Week ending July 24, 2026
Updated August 8: trimmed editorial asides for concision. No facts, sources, or conclusions changed.
The most useful thing this week is a small change in what an identity provider hands over. The OpenID Foundation moved its ephemeral subject identifier profile into final review — a way for a provider to confirm that somebody is authenticated without also giving the relying party a durable handle for recognising them later. Narrow and procedural: it makes correlation structurally hard rather than something operators promise not to do. The harder version of the same question — not what a verifier learns, but who is entitled to vouch in the first place — was moving in telecom the same week, where STI-GA began defining a class of governance authority that no national regulator stands behind.
Standards in motion
A new category in the caller-trust chain — but what is it? STI-GA — the Secure Telephone Identity Governance Authority, the ATIS-administered body that runs STIR/SHAKEN certificate governance in the US — selected Numeracle on July 23 to design a framework for vetting “non-jurisdictional governance authorities” (NJGAs) seeking interoperability with the US ecosystem. The term is new, and the public record so far defines it mostly by what it is not. It does not mean “foreign”: the established cross-border path runs between regulator-backed authorities — the US STI-GA and Canada’s CST-GA hold a mutual-recognition MoU and are targeting automated Canada–US call signing in 2026 — and that path is jurisdictional by definition. NJGAs are the other kind, described by STI-GA’s chair as “non-jurisdictional governance entities, those not established by national regulators.” That is the whole of the available definition, and it leaves the operative questions open: what qualifies a body as non-jurisdictional, what it is assessed against, and what stands in for the regulator that is not there. Regulator backing is what has made trust in this chain legible so far — a national mandate is public and accountable by construction — so where there is no mandate, the criteria carry that weight instead. The framework is being designed now and the details are not public yet.
An identifier designed not to be linkable. The OpenID Foundation opened a 60-day public review on July 17 for OpenID Connect Ephemeral Subject Identifier 1.0 — a profile that lets a provider return a subject (sub) identifier that is not reused across authentications, so a relying party can confirm a user is authenticated without receiving a stable handle it can use to link that user’s sessions over time or build a profile. The mechanism prevents correlation, rather than the operator promising not to correlate. It extends, rather than replaces, the pairwise pseudonymous identifiers OpenID Connect already supports — those stop one site from correlating a user with another, ephemeral identifiers stop a single site from correlating a user with themselves across visits. Open, multi-vendor, consumer-protective, and squarely on the “what can the verifier learn and link” question this beat exists to read. Adoption read: none yet — this is a final-specification review, upstream of deployment — and the thing to watch is whether any large provider signals intent to emit ephemeral identifiers, because the mechanism only protects people once an operator chooses to turn it on.
Implementations & adoption
Passkeys grow a signature. Yubico shipped YubiKey 5.8 on July 21. It ships a developer preview of the WebAuthn signing extension together with CTAP 2.3 — the FIDO client-to-authenticator protocol — which together let a hardware key produce a verifiable, hardware-bound signature over a specific action (a signed document, a payment confirmation, an approval of something an AI agent is about to do) rather than only asserting a login. This is a real implementation of an emerging open capability: WebAuthn and CTAP are multi-vendor W3C/FIDO specifications, not a proprietary Yubico surface, so the read is open and phishing-resistant by construction. Adoption read: developer preview, so early — the signal to watch is whether other authenticator vendors implement the same signing extension rather than shipping proprietary action-signing of their own, because that is the fork between a portable capability and a set of incompatible ones. It also lands on the week’s recurring question — how you authorize what an autonomous agent may do — which YubiKey’s own framing puts front and center.
C2PA reaches audio. SoundPatrol completed C2PA validator product conformance on July 15 — the first in recorded music. C2PA — the Coalition for Content Provenance and Authenticity — is the open standard for attaching verifiable provenance to media, and it runs a conformance program: a validator that passes conformance is checked to read and verify credentials to spec, so it interoperates with anything signed to the same standard rather than implementing a private dialect. The move is worth noting because it extends C2PA from images and video into audio, where provenance tooling has lagged, and it does so through the standard’s own conformance path rather than around it. On the axis: open, and adopted in the sense that counts — conformance is a test passed, not a launch announced.
Capital & motivation
Truecaller joins the GSMA. Truecaller joined the GSMA on July 21, taking part in working groups covering mobile security, fraud prevention and caller identity. The company is best known for its consumer caller-ID and spam-blocking app, and also runs Verified Business Caller ID, which issues verified brand profiles to businesses, scores numbers, and supplies fraud signals — distributed through its own installed base, through carrier-level integrations, and through CPaaS partners.