HTML + 2 PDFs PACE: Verifiable Safety and Cyber Evidence Graphs for Physical AI
A PACE reference architecture for verifiable safety and cyber evidence, faster Physical AI commissioning, controlled change and continuous assurance.
Spherity Research
Evidence-led work on Digital Product Passports (DPPs), organizational identity, verifiable credentials, European Business Wallets (EBW), trusted AI, and the cryptographic infrastructure behind the real economy.
Research scope
Spherity Research examines how organizations, products, AI agents and machines can establish identity, authority, provenance and trustworthy evidence across regulated digital systems. The current agenda spans Digital Product Passports (DPPs), Digital Battery Passports (DBPs) and Cyber Resilience Act (CRA) product-evidence infrastructure; European Business Wallets (EBW), Data Spaces and governed data sharing; Trusted AI, Industrial AI and Physical AI, including functional-safety and cyber assurance for robots; post-quantum resilience; and European AI competitiveness through trusted execution and industrial renewal.
Open-access papers, executive briefs and policy roadmaps connect architecture, regulation and operating models for policy makers, industry leaders, researchers and technology teams.
Research library
Long-form papers, executive briefs, roadmaps and visual explainers for decision-makers building trustworthy digital ecosystems.
HTML + 2 PDFs A PACE reference architecture for verifiable safety and cyber evidence, faster Physical AI commissioning, controlled change and continuous assurance.
HTML + 2 PDFs How trust becomes a production factor and trusted execution capital for European AI productivity, industrial renewal, and transformation speed.
HTML + PDF A federated transformation architecture for Industrial AI, sustainable industry, security, resilience, metropolitan regions, and European competitiveness.
HTML + PDF A China-EU-US comparative analysis of Trusted AI, agentic AI deployment capability, legal authority, provenance, TEVV, and action evidence.
HTML + 2 PDFs A management brief and full research paper on CRA-capable DPPs for SBOM, VEX, evidence graphs, cyber assurance, and product lifecycle evidence.
HTML + PDF An energy data-X case study showing how European Business Wallets, governed market roles, and policy engines enable controlled DPP, DBP, and BESS data access.
HTML + PDF Spherity's identity-first DPP and DBP strategy, Gartner® Pioneers position, EBW convergence, cyber-secure product data, and Trusted AI outlook.
HTML + PDF An evidence-led 2026 outlook on ten German companies spanning Industrial AI, Physical AI, agentic commerce, and cross-company trust infrastructure.
HTML + PDF A two-plane architecture for authorized DPP and DBP transactions, decentralized product evidence, BESS, and European Business Wallets.
HTML + PDF A data-plane architecture for Industrial AI that links provenance, validation, freshness, and issuer-bound claims into auditable evidence paths.
HTML + PDF The control-plane architecture for proving who an AI agent represents, which mandate applies, and whether each cross-company action is permitted.
HTML + PDF A governance and systems architecture for organizational identity, quantum-safe trust infrastructure, business wallets, and repeatable PQC Corridors.
HTML An attack taxonomy, macro-economic risk model, and migration strategy for post-quantum identity corridors.
HTML Milestones, dependencies, standards, and adoption gates for the European Business Wallet under eIDAS 2.0.
HTML A cross-domain escalation and operational-readiness model for German and European decision-makers.
No publications match this search. Try a broader topic or clear the search field.
Market position
Gartner® published the Emerging Market Quadrant for Digital Product Passport — Established Vendors on 6 July 2026. Spherity is positioned as the sole vendor in the Pioneers quadrant. [1]
At Spherity, we see our identity-first strategy as the foundation for a wider trust architecture that extends from physical-product DPPs to AI Service Passports for AI systems and services. This extension reflects our own strategic outlook and was not part of Gartner's DPP evaluation.
Spherity treats the Gartner placement as one independent market perspective. Spherity's own view is that its technology leadership in identity-first and cyber-secure DPP infrastructure rests on its architecture, regulated production experience and partner ecosystem. The strategic objective is to make product data trustworthy, usable across company boundaries and suitable for automated decisions.
[1] Emerging Market Quadrant for Digital Product Passport — Established Vendors, 6 July 2026, Gartner document 8098797.
Gartner does not endorse any company, vendor, product or service depicted in its publications, and does not advise technology users to select only those vendors with the highest ratings or other designation. Gartner publications consist of the opinions of Gartner’s business and technology insights organization and should not be construed as statements of fact. Gartner disclaims all warranties, expressed or implied, with respect to this publication, including any warranties of merchantability or fitness for a particular purpose.
GARTNER is a trademark of Gartner, Inc. and/or its affiliates.
DPP & DBP infrastructure
Digital Product Passports and Digital Battery Passports need more than a product record. They need trustworthy evidence, governed disclosure and accountable actors across the product lifecycle.
Read Verifiable, Access-Controlled Digital Product PassportsProduct-linked identity connects identifiers, provenance, lifecycle claims, conformity data, SBOM and VEX records, and evidence-graph relationships.
European Business Wallets connect legal-person identity, roles, mandates, authorization policies and action evidence to each disclosure or transaction.
Machine-readable policy evaluates role, purpose, context and current status before product data crosses company, sector or jurisdictional boundaries.
Trusted Industrial AI
Regulated AI needs separate, interoperable evidence for legal authority and for the facts supporting a decision.
European Business Wallets connect legal-person identity, agent identity, bounded mandates, current status, policy decisions, and action receipts.
Read the control-plane paperEvidence graphs connect provenance, validation, freshness, transformations, conflicts, uncertainty, issuer status, and auditable evidence paths.
Read the data-plane paperA valid mandate does not prove that an AI output is factually supported. Reliable evidence does not prove that an AI agent was legally authorized to act. Regulated AI systems require both layers.
Quantum-resilient trust
B2B, B2G, G2G, machine, and AI-agent ecosystems depend on proving which organization is acting, under which authority, and whether the complete trust chain remains valid as cryptography changes.
Bind legal existence, representation rights, roles, licenses, delegated authority, purpose, and validity periods into reusable organizational credentials.
Cover issuers, wallets, verifiers, trust anchors, status, revocation, registries, qVDR functions, DNSSEC, WebPKI, semantics, vendors, and long-term evidence.
Align actors, assurance, evidence horizons, trust boundaries, hybrid or post-quantum profiles, downgrade rules, lifecycle controls, and reusable conformance evidence.
Algorithm replacement alone cannot preserve legal reliance when counterparties, trust anchors, status services, lifecycle controls, and evidence do not migrate coherently.
Read the PQC Corridor paperResearch FAQ
Concise answers with direct links to the underlying open-access research, executive briefs and policy roadmaps.
Strategy and policy questions about trusted execution, competitiveness and coordinated transformation.
Europe can convert its legal, institutional and industrial strengths into trusted execution capital: reusable identity, authorization, evidence and accountability infrastructure that lets organizations act faster without weakening control.
Read Europe’s Fundamental AI OpportunityThe proposed model treats Germany as a federated transformation system in which metropolitan regions, industry, the Mittelstand, research and government share missions, interoperable infrastructure, decision rights and measurable outcomes.
Read the Deutschland AG 2.0 paperThe three regions combine scale, regulation, industrial capacity and digital infrastructure differently. Europe’s opportunity is to make verifiable authority, evidence provenance and accountable execution a practical advantage for Industrial AI and Physical AI.
Read the China–EU–US comparative analysisThe research identifies ten emerging companies and complementary corporate anchors across AI, automation, robotics, energy, autonomous systems and cross-company trust infrastructure, using an explicit selection method rather than a valuation ranking.
Read the German technology outlookImplementation questions about product evidence, regulated access and reusable organizational authority.
A CRA-capable DPP can connect signed SBOM, VEX, vulnerability, conformity and lifecycle evidence in an access-controlled evidence graph, giving manufacturers and authorized parties current, verifiable product-security information.
Read the CRA-capable DPP researchThe architecture links product-bound identity and evidence with legal-person identity, verifiable credentials, mandates and policy checks, so a relying party can verify both what is claimed about a product and who is authorized to disclose or act on it.
Read Verifiable, Access-Controlled Digital Product PassportsEuropean Business Wallets can present verifiable company and market-role credentials to a policy engine, which evaluates purpose, role, mandate and context before granting access to sensitive product or energy data.
Read the energy data-X reference caseSpherity treats the Gartner placement as one independent market perspective and describes an identity-first strategy that connects cyber-secure DPP and DBP infrastructure with European Business Wallets, governed data sharing and a longer-term AI Service Passport outlook.
Read Spherity’s DPP and DBP strategy paperAdoption depends on legislation, implementing acts, standards, wallet and trust-service readiness, governance, conformance testing, procurement and viable cross-border use cases progressing in a coordinated sequence.
Read the European Business Wallet roadmapArchitecture questions about accountable AI, provenance and migration of the trust fabric.
PACE binds product identity and the current configuration to scoped safety, cybersecurity, AI and lifecycle evidence. This helps qualified parties find affected claims, tests and missing evidence faster after a change while deterministic safety controls and human assessment remain authoritative.
Read the PACE Physical AI researchEvidence graphs represent claims, sources, issuers, transformations, validation status, timestamps, conflicts and uncertainty as connected evidence paths that people and machines can inspect and audit.
Read the Industrial AI evidence-graph paperAn enterprise can bind the agent to a verified legal person, a current mandate, explicit policy constraints and an action receipt, then validate that authorization independently at the time of the transaction.
Read the European Business Wallet control-plane paperOrganizations first establish accountable identity and mandates, then map issuers, wallets, verifiers, trust anchors and lifecycle dependencies before coordinating assurance levels, cryptographic profiles, downgrade rules and migration evidence within a bounded ecosystem.
Read the PQC Corridor paperMigration must cover more than algorithms: keys, certificates, trust anchors, wallets, registries, status and revocation services, protocols, vendors, governance and long-lived evidence all need crypto-agile transition plans.
Read the quantum-vulnerability researchDecision-makers can use cross-domain scenarios to test how cyber, AI, quantum, hybrid and physical risks reinforce one another, then assign indicators, owners, thresholds and coordinated response actions.
Read the integrated threat modelOpen research
The publication source is maintained openly on GitHub for stable linking, transparent revision, and long-term discoverability.
Open the repository