col-xs-12
col-sm-12
col-md-12
col-lg-12
col-xs-12
col-sm-12
col-md-12
col-lg-12
videoType
dynamic-media
videoDmUrl
https://delivery-p136806-e1377785.adobeaemcloud.com/adobe/assets/urn:aaid:aem:0888225b-2e62-4fb2-90a3-2cd0eee4f1f3/play?assetname=WDR2025-Digital_Public_Infrastructure.mp4
keyFrameImage
videoDescription
In this World Development Report 2025 seminar series, Siddharth Shetty (CEO, Finternet Labs and Co-creator of the Finternet) and Abhishek Sankritik (Director, Policy and Programs, Finternet Labs) discuss "Digital Public Infrastructure: Setting Standards with the Hourglass Model" with chair Devesh Kapur, Academic Lead, World Development Report 2025.
timestamp

00:00 This is just to welcome all of you.

00:02 This is part of

00:04 the World Development Report 2025 seminar

00:09 series.

00:10 Uh,

00:10 I'm Devesh Kapoor.

00:11 I'm the academic lead for the report.

00:15 And,

00:15 uh,

00:17 today,

00:17 uh,

00:18 we have a great,

00:19 uh,

00:21 Uh,

00:21 presentation on

00:23 digital public infrastructure,

00:26 setting standards with the Hourglass model.

00:30 And our speakers who've,

00:32 who've also written a a background paper on this topic,

00:37 uh,

00:38 Siddharth

00:38 Shetty,

00:39 who's the CEO

00:41 of

00:41 Fin

00:43 Finternet Labs,

00:45 and the co-creator of the Finternet.

00:47 I hope he'll

00:48 tell us a bit about what it is about,

00:51 uh,

00:52 and

00:52 Abhishek.

00:53 Uh,

00:54 San K

00:54 Kritik,

00:55 uh,

00:56 who is the,

00:57 the director of policy and programs of Finternet Labs.

01:02 Uh,

01:02 uh,

01:02 welcome,

01:03 and,

01:03 uh,

01:04 the sort of floor is yours.

01:07 Thank you

01:16 that you describe?

01:18 OK,

01:18 great,

01:18 yeah.

01:20 Uh,

01:20 so Abhishek,

01:21 do you want to share the slides,

01:22 and then I,

01:24 I'm just doing that.

01:27 I think it requires some permissions.

01:31 01 2nd.

01:54 I can share from my end.

02:18 The screen did come up.

02:20 Uh,

02:20 I appreciate you.

02:22 Yeah,

02:22 I'm back.

02:25 It required me to

02:26 quit in order to come back.

02:31 We know.

02:33 Uh,

02:34 there are very unique

02:36 proposition,

02:37 but yes.

02:38 So I hope everybody can see my screen.

02:41 Yep.

02:44 Yeah,

02:45 thanks,

02:45 uh,

02:45 Abhishek.

02:46 So we'll start out with a quick,

02:47 uh,

02:48 introduction,

02:50 and then you can dive

02:52 into this.

02:53 Um,

02:54 so we've spent,

02:55 I've spent the last 10 years

02:57 designing and building digital public infrastructure.

03:00 Um,

03:01 so I've been part of the team that built

03:02 out digital identity systems that rolled out to over

03:06 1.4 billion people,

03:08 uh,

03:08 digital payment systems that are used millions of times a day.

03:12 Um,

03:13 uh,

03:13 I myself architected a,

03:15 a consented data sharing system

03:17 that's been used by over 250 million people so far.

03:21 And,

03:21 um,

03:22 more recently,

03:24 um,

03:25 As we were building out a lot of these,

03:27 realized that we are building something that was very purpose-specific,

03:31 and we needed a much more universal approach,

03:34 uh,

03:34 an approach that really

03:36 empowers both individuals and businesses with

03:39 their identity,

03:40 credential,

03:40 and any type of asset.

03:42 And,

03:43 uh,

03:43 that's when we articulated the Finternet vision.

03:46 So,

03:47 uh,

03:47 I've been working across both

03:49 the legislative aspects of this infrastructure,

03:51 as well as the technology.

03:53 And,

03:53 um,

03:54 and so we'll cover

03:56 both dimensions,

03:57 uh,

03:58 in,

03:58 in today's conversation,

04:00 including,

04:01 uh,

04:01 how

04:02 the market side of adoption takes place as well.

04:04 So,

04:05 the commercial side,

04:06 the legal,

04:06 as well as the technology side.

04:08 Um,

04:09 I'll hand it over to Abhishek,

04:10 if you can do a quick introduction as well,

04:12 and then,

04:13 um,

04:14 we can kick it off.

04:16 Absolutely,

04:16 thanks for that.

04:17 So I come from a very different background.

04:20 I come from a disputes background in lit in law.

04:24 I practiced in the courts for about 6.5 years before taking a jump into

04:28 a,

04:28 a corporate setting but with a technology firm which was looking at tokenization.

04:33 In in India at that point in time,

04:35 I think the regulations were at the nascent stage and globally there was

04:40 what what we've seen at the crypto summer and

04:42 then the entire crash that it's we've seen after.

04:46 So it was an interesting time to have dived into the

04:48 entire web 3 market and it's from there that I had,

04:51 uh,

04:52 found out about the finternet met uh

04:55 then we started working on a couple of projects and,

04:57 and now we work on a lot of

04:59 things within the finternet that.

05:02 Intersect with

05:04 legal

05:05 permutations and combinations whether they're regulations,

05:08 supervisory tech,

05:10 or whether they're simply how,

05:12 what do you construe tokenization tokenized assets as

05:16 back to you sir.

05:18 Thanks,

05:18 Abhishek.

05:19 So,

05:19 we'll start out,

05:20 we'll keep the presentation brief.

05:22 So we'll cover it in about,

05:24 um,

05:25 you know,

05:26 um,

05:27 uh,

05:27 30

05:28 minutes,

05:28 and then we can,

05:30 uh,

05:30 dive into a whole range of questions that are there.

05:35 Um,

05:35 so,

05:35 the,

05:36 a brief thing on the internet before we then dive into

05:39 also

05:40 the basis of the paper,

05:42 which has been about what is this hourglass

05:44 model towards digital public infrastructure and standard setting.

05:48 Uh,

05:48 the Finternet was a paper,

05:49 you can read more about it at Finternetlab.io

05:53 that was co-authored by Augustin Carstens,

05:55 the

05:56 former general manager of the BIS and Nanar Nalikani.

05:59 And the main idea behind it was,

06:02 um,

06:03 I would distill it into 3 simple

06:05 uses.

06:06 Uh,

06:06 the first you is a user-centric vision.

06:08 So how do you give users,

06:10 individuals and businesses control over their identity credentials or assets.

06:15 The assets could be regulated assets like money,

06:17 securities.

06:19 Registered assets like physical property or vehicles,

06:22 anything that has a registrar behind it.

06:24 It could be

06:25 um

06:26 attested assets,

06:27 energy resources,

06:28 gold,

06:28 silver,

06:29 commodities,

06:30 or

06:30 user-controlled digital assets.

06:32 And so across this entire spectrum,

06:34 how do we give control back

06:36 to users across the world?

06:38 Um,

06:38 and

06:39 what this means is really thinking through two key properties.

06:43 One

06:43 is the property of verifiability

06:46 of these,

06:47 uh,

06:47 identity credentials and assets.

06:49 So because provenance is critical in different flows.

06:52 And second is the property of transactability,

06:55 um,

06:56 which is the ability to transfer these different assets

06:59 between individuals and businesses.

07:01 And

07:01 these could be financial,

07:03 uh,

07:03 transactions,

07:04 like I'm transferring money to you.

07:06 Uh,

07:06 but it could also be non-financial transactions where I'm

07:09 transferring a subset of property rights to you,

07:12 like ownership of a physical land deed,

07:14 which in most countries today often involves

07:17 in-person paper transactions.

07:20 So,

07:20 um,

07:21 uh,

07:21 what we did is we conceptualized an architecture where users have control.

07:26 You can do this in a unified manner.

07:28 So each of these assets are governed by different public authorities.

07:32 So,

07:32 how do you deal with

07:34 their own

07:35 sovereignty,

07:35 autonomy considerations,

07:37 but also

07:38 unify it for the end user.

07:40 And then the third was,

07:42 what is the universal infrastructure we can build?

07:44 So that's the 3rd you,

07:46 uh,

07:46 because we realized that building very purpose-specific infrastructure,

07:50 sort of

07:50 in the financial system today,

07:52 it's like every time you build a new car,

07:54 we build a new road.

07:56 And that doesn't scale,

07:57 that creates,

07:58 you know,

07:59 high costs,

07:59 and that's the reason you have 100 countries,

08:01 less than 10 million in population.

08:04 They struggle to adopt uh the advances in financial infrastructure.

08:08 And our view was,

08:09 if you can take an approach much like what

08:11 If you think about it,

08:12 all of you have a phone in front of you,

08:14 or are dialed in through a laptop or a computer or desktop,

08:18 uh,

08:18 all of it is running on operating systems.

08:20 And so,

08:21 there's much more universal technology that can power this,

08:24 while allowing for,

08:26 depending on the type of asset,

08:28 different regulatory constraints to be applied.

08:30 So that's sort of the broad summary behind the Finternet.

08:33 And so a lot of these questions of what gets standardized,

08:35 how do you think about interoperability,

08:38 so on and so forth.

08:39 These are questions we've been thinking about as well within the Finternet lab.

08:42 Um,

08:43 so we can,

08:43 you know,

08:44 take questions around this

08:46 later,

08:47 but Abhishek,

08:47 let's dive into

08:49 the DPI part and then take it from there.

08:52 So,

08:52 I'll spend some context setting on what digital public infrastructure means to us.

08:57 Um,

08:58 one is,

08:59 you know,

09:00 if you go by what does digital mean,

09:03 fundamentally,

09:04 digital means that these are digital interventions,

09:08 uh,

09:08 and this is very critical.

09:10 So,

09:10 these are digital interventions,

09:12 they have a digital backbone.

09:13 It doesn't necessarily mean that the user

09:16 needs to have a digital channel to access them.

09:19 So many DPIs work in assisted modes,

09:22 they work in offline modes.

09:24 So there are mechanisms for users,

09:26 even if the user itself doesn't have a digital means,

09:29 they can access it,

09:30 but fundamentally,

09:31 the backbone of it

09:33 is digital.

09:33 So,

09:34 these are digital interventions,

09:35 but doesn't necessarily mean the user needs to have a

09:38 smartphone or a

09:39 digital device to access.

09:41 The second is,

09:43 what does public mean in public infrastructure?

09:46 Many times this often gets construed to mean,

09:49 OK,

09:49 all this infrastructure is public owned or public operated,

09:52 as in,

09:53 it's government owned or state-owned,

09:55 state operated,

09:57 uh,

09:57 but that's actually not true,

09:58 and we'll talk about different examples where

10:00 there's been a strong role of private sector and in fact,

10:03 in some DPIs,

10:04 it's only private sector.

10:06 So,

10:07 public out here fundamentally means designed in public interest.

10:11 And so how do you bridge both the public ecosystems and the private ecosystems

10:16 towards a larger public interest goal?

10:19 And those public interest goals might be financial inclusion,

10:22 democratizing credit,

10:24 health inclusion,

10:25 so on and so forth.

10:26 So how do you align incentives,

10:28 uh,

10:29 align requirements between both of these ecosystems?

10:32 And in some countries,

10:33 you might have a stronger role of the public sector.

10:35 In some countries,

10:36 you may have a stronger role of the private sector.

10:38 Um,

10:39 and so depending on the different state and market capacity dynamics,

10:43 as long as they're working towards the larger public interest,

10:47 which is what the

10:48 AI is meant to enable

10:49 all of those different models fall under our view of,

10:52 of what DPI looks like.

10:54 So,

10:54 digital interventions,

10:56 designed and public interest.

10:57 And the third part,

10:58 infrastructure means that these are not,

11:01 you know,

11:01 it's not one app or it's not one solution.

11:05 Uh,

11:05 it's fundamentally laying the highway,

11:07 laying the roads,

11:08 on top of which multiple solutions can coexist,

11:11 both compete

11:12 and coexist.

11:14 Uh,

11:14 and that's very key,

11:15 because what you're doing is

11:17 creating

11:18 very foundational infrastructure,

11:20 much like what the internet has created or smartphones have created,

11:24 that allow for different entrepreneurs,

11:26 different problems to be solved

11:28 using

11:29 common tools.

11:29 And those common tools,

11:31 lower transaction cost,

11:33 therefore,

11:33 making a wider part of society access it,

11:36 if,

11:37 which wouldn't have been possible before.

11:39 So,

11:40 that's really the broad view behind DPI and,

11:42 and

11:44 through this presentation,

11:45 as well as in the working paper,

11:47 uh,

11:47 we've outlined various different modalities of what it means to

11:51 have digital interventions,

11:53 what are the different types of public ownership,

11:56 operations,

11:56 models.

11:57 That are there,

11:57 and what does infrastructure mean at the level of technology,

12:00 protocols,

12:01 standards,

12:02 so on and so forth.

12:03 So,

12:04 of course,

12:05 the dominant areas DPIs are often thought about,

12:08 and,

12:08 and quite a few World Bank reports reference these

12:11 are in the areas of identity payments and data sharing.

12:15 Uh,

12:15 but it goes beyond that.

12:16 So,

12:17 even in the world of identity,

12:19 we see different types of identity constructs becoming important,

12:23 identity of individuals,

12:25 identity of organizations,

12:27 identity of things.

12:28 So,

12:29 AI agents.

12:31 Um,

12:31 when it,

12:32 when,

12:32 when We take,

12:33 let's say

12:34 we drill this down even further,

12:36 when it comes to identity of individuals,

12:38 you'll have different types of identities,

12:40 even in that,

12:41 you may have foundational IDs,

12:43 like Aadhar,

12:44 which is,

12:44 in some sense,

12:45 establishes a proof.

12:46 It's an attestation that

12:48 you are who you claim to be.

12:50 But then you have different functional IDs

12:52 that get created on top,

12:54 like your driver's license,

12:55 or are you eligible to vote,

12:57 or are you eligible to,

12:59 you know,

12:59 avail this government service or not.

13:01 Uh,

13:01 for example,

13:02 are you eligible for welfare or not?

13:04 So you have both foundational IDs,

13:06 as well as functional IDs that come up.

13:09 And now what we're starting to see across the world

13:12 is the,

13:13 the,

13:13 the universe of identity is broadening to

13:17 other types of credentials and attestations as well.

13:19 So,

13:20 which school did you go to,

13:21 which university did you go to,

13:23 where did you work?

13:24 All of these,

13:25 which form a critical part of,

13:27 you know,

13:27 who you are

13:28 in a larger sense,

13:30 are being credentialized and issued back to the user,

13:33 so that they can reuse it

13:35 in a whole range of digital journeys.

13:37 So,

13:37 That's one building block when it comes to identity.

13:41 The second building block is payments,

13:43 the ability to transfer value.

13:45 This is where real-time payment systems like UPI in India,

13:49 PayNow in Singapore,

13:50 PrompPay in Thailand,

13:52 PI in Brazil come up.

13:53 Fundamentally,

13:54 a lot of these real-time payment systems

13:57 created an interoperable mechanism for money movement.

14:01 Uh,

14:02 between banks,

14:03 but then brought in private sector to create front-end applications,

14:07 um,

14:07 um,

14:08 uh,

14:08 brought in private sector to

14:10 onboard merchants,

14:13 so on and so forth.

14:14 And then what we've articulated in the Finternet is a much

14:17 broader version of value transfer that goes even beyond real-time payments.

14:21 And then the third piece is data sharing,

14:23 because as people transact digitally,

14:25 they're generating a lot of data.

14:27 And so how do you create the right kinds of consent frameworks

14:31 where data can be fetched from source

14:34 and then shared in real time,

14:36 if the user is sharing it as part

14:37 of a lending transaction or an insurance transaction,

14:41 so on and so forth.

14:42 And that's where if you look at open finance efforts in Brazil,

14:46 Singapore Findex,

14:48 which gives you an aggregation of different asset standings,

14:51 or the account aggregator Sharmati framework in India,

14:55 are all examples of consent-driven data sharing.

14:58 So these are the three,

14:59 what I would call foundational DPIs in some sense,

15:03 but this is just a start.

15:04 There are many more categories,

15:05 some of which we'll touch upon

15:07 in the presentation as well.

15:09 Um,

15:09 so,

15:10 over you,

15:10 over to you,

15:11 Abhishek,

15:11 to go to the next slide and,

15:13 and sort of cover

15:14 all the different themes that we've touched upon in the paper.

15:19 Thanks Sad that.

15:20 So just to cover up

15:22 what Siddharth is also saying in,

15:23 in terms of decisions that governments have ended up taking or

15:27 do end up having to take in relation to digital public infrastructure

15:31 because of the population scale implementation,

15:34 it's very crucial for them to look at

15:36 regulatory and legal architecting because of the nature

15:40 and the risk that is involved in some of these infrastructures that are rolled out.

15:45 But the second and most crucial element is that

15:50 the definition of what

15:52 constitutes public infrastructure and what should be

15:55 defined as public infrastructure

15:58 will change from decade to decade as

16:01 technology and as

16:04 people's needs,

16:05 wants,

16:05 and demands do change.

16:07 So we,

16:08 as the internet has become more and more accessible,

16:11 we've noted that digital public infrastructure.

16:13 And and entire tooling around identity and payments and data exchange

16:18 especially has become interesting,

16:20 but in an era,

16:22 for example,

16:22 without internet,

16:23 and this is why

16:25 one of the questions that we started

16:27 this entire presentation was that imagine COVID,

16:30 the entire pandemic without

16:32 digital infrastructure.

16:34 It's a really,

16:35 really daunting task to imagine what it will look like.

16:39 So moving on to the next

16:41 piece of this entire conversation and something that

16:43 we talked about within the paper itself,

16:46 payments,

16:47 surprisingly unlike what one would traditionally assume,

16:51 is the most prevalent digital public infrastructure across the globe

16:56 now.

16:59 Conventionally one assumes that you place the identity

17:01 infrastructure first because you need to know who

17:05 the client is before you can onboard them to get a bank account

17:09 and have them be able to access digital public infrastructure,

17:12 but we found that.

17:14 Needs must want.

17:16 So you have

17:18 the entire

17:19 set.

17:19 There are over 95 countries and something that Devish

17:22 also has been working on in the DPI map

17:24 which have DPI-like infrastructure and,

17:28 and several more who are

17:30 building up their infrastructure to be considered DPI-like.

17:34 Now

17:35 in the paper itself we've talked about

17:37 Brazil,

17:38 Kenya,

17:39 and India.

17:40 To look at 3 specific ways in which

17:43 the same fast payment system

17:45 has been implemented.

17:47 In Kenya we saw that it was a completely private run

17:51 uh

17:52 infrastructure until Pesa Link,

17:54 which was,

17:56 uh,

17:57 uh,

17:57 which was pushed by the central bank.

18:00 Was brought in as an interoperability tool,

18:02 so it was a post hoc interoperability and state

18:05 intervention,

18:06 whereas in Brazil it was state run from the get-go.

18:10 They had the entire learnings both from Kenya

18:12 as well as India to look at in the rearview mirror

18:15 and India had.

18:17 Pioneering,

18:18 of course,

18:18 the India stack as we call it.

18:21 Come out with

18:22 a public-private consortium

18:24 which involved banks.

18:26 It involved private participants.

18:28 It involved advisers and the government

18:31 reserve Bank coming together

18:33 to create a consortium,

18:36 an entity known as NPCI,

18:38 which would then

18:39 go about setting up UPI

18:42 in multiple jurisdictions,

18:43 most recently

18:45 with

18:46 the neighboring countries in Nepal.

18:50 Right,

18:50 so

18:52 We've not,

18:52 when we're looking at payments,

18:54 however,

18:56 There is an interesting conversation that we have to really,

18:59 really note

19:00 aside from the fact that fast payment systems

19:02 are processing maybe over 13 billion transactions,

19:06 and there's an entire conversation

19:08 about how the payment infrastructure is actually

19:11 composed of several components.

19:14 What is

19:15 very crucial to

19:17 to

19:17 note right now with the

19:19 stablecoins regulations,

19:21 the Genius Act currently within Washington.

19:24 Is that there is an entirely new payments

19:27 landscape that is opening up

19:29 with stablecoins.

19:31 Right,

19:31 so

19:32 if you look at some of the

19:34 The pain points that we still have,

19:37 we still have a 5.16% cost

19:40 in the lowest cost receiving region,

19:42 and we have 7.73% as the highest cost receiving region

19:46 for any sort of money transfer organization.

19:50 In Q1 2024.

19:53 Despite digital payments becoming such a wanted

19:57 conversation in terms of digital public infrastructure,

20:01 credit or debit is still one of the major instruments

20:05 to originate any sort of remittance.

20:08 And so when you look at remittances that are happening both

20:12 across borders.

20:14 Which is one of the biggest friction points

20:17 that a

20:18 payment system that has been developed in a silo versus

20:22 which has been developed in an interoperable manner phases,

20:25 you see that stablecoins actually from

20:28 a 6% cost.

20:31 In 2020

20:32 have dropped to a

20:35 0.01% cost on some chains

20:39 in 2024.

20:41 Now this

20:43 With the movements of regulation may keep vary,

20:47 but.

20:48 Generally we perceive and the trend is that these costs are always going to stay low.

20:54 The data,

20:54 the manner in which the,

20:56 the technology is developed,

20:58 as well as how

20:59 the the transactability and the the proofs relating to transactions

21:05 are stored,

21:06 means that you're going to have a low cost of compliance

21:09 constantly.

21:10 So it's interesting to note that

21:13 while fiat currency and while traditional

21:16 payment systems

21:18 have spent a very long time

21:20 to reach

21:21 at the 6 point

21:22 level.

21:24 It took stablecoins five years to take that 6%,

21:27 6% level

21:29 and come down to 0.01%.

21:32 We've also seen that there are decisions that governments need to make,

21:36 especially when they're looking at.

21:40 How they want to regulate stablecoins,

21:42 how they want to regulate CBDCs,

21:44 and how they want to regulate these instruments

21:46 which are getting used as currency coolants.

21:49 There are,

21:49 of course,

21:50 and we need to recognize

21:52 several reg

21:53 regulatory changes and.

21:57 Learning curves that we're going to have to take,

21:59 especially with a large portion of stablecoin utilization still being

22:04 within DFAT,

22:05 which stays

22:06 within a regulatory gray zone as of date.

22:10 I'll stop here so that for any comments in case you have

22:13 before I move on to the next slide.

22:14 No,

22:15 let's,

22:15 uh,

22:15 let's move on a bit quicker,

22:17 yeah.

22:18 Yeah

22:19 So moving on to digital identity,

22:21 digital identity frameworks,

22:24 the DPI map indicates 57 countries

22:26 have a DPI-like system,

22:28 but one of the most important things we note when digital identity

22:32 and

22:33 is is spoken of is that

22:36 you need to look at its utilization

22:38 as one of the going in principles when

22:41 you're rolling out a DPI around digital identity.

22:44 Which means that you need to calibrate for policy changes before you deploy,

22:48 whether it's putting up privacy laws,

22:49 whether it's putting up data exchange laws,

22:52 whether it's whether it's

22:54 deciding what compliance is going to look like between

22:58 your country and another country,

23:00 especially when you have clients or commerce that occurs cross border.

23:05 We also need to look at

23:08 how this identity gets utilized within domestic flows,

23:13 particularly within.

23:15 Maybe banking flows or

23:18 verification flows that involve finance,

23:21 credit,

23:22 bank securities,

23:24 so on and so forth.

23:25 One of the biggest boons within

23:27 India and Adhar

23:28 was that bank account opening

23:31 became cheaper for banks as well as faster,

23:33 and we saw an uptick in the total number of bank accounts

23:36 opened within India

23:38 due to digital identity systems,

23:39 and it's a trend that we've noticed across the globe

23:42 relating to digital identity.

23:45 So that

23:48 Yeah.

23:50 The only other thing I would mention is,

23:52 um,

23:54 uh,

23:54 one of the things which we've spoken about in,

23:56 in,

23:57 in the paper is really,

23:59 some of these are DPI efforts,

24:01 some of these are DPI like efforts,

24:03 and some of these are,

24:04 you know,

24:04 uh,

24:05 non-DPI efforts,

24:06 but are still nonetheless,

24:08 efforts around standardization and different approaches

24:11 with which standards can be created,

24:14 standards can be adopted,

24:15 the competitive effects,

24:17 some of the talk.

24:18 Down,

24:18 bottom up,

24:19 incumbent setting it versus not.

24:22 Um,

24:22 and so we've really

24:24 tried to surface,

24:25 you know,

24:25 not opine on what's the right approach,

24:27 but really surface,

24:29 what are the different trade-offs we've been seeing

24:31 as technology has been adopted at population scale,

24:35 uh,

24:35 both within DPI ecosystems,

24:37 but also across non-DPI ecosystems.

24:40 Uh,

24:40 back to you,

24:41 Abhishek.

24:42 Yes.

24:43 So this is one of these

24:45 uh

24:46 imaginations of what a unified identity schema might look like,

24:49 where,

24:50 where we envision

24:51 the outcomes of an ideal identity

24:54 system are you can

24:56 tell

24:57 the entire system once who you are or what your credentials are,

25:00 and you're able to reutilize those credentials through a series of proofs

25:05 across.

25:06 Countless

25:07 transactions and use cases,

25:09 and this is something that

25:11 has been spoken about in the W3C

25:14 uh VC blogs,

25:16 and it's something that

25:18 even we at theinternet have been working on.

25:21 Now the next as Siddharto was speaking about is

25:24 how does this end up

25:26 within standards

25:27 and so one of the first things that uh like we must note

25:31 is that digital public infrastructure is both composed of standards

25:35 and it results in standards.

25:38 So in some cases

25:39 you will have standards like ISO

25:43 8583 or 20,00022 being implemented within

25:47 payment systems,

25:48 but you also have standards around hardware for

25:50 post machines or biometric systems for digital identity

25:53 that get implemented as a base.

25:56 Functioning or utilizable hardware standard in order for biometric verification

26:01 to get conducted

26:02 so it also sets about process and regulatory standards.

26:07 So within India especially we had,

26:09 we hadn't had a privacy act

26:11 when Aadhar had come out and we had built it

26:14 post hoc through,

26:15 uh,

26:15 which,

26:16 which is also noted within some of the litigation within the Supreme Court.

26:20 Now one of the things that we had ended up

26:23 pointing out was

26:24 a what who could access Aadha data and

26:29 what was the sort of ability to access these flows.

26:33 So

26:34 when,

26:34 when,

26:34 when you look at the standards that

26:36 get created out of digital public infrastructure,

26:40 some of these are very context specific.

26:43 Now

26:44 openness of standards and something that has often been spoken about

26:48 where where you have standards

26:50 that could

26:51 be completely open like OA2 or FHA which

26:55 which are aimed at facilitating broad participation

26:59 with the idea that

27:02 they will always result in more innovative outcomes

27:05 and diverse outcomes.

27:08 But proprietary standards also exist and are utilized.

27:12 Governments across the board end up utilizing proprietary standards

27:16 for

27:17 data storage and for data sharing.

27:21 Now this doesn't mean that proprietary standards are bad.

27:24 They provide

27:25 other

27:26 functions like security.

27:28 They provide

27:29 tighter control.

27:30 They provide intellectual property protection

27:33 and

27:34 maybe in certain.

27:36 segments or in purposes.

27:39 The infrastructure

27:41 is

27:42 better when there is limited ecosystem participation,

27:45 so maybe that is fit for purpose for those sorts of

27:49 areas or zones in which.

27:52 Proprietary standards need to be implemented.

27:55 On the whole,

27:56 of course,

27:56 we do note

27:57 that the G20,

27:58 World Bank,

27:59 UNDP,

27:59 IMF,

28:00 global coordinating bodies across the globe,

28:02 endorse open standards,

28:04 and,

28:05 and to that effect,

28:07 we need to look at openness as a spectrum

28:10 where you can

28:11 choose where to be open so long as outcomes

28:15 that

28:16 benefit development

28:18 are achieved by the decisions to stay open.

28:23 So,

28:25 The stages of development in standards despite having been

28:28 top down,

28:29 bottom up,

28:30 having gone and in different places you might see in an ISO whether the W3C

28:37 or now you've seen in the Ethereum Foundation

28:39 and and other public blockchain foundations that exist,

28:43 they generally start in the same manner where we research,

28:46 scope,

28:47 plan the standard,

28:49 create it.

28:50 Create resources for it,

28:52 launch it,

28:53 test it,

28:54 review it,

28:55 see what the impact has been,

28:57 and then

28:58 basis the impacts,

29:00 check it,

29:01 update it,

29:02 and retire it,

29:03 which means that if a standard

29:05 is created.

29:07 The

29:08 part where it needs to be updated in order for it to constantly be reusable

29:12 means that it is an active cost.

29:15 And these are one of the

29:17 Thoughts that need to go in

29:19 when governments or

29:22 anybody is looking at creating digital infrastructure

29:25 while using open standards,

29:27 because you can't just create a standard and hope that it maintains itself.

29:32 The costs need to be thought about,

29:34 built into,

29:35 and,

29:36 and considered when you're looking at infrastructure.

29:40 Now one of the interesting conversations that we've also spoken about within

29:44 our uh paper

29:46 is

29:47 the adoption of SWIFT.

29:50 Swift

29:51 As a payments standard is ubiquitous,

29:54 but 20022 saw a significant

29:59 Pushback in terms of its adoption simply because

30:02 it had an extremely high

30:04 cost of adoption and a payback period that ranged anywhere between 11 to 18 years

30:10 according to whose calculation we saw.

30:12 So this

30:13 gives us an example of how even if standards are.

30:18 Globally adopted and and what would seem adopted in a democratic manner.

30:24 They may not always be for the best intended

30:27 purposes or may not always achieve adoption as intended.

30:33 So this is where we move now into speaking about interoperability,

30:38 and I'll pass the mic back over to Siddharth

30:40 so we can start looking at a first principles framework for DPI and,

30:44 and how do we look at baking interoperability within the stack itself.

30:51 Yeah,

30:51 so I think

30:52 there are different,

30:54 you know,

30:54 especially when it comes to interoperability.

30:57 Uh,

30:57 many times,

30:58 if I look at,

30:59 let's say,

30:59 retail payments as an example,

31:02 many times,

31:03 people often just think about it as,

31:06 hey,

31:06 we need to solve for technical interoperability.

31:09 You're dealing with different APIs,

31:12 different programming languages,

31:14 uh,

31:14 different

31:15 protocol specifications,

31:17 um,

31:18 you know,

31:18 how do you actually make them work together?

31:21 Uh,

31:21 my view is actually interoperability,

31:24 that's the least

31:25 of one's concern.

31:27 Uh,

31:27 especially in an AI-driven world where you can generate code to manage

31:31 different,

31:32 um,

31:33 specifications,

31:34 you know,

31:34 you'll need 45 adapters.

31:36 You can make that happen very easily.

31:39 Often,

31:40 the biggest issues to interoperability come down to legal,

31:43 contractual frameworks and incentive alignment.

31:46 And the,

31:47 the biggest one actually being incentive alignment.

31:50 So in a lot of cases,

31:51 if you take an

31:52 honest look at ecosystems that are not interoperable,

31:56 the reason they're often not interoperable is because

31:58 the incentives to be interoperable just don't exist.

32:02 Uh,

32:02 if they do,

32:03 as we've seen,

32:03 for examples,

32:04 in like hard networks where

32:06 there's an aligned business model towards being interoperable,

32:09 those ecosystems get built very naturally.

32:12 Um,

32:13 with the only caveat being unless interoperability is forced

32:16 from a regulatory pers

32:18 perspective to bring in competition.

32:20 But even in those situations we've seen,

32:22 um,

32:22 if it's not

32:24 incentive aligned,

32:25 that becomes really difficult,

32:27 and you have a lot of back and

32:28 forth between the regulator and the market participants,

32:31 and

32:32 this sort of,

32:32 you know,

32:32 one's strudging along,

32:34 but adoption is really limited.

32:36 They,

32:36 they comply in spirit,

32:37 but,

32:38 you know,

32:38 uh,

32:39 comply

32:40 really in the letter of the law,

32:41 but not really in spirit.

32:43 And,

32:43 and so,

32:44 uh,

32:45 adoption doesn't take up.

32:46 So one point we wanted to bring out is we

32:49 really need to think about interoperability across the entire stack.

32:52 Therefore,

32:53 across

32:54 business and commercial incentives,

32:56 interoperability across legal,

32:58 contractual frameworks,

32:59 and then,

33:00 of course,

33:00 interoperability at the level of,

33:02 of technology.

33:03 So,

33:04 all three of these

33:05 are very critical anytime you're architecting an ecosystem,

33:09 uh,

33:10 when it comes to,

33:11 you know,

33:12 enabling multiple actors,

33:13 often with different self-interests to come together

33:16 in an operable way to

33:18 benefit

33:19 the end

33:20 user.

33:21 Um,

33:21 and as part of that,

33:23 uh,

33:23 then through that journey,

33:24 yes,

33:25 you do need to create different institutional arrangements

33:28 where you can get feedback from these diverse players

33:31 and,

33:31 uh,

33:32 create standards.

33:33 Uh,

33:33 and as Abhishek mentioned,

33:35 some of that may happen bottom up.

33:36 For example,

33:37 if you look at

33:38 the ERC 3643 standard and some of those ERC20 tokens,

33:43 where these have been adopted by.

33:45 financial institutions today,

33:47 but they were essentially community-red.

33:50 Or you have ISO standards,

33:51 which are set

33:52 a bit more formally,

33:54 a bit more top-down,

33:56 uh,

33:56 as well,

33:56 which have then been adopted across the world.

33:58 So,

33:59 you have both dynamics,

34:00 some of it's bottom up,

34:01 some of it's top-down.

34:03 Uh,

34:03 but

34:04 when it comes to,

34:05 you know,

34:05 us looking at interoperability,

34:07 we really need to think through standardization.

34:10 At levels that go beyond just technology.

34:14 And typically,

34:15 technology,

34:15 what we see

34:16 can be solved for

34:18 either through the creation of common adapters or eventually,

34:21 you know,

34:22 it starts off with multiple tech implementations.

34:25 Eventually,

34:25 you can merge with 4 or 5,

34:27 and then you build adapters.

34:28 So,

34:29 some of the heterogeneity 1 may see in early markets,

34:32 early ecosystems and technology.

34:35 It typically ends up converging towards 4 or 5 implementations.

34:39 Um,

34:40 back to you,

34:40 Abhishek on anything else if you want to add.

34:44 Thank you,

34:45 sir.

34:45 So,

34:46 but it's,

34:47 it's a natural segue into what the role of the public sector

34:50 is and how it's constantly changing as we move into maybe what,

34:54 what some people.

34:56 The digital age,

34:57 uh,

34:57 the,

34:58 the public sector significantly shapes DPI outcomes,

35:01 and this is either

35:02 through regulatory frameworks,

35:04 maybe on data privacy standards,

35:06 uh,

35:06 thoughts around what technological sovereignty might look like.

35:09 And,

35:10 and even when it comes down to

35:12 infrastructure specifications down to,

35:15 for example,

35:15 you know,

35:16 how Japan has mandated that

35:18 warm storage be maintained at 10% and cold

35:21 storage be maintained at 90% for ETFs that are

35:24 that are dealing in the 3 crypto markets.

35:27 So public sector responsibilities include managing risks,

35:31 and they basically exist

35:33 to safeguard public interest and promote

35:36 recourse and equity.

35:38 While

35:40 they need to ensure that they don't.

35:43 Place a chilling effect on innovation

35:45 through

35:46 through the oversight mechanisms that they do end up creating

35:49 and so effective DPI regulation

35:51 really

35:53 tells the regulator to look at

35:55 what is the best path for the regulator to be able to shepherd innovation

36:00 so that the outcomes that they generate

36:03 are not harmful for the country or the society as a whole.

36:07 The,

36:08 the broad technological spokes that we're going to have to deal with

36:12 will range from data whether it's privacy and sovereignty,

36:15 hardware and software standards,

36:17 blockchain and DA,

36:18 and,

36:19 and,

36:19 and of course artificial intelligence,

36:21 but

36:22 the happy medium is somewhere of course between,

36:25 uh,

36:25 private,

36:27 uh,

36:27 a pri,

36:27 you know,

36:28 happy private public collaboration.

36:30 And,

36:30 and you might swing

36:32 on either side of the pendulum depending on on the

36:35 specific jurisdictional context that you have more

36:38 towards the state and more towards the

36:40 the light touch and the regulation,

36:42 but,

36:42 but what,

36:43 what seems to be something that we can't look beyond the pale

36:47 is that the future regulator needs to be

36:50 tech savvy.

36:51 They need to encompass technological competence within

36:56 governance models

36:57 so that they're proactive when regulate

37:00 when technology changes and requires regulatory

37:03 alignment or they're intelligent enough

37:06 to understand what requires their regulation

37:09 and what doesn't require them to worry too much

37:12 and so either

37:13 they or someone in the room needs to be technologically savvy

37:17 as.

37:18 We start having more and more conversations around red tech

37:21 soup tech.

37:23 Smart contracts executing compliance and and and a lot,

37:27 uh,

37:28 you know what seemed like futuristic ideas.

37:31 So,

37:32 and this is,

37:33 I'll pass the mic back to Siddharth after this.

37:35 So one of the

37:38 The pieces that we've put out there is a thin waste

37:41 that you need to have

37:42 in order for

37:44 for digital public infrastructure or indeed digital infrastructure

37:47 to be truly interoperable

37:50 is a narrow stem

37:52 and and there is.

37:53 No better example than Adha

37:56 that to

37:58 to describe how the hourglass model

38:00 could be could,

38:01 you know.

38:03 As it was within the internet era,

38:06 we found that you find the same outcomes

38:09 within digital public infrastructure like Aha,

38:12 yes sir.

38:17 Yeah,

38:18 so I think um we can really

38:21 open up for questions.

38:22 In fact,

38:23 before that,

38:23 another example of the Hourglass model,

38:26 uh,

38:27 which we can touch upon is really the internet packet structure,

38:30 uh,

38:30 which you see on the left,

38:31 right?

38:32 And so fundamentally,

38:33 what this means is we went from a world

38:35 pre

38:36 all these open standards on the internet that got created,

38:40 many of which were created.

38:41 by volunteers,

38:42 but now everyone uses it,

38:43 you know,

38:43 right from

38:44 multilateral institutions to large enterprises to small startups,

38:49 uh,

38:49 which are the HTTP,

38:50 WWW,

38:52 um,

38:53 uh,

38:53 packets,

38:54 IP packets,

38:55 uh,

38:55 protocols.

38:56 These were drafted in IETF by individual contributors in many cases.

39:01 Um,

39:02 if you think about that structure as well,

39:03 much.

39:04 Like the other example,

39:05 um,

39:06 pre-TCPIP

39:08 you had different companies providing their own network,

39:11 their own internet.

39:12 Uh,

39:12 and what would happen is this was often bound

39:15 to the hardware as well as to the software.

39:17 So,

39:18 I need to purchase my own networking infrastructure,

39:21 the own device infrastructure,

39:23 own client site,

39:24 software infrastructure like an email client,

39:26 all of it was bundled.

39:28 Then came in

39:29 the TCP IP innovation where you could represent anything as a packet.

39:33 And so today,

39:35 anything from,

39:35 you know,

39:36 the very call that we're having,

39:37 the audio stream,

39:39 the

39:39 images that you're seeing on your screen,

39:41 all of it at the lowest level is converted into a packet,

39:44 sent across the world,

39:46 and then put

39:47 and built back together into

39:49 what you're hearing or seeing on the other end.

39:51 And that is agnostic of,

39:52 you know,

39:53 you could be dialing in through

39:55 stalling.

39:56 So this is flowing through

39:57 satellite communication.

39:59 You could have

40:00 logged into this through a broadband cable,

40:03 you could have logged into this through Wi Fi.

40:05 It's agnostic of the hardware,

40:06 agnostic of the software.

40:08 And so,

40:08 one of the,

40:09 you know,

40:10 most powerful design patterns we've seen when it comes to standard setting

40:14 is really thinking about standards in this algorith.

40:17 model where

40:18 you unlock innovation both on the software side on top,

40:22 as well as

40:23 uh innovation across the hardware ecosystem at the bottom.

40:26 So,

40:27 um,

40:28 um,

40:29 that's it.

40:30 Um,

40:30 uh,

40:30 I will take any quick concluding remarks,

40:32 and then let's,

40:33 let's get to questions.

40:35 Yeah,

40:36 and,

40:36 and

40:37 very short,

40:37 I think our concluding remarks,

40:39 as we've noted in the paper itself,

40:40 is that

40:41 choosing the right balance

40:43 between,

40:44 you know,

40:44 whether you want to choose open or you want to choose closed standards

40:48 is,

40:48 is about empowering local ecosystems.

40:51 It's,

40:52 you prioritize the standards

40:54 that maximize interoperability so that you don't see

40:57 worse off outcomes in the future.

40:58 Short run it might work out,

41:00 but in the long run we don't see that panning out.

41:03 To recognize that there are technology standards

41:06 that that achieve great outcomes,

41:08 but they're not the only be all and end all.

41:10 So that's where the public

41:12 private collaboration in the public sector really needs to come into the fore,

41:15 which is to provide the sort of

41:17 uh

41:18 area or or or or or ecosystem for innovation and for digital.

41:23 Structure to thrive

41:24 and finally we can't let go of power of network effects,

41:28 right?

41:28 The economy that we look at today

41:30 exists because we could start looking at globalized

41:33 money transfer.

41:33 It was because of international card networks,

41:36 because of SWIFT,

41:37 because of

41:37 standards like ISO which made sure that the value couldn't move across globally.

41:42 We're seeing that next step.

41:43 Revolution take place and play out

41:45 across the global and across the technological scale,

41:48 but it requires

41:50 governments that are looking at

41:52 implementing or adopting these sort of technologies

41:56 to,

41:56 to be part of global networks and not,

42:00 uh,

42:01 uh,

42:01 shut themselves away from these sort of networks.

42:04 So

42:04 that's it from our end.

42:06 Uh,

42:06 we're opened up the questions at this point in time.

42:09 Uh,

42:11 thank you so much,

42:12 uh,

42:13 Doc.

42:13 Hello Bhishek.

42:14 Um,

42:15 This is something I think we all are,

42:18 technology is moving so rapidly,

42:20 and I think most of us are way behind the curve

42:24 compared to where you guys are.

42:26 Just to start off with uh uh one

42:29 question.

42:31 I mean,

42:32 this whole

42:33 massive

42:35 sort of promise of

42:36 the digital,

42:37 uh

42:39 Uh,

42:39 the universality,

42:41 uh,

42:42 the scale.

42:45 What

42:47 There is one issue that's been bothering me is,

42:50 are we concentrating risk

42:53 and how have we thought of the security

42:56 standards

42:57 underlying all this

42:58 and that is at the individual level,

43:00 the firm level,

43:01 and now,

43:02 of course,

43:02 the national level because.

43:05 Clearly,

43:06 uh,

43:07 uh,

43:08 and you both are much more aware,

43:11 uh,

43:11 whether it is the weaponization of SWIFT,

43:14 uh,

43:15 you know,

43:16 cutting off

43:18 access,

43:18 etc.

43:18 etc.

43:19 or about hacking,

43:21 cyberattacks,

43:22 all of that.

43:24 Have

43:25 security,

43:26 to what degree

43:28 have security standards been built in?

43:31 And to what

43:40 Yeah,

43:40 so I think a couple of thoughts on that.

43:43 And,

43:43 you know,

43:44 more recently,

43:45 obviously,

43:46 national security is an extremely important part of um

43:51 infrastructure.

43:53 Design,

43:54 development,

43:55 and,

43:55 and purchase considerations.

43:57 Uh,

43:57 the broader question of risk that you mentioned also depends on

44:02 one part is cybersecurity risks.

44:05 Uh,

44:05 and then the second part is also broader systemic risks that come up as,

44:10 you know,

44:10 infrastructure gets adopted at population scale,

44:13 which are like the monopoly effects and so on that you mentioned.

44:17 So if I give you to make it concrete,

44:18 if I give you an example,

44:19 let's say,

44:21 From the ecosystem of UPI,

44:23 uh,

44:23 the way that got architected to

44:26 formally bring in

44:27 hundreds of millions of people into digital payments,

44:29 you could have either done that

44:31 by,

44:32 let's say,

44:34 Maybe creating one app and spreading that to everyone,

44:37 and then you would have

44:38 had all risk concentrated in that one app or one provider,

44:41 which is OK.

44:42 If you look at it,

44:43 for example,

44:43 in,

44:44 in China,

44:45 essentially,

44:45 the mental model was you had WeChat and,

44:47 you know,

44:48 Alipay,

44:49 two app providers owning that ecosystem,

44:51 but eventually,

44:52 the government did step in

44:54 uh through boat control and things like that.

44:56 What we did in the case of UPI was a bit different,

44:59 right?

44:59 So we said,

45:00 hey,

45:01 If you architect an interoperable protocol

45:04 that allows value to move,

45:06 now you can layer this out.

45:08 So you had one,

45:09 a public institution,

45:10 the National Payments Corporation of India,

45:12 running the cost switch,

45:14 and they're responsible for all the,

45:16 you know,

45:17 compliances,

45:18 settlement,

45:19 guarantees,

45:19 etc.

45:21 Then the money

45:22 always flowed

45:23 within the regulated system of banks,

45:26 wallets,

45:28 uh,

45:28 and other regulated stores of value.

45:30 And then they unbundled

45:32 the consumer experience to third-party apps.

45:35 So now these third-party apps could go out and acquire hundreds of millions of users

45:40 or millions of merchants,

45:42 and it was completely interoperable.

45:44 So some of these apps are owned by American companies,

45:47 some of them are Indian companies,

45:48 so on and so forth.

45:49 But tomorrow,

45:50 if,

45:50 you know,

45:51 some of these apps decide to shut off,

45:53 the rest of the infrastructure works,

45:54 and you just,

45:55 anyone can create an app and go live and

45:58 Yeah,

45:58 you can continue to use UPI.

46:00 So there are ways you can start to mitigate and address systemically

46:04 financial risk.

46:05 When it comes to cybersecurity,

46:07 there's a lot of work that happens across

46:09 encryption,

46:10 digital signing of pinpoints,

46:13 so that integrity of every payment transaction is maintained,

46:16 um,

46:17 a lot of continuous monitoring.

46:18 I mean,

46:19 that's a whole other session in terms of the

46:21 depth that one goes into from a cybersecurity perspective.

46:25 But I just want to give you a bit of an architecture as well on

46:28 how we can think about

46:29 the very types of risks,

46:31 but still address it,

46:32 uh,

46:33 and create the right kinds of competition,

46:35 uh,

46:35 ensure you're not dependent in any which way on one sole provider.

46:39 Uh,

46:39 these are some of the sort of tools

46:42 one could employ,

46:43 uh,

46:44 to address the risk that exists.

46:46 Yeah,

46:47 quick 32nd dovetail.

46:48 I'd also think that

46:50 these sort of risks are constantly growing like uh as you close off risk,

46:54 a new one constantly emerges.

46:56 So I think that there is never

46:58 a going in answer where you'll always be able to

47:01 have a 100% certainty or.

47:03 99% certainty

47:05 when you go in,

47:06 but it's,

47:06 it's about being able to create

47:08 good recourse mechanisms so that in case you do face problems or errors,

47:13 you're able to mitigate

47:15 the total fallout of the contagion that does happen from any risk.

47:21 Uh,

47:22 I'm not sure if I can see

47:24 people's hands,

47:24 so if you have any questions,

47:26 please,

47:26 uh,

47:27 do ask.

47:28 Uh

47:35 See,

47:35 uh,

47:36 I'm not sure if I'm

47:37 missing out of it,

47:39 uh.

47:41 Shavi Milo,

47:42 uh,

47:42 I'm not sure if you guys are there.

47:45 So the

47:46 the

47:47 the.

47:48 Yeah,

47:49 there's a question in the chat.

47:51 Oh,

47:51 I can't see it.

47:52 Can you guys read it?

47:55 Yeah.

47:55 So,

47:56 so the question was,

47:57 do you have any thoughts on

47:59 how international regulations

48:01 like anti-money laundering need to be

48:03 coordinated to achieve uh cross-border interoperability?

48:12 Yeah,

48:13 so,

48:13 yeah.

48:15 Yeah,

48:15 I can,

48:15 I can touch on that.

48:16 Uh,

48:16 and this is something that we've looked at quite

48:19 a bit within the context of the internet.

48:22 Um,

48:22 so a couple of points.

48:24 One,

48:25 if you think about the

48:27 EML regulations,

48:28 uh,

48:28 the root of it comes down to identity

48:30 and the ability to create identity proofs to declare who you are,

48:35 what your purpose,

48:36 intent,

48:37 background,

48:37 etc.

48:38 are.

48:39 So now the work that's happening on credentials and wallets

48:42 means that people can have digital credentials

48:46 that they can then share back

48:47 with a regulated entity

48:49 to authenticate and prove themselves or their activities or their business.

48:54 So that's one piece that.

48:55 is important.

48:56 Um,

48:57 and the benefit of doing this is

48:59 in the old world,

49:00 you would have had to either share paper documents

49:02 or you would have had to create this whole new

49:04 centralized database and multiple banks are connecting to it to fetch

49:08 KYC information,

49:10 but that was outdated very quickly.

49:12 Uh,

49:12 in the new world,

49:13 you just issue credentials back to the user.

49:15 The user in a consented manner is just re-sharing that every time they're opening a

49:20 bank account or capital markets account,

49:22 and so on.

49:22 So,

49:23 so one is the user-centric data sharing

49:26 approach that is kicking in across the world.

49:29 Uh,

49:29 the second part of obviously AMLCFT compliance comes in when,

49:33 when,

49:34 when you think about

49:35 the risk

49:36 according to the type of transaction,

49:38 right?

49:38 So,

49:39 obviously,

49:39 if I'm Transferring $10 versus I'm transferring

49:43 $100,000 versus

49:45 $10 million

49:46 the risk varies.

49:48 And so one of the constructs we're seeing come in is the idea of layered proofing.

49:53 And all that means is depending on the risk of a transaction,

49:57 you produce

49:58 additional proofs.

49:59 So for some transactions,

50:00 I could transact anonymously.

50:02 For some transactions up to a certain limit,

50:05 I need to produce

50:06 just one identity document.

50:07 And

50:08 for some,

50:09 I need to produce

50:10 more than one

50:11 document or credential.

50:13 So the idea of layered proofing is a powerful construct

50:16 we're now seeing starting to get applied in different regions.

50:19 The third idea

50:21 is,

50:21 I think,

50:22 and if we,

50:22 we've spent a lot of time within the internet lab on the whole de-risking,

50:27 um,

50:28 uh,

50:28 that's taking place,

50:29 the withdrawal of correspondent banks,

50:31 and,

50:31 you know,

50:31 a large part of that comes to AML CFT compliance costs.

50:35 And so you need infrastructure that dramatically reduces

50:39 the ability to enforce compliance rules,

50:43 to supervise these transactions,

50:44 to generate audit reports,

50:46 all of which in most cases today happens physically and it's very expensive.

50:51 So,

50:52 if you imagine tomorrow in the future,

50:54 have universal rails,

50:55 you will have entrepreneurs building best in class compliance tech apps,

50:59 supervisory tech apps,

51:01 uh,

51:01 so on and so forth.

51:03 That can do your end to end,

51:05 you know,

51:05 monitoring and regulatory surveillance of the

51:09 flows,

51:10 uh,

51:10 all programmatically at low transaction cost.

51:13 If that infrastructure is not available,

51:16 then yes,

51:16 you have to do it in a very bilateral manner.

51:18 People have to write out tenders.

51:20 It takes forever.

51:21 It becomes really expensive.

51:22 So,

51:23 the other angle we are seeing when it comes to compliance globally

51:27 is if they have universal infra that they can

51:30 apply.

51:31 Uh,

51:31 all of these technologies onto,

51:34 uh,

51:34 versus the fragmented siloed infra that exists today,

51:37 then that can really strengthen

51:39 compliance while reducing transaction cost.

51:44 Javi

51:45 Camilo.

51:48 Um,

51:48 uh,

51:48 Milo,

51:49 you wanna go ahead,

51:49 or

51:50 should I,

51:51 should I go?

51:52 Yeah,

51:52 yeah,

51:52 so,

51:53 um.

51:54 So,

51:54 uh,

51:54 and sorry,

51:55 Su and,

51:55 and Abhishek,

51:56 I mean,

51:57 you know,

51:58 abuse me if,

51:58 if,

51:59 if I'm correct here,

52:00 but this is something that,

52:01 you know,

52:01 one of the concerns,

52:02 I guess,

52:03 with,

52:04 with 5G and some of the,

52:05 uh,

52:06 some of the firms in China is that there might be

52:09 a backdoor,

52:11 uh,

52:11 because,

52:11 you know,

52:12 these,

52:12 these companies might be too cozy with,

52:14 with the government.

52:15 And so,

52:16 so,

52:16 here,

52:17 uh,

52:17 you know,

52:17 as we strive for interoperability,

52:21 Um,

52:21 and,

52:22 and,

52:22 and,

52:22 you know,

52:23 common,

52:23 common pipes and,

52:25 and common,

52:25 uh,

52:26 infrastructure.

52:27 So,

52:27 I,

52:27 I wonder whether

52:29 There is a risk of,

52:31 of a rogue

52:32 actor,

52:33 you know,

52:33 the state,

52:34 uh,

52:34 basically,

52:35 you know,

52:35 tapping into these infra infrastructure

52:39 and then,

52:39 um,

52:40 you know,

52:40 for example,

52:41 sorry,

52:41 uh,

52:42 you know,

52:42 for example,

52:42 you know,

52:43 the tax authority

52:44 wanting to have access to all the UPI payments,

52:47 uh,

52:47 basically to,

52:48 to,

52:49 uh,

52:49 you know,

52:50 to,

52:50 To,

52:51 to,

52:51 uh,

52:52 you know,

52:52 to tax,

52:53 uh,

52:53 some of these businesses that are,

52:54 you know,

52:55 where most of their transactions are,

52:57 are,

52:58 um,

52:58 you know,

52:59 are,

52:59 are,

52:59 are done via,

53:00 via this payment system

53:01 or,

53:02 you know,

53:02 in more,

53:03 you know,

53:03 more nefarious ways,

53:05 um,

53:05 you know,

53:05 wanting to use this technology to track,

53:07 track certain minorities or certain individuals,

53:10 right?

53:10 I mean,

53:11 you know,

53:11 they have the identity they can,

53:13 and,

53:13 and then they can,

53:14 you know,

53:14 they can use the this infrastructure to,

53:16 to,

53:16 to track where,

53:17 where people are.

53:18 So,

53:18 so,

53:19 so I guess what do you say to that?

53:20 I mean,

53:20 what do you say to,

53:21 to this concern about

53:23 a backdoor

53:25 that can be used by,

53:26 by the state or by some,

53:28 some rogue agent?

53:29 I,

53:29 I,

53:29 I guess this links a bit to the,

53:31 you know,

53:31 to the concern that the vest had on,

53:33 on security,

53:33 but it's not so much on

53:35 consumer protection,

53:36 but it's more on the,

53:37 well,

53:37 it's it's on the,

53:38 on the,

53:38 on the national security.

53:40 Yeah,

53:40 exactly.

53:41 So,

53:41 yeah,

53:42 I mean,

53:42 and again,

53:43 you know,

53:43 you guys can disabuse me.

53:45 I look,

53:45 I,

53:45 I don't know the topic,

53:46 right?

53:46 And so you can say,

53:47 look,

53:47 this is overblown,

53:48 and,

53:49 you know,

53:49 maybe in the case of 5G or even in the case of UPI,

53:52 this is,

53:52 this is not real because,

53:54 you know,

53:54 there's,

53:54 there's mechanisms in place that,

53:56 that prevent this from happening.

53:57 But,

53:58 but,

53:58 you know,

53:58 just,

53:58 just,

53:59 you know,

53:59 what,

53:59 what,

53:59 what your thoughts are.

54:01 Yeah,

54:01 so I,

54:02 I think I'll take the 5G bit and,

54:03 and I'll let's set up take the UPI bit,

54:06 um,

54:07 so simply on the 5G bit also and,

54:09 and so that you can add on your constant to that,

54:12 uh,

54:13 I,

54:13 I think that it's,

54:14 it's one like you said,

54:15 right?

54:15 So

54:16 it's about the risk and the risk that you're,

54:19 you're willing to be able to take.

54:20 So even if in,

54:21 in a hypothetical that everything that you've heard and read is true.

54:25 There are states that still accept taking Huawei

54:29 hardware and putting it into military facilities,

54:32 right?

54:32 There are states that decide not to put it into military facilities,

54:35 and there are states that completely ban any hardware

54:38 at all being able to enter into the country.

54:40 So it's,

54:41 it's a question of

54:42 where

54:43 and what do you quantify the risk as.

54:47 Um,

54:48 on,

54:49 on the idea that

54:51 whether or not it should be permitted,

54:52 I think the market sort of

54:55 Finds its ways to be able to

54:59 choose alternatives.

55:00 It's not like there is,

55:01 there's only one

55:02 hardware manufacturer that's there for 5G.

55:06 So you have the ability to make a choice and so therefore,

55:09 it always comes down to the choice that you have.

55:12 And,

55:13 and as far as risks around UPI and around data

55:17 accessibility go,

55:18 I think this is one of the reasons why the Finternet Lab also focuses

55:22 a lot on the idea of user centricity of data

55:25 so that you,

55:25 the user is always constantly in the center of all data flows that take place.

55:30 But let's take the most specific questions around the UPI side

55:34 since he had also co-founded and was the CT of Sati,

55:38 which had done a lot of the data exchange work in India.

55:42 Yes,

55:43 I,

55:43 I want to touch upon two things.

55:45 One,

55:45 a bit of the backdoor question.

55:46 I think more broadly,

55:48 the backdoor concern is also there's no point solution to it.

55:52 Um,

55:53 you really need to think about the entire life cycle across,

55:56 you know,

55:56 how that technology has been designed,

55:59 developed,

56:00 uh,

56:00 distributed,

56:01 and,

56:02 uh,

56:02 consumed.

56:03 Um,

56:04 and,

56:04 you know,

56:04 these are

56:06 Really,

56:06 they are far beyond even

56:08 my own,

56:09 uh,

56:09 I would say,

56:10 uh,

56:11 knowledge of the space.

56:12 But if you even look at the recent,

56:14 uh,

56:14 Ukraine attack,

56:15 uh,

56:15 where you,

56:16 you had a whole new,

56:17 or you look at the pager attack,

56:19 uh,

56:19 that happened,

56:20 uh,

56:21 one was using drones,

56:22 the other using pagers.

56:23 So I think there's a whole range where these are extremely legitimate concerns.

56:27 Similarly,

56:28 Within the crypto ecosystem,

56:29 there are often concerns of,

56:31 you may have a smart contract,

56:33 and you start trusting it,

56:34 and tomorrow,

56:35 you know,

56:36 essentially,

56:36 that smart contract could

56:38 have a backdoor where all the funds get drained,

56:41 and there have been examples of this.

56:42 So,

56:43 so I think there are,

56:44 you know,

56:44 many such real-world examples.

56:46 So I don't think the,

56:48 the paranoia is unfounded.

56:50 It's pretty genuine.

56:51 Um,

56:51 the way to address that is really one has to look at the entire life cycle.

56:55 I don't think there's any one single point solution.

56:58 Across the life cycle.

56:59 Obviously,

57:00 there are different interventions around how can you have greater transparency,

57:04 provenance,

57:05 testing,

57:05 certification,

57:07 things like that,

57:08 better cryptographic primitives,

57:09 more research happening in that area

57:11 to address this.

57:13 So those are some of the mechanisms,

57:14 uh,

57:15 I think.

57:15 Uh,

57:16 second is,

57:17 uh,

57:17 to your question,

57:18 when it came to UBI.

57:20 Uh,

57:20 if you look at UPI or,

57:22 uh,

57:22 similarly,

57:23 where you look at most digital public infrastructure,

57:26 they often have a legislative component towards how,

57:28 uh,

57:29 uh,

57:29 and what data can be used and for what purpose.

57:32 So,

57:32 for example,

57:33 in the case of Wadhar,

57:34 there was a very clear,

57:36 uh,

57:36 stipulation that,

57:37 uh,

57:37 government agencies cannot access the data without the user's consent.

57:42 Um,

57:42 and similarly,

57:43 in the case of UPI,

57:44 um,

57:45 uh,

57:45 it's,

57:46 there's no blanket access to one's UPI transactions data,

57:50 uh,

57:50 and it has to fit in within existing legal frameworks that are there,

57:53 whether that's the Payment Settlement Systems Act or the,

57:56 you know,

57:57 Tax Acts that,

57:58 that,

57:58 that are there in India.

58:00 So,

58:00 again,

58:00 that's really a function of.

58:01 Of the,

58:02 the legal structures in different jurisdictions,

58:05 uh,

58:05 that may be in India,

58:06 but that might be different in Thailand or Brazil

58:08 or in other countries that have real-time payment systems.

58:11 Uh,

58:11 so I would have to investigate that,

58:13 uh,

58:13 to,

58:14 to develop a,

58:15 a,

58:15 a view on,

58:16 you know,

58:17 what data can be used and how and what data can't be used for what purpose.

58:22 So,

58:22 because we are almost out of time,

58:24 just to,

58:25 uh I'll just

58:27 read one of the questions,

58:28 and then Milo,

58:29 you can ask yours.

58:31 Uh,

58:32 uh,

58:32 so,

58:32 so the question in the chat is,

58:34 how do you envision

58:37 applications of digital

58:38 technologies to exchange of natural resources between countries?

58:44 For example,

58:44 attaching digital ID ID to natural resources like,

58:49 like water.

58:50 Can policy makers prepare themselves

58:53 for such a future?

58:55 So before you answer that,

58:56 Milo.

58:58 Yeah.

58:59 Uh,

59:00 I,

59:00 I just wanted to

59:02 To get your vision on,

59:03 on the role of,

59:04 uh,

59:05 of developing countries here,

59:07 uh,

59:07 you know,

59:08 some of the example you gave

59:10 like India and Brazil,

59:11 we think about,

59:12 you know,

59:12 large country with some

59:14 state capacity with some

59:15 technical knowledge

59:17 and so

59:18 I wanted to,

59:19 to hear your views on how,

59:21 uh,

59:22 this model could be sort of exported in,

59:25 in,

59:25 in smaller countries with,

59:26 uh,

59:26 you know,

59:27 limited financial resources,

59:28 limited state capacity,

59:29 limited technical knowledge.

59:31 Ah,

59:31 you know how much of this can be just.

59:34 Exported and and how it can be adapted in these contexts.

59:42 So,

59:43 why don't you take Milo's question and I'll take the one in the chat.

59:48 Yeah.

59:48 So,

59:49 um,

59:50 I think the way to look at it is,

59:52 um,

59:53 Especially when it comes to,

59:55 uh,

59:56 smaller,

59:56 more emerging economies that are out there,

59:59 uh,

59:59 and based on some of our work we've been doing in many of these jurisdictions,

1:00:03 uh,

1:00:03 there are two parts.

1:00:04 One,

1:00:05 their participation in standard setting

1:00:07 itself,

1:00:08 right?

1:00:08 And that

1:00:09 is dependent on

1:00:10 what are the governance bodies they have access to.

1:00:13 They have the capacity to participate and contribute,

1:00:16 uh,

1:00:16 or provide feedback,

1:00:18 uh,

1:00:18 all the communities they have access.

1:00:20 To,

1:00:20 in some cases,

1:00:21 it may not be formal governance bodies.

1:00:23 It may be,

1:00:24 you know,

1:00:25 smaller,

1:00:25 more informal communities that are setting standards and become de facto,

1:00:29 much like the internet.

1:00:31 Um,

1:00:32 however,

1:00:32 what we've realized is,

1:00:34 uh,

1:00:34 standard,

1:00:34 a lot of the,

1:00:36 um,

1:00:36 there's interesting parallels,

1:00:38 I think technology versus regulatory standards as well.

1:00:41 So if you think about regulatory standards when it comes to data privacy,

1:00:45 GDPR,

1:00:45 and some of these.

1:00:48 Uh,

1:00:48 what we've seen is eventually that ends

1:00:50 up shutting out smaller coun countries because,

1:00:53 you know,

1:00:53 they don't have the capacity to meet some of these requirements,

1:00:56 uh,

1:00:56 as a result of which,

1:00:58 it becomes really expensive for

1:01:00 the ability to transact with these economies.

1:01:02 And so then you further the divide

1:01:04 to some extent,

1:01:05 and that's often been an unintended consequence of many of these

1:01:08 regulatory standards that may not co-opt,

1:01:11 you know,

1:01:11 a broader part of the society.

1:01:14 Uh,

1:01:14 but on the other hand,

1:01:15 uh,

1:01:16 technology standards like internet,

1:01:17 uh,

1:01:18 works across the board,

1:01:19 but,

1:01:19 you know,

1:01:20 no matter whether it's a rich country or a poor country.

1:01:22 Uh,

1:01:23 obviously,

1:01:23 the distribution and availability of the service is key,

1:01:27 uh,

1:01:27 but at the end of the day,

1:01:28 the,

1:01:28 the protocols aren't really discriminating.

1:01:30 So,

1:01:31 I think one,

1:01:31 there's an interesting difference between regulatory and,

1:01:34 and,

1:01:34 um,

1:01:36 Uh,

1:01:36 technology standards when it comes to that.

1:01:38 Um,

1:01:39 and then the second piece,

1:01:40 uh,

1:01:41 I would,

1:01:41 I would also add,

1:01:43 uh,

1:01:43 when it comes to,

1:01:44 um,

1:01:46 Smaller countries being able to participate

1:01:49 or benefit from this infrastructure

1:01:51 is actually very low transaction costs when it comes to implementation.

1:01:56 So,

1:01:56 one of the biggest gaps that we've seen

1:01:58 is,

1:01:59 you know,

1:01:59 even if they participate in the standard setting,

1:02:01 even if these standards are very generic,

1:02:03 lightweight,

1:02:04 easy to implement,

1:02:06 um,

1:02:06 like you mentioned,

1:02:07 they may not have the market or state capacity to implement this.

1:02:10 And so,

1:02:11 the more universal you make the infrastructure,

1:02:13 the more.

1:02:14 Cost you make it,

1:02:15 uh,

1:02:15 what you start doing is you can unlock potential economies of scale,

1:02:19 because

1:02:20 then what happens is rather than this being deployed.

1:02:23 So today,

1:02:24 traditionally,

1:02:24 you,

1:02:25 you would deploy an ID system from scratch,

1:02:27 a payment system from scratch,

1:02:29 a data sharing system from scratch in many of these countries,

1:02:31 these are

1:02:33 Five-year projects,

1:02:34 you know,

1:02:34 what I find it often take a lot of effort and time.

1:02:37 And then to also get adoption,

1:02:38 it takes even more effort,

1:02:40 uh,

1:02:40 versus some of the thinking we've laid out

1:02:42 in the internet papers essentially to address this,

1:02:45 where,

1:02:46 uh,

1:02:46 if you have universal rails,

1:02:48 you distribute the costs,

1:02:50 you make it

1:02:51 much more of a shared playground where participants can come in,

1:02:54 uh,

1:02:54 and they're OK,

1:02:56 because even if the unit economics in one country doesn't work out,

1:02:59 eventually on the whole,

1:03:01 on the aggregated.

1:03:02 So it's the equivalent of saying,

1:03:04 do you build today a WhatsApp in each country?

1:03:07 No,

1:03:07 you don't.

1:03:08 You can actually create a WhatsApp and distribute that regionally or a,

1:03:12 you know,

1:03:12 equivalent messaging app in other parts of the world.

1:03:15 So,

1:03:16 uh,

1:03:17 sort of my views to,

1:03:18 to your question,

1:03:19 Milo.

1:03:19 Uh,

1:03:19 Abhishek,

1:03:20 maybe you wanna answer the,

1:03:21 uh,

1:03:22 question in the chat,

1:03:23 uh,

1:03:24 and you could also touch on the liability piece,

1:03:26 uh,

1:03:26 as well.

1:03:28 E ledger,

1:03:29 I think,

1:03:29 yeah,

1:03:32 yeah,

1:03:33 so I,

1:03:33 I,

1:03:33 I also think on,

1:03:35 on the idea of how the global South and

1:03:38 developing countries can work,

1:03:40 uh,

1:03:40 like Saddha noted,

1:03:42 if you're coordinating entities or you have,

1:03:45 for example,

1:03:46 how UPS has been adopted in multiple jurisdictions,

1:03:50 we've seen that there are

1:03:52 Arrangements where 11 country who has had learnings

1:03:56 in that sphere can turn up and assist governments

1:03:59 in being able to enable and bring to life some of their own digital infrastructure.

1:04:03 So that's always food for thought,

1:04:05 uh,

1:04:05 coming on to the idea of natural resources,

1:04:08 and it's an interesting thing and something that I think tokenization

1:04:11 has been looking to try and pick up,

1:04:13 and we've seen tokenization use cases

1:04:16 across the board.

1:04:17 We've seen some of them looking at uranium.

1:04:19 Uh,

1:04:20 technology on the whole,

1:04:22 also beyond just ledger technology

1:04:24 has interesting utility.

1:04:28 Which in combination with AI,

1:04:30 DLT,

1:04:31 IOT,

1:04:32 you're starting to see an entire,

1:04:34 you know,

1:04:34 synchronized gamut of technologies that can

1:04:37 execute complex requirements and compliances without having

1:04:41 too much

1:04:42 human intervention.

1:04:43 So some of these examples could be,

1:04:45 uh,

1:04:46 you,

1:04:46 you have.

1:04:48 Countries that have water sharing arrangements

1:04:50 and in order for you to be able to determine what the,

1:04:53 the

1:04:55 The,

1:04:55 the exact amount of water flow,

1:04:57 uh,

1:04:57 needs to be able to go the reservoir needs to release based on,

1:05:01 say,

1:05:01 what are the rainfall that you've had.

1:05:03 These sort of complex calculations can become,

1:05:06 which,

1:05:06 which often become center points of

1:05:08 disputes start becoming more and more trustworthy

1:05:11 because you've got cryptographic signatures.

1:05:13 You've got,

1:05:13 uh,

1:05:15 IOT devices that are capturing data real time,

1:05:17 providing you outcomes.

1:05:19 Something that we've been working on the Finternet

1:05:20 labs and Sara had spoken about the EAJ Institute

1:05:24 is looking at taking

1:05:26 carbon emissions and GHG emissions

1:05:30 across the supply chain and tracking them

1:05:32 based on.

1:05:34 The

1:05:34 ledgers,

1:05:35 and these are conventional ledgers,

1:05:36 your balance,

1:05:37 balance sheets,

1:05:38 your financial statements

1:05:40 prepared by companies

1:05:41 as a part of their annual compliances

1:05:44 and and looking at what these raw

1:05:46 materials as they get utilized within chemical reactions

1:05:51 or

1:05:51 known.

1:05:53 Known chemical reactions,

1:05:55 so you,

1:05:56 you would always be able to quantify scientifically what the

1:05:58 outputs in terms of the greenhouse gasses would be,

1:06:01 how you can attribute attribute causally

1:06:04 to each product that you end up creating and selling,

1:06:08 what their GIG emission equivalent is so that the entire supply chain.

1:06:12 Down to the consumer good and at a jurisdictional level

1:06:16 is able to track and tally what is GIG emission was,

1:06:19 what the jurisdictional tally is,

1:06:21 and it's able to square it off to a degree of certainty,

1:06:25 so.

1:06:26 Some of these efforts which

1:06:29 are now

1:06:32 Being able to unlock

1:06:34 the aims such as

1:06:36 carbon credits or,

1:06:38 or,

1:06:39 you know,

1:06:40 global supply chains that that were harder to do

1:06:42 are now becoming easier because of technologies like this.

1:06:45 I think

1:06:46 that's the way

1:06:47 I would look at

1:06:49 the applications of these technologies.

1:06:52 So that any thoughts you have on this?

1:06:54 No,

1:06:54 we can wrap up,

1:06:56 and we are at time,

1:06:57 uh,

1:06:58 back to you there.

1:07:06 Thank you guys.

1:07:07 Uh,

1:07:07 this has been a fascinating question.

1:07:10 I'm not sure if I understood everything.

1:07:13 So,

1:07:14 but,

1:07:14 uh,

1:07:15 uh,

1:07:15 uh,

1:07:16 thank you for your paper.

1:07:17 Uh,

1:07:17 I'm sure,

1:07:18 uh,

1:07:18 we,

1:07:18 we,

1:07:19 we might,

1:07:19 uh,

1:07:19 if,

1:07:20 if you guys are OK,

1:07:21 uh,

1:07:21 we might

1:07:22 come back to you with,

1:07:23 with more specific questions as we finish writing this,

1:07:26 this report.

1:07:28 But again,

1:07:29 thank you all for joining us

1:07:31 and,

1:07:31 uh,

1:07:31 uh,

1:07:32 we hope we can have you again some,

1:07:34 sometime later.

1:07:36 Thanks.

1:07:36 Bye-bye.

1:07:37 Thank you.

1:07:38 Thank you for having us.

showAllTimestamps
no
transcript
This is just to welcome all of you. This is part of the World Development Report 2025 seminar series. Uh, I'm Devesh Kapoor. I'm the academic lead for the report. And, uh, today, uh, we have a great, uh, Uh, presentation on digital public infrastructure, setting standards with the Hourglass model. And our speakers who've, who've also written a a background paper on this topic, uh, Siddharth Shetty, who's the CEO of Fin Finternet Labs, and the co-creator of the Finternet. I hope he'll tell us a bit about what it is about, uh, and Abhishek. Uh, San K Kritik, uh, who is the, the director of policy and programs of Finternet Labs. Uh, uh, welcome, and, uh, the sort of floor is yours. Thank you that you describe? OK, great, yeah. Uh, so Abhishek, do you want to share the slides, and then I, I'm just doing that. I think it requires some permissions. 01 2nd. I can share from my end. The screen did come up. Uh, I appreciate you. Yeah, I'm back. It required me to quit in order to come back. We know. Uh, there are very unique proposition, but yes. So I hope everybody can see my screen. Yep. Yeah, thanks, uh, Abhishek. So we'll start out with a quick, uh, introduction, and then you can dive into this. Um, so we've spent, I've spent the last 10 years designing and building digital public infrastructure. Um, so I've been part of the team that built out digital identity systems that rolled out to over 1.4 billion people, uh, digital payment systems that are used millions of times a day. Um, uh, I myself architected a, a consented data sharing system that's been used by over 250 million people so far. And, um, more recently, um, As we were building out a lot of these, realized that we are building something that was very purpose-specific, and we needed a much more universal approach, uh, an approach that really empowers both individuals and businesses with their identity, credential, and any type of asset. And, uh, that's when we articulated the Finternet vision. So, uh, I've been working across both the legislative aspects of this infrastructure, as well as the technology. And, um, and so we'll cover both dimensions, uh, in, in today's conversation, including, uh, how the market side of adoption takes place as well. So, the commercial side, the legal, as well as the technology side. Um, I'll hand it over to Abhishek, if you can do a quick introduction as well, and then, um, we can kick it off. Absolutely, thanks for that. So I come from a very different background. I come from a disputes background in lit in law. I practiced in the courts for about 6.5 years before taking a jump into a, a corporate setting but with a technology firm which was looking at tokenization. In in India at that point in time, I think the regulations were at the nascent stage and globally there was what what we've seen at the crypto summer and then the entire crash that it's we've seen after. So it was an interesting time to have dived into the entire web 3 market and it's from there that I had, uh, found out about the finternet met uh then we started working on a couple of projects and, and now we work on a lot of things within the finternet that. Intersect with legal permutations and combinations whether they're regulations, supervisory tech, or whether they're simply how, what do you construe tokenization tokenized assets as back to you sir. Thanks, Abhishek. So, we'll start out, we'll keep the presentation brief. So we'll cover it in about, um, you know, um, uh, 30 minutes, and then we can, uh, dive into a whole range of questions that are there. Um, so, the, a brief thing on the internet before we then dive into also the basis of the paper, which has been about what is this hourglass model towards digital public infrastructure and standard setting. Uh, the Finternet was a paper, you can read more about it at Finternetlab.io that was co-authored by Augustin Carstens, the former general manager of the BIS and Nanar Nalikani. And the main idea behind it was, um, I would distill it into 3 simple uses. Uh, the first you is a user-centric vision. So how do you give users, individuals and businesses control over their identity credentials or assets. The assets could be regulated assets like money, securities. Registered assets like physical property or vehicles, anything that has a registrar behind it. It could be um attested assets, energy resources, gold, silver, commodities, or user-controlled digital assets. And so across this entire spectrum, how do we give control back to users across the world? Um, and what this means is really thinking through two key properties. One is the property of verifiability of these, uh, identity credentials and assets. So because provenance is critical in different flows. And second is the property of transactability, um, which is the ability to transfer these different assets between individuals and businesses. And these could be financial, uh, transactions, like I'm transferring money to you. Uh, but it could also be non-financial transactions where I'm transferring a subset of property rights to you, like ownership of a physical land deed, which in most countries today often involves in-person paper transactions. So, um, uh, what we did is we conceptualized an architecture where users have control. You can do this in a unified manner. So each of these assets are governed by different public authorities. So, how do you deal with their own sovereignty, autonomy considerations, but also unify it for the end user. And then the third was, what is the universal infrastructure we can build? So that's the 3rd you, uh, because we realized that building very purpose-specific infrastructure, sort of in the financial system today, it's like every time you build a new car, we build a new road. And that doesn't scale, that creates, you know, high costs, and that's the reason you have 100 countries, less than 10 million in population. They struggle to adopt uh the advances in financial infrastructure. And our view was, if you can take an approach much like what If you think about it, all of you have a phone in front of you, or are dialed in through a laptop or a computer or desktop, uh, all of it is running on operating systems. And so, there's much more universal technology that can power this, while allowing for, depending on the type of asset, different regulatory constraints to be applied. So that's sort of the broad summary behind the Finternet. And so a lot of these questions of what gets standardized, how do you think about interoperability, so on and so forth. These are questions we've been thinking about as well within the Finternet lab. Um, so we can, you know, take questions around this later, but Abhishek, let's dive into the DPI part and then take it from there. So, I'll spend some context setting on what digital public infrastructure means to us. Um, one is, you know, if you go by what does digital mean, fundamentally, digital means that these are digital interventions, uh, and this is very critical. So, these are digital interventions, they have a digital backbone. It doesn't necessarily mean that the user needs to have a digital channel to access them. So many DPIs work in assisted modes, they work in offline modes. So there are mechanisms for users, even if the user itself doesn't have a digital means, they can access it, but fundamentally, the backbone of it is digital. So, these are digital interventions, but doesn't necessarily mean the user needs to have a smartphone or a digital device to access. The second is, what does public mean in public infrastructure? Many times this often gets construed to mean, OK, all this infrastructure is public owned or public operated, as in, it's government owned or state-owned, state operated, uh, but that's actually not true, and we'll talk about different examples where there's been a strong role of private sector and in fact, in some DPIs, it's only private sector. So, public out here fundamentally means designed in public interest. And so how do you bridge both the public ecosystems and the private ecosystems towards a larger public interest goal? And those public interest goals might be financial inclusion, democratizing credit, health inclusion, so on and so forth. So how do you align incentives, uh, align requirements between both of these ecosystems? And in some countries, you might have a stronger role of the public sector. In some countries, you may have a stronger role of the private sector. Um, and so depending on the different state and market capacity dynamics, as long as they're working towards the larger public interest, which is what the AI is meant to enable all of those different models fall under our view of, of what DPI looks like. So, digital interventions, designed and public interest. And the third part, infrastructure means that these are not, you know, it's not one app or it's not one solution. Uh, it's fundamentally laying the highway, laying the roads, on top of which multiple solutions can coexist, both compete and coexist. Uh, and that's very key, because what you're doing is creating very foundational infrastructure, much like what the internet has created or smartphones have created, that allow for different entrepreneurs, different problems to be solved using common tools. And those common tools, lower transaction cost, therefore, making a wider part of society access it, if, which wouldn't have been possible before. So, that's really the broad view behind DPI and, and through this presentation, as well as in the working paper, uh, we've outlined various different modalities of what it means to have digital interventions, what are the different types of public ownership, operations, models. That are there, and what does infrastructure mean at the level of technology, protocols, standards, so on and so forth. So, of course, the dominant areas DPIs are often thought about, and, and quite a few World Bank reports reference these are in the areas of identity payments and data sharing. Uh, but it goes beyond that. So, even in the world of identity, we see different types of identity constructs becoming important, identity of individuals, identity of organizations, identity of things. So, AI agents. Um, when it, when, when We take, let's say we drill this down even further, when it comes to identity of individuals, you'll have different types of identities, even in that, you may have foundational IDs, like Aadhar, which is, in some sense, establishes a proof. It's an attestation that you are who you claim to be. But then you have different functional IDs that get created on top, like your driver's license, or are you eligible to vote, or are you eligible to, you know, avail this government service or not. Uh, for example, are you eligible for welfare or not? So you have both foundational IDs, as well as functional IDs that come up. And now what we're starting to see across the world is the, the, the universe of identity is broadening to other types of credentials and attestations as well. So, which school did you go to, which university did you go to, where did you work? All of these, which form a critical part of, you know, who you are in a larger sense, are being credentialized and issued back to the user, so that they can reuse it in a whole range of digital journeys. So, That's one building block when it comes to identity. The second building block is payments, the ability to transfer value. This is where real-time payment systems like UPI in India, PayNow in Singapore, PrompPay in Thailand, PI in Brazil come up. Fundamentally, a lot of these real-time payment systems created an interoperable mechanism for money movement. Uh, between banks, but then brought in private sector to create front-end applications, um, um, uh, brought in private sector to onboard merchants, so on and so forth. And then what we've articulated in the Finternet is a much broader version of value transfer that goes even beyond real-time payments. And then the third piece is data sharing, because as people transact digitally, they're generating a lot of data. And so how do you create the right kinds of consent frameworks where data can be fetched from source and then shared in real time, if the user is sharing it as part of a lending transaction or an insurance transaction, so on and so forth. And that's where if you look at open finance efforts in Brazil, Singapore Findex, which gives you an aggregation of different asset standings, or the account aggregator Sharmati framework in India, are all examples of consent-driven data sharing. So these are the three, what I would call foundational DPIs in some sense, but this is just a start. There are many more categories, some of which we'll touch upon in the presentation as well. Um, so, over you, over to you, Abhishek, to go to the next slide and, and sort of cover all the different themes that we've touched upon in the paper. Thanks Sad that. So just to cover up what Siddharth is also saying in, in terms of decisions that governments have ended up taking or do end up having to take in relation to digital public infrastructure because of the population scale implementation, it's very crucial for them to look at regulatory and legal architecting because of the nature and the risk that is involved in some of these infrastructures that are rolled out. But the second and most crucial element is that the definition of what constitutes public infrastructure and what should be defined as public infrastructure will change from decade to decade as technology and as people's needs, wants, and demands do change. So we, as the internet has become more and more accessible, we've noted that digital public infrastructure. And and entire tooling around identity and payments and data exchange especially has become interesting, but in an era, for example, without internet, and this is why one of the questions that we started this entire presentation was that imagine COVID, the entire pandemic without digital infrastructure. It's a really, really daunting task to imagine what it will look like. So moving on to the next piece of this entire conversation and something that we talked about within the paper itself, payments, surprisingly unlike what one would traditionally assume, is the most prevalent digital public infrastructure across the globe now. Conventionally one assumes that you place the identity infrastructure first because you need to know who the client is before you can onboard them to get a bank account and have them be able to access digital public infrastructure, but we found that. Needs must want. So you have the entire set. There are over 95 countries and something that Devish also has been working on in the DPI map which have DPI-like infrastructure and, and several more who are building up their infrastructure to be considered DPI-like. Now in the paper itself we've talked about Brazil, Kenya, and India. To look at 3 specific ways in which the same fast payment system has been implemented. In Kenya we saw that it was a completely private run uh infrastructure until Pesa Link, which was, uh, uh, which was pushed by the central bank. Was brought in as an interoperability tool, so it was a post hoc interoperability and state intervention, whereas in Brazil it was state run from the get-go. They had the entire learnings both from Kenya as well as India to look at in the rearview mirror and India had. Pioneering, of course, the India stack as we call it. Come out with a public-private consortium which involved banks. It involved private participants. It involved advisers and the government reserve Bank coming together to create a consortium, an entity known as NPCI, which would then go about setting up UPI in multiple jurisdictions, most recently with the neighboring countries in Nepal. Right, so We've not, when we're looking at payments, however, There is an interesting conversation that we have to really, really note aside from the fact that fast payment systems are processing maybe over 13 billion transactions, and there's an entire conversation about how the payment infrastructure is actually composed of several components. What is very crucial to to note right now with the stablecoins regulations, the Genius Act currently within Washington. Is that there is an entirely new payments landscape that is opening up with stablecoins. Right, so if you look at some of the The pain points that we still have, we still have a 5.16% cost in the lowest cost receiving region, and we have 7.73% as the highest cost receiving region for any sort of money transfer organization. In Q1 2024. Despite digital payments becoming such a wanted conversation in terms of digital public infrastructure, credit or debit is still one of the major instruments to originate any sort of remittance. And so when you look at remittances that are happening both across borders. Which is one of the biggest friction points that a payment system that has been developed in a silo versus which has been developed in an interoperable manner phases, you see that stablecoins actually from a 6% cost. In 2020 have dropped to a 0.01% cost on some chains in 2024. Now this With the movements of regulation may keep vary, but. Generally we perceive and the trend is that these costs are always going to stay low. The data, the manner in which the, the technology is developed, as well as how the the transactability and the the proofs relating to transactions are stored, means that you're going to have a low cost of compliance constantly. So it's interesting to note that while fiat currency and while traditional payment systems have spent a very long time to reach at the 6 point level. It took stablecoins five years to take that 6%, 6% level and come down to 0.01%. We've also seen that there are decisions that governments need to make, especially when they're looking at. How they want to regulate stablecoins, how they want to regulate CBDCs, and how they want to regulate these instruments which are getting used as currency coolants. There are, of course, and we need to recognize several reg regulatory changes and. Learning curves that we're going to have to take, especially with a large portion of stablecoin utilization still being within DFAT, which stays within a regulatory gray zone as of date. I'll stop here so that for any comments in case you have before I move on to the next slide. No, let's, uh, let's move on a bit quicker, yeah. Yeah So moving on to digital identity, digital identity frameworks, the DPI map indicates 57 countries have a DPI-like system, but one of the most important things we note when digital identity and is is spoken of is that you need to look at its utilization as one of the going in principles when you're rolling out a DPI around digital identity. Which means that you need to calibrate for policy changes before you deploy, whether it's putting up privacy laws, whether it's putting up data exchange laws, whether it's whether it's deciding what compliance is going to look like between your country and another country, especially when you have clients or commerce that occurs cross border. We also need to look at how this identity gets utilized within domestic flows, particularly within. Maybe banking flows or verification flows that involve finance, credit, bank securities, so on and so forth. One of the biggest boons within India and Adhar was that bank account opening became cheaper for banks as well as faster, and we saw an uptick in the total number of bank accounts opened within India due to digital identity systems, and it's a trend that we've noticed across the globe relating to digital identity. So that Yeah. The only other thing I would mention is, um, uh, one of the things which we've spoken about in, in, in the paper is really, some of these are DPI efforts, some of these are DPI like efforts, and some of these are, you know, uh, non-DPI efforts, but are still nonetheless, efforts around standardization and different approaches with which standards can be created, standards can be adopted, the competitive effects, some of the talk. Down, bottom up, incumbent setting it versus not. Um, and so we've really tried to surface, you know, not opine on what's the right approach, but really surface, what are the different trade-offs we've been seeing as technology has been adopted at population scale, uh, both within DPI ecosystems, but also across non-DPI ecosystems. Uh, back to you, Abhishek. Yes. So this is one of these uh imaginations of what a unified identity schema might look like, where, where we envision the outcomes of an ideal identity system are you can tell the entire system once who you are or what your credentials are, and you're able to reutilize those credentials through a series of proofs across. Countless transactions and use cases, and this is something that has been spoken about in the W3C uh VC blogs, and it's something that even we at theinternet have been working on. Now the next as Siddharto was speaking about is how does this end up within standards and so one of the first things that uh like we must note is that digital public infrastructure is both composed of standards and it results in standards. So in some cases you will have standards like ISO 8583 or 20,00022 being implemented within payment systems, but you also have standards around hardware for post machines or biometric systems for digital identity that get implemented as a base. Functioning or utilizable hardware standard in order for biometric verification to get conducted so it also sets about process and regulatory standards. So within India especially we had, we hadn't had a privacy act when Aadhar had come out and we had built it post hoc through, uh, which, which is also noted within some of the litigation within the Supreme Court. Now one of the things that we had ended up pointing out was a what who could access Aadha data and what was the sort of ability to access these flows. So when, when, when you look at the standards that get created out of digital public infrastructure, some of these are very context specific. Now openness of standards and something that has often been spoken about where where you have standards that could be completely open like OA2 or FHA which which are aimed at facilitating broad participation with the idea that they will always result in more innovative outcomes and diverse outcomes. But proprietary standards also exist and are utilized. Governments across the board end up utilizing proprietary standards for data storage and for data sharing. Now this doesn't mean that proprietary standards are bad. They provide other functions like security. They provide tighter control. They provide intellectual property protection and maybe in certain. segments or in purposes. The infrastructure is better when there is limited ecosystem participation, so maybe that is fit for purpose for those sorts of areas or zones in which. Proprietary standards need to be implemented. On the whole, of course, we do note that the G20, World Bank, UNDP, IMF, global coordinating bodies across the globe, endorse open standards, and, and to that effect, we need to look at openness as a spectrum where you can choose where to be open so long as outcomes that benefit development are achieved by the decisions to stay open. So, The stages of development in standards despite having been top down, bottom up, having gone and in different places you might see in an ISO whether the W3C or now you've seen in the Ethereum Foundation and and other public blockchain foundations that exist, they generally start in the same manner where we research, scope, plan the standard, create it. Create resources for it, launch it, test it, review it, see what the impact has been, and then basis the impacts, check it, update it, and retire it, which means that if a standard is created. The part where it needs to be updated in order for it to constantly be reusable means that it is an active cost. And these are one of the Thoughts that need to go in when governments or anybody is looking at creating digital infrastructure while using open standards, because you can't just create a standard and hope that it maintains itself. The costs need to be thought about, built into, and, and considered when you're looking at infrastructure. Now one of the interesting conversations that we've also spoken about within our uh paper is the adoption of SWIFT. Swift As a payments standard is ubiquitous, but 20022 saw a significant Pushback in terms of its adoption simply because it had an extremely high cost of adoption and a payback period that ranged anywhere between 11 to 18 years according to whose calculation we saw. So this gives us an example of how even if standards are. Globally adopted and and what would seem adopted in a democratic manner. They may not always be for the best intended purposes or may not always achieve adoption as intended. So this is where we move now into speaking about interoperability, and I'll pass the mic back over to Siddharth so we can start looking at a first principles framework for DPI and, and how do we look at baking interoperability within the stack itself. Yeah, so I think there are different, you know, especially when it comes to interoperability. Uh, many times, if I look at, let's say, retail payments as an example, many times, people often just think about it as, hey, we need to solve for technical interoperability. You're dealing with different APIs, different programming languages, uh, different protocol specifications, um, you know, how do you actually make them work together? Uh, my view is actually interoperability, that's the least of one's concern. Uh, especially in an AI-driven world where you can generate code to manage different, um, specifications, you know, you'll need 45 adapters. You can make that happen very easily. Often, the biggest issues to interoperability come down to legal, contractual frameworks and incentive alignment. And the, the biggest one actually being incentive alignment. So in a lot of cases, if you take an honest look at ecosystems that are not interoperable, the reason they're often not interoperable is because the incentives to be interoperable just don't exist. Uh, if they do, as we've seen, for examples, in like hard networks where there's an aligned business model towards being interoperable, those ecosystems get built very naturally. Um, with the only caveat being unless interoperability is forced from a regulatory pers perspective to bring in competition. But even in those situations we've seen, um, if it's not incentive aligned, that becomes really difficult, and you have a lot of back and forth between the regulator and the market participants, and this sort of, you know, one's strudging along, but adoption is really limited. They, they comply in spirit, but, you know, uh, comply really in the letter of the law, but not really in spirit. And, and so, uh, adoption doesn't take up. So one point we wanted to bring out is we really need to think about interoperability across the entire stack. Therefore, across business and commercial incentives, interoperability across legal, contractual frameworks, and then, of course, interoperability at the level of, of technology. So, all three of these are very critical anytime you're architecting an ecosystem, uh, when it comes to, you know, enabling multiple actors, often with different self-interests to come together in an operable way to benefit the end user. Um, and as part of that, uh, then through that journey, yes, you do need to create different institutional arrangements where you can get feedback from these diverse players and, uh, create standards. Uh, and as Abhishek mentioned, some of that may happen bottom up. For example, if you look at the ERC 3643 standard and some of those ERC20 tokens, where these have been adopted by. financial institutions today, but they were essentially community-red. Or you have ISO standards, which are set a bit more formally, a bit more top-down, uh, as well, which have then been adopted across the world. So, you have both dynamics, some of it's bottom up, some of it's top-down. Uh, but when it comes to, you know, us looking at interoperability, we really need to think through standardization. At levels that go beyond just technology. And typically, technology, what we see can be solved for either through the creation of common adapters or eventually, you know, it starts off with multiple tech implementations. Eventually, you can merge with 4 or 5, and then you build adapters. So, some of the heterogeneity 1 may see in early markets, early ecosystems and technology. It typically ends up converging towards 4 or 5 implementations. Um, back to you, Abhishek on anything else if you want to add. Thank you, sir. So, but it's, it's a natural segue into what the role of the public sector is and how it's constantly changing as we move into maybe what, what some people. The digital age, uh, the, the public sector significantly shapes DPI outcomes, and this is either through regulatory frameworks, maybe on data privacy standards, uh, thoughts around what technological sovereignty might look like. And, and even when it comes down to infrastructure specifications down to, for example, you know, how Japan has mandated that warm storage be maintained at 10% and cold storage be maintained at 90% for ETFs that are that are dealing in the 3 crypto markets. So public sector responsibilities include managing risks, and they basically exist to safeguard public interest and promote recourse and equity. While they need to ensure that they don't. Place a chilling effect on innovation through through the oversight mechanisms that they do end up creating and so effective DPI regulation really tells the regulator to look at what is the best path for the regulator to be able to shepherd innovation so that the outcomes that they generate are not harmful for the country or the society as a whole. The, the broad technological spokes that we're going to have to deal with will range from data whether it's privacy and sovereignty, hardware and software standards, blockchain and DA, and, and, and of course artificial intelligence, but the happy medium is somewhere of course between, uh, private, uh, a pri, you know, happy private public collaboration. And, and you might swing on either side of the pendulum depending on on the specific jurisdictional context that you have more towards the state and more towards the the light touch and the regulation, but, but what, what seems to be something that we can't look beyond the pale is that the future regulator needs to be tech savvy. They need to encompass technological competence within governance models so that they're proactive when regulate when technology changes and requires regulatory alignment or they're intelligent enough to understand what requires their regulation and what doesn't require them to worry too much and so either they or someone in the room needs to be technologically savvy as. We start having more and more conversations around red tech soup tech. Smart contracts executing compliance and and and a lot, uh, you know what seemed like futuristic ideas. So, and this is, I'll pass the mic back to Siddharth after this. So one of the The pieces that we've put out there is a thin waste that you need to have in order for for digital public infrastructure or indeed digital infrastructure to be truly interoperable is a narrow stem and and there is. No better example than Adha that to to describe how the hourglass model could be could, you know. As it was within the internet era, we found that you find the same outcomes within digital public infrastructure like Aha, yes sir. Yeah, so I think um we can really open up for questions. In fact, before that, another example of the Hourglass model, uh, which we can touch upon is really the internet packet structure, uh, which you see on the left, right? And so fundamentally, what this means is we went from a world pre all these open standards on the internet that got created, many of which were created. by volunteers, but now everyone uses it, you know, right from multilateral institutions to large enterprises to small startups, uh, which are the HTTP, WWW, um, uh, packets, IP packets, uh, protocols. These were drafted in IETF by individual contributors in many cases. Um, if you think about that structure as well, much. Like the other example, um, pre-TCPIP you had different companies providing their own network, their own internet. Uh, and what would happen is this was often bound to the hardware as well as to the software. So, I need to purchase my own networking infrastructure, the own device infrastructure, own client site, software infrastructure like an email client, all of it was bundled. Then came in the TCP IP innovation where you could represent anything as a packet. And so today, anything from, you know, the very call that we're having, the audio stream, the images that you're seeing on your screen, all of it at the lowest level is converted into a packet, sent across the world, and then put and built back together into what you're hearing or seeing on the other end. And that is agnostic of, you know, you could be dialing in through stalling. So this is flowing through satellite communication. You could have logged into this through a broadband cable, you could have logged into this through Wi Fi. It's agnostic of the hardware, agnostic of the software. And so, one of the, you know, most powerful design patterns we've seen when it comes to standard setting is really thinking about standards in this algorith. model where you unlock innovation both on the software side on top, as well as uh innovation across the hardware ecosystem at the bottom. So, um, um, that's it. Um, uh, I will take any quick concluding remarks, and then let's, let's get to questions. Yeah, and, and very short, I think our concluding remarks, as we've noted in the paper itself, is that choosing the right balance between, you know, whether you want to choose open or you want to choose closed standards is, is about empowering local ecosystems. It's, you prioritize the standards that maximize interoperability so that you don't see worse off outcomes in the future. Short run it might work out, but in the long run we don't see that panning out. To recognize that there are technology standards that that achieve great outcomes, but they're not the only be all and end all. So that's where the public private collaboration in the public sector really needs to come into the fore, which is to provide the sort of uh area or or or or or ecosystem for innovation and for digital. Structure to thrive and finally we can't let go of power of network effects, right? The economy that we look at today exists because we could start looking at globalized money transfer. It was because of international card networks, because of SWIFT, because of standards like ISO which made sure that the value couldn't move across globally. We're seeing that next step. Revolution take place and play out across the global and across the technological scale, but it requires governments that are looking at implementing or adopting these sort of technologies to, to be part of global networks and not, uh, uh, shut themselves away from these sort of networks. So that's it from our end. Uh, we're opened up the questions at this point in time. Uh, thank you so much, uh, Doc. Hello Bhishek. Um, This is something I think we all are, technology is moving so rapidly, and I think most of us are way behind the curve compared to where you guys are. Just to start off with uh uh one question. I mean, this whole massive sort of promise of the digital, uh Uh, the universality, uh, the scale. What There is one issue that's been bothering me is, are we concentrating risk and how have we thought of the security standards underlying all this and that is at the individual level, the firm level, and now, of course, the national level because. Clearly, uh, uh, and you both are much more aware, uh, whether it is the weaponization of SWIFT, uh, you know, cutting off access, etc. etc. or about hacking, cyberattacks, all of that. Have security, to what degree have security standards been built in? And to what Yeah, so I think a couple of thoughts on that. And, you know, more recently, obviously, national security is an extremely important part of um infrastructure. Design, development, and, and purchase considerations. Uh, the broader question of risk that you mentioned also depends on one part is cybersecurity risks. Uh, and then the second part is also broader systemic risks that come up as, you know, infrastructure gets adopted at population scale, which are like the monopoly effects and so on that you mentioned. So if I give you to make it concrete, if I give you an example, let's say, From the ecosystem of UPI, uh, the way that got architected to formally bring in hundreds of millions of people into digital payments, you could have either done that by, let's say, Maybe creating one app and spreading that to everyone, and then you would have had all risk concentrated in that one app or one provider, which is OK. If you look at it, for example, in, in China, essentially, the mental model was you had WeChat and, you know, Alipay, two app providers owning that ecosystem, but eventually, the government did step in uh through boat control and things like that. What we did in the case of UPI was a bit different, right? So we said, hey, If you architect an interoperable protocol that allows value to move, now you can layer this out. So you had one, a public institution, the National Payments Corporation of India, running the cost switch, and they're responsible for all the, you know, compliances, settlement, guarantees, etc. Then the money always flowed within the regulated system of banks, wallets, uh, and other regulated stores of value. And then they unbundled the consumer experience to third-party apps. So now these third-party apps could go out and acquire hundreds of millions of users or millions of merchants, and it was completely interoperable. So some of these apps are owned by American companies, some of them are Indian companies, so on and so forth. But tomorrow, if, you know, some of these apps decide to shut off, the rest of the infrastructure works, and you just, anyone can create an app and go live and Yeah, you can continue to use UPI. So there are ways you can start to mitigate and address systemically financial risk. When it comes to cybersecurity, there's a lot of work that happens across encryption, digital signing of pinpoints, so that integrity of every payment transaction is maintained, um, a lot of continuous monitoring. I mean, that's a whole other session in terms of the depth that one goes into from a cybersecurity perspective. But I just want to give you a bit of an architecture as well on how we can think about the very types of risks, but still address it, uh, and create the right kinds of competition, uh, ensure you're not dependent in any which way on one sole provider. Uh, these are some of the sort of tools one could employ, uh, to address the risk that exists. Yeah, quick 32nd dovetail. I'd also think that these sort of risks are constantly growing like uh as you close off risk, a new one constantly emerges. So I think that there is never a going in answer where you'll always be able to have a 100% certainty or. 99% certainty when you go in, but it's, it's about being able to create good recourse mechanisms so that in case you do face problems or errors, you're able to mitigate the total fallout of the contagion that does happen from any risk. Uh, I'm not sure if I can see people's hands, so if you have any questions, please, uh, do ask. Uh See, uh, I'm not sure if I'm missing out of it, uh. Shavi Milo, uh, I'm not sure if you guys are there. So the the the. Yeah, there's a question in the chat. Oh, I can't see it. Can you guys read it? Yeah. So, so the question was, do you have any thoughts on how international regulations like anti-money laundering need to be coordinated to achieve uh cross-border interoperability? Yeah, so, yeah. Yeah, I can, I can touch on that. Uh, and this is something that we've looked at quite a bit within the context of the internet. Um, so a couple of points. One, if you think about the EML regulations, uh, the root of it comes down to identity and the ability to create identity proofs to declare who you are, what your purpose, intent, background, etc. are. So now the work that's happening on credentials and wallets means that people can have digital credentials that they can then share back with a regulated entity to authenticate and prove themselves or their activities or their business. So that's one piece that. is important. Um, and the benefit of doing this is in the old world, you would have had to either share paper documents or you would have had to create this whole new centralized database and multiple banks are connecting to it to fetch KYC information, but that was outdated very quickly. Uh, in the new world, you just issue credentials back to the user. The user in a consented manner is just re-sharing that every time they're opening a bank account or capital markets account, and so on. So, so one is the user-centric data sharing approach that is kicking in across the world. Uh, the second part of obviously AMLCFT compliance comes in when, when, when you think about the risk according to the type of transaction, right? So, obviously, if I'm Transferring $10 versus I'm transferring $100,000 versus $10 million the risk varies. And so one of the constructs we're seeing come in is the idea of layered proofing. And all that means is depending on the risk of a transaction, you produce additional proofs. So for some transactions, I could transact anonymously. For some transactions up to a certain limit, I need to produce just one identity document. And for some, I need to produce more than one document or credential. So the idea of layered proofing is a powerful construct we're now seeing starting to get applied in different regions. The third idea is, I think, and if we, we've spent a lot of time within the internet lab on the whole de-risking, um, uh, that's taking place, the withdrawal of correspondent banks, and, you know, a large part of that comes to AML CFT compliance costs. And so you need infrastructure that dramatically reduces the ability to enforce compliance rules, to supervise these transactions, to generate audit reports, all of which in most cases today happens physically and it's very expensive. So, if you imagine tomorrow in the future, have universal rails, you will have entrepreneurs building best in class compliance tech apps, supervisory tech apps, uh, so on and so forth. That can do your end to end, you know, monitoring and regulatory surveillance of the flows, uh, all programmatically at low transaction cost. If that infrastructure is not available, then yes, you have to do it in a very bilateral manner. People have to write out tenders. It takes forever. It becomes really expensive. So, the other angle we are seeing when it comes to compliance globally is if they have universal infra that they can apply. Uh, all of these technologies onto, uh, versus the fragmented siloed infra that exists today, then that can really strengthen compliance while reducing transaction cost. Javi Camilo. Um, uh, Milo, you wanna go ahead, or should I, should I go? Yeah, yeah, so, um. So, uh, and sorry, Su and, and Abhishek, I mean, you know, abuse me if, if, if I'm correct here, but this is something that, you know, one of the concerns, I guess, with, with 5G and some of the, uh, some of the firms in China is that there might be a backdoor, uh, because, you know, these, these companies might be too cozy with, with the government. And so, so, here, uh, you know, as we strive for interoperability, Um, and, and, and, you know, common, common pipes and, and common, uh, infrastructure. So, I, I wonder whether There is a risk of, of a rogue actor, you know, the state, uh, basically, you know, tapping into these infra infrastructure and then, um, you know, for example, sorry, uh, you know, for example, you know, the tax authority wanting to have access to all the UPI payments, uh, basically to, to, uh, you know, to, To, to, uh, you know, to tax, uh, some of these businesses that are, you know, where most of their transactions are, are, um, you know, are, are, are done via, via this payment system or, you know, in more, you know, more nefarious ways, um, you know, wanting to use this technology to track, track certain minorities or certain individuals, right? I mean, you know, they have the identity they can, and, and then they can, you know, they can use the this infrastructure to, to, to track where, where people are. So, so, so I guess what do you say to that? I mean, what do you say to, to this concern about a backdoor that can be used by, by the state or by some, some rogue agent? I, I, I guess this links a bit to the, you know, to the concern that the vest had on, on security, but it's not so much on consumer protection, but it's more on the, well, it's it's on the, on the, on the national security. Yeah, exactly. So, yeah, I mean, and again, you know, you guys can disabuse me. I look, I, I don't know the topic, right? And so you can say, look, this is overblown, and, you know, maybe in the case of 5G or even in the case of UPI, this is, this is not real because, you know, there's, there's mechanisms in place that, that prevent this from happening. But, but, you know, just, just, you know, what, what, what your thoughts are. Yeah, so I, I think I'll take the 5G bit and, and I'll let's set up take the UPI bit, um, so simply on the 5G bit also and, and so that you can add on your constant to that, uh, I, I think that it's, it's one like you said, right? So it's about the risk and the risk that you're, you're willing to be able to take. So even if in, in a hypothetical that everything that you've heard and read is true. There are states that still accept taking Huawei hardware and putting it into military facilities, right? There are states that decide not to put it into military facilities, and there are states that completely ban any hardware at all being able to enter into the country. So it's, it's a question of where and what do you quantify the risk as. Um, on, on the idea that whether or not it should be permitted, I think the market sort of Finds its ways to be able to choose alternatives. It's not like there is, there's only one hardware manufacturer that's there for 5G. So you have the ability to make a choice and so therefore, it always comes down to the choice that you have. And, and as far as risks around UPI and around data accessibility go, I think this is one of the reasons why the Finternet Lab also focuses a lot on the idea of user centricity of data so that you, the user is always constantly in the center of all data flows that take place. But let's take the most specific questions around the UPI side since he had also co-founded and was the CT of Sati, which had done a lot of the data exchange work in India. Yes, I, I want to touch upon two things. One, a bit of the backdoor question. I think more broadly, the backdoor concern is also there's no point solution to it. Um, you really need to think about the entire life cycle across, you know, how that technology has been designed, developed, uh, distributed, and, uh, consumed. Um, and, you know, these are Really, they are far beyond even my own, uh, I would say, uh, knowledge of the space. But if you even look at the recent, uh, Ukraine attack, uh, where you, you had a whole new, or you look at the pager attack, uh, that happened, uh, one was using drones, the other using pagers. So I think there's a whole range where these are extremely legitimate concerns. Similarly, Within the crypto ecosystem, there are often concerns of, you may have a smart contract, and you start trusting it, and tomorrow, you know, essentially, that smart contract could have a backdoor where all the funds get drained, and there have been examples of this. So, so I think there are, you know, many such real-world examples. So I don't think the, the paranoia is unfounded. It's pretty genuine. Um, the way to address that is really one has to look at the entire life cycle. I don't think there's any one single point solution. Across the life cycle. Obviously, there are different interventions around how can you have greater transparency, provenance, testing, certification, things like that, better cryptographic primitives, more research happening in that area to address this. So those are some of the mechanisms, uh, I think. Uh, second is, uh, to your question, when it came to UBI. Uh, if you look at UPI or, uh, similarly, where you look at most digital public infrastructure, they often have a legislative component towards how, uh, uh, and what data can be used and for what purpose. So, for example, in the case of Wadhar, there was a very clear, uh, stipulation that, uh, government agencies cannot access the data without the user's consent. Um, and similarly, in the case of UPI, um, uh, it's, there's no blanket access to one's UPI transactions data, uh, and it has to fit in within existing legal frameworks that are there, whether that's the Payment Settlement Systems Act or the, you know, Tax Acts that, that, that are there in India. So, again, that's really a function of. Of the, the legal structures in different jurisdictions, uh, that may be in India, but that might be different in Thailand or Brazil or in other countries that have real-time payment systems. Uh, so I would have to investigate that, uh, to, to develop a, a, a view on, you know, what data can be used and how and what data can't be used for what purpose. So, because we are almost out of time, just to, uh I'll just read one of the questions, and then Milo, you can ask yours. Uh, uh, so, so the question in the chat is, how do you envision applications of digital technologies to exchange of natural resources between countries? For example, attaching digital ID ID to natural resources like, like water. Can policy makers prepare themselves for such a future? So before you answer that, Milo. Yeah. Uh, I, I just wanted to To get your vision on, on the role of, uh, of developing countries here, uh, you know, some of the example you gave like India and Brazil, we think about, you know, large country with some state capacity with some technical knowledge and so I wanted to, to hear your views on how, uh, this model could be sort of exported in, in, in smaller countries with, uh, you know, limited financial resources, limited state capacity, limited technical knowledge. Ah, you know how much of this can be just. Exported and and how it can be adapted in these contexts. So, why don't you take Milo's question and I'll take the one in the chat. Yeah. So, um, I think the way to look at it is, um, Especially when it comes to, uh, smaller, more emerging economies that are out there, uh, and based on some of our work we've been doing in many of these jurisdictions, uh, there are two parts. One, their participation in standard setting itself, right? And that is dependent on what are the governance bodies they have access to. They have the capacity to participate and contribute, uh, or provide feedback, uh, all the communities they have access. To, in some cases, it may not be formal governance bodies. It may be, you know, smaller, more informal communities that are setting standards and become de facto, much like the internet. Um, however, what we've realized is, uh, standard, a lot of the, um, there's interesting parallels, I think technology versus regulatory standards as well. So if you think about regulatory standards when it comes to data privacy, GDPR, and some of these. Uh, what we've seen is eventually that ends up shutting out smaller coun countries because, you know, they don't have the capacity to meet some of these requirements, uh, as a result of which, it becomes really expensive for the ability to transact with these economies. And so then you further the divide to some extent, and that's often been an unintended consequence of many of these regulatory standards that may not co-opt, you know, a broader part of the society. Uh, but on the other hand, uh, technology standards like internet, uh, works across the board, but, you know, no matter whether it's a rich country or a poor country. Uh, obviously, the distribution and availability of the service is key, uh, but at the end of the day, the, the protocols aren't really discriminating. So, I think one, there's an interesting difference between regulatory and, and, um, Uh, technology standards when it comes to that. Um, and then the second piece, uh, I would, I would also add, uh, when it comes to, um, Smaller countries being able to participate or benefit from this infrastructure is actually very low transaction costs when it comes to implementation. So, one of the biggest gaps that we've seen is, you know, even if they participate in the standard setting, even if these standards are very generic, lightweight, easy to implement, um, like you mentioned, they may not have the market or state capacity to implement this. And so, the more universal you make the infrastructure, the more. Cost you make it, uh, what you start doing is you can unlock potential economies of scale, because then what happens is rather than this being deployed. So today, traditionally, you, you would deploy an ID system from scratch, a payment system from scratch, a data sharing system from scratch in many of these countries, these are Five-year projects, you know, what I find it often take a lot of effort and time. And then to also get adoption, it takes even more effort, uh, versus some of the thinking we've laid out in the internet papers essentially to address this, where, uh, if you have universal rails, you distribute the costs, you make it much more of a shared playground where participants can come in, uh, and they're OK, because even if the unit economics in one country doesn't work out, eventually on the whole, on the aggregated. So it's the equivalent of saying, do you build today a WhatsApp in each country? No, you don't. You can actually create a WhatsApp and distribute that regionally or a, you know, equivalent messaging app in other parts of the world. So, uh, sort of my views to, to your question, Milo. Uh, Abhishek, maybe you wanna answer the, uh, question in the chat, uh, and you could also touch on the liability piece, uh, as well. E ledger, I think, yeah, yeah, so I, I, I also think on, on the idea of how the global South and developing countries can work, uh, like Saddha noted, if you're coordinating entities or you have, for example, how UPS has been adopted in multiple jurisdictions, we've seen that there are Arrangements where 11 country who has had learnings in that sphere can turn up and assist governments in being able to enable and bring to life some of their own digital infrastructure. So that's always food for thought, uh, coming on to the idea of natural resources, and it's an interesting thing and something that I think tokenization has been looking to try and pick up, and we've seen tokenization use cases across the board. We've seen some of them looking at uranium. Uh, technology on the whole, also beyond just ledger technology has interesting utility. Which in combination with AI, DLT, IOT, you're starting to see an entire, you know, synchronized gamut of technologies that can execute complex requirements and compliances without having too much human intervention. So some of these examples could be, uh, you, you have. Countries that have water sharing arrangements and in order for you to be able to determine what the, the The, the exact amount of water flow, uh, needs to be able to go the reservoir needs to release based on, say, what are the rainfall that you've had. These sort of complex calculations can become, which, which often become center points of disputes start becoming more and more trustworthy because you've got cryptographic signatures. You've got, uh, IOT devices that are capturing data real time, providing you outcomes. Something that we've been working on the Finternet labs and Sara had spoken about the EAJ Institute is looking at taking carbon emissions and GHG emissions across the supply chain and tracking them based on. The ledgers, and these are conventional ledgers, your balance, balance sheets, your financial statements prepared by companies as a part of their annual compliances and and looking at what these raw materials as they get utilized within chemical reactions or known. Known chemical reactions, so you, you would always be able to quantify scientifically what the outputs in terms of the greenhouse gasses would be, how you can attribute attribute causally to each product that you end up creating and selling, what their GIG emission equivalent is so that the entire supply chain. Down to the consumer good and at a jurisdictional level is able to track and tally what is GIG emission was, what the jurisdictional tally is, and it's able to square it off to a degree of certainty, so. Some of these efforts which are now Being able to unlock the aims such as carbon credits or, or, you know, global supply chains that that were harder to do are now becoming easier because of technologies like this. I think that's the way I would look at the applications of these technologies. So that any thoughts you have on this? No, we can wrap up, and we are at time, uh, back to you there. Thank you guys. Uh, this has been a fascinating question. I'm not sure if I understood everything. So, but, uh, uh, uh, thank you for your paper. Uh, I'm sure, uh, we, we, we might, uh, if, if you guys are OK, uh, we might come back to you with, with more specific questions as we finish writing this, this report. But again, thank you all for joining us and, uh, uh, we hope we can have you again some, sometime later. Thanks. Bye-bye. Thank you. Thank you for having us.
showAllTranscripts
no
duration
PT1H7M39S
scene7File
worldbank/WDR2025-Digital_Public_Infrastructure
scene7Domain
https://worldbank.scene7.com/
scene7FileAvs
worldbank/WDR2025-Digital_Public_Infrastructure-AVS
title
WDR2025-Digital Public Infrastructure
description
WDR2025-Digital Public Infrastructure
showTimestampAndTranscript
yes
col-xs-12
col-sm-12
col-md-3
col-lg-3
col-xs-12
col-sm-12
col-md-7
col-lg-7
  • add-style
  • lp-body-content
lp-heading-top-medium
lp-heading-bottom-medium
col-xs-12
col-sm-12
col-md-2
col-lg-2