A while ago I published a piece on Technology Paternalism, the anti-pattern by which a technology system is designed to shape, restrict, or pre-decide choices for people, commonly justified as safety, efficiency, or protection. What resulted were vivid discussions. A huge thank you to all the voices in the discussion. This article picks up on them.
If I stare long enough, whatever looks complicated will eventually collapse into something much smaller, much sharper, and a bit more unsettling. Object, Controller, Event, 32 bytes (OCE-32) came out of that kind of staring... Let’s talk about the 32 bytes…
Estimates suggest the United States has lost $3 trillion to fraud and improper payments across just federal government programs over the last two decades.[⁵] The old model is failing catastrophically, and the first, second, and third-order costs are being borne by individuals, institutions, and taxpayers alike.
Utah’s Chief Privacy Officer, Christopher Bramwell, has been explicit about the strategy: embed rights-first principles into statute before systems deploy, not after. “If we fail to act,” Bramwell wrote in GovTech, “identity will be defined for us by whoever has the resources and ambition to control it.”[¹¹]
This blog post explores what it takes to issue verifiable digital credentials, with a focus on mobile driver’s licenses (mDLs). We’ll look at how issuance works today in practice, where inconsistencies exist, and how standards bodies (FIDO, ISO and OpenID Foundation) are working to bring greater trust and interoperability.
By reframing digital identity as What You Really Need To Know? and building infostructure to secure the story behind the data, enormous opportunities would open up in bigger more urgent areas, including open data, the Internet of Things, supply chain integrity, digital safety and generative AI quality. Different credentials would be issued to respective digital Subjects, to assert and protect any qualities of interest. The Subjects of these focused VCs can be non-human; they can even be intangible, such as data itself.
Data is not flat, and pretending it is flat is where most systems quietly lose the plot. An address is a structured thing with parts. An employer employs an employee. A seller is related to a buyer. A department is part of an organization. These relationships are not decoration: they are the meaning.
Digital identity has been “the future” for over a decade, but the data tells a more nuanced story.
I have been trying to stress that identification and identity are two different things - that identity is not only who you, an organisation, their AI-agents or things are - but also what you/they are - and on whose account you/they can act.
A C2PA Certificate lets you attach a cryptographically signed provenance record, a “content credential,” to any media file. Anyone who receives the file can verify its origin, check whether it’s been altered, and see an auditable chain of custody from creation to distribution. Built on the open C2PA standard, backed by Adobe, Google, Microsoft, BBC, Reuters, Sony, Nikon and the broader Content Authenticity Initiative.
The C2PA Free Tier (since May 2026) includes one Level 1 Claim Signing Certificate valid for 1 year, plus 10,000 trusted timestamps per year, issued via the SSL portal.
Why non-human identities solve the wrong problem, and why machine governance requires single-use warrants at the execution boundary, not standing permissions.
If anything, proofing creep has now reached production scale. It arrives bundled into platforms, marketed as innovation, and justified through architecture diagrams with many arrows and little restraint.
The paper speaks often of trust, governance, assurance, accreditation, and interoperability. It asks how trust can be exported across jurisdictions and how credentials issued in one country might be recognized in another.
But beneath all of these questions lies another, more fundamental one that is never explicitly articulated:
Who controls the record?
But making sense of that data — curating which registries to trust for which purposes, interpreting what the data means for specific compliance requirements, governing the edge cases where automated answers aren’t sufficient — that requires domain expertise, industry relationships, and governed judgment that competitors cannot replicate.
Six standards bodies [IETF / OpenID Foundation / W3C / FIDO Alliance / The Linux Foundation / National Institute of Standards and Technology (NIST)] are hardening the vocabulary of autonomous systems governance right now. None of them can name the bearer of consequence. The American Bar Association's Autonomous Systems Governance Working Group is moving. But it needs to move faster than the ratification process. Vocabulary before standards. We only get one shot at this.
Profit optimisation kills privacy instrumentally: data extraction to target ads and maximise engagement left the information environment degraded. Privacy had to die so the machine could learn your preferences.
In 2020, I argued that a diluted information environment degrades autonomy (independence to decide), and that shrinking autonomy contracts human agency (power to do). Philosopher Isaiah Berlin offers “two liberties” to distinguish the two: negative liberty (“freedom from”) and positive liberty (“freedom to”).
In 2020, I argued that a direct line connects identity systems to political infrastructure. In the last chapter of the book I even went so far as arguing that different identity regimes would lead to different human futures, as our attitudes to identity would be a proxy for our relationship with AI. When we give the robots wallets, identity, or assigned consciousness, all of the above applies. This was rather radical at the time. Now, decidedly less so.
We are pleased to share this new non-paper organised by WE BUILD participants about AI agents, digital wallets and payments….It is clear to most that AI agents will manage many situations in our daily lives. Without a solid foundation that ensures a chain of trust our societies are at risk.
The accountability substrate: completing the AI-native Internet.
The AI-native Internet will not scale on distributed intelligence alone. It requires distributed responsibility, made enforceable through verifiable accountability. Responsibility is the social outcome of coordinated action; accountability is the technical substrate that makes responsibility enforceable at machine speed.
No posts

Comments
Nothing yet. Say the first thing.
Sign in to join the conversation.