest protocol which is connecting things. It's like the API essentially for agents. And A2A is agent to agent protocol.
So you can imagine with these two protocol give you a prototype of how do you build multi-agent and really fancy and complex autonomous features for that. So the immediate question will come to these two protocols, how secure they are. That's number one. But I would say security is not enough. So we need to enhance that so that we can also talk about trust. And so a very quick review of the work we've been doing in those open source communities in the past five years or so, all these new framework of how do we deal with that. And so I'm gonna go really, really quick. It's short in time.
I prepared this for 30 minutes then I realized that I have only 20. So I think the autonomous endpoints or autonomous agents, right, require some kind of identity that's besides decentralized monitoring and the control system we have built. And that's what autonomous requires. And so this is what I would introduce the concept of a wallet. And this is not new. I think we all kind of understand what a wallet is. So that you enable this wallet to clients, servers, agents, all of those software entities that give them some kind of a sort of definition of what it is.
And the second thing is that we will need some type of identity, very different from the IAM-like identity. But these identity are self-managed by these endpoints. So that also give them autonomy and also a basis for reputation that they will have history. These are not passive softwares. They are decision makers. We need to know how they made decisions in the past that will allow us to have a reputation or evaluation of how to trust them. And we also need a way to do protocols such that the protocols have direction. So trust always have a direction. All our existing internet protocols don't.
They use what we call shared secret. And I would hope you all understand among all of us that shared secret is no secret.
Right, once you share it, it's not a secret anymore. Okay, at least two parties know of them. And so in order to have a clear responsibility is party A or party B's mistake, for instance, you would need that the protocol they're communicating have a direction. And these direction are hard that can be proved. So I'm gonna skip a little bit about authenticity and privacy because these protocol would also allow us to do accountability afterwards. I think you hear previous talk about auditing. Auditing is a evaluation of facts after the event happened.
And we also need some kind of a responsibility. So privacy, we've been talking quite a bit about, but most of our privacy today is a hope. It's a USA, I wish you would respect my privacy. So you don't have direct control over that.
And then, very technical term, we designed the TSP protocol as a open portal like any other internet protocol. It's debated and discussed in open meetings and open organizations. And we wrote a prototype implementation with that in open source projects, et cetera. But the protocol allow us to do layering so that all of your software you have today can somehow magically get these features by basing that into this layer.
So if you think about that this will be a very lower fundamental layer, we are replacing the lower layer so that your up layer, your application, your business don't have to see dramatic changes. But we'll have this capability available to you. So that's the design philosophy of this particular protocol. Okay. So as an example, we're currently working on making the MCP and A2A, probably two of the best known agent sort of communication protocols, so that we'll have a trusted or the TSP-based MCP and TSP-based A2A. And I welcome anybody have interest to try that out. So a quick recap.
When we say my phone has not been hacked, that's security. Most of people, I think, understand that. When I say I'm okay to let my sister Alice to do shopping for me, that is trust. I'm giving her the credit card. I may have some control, I may have some redress maybe, but I really don't have full control. She's autonomous, she can decide to do things that I may or may not mean to, right? So that is what we're dealing with, with AI agents. And then today's APIs are really about security, but not about trust.
We need a new way, and the Trust Binding Protocol, I've been part of working on that, is an attempt to create those primitives so that our software, our business can actually, in the future, build these into your offerings to your customers. Okay, so I'd love to talk to you about how to build more trustworthy agents. You can find me on LinkedIn and anything else. My name's very unique, so it's relatively easy to find me, and I'm open for two minutes for Q&A.
Okay, thank you. Do we have any questions from the floor? Any questions online, Osman? No. Okay.
Well, thanks then. Thank you.