Leaders TalkX 5 - Building Resilience: Secure and Trusted Digital Public Infrastructure
This panel discussion brought together government officials and digital policy experts to explore how countries are building secure, trusted, and resilient digital public infrastructure (DPI) as a foundation for inclusive development.
Moderated by Cheryl Miller, several countries shared concrete progress in deploying DPI. Senegal outlined a three-part DPI strategy covering digital identity, data exchange to address institutional fragmentation, and a payment gateway, aiming to raise the digital economy's contribution to GDP from 7% to 15% by 2029 . Somalia described reaching key milestones, including its first National DPI Summit and the development of a national DPI roadmap integrating digital identity, payments, and secure data exchange, underpinned by a data protection law enacted in 2023 . The Philippines highlighted its 'digital bayanihan' whole-of-nation approach, with over 90 million citizens registered under its national identity system and an e-governance act supporting interoperable public services . India's experience demonstrated population-scale impact, with its Unified Payment Interface recording 23.2 billion transactions in a single month, representing 50% of global digital transactions, built on a three-layer system of identity (Aadhaar), payments (UPI), and data management .
On resilience and security, Poland emphasised the convergence of satellite and mobile technologies, drawing on its 2024 flood experience when terrestrial networks failed, and satellite communications provided emergency connectivity . Kenya stressed collaboration across policy, regulation, and security agencies, including a multi-agency cybercrime coordination committee and regional interoperability efforts through the East African Communications Organisation . Nigeria articulated that trust must be continuously maintained across identity, networks, and markets, rather than established once .
Broader principles were offered by the Commonwealth Telecommunications Organisation and Women in Gen AI. Bernadette Lewis noted that governments are uniquely positioned as custodians of citizens' data across their entire lives, and that effective DPI renews the social contract . Tatyana Kanzaveli proposed four non-negotiable design rules for AI-enabled DPI: no single point of failure, no single point of control, no invisible decisions, and no automated dead ends, arguing that DPI has become rights infrastructure .
The panel collectively concluded that resilient DPI cannot be built by government alone , requires strong multi-stakeholder partnerships , and must embed security, trust, and inclusivity by design from the outset , with the ultimate measure of success being citizens' ability to trust the system even when things go wrong .
Overall Purpose
- The discussion is a multi-nation panel to examine how countries are designing, implementing, and safeguarding Digital Public Infrastructure (DPI). The goal is to share practical experiences, lessons learned, and design principles that can help governments worldwide build DPI that is secure, trusted, resilient, and inclusive - particularly in the context of emerging technologies such as AI.
- --
Major Discussion Points
- DPI as a foundational national development priority, structured around three core layers - identity, payments, and data exchange. Multiple nations described their DPI frameworks as built upon these interconnected pillars. Senegal outlined its three-part DPI evolution covering digital identity, a data exchange platform to address institutional fragmentation, and a payment gateway aimed at growing its digital economy from 7% to 15% of GDP by 2029 . Somalia similarly described its National DPI Roadmap as integrating digital identity, digital payment, and secure data exchange into a citizen-centric ecosystem . India detailed its "three-layer system" of Aadhaar (identity), UPI (payments), and data management, which together enabled population-scale digitisation .
- Security and trust must be embedded by design from the outset, not added retrospectively. Several panellists emphasised that trust is a continuous obligation rather than a one-time achievement. Somalia stated explicitly that 'trust and security cannot be added at the end of the process - they must be enabled by design from the very beginning' . India described integrating security protocols directly into the source code of Aadhaar and UPI, applying zero-trust networks and encrypted single-use digital tokens to prevent large-scale tracking or data profiling . Nigeria framed trust as 'not a destination' but 'an ongoing journey that must be earned, protected, and constantly maintained,' built across three interconnected foundations: trust in identity, trust in networks, and trust in markets .
- Resilience of digital infrastructure requires redundancy, satellite-mobile convergence, and robust legal and regulatory frameworks. Poland highlighted the critical importance of satellite communications during the 2024 floods, when terrestrial base stations lost connectivity, and called for further convergence of satellite and mobile technologies through 6G standardisation . The Philippines outlined three pillars of resilient infrastructure: connectivity, trusted digital identity, and interoperable digital governance, and stressed that 'government must do the connecting, not the citizen' . Kenya emphasised its investment in a national fibre backbone reaching all 47 regions and border points, complemented by satellite communications, interoperable cross-border payment systems, and a multi-agency cybersecurity coordination committee .
- Inclusive design encompassing language access, biometric verification, and citizen-centric services as essential to ensuring DPI reaches all populations. India's experience demonstrated that AI-powered multilingual tools and biometric-based verification can extend DPI access to citizens who cannot read or write or possess traditional identification documents . The Philippines noted that over 90 million Filipinos are registered under its national ID system, while stressing that identity systems must 'empower citizens while safeguarding privacy, protecting rights, and ensuring accountability' . The Commonwealth Telecommunications Organisation's representative noted that citizens must also possess the skills and literacy to benefit from DPI, and that systems for timely recourse must be in place when things go wrong .
- AI-enabled DPI must be governed by clear design principles: no single point of failure, no single point of control, no invisible decisions, and no automated dead ends. Tatyana Kanzaveli argued that DPI has become 'rights infrastructure' and proposed four non-negotiable design rules for AI-driven public systems . These include mandatory redundancy and offline alternatives , open standards and interoperability to prevent vendor lock-in , full traceability and independent oversight of consequential decisions , and guaranteed human appeal mechanisms built into services themselves . She concluded that 'the strongest digital public infrastructure will not be the system with the most AI, it will be the system where people can still trust when something goes wrong' .
- --
Overall Tone
- The overall tone of the discussion is constructive, collaborative, and optimistic, with a strong undercurrent of urgency. Panellists spoke about their respective DPI achievements with pride, yet consistently acknowledged the challenges that remain, particularly around trust, inclusion, and cybersecurity. The tone was largely consistent throughout, though it became notably more cautionary and principled towards the end, particularly during the contributions from Nigeria and Tatyana Kanzaveli, who introduced sharper warnings about the risks of poorly governed AI-enabled infrastructure . The moderator, Cheryl Miller, maintained an energetic and encouraging tone throughout, helping to sustain momentum across a lengthy panel .
Expanded Summary: Building Resilience, Secure and Trusted Digital Public Infrastructure
#
Panel Overview and Context
This panel discussion, moderated by Cheryl Miller, was convened at the WSIS Forum and brought together senior government officials, regulators, and digital policy experts from across the globe to examine how countries are designing, implementing, and safeguarding Digital Public Infrastructure (DPI). The discussion spanned contributions from Senegal, Somalia, the Philippines, Poland, India, Kenya, and Nigeria, alongside perspectives from the Commonwealth Telecommunications Organisation (CTO) and Women in Gen AI. Speakers included Samba Diouf (Senegal), Mohamed Adan Moalim Ali (Somalia), Sarah Maria Q. Sison (the Philippines), Rafał Rosiński (Poland), Anil Kumar Lahoti (India), David Mugonyi (Kenya), Aminu Maida (Nigeria), Bernadette Lewis (CTO), and Tatyana Kanzaveli (Women in Gen AI). The overarching aim was to share practical national experiences, lessons learned, and design principles that can help governments worldwide build DPI that is secure, trusted, resilient, and inclusive - particularly in the context of rapidly emerging technologies such as artificial intelligence .
The panel's tone was constructive, collaborative, and optimistic throughout, with a strong undercurrent of urgency. Speakers expressed evident national pride in their respective DPI achievements whilst consistently acknowledging the challenges that remain, particularly around trust, inclusion, and cybersecurity. The tone became notably more cautionary and principled towards the close of the session, particularly during contributions from Nigeria and Women in Gen AI, which introduced sharper warnings about the risks of poorly governed AI-enabled infrastructure .
---
#
DPI as a National Development Priority: The Three-Pillar Framework
A striking point of convergence across the panel was the consistent framing of DPI not as a technical project but as a foundational national development priority. Mohamed Adan Moalim Ali of Somalia articulated this most directly, stating that "for Somalia, digital public infrastructure is not simply a technology initiative - it's a national development priority fully aligned with our national development plan" . This framing was echoed across multiple speakers and set the normative tone for the discussion.
Across the national presentations, a remarkably consistent structural pattern emerged: virtually every country described its DPI strategy as built upon three interconnected pillars of digital identity, data exchange or payments, and interoperable governance. Samba Diouf of Senegal outlined his country's three-part DPI evolution, covering digital identity, a data exchange platform designed to resolve institutional and platform fragmentation , and a payment gateway intended to mobilise actors and develop the digital economy . Senegal's ambition is to raise the digital economy's contribution to GDP from its current level of 7% to 15% by 2029, as part of the country's "new deal technology" programme . Notably, Diouf acknowledged that whilst Senegal has identified the responsible entity for its digital identity project, a full strategy is still being developed and is currently included in the business plan, with realisation anticipated in the near term .
Somalia's National DPI Roadmap similarly integrates digital identity, digital payment, and secure data exchange into a citizen-centric ecosystem, developed following the country's first National Digital Public Infrastructure Summit, which brought together government, private sector, development partners, academia, and civil society . The Philippines described three fundamental pillars of resilient digital infrastructure: connectivity, trusted digital identity, and interoperable digital governance . Sarah Maria Q. Sison noted that more than 90 million Filipinos are now registered under the national identity system , and that the country's e-governance act and unified digital gateway are building integrated public services . Sison also outlined four characteristics of digital infrastructure - public in purpose, secure by design, inclusive in reach, and a fourth characteristic that was not completed in the available record - as part of her framing of the Philippines' approach .
India presented the most mature and operationally scaled example, with Anil Kumar Lahoti describing a "unique three-layer system" of Aadhaar for identity, UPI for payments, and data management , which together enabled what he characterised as the "secure democratisation of online resources" . Cheryl Miller noted that India's Unified Payment Interface recorded 23.2 billion transactions in May 2026, accounting for approximately 50% of the world's total digital transactions for that month . Lahoti attributed India's success to three distinguishing characteristics: "scale, openness, and integration" , describing how each layer of the three-layer system solved a specific friction: "identity verified trust, payments enabled instant value exchange, data made consent and standardisation real" .
India is now combining its DPI with artificial intelligence. In public health management, the convergence of DPI and AI is driving a shift "from reactive treatments towards population-scale preventive care" . The current ecosystem holds 932 million health IDs, over one billion digital health records, half a million healthcare facilities, and approximately one million groups of doctors, nurses, and pharmacists combined . India is also democratising AI by making available compute, tested datasets, open AI models, and tools to the public at affordable prices, alongside an extensive skilling programme focused on enabling and empowering youth and their startups .
Kenya's David Mugonyi described a decade-long deliberate investment in a digital fibre backbone reaching all 47 regions and principal border points , complemented by interoperable payment and customs systems with regional neighbours . This convergence on similar structural components across countries at very different stages of development suggests an emerging global consensus on the building blocks of effective DPI.
---
#
Security and Trust by Design: A Non-Negotiable Principle
A second major area of consensus was the insistence that security and trust must be embedded into DPI from the outset, rather than added retrospectively. Mohamed Adan Moalim Ali stated explicitly that "trust and security cannot be added at the end of the process - they must be enabled by design from the very beginning" . Somalia has sought to operationalise this principle through legal and institutional foundations, including the enactment of a data protection law and the establishment of a data protection authority in 2023 , alongside advancing cybersecurity, cybercrime, and electronic transaction legislation .
India provided the most technically detailed account of security-by-design. Anil Kumar Lahoti described how "security protocols were integrated directly into the source code of Aadhaar and UPI, applying zero-trust networks and the use of data-based cloud architecture" . Crucially, the processing and ownership of data were separated, enabling secure transfer of information between financial institutions using "encrypted single-use digital tokens without storing or viewing the personal data itself" . This architectural choice prevents targeting of the central database and large-scale tracking or user profiling . By anchoring the India Stack to open APIs, the government permits private fintech companies to build applications on top of the public rail, achieving what Lahoti described as "modularity, scalability, and resilience" .
Nigeria's Aminu Maida introduced a distinctive and dynamic conception of trust, arguing that it "is not established once - it must be continuously maintained" . He described Nigeria's approach as building trust on three interconnected foundations: trust in identity, through mandatory linkage of SIM cards with the National Identification Number and a telecommunications identity risk management system to track lifecycle events such as number recycling and fraudulent use ; trust in networks, through a cyber resilience framework for the communications sector, operationalisation of the President's 2024 Executive Order on Critical National Information Infrastructure, and transparency through nationwide quality of service monitoring, drive tests, and public coverage maps ; and trust in markets, through transparent, predictable, and consistently enforced regulation . Maida concluded that "trust is not a destination - it's an ongoing journey that must be earned, protected, and constantly maintained" .
---
#
Resilience Through Redundancy: Satellite, Connectivity, and Regulatory Frameworks
The question of physical and technical resilience - particularly in the face of natural disasters and geographic challenges - generated some of the panel's most concrete and practically grounded contributions. Poland's Rafał Rosiński drew directly on his country's experience during the 2024 floods, when "terrestrial base stations lost connectivity" and Poland "relied on satellite communications to provide emergency connectivity" . He argued that "the further convergence of satellite and mobile technologies is essential to ensure sufficient level of resilience of public digital infrastructure worldwide" , and welcomed ongoing work on 6G standardisation through ITU's IMT-2030 process, which will integrate mobile and satellite systems by default . Poland is actively working on mobile satellite services across different radio spectrum bands to establish an efficient and predictable regulatory framework . It is also worth noting that Poland had previously been recognised with a WSIS Prize for its work connecting schools, a distinction acknowledged by the moderator in her introduction to Rosiński's contribution .
The Philippines, as an archipelagic and disaster-prone country, approached resilience through its National Digital Connectivity Plan and National Fibre Backbone , with Sison articulating the principle that "digital services cannot empower citizens who remain disconnected" . Kenya similarly described its decade-long investment in fibre infrastructure reaching all 47 regions and border points, complemented by satellite communications that are "gaining a lot of popularity" . The shared recognition of satellite communications as a resilience tool across a European country recovering from floods, an African nation building cross-border connectivity, and an archipelagic Asian nation prone to natural disasters represents a notable area of practical convergence.
Beyond physical infrastructure, several speakers emphasised that legal and regulatory frameworks are equally foundational to resilience. Kenya's Mugonyi argued that "robust policy and regulatory frameworks are the foundation of digital transformation" , describing collaboration across policy, regulation, and security as the "one big idea" underpinning Kenya's approach . Kenya has established a multi-agency National Computer and Cyber Crimes Coordination Committee comprising the communications authority alongside security agencies, financial institutions, and judicial bodies , and is collaborating through the East African Communications Organisation towards full regional interoperability and a one-area network . Kenya has also passed the Virtual Asset Service Providers Act 2025 to provide regulatory clarity for digital assets and developed a National Artificial Intelligence Strategy 2025-2030 emphasising ethical and innovation-driven deployment . Mugonyi also extended a direct invitation to all attendees to join Kenya in December for the Internet Governance Forum .
---
#
Inclusion and Citizen-Centricity: Reaching All Populations
A consistent thread throughout the panel was the insistence that DPI must be designed to serve all citizens, regardless of literacy, language, location, or income. Sarah Maria Q. Sison articulated this most directly, stating that "access to public service should no longer depend on where you live, how much you earn, and whether you possess the resources to overcome institutional barriers" . She introduced the Philippine concept of "digital bayanihan" - derived from the root word for hero - as a tradition reflecting the power of collective action and a whole-of-nation approach requiring cooperation amongst government, industry, and civil society . Her principle that "government must do the connecting and not the citizen" placed the burden of accessibility and integration squarely on the state rather than on individual users.
India's experience offered the most detailed account of how DPI can be engineered for inclusion at population scale. The Aadhaar payment bridge system routes welfare funds directly to beneficiaries using a 12-digit identity number, automatically routing money to whichever bank account is linked to that identity . Biometric-based verification ensures inclusion of "citizens who cannot read, write or lack traditional identification documents" . To address language barriers, India integrated the AI-powered Bhashini translation platform into its DPI, enabling non-English-speaking citizens to access government welfare portals, banking services, and digital documents in 22 official Indian languages using voice commands . India has also developed the Open Network for Digital Commerce (ONDC), which democratises e-commerce by allowing any seller to begin trading at a flat transactional price of 0.1 cent per transaction .
Somalia's Mohamed Adan Moalim Ali articulated a vision of citizen-centricity that extended beyond service delivery to the transformation of the relationship between citizens and government: "whether registering a birth, starting a business, accessing social protection or paying government fees, citizens should experience services that are simple, seamless, secure and also centred on their needs" . The Philippines' Sison reinforced this by describing digital public infrastructure as "an essential public good, much like roads, power systems, and financial networks" , upon which modern societies function.
---
#
Government's Unique Role and the Social Contract
Bernadette Lewis of the Commonwealth Telecommunications Organisation offered what proved to be one of the panel's most philosophically resonant contributions, addressing the unique position of government in relation to DPI. She argued that "government is unique among institutions in that it is the only institution with which a citizen has to interact in every stage of life - from birth, registration of birth, health, education, taxation, registration, until they're finally registered as having left the world" . This makes governments the custodians of vast repositories of citizen information , with a fundamental obligation to use that information to deliver services, protect privacy, and maintain security .
Lewis acknowledged that governments cannot establish DPIs alone and must work in strategic partnerships with diverse players . She identified the characteristics that engender citizens' trust as including universally affordable access, security, interoperability of systems, and the confidence built through these features . Critically, she emphasised that citizens must possess the skills and literacy to benefit from DPI , and that "when things go wrong, there must be systems of acceptable and timely recourse so that the citizen isn't left high and dry" , noting that the absence of such systems erodes confidence . She concluded that "an effective DPI helps in the renewal and the renewing of that social contract" - a framing that elevated DPI from an infrastructure question to a matter of democratic legitimacy.
This point about the necessity of partnership was echoed by Mohamed Adan Moalim Ali, who stated that "resilient digital public infrastructure cannot be built by government alone" and requires "strong partnership between government, regulatory and also private sector" .
---
#
AI-Enabled DPI as Rights Infrastructure: Four Non-Negotiable Design Rules
The panel's most forward-looking and provocative contribution came from Tatyana Kanzaveli of Women in Gen AI, who reframed the entire discussion by arguing that "digital public infrastructure is no longer simply technology - it's rights infrastructure" . She grounded this claim in the observation that when AI-enabled public infrastructure fails, "citizens don't just experience a software bug - they may lose access to healthcare benefits, education, public services or even the ability to prove who they are" .
Kanzaveli proposed four non-negotiable design rules for AI-driven public infrastructure. First, no single point of failure: essential services require redundancy, graceful degradation, offline alternatives, and tested continuity plans, and "a platform that collapses when connectivity, data or vendor fails is not resilient" . Second, no single point of control: interoperability must be mandatory, requiring open standards, modular architecture, portable data, and well-governed APIs to "prevent permanent dependence on one supplier, one platform, or one model" . Third, no invisible decisions: every consequential action must be traceable through data provenance, system versioning, independent testing, and clear lines of accountability, and "oversight cannot end at the deployment time" because "models drift, data changes, threats adapt" . Fourth, no automated dead end: every person must be able to understand a decision, correct inaccurate information, reach a qualified human, and obtain timely review, with the point of contact built into the service itself rather than buried on a website .
Kanzaveli was explicit that "security, privacy, accessibility, multilingual inclusion, and data minimisation are not optional features - they are the foundation" , and that no automated system should make consequential decisions about a person unless that decision can be understood, challenged, and reversed . She concluded with a reframing of resilience itself: "the strongest digital public infrastructure will not be the system with the most AI - it will be the system where people can still trust when something goes wrong. Resilience is not the promise that failure never happened. It is the capacity to fail safely, reveal what happened, recover quickly, correct the harm, and preserve the rights and dignity of the person on the other side of the screen" . Her closing formulation - that AI-enabled DPI must be "secure by design, interoperable by architecture, auditable by default, and open to appeal - not as courtesy, but as a right" - provided one of the session's most memorable and principled conclusions .
---
#
Implicit Tensions and Unresolved Questions
Whilst the panel presented a broadly consensual surface, several meaningful tensions ran beneath the discussion. One notable area of contrast emerged between India's presentation of its automated welfare transfer system - which routes funds directly using a 12-digit identity number with biometric verification - and Kanzaveli's insistence that no automated system should make consequential decisions without the ability to challenge and reverse them . Kanzaveli argued that appeal and recourse mechanisms are non-negotiable design requirements , a principle that was not explicitly addressed in Lahoti's account of the India Stack. Whether this reflects a genuine design gap or simply a difference in emphasis between speakers is not clear from the transcript, but the juxtaposition highlights an important question about how efficiency-first automation and rights-protective human oversight can be reconciled in practice.
A related tension emerged around DPI architecture. Lahoti described India's model as a "Secure Core" with "multiple distributary arms" achieved through open APIs , framing centralisation at the foundation as the basis of success. Kanzaveli's framework, however, would treat any single point of control - even one with open APIs - as a structural risk . Similarly, speakers emphasised different aspects of resilience: Poland foregrounded technical infrastructure convergence , whilst Kenya, Nigeria, and Somalia emphasised legal and regulatory frameworks . These differences in emphasis have important implications for how global DPI norms and standards might be developed.
A further area of complementary but distinct framing concerned the fundamental nature of DPI itself. Senegal framed it primarily in economic terms - raising GDP contribution - whilst Kanzaveli characterised it as rights infrastructure , Lewis framed it as a mechanism for renewing the social contract , and Moalim Ali positioned it as a tool to transform the relationship between citizens and government . These different framings carry significant implications for how DPI should be designed, governed, and evaluated, and whilst they are not necessarily contradictory, they were not openly reconciled during the session.
---
#
Collective Conclusions and the Path Forward
The panel collectively reinforced several overarching conclusions. DPI is increasingly recognised as the backbone of modern societies , with countries at various stages of developing national strategies centred on the three core pillars of identity, payments, and data exchange. Trust and security must be embedded by design from the outset , maintained continuously across the system lifecycle , and governed by legal frameworks, technical architecture, and human oversight mechanisms working in concert. Resilience requires redundancy, satellite-mobile convergence, robust regulatory frameworks, and multi-stakeholder collaboration . Inclusion demands that DPI reach citizens regardless of literacy, language, location, or income . And as AI becomes increasingly integrated into public infrastructure, the governance stakes are elevated to the level of fundamental rights .
Bernadette Lewis's observation that effective DPI "helps in the renewal and the renewing of that social contract" , and Kanzaveli's insistence that AI-enabled DPI must be "secure by design, interoperable by architecture, auditable by default, and open to appeal - not as courtesy, but as a right" , together with her framing of resilience as "the capacity to fail safely, reveal what happened, recover quickly, correct the harm, and preserve the rights and dignity of the person on the other side of the screen" , provided a fitting conceptual capstone for the discussion. The panel's most significant collective contribution was the convergence - across very different national contexts, institutional roles, and levels of digital development - on the idea that trust in DPI is not a technical feature to be added, but a continuous, multi-dimensional commitment to be earned, maintained, and institutionally protected .
Senegal's three-pillar DPI evolution covering digital identity, data exchange, and payment gateway, with a goal to raise digital economy's GDP contribution from 7% to 15% by 2029
Arg. 1Samba Diouf outlined Senegal's DPI strategy as comprising three interconnected pillars: a digital identity project, a data exchange platform to resolve institutional fragmentation, and a payment gateway to drive the digital economy. This roadmap was established under the new deal technology authority and is part of a broader national digital transformation agenda. The ambition is to significantly grow the digital economy's share of GDP over the coming years.
Diouf explained that Senegal's DPI evolution is divided into three parts: digital identity, data exchange, and a payment gateway . He noted that the digital economy currently contributes 7% to Senegal's GDP and that the strategy aims to push this figure to 15% by 2029 .
on: DPI is a national development priority and foundational public good, not merely a technical project
Senegal's data exchange platform is designed to resolve institutional and platform fragmentation, enabling all public platforms to communicate and share data securely and efficiently
Arg. 2Diouf highlighted that Senegal currently suffers from fragmentation across institutions, platforms, and public infrastructure, which hampers efficient service delivery. The data exchange platform is intended to bridge these silos, allowing all platforms to interact and share data in a secure and efficient manner. This is positioned as a critical enabler of a trusted and functional digital ecosystem.
Diouf described the current situation as one of fragmentation across institutions, platforms, and public infrastructure , and explained that the data exchange platform will enable all those platforms to see each other and exchange data securely and efficiently .
on: Interoperability is an essential design requirement for effective DPI, enabling seamless service delivery and cross-border integration
Somalia's National DPI Roadmap providing a phased strategy integrating digital identity, digital payments, and secure data exchange, developed following the country's first National Digital Public Infrastructure Summit
Arg. 1Mohamed Adan Moalim Ali described how Somalia developed a National DPI Roadmap following its first National Digital Public Infrastructure Summit, which brought together government, private sector, development partners, academia, and civil society. The roadmap sets out a phased strategy for integrating digital identity, digital payments, and secure data exchange into a resilient, interoperable, and citizen-centric ecosystem. This positions DPI as a national development priority aligned with Somalia's national development plan.
He noted that Somalia convened its first National Digital Public Infrastructure Summit to establish a shared national vision , and subsequently developed a National DPI Roadmap setting out a phased strategy for integrating digital identity, digital payment, secure data exchange, and trust services . He also emphasised that DPI is fully aligned with Somalia's national development plan .
on: Interoperability is an essential design requirement for effective DPI, enabling seamless service delivery and cross-border integration
Trust and security must be enabled by design from the very beginning, not added at the end of the process, as Somalia embeds legal and institutional foundations including data protection law and cybersecurity legislation
Arg. 2Mohamed Adan Moalim Ali stressed that trust and security are not afterthoughts but must be built into DPI from the outset. Somalia has taken concrete steps to embed these principles institutionally, including enacting a data protection law and establishing a data protection authority. The country is also advancing cybersecurity, cybercrime, and electronic transaction legislation to underpin digital trust.
He stated explicitly that trust and security must be enabled by design from the very beginning . He cited the enactment of Somalia's data protection law and the establishment of a data protection authority in 2023 , and noted that Somalia is advancing cybersecurity, cybercrime, and electronic transaction legislation .
on: Legal and regulatory frameworks are foundational to digital trust and must underpin DPI implementation
on: The primary driver of DPI resilience: technical infrastructure convergence versus legal and regulatory frameworks
Somalia's vision is to transform the relationship between citizens and government so that registering a birth, starting a business, or accessing social protection is simple, seamless, secure, and citizen-centred
Arg. 3Mohamed Adan Moalim Ali articulated a vision in which DPI fundamentally changes how citizens interact with government, making everyday transactions simple, seamless, and secure. Rather than merely digitalising existing services, the goal is to place citizens at the centre of service design. This citizen-centric approach is framed as a transformation of the social relationship between the state and its people.
He stated that Somalia's ambition is not merely to digitalise government services but to transform the relationship between citizens and the government , giving examples such as registering a birth, starting a business, accessing social protection, or paying government fees as services that should be simple, seamless, secure, and centred on citizens' needs .
on: Citizen-centricity must be at the heart of DPI design, ensuring services are simple, seamless, and accessible to all
Resilient DPI cannot be built by government alone; it requires strong partnerships between government, regulatory bodies, the private sector, civil society, and development partners
Arg. 4Mohamed Adan Moalim Ali emphasised that no single actor can build resilient DPI in isolation, and that meaningful collaboration across sectors is essential. This lesson was reinforced through Somalia's own experience of convening diverse stakeholders at its National DPI Summit. He framed this multi-stakeholder approach as a prerequisite for sustainable and inclusive digital infrastructure.
He stated that resilient digital public infrastructure cannot be built by government alone and requires strong partnership between government, regulatory bodies, and the private sector . He also noted that Somalia's first National DPI Summit brought together government institutions, private sector, development partners, academia, and civil society .
on: Resilient DPI cannot be built by government alone and requires strong multi-stakeholder partnerships
Philippines' three-pillar approach to resilient digital infrastructure: connectivity, trusted digital identity, and interoperable digital governance, underpinned by the principle that government must do the connecting, not the citizen
Arg. 1Sarah Maria Q. Sison outlined the Philippines' framework for resilient digital infrastructure as resting on three pillars: connectivity, trusted digital identity, and interoperable digital governance. She emphasised that the burden of navigating digital systems should fall on government, not on citizens. This whole-of-nation approach, called 'digital bayanihan', requires cooperation across government, industry, and civil society.
She described the three pillars as connectivity (supported by the National Digital Connectivity Plan and National Fiber Backbone) , trusted digital identity (with over 90 million Filipinos registered under the national IT system) , and interoperable digital governance (through the e-governance act and unified digital gateway) . She articulated the principle that government must do the connecting, not the citizen .
on: Resilient DPI cannot be built by government alone and requires strong multi-stakeholder partnerships
Access to public services should no longer depend on where one lives or how much one earns; digital public infrastructure is an essential public good, like roads and power systems, requiring a whole-of-nation approach
Arg. 2Sison argued that digital public infrastructure has moved beyond being a convenience and is now an essential public good comparable to roads, power systems, and financial networks. She stressed that access to public services must be universal and not contingent on geography or economic status. The Philippines' 'digital bayanihan' principle reflects this commitment to collective action and inclusion.
She stated that access to public services should no longer depend on where one lives, how much one earns, or whether one possesses the resources to overcome institutional barriers , and that digital public platforms now form part of the foundation upon which modern societies function, much like roads, power systems, and financial networks . She introduced the concept of 'digital bayanihan' as a whole-of-nation approach requiring cooperation amongst government, industry, and civil society .
on: Citizen-centricity must be at the heart of DPI design, ensuring services are simple, seamless, and accessible to all
The Philippines' e-governance act and unified digital gateway are building integrated public services, with the principle that digital infrastructure must be public in purpose, secure by design, inclusive in reach, and interoperable
Arg. 3Sison described how the Philippines is constructing integrated public services through its e-governance act and a unified digital gateway, ensuring that government services are accessible through a single, coherent platform. She articulated four guiding principles for digital infrastructure: public in purpose, secure by design, inclusive in reach, and interoperable. These principles are intended to ensure that the infrastructure serves all citizens while respecting sovereignty and human rights.
She noted that through the enactment of the e-governance act and the expansion of the e-government platform, the Philippines is building integrated public services through a unified digital gateway . She stated that digital infrastructure must be first public in purpose, second secure by design, third inclusive in reach, and fourth interoperable .
on: Interoperability is an essential design requirement for effective DPI, enabling seamless service delivery and cross-border integration
Poland's experience during the 2024 floods demonstrated the critical importance of satellite communications as a resilience backup when terrestrial base stations lost connectivity, highlighting the need for convergence of satellite and mobile technologies
Arg. 1Rafał Rosiński argued that the convergence of satellite and mobile technologies is essential to ensure sufficient resilience in public digital infrastructure. Poland's experience during the 2024 floods, when terrestrial base stations lost connectivity, demonstrated in practice the critical value of satellite communications as a backup. He noted that work on 6G standardisation, which will integrate mobile and satellite systems by default, is a welcome development in this regard.
He cited Poland's experience during the 2024 floods, when terrestrial base stations lost connectivity and the country relied on satellite communications to provide emergency connectivity . He also referenced the ongoing work on 6G standardisation through ITU's IMT 2030 and standard development organisations such as 3GPP, which will include the integration of mobile and satellite systems by default .
on: The primary driver of DPI resilience: technical infrastructure convergence versus legal and regulatory frameworks
India's three-layer DPI system (Aadhaar for identity, UPI for payments, and data management) engineered for scale, openness, and integration to advance inclusion and efficiency simultaneously
Arg. 1Anil Kumar Lahoti described India's DPI as a unique three-layer system comprising Aadhaar for digital identity, UPI for payments, and a data management layer, all engineered to work together at population scale. Each layer was designed to solve a specific friction: identity verified trust, payments enabled instant value exchange, and data made consent and standardisation real. This integrated approach has enabled the secure democratisation of online resources across the country.
He explained that India's DPI is built on a three-layer system of identity (Aadhaar), payments (UPI), and data management , with each layer solving a specific friction: identity verified trust, payments enabled instant value exchange, and data made consent and standardisation real . He noted that this led to the secure democratisation of online resources .
on: Whether DPI architecture should prioritise a secure centralised core with open APIs or mandatory decentralisation to prevent single points of control
India implemented security by design by integrating security protocols directly into the source code of Aadhaar and UPI, applying zero-trust networks and separating data processing from ownership to prevent large-scale tracking
Arg. 2Lahoti explained that India embedded security directly into the architecture of its DPI systems rather than treating it as an add-on. Security protocols were integrated into the source code of Aadhaar and UPI, and a zero-trust network approach was applied. Crucially, data processing and ownership were separated, using encrypted single-use digital tokens to enable secure information transfer without storing or exposing personal data.
He stated that security protocols were integrated directly into the source code of Aadhaar and UPI, applying zero-trust networks and data-based cloud architecture . He further explained that Aadhaar and UPI were designed to separate data processing from ownership, enabling secure transfer of information between financial institutions using encrypted single-use digital tokens without storing or viewing personal data, thereby preventing large-scale tracking or user profiling .
on: Legal and regulatory frameworks are foundational to digital trust and must underpin DPI implementation
India's Aadhaar payment bridge system routes welfare funds directly using a 12-digit identity number, with biometric verification ensuring inclusion of citizens who cannot read, write, or lack traditional identification documents
Arg. 3Lahoti highlighted how India uses the Aadhaar payment bridge system to transfer welfare funds directly to beneficiaries using only their 12-digit Aadhaar number, automatically routing money to the linked bank account. This approach eliminates duplicate or fake beneficiaries and reduces institutional leakages. Biometric-based verification further ensures that citizens who are illiterate or lack traditional identification documents are not excluded from welfare programmes.
He explained that the government transfers welfare funds using just the beneficiary's 12-digit Aadhaar number via the Aadhaar payment bridge system, which automatically routes money to the linked bank account . He noted that biometric-based verification ensures inclusion of citizens who cannot read, write, or lack traditional identification documents .
on: Citizen-centricity must be at the heart of DPI design, ensuring services are simple, seamless, and accessible to all
on: Whether automated decision-making in DPI welfare systems is an unqualified benefit or a rights risk requiring strict safeguards
India integrated the AI-powered Bhashini translation platform into its DPI, enabling non-English-speaking citizens to access government and banking services in 22 official languages via voice commands
Arg. 4Lahoti described how India addressed language barriers within its DPI by integrating the AI-powered Bhashini translation platform, which allows citizens to interact with government welfare portals, banking services, and digital documents in any of 22 official Indian languages using voice commands. This innovation has been operational since 2023 and is a key tool for ensuring linguistic inclusion within the digital ecosystem. It demonstrates how AI can be harnessed to make DPI more accessible to diverse populations.
He stated that India integrated the AI-powered Bhashini translation platform into its DPI to allow non-English-speaking beneficiaries to access government welfare portals, banking services, and digital documents in 22 official Indian languages using voice commands, operational since 2023 .
India is combining DPI with AI, including a public health ecosystem of 932 million health IDs and over one billion digital health records, shifting from reactive treatment to population-scale preventive care
Arg. 5Lahoti described India's convergence of DPI and AI in the public health domain as a forward leap towards population-scale preventive care. The existing health ecosystem is vast, encompassing hundreds of millions of health IDs, billions of digital health records, and extensive networks of healthcare facilities and professionals. This integration is intended to shift the health system from reactive treatment towards proactive, data-driven prevention.
He stated that the convergence of DPI and AI is driving India's public health system from reactive treatments towards population-scale preventive care . He cited the current ecosystem as holding 932 million health IDs, over 1 billion digital health records, half a million healthcare facilities, and about a million groups of doctors, nurses, and pharmacists combined .
India is democratising AI by making compute, tested datasets, open AI models, and tools available to the public at affordable prices, alongside extensive skilling programmes focused on youth and startups
Arg. 6Lahoti explained that India is extending its DPI philosophy to the domain of AI by making the building blocks of AI — compute, datasets, and open models — available to the public at affordable prices. This is complemented by extensive skilling programmes aimed at empowering youth and startups to participate in and benefit from the AI economy. The approach reflects India's broader commitment to democratising access to transformative technologies.
He stated that India's DPI experience is being extended to democratise the design, deployment, and use of AI, including making available compute, tested datasets, and open AI models and tools to the public at affordable prices, alongside an extensive skilling programme focused on enabling and empowering youth and their startups .
Government is the only institution with which a citizen must interact at every stage of life, making it the custodian of vast repositories of citizen information and therefore uniquely responsible for delivering services, protecting privacy, and maintaining security
Arg. 1Bernadette Lewis argued that government occupies a uniquely privileged and responsible position in relation to DPI because it is the sole institution that interacts with citizens from birth to death. This means governments accumulate vast repositories of citizen data, making them the primary custodians of that information. With this custodianship comes a fundamental obligation to use that data to deliver services while protecting privacy and security.
She stated that government is the only institution with which a citizen has to interact at every stage of life, from birth registration through health, education, and taxation until death . She noted that governments consequently hold huge repositories of citizens' information and are the custodians of that information, obliged to use it to deliver services, protect privacy, and keep citizens secure .
on: Resilient DPI cannot be built by government alone and requires strong multi-stakeholder partnerships
An effective DPI helps renew the social contract between citizens and the state, requiring universally affordable access, security, interoperability, digital literacy, and accessible systems of timely recourse when things go wrong
Arg. 2Lewis argued that effective DPI is not merely a technical system but a mechanism for renewing the social contract between citizens and the state. She identified several characteristics that engender citizens' trust: universally affordable access, security, interoperability, and seamless government services. She also stressed that citizens must have the skills to use these systems and that accessible, timely recourse mechanisms are essential when things go wrong.
She listed the characteristics that engender citizens' trust as universally affordable access, security, the ability to use the technology, and interoperability of systems for seamless government . She emphasised that citizens must have the skills and literacy to benefit from DPI , and that when things go wrong, there must be systems of acceptable and timely recourse so that citizens are not left without remedy . She concluded that an effective DPI helps in the renewal of the social contract .
on: Citizen-centricity must be at the heart of DPI design, ensuring services are simple, seamless, and accessible to all
Kenya's deliberate investment in a digital fibre backbone reaching all 47 regions and principal border points, combined with interoperable payment and customs systems with regional neighbours
Arg. 1David Mugonyi described Kenya's decade-long deliberate investment in a digital fibre backbone that now reaches all 47 regions of the country and principal border points. This infrastructure has been complemented by the deployment of satellite communications and the development of interoperable payment and customs systems with regional neighbours. Kenya positions itself as a digitally ambitious nation that has laid the foundation for cross-border digital services.
He stated that Kenya has deliberately invested in a digital fibre backbone reaching all 47 regions and principal border points over the past decade , and that international organisations have also deployed satellite communications . He noted that Kenya has an interoperable system with integrated payments and customs systems with its neighbours , and that Kenya was the first country to launch mobile money transfer .
Kenya has established an interoperable system with integrated payments and customs with regional neighbours, and collaborates through the East African Communications Organisation to work towards full interoperability and a one-area network
Arg. 2Mugonyi highlighted Kenya's progress in building cross-border digital integration, including interoperable payment and customs systems with neighbouring countries. Kenya collaborates through the East African Communications Organisation (EACO) to harmonise communication policy and regulation across the region, with the goal of achieving full interoperability and a one-area network. This regional approach is seen as essential for enabling seamless cross-border trade.
He stated that Kenya has an interoperable system with integrated payments and customs systems with its neighbours , and that Kenya collaborates at the regional level through the East African Communications Organisation, the governmental body responsible for harmonising communication policy and regulation across the region, working towards full interoperability and a one-area network .
on: Interoperability is an essential design requirement for effective DPI, enabling seamless service delivery and cross-border integration
Kenya's approach demonstrates that robust, collaborative, and inclusive policymaking is the foundation of digital transformation, extending regulatory rigour to emerging technologies such as AI and virtual assets
Arg. 3Mugonyi argued that Kenya's digital transformation has been built on a foundation of robust, collaborative, and inclusive policymaking, which he described as the country's defining approach. This regulatory rigour is being extended to emerging technologies, including AI and virtual assets, through dedicated strategies and legislation. He presented collaboration across policy, regulation, and security as the key idea underpinning Kenya's digital ambitions.
He stated that robust policy and regulatory frameworks are the foundation of digital transformation, and that robust policy is the product of collaborative, inclusive policymaking . He cited Kenya's National Artificial Intelligence Strategy 2025-2030, which emphasises ethical and innovation-driven deployment with a focus on infrastructure and data governance , and the Virtual Asset Service Providers Act 2025, passed by parliament to provide regulatory clarity for digital assets .
on: Legal and regulatory frameworks are foundational to digital trust and must underpin DPI implementation
on: The primary driver of DPI resilience: technical infrastructure convergence versus legal and regulatory frameworks
Nigeria builds trust on three interconnected foundations: trust in identity (SIM-NIN linkage), trust in networks (cyber resilience framework), and trust in markets (transparent regulation), recognising that trust must be continuously maintained, not established once
Arg. 1Aminu Maida presented Nigeria's approach to DPI trust as resting on three deeply interconnected foundations: trust in identity, trust in networks, and trust in markets. He argued that trust is not a one-time achievement but must be continuously earned and maintained throughout the lifecycle of digital systems. Each foundation is supported by concrete policy and regulatory measures, including mandatory SIM-NIN linkage, a cyber resilience framework, and transparent market regulation.
He stated that Nigeria intentionally builds trust on three interconnected foundations: trust in identity, trust in networks, and trust in markets . For trust in identity, he cited the mandatory linkage of SIM cards with the National Identification Number and the development of a telecommunications identity risk management system to track lifecycle events such as number recycling and fraudulent use . For trust in networks, he referenced the NCC's recently issued cyber resilience framework and work to operationalise the President's 2024 Executive Order on Critical National Information Infrastructure . He emphasised that trust must be continuously maintained, not just established at the point of initial onboarding , and concluded that trust is an ongoing journey .
on: Legal and regulatory frameworks are foundational to digital trust and must underpin DPI implementation
on: The primary driver of DPI resilience: technical infrastructure convergence versus legal and regulatory frameworks
AI-enabled DPI requires four non-negotiable design rules: no single point of failure, no single point of control, no invisible decisions, and no automated dead end, with security and privacy as foundational rather than optional features
Arg. 1Tatyana Kanzaveli proposed four non-negotiable design rules for AI-driven public infrastructure to ensure it is resilient, interoperable, auditable, and open to appeal. These rules address systemic vulnerabilities: the need for redundancy and offline alternatives, mandatory interoperability through open standards, full traceability of consequential decisions, and guaranteed human recourse for every person affected by automated decisions. She framed security, privacy, accessibility, and data minimisation as foundational requirements, not optional features.
She outlined four design rules: no single point of failure (requiring redundancy, graceful degradation, offline alternatives, and tested continuity plans) ; no single point of control (requiring mandatory interoperability, open standards, modular architecture, portable data, and well-governed APIs) ; no invisible decisions (requiring data provenance, system versioning, independent testing, and clear accountability, with ongoing oversight beyond deployment) ; and no automated dead end (requiring every person to be able to understand a decision, correct inaccurate information, reach a qualified human, and obtain timely review) . She stated that security, privacy, accessibility, multilingual inclusion, and data minimisation are not optional features but the foundation .
on: Interoperability is an essential design requirement for effective DPI, enabling seamless service delivery and cross-border integration
on: Whether DPI architecture should prioritise a secure centralised core with open APIs or mandatory decentralisation to prevent single points of control
When AI-enabled public infrastructure fails, citizens may lose access to healthcare, benefits, education, or the ability to prove their identity; DPI is therefore rights infrastructure, not merely technology infrastructure
Arg. 2Kanzaveli argued that AI-enabled DPI carries profound consequences for citizens' fundamental rights, going far beyond technical functionality. When such systems fail, the impact is not merely a software bug but can result in citizens losing access to healthcare, benefits, education, or the ability to prove who they are. This framing positions DPI as rights infrastructure, demanding a correspondingly high standard of design, accountability, and protection.
She stated that when AI-enabled public infrastructure fails, citizens do not just experience a software bug but may lose access to healthcare benefits, education, public services, or even the ability to prove who they are . She therefore characterised digital public infrastructure as rights infrastructure, not simply technology .
on: Citizen-centricity must be at the heart of DPI design, ensuring services are simple, seamless, and accessible to all
Every consequential AI-driven decision must be traceable through data provenance, system versioning, and independent testing, with ongoing oversight beyond deployment as models drift and threats adapt
Arg. 3Kanzaveli emphasised that accountability in AI-driven DPI cannot end at the point of deployment; it must be an ongoing process. Every consequential decision made by an automated system must be traceable through data provenance, system versioning, and independent testing, with clear lines of accountability. She highlighted that models drift, data changes, and threats adapt over time, making continuous oversight an essential design requirement.
She stated that every consequential action must be traceable, requiring governments to have data provenance, system versioning, independent testing, and clear lines of accountability . She noted that oversight cannot end at deployment time because models drift, data changes, and threats adapt .
DPI is a key enabler of long-term digital transformation, and countries must embed resilience, inclusion, and citizen-centricity into their digital public infrastructure strategies from the outset
Arg. 1Cheryl Miller framed the panel discussion by highlighting that digital public infrastructure is central to building resilient, inclusive, and citizen-centred digital states. She consistently directed questions towards how countries are embedding these principles into their DPI strategies, signalling that these are the defining characteristics of successful digital transformation. Her framing positioned DPI not merely as a technical project but as a foundational national priority.
She introduced Senegal's DPI journey by asking how digital public infrastructures fit into the long-term vision for building a resilient, inclusive, and citizen-centred digital state . She similarly asked Somalia how it is ensuring that security, trust, and resilience are embedded from the outset in the design and implementation of digital public infrastructure .
The Philippines, as an archipelagic and disaster-prone country, faces unique challenges in ensuring digital public infrastructure remains available and resilient for remote and vulnerable communities
Arg. 2Cheryl Miller drew attention to the particular geographic and environmental vulnerabilities of the Philippines, noting that its archipelagic nature and susceptibility to natural disasters create specific challenges for maintaining resilient digital infrastructure. She used the example of a recent earthquake in Mindanao to contextualise the question of how DPI can serve remote and vulnerable populations even in crisis conditions. This framing highlighted the intersection of disaster resilience and digital inclusion.
She noted that there had been an earthquake in the southern Philippines in General Santos, Mindanao , and asked how the Philippines is ensuring that digital public infrastructure remains available and resilient, particularly for remote and vulnerable communities .
The convergence of satellite and mobile technologies is an increasingly important issue for ensuring the resilience of digital public infrastructure worldwide
Arg. 3Cheryl Miller identified the convergence of satellite and mobile technologies as a pressing contemporary issue for digital infrastructure resilience, framing it as a topic of growing relevance in current discussions. She invited Poland to elaborate on this convergence in the context of its own experiences and actions to ensure DPI resilience. This framing positioned satellite-mobile integration as a frontier issue for the global digital infrastructure agenda.
She asked Poland's representative to elaborate on the convergence of satellite and mobile technologies, noting that these issues are being discussed a lot more in the present day .
India's experience with population-scale DPI, including the Unified Payment Interface reaching 23.2 billion transactions and accounting for 50% of the world's total digital transactions in a single month, offers important lessons for the global community on building resilient, secure, and inclusive digital systems in the age of AI
Arg. 4Cheryl Miller highlighted India's remarkable scale of digital transactions as evidence of the country's success in building population-scale DPI, framing this as a source of globally relevant lessons. She specifically noted that UPI accounted for half of the world's total digital transactions in May 2026, underscoring the extraordinary reach and impact of India's digital infrastructure. She positioned India's experience as a model for other countries seeking to build resilient, secure, trusted, and citizen-centric systems.
She stated that the Unified Payment Interface had reached 23.2 billion transactions in May 2026 , and that this accounted for 50% of the world's total digital transactions for that month . She then asked what lessons India's experience with population-scale DPI can offer to the global community in creating resilient, secure, trusted, and citizen-centric digital systems for inclusive development in the age of AI .
Kenya's digital public infrastructure, including its cross-border capabilities, is of particular importance to business, and ensuring its security and regional availability is essential for enabling seamless cross-border trade
Arg. 5Cheryl Miller framed Kenya's DPI in terms of its significance for the business community, emphasising that cross-border trade is a key concern for the private sector. She acknowledged Kenya's powerful digital infrastructure and directed the question towards how security and regional availability are being ensured to support seamless cross-border commerce. This framing highlighted the economic and commercial dimensions of DPI beyond domestic service delivery.
She acknowledged that Kenya has built a powerful digital public infrastructure and asked how the country is ensuring the infrastructure is secure and available regionally to enable seamless cross-border trade, describing this as something extremely important to business .
As countries build AI-enabled digital public infrastructure, governments must adopt concrete design principles to ensure DPI is secure, interoperable, auditable, and open to appeal by the citizens it serves
Arg. 6Cheryl Miller posed a forward-looking question about the design principles that should govern AI-enabled DPI, covering identity, health, benefits, and education systems. She emphasised that these principles must address security, interoperability, auditability, and the right of citizens to appeal decisions made about them. This framing positioned the governance of AI-enabled DPI as a critical and urgent challenge requiring concrete, actionable responses.
She asked what concrete design principles governments should adopt as they build out AI-enabled digital public infrastructure for identity, health, benefits, and education, so that DPI is secure, interoperable, auditable, and open to appeal by those it serves .
The panel demonstrates that countries are moving from talk to action on DPI, with concrete implementations already underway across multiple nations
Arg. 7Cheryl Miller observed that throughout the conference there had been much discussion about translating talk into action, and that the panellists were demonstrating precisely this through their concrete national DPI implementations. She used this observation to affirm the value of the panel's contributions and to signal that the global DPI agenda is advancing beyond rhetoric. This framing positioned the panel as evidence of real-world progress on digital transformation.
She noted that throughout the conference there had been a lot of discussion about putting talk into action, and that everything she was hearing from the panellists showed they were doing a lot on the action part .
Session Knowledge Graph
Speakers · Topics · Arguments · Relationships
Mohamed Adan Moalim Ali explicitly stated that trust and security must be enabled by design from the very beginning . Anil Kumar Lahoti confirmed that India integrated security protocols directly into the source code of Aadhaar and UPI, applying zero-trust networks . Tatyana Kanzaveli proposed that security, privacy, accessibility, multilingual inclusion, and data minimisation are not optional features but the foundation . Aminu Maida argued that trust must be continuously maintained throughout the lifecycle of digital systems, not just at the point of initial onboarding . Sarah Maria Q. Sison articulated that digital infrastructure must be secure by design as one of its four core principles .
Trust and security must be enabled by design from the very beginning, not added at the end of the process, as Somalia embeds legal and institutional foundations including data protection law and cybersecurity legislation
India implemented security by design by integrating security protocols directly into the source code of Aadhaar and UPI, applying zero-trust networks and separating data processing from ownership to prevent large-scale tracking
AI-enabled DPI requires four non-negotiable design rules: no single point of failure, no single point of control, no invisible decisions, and no automated dead end, with security and privacy as foundational rather than optional features
Nigeria builds trust on three interconnected foundations: trust in identity (SIM-NIN linkage), trust in networks (cyber resilience framework), and trust in markets (transparent regulation), recognising that trust must be continuously maintained, not established once
The Philippines' e-governance act and unified digital gateway are building integrated public services, with the principle that digital infrastructure must be public in purpose, secure by design, inclusive in reach, and interoperable
Mohamed Adan Moalim Ali stated that resilient digital public infrastructure cannot be built by government alone and requires strong partnership between government, regulatory bodies, and the private sector , as demonstrated by Somalia's first National DPI Summit which brought together government, private sector, development partners, academia, and civil society . Bernadette Lewis acknowledged that governments cannot establish DPIs alone and must work in strategic partnerships with diverse players . David Mugonyi described collaboration across policy, regulation, and security as the key idea underpinning Kenya's digital ambitions . Sarah Maria Q. Sison introduced the concept of 'digital bayanihan' as a whole-of-nation approach requiring cooperation amongst government, industry, and civil society .
Resilient DPI cannot be built by government alone; it requires strong partnerships between government, regulatory bodies, the private sector, civil society, and development partners
Government is the only institution with which a citizen must interact at every stage of life, making it the custodian of vast repositories of citizen information and therefore uniquely responsible for delivering services, protecting privacy, and maintaining security
Kenya's approach demonstrates that robust, collaborative, and inclusive policymaking is the foundation of digital transformation, extending regulatory rigour to emerging technologies such as AI and virtual assets
Philippines' three-pillar approach to resilient digital infrastructure: connectivity, trusted digital identity, and interoperable digital governance, underpinned by the principle that government must do the connecting, not the citizen
Nigeria builds trust on three interconnected foundations: trust in identity (SIM-NIN linkage), trust in networks (cyber resilience framework), and trust in markets (transparent regulation), recognising that trust must be continuously maintained, not established once
Mohamed Adan Moalim Ali stated that for Somalia, digital public infrastructure is not simply a technology initiative but a national development priority fully aligned with the national development plan . Sarah Maria Q. Sison argued that digital public infrastructure is no longer a mere convenience but an essential public good, much like roads, power systems, and financial networks . Samba Diouf framed Senegal's DPI as part of a broader national digital transformation agenda with measurable economic targets . Bernadette Lewis concluded that an effective DPI helps in the renewal of the social contract . Tatyana Kanzaveli characterised DPI as rights infrastructure, not simply technology .
Somalia's National DPI Roadmap providing a phased strategy integrating digital identity, digital payments, and secure data exchange, developed following the country's first National Digital Public Infrastructure Summit
Access to public services should no longer depend on where one lives or how much one earns; digital public infrastructure is an essential public good, like roads and power systems, requiring a whole-of-nation approach
Senegal's three-pillar DPI evolution covering digital identity, data exchange, and payment gateway, with a goal to raise digital economy's GDP contribution from 7% to 15% by 2029
An effective DPI helps renew the social contract between citizens and the state, requiring universally affordable access, security, interoperability, digital literacy, and accessible systems of timely recourse when things go wrong
When AI-enabled public infrastructure fails, citizens may lose access to healthcare, benefits, education, or the ability to prove their identity; DPI is therefore rights infrastructure, not merely technology infrastructure
Samba Diouf described Senegal's data exchange platform as designed to resolve fragmentation across institutions and platforms, enabling all platforms to see each other and exchange data securely . Mohamed Adan Moalim Ali's roadmap explicitly includes secure data exchange and trust services into a resilience, interoperability, and citizen-centric digital ecosystem . Sarah Maria Q. Sison described interoperable digital governance as the third pillar of the Philippines' approach, building integrated public services through a unified digital gateway . David Mugonyi highlighted Kenya's interoperable system with integrated payments and customs systems with neighbours and collaboration through the East African Communications Organisation towards full interoperability . Tatyana Kanzaveli stated that interoperability must be mandatory, requiring open standards, modular architecture, portable data, and well-governed APIs . Bernadette Lewis listed interoperability of systems as a key characteristic engendering citizens' trust .
Senegal's data exchange platform is designed to resolve institutional and platform fragmentation, enabling all public platforms to communicate and share data securely and efficiently
Somalia's National DPI Roadmap providing a phased strategy integrating digital identity, digital payments, and secure data exchange, developed following the country's first National Digital Public Infrastructure Summit
The Philippines' e-governance act and unified digital gateway are building integrated public services, with the principle that digital infrastructure must be public in purpose, secure by design, inclusive in reach, and interoperable
Kenya has established an interoperable system with integrated payments and customs with regional neighbours, and collaborates through the East African Communications Organisation to work towards full interoperability and a one-area network
AI-enabled DPI requires four non-negotiable design rules: no single point of failure, no single point of control, no invisible decisions, and no automated dead end, with security and privacy as foundational rather than optional features
An effective DPI helps renew the social contract between citizens and the state, requiring universally affordable access, security, interoperability, digital literacy, and accessible systems of timely recourse when things go wrong
Mohamed Adan Moalim Ali cited Somalia's enactment of a data protection law and establishment of a data protection authority in 2023 , alongside advancing cybersecurity, cybercrime, and electronic transaction legislation . David Mugonyi stated that robust policy and regulatory frameworks are the foundation of digital transformation , citing Kenya's National AI Strategy 2025-2030 and the Virtual Asset Service Providers Act 2025 . Aminu Maida described Nigeria's cyber resilience framework and the operationalisation of the President's 2024 Executive Order on Critical National Information Infrastructure . Anil Kumar Lahoti described how India's security protocols were integrated directly into the source code of its DPI systems .
Trust and security must be enabled by design from the very beginning, not added at the end of the process, as Somalia embeds legal and institutional foundations including data protection law and cybersecurity legislation
Kenya's approach demonstrates that robust, collaborative, and inclusive policymaking is the foundation of digital transformation, extending regulatory rigour to emerging technologies such as AI and virtual assets
Nigeria builds trust on three interconnected foundations: trust in identity (SIM-NIN linkage), trust in networks (cyber resilience framework), and trust in markets (transparent regulation), recognising that trust must be continuously maintained, not established once
India implemented security by design by integrating security protocols directly into the source code of Aadhaar and UPI, applying zero-trust networks and separating data processing from ownership to prevent large-scale tracking
Mohamed Adan Moalim Ali articulated a vision where citizens experience services that are simple, seamless, secure, and centred on their needs, whether registering a birth, starting a business, or accessing social protection . Sarah Maria Q. Sison stated that access to public services should no longer depend on where one lives or how much one earns , and that government must do the connecting, not the citizen . Anil Kumar Lahoti described how biometric-based verification ensures inclusion of citizens who cannot read, write, or lack traditional identification documents . Bernadette Lewis emphasised that citizens must have the skills and literacy to benefit from DPI and that timely recourse must be available when things go wrong . Tatyana Kanzaveli stressed that every person must be able to understand a decision, correct inaccurate information, reach a qualified human, and obtain timely review .
Somalia's vision is to transform the relationship between citizens and government so that registering a birth, starting a business, or accessing social protection is simple, seamless, secure, and citizen-centred
Access to public services should no longer depend on where one lives or how much one earns; digital public infrastructure is an essential public good, like roads and power systems, requiring a whole-of-nation approach
India's Aadhaar payment bridge system routes welfare funds directly using a 12-digit identity number, with biometric verification ensuring inclusion of citizens who cannot read, write, or lack traditional identification documents
An effective DPI helps renew the social contract between citizens and the state, requiring universally affordable access, security, interoperability, digital literacy, and accessible systems of timely recourse when things go wrong
When AI-enabled public infrastructure fails, citizens may lose access to healthcare, benefits, education, or the ability to prove their identity; DPI is therefore rights infrastructure, not merely technology infrastructure
All five speakers described multi-pillar or multi-layer national DPI strategies that consistently incorporate digital identity, digital payments, and data exchange or interoperability as core components. Samba Diouf outlined Senegal's three-part DPI evolution covering identity, data exchange, and a payment gateway . Mohamed Adan Moalim Ali described Somalia's roadmap as integrating digital identity, digital payment, and secure data exchange . Sarah Maria Q. Sison described the Philippines' three pillars of connectivity, trusted digital identity, and interoperable digital governance . Anil Kumar Lahoti described India's three-layer system of identity (Aadhaar), payments (UPI), and data management . David Mugonyi described Kenya's fibre backbone, interoperable payment and customs systems, and satellite communications . This convergence on similar structural components suggests an emerging global consensus on the building blocks of effective DPI. All three speakers converged on the view that trust in DPI is not a static achievement but a continuous, ongoing process that must be actively maintained. Aminu Maida stated explicitly that trust is not established once but must be continuously maintained , and concluded that trust is an ongoing journey that must be earned, protected, and constantly maintained . Tatyana Kanzaveli emphasised that oversight cannot end at deployment time because models drift, data changes, and threats adapt , and that the strongest DPI will be the system where people can still trust when something goes wrong . Mohamed Adan Moalim Ali stressed that trust and security must be enabled by design from the very beginning and that Somalia is investing in governance, institutions, and capacity to ensure DPI is secure, resilient, and sustainable . All three speakers addressed the convergence of AI and DPI, recognising it as a critical frontier requiring careful governance. Anil Kumar Lahoti described India's combination of DPI with AI in public health, creating an ecosystem of 932 million health IDs and over one billion digital health records to shift towards population-scale preventive care , and noted that India is democratising AI by making compute, datasets, and open models available at affordable prices . Tatyana Kanzaveli argued that every consequential AI-driven decision must be traceable through data provenance, system versioning, and independent testing , with ongoing oversight beyond deployment . Cheryl Miller framed the governance of AI-enabled DPI as a critical challenge requiring concrete design principles covering security, interoperability, auditability, and the right of citizens to appeal . All three speakers addressed the physical and technical resilience of digital infrastructure, particularly in the context of geographic challenges and disaster scenarios. Sarah Maria Q. Sison, representing an archipelagic and disaster-prone country, described connectivity as the first pillar of resilient digital infrastructure, supported by a National Digital Connectivity Plan and National Fiber Backbone . Rafał Rosiński cited Poland's experience during the 2024 floods, when terrestrial base stations lost connectivity and the country relied on satellite communications for emergency connectivity , arguing for the convergence of satellite and mobile technologies . David Mugonyi described Kenya's decade-long investment in a digital fibre backbone reaching all 47 regions and principal border points, complemented by satellite communications . All four speakers shared the view that government occupies a unique and central role in DPI, but that this role must be exercised in partnership with other stakeholders. Bernadette Lewis argued that government is the only institution interacting with citizens at every stage of life , making it the custodian of citizens' information with a fundamental obligation to deliver services, protect privacy, and maintain security , while acknowledging that governments cannot establish DPIs alone . Mohamed Adan Moalim Ali reinforced that resilient DPI cannot be built by government alone and requires strong partnership . David Mugonyi stated that robust policy is the product of collaborative, inclusive policymaking . Sarah Maria Q. Sison described the Philippines' whole-of-nation approach requiring cooperation amongst government, industry, and civil society . All three speakers highlighted the role of DPI in driving economic inclusion and growth, particularly through digital payments and identity systems. Anil Kumar Lahoti described how India's Aadhaar payment bridge system eliminates duplicate or fake beneficiaries and routes welfare funds directly to citizens , with biometric verification ensuring inclusion of those who cannot read, write, or lack traditional identification . Samba Diouf described Senegal's payment gateway as a means to mobilise actors and develop the digital economy, with a target to raise the digital economy's contribution to GDP from 7% to 15% by 2029 . Mohamed Adan Moalim Ali articulated a vision where citizens can start a business, access social protection, or pay government fees through simple, seamless, secure services .
It is somewhat unexpected that government officials from developing nations and a civil society/technology representative converged so strongly on framing DPI in rights-based terms. Tatyana Kanzaveli explicitly characterised DPI as rights infrastructure , arguing that when AI-enabled systems fail, citizens may lose access to healthcare, benefits, education, or the ability to prove who they are . This framing was echoed by Mohamed Adan Moalim Ali, who described Somalia's ambition as transforming the relationship between citizens and government , and by Bernadette Lewis, who argued that effective DPI helps renew the social contract . Sarah Maria Q. Sison stated that access to public services should no longer depend on where one lives or how much one earns . The convergence between a technology-focused civil society voice and government officials from Somalia, the Philippines, and the Commonwealth on a rights-based framing of DPI represents a notable and somewhat unexpected area of consensus across very different institutional perspectives.
It is notable that speakers from very different backgrounds - a civil society technology advocate, the Secretary General of the Commonwealth Telecommunications Organisation, and the head of Nigeria's communications regulator - all converged on the importance of accessible recourse mechanisms for citizens when DPI systems fail or produce adverse outcomes. Tatyana Kanzaveli proposed as a non-negotiable design rule that every person must be able to understand a decision, correct inaccurate information, reach a qualified human, and obtain timely review, stating that a point of contact cannot be a phone number buried on a website but must be built into the service itself . Bernadette Lewis emphasised that when things go wrong, there must be systems of acceptable and timely recourse so that citizens are not left high and dry, noting that the absence of such systems erodes confidence . Aminu Maida stressed that trust requires transparency and accountability , and that trust must be continuously maintained as an ongoing journey . This convergence on the necessity of human recourse mechanisms across technical, institutional, and regulatory perspectives was unexpected.
It is somewhat unexpected that Poland, Kenya, and the Philippines - representing very different geographic, economic, and developmental contexts - all converged on the importance of satellite communications as a component of resilient digital infrastructure. Rafał Rosiński argued from Poland's experience during the 2024 floods that satellite communications are a critical backup when terrestrial infrastructure fails , and welcomed 6G standardisation integrating mobile and satellite systems by default . David Mugonyi noted that international organisations have deployed satellite communications in Kenya, which is gaining a lot of popularity . Sarah Maria Q. Sison, representing an archipelagic and disaster-prone country, described connectivity - including satellite options - as the first pillar of resilient digital infrastructure . The shared recognition of satellite communications as a resilience tool across a European country recovering from floods, an African nation building cross-border connectivity, and an archipelagic Asian nation prone to natural disasters represents an unexpected area of practical consensus.
It is notable that a government official from India, a civil society technology advocate, and a regulator from Kenya all converged on the importance of open standards and open architectures as essential to DPI resilience and preventing vendor lock-in. Anil Kumar Lahoti described how India anchors the India Stack to open APIs, permitting private fintech companies to build apps on top of the public rail, achieving modularity, scalability, and resilience , and noted that India is making available open AI models and tools to the public at affordable prices . Tatyana Kanzaveli proposed as a non-negotiable design rule that interoperability must be mandatory, requiring open standards, modular architecture, portable data, and well-governed APIs to prevent permanent dependence on one supplier, one platform, or one model . David Mugonyi described Kenya's National AI Strategy as emphasising ethical and innovation-driven deployment with a focus on infrastructure and data governance . This convergence on openness as a design principle across government, civil society, and regulatory perspectives was somewhat unexpected.
The panel demonstrated a remarkably high level of consensus across speakers from diverse national contexts — including developing nations in Africa (Senegal, Somalia, Nigeria, Kenya), an emerging economy (India), a Southeast Asian archipelago (Philippines), a European nation (Poland), and civil society/international organisations (Women in Gen AI, Commonwealth Telecommunications Organisation). Key areas of agreement included: security and trust must be embedded by design from the outset; DPI requires multi-stakeholder partnerships; DPI is a national development priority and foundational public good; interoperability is essential; legal and regulatory frameworks underpin digital trust; and citizen-centricity must be at the heart of DPI design. There was also notable convergence on the importance of human recourse mechanisms, the rights-based framing of DPI, the role of satellite communications in resilience, and the need for open standards and architectures. The panel also identified AI integration with DPI as an emerging frontier requiring careful governance, with both practical implementations (India's health ecosystem, Bhashini translation platform) and principled design frameworks (Kanzaveli's four non-negotiable rules) presented.
Aminu Maida explicitly argued that trust 'must be continuously maintained' and is 'not established once' , framing it as 'an ongoing journey that must be earned, protected, and constantly maintained' . Mohamed Adan Moalim Ali, by contrast, emphasised that trust and security 'must be enabled by design from the very beginning' , focusing on the foundational moment of design rather than ongoing maintenance. Tatyana Kanzaveli bridged both perspectives but added a further dimension, arguing that 'oversight cannot end at the deployment time' because 'models drift, data changes, threats adapt' , suggesting that neither design-time embedding nor periodic maintenance is sufficient - continuous, adaptive oversight is required. These represent meaningfully different framings of where the primary responsibility for trust lies in the DPI lifecycle.
Nigeria builds trust on three interconnected foundations: trust in identity (SIM-NIN linkage), trust in networks (cyber resilience framework), and trust in markets (transparent regulation), recognising that trust must be continuously maintained, not established once
Trust and security must be enabled by design from the very beginning, not added at the end of the process, as Somalia embeds legal and institutional foundations including data protection law and cybersecurity legislation
AI-enabled DPI requires four non-negotiable design rules: no single point of failure, no single point of control, no invisible decisions, and no automated dead end, with security and privacy as foundational rather than optional features
Anil Kumar Lahoti presented India's Aadhaar payment bridge system - which automatically routes welfare funds to beneficiaries using a 12-digit identity number without human intermediation - as an unqualified success in eliminating 'duplicate or fake beneficiaries and layered institutional leakages' . He described biometric-based verification as a tool for inclusion , with no mention of appeal mechanisms or recourse for citizens wrongly excluded. Tatyana Kanzaveli, however, argued that 'every person must be able to understand a decision, correct inaccurate information, reach a qualified human, and obtain timely review' , and that 'no automated system should make inconsequential decisions about the person' without the ability to challenge and reverse them . She explicitly warned that when AI-enabled infrastructure fails, citizens 'may lose access to healthcare benefits, education, public services or even the ability to prove who they are' . These positions are in direct tension: India's model prioritises efficiency and inclusion through automation, while Kanzaveli's framework prioritises rights protection and human recourse as non-negotiable design requirements.
India's Aadhaar payment bridge system routes welfare funds directly using a 12-digit identity number, with biometric verification ensuring inclusion of citizens who cannot read, write, or lack traditional identification documents
AI-enabled DPI requires four non-negotiable design rules: no single point of failure, no single point of control, no invisible decisions, and no automated dead end, with security and privacy as foundational rather than optional features
Anil Kumar Lahoti described India's model as a 'Secure Core' with 'multiple distributary arms' achieved by permitting private fintech companies to build apps on top of the public rail via open APIs , framing this as achieving 'modularity, scalability, and resilience' . The architecture is centralised at its foundation (Aadhaar, UPI) with openness at the application layer. Tatyana Kanzaveli, however, argued that 'no single point of control' is a non-negotiable design rule, requiring 'mandatory interoperability, open standards, modular architecture, portable data, and well-governed APIs' to 'prevent permanent dependence on one supplier, one platform, or one model' . While both value openness and modularity, Kanzaveli's framework would treat a centralised identity and payment core - even one with open APIs - as a structural risk, whereas Lahoti presented it as the foundation of India's success.
India's three-layer DPI system (Aadhaar for identity, UPI for payments, and data management) engineered for scale, openness, and integration to advance inclusion and efficiency simultaneously
AI-enabled DPI requires four non-negotiable design rules: no single point of failure, no single point of control, no invisible decisions, and no automated dead end, with security and privacy as foundational rather than optional features
Rafał Rosiński focused almost exclusively on technical infrastructure as the key to resilience, citing Poland's 2024 flood experience where 'terrestrial base stations lost connectivity' and the country 'relied on satellite communications to provide emergency connectivity' . He pointed to 6G standardisation and spectrum regulation as the primary tools . David Mugonyi, by contrast, argued that 'robust policy and regulatory frameworks are the foundation of digital transformation' , with collaboration, policies, regulation, and security as the 'one big idea' . Aminu Maida similarly emphasised regulatory frameworks - a cyber resilience framework and an executive order on critical infrastructure - alongside transparency mechanisms . Mohamed Adan Moalim Ali stressed legal foundations including data protection law and cybersecurity legislation . These speakers implicitly disagree on whether technical infrastructure convergence or legal-regulatory architecture is the primary enabler of DPI resilience.
Poland's experience during the 2024 floods demonstrated the critical importance of satellite communications as a resilience backup when terrestrial base stations lost connectivity, highlighting the need for convergence of satellite and mobile technologies
Kenya's approach demonstrates that robust, collaborative, and inclusive policymaking is the foundation of digital transformation, extending regulatory rigour to emerging technologies such as AI and virtual assets
Nigeria builds trust on three interconnected foundations: trust in identity (SIM-NIN linkage), trust in networks (cyber resilience framework), and trust in markets (transparent regulation), recognising that trust must be continuously maintained, not established once
Trust and security must be enabled by design from the very beginning, not added at the end of the process, as Somalia embeds legal and institutional foundations including data protection law and cybersecurity legislation
In a panel ostensibly united around building 'secure and trusted digital public infrastructure', an unexpected fault line emerged around the fundamental nature of DPI itself. Diouf framed DPI primarily in economic terms - raising GDP contribution from 7% to 15% by 2029 - and as a platform for government and private sector efficiency . Lahoti similarly emphasised scale, efficiency, and economic democratisation . By contrast, Kanzaveli explicitly reframed DPI as 'rights infrastructure' rather than 'simply technology' , arguing that when it fails, citizens lose fundamental rights. Bernadette Lewis framed DPI as a mechanism for 'the renewal of the social contract' , emphasising recourse mechanisms when things go wrong . Mohamed Adan Moalim Ali positioned DPI as a tool to 'transform the relationship between citizens and the government' . This was unexpected because the panel was framed as a consensus-building exercise on DPI, yet the speakers implicitly held quite different views on whether DPI is fundamentally an economic efficiency tool, a social contract instrument, or a rights infrastructure - with significant implications for how it should be designed, governed, and evaluated.
This disagreement was unexpected given the panel's broadly collaborative framing. Lahoti presented India's model of permitting 'private fintech companies to build apps on top of the public rail by anchoring the India stack to open APIs' as a straightforward success, enabling 'modularity, scalability, and resilience' . This positions private sector participation as an unqualified benefit. Kanzaveli, however, implicitly challenged this by arguing that 'interoperability must be mandatory' and that 'open standards, modular architecture, portable data, and well-governed APIs prevent permanent dependence on one supplier, one platform, or one model' - suggesting that private sector involvement without strict architectural constraints creates lock-in risks. David Mugonyi's emphasis on regulatory frameworks including the Virtual Asset Service Providers Act and multi-agency cyber threat response implicitly acknowledged that private sector actors in DPI require regulatory oversight rather than simply being welcomed as partners. The tension between welcoming private sector innovation and guarding against private sector capture of public infrastructure was not openly debated but ran as an undercurrent through these contributions.
This was an unexpected area of implicit disagreement given that all speakers endorsed digital identity as a positive development. Lahoti presented biometric-based verification as a tool for inclusion, specifically enabling 'citizens who cannot read, write or lack traditional identification documents' to access welfare . Sison noted that over 90 million Filipinos are registered under the national identity system and that 'identity systems must always empower citizens while safeguarding privacy, protecting rights, and ensuring accountability' - acknowledging potential risks without elaborating on them. Kanzaveli, however, raised the alarming scenario that when AI-enabled identity infrastructure fails, citizens may lose 'the ability to prove who they are' , and argued that every person must be able to 'correct inaccurate information' and 'reach a qualified human' . This implies that biometric identity systems - presented by Lahoti as inclusive - could in fact exclude or harm the very citizens they are meant to serve if they fail or produce errors, and that the absence of appeal mechanisms (which Lahoti did not mention) is a serious design flaw. The disagreement was unexpected because it emerged within a shared commitment to digital identity as an inclusion tool.
The panel presented a broadly consensual surface on the value of digital public infrastructure, with all speakers endorsing DPI as essential for development, inclusion, and economic growth. However, beneath this consensus lay meaningful disagreements on: (1) the fundamental nature of DPI - whether it is primarily an economic efficiency tool, a social contract instrument, or rights infrastructure; (2) the appropriate architecture for DPI - centralised secure core with open APIs versus mandatory decentralisation to prevent single points of control; (3) the role of automated decision-making - celebrated by India as an inclusion mechanism but challenged by Kanzaveli as a rights risk without human recourse; (4) the primary driver of resilience - technical infrastructure convergence (Poland) versus legal-regulatory frameworks (Kenya, Nigeria, Somalia); and (5) the lifecycle of trust - whether it is established by design (Somalia), continuously maintained (Nigeria), or requires ongoing adaptive oversight (Kanzaveli). The most significant implicit disagreement was between India's presentation of its automated welfare transfer system and Kanzaveli's insistence that no automated system should make consequential decisions without the ability to challenge and reverse them . This tension was never directly addressed in the panel.
All four speakers agreed that multi-stakeholder collaboration is essential for DPI. Mohamed Adan Moalim Ali stated that 'resilient digital public infrastructure cannot be built by government alone' and requires 'strong partnership between government, regulatory and also private sector' . Bernadette Lewis similarly acknowledged that 'governments cannot establish the DPIs alone' and 'have to work in strategic partnerships with diverse players' . David Mugonyi described collaboration as 'one big idea' . However, they disagreed on the primacy of government's role: Lewis emphasised government's unique custodial responsibility as the only institution interacting with citizens 'at every stage of life from birth' to death , positioning government as the irreplaceable anchor. Sison, by contrast, articulated the principle that 'government must do the connecting and not the citizen' , emphasising government's service obligation rather than its custodial authority. These different emphases — government as custodian versus government as service connector — reflect a subtle but meaningful tension about the nature of government's role in DPI.
Resilient DPI cannot be built by government alone; it requires strong partnerships between government, regulatory bodies, the private sector, civil society, and development partners Government is the only institution with which a citizen must interact at every stage of life, making it the custodian of vast repositories of citizen information and therefore uniquely responsible for delivering services, protecting privacy, and maintaining security Philippines' three-pillar approach to resilient digital infrastructure: connectivity, trusted digital identity, and interoperable digital governance, underpinned by the principle that government must do the connecting, not the citizen Kenya's approach demonstrates that robust, collaborative, and inclusive policymaking is the foundation of digital transformation, extending regulatory rigour to emerging technologies such as AI and virtual assets
All three speakers agreed on the principle of security-by-design — that security must be embedded from the outset rather than added later. Lahoti described how 'security protocols were integrated directly into the source code of Aadhaar and UPI' , and that data processing and ownership were separated using 'encrypted single-use digital tokens without storing or viewing the personal data itself' . Mohamed Adan Moalim Ali stated that 'trust and security cannot be added at the end of the process' and 'must be enabled by design from the very beginning' . Kanzaveli similarly argued that 'security, privacy, accessibility, multilingual inclusion, and data minimisation are not optional features' but 'the foundation' . However, they disagreed on what security-by-design entails in practice: Lahoti focused on technical architecture (zero-trust networks, token-based data transfer) ; Moalim Ali focused on legal and institutional frameworks (data protection law, cybersecurity legislation) ; and Kanzaveli added human rights dimensions (auditability, appeal rights, no automated dead ends) that the others did not address.
India implemented security by design by integrating security protocols directly into the source code of Aadhaar and UPI, applying zero-trust networks and separating data processing from ownership to prevent large-scale tracking AI-enabled DPI requires four non-negotiable design rules: no single point of failure, no single point of control, no invisible decisions, and no automated dead end, with security and privacy as foundational rather than optional features Trust and security must be enabled by design from the very beginning, not added at the end of the process, as Somalia embeds legal and institutional foundations including data protection law and cybersecurity legislation
All four speakers agreed that interoperability and integration across government platforms is a core DPI objective. Diouf described Senegal's data exchange platform as enabling 'all those platforms to see each other, to exchange the data' to resolve fragmentation . Moalim Ali's roadmap included 'secure data exchange' as a key pillar . Sison described building 'integrated public services through a unified digital gateway' . Lahoti described India's three-layer system as enabling 'economy-wide digitization of services' . However, they disagreed on the sequencing and current state of implementation: India presented a mature, operational system at population scale ; the Philippines described an advanced but still-developing system [73-74, 77]; Somalia presented a roadmap that is still in its phased planning stage ; and Senegal acknowledged it does not yet have a complete strategy for its identity layer, noting 'we don't have a strategy yet, but we have it in our business plan' . This reveals a significant gap between aspirational alignment and actual implementation maturity.
Senegal's data exchange platform is designed to resolve institutional and platform fragmentation, enabling all public platforms to communicate and share data securely and efficiently Somalia's National DPI Roadmap providing a phased strategy integrating digital identity, digital payments, and secure data exchange, developed following the country's first National Digital Public Infrastructure Summit The Philippines' e-governance act and unified digital gateway are building integrated public services, with the principle that digital infrastructure must be public in purpose, secure by design, inclusive in reach, and interoperable India's three-layer DPI system (Aadhaar for identity, UPI for payments, and data management) engineered for scale, openness, and integration to advance inclusion and efficiency simultaneously
Both Lahoti and Kanzaveli agreed that the convergence of DPI and AI represents a significant and consequential development. Lahoti described how 'the convergence of DPI and AI is driving India's public health for the next generation' towards 'population-scale preventive care' , presenting this as an unambiguously positive development. Kanzaveli agreed that AI-enabled DPI has profound implications for citizens' lives, but framed this as a source of risk as much as opportunity: 'when AI-enabled public infrastructure fails, citizens don't just experience a software bug — they may lose access to healthcare benefits, education, public services or even the ability to prove who they are' . Both agreed on the transformative scale of AI-DPI integration, but disagreed fundamentally on whether the primary lens should be opportunity (Lahoti) or risk and rights protection (Kanzaveli).
India is combining DPI with AI, including a public health ecosystem of 932 million health IDs and over one billion digital health records, shifting from reactive treatment to population-scale preventive care When AI-enabled public infrastructure fails, citizens may lose access to healthcare, benefits, education, or the ability to prove their identity; DPI is therefore rights infrastructure, not merely technology infrastructure
- Digital Public Infrastructure (DPI) is increasingly recognised as the backbone of modern societies, with countries at various stages of developing national DPI strategies centred on three core pillars: digital identity, data exchange or payments, and interoperable governance.
- Trust and security must be embedded by design from the outset of DPI development, not retrofitted after deployment. This includes legal frameworks, cybersecurity legislation, data protection laws, and technical measures such as zero-trust networks and encrypted tokens.
- Resilience in DPI requires redundancy and the convergence of multiple technologies. Poland's 2024 flood experience demonstrated that satellite communications are a critical backup when terrestrial infrastructure fails, underscoring the importance of integrating satellite and mobile systems.
- Interoperability is a foundational requirement for effective DPI, both domestically and across borders. Open standards, modular architecture, portable data, and well-governed APIs are essential to prevent dependence on a single supplier or platform and to enable cross-border trade and services.
- Inclusion and citizen-centricity must be core design principles. DPI should serve citizens regardless of literacy, language, location, or income. India's use of biometric verification and AI-powered multilingual voice interfaces exemplifies how DPI can reach marginalised populations.
- Government holds a unique and irreplaceable role as the custodian of citizen data across the entire life cycle, from birth registration to death. This responsibility requires governments to deliver services, protect privacy, maintain security, and renew the social contract with citizens.
- Resilient DPI cannot be built by government alone. It requires strategic partnerships across government, the private sector, civil society, development partners, and academia.
- AI integration with DPI elevates the stakes significantly. When AI-enabled public infrastructure fails, citizens may lose access to essential services or the ability to prove their identity. DPI must therefore be treated as rights infrastructure, not merely technology infrastructure.
- Four non-negotiable design rules were proposed for AI-driven DPI: no single point of failure, no single point of control, no invisible decisions, and no automated dead end. Every consequential AI-driven decision must be traceable, challengeable, and reversible.
- Trust in DPI is not a one-time achievement but an ongoing journey that must be continuously earned, protected, and maintained across identity, networks, and markets.
- Scale, openness, and integration are key distinguishing features of successful DPI, as demonstrated by India's experience with Aadhaar and UPI, which together account for approximately 50% of the world's total digital transactions in a single month.
- Digital literacy, affordable access, interoperability, and accessible systems of timely recourse are all necessary conditions for citizens to trust and benefit from DPI.
“Digital public infrastructure is not simply a technology initiative — it's a national development priority. Trust and security cannot be added at the end of the process. They must be enabled by design from the very beginning.”
“Government must do the connecting, not the citizen. It must be supported by institutions capable of governing systems responsibly over the long term, and it must earn the public trust of the people.”
“India engineered trust into the systems through a unique three-layer system — identity (Aadhaar), payments (UPI), and data management. Processing and ownership of data has been separated, enabling secure transfer of information using encrypted single-use digital tokens without storing or viewing personal data itself.”
“Trust is not established once — it must be continuously maintained. Nigeria builds trust on three interconnected foundations: trust in identity, trust in networks, and trust in markets.”
“An effective DPI helps in the renewal and the renewing of that social contract. Government is the only institution with which a citizen has to interact in every stage of life — from birth registration to death — and therefore governments are the custodians of enormous repositories of citizen information.”
“When AI-enabled public infrastructure fails citizens, they don't just experience a software bug — they may lose access to healthcare, benefits, education, or even the ability to prove who they are. That is why digital public infrastructure is no longer simply technology. It is rights infrastructure. Four non-negotiable design rules: no single point of failure, no single point of control, no invisible decisions, and no automated dead end.”
What is Senegal's concrete strategy for digital identity, and when will it be fully realised?
Samba Diouf acknowledged that while a digital identity project exists within Senegal's DPI roadmap, a fully defined strategy has not yet been established. He noted it is in the business plan and will be realised 'very soon,' leaving open the question of timelines, governance structures, and implementation details that warrant further exploration.
How can Senegal accelerate the growth of its digital economy's contribution to GDP from 7% to 15% by 2029, and what specific mechanisms will drive this?
Diouf set an ambitious target of doubling the digital economy's share of GDP within a few years. The specific policy levers, investment strategies, and risk mitigation approaches needed to achieve this goal were not elaborated upon and merit further research.
How is Somalia ensuring the sustainability and long-term funding of its National Digital Public Infrastructure Roadmap, particularly given its fragile institutional context?
Somalia's representative outlined an ambitious phased DPI roadmap but did not address how it will be financed and sustained over time in a country still consolidating its institutions. The intersection of fragility, donor dependence, and long-term digital resilience is an important area for further research.
How is Somalia advancing its cybersecurity, cybercrime, and electronic transaction legislation, and what is the expected timeline for enactment?
Ali mentioned that Somalia is 'advancing' these legislative frameworks but did not provide details on their current status, content, or timelines. Given that legal foundations are critical to DPI trust and resilience, the progress and design of these laws require further investigation.
How is the Philippines ensuring DPI resilience and service continuity for remote and vulnerable communities during natural disasters such as earthquakes and typhoons?
Cheryl Miller raised this question directly in the context of the Philippines being an archipelagic and disaster-prone country. While Sison outlined the three pillars of connectivity, digital identity, and interoperable governance, she did not specifically address disaster-recovery protocols or offline continuity mechanisms for remote communities, leaving this as an open area for further research.
What governance and accountability mechanisms are in place to ensure that the Philippines' national ID system, covering over 90 million citizens, safeguards privacy and protects rights?
Sison acknowledged that identity systems must empower citizens while safeguarding privacy and ensuring accountability, but did not elaborate on the specific oversight bodies, audit processes, or redress mechanisms in place. This is a critical area requiring further examination.
How can satellite and mobile technology convergence be regulated effectively at the international level to ensure resilient emergency communications during disasters?
Rosiński highlighted Poland's experience during the 2024 floods, where satellite communications were essential when terrestrial infrastructure failed. He noted ongoing work on 6G standardisation and mobile satellite services but did not detail how an efficient and predictable international regulatory framework for this convergence would be designed and enforced.
What role will the ITU's IMT-2030 framework and 3GPP standards play in integrating satellite and mobile systems, and how can developing countries participate meaningfully in this standardisation process?
Rosiński referenced ITU and 3GPP as important actors in 6G standardisation but did not address how lower-income or less technically advanced countries can engage in and benefit from these processes. This raises important equity and inclusion questions for further research.
How can India's DPI model, particularly its three-layer stack of identity, payments, and data management, be adapted for countries with weaker institutional capacity and lower digital literacy?
Lahoti presented India's DPI as a global learning experience, but the question of transferability to contexts with different infrastructure, governance, and literacy levels was not addressed. Understanding the conditions under which India's model can be replicated or adapted is a critical area for further research.
How is India managing the risks of large-scale biometric data collection under Aadhaar, particularly in relation to exclusion errors and civil liberties concerns?
Lahoti highlighted biometric verification as a tool for inclusion, but did not address documented concerns about exclusion of legitimate beneficiaries due to biometric failures, or broader civil liberties debates around mass biometric surveillance. These are significant areas requiring further investigation.
How is India's AI-powered Bhashini translation platform being evaluated for accuracy and bias across its 22 supported languages, and what recourse exists for citizens who receive incorrect translations?
Lahoti mentioned Bhashini as a tool for breaking language barriers in DPI access, but did not address quality assurance, error rates, or appeal mechanisms. Given that mistranslations in welfare or health contexts could have serious consequences, this is an important area for further research.
How is Kenya ensuring cybersecurity and data protection as it expands cross-border digital payment interoperability with regional neighbours?
Mugonyi described Kenya's interoperable payment and customs systems with regional partners but acknowledged cybersecurity and data protection as current priorities without detailing the specific frameworks in place. The security architecture underpinning cross-border digital trade is an important area for further research.
How will Kenya's National Artificial Intelligence Strategy 2025–2030 be implemented in practice, and what mechanisms will ensure ethical AI deployment in public services?
Mugonyi referenced the strategy but did not elaborate on implementation mechanisms, enforcement bodies, or how ethical principles will be operationalised. Given the rapid pace of AI adoption, the practical governance of AI in Kenya's public sector warrants further investigation.
How will Kenya's Virtual Asset Service Providers Act 2025 interact with existing DPI frameworks, and what consumer protection measures are embedded within it?
Mugonyi mentioned the recently passed Act as providing regulatory clarity for digital assets but did not detail its consumer protection provisions or how it integrates with Kenya's broader DPI ecosystem. This is a novel regulatory area requiring further research.
How can Nigeria's telecommunications identity risk management system be used as a model for other African nations to manage SIM card fraud and number recycling at scale?
Maida described Nigeria's system for tracking lifecycle events such as number recycling and dormancy but did not elaborate on its technical architecture, governance, or lessons learned. Given the prevalence of SIM-related fraud across Africa, this is a valuable area for further research and knowledge sharing.
How is Nigeria operationalising the 2024 Presidential Executive Order on Critical National Information Infrastructure, and what sectors are prioritised?
Maida referenced the Executive Order as a key instrument for cyber resilience but did not provide details on its implementation status, scope, or the sectors designated as critical. This is an important policy area requiring further examination.
What mechanisms should governments put in place to ensure timely and accessible recourse for citizens when DPI systems fail or produce harmful outcomes?
Lewis emphasised that when things go wrong, systems of acceptable and timely recourse must exist, noting that their absence erodes public confidence. However, she did not detail what such mechanisms should look like in practice. Designing effective, accessible redress systems for DPI is a critical area for further research.
How can governments build and maintain the digital literacy and skills necessary for citizens to effectively use DPI systems, particularly among marginalised populations?
Lewis highlighted that citizens must have the skills and literacy to benefit from DPI, but did not address how governments should design and fund such programmes. The intersection of digital skills, inclusion, and DPI effectiveness is an important area for further research.
How should governments design AI-enabled DPI to ensure no single point of failure, including offline alternatives and tested continuity plans?
Kanzaveli identified the absence of a single point of failure as a non-negotiable design principle but did not elaborate on specific technical architectures or governance models that achieve this. The engineering and policy dimensions of resilient AI-enabled DPI require further research.
What international standards or frameworks should govern the use of open APIs and interoperability requirements in AI-driven digital public infrastructure to prevent vendor lock-in?
Kanzaveli called for mandatory interoperability through open standards and well-governed APIs but did not specify which existing or emerging international frameworks could provide this governance. Developing such standards is a significant area for further research and multilateral cooperation.
How should governments implement independent auditing and oversight of AI models used in DPI, given that models drift and threats adapt over time?
Kanzaveli stressed that oversight cannot end at deployment and that models require ongoing independent testing and accountability. The design of continuous audit regimes for AI in public services, including who conducts them and how findings are acted upon, is an important area for further research.
Where should the red line be drawn regarding automated decision-making in DPI, and how should the right to human review be operationalised across different service contexts?
Kanzaveli called for a clear red line preventing automated systems from making inconsequential decisions without the possibility of human challenge and reversal, but acknowledged ambiguity in defining this boundary. Establishing clear, context-sensitive criteria for when human oversight is mandatory is a critical area for further research and policy development.
How can the lessons from multiple national DPI experiences presented at this panel be synthesised into a globally applicable framework for secure, resilient, and inclusive digital public infrastructure?
Miller noted at the close of the panel that there was more to discuss and that the conversation would continue beyond the session. The synthesis of diverse national experiences from Senegal, Somalia, the Philippines, Poland, India, Kenya, and Nigeria into transferable global guidance is an important area for further research and multilateral dialogue.
