GDC 2026 thread

GDC 2026:

Let’s Discuss the road to Geneva

Event: Global Digital Collaboration 2026, 1 to 3 September 2026, Geneva Proposal deadline: 31 July 2026. Four working weeks. Co-organizer confirmations are the critical path.

BGIN co-organized GDC 2025. For 2026 we have three breakout session proposals in the pipeline (50 minutes each; GDC requires at least two confirmed co-organizers per session). Before I finalise the session agenda, I want this thread to be a genuine discussion of what these sessions could achieve, who should be in the room, and where the community sees the sharpest questions. The proposals below are the current shape, not the final one.

The three proposals

# Session title WG lead GDC alignment Co-organizers (status)
1 Vulnerability Handling in the Agentic AI Era Cyber Other (AI-era sharing and triage) BGIN + ISO (primary); exploring ETSI, ENISA, CEN-CENELEC
2 PQC Migration on DLTs: Crypto Agility, ZKP, and Resource Estimates IKP Post-quantum ZKP BGIN + ISO (candidate); ECDSA.fail community invited
3 Wallet Security Assurance: ST/PP and FIDO/OpenID/GP IKP / Cyber Certifications for digital identity BGIN + FIDO, OpenID, GlobalPlatform (TBD)

Session 2 has grown, deliberately

The earlier framing was crypto migration only. I have widened the scope to hold both halves of the PQC problem in one session:

  1. Migration and crypto agility: the NIST PQC signature transition, ZKP systems under post-quantum assumptions, and what agility actually requires of DLT architectures that were never designed to rotate their cryptography.
  2. Resource estimates: the community effort quantifying what breaking ECDSA actually costs, gate counts, error correction overheads, and honest timelines. The ECDSA.fail benchmark work (with contributors from the Ethereum ecosystem and Eigen Labs, now writing a paper reflecting on the agentic auto-research challenge) has produced the most grounded numbers in this conversation.

The reason for merging: migration urgency is a function of resource estimates. Policy audiences at GDC keep hearing “migrate now” and “decades away” from different rooms. Putting the people who produce the estimates in the same 50 minutes as the people designing the migration is the whole point of a multistakeholder venue. The “Post-quantum ZKP” checkbox on the GDC form now fits the session better than it did, though I will still confirm scope with the GDC programme team.

Invitation: ECDSA.fail community, come to Geneva

BGIN holds organiser tickets for GDC 2026, and I would like to use some of them to bring members of the resource-estimation community into this room in person. If you contributed to the benchmark challenge, or you are working on the reflection paper, and Geneva on 1 to 3 September is feasible for you, reply in this thread or contact the IKP chairs directly. This community and the standards/policy community meeting face to face is exactly the bridge BGIN exists to build; the academics hold the measurement rigour, the practitioners hold the numbers, and the policymakers need both.

Open channel

This post is the start of the conversation, not the record of a decision. Alongside this thread we will stand up an open channel for the PQC session discussion, running from now through GDC: a dedicated Discourse category thread for asynchronous work, plus an open call in the IKP WG calendar for anyone who wants to shape the session agenda, propose speakers, or contest the framing. Details of the call cadence will follow in this thread within the week. Everything is on the table except the deadline.

Look into the BGIN AI Travels With Us post i’ll include next in this thread.

What I’d like to discuss here

  • Session 2: does the merged scope work in 50 minutes, or should resource estimates anchor the narrative with migration as the consequence? What would make this session worth a policymaker’s hour?
  • Session 1: the real question is whether we demo the IKP working group threat system live in the room. If yes, we need to decide specifically what gets built for a 50-minute policy audience and who builds it. If no, where does agentic AI genuinely change vulnerability handling, versus rebranding existing coordinated disclosure problems? ISO is primary; who else must be in the room? (See the companion post, BGIN AI Travels With Us, for the interactive session infrastructure this demo would sit inside.)
  • Session 3: which certification gap between ST/PP approaches and the FIDO/OpenID/GlobalPlatform schemes should this session target first?
  • Names: speakers, co-organizers, and specifically eth contributors interested in the Geneva invitation.

Decisions and guidance requested (Steering Committee)

  1. Finalise BGIN will submit and maintain all three proposals delivered after friday the 10th, 31 July deadline.
  2. Approve outreach to NIST/other related parties for co-organizer or speaker roles on Sessions 1 and 2.
  3. Approve allocation of BGIN organiser tickets to invited ECDSA.fail /ETH community members.
  4. Name the session submitter and contact email for the Airtable forms.

Please contribute to this thread by Friday 10 July. That is the deadline for forming the session agendas, and it holds three weeks of margin against the 31 July submission deadline for co-organizer confirmations and form logistics. Co-organizer / Main discussant contacts are the most time-sensitive item; everything else can iterate in the open channel. we will use this to form an email outreach to relevant parties notifying them. asap

@shinichiro.matsuo @nat @ChloeWhiteAus @JBringer @Carole_House

Related thread: *Three Session proposals to GDC 27

This does not include the information from the transcript we spoke yesterday in IKP WG+steer co, I will make another post if there is any of those actions/comments missed in this thread.*

BGIN AI Travels With Us: Interactive Infrastructure for GDC, Block 15, and Beyond

Companion post to the GDC 2026 session proposals thread. Feedback wanted by Friday 10 July, alongside the session agenda deadline.

The premise

BGIN sessions describe systems: threat sharing, credential ceremonies, machine-readable terms, trust graphs, PQC evaluation. At GDC and at Block 15 we will stand in rooms full of policymakers and standards people and describe them again. This post proposes that we stop only describing and start letting the room touch the work, and that the infrastructure we build for it travels with us from event to event. Hence the name. This is easier to do than it sounds; most of the pieces already exist.

I host bgin.ai, and I am offering to use it as the vehicle.

What I am proposing to build

1. A live demo surface per session, or one consolidated BGIN interface

Two options, and I want the community’s preference:

  • Per-session: each Block 15 / GDC session gets an updated demo of the relevant working group’s current output, hosted at bgin.ai and shown live in the room.
  • Consolidated: a single BGIN at GDC interface, one front door for the three sessions, with each session’s demo behind it.

My lean is consolidated for GDC (one URL a policymaker can remember from a slide) and per-session for Block 15 (working group depth). Both are cheap once the first is built. [GDC.bgin.ai]

2. A MyTerms primitive at the front door

When someone visits the BGIN interface, they should not meet a cookie banner. They should meet an agreement ceremony: the visitor’s side presents machine-readable terms, ours responds, and the agreement is recorded before anything else happens. This is IEEE P7012 made tactile. Fifty people in a Geneva breakout room experiencing the contractual privacy paradigm at the door, instead of hearing the phrase “notice and consent” one more time, is worth more than a slide deck. It also gives Session 3 (wallet assurance and certification) a live artefact to point at.

3. Trust graph formation as the room participates

Each visit, each agreement, each gate opened (see below) forms an edge. Over the days of the event, the room grows a visible trust graph of its own making. We display it at the close: this is what the community built by showing up and agreeing to terms with each other. The graph is the demo. Nothing teaches relationship-based identity faster than watching your own edge appear.

4. Federated wiki as the system of record

For record keeping and exploration of the sessions, I propose forming a federated local wiki: each session’s notes, artefacts, and follow-ups live as wiki pages that can be forked, annotated, and carried home by participants, in the lineage of the federated wiki work already running in the Hitchhiker timeline project. The record does not sit in one silo owned by one host. It federates, which is the point: BGIN’s outputs behave the way BGIN says infrastructure should behave.

5. The Gatehouse: encrypted document access as a shared ceremony

I have just built an encrypted wiki sharing system at guide.agentprivacy.ai/gates. A gate opens with two factors that are useless alone: a sigil (an emoji string) and a proverb (a spoken line). Trace one, speak the other, and the gate opens to a unique set of documents.

Here is how it plays in a session room:

  1. At the close of the session, the proverb is spoken aloud from the front of the room. If you were there, you heard it.
  2. The sigil drops into the session group chat that formed during the hour. If you joined, you can copy it.
  3. Each attendee casts both at the gate and receives access to a unique document set: the session’s deep materials, the drafts, the references, the follow-up pathway.
  4. They can point their own agent at those documents afterwards. The session does not end when the room empties; it ends when their agent has finished reading.
  5. Soulbae, the first mage, saves the moment: the ceremony is recorded as an event in the record, an edge in the trust graph, a page in the wiki.

Presence plus participation as the access credential. No account creation, no email harvesting, no badge scan. You had to be in the room and in the conversation. That is the whole authentication model, and it is a better demonstration of “understanding as key” than any talk about it.

6. The threat system demo (Session 1 decision)

Cross-referencing the GDC thread: if we choose to demo the working group threat system in Session 1, it becomes the sixth surface in this stack, sharing the front door, the terms ceremony, and the record keeping. The open question there stands: what specifically do we build for a 50-minute policy audience, and who builds it? Concrete suggestions welcome in either thread; I will consolidate.

Why this is worth the build

GDC’s audience decides on certifications, standards, and regulatory posture. Most of them have never watched a machine-readable terms agreement complete, never seen a trust graph grow from their own participation, and never opened an encrypted resource with a spoken proverb instead of a password. Every one of those experiences argues for BGIN’s positions more efficiently than the accompanying paper does. And because the infrastructure federates and travels, whatever the Geneva room builds is waiting in Washington when Block 15 opens.

Asks

  1. Preference: consolidated BGIN at GDC interface vs. per-session demos, or the hybrid proposed above.
  2. Session 1: yes or no on the threat system demo, and if yes, the specific build scope and builder(s).
  3. Content owners: one volunteer per session to curate what goes behind that session’s gate.
  4. A dry run: I propose we rehearse the full loop (terms ceremony, gate, wiki, graph) at the next public IKP session on biometric ZKP / PQC (perhaps resource estimates) before September, so GDC gets the second performance, not the first if possible.
  5. Naming and blessing: if the Steering Committee wants this branded and reviewed before it stands under bgin.ai, say so early. I would rather adjust in July than in August

Mitchell, thanks for the 3 suggested sessions.

For the migration session, in addition to “ZKP systems under post-quantum assumptions” we should also discuss MPC given the impact of PQ on key management.

1 Like

Thanks for the suggestion, Mitchell. Concatenating both migration and resource estimates is actually a great 50-minute design, I believe.

However, I also think no one (even in the ECDSA.fail community) can give a concrete estimate of Q-day anyway, so most of the session will be spent on migration, focusing on the ZKP side, such as mnemonic code proof and STARK signature aggregation

1 Like

@Mitchell @JBringer

Can we have a call on GDC prep this Monday (7/13), the day before the GDC co-organizer call?

I’m available at the following slots

  • 6 am-9 am EDT
  • 1:30-3pm EDT

@Mitchell

We need to officially secure co-organizers for all sessions before the due date. The co-organizers should be selected from confirmed GDC co-organizers.

Session 1: We need to reach out to ISO. Considering the recent document by ENISA (linked), ENISA should be considered.

Session 2: We need to reach out to ISO. Namirial is interested in this session.
Session 3: We need to receive confirmation from GP. OWF sent us its interest.

@Mitchell
Could you join the GDC co-organizer call tomorrow?

ill be in that meeting today