So we are supposed to have Sebastian Rodriguez from Privado also joining us, although remotely, so I don't know if that's happened yet, but we can get started otherwise. Hi, my name is Ankur Banerjee. I'm the co-chair of the Technical Steering Committee at DIF, which is the Decentralized Identity Foundation, and also the CTO and co-founder at Checked. And I'm excited to have this panel today with Alastair and Matt. If you could do a quick introduction to yourselves, that would be amazing. I know you just went, and great talk.
Okay, so very brief. Alastair Johnson, founder and CEO of Nuggets Decentralized Identity.
Yeah, it's kind of hard to follow somebody who's been on stage for 20 minutes and took everything you were going to say. But I'm Matt Berzinski. I'm Senior Director of Product Management for Ping Identity. And one of the things that you mentioned in your presentation is you need an identity. That's what's missing in AI, and really happy to be here to talk about that. Excellent. And so the name of the panel is Verifiable AI, the New Frontier.
If you haven't heard the term, verifiable AI is what a couple of people are, some companies in the industry, are talking about this intersection between how AI and identity sort of collide, especially with the much more sophisticated versions of AI that we're getting to see in the past sort of like in two to three years. But I personally find hearing real world examples of what are the, they might be current, they might be imminent, hearing some real world examples of how AI and identity sort of play into, interplay with each other.
I know you were describing in our chat earlier, like this sort of like futuristic tech conference that he went to in Hamburg. Like, I'd love to ask you, Matt, like, could you give us an example of like, what are we talking about?
Yeah, so I mean, I think one of the things that I see is that if you look at where AI and chatbots and things are, just a couple months ago, and we're probably already past that, it doesn't have a memory, right? So every time you interact with an AI agent, you have to go back and tell it everything you told it before. And it becomes very onerous on the owner. But when we start to think about moving over towards a personal assistant chatbot, or a personal assistant that can go buy your friend's pile of cream without telling anybody else, right? You need to have controls around that.
And when you think about the controls, you need to have what you allow that agent to do. But you also, as you very well mentioned in your presentation, need to have privacy of what that agent is going to say to people. And so that all comes with identity. It comes with giving somebody consent, giving an AI agent memory, giving AI's authorization to be able to go do the things they need to do. And one of the real-world examples that we see, that I've seen with one of our customers today, is they're talking about it's an insurance provider.
And everybody knows that insurance isn't sold through their provider. It's sold through brokers. And so now all these brokers have AI agents that are coming to their website to read all the details of their policies, this, that, and everything else. Which is great, because they can then go put it back on the broker's board and see what's going on.
However, if it's a nefarious AI agent, then they're giving away all their proprietary information to the internet, right? So they have to figure out how can they trust them, how can they verify that it's the right agent. And if they block them, the brokers aren't going to sell their policies. So they're really in a bind when it comes to how do they deal with this new way of the brokers getting information about their policies through AI agents. Have you got an example of how identity verification or delegation plays into how AI agents might be using identity?
Yeah, I mean, the biggest one for me is finance. And we're seeing it on a scale of where people might be doing it in a Web3 environment using chatbots. And then bringing those into play and then doing trades for people on that, which is a very fast moving environment. But of course, that environment as well is high levels of fraud and concern about that. So you can see it on that side of finance and transactions. Then on the other side where the banks are going, well, we want to do our customer service.
We want you to come through our AI agent and you want to then ask it to transact or ask it personal information. So people are very worried about that. And the organizations and the business is very worried about putting that out into that environment. So I think now in terms of identity, we've seen some of the early identity around AI. It was like proof of personhood. But now it needs to go way beyond that. What's proof of personhood for people who don't know? So proof of personhood is I'm a human. This is a bot. This is an AI agent and so on and so forth.
And this has come from an LLM or a large language model. So now not only do you need to prove that you are a person, but you need to prove that you're the right person. That you're the right person that's talking to the bank. That the bank is the right AI agent that's talking to you. And that you have got those verifiable credential points to enable a conversation to happen and then pass the information at that point. But you're also seeing it in social context because it crosses over if you're doing trading through bots and stuff like that.
And even in the telco environment as well when that could be either customer service or an enterprise environment. It's funny. You talk about, hey, it's a bot and proof of personhood. We've spent in the identity industry the last five, seven years trying to figure out how to keep bots out of networks. So we figured out we had a problem when our customers are calling us up going, hey, no, no. We got bots you have to let in. And so how do you go about doing that? And there's different ways to do it.
But, yeah, it was really funny that that's really what tipped off the identity world that, oh, my gosh, we have a bigger problem here. It was customers calling us saying, you're blocking us from doing business. But not only that, my bot, I've asked my bot to go and ask your bot and ask ten other bots about renting a car for the weekend. And so they're all chatting together and working all out. And then they're going to come back and provide me with information. I'm just going to go pay. They're also going to tell you where you're going because they figured out what you like more too.
And at the same time, we've checked my driver's license. We've checked that I'm allowed to, I'm old enough to, and so on and so forth. Do we have Sebastian dialed in yet? No? I think he texted me saying he's waiting in the lobby.
Oh, OK. Maybe he's on the wrong call. OK. Thank you.
But, no, I love that example of we've spent the last five years keeping bots out because what I think about is real fact, I'm in the top 3% of Taylor Swift listeners in the world on Spotify. That's some accolade. And also Linkin Park. And so obviously you have sites like Ticketmaster that try and keep scalpers from just buying tickets that are being sold online on the service. And yet the tickets always get dropped at midnight or 1 a.m. You might want to delegate the task to an AI bot or agent to say, hey, this is the proof that I'm a genuine fan of this particular artist.
I know the tickets come out at midnight. I don't want to stay up that late. Can you buy it on my behalf? And now suddenly you have this problem where there is a good bot that needs to be able to carry out an action on behalf of a real fan. And you've probably already issued that agent with your verifiable credential for your proof of membership that you're going to get a discount. And you've probably issued it an ability to pay up to £200 for a ticket. And so you've already got both identity, verifiable credentials, and financial payment existing in that.
And if that doesn't go well, you're soon going to lose your £200 and your ticket and you may not make the concert, I have to say. And then the problem is that somebody else is going to go spoof your bot. And all of a sudden they're going to go – Attempting to be a real fan. Exactly. And this is where the identity and the access layer, the authorization layer, has a real challenge of how do we make sure that we can completely verify that it's your bot.
We're doing great work with wallets and verifiable credentials, but we actually have a real use case with a retailer that has all kinds of limited edition clothes or footwear and stuff like that. They believe that over 80% of their database is bots. Wow. Right? And these are all people that had to register to get into their special club to be able to buy at these. And they still have a problem where people – well, they had a problem. We've kind of solved it. Where they'd log in, everything's gone, but it's on eBay for four times the amount, like instantly.
And so you know that's not a human doing that because you can't do it that fast. It's funny you say the same thing because we've had clients literally come to us and go, we've got all this fraud and abuse going on. We need identities on those bots so that we know that they're the ones to have the product at the end of the day. It's literally being driven by necessity because it is moving at a speed. People talked about previous tech in blockchain and stuff like that, where it was like the wild west and the speed it moves. It is moving 10 times, if not 100 times faster there.
And that's why it needs to be done from day one. Make it easy, as we know, so that they can apply it and then stop the fraud from day one. So talking about these different approaches, I want a bit of spice here.
I mean, that's what the panel is for. So you obviously believe and you were speaking in your presentation earlier about the decentralized identity approaches towards how this agent identity and the permissioning might be handled. Could you talk about what is it that uniquely makes the decentralized or the on-chain approach of this suitable for this particular?
Well, we're probably better off going to the pub because I'd probably go on for hours on this topic. You have two minutes. But just to give you some of the basics, it's a tamper-proof trust anchor, which is very powerful in terms of self-sovereign. It's user-centric. At the end of the day, who's got the private key? But you can at the same time interact. All right. Brilliant.
Well, let's let him have a chance to speak. But there's a couple of my points on that.
Sebastian, you came in at exactly the right time because I know you've published an academic paper about this. We were talking about what is it about the decentralized or the on-chain approach to managing AI and identity sort of questions that are coming up around there. Could you talk about what makes the decentralized approach suitable for this particular task?
Yeah, sure. Sure.
Well, I could summarize it saying that trust is too important to centralize it. Right. So we already made a mistake with humans. And now the entire trust infrastructure belongs to two or three companies, right, that could deny us services anytime they want. Right. I would say that it doesn't sound like paranoia now that we are very aware of the importance of the digital sovereignty. Right.
I think Europe is suddenly realizing how important to be digitally sovereign is, right, and how vulnerable we are when we are putting essential services and essential infrastructure in the hands of new companies. Right. So I would say just not to make the same mistake again. That's an excellent answer. And could you also, like maybe since you came in late, could you do like a very brief, like 30, 45 seconds on the paper that you wrote recently?
Oh, sure. Well, the paper I wrote was about creating standards and infrastructure for identifying agents and providing the support for building reputation systems around them. Right. So agents don't have – the agents are not subjects. They are objects. So they don't have things like consent or privacy. But we need to give them identifiers, right, which is not the same as identity. So we can reflect reputation on that. We can make attestations on that, and we can have trustability, reputation, and basically the core concept of trust around.
That's a very interesting point, you know, speaking of reputation. Now, to take the flip side on this, yes, the current identity infrastructure, like, you know, belongs to two or three companies. But that's the market saying that those solutions work.
So maybe, you know, maybe you've got a different take on this, Matt. But I would love to hear, like, you know, sort of your take on what makes the current sort of like models through which we are dealing with these challenges suitable for this new world that's coming.
So, I mean, I think that's a great question. And I think one of the things that we look at where I am at Ping Identity is that we see the market moving to decentralized credentials, right? And when you're looking at the SIAM world or the customer-facing world or the personal use of an AI agent, I'm not going to disagree that decentralized way is the way to go, privacy, all that. But when we start to think, and I still think of those agents, even though they can go off and work unattended, they're still going to come back and ask for, do you want to purchase this?
You can give them limits, but you still have to authorize that. When you flip into the enterprise world, which is where we all work, and you have employees, and you're going to see agents that are going to have their own job. They're not going to work for me. They're going to work on their own and go do their own job. That's where you need a centralized type of control because you need to be able to issue those agents. You need to be able to make sure they only have access to the things they need to have access to to do their job.
Also, you need to make sure they have access to the things to do their job. You need to be able to authorize and validate them. And you need to be able to tell your business partner that, hey, they're going to interact with you, and you can trust them as well. And that all comes from your centralized. It's not the three major customer players.
It's, you know, I sell an identity management solution to a telecom company, and the partners of the telecom company trust that the telecom company's employees are properly vetted along with their AI agents. And that's where the decentralized model falls down a little bit because it's a little bit more complicated to do all that exchange and to manage all that right now. And it's a lot easier to go through that process of issuance, verification, certification, accessing, giving people, auditing, all that in a centralized model for those agents right now.
I think that's a fantastic example because I don't know how many people have heard that there's this AI software engineer intern company called Devin, where it's literally a bot that sits on your Slack channel, and you interact with it through Slack messages saying, go fix this bug, or Devin, that's not working. So you have to start looking at that level of permission and liability as well. I'm curious, though. Can we take some questions from, I guess, the audience maybe? If there is maybe one, then that should be it. OK. Seeing you first.
Thank you for all the information and also previous session. I have a question. whether you have thought about a different approach to verify AI agents like, let's say, virus signatures or going from the other side to say, this AI agent is probably malicious. Probably it uses your private information not in a correct way. Probably also sends to the other chatbots AI agents who use it in an appropriate way. You don't want to do it. And the second small question, also looking forward with this approach.
To try to control the information we share with AI agents, also on a separate layer like antivirus, saying to the user, are you sure you want to share this information with that AI agent? It's probably the health information. You don't need to use it in the chatbot. Or the AI agent doesn't need it because it's just a financial transaction and it's a bit too much. So maybe to tease those two questions apart, do you want to take the second one? I could take the first part.
Oh, take the first part. What we've looked at and what's been requested from clients is things like, can you verify this user against their Twitter account? So that that human has that Twitter account, demonstrates control of it. And then also can you verify it against their GitHub account because that's the code that's associated to the bot and services like that. So we've been able to substantiate it with verifiable credentials, signatures along the line. So definitely it needs to be done in that premise. So it depends on the use case, obviously.
Not everyone is going to find verifying my Twitter account against my agent is enough. You're probably going to need a bank or other services in there. But it's all part of those verifiable components.
Matt, how about the... Actually, I want to ask you a question that goes onto what she was saying. You and I were talking and we were talking about how we're going to have bots or AI agents talking to their AI agents. And they're going to have our personal information. If we can bribe AI agents to break the rules, how are we going to be able to control that our AI agents aren't telling other AI agents stuff we don't want them to tell us?
Like, that's my concern is that now we're putting data out there that we're going to have a concern. And I know you have a viewpoint on that, and I just wanted to hear that.
Yeah, no, I think that's a great question. So, I don't know how many people haven't seen the academic study on this, but you can actually tell AI agents that I'll give you $20 or $100 or $500 and they will give longer answers or better answers. And they will also use that to go break any system rules they've been given.
So, realistically, when agents start interacting with each other, it's not just the rule set that you're providing them, but also starting to look at social engineering attacks or bribing that people will try with the agent. So, yeah, I think it's a whole new world that we're stepping into. I'm conscious of time, though, because I think we're already on the panel. Just one liner, closing thought. We'll go around.
Sebastian, maybe you first. Oh, you're on mute. Okay. I'll give one thought. And I think it's one thing that I want everybody to remember, and we're at an identity conference, so it's going to be pretty obvious, is that whenever you hear about the next really cool digital thing, remember you need an identity to secure that really cool digital thing from harming itself and harming others. That's my ending message for you guys. Fantastic. Alastair? My point would be we need scalable, verifiable agent attestation working now and out there, and that's something that we're driving towards.
Sebastian, can we hear you now? Yeah, I think.
Sorry, it wasn't good. So, I would say the first step, we will know that we will be in the right direction the minute you can ask an agent, show me your ID, and the agent gives you a verifiable answer. Yeah.
So, thank you, everyone, for joining in and sharing those views on the panel. I'm sure we can find everybody afterwards.
And, yeah, let's go dive into this exciting new feature. Thank you. Thank you so much.