00:00 This is just to welcome all of you.
00:02 This is part of
00:04 the World Development Report 2025 seminar
00:09 series.
00:10 Uh,
00:10 I'm Devesh Kapoor.
00:11 I'm the academic lead for the report.
00:15 And,
00:15 uh,
00:17 today,
00:17 uh,
00:18 we have a great,
00:19 uh,
00:21 Uh,
00:21 presentation on
00:23 digital public infrastructure,
00:26 setting standards with the Hourglass model.
00:30 And our speakers who've,
00:32 who've also written a a background paper on this topic,
00:37 uh,
00:38 Siddharth
00:38 Shetty,
00:39 who's the CEO
00:41 of
00:41 Fin
00:43 Finternet Labs,
00:45 and the co-creator of the Finternet.
00:47 I hope he'll
00:48 tell us a bit about what it is about,
00:51 uh,
00:52 and
00:52 Abhishek.
00:53 Uh,
00:54 San K
00:54 Kritik,
00:55 uh,
00:56 who is the,
00:57 the director of policy and programs of Finternet Labs.
01:02 Uh,
01:02 uh,
01:02 welcome,
01:03 and,
01:03 uh,
01:04 the sort of floor is yours.
01:07 Thank you
01:16 that you describe?
01:18 OK,
01:18 great,
01:18 yeah.
01:20 Uh,
01:20 so Abhishek,
01:21 do you want to share the slides,
01:22 and then I,
01:24 I'm just doing that.
01:27 I think it requires some permissions.
01:31 01 2nd.
01:54 I can share from my end.
02:18 The screen did come up.
02:20 Uh,
02:20 I appreciate you.
02:22 Yeah,
02:22 I'm back.
02:25 It required me to
02:26 quit in order to come back.
02:31 We know.
02:33 Uh,
02:34 there are very unique
02:36 proposition,
02:37 but yes.
02:38 So I hope everybody can see my screen.
02:41 Yep.
02:44 Yeah,
02:45 thanks,
02:45 uh,
02:45 Abhishek.
02:46 So we'll start out with a quick,
02:47 uh,
02:48 introduction,
02:50 and then you can dive
02:52 into this.
02:53 Um,
02:54 so we've spent,
02:55 I've spent the last 10 years
02:57 designing and building digital public infrastructure.
03:00 Um,
03:01 so I've been part of the team that built
03:02 out digital identity systems that rolled out to over
03:06 1.4 billion people,
03:08 uh,
03:08 digital payment systems that are used millions of times a day.
03:12 Um,
03:13 uh,
03:13 I myself architected a,
03:15 a consented data sharing system
03:17 that's been used by over 250 million people so far.
03:21 And,
03:21 um,
03:22 more recently,
03:24 um,
03:25 As we were building out a lot of these,
03:27 realized that we are building something that was very purpose-specific,
03:31 and we needed a much more universal approach,
03:34 uh,
03:34 an approach that really
03:36 empowers both individuals and businesses with
03:39 their identity,
03:40 credential,
03:40 and any type of asset.
03:42 And,
03:43 uh,
03:43 that's when we articulated the Finternet vision.
03:46 So,
03:47 uh,
03:47 I've been working across both
03:49 the legislative aspects of this infrastructure,
03:51 as well as the technology.
03:53 And,
03:53 um,
03:54 and so we'll cover
03:56 both dimensions,
03:57 uh,
03:58 in,
03:58 in today's conversation,
04:00 including,
04:01 uh,
04:01 how
04:02 the market side of adoption takes place as well.
04:04 So,
04:05 the commercial side,
04:06 the legal,
04:06 as well as the technology side.
04:08 Um,
04:09 I'll hand it over to Abhishek,
04:10 if you can do a quick introduction as well,
04:12 and then,
04:13 um,
04:14 we can kick it off.
04:16 Absolutely,
04:16 thanks for that.
04:17 So I come from a very different background.
04:20 I come from a disputes background in lit in law.
04:24 I practiced in the courts for about 6.5 years before taking a jump into
04:28 a,
04:28 a corporate setting but with a technology firm which was looking at tokenization.
04:33 In in India at that point in time,
04:35 I think the regulations were at the nascent stage and globally there was
04:40 what what we've seen at the crypto summer and
04:42 then the entire crash that it's we've seen after.
04:46 So it was an interesting time to have dived into the
04:48 entire web 3 market and it's from there that I had,
04:51 uh,
04:52 found out about the finternet met uh
04:55 then we started working on a couple of projects and,
04:57 and now we work on a lot of
04:59 things within the finternet that.
05:02 Intersect with
05:04 legal
05:05 permutations and combinations whether they're regulations,
05:08 supervisory tech,
05:10 or whether they're simply how,
05:12 what do you construe tokenization tokenized assets as
05:16 back to you sir.
05:18 Thanks,
05:18 Abhishek.
05:19 So,
05:19 we'll start out,
05:20 we'll keep the presentation brief.
05:22 So we'll cover it in about,
05:24 um,
05:25 you know,
05:26 um,
05:27 uh,
05:27 30
05:28 minutes,
05:28 and then we can,
05:30 uh,
05:30 dive into a whole range of questions that are there.
05:35 Um,
05:35 so,
05:35 the,
05:36 a brief thing on the internet before we then dive into
05:39 also
05:40 the basis of the paper,
05:42 which has been about what is this hourglass
05:44 model towards digital public infrastructure and standard setting.
05:48 Uh,
05:48 the Finternet was a paper,
05:49 you can read more about it at Finternetlab.io
05:53 that was co-authored by Augustin Carstens,
05:55 the
05:56 former general manager of the BIS and Nanar Nalikani.
05:59 And the main idea behind it was,
06:02 um,
06:03 I would distill it into 3 simple
06:05 uses.
06:06 Uh,
06:06 the first you is a user-centric vision.
06:08 So how do you give users,
06:10 individuals and businesses control over their identity credentials or assets.
06:15 The assets could be regulated assets like money,
06:17 securities.
06:19 Registered assets like physical property or vehicles,
06:22 anything that has a registrar behind it.
06:24 It could be
06:25 um
06:26 attested assets,
06:27 energy resources,
06:28 gold,
06:28 silver,
06:29 commodities,
06:30 or
06:30 user-controlled digital assets.
06:32 And so across this entire spectrum,
06:34 how do we give control back
06:36 to users across the world?
06:38 Um,
06:38 and
06:39 what this means is really thinking through two key properties.
06:43 One
06:43 is the property of verifiability
06:46 of these,
06:47 uh,
06:47 identity credentials and assets.
06:49 So because provenance is critical in different flows.
06:52 And second is the property of transactability,
06:55 um,
06:56 which is the ability to transfer these different assets
06:59 between individuals and businesses.
07:01 And
07:01 these could be financial,
07:03 uh,
07:03 transactions,
07:04 like I'm transferring money to you.
07:06 Uh,
07:06 but it could also be non-financial transactions where I'm
07:09 transferring a subset of property rights to you,
07:12 like ownership of a physical land deed,
07:14 which in most countries today often involves
07:17 in-person paper transactions.
07:20 So,
07:20 um,
07:21 uh,
07:21 what we did is we conceptualized an architecture where users have control.
07:26 You can do this in a unified manner.
07:28 So each of these assets are governed by different public authorities.
07:32 So,
07:32 how do you deal with
07:34 their own
07:35 sovereignty,
07:35 autonomy considerations,
07:37 but also
07:38 unify it for the end user.
07:40 And then the third was,
07:42 what is the universal infrastructure we can build?
07:44 So that's the 3rd you,
07:46 uh,
07:46 because we realized that building very purpose-specific infrastructure,
07:50 sort of
07:50 in the financial system today,
07:52 it's like every time you build a new car,
07:54 we build a new road.
07:56 And that doesn't scale,
07:57 that creates,
07:58 you know,
07:59 high costs,
07:59 and that's the reason you have 100 countries,
08:01 less than 10 million in population.
08:04 They struggle to adopt uh the advances in financial infrastructure.
08:08 And our view was,
08:09 if you can take an approach much like what
08:11 If you think about it,
08:12 all of you have a phone in front of you,
08:14 or are dialed in through a laptop or a computer or desktop,
08:18 uh,
08:18 all of it is running on operating systems.
08:20 And so,
08:21 there's much more universal technology that can power this,
08:24 while allowing for,
08:26 depending on the type of asset,
08:28 different regulatory constraints to be applied.
08:30 So that's sort of the broad summary behind the Finternet.
08:33 And so a lot of these questions of what gets standardized,
08:35 how do you think about interoperability,
08:38 so on and so forth.
08:39 These are questions we've been thinking about as well within the Finternet lab.
08:42 Um,
08:43 so we can,
08:43 you know,
08:44 take questions around this
08:46 later,
08:47 but Abhishek,
08:47 let's dive into
08:49 the DPI part and then take it from there.
08:52 So,
08:52 I'll spend some context setting on what digital public infrastructure means to us.
08:57 Um,
08:58 one is,
08:59 you know,
09:00 if you go by what does digital mean,
09:03 fundamentally,
09:04 digital means that these are digital interventions,
09:08 uh,
09:08 and this is very critical.
09:10 So,
09:10 these are digital interventions,
09:12 they have a digital backbone.
09:13 It doesn't necessarily mean that the user
09:16 needs to have a digital channel to access them.
09:19 So many DPIs work in assisted modes,
09:22 they work in offline modes.
09:24 So there are mechanisms for users,
09:26 even if the user itself doesn't have a digital means,
09:29 they can access it,
09:30 but fundamentally,
09:31 the backbone of it
09:33 is digital.
09:33 So,
09:34 these are digital interventions,
09:35 but doesn't necessarily mean the user needs to have a
09:38 smartphone or a
09:39 digital device to access.
09:41 The second is,
09:43 what does public mean in public infrastructure?
09:46 Many times this often gets construed to mean,
09:49 OK,
09:49 all this infrastructure is public owned or public operated,
09:52 as in,
09:53 it's government owned or state-owned,
09:55 state operated,
09:57 uh,
09:57 but that's actually not true,
09:58 and we'll talk about different examples where
10:00 there's been a strong role of private sector and in fact,
10:03 in some DPIs,
10:04 it's only private sector.
10:06 So,
10:07 public out here fundamentally means designed in public interest.
10:11 And so how do you bridge both the public ecosystems and the private ecosystems
10:16 towards a larger public interest goal?
10:19 And those public interest goals might be financial inclusion,
10:22 democratizing credit,
10:24 health inclusion,
10:25 so on and so forth.
10:26 So how do you align incentives,
10:28 uh,
10:29 align requirements between both of these ecosystems?
10:32 And in some countries,
10:33 you might have a stronger role of the public sector.
10:35 In some countries,
10:36 you may have a stronger role of the private sector.
10:38 Um,
10:39 and so depending on the different state and market capacity dynamics,
10:43 as long as they're working towards the larger public interest,
10:47 which is what the
10:48 AI is meant to enable
10:49 all of those different models fall under our view of,
10:52 of what DPI looks like.
10:54 So,
10:54 digital interventions,
10:56 designed and public interest.
10:57 And the third part,
10:58 infrastructure means that these are not,
11:01 you know,
11:01 it's not one app or it's not one solution.
11:05 Uh,
11:05 it's fundamentally laying the highway,
11:07 laying the roads,
11:08 on top of which multiple solutions can coexist,
11:11 both compete
11:12 and coexist.
11:14 Uh,
11:14 and that's very key,
11:15 because what you're doing is
11:17 creating
11:18 very foundational infrastructure,
11:20 much like what the internet has created or smartphones have created,
11:24 that allow for different entrepreneurs,
11:26 different problems to be solved
11:28 using
11:29 common tools.
11:29 And those common tools,
11:31 lower transaction cost,
11:33 therefore,
11:33 making a wider part of society access it,
11:36 if,
11:37 which wouldn't have been possible before.
11:39 So,
11:40 that's really the broad view behind DPI and,
11:42 and
11:44 through this presentation,
11:45 as well as in the working paper,
11:47 uh,
11:47 we've outlined various different modalities of what it means to
11:51 have digital interventions,
11:53 what are the different types of public ownership,
11:56 operations,
11:56 models.
11:57 That are there,
11:57 and what does infrastructure mean at the level of technology,
12:00 protocols,
12:01 standards,
12:02 so on and so forth.
12:03 So,
12:04 of course,
12:05 the dominant areas DPIs are often thought about,
12:08 and,
12:08 and quite a few World Bank reports reference these
12:11 are in the areas of identity payments and data sharing.
12:15 Uh,
12:15 but it goes beyond that.
12:16 So,
12:17 even in the world of identity,
12:19 we see different types of identity constructs becoming important,
12:23 identity of individuals,
12:25 identity of organizations,
12:27 identity of things.
12:28 So,
12:29 AI agents.
12:31 Um,
12:31 when it,
12:32 when,
12:32 when We take,
12:33 let's say
12:34 we drill this down even further,
12:36 when it comes to identity of individuals,
12:38 you'll have different types of identities,
12:40 even in that,
12:41 you may have foundational IDs,
12:43 like Aadhar,
12:44 which is,
12:44 in some sense,
12:45 establishes a proof.
12:46 It's an attestation that
12:48 you are who you claim to be.
12:50 But then you have different functional IDs
12:52 that get created on top,
12:54 like your driver's license,
12:55 or are you eligible to vote,
12:57 or are you eligible to,
12:59 you know,
12:59 avail this government service or not.
13:01 Uh,
13:01 for example,
13:02 are you eligible for welfare or not?
13:04 So you have both foundational IDs,
13:06 as well as functional IDs that come up.
13:09 And now what we're starting to see across the world
13:12 is the,
13:13 the,
13:13 the universe of identity is broadening to
13:17 other types of credentials and attestations as well.
13:19 So,
13:20 which school did you go to,
13:21 which university did you go to,
13:23 where did you work?
13:24 All of these,
13:25 which form a critical part of,
13:27 you know,
13:27 who you are
13:28 in a larger sense,
13:30 are being credentialized and issued back to the user,
13:33 so that they can reuse it
13:35 in a whole range of digital journeys.
13:37 So,
13:37 That's one building block when it comes to identity.
13:41 The second building block is payments,
13:43 the ability to transfer value.
13:45 This is where real-time payment systems like UPI in India,
13:49 PayNow in Singapore,
13:50 PrompPay in Thailand,
13:52 PI in Brazil come up.
13:53 Fundamentally,
13:54 a lot of these real-time payment systems
13:57 created an interoperable mechanism for money movement.
14:01 Uh,
14:02 between banks,
14:03 but then brought in private sector to create front-end applications,
14:07 um,
14:07 um,
14:08 uh,
14:08 brought in private sector to
14:10 onboard merchants,
14:13 so on and so forth.
14:14 And then what we've articulated in the Finternet is a much
14:17 broader version of value transfer that goes even beyond real-time payments.
14:21 And then the third piece is data sharing,
14:23 because as people transact digitally,
14:25 they're generating a lot of data.
14:27 And so how do you create the right kinds of consent frameworks
14:31 where data can be fetched from source
14:34 and then shared in real time,
14:36 if the user is sharing it as part
14:37 of a lending transaction or an insurance transaction,
14:41 so on and so forth.
14:42 And that's where if you look at open finance efforts in Brazil,
14:46 Singapore Findex,
14:48 which gives you an aggregation of different asset standings,
14:51 or the account aggregator Sharmati framework in India,
14:55 are all examples of consent-driven data sharing.
14:58 So these are the three,
14:59 what I would call foundational DPIs in some sense,
15:03 but this is just a start.
15:04 There are many more categories,
15:05 some of which we'll touch upon
15:07 in the presentation as well.
15:09 Um,
15:09 so,
15:10 over you,
15:10 over to you,
15:11 Abhishek,
15:11 to go to the next slide and,
15:13 and sort of cover
15:14 all the different themes that we've touched upon in the paper.
15:19 Thanks Sad that.
15:20 So just to cover up
15:22 what Siddharth is also saying in,
15:23 in terms of decisions that governments have ended up taking or
15:27 do end up having to take in relation to digital public infrastructure
15:31 because of the population scale implementation,
15:34 it's very crucial for them to look at
15:36 regulatory and legal architecting because of the nature
15:40 and the risk that is involved in some of these infrastructures that are rolled out.
15:45 But the second and most crucial element is that
15:50 the definition of what
15:52 constitutes public infrastructure and what should be
15:55 defined as public infrastructure
15:58 will change from decade to decade as
16:01 technology and as
16:04 people's needs,
16:05 wants,
16:05 and demands do change.
16:07 So we,
16:08 as the internet has become more and more accessible,
16:11 we've noted that digital public infrastructure.
16:13 And and entire tooling around identity and payments and data exchange
16:18 especially has become interesting,
16:20 but in an era,
16:22 for example,
16:22 without internet,
16:23 and this is why
16:25 one of the questions that we started
16:27 this entire presentation was that imagine COVID,
16:30 the entire pandemic without
16:32 digital infrastructure.
16:34 It's a really,
16:35 really daunting task to imagine what it will look like.
16:39 So moving on to the next
16:41 piece of this entire conversation and something that
16:43 we talked about within the paper itself,
16:46 payments,
16:47 surprisingly unlike what one would traditionally assume,
16:51 is the most prevalent digital public infrastructure across the globe
16:56 now.
16:59 Conventionally one assumes that you place the identity
17:01 infrastructure first because you need to know who
17:05 the client is before you can onboard them to get a bank account
17:09 and have them be able to access digital public infrastructure,
17:12 but we found that.
17:14 Needs must want.
17:16 So you have
17:18 the entire
17:19 set.
17:19 There are over 95 countries and something that Devish
17:22 also has been working on in the DPI map
17:24 which have DPI-like infrastructure and,
17:28 and several more who are
17:30 building up their infrastructure to be considered DPI-like.
17:34 Now
17:35 in the paper itself we've talked about
17:37 Brazil,
17:38 Kenya,
17:39 and India.
17:40 To look at 3 specific ways in which
17:43 the same fast payment system
17:45 has been implemented.
17:47 In Kenya we saw that it was a completely private run
17:51 uh
17:52 infrastructure until Pesa Link,
17:54 which was,
17:56 uh,
17:57 uh,
17:57 which was pushed by the central bank.
18:00 Was brought in as an interoperability tool,
18:02 so it was a post hoc interoperability and state
18:05 intervention,
18:06 whereas in Brazil it was state run from the get-go.
18:10 They had the entire learnings both from Kenya
18:12 as well as India to look at in the rearview mirror
18:15 and India had.
18:17 Pioneering,
18:18 of course,
18:18 the India stack as we call it.
18:21 Come out with
18:22 a public-private consortium
18:24 which involved banks.
18:26 It involved private participants.
18:28 It involved advisers and the government
18:31 reserve Bank coming together
18:33 to create a consortium,
18:36 an entity known as NPCI,
18:38 which would then
18:39 go about setting up UPI
18:42 in multiple jurisdictions,
18:43 most recently
18:45 with
18:46 the neighboring countries in Nepal.
18:50 Right,
18:50 so
18:52 We've not,
18:52 when we're looking at payments,
18:54 however,
18:56 There is an interesting conversation that we have to really,
18:59 really note
19:00 aside from the fact that fast payment systems
19:02 are processing maybe over 13 billion transactions,
19:06 and there's an entire conversation
19:08 about how the payment infrastructure is actually
19:11 composed of several components.
19:14 What is
19:15 very crucial to
19:17 to
19:17 note right now with the
19:19 stablecoins regulations,
19:21 the Genius Act currently within Washington.
19:24 Is that there is an entirely new payments
19:27 landscape that is opening up
19:29 with stablecoins.
19:31 Right,
19:31 so
19:32 if you look at some of the
19:34 The pain points that we still have,
19:37 we still have a 5.16% cost
19:40 in the lowest cost receiving region,
19:42 and we have 7.73% as the highest cost receiving region
19:46 for any sort of money transfer organization.
19:50 In Q1 2024.
19:53 Despite digital payments becoming such a wanted
19:57 conversation in terms of digital public infrastructure,
20:01 credit or debit is still one of the major instruments
20:05 to originate any sort of remittance.
20:08 And so when you look at remittances that are happening both
20:12 across borders.
20:14 Which is one of the biggest friction points
20:17 that a
20:18 payment system that has been developed in a silo versus
20:22 which has been developed in an interoperable manner phases,
20:25 you see that stablecoins actually from
20:28 a 6% cost.
20:31 In 2020
20:32 have dropped to a
20:35 0.01% cost on some chains
20:39 in 2024.
20:41 Now this
20:43 With the movements of regulation may keep vary,
20:47 but.
20:48 Generally we perceive and the trend is that these costs are always going to stay low.
20:54 The data,
20:54 the manner in which the,
20:56 the technology is developed,
20:58 as well as how
20:59 the the transactability and the the proofs relating to transactions
21:05 are stored,
21:06 means that you're going to have a low cost of compliance
21:09 constantly.
21:10 So it's interesting to note that
21:13 while fiat currency and while traditional
21:16 payment systems
21:18 have spent a very long time
21:20 to reach
21:21 at the 6 point
21:22 level.
21:24 It took stablecoins five years to take that 6%,
21:27 6% level
21:29 and come down to 0.01%.
21:32 We've also seen that there are decisions that governments need to make,
21:36 especially when they're looking at.
21:40 How they want to regulate stablecoins,
21:42 how they want to regulate CBDCs,
21:44 and how they want to regulate these instruments
21:46 which are getting used as currency coolants.
21:49 There are,
21:49 of course,
21:50 and we need to recognize
21:52 several reg
21:53 regulatory changes and.
21:57 Learning curves that we're going to have to take,
21:59 especially with a large portion of stablecoin utilization still being
22:04 within DFAT,
22:05 which stays
22:06 within a regulatory gray zone as of date.
22:10 I'll stop here so that for any comments in case you have
22:13 before I move on to the next slide.
22:14 No,
22:15 let's,
22:15 uh,
22:15 let's move on a bit quicker,
22:17 yeah.
22:18 Yeah
22:19 So moving on to digital identity,
22:21 digital identity frameworks,
22:24 the DPI map indicates 57 countries
22:26 have a DPI-like system,
22:28 but one of the most important things we note when digital identity
22:32 and
22:33 is is spoken of is that
22:36 you need to look at its utilization
22:38 as one of the going in principles when
22:41 you're rolling out a DPI around digital identity.
22:44 Which means that you need to calibrate for policy changes before you deploy,
22:48 whether it's putting up privacy laws,
22:49 whether it's putting up data exchange laws,
22:52 whether it's whether it's
22:54 deciding what compliance is going to look like between
22:58 your country and another country,
23:00 especially when you have clients or commerce that occurs cross border.
23:05 We also need to look at
23:08 how this identity gets utilized within domestic flows,
23:13 particularly within.
23:15 Maybe banking flows or
23:18 verification flows that involve finance,
23:21 credit,
23:22 bank securities,
23:24 so on and so forth.
23:25 One of the biggest boons within
23:27 India and Adhar
23:28 was that bank account opening
23:31 became cheaper for banks as well as faster,
23:33 and we saw an uptick in the total number of bank accounts
23:36 opened within India
23:38 due to digital identity systems,
23:39 and it's a trend that we've noticed across the globe
23:42 relating to digital identity.
23:45 So that
23:48 Yeah.
23:50 The only other thing I would mention is,
23:52 um,
23:54 uh,
23:54 one of the things which we've spoken about in,
23:56 in,
23:57 in the paper is really,
23:59 some of these are DPI efforts,
24:01 some of these are DPI like efforts,
24:03 and some of these are,
24:04 you know,
24:04 uh,
24:05 non-DPI efforts,
24:06 but are still nonetheless,
24:08 efforts around standardization and different approaches
24:11 with which standards can be created,
24:14 standards can be adopted,
24:15 the competitive effects,
24:17 some of the talk.
24:18 Down,
24:18 bottom up,
24:19 incumbent setting it versus not.
24:22 Um,
24:22 and so we've really
24:24 tried to surface,
24:25 you know,
24:25 not opine on what's the right approach,
24:27 but really surface,
24:29 what are the different trade-offs we've been seeing
24:31 as technology has been adopted at population scale,
24:35 uh,
24:35 both within DPI ecosystems,
24:37 but also across non-DPI ecosystems.
24:40 Uh,
24:40 back to you,
24:41 Abhishek.
24:42 Yes.
24:43 So this is one of these
24:45 uh
24:46 imaginations of what a unified identity schema might look like,
24:49 where,
24:50 where we envision
24:51 the outcomes of an ideal identity
24:54 system are you can
24:56 tell
24:57 the entire system once who you are or what your credentials are,
25:00 and you're able to reutilize those credentials through a series of proofs
25:05 across.
25:06 Countless
25:07 transactions and use cases,
25:09 and this is something that
25:11 has been spoken about in the W3C
25:14 uh VC blogs,
25:16 and it's something that
25:18 even we at theinternet have been working on.
25:21 Now the next as Siddharto was speaking about is
25:24 how does this end up
25:26 within standards
25:27 and so one of the first things that uh like we must note
25:31 is that digital public infrastructure is both composed of standards
25:35 and it results in standards.
25:38 So in some cases
25:39 you will have standards like ISO
25:43 8583 or 20,00022 being implemented within
25:47 payment systems,
25:48 but you also have standards around hardware for
25:50 post machines or biometric systems for digital identity
25:53 that get implemented as a base.
25:56 Functioning or utilizable hardware standard in order for biometric verification
26:01 to get conducted
26:02 so it also sets about process and regulatory standards.
26:07 So within India especially we had,
26:09 we hadn't had a privacy act
26:11 when Aadhar had come out and we had built it
26:14 post hoc through,
26:15 uh,
26:15 which,
26:16 which is also noted within some of the litigation within the Supreme Court.
26:20 Now one of the things that we had ended up
26:23 pointing out was
26:24 a what who could access Aadha data and
26:29 what was the sort of ability to access these flows.
26:33 So
26:34 when,
26:34 when,
26:34 when you look at the standards that
26:36 get created out of digital public infrastructure,
26:40 some of these are very context specific.
26:43 Now
26:44 openness of standards and something that has often been spoken about
26:48 where where you have standards
26:50 that could
26:51 be completely open like OA2 or FHA which
26:55 which are aimed at facilitating broad participation
26:59 with the idea that
27:02 they will always result in more innovative outcomes
27:05 and diverse outcomes.
27:08 But proprietary standards also exist and are utilized.
27:12 Governments across the board end up utilizing proprietary standards
27:16 for
27:17 data storage and for data sharing.
27:21 Now this doesn't mean that proprietary standards are bad.
27:24 They provide
27:25 other
27:26 functions like security.
27:28 They provide
27:29 tighter control.
27:30 They provide intellectual property protection
27:33 and
27:34 maybe in certain.
27:36 segments or in purposes.
27:39 The infrastructure
27:41 is
27:42 better when there is limited ecosystem participation,
27:45 so maybe that is fit for purpose for those sorts of
27:49 areas or zones in which.
27:52 Proprietary standards need to be implemented.
27:55 On the whole,
27:56 of course,
27:56 we do note
27:57 that the G20,
27:58 World Bank,
27:59 UNDP,
27:59 IMF,
28:00 global coordinating bodies across the globe,
28:02 endorse open standards,
28:04 and,
28:05 and to that effect,
28:07 we need to look at openness as a spectrum
28:10 where you can
28:11 choose where to be open so long as outcomes
28:15 that
28:16 benefit development
28:18 are achieved by the decisions to stay open.
28:23 So,
28:25 The stages of development in standards despite having been
28:28 top down,
28:29 bottom up,
28:30 having gone and in different places you might see in an ISO whether the W3C
28:37 or now you've seen in the Ethereum Foundation
28:39 and and other public blockchain foundations that exist,
28:43 they generally start in the same manner where we research,
28:46 scope,
28:47 plan the standard,
28:49 create it.
28:50 Create resources for it,
28:52 launch it,
28:53 test it,
28:54 review it,
28:55 see what the impact has been,
28:57 and then
28:58 basis the impacts,
29:00 check it,
29:01 update it,
29:02 and retire it,
29:03 which means that if a standard
29:05 is created.
29:07 The
29:08 part where it needs to be updated in order for it to constantly be reusable
29:12 means that it is an active cost.
29:15 And these are one of the
29:17 Thoughts that need to go in
29:19 when governments or
29:22 anybody is looking at creating digital infrastructure
29:25 while using open standards,
29:27 because you can't just create a standard and hope that it maintains itself.
29:32 The costs need to be thought about,
29:34 built into,
29:35 and,
29:36 and considered when you're looking at infrastructure.
29:40 Now one of the interesting conversations that we've also spoken about within
29:44 our uh paper
29:46 is
29:47 the adoption of SWIFT.
29:50 Swift
29:51 As a payments standard is ubiquitous,
29:54 but 20022 saw a significant
29:59 Pushback in terms of its adoption simply because
30:02 it had an extremely high
30:04 cost of adoption and a payback period that ranged anywhere between 11 to 18 years
30:10 according to whose calculation we saw.
30:12 So this
30:13 gives us an example of how even if standards are.
30:18 Globally adopted and and what would seem adopted in a democratic manner.
30:24 They may not always be for the best intended
30:27 purposes or may not always achieve adoption as intended.
30:33 So this is where we move now into speaking about interoperability,
30:38 and I'll pass the mic back over to Siddharth
30:40 so we can start looking at a first principles framework for DPI and,
30:44 and how do we look at baking interoperability within the stack itself.
30:51 Yeah,
30:51 so I think
30:52 there are different,
30:54 you know,
30:54 especially when it comes to interoperability.
30:57 Uh,
30:57 many times,
30:58 if I look at,
30:59 let's say,
30:59 retail payments as an example,
31:02 many times,
31:03 people often just think about it as,
31:06 hey,
31:06 we need to solve for technical interoperability.
31:09 You're dealing with different APIs,
31:12 different programming languages,
31:14 uh,
31:14 different
31:15 protocol specifications,
31:17 um,
31:18 you know,
31:18 how do you actually make them work together?
31:21 Uh,
31:21 my view is actually interoperability,
31:24 that's the least
31:25 of one's concern.
31:27 Uh,
31:27 especially in an AI-driven world where you can generate code to manage
31:31 different,
31:32 um,
31:33 specifications,
31:34 you know,
31:34 you'll need 45 adapters.
31:36 You can make that happen very easily.
31:39 Often,
31:40 the biggest issues to interoperability come down to legal,
31:43 contractual frameworks and incentive alignment.
31:46 And the,
31:47 the biggest one actually being incentive alignment.
31:50 So in a lot of cases,
31:51 if you take an
31:52 honest look at ecosystems that are not interoperable,
31:56 the reason they're often not interoperable is because
31:58 the incentives to be interoperable just don't exist.
32:02 Uh,
32:02 if they do,
32:03 as we've seen,
32:03 for examples,
32:04 in like hard networks where
32:06 there's an aligned business model towards being interoperable,
32:09 those ecosystems get built very naturally.
32:12 Um,
32:13 with the only caveat being unless interoperability is forced
32:16 from a regulatory pers
32:18 perspective to bring in competition.
32:20 But even in those situations we've seen,
32:22 um,
32:22 if it's not
32:24 incentive aligned,
32:25 that becomes really difficult,
32:27 and you have a lot of back and
32:28 forth between the regulator and the market participants,
32:31 and
32:32 this sort of,
32:32 you know,
32:32 one's strudging along,
32:34 but adoption is really limited.
32:36 They,
32:36 they comply in spirit,
32:37 but,
32:38 you know,
32:38 uh,
32:39 comply
32:40 really in the letter of the law,
32:41 but not really in spirit.
32:43 And,
32:43 and so,
32:44 uh,
32:45 adoption doesn't take up.
32:46 So one point we wanted to bring out is we
32:49 really need to think about interoperability across the entire stack.
32:52 Therefore,
32:53 across
32:54 business and commercial incentives,
32:56 interoperability across legal,
32:58 contractual frameworks,
32:59 and then,
33:00 of course,
33:00 interoperability at the level of,
33:02 of technology.
33:03 So,
33:04 all three of these
33:05 are very critical anytime you're architecting an ecosystem,
33:09 uh,
33:10 when it comes to,
33:11 you know,
33:12 enabling multiple actors,
33:13 often with different self-interests to come together
33:16 in an operable way to
33:18 benefit
33:19 the end
33:20 user.
33:21 Um,
33:21 and as part of that,
33:23 uh,
33:23 then through that journey,
33:24 yes,
33:25 you do need to create different institutional arrangements
33:28 where you can get feedback from these diverse players
33:31 and,
33:31 uh,
33:32 create standards.
33:33 Uh,
33:33 and as Abhishek mentioned,
33:35 some of that may happen bottom up.
33:36 For example,
33:37 if you look at
33:38 the ERC 3643 standard and some of those ERC20 tokens,
33:43 where these have been adopted by.
33:45 financial institutions today,
33:47 but they were essentially community-red.
33:50 Or you have ISO standards,
33:51 which are set
33:52 a bit more formally,
33:54 a bit more top-down,
33:56 uh,
33:56 as well,
33:56 which have then been adopted across the world.
33:58 So,
33:59 you have both dynamics,
34:00 some of it's bottom up,
34:01 some of it's top-down.
34:03 Uh,
34:03 but
34:04 when it comes to,
34:05 you know,
34:05 us looking at interoperability,
34:07 we really need to think through standardization.
34:10 At levels that go beyond just technology.
34:14 And typically,
34:15 technology,
34:15 what we see
34:16 can be solved for
34:18 either through the creation of common adapters or eventually,
34:21 you know,
34:22 it starts off with multiple tech implementations.
34:25 Eventually,
34:25 you can merge with 4 or 5,
34:27 and then you build adapters.
34:28 So,
34:29 some of the heterogeneity 1 may see in early markets,
34:32 early ecosystems and technology.
34:35 It typically ends up converging towards 4 or 5 implementations.
34:39 Um,
34:40 back to you,
34:40 Abhishek on anything else if you want to add.
34:44 Thank you,
34:45 sir.
34:45 So,
34:46 but it's,
34:47 it's a natural segue into what the role of the public sector
34:50 is and how it's constantly changing as we move into maybe what,
34:54 what some people.
34:56 The digital age,
34:57 uh,
34:57 the,
34:58 the public sector significantly shapes DPI outcomes,
35:01 and this is either
35:02 through regulatory frameworks,
35:04 maybe on data privacy standards,
35:06 uh,
35:06 thoughts around what technological sovereignty might look like.
35:09 And,
35:10 and even when it comes down to
35:12 infrastructure specifications down to,
35:15 for example,
35:15 you know,
35:16 how Japan has mandated that
35:18 warm storage be maintained at 10% and cold
35:21 storage be maintained at 90% for ETFs that are
35:24 that are dealing in the 3 crypto markets.
35:27 So public sector responsibilities include managing risks,
35:31 and they basically exist
35:33 to safeguard public interest and promote
35:36 recourse and equity.
35:38 While
35:40 they need to ensure that they don't.
35:43 Place a chilling effect on innovation
35:45 through
35:46 through the oversight mechanisms that they do end up creating
35:49 and so effective DPI regulation
35:51 really
35:53 tells the regulator to look at
35:55 what is the best path for the regulator to be able to shepherd innovation
36:00 so that the outcomes that they generate
36:03 are not harmful for the country or the society as a whole.
36:07 The,
36:08 the broad technological spokes that we're going to have to deal with
36:12 will range from data whether it's privacy and sovereignty,
36:15 hardware and software standards,
36:17 blockchain and DA,
36:18 and,
36:19 and,
36:19 and of course artificial intelligence,
36:21 but
36:22 the happy medium is somewhere of course between,
36:25 uh,
36:25 private,
36:27 uh,
36:27 a pri,
36:27 you know,
36:28 happy private public collaboration.
36:30 And,
36:30 and you might swing
36:32 on either side of the pendulum depending on on the
36:35 specific jurisdictional context that you have more
36:38 towards the state and more towards the
36:40 the light touch and the regulation,
36:42 but,
36:42 but what,
36:43 what seems to be something that we can't look beyond the pale
36:47 is that the future regulator needs to be
36:50 tech savvy.
36:51 They need to encompass technological competence within
36:56 governance models
36:57 so that they're proactive when regulate
37:00 when technology changes and requires regulatory
37:03 alignment or they're intelligent enough
37:06 to understand what requires their regulation
37:09 and what doesn't require them to worry too much
37:12 and so either
37:13 they or someone in the room needs to be technologically savvy
37:17 as.
37:18 We start having more and more conversations around red tech
37:21 soup tech.
37:23 Smart contracts executing compliance and and and a lot,
37:27 uh,
37:28 you know what seemed like futuristic ideas.
37:31 So,
37:32 and this is,
37:33 I'll pass the mic back to Siddharth after this.
37:35 So one of the
37:38 The pieces that we've put out there is a thin waste
37:41 that you need to have
37:42 in order for
37:44 for digital public infrastructure or indeed digital infrastructure
37:47 to be truly interoperable
37:50 is a narrow stem
37:52 and and there is.
37:53 No better example than Adha
37:56 that to
37:58 to describe how the hourglass model
38:00 could be could,
38:01 you know.
38:03 As it was within the internet era,
38:06 we found that you find the same outcomes
38:09 within digital public infrastructure like Aha,
38:12 yes sir.
38:17 Yeah,
38:18 so I think um we can really
38:21 open up for questions.
38:22 In fact,
38:23 before that,
38:23 another example of the Hourglass model,
38:26 uh,
38:27 which we can touch upon is really the internet packet structure,
38:30 uh,
38:30 which you see on the left,
38:31 right?
38:32 And so fundamentally,
38:33 what this means is we went from a world
38:35 pre
38:36 all these open standards on the internet that got created,
38:40 many of which were created.
38:41 by volunteers,
38:42 but now everyone uses it,
38:43 you know,
38:43 right from
38:44 multilateral institutions to large enterprises to small startups,
38:49 uh,
38:49 which are the HTTP,
38:50 WWW,
38:52 um,
38:53 uh,
38:53 packets,
38:54 IP packets,
38:55 uh,
38:55 protocols.
38:56 These were drafted in IETF by individual contributors in many cases.
39:01 Um,
39:02 if you think about that structure as well,
39:03 much.
39:04 Like the other example,
39:05 um,
39:06 pre-TCPIP
39:08 you had different companies providing their own network,
39:11 their own internet.
39:12 Uh,
39:12 and what would happen is this was often bound
39:15 to the hardware as well as to the software.
39:17 So,
39:18 I need to purchase my own networking infrastructure,
39:21 the own device infrastructure,
39:23 own client site,
39:24 software infrastructure like an email client,
39:26 all of it was bundled.
39:28 Then came in
39:29 the TCP IP innovation where you could represent anything as a packet.
39:33 And so today,
39:35 anything from,
39:35 you know,
39:36 the very call that we're having,
39:37 the audio stream,
39:39 the
39:39 images that you're seeing on your screen,
39:41 all of it at the lowest level is converted into a packet,
39:44 sent across the world,
39:46 and then put
39:47 and built back together into
39:49 what you're hearing or seeing on the other end.
39:51 And that is agnostic of,
39:52 you know,
39:53 you could be dialing in through
39:55 stalling.
39:56 So this is flowing through
39:57 satellite communication.
39:59 You could have
40:00 logged into this through a broadband cable,
40:03 you could have logged into this through Wi Fi.
40:05 It's agnostic of the hardware,
40:06 agnostic of the software.
40:08 And so,
40:08 one of the,
40:09 you know,
40:10 most powerful design patterns we've seen when it comes to standard setting
40:14 is really thinking about standards in this algorith.
40:17 model where
40:18 you unlock innovation both on the software side on top,
40:22 as well as
40:23 uh innovation across the hardware ecosystem at the bottom.
40:26 So,
40:27 um,
40:28 um,
40:29 that's it.
40:30 Um,
40:30 uh,
40:30 I will take any quick concluding remarks,
40:32 and then let's,
40:33 let's get to questions.
40:35 Yeah,
40:36 and,
40:36 and
40:37 very short,
40:37 I think our concluding remarks,
40:39 as we've noted in the paper itself,
40:40 is that
40:41 choosing the right balance
40:43 between,
40:44 you know,
40:44 whether you want to choose open or you want to choose closed standards
40:48 is,
40:48 is about empowering local ecosystems.
40:51 It's,
40:52 you prioritize the standards
40:54 that maximize interoperability so that you don't see
40:57 worse off outcomes in the future.
40:58 Short run it might work out,
41:00 but in the long run we don't see that panning out.
41:03 To recognize that there are technology standards
41:06 that that achieve great outcomes,
41:08 but they're not the only be all and end all.
41:10 So that's where the public
41:12 private collaboration in the public sector really needs to come into the fore,
41:15 which is to provide the sort of
41:17 uh
41:18 area or or or or or ecosystem for innovation and for digital.
41:23 Structure to thrive
41:24 and finally we can't let go of power of network effects,
41:28 right?
41:28 The economy that we look at today
41:30 exists because we could start looking at globalized
41:33 money transfer.
41:33 It was because of international card networks,
41:36 because of SWIFT,
41:37 because of
41:37 standards like ISO which made sure that the value couldn't move across globally.
41:42 We're seeing that next step.
41:43 Revolution take place and play out
41:45 across the global and across the technological scale,
41:48 but it requires
41:50 governments that are looking at
41:52 implementing or adopting these sort of technologies
41:56 to,
41:56 to be part of global networks and not,
42:00 uh,
42:01 uh,
42:01 shut themselves away from these sort of networks.
42:04 So
42:04 that's it from our end.
42:06 Uh,
42:06 we're opened up the questions at this point in time.
42:09 Uh,
42:11 thank you so much,
42:12 uh,
42:13 Doc.
42:13 Hello Bhishek.
42:14 Um,
42:15 This is something I think we all are,
42:18 technology is moving so rapidly,
42:20 and I think most of us are way behind the curve
42:24 compared to where you guys are.
42:26 Just to start off with uh uh one
42:29 question.
42:31 I mean,
42:32 this whole
42:33 massive
42:35 sort of promise of
42:36 the digital,
42:37 uh
42:39 Uh,
42:39 the universality,
42:41 uh,
42:42 the scale.
42:45 What
42:47 There is one issue that's been bothering me is,
42:50 are we concentrating risk
42:53 and how have we thought of the security
42:56 standards
42:57 underlying all this
42:58 and that is at the individual level,
43:00 the firm level,
43:01 and now,
43:02 of course,
43:02 the national level because.
43:05 Clearly,
43:06 uh,
43:07 uh,
43:08 and you both are much more aware,
43:11 uh,
43:11 whether it is the weaponization of SWIFT,
43:14 uh,
43:15 you know,
43:16 cutting off
43:18 access,
43:18 etc.
43:18 etc.
43:19 or about hacking,
43:21 cyberattacks,
43:22 all of that.
43:24 Have
43:25 security,
43:26 to what degree
43:28 have security standards been built in?
43:31 And to what
43:40 Yeah,
43:40 so I think a couple of thoughts on that.
43:43 And,
43:43 you know,
43:44 more recently,
43:45 obviously,
43:46 national security is an extremely important part of um
43:51 infrastructure.
43:53 Design,
43:54 development,
43:55 and,
43:55 and purchase considerations.
43:57 Uh,
43:57 the broader question of risk that you mentioned also depends on
44:02 one part is cybersecurity risks.
44:05 Uh,
44:05 and then the second part is also broader systemic risks that come up as,
44:10 you know,
44:10 infrastructure gets adopted at population scale,
44:13 which are like the monopoly effects and so on that you mentioned.
44:17 So if I give you to make it concrete,
44:18 if I give you an example,
44:19 let's say,
44:21 From the ecosystem of UPI,
44:23 uh,
44:23 the way that got architected to
44:26 formally bring in
44:27 hundreds of millions of people into digital payments,
44:29 you could have either done that
44:31 by,
44:32 let's say,
44:34 Maybe creating one app and spreading that to everyone,
44:37 and then you would have
44:38 had all risk concentrated in that one app or one provider,
44:41 which is OK.
44:42 If you look at it,
44:43 for example,
44:43 in,
44:44 in China,
44:45 essentially,
44:45 the mental model was you had WeChat and,
44:47 you know,
44:48 Alipay,
44:49 two app providers owning that ecosystem,
44:51 but eventually,
44:52 the government did step in
44:54 uh through boat control and things like that.
44:56 What we did in the case of UPI was a bit different,
44:59 right?
44:59 So we said,
45:00 hey,
45:01 If you architect an interoperable protocol
45:04 that allows value to move,
45:06 now you can layer this out.
45:08 So you had one,
45:09 a public institution,
45:10 the National Payments Corporation of India,
45:12 running the cost switch,
45:14 and they're responsible for all the,
45:16 you know,
45:17 compliances,
45:18 settlement,
45:19 guarantees,
45:19 etc.
45:21 Then the money
45:22 always flowed
45:23 within the regulated system of banks,
45:26 wallets,
45:28 uh,
45:28 and other regulated stores of value.
45:30 And then they unbundled
45:32 the consumer experience to third-party apps.
45:35 So now these third-party apps could go out and acquire hundreds of millions of users
45:40 or millions of merchants,
45:42 and it was completely interoperable.
45:44 So some of these apps are owned by American companies,
45:47 some of them are Indian companies,
45:48 so on and so forth.
45:49 But tomorrow,
45:50 if,
45:50 you know,
45:51 some of these apps decide to shut off,
45:53 the rest of the infrastructure works,
45:54 and you just,
45:55 anyone can create an app and go live and
45:58 Yeah,
45:58 you can continue to use UPI.
46:00 So there are ways you can start to mitigate and address systemically
46:04 financial risk.
46:05 When it comes to cybersecurity,
46:07 there's a lot of work that happens across
46:09 encryption,
46:10 digital signing of pinpoints,
46:13 so that integrity of every payment transaction is maintained,
46:16 um,
46:17 a lot of continuous monitoring.
46:18 I mean,
46:19 that's a whole other session in terms of the
46:21 depth that one goes into from a cybersecurity perspective.
46:25 But I just want to give you a bit of an architecture as well on
46:28 how we can think about
46:29 the very types of risks,
46:31 but still address it,
46:32 uh,
46:33 and create the right kinds of competition,
46:35 uh,
46:35 ensure you're not dependent in any which way on one sole provider.
46:39 Uh,
46:39 these are some of the sort of tools
46:42 one could employ,
46:43 uh,
46:44 to address the risk that exists.
46:46 Yeah,
46:47 quick 32nd dovetail.
46:48 I'd also think that
46:50 these sort of risks are constantly growing like uh as you close off risk,
46:54 a new one constantly emerges.
46:56 So I think that there is never
46:58 a going in answer where you'll always be able to
47:01 have a 100% certainty or.
47:03 99% certainty
47:05 when you go in,
47:06 but it's,
47:06 it's about being able to create
47:08 good recourse mechanisms so that in case you do face problems or errors,
47:13 you're able to mitigate
47:15 the total fallout of the contagion that does happen from any risk.
47:21 Uh,
47:22 I'm not sure if I can see
47:24 people's hands,
47:24 so if you have any questions,
47:26 please,
47:26 uh,
47:27 do ask.
47:28 Uh
47:35 See,
47:35 uh,
47:36 I'm not sure if I'm
47:37 missing out of it,
47:39 uh.
47:41 Shavi Milo,
47:42 uh,
47:42 I'm not sure if you guys are there.
47:45 So the
47:46 the
47:47 the.
47:48 Yeah,
47:49 there's a question in the chat.
47:51 Oh,
47:51 I can't see it.
47:52 Can you guys read it?
47:55 Yeah.
47:55 So,
47:56 so the question was,
47:57 do you have any thoughts on
47:59 how international regulations
48:01 like anti-money laundering need to be
48:03 coordinated to achieve uh cross-border interoperability?
48:12 Yeah,
48:13 so,
48:13 yeah.
48:15 Yeah,
48:15 I can,
48:15 I can touch on that.
48:16 Uh,
48:16 and this is something that we've looked at quite
48:19 a bit within the context of the internet.
48:22 Um,
48:22 so a couple of points.
48:24 One,
48:25 if you think about the
48:27 EML regulations,
48:28 uh,
48:28 the root of it comes down to identity
48:30 and the ability to create identity proofs to declare who you are,
48:35 what your purpose,
48:36 intent,
48:37 background,
48:37 etc.
48:38 are.
48:39 So now the work that's happening on credentials and wallets
48:42 means that people can have digital credentials
48:46 that they can then share back
48:47 with a regulated entity
48:49 to authenticate and prove themselves or their activities or their business.
48:54 So that's one piece that.
48:55 is important.
48:56 Um,
48:57 and the benefit of doing this is
48:59 in the old world,
49:00 you would have had to either share paper documents
49:02 or you would have had to create this whole new
49:04 centralized database and multiple banks are connecting to it to fetch
49:08 KYC information,
49:10 but that was outdated very quickly.
49:12 Uh,
49:12 in the new world,
49:13 you just issue credentials back to the user.
49:15 The user in a consented manner is just re-sharing that every time they're opening a
49:20 bank account or capital markets account,
49:22 and so on.
49:22 So,
49:23 so one is the user-centric data sharing
49:26 approach that is kicking in across the world.
49:29 Uh,
49:29 the second part of obviously AMLCFT compliance comes in when,
49:33 when,
49:34 when you think about
49:35 the risk
49:36 according to the type of transaction,
49:38 right?
49:38 So,
49:39 obviously,
49:39 if I'm Transferring $10 versus I'm transferring
49:43 $100,000 versus
49:45 $10 million
49:46 the risk varies.
49:48 And so one of the constructs we're seeing come in is the idea of layered proofing.
49:53 And all that means is depending on the risk of a transaction,
49:57 you produce
49:58 additional proofs.
49:59 So for some transactions,
50:00 I could transact anonymously.
50:02 For some transactions up to a certain limit,
50:05 I need to produce
50:06 just one identity document.
50:07 And
50:08 for some,
50:09 I need to produce
50:10 more than one
50:11 document or credential.
50:13 So the idea of layered proofing is a powerful construct
50:16 we're now seeing starting to get applied in different regions.
50:19 The third idea
50:21 is,
50:21 I think,
50:22 and if we,
50:22 we've spent a lot of time within the internet lab on the whole de-risking,
50:27 um,
50:28 uh,
50:28 that's taking place,
50:29 the withdrawal of correspondent banks,
50:31 and,
50:31 you know,
50:31 a large part of that comes to AML CFT compliance costs.
50:35 And so you need infrastructure that dramatically reduces
50:39 the ability to enforce compliance rules,
50:43 to supervise these transactions,
50:44 to generate audit reports,
50:46 all of which in most cases today happens physically and it's very expensive.
50:51 So,
50:52 if you imagine tomorrow in the future,
50:54 have universal rails,
50:55 you will have entrepreneurs building best in class compliance tech apps,
50:59 supervisory tech apps,
51:01 uh,
51:01 so on and so forth.
51:03 That can do your end to end,
51:05 you know,
51:05 monitoring and regulatory surveillance of the
51:09 flows,
51:10 uh,
51:10 all programmatically at low transaction cost.
51:13 If that infrastructure is not available,
51:16 then yes,
51:16 you have to do it in a very bilateral manner.
51:18 People have to write out tenders.
51:20 It takes forever.
51:21 It becomes really expensive.
51:22 So,
51:23 the other angle we are seeing when it comes to compliance globally
51:27 is if they have universal infra that they can
51:30 apply.
51:31 Uh,
51:31 all of these technologies onto,
51:34 uh,
51:34 versus the fragmented siloed infra that exists today,
51:37 then that can really strengthen
51:39 compliance while reducing transaction cost.
51:44 Javi
51:45 Camilo.
51:48 Um,
51:48 uh,
51:48 Milo,
51:49 you wanna go ahead,
51:49 or
51:50 should I,
51:51 should I go?
51:52 Yeah,
51:52 yeah,
51:52 so,
51:53 um.
51:54 So,
51:54 uh,
51:54 and sorry,
51:55 Su and,
51:55 and Abhishek,
51:56 I mean,
51:57 you know,
51:58 abuse me if,
51:58 if,
51:59 if I'm correct here,
52:00 but this is something that,
52:01 you know,
52:01 one of the concerns,
52:02 I guess,
52:03 with,
52:04 with 5G and some of the,
52:05 uh,
52:06 some of the firms in China is that there might be
52:09 a backdoor,
52:11 uh,
52:11 because,
52:11 you know,
52:12 these,
52:12 these companies might be too cozy with,
52:14 with the government.
52:15 And so,
52:16 so,
52:16 here,
52:17 uh,
52:17 you know,
52:17 as we strive for interoperability,
52:21 Um,
52:21 and,
52:22 and,
52:22 and,
52:22 you know,
52:23 common,
52:23 common pipes and,
52:25 and common,
52:25 uh,
52:26 infrastructure.
52:27 So,
52:27 I,
52:27 I wonder whether
52:29 There is a risk of,
52:31 of a rogue
52:32 actor,
52:33 you know,
52:33 the state,
52:34 uh,
52:34 basically,
52:35 you know,
52:35 tapping into these infra infrastructure
52:39 and then,
52:39 um,
52:40 you know,
52:40 for example,
52:41 sorry,
52:41 uh,
52:42 you know,
52:42 for example,
52:42 you know,
52:43 the tax authority
52:44 wanting to have access to all the UPI payments,
52:47 uh,
52:47 basically to,
52:48 to,
52:49 uh,
52:49 you know,
52:50 to,
52:50 To,
52:51 to,
52:51 uh,
52:52 you know,
52:52 to tax,
52:53 uh,
52:53 some of these businesses that are,
52:54 you know,
52:55 where most of their transactions are,
52:57 are,
52:58 um,
52:58 you know,
52:59 are,
52:59 are,
52:59 are done via,
53:00 via this payment system
53:01 or,
53:02 you know,
53:02 in more,
53:03 you know,
53:03 more nefarious ways,
53:05 um,
53:05 you know,
53:05 wanting to use this technology to track,
53:07 track certain minorities or certain individuals,
53:10 right?
53:10 I mean,
53:11 you know,
53:11 they have the identity they can,
53:13 and,
53:13 and then they can,
53:14 you know,
53:14 they can use the this infrastructure to,
53:16 to,
53:16 to track where,
53:17 where people are.
53:18 So,
53:18 so,
53:19 so I guess what do you say to that?
53:20 I mean,
53:20 what do you say to,
53:21 to this concern about
53:23 a backdoor
53:25 that can be used by,
53:26 by the state or by some,
53:28 some rogue agent?
53:29 I,
53:29 I,
53:29 I guess this links a bit to the,
53:31 you know,
53:31 to the concern that the vest had on,
53:33 on security,
53:33 but it's not so much on
53:35 consumer protection,
53:36 but it's more on the,
53:37 well,
53:37 it's it's on the,
53:38 on the,
53:38 on the national security.
53:40 Yeah,
53:40 exactly.
53:41 So,
53:41 yeah,
53:42 I mean,
53:42 and again,
53:43 you know,
53:43 you guys can disabuse me.
53:45 I look,
53:45 I,
53:45 I don't know the topic,
53:46 right?
53:46 And so you can say,
53:47 look,
53:47 this is overblown,
53:48 and,
53:49 you know,
53:49 maybe in the case of 5G or even in the case of UPI,
53:52 this is,
53:52 this is not real because,
53:54 you know,
53:54 there's,
53:54 there's mechanisms in place that,
53:56 that prevent this from happening.
53:57 But,
53:58 but,
53:58 you know,
53:58 just,
53:58 just,
53:59 you know,
53:59 what,
53:59 what,
53:59 what your thoughts are.
54:01 Yeah,
54:01 so I,
54:02 I think I'll take the 5G bit and,
54:03 and I'll let's set up take the UPI bit,
54:06 um,
54:07 so simply on the 5G bit also and,
54:09 and so that you can add on your constant to that,
54:12 uh,
54:13 I,
54:13 I think that it's,
54:14 it's one like you said,
54:15 right?
54:15 So
54:16 it's about the risk and the risk that you're,
54:19 you're willing to be able to take.
54:20 So even if in,
54:21 in a hypothetical that everything that you've heard and read is true.
54:25 There are states that still accept taking Huawei
54:29 hardware and putting it into military facilities,
54:32 right?
54:32 There are states that decide not to put it into military facilities,
54:35 and there are states that completely ban any hardware
54:38 at all being able to enter into the country.
54:40 So it's,
54:41 it's a question of
54:42 where
54:43 and what do you quantify the risk as.
54:47 Um,
54:48 on,
54:49 on the idea that
54:51 whether or not it should be permitted,
54:52 I think the market sort of
54:55 Finds its ways to be able to
54:59 choose alternatives.
55:00 It's not like there is,
55:01 there's only one
55:02 hardware manufacturer that's there for 5G.
55:06 So you have the ability to make a choice and so therefore,
55:09 it always comes down to the choice that you have.
55:12 And,
55:13 and as far as risks around UPI and around data
55:17 accessibility go,
55:18 I think this is one of the reasons why the Finternet Lab also focuses
55:22 a lot on the idea of user centricity of data
55:25 so that you,
55:25 the user is always constantly in the center of all data flows that take place.
55:30 But let's take the most specific questions around the UPI side
55:34 since he had also co-founded and was the CT of Sati,
55:38 which had done a lot of the data exchange work in India.
55:42 Yes,
55:43 I,
55:43 I want to touch upon two things.
55:45 One,
55:45 a bit of the backdoor question.
55:46 I think more broadly,
55:48 the backdoor concern is also there's no point solution to it.
55:52 Um,
55:53 you really need to think about the entire life cycle across,
55:56 you know,
55:56 how that technology has been designed,
55:59 developed,
56:00 uh,
56:00 distributed,
56:01 and,
56:02 uh,
56:02 consumed.
56:03 Um,
56:04 and,
56:04 you know,
56:04 these are
56:06 Really,
56:06 they are far beyond even
56:08 my own,
56:09 uh,
56:09 I would say,
56:10 uh,
56:11 knowledge of the space.
56:12 But if you even look at the recent,
56:14 uh,
56:14 Ukraine attack,
56:15 uh,
56:15 where you,
56:16 you had a whole new,
56:17 or you look at the pager attack,
56:19 uh,
56:19 that happened,
56:20 uh,
56:21 one was using drones,
56:22 the other using pagers.
56:23 So I think there's a whole range where these are extremely legitimate concerns.
56:27 Similarly,
56:28 Within the crypto ecosystem,
56:29 there are often concerns of,
56:31 you may have a smart contract,
56:33 and you start trusting it,
56:34 and tomorrow,
56:35 you know,
56:36 essentially,
56:36 that smart contract could
56:38 have a backdoor where all the funds get drained,
56:41 and there have been examples of this.
56:42 So,
56:43 so I think there are,
56:44 you know,
56:44 many such real-world examples.
56:46 So I don't think the,
56:48 the paranoia is unfounded.
56:50 It's pretty genuine.
56:51 Um,
56:51 the way to address that is really one has to look at the entire life cycle.
56:55 I don't think there's any one single point solution.
56:58 Across the life cycle.
56:59 Obviously,
57:00 there are different interventions around how can you have greater transparency,
57:04 provenance,
57:05 testing,
57:05 certification,
57:07 things like that,
57:08 better cryptographic primitives,
57:09 more research happening in that area
57:11 to address this.
57:13 So those are some of the mechanisms,
57:14 uh,
57:15 I think.
57:15 Uh,
57:16 second is,
57:17 uh,
57:17 to your question,
57:18 when it came to UBI.
57:20 Uh,
57:20 if you look at UPI or,
57:22 uh,
57:22 similarly,
57:23 where you look at most digital public infrastructure,
57:26 they often have a legislative component towards how,
57:28 uh,
57:29 uh,
57:29 and what data can be used and for what purpose.
57:32 So,
57:32 for example,
57:33 in the case of Wadhar,
57:34 there was a very clear,
57:36 uh,
57:36 stipulation that,
57:37 uh,
57:37 government agencies cannot access the data without the user's consent.
57:42 Um,
57:42 and similarly,
57:43 in the case of UPI,
57:44 um,
57:45 uh,
57:45 it's,
57:46 there's no blanket access to one's UPI transactions data,
57:50 uh,
57:50 and it has to fit in within existing legal frameworks that are there,
57:53 whether that's the Payment Settlement Systems Act or the,
57:56 you know,
57:57 Tax Acts that,
57:58 that,
57:58 that are there in India.
58:00 So,
58:00 again,
58:00 that's really a function of.
58:01 Of the,
58:02 the legal structures in different jurisdictions,
58:05 uh,
58:05 that may be in India,
58:06 but that might be different in Thailand or Brazil
58:08 or in other countries that have real-time payment systems.
58:11 Uh,
58:11 so I would have to investigate that,
58:13 uh,
58:13 to,
58:14 to develop a,
58:15 a,
58:15 a view on,
58:16 you know,
58:17 what data can be used and how and what data can't be used for what purpose.
58:22 So,
58:22 because we are almost out of time,
58:24 just to,
58:25 uh I'll just
58:27 read one of the questions,
58:28 and then Milo,
58:29 you can ask yours.
58:31 Uh,
58:32 uh,
58:32 so,
58:32 so the question in the chat is,
58:34 how do you envision
58:37 applications of digital
58:38 technologies to exchange of natural resources between countries?
58:44 For example,
58:44 attaching digital ID ID to natural resources like,
58:49 like water.
58:50 Can policy makers prepare themselves
58:53 for such a future?
58:55 So before you answer that,
58:56 Milo.
58:58 Yeah.
58:59 Uh,
59:00 I,
59:00 I just wanted to
59:02 To get your vision on,
59:03 on the role of,
59:04 uh,
59:05 of developing countries here,
59:07 uh,
59:07 you know,
59:08 some of the example you gave
59:10 like India and Brazil,
59:11 we think about,
59:12 you know,
59:12 large country with some
59:14 state capacity with some
59:15 technical knowledge
59:17 and so
59:18 I wanted to,
59:19 to hear your views on how,
59:21 uh,
59:22 this model could be sort of exported in,
59:25 in,
59:25 in smaller countries with,
59:26 uh,
59:26 you know,
59:27 limited financial resources,
59:28 limited state capacity,
59:29 limited technical knowledge.
59:31 Ah,
59:31 you know how much of this can be just.
59:34 Exported and and how it can be adapted in these contexts.
59:42 So,
59:43 why don't you take Milo's question and I'll take the one in the chat.
59:48 Yeah.
59:48 So,
59:49 um,
59:50 I think the way to look at it is,
59:52 um,
59:53 Especially when it comes to,
59:55 uh,
59:56 smaller,
59:56 more emerging economies that are out there,
59:59 uh,
59:59 and based on some of our work we've been doing in many of these jurisdictions,
1:00:03 uh,
1:00:03 there are two parts.
1:00:04 One,
1:00:05 their participation in standard setting
1:00:07 itself,
1:00:08 right?
1:00:08 And that
1:00:09 is dependent on
1:00:10 what are the governance bodies they have access to.
1:00:13 They have the capacity to participate and contribute,
1:00:16 uh,
1:00:16 or provide feedback,
1:00:18 uh,
1:00:18 all the communities they have access.
1:00:20 To,
1:00:20 in some cases,
1:00:21 it may not be formal governance bodies.
1:00:23 It may be,
1:00:24 you know,
1:00:25 smaller,
1:00:25 more informal communities that are setting standards and become de facto,
1:00:29 much like the internet.
1:00:31 Um,
1:00:32 however,
1:00:32 what we've realized is,
1:00:34 uh,
1:00:34 standard,
1:00:34 a lot of the,
1:00:36 um,
1:00:36 there's interesting parallels,
1:00:38 I think technology versus regulatory standards as well.
1:00:41 So if you think about regulatory standards when it comes to data privacy,
1:00:45 GDPR,
1:00:45 and some of these.
1:00:48 Uh,
1:00:48 what we've seen is eventually that ends
1:00:50 up shutting out smaller coun countries because,
1:00:53 you know,
1:00:53 they don't have the capacity to meet some of these requirements,
1:00:56 uh,
1:00:56 as a result of which,
1:00:58 it becomes really expensive for
1:01:00 the ability to transact with these economies.
1:01:02 And so then you further the divide
1:01:04 to some extent,
1:01:05 and that's often been an unintended consequence of many of these
1:01:08 regulatory standards that may not co-opt,
1:01:11 you know,
1:01:11 a broader part of the society.
1:01:14 Uh,
1:01:14 but on the other hand,
1:01:15 uh,
1:01:16 technology standards like internet,
1:01:17 uh,
1:01:18 works across the board,
1:01:19 but,
1:01:19 you know,
1:01:20 no matter whether it's a rich country or a poor country.
1:01:22 Uh,
1:01:23 obviously,
1:01:23 the distribution and availability of the service is key,
1:01:27 uh,
1:01:27 but at the end of the day,
1:01:28 the,
1:01:28 the protocols aren't really discriminating.
1:01:30 So,
1:01:31 I think one,
1:01:31 there's an interesting difference between regulatory and,
1:01:34 and,
1:01:34 um,
1:01:36 Uh,
1:01:36 technology standards when it comes to that.
1:01:38 Um,
1:01:39 and then the second piece,
1:01:40 uh,
1:01:41 I would,
1:01:41 I would also add,
1:01:43 uh,
1:01:43 when it comes to,
1:01:44 um,
1:01:46 Smaller countries being able to participate
1:01:49 or benefit from this infrastructure
1:01:51 is actually very low transaction costs when it comes to implementation.
1:01:56 So,
1:01:56 one of the biggest gaps that we've seen
1:01:58 is,
1:01:59 you know,
1:01:59 even if they participate in the standard setting,
1:02:01 even if these standards are very generic,
1:02:03 lightweight,
1:02:04 easy to implement,
1:02:06 um,
1:02:06 like you mentioned,
1:02:07 they may not have the market or state capacity to implement this.
1:02:10 And so,
1:02:11 the more universal you make the infrastructure,
1:02:13 the more.
1:02:14 Cost you make it,
1:02:15 uh,
1:02:15 what you start doing is you can unlock potential economies of scale,
1:02:19 because
1:02:20 then what happens is rather than this being deployed.
1:02:23 So today,
1:02:24 traditionally,
1:02:24 you,
1:02:25 you would deploy an ID system from scratch,
1:02:27 a payment system from scratch,
1:02:29 a data sharing system from scratch in many of these countries,
1:02:31 these are
1:02:33 Five-year projects,
1:02:34 you know,
1:02:34 what I find it often take a lot of effort and time.
1:02:37 And then to also get adoption,
1:02:38 it takes even more effort,
1:02:40 uh,
1:02:40 versus some of the thinking we've laid out
1:02:42 in the internet papers essentially to address this,
1:02:45 where,
1:02:46 uh,
1:02:46 if you have universal rails,
1:02:48 you distribute the costs,
1:02:50 you make it
1:02:51 much more of a shared playground where participants can come in,
1:02:54 uh,
1:02:54 and they're OK,
1:02:56 because even if the unit economics in one country doesn't work out,
1:02:59 eventually on the whole,
1:03:01 on the aggregated.
1:03:02 So it's the equivalent of saying,
1:03:04 do you build today a WhatsApp in each country?
1:03:07 No,
1:03:07 you don't.
1:03:08 You can actually create a WhatsApp and distribute that regionally or a,
1:03:12 you know,
1:03:12 equivalent messaging app in other parts of the world.
1:03:15 So,
1:03:16 uh,
1:03:17 sort of my views to,
1:03:18 to your question,
1:03:19 Milo.
1:03:19 Uh,
1:03:19 Abhishek,
1:03:20 maybe you wanna answer the,
1:03:21 uh,
1:03:22 question in the chat,
1:03:23 uh,
1:03:24 and you could also touch on the liability piece,
1:03:26 uh,
1:03:26 as well.
1:03:28 E ledger,
1:03:29 I think,
1:03:29 yeah,
1:03:32 yeah,
1:03:33 so I,
1:03:33 I,
1:03:33 I also think on,
1:03:35 on the idea of how the global South and
1:03:38 developing countries can work,
1:03:40 uh,
1:03:40 like Saddha noted,
1:03:42 if you're coordinating entities or you have,
1:03:45 for example,
1:03:46 how UPS has been adopted in multiple jurisdictions,
1:03:50 we've seen that there are
1:03:52 Arrangements where 11 country who has had learnings
1:03:56 in that sphere can turn up and assist governments
1:03:59 in being able to enable and bring to life some of their own digital infrastructure.
1:04:03 So that's always food for thought,
1:04:05 uh,
1:04:05 coming on to the idea of natural resources,
1:04:08 and it's an interesting thing and something that I think tokenization
1:04:11 has been looking to try and pick up,
1:04:13 and we've seen tokenization use cases
1:04:16 across the board.
1:04:17 We've seen some of them looking at uranium.
1:04:19 Uh,
1:04:20 technology on the whole,
1:04:22 also beyond just ledger technology
1:04:24 has interesting utility.
1:04:28 Which in combination with AI,
1:04:30 DLT,
1:04:31 IOT,
1:04:32 you're starting to see an entire,
1:04:34 you know,
1:04:34 synchronized gamut of technologies that can
1:04:37 execute complex requirements and compliances without having
1:04:41 too much
1:04:42 human intervention.
1:04:43 So some of these examples could be,
1:04:45 uh,
1:04:46 you,
1:04:46 you have.
1:04:48 Countries that have water sharing arrangements
1:04:50 and in order for you to be able to determine what the,
1:04:53 the
1:04:55 The,
1:04:55 the exact amount of water flow,
1:04:57 uh,
1:04:57 needs to be able to go the reservoir needs to release based on,
1:05:01 say,
1:05:01 what are the rainfall that you've had.
1:05:03 These sort of complex calculations can become,
1:05:06 which,
1:05:06 which often become center points of
1:05:08 disputes start becoming more and more trustworthy
1:05:11 because you've got cryptographic signatures.
1:05:13 You've got,
1:05:13 uh,
1:05:15 IOT devices that are capturing data real time,
1:05:17 providing you outcomes.
1:05:19 Something that we've been working on the Finternet
1:05:20 labs and Sara had spoken about the EAJ Institute
1:05:24 is looking at taking
1:05:26 carbon emissions and GHG emissions
1:05:30 across the supply chain and tracking them
1:05:32 based on.
1:05:34 The
1:05:34 ledgers,
1:05:35 and these are conventional ledgers,
1:05:36 your balance,
1:05:37 balance sheets,
1:05:38 your financial statements
1:05:40 prepared by companies
1:05:41 as a part of their annual compliances
1:05:44 and and looking at what these raw
1:05:46 materials as they get utilized within chemical reactions
1:05:51 or
1:05:51 known.
1:05:53 Known chemical reactions,
1:05:55 so you,
1:05:56 you would always be able to quantify scientifically what the
1:05:58 outputs in terms of the greenhouse gasses would be,
1:06:01 how you can attribute attribute causally
1:06:04 to each product that you end up creating and selling,
1:06:08 what their GIG emission equivalent is so that the entire supply chain.
1:06:12 Down to the consumer good and at a jurisdictional level
1:06:16 is able to track and tally what is GIG emission was,
1:06:19 what the jurisdictional tally is,
1:06:21 and it's able to square it off to a degree of certainty,
1:06:25 so.
1:06:26 Some of these efforts which
1:06:29 are now
1:06:32 Being able to unlock
1:06:34 the aims such as
1:06:36 carbon credits or,
1:06:38 or,
1:06:39 you know,
1:06:40 global supply chains that that were harder to do
1:06:42 are now becoming easier because of technologies like this.
1:06:45 I think
1:06:46 that's the way
1:06:47 I would look at
1:06:49 the applications of these technologies.
1:06:52 So that any thoughts you have on this?
1:06:54 No,
1:06:54 we can wrap up,
1:06:56 and we are at time,
1:06:57 uh,
1:06:58 back to you there.
1:07:06 Thank you guys.
1:07:07 Uh,
1:07:07 this has been a fascinating question.
1:07:10 I'm not sure if I understood everything.
1:07:13 So,
1:07:14 but,
1:07:14 uh,
1:07:15 uh,
1:07:15 uh,
1:07:16 thank you for your paper.
1:07:17 Uh,
1:07:17 I'm sure,
1:07:18 uh,
1:07:18 we,
1:07:18 we,
1:07:19 we might,
1:07:19 uh,
1:07:19 if,
1:07:20 if you guys are OK,
1:07:21 uh,
1:07:21 we might
1:07:22 come back to you with,
1:07:23 with more specific questions as we finish writing this,
1:07:26 this report.
1:07:28 But again,
1:07:29 thank you all for joining us
1:07:31 and,
1:07:31 uh,
1:07:31 uh,
1:07:32 we hope we can have you again some,
1:07:34 sometime later.
1:07:36 Thanks.
1:07:36 Bye-bye.
1:07:37 Thank you.
1:07:38 Thank you for having us.
- add-style
- lp-body-content