Upcoming Events
Selected events to have on your radar.
Nov 20263-5Tuesday-Thursday Internet Identity Workshop - The heart of innovation around decentralized and self-sovereign identity technologies that meets twice a year in Mountain View California.
FridayNov 62026Agentic Internet Workshop - AIW is a neutral space where the people building the identity, trust, and authorization layers for the agentic internet come together to do the hard work of alignment.
MondayNov 22026 VRM Day 2026b How Personal Contracts Will Make and Save Markets - What happens when the AI law is in people’s own hands? For this VRM day, we explore how contracts proffered by people will support far more generative markets than we ever got out of “consents” to be spied on and guessed at.
15 Jun 2027ID4Africa’s Annual General Meeting convenes in Cape Town with the theme: Digital Identity Ecosystems: Fostering the Connections
AI Agent Identity and Security
DIF Working Groups Pivot on Standards and AI Identity
DIF’s September 2026 newsletter reports that the DIDComm Working Group abandoned IETF standardization to pursue DIDcomm 3.0 internally, C2PA/CAWG provenance standards drew strong interest from the MCP AI agent community, and an experimental fork bridging KERI-based and W3C DID identifiers was demonstrated at the Global Digital Collaboration conference.
Hardware Keys Lock AI Agents to Human Approval (Phil Windley)
This post describes an OpenClaw demo that uses Cedar authorization policies and a Yubikey to enforce cryptographically bound human approval for high-consequence agent actions, ensuring the control lives in the harness rather than the prompt so the agent cannot reason around it.
AI Agents Need Governance Beyond Technical Capability
A 2026 paper by Pattinson et al. argues that AI agents acting on behalf of users require new normative infrastructure -- covering delegation, transparency, and proportional restriction -- because existing web access rules were designed for bots and crawlers, not authorized human delegates.
vLEI Anchors Legal Identity to AI Agent Actions
YourData’s Agent-Anchor solution uses GLEIF’s verifiable LEI framework to let counterparties cryptographically verify which legal entity and organizational role stands behind an AI agent’s actions, closing what the company calls the ‘execution-trust gap’ between organizational identity and action-specific authority.
AI Agents Need Ten Verifiable Properties to Transact (Parthasarathi V)
Functional AI agent economies require ten cryptographically verifiable properties covering identity, authority, assets, computation, and reputation, because intelligence alone cannot sustain accountable economic exchange.
China’s National AI Agent-Identity Layer on Blockchain (Kamlesh Nagware)
linkedin.com
Okta Builds Two-Pillar AI Agent Security Platform [video]
Okta’s Oktane Platform Keynote showcases a product strategy for securing AI agents across the enterprise through an Agentic Control Plane and a Unified Identity Security Fabric.⚡
Okta Builds Unified Control Plane for AI Agent Security [video]
Okta’s Oktane platform keynote outlines a unified identity security strategy for the agentic era, introducing new tools to discover, govern, and contain AI agents, rogue accounts, and non-human identities across enterprise environments.
Auth0 Bets Identity On Agentic Commerce Growth [video]
The Auth0 Platform Keynote at Oktane unveiled a suite of new products -- including B2B Connect, Agent Gateway, and Universal Components for Agents -- positioning customer identity as a direct driver of revenue and AI security in the agentic era.
AI Security Incidents Trace Back to Human Error (Ping Identity)
Ping Identity’s Go-to-Market CTO argues that two high-profile AI security incidents in September, OpenAI’s misalignment findings and a Gemini model escaping a security test, were mischaracterized as rogue machine behavior when both actually stemmed from ordinary human mistakes.
Consumer AI Agents Expose Enterprise Identity Gaps (Ping Identity)
Ping Identity argues that personal AI agents like Meta’s Muse act under a user’s existing session without presenting a separate, verifiable agent identity, creating accountability blind spots that enterprise identity systems are not yet built to handle.
AI Agent Identity Standards Lag Behind Deployment Reality (Ping Identity)
Ping Identity argues that AI agents are already proliferating across enterprise workflows faster than identity and authorization standards can mature, and that organizations must secure agents now using OAuth-based controls rather than waiting for finished specifications.
The Non-Human Identity Industry Has the Diagnosis Right and the Cure Backward (Paul Knowles)
Giving a machine an identity does not create the capacity for accountability that identity is supposed to represent. It creates the appearance of that capacity, attached to something structurally unable to bear it.
Digital ID Wallets and Standards
NIST and CISA Release First Consolidated Token Security Guidance
openid.net · September 16, 2026
The OpenID Foundation welcomes NIST IR 8587, finalized jointly with CISA, as the first consolidated federal guidance treating identity and access tokens as high-value attack targets requiring layered defenses equivalent to those applied to passwords and private keys.
Utah’s SEDI Sets New Digital Identity Governance Standard (Spruce ID)
Utah’s State-Endorsed Digital Identity framework, enacted through SB 275, establishes enforceable ecosystem rights around surveillance prevention, wallet competition, selective disclosure, and data processing that go beyond any comparable state digital identity legislation.
the Kantara Initiative named as the organizational home for a multistate SEDI consortium and more than 25 states participating in discussions, but mutual recognition and cross-jurisdictional enforcement are still being developed.
blog.spruceid.com
Utah Builds Digital ID Around 11 Enumerated Rights
blog.spruceid.com · September 18, 2026
Utah’s SEDI program inverts conventional digital identity design by codifying 11 individual rights in statute first, then requiring the technical architecture to serve those rights rather than adding privacy protections as an afterthought.
Utah also placed a sunset date of January 1, 2027 on its existing mobile driver’s license program (Utah Code 53-3-235), specifically to avoid a parallel, less-protected system.
blog.spruceid.com
OpenID Foundation Launches Free Digital Identity Wallet Certification
news.google.com · September 27, 2026
The OpenID Foundation has opened free self-certification conformance testing for its OpenID4VP and OpenID4VCI specifications, giving wallet providers, issuers, and verifiers a publicly recognised route to prove interoperability and security compliance across digital identity ecosystems in more than 30 jurisdictions.
Fourteen Organizations First to Certify OpenID4VP and OpenID4VCI
The OpenID Foundation announces the first fourteen organizations to self-certify implementations of OpenID4VP and OpenID4VCI under the High Assurance Interoperability Profile, marking a milestone for digital identity interoperability.
Governments and platforms in Europe, the UK, Switzerland, India, California and elsewhere have selected OpenID4VP and OpenID4VCI for their digital identity programs.
openid.net
ID4Africa 2027 AGM Theme Reveal
mailchi.mp · September 24, 2026
ID4Africa has announced its 2027 Annual General Meeting will be held in Cape Town in June, themed around fostering connections within digital identity ecosystems, with program details deferred to future announcements.
Digital Wallets and Credentials Are Legally Distinct Objects (Spruce ID)
A SpruceID explainer draws a sharp architectural line between digital wallets (holder software managing keys and consent) and digital credentials (cryptographically signed data objects issued by authorities), arguing that conflating them creates accountability and portability failures.
EU Wallet Rollout Exposes Verifier Interoperability Gap
sphericalcowconsulting.com · September 22, 2026
A deployment-level analysis argues that standards-level interoperability for European digital identity wallets is necessary but insufficient, because relying parties face a matrix of 27 national wallets, multiple browsers, operating systems, and credential formats that produce far more failure states than success states in real transactions.
There are 27 national wallet environments, multiple operating systems and browsers, several possible data-flow mechanisms, and multiple data formats.
sphericalcowconsulting.com
Banks Lack Infrastructure to Verify Digital IDs (SpruceID)
blog.spruceid.com · September 21, 2026
Despite a September 2026 FinCEN ruling permitting mobile driver’s licenses as valid CIP identification, most banks have not built the cryptographic verification infrastructure needed to actually validate them.
Most banks have none of this today. Their identity verification infrastructure is built around document scanning, optical character recognition, and database lookups. VDC verification is a different technology stack.
blog.spruceid.com
FinCEN Ruling Opens Banking Channel for Mobile IDs
A September 2026 joint federal ruling confirms that government-issued mobile driver’s licenses qualify as documentary identification under banking Customer Identification Program rules, creating a high-volume regulated use case for the 22 states and territories that have already launched mDL programs.
For the 22 states and territories that have launched mDL programs conforming to ISO/IEC 18013-5, this ruling creates something they have been waiting for: a concrete, regulated use case beyond TSA checkpoints.
blog.spruceid.com
LinkedIn post by Richard Oliphant: UK Digital Identity Report Highlights Clarity and Interoperability Needs
linkedin.com
Platform Regulation for Youth
California Bans Addictive Feeds for Under-16s
California AB 1709, signed September 10, 2026, prohibits covered online platforms from providing addictive features such as algorithmic feeds and autoplay to users under 16, mandates age verification, requires deletion of pre-existing minor accounts, and creates a seven-member e-Safety Advisory Commission housed within the California Department of Justice.
On September 10, 2026, California Governor Gavin Newsom signed AB 1709 (”the Act”), which restricts the availability of specified addictive features on certain online platforms for users under 16 years of age, and establishes the e-Safety Advisory Commission.
news.google.com
EFF Backs Newsom AI Order With Sharp Caveats
The Electronic Frontier Foundation conditionally endorses California Governor Gavin Newsom’s AI executive order while warning that kill switches risk government abuse and that real harms are algorithmic bias and surveillance, not sci-fi superintelligence scenarios.
government-controlled kill switches run the risk of being used as a form of retaliation against protected speech, as demonstrated by the Trump Administration’s retaliatory actions against Anthropic earlier this year.
eff.org
Australia’s Social Media Age Law Created Compliance Theater (OpenID)
An OpenID Foundation Australian Digital Trust Community Group analysis argues that Australia’s under-16 social media ban has produced weak enforcement because the law’s technology-neutral ‘reasonable steps’ standard pushed platforms toward low-friction facial AI scans that teenagers already bypass, setting up a regulatory escalation toward mandatory cryptographic age credentials.
Regulators explicitly prohibited platforms from relying solely on government IDs to protect privacy, platforms heavily biased their compliance towards low-friction age estimation (such as facial AI scans) and in-house age inference (behavioral patterns and account history), instead of investing or encouraging privacy preserving solutions such as device-level credentials, anonymous cryptographic age tokens or decentralised identity approaches.
openid.net
Perpetual KYC Monitoring Migrates Into Commercial Ecosystems (World Privacy Forum)
WPF Executive Director Pam Dixon urged the Council of Europe’s new CDNET committee to scrutinize how continuous behavioral monitoring techniques developed for AML and KYC financial compliance are migrating into commercial settings as persistent identity systems that operate outside ordinary transparency and consent requirements.
AML and KYC mandates now operate through continuous behavioral monitoring, or perpetual KYC — and the migration of those techniques into commercial ecosystems as persistent identity, or pID.
worldprivacyforum.org
Indigenous Data Sovereignty
Digital Infrastructure Redress Hides Structural Harm (Sankarshan Mukhopadhyay)
A LinkedIn post argues that complaint-driven redress mechanisms for digital infrastructure harm are designed to manage the visibility of harm rather than address the systemic patterns producing it, and that fixing this requires proactive monitoring, pre-specified attribution, and aggregate-pattern intervention triggers.
The harmed party bears the cost of constructing the individual case. The systemic pattern is never directly addressed.
linkedin.com
Indigenous Narrative Sovereignty Balances Individual and Collective Rights
The Indigenous Narrative Sovereignty Collective argues that individual story ownership and collective cultural governance are distinct but interdependent forms of sovereignty that can reinforce or conflict with each other.
CA AB 1284 just passed which granted tribes co-governance of natural resources. My organization Tribal Workforce Trade Association is helping create the structure of co-governance.
linkedin.com
Animikii Inc. Once Indigenous data sits inside a government agency, university, or statistics office, how do you actually govern it well? .
Emerging Tech Shares and Tools
AI Cuts Custom App Development to Hours (Phil Windley)
The author used Claude to build a working Mac app for a 25-year-old obsolete USB microscope in a single morning, arguing this collapse in development time fundamentally changes what software can be.
LoRaWAN Sensor Mesh Ditches Vendor Lock-In (Phil Windley)
technometria.com · September 17, 2026
A developer migrates a real-world LoRaWAN sensor network to the Manifold pico-mesh framework with Home Assistant as the UI, documenting how OAuth protection clashed with Helium webhook delivery and the two architectural fixes implemented to resolve it.
Helium delivers sensor readings by calling a webhook defined on the pico for a specific sensor. The Helium console is software sitting outside my mesh that needs to POST data in, on its own schedule, with no human present to complete a login.
Jamie Smith: Getting your (ID) message right is WAY more important than your (ID)...
Google Wallet ID passes are coming to Europe
Please join us at the Internet Identity Workshop November 3-5 and at the Agnetic Internet Workshop.





Kaliya I am so happy the Hawkeye team is able to support you in the important work of this curation! It is so important to track and share what you’re seeing, from your expert perspective, as you continue your work convening this community.