About the Standard

From Trusted Computing to AI-Readable Infrastructure

Mission

The AI Discovery Standard exists so that every organization on the web can declare its identity, capabilities, and policies in a format AI agents can read, verify, and act on — without scraping, without intermediaries, and with cryptographic proof of origin.

We believe the web needs a protocol layer for AI the way it needed HTTP for browsers. The standard is open (CC-BY-4.0), vendor-neutral, and designed for universal adoption.

The Insight: Origin, Not Trust

In 1999, the Trusted Computing Group (TCG) faced a problem: how do you know what software is running on a computer? Their answer was the Trusted Platform Module (TPM) — a chip that measures what code executes, creates a cryptographic record, and lets a remote party verify those measurements. The TPM doesn't decide if the software is good. It proves what's running. The verifier decides trust.

The Same Problem, 25 Years Later

Today, AI agents face the identical problem with websites: how do you know what an organization actually does, what it offers, what policies it has? The current answer — scrape HTML and guess — is the equivalent of asking a stranger on the street what software your computer is running. The AI Discovery Standard applies the TPM principle to the web: the domain declares its identity in a structured, signed format. The AI agent verifies origin. The user decides trust.

This is the principle of Origin, Not Trust. The standard doesn't ask AI to trust a website. It gives AI a way to verify what a domain declares, trace it to a cryptographic identity, and let the human or application consuming the AI's output make the trust decision.

History

The AI Discovery Standard grows directly from 25 years of work in trusted computing, hardware security, and data provenance.

1999

Trusted Computing Group founded. The industry consortium that created the TPM specification, establishing hardware-rooted measurement as the foundation for computer security. Steven Sprague was instrumental in building the TPM standards and bringing trusted computing to market as president of Wave Systems.

2003

TPM ships in commercial PCs. The Trusted Platform Module becomes standard hardware in enterprise computers. Today, over 2 billion devices ship with TPMs annually.

2017

Rivetz launches. Mobile trusted execution environment (TEE) platform for blockchain key management, applying hardware security to decentralized identity and attestation.

2024

Rootz Corp founded. Built on the insight that AI has broken content authenticity. Data needs proof of origin and ownership to have value. The company creates Data Wallets, Digital Names, and blockchain infrastructure for data provenance.

February 2025

AI Discovery Standard v0.1 drafted. First specification for structured organizational identity at /.well-known/ai. Three-tier architecture: Discovery, Knowledge, Feed.

February 2026

v1.2 released with enterprise adoption. Full specification with content endpoint, policies, WebMCP tools, cryptographic signing, and content hashes. WordPress plugin published. Made in USA Inc. launches enterprise certification through the Veritize™ platform.

2026

Standards body formation. Founding members recruited. Open governance established. IANA registration for /.well-known/ai filed. Working groups convened for v1.3.

Why This Standard Matters

For Organizations

Right now, when ChatGPT or Perplexity answers a question about your company, it's guessing from scraped HTML. Half the time it's wrong. The AI Discovery Standard lets you declare exactly who you are, what you do, and what AI is allowed to say — at a standard URL that every AI agent can check before answering.

For AI Platforms

Instead of building scrapers that break when websites change, AI platforms can read one structured endpoint per domain. The data is typed, versioned, signed, and designed for machine consumption. Better data in, fewer hallucinations out.

For the Web

The web was built for humans reading pages. Now half the traffic is bots. We need a protocol layer where websites can communicate with AI agents directly — not through scrapers, not through training data snapshots, but in real time from the authoritative source. That's what /.well-known/ai provides.

People

Steven Sprague

Standard Author · CEO, Rootz Corp

Built the TPM standards at the Trusted Computing Group. Former president of Wave Systems. 25 years in hardware security, cryptographic measurement, and data provenance. The design philosophy of "Origin, Not Trust" extends TPM measurement principles to the AI-readable web.

Adam Reiser

Founding Partner · CEO, Made in USA Inc.

Leads the enterprise and government implementation of the AI Discovery Standard through the Veritize™ platform. Existing government contracts position MIUSA as the certification authority for AI readiness in regulated industries.

Michael Sprague

Core Engineer · CTO, Epistery

Architect of the Epistery platform powering the signing infrastructure, AI proxy service, and agent framework. Builds the reference implementation and developer tooling for the standard.

The standard is open to contributions from the community. See governance →