[MINUTES] CCG Atlantic 2026-09-15

CCG Atlantic Meeting Summary - September 15, 2026

The CCG Atlantic meeting on September 15, 2026, featured a comprehensive
presentation by Leonard Rosenthol from Adobe on the C2PA (Coalition for
Content Provenance and Authenticity) and its content credentials
technology. The discussion delved into the technical specifications of
content credentials, including their structure, cryptographic signing, and
trust models, as well as the complementary COG (Creator Assertions Working
Group) for identity assertions. The adoption and application of C2PA
technology across various platforms, devices, and government agencies were
highlighted, alongside a detailed Q&A session addressing adoption, trust
frameworks, and pricing for certifications.

*Topics Covered:*

   - *Introduction to C2PA and Content Credentials:* Leonard Rosenthol
   introduced the Coalition for Content Provenance and Authenticity (C2PA) and
   its core technology, Content Credentials, which cryptographically binds
   factual information about an asset, making it tamper-evident. The system is
   designed to be flexible, supporting various stages from content creation to
   consumption.
   - *Technical Specification of Content Credentials:* The presentation
   detailed the structure of content credentials, including assertion stores,
   claims, and digital signatures, and explained their compatibility with
   standards like JUMBF and ISO BMFF. The use of X.509 certificates for
   cryptographic verification and the C2PA's trust list model were also
   covered.
   - *Generative AI and Content Provenance:* The significance of C2PA in
   identifying AI usage in content creation and editing was emphasized,
   including the ability to specify AI involvement in specific regions and
   temporal aspects, as well as supporting "do not train" stipulations.
   - *COG and Identity Assertions:* The role of the Creator Assertions
   Working Group (COG) was explained, focusing on its enhancements to C2PA,
   particularly in identity assertions, allowing for verifiable credentials,
   social media accounts, and potentially agentic identity. COG enables
   individuals and organizations to take responsibility for specific aspects
   of content while supporting multiple identities.
   - *C2PA Adoption and Usage:* Examples of C2PA's adoption were showcased,
   including social media platforms like LinkedIn, TikTok, and Meta, as well
   as government use cases like the US Department of Defense, and its presence
   on devices like Google Pixel and in tools like Dash.js and XF Tool.
   - *Trust Frameworks and Certification:* The discussion clarified C2PA's
   trust model, which relies on standard Certificate Authorities and a C2PA
   trust list for hardware and software conformance. The pricing and
   availability of conformance programs and certificates were addressed, with
   the conformance program itself being free, while certificate pricing is
   subject to market evolution.
   - *Redaction and Versioning:* The possibility of redaction for content
   credentials was discussed, noting that while new versions can be published,
   previously distributed credentials cannot be retroactively removed. The
   responsibility for managing authoritative versions was acknowledged as
   lying with implementers, not the C2PA standard itself.
   - *Future of COG and Decentralization:* The evolving nature of COG and
   its approach to identity, including potential for decentralized trust
   models and registries of registries, was discussed, with an invitation to
   participate in relevant working groups.

*Action Items:*

   - Leonard Rosenthol to share his presentation with the CCG mailing list.
   - Harrison Tang and other interested participants to consider joining
   the COG working group within DIFF to engage in discussions about trust
   registries and decentralized identity.

Text: https://meet.w3c-ccg.org/archives/w3c-ccg-atlantic-2026-09-15.md

Video: https://meet.w3c-ccg.org/archives/w3c-ccg-atlantic-2026-09-15.mp4
*CCG Atlantic - 2026/09/15 12:00 EDT - Transcript* *Attendees*

Alex Higuera, Benjamin Young, Brent Zundel, Calendly Nоtеtаkеr, Dmitri
Zagidulin, Erica Connell, Grace Rachmany, Harrison Tang, Hiroyuki Sano,
JeffO - HumanOS, Jennie Meier, Joe Andrieu, Lancine Toure, Leonard
Rosenthol, Mahmoud Alkhraishi, Maxime Mansiet, Phillip Long, Ted Thibodeau
Jr, Will Abramson
*Transcript*

Mahmoud Alkhraishi: Hi We're just going to give it another four minutes
before we get started.

Mahmoud Alkhraishi: All right. let's kick this off. thank you everybody for
joining us. It is Tuesday, September the 15th. we're on our weekly CCG
meeting call. Code of ethics and professional conduct reminder. We have a
code of ethics that we request everybody adhere to. You can find it on our
website. And as an IP note, anybody can participate in these calls.
However, all substantive contributors to any work of the CCG must be a
member of the CCG with full RPR agreements signed. do we have any
announcements that anybody would like to make? I am not sure who this note
taker Is this a person or this is a bot, right?

Ted Thibodeau Jr: Yes, that is a bot.
00:05:00

Mahmoud Alkhraishi: Okay, let me try and kick that off. Give me a second.
while I do, does everybody have any announcements they would like to make?

Mahmoud Alkhraishi: Okay, hearing none. we have Leonard Rosenthal today to
present to us on the C2PA. Leonard, would you mind introducing yourself
quickly and…

Mahmoud Alkhraishi: walking everybody through what you do and then through
your presentation?

Leonard Rosenthol: Great. yeah,…

Leonard Rosenthol: happy to do So I know a number of you from many other
meetings in the W3C and elsewhere. so I work for Adobe as my day job. I
have a number of responsibilities there, but the ones I'm most well known
for, I have been Adobe's PDF architect for just about 30 years now. and
since 2019 when Adobe started what you're going to hear about today or what
you're going to hear about today, I have been leading the content
authenticity architecture as well within Adobe and then the C2PA itself. So
that's who I am.

Leonard Rosenthol: and again I've been a member of the W3C and involved in
standards here for I don't know 20 years give or take in various groups.
but let me talk this out and those of you who know me I am happy to take
questions at any point in the presentation. just raise hands, jump in. I'm
pretty easy. All right. So we'll talk about really the technology itself
more the organization is the coalition for content provenence and
authenticity. and our technology that I'm going to talk about is content
credentials. So let me dive in here. So the organization itself we were
founded in 2020. we currently have 11 steering committee members.

Leonard Rosenthol: as you can see their logos there. we are part of the
Linux Foundation JDF and we also have over 500 general and contributor
members. and any standards body, some of them are more active than others.
we also do our work actually very similarly to the W3C in terms of
utilizing GitHub asynchronous communications. we do however hold regular
meetings again not unlike this and we break down into a technical working
group and about a dozen task forces and task forces come and go based on
the topics that they're focused on and we can talk more about that if
you're interested. so what do we focus on? We focus on content provenence.

Leonard Rosenthol: provenence being the set of basic facts about an asset
that are cryptographically bound to that asset and tamper evidence. So this
could be how and why of the asset, its process, creation, editing,
publishing. it's certainly in the last few years whether or not AI was used
and where becomes very significant. We'll talk a little bit about that. so
at the end of the day we enable people, organizations, entities, hardware
to declare what's going on rather than consumers having to guess
information. And as mentioned, we sort of talk about this as glass to glass.

Leonard Rosenthol: The idea of course being that and it does not have to
be. this is sort of the rainbow and unicorn world. if we can go all the way
from capture to view, creation, editing, publishing, and then consumption.
but you don't have to start all the way at the beginning. You can have gaps
along the way. that's all perfectly acceptable. we also of course recognize
that there are billions and billions of digital assets created long before
we came into existence. you may want to associate a content credential and
provenence with those existing assets. so the system itself is extremely
flexible. It doesn't force any one particular way of doing things. it
really is a foundational set of technologies and I'll talk a little bit
more about that.
00:10:00

Leonard Rosenthol: So as I mentioned we have a specification as I mentioned
it is about ensuring cryptographically verifiable and tamper evident
information with a defined trust model and I'll talk about those in detail.
We are currently at version 2.4 of our specification. you can find it
online. as you can see here in addition to our technical specification
itself we also have about a half dozen or so informative documents. we have
an explainer. We have guidance for general implementation for user
experience. We have a harms document that talks about threats and harms
etc. So a lot of different material that we make available to folks both
normative and informative.

Leonard Rosenthol: and we're on our way to becoming an standard ISO 22144.
and that's a in process and I'm sure many of you have dealt with that long
and involved process of ISO standardization. So let's get into the gory
details. so if you think about it on the left, a content credential is
basically a container of information. If it means anything to you, it's
stored in binary format called Jump JBF which is an ISO standard which is
compatible with ISOB BMF the base media file format it's a bunch of boxes
the key things to know are that the blue box the assertion store this
contains one or more assertions these are the facts if you will that are
stated about the operation and the asset and whatever itself

Leonard Rosenthol: Those assertions are gathered together along with some
additional information into a claim. That's the red box. And then all of
that is then digitally signed and that's the orange box. And so you can
kind of see this mock UI over on the right. This is of course a very very
old UI. I'll show you some more modern ones. but you can see the fact that
the information sort of can point to and is directly used to derive the
user experience. I always talk about this one because it's something of
course that's relevant for most people. So while we did not start with
generative AI as reason for being our reason on detra it certainly is a
very high use today especially with laws that have gone into place in
California, the European Union, China and various other countries around
the world.

Leonard Rosenthol: So you can of course identify not only that an asset has
utilized AI either it was created entirely from AI or it was edited or of
course the opposite being humans were involved in some fashion but you can
also identify individual regions. So if you look at this particular
example, it's not so you can tell sort of by looking at it that it started
as a camera capture and then someone went and obviously used AI to add the
flowered hair. The fact is that inside of that particular asset, the actual
region representing the hair clearly stipulates AI was here, but the actual
rest of it was a camera capture.

Leonard Rosenthol: So you can actually get to very detailed regions and not
just spatial regions. We also support temporal regions, framebased regions,
page and pagebased regions etc. we also support the idea of a recipe so
that if you wanted to incorporate information such as the prompt that was
used, seed values, reference assets, that can all be incorporated as well.
And then in line with some of the various policies in the EU and elsewhere,
we also allow for stipulation of AI usage what is colloquially known as do
not train. So whether or not someone downstream could train on your asset,
use it at inference time or some combination of those things.

Leonard Rosenthol: All right. So, I mentioned that we have a trust model is
the same as PDF in the web. It's X509 certificates. standard cryptographic
hashing. So, all of the things and love. the only thing that we do a little
different is that we maintain our own trust list. and that's also because
we have our own conformance program. So that software and hardware goes
through the conformance program and that a completion and verification of
conformance you get access to ACA which will issue a specific certificate
to then be part of the C2PA Trust list is publicly available. There's
actually two of The regular trust list and also one for TSAs. So we also
have a special one for TSAs as well.
00:15:00

Leonard Rosenthol: We also support hardware at testation. and then all the
other things you would expect. We also have a model for what we call soft
bindings. so it's no surprise that and I'll talk a little bit more about
that. But while the default is to embed these content credentials into
assets and as you can see here we have lots of different formats different
types of assets into which you can embed those credentials including things
not only things you would expect but even HTL, XML, JSON, various other
structured and unstructured text formats even fonts.

Leonard Rosenthol: Sometimes those can be removed and so we also are fully
supportive of one having them stored either in addition to or instead of in
file systems, blockchains, the cloud. we don't care. at the end of the day
there you can store it where you want. on a floppy disc is also perfectly
fine. and as long as they can be retrieved at some point and one way in
which they can be retrieved is through this idea of watermarking and
fingerprinting.

Leonard Rosenthol: so that there's a model we don't stipulate any specific
algorithms what we do instead is we keep a registry of known compatible
algorithms and the reason I consider them compatible is that rather than
simply identifying this is not AI the watermarker fingerprint actually
gives you a way to go and find the associated content credential through
lookup on some form of remote service. And so this is why we have our
softbinding resolution API. and so again those watermarks and fingerprints
combined with the API enable compatible systems to perform the lookups,
retrieve the manifests,

Leonard Rosenthol: the content credentials so we talked a lot about this
and what I want to be one of the things we talk about very frequently is
that trust is not binary. this is why I love this particular picture. trust
is on a scale and it is not determinated by a machine. Trust is determined
by a human. And so each one of these pieces of information that we've
talked about, the individual assertions, what the signer is, each one of
these things is a signal to the end user to help them determine whether or
not they trust a given asset. my favorite example of this is that, here in
the United States, we have a well-known news service called CNN.

Leonard Rosenthol: But so if I had a video from CNN and no one questioned
the fact that it came from CNN, so it was digitally signed. It had a
content credential from CNN. So there's no question about that. But you
showed it to, a hundred individuals, 100 US citizens, 50 of them would
trust it because it came from CNN and 50 of them would not trust it because
it came from CNN. So this is where again it has to be a human-based
decision and our goal is in providing those provenence records containing
all of those signals to help end users make the right decision. All right.
So I've talked about C2PA.

Leonard Rosenthol: I want to introduce another organization because one of
the things we haven't really talked about is identity and that's something
obviously near and dear to your hearts and that's where we have another
organization called COG. This is a partner organization. it is separately
it's part of diff today the decentralized identity forum. so COG the
creator assertions working group is responsible for providing enhancements
to the C2BA content credentials in a couple of areas. So I mentioned the
training and data mining earlier. the big one is identity.
00:20:00

Leonard Rosenthol: So the identity assertion is how one can use X509
certificates, verifiable credentials, social media accounts, and someday
agentic identity. Once we figure out exactly how to specify agentic
identity, for those of you tracking that that's a lot of work in progress.
but as that's figured out then that also can become a perfectly reasonable
identity to be asserted in the process. Oops. There we go. So if you Think
about it this way. We take the subset of the information provided in the
content combine that with the verifiable identity of the credential
subject, and then sign over all of that.

Leonard Rosenthol: And so this is rather than signing over everything,
although you're absolutely welcome to do that, the COG identity allows for
signing only over certain aspects. So for example, I'll back up in a
second. if the human or organization signing only wants to take
responsibility for the asset itself, so the hard binding the hash of the
asset and say the metadata and the actions that they performed, they can do
that even if there are a whole bunch of other assertions in there.

Leonard Rosenthol: So this also enables and I'll show you an example of
this momentarily so this allows for multiple identities. So here's an
example of how we can connect meta data with identities. So this is XMP
serialized as JSONLDD. this is again from a standard 16 ISO 16684-3 I
believe it is. and so you can see here that we've linked from this DC
creator field to a cog identity field. and so this is identity one.

Leonard Rosenthol: This is Stefan. But Jean, and I'm sure I'm screwing the
French up very badly and my apologies. also I don't know. Also has a second
identity. So here I can have multiple identities and each one is taking
responsibility for different things. And I might even have an RL. ODRL.
declaration for the rights incorporated in here as and so all of these
things can be interrelated and interconnected accordingly. So how does that
then break down? So the way to think about it is that the C2PA it's is
responsible for the hardware or software that's producing that content
credential. Okay.

Leonard Rosenthol: And it will use an X509 certificate as to a cozy
signature to sign the overall content credential. And as I mentioned, those
implementations go through the conformance program. But individual named
actors, humans, organizations, as I mentioned, someday agents can also take
responsibility for the pieces that they want and they can use a more
flexible framework. So they're not bound only to X509. They can use
verifiable credentials of various flavors. There's for VLI and GLE. There's
support for Curry.

Leonard Rosenthol: So other standard identity technologies are also usable
as part of the cog identity so that those identity frameworks can be
utilized and then connected to the conforming hardware software tool. So
there we go. So where is this stuff being used today? so here you can see
some shots from online sites LinkedIn, Tik Tok, Meta. taking a look at
these are some photos. you can also see this on YouTube and various other
sites as well. But this is an example for as I mentioned AI generated
disclosures. There was a huge project I'm very proud of this one.
00:25:00

Leonard Rosenthol: Back in 2023, Truepic, which is a small company in
Microsoft, did a project to use verified media to basically put content
credentials on photos of before and after of sites in the Ukraine. So, this
is a before and after shot of the same site as part of what went on there.
really really important work and having these verifiable assets. Oops.
here's an example. The US Department of Defense. so if you ever want to get
official videos or imagery of the US troops in action, there's a site. It's
DIA Divids is how you pronounce this.

Leonard Rosenthol: all of those imagery now contain content credentials. I
will say that I personally find it very interesting if you look at the
examples of the data they put here. It also identifies all of the people in
the photo. so if I were Captain Powell Pakuko, I'm not so sure I'd be
thrilled about having myself IDed in this particular photo, and my email
address also made available. But That's on the DoD. and they decided what
they wanted to expose.

Leonard Rosenthol: But this gives you an example of how one could use this
for verified again imagery. I guess I've got a question there. Yes, I can't
see…

Mahmoud Alkhraishi: Is there anything they can do to redact that
information now that it is associated with this or…

Leonard Rosenthol: who I'll say yes.

Mahmoud Alkhraishi: public or anything like that? let's say somebody made a
mistake and associated too much information. Is there anything that can be
done after the fact?

Leonard Rosenthol: So you can perform redactions. We have a whole mechanism
for redaction. so you can create a redacting the previous redacting the
specific information that you wish to redact and then publish a new
version. But obviously the old version is still out there somewhere
potentially. And so there's no access to it. There's no phone homes, so
there's no way to redact things that are already out there. But you could
absolutely redact something and republish. That's a good question.

Mahmoud Alkhraishi: And how would somebody down the chain know which
version is the authoritative version that they should be referencing? how
do they know this is the latest redacted version? That's the one I'm
supposed to be pointing to than an older version.

Leonard Rosenthol: We don't deal in versioning. We don't deal in
authoritative what we see have seen is that a number of our members so
again our goal is to build provenence technology we do that and then our
members utilize it in various ways. So this is an example of they're not a
member but they're somebody utilizing the open standard but we have members
who for example do media registries on blockchains and in that case they
utilize blockchains to ensure this is the latest and greatest and
retrieving timestamps and all of those things that one can do when you've
built a technology around something like a blockchain or distributed ledger
and

Leonard Rosenthol: That's great and we're very happy for them that they've
done that. but it's again built on top of our infrastructure. So we don't
solve that problem of the authoritative version so somebody else can that
make sense.

Mahmoud Alkhraishi: Yeah, it

Leonard Rosenthol: You may not agree with it but we sort of drew we had to
draw the line somewhere and our goal was not to build a workflow. Our goal
was not to build systems we don't do software in fact we do not distribute
software at all we develop an open standard of which there and then there
are many implementations both open source and commercial deployed in and I
think that's my next slide there we go deployed in a lot of places by a lot
of folks this slide admittedly does not mention some of the source
implementation

Leonard Rosenthol: And I apologize for that. but for example, it's in
dash.js for video. It's in XF tool. very wellknown. there's work going on
to get it into FFmpeg. so a lot of the well-known open- source solutions
are adopting it. But as you can see here, it's also in everything from
hardware. If I was actually I guess I could temporarily turn on my camera.
maybe there we go. So I always like to show So This happens to be a Google
Pixel. every video I take on this camera has a content credential. So this
is sort of that glass scenario that I was mentioning before. and that's
great to be able to say that I can do that.
00:30:00

Leonard Rosenthol: stuff coming out of your AI systems, things being
published by publishers. I showed you some of the government examples,
standard tools. so adoption is very very high. which is what we're very
happy to see and we're hoping that that any other standards work. and so
that's really the presentation. I really wanted to give you folks a chance
to ask questions. I'm happy to dive into areas that you've got. So, let me
stop sharing just so I I can figure there we go. Stop presenting. All
right. And now I know I have questions. Grace, please.

Grace Rachmany: Yeah, thank That was great. my first question is on the
adoption side because you showed where it's being adopted and is that just
on the marking side or on the presentation side,…

Grace Rachmany: if you're adopting it as Facebook are they making sure that
content has a marker like a CTPa or a cog before they show it to me like
that?

Leonard Rosenthol: So a better way to think of So the list,…

Grace Rachmany: because I'd like to

Leonard Rosenthol: I'll pull that back up for a second because I actually
think it's a really nice list. Yeah.

Leonard Rosenthol: So this list here is sort of the big displays in other
words in terms of things like social media. So Tik Tok, Instagram,
Facebook, LinkedIn, YouTube. if and you can see this on the right. So this
is this picture here on the right was taken right out of LinkedIn. you go
on LinkedIn today, you'll see a bunch of images and videos with CR. You go
into YouTube, etc. You'll see this on their sites now that there's nothing
mandatory about it. If you upload an image or a video with it, then the
site will present the consumer with that in the case of LinkedIn, they use
this pin. We call the CR pin. in the case of Meta's platforms, they put up
AI edited or AI modified. That's what they've chosen to do. we don't have a
standard UI treatment.

Leonard Rosenthol: We have UI guidance but it doesn't put in pixel level
you should make it look like this because what we found is that every
single group wants to do it their own way because they're graphic
designers. So we sort of gave up on that and instead we talk about the
types of things. So we talk about progressive disclosure. We talk about,
sort of this in this box here, you could see examples of what we think are
key pieces of information that should be present. but we don't mandate, how
it's presented or anything like that. you also see this on publisher sites.
So if you go to the BBC, for example, you'll see it on a variety of the
media on the BBC site.

Leonard Rosenthol: if you go to AFP which is the French this is not the old
document publishing technology this is the French photographers association
I think it's photographers you'll see information there Hong Kong etc so
those are places absolutely you're going to see it you can also see it on
devices so if I have one on my device it'll show up

Leonard Rosenthol: on the Google Pixel, even if I don't take it, but I
receive it, it'll show me the credential. they're just a good example. if
you do a Google image search, it'll show you in what's called about this
image, if it has a credential. So, it's in a lot of viewing places as well
as in creating places and growing. yes, I can't see who that is. Yeah, of
course.

Grace Rachmany: All right. Thank you.

Mahmoud Alkhraishi: Harrison.

Leonard Rosenthol: Yeah.

Harrison Tang: Yeah. …
00:35:00

Harrison Tang: thanks Leonard for a great presentation. really enjoy it.

Leonard Rosenthol: That's a great question.

Harrison Tang: My question followup question to Grace's qu question is how
does the kind of a trust framework works in this or does the spec it sounds
like the spec does not really do that? does it just kind of defer to
different publishers like LinkedIn, Google on which identity they trust how
does it work? Yeah.

Leonard Rosenthol: So the C2PA has an established trust model. So, as I
said, we have a trust list. So, just your browser has a trust list, your
PDF viewer has a trust list, the European Union has a trust list, there is
what we call the C2PA trust list.

Leonard Rosenthol: So that is the list of root and intermediate and end
route certificates that certificates used to sign media can chain up to and
they will be identified as trusted. Again just like your SSL TLSerts PDF
signing searchs. So there is a standard trust list. Everybody uses that
trust list. All right. and…

Harrison Tang: Got it.

Leonard Rosenthol: you get on that trust list by being a conforming
product. So that's the C2PA. That's that outer wrapper on the credential.
That's the hardware and software. What that exists today. That's what's
used by all of these examples I was giving you in terms of showing those
links and showing trustedness.

Leonard Rosenthol: What isn't there yet and they're working on it because
COG is a little further behind is what is the equivalent for human and
organizational trust because obviously we already have a lot of that today.
We have things like the EUL which establishes it GLE and various industry
ates the IPCC is working on So human and organizational trust still being
worked on. in terms of how that's going to play out but the actual
credential itself the hardware and software that's there today.

Harrison Tang: So is it fair to say it kind of works certificate or
authorities and then you kind of delegate? Okay, got it.

Leonard Rosenthol: So for the C2BA it's standard certificate authorities.

Leonard Rosenthol: Again, it's that same infrastructure that we use, used
for signing PDF files, what is it almost 40 years at this point of known
work. Yep. Yeah.

Harrison Tang: Got it.

Harrison Tang: Thank you.

Leonard Rosenthol: The thing is that for things like verifiable credentials
and that's where the human and organizational comes in and we definitely
want that. It's just again we've separated the hardware and the software,
how from the who. yeah,…

Leonard Rosenthol: Harrison, go ahead, please. Yep.

Harrison Tang: So now I have a followup question on the cog right c yeah
cog and…

Harrison Tang: so what's the kind of a direction where cog is it more going
to be a centralized authority or decentralized because when we're dealing
with personal organizational identities often times like it has different
contextes right so I'm just curious…

Harrison Tang: where is Cox's thinking and kind of philosophy behind

Leonard Rosenthol: That's a good question.

Leonard Rosenthol: To be honest, I think that's still really a big open
question because again, you've already in that world there's already
wellestablished lists. Like I said, you've got things like Glyfe and its
world, you've got Kerry, you've got the EUL, you have IPC's list. So, I
don't think that there's certainly not going to be one list to rule them
all. That certainly is not the answer.

Leonard Rosenthol: it's distributed in some fashion. I think they are still
trying to figure out exactly what it looks like and how do they make it
work in a consistent fashion because obviously the thing we don't want is
you view it on one place and it says trusted and you view it somewhere else
and it says not trusted. So it's a big problem space. I can connect you if
you guys would like to have to dive deeper. I'm happy to connect you to
Scoutton. Eric is my equivalent over in Cog. He runs their technical
working group. I know he's presented at IIF and to other groups and I'm
sure he'd be happy to present to yours as well. He can dive deep into that
work.
00:40:00

Harrison Tang: Cool. Thank you.

Leonard Rosenthol: Yeah, of course.

Harrison Tang: And then a quick comment. I know Grace is kind of in the
line,…

Harrison Tang: but quick comment. earlier we have IRA kind of presenting
and their idea is kind of a trust frameworks. So perhaps cock can take some
inspirations from that instead of saying that I want to create a
centralized one trust framework that rule them rules them all which is very
hard because different industries have different contextes you can kind of
be the trust frameworks just want to share that.

Leonard Rosenthol: Y and…

Leonard Rosenthol: I'll pass that and dark. Thanks. Yeah. Greece.

Grace Rachmany: Yeah, just also to answer Harrison's question. So I'm the
director of DIFF. So yeah, that is an active working group at DIFF. if
you're interested Harrison or anybody else here to join that working group,
they're discussing trust registry. IRA has also presented to them. So they
are talking about a registry of registries and part of the issue is really
that this is an industry I mean depending on the industry, These are
generally very centralized industries. So if you're talking about the
recording artists in the industry, it's quite centralized who is really the
legit recording artist for this recording label and there are very
centralized registries for that. And the same with the news industry,
although in the news industry, people are going to alternative news media,
which is not what the centralized news media would like to happen.

Grace Rachmany: So there's this actually happening simultaneously with the
sort of shaking up of the authorities that are considered like what is true
and artists are becoming more independent and so it's actually a really
difficult problem to solve and I think registries of registries are
important but what C2PA has really done right at the beginning is C2PA has
a conformance program and a centralized ized authority for C2PA. and you
can see organizations SSL you can actually get compliance certificates
there. It's a little pricey, but you can actually get your compliance
certificates there and stuff.

Grace Rachmany: So it's starting to take the form of a more centralized
industry that it comes from but they've chosen to be in diff at least for
now because the looking at these more decentralized alternatives may be a
trend of where these industries are going. So if you want to be part of
that conversation I mean please join. We're happy to have people come in
and do that.

Leonard Rosenthol: 100%. Yeah. Thanks, race. Absolutely. What else can I
tell you?

Mahmoud Alkhraishi: Thank you so much, Lard. …

Leonard Rosenthol: My pleasure.

Mahmoud Alkhraishi: does anybody else have Any other comments? Anything
anybody wants to bring up? Where can we contribute?

Grace Rachmany: I mean I did want to ask about the certification…

Mahmoud Alkhraishi: How can we help? I'll play this.

Grace Rachmany: but it might not be your area because I was looking at the
SSL program and it just feels like in some cases it's very difficult becau
to pay those kinds of prices simply because some organizations are big like
recording studios but some are just independent artists and then with the
COG certifications it's like the amount of money that you make on one piece
of content is very small.

Grace Rachmany: It feels like there may be still some I don't know market
experimentation around the pricing for getting those conformance and
certifications. Can you talk a little bit about how you're thinking about
the pricing of that?

Leonard Rosenthol: Yeah, absolutely.

Leonard Rosenthol: And so I should start by saying that the conformance
program itself is free. We don't charge to go through conformance and our
goal is to always keep conformance free. we don't believe anyone should
have to pay to become conformant. Now getting the certificate is sort of
outside of our so we have given guidance. So SSL.com is one but they're not
the only ones. I think it's at least half a dozen. I can look how many CAS
we currently can offer certificates. so yeah it's not just them.

Leonard Rosenthol: There are a number of other and we're even seeing new
folks who are applying to be CA who've not been CASs for the web or
anything else who want to be CAS just for C2PA. So there's a little company
called Trufo for example who just recently went through the process and
they are just going to be a CA for C2PA. if you go through you, we have a
process to become a CA. You go, great. we're happy to do that. And again,
there's no cost for that either. So, if somebody wants to be a CA, they can
do that for no cost. yeah.
00:45:00

Leonard Rosenthol: But the actual price for certificates at the moment,
yeah, not are doing. I will say and this is pure speculation, but if you
look at buying what is now a TLS certificate, if you look at its price
point over time, as more and more people needed them, as it became a
commodity item, price went down. We're just at the beginning of C2PA
issuance and conformance. my hope is that we will see a similar trend as
more and more certificates are needed but pure speculation just looking at
history.

Grace Rachmany: That was great. Thank you so

Leonard Rosenthol: Yeah of course yeah and with that let me also mention if
anyone is interested in joining and participating in our work membership is
free so we have a free tier you go to c2pa.org

Leonard Rosenthol: membership. There's a big blue button that says apply
now. You sign the paperwork and you're basically a member. it usually takes
about a week for us to roll through all the internal stuff. but that's it.
Click the button, pay us no money, and we're happy to have you if you're
interested in participating and…

Mahmoud Alkhraishi: Thank you so much, Leonard. before I let you go, does
anybody have anything else they'd like to bring up? Anyone have any final
questions?

Leonard Rosenthol:

Leonard Rosenthol: I'll share the presentation. you're welcome to utilize
it.

Mahmoud Alkhraishi: Please do. Can you share it to the CCG mailing list,…

Mahmoud Alkhraishi: please? Thank you.

Leonard Rosenthol: Yes, that's what I will do. My pleasure.

Ted Thibodeau Jr: just to speak at a loud throw a couple of things into the
chat.

Ted Thibodeau Jr: Leonard's also participated in the credible web community
group which has produced a few reports. they're not active at the moment,
but when new tech or new problems come up, it's a good place to focus
discussion. and there's also a link to the Providence ontology, which is
key to all of this. it developed this a decade or more ago. there's a stack
of standards for Providence and they are exceedingly useful when you start
doing this especially in places like within your company to say that this
coder wrote this section of code and a decade later after they retired you
can still go back to them and say what did you mean by that comment cuz I
don't understand it. That's all.

Mahmoud Alkhraishi: Thank you, Leonard, for a wonderful presentation.

Leonard Rosenthol: Benjamin's got something.

Mahmoud Alkhraishi: Thank you, everybody. Benjamin, please.

Benjamin Young: Yeah, sorry.

Benjamin Young: I know we're trying to wrap up.

Benjamin Young: Leonard,…

Mahmoud Alkhraishi: No, we have fenced.

Benjamin Young: And I may have missed this. I was away for part of the
Q\&A, but there was a self hash something identifier in the JLD you had on
screen.

Leonard Rosenthol: Yes I Yes.

Benjamin Young: I wondered if that had its own chunk of the specification
somewhere and…

Leonard Rosenthol: Yeah. Yes.

Benjamin Young: if there was a way to engage around that at some point

Leonard Rosenthol: So I mentioned that the credential is stored in a format
called Jump Jumbf which is ISO 19566-5. in the JF standard is what are
referred to as JF URIs. So that's how one refers to those individual boxes
within the Jump. Those are Jump URIs that you saw. So those are specified
in that ISO standard. We are just leveraging the answer to that is we point
you over there.

Benjamin Young: Cool. Yeah.

Leonard Rosenthol: But yeah, it's a definfined standard. and I'm curious
how to find me and I'm curious why you find them interesting.

Benjamin Young: No, it's mostly in the context of JSON LD and the
processing that would happen there and what those would become.

Leonard Rosenthol: Got it.

Benjamin Young: And happy to chat about it. I was not familiar with Jump.
So, I'll dig into that and then maybe we'll chat.

Leonard Rosenthol: Excellent. Yeah,…

Benjamin Young: Thanks, Leonard. Great presentation.

Leonard Rosenthol: of course. My pleasure. All right. Thank you all for
putting up with me today.

Mahmoud Alkhraishi: Thank you, onard. And thank you everybody else for
participating. Have a great rest of your week.
Meeting ended after 00:49:45 👋

*This editable transcript was computer generated and might contain errors.
People can also change the text after it was created.*

Received on Saturday, 19 September 2026 20:27:54 UTC