Hi, thanks for being here today. We're here, gathered here today to talk about private personal AI and verified identity for AI agents. My name is Alastair Johnson. I'm part of the DIF community. I'm also the founder and the CEO for Nuggets, which is a decentralised identity and wallet and trust framework. So what are the identity challenges?
Currently, AI is going from tools to agents. AI no longer just assists, it acts. Agents now transact, communicate and decide on our behalf.
Literally, personal assistants are getting to the stage where you'll talk to it, you'll ask it to do something, it will go off and do it, it will source it, bring it back, pay for it and then order it and send it through. And it's really getting to that level.
But now, when you start to think about that getting into private and personal environments, it starts to get a bit more concerning. So why agent identity now matters? As we know, AI agents access private data and make real world decisions on a daily basis now. They're moving around as we speak. But who are they and can we trust them? These personal assistants are now looking at our medical records, our payment information. We're starting to give more and more accountability. Probably not us here, because we're probably a little bit suspicious of it.
But people out there are already doing transactions in the AI environment. We're already working with partners who've got these problems immediately in this space and time. Because when it starts to become your medical information, it starts to get really serious. So what are some of the risks? Impersonation, deepfakes, synthetic ID scams, centralised control, threatening users' autonomy, tracking correlation through that and no standards and no accountability. We've all heard of the CFOs sending money on behalf of the CEO and then finding out it wasn't the CEO because it was deepfaked.
This is really on the forefront. This is just the early days scenarios. When you think of it coming into play with AI agents and interacting in those environments, it's going to get more serious and they're going to be doing jobs for you in the tenfold. So it's going to quantify the problem far more as we go on. So when you're thinking about customer services and how you're interacting with them, is it the customer service? Is it the bank? Is it the right authority that you're communicating with? You need to know that.
So what we really need is a verified identity and a personal, private AI environment. And with that, user sovereignty. We believe that you should approach it in your personal identity wallet, that you keep your assets, your information, your health information, all in that personal environment. And then when you come to interact, you can engage with an agent.
But first, they're passing you verifiable credentials. They're passing you dids and information. So you know that that is the right source that you're going to. And now we're starting to see passports and driver's licences coming direct from source. The UK are looking at it. Some of the European countries are doing it. America's looking at it as well.
So if you're thinking you're getting your driver's licence from, in the UK, DVLA, or the driver's authority in Europe, and so on and so forth, or your passport's in future getting sent straight to you, this is a world that is becoming faster and more verifiable, because you'll have those verifiable credentials that you can pass them on. But you don't want to be passing those verifiable credentials on to AI agents that you're not assured that they are your bank, they are your doctor, they are your hospital treatment, your insurer, or whatever.
So a friend recently said how he's always wanted his own PA. And he's certainly in a position where he can have his own PA. But he said he was always too embarrassed to send that PA off to the chemist to get his pile cream. So he said he's never going to have a personal assistant. But now you're getting personal assistants that can do it for you in a private and personal environment, truly personal environment, that only your data transfers into their environment and back again.
And so they can do those chores for you, they can transact for you in the future, without passing on that personal information. But you can interact with them, so they act as a service agent. So the problem, AI agents are everywhere. Exploding use in customer service, finance, healthcare, moving from helpful tools to trusted representatives.
The other day, I chatted with Amazon, and I had quite a good conversation, such a good conversation with Amazon customer services, I was led to believe that I was talking to an AI agent, because normally, the customer services will either cut me off, or redirected me and never answered the question. It was so effective, I started to believe that it was an AI agent, but I had no information to suggest that I was talking to an AI agent, had no identity of proof, no verifiable credential to demonstrate this.
Again, when you start to move into finance matters, and healthcare, that gets extremely worrying. So the problem is, you're not ready, we're not ready as a whole, no verified identity for AI exists at the moment, no visibility in how they use our data, and centralised systems are single points of failure, and enable surveillance.
Sometimes you want to know where things are going, and it can be provable, but other times, you don't necessarily be wanting to go to your gaming site, then go to your banking site, and then go to your work site, and then see those points correlated, and have those agents and services that interact with those correlate them either. I mean, we've all seen already, one of the big LLMs, I won't mention any brands, have already spilled personal data all over the internet, and that is right in the early days, and it's only going to get worse as it builds up.
So AI scope is growing so fast, agents now handle, like we say, legal, financial, medical decisions. The stakes are too high to ignore the identity and trust. I want them to be able to do this, I want to be able to interact with these services, book my doctor's appointment, tell them that it's an urgent thing so that I get the appointment quicker, and all these personal things that do it, but what I don't want is little dumps of my personal data left all over the internet that's accessible by other people, and can be used and abused.
We've already seen this on a drastic scale, where it's been happening already. So, personalisation, why we need private personal AI. Personal AI equals your preferences, your rules, your information, your data. Agents that serve the individual's needs, and embed with your values, preferences, and boundaries, and then how they interact with businesses with that. I want my stuff everywhere I go, and I see the common denominator is myself, and in the digital sense, that is my identity, my digital identity, and most possibly my identity wallet, where I can keep that all in one place.
So, centralised AI does not equal safe AI. Privacy risks from mass data aggregation, misaligned incentives, your data, their profit, susceptible to manipulation and misuse. We've seen those data aggregators in the past, where they've pulled them and then sold them on for sources, or they've been breached or ransomed in the past, and it's happening this week especially with some of the other brands. We've already seen it happening, and the use and abuse that is going on.
So, we need to fix it at the core in the early days. We've got a great opportunity. It is moving so fast. I saw yesterday that Microsoft have now taken on agent-to-agent principle that Google have put in place, MCP that Anthropic have put in place, has also moved on to open AI and other systems like that. It is moving at such a speed.
So, we want to get it done early days, privacy by design, in that structure and have a system that's easily integrated and applied, and not sellotaped on and added on to the existing systems and existing systems, because often they've not been designed for what's happening today. So, power to the user, trusted hyper-personalised customer interaction to business, because that's the other point when the user interacts with your business, your organisation, or other people's.
You still want to own and control your data, and that is the same whether it's an individual or a business when you're interacting as well. I saw a talk earlier today where we were talking about building your identity profile as an individual and then how that associates to your business, and how those business identities then interact with the services and what you can do. At the end of the day, individuals and businesses want to keep that data all in their own realms.
So, we're seeing smart processing and storage choices. We're already seeing LLMs and data storage methodologies that can be kept in local environments or in owned and controlled cloud environments. Businesses can have their own LLMs and private tiers. You've seen stuff like Bedrock, AWS Bedrock, and competitor equivalents of that. And also then, obviously, the global. If you've got a public question that goes out to the global LLMs, we're also seeing that these routing systems are already coming into place.
Where you might be asking a health question, it automatically knows which services and which RAG interface it's interacting with so that it can bring back that data and then supply it correctly. We've just seen, I think, two weeks ago, Google Workspace adopt the bring your own key policy.
So, if you're thinking about decentralised identity and how you own and control that private key, suddenly you can have that private key and use it to interact with your Google tools and services and encrypt it. And ideally now, use that so you've got post-quantum encryption. Something we ourselves at Nuggets have already put in place with all the encryption that we do for any personal data.
So, it's only available to that private key holder. So, what we need to be is way beyond the binary consent. Dynamic textual permissions, right to be forgotten, portability, baiting AI design. It needs to be able to cross over through different systems, through one centralised system to another, from peer to peer.
So, these are all opportunities where things like decentralised identifiers and verifiable credentials can be used to establish permissions and rules in how these interact. If an AI agent acts, who's accountable? Trust starts with identity at the end of the day. We're all here on that premise and we know that. But as we heard in the discussion earlier, people are doubting that how easy is it to use? Will people use it? We're still getting phished. It should be in a principle where you don't have to check which link is, check which domain is.
It should come with a verifiable credential that proves that it's from the bank. It proves it's from the business and principles like that. And we verify humans and businesses now with AI in those services, but it's got to be done against strong KYC, KYB as platforms to integrating and having that accountability. At the end of the day, when you're dealing with customer service and if they don't see themselves as accountable, they'll drop the phone on you. If you're transacting with someone and they run off with the money, it's because they're not accountable.
That accountability has to be programmed in to the framework so that people, you know who they are and they can't just run away. So, why verified identity matters here?
Well, the key challenge is, can it do what it claims? Is it authorised to access this? Who's responsible when things go wrong?
Basically, is it legitimate? That's what needs to be proved at the point of interaction with these services. With identity, we get impersonation, we get fraud, we get zero accountability. And that's identity on an individual level, on a KYB level, on a know your agent level as well. What we're doing is we're substantiating that the identity is the individual and that individual works that business and that business has that agent and that is accountable all the way down the chain in terms of doing that.
So, bringing self-sovereign identity to AI. Decentralised trust equals verified and private environments. We're using DIDS to assign unique cryptographically verifiable identity, equip agents with W3C verifiable credentials, and also integrating with OIDC as an integration method. Because this is all based around API interactions and services that are available, MCP.
But what we've actually done, as an example, is we connect through OIDC so you can have token or you can have self-hosted private keys and we establish the DID alongside the token to ensure that then you can go peer-to-peer and you can go outside networks as well in terms of that. So, trust without central control, proof without surveillance. We ourselves always tried and worked with BBS. We can work with other verifiable credentials. But when you're using these tools and open standards that are now available and principles, you can apply it so you can give a proof without being traceable.
You can use zero knowledge proofs to prove your age without giving your date of birth. So, there are the tools that are around there and as I mentioned earlier, one of those tools that help you interface with AI, LLM, storage models and other services is obviously the model context protocol. It's important to be able to work with these, but when working with these, have easy methods to establish those identities of those agents, of those individuals and of those businesses interacting with these MCPs.
So, think of it as a digital passport for AI agents. So, privacy preserving tech that makes it work.
So, tech stack for trust, privacy, local learning, training models, you own and control. This doesn't necessarily mean just on device. It could be encrypted to cloud or distributed storage, but it still has to be GDPR compliant, right to be forgotten, so forth. Confidential compute. If you are doing frameworks and systems within the organisation, do it in a confidential compute environment, so you're not seeing any traffic moving from one point to the other. Differential privacy. Hide individual data points in the crowd, so it has no value or relevance when they're being returned.
It makes sense to build self-sovereign data on local and device and cloud, then have private partner LLMs and layers of global ones thereafter. So, we're real world use cases. We're seeing secure payments. Verified AI handles financial transactions safely. There's thousands and thousands of opportunities where this is, you're seeing some of the big players, Stripe, Adeon, and all the payment systems starting to bring this into play now. Data portability. You need those elements to go with you as an individual, as a business, and your interactions, and with your agents. AI governance.
Sign and enforce digital contracts with verified authority throughout. This is happening now, and it is needed right now, and was needed yesterday.
So, it really is important how we push it forward. So, what it takes to implement. Tech integration, I've talked about some of the methodologies we've used, but at the same time, it's UX. We're interfacing with humans with this new AI agent tool. It's always a service for humans at the end of the day. It needs to be regulation ready. It needs to be GDPR, EU AI Act. It all needs to be compliant from day one, and I believe with all the ability of the current technology available, it can be done as this, and we're actually exercising this with some of our partners and clients as we do it.
And, like I say, industry-specific needs. Finance and healthcare, massive concern. We've seen problems in the past with healthcare, with existing systems.
So, it really needs to be got right from day one. We've got the MCP. We've got agent-to-agent. Like I say, it's gone from Google to Microsoft overnight. This is moving on a speed I have never seen before.
In fact, probably why I've been here, I've missed some opportunities that we should be working on in terms of doing this. So, where are we heading? Near-term milestones. AI identity registries. We'll see those happening, driven by our own brands and services, by governments, by organisations, and then model provenance tools. You want to know that that's the AI agent that works for the bank, the service, and so on and so forth.
And also, open source privacy layers, the ability to use those and work with those networks. And this will become a requirement and necessity as it is right now.
So, just wrapping up the vision, personal, private, verified, user, business-controlled AI agents. Built on trust, not just tech. And that's something that we all have to work with as we move forward in this area. And I feel that more and more of us will be bumping into this on a daily basis as we go forward.
So, we've got to get it right from day one. So, thank you very much. You want to speak to more? Thank you.