The quiet rise of a new state utility
For most of modern history, identity was a documentary matter: a passport, a birth certificate, a voter roll entry, a paper credential presented at a counter. In the past decade that narrow administrative function has expanded into something larger. Digital identity now sits at the junction of welfare delivery, taxation, migration control, health systems, financial access and online services. In practical terms, it is becoming a state utility: a layer of infrastructure through which citizens and residents prove who they are, claim entitlements and navigate both public and private institutions.
This shift matters because infrastructure decisions are rarely neutral. They shape power long after their technical details are forgotten. A road network changes trade routes; a payments system alters market structure; an electricity grid defines who is connected and on what terms. Digital identity works in much the same way. Once embedded into everyday transactions, it becomes difficult to avoid and costly to redesign.
Digital identity is not merely an administrative upgrade; it is a reallocation of power between the individual, the state and the intermediaries that sit between them.
The attraction for governments is obvious. Reliable digital identity can reduce duplication, speed service delivery, improve auditability and help reach people who have historically been poorly served by fragmented bureaucracies. The World Bank’s Identification for Development initiative has long argued that identification is essential for access to services and rights, especially where civil registration systems are weak. Yet the same infrastructure can harden exclusion if enrolment is uneven, if authentication fails, or if legal safeguards lag behind technical deployment. The strategic question is therefore not simply how to build digital identity, but what constitutional and institutional framework should govern it.
Why governments keep returning to the problem
The appetite for digital identity reflects structural pressures on the state. Public administrations are expected to deliver more services remotely, exchange information across agencies and reduce fraud without imposing endless paperwork on citizens. Demographic change and fiscal strain only heighten the appeal of systems that promise cleaner records and lower transaction costs.
There is also a geopolitical dimension. Governments increasingly see digital public infrastructure, including identity, as a component of sovereignty. If crucial authentication systems are weak, fragmented or dependent on foreign platforms, states lose control over how public authority is exercised online. The OECD has noted that digital identity is a core enabler of digital government, allowing people to authenticate once and use multiple services securely. The European Union has pushed this logic further through its revised framework for electronic identification and trust services, seeking interoperability across borders while retaining public oversight.
Yet recurring state interest should not be mistaken for a settled model. Different countries have taken markedly different paths, shaped by legal traditions, administrative capacity and political culture. Some systems are centralised and universal; others federate existing credentials. Some rely on biometric deduplication; others minimise biometric use. Some are designed mainly for accessing government services; others are explicitly intended to support private-sector transactions as well. The diversity of approaches underscores a wider truth: digital identity is always political before it is technical.
Inclusion is the first test, not the last
The strongest normative argument for digital identity is inclusion. Without a recognised identity, people can struggle to open a bank account, receive social protection, register property, vote, study or cross borders safely. This is especially acute for women, migrants, refugees, informal workers and people living in remote areas. UN agencies and the World Bank have repeatedly highlighted the connection between legal identity and access to rights.
But inclusion cannot be assumed simply because a system exists. A digital identity regime can exclude in old ways and new ones. Old barriers include incomplete birth registration, documentary gaps, language barriers, fees, inaccessible enrolment centres and distrust of authorities. New barriers arise from biometric failures, ageing devices, intermittent connectivity, inaccessible interfaces and tightly coupled systems that deny access when one component malfunctions.
Those risks are not abstract. Research from the Centre for Digital Public Infrastructure and other institutions has shown that success depends on the full enrolment journey and the wider service ecosystem, not just on the credential itself. A person may be formally registered yet still unable to authenticate in practice. This distinction between identity possession and identity usability is often underestimated in policy debates.
The measure of a digital identity system is not how elegantly it authenticates the median user, but how rarely it fails the person at the edge.
Digital identity is not merely an administrative upgrade; it is a reallocation of power between the individual, the state and the intermediaries that sit between them.
If states want identity to serve as an equalising platform, they must treat inclusion as an operating requirement. That means multiple enrolment channels, strong exception handling, human appeal routes, offline functionality where possible and a legal commitment that essential services will not be denied merely because a digital check fails. In other words, analogue resilience remains part of digital justice.
Centralisation promises efficiency but concentrates risk
Digital identity debates often turn on architecture. Should a state maintain a single foundational register, allow multiple credentials to interoperate, or build a federation in which different institutions verify different attributes? There is no universal answer, but there is a universal trade-off. Centralisation can simplify administration and improve consistency; it also concentrates technical and political risk.
A large, central register may reduce duplication and make updates easier. It can support broad interoperability and lower verification costs across government. But it can also become an irresistible target for criminals, a point of systemic failure and a powerful instrument of surveillance if governance is weak. Conversely, highly decentralised arrangements may reduce concentration risk but introduce complexity, uneven assurance levels and gaps in accountability.
Cyber-security agencies have repeatedly warned that identity systems deserve treatment as critical national infrastructure. The reason is straightforward: compromise of identity data can have cascading effects across banking, healthcare, taxation and welfare. Unlike a password, a date of birth or a biometric trait cannot simply be replaced without consequence. The UK’s National Cyber Security Centre and the US National Institute of Standards and Technology have both stressed principles such as data minimisation, layered assurance and careful lifecycle management in digital identity design.
Architecture should therefore follow governance rather than the reverse. If legal oversight is weak, mission boundaries are vague and audit capacity is thin, even an elegant system can become dangerous. Good design can reduce risk, but it cannot substitute for constitutional restraint.
The surveillance dilemma is built in
Identity is attractive to the state precisely because it links records, transactions and individuals. That linkage can make public administration more coherent, but it also creates the conditions for pervasive observation. A single identifier reused across domains can enable comprehensive profiling. Authentication logs can reveal patterns of life. Function creep can normalise uses that were never part of the original mandate.
This is where digital identity departs from simpler service modernisation. It implicates civil liberties directly. Data protection authorities and human-rights organisations have repeatedly warned that identification systems can facilitate discrimination, chilling effects and disproportionate monitoring unless strict purpose limitation is enforced. The European Data Protection Supervisor, among others, has argued for privacy by design, selective disclosure and safeguards against unnecessary correlation of personal data.
Much depends on whether a system proves a person’s identity wholesale or only confirms a specific attribute. In many transactions, the state or a service provider does not need to know everything about a person. It may need only to know that someone is over 18, resident in a certain district or entitled to a service. Attribute-based and verifiable-credential approaches aim to reduce oversharing, though implementation remains uneven and standards are still evolving.
None of this eliminates the underlying dilemma. The very success of digital identity increases the temptation to extend it. Once a trusted mechanism exists, institutions will want to use it for more purposes. The essential policy task is to make restraint durable, not aspirational.
Trust depends on law more than software
Public trust in digital identity is often discussed as if it were a communications problem. In reality it is a constitutional one. People trust identity systems when they know what data are collected, who can use them, how errors are corrected, what remedies exist and where the boundaries lie. Technology can support these goals, but only law can stabilise them over time.
Several principles recur across stronger frameworks. First, purpose limitation: identity data should be used only for clearly defined and legally authorised functions. Secondly, proportionality: the amount of data collected and retained should be no more than necessary. Thirdly, independent oversight: regulators, courts, auditors and legislatures must be able to scrutinise system operators. Fourthly, redress: individuals must be able to challenge decisions, correct records and obtain service continuity while disputes are resolved.
NIST’s digital identity guidance is useful precisely because it frames identity not as a monolith but as a set of assurance decisions, risks and lifecycle obligations. Likewise, the European Union Agency for Cybersecurity has emphasised that trust services and electronic identification depend on coherent governance as much as on cryptographic soundness. In this sense, digital identity resembles public finance: confidence rests on institutions, not merely on instruments.
The measure of a digital identity system is not how elegantly it authenticates the median user, but how rarely it fails the person at the edge.
In digital identity, trust is created less by innovation than by enforceable limits.
For states, this has an uncomfortable implication. Ambiguity can be politically convenient during rollout, but it is corrosive in the long run. If citizens suspect that the scope of identity systems may quietly expand, adoption may become shallow, compliance grudging and legitimacy fragile.
Interoperability is strategic, but so is restraint
As public services digitise, pressure grows for identity systems to work across ministries, borders and sectors. Interoperability can reduce duplication, help migrants and mobile workers, support regional trade and simplify compliance. The appeal is especially strong in economic blocs seeking seamless digital services across jurisdictions.
The European framework for cross-border electronic identification illustrates both the promise and complexity of this ambition. Common standards can make credentials more portable and improve trust among member states. But interoperability also raises governance questions: whose rules apply, what assurance levels are recognised, and how are disputes resolved when one jurisdiction relies on another’s credential? These are not marginal technicalities; they shape sovereignty in practice.
Moreover, interoperability can become a Trojan horse for overlinkage. Systems designed to communicate easily may also make it easier to correlate data across domains. The same standards that reduce friction can, if poorly governed, reduce anonymity and expand secondary use. A prudent state therefore pursues interoperability with segmentation, logging controls and legally enforced firebreaks between functions.
In effect, the mature goal is not maximal connectivity but appropriate connectivity. The best identity ecosystem is one that allows necessary verification while preserving institutional distance where democratic societies require it.
Biometrics solve some problems and create others
Biometric technologies have become central to many digital identity programmes because they promise uniqueness at scale. Fingerprints, iris scans and facial images can help deduplicate records and support authentication where documentary evidence is weak. For populations with inconsistent paper trails, this can appear transformative.
Yet biometrics are not magic. They are probabilistic systems embedded in social contexts. Error rates vary by modality, environment and population. Ageing, manual labour, disability, poor capture conditions and algorithmic bias can all affect performance. The UK Information Commissioner’s Office, among others, has warned that biometric data are particularly sensitive because they are intrinsic to the person and difficult to change if compromised.
There is also a category error in some policy thinking. A biometric is not an identity; it is evidence used within an identity system. Overreliance on biometrics can obscure the need for broader evidentiary chains, update processes and fallback mechanisms. It can also produce a false sense of certainty around automated decisions.
For this reason, prudent systems treat biometrics as one tool among several, not as the sole gatekeeper of rights. Where biometrics are used, they should sit within a framework of necessity, proportionality, secure storage, clear retention limits and accessible alternatives for those who cannot enrol or authenticate reliably.
The private sector will shape outcomes whether invited or not
Even where the state leads, digital identity quickly spills beyond government. Banks, telecoms providers, employers, universities and online platforms all need ways to verify people. In many countries, these actors already issue or rely on credentials that carry social weight. The state can ignore this ecology, but it cannot escape it.
In digital identity, trust is created less by innovation than by enforceable limits.
This creates a strategic choice. Governments can try to dominate the identity layer completely, or they can set rules that allow multiple actors to participate under public standards. The latter approach may spur usability and uptake, but it also introduces market power concerns and complicated liability questions. If private institutions become indispensable gateways to authentication, exclusion can shift from the administrative to the commercial domain.
The OECD’s work on digital government has stressed the importance of user-centric design and ecosystem thinking. That is sensible, but user-centricity alone is insufficient. Identity markets can entrench dependency just as easily as they can promote convenience. The public interest lies in ensuring portability, open standards, contestability and non-discriminatory access, while preserving the state’s duty to guarantee identity as a public function tied to rights.
The line between public infrastructure and commercial intermediation is therefore one of the defining policy boundaries of the next decade. States that fail to draw it clearly may find that accountability becomes diffuse just when identification becomes indispensable.
What a durable settlement looks like
No identity system is risk-free. The realistic objective is not perfection, but a durable settlement that aligns administrative efficiency with democratic safeguards. Such a settlement has several features.
- A strong civil registration foundation, so digital identity rests on accurate life-event records rather than on ad hoc enrolment alone.
- Clear statutory limits on data sharing, retention and secondary use, backed by independent oversight.
- Multiple assurance levels and authentication methods, allowing services to calibrate checks to actual risk.
- Robust exception handling, including offline and human channels for those who cannot use digital tools easily.
- Privacy-enhancing design choices, such as selective disclosure and minimised identifiers where feasible.
- Regular public auditing of error rates, security incidents, exclusion patterns and vendor dependence.
- A presumption that essential rights and benefits must remain accessible during technical failure or identity disputes.
These features are less glamorous than debates about frontier cryptography or sleek interfaces. But they are what distinguish identity systems that merely function from those that deserve legitimacy. The history of state infrastructure suggests that legitimacy is the harder achievement.
Digital identity will keep expanding because modern administration needs reliable ways to recognise people at scale. The question is whether states can resist the gravitational pull towards overcentralisation and overcollection. If they can, digital identity may become a quiet enabler of capability and inclusion. If they cannot, it may become an architecture of dependency that citizens are expected to trust but are given little power to question.
That is why digital identity should be treated as a constitutional project in technical form. Its real significance lies not in the credential on a phone or the record in a register, but in the rules that determine who is seen, who is served and who gets to decide.



