Video summary
The Ecosystem & Governance monthly meeting focused on critical updates regarding task force operations and the modernization of the governance meta-model. Significant structural changes were announced for several working groups, including the establishment of a new Reporting Task Force to coordinate outputs for all members and TAC meetings, alongside a specialized group exploring AI-driven automated pipelines for processing transcripts into reports. While manual reporting methods remain an option, other initiatives like the Governance Architecture and Data Modeling task forces are transitioning from scheduled meetings to an on-demand model with notes hosted on Discord channels. Central to the agenda was the review of the current meta-model, which is approximately five years old and lacks coverage for emerging AI agents; the group aims to update it by integrating inputs from existing frameworks such as VLEI and GLYfe, as well as assessments generated by tools like Gemini, ChatGPT, and Claude.
To guide this modernization effort, participants adopted a methodology led by Carla that leverages her real-world experience rather than relying solely on a purely methodical review process. The strategy involves creating a requirements document to catalog current inputs and gaps, specifically highlighting the need to address agentic systems before proceeding with model updates. A major theme of the discussion shifted from static risk assessment documents toward dynamic telemetry and observability mechanisms, which would enable continuous, machine-readable monitoring of decisions and risk profiles instead of one-time evaluations. The group debated the balance between having these systems be fully machine-controlled versus remaining machine-readable with human oversight to ensure necessary safety guardrails are maintained. Additionally, a decision was made to create a shared Google Doc titled "Governance Meta Model V2 Planning" to catalog references, requirements, and the evolution of the framework, with further discussions on converting documents to Markdown for GitHub Pages or utilizing SpecUpT for standardization.
The session concluded with preparations for Verona's upcoming presentation in two weeks, which will showcase long-term work on an open-source project utilizing familiar standards like the Trust Registry Query Protocol, TSP, and W3C DID. The core objective of this presentation is to identify a missing governance framework for such infrastructure and invite attendees to discuss potential solutions. Administrative updates included Carly coordinating with Fabris to submit information to the Linux Foundation's decentralized trust LinkedIn group; she has already sent the link and expects the submission by tomorrow, after which she will post it or facilitate permissions for others to do so. The meeting ended with expressions of gratitude and a formal dismissal, marking the completion of the agenda items.
Read the full video transcript
Hello.
I thought I was in the wrong meeting or
something. Sometimes there were double
links.
>> Double links.
>> Hello. Hello.
>> Yeah,
I have a new budgy.
>> You have a new budgy?
>> Yeah.
>> Do you always have to give the same
names or you give him a different name?
This one was named by the pound.
>> By the pound
>> in the animal shelter.
>> The shelter. Okay. What was it name?
>> Yeah.
>> Her name is Pez. P E Z.
>> Oh, Pez dispenser.
>> Yeah, like a Pez dispenser. [laughter]
Anyway, she's a very nervous budgie. And
she doesn't want to go back in her cage.
[laughter]
Well, I'd be nervous to go back in the
cage. Well,
[laughter] yeah.
[clears throat] Um, so we did not
publicize this meeting and we haven't
met for for weeks or months because of
the break and then the GDC and so, um, I
don't know if we're going to get many
attendees, but
it could be a good planning session
because we've got a couple things
happening.
Sankerstein is working on some
governance stuff and John um put John
Phillips put some governance stuff as
well.
So
hey Stephen
is this recording it just automatically
recording
>> automatically records unless with the
host key you stop the or pause the
recording but the transcript will keep
going.
Okay.
Um,
let's see here.
How's it going, Lynn?
>> Very well, thank you. Good morning.
>> Thank you, Mayor. You guys ready to join
the EU?
Well, that remains to be seen. I don't
know. Pluses and minuses, I guess.
>> Associate member, not a full member, but
>> yeah,
>> sounds reasonable.
>> Regardless of the terminology, it was a
pretty cool speech, I have to say, from
my side of [laughter] the world.
>> Now, now, now the tantrum is is hitting
us. [laughter]
He our president's so upset he's gonna
stop trading full stop with the EU.
>> Yeah.
>> Yeah. Go for it.
>> Cool. [laughter]
>> Yeah. Um
>> after he demolishes the Kennedy Center
[snorts]
is justified. I mean put his name on it.
So
Well, let's look at um let's look at a
couple things here.
>> But speaking of governance, I know Sam
Shan's on the call, so that's cool
because I know he's written a lot of
stuff.
>> Um for those of us who happened to be on
the steering committee call yesterday, I
thought the
>> when it was declared the fastest meeting
ever, which was great. Uh it was the
after meeting part which was actually
much more interesting for me. I think uh
whatever Drummond revealed from that
meeting yesterday was pretty exciting or
interesting I would say. It's
fascinating to think that uh had Bernie
Sanders on stage followed up by Steve
Bannon. So I think that in itself is is
a great
>> uh photo op if they took it. I'm sure
they did. But um
I [clears throat] I didn't catch the
name of the book Drummond was referring
to. If we all if we built it, we all die
or something like that, but
>> I was quite captivated by it.
Yeah, I'm I've not read that.
>> And today even what uh King Charles had
some meetings
>> AI
>> in Scotland maybe about uh putting some
kind of governance around AI with all
the other big leaders there and
Microsoft is saying that um there you
go. Thanks. Um Microsoft was saying now
is the time. So basically we know now
what what it's not a bad logic if you
want to reverse uh think it or reverse
engineer it look we'll build governance
around what we know what we're building
governance around so I think you know
the question is do they they're not
going to stop obviously
but uh the governance may have could
come out a bit earlier especially since
open eye now admitted six more
breaches to put it lightly
>> I mean but There there there was a video
that I watched yesterday that that talks
about this and there's a group that's
actually uh actively uh you know going
to release additional ones and and and
the scenario for getting rid of humanity
is well AI wants more and more
resources. So okay uh do we give people
more resources or do we grab more
resources? So it it's not it's not it's
not a deliberate decision. It's just
we're going to put ourselves first.
Yeah, they I mean just being in Europe
and ever let's say the last three years
when it's really gone warp speed with AI
and and Europe's been beating the drum
about governance and regulation and and
the US is like no no we're going to
regulate ourselves or or let the market
regulate and all this kind of stuff. So
it's good to see that it's it's they're
taking it seriously. But the um the
narrative that I hear as well is that
all these companies are like we need we
don't want open-source AI to to gain any
traction and so by doing this it allow
them to sort of keep a strangle hold on
the development etc.
Well, I mean on the other hand, if
everything is open source, which if I
understand correctly, I mean the next
hour will be Wayne Jean's call, which
will be great because he always has
really good insight into these things.
Um I mean the problem with open source
is anybody could get open source
[laughter and gasps] and and if there's
a governance layer or waiting whatever
they can go, yeah, I don't think I
really want that or here's mine instead.
M
>> so I don't know how you regulate uh open
source
by the time you get around to regulating
it the the genie or the toothpaste is
out of the bottle. I mean it doesn't
it's like what was the what was the line
uh they gave or or Drummond gave an
example of it's like a race a nuclear
race who who pushes the button first
once you push the button it makes no
difference who pushes it second.
>> Yeah. Yeah.
Yeah. they'll be regulated the same, but
I I don't I haven't followed that
thread, but that's just the sort of
>> unless there's some kind of executable
governance, right? I mean, legislation,
by the time legislation comes in, we're
just like a puff of smoke at that point.
Who cares?
>> Well, I mean, in Europe, they won't even
let them release the models. I mean, so
it's [clears throat] I [snorts] I don't
know.
I don't know. Should we start this this
meeting though and we can continue to
talk about that because there's some AI
stuff and then I'll I'll go ahead and
share my screen I think.
Gosh, I haven't been on Zoom in a while.
So, and sorry I missed the uh steering
committee meeting.
Where is this? I think it's this one.
Okay. Can you see my screen?
>> Yes.
>> Okay. Okay. Well, let's go ahead and
start the meeting. The recording is has
um started already. Antirust policy
notice. Um
no need to read it out loud, but you
guys can read it here. Is that legible
for you?
>> We're all members anyway.
>> Yeah. So, we've all done that. Okay. Um
Carly has um she's retired as co-chair,
but um nice. Yeah, she's she's smiling.
Big big smile.
Um but thank you for your service,
Carly. And um we will continue to forge
forward without you and or with you just
joining the meetings. So thank you for
that. Any other announcements we want to
talk about before
uh we get into the meat of the meeting?
Anybody have anything else to
offer?
Do you want to talk?
>> What's that?
>> I just said everything I had to say. I'm
done.
>> All right. Okay. Do you want to say
anything about byite-size trust? Carly,
>> you're on mute though.
>> Uh there are three task force updates
now. [clears throat] So number one,
governance architecture. They are
putting it as a pause on the calendar
but holding the spot.
Byte-size trust. I'm in the midst of
trying to work on some scripts because
trust query protocol is coming up to the
1.0 release and it'll be great to have
some scripts associated with that and
I'm looking for feedback. I posted one
in the trust registry query. I mean it's
on the byite-size trust document. Uh and
then number three there is a third task
force under ecosystem and governance. Uh
and that new task force is the reporting
task force.
>> Yeah, I was going to ask about that.
Okay.
>> Yeah. So the reporting task force right
now um
the so this task force chairs will need
to uh be ready because reporting is
coming up. Reporting for everyone is
coming up. We always schedule it now
right before I
for both the all members meeting slides
and the TAC technical advisory committee
report.
>> So I'm coordinating with Thomas
the uh in the reporting working group we
came up with like a prompt.
So then the different members different
different ecosystem working group uh
sorry different working groups and task
forces can either use the prompt or
discuss manually to pull together the
content for the TAC.
So that should be coming out in an email
from Thomas the
>> I ask what are you prompting?
>> It's a it's a it's a a skill. So it it'
be like
um
there there's a report and you can fill
out the notes about the report manually
and then send them back to Thomas
or
>> where is the content coming from that's
I I don't understand the user
>> that would be it would be from from it
depends on which work what the working
group uses. So for example for ecosystem
and governance we would probably take it
from our confluence notes or the meeting
transcripts
or and or uh if we had anything on
GitHub. So because different working
groups have their conversations
happening in different places. So
>> okay well in our in our case right we're
not too good at we don't bother with
notetaking so it would have to be the
transcripts. So now you want to take the
transcripts from all the calls
>> and
>> what put them into Google notebook LM.
>> Yeah, I guess and then try with the
skill uh like we're we have never
we have never tried this before and I
was try and I was trying to make it
easier for everybody. You can also take
from the steering committee meeting
minutes [snorts]
if there is anything that was discussed
there. Use that as another source
and uh but there is the manual the human
version of it
and you can also just talk about
>> there's this thing called Rosie as well
right? Can't we feed it into Rosie?
>> Rosie is mine. [laughter]
No.
>> So, here's this is the
>> the drafts of the the human.
So, we've had a we've had a a um
a uh a form before.
So, if you want to just fill this out
here while you sit in a meeting and
talk. So, if you want to lead by example
for the other groups, right, we should
probably try to do that ourselves first
and then say this is how we did it.
>> Yeah.
>> And I think the uh most consistent
>> way to do it would just to say download
all the transcripts.
>> Yeah.
>> Um put them I would say notebook LM. uh
the only ones that would repeat I I
don't even think you would want to inter
interfere
with let's say steering committee notes
in your working group notes I think you
should keep it here's my working group
>> here's all all the transcripts
>> and you could say whatever prompt you
you want to come up with whatever you
need at least you play with it like that
and then you say or you say fill out
this report for me
>> right I don't think it has no
I'm surprised that within
Zoom
since it does have the AI note
takingaking. I would have imagined that
it would have this kind of ability
somewhere within Zoom.
>> Yeah. Yeah, it does. I don't know where
the
>> where the transcripts are saved. So, the
transcripts are saved as what likevtt or
something,
>> right? I mean, but you have to go and
download every every VTT individually
and do it. I'm saying since Zoom already
has the note takingaking capability and
since Zoom already has the transcripts,
it seems like Zoom would be the one to
best say if you if there is a way and I
don't I don't have a Zoom account
myself. So, but LFDT would certainly
know this. Most of the work that you
need done is probably available somehow
through Zoom and we just don't know the
right door to open.
>> That's step two. So, we're trying to do
it to be more automated, but that's a
that requires a pipeline and and access
to Zoom accounts and stuff like that. So
absolutely
that would be uh so I'm looking at so if
you if you look at your meeting
dashboard [snorts]
uh um
let me let me uh
>> so
>> if you if you go to the meeting
dashboard
>> yeah exactly in past meetings
>> right you can look at the recording
download the VTT files and down the AI
summary as well.
>> Okay,
>> if you want to download the summary,
>> but I I in my opinion, I would take the
whole transcript, not the AI summary
because the summary is somewhat
>> Yeah.
>> So once you're letting it consume all
that content, I would say
>> if you want to try it manually, it's not
hard. I mean, we could do it for a few
months. just test it,
>> download it, put it into notebook LM
>> and then give it the form that you want
field and say fill out the form.
>> I there's a there is a there is a prompt
that we used and I shared that in there
as well. So it's the second link in of
the docs. So that one had it was more
than just filling out the form and that
came from the work that we were doing
the last time when we wrote the TAC
report Drummond and me and then
shoot what's her name on the TAC she
wrote that so uh um so so it's a bit it
has a bit more than just here are the
headings fill it out
>> okay so this will be uh all this will be
worked through in the task force when is
the task force
Uh
>> uh the task force meet this this this um
>> yeah uh uh we could so in the task force
then next week it it's right now it's
still meeting once a week we could meet
and and test that out with uh ecosystem
>> when when is it when on the calendar is
it
>> yeah uh it is
12 till 100 p.m. on Wednesday
>> Eastern
>> Eastern time.
>> On Wednesday, what' you say? Wednesdays.
>> Wednesdays. Yeah.
>> Okay.
>> And then the other thing is that we are
uh trying to work with other Linux
Foundation members to come up with an
more automated pipeline.
>> Right. [snorts]
The invitation.
Um, so Mackey, I think you go to Do you
have the link? Does everybody have the
link to these um your individual
dashboard?
No, actually it's not that one. It's
this one.
So, you just go to the Linux LF
the calendar.
>> Yeah, there there I am.
>> So, reporting. And does it have a send
invitation?
>> And you can let me see. Can you do that
>> either that? Yeah. I don't know how to
add another invitation.
>> Okay. No, there
>> Yeah.
Or are those past meetings? So maybe go
to the future meeting
>> and maybe they're the
>> There we are. public calendar or or
you're a signed in one.
>> What's that?
>> Are you in the public calendar or
>> I think I'm in the public one?
>> I think I'm in the public one.
>> Well, that should still allow you to add
a meeting.
>> So, let's go to Wednesday right there.
Yeah. And then register.
>> Register. Yeah.
>> You go to a future meeting, then you
register.
And then um I think at that point it's
in all of your
all of your all the meetings will then
populate to your calendar I believe to
your personal calendar but I'm not sure.
>> Yeah that's that that that's correct. I
I did that initially. Yeah.
>> Yeah. Okay.
Um
>> so a question to Carly. What what is
what technology is the skill assuming?
uh Frontier AI model that you can
publicly access and I've made a free
account on one of them on chat GPT and
gave it the skill and gave it some of
the files and but Google LLM would
probably also notebook LM sorry would
also probably work
but but it it can also be done manually.
the [snorts] group can just sit and try
and remember what they did.
It was just that the AI skill was to try
and smooth it out, make it a bit easier
if people have
>> We also want to be consistent, right,
across the groups. Everyone should be
using the same inputs and and hopefully
the same prompt to get the same so the
results can coales at least.
>> Yeah. I I I mean, we're going to keep
trying. This is a continually improving
system because up until now it's been
Drummond and me.
>> Yeah. Okay.
>> Trying to remember.
>> Okay. So that's
>> if you ask Linux Foundation if there is
>> some feature.
>> We're working on that.
>> Join the Wednesday task force. Um and
and you that's where you're going to be
working through all these questions,
right?
>> Uh
technically I mean technically ecosystem
should do it on their own. Yeah, I know.
>> But but I'm gonna so so the next meeting
then uh we're going to discuss the
proposal from AifaQ about running our
own
rag running our own rag and what it
would take to run that at Linux
Foundation and also then we can test uh
um ecosystem at the same time.
[clears throat]
>> Okay.
But at the moment we don't Yeah. So we
don't take notes. We're just relying on
transcripts. And so however we feed
those transcripts into I mean it
shouldn't be difficult. You just say
listen this is what I want the output.
Take all the take all of the transcripts
and and fill it in.
>> Yeah.
>> So okay.
All right. Thank you. So any other task
force updates?
Oh, and the official name of the task
force is reporting tools task force.
>> All right. So, just just a note, I I
took the action item to um
ask for the changes for both the uh
governance architecture group and the
data modeling group in terms of quote
suspending them. So, I'll be feeding the
details. Uh the intent would be to have
notes hosted on Discord
specifically on those channels uh and
also quote suspend the Discord channels.
I need to have some technical
discussions with people with what that
means. Um but that's the the intent. So
you know they're not dead. They're
there. It's not that there's so much
going to be suspended is that they're
both going to move from regular to on
demand.
>> Which which task force are these? the
data modeling and the uh architectural
uh ecosystem architecture task force
under John Phillips and company
>> uh the governance on this one.
>> Yes.
>> Okay. So data modeling. So um
so there
so both of these
are pausing.
Right.
>> Well, they're not pausing. They're just
going from regularly scheduled show up
and you'll have something to on demand.
>> Oh,
>> right. So we're not getting rid of the
time slot. We're not going to drop them.
We're just going to say these things are
not, you know, don't don't show up
assuming a meeting's happening. Uh
they're on demand. So expect an explicit
posting in Discord about an upcoming uh
schedule.
>> Okay.
>> Or upcoming meeting.
>> Does that sound reasonable?
>> Yep. Yeah. Got it.
>> We may eventually move that way if we
don't uh get our act together. So let's
uh see what we got here.
Um,
okay. So, let's go ahead. So, this is
uh, you know, we've been talking for a
couple of months about the direction and
where we want to go and the feedback
that we've gotten is that we should
really, uh, it's time to look at the
governance metal model which is, I
think, five years old. Um, it doesn't
account for things like AI and agents.
It's uh as these trust frameworks are
becoming a little bit more mature and
the Glyfe uh framework for example have
or the VLEI governance framework having
gone through a couple of iterations it's
it's a good time to to assess and so
that has been the consensus of the
working group and people who who've um
made their thoughts known that they'd
like to work on this and so the question
is how do we do that
And um so we we've got here in this in
this um
uh little box some links to the um the
VLEI governance framework. We've got
this um document here that um that John
Phillips has [snorts]
um asked various AI
Gemini chat GPT Gro
Claude I don't know what system is
Grock and Claude um he's asked them to
to assess the governance framework
um and you see the prompt here does have
that. I'll put that in the in the
meeting link here.
Um so this is something we can review
um on this call. Let me go back to the
thing. Um and then we've got um Sankhan
who has put
this together I think. Is that right?
Sankhan are you the author? Is Sashan
still with us?
>> No, not that I can see.
>> Okay. So Sanka put this together.
Governance, authority, and assurance
meta model.
So we could go through this and see if
there's things here that can then be um
fed into the updated meta model. And
this has a you know GitHub repository
where you can see all of these
things if you want to look at that
version.
So
um
so that's that's the the focus. Now the
question again is how do we do it? You
know what's the approach to going
through this? Is it just a really
methodical take a look at the meta
model? Go through the table of contents.
Go through piece by piece. What would
people suggest? And I guess I should
pull up the meta model, right?
I think based on discussions we've had
with Carla is that it would be great.
She I believe she has a bunch of notes
>> on what changes are required because if
we just go through it from beginning to
end, we're probably going to go, "Yeah,
that's good. Yeah, I like that."
So since she actually has real world
experience
uh we should start with her feedback
as uh maybe new requirements and then go
and update the model afterwards.
I don't personally if we just review it
I don't have real world experience with
it. I couldn't say yeah this is no
longer valid or we didn't we skimped on
this.
Okay.
So that's so that's a sort of a glyled
approach. Any other suggestions or
approaches?
>> Haven't we found anybody else using it?
Scott,
>> I've asked a mind.
>> I've asked uh the Bhutan NDI folks and
they said, "Yeah, yeah, we're using it."
It's like, "Wow, you know, how exactly?"
and they're supposed to get back to me,
but
I don't think
I don't think they're using it word for
word. I think they were inspired uh by
its in spirit.
>> Yeah.
>> Right.
Scott said he's used it, right? So, he
must have his own notes as to what
updates he'd want to make anyway. I
mean, that's a
>> to me would be the straight from the
horse's mouth.
>> So, here I mean, let's look at this.
This first one would if we said that the
primary document all right it's a
homepage for the governance framework it
must have a did is that I mean is that
something that is
you know still relevant does it does it
have to be a did or do we want to update
it to uh to to vid which is the higher
class
>> any do any docs have a did
>> or vid do any of the docs any of the
specifications delivered any
deliverables do any of actually have a
real life did.
>> Well, they should.
>> At best, they have a Shaw
[clears throat]
from GitHub,
>> right? But I don't know if they have a
uh triangular did.
>> So, I think that's
>> that was probably um
nice to have, not a must. That was wish
that was inspirational. I think when it
was originally written seven years ago,
that was the inspiration that Oh, yeah.
every document ever did.
>> Okay. But so that Yeah. So that's I
guess the the the conversation we should
have as a group is is that something
that should be updated to say that it
should have a
so the trust spanning protocol I think
and maybe is even the trust registry
query protocol have introduced a concept
of a vid right so it's a verifiable
ident identifier as a sort of an
overarching class and within the vids
you've got did you've got
>> aids the autonomic identifiers
>> and even X509's are verifiable, but
they're not decentralized. So, should we
update this document to say that um the
governance framework must have a a vid?
>> Does GLE give it a
>> I don't know.
>> Has gly given it a did.
>> Yeah. So, I guess how do we do Yeah. Do
we want to actually just
um I mean because these are good
questions that we should go back to and
somebody should take notes. Um
maybe I should take notes. Um
does glide
give
the
uh the lei governance framework a did
okay that's a question.
Okay.
Um,
and then
let's do this
with
um
should we update
must have a bid to vid. Okay.
Um
yeah. So I mean these are the kind of
things I mean we we kind of have to
either ask an AI to go through it like
like John did and say you know what's
missing where are the gaps and that that
will be a little bit more comprehensive
or we just go through it methodically
and say you know what are our opinions
or we wait for GLE to lead.
>> So I know Stephen you're voting for Gly.
Anybody else?
Well, I mean to some extent huge numbers
of documents have been thrown around on
this discussion. We need a catalog. Um
uh I I've tried to capture them as we're
going through here, but I don't have
that catalog. Um uh using gly as as
probably somebody who's had to think
this through commercially as a lead
would be found is actually requirement
and not.
>> I suspect that uh the combination of two
is going to be very fruitful.
Carlos, nothing if if not thorough. Um,
so you know what's that look like going
forward? But you know, we need to have a
repository of all the
information that we're dealing with
here.
>> So,
>> okay.
So, we need to create a document with
all of these
um
references such as this one that
Sankashan has put out, this one that
John Phillips has done.
Okay.
>> Yeah, that that that would certainly be
a start.
>> Yeah. Okay.
What else? I uh I asked the a Glyfe AI
they have a they have their own rag
>> it looks like and they say that yes they
use decentralized identifiers but they
haven't said that they used it for their
darance document but then they switched
from DIDs to car's aids autonomic
identifiers
>> okay
So, I'm gonna keep looking.
>> Okay.
Um,
okay.
We're all becoming part of a carry-on
movie.
I can carry onward.
>> Everything is carry. It's carry all the
way down.
>> Yeah.
Okay.
Anything else?
[snorts]
What about
I mean having a web version of this? It
would it shouldn't take too much to to
turn this PDF into like a website that
you can navigate.
>> Does somebody know how to turn it into a
GitHub pages which would be we could
then put it up on GitHub and have it
accessible as a GitHub pages
on uh the trust over IP GitHub.
to GitHub what pages
>> certainly tools available but maybe even
um Google Docs does it if you could
import the PDF and then say export to
markdown
>> no
>> markdown is native GitHub
I don't know how to do the pages
certainly does
>> as [clears throat] we saw in the link um
but yeah I think just starting off with
uh you know markdown is there's a
markdown editor You could just do it
directly in GitHub. We don't have to
make it more complicated than that.
>> I mean, actually, we should, if we're
going to work and dissect this, we
should probably turn this into a a
Google doc or something so people can
make comments and we can
>> Yep. Good idea.
>> Yeah. Having been through this recently
on on another project, um, generally
speaking, it's first first pass for
general consumption is is Google Doc.
>> Yeah. Um, and then for version control,
it then moves into GitHub and it becomes
Markdown,
>> right?
>> So, so I think that's that that's that
seems to be where where people are
trending. So,
hey, look at this. So Carrie
the sorry the VLEI governance framework
there there's a little bit of funniness
about the language because in in 1.1
about the did
>> Mhm.
>> we said that the organization
>> needs a did
>> who we did.
>> Okay. No no okay the primary document.
Okay. So the primary go document for the
governance framework and it must have a
DID that serves on the identifier of the
entire governance framework. Okay. So
the primary document needs a DID and
when you download the VLEI governance
framework version 4.0 it's called
primary document
>> and it has a document name and it has a
document did URL which is did Harry blah
[snorts] blah blah.
>> Okay.
Okay. So good. That's that's so far
they've got two for two.
>> Yeah.
>> Um and does it have authoritative
references to all other documents in the
governance?
>> I'm looking because it's all on the web
page, but I don't know if it it doesn't
reference it from within
this document.
Soon said, if there's a planned activity
to update the meta model, it might be
ideal to create a list of inputs that
could be examined to determine whether
an update is a minor change or a major
release. At this point, I don't think we
have that input requirements in place
yet. So inputs, a list of inputs. What's
an input? What's an example of an input?
>> The VI governance that I put a link into
that we can use as reference. An example
of an input could be why do you want to
>> change or update the meta model itself.
Like if somebody comes and says that
meta model doesn't cover agentic systems
and it doesn't cover certain specific
aspects of agentic systems.
>> Yeah. Yeah. So you have a well scoped
gap that can be evaluated as does it
does the meta model really need to
include agentic systems or if it does
how does it cover that and so on and so
forth.
>> Okay.
>> So
>> yeah sounds like a GitHub issue to me.
Uh yes,
>> it it does work well if it's a GitHub
issue, but uh and I see a quite a few
groups in trust over IP adopting that
path. I'm not sure if this working group
is keen to go down that route.
>> Not yet.
a list of requirements or inputs
requirements that will um help determine
um
whether or how the the governance
framework might updated. Okay, so we've
got Yeah, I mean I think that's the big
one is AI and Agentic AI systems. Um,
yeah. So, maybe we can
Yeah, Mackie, that's what we're trying
to get is we're trying to get Carla
because I think Carla's been taking
notes over she they have to update it
like once a year or something. So, she's
been taking notes. Um,
should we start a document now?
>> So, we can, you know, put this in a in a
document that then is distributed and
people can contribute to.
>> Yeah. Are you going to do it in Google
Docs? Because my problem is now nobody
every time I try and share something
from the trust over IP Google Docs drive
nobody has access even people who should
have access
>> and and uh uh uh um the uh we we could
put it in GitHub markdown and I'm a
speaking as person who hated GitHub
[laughter] at the beginning but
eventually I learned it doesn't have to
be trusted of IP Google I mean doc does
Yeah. Okay.
>> Um,
>> discovery is a bit harder then.
>> Well, then somebody's going to have to
own it. So, if we say ecosystem
governance working group, let's see if
we can do here. No.
>> Yeah.
>> Here we go. It's called um
governance
>> data model V2
>> governance meta model
um V2
planning or whatever.
Okay. So
let's call share
save it.
Let's just copy a link and let's see who
gets it.
Who can access that?
>> I can access it.
>> Everybody. Okay. All right. So, this is
in this is within the
shared drive ecosystem governance um
working group folder.
And it's um so so okay everybody's got
it. So let's work on this document.
And uh where'd it go?
Right there. And um we'll do the list of
requirements why we want to do this.
will have a reference of a catalog of
different references for Sankers's work
and for John Phillips document
and to the Golia VLEI governance
framework etc. So we'll start just
working from this document to um to kind
of work our way through this whole
process.
Everybody happy with that
>> about the alternative
is based on a metal model but not not
exact. So I think Sakshan I think so Gly
have I think the the Glyfe version is
practically
like mirror version of the meta model
but it's in all of the control documents
where things just become um tailored to
the specific environment and the use
case. So I think if we look at the um
maybe we can do that maybe we can run
the GLY framework the BI framework
through AI and give it the meta model
and say does this match up? Is there
anything that doesn't match up? I mean I
don't know what that will tell us but
>> I think that would be problematic.
>> Why?
Because the meta model started off maybe
like 14 pages and gly must be hundreds
if not thousands of pages.
>> Yeah.
Engineer to the 14 pages and see how far
it's diff. It's going to be
>> thousands of pages of diffs.
>> Um
well you can give us some guidance
monkey.
Yeah, actually I think it's it's a good
idea if we can start envisioning how
that would look like from our own
perspective and then I think you know
meeting with Carla could you know like
we can then go through it with Carla and
see what's missing uh because you know
like really at the end of the day I I
think she should be able to gather some
feedback from the community who who used
it already. Uh but I think from our own
u you know like proposal like we can
propose something and then connect the
dots with with her. Um yeah at least you
know we can find gaps uh uh maybe you
know we can envision for example that it
needs to include agentic as you know
like uh Sankrashan just mentioned
>> you know like any other uh dimensions
you know we are we see that would be a
requirement for the next version um and
then you know we can work backwards uh
or even adjust uh based on her feedback
um yeah
>> yeah okay so we'll get Carla we'll we'll
We'll um send this document once we get
it started. Um this one, not that one,
this one. And get uh so we'll do I'll do
an introduction
and start making this document a place
where everybody goes to figure out
what's happening. And uh we'll insist
that we we really need Carla's help to
get us going on this journey.
Yep. Yep. Yep. Um Carly,
>> I think we're going to have to
eventually have this in spec up T.
>> Okay.
I mean, we want to get it to a point
where it's
>> so
>> so then it would make sense to actually
get the the meta model either word doc
or get a a word version or a Google doc
version and then
>> I mean
>> and then export in a smart well then
figure out how to get it into specup t.
It might be I
maybe I will look into starting at
specup T because it might be a lot of
work to retroactively fit it. We'll see.
>> Okay. So
calling to
expect spec
um
sp
Okay.
Do we want to take a look at this um at
this? Where' it go?
Where did it go? This one. No. No.
Where's John's?
Should make that bigger.
So
these are based on this prompt. I want
you to act as a PhD level research
assistant and research the
state-of-the-art of governance of AI. So
this comes from the perspective wow is
this today done today um that that they
believe that it is missing
uh it's it's not perfectly relevant for
uh AI at the moment and so they want to
figure out where the gaps are. Is the
TOIP governance framework suitable for
AI governance as is? If not, what needs
to be done to enhance the meta model to
address AI governance? So this is the
early returns telemetry. Who can tell me
what telemetry means?
>> Basic. It's [clears throat] basically
the equivalent of airline, you know, an
aircraft telemetry,
right? It's basically it's a diagnostic
uh stream.
>> Okay. Byte-size trust. Carly
telemetry.
So replace static risk assessment
documents with a telemetry. An
observability control document.
I
>> think you say telemetry.
>> Telemetry.
>> Not a telemetry. No.
>> With a with a telemetry and
observability. Well, yeah.
>> That's a Canadian pronunciation. We say
tele. [laughter]
you in there somewhere.
>> I I'm still don't understand what it is.
Telemetry.
>> It's actually try to tell me.
>> So replace static. So at the moment the
the risk Yeah, it's probably right. The
governance meta model says all right
identify the risks and then construct a
um a framework that addresses those
mitigates those. So the government meta
model that we have right now takes the
uh
risks and puts them in some sort of a
what is could be described as a register
and then through various uh processes
allows the evaluation of the risks in
terms of how they would pan out when the
governance framework is adopted by any
deployment. I think what uh John's AI
adventure is suggesting is that this
one-time activity will end up being
fairly fluid and thus no longer it's
static and end up being versioned so
that at any point you are able to run
audits based on a particular version and
figure out what your risk profile is and
how is the government's framework
managing to handle the risk.
Yeah. So this is the the I mean just the
general trend in cyber security and and
others continuous authentication
continuous
um
um well observability. Yeah. Maki.
>> Yeah. actually you know I I just wanted
to mention that to move away from that
the static uh you know note version um
that's the reason why we wanted to have
some tools to enable uh implementation
like the risk and principles document we
started with so I think this will be
very fluid like later on if anyone would
like for example to adjust or add to the
risks and and the uh principles that
could be done so I think um this could
be more into the implementation tools
like enabling the governance metadata
document uh basically
Um uh but you know like I just had a a
comment in terms of the second one uh
the telemetry and observability when it
comes to mandate carry anchored
continuous machine controlled I think it
will be safer to have machine readable
as opposed to machine controlled you
know machine controlled could be like
aentic which which could you know raise
a lot of threats like you can use
agentic but you need to have some sort
of you know like um you know guard rails
or or you know some some um uh methods
that you can um basically have uh human
enablement in the process. So I think
will be good to have it as machine uh
readable. Um Gary anchored I do agree
with this. U I think things are are
shifting towards Gary. U we've discussed
this before as well.
>> So how would that work if you've got if
you've done a risk assessment? You're
like okay we know industry we know our
use case. you know, um the data we're
playing with whatever we've got our risk
assessment and if you move that to an
ongoing sort of continuous risk
assessment, how does that get fed back
into the governance framework and
updated
>> or the governance document should be?
Yeah, I think it should be as broad as
possible like without really becoming
like a policy kind of uh document. I
think it should be like a high level
guidance and then you know the tools
could could enable us to fluidly you
know uh implement uh also the tools can
can help us you know like um update
rapidly like uh like moving away from a
static document. So I think the next
version should be like very uh I would
say u fluid like very broad uh document
broader than the first uh version.
>> Okay. I mean I think we should it would
all be good it would be good for
everybody to if we just reread this
because I think it is fairly generic
and all the real
>> it is designed to be generic.
>> Yeah. So for instance, if I go back to
the question you had,
governance framework at a meta model
level will essentially just mention that
>> you will need to have a risk register of
some sort that's likely machine readable
and continuously updated and managed and
controlled. It is not going to give an
entire let's say a vocabulary of risks
to populate a risk register or it could
give it as an example in an appendix of
sort but the main uh declaration would
be that you would need that you require
that artifact to have be present.
>> Yeah.
>> It will not go deeper into what the
shape and form of that artifact would
be.
>> Right. Yeah. Okay. Yeah. So that just
missing. Huh.
So, so just a thought here I mean
[clears throat] what I think is missing
is you know uh static risk assessment
documents with operational tone watcher
it's the decisions that are being made
you know under the opaces of a
specification
right so you need to have observability
of decisions being made using the
specification
right if you design a process for you
know flights for aircraft
>> you know there's There's policies about
how you fly, how you, [snorts] you know,
how you follow a route, how do you
interact at at way points with air
traffic control. Um, and the telemetry
is all about the actual operations. It's
it's the verification that the process
is being followed.
>> Okay.
>> Um,
>> so telemetry about the documents is
uh you know the specifications is
nothing more than version control and
version handling management.
Okay. So, yeah, that's going to have to
those are the kind of things are going
to have to go into
people language. I don't understand any
of this.
>> I I don't even know what like so
telemetry is like
real time ongoing collection and
transmission of the data. And how on
earth would
>> well it's it it's not necessarily the
data. In this case, we're talking about
documents. It's about decisions that are
being made about the implementation of
the specifications.
>> But they're saying replace risk
assessment documents
>> with a telemetry
>> an observability controlled document.
Like
>> is that is that just slop? That's like
implementation.
>> Yeah, I think to me that it's it to me
it says you were going to work on git
control documents and if you make
changes to those git control documents
then there should be a notification.
So I'm not I haven't looked through this
document that John had shared uh but I
think given what the prompt is it is
attempting to reshape the existing meta
model framework and trying to highlight
if the meta existing version that we
have were to be expanded to cover
agentic systems what are the capability
gaps that it should also factor. in so
telemetry, observability and all of that
are capability gaps. Now I think that
one of the things that I should
emphasize is we
want we would like to begin by
considering that we have this existing
meta model version and then create a
requirements document that is gathering
from
>> as many inputs sources as possible and
then evaluate in terms of how the next
version would emerge. So the agentic
document that John has is not is very
focused on one particular problem to be
solved.
>> Ensure that a metal model meets the
agentic world.
>> Yeah. Yeah. Yeah.
So I mean that that's I guess that's the
point is that yeah we we need to
there's you know no shortcuts. we need
to go through these these documents and
this is very specific to the prompt of
you know is it suitable for for AI um
and where are the gaps but that's just
one aspect and if we um so we've got
here in the notes
to
um begin a list of inputs requirements
that will help determine whether and how
the government's framework might be
updated. So what's missing? What are we
trying to get out of an update? What are
we trying to address? um etc. So I'll
try to write that into the um into the
introduction. So I'll try to put this
here. I'll get a starter text here.
Everybody contribute so that we all
understand what we're doing and why
we're doing it. And then once we're
happy with that intro, then we can sort
of go off and and look at all these
different um um references and start
working. But we've got a minute and I
just want to make sure everybody knows
two weeks from now Verona is going to
come and present and they're going to
present what they've got. They've been
working on it for a long time. It's open
um source I believe open standards for
sure. They're using all of the standards
that we're familiar with trust trust
registry query protocol. They probably
they might have some TSP in there. They
got DIS W3C uh bur fiber credentials
etc. Um, so they'll present that, but
then they're going to get to the point
after the presentation where they're
saying, "We've got all this. What we're
kind of missing is a nice um, governance
framework." And so that will lead to a
discussion where we can um, exchange
with them about how that might look.
Carly,
>> so if you share with me the ad and the
info, then I have permissions to add it
to Linux Foundation decentralized trust
LinkedIn.
Okay. Okay. Yeah. I've already sent them
the link so they can fill in the
information and I hope to get that by
tomorrow.
>> Yeah. Okay. So then make the picture and
the and the info and then I can post it
I will I can post it up and if somebody
then wants permission to post on Linux
Foundation
>> LinkedIn
>> uh yeah or or you can submit to get your
own permission to do that.
>> Okay. But so this is with Fabris uh who
has been part of the trust registry
protocol and we we you know so he's part
of trust over IP and they've been
working on this for a long time. They've
they've built some you know interesting
stuff and they've got some interesting
use cases but their um whole um point
after the presentation is to talk about
you know how can infrastructure like
this be governed. So um please join in
if you can.
>> Yeah. Yeah. Let's get that ad out
because uh trust registry query protocol
>> was looking for people who are working
with trust registries.
>> Yeah. Okay.
>> Okay. Good. Thank you.
>> All right. Thanks everybody.
>> Bye.
>> We'll call it a day. All right. Thank
you.
>> Thank you. All right. Cheers. Bye. Bye.