Back to All Episodes
Season 5Episode 241

OpenOrigins: Cryptographic Provenance for the AI Era

September 11, 2026
30m
2 Guests

Listen Now

About This Episode

In this episode of DevNTell, Narb welcomes Dr. Manny Ahmed and Ari Abelson, co-founders of OpenOrigins. They discuss how OpenOrigins provides real-time, permanent trust and cryptographic provenance for digital media and AI agents. Manny and Ari elaborate on the rise of synthetic content, deepfakes, and data poisoning, explaining why post-hoc AI detection methods fall short and why capturing provenance at genesis is essential. They explain their underlying decentralized Merkle tree architecture, Cambium, alongside products like Source and Tally, which log, timestamp, and cryptographically secure AI agent workflows and authentic media for media organizations, enterprises, and developers.

Key Takeaways

1

OpenOrigins is building a permanent cryptographic trust layer to verify real-time human and AI digital interactions.

2

Post-hoc detection methods for AI-generated media inevitably fail in an adversarial arms race; immutable proof must be captured at genesis.

3

Cambium is a decentralized Merkle tree consensus framework that scales throughput logarithmically as nodes increase, avoiding traditional blockchain bottlenecks.

4

Tally provides immutable, tamper-proof logging for AI agents and developer harnesses (like LangChain and Codex), preventing agents from falsifying their own audit trails.

5

Cryptographically proven provenance enables safe, high-value data licensing for AI companies aiming to prevent model collapse.

Featured Guests

DM

Dr. Manny Ahmed

Co-Founder & CEO @ OpenOrigins

OpenOrigins
AA

Ari Abelson

Co-Founder & CSO @ OpenOrigins

OpenOrigins

Timestamps(click to jump)

Episode Transcript

Narb

GM, GM. Welcome to what's going to be another fantastic episode of DevNTell. So if you didn't know, DevNTell is a 30-minute podcast held every week, allowing founders, hackers, and anyone in between the opportunity to come on the show and showcase what they built. And today, I'm ecstatic to welcome Dr. Manny Ahmed and Ari Abelson, who are the co-founders of OpenOrigins. OpenOrigins are building the real-time, permanent trust layer for human and AI interactions online. If you stick around for today's episode, you'll get to meet Manny and Ari, learn about OpenOrigins, how it works, and how you can get started using it today. All right, let's get into it.

Narb

GM, GM. Welcome to the show, guys. I'm ecstatic to have you on today.

Ari Abelson

Yeah, thanks for having us.

Dr. Manny Ahmed

Good to be on here.

Narb

Excellent, excellent. Yes, happy Friday. And yeah, I know you guys are working on some important tech, especially for the AI landscape that we live in today. So I'm really excited to learn more about what you guys are doing, as I'm sure our audience is. But before we get into that, would you just like to give an introduction about yourselves?

Ari Abelson

Sure.

Dr. Manny Ahmed

Sure, I'll go first. I'm Manny, I'm the founder of OpenOrigins. Before starting OpenOrigins, I was an academic. I did my PhD and postdoc at the University of Cambridge, where I did my thesis on consensus algorithms and distributed computing. So I come at the crypto world from a theoretical lens. I also worked on a lot of systems that were used by journalists. So I got into OpenOrigins, or the idea of OpenOrigins, by working with journalists on whistleblowing systems. One of the things that we worked on during my PhD was designing a whistleblowing system that allowed sources to contact journalists anonymously even if they are under a mass surveillance state. And now that system is used by organizations like The Guardian. That's me. I'll pass it off to Ari.

Ari Abelson

Hey, I'm Ari. I'm co-founder of OpenOrigins. Well, OpenOrigins has been running for about half a decade now, so I feel like most of my identity is associated with this company now. But before that, I was working as a misinformation and disinformation researcher on projects for the Ministry of Defence and for large technology companies. I've been in startups for most of my career. In those projects is when I started to pivot and understand what we were kind of about to approach and about to reach in the landscape of AI, which was hyper-realistic synthetic content, disruptive communication systems. And that's where kind of the genesis interest in what we're building at OpenOrigins came to be. How do you govern AI models? How do you ensure that we can understand what AI systems are actually doing and how we can interact with them in healthy and sustainable ways? But yeah, that's my background.

Narb

Amazing. And how did your guys's paths kind of intersect and how did you guys find each other and co-found the company?

Ari Abelson

Yeah, so I mean, I can answer this. We met at an incubator, so at Entrepreneur First. We were building different things at the time. So Manny had just started thinking about the concept of OpenOrigins and actually left the incubator to kind of start the genesis roots of the company. I was building a different company at the time with somebody else. And then we came together several months later, maybe a year later actually, and started thinking about OpenOrigins and building that together, and kind of collaborating on that.

Narb

Excellent. And is it just you two, or do you guys have a full-fledged team under you as well?

Dr. Manny Ahmed

Yeah, no, we've got an engineering team based out of the UK, and then we've got our business team here. We're around 15 people right now.

Narb

Awesome. Awesome. Yeah. And like I mentioned, you guys are doing some important work. But for the audience who might not realize what's kind of going on or might just be getting into AI themselves, could either of you or both of you kind of touch on the current state of generative AI and what its impact has been on at least social media, and why it's so important for people to be able to distinguish that type of content from human-generated content?

Dr. Manny Ahmed

Yeah. Do you want to take this or should I take it, Ari?

Ari Abelson

I mean, I can take a bit. I can give a small take if you want to add. I think that what we're witnessing now is pretty remarkable, which is, it is itself kind of like a flywheel, right? It's AI models that are becoming increasingly better at a pace that we I think almost can't catch up to anymore, right? Like Astra and Fable are really good examples of this. What it means is, initially when OpenOrigins started, the problems we were really concerned about were synthetic content, like photos and videos, deepfakes, etc. Like this was where we were like sitting and saying, okay, you know, this is going to be the genesis problem of the world: How do you tell if an image is real? How do you know if a person's face is real?

Dr. Manny Ahmed

Just for context, we started in 2022. So, right, like before ChatGPT became mainstream, right? This is before the AI...

Ari Abelson

Yeah. So right at the beginning, exactly. So that was our initial fear. That was what we were thinking about. We were thinking about these AI risks. But over the last, I would say, year, especially the last year, the risks are expansive and the landscape has changed fundamentally, right? Cybersecurity risks now are a thing that I think are the predominant fear. Systems that we've thought were deeply stable and deeply secure are able to be corrupted within a matter of days. And that landscape change is really fascinating because what it means is we've shifted from, 'Oh, can this AI model kind of fake a photo, fake a commit, and trick somebody in a shallow way?' to, 'Are the fundamental infrastructures that we built our entire digital ecosystem on actually going to be able to sustain not just the next year, but the next few months to the next model release?' And that shift has really been, I think, the big fascination of us as a company over the last several months. It's how do you track not just the proof of a human face through a photo, but how do you actually start to audit and understand broader systems and broader AI systems within them? I'm not sure if I caught everything, Manny, you might want to add things.

Dr. Manny Ahmed

Yeah, I mean, just to elaborate on that idea further, the story of OpenOrigins has been an expansion of scope for us, right? So when I started the company, the thing I was concerned about was early deepfakes, faking a journalist's face, right? Most of the video was actually real, it's just like a central part of that has been changed. And then AI sophistication increased to the point where we're now generating photos and images from scratch, and we're at a point where detection no longer works, right? So we've crossed that horizon. And sort of our tooling has expanded to keep up with it. So we expanded from just doing narrow scope face deepfake detection or deepfake prevention to all photos and videos, archival content, etc. But recently, as Ari was mentioning, I think our realization has been that that is a narrow slice of the attack surface that the generative AI models have now exposed. The attack surface is now the infrastructure itself, right? It's like the Hugging Face incident I think is a really good example of like, look, there are these, you know, so-called perimeters that we like to think of. Like as a security engineer, I like to think of things in terms of: Here's my security perimeter, here's my security perimeter, and I have these defenses. But these are being proven to be really fragile. And I think that's going to be the story evolving over the next few years, is we're going to realize that a lot of the fundamental things that we thought were very secure or that we could base our security assumptions on don't hold anymore.

Narb

Yeah, absolutely. I think that's—it might even be an understatement, I don't know. We're moving so fast in this space, and there's all these different takes of like, is AI being trained responsibly and all that jazz that came out this week, right? So it's, yeah, certainly going to be—if you're an engineer or somebody who has to like keep these systems secure, you'll definitely be employed, that's for sure. I don't know if you'll have fun, though. But yeah, I'm really keen to learn how the system works. So I guess could you guys kind of walk us through an end-to-end example of how the platform would work?

Dr. Manny Ahmed

Sure, yeah. I'll go for that one. So there's two components to this. One is the backend infrastructure, which is built on a consensus algorithm we call Cambium. And Cambium is not a blockchain. It works on a decentralized Merkle tree. And what that allows us to do is scale that network massively. So Cambium has this unique and wonderful property that its throughput and its performance increases as you add a number of nodes, right? Most blockchain networks have the opposite property: You add more nodes, the network slows down because consensus needs to be global. Because we're building on top of a Merkle tree instead of a linear blockchain, we only need to communicate with a logarithmic number of nodes as the network grows. So if you want to add more throughput, if you want to add more capacity, you just add more nodes. So it's wonderful in that sense. And I think that's why it serves as a really nice base layer for doing the stuff that we want to do, which is doing agentic security. So that's component number one. The second component is how we ingest content onto the Cambium network. And so far, we've been focused on content provenance, as I mentioned earlier, where we've got applications that are now open source that allow you to take content using your phones and prove that this happened at this particular time and place, there's a 3D depth to prove that you were actually there (this is not a photo of a photo), and that proof then gets anchored onto the Cambium network. The thing that we're now releasing, and I'd be super excited for your audience to try out, is Tally, which is a way for keeping track of what your agents have done, and doing so in an irrevocable manner. So we've got hooks that you can put into your harnesses like Claude Code, Codex, LangChain, and Tally will keep track of what each of your agents is doing, flag when suspicious actions are taking place, and prove that this actually happened. So one of the issues that we've faced in a lot of this security discourse that we're having around agents is that it's very hard to prove what an agent has actually done, especially when the agent has access to write logs themselves. They can rewrite history, they can manipulate history. Cambium allows us to prevent that and makes the attack surface so big that the agent can't do that. That's kind of the overall landscape. I don't know if I missed anything, Ari.

Ari Abelson

No, I think you nailed it.

Narb

I guess yeah, so it definitely seems it's a complete end-to-end solution here. And for keeping track of what the agent has done, are these actions recorded on Cambium or how does that work?

Dr. Manny Ahmed

Yeah, so there's two ways to do it, and it depends on your privacy policies around the content that your agents are touching. So we work with some clients that would not be okay with their plaintext data being exported out of their infrastructure. In that case, we just take a hash of the actual plaintext, store a pointer to where the plaintext can be found, and then store that reference on Cambium. So we can always prove if something has been manipulated, but we don't actually store the plaintext. If you are someone who doesn't have those kind of strict requirements on exploitation of data, then we've got a service where you can just send us your logs, we'll store the logs, and we'll also anchor them to Cambium.

Narb

Amazing. Yeah, this particular part of the agent equation is something a lot of people kind of overlook, just because I feel like we're still kind of in that—I guess we're kind of transitioning to another phase, but kind of still in that toy version of all these things, right? People are just excited to build something ad-hoc, get it working on their computer, switch out the models. But when you start to actually deploy these shiny things in like an enterprise environment, for example, or high-stakes environments, then you kind of need all the bells and whistles for observability metrics and keeping track of what it did, why it did it. So yeah, very fascinating. And kind of switching back to the verifiability part through the app, you guys kind of take a different approach as far as I understand compared to some of the other competing products where you guys prove before or during the generation of the media, whereas other people kind of chase it after the fact. From your perspective, why is that a better approach? I mean, it might be obvious, but I just want to hear it from your mouth.

Dr. Manny Ahmed

I mean, it's been sort of the foundational thesis of OpenOrigins like five years ago when we started on this journey. Even back then, I could see the trajectory of how adversarial training is going to lead to increasing sophistication of generated media to the point where detection was not going to work, right? Even back in 2021 where Will Smith was eating spaghetti noodles in a weird way, it was clear to me that investing in detection, like post-hoc detection, was a waste of time, because every single model was going to result in a step-function improvement. And if you made a good detector, you were basically giving training data to create a better generative image, right? So detectors get used to make better generators. And I didn't want to get involved in that arms race, right? What I would rather have is sort of actual, irrevocable proof of my content. So yeah, you mentioned proving the photos on phones, that's what Source does. Source uses the trusted execution environment on modern iPhones as well as Android phones to prove that this is a real physical device. Then we do some interesting photogrammetry to prove that there is actual depth in front of the camera sensors, so someone isn't just putting their phone up to the screen and taking a photo of the screen. And we do remote attestation to prove that the camera sensors are real camera sensors, not some sort of an emulated camera. So this is like hardware-backed security that helps us prove that the photo that finally resulted from this pipeline is real. And so it doesn't matter how much more sophisticated the AI algorithms get, how more sophisticated Grok's image generation gets, this is still going to work.

Ari Abelson

And just to kind of expand on that, I think more broadly, the ability to fossilize or create immutability around genesis information is really the core of what we think of as a company, right? It's like when information is created, at the genesis point of new data, it's important to build immutability at that genesis. And the reason that is, is because in the case of a photo or video, without the initial genesis moment proof, it becomes almost impossible for us to verify if the photo is in fact real post-hoc, right? So it means that we can't trust a photo anymore or video anymore. But even within AI agents and the logs of AI agents, which is kind of our new technology, we're focusing on getting these logs as they're being created at the genesis point, and creating immutable structures around those logs at that point, fossilizing them, right? The reason that's important is because agents are good at two things: One is reclaiming their truth when they've done something incorrect or wrong and they want to potentially hide that, and they're also potentially very good at creating distrust in these logs, right? So what we are trying to do is we're trying to find evidence as it's being created at the genesis point. We're trying to build through Cambium immutable structures around that evidence, so we can prove for the indefinite future that this is in fact real information that was actually collected or created, right? And that becomes kind of the root of trust that we really focus on as a company, that I think is something that is almost oversimplified. Like right now, even within log formats, etc., they're often just stored in plaintext databases, which can sometimes be accessed by the agents, but even if they can't be, we have to assume that these systems are going to become more vulnerable, and we have to then assume that we have to have much better security parameters and frameworks around how we're actually securing and fossilizing these records, ensuring that we can actually trust them into the future. And that's actually where decentralization becomes really important, much more important than it used to be in the past.

Narb

Absolutely, absolutely. And as we're a developer show, I'm sure our audience is very keen to start playing around with this technology. What are some APIs, SDKs, or different ways people can start using Tally, for example?

Dr. Manny Ahmed

Yeah, I mean, Tally is open for access if you just want an API key to start playing around with it. We'll post a link, I'm sure Narb you'll post that in the show notes somewhere. But also you can just go to openorigins.com/tally, and you'll be able to find it. Once you've got the API key, we've got pretty extensive documentation for how you would link it to your harness. If you're using one of the mainstream ones like Claude Code or Codex, we've got a one-click installer. So as you go through the onboarding flow, you literally just have to click on install, it'll download a DMG or an EXE, and you know, you're off to the races.

Narb

Amazing. And yes, indeed, we will have all those resources for you to play around with Tally and the other OpenOrigins products in the description below. So if that is something that interests you, definitely give that a checkout. And kind of coming back to the verifiable multimedia again, I don't know if you guys recall like the NFT phase, and there was this big dispute in a lot of the decentralized communities over how the image was being stored and how you could prove nobody can mess with your NFT or anything. It kind of sort of feels like the same type of vibe. I don't know if vibe is the right word. But basically, just curious, when people do create these images, these videos, are there ways that they can license it to other people to use?

Dr. Manny Ahmed

Yeah, I think the one sort of crucial line to be drawn between what we're doing with Source versus what NFTs were trying to do is that they were trying to enforce scarcity, whereas we're trying to prove authenticity, right? So the sort of fundamental design goals are different. So as far as we're concerned, you make a copy of the proof package, that's fine. We encourage it, in fact, because most of our clients are media organizations, they would love for things to go viral. So there's that fundamental difference. As far as licensing goes, interesting question, because we actually do have a sort of licensing marketplace. So we work with our customers who've used one of our products to secure their historical archives for authenticity purposes, but then interestingly enough, going through that process means that their archives are now a very interesting licensing opportunity for AI companies. Because as an AI company, when I'm ingesting a bunch of content to train my model, I want to make sure that I'm not ingesting the outputs of someone else's model. I don't want to be incorporating the biases of those previous models that will lead to model collapse. So this we discovered as a positive side effect—this was not like by design initially—that once you've done the process of anchoring your archive with us, when we've gone through the process of proving that the content you have is real, AI companies are suddenly very interested in licensing that content. And yeah, we'd be happy to help you with that.

Ari Abelson

Yeah, I think that just expanding on this, authenticity becomes deeply important for licensing, right? Data is becoming the new moat for a lot of these models, especially for hyper-specific use cases. But now it's just super easy to fabricate data, right, in a way that just wasn't necessarily the case before, in a way that's hyper-realistic. So if you're thinking of a medical archive, test trials, etc., you want to train a model on this. It's extremely easy to just fabricate a ton of studies, a ton of fake content, etc., populate different pages, and then license in bulk 10,000 articles instead of 1,000 articles to a company that's willing to buy them. So data fraud is something that I think is going to become an increasing concern for companies, not just who owns the IP, but in fact, are these scientific articles real or are they just unbelievably well-designed fake articles? This goes back to genesis. I think NFTs in the future are going to be—all data is going to have to have some sort of NFT associated to it, right? Like every individual log needs to have some certificate or hash associated to it. Every single photo and video must, for us to believe in the authenticity of it. And with that, it means that that data becomes extremely valuable because it's authentic data. We know it was actually created, we know where it was created, we know why it was created, which means for licensing purposes, it offers a much higher value than thousands of fabricated articles that may or may not have scientific validity or may just be kind of fluff.

Narb

One thing that kind of comes to mind as you guys were saying that: This week we had the whole OpenAI fiasco where people came out and said, 'Oh, we solved this Millennium Prize problem.' Right? And then the math community's like, 'Oh, maybe not,' right? It's like you might have used notes from somebody else. Yeah, basically. So just curious, do you think if your tech was in place, like that kind of 'he said, she said' kind of thing would be thrown out the window?

Dr. Manny Ahmed

That's quite an interesting use case. I actually hadn't thought of that. But yes, if those researchers were using Tally, they would have irrevocable proof of the fact that they had these conversations and they could export those proofs and show it to the world. So that is actually—that's an interesting example. I'm going to use that going forward.

Narb

There you go. Everyone gets one for free! Yeah, I mean, the gears were turning as you guys were speaking, like, 'Oh yeah, this seems very relevant for now.' And I'm sure we're going to see much more of these cases going forward as the models get better as well. So yeah, definitely keen to see the developments around that. But I guess as we're kind of coming to time here, is there anything you guys want to tease on, share some alpha around anything you guys are doing for the rest of the year and starting into next year?

Dr. Manny Ahmed

Yeah, I mean, I think we're really focused right now on Tally. We want to build the best possible trust layer for AI agents, and would love any feedback, right? Like we've just launched this product, it's still really new. We're very, very interested in having developers come in and try it out and, you know, basically grill us on all the mistakes that we've inevitably made, and hopefully build it into a product that somewhat decentralizes the power that these organizations have, like the example that you just gave, but also that allows us to deploy agents in places that right now we're too scared to deploy them because we don't know what they're going to do once we deploy them. So yeah, a more robust AI agent infrastructure.

Ari Abelson

Yeah, I would just say that we're really keen on building in public. We're a pretty small team, and I think we've launched a really cool generation one of Tally. It's going to be updating probably every week to two weeks right now at current pace with new features and really cool things, which means that it's a really cool time for people to build with it and start using it because they can actually be part of the build process, right? And yeah, I mean, I don't think it's alpha, but what's fun is in six months, Tally's going to look entirely different based on the feedback of the early users, hopefully much more useful for every one of them. And that entirely comes from everybody who just DMs us. We're a pretty open team, so it's a pretty public build, and we're kind of excited to get those first few people on.

Dr. Manny Ahmed

Yeah, please do DM us. That's a great way to sort of give us feedback.

Narb

That's a good segue. We'll have it in the details of the description below. So definitely if people watching or listening today are keen to try out Tally or any other OpenOrigins products or just chat with the co-founders, definitely reach out. And I guess just before we let you guys go, for the aspiring founders who are watching today or might be on the fence of wanting to start their own company or finally build out something they've been dreaming of building out, what's some advice you'd be willing to give them?

Dr. Manny Ahmed

I feel like we'll have very different advice because we came at this from very different angles. I think at my core, I'm an academic, and I just found a problem that I was obsessed with that academia didn't give me a path to continue pursuing, and so the startup happened as a positive side effect of me being super obsessed about this problem. And so I would say be a real nerd and take your passionate nerd energy into something. But Ari, you'd probably have different advice.

Ari Abelson

I mean, I actually totally agree with what you're saying. I think it's a really big part of it. Like obsession is really key. It's not easy building a company. I think a lot of people assume it's super fun every day and you wake up and you're just super excited to do it. It's like, in fact, the opposite: It's extremely hard, especially at the beginning, and it takes a long time. You know, I forget the quote, I think 'a good company takes 5 years to succeed and a bad one takes 10 years to fail,' right? It's a long portion of your life and you've got to be obsessed. So I totally agree with that. What I'd add to it is something that the very first person I ever worked for when I was I think 17 years old told me, because I wanted to be a founder back then, and I was asking him how to do it. I was like, 'I'll work for you for a couple years and I'll work for somebody else and then I'll get these skills to become a founder.' And he said, 'If you want to be a founder, the easiest way to learn how to be a founder is by founding a company and failing.' And that's really what you have to do. So I'd say that if you're kind of on the fence, just have a bias for execution. Don't think you have to build a skill set; there is no skill set for this except for iterative failure and success through it. So bias for execution and go found something if you want to found something. There's no other way of developing the skills.

Narb

Excellent. Well said by both of you. And hopefully that inspires at least one or a few people watching the show today to go chase their dreams. And with that, Manny, Ari, thank you so much for taking the time out of your busy day to come chat with us today. Really wishing you guys the best of luck continuing to build out some really critical pieces of the future here. And yeah, we'll be very keen to see all the developments of Tally and OpenOrigins itself.

Ari Abelson

Yeah, for sure.

Dr. Manny Ahmed

Yeah, no, thanks for having us, man.

Narb

Yeah, my pleasure, my pleasure. And yeah, with that, I just want to wish everybody a very happy Friday, happy weekend wherever you may be. And we will catch you back here next week for another great episode of DevNTell. Till then, have a good one, folks. Cheers.

Listen On

Resources & Links

Share This Episode

Share on X

Watch Episodes Live!

Subscribe to our event calendar and never miss a live episode.

View Event Calendar