Sign in

Fraser

@fraser.bsky.social
56 followers 6 following 380 posts

CEO @ Authrty & cheqd: building trust and governance layers. Identity, credentials, an FinOPs for AI agents and individuals | Ex-Accenture | Climber, Cyclist

PostsRepliesMedia
Fraser @fraser.bsky.social · 14h
. @Google's @GeminiApp AI summaries not getting extreme basics like the correct time really does not inspire confidence in AI... Thanks to @EHotta for flagging this!
000
Fraser @fraser.bsky.social · 16h
For Dots I want to see how many people set one up and whether it's still doing real work for them a month on, and nobody outside Meta or OpenAI can see that yet.
000
Fraser @fraser.bsky.social · 16h
So the number I'd watch is permissions: whether these agents get your inbox, your card and your passwords, and whether those grants survive the first month.
100
Fraser @fraser.bsky.social · 16h
The controls around Dots are written and enforced by OpenAI, so in both cases a court is the only independent check, and it arrives years after the harm.
100
Fraser @fraser.bsky.social · 16h
OpenAI has no verdict against it, though it faces open allegations of its own, including a Florida attorney general suit and a class action over tracking pixels: untested isn't the same as trusted.
100
Fraser @fraser.bsky.social · 16h
this year.That doesn't show Muse will misuse anything, but it is a reason to weigh up the promise rather than take it at face value.
100
Fraser @fraser.bsky.social · 16h
"Secure, private" is exactly the kind of statement the Santa Fe jury found Meta misled users with, now made about your inbox and your card rather than your posts, and the Secure VM is closed to Meta by company policy rather than by design, with a Confidential VM promised later
100
Fraser @fraser.bsky.social · 16h
two weeks, @Apptopia says over 95% of its users were already on @Facebook, and an @Oppenheimer survey reportedly has only 8% of US consumers trusting Meta with a password. Does Meta's record matter here? Not for downloads, but it matters for what Muse is selling.
100
Fraser @fraser.bsky.social · 16h
It seems to be priced in that Meta will say one thing about your data and do another, and people download its products anyway, which says the downloads measure Meta's distribution more than trust: by Sensor Tower's count Muse took up to half of Meta's own house-ad impressions for
100
Fraser @fraser.bsky.social · 16h
- 29 Sept: @OpenAI launches Dots, always-on agents with their own cloud computer and, it says, read-only defaults on proactive work and approval rules for sensitive actions
100
Fraser @fraser.bsky.social · 16h
- 25 Sept: a Santa Fe jury finds Meta misled users about protecting their data, with more than 43 million violations, five years after New Mexico filed and eight after Cambridge Analytica
100
Fraser @fraser.bsky.social · 16h
- 8 Sept: @Meta launches @Muse, a "secure, private" agent with access to your email, calendar and payments, and it reaches around five million downloads in three weeks (a @SensorTower estimate)
100
Fraser @fraser.bsky.social · 16h
Three weeks, three data points on how much we trust the companies building personal agents:
100
Fraser @fraser.bsky.social · 02/10/2026
I do this for a living and I still came away unsettled, somewhere in the uncanny valley where I couldn't tell who or what I was dealing with.
000
Fraser @fraser.bsky.social · 02/10/2026
That is the non-human identity problem in a microcosm, automation acting through human accounts with no way for the person on the receiving end to verify who or what is acting, so platforms guess from behaviour.
100
Fraser @fraser.bsky.social · 02/10/2026
Different channels but the same pattern: a human face on something that isn't behaving like one.
100
Fraser @fraser.bsky.social · 02/10/2026
Then, the same week, I booked a call with a BDR and was handed over to a real person. Three of their “colleagues” then sent me the same reminder at the same moment, word for word, down to a template glitch that repeats "Here's the meeting link" twice (screenshot below).
100
Fraser @fraser.bsky.social · 02/10/2026
Goodhart's law does the rest: “when a measure becomes a target, it ceases to be a good measure”.
110
Fraser @fraser.bsky.social · 02/10/2026
Quality gates are always an arms race, and I suspect the missing comments give it away: likes are trivial to script, while a convincing comment costs more and is easier to flag, so the cheap signal gets farmed first, as always.
100
Fraser @fraser.bsky.social · 02/10/2026
Reactions are a commodity signal, cheap enough to script or trade that a burst says nothing about the engager's tooling or about whether anyone read the post.
100
Fraser @fraser.bsky.social · 02/10/2026
There were no comments, it hasn't happened since, and my best guess is one large account with a lot of followers and itchy thumbs, but not being able to tell left me both curious and a little uneasy.
100
Fraser @fraser.bsky.social · 02/10/2026
I got around 20 reactions on a post in under ten minutes on @LinkedIn this week, almost all from leadership coaches, and I couldn’t tell whether a person, a pod or a script was behind any of them.
100
Fraser @fraser.bsky.social · 30/09/2026
That gap: who authorised what, under what constraints, and whether the record proving it can actually be trusted, is exactly what IVOs, suppliers and the underlying verification technology now have to answer.
000
Fraser @fraser.bsky.social · 30/09/2026
California has removed the excuse and the frontier labs have admitted they don't know what fills the gap it leaves behind.
100
Fraser @fraser.bsky.social · 30/09/2026
I'd expect other states and other countries to follow California's lead here, since once one jurisdiction closes the autonomy defence it gets a lot harder for the next one to leave it open.
100
Fraser @fraser.bsky.social · 30/09/2026
So one of the most capable labs in the world is telling its own investors, under securities disclosure obligations, that it doesn't fully know who's on the hook when its agents go wrong.
100
Fraser @fraser.bsky.social · 30/09/2026
"Limits on our liability may not be enforceable or adequate against claims over the actions of autonomous agents."
100
Fraser @fraser.bsky.social · 30/09/2026
"[Questions of how existing laws apply to AI agents] are unsettled and could expose us to significant and unpredictable legal claims." And on its own contracts with customers:
100
Fraser @fraser.bsky.social · 30/09/2026
Thanks to Bourn Collier for flagging the timing here, because @AnthropicAI filed its IPO prospectus this week and told investors, in writing, that the legal framework for rogue AI agents is genuinely unsettled (globally):
100
Fraser @fraser.bsky.social · 30/09/2026
It closes a door a 2024 tribunal had already started shutting, when @AirCanada tried to argue its own chatbot was a separate legal entity after it invented a discount policy, and the tribunal wasn't having it either.
100
Fraser @fraser.bsky.social · 30/09/2026
The law is AB 316, in force since 1 January, and it adds one line to the Civil Code: if you developed, modified or used an AI system alleged to have caused harm, you can't argue the AI acted autonomously.
100
Fraser @fraser.bsky.social · 30/09/2026
"Sorry, it wasn't me, guv" doesn't work as a legal defence in California anymore, and @AnthropicAI’s own IPO filing shows just how critical this is.
100
Fraser @fraser.bsky.social · 29/09/2026
So California is building real independence with no legal teeth behind it, and the EU has the teeth with barely any independence. Still, it’s a start.
000
Fraser @fraser.bsky.social · 29/09/2026
Set that against the EU AI Act, which runs the opposite way round: mandatory in law but mostly self-assessed in practice, since most high-risk systems can self-certify and third-party checks only bite for a narrow set of cases like biometrics.
100
Fraser @fraser.bsky.social · 29/09/2026
- @Google , @OpenAI and @AnthropicAI are reportedly setting up their own standards body for pre-release audits, which is industry marking its own homework all over again, just with better branding
100
Fraser @fraser.bsky.social · 29/09/2026
- AB 316 quietly removed the "the AI did it" defence for anyone who builds, integrates or deploys a harmful system
100
Fraser @fraser.bsky.social · 29/09/2026
- California also passed AB 1405, a state registry of AI auditors with independence standards attached - Gavin Newsom signed an executive order in September pushing for AI kill switches and onsite verifiers at frontier labs
100
Fraser @fraser.bsky.social · 29/09/2026
California signed that model into law this month with SB 813, though it's voluntary and nothing has actually been designated yet. And the safeguards are turning up from every direction at once, not just this one bill:
100
Fraser @fraser.bsky.social · 29/09/2026
Her explanation traced how policymakers spent the last year or so moving off a wait-and-see stance and onto a specific mechanism: government sets the risk threshold and then designates independent experts to verify against it, rather than asking industry to mark its own homework.
100
Fraser @fraser.bsky.social · 29/09/2026
and it caught my ear given the contrast with where the EU has landed:
100
Fraser @fraser.bsky.social · 29/09/2026
First heard of independent verification organisations, or IVOs, from @BriTreece_, (co-founder and president of @fathom_org and executive director of @pactai_org, on a @linuxfoundation webinar launching “Proof of Control” (congrats @triciawang and @aai_society)
100
Fraser @fraser.bsky.social · 28/09/2026
Big thanks to @EEAnder1 for the groundwork on how cheqd, KYA-OS, A2A and AP2 actually fit together, both now and as they develop!
000
Fraser @fraser.bsky.social · 28/09/2026
This is the start, not the finish so the repos are scaffolding and intent signalling, with much more to come. Scaffolding today, nothing implemented yet, and every page says so. More to come. As usual, we prefer to build in public. Especially where we'll need to coordinate with others as we build!
110
Fraser @fraser.bsky.social · 28/09/2026
Two repos, deliberately: - cheqd/agent-trust: the implementation, ships to npm - cheqd/a2a-ext-cheqd-trust: the A2A extension spec and reference sample Split this way, the spec can go upstream neatly. github.com/cheqd/agent... github.com/cheqd/a2a-e...
github.com
GitHub - cheqd/a2a-ext-cheqd-trust: cheqd Trust Extensions for A2A — specification and reference sample (experimental)
cheqd Trust Extensions for A2A — specification and reference sample (experimental) - cheqd/a2a-ext-cheqd-trust
100
Fraser @fraser.bsky.social · 28/09/2026
The aim: DID-anchored identity, delegation and per-request proof, usable inside both protocols. A2A answers how agents talk, AP2 answers whether a user authorised a payment. Neither answers whether you should trust an agent across an org boundary, that's our area of expertise.
100
Fraser @fraser.bsky.social · 28/09/2026
A2A and AP2 were both built at @Google and since contributed: A2A to @linuxfoundation, AP2's core spec to @FIDOAlliance. KYA-OS came out of @VouchedID and was contributed to @DecentralizedID.
100
Fraser @fraser.bsky.social · 28/09/2026
Great to see agent trust on @cheqd_io getting started. This follows a stretch of assessing a lot of fast-moving repos👇
100
Fraser @fraser.bsky.social · 25/09/2026
digitaleconomy.stanford.edu/publication...
digitaleconomy.stanford.edu
Canaries in the Coal Mine? Six Facts about the Recent Employment Effects of Artificial Intelligence - Stanford Digital Economy Lab
000
Fraser @fraser.bsky.social · 25/09/2026
Anyone still invoicing for the water is charging us for something we can make ourselves. Anyone else seeing the same pattern?
100
Fraser @fraser.bsky.social · 25/09/2026
- The reduction appears to be almost entirely reduced hiring, not layoffs: companies aren't firing junior engineers, they're just not hiring the role that used to train them in the first place (how this will shape up longer term is going to be fun)
100