Skip to main content
Status · as of

Where WAI stands

What is in the standard, what is being built now, and what comes next, as of . Each capability in the standard links to its specification text, its workflow or the demonstration that runs it.

The three labels

In the standard
In the main branch of the open-standards repository.
Building
The next pull requests, in active development.
Roadmap
The next builds, in order.
In the standard

In the standard

Everything here is in the main branch of the open-standards repository, under Apache-2.0.

Envelope, dispatch and registry

Envelope, dispatch and registry, in the standard: capability, notes and where it is specified
Capability Notes Where
Single-payload envelope, manifest and capability dispatch with a declared fallback. A sink without the capability reports the file inert. A fallback decodes the same payload; alternate content travels as renditions.
Multi-rendition envelope, with companion descriptors for HDR metadata. Every rendition ships in the envelope and the deployer sets the selection policy.
Companion conformance rules, and an enhancement layer bound to exactly one base rendition in the same envelope. The sink supplies the enhancement decoder; the registry records its licence class.
Capability constraint sets, evaluated before dispatch. Specification text.
Mandatory floor (PNG, FLAC, zstd) and a recommended set. The floor has no video capability.
The model a neural payload needs is named, pinned by digest and never carried in the envelope; a mismatch is refused. A pinned prior can declare its artifact's wire form, and the NNC bitstream is registered as one. A replicate whose prior declares a wire form the sink cannot read is refused.
A licence class for each capability in the codec registry, queryable in code. The deployer enforces it.
Determinism tiers — entropy-consistency and decode-equivalence — typed in code, with replicate meaning exactly what its tier guarantees. —
Broadcast and streaming codec registrations, each licence-classified and never a default. The reference implementation carries them through the envelope; the sink's own libraries decode them.
Derived tracks: derivation operations over decoded samples as capabilities, each with a stated determinism tier. —

Codecs and evidence

Codecs and evidence, in the standard: capability, notes and where it is specified
Capability Notes Where
Integer learned image codecs, integer inter-frame video with half-pel motion, video with a learned integer keyframe, integer learned audio, and an integer splat codec. Conformance requires byte-identical output.
wai.neural.int_mlicpp: the MLIC++ entropy topology, integer end to end. Its conformance vector uses synthetic weights and states no quality figure.
JPEG AI exact decoder: an integer entropy stage, then reconstruction in a fixed evaluation order with no platform maths library. Its output is pinned, and CI runs the whole decode. One configuration. The capability is registered at entropy-consistency; the pinned reconstruction is a property of the exact decoder under its stated build conditions.
Quality evidence for the integer learned image codec: the integer decode is held to a bar against the same model's float decode. Held to within 1 dB of the float decode on a pinned photograph.
Fast integer decode kernels that give the same integer for every output, with a throughput note. Timed on one machine. WebAssembly runs the same kernels single-threaded, untimed.
Bounded, machine-checked proofs over the integer rANS core. The text lists what is proved.
Encoders. Classical encoding in the command-line tool. The learned and integer encoders are offline tools.

Instruction cargo

Content carried as state or instructions and rebuilt at the sink.

Instruction cargo, in the standard: capability, notes and where it is specified
Capability Notes Where
Worlds (scene, replay, live), film (linear, reel), feeds, avatar pose, spatial audio scenes, score, haptics and 4D splats. Conformance covers state, samples or per-frame identity, with a conformance corpus per class; the render belongs to the sink. A binaural render is perceptual and declares its metric.
World model. Conformance covers the action trace, not the frames.
Deterministic spectral generation. —
Live world operations: a relay verifies each signed operation, and late joiners re-derive the world. A late joiner replays the full log. A room has a fixed capacity.

Delivery workflow

The attested on-demand and channel workflow: wai.video.manifest, .ssai, .keys, .package and .channel.

Delivery workflow, in the standard: capability, notes and where it is specified
Capability Notes Where
Session-class manifest: an HLS media playlist generated once per session class. On-demand media playlists. The signer declares the viewer count behind any per-viewer figure.
Ad-insertion decisions with per-impression receipts. A verifier rejects a record whose spend exceeds the grant's funds ceiling.
Key-release decision records: every release and every refusal is a signed receipt. Records decisions; speaks no licence protocol.
Packaging: segmentation on group-of-pictures boundaries into content-hashed segments. The caller supplies the slices. A verifier recomputes the deduplication totals from the signed entries.
Virtual linear channel: attested playback windows chained into a record of what aired. —

Carriage

Carriage, in the standard: capability, notes and where it is specified
Capability Notes Where
Media over QUIC streaming format: the packaging value "wai", catalog capability fields, and an optional per-object WAI_RECEIPT property that names the figure's acquisition class. Tracks IETF Internet-Drafts. Each object is one whole single-payload envelope. An energy claim carries an object's class under a signature.
Unidirectional delivery. Specification text; no bearer binding.

Edge

Edge, in the standard: capability, notes and where it is specified
Capability Notes Where
Relay preservation: forward envelopes and receipts byte for byte, with no transcoding, rewriting or re-signing. A relay attests in a separate, parallel receipt.
A transform recorded as its own signed lineage step. —

Receipts, provenance and energy

Receipts, provenance and energy, in the standard: capability, notes and where it is specified
Capability Notes Where
Group receipts: a content hash per object, a Merkle root per group, an Ed25519 publisher signature and a link to the previous receipt. —
Typed receipt classes — delivery, energy, lawful-basis and log-inclusion — with an independent verifier and differential tests. —
Per-class decode receipts (video, film, world, score, haptics, 4D splats) that separate recomputable fields from the attested energy figure. —
OER/2 receipts, with independent implementations including a C kernel. The C kernel's energy meter is modelled.
C2PA manifest emission binding energy and reconstruction. An optional build feature. The manifest validates; signer trust comes from the verifier's trust list.
Reconstruction binding, and a soft binding: a receipt reached through a soft binding attests the ancestor, never the object in hand. A lossy re-encode breaks the hard binding; the soft binding is the path back.
Asset provenance steps. The demonstration asset is synthesised, and its origin step is not metered.
Energy acquisition classes: CalibratedInstrument and OnChipCounter (each with a declared uncertainty), ModelBased, or Estimator, signed beside the figure in an energy claim and as a label on decode receipts. HwShunt is legacy: accepted in receipts sealed before the refinement, never emitted. Unmetered work carries no figure and reads as not metered. Classes for group and object receipts are building now.
Energy meters: a hardware counter meter that yields OnChipCounter, or CalibratedInstrument with a calibration reference; a model meter that only ever yields ModelBased. A meter that cannot measure returns no figure; it never falls back to a fabricated one.

Confidentiality and rights

Confidentiality and rights, in the standard: capability, notes and where it is specified
Capability Notes Where
Encrypted payloads and private channels (MLS and SFrame). The demonstration runs on a companion implementation, which carries its own licence.
Transparency (an external receipt encoding and transparency-service registration), log-inclusion claims, and task fidelity. A log-inclusion claim carries the log's evidence verbatim; accepting the claim is not verifying the inclusion.

Browser and portability

Browser and portability, in the standard: capability, notes and where it is specified
Capability Notes Where
Browser sink: parses and packs envelopes and runs the integer decoders. The full JPEG AI decode in the browser is not integer end to end. High-resolution learned decoding is the sink's registered decoder's job, not WebAssembly's.
Native and browser builds produce the same output for the integer-exact capabilities. Checked in the page, per frame, with a 64-bit FNV-1a hash; receipts use BLAKE3.

Parameter-set pin and component identity

Parameter-set pin and component identity, in the standard: capability, notes and where it is specified
Capability Notes Where
The model pin is normative: one SHA-256 over a whole parameter set, a set of several files pinned through its listing, a closed determinism vocabulary and an informative predecessor link. A sink verifies the pin before it decodes and decodes only from the bytes it verified. A pin that does not resolve makes its capability unsupported for that envelope: dispatch continues at the fallback, and selection at the next rendition.
Component identity in multi-rendition envelopes: each entry may carry an id, a payload digest and its pin, and a companion names its base by id. —
One dispatch rule on every selection path: candidates, companion-only capabilities, records and derivations are never dispatched. —

Energy reports and what receipts cover

Energy reports and what receipts cover, in the standard: capability, notes and where it is specified
Capability Notes Where
Measurement and operating-point claims report on an energy figure without changing the receipt that seals it; ratios and verdicts are derived by every reader, never stated. —
A power reader counts only while it is live: a rail that stops advancing is refused, never sealed under a hardware class. Unmetered work is never a figure of zero joules. —
A receipt object's figure, class and origin are bound into its Merkle leaf, and a labelled group signs its total's class, its coverage and the parent link. —

Keys, signing authority and revocation

Keys, signing authority and revocation, in the standard: capability, notes and where it is specified
Capability Notes Where
A signer names a web origin that publishes a key log: revisions under a root key that pre-commits to its successor, each key's authorities, and its status. Verifiers confirm receipts, claims and module grants against it offline. —
Decoder and reconstruct modules, and pinned parameter sets, are authorised by digest and revoked by digest. A sink that holds a key log refuses a revoked parameter set, and its dispatch falls back. A runtime host that loads signed modules is on the roadmap.

Registry and public text

Registry and public text, in the standard: capability, notes and where it is specified
Capability Notes Where
Every registered string in one table with its kind, status, media class and registering section; a machine-readable export and vocabulary v2 are generated from it and checked for drift in CI. —
Candidate capabilities, whose payload format is not yet pinned, are never emitted or dispatched. —
The codec glossary is linked to the registry and held to its schema by a test. —
The browser sink builds for wasm32 in CI. —

Continuous integration

Each workflow shows its current status on the forge.

Continuous integration, in the standard: capability, notes and where it is specified
Capability Notes Where
Byte equality of the integer decode paths on macOS arm64, Linux x86-64 and Linux arm64. —
Conformance corpora, fast-kernel equivalence (audio and splat included), the OER C kernel and C2PA isolation. —
Headline decode tests that fail on a missing input, with CI supplying inputs pinned by digest. —
Neural end-to-end decode runs in CI. —

The live relay behind the shared-world and private-channel demonstrations is a companion implementation, reached through a WebSocket bridge. It lives outside the open-standards repository and carries its own licence.

Building

Building

The next pull requests, in active development on top of the standard's main branch.

Binary payloads for the integer codecs

  • The integer video, image, audio and splat capabilities each get a pinned binary payload format, refused when malformed by a closed list of reasons.
  • An integer decode path that needs no machine-learning runtime.
  • Vectors with an independent verifier, and byte-exact goldens across platforms.
Roadmap

Roadmap

The next builds, in the order they come.

  1. Staged delivery

    A base first and refinements as separate objects, with a browser demonstration and measured bytes and quality.

  2. HTTP binding

    Byte-range renditions, so a sink fetches only the rendition it picks.

  3. wai-pack

    The segmenter and packager, with a per-piece policy that chooses each piece's representation.

  4. Runtime host

    A host that runs signed, revocable modules.

  5. Player integration

    Runtime fallback, two DRM lanes and a continuity harness.

  6. Deriving edge

    An edge that evaluates derived tracks and rebuilds or re-packs content under its own receipt, chained to the source.

  7. MoQ live delivery

    Live tracks over Media over QUIC.

  8. Energy along the delivery path, and content steering

    Energy receipts for origins, hops and relays, and steering that reads them.

Why it is built this way

The sink is a computer, so every hop does work: the encoder splits and chooses, the edge selects without rewriting, and the sink rebuilds and proves.