I think the identity industry has spent too much time answering the privacy question.
People aren't afraid you'll know who they are.
They're afraid you'll turn them off.
A passport already tells the state who I am. The fear changes when identity becomes permission.
Permission to work, bank, travel, buy something or access a service.
Privacy asks what somebody can see. The harder question asks what they can stop you doing.
Most digital identity systems spend enormous effort on the successful check. The credential matches. The user gets through. The service starts.
I am more interested in what happens after no.
What happens after no?
It has already happened.
In India, families entitled to subsidised grain were denied rations because their Aadhaar number was not linked correctly or biometric authentication failed. The Right to Food campaign investigated 57 starvation deaths from 2015 onwards and linked at least 19 directly to Aadhaar-related denial. One involved 11-year-old Santoshi Kumari in Jharkhand, whose family had gone months without its grain entitlement.
China produced a different version during Covid. Its Health Code was not a national identity credential, but it attached a live status to an individual. Green meant movement. Yellow or red meant restrictions. Human Rights Watch reported that local authorities required the code to enter supermarkets, use public transport and enter residential areas. Access to work, movement, necessities and medical care could depend on the colour the system assigned.
Different systems. Different reasons for building them.
The common problem appears when a digital status sits in front of something essential.
A false no stops being a technology problem.
It can mean no food.
No transport.
No work.
Britain never got that far. But in September 2025, then Prime Minister Keir Starmer announced plans for a national digital ID and said:
"You will not be able to work in the United Kingdom if you do not have digital ID. It's as simple as that."
A petition against the scheme reached 2,984,191 signatures. The government ultimately cancelled the national Digital ID programme. On 8 September 2026 it confirmed that employers would not be required to conduct all right to work checks digitally.
The fallback numbers explain why this mattered. The Home Affairs Committee found that 5.2 percent of the working age population in England and Wales did not hold a valid passport. In Scotland, the latest census found that 17.7 percent of people hold no passport. (This stat amazes me to be honest)
The digital verification route for British and Irish citizens relies on passport evidence. The manual route still exists. Remove that fallback and a legitimate person can fail before anyone has questioned who they are.
A system can exclude someone without deleting their identity. It only has to make one proof the gate to something they need.
That is the part I think the privacy debate misses. The fear is not only that somebody can see your data. It is that a status attached to you can decide whether the next door opens.

A credential can open one door or control many. The difference matters when a check fails.
The refusal path
Every identity check can fail.
Fingerprints wear. Connectivity drops. Databases contain mistakes. Phones get lost. Names fail to match. A legitimate person eventually gets a no.
The important questions start there.
Can they use another document? Can they reach a human? How long does recovery take? What happens to the thing they needed while they wait?

The successful check gets specified in detail. The difficult branch starts after no match.
Building regulations learned this lesson long ago. Fire codes spend enormous effort on what happens when the normal route fails. Identity infrastructure needs the same discipline.
Prove less
Better systems can reduce how much one identity check controls.
If a bar needs to know whether I am over 18, it has no reason to learn my exact birthday, home address and document number. It needs one fact.
Aadhaar's offline paperless eKYC now lets holders omit some demographic fields. That reduces disclosure. It still does not provide the same thing as proving "over 18" without revealing the underlying date of birth.
The best digital identity lets you identify yourself less.
Selective disclosure only solves half the privacy problem. I can reveal nothing except "over 18" and still hand every website a persistent identifier that lets them recognise me again.
Spain's data protection authority has warned that selective disclosure without unlinkability can still enable tracking and profiling.
Recovery matters too.
In 2017, a chip vulnerability put hundreds of thousands of Estonian ID cards at risk. The state suspended roughly 760,000 affected certificates. Many cards were updated remotely. The physical cards continued to work as identity documents while the digital layer was repaired.
Break one layer without breaking the person.
Biometrics make that harder. Amazon lets customers pay with their palm across more than 500 Whole Foods stores.
You can revoke a biometric template. You cannot issue me another palm.
Businesses have a second identity problem
Everything above concerns people proving who they are.
Companies need another proof.
When a company opens a bank account, the bank checks the passport of the person sitting across the desk. Then it checks something separate: a board resolution, account mandate or signatory list.
The passport proves who the person is. The mandate proves whether that person may instruct the account, alone or jointly, and sometimes within specific limits.
Banks have done this for decades. FATF has required financial institutions since at least 2003 to verify both the identity of somebody acting for a customer and that person's authority to act.
Digital identity has made the first check much easier.
The second check still travels badly.
For business, proving identity only gets you halfway. You also need proof of authority.
A counterparty may know that James Smith works for Company X. It still needs to know whether James can bind Company X to this payment.
Today that answer often sits inside one bank, one ERP system, one corporate mandate or one set of documents.
GLEIF has started building part of the missing layer through the verifiable LEI framework. vLEI credentials can cryptographically connect a legal entity to named people in official or functional roles. Its current framework also supports chains of authorisation for issuing and revoking those role credentials.
On 1 September, GLEIF described the next problem directly: proving at machine speed which organisation stands behind an AI agent, who authorised it to act and the boundaries of that authority.
That matters well beyond AI.
A Gulf bank making a cross-border payment to an African company does not only need confidence in the identity of the people involved. It needs confidence that the person or machine giving the instruction may actually commit the company.
That proof needs to survive the move from one institution to another.
We have made personal identity increasingly portable. Business authority still gets rebuilt at every boundary.
Trust moves closer to the transaction
Most corporate banking still places a large amount of trust around the account.
The bank onboards the company, verifies beneficial owners, establishes signatories and sets permissions. Later payments rely heavily on that controlled relationship.
AI agents, tokenised assets and cross-border settlement put pressure on that model.
Over time, more of the evidence will need to travel with the transaction itself.
A payment will not just tell you where the money came from. It will increasingly carry proof of why it was allowed to move.
Who authorised it? On behalf of which legal entity? Under what role? Within what limit? Does this transaction fit?
That gives digital identity two very different design jobs.
For individuals, limit how much one failed credential can stop.
For businesses, make authority portable enough that another institution can verify who may act.
Refuse the transaction, not the person
Regulated systems still need to refuse things.
Anti-money laundering controls must reject some customers and payments. Sanctions controls must block transactions. Age verification exists so minors get turned away.
A system that always says yes offers no useful control.
The important question concerns scope.
A bar refusing a 15-year-old an alcohol purchase means the check worked. A bank stopping a sanctioned payment means the check worked.
Neither requires making the person impossible to verify everywhere else.
Refuse the transaction, service or relationship when the rules require it. Do not turn the identity itself into a universal no.
Nobody wants digital ID
McKinsey estimated that digital ID could unlock value equivalent to 3 to 13 percent of GDP by 2030 across seven focus countries. Those scenarios depend on high usage.
Most people do not wake up one day wanting a digital identity.
They want the bank account, the government service, the payment, the job or the thing behind the gate.
The industry talks about convenience, onboarding and inclusion. Its opponents talk about losing the ability to work, buy or participate.
Adoption follows utility. Compulsion can raise enrolment while destroying trust.
The bet
We should build better identity infrastructure.
But the next billion users should not depend on one perfect check.
People need a route back when the system gets them wrong.
Businesses need a portable way to prove who may act for them.
Both questions start after the identity check.
People aren't afraid you'll know who they are. They're afraid you'll turn them off - or whoever is in power in ten, twenty years decides to.
See you next week.
James Smith
