This is slightly old news, but on October 23 I participated remotely as a member in the Digital Agency’s “Expert Meeting on Organizing Issues Concerning Attribute Credentials,” specifically its 1st meeting. It is the autumn travel season, after all… But whether because of Microsoft Teams or my microphone, I could understand only about 2/3 of what was said, so I participated while privately chatting “This is painful…” with Professor Matsuo, who was also remote. (At the start, remote participant Mr. Fujie had great difficulty joining, and Professor Matsuo ultimately could not join from the web and participated from his iPhone. MS Teams is truly painful…) So I too am eagerly awaiting publication of the minutes.
The materials are available on the page above. The members are listed below.
Members (honorifics omitted)
● Yoichiro Itakura (Partner Attorney, Hikari Sogoh Law Offices)
● Reiko Kasai (Senior Manager, Digital Solutions Promotion Department, Incubation Company, Lawson, Inc.)
● Jiro Kokuryo (Professor Emeritus, Keio University)
● Natsuhiko Sakimura (Managing Member, NAT Consulting LLC)
● Toshio Taki (Group CoPA Executive Officer, Money Forward, Inc.; Head, Money Forward Institute)
● Motonori Nakamura (Director and Professor, IT Infrastructure Center, Institute for Information Management and Communication, Kyoto University)
● Naohiro Fujie (Representative Director, OpenID Foundation Japan)
● Shinichiro Matsuo (Research Professor, Georgetown University and Virginia Tech)
● Yasushi Matsumoto (Fellow, Japan Network Security Association)
● Akemi Yokota (Professor, School of Law, Meiji University)
● Masako Wakae (Editorial Writer, Tokyo Head Office, The Asahi Shimbun)
I debated whether to use my title at NAT Consulting LLC, my title as chairman of the U.S.-based OpenID Foundation, or my MyData Japan title. This time, I registered under the hat that lets me speak most freely.
This expert meeting combines the DIW Advisory Board, which operated through the last fiscal year and was closed to the public (although its report can be viewed here), with the Expert Meeting on Governance in the Use of Verifiable Credentials (VC/VDC), and makes the combined body a public meeting, something strongly requested by members of the DIW Advisory Board.
With that background, I will leave the details to the minutes, but the points that caught my attention included the following:
- Should there be more discussion of Derived Credentials, the equivalent of the EU’s (Q)EAA? These will probably be the primary type used, such as age-verification VCs.
- Social implementation should proceed from “low-risk use cases (lightweight use cases).”
- Guidelines alone have limits as a means of driving adoption. Consider incorporating them into procurement requirements and standard specifications.
- Consideration of antitrust law and fair competition is also essential. Concentration in platforms also requires caution.
- A legal basis is needed to ensure consumer protection and privacy. A legal basis is needed to ensure consumer protection and privacy.
- A certification scheme and legal safeguards are needed to prevent risks from verifier entry and misuse. (I also stated that wallet providers are effectively information banks and that we should draw on experience with the information-bank certification scheme, including visibility of requested information, consent UI, and certification criteria.)
- Consider administrative agencies’ systems for accepting privately issued VCs and the necessary legal framework, including amendments to ordinances and ministerial regulations.
These were among the points raised. At the end, Director-General Kusunoki made the following forceful remarks:
- Eliminating paper is not the objective but an inevitability. A mechanism for realizing digital first is needed.
- As automated procedures performed by AI agents advance, VCs will become the infrastructure that ensures “trust between humans and AI.”
- This fiscal year, concrete results will first be produced from “feasible use cases.”
- From the next meeting onward, the technical WG will refine requirements by risk category and compile draft guidelines within the fiscal year.
The meeting concluded with those strong words.
I can hardly wait for the minutes.
Until next time! (From the hotel at the IETF 124 venue in Montreal)
Update, November 28, 2025
The minutes have been published → They can be obtained from this Digital Agency website.
