Where WAI stands
What is in the standard, what is being built now, and what comes next, as of . Each capability in the standard links to its specification text, its workflow or the demonstration that runs it.
The three labels
- In the standard
- In the main branch of the open-standards repository.
- Building
- The next pull requests, in active development.
- Roadmap
- The next builds, in order.
In the standard
Everything here is in the main branch of the open-standards repository, under Apache-2.0.
- Envelope, dispatch and registry
- Codecs and evidence
- Instruction cargo
- Delivery workflow
- Carriage
- Edge
- Receipts, provenance and energy
- Confidentiality and rights
- Browser and portability
- Parameter-set pin and component identity
- Energy reports and what receipts cover
- Keys, signing authority and revocation
- Registry and public text
- Continuous integration
Envelope, dispatch and registry
| Capability | Notes | Where |
|---|---|---|
| Single-payload envelope, manifest and capability dispatch with a declared fallback. A sink without the capability reports the file inert. | A fallback decodes the same payload; alternate content travels as renditions. | |
| Multi-rendition envelope, with companion descriptors for HDR metadata. | Every rendition ships in the envelope and the deployer sets the selection policy. | |
| Companion conformance rules, and an enhancement layer bound to exactly one base rendition in the same envelope. | The sink supplies the enhancement decoder; the registry records its licence class. | |
| Capability constraint sets, evaluated before dispatch. | Specification text. | |
| Mandatory floor (PNG, FLAC, zstd) and a recommended set. | The floor has no video capability. | |
| The model a neural payload needs is named, pinned by digest and never carried in the envelope; a mismatch is refused. A pinned prior can declare its artifact's wire form, and the NNC bitstream is registered as one. | A replicate whose prior declares a wire form the sink cannot read is refused. | |
| A licence class for each capability in the codec registry, queryable in code. | The deployer enforces it. | |
| Determinism tiers — entropy-consistency and decode-equivalence — typed in code, with replicate meaning exactly what its tier guarantees. | — | |
| Broadcast and streaming codec registrations, each licence-classified and never a default. | The reference implementation carries them through the envelope; the sink's own libraries decode them. | |
| Derived tracks: derivation operations over decoded samples as capabilities, each with a stated determinism tier. | — |
Codecs and evidence
| Capability | Notes | Where |
|---|---|---|
| Integer learned image codecs, integer inter-frame video with half-pel motion, video with a learned integer keyframe, integer learned audio, and an integer splat codec. | Conformance requires byte-identical output. | |
| wai.neural.int_mlicpp: the MLIC++ entropy topology, integer end to end. | Its conformance vector uses synthetic weights and states no quality figure. | |
| JPEG AI exact decoder: an integer entropy stage, then reconstruction in a fixed evaluation order with no platform maths library. Its output is pinned, and CI runs the whole decode. | One configuration. The capability is registered at entropy-consistency; the pinned reconstruction is a property of the exact decoder under its stated build conditions. | |
| Quality evidence for the integer learned image codec: the integer decode is held to a bar against the same model's float decode. | Held to within 1 dB of the float decode on a pinned photograph. | |
| Fast integer decode kernels that give the same integer for every output, with a throughput note. | Timed on one machine. WebAssembly runs the same kernels single-threaded, untimed. | |
| Bounded, machine-checked proofs over the integer rANS core. | The text lists what is proved. | |
| Encoders. | Classical encoding in the command-line tool. The learned and integer encoders are offline tools. |
Instruction cargo
Content carried as state or instructions and rebuilt at the sink.
| Capability | Notes | Where |
|---|---|---|
| Worlds (scene, replay, live), film (linear, reel), feeds, avatar pose, spatial audio scenes, score, haptics and 4D splats. | Conformance covers state, samples or per-frame identity, with a conformance corpus per class; the render belongs to the sink. A binaural render is perceptual and declares its metric. | |
| World model. | Conformance covers the action trace, not the frames. | |
| Deterministic spectral generation. | — | |
| Live world operations: a relay verifies each signed operation, and late joiners re-derive the world. | A late joiner replays the full log. A room has a fixed capacity. |
Delivery workflow
The attested on-demand and channel workflow: wai.video.manifest, .ssai, .keys, .package and .channel.
| Capability | Notes | Where |
|---|---|---|
| Session-class manifest: an HLS media playlist generated once per session class. | On-demand media playlists. The signer declares the viewer count behind any per-viewer figure. | |
| Ad-insertion decisions with per-impression receipts. | A verifier rejects a record whose spend exceeds the grant's funds ceiling. | |
| Key-release decision records: every release and every refusal is a signed receipt. | Records decisions; speaks no licence protocol. | |
| Packaging: segmentation on group-of-pictures boundaries into content-hashed segments. | The caller supplies the slices. A verifier recomputes the deduplication totals from the signed entries. | |
| Virtual linear channel: attested playback windows chained into a record of what aired. | — |
Carriage
| Capability | Notes | Where |
|---|---|---|
| Media over QUIC streaming format: the packaging value "wai", catalog capability fields, and an optional per-object WAI_RECEIPT property that names the figure's acquisition class. | Tracks IETF Internet-Drafts. Each object is one whole single-payload envelope. An energy claim carries an object's class under a signature. | |
| Unidirectional delivery. | Specification text; no bearer binding. |
Edge
| Capability | Notes | Where |
|---|---|---|
| Relay preservation: forward envelopes and receipts byte for byte, with no transcoding, rewriting or re-signing. | A relay attests in a separate, parallel receipt. | |
| A transform recorded as its own signed lineage step. | — |
Receipts, provenance and energy
| Capability | Notes | Where |
|---|---|---|
| Group receipts: a content hash per object, a Merkle root per group, an Ed25519 publisher signature and a link to the previous receipt. | — | |
| Typed receipt classes — delivery, energy, lawful-basis and log-inclusion — with an independent verifier and differential tests. | — | |
| Per-class decode receipts (video, film, world, score, haptics, 4D splats) that separate recomputable fields from the attested energy figure. | — | |
| OER/2 receipts, with independent implementations including a C kernel. | The C kernel's energy meter is modelled. | |
| C2PA manifest emission binding energy and reconstruction. | An optional build feature. The manifest validates; signer trust comes from the verifier's trust list. | |
| Reconstruction binding, and a soft binding: a receipt reached through a soft binding attests the ancestor, never the object in hand. | A lossy re-encode breaks the hard binding; the soft binding is the path back. | |
| Asset provenance steps. | The demonstration asset is synthesised, and its origin step is not metered. | |
| Energy acquisition classes: CalibratedInstrument and OnChipCounter (each with a declared uncertainty), ModelBased, or Estimator, signed beside the figure in an energy claim and as a label on decode receipts. HwShunt is legacy: accepted in receipts sealed before the refinement, never emitted. | Unmetered work carries no figure and reads as not metered. Classes for group and object receipts are building now. | |
| Energy meters: a hardware counter meter that yields OnChipCounter, or CalibratedInstrument with a calibration reference; a model meter that only ever yields ModelBased. | A meter that cannot measure returns no figure; it never falls back to a fabricated one. |
Confidentiality and rights
| Capability | Notes | Where |
|---|---|---|
| Encrypted payloads and private channels (MLS and SFrame). | The demonstration runs on a companion implementation, which carries its own licence. | |
| Transparency (an external receipt encoding and transparency-service registration), log-inclusion claims, and task fidelity. | A log-inclusion claim carries the log's evidence verbatim; accepting the claim is not verifying the inclusion. |
Browser and portability
| Capability | Notes | Where |
|---|---|---|
| Browser sink: parses and packs envelopes and runs the integer decoders. | The full JPEG AI decode in the browser is not integer end to end. High-resolution learned decoding is the sink's registered decoder's job, not WebAssembly's. | |
| Native and browser builds produce the same output for the integer-exact capabilities. | Checked in the page, per frame, with a 64-bit FNV-1a hash; receipts use BLAKE3. |
Parameter-set pin and component identity
| Capability | Notes | Where |
|---|---|---|
| The model pin is normative: one SHA-256 over a whole parameter set, a set of several files pinned through its listing, a closed determinism vocabulary and an informative predecessor link. A sink verifies the pin before it decodes and decodes only from the bytes it verified. | A pin that does not resolve makes its capability unsupported for that envelope: dispatch continues at the fallback, and selection at the next rendition. | |
| Component identity in multi-rendition envelopes: each entry may carry an id, a payload digest and its pin, and a companion names its base by id. | — | |
| One dispatch rule on every selection path: candidates, companion-only capabilities, records and derivations are never dispatched. | — |
Energy reports and what receipts cover
| Capability | Notes | Where |
|---|---|---|
| Measurement and operating-point claims report on an energy figure without changing the receipt that seals it; ratios and verdicts are derived by every reader, never stated. | — | |
| A power reader counts only while it is live: a rail that stops advancing is refused, never sealed under a hardware class. Unmetered work is never a figure of zero joules. | — | |
| A receipt object's figure, class and origin are bound into its Merkle leaf, and a labelled group signs its total's class, its coverage and the parent link. | — |
Keys, signing authority and revocation
| Capability | Notes | Where |
|---|---|---|
| A signer names a web origin that publishes a key log: revisions under a root key that pre-commits to its successor, each key's authorities, and its status. Verifiers confirm receipts, claims and module grants against it offline. | — | |
| Decoder and reconstruct modules, and pinned parameter sets, are authorised by digest and revoked by digest. A sink that holds a key log refuses a revoked parameter set, and its dispatch falls back. | A runtime host that loads signed modules is on the roadmap. |
Registry and public text
| Capability | Notes | Where |
|---|---|---|
| Every registered string in one table with its kind, status, media class and registering section; a machine-readable export and vocabulary v2 are generated from it and checked for drift in CI. | — | |
| Candidate capabilities, whose payload format is not yet pinned, are never emitted or dispatched. | — | |
| The codec glossary is linked to the registry and held to its schema by a test. | — | |
| The browser sink builds for wasm32 in CI. | — |
Continuous integration
Each workflow shows its current status on the forge.
| Capability | Notes | Where |
|---|---|---|
| Byte equality of the integer decode paths on macOS arm64, Linux x86-64 and Linux arm64. | — | |
| Conformance corpora, fast-kernel equivalence (audio and splat included), the OER C kernel and C2PA isolation. | — | |
| Headline decode tests that fail on a missing input, with CI supplying inputs pinned by digest. | — | |
| Neural end-to-end decode runs in CI. | — |
The live relay behind the shared-world and private-channel demonstrations is a companion implementation, reached through a WebSocket bridge. It lives outside the open-standards repository and carries its own licence.
Building
The next pull requests, in active development on top of the standard's main branch.
Binary payloads for the integer codecs
- The integer video, image, audio and splat capabilities each get a pinned binary payload format, refused when malformed by a closed list of reasons.
- An integer decode path that needs no machine-learning runtime.
- Vectors with an independent verifier, and byte-exact goldens across platforms.
Roadmap
The next builds, in the order they come.
-
Staged delivery
A base first and refinements as separate objects, with a browser demonstration and measured bytes and quality.
-
HTTP binding
Byte-range renditions, so a sink fetches only the rendition it picks.
-
wai-pack
The segmenter and packager, with a per-piece policy that chooses each piece's representation.
-
Runtime host
A host that runs signed, revocable modules.
-
Player integration
Runtime fallback, two DRM lanes and a continuity harness.
-
Deriving edge
An edge that evaluates derived tracks and rebuilds or re-packs content under its own receipt, chained to the source.
-
MoQ live delivery
Live tracks over Media over QUIC.
-
Energy along the delivery path, and content steering
Energy receipts for origins, hops and relays, and steering that reads them.
Why it is built this way
The sink is a computer, so every hop does work: the encoder splits and chooses, the edge selects without rewriting, and the sink rebuilds and proves.