GDC 2026:
Let’s Discuss the road to Geneva
Event: Global Digital Collaboration 2026, 1 to 3 September 2026, Geneva Proposal deadline: 31 July 2026. Four working weeks. Co-organizer confirmations are the critical path.
BGIN co-organized GDC 2025. For 2026 we have three breakout session proposals in the pipeline (50 minutes each; GDC requires at least two confirmed co-organizers per session). Before I finalise the session agenda, I want this thread to be a genuine discussion of what these sessions could achieve, who should be in the room, and where the community sees the sharpest questions. The proposals below are the current shape, not the final one.
The three proposals
| # | Session title | WG lead | GDC alignment | Co-organizers (status) |
|---|---|---|---|---|
| 1 | Vulnerability Handling in the Agentic AI Era | Cyber | Other (AI-era sharing and triage) | BGIN + ISO (primary); exploring ETSI, ENISA, CEN-CENELEC |
| 2 | PQC Migration on DLTs: Crypto Agility, ZKP, and Resource Estimates | IKP | Post-quantum ZKP | BGIN + ISO (candidate); ECDSA.fail community invited |
| 3 | Wallet Security Assurance: ST/PP and FIDO/OpenID/GP | IKP / Cyber | Certifications for digital identity | BGIN + FIDO, OpenID, GlobalPlatform (TBD) |
Session 2 has grown, deliberately
The earlier framing was crypto migration only. I have widened the scope to hold both halves of the PQC problem in one session:
- Migration and crypto agility: the NIST PQC signature transition, ZKP systems under post-quantum assumptions, and what agility actually requires of DLT architectures that were never designed to rotate their cryptography.
- Resource estimates: the community effort quantifying what breaking ECDSA actually costs, gate counts, error correction overheads, and honest timelines. The ECDSA.fail benchmark work (with contributors from the Ethereum ecosystem and Eigen Labs, now writing a paper reflecting on the agentic auto-research challenge) has produced the most grounded numbers in this conversation.
The reason for merging: migration urgency is a function of resource estimates. Policy audiences at GDC keep hearing “migrate now” and “decades away” from different rooms. Putting the people who produce the estimates in the same 50 minutes as the people designing the migration is the whole point of a multistakeholder venue. The “Post-quantum ZKP” checkbox on the GDC form now fits the session better than it did, though I will still confirm scope with the GDC programme team.
Invitation: ECDSA.fail community, come to Geneva
BGIN holds organiser tickets for GDC 2026, and I would like to use some of them to bring members of the resource-estimation community into this room in person. If you contributed to the benchmark challenge, or you are working on the reflection paper, and Geneva on 1 to 3 September is feasible for you, reply in this thread or contact the IKP chairs directly. This community and the standards/policy community meeting face to face is exactly the bridge BGIN exists to build; the academics hold the measurement rigour, the practitioners hold the numbers, and the policymakers need both.
Open channel
This post is the start of the conversation, not the record of a decision. Alongside this thread we will stand up an open channel for the PQC session discussion, running from now through GDC: a dedicated Discourse category thread for asynchronous work, plus an open call in the IKP WG calendar for anyone who wants to shape the session agenda, propose speakers, or contest the framing. Details of the call cadence will follow in this thread within the week. Everything is on the table except the deadline.
Look into the BGIN AI Travels With Us post i’ll include next in this thread.
What I’d like to discuss here
- Session 2: does the merged scope work in 50 minutes, or should resource estimates anchor the narrative with migration as the consequence? What would make this session worth a policymaker’s hour?
- Session 1: the real question is whether we demo the IKP working group threat system live in the room. If yes, we need to decide specifically what gets built for a 50-minute policy audience and who builds it. If no, where does agentic AI genuinely change vulnerability handling, versus rebranding existing coordinated disclosure problems? ISO is primary; who else must be in the room? (See the companion post, BGIN AI Travels With Us, for the interactive session infrastructure this demo would sit inside.)
- Session 3: which certification gap between ST/PP approaches and the FIDO/OpenID/GlobalPlatform schemes should this session target first?
- Names: speakers, co-organizers, and specifically eth contributors interested in the Geneva invitation.
Decisions and guidance requested (Steering Committee)
- Finalise BGIN will submit and maintain all three proposals delivered after friday the 10th, 31 July deadline.
- Approve outreach to NIST/other related parties for co-organizer or speaker roles on Sessions 1 and 2.
- Approve allocation of BGIN organiser tickets to invited ECDSA.fail /ETH community members.
- Name the session submitter and contact email for the Airtable forms.
Please contribute to this thread by Friday 10 July. That is the deadline for forming the session agendas, and it holds three weeks of margin against the 31 July submission deadline for co-organizer confirmations and form logistics. Co-organizer / Main discussant contacts are the most time-sensitive item; everything else can iterate in the open channel. we will use this to form an email outreach to relevant parties notifying them. asap
@shinichiro.matsuo @nat @ChloeWhiteAus @JBringer @Carole_House
Related thread: *Three Session proposals to GDC 27
This does not include the information from the transcript we spoke yesterday in IKP WG+steer co, I will make another post if there is any of those actions/comments missed in this thread.*