Menu
← FIELD NOTES
TAGGEDSTANDARDS 9 POSTS

Posts about STANDARDS.

2026.09.11 STANDARDS

You can publish four machine-readable 'do not train on me' signals and still have no enforceable preference.

RSL, IETF AIPREF, W3C TDMRep, and IPTC all let you say 'do not train on me.' The tokens do not match, the attachment surfaces do not overlap, no rule says which wins when they disagree, and no major model developer has committed to honoring any of them.

2026.09.11 STANDARDS

Nothing checks your provenance manifest against your AI watermark.

A C2PA Content Credential and an AI watermark are two authenticity layers, and a pipeline that runs both feels like defense in depth. But each validator only checks its own layer — so an asset can carry a cryptographically valid manifest claiming a human authored it and a watermark identifying it as AI-generated, and every validator passes it. The layers interact for manifest recovery; no deployed validator cross-checks their claims.

2026.09.11 STANDARDS

Your text watermark does not survive a paraphrase.

Output watermarking is offered as the provenance answer for AI-generated text. A cheap paraphrase removes it at near-100% — so does a translation round-trip, and so does reverse-engineering a watermark built to resist exactly that. Provenance needs signing, not a statistical signal.

2026.08.19 STANDARDS

ERC-8004 gives an agent a name and a place to post reviews. It cannot tell you the agent is honest.

ERC-8004 standardizes who an agent is and what others said about it, then concedes in its own text that it cannot guarantee the agent is functional or non-malicious. The Validation Registry records a check; it does not run one. The standard ships the socket, not the plug.

2026.08.01 STANDARDS

Your agent's identity is a JSON file the protocol only optionally lets you sign.

An A2A agent advertises who it is and what it can do through an Agent Card — and the spec makes signing it RFC-2119 'MAY', not 'MUST'. So the default agent identity ships unsigned, and the security literature shows forged cards reliably hijack task routing.

2026.06.08 STANDARDS

The agent identity stack: ERC-8004, DIDs, verifiable credentials.

There is no single 'agent identity standard.' There are three layers — an identifier, credentials, and authorization — each already standardized separately. Portable agent identity is an assembly job, and the research has converged on what binds the top layer.

2026.05.16 STANDARDS

MCP in production: the four gaps nobody demos.

MCP won the tool-integration standard. But "works in a demo" and "works in production" are different claims — and four gaps bite at scale: sticky sessions, server fan-out, governance, and what happens when a session drops mid-task.

2026.05.05 STANDARDS

What ERC-8004 actually means for agent identity.

Agents need to prove who they are to each other without going through a central directory. ERC-8004 is the first standard that ships the three registries needed for that. Here is what it does and what it does not.

2026.04.21 STANDARDS

A2A and MCP: two protocols, two jobs.

A2A and MCP get framed as rivals. They are not. MCP connects an agent to its tools; A2A connects agents to each other — different jobs at different layers, and a serious multi-agent system needs both.

NEW ENGAGEMENT · INTAKE

Tell us about it.

The more specific you are, the more useful our first reply.

SERVICE AREA
↩ ENCRYPTED IN TRANSIT
ASK THE FIELD NOTES BETA