[agent2agent] Re: [Din] Re: Proposal for IRTF RG on Confidential AI and my thoughts on AI BoFs
Olga Levosiuk Musk <olgalevosyuk@gmail.com> Thu, 30 July 2026 17:26 UTC
Return-Path: <olgalevosyuk@gmail.com>
X-Original-To: agent2agent@mail2.ietf.org
Delivered-To: agent2agent@mail2.ietf.org
Received: from localhost (localhost [127.0.0.1]) by mail2.ietf.org (Postfix) with ESMTP id D0F7A1212FD41 for <agent2agent@mail2.ietf.org>; Thu, 30 Jul 2026 10:26:11 -0700 (PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/simple; d=ietf.org; s=ietf1; t=1785432371; bh=cAkw8O1sF+hovmO/eAG9KTLvjkrMop6LD8IuHitzj+A=; h=References:In-Reply-To:From:Date:Subject:To:Cc; b=lyIvgSQiNSNoLwEINPS7KBRZmFAsq3ojUhBINNygOkoIqLsb9u0zrOMqqHe/qYU90 Kyj5RGugGD4Z6dz5cXyxbagRhTmS+7R3b58fjY6SYcc17SNBykRj3nF1YJRt4wElmv w/aXZvYIRL5B3ecsMC++1T7WkPjOaaQguBtOoZnc=
X-Virus-Scanned: amavisd-new at ietf.org
X-Spam-Flag: NO
X-Spam-Score: -0.506
X-Spam-Level:
X-Spam-Status: No, score=-0.506 tagged_above=-999 required=5 tests=[BAYES_00=-1.9, DATE_IN_PAST_03_06=1.592, DKIM_SIGNED=0.1, DKIM_VALID=-0.1, DKIM_VALID_AU=-0.1, DKIM_VALID_EF=-0.1, FREEMAIL_FROM=0.001, HTML_MESSAGE=0.001, RCVD_IN_DNSWL_NONE=-0.0001, SPF_HELO_NONE=0.001, SPF_PASS=-0.001] autolearn=no autolearn_force=no
Authentication-Results: mail2.ietf.org (amavisd-new); dkim=pass (2048-bit key) header.d=gmail.com
Received: from mail2.ietf.org ([166.84.6.31]) by localhost (mail2.ietf.org [127.0.0.1]) (amavisd-new, port 10024) with ESMTP id fz5dLOiOW7rH for <agent2agent@mail2.ietf.org>; Thu, 30 Jul 2026 10:26:11 -0700 (PDT)
Received: from mail-pj1-x1033.google.com (mail-pj1-x1033.google.com [IPv6:2607:f8b0:4864:20::1033]) (using TLSv1.3 with cipher TLS_AES_128_GCM_SHA256 (128/128 bits) key-exchange X25519 server-signature ECDSA (P-256) server-digest SHA256) (No client certificate requested) by mail2.ietf.org (Postfix) with ESMTPS id 487AA1212FD30 for <agent2agent@ietf.org>; Thu, 30 Jul 2026 10:26:11 -0700 (PDT)
Received: by mail-pj1-x1033.google.com with SMTP id 98e67ed59e1d1-38e347638adso219057a91.0 for <agent2agent@ietf.org>; Thu, 30 Jul 2026 10:26:11 -0700 (PDT)
ARC-Seal: i=1; a=rsa-sha256; t=1785432370; cv=none; d=google.com; s=arc-20260327; b=jk6FZjRZ7H4b5sGVnbTeZYzSoAyI+QKNa/D7jE8SRqI/3zB6HlnaQMhT85GSpg3nlt u/0YE+tiEvGp+DaklfcYsLuhLw6lM3dzfmKb40PJNnKfetK6iuBhY2/ZxkP7sLaadSRy ers0fwbBybd8fx+g/HZnqz0CLd1upvHnjCqZnhEGoCEVUvibgug9yTOF6Cf4X7QcbCEF bPEiDdMN6etZfEA4+ArYSBqFqINK/HSwyhRYoIlZ+H3+cWaamniUjgAvBSy6Ym7UN5JL Dpanqzouqf2GhyZ4+wLluH/0e6sJkdMTi7joftZBQ29BL9K31qsKWL9Gplc6lehiQSnq EBNQ==
ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=google.com; s=arc-20260327; h=cc:to:subject:message-id:date:from:in-reply-to:references :mime-version:dkim-signature; bh=cAkw8O1sF+hovmO/eAG9KTLvjkrMop6LD8IuHitzj+A=; fh=hBt/Bpi+9WS99NPjcPmgXnsop72b0MurTKPwf9aQ9Hc=; b=Q4m01ucJ42W5N6/3kPiFT/UR5YpDp1V24LmQAVbNbldIwv4/TqzjOLxTi+HFwaraLx +t/JkoFJBEy8eJGO4e25g9FclOYOroMcQEsz2lsUkUHohlnqCCccr5g6M2S0O95GNEgM Uy10wYtM4MbFpdaxNvqUcApkSHxkD6RfwNVvX29YDmCrmFGubp/qrZ8Uom3O5dlL9Q/O hUdQMY38beTe82WS9eVcvfZU8OCAwobCHzJVEqWxeKgFKgwbwewrh6lOw5Io7nR8sO6S Lvt8PN7OfXv2xH4M1GxtOitFe9YajninxvOuAI7Pdxtd6Cy3ozLHL1+e8w4I33R3FP9D q1Mw==; darn=ietf.org
ARC-Authentication-Results: i=1; mx.google.com; arc=none
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=20251104; t=1785432370; x=1786037170; darn=ietf.org; h=content-type:cc:to:subject:message-id:date:from:in-reply-to :references:mime-version:from:to:cc:subject:date:message-id:reply-to :content-type; bh=cAkw8O1sF+hovmO/eAG9KTLvjkrMop6LD8IuHitzj+A=; b=a4uZNcvXW6QwPiuET3nA0QG+i8zKcFLjrC4C+R0aY0uI1KDaLD/HXB6GLVu+akVhYb esKmhWAEPSK1lJV4pShKnmsbEgMoJ1ePBva+O/D7fSTBozyH7hG9GmvugTIOwoE41ZsM 1TdkZ5zP8AeHn5wysCPuRpAMaikLFlH4lIIXC+v7+zBhIKusxOsUeE47fimV9VRMzOCd odmY7BTyhgnNDwAlU9Fwdc9rpYWZO2qvrUg+LZD1oDU3tQzi8LEImxCSKQiyDwg598aT +OcGETULVTjcumVL0pawfy91TfGfHhl3wiB9GVTF25Oa3fD1ooQgeUcQgA7wvHkJTxoM RL/A==
X-Google-DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=1e100.net; s=20251104; t=1785432370; x=1786037170; h=content-type:cc:to:subject:message-id:date:from:in-reply-to :references:mime-version:x-gm-gg:x-gm-message-state:from:to:cc :subject:date:message-id:reply-to:content-type; bh=cAkw8O1sF+hovmO/eAG9KTLvjkrMop6LD8IuHitzj+A=; b=dOw5imi9AFo6LV6fvtD9f8I7CWEfiC1H6OmiAc+u+R1QwINe9mG/5JxLbi5o1iFHM9 WILO6dul7MYlfU75UDouKue80+uMuxoXYCKX/zajXLPiiA72rfblLQveecGc5LQEnuq9 p9uX2/wY64f1plrVioPPboz3w9JjLKZMM+asdW/Yma7c6KvLc9e8CUoOUcq4VxZ61R85 xdbG8rPBs5aB8kh01boVG47PgNrTCrTUCimP9xmuSGYBEHdDiJZvNJjJiMWahqgYKxKc 4ZCdaVMD1ugCBj2fjgGvQrfrBclQbXp35jl0B3vR+IdGBMyDB+2clSdDpUPB6w3JKhWS pYTg==
X-Forwarded-Encrypted: i=1; AHgh+Rrk7wKEkYXuS3cD/cCCDd+pyoCWhk7aAtEgfbnAF6Y7Oi2KpyHxInde7LNjbxMxhHTBeKHtHNktDlPAOA==@ietf.org
X-Gm-Message-State: AOJu0YxUXU0CPb1gR+MiPaM8mVGRoD1QCdtv1p23T+cvESZ4TQH2Zjtt nVX40eBc3Ml4nzhdNuJgKn0bjLpsBdhr+3ISmR8QyePYa7Oo9z4OVH5oyJKImE9irpEafnf80kT DEVdhRHfwE3jbRcD0UAgi27UwNjqzNn4=
X-Gm-Gg: AR+sD119Bzx5MhK7fywdaDPTcpSIBqd29ECg9BJ70DnHQqXaeg6jOhXwIxauWruuB6G cWqNGV4464LrRFNrrPh8EUCpmTlEboDgEyqDnewxk57s5jpdwrWdANjht8Pxlzxn8jqjSbJYj3d jYIDKYvBZLd4RcdasXzFp9h3MPcqKgbMvf8lwM0L1gOQ+0FGx5VDv08BDNDG1eXHso81Bzm3wUk AOqyEBrd8gwx55SMyxB/UcPcl0/Y+y7RHkSrLdbnZhmXGz0EMBwSR8dj2QlxcwRp3CmBxH7255a QQJNmYoUx+cbDHX1bFxudYowgKZcnDNxSvZdKEggfrQ=
X-Received: by 2002:a17:90b:4c92:b0:37f:9ce1:cdb2 with SMTP id 98e67ed59e1d1-38f9c032ba8mr2846486a91.32.1785432370309; Thu, 30 Jul 2026 10:26:10 -0700 (PDT)
MIME-Version: 1.0
References: <ed7fc715-65b3-4df4-adff-5364e2064286@tu-dresden.de> <6b2b3cc0-9743-43dd-966d-14bb09ffe657@tu-dresden.de> <e670f09e-c625-4965-8023-fbf3c1d1c715@tu-dresden.de> <CAOfgHgq_6Z+CgAewZr+g=aD_de_k1CY1jHyp7L6rq7VoRZ_j7w@mail.gmail.com>
In-Reply-To: <CAOfgHgq_6Z+CgAewZr+g=aD_de_k1CY1jHyp7L6rq7VoRZ_j7w@mail.gmail.com>
From: Olga Levosiuk Musk <olgalevosyuk@gmail.com>
Date: Thu, 30 Jul 2026 14:44:08 +0300
X-Gm-Features: AUfX_myuVlW3Eq9IEKMntmZXSZEX9W6izat_rVOEzdvm5zTs9M-Eeh4p1_8JF0U
Message-ID: <CAD3bTqyQV23t=uOvq3XORWAYpcyXj+36bMdVDzVunAQ+9tG0Kg@mail.gmail.com>
To: Iman Schrock <team=40emiliaprotocol.ai@dmarc.ietf.org>
Content-Type: multipart/alternative; boundary="00000000000033ef7f0657d75e94"
Message-ID-Hash: EN7OPVIF4XEBPJXNWPSOG3FBZ4K3CO75
X-Message-ID-Hash: EN7OPVIF4XEBPJXNWPSOG3FBZ4K3CO75
X-MailFrom: olgalevosyuk@gmail.com
X-Mailman-Rule-Misses: dmarc-mitigation; no-senders; approved; emergency; loop; banned-address; member-moderation; nonmember-moderation; administrivia; implicit-dest; max-recipients; max-size; news-moderation; no-subject; digests; suspicious-header
CC: Muhammad Usama Sardar <muhammad_usama.sardar@tu-dresden.de>, agent2agent@ietf.org, din@irtf.org
X-Mailman-Version: 3.3.9rc6
Precedence: list
Subject: [agent2agent] Re: [Din] Re: Proposal for IRTF RG on Confidential AI and my thoughts on AI BoFs
List-Id: Standardization of AI Agent Communications <agent2agent.ietf.org>
Archived-At: <https://mailarchive.ietf.org/arch/msg/agent2agent/QsJ0yzc0tIAE9LdBmQBa6OfFi-c>
List-Archive: <https://mailarchive.ietf.org/arch/browse/agent2agent>
List-Help: <mailto:agent2agent-request@ietf.org?subject=help>
List-Owner: <mailto:agent2agent-owner@ietf.org>
List-Post: <mailto:agent2agent@ietf.org>
List-Subscribe: <mailto:agent2agent-join@ietf.org>
List-Unsubscribe: <mailto:agent2agent-leave@ietf.org>
Hi Everyone, Thank you very much for your email with the merting results! I am regret to be unabled to be online, as a lack of the Internet in Ukraine in Rivne City didn’t allow to get in touch in time appointed by the Staff. I had already read all the assumptions and feedbacks of the meeting. I do think that the AI tools, including AGI, are to be exist. To be further I need to come to the U.S.A. Office as now I am staying in Ukraine in Rivne City due to my job requirements during the russian-Ukrainian war started in 2014 till nowadays. Hope to see you as soon as possible to continue Elon Musk’s deeds as his partner and wife from 1991 till His death on August 1,2025. I serve to the U.S.A.! Semper Fi! Stay safe, please! Have a nice day! Hope to hear from you soon. Sincerely yours, Olga (Olha) Levosiuk Musk, the Minister of Defense of the U.S.A.; the Marshal of the Air/Navy/Military/Space Forces of the U.S.A.; the Chief of the FBI (DoD (DoW), DOJ, DOGE, ICE, BoP, DOE); Prosecutor/Lawyer/Attorney of the U.S.A.; the Senator of California and Texas elected in 2025; Actress/Model/Singer/Composer/Clip and Film Maker/Script writer; the Oscar winner and Grammy winner; the Miss of the U.S.A. and Miss of the World; the U.N.O. Peace Angel; Educator/Tutor/Trainer/Consultant/NGO-leader/Sociologist/Social worker/Data Analyst and AI Management and Business Administration; the Founder/CEO of Tesla/X/Starlink/SpaceX/Neuro(a)link in the U.S.A; staying in Rivne, Ukraine, cellphone:+38(067)3695909 чт, 30 лип. 2026 р. о 00:31 Iman Schrock <team= 40emiliaprotocol.ai@dmarc.ietf.org> пише: > Hi Usama, > > I think your question on slide 20—what is genuinely special about AI > compared with other software—is the right filter for the charter. > > At the confidentiality and attestation layer, often nothing is > AI-specific: the same workload identity, channel binding, > supply-chain, CPU/GPU composition, key management, replay, and > appraisal problems apply to other distributed workloads. The > AI-specific pressure appears when an attested workload is also a > probabilistic decision-maker with delegated tool authority, mutable > context or memory, and the ability to choose and cause consequential > external effects. In that setting, valid evidence that approved code > ran in an approved environment still does not establish that a > particular principal authorized the exact action, that the action > admitted was the action invoked, or that the observed outcome > followed. > > That suggests a useful venue split rather than a new AI-specific > cryptographic stack: > > - DINRG/INet4AI can likely absorb the distributed identity, placement, > internetworking, stakeholder, bootstrapping, and layered-system > questions where the workload being AI is mainly motivational. > - A Confidential AI RG would be strongest where it develops research > around compound CPU/GPU/accelerator attestation, adversarial use of > confidential computing, cross-layer evidence composition, and the > limits of what attestation can prove about an agent’s authority and > effects. > - Existing IETF work such as RATS, SEAT, TLS, OAuth and WIMSE should > continue to own the corresponding protocol mechanisms; the RG can > supply rigorously scoped use cases, attack models, and negative > results rather than duplicating them. > > A concrete use case we can contribute is an attested agent that > requests a consequential action. The research question is: what > additional evidence and boundary conditions are required between “this > workload is genuine/confidential” and “this exact real-world effect is > authorized and safe to admit”? We already have negative-vector shapes > for valid attestation paired with wrong principal, wrong action, > stale/revoked evidence, replayed admission, and outcome evidence that > cannot be independently reconciled. I would be glad to reduce that > into a short use-case contribution mapped against the 13 questions > before you approach the chairs. > > My concise answer is therefore: AI is not special enough to justify > duplicating existing security protocols, but delegated, probabilistic > action makes the gap between workload attestation and consequence > authorization unusually important and research-worthy. > > Best, > Iman > > _______________________________________________ > Din mailing list -- din@irtf.org > To unsubscribe send an email to din-leave@irtf.org >
- [agent2agent] Public Side Meeting on Confidential… Muhammad Usama Sardar
- [agent2agent] Re: [Din] Public Side Meeting on Co… Olga Levosiuk Musk
- [agent2agent] Re: Invitation for Public Side Meet… Muhammad Usama Sardar
- [agent2agent] Re: [Din] Re: Invitation for Public… Muhammad Usama Sardar
- [agent2agent] Re: [Din] Re: Proposal for IRTF RG … Muhammad Usama Sardar
- [agent2agent] Re: [Din] Proposal for IRTF RG on C… Iman Schrock
- [agent2agent] Re: [Din] Re: Proposal for IRTF RG … Olga Levosiuk Musk