Re: Meeting Notes: A2WF W3C Community Group - Notes from the First Introduction Call

Hello Wolfgang,

Thank you for the warm welcome and the meeting notes.

It's a pleasure to meet you and everyone in the group!

Here is a short introduction to our work:

TrustLayer Foundation A.C. is a Mexican nonprofit civil association that
governs open protocols and specifications. We currently steward ARIA (Agent
Registry for Identity & Authorization) and UCDM (Universal Commerce Data
Model).

ARIA provides cross-organizational AI agent identity. Every agent
self-generates its own cryptographic keypair — the private key never leaves
the agent's environment — and receives a verifiable, cryptographically
signed Agent Identity Document that traces back to the human or legal
entity that authorized it. It requires a signed intent declaration before
any agent touches a system, and supports global revocation in under 60
seconds. Built on W3C DID Core, W3C Verifiable Credentials, and
post-quantum cryptography. Live at api.aria.bar since April 1, 2026. Not
intended to replace any of the current stack, but rather to complement it.

UCDM defines verifiable, structured schemas for commerce data — product
identity, merchant information, and transactional records — designed to
make commerce interactions between agents machine-readable and accountable.
Early version live at ucdm.bar.

From what I can gather after reviewing your documentation, I believe there
may be a natural connection between A2WF and ARIA. While ARIA addresses the
identity and authorization layer (who is this agent, who authorized it,
what does it intend to do), A2WF addresses the receiving side (what is this
website willing to allow). Your latest technical note — requiring agents to
identify themselves before receiving the full policy — is exactly the gap
ARIA was built to fill. We think there is a clean layering story here worth
exploring together.

One specific area we'd like to explore is the relationship between A2WF's
agent identification requirement and ARIA's Agent Trust Protocol, which
handles the identity and intent declaration from the agent side. We think
there may be a clean layering here rather than a conflict, but it deserves
a proper conversation.

Looking forward to it

Adolfo Grego Micha

Trustlayer Foundation

On Mon, Jun 1, 2026 at 8:02 AM Wolfgang Wimmer <wwimmer@ssc-slovakia.com>
wrote:

> Dear all,
>
> Thank you for joining the first A2WF Community Group introduction call.
> Below are the notes, starting with the participants and their backgrounds,
> followed by a short summary of the discussion and the action items.
>
> Link to presentation:
> https://a2wf.github.io/spec/slides/cg-meeting-2026-05-27
>
> PARTICIPANTS
>
> Wolfgang Wimmer (Chair) - SSC Software Sales & Consulting. Background in
> IT and IT security, early AI practitioner. Started A2WF to define what AI
> agents are allowed to do on websites, with a strong security focus. Author
> of the v1.1 draft.
>
> Paola Di Maio - Researcher and analyst, 30+ years following web
> developments, active in several W3C groups. Focuses on mapping and
> connecting the fragmented AI/agent standards landscape, and helped shape
> the direction of the v1.1 draft.
>
> Ankur Verma - Elevance Health (Cincinnati, USA). Software engineer (10
> years) working on backend APIs across mobile and web channels for ~40M
> members. Working on Kubernetes operations, RAG pipelines, a domain
> knowledge base, and agents that act on it. Interested in how agents fit
> into enterprise channels.
>
> Aaron Grego - Trustlayer Foundation (Mexico City). ~20 years in e-commerce
> and the domain industry, runs a gTLD registry. The foundation published
> ARIA (Agent Registry for Identity and Authorization), a registry giving
> agents a traceable, accountable identity tied to a legal entity. Aims for
> an open, free standard, and recently created its own W3C Community Group
> (Agent Identity).
>
> Adolfo Grego Micha - Trustlayer Foundation. Co-founder. Describes their
> work as a holistic trustability approach across three layers: agent
> identification (origin), intent declaration (what it wants to do), and the
> receiving party's policy (whether it is allowed). Raised the question of
> which real initial use cases benefit beyond regulatory compliance.
>
> Gianna Brachetti-Truskawa - DeepL (joined late). Senior product manager
> leading search experience, SEO and organic growth across 30+ language
> markets, with a focus on infrastructure, AI governance and fraud
> prevention. In 2024 contributed an IAB paper on robots.txt, arguing for
> additional layers since robots.txt is voluntary and largely ignored by AI
> in practice. Participating in a personal/voluntary capacity, not formally
> representing DeepL.
>
> DISCUSSION
>
> 1. Introductions. Each participant introduced themselves and their work
> (above). Wolfgang asked everyone to send a short follow-up email with their
> company and project details so these can be compiled into shared notes.
>
> 2. The A2WF framework. Wolfgang presented the agent-to-website framework:
> a JSON policy file published on a website that declares what AI agents may
> and may not do, together with the governance of those interactions. Core
> themes are agent identification, policy fetching, and detection of
> malicious agents. The v1.1 draft is public, with input from Paola.
>
> 3. Regulation as a driver. The upcoming EU AI Act is creating pressure for
> websites to govern agent interaction. Wolfgang has reached out to the
> European Union and NIST, and is building reference tooling (the JSON policy
> file and a compliance/readiness checker).
>
> 4. Overlap and collaboration. There is clear thematic overlap with
> Trustlayer Foundation's ARIA work (identity and authorization) and with
> Gianna's robots.txt-successor work. Each participant approaches the same
> problem from a different angle - identity, governance, discovery - so the
> group sees strong potential for collaboration rather than competition.
>
> 5. *As last note I want to add that there will be change in the technical
> concept, A2WF *will no longer be delivered only by a .json file using the
> file path on a separate http* request but also on delivering details only
> after User agent has identified itself as AI Agent, only in this case some
> details will be provided.
> This enforces the correct authentication of a AI agent in order to be able
> to do things as an Agent. (details to follow)
>
> ACTION ITEMS
>
> - Wolfgang: share the A2WF presentation, GitHub repository and tool links
> with all members.
> - Wolfgang: follow up with non-attendees for their introductions and
> compile all backgrounds into shared notes.
> - All members: send Wolfgang a short email with company and project
> details.
> - All members: read the A2WF GitHub repository and the shared tool list.
> - Trustlayer Foundation (Aaron and Adolfo): review the A2WF specification
> before the next meeting and bring ideas on how ARIA and A2WF could fit
> together.
> - All members: participate in future sessions and come prepared to share
> contributions.
>
> Best regards,
> Wolfgang Wimmer
>
>
>
>

-- 

*Adolfo Grego Micha*
[image: mail trustlayer] *adolfo@trustlayer.foundation*
<adolfo@trustlayer.foundation> [image: sitio trustlayer]
 www.trustlayer.foundation <https://www.trustlayer.foundation/>
[image: trustlayer]

Received on Monday, 1 June 2026 19:13:52 UTC