Mission
The AI Discovery Standard exists so that every organization on the web can declare its identity, capabilities, and policies in a format AI agents can read, verify, and act on — without scraping, without intermediaries, and with cryptographic proof of origin.
We believe the web needs a protocol layer for AI the way it needed HTTP for browsers. The standard is open (CC-BY-4.0), vendor-neutral, and designed for universal adoption.
The Insight: Origin, Not Trust
In 1999, the Trusted Computing Group (TCG) faced a problem: how do you know what software is running on a computer? Their answer was the Trusted Platform Module (TPM) — a chip that measures what code executes, creates a cryptographic record, and lets a remote party verify those measurements. The TPM doesn't decide if the software is good. It proves what's running. The verifier decides trust.
The Same Problem, 25 Years Later
Today, AI agents face the identical problem with websites: how do you know what an organization actually does, what it offers, what policies it has? The current answer — scrape HTML and guess — is the equivalent of asking a stranger on the street what software your computer is running. The AI Discovery Standard applies the TPM principle to the web: the domain declares its identity in a structured, signed format. The AI agent verifies origin. The user decides trust.
This is the principle of Origin, Not Trust. The standard doesn't ask AI to trust a website. It gives AI a way to verify what a domain declares, trace it to a cryptographic identity, and let the human or application consuming the AI's output make the trust decision.
History
The AI Discovery Standard grows directly from 25 years of work in trusted computing, hardware security, and data provenance.
Trusted Computing Group founded. The industry consortium that created the TPM specification, establishing hardware-rooted measurement as the foundation for computer security. Steven Sprague was instrumental in building the TPM standards and bringing trusted computing to market as president of Wave Systems.
TPM ships in commercial PCs. The Trusted Platform Module becomes standard hardware in enterprise computers. Today, over 2 billion devices ship with TPMs annually.
Rivetz launches. Mobile trusted execution environment (TEE) platform for blockchain key management, applying hardware security to decentralized identity and attestation.
Rootz Corp founded. Built on the insight that AI has broken content authenticity. Data needs proof of origin and ownership to have value. The company creates Data Wallets, Digital Names, and blockchain infrastructure for data provenance.
AI Discovery Standard v0.1 drafted. First specification for structured organizational identity at /.well-known/ai. Three-tier architecture: Discovery, Knowledge, Feed.
v1.2 released with enterprise adoption. Full specification with content endpoint, policies, WebMCP tools, cryptographic signing, and content hashes. WordPress plugin published. Made in USA Inc. launches enterprise certification through the Veritize™ platform.
Standards body formation. Founding members recruited. Open governance established. IANA registration for /.well-known/ai filed. Working groups convened for v1.3.
Why This Standard Matters
For Organizations
Right now, when ChatGPT or Perplexity answers a question about your company, it's guessing from scraped HTML. Half the time it's wrong. The AI Discovery Standard lets you declare exactly who you are, what you do, and what AI is allowed to say — at a standard URL that every AI agent can check before answering.
For AI Platforms
Instead of building scrapers that break when websites change, AI platforms can read one structured endpoint per domain. The data is typed, versioned, signed, and designed for machine consumption. Better data in, fewer hallucinations out.
For the Web
The web was built for humans reading pages. Now half the traffic is bots. We need a protocol layer where websites can communicate with AI agents directly — not through scrapers, not through training data snapshots, but in real time from the authoritative source. That's what /.well-known/ai provides.
People
Steven Sprague
Built the TPM standards at the Trusted Computing Group. Former president of Wave Systems. 25 years in hardware security, cryptographic measurement, and data provenance. The design philosophy of "Origin, Not Trust" extends TPM measurement principles to the AI-readable web.
Adam Reiser
Leads the enterprise and government implementation of the AI Discovery Standard through the Veritize™ platform. Existing government contracts position MIUSA as the certification authority for AI readiness in regulated industries.
Michael Sprague
Architect of the Epistery platform powering the signing infrastructure, AI proxy service, and agent framework. Builds the reference implementation and developer tooling for the standard.
The standard is open to contributions from the community. See governance →