RSS Amplifier

In the future, everyone will be famous for 15Mb · Jul 23, 2026

Will Robots Need Passports Redux

0
Sign in to vote or save

David G.W. Birch · In the future, everyone will be famous for 15Mb

Dateline: Woking, 23rd July 2026.

I was just on a call about a project I’m working and someone asked me what the British government’s digital identity strategy is. I had to confess that I don’t know, so I’d be genuinely grateful if anyone reading this who does know could perhaps tip me the wink in a comment?

One of the new Prime Minister’s first actions was to scrap the currently non-existent digital identity scheme and redirect the current non-existent money for this scheme to other good causes, leaving us back where we were before, sort of. There were three government departments working on identity stuff: The Cabinet Office was responsible a for now-scrapped scheme, the now-scrapped Department for Science, etc. (DSIT) was responsible for the OneLogin public sector single sign-on (SSO) service and governance of the private sector Digital Verification Services (DVS) Trust Framework, while the Home Office is still in charge of immigration, the focus of the now-scrapped scheme.

(The Institute for Government, a think tank, calls the government’s digital identity diversion a lesson in how not to approach policy making and attributes its failure, at least in part, to a “poor policy process.”)

With respect to the private sector situation, there is no point in me simply rewrapping what a more informed person says, so let me refer you to the brilliant Richard Oliphant. He summarises the private sector perspective very well, so I will merely paraphrase him and say that there are 45+ identity providers certified against the DVS Trust Framework which has been on a statutory footing since December 2025. Leading identity providers such as OneID and Yoti offer reusable digital IDs or proof of age, identity and eligibility. We are already seeing a positive regulatory change and in February, HM Treasury confirmed that DVS may be used for identity checks under the UK AML regime.

(And yet yesterday a leading financial service organisation asked me to prove my bank account details by sending them a recent bank statement.)

Where the government will go from here, I couldn’t say. Earlier this year, the UK Cabinet Office (the bit of the government that is in charge of running the government) launched a consultation on proposals for a UK digital identity system, described as part of a wider ‘national conversation’ on how individuals could prove their identity online other than with a PDF of their British Gas Quarterly Bill, the current gold standard. As you might imagine, this has implications for financial services, so it is important to understand what is going on.

The consultation closed earlier this year and now the government is consulting a hundred random people about the future design for our national digital identity infrastructure. Invitations went out to 36,000 UK addresses (mine wasn’t one of them) asking recipients to comment on “How should we design a Digital ID system for the UK?”. From those who responded, the government chose (via some opaque process) somewhere between 100 and 120 of them to come to central Birmingham for a couple of weekend sessions (plus some Zoom sessions in the week). The government says that those chosen will represent “a cross-section of the UK population”. Seriously. Welcome to the future.

Who knows what the panel will come up with, given that the British public are wrong about pretty much everything. If you think that is a sweeping statement please note that the public think that approximately a quarter of welfare benefits are claimed fraudulently (it’s actually around 0.7%, 34 times lower), that black and Asian people are a third of the population (actually a tenth), that 15% of girls under 16 get pregnant (it’s actually 0.6%) and that the country spends more on Jobseekers’ Allowance (JSA) than on pensions whereas spending on pensions is actually 15 times the spending on JSA. I could go on, but you get my point.

(These are all examples where narrative trumps data and I have some concern that this is precisely how the digital identity discussions will be undermined.)

I couldn’t even tell you when we will get a mobile driving license (mDL) in the UK. It was supposed to be last year, now we are going to something that we will be able to load into our Gov.UK “wallet” later this year so quite when we’ll be able to use this to open a savings account online I have no idea.

Meanwhile, in advanced nations, life goes on. China has announced that robots will be getting digital identities and launched the Humanoid Full Lifecycle Management Service Platform to manage them. The identities will be used to track the robots from assembly through to recycling in a programme led by the Humanoid Robotics and Embodied Intelligence Standardisation (HEIS) committee, part of the country’s Ministry of Industry and Information Technology.

Estonia, the nation that I am convinced inspired the previous Prime Minister’s advisors to start going on about an identity card again) has already moved on and plans to become the first country to create IDs for AI agents in an effort to avoid losing control over the technology, which is spreading fast in its digitally advanced society. The “Eesti.ai Advisory Board”, established on the initiative of Prime Minister Kristen Michal, agreed to proceed with a plan to introduce special “AI ID codes” that will allow AI to act for people, companies and organisations in what they call a “verifiable and auditable” manner.

We need to follow their examples and start thinking about identity in a more strategic context. The fact is that the demands of the economy mean that we need digital identities not only for people but also for businesses and bots. These identities are a priority and a foundational layer for not only the economy but for a safe and secure society. If we want economic growth, we have to get this layer in place.

Share

It is interesting to see that there is pressure for action coming from those who are trying to build that new economy. Noelle Acheson, who knows her onions* when it comes to real-world markets, says “It’s unlikely that a tokenised share in Palantir will be able to ‘seamlessly’ plug into a Russian DeFi application, for instance, or any DeFi application that has no KYC unless we finally sort out the on-chain identity issue”.

I am a big believer in digital assets and tokens and next-generation financial market infrastructure (FMI) and all that jazz and I know that Noelle is right. And we are not alone. In the Bank for International Settlement (BIS) white paper on the topic of next generation FMI, they themselves frame digital identity as a fundamental platform on which the financial internet (that is, the “finternet”) rest. Until there is a working identity infrastructure in place, the finternet cannot happen.

Now, that infrastructure does not need a global ID solution used for everything or network of national IDs or anything like it. It might well be an identity infrastructure solely for financial services. Some kind of financial services passport, for want of a better term. In fact I think that one way we can make some progress is by focusing on a practical solution for this specific problem rather than try to boil the ocean and solve the entire world’s superset of (wholly different) identity problems.

What if financial institutions got together to solve this problem for themselves? That is, what if there was some kind of financial ID that could be issued to people, to businesses and to robots? It is a fairly straightforward idea, after all. The first time you or your company or your bot or your company’s bot come into contact with the financial system, you/they/it are KYCd, AMLd, CTFd and PEPd up the wazoo: folded, spindled and mutilated until a certified player. Once you, for example, are issued with such a financial services passport then you can use it to visit other institutions, accountants, lawyers and so on without having to be folded, spindled or mutilated all over again.

Instead of sending your personally-identifiable information with a transaction, you need only send a pointer to the passport (a public key, in essence). There will be a visa to the land of (e.g.,) Barclays stamped inside the passport (a verifiable credential, in essence) which testifies to your certified playerness. You can show this visa to anyone: they can’t copy it or counterfeit it because they do not have access to the private key, which is locked away in secure hardware somewhere. Your passport to the finternet would then be your financial ID, or “FID”.

In one of their reports last year, McKinsey said that what they label “credentialling and identity” is the first of their key control points in the agentic economy because agents need secure, user-granted permission before they can initiate transactions across multiple institutions. Indeed they do and therefore organisations that already manage high-trust credentials start with a clear advantage. They go on to highlight some success factors: zero-trust architectures that never assume persistent access, dynamic consent via standardised protocols (for example, OAuth2/OpenID Connect) and continuous audit trails.

Give a gift subscription

A system to meet these success factors is actually not that difficult to build. We have all of the technology needed to create an identity. Infrastructure that offers both more security and more privacy. For one example, look at the paper on “A Cryptographic Framework for Proof of Personhood” from February this year. The authors combine:

Personhood credentials (PHCs) issued by trusted authorities and provide evidence that an individual is a real, unique human. These authorities can include educational institutions issuing student IDs, governments issuing passports or driver’s licenses, employers certifying employment, or ride-sharing platforms issuing driver credentials. Any organisation can serve as a credential-issuing authority, provided it ensures that each person receives at most one PHC and follows revocation protocols when necessary. PHCs may also encode additional structured information, such as age or role, to support specific applications; and

Verifiable relationship credentials (VRCs) and efficient zero-knowledge proofs on top of them to form a coherent system for a proof of personhood. VRCs are issued peer-to-peer between individuals and capture real-world interactions or trust relation- ships. For example, a passenger and driver on a ride-sharing platform may issue VRCs to one another after a completed trip. VRCs can also carry endorsements or qualitative feedback, such as a colleague vouching for reliability or a landlord attesting to tenant trustworthiness.

Their approach is to combine multiple PHCs from different authorities and VRCs from peers to create a robust digital identity infrastructure whereby participants need not reveal all of their credentials to every counterparty. Using zero-knowledge proofs, individuals can prove properties such as being over 18 or a qualified dentist without exposing underlying personal data. This approach allows verification to be both wholly secure and privacy-preserving at scale and I have long argued that this is where we should be going.

(Note also that this is congruent with the European Digital Identity Wallet approach. eIDAS encourages ZKPs as a privacy-preserving technology and the relevant regulation requires that the wallet not allow issuers or verifiers to track user behaviour without consent. The current reference framework does not mandate a specific ZKP scheme as it sees this as a topic for future implementation.)

Banks could do this with the data that they already have. Barclays could easily give me a verifiable credential that I could present to a fintech that wants proof of my bank account without gas bills or driving licences or anything else involved. This is a practical way to develop an ecosystem of users, companies and robots that could provide the backbone of a decentralised trust layer for financial services that would enable the online world to continue to grow and flourish in the age of AI. Let’s ask the public what they think about it.

* I deliberately used onions here, rather than apples or SEC rules, because the trading of onion futures in the US is illegal, a fact that to my mind at least highlights just why markets are not just about technology.

Leave a comment

Are you looking for:

  • A speaker/moderator for your online or in person event?

  • Written content or contribution for your publication?

  • A trusted advisor for your company’s board?

  • Some comment on the latest digital financial services news/media?

Book Dave

No posts

Read the original on dgwbirch.substack.com

Comments

Nothing yet. Say the first thing.

    Sign in to join the conversation.