- From: W3C CCG Meetings <meetings@w3c-ccg.org>
- Date: Sat, 19 Sep 2026 16:27:45 -0400
- To: public-credentials@w3.org
- Message-ID: <CA+ChqYd3F8OnRqZmGTVXCt3sNb3FdihN7pagOT1SPsFMzG37TQ@mail.gmail.com>
CCG Atlantic Meeting Summary - September 15, 2026 The CCG Atlantic meeting on September 15, 2026, featured a comprehensive presentation by Leonard Rosenthol from Adobe on the C2PA (Coalition for Content Provenance and Authenticity) and its content credentials technology. The discussion delved into the technical specifications of content credentials, including their structure, cryptographic signing, and trust models, as well as the complementary COG (Creator Assertions Working Group) for identity assertions. The adoption and application of C2PA technology across various platforms, devices, and government agencies were highlighted, alongside a detailed Q&A session addressing adoption, trust frameworks, and pricing for certifications. *Topics Covered:* - *Introduction to C2PA and Content Credentials:* Leonard Rosenthol introduced the Coalition for Content Provenance and Authenticity (C2PA) and its core technology, Content Credentials, which cryptographically binds factual information about an asset, making it tamper-evident. The system is designed to be flexible, supporting various stages from content creation to consumption. - *Technical Specification of Content Credentials:* The presentation detailed the structure of content credentials, including assertion stores, claims, and digital signatures, and explained their compatibility with standards like JUMBF and ISO BMFF. The use of X.509 certificates for cryptographic verification and the C2PA's trust list model were also covered. - *Generative AI and Content Provenance:* The significance of C2PA in identifying AI usage in content creation and editing was emphasized, including the ability to specify AI involvement in specific regions and temporal aspects, as well as supporting "do not train" stipulations. - *COG and Identity Assertions:* The role of the Creator Assertions Working Group (COG) was explained, focusing on its enhancements to C2PA, particularly in identity assertions, allowing for verifiable credentials, social media accounts, and potentially agentic identity. COG enables individuals and organizations to take responsibility for specific aspects of content while supporting multiple identities. - *C2PA Adoption and Usage:* Examples of C2PA's adoption were showcased, including social media platforms like LinkedIn, TikTok, and Meta, as well as government use cases like the US Department of Defense, and its presence on devices like Google Pixel and in tools like Dash.js and XF Tool. - *Trust Frameworks and Certification:* The discussion clarified C2PA's trust model, which relies on standard Certificate Authorities and a C2PA trust list for hardware and software conformance. The pricing and availability of conformance programs and certificates were addressed, with the conformance program itself being free, while certificate pricing is subject to market evolution. - *Redaction and Versioning:* The possibility of redaction for content credentials was discussed, noting that while new versions can be published, previously distributed credentials cannot be retroactively removed. The responsibility for managing authoritative versions was acknowledged as lying with implementers, not the C2PA standard itself. - *Future of COG and Decentralization:* The evolving nature of COG and its approach to identity, including potential for decentralized trust models and registries of registries, was discussed, with an invitation to participate in relevant working groups. *Action Items:* - Leonard Rosenthol to share his presentation with the CCG mailing list. - Harrison Tang and other interested participants to consider joining the COG working group within DIFF to engage in discussions about trust registries and decentralized identity. Text: https://meet.w3c-ccg.org/archives/w3c-ccg-atlantic-2026-09-15.md Video: https://meet.w3c-ccg.org/archives/w3c-ccg-atlantic-2026-09-15.mp4 *CCG Atlantic - 2026/09/15 12:00 EDT - Transcript* *Attendees* Alex Higuera, Benjamin Young, Brent Zundel, Calendly Nоtеtаkеr, Dmitri Zagidulin, Erica Connell, Grace Rachmany, Harrison Tang, Hiroyuki Sano, JeffO - HumanOS, Jennie Meier, Joe Andrieu, Lancine Toure, Leonard Rosenthol, Mahmoud Alkhraishi, Maxime Mansiet, Phillip Long, Ted Thibodeau Jr, Will Abramson *Transcript* Mahmoud Alkhraishi: Hi We're just going to give it another four minutes before we get started. Mahmoud Alkhraishi: All right. let's kick this off. thank you everybody for joining us. It is Tuesday, September the 15th. we're on our weekly CCG meeting call. Code of ethics and professional conduct reminder. We have a code of ethics that we request everybody adhere to. You can find it on our website. And as an IP note, anybody can participate in these calls. However, all substantive contributors to any work of the CCG must be a member of the CCG with full RPR agreements signed. do we have any announcements that anybody would like to make? I am not sure who this note taker Is this a person or this is a bot, right? Ted Thibodeau Jr: Yes, that is a bot. 00:05:00 Mahmoud Alkhraishi: Okay, let me try and kick that off. Give me a second. while I do, does everybody have any announcements they would like to make? Mahmoud Alkhraishi: Okay, hearing none. we have Leonard Rosenthal today to present to us on the C2PA. Leonard, would you mind introducing yourself quickly and… Mahmoud Alkhraishi: walking everybody through what you do and then through your presentation? Leonard Rosenthol: Great. yeah,… Leonard Rosenthol: happy to do So I know a number of you from many other meetings in the W3C and elsewhere. so I work for Adobe as my day job. I have a number of responsibilities there, but the ones I'm most well known for, I have been Adobe's PDF architect for just about 30 years now. and since 2019 when Adobe started what you're going to hear about today or what you're going to hear about today, I have been leading the content authenticity architecture as well within Adobe and then the C2PA itself. So that's who I am. Leonard Rosenthol: and again I've been a member of the W3C and involved in standards here for I don't know 20 years give or take in various groups. but let me talk this out and those of you who know me I am happy to take questions at any point in the presentation. just raise hands, jump in. I'm pretty easy. All right. So we'll talk about really the technology itself more the organization is the coalition for content provenence and authenticity. and our technology that I'm going to talk about is content credentials. So let me dive in here. So the organization itself we were founded in 2020. we currently have 11 steering committee members. Leonard Rosenthol: as you can see their logos there. we are part of the Linux Foundation JDF and we also have over 500 general and contributor members. and any standards body, some of them are more active than others. we also do our work actually very similarly to the W3C in terms of utilizing GitHub asynchronous communications. we do however hold regular meetings again not unlike this and we break down into a technical working group and about a dozen task forces and task forces come and go based on the topics that they're focused on and we can talk more about that if you're interested. so what do we focus on? We focus on content provenence. Leonard Rosenthol: provenence being the set of basic facts about an asset that are cryptographically bound to that asset and tamper evidence. So this could be how and why of the asset, its process, creation, editing, publishing. it's certainly in the last few years whether or not AI was used and where becomes very significant. We'll talk a little bit about that. so at the end of the day we enable people, organizations, entities, hardware to declare what's going on rather than consumers having to guess information. And as mentioned, we sort of talk about this as glass to glass. Leonard Rosenthol: The idea of course being that and it does not have to be. this is sort of the rainbow and unicorn world. if we can go all the way from capture to view, creation, editing, publishing, and then consumption. but you don't have to start all the way at the beginning. You can have gaps along the way. that's all perfectly acceptable. we also of course recognize that there are billions and billions of digital assets created long before we came into existence. you may want to associate a content credential and provenence with those existing assets. so the system itself is extremely flexible. It doesn't force any one particular way of doing things. it really is a foundational set of technologies and I'll talk a little bit more about that. 00:10:00 Leonard Rosenthol: So as I mentioned we have a specification as I mentioned it is about ensuring cryptographically verifiable and tamper evident information with a defined trust model and I'll talk about those in detail. We are currently at version 2.4 of our specification. you can find it online. as you can see here in addition to our technical specification itself we also have about a half dozen or so informative documents. we have an explainer. We have guidance for general implementation for user experience. We have a harms document that talks about threats and harms etc. So a lot of different material that we make available to folks both normative and informative. Leonard Rosenthol: and we're on our way to becoming an standard ISO 22144. and that's a in process and I'm sure many of you have dealt with that long and involved process of ISO standardization. So let's get into the gory details. so if you think about it on the left, a content credential is basically a container of information. If it means anything to you, it's stored in binary format called Jump JBF which is an ISO standard which is compatible with ISOB BMF the base media file format it's a bunch of boxes the key things to know are that the blue box the assertion store this contains one or more assertions these are the facts if you will that are stated about the operation and the asset and whatever itself Leonard Rosenthol: Those assertions are gathered together along with some additional information into a claim. That's the red box. And then all of that is then digitally signed and that's the orange box. And so you can kind of see this mock UI over on the right. This is of course a very very old UI. I'll show you some more modern ones. but you can see the fact that the information sort of can point to and is directly used to derive the user experience. I always talk about this one because it's something of course that's relevant for most people. So while we did not start with generative AI as reason for being our reason on detra it certainly is a very high use today especially with laws that have gone into place in California, the European Union, China and various other countries around the world. Leonard Rosenthol: So you can of course identify not only that an asset has utilized AI either it was created entirely from AI or it was edited or of course the opposite being humans were involved in some fashion but you can also identify individual regions. So if you look at this particular example, it's not so you can tell sort of by looking at it that it started as a camera capture and then someone went and obviously used AI to add the flowered hair. The fact is that inside of that particular asset, the actual region representing the hair clearly stipulates AI was here, but the actual rest of it was a camera capture. Leonard Rosenthol: So you can actually get to very detailed regions and not just spatial regions. We also support temporal regions, framebased regions, page and pagebased regions etc. we also support the idea of a recipe so that if you wanted to incorporate information such as the prompt that was used, seed values, reference assets, that can all be incorporated as well. And then in line with some of the various policies in the EU and elsewhere, we also allow for stipulation of AI usage what is colloquially known as do not train. So whether or not someone downstream could train on your asset, use it at inference time or some combination of those things. Leonard Rosenthol: All right. So, I mentioned that we have a trust model is the same as PDF in the web. It's X509 certificates. standard cryptographic hashing. So, all of the things and love. the only thing that we do a little different is that we maintain our own trust list. and that's also because we have our own conformance program. So that software and hardware goes through the conformance program and that a completion and verification of conformance you get access to ACA which will issue a specific certificate to then be part of the C2PA Trust list is publicly available. There's actually two of The regular trust list and also one for TSAs. So we also have a special one for TSAs as well. 00:15:00 Leonard Rosenthol: We also support hardware at testation. and then all the other things you would expect. We also have a model for what we call soft bindings. so it's no surprise that and I'll talk a little bit more about that. But while the default is to embed these content credentials into assets and as you can see here we have lots of different formats different types of assets into which you can embed those credentials including things not only things you would expect but even HTL, XML, JSON, various other structured and unstructured text formats even fonts. Leonard Rosenthol: Sometimes those can be removed and so we also are fully supportive of one having them stored either in addition to or instead of in file systems, blockchains, the cloud. we don't care. at the end of the day there you can store it where you want. on a floppy disc is also perfectly fine. and as long as they can be retrieved at some point and one way in which they can be retrieved is through this idea of watermarking and fingerprinting. Leonard Rosenthol: so that there's a model we don't stipulate any specific algorithms what we do instead is we keep a registry of known compatible algorithms and the reason I consider them compatible is that rather than simply identifying this is not AI the watermarker fingerprint actually gives you a way to go and find the associated content credential through lookup on some form of remote service. And so this is why we have our softbinding resolution API. and so again those watermarks and fingerprints combined with the API enable compatible systems to perform the lookups, retrieve the manifests, Leonard Rosenthol: the content credentials so we talked a lot about this and what I want to be one of the things we talk about very frequently is that trust is not binary. this is why I love this particular picture. trust is on a scale and it is not determinated by a machine. Trust is determined by a human. And so each one of these pieces of information that we've talked about, the individual assertions, what the signer is, each one of these things is a signal to the end user to help them determine whether or not they trust a given asset. my favorite example of this is that, here in the United States, we have a well-known news service called CNN. Leonard Rosenthol: But so if I had a video from CNN and no one questioned the fact that it came from CNN, so it was digitally signed. It had a content credential from CNN. So there's no question about that. But you showed it to, a hundred individuals, 100 US citizens, 50 of them would trust it because it came from CNN and 50 of them would not trust it because it came from CNN. So this is where again it has to be a human-based decision and our goal is in providing those provenence records containing all of those signals to help end users make the right decision. All right. So I've talked about C2PA. Leonard Rosenthol: I want to introduce another organization because one of the things we haven't really talked about is identity and that's something obviously near and dear to your hearts and that's where we have another organization called COG. This is a partner organization. it is separately it's part of diff today the decentralized identity forum. so COG the creator assertions working group is responsible for providing enhancements to the C2BA content credentials in a couple of areas. So I mentioned the training and data mining earlier. the big one is identity. 00:20:00 Leonard Rosenthol: So the identity assertion is how one can use X509 certificates, verifiable credentials, social media accounts, and someday agentic identity. Once we figure out exactly how to specify agentic identity, for those of you tracking that that's a lot of work in progress. but as that's figured out then that also can become a perfectly reasonable identity to be asserted in the process. Oops. There we go. So if you Think about it this way. We take the subset of the information provided in the content combine that with the verifiable identity of the credential subject, and then sign over all of that. Leonard Rosenthol: And so this is rather than signing over everything, although you're absolutely welcome to do that, the COG identity allows for signing only over certain aspects. So for example, I'll back up in a second. if the human or organization signing only wants to take responsibility for the asset itself, so the hard binding the hash of the asset and say the metadata and the actions that they performed, they can do that even if there are a whole bunch of other assertions in there. Leonard Rosenthol: So this also enables and I'll show you an example of this momentarily so this allows for multiple identities. So here's an example of how we can connect meta data with identities. So this is XMP serialized as JSONLDD. this is again from a standard 16 ISO 16684-3 I believe it is. and so you can see here that we've linked from this DC creator field to a cog identity field. and so this is identity one. Leonard Rosenthol: This is Stefan. But Jean, and I'm sure I'm screwing the French up very badly and my apologies. also I don't know. Also has a second identity. So here I can have multiple identities and each one is taking responsibility for different things. And I might even have an RL. ODRL. declaration for the rights incorporated in here as and so all of these things can be interrelated and interconnected accordingly. So how does that then break down? So the way to think about it is that the C2PA it's is responsible for the hardware or software that's producing that content credential. Okay. Leonard Rosenthol: And it will use an X509 certificate as to a cozy signature to sign the overall content credential. And as I mentioned, those implementations go through the conformance program. But individual named actors, humans, organizations, as I mentioned, someday agents can also take responsibility for the pieces that they want and they can use a more flexible framework. So they're not bound only to X509. They can use verifiable credentials of various flavors. There's for VLI and GLE. There's support for Curry. Leonard Rosenthol: So other standard identity technologies are also usable as part of the cog identity so that those identity frameworks can be utilized and then connected to the conforming hardware software tool. So there we go. So where is this stuff being used today? so here you can see some shots from online sites LinkedIn, Tik Tok, Meta. taking a look at these are some photos. you can also see this on YouTube and various other sites as well. But this is an example for as I mentioned AI generated disclosures. There was a huge project I'm very proud of this one. 00:25:00 Leonard Rosenthol: Back in 2023, Truepic, which is a small company in Microsoft, did a project to use verified media to basically put content credentials on photos of before and after of sites in the Ukraine. So, this is a before and after shot of the same site as part of what went on there. really really important work and having these verifiable assets. Oops. here's an example. The US Department of Defense. so if you ever want to get official videos or imagery of the US troops in action, there's a site. It's DIA Divids is how you pronounce this. Leonard Rosenthol: all of those imagery now contain content credentials. I will say that I personally find it very interesting if you look at the examples of the data they put here. It also identifies all of the people in the photo. so if I were Captain Powell Pakuko, I'm not so sure I'd be thrilled about having myself IDed in this particular photo, and my email address also made available. But That's on the DoD. and they decided what they wanted to expose. Leonard Rosenthol: But this gives you an example of how one could use this for verified again imagery. I guess I've got a question there. Yes, I can't see… Mahmoud Alkhraishi: Is there anything they can do to redact that information now that it is associated with this or… Leonard Rosenthol: who I'll say yes. Mahmoud Alkhraishi: public or anything like that? let's say somebody made a mistake and associated too much information. Is there anything that can be done after the fact? Leonard Rosenthol: So you can perform redactions. We have a whole mechanism for redaction. so you can create a redacting the previous redacting the specific information that you wish to redact and then publish a new version. But obviously the old version is still out there somewhere potentially. And so there's no access to it. There's no phone homes, so there's no way to redact things that are already out there. But you could absolutely redact something and republish. That's a good question. Mahmoud Alkhraishi: And how would somebody down the chain know which version is the authoritative version that they should be referencing? how do they know this is the latest redacted version? That's the one I'm supposed to be pointing to than an older version. Leonard Rosenthol: We don't deal in versioning. We don't deal in authoritative what we see have seen is that a number of our members so again our goal is to build provenence technology we do that and then our members utilize it in various ways. So this is an example of they're not a member but they're somebody utilizing the open standard but we have members who for example do media registries on blockchains and in that case they utilize blockchains to ensure this is the latest and greatest and retrieving timestamps and all of those things that one can do when you've built a technology around something like a blockchain or distributed ledger and Leonard Rosenthol: That's great and we're very happy for them that they've done that. but it's again built on top of our infrastructure. So we don't solve that problem of the authoritative version so somebody else can that make sense. Mahmoud Alkhraishi: Yeah, it Leonard Rosenthol: You may not agree with it but we sort of drew we had to draw the line somewhere and our goal was not to build a workflow. Our goal was not to build systems we don't do software in fact we do not distribute software at all we develop an open standard of which there and then there are many implementations both open source and commercial deployed in and I think that's my next slide there we go deployed in a lot of places by a lot of folks this slide admittedly does not mention some of the source implementation Leonard Rosenthol: And I apologize for that. but for example, it's in dash.js for video. It's in XF tool. very wellknown. there's work going on to get it into FFmpeg. so a lot of the well-known open- source solutions are adopting it. But as you can see here, it's also in everything from hardware. If I was actually I guess I could temporarily turn on my camera. maybe there we go. So I always like to show So This happens to be a Google Pixel. every video I take on this camera has a content credential. So this is sort of that glass scenario that I was mentioning before. and that's great to be able to say that I can do that. 00:30:00 Leonard Rosenthol: stuff coming out of your AI systems, things being published by publishers. I showed you some of the government examples, standard tools. so adoption is very very high. which is what we're very happy to see and we're hoping that that any other standards work. and so that's really the presentation. I really wanted to give you folks a chance to ask questions. I'm happy to dive into areas that you've got. So, let me stop sharing just so I I can figure there we go. Stop presenting. All right. And now I know I have questions. Grace, please. Grace Rachmany: Yeah, thank That was great. my first question is on the adoption side because you showed where it's being adopted and is that just on the marking side or on the presentation side,… Grace Rachmany: if you're adopting it as Facebook are they making sure that content has a marker like a CTPa or a cog before they show it to me like that? Leonard Rosenthol: So a better way to think of So the list,… Grace Rachmany: because I'd like to Leonard Rosenthol: I'll pull that back up for a second because I actually think it's a really nice list. Yeah. Leonard Rosenthol: So this list here is sort of the big displays in other words in terms of things like social media. So Tik Tok, Instagram, Facebook, LinkedIn, YouTube. if and you can see this on the right. So this is this picture here on the right was taken right out of LinkedIn. you go on LinkedIn today, you'll see a bunch of images and videos with CR. You go into YouTube, etc. You'll see this on their sites now that there's nothing mandatory about it. If you upload an image or a video with it, then the site will present the consumer with that in the case of LinkedIn, they use this pin. We call the CR pin. in the case of Meta's platforms, they put up AI edited or AI modified. That's what they've chosen to do. we don't have a standard UI treatment. Leonard Rosenthol: We have UI guidance but it doesn't put in pixel level you should make it look like this because what we found is that every single group wants to do it their own way because they're graphic designers. So we sort of gave up on that and instead we talk about the types of things. So we talk about progressive disclosure. We talk about, sort of this in this box here, you could see examples of what we think are key pieces of information that should be present. but we don't mandate, how it's presented or anything like that. you also see this on publisher sites. So if you go to the BBC, for example, you'll see it on a variety of the media on the BBC site. Leonard Rosenthol: if you go to AFP which is the French this is not the old document publishing technology this is the French photographers association I think it's photographers you'll see information there Hong Kong etc so those are places absolutely you're going to see it you can also see it on devices so if I have one on my device it'll show up Leonard Rosenthol: on the Google Pixel, even if I don't take it, but I receive it, it'll show me the credential. they're just a good example. if you do a Google image search, it'll show you in what's called about this image, if it has a credential. So, it's in a lot of viewing places as well as in creating places and growing. yes, I can't see who that is. Yeah, of course. Grace Rachmany: All right. Thank you. Mahmoud Alkhraishi: Harrison. Leonard Rosenthol: Yeah. Harrison Tang: Yeah. … 00:35:00 Harrison Tang: thanks Leonard for a great presentation. really enjoy it. Leonard Rosenthol: That's a great question. Harrison Tang: My question followup question to Grace's qu question is how does the kind of a trust framework works in this or does the spec it sounds like the spec does not really do that? does it just kind of defer to different publishers like LinkedIn, Google on which identity they trust how does it work? Yeah. Leonard Rosenthol: So the C2PA has an established trust model. So, as I said, we have a trust list. So, just your browser has a trust list, your PDF viewer has a trust list, the European Union has a trust list, there is what we call the C2PA trust list. Leonard Rosenthol: So that is the list of root and intermediate and end route certificates that certificates used to sign media can chain up to and they will be identified as trusted. Again just like your SSL TLSerts PDF signing searchs. So there is a standard trust list. Everybody uses that trust list. All right. and… Harrison Tang: Got it. Leonard Rosenthol: you get on that trust list by being a conforming product. So that's the C2PA. That's that outer wrapper on the credential. That's the hardware and software. What that exists today. That's what's used by all of these examples I was giving you in terms of showing those links and showing trustedness. Leonard Rosenthol: What isn't there yet and they're working on it because COG is a little further behind is what is the equivalent for human and organizational trust because obviously we already have a lot of that today. We have things like the EUL which establishes it GLE and various industry ates the IPCC is working on So human and organizational trust still being worked on. in terms of how that's going to play out but the actual credential itself the hardware and software that's there today. Harrison Tang: So is it fair to say it kind of works certificate or authorities and then you kind of delegate? Okay, got it. Leonard Rosenthol: So for the C2BA it's standard certificate authorities. Leonard Rosenthol: Again, it's that same infrastructure that we use, used for signing PDF files, what is it almost 40 years at this point of known work. Yep. Yeah. Harrison Tang: Got it. Harrison Tang: Thank you. Leonard Rosenthol: The thing is that for things like verifiable credentials and that's where the human and organizational comes in and we definitely want that. It's just again we've separated the hardware and the software, how from the who. yeah,… Leonard Rosenthol: Harrison, go ahead, please. Yep. Harrison Tang: So now I have a followup question on the cog right c yeah cog and… Harrison Tang: so what's the kind of a direction where cog is it more going to be a centralized authority or decentralized because when we're dealing with personal organizational identities often times like it has different contextes right so I'm just curious… Harrison Tang: where is Cox's thinking and kind of philosophy behind Leonard Rosenthol: That's a good question. Leonard Rosenthol: To be honest, I think that's still really a big open question because again, you've already in that world there's already wellestablished lists. Like I said, you've got things like Glyfe and its world, you've got Kerry, you've got the EUL, you have IPC's list. So, I don't think that there's certainly not going to be one list to rule them all. That certainly is not the answer. Leonard Rosenthol: it's distributed in some fashion. I think they are still trying to figure out exactly what it looks like and how do they make it work in a consistent fashion because obviously the thing we don't want is you view it on one place and it says trusted and you view it somewhere else and it says not trusted. So it's a big problem space. I can connect you if you guys would like to have to dive deeper. I'm happy to connect you to Scoutton. Eric is my equivalent over in Cog. He runs their technical working group. I know he's presented at IIF and to other groups and I'm sure he'd be happy to present to yours as well. He can dive deep into that work. 00:40:00 Harrison Tang: Cool. Thank you. Leonard Rosenthol: Yeah, of course. Harrison Tang: And then a quick comment. I know Grace is kind of in the line,… Harrison Tang: but quick comment. earlier we have IRA kind of presenting and their idea is kind of a trust frameworks. So perhaps cock can take some inspirations from that instead of saying that I want to create a centralized one trust framework that rule them rules them all which is very hard because different industries have different contextes you can kind of be the trust frameworks just want to share that. Leonard Rosenthol: Y and… Leonard Rosenthol: I'll pass that and dark. Thanks. Yeah. Greece. Grace Rachmany: Yeah, just also to answer Harrison's question. So I'm the director of DIFF. So yeah, that is an active working group at DIFF. if you're interested Harrison or anybody else here to join that working group, they're discussing trust registry. IRA has also presented to them. So they are talking about a registry of registries and part of the issue is really that this is an industry I mean depending on the industry, These are generally very centralized industries. So if you're talking about the recording artists in the industry, it's quite centralized who is really the legit recording artist for this recording label and there are very centralized registries for that. And the same with the news industry, although in the news industry, people are going to alternative news media, which is not what the centralized news media would like to happen. Grace Rachmany: So there's this actually happening simultaneously with the sort of shaking up of the authorities that are considered like what is true and artists are becoming more independent and so it's actually a really difficult problem to solve and I think registries of registries are important but what C2PA has really done right at the beginning is C2PA has a conformance program and a centralized ized authority for C2PA. and you can see organizations SSL you can actually get compliance certificates there. It's a little pricey, but you can actually get your compliance certificates there and stuff. Grace Rachmany: So it's starting to take the form of a more centralized industry that it comes from but they've chosen to be in diff at least for now because the looking at these more decentralized alternatives may be a trend of where these industries are going. So if you want to be part of that conversation I mean please join. We're happy to have people come in and do that. Leonard Rosenthol: 100%. Yeah. Thanks, race. Absolutely. What else can I tell you? Mahmoud Alkhraishi: Thank you so much, Lard. … Leonard Rosenthol: My pleasure. Mahmoud Alkhraishi: does anybody else have Any other comments? Anything anybody wants to bring up? Where can we contribute? Grace Rachmany: I mean I did want to ask about the certification… Mahmoud Alkhraishi: How can we help? I'll play this. Grace Rachmany: but it might not be your area because I was looking at the SSL program and it just feels like in some cases it's very difficult becau to pay those kinds of prices simply because some organizations are big like recording studios but some are just independent artists and then with the COG certifications it's like the amount of money that you make on one piece of content is very small. Grace Rachmany: It feels like there may be still some I don't know market experimentation around the pricing for getting those conformance and certifications. Can you talk a little bit about how you're thinking about the pricing of that? Leonard Rosenthol: Yeah, absolutely. Leonard Rosenthol: And so I should start by saying that the conformance program itself is free. We don't charge to go through conformance and our goal is to always keep conformance free. we don't believe anyone should have to pay to become conformant. Now getting the certificate is sort of outside of our so we have given guidance. So SSL.com is one but they're not the only ones. I think it's at least half a dozen. I can look how many CAS we currently can offer certificates. so yeah it's not just them. Leonard Rosenthol: There are a number of other and we're even seeing new folks who are applying to be CA who've not been CASs for the web or anything else who want to be CAS just for C2PA. So there's a little company called Trufo for example who just recently went through the process and they are just going to be a CA for C2PA. if you go through you, we have a process to become a CA. You go, great. we're happy to do that. And again, there's no cost for that either. So, if somebody wants to be a CA, they can do that for no cost. yeah. 00:45:00 Leonard Rosenthol: But the actual price for certificates at the moment, yeah, not are doing. I will say and this is pure speculation, but if you look at buying what is now a TLS certificate, if you look at its price point over time, as more and more people needed them, as it became a commodity item, price went down. We're just at the beginning of C2PA issuance and conformance. my hope is that we will see a similar trend as more and more certificates are needed but pure speculation just looking at history. Grace Rachmany: That was great. Thank you so Leonard Rosenthol: Yeah of course yeah and with that let me also mention if anyone is interested in joining and participating in our work membership is free so we have a free tier you go to c2pa.org Leonard Rosenthol: membership. There's a big blue button that says apply now. You sign the paperwork and you're basically a member. it usually takes about a week for us to roll through all the internal stuff. but that's it. Click the button, pay us no money, and we're happy to have you if you're interested in participating and… Mahmoud Alkhraishi: Thank you so much, Leonard. before I let you go, does anybody have anything else they'd like to bring up? Anyone have any final questions? Leonard Rosenthol: Leonard Rosenthol: I'll share the presentation. you're welcome to utilize it. Mahmoud Alkhraishi: Please do. Can you share it to the CCG mailing list,… Mahmoud Alkhraishi: please? Thank you. Leonard Rosenthol: Yes, that's what I will do. My pleasure. Ted Thibodeau Jr: just to speak at a loud throw a couple of things into the chat. Ted Thibodeau Jr: Leonard's also participated in the credible web community group which has produced a few reports. they're not active at the moment, but when new tech or new problems come up, it's a good place to focus discussion. and there's also a link to the Providence ontology, which is key to all of this. it developed this a decade or more ago. there's a stack of standards for Providence and they are exceedingly useful when you start doing this especially in places like within your company to say that this coder wrote this section of code and a decade later after they retired you can still go back to them and say what did you mean by that comment cuz I don't understand it. That's all. Mahmoud Alkhraishi: Thank you, Leonard, for a wonderful presentation. Leonard Rosenthol: Benjamin's got something. Mahmoud Alkhraishi: Thank you, everybody. Benjamin, please. Benjamin Young: Yeah, sorry. Benjamin Young: I know we're trying to wrap up. Benjamin Young: Leonard,… Mahmoud Alkhraishi: No, we have fenced. Benjamin Young: And I may have missed this. I was away for part of the Q\&A, but there was a self hash something identifier in the JLD you had on screen. Leonard Rosenthol: Yes I Yes. Benjamin Young: I wondered if that had its own chunk of the specification somewhere and… Leonard Rosenthol: Yeah. Yes. Benjamin Young: if there was a way to engage around that at some point Leonard Rosenthol: So I mentioned that the credential is stored in a format called Jump Jumbf which is ISO 19566-5. in the JF standard is what are referred to as JF URIs. So that's how one refers to those individual boxes within the Jump. Those are Jump URIs that you saw. So those are specified in that ISO standard. We are just leveraging the answer to that is we point you over there. Benjamin Young: Cool. Yeah. Leonard Rosenthol: But yeah, it's a definfined standard. and I'm curious how to find me and I'm curious why you find them interesting. Benjamin Young: No, it's mostly in the context of JSON LD and the processing that would happen there and what those would become. Leonard Rosenthol: Got it. Benjamin Young: And happy to chat about it. I was not familiar with Jump. So, I'll dig into that and then maybe we'll chat. Leonard Rosenthol: Excellent. Yeah,… Benjamin Young: Thanks, Leonard. Great presentation. Leonard Rosenthol: of course. My pleasure. All right. Thank you all for putting up with me today. Mahmoud Alkhraishi: Thank you, onard. And thank you everybody else for participating. Have a great rest of your week. Meeting ended after 00:49:45 👋 *This editable transcript was computer generated and might contain errors. People can also change the text after it was created.*
Received on Saturday, 19 September 2026 20:27:54 UTC