1 · Concept overview

Digital citizenship names two things routinely argued as one. The first is a credential: a state-issued digital identity — Estonia's eID card, India's Aadhaar number, a European Digital Identity Wallet — authenticating a person to a government, a bank or a ration shop, and which Estonia also issues to non-residents as “e-Residency”. The second is a right: internet access, digital literacy and online participation as entitlements of membership rather than as a card. Almost all of the money, and very nearly all of the measurement, sit on the first. This brief covers identity, membership, credentials and access; the constitutional-order questions next to it — amendment rules, judicial review of algorithmic decisions, on-chain constitutions — belong to the digital constitutional systems slot on this map and are deliberately absent.

The framing under test has three limbs: that digital identity and residency make membership portable, inclusive and more efficient. They do not stand or fall together. Efficiency is real and channel-dependent — the same three authors measured a large gain in Andhra Pradesh and a null in Jharkhand, and what differs is not the biometrics but what the intervention replaced. Inclusion runs negative at the margin wherever it has been measured, because a credential system's errors land on the people whose claim on the polity was already weakest. Portability is close to unmeasured and, where measured, close to absent. A fourth finding is not about the technology at all: four of the numbers this field runs on trace only to parties with a stake in the answer, which is why the provenance audit here is a section rather than a footnote.

2 · Current scientific position

Established The two best studies in this field were run by the same three authors, on the same technology, in two Indian states, and they point in opposite directions. Andhra Pradesh, in the American Economic Review in 2016, found large gains on every dimension measured; Jharkhand, circulated as NBER Working Paper 26744, found no detectable efficiency gain and a measured exclusion cost. Almost nobody cites both. The reconciliation is the useful result, and it is not “the evidence is mixed”.

Established Andhra Pradesh is the largest randomised evaluation of a biometric identity intervention ever run, and it worked. It randomised across 157 sub-districts covering about 19 million people, replacing the payment channel for the employment guarantee and the pension programme with biometric smartcards. Leakage fell 12.7 percentage points, a 41% relative reduction; collection took 22 fewer minutes; payments arrived 5.8 to 10 days sooner; beneficiary earnings rose 24% with government outlays unchanged, meaning the money went to beneficiaries rather than to the chain between them and the treasury. And no exclusion cost was detected.

Established Jharkhand, by the same authors, found the opposite on the same technology. A randomised rollout of Aadhaar-Based Biometric Authentication in the Public Distribution System across 132 blocks — 87 treatment, 45 control — with a household sample of 3,840 across 396 fair-price shops from August 2016, designed to be representative of 15.1 million beneficiaries in 17 districts. Authentication alone produced no significant reduction in leakage: the interval on the change spans −1.7% to +6.5%, including zero and including an increase. Beneficiary transaction costs rose 17%, Rs 7 on a Rs 41 base, through failed trips to the shop. For the 23% of households whose Aadhaar was not correctly “seeded” to the ration record, benefits fell 8.4% and the probability of receiving nothing rose 10 percentage points, a 50% increase on a 20% base. In the later reconciliation phase, which did cut disbursals, 22–34% of the reduction came out of genuine beneficiaries' receipts rather than out of leakage. The authors' decision rule: a planner would have to value marginal fiscal revenue at at least 28% of the value placed on transfers to marginal households before this was worth adopting.

Frontier The reconciliation: Andhra Pradesh changed the payment channel; Jharkhand bolted authentication onto an unchanged one. In Andhra Pradesh the smartcard replaced how money physically reached a person — who handled it, where it was collected, how many hands it passed through. In Jharkhand the shop, the dealer, the stock and the supply chain were left exactly as they were and a fingerprint check was added in front of them. Authentication is not the mechanism; disintermediation is. This is a synthesis across two papers rather than a headline either states, so it is flagged frontier — but it is the only account fitting both sets of coefficients, and it predicts which deployments produce a benefit and which produce a checkpoint. Established Both papers agree that the exclusion cost belongs to the authentication layer: Andhra Pradesh added no gatekeeping and excluded nobody measurably; Jharkhand added gatekeeping and excluded measurably.

Established The operator of the world's largest biometric authentication system does not measure why it fails. India's Comptroller and Auditor General, in Report No. 24 of 2021, found more than 475,000 Aadhaars cancelled as duplicates by November 2019, including identical biometric data assigned to different residents; over 73% of 30.4 million biometric updates in 2018-19 being corrections residents paid for after faulty initial capture; Bal Aadhaars issued to under-fives on parental biometrics without establishing uniqueness, “violative of statutory provisions”, at avoidable cost of ₹310 crore plus ₹288.11 crore; and that UIDAI “did not have a system to analyze the factors leading to authentication errors”. Established That is why no authoritative national failure rate exists: the only nationally scoped figure in circulation, 12%, is the UIDAI chief executive's own admission as reported by Reetika Khera. The system publishes a transaction count, not a failure rate.

Established The best-measured failure rates are sub-national, from a state government's own files, obtained by a journalist. Anumeha Yadav, under a Pulitzer Center grant, obtained Rajasthan Department of Social Justice figures for January–April 2025: fingerprint authentication succeeded 76.27% of the time, facial 69.11%, one-time passwords over 90%. On one day in early May 2025 fingerprint authentication failed for 5,951 of 28,969 attempts and facial succeeded for 390 of 747. These are pensioners — fingerprints worn by manual labour, faces and irises aged — the group the Parliamentary Public Accounts Committee was told in 2025 was being blocked from rations and employment. Frontier In the same state 1.55 million social security pensioners stopped receiving payments from January 2024, out of roughly 10 million, attributed by the government to verification and to name mismatches between two databases.

Frontier Estonia's e-Residency is the flagship case for portable membership, and the programme and its auditor do not agree about the size of the programme. Enterprise Estonia, February 2026: €124.9 million of state revenue attributed to e-residents in 2025, up 87%; 13,828 new e-residents and 135,000+ cumulatively; 5,556 new companies against 39,000+ cumulatively; a claimed 12:1 return on €10 million of expenditure, on a revenue definition the programme wrote itself. Established The National Audit Office, auditing 2014–2019, found €15.7 million of cumulative expenditure and revenue exceeding expenses “by almost €10 million” — implying roughly €25.7 million cumulative over six years, about a fifth of the single-year figure now reported. The widely circulated €41 million is the programme's own June 2020 claim, not the auditor's finding, and this brief carries the correction because the research pack behind it made that substitution twice. The audit also found 95% of revenue from 6% of companies, about 1,900 digital IDs renewed — roughly 10% of those eligible — and 48 e-residents holding Finnish citizenship with a valid criminal penalty in Finland when they applied. Frontier The independent check comes from Estonian World's Silver Tambur: of about 29,000 companies founded, roughly 22,000 still exist and around 2,000 pay any tax, with meaningful activity estimated at about half the survivors; and part of the 2025 “record” was dividend payouts accelerated ahead of an Estonian tax rise, which officials have acknowledged.

Established In high-capacity states, failure and rollback are the modal outcome, and the best-documented failure was documented by a national audit office. GOV.UK Verify was targeted in 2016 at 25 million users by 2020; it had 3.6 million sign-ups by February 2019. Against 46 connected services by March 2018 it had 19, at least 11 of them reachable by other routes anyway. Verification succeeded 48% of the time against a 2015 projection of 90%, and 38% for Universal Credit claimants. Spending was at least £154 million from 2011-12 to September 2018 — covering Verify and its predecessor Identity Assurance Programme together, and believed by the NAO to be an underestimate — of which £58 million went to commercial identity providers. The Cabinet Office's own benefits estimate was cut from £873 million to £217 million, and the NAO “has not been able to replicate or validate” even the reduced figure. Established The UK's earlier scheme, the 2006 identity register, was repealed with all cards invalid from 22 January 2011; the government's written statement publishes unwinding costs but neither total spend nor issuance, which the Institute for Government puts at roughly 15,000 cards.

Established On portability, the strongest evidence against the claim comes from the body with the greatest interest in asserting it. In its 2021 proposal for a European Digital Identity Framework the European Commission assessed its own eIDAS 1.0 regime and reported that only 59% of EU residents have access to trusted and secure eID schemes across borders, that only 14 Member States had notified at least one scheme, that only 7 schemes were entirely mobile, and that “very few online public services accessible domestically can be reached cross-border via the eIDAS network” — concluding that “eIDAS has not achieved its potential”, its added value “limited due to its low coverage, uptake and usage”. That is mandatory mutual recognition among 27 states sharing a legal order, a court and a currency — the most favourable conditions for identity portability on earth — graded by its own author as negligible in practice. Frontier The replacement, Regulation (EU) 2024/1183, requires every Member State to offer a wallet by 2026; the Commission's own portal records the reference framework reaching 2.0 in May 2025, four large-scale pilots running, and tells citizens to expect the wallet “in the next few years”.

Established The largest digital public rail in the world is not an identity system, and its operator publishes exactly the number UIDAI publishes: a transaction count, not a failure rate. India's Unified Payments Interface, run by the National Payments Corporation of India, crossed ten billion transactions in a single month in August 2023. Frontier The operator's own series carries volume, value and a per-application market split. It does not carry a decline rate disaggregated by cause, by bank or by beneficiary population, which is the one number that would say whether the rail excludes anybody. The measurement asymmetry this brief documents in the identity layer reproduces itself, unaltered, one layer up the stack.

Established That rail has no revenue model and a cap its own operator has never enforced. India abolished the merchant discount rate on UPI and RuPay debit transactions from 1 January 2020, removing the interchange that funds card networks, and has since paid banks a discretionary annual incentive to keep the rails running. Established Separately, NPCI announced in November 2020 a 30% ceiling on any one third-party application's share of volume, and has deferred the deadline more than once. Frontier Through every deferral two applications have held roughly four-fifths of volume between them. Interoperability of a rail is not competition on it, and the most interoperable retail payment system ever built produced a duopoly at the interface layer.

Established Brazil ran the same experiment with the central bank as operator rather than a bank consortium, which is the cleanest natural comparison this field has. Pix launched in November 2020 with participation mandatory for institutions above a size threshold rather than voluntary, and Banco Central do Brasil publishes a statistics series on it. Frontier Within roughly three years instant transfers had overtaken card transactions by count on the operator's own numbers, with adoption reported above 150 million individuals. Frontier In 2025 the United States opened a trade investigation naming Brazil's treatment of electronic payment services among the practices at issue — an initiation, not a finding. A payment rail operated by the state is a trade-policy object as well as a domestic one, a constraint the identity layer never encounters.

Established The data-exchange rail has the best governance record in this brief and the least evidence, and the two facts are connected. Estonia's X-Road, in service since 2001, has since 2017 been governed by the Nordic Institute for Interoperability Solutions, a non-profit founded jointly by Estonia and Finland and later joined by Iceland — a rare public rail whose source is open and whose roadmap is decided by more than one state. Established Europe has an instrument of the same shape: Regulation (EU) 2018/1724 established the Single Digital Gateway and its once-only technical system, operational by December 2023. Frontier Member State readiness was uneven, on the Commission's own reporting. No outcome evaluation of a data-exchange layer — burden avoided, errors prevented, people not asked twice — was located on this pass, in Estonia or anywhere else. The governance is exemplary and the effect size is unmeasured.

3 · Frontier questions

Frontier Which component of a digital-identity intervention produces the benefit? The channel hypothesis — the gain comes from removing intermediaries between treasury and recipient, and the biometric is incidental — fits both Indian trials. Speculative A competing reading holds that Jharkhand's null reflects a weaker baseline leakage rate or a differently corrupt distribution system, and neither paper was designed to separate those. Handwave A third, common in advocacy material, is that Jharkhand simply implemented badly — unfalsifiable as stated, and the step where the argument does its work by assertion.

Established What is the authentication failure rate for the largest biometric system in the world? Nobody knows, and the reason is on the record. The CAG found UIDAI had no system for analysing authentication errors. Frontier The candidates are a 12% admission by the agency's chief executive, roughly 24% fingerprint and 31% facial failure in one state department's pension caseload, and a monthly transaction count the agency does publish. Speculative Whether sub-national rates generalise is unknown: an elderly pension caseload is near a worst case and a young urban banking population near a best case, and no study spans both.

Frontier How many people has authentication failure killed? Three counts circulate and none can be certified. The Right to Food Campaign documented 14 starvation deaths in Jharkhand between September 2017 and July 2018, roughly 7 with clear Aadhaar-related denial; Khera counts 42 hunger-related deaths since 2017; an anonymous advocacy tracker claims around 100 since 2015, which this pass could not verify. Established Jharkhand's food minister rejected the attribution — the deaths “can be attributed to the lack of ration cards... but they are not starvation deaths” — and called the campaigners politically motivated. Speculative The causal chain runs through prolonged malnutrition, which kills through infection, so no death certificate will ever say “authentication failure” and no count will ever be certified. Reported here as unresolved rather than dropped. What is not in dispute is that denials happened: Jean Drèze's analysis of government data found Ranchi district beneficiaries receiving only 49% of entitlements after Aadhaar-PDS linkage in mid-2016.

Frontier How many were cut off, and by what? India's government states approximately 2.06 crore ration cards cancelled 2017–2020 for deduplication, death and migration, explicitly denying Aadhaar as a ground; counsel told the Supreme Court in March 2021 that 3 crore had been cancelled over Aadhaar non-linking, and Chief Justice Bobde's bench issued notice. Neither figure has been independently audited. Frontier Nigeria gives the cleanest measured disconnection and the same ambiguity: active mobile subscriptions fell from 219.01 million to 154.63 million between March and September 2024 across barring phases of 50 million, 40 million and 24.8 million lines, mobile internet down 19.21% — but a regulator's audit found one operator had counted roughly 40 million inactive lines as active. The true exclusion count is smaller than 64 million and larger than zero, and nobody has separated the components.

Speculative Does a wallet make a credential portable, or only mobile? The eIDAS 1.0 record says mutual recognition in law produced almost no cross-border usage in fact, and the live hypothesis is that the binding constraint was never the credential format but the willingness of a relying party in state B to accept liability for an assertion made by state A. Frontier Sixteen named cryptographers — Lysyanskaya, Camenisch, Preneel, Troncoso, Hoepman and others — filed feedback on the wallet's own architecture framework in June 2024 stating that SD-JWT and ISO mDL “were never designed for” the unlinkability the Regulation mandates, recommending BBS anonymous credentials, “mature technology... developed more than twenty years ago”. EDRi reported in March 2026 that the draft implementing acts move further from those safeguards.

Established The rights reading of digital citizenship has almost no evidence base, and this brief will not manufacture one. Finland's 2010 broadband universal service obligation, France's 2009 Constitutional Council decision and Costa Rica's recognition of internet access are asserted constantly. This pass could not fetch a primary or authoritative secondary source for any of the three, so none is cited and a reader should not treat any of them as substantiated on this brief's authority. Speculative Independently of that sourcing failure, no outcome evaluation of any of them was located either. Frontier The adjacent education literature is dominated by frameworks and implementation reviews; the one cluster-randomised trial found, across 14 US schools and 1,072 students, gains in knowledge and self-efficacy and no significant impact on privacy behaviour, cyberbullying, online civility or parental help-seeking — funded by the company that wrote the curriculum, which is why the nulls carry weight.

Frontier Does the channel reading survive the move from identity to payments? This brief's central synthesis is that Andhra Pradesh's gain came from replacing the payment channel, not from the biometric. A national instant-payment rail performs that same disintermediation for a whole economy at once: money moves payer to payee with no correspondent, cash-out agent or shop between. If the channel reading is right, UPI and Pix are where the welfare gains actually are, and the identity layer looks in retrospect like the part that got measured because it was contested rather than because it mattered. Speculative The test is unavailable: neither rail was randomised, neither has a counterfactual, both were national by design. Handwave The percentage-point contribution to output routinely attributed to a payment rail is growth accounting on aggregate series, and is where that argument does its work by assertion.

Frontier When a rail fails, who pays — and is there one case where the answer is written down? There is, and it is the strongest counter-example this brief holds to its own pessimism about fallbacks. The Reserve Bank of India's harmonisation of turn-around times, issued 20 September 2019, requires auto-reversal of a failed transaction within a stated window and pays the customer a fixed daily penalty — of the order of ₹100 a day — beyond it. That is a fallback that pays when the rail fails, the exact feature this brief records as missing from every identity deployment it examines. Frontier Enforcement is unknown: no independent compliance audit was located and no aggregate of compensation paid is published. Speculative The generalisable claim is that a rail carrying money inherits a redress regime because a financial regulator already had one, while a rail carrying entitlement does not, because no regulator owns it.

4 · Technological bottlenecks

Established The binding physical constraint is that biometrics degrade in exactly the populations that most need the entitlement. Manual labour wears fingerprints; age changes irises and faces. Rajasthan's departmental data put fingerprint success at 76.27% and facial at 69.11% in a pension caseload against over 90% for one-time passwords — and a one-time password needs a working phone, a live network and a SIM registered to the right person, which is the constraint Nigeria's disconnection made visible. Frontier No deployment has published a roadmap that closes the gap rather than routing around it.

Established The second bottleneck is not biometric at all: it is record linkage. Jharkhand's exclusion fell almost entirely on the 23% of households whose Aadhaar was not correctly seeded to the ration record; the CAG found over 73% of 30.4 million updates in one year were resident-funded corrections to faulty capture; Rajasthan's stopped pensions were attributed partly to name mismatches between two databases. A national identity system's error rate is dominated by the join between two databases, not by the sensor — a solvable engineering problem, unsolved at scale anywhere in this record.

Established The third is that nothing is instrumented. An operator that does not analyse authentication failures cannot tell an outage from a fraud attempt from a worn fingerprint, cannot target remediation, and cannot be audited on the outcome that matters. The CAG said so in 2021; the Public Accounts Committee was still asking in 2025 and set a six-week deadline for an action plan. Frontier The fourth is cryptographic, and unresolved on the record of the project it concerns. The EU wallet's mandated unlinkability and pseudonymity are, on sixteen cryptographers' assessment, not deliverable by the credential formats the architecture selected; credentials accumulate at service providers and issuers can observe where they are used.

Established The fifth is that a national eID is a single point of failure, and Estonia ran the experiment. The ROCA vulnerability in Infineon chips affected approximately 800,000 Estonian ID cards issued since October 2014, over half the population. Discovered 30 August 2017, suspended 3 November 2017, revoked 1 April 2018; RIA's own post-mortem records that revocation would have disrupted e-health, tax, government document exchange and financial transactions. Of the 494,000 cards renewed, 354,000 were updated remotely, reaching 94% of electronically-used cards by April 2018. The recovery was a genuine institutional achievement and the exposure was total, and both halves belong in the same sentence.

Established The sixth is that a credential's value is granted by relying parties, who can withdraw it without touching the credential. In March 2018, after the ABLV and Danske money-laundering scandals, Estonian banks began mass-closing non-resident accounts: one small bank closed roughly 1,000, and a consultant estimated large banks had closed 5,000–10,000 between them. The cards stayed perfectly valid; the banking they were supposed to unlock stopped being available. A membership a private compliance department can switch off is not membership, and no amount of cryptography addresses it.

Frontier Beyond identity the binding constraints change shape but not character, and three are worth naming. The first is the agent layer: where a rail reaches the last mile through human correspondents — Aadhaar-enabled payment operators, banking agents, fair-price dealers — the failure modes are impersonation, over-charging and coerced biometrics rather than downtime, and they are prosecuted as crimes rather than measured as system performance, so they never enter the operator's statistics. Established The second is grievance capacity: statutory redress officers exist on paper in the Indian entitlement system under the 2013 food-security legislation, and the audit literature that supplies the rest of this brief repeatedly finds those posts unfilled or bolted onto a district officer's existing duties. A rail with a redress right and no redress staff is a rail with no redress right. Frontier The third is that consent-based data exchange moves the exclusion risk from authentication to comprehension, and no deployment here measures comprehension.

5 · Research dependencies

Established Nothing on this map produces a result this brief waits on. The constraints are institutional decisions rather than discoveries, recorded as typed requirements below: a second state that will accept the first state's credential; a published authentication failure rate disaggregated by the populations that fail; a statutory fallback that pays when authentication fails; and one outcome evaluation commissioned by a body that does not sell identity systems. Each could be supplied tomorrow by a government, an auditor or a funder, and none has been.

Established What the brief waits on from research is narrow. A trial varying the payment channel and the authentication layer independently — the Andhra Pradesh and Jharkhand designs differ on both at once, which is why their reconciliation is a synthesis rather than an estimate. An authentication failure rate on a nationally representative sample rather than one state's pension caseload. And an exclusion estimate from a survey team with no portfolio interest in identity infrastructure, to sit beside the 0.8% figure produced by a consultancy funded by an investor in the sector.

Speculative Three areas are empty rather than thin, and the emptiness is the finding. No independent outcome evaluation of any MOSIP deployment was located in any of its countries — enrolment counts exist in abundance, outcomes do not. No ex-post study measuring whether any country realised anything inside McKinsey's 3–13% band was located, seven years after it entered every national business case. No outcome evaluation of any internet-access-as-a-right instrument was located, and this pass could not verify the instruments themselves.

6 · Required experiments

Established The highest-value experiment is the decomposition the two Indian trials came within one design choice of running. Randomise the channel change and the authentication layer separately — four arms: unchanged channel with and without biometric authentication, disintermediated channel with and without — on one welfare programme in one state. That settles whether the 12.7-point leakage reduction belongs to the smartcard or to the removal of the intermediary, the most consequential open question for every country now buying this technology. Frontier It is cheap, it reuses instruments both papers validated, and no announced design is attached to it.

Established Second: instrument the authentication layer and publish the log. An operator processing on the order of 221 crore authentication transactions a month could publish success rates disaggregated by age band, district and occupation at essentially zero marginal cost, and its national auditor has already told it to. That single act would replace the entire contested literature on exclusion with a measurement. Frontier Its absence after a formal audit finding, a parliamentary instruction and a six-week deadline is itself evidence about what the operator expects the number to show.

Frontier Third: pre-register the evaluation of the EU wallet rollout with cross-border transaction counts as the primary outcome, before the wallets ship. The eIDAS 1.0 baseline is unusually clean — 59% coverage, 14 notifying states, “very few” services reachable cross-border, stated by the Commission itself — so a genuine before-and-after is available for the price of deciding to collect it. Speculative Without that decision the wallet will be evaluated on issuance counts, as every predecessor was. Frontier Fourth: separate Nigeria's audit artefact from Nigeria's exclusion with operator-level reconnection data, because until someone does, the largest disconnection event in this literature has no usable magnitude. Speculative Fifth, and least likely to be funded: replicate the Andhra Pradesh design outside India, since every large causal estimate in this field comes from one country.

7 · Engineering requirements

Established The throughput engineering is genuinely solved, and saying so is necessary before the rest of this brief is credible. India enrolled a billion people in about five and a half years at a claimed cost under a dollar per successful enrolment and roughly a cent per authentication, and now runs hundreds of crore of authentications a month with face authentication and e-KYC as routine sub-services. Frontier Those are the system architects' own figures, published in a computing venue, and they are throughput and cost metrics rather than outcome measures — but nothing independent disputes that the pipes work. Frontier The one recovery capability worth copying is Estonian: remote re-keying at national scale, 354,000 of 494,000 renewals completed without the holder attending in person, is the only piece of identity infrastructure here that was tested by a genuine emergency and passed.

Established What is not solved is delivery inside a high-capacity administration, and the UK has failed twice with a third attempt carrying documented internal objections. Computer Weekly's reporting on internal GOV.UK One Login documents records an internal security warning about absent risk assessments in July 2022; the Cabinet Office's data protection officer identifying “serious data protection failings” across 11 recommendations and advising suspension in November 2022; the National Cyber Security Centre flagging “severe shortcomings” including bulk data breach and mass fraud risk in September 2023; and the GDS chief information security officer recording in November 2023 that 39% of production administrators lacked proper vetting. Established A separately reported figure of 6,222 accesses to the production environment belongs to January 2024, not to the November 2023 record — worth stating precisely, because the compressed version circulates and is chronologically impossible. The same reporting cites over 10,000 critical and 7,000 high-priority vulnerabilities, more than 3 million users and £330m+ approved; GDS states it complies with UK data protection law and NCSC guidance.

Established Verify's engineering failure was a verification-rate failure, and its distribution is the point. A 48% overall success rate against a 90% projection is a bad system; 38% for Universal Credit claimants is a system whose errors concentrate on its most dependent users — the same shape as Jharkhand's unseeded 23% and Rajasthan's pensioners. Three deployments in two countries produce the same distributional signature, and no procurement document in this record treats that signature as a design requirement.

Established And the exported stack is an artefact whose evaluation is missing by construction. MOSIP, developed at IIIT-Bangalore, reports 29 active country engagements, 185+ million IDs generated across 14 national rollouts in production, 15 further countries in pilot, and a “total population reach” of 970.8 million. Those are the platform's own enrolment counts, and no independent evaluation of service access, error rates or exclusion in any MOSIP country was located. Speculative A model exporting the architecture without the evaluation standard will reproduce the measurement gap in every country that adopts it.

8 · Adjacent technologies

Within this map: Civic Technology, which owns the delivery layer this credential sits under; Future Public Administration, whose finding that evaluation is discretionary explains why enrolment counts exist and outcome studies do not; Distributed Governance, the same membership question asked of non-territorial structures; Institutional Design, where the incentive problem measured here as an unmeasured failure rate is stated generally; Future Democracies, which owns the franchise and the electoral roll a national register eventually touches; Future Legal Systems, for the litigation record; Global Cooperation Models, where cross-border recognition would have to be built if it is built at all; Smart Cities, which inherits the authentication chokepoint at municipal scale; and Future Federalism, whose finding that consent to a formula is the binding constraint has an exact analogue here.

Deliberately out of scope. Constitutional-order questions — amendment rules, judicial review of algorithmic decisions, on-chain constitutions, the legal status of code as law — belong to the digital constitutional systems slot, authored in parallel and therefore not linked from here. This brief's boundary is identity, membership, credentials and access; where a court decision appears it appears as evidence about whether a judgment changed an outcome, not as constitutional analysis. Outside the map: cryptography and the anonymous-credential literature, which supplies the unlinkability objection; development economics, which supplies both randomised trials; public audit, which supplies almost everything trustworthy here; and refugee protection law, which supplies the hardest case.

9 · Institutional requirements

Established This section exists because four of the numbers this field runs on trace only to parties with a stake in the answer, and a reader who does not know that will read a sales document as a literature.

Handwave “Digital ID could unlock economic value equivalent to 3–13% of GDP by 2030.” McKinsey Global Institute, April 2019, modelling seven countries with “McKinsey's proprietary general equilibrium macroeconomic model” and assuming roughly 70% adoption by 2030 plus accompanying digital infrastructure. Established McKinsey states in its own text that these are not forecasts, that “realizing this value is by no means certain or automatic” and that “not all of these potential sources of economic value may translate into GDP”. There is no independent replication and no ex-post study measuring any country against the band. It is a model output from a consultancy that sells digital-transformation work, circulating as though it were an observation.

Frontier “850 million people lack official proof of identity.” Produced by the World Bank's ID4D programme — the programme that finances and promotes national ID systems, modelling the size of the problem its product solves. Its own dataset volume calls the figure derived from “new data and modeling” and “only a snapshot as of July 2022”, and the derivative claims escalate: 1.1 billion without a digital identity record, 1.25 billion without digitally verifiable credentials, 3.3 billion unable to authenticate online — each more modelled than the last, with the programme homepage adding “550+ Million People Impacted” and no stated attribution method. Established The survey-grounded alternative exists: UNICEF's 150 million unregistered under-fives plus over 50 million registered without a certificate, resting on household surveys, civil registration statistics and censuses across 173 countries covering 98% of the global under-five population.

Handwave “Digital-ID-enabled Direct Benefit Transfer has saved India ₹3.48 lakh crore.” Published by the Press Information Bureau, the government's own communications arm, naming its source as a “quantitative assessment by the BlueKraft Digital Foundation” without reproducing the methodology. BlueKraft is a private organisation whose stated purpose is advancing “Viksit Bharat”, whose output is policy papers and books on government initiatives from 2014 onward, and which publishes ministerial commentary — not an auditor, a university or a statistical agency. Established The flagship savings figure for the world's largest digital identity programme is produced by a foundation aligned with the government and published by the government's press office.

Established And there is a natural experiment on what happens when a claim of that shape meets an audit office. In 2015-16 the government claimed ₹21,552 crore in savings from PAHAL, the Aadhaar-linked LPG subsidy transfer. The CAG reported to Parliament on 12 August 2016 that of the ₹23,316.12 crore fall in subsidy payout, ₹21,552.28 crore was attributable to the collapse in crude prices and only ₹1,763.93 crore — about 7.6% — to reduced offtake from eliminating duplicate and fake connections. When an audit office tested a DBT savings claim of exactly this shape, roughly 92% of it turned out not to have been caused by the identity system at all. No comparable audit of the ₹3.48 lakh crore figure exists.

Handwave “e-Residency generated €124.9 million for Estonia in 2025.” Produced by Enterprise Estonia, the implementing agency, on the programme's own blog, on a revenue definition the National Audit Office disputed and the programme defended as “our own intergovernmental agency-developed and accepted methodology”. Established The only independent examination found €15.7 million spent and revenue exceeding expenses “by almost €10 million” to 2019 — roughly €25.7 million cumulative — alongside 95%-of-revenue-from-6%-of-companies and a renewal rate near 10%. The €41 million figure widely attributed to the auditor is the programme's own June 2020 claim, and handing an audited body's number to its auditor is precisely the error this section exists to catch. The programme's managing director answered the audit in an open letter foregrounding the Auditor-General's remark that e-Residency is “unique” and profitable, arguing some audited information was out of date, disputing the revenue treatment, and rejecting enhanced background checks as impractical.

Established And the asymmetry in what a reader can obtain is itself a finding. The audit report could not be retrieved: it is not listed among the 521 audits on Riigikontroll's English audits index, and its figures reach the English-language record only through Estonia's public broadcaster and the programme's own acknowledgement of them. The programme's rebuttal of the audit is available in three places. An evidence base whose promotional corpus is abundant and multilingual while the audit is not published in the working language of the field is not neutral, and its skew has a direction.

Frontier Two further programme-side evaluations should be named for what they are. MOSIP's country and enrolment counts come from MOSIP's own progress report, with no independent outcome evaluation located. Ukraine's Diia was principally evaluated by the e-Governance Academy — an Estonian body whose institutional purpose is promoting digital government — on an EU-funded digitalisation platform, reporting 10–11 million users, 96.8% agreeing the app simplified identification, 100% reporting never experiencing corruption through it and 100% rating its social impact positive or very positive, and finding no major shortcomings. Established A survey instrument returning 100% on two separate items is measuring its own respondent selection.

Frontier Interest cuts both ways, and the clearest case is the one Aadhaar's critics cite least. State of Aadhaar 2019 was Dalberg research funded by Omidyar Network India, an investor with a portfolio interest in identity infrastructure. Across 147,868 households in 28 states it found 0.8% exclusion from a key welfare service for Aadhaar-related reasons against 3.3% for non-Aadhaar reasons, 92% satisfaction, and that 67% of people excluded because of Aadhaar problems remained satisfied with it. Established It also found an estimated 28 million adults without Aadhaar, concentrated in Assam and Meghalaya, including 30% of third-gender residents and 27% of homeless people. The report's inconvenient findings are its most credible ones, precisely because they run against its funder.

Established The sources weighted highest here are the ones running against their author's interest: the National Audit Office demolishing a flagship UK programme; the CAG contradicting Indian government savings claims twice; RIA publishing a post-mortem on the near-collapse of Estonia's own eID; UNHCR's 2016 internal audit conceding inadequate information to refugees in four of five countries reviewed; the European Commission declaring that its own eIDAS regime “has not achieved its potential”; the Estonian audit office reporting a 10% renewal rate on a programme its government promotes; and a Google-funded evaluation of a Google curriculum reporting behavioural nulls.

Established The governance layer for digital public infrastructure now exists as text and does not yet exist as an audit function. The United Nations released a Universal DPI Safeguards Framework promoting safe and inclusive digital public infrastructure, published as guidance; the Group of Twenty endorsed a DPI framing in 2023 with a repository and a financing vehicle beside it. Frontier These instruments are non-binding, carry no inspection power, and name no body that can withhold money from a deployment that excludes people. Handwave Treating a published framework as evidence that deployments are safer is the unearned step, and it is taken constantly.

10 · Ethical & societal considerations

Established The hardest case is where identity infrastructure meets contested membership, and there the evidence is not ambiguous. Human Rights Watch found in June 2021 that UNHCR collected biometric and biographic data from Rohingya refugees in Bangladesh from June 2018, and that Bangladesh submitted at least 830,000 names with associated data to Myanmar — the state that had driven them out — for repatriation eligibility assessment. Of 24 refugees interviewed, 23 believed the collection was only for the Smart Card and camp services. One had been asked about sharing with Myanmar and said: “I could not say no because I needed the Smart Card.” Receipts were in English only, with data-sharing consent boxes marked “yes”, and the card was the condition of access to food, aid and health care. UNHCR denied wrongdoing while acknowledging some refugees might have benefited from clearer communication.

Established This is structural, not one operation's failure. ODI researchers record UNHCR's own 2016 internal audit finding that inadequate information was provided to refugees in four of the five countries reviewed — an interested party conceding the point three years earlier — and document the same pattern in Jordan, Kenya and Ethiopia, where refugees who declined biometric enrolment faced aid cutoffs. Where consent is the price of food, consent is not consent, and the credential does not extend membership; it makes non-membership legible and transferable to the party with an interest in enforcing it.

Established The exclusion arithmetic should be given in both readings, because each alone misleads. A 0.8% Aadhaar-caused exclusion rate is genuinely low, lower than critics assert, and comes from the largest survey in the field. Applied to India's adult population it is on the order of 8 million people denied a welfare entitlement. A system can be 99.2% inclusive and still exclude the population of Switzerland, and a design conversation reporting only the percentage has removed the number that describes the harm. Frontier That is the signature rather than a side-effect: Jharkhand's harm fell on the 23% with a broken database join, Verify's on Universal Credit claimants, Rajasthan's on pensioners, Aadhaar's coverage gap on third-gender residents and homeless people, and the Rohingya case on people with no alternative to the card. The error rate is highest in the population with the weakest claim on the polity and the least capacity to appeal.

Established Court victories have not, on this evidence, reduced exclusion. India's Supreme Court held in 2018 that benefits cannot be denied for authentication failure with no fault of the individual, read down section 57 and struck the bank and SIM linking mandates — and Rajasthan stopped 1.55 million pensions in January 2024. Kenya's High Court held the Huduma Card rollout unlawful in October 2021 for proceeding without the data protection impact assessment its own statute required, after a January 2020 ruling had already barred GPS and DNA collection; the programme continued. Jamaica is the one case in this record where a court order actually stopped a system: on 12 April 2019 the Supreme Court declared the National Identification and Registration Act null and void in its entirety, unanimously, holding that mandatory biometric submission violated the constitutional right to privacy and declining to sever. Frontier One stoppage against two continuations is a thin base rate, but it is the base rate there is.

Established Public objection has been recorded at a scale no other digital-ID scheme has produced, and the policy has since moved. UK Petition 730194 closed on 9 January 2026 with 2,984,191 signatures and was debated in the Commons on 8 December 2025; a coalition of 13 NGOs briefed against it, citing mission creep across right-to-rent checks, welfare, childcare, education, banking and voting, and pointing to 76,000 Home Office records corrupted in March 2024 under the eVisa scheme. The current UK position is a public consultation launched in March 2026 with a minister confirming the scheme will not be mandatory; accounts describing it as mandatory for right-to-work checks are superseded.

11 · Civilizational implications

Established The terminal position is a split verdict across the three limbs, worth stating in full because the field states it in halves. Efficiency: partly supported, conditional on what changes. Replacing the payment channel produced a 41% relative reduction in leakage across 19 million people with no measured exclusion cost; adding authentication to an unchanged channel produced an interval spanning zero, a 17% rise in beneficiary transaction costs and a 10-point rise in the chance of receiving nothing among the badly linked. Inclusion: not supported, and measured negative at the margin. Portability: essentially unmeasured, and where measured, close to absent. Picking a side on the framing requires ignoring one of the three.

Established What follows is a change of question, from “does digital identity work” to “what does it replace”. A credential inserted in front of an unreformed delivery system is a checkpoint, and a checkpoint's measurable outputs are refusals. A credential that removes the intermediaries between a treasury and a household is a channel, and a channel's measurable outputs are speed and leakage. Frontier The same smartcard is both, depending on what the administration around it was willing to give up — which makes this an institutional-reform question wearing a technology's clothes, and explains why the technology transfers across borders far more readily than the result does.

Established The second civilizational fact is that these systems create a revocable membership. Estonian banks switched off what e-Residency was supposed to unlock without touching a certificate. A ROCA-class vulnerability came within a revocation of disabling half a country's access to health records, tax and banking at once. Nigeria's regulator barred over 100 million lines across three phases. Frontier Analogue citizenship degrades gracefully — a lost paper card is replaced, a misspelled name is argued with a clerk. A credential system fails as a step function, at population scale, on a schedule set by somebody else. No deployment in this record has a statutory fallback that pays the entitlement when authentication fails, which is the single institutional feature that would turn the step function back into a graceful degradation.

Speculative The third is that the identity layer is where a polity's boundary becomes computable, and no evidence yet says which way that cuts hardest. The optimistic reading is that a legible population is a servable population, and 221 crore monthly authentications, working payment rails and a demonstrated remote re-keying capability are not nothing. Speculative The pessimistic reading is the Rohingya case generalised: an identity register is a list, lists are transferable, and the party most interested in a refugee register is the state the refugees fled. Handwave Which dominates over a century is asserted rather than measured by everyone who asserts it, this brief included.

Frontier And the durable finding is about evidence rather than technology. The best studies in this field are the least favourable to it and the least cited; the most cited numbers are the least independently produced. That is what happens when the institutions that build a technology are also the institutions that measure it, and when the audit that would settle the question is not published in the language the field argues in.

12 · Timelines

These horizons track statutory deadlines, consultation outcomes and audit cycles rather than technology, because none of the binding constraints here are technical:

  • 10 yr: Frontier Three dates dominate. Every EU Member State is legally obliged to offer a wallet in 2026 while the Commission's own portal tells citizens to expect it “in the next few years”; that gap resolves inside this window and is the cleanest available test of whether a legal mandate produces cross-border usage. The UK's March 2026 consultation determines whether a third national scheme proceeds voluntarily after two failures and a three-million-signature petition. And UIDAI either publishes a disaggregated authentication failure rate under parliamentary pressure or does not. Speculative The likeliest outcome on present evidence is wallets shipping domestically with cross-border usage still unmeasured, because nobody has committed to measuring it.
  • 25 yr: Speculative The plausible split is that credential technology converges — formats standardise, unlinkability is either solved with anonymous credentials or abandoned — while acceptance stays national, because a relying party accepting a foreign assertion is accepting foreign liability and no regime has solved that even inside the EU. Speculative Biometric degradation is either engineered around by multi-modal fallback or routed around by phone-based authentication, which relocates the exclusion to people without phones rather than removing it. Handwave Forecasting genuine portability in this window asserts a change in liability law, not an extrapolated measurement.
  • 50 yr: Speculative If the channel-not-authentication reading holds, the durable gains accrue to states that used identity as an excuse to disintermediate delivery, and the checkpoint deployments look in retrospect like an expensive detour. Speculative The rights reading of digital citizenship either acquires an evidence base or stays what it is now — widely repeated instruments with no located outcome evaluation and, on this pass, no fetchable authoritative source. Handwave Both extrapolate from a two-trial literature in one country.
  • 100 / 250+ yr: Handwave Beyond useful forecasting. The only durable observations at that horizon are that population registers outlive the governments that build them, and that what a register is used for is decided by whoever holds it later. Handwave Neither is a base rate, and anyone offering a century-scale claim about digital citizenship is doing political theory.

Frontier One horizon line belongs to the rails beyond identity, and it is nearer than the identity ones. Inside the ten-year window the deferred UPI market-share cap either binds or is abandoned, and the European once-only system either shows measurable cross-border reuse of administrative data or joins eIDAS 1.0 as a mandate that produced compliance without usage.

13 · Technology tree & dependencies

  • Depends on Nothing on this map. This brief waits on no result another brief produces: the two strongest studies in the field were completed a decade ago, and every constraint that binds is a decision some institution has not taken. No typed depends-on edge is claimed.
  • Requires (not on this map) Portability is the weakest limb of this brief's framing, and the constraint can be stated precisely because the most interested party measured it and published the result. Assessing its own eIDAS regime — mandatory mutual recognition among 27 states sharing a legal order, a court and a currency — the European Commission reported 59% of EU residents with cross-border access to trusted eID schemes, only 14 Member States having notified any scheme, only 7 schemes entirely mobile, and “very few” domestically accessible online public services reachable cross-border, concluding that the regime “has not achieved its potential”. Outside the EU no credential in this record is accepted by a second state's government as identity, and Estonian e-Residency — the most-cited portable membership — confers no right of entry to any country including Estonia. What is missing is not a format or a protocol but a relying party in state B willing to accept liability for an assertion made by state A. The second requirement is a published authentication failure rate disaggregated by age and occupation: the operator of the largest such system was found by its own national auditor to have no system for analysing authentication errors, and the best figures available anywhere are one state department's pension files obtained by a journalist. The third is a statutory fallback that pays the entitlement when authentication fails — the feature that converts a step-function failure into a graceful one, which no deployment here has. The fourth is one outcome evaluation commissioned by a body that does not finance, sell or promote identity systems: the field's headline economic figure is a consultancy's model, its headline problem figure is produced by the programme that funds the solution, its largest national savings claim traces to a government-aligned advocacy foundation, and its flagship revenue figure is published by the programme that earns it. None of the four is a research result; all four are things a legislature, an auditor or a funder could choose to supply. A fifth requirement arrives with the non-identity rails and is the same species as the second: a published decline rate for a public payment or data-exchange rail, disaggregated by cause. The operators of the two largest instant-payment systems publish counts, values and market splits and no decline rate, so whether a payment rail excludes anybody cannot be asked with numbers. Like the other four it is a disclosure a central bank could require tomorrow, not a research result.
  • Enables In principle any service that must know who it is serving — targeted transfers, portable entitlements, cross-border service access, remote enrolment in anything — rests on an identity layer that works for the people it is meant to reach. No typed enabling edge is claimed, and the reason is a finding: no independent outcome evaluation of any exported identity deployment was located, so the enabling relationship has been asserted for a decade and measured nowhere.
  • Adjacent Cryptography and the anonymous-credential literature, which supplies the unlinkability objection; development economics, which supplies both randomised trials; public audit, which supplies nearly everything trustworthy in this brief; refugee protection law, which supplies the hardest case; and within this map Civic Technology, Future Public Administration and Distributed Governance.

14 · Common misconceptions & speculative claims

Handwave “Digital ID unlocks 3–13% of GDP.” A consultancy's proprietary general-equilibrium model over seven countries assuming roughly 70% adoption by 2030, which its authors explicitly label potential value and not a forecast. Established No independent replication and no ex-post measurement of any country against the band exists, seven years after it entered every national business case. Frontier The same applies to “850 million people lack official proof of identity”: modelled by the World Bank programme that finances national ID systems, self-described as a July 2022 snapshot, its derivative 1.1, 1.25 and 3.3 billion figures growing more modelled as they grow larger. Established Where the question is documentary identity, use UNICEF's survey-grounded 150 million unregistered under-fives instead.

Handwave “Aadhaar-enabled transfers have saved India ₹3.48 lakh crore.” A government press release citing a government-aligned advocacy foundation, with no published methodology. Established The one claim of this shape an audit office actually tested collapsed: of the ₹23,316.12 crore fall in LPG subsidy payout in 2015-16, the CAG attributed ₹21,552.28 crore to falling crude prices and ₹1,763.93 crore — about 7.6% — to the identity system. Roughly 92% of the claimed saving was the oil market.

Established “The strongest evidence shows biometric authentication does not work.” This is the overcorrection and this brief refuses it. The same three authors who found the Jharkhand null found, across 157 sub-districts and about 19 million people in Andhra Pradesh, a 12.7 percentage point (41% relative) leakage reduction, 22 fewer minutes per payment, payments 5.8 to 10 days sooner, earnings up 24% with government outlays unchanged, and no exclusion cost. Frontier The reconciliation is the point: Andhra Pradesh changed the payment channel, Jharkhand bolted authentication onto an unchanged one. Claiming the efficiency benefit was undetectable under the strongest available research design means omitting the larger randomised trial, by the same authors, that detected it.

Established Two Estonian numbers in wide circulation are wrong, and both errors run in the programme's favour. “Roughly 93% of e-resident companies are dormant” is a division performed on two figures that do not divide, and it contradicts its own source, which gives about 29,000 companies founded, roughly 22,000 still existing, around 2,000 paying any tax, and the author's estimate of meaningful activity at about half the survivors. Established And “the audit office found €41 million of cumulative revenue” hands the audited body's number to its auditor: €41 million was the programme's own June 2020 claim, while the auditor found €15.7 million of expenditure and revenue exceeding expenses “by almost €10 million”, implying roughly €25.7 million. Against €124.9 million for a single year that is about a fifth — not an order of magnitude, which is wrong on either number. This substitution occurred inside the research pack behind this brief, twice.

Established “e-Residency gives you EU residency”, or a post-Brexit loophole. It confers no physical residency, no right of entry to Estonia or the EU, no passport function, no citizenship, no tax residency and no political rights — it is an authentication and digital-signature credential permitting company registration, tax declaration and qualified electronic signatures. A cluster of international outlets ran the loophole framing in August 2017 about a document conferring no right to enter or remain anywhere, and that gap between what the credential does and what it is reported to do is the mechanism by which “digital residency extends citizenship” became conventional wisdom.

Frontier “Aadhaar has killed around a hundred people” — and its mirror, “nobody has died.” Both are asserted; neither is established. The counts are 14 documented starvation deaths in Jharkhand with roughly 7 showing clear Aadhaar-linked denial, 42 hunger-related deaths since 2017 on Khera's count, and around 100 on an advocacy tracker this pass could not verify. Established The state government rejects the attribution, and the causal chain runs through malnutrition and infection, so no death certificate will record authentication failure and no count will ever be certified. Speculative Reported here as unresolved rather than dropped: dropping it implies the question was answered downward, asserting it claims a certification that cannot exist. What is solidly established is denial of entitlements at scale.

Handwave “Internet access is a legal right in Finland, France and Costa Rica.” Cited constantly in digital-citizenship literature. Established This pass could not fetch a primary or authoritative secondary source for any of the three within the project's evidentiary rules, so this brief cites none of them, and a reader should not treat any of the three as substantiated on this brief's authority. Speculative That is a statement about this brief's sourcing rather than a claim the instruments do not exist — but the separate, independently established point is that no outcome evaluation of any of them was located either.

Frontier “The EU Digital Identity Wallet has shipped”, and its companion, “it will be privacy-preserving.” The reference framework reached version 2.0 in May 2025, four large-scale pilots are running, and the Commission's own portal tells citizens to expect the wallet “in the next few years” against a Member State obligation dated 2026. Frontier Sixteen named cryptographers state on the project's own repository that the selected credential formats cannot deliver the unlinkability the Regulation mandates; the objection is unresolved, and EDRi reports the implementing acts moving away from it while adding mandatory biometric facial processing not present in the Regulation.

Established “The UK is making digital ID mandatory.” Superseded. The current position is a public consultation launched in March 2026 with a minister confirming the scheme will not be mandatory; accounts of a right-to-work mandate describe a policy that has since moved. Established And “a court ruling protects people from exclusion” fails on the same kind of evidence: India's Supreme Court barred denial for authentication failure in 2018 and Rajasthan stopped 1.55 million pensions in 2024; Kenya's High Court required a data protection impact assessment and the programme continued; Jamaica voided its Act in its entirety and is the single case in this record where a judgment actually stopped a system.

Frontier “Digital citizenship education makes children safer online.” The one cluster-randomised trial located found gains in knowledge and self-efficacy and nulls on privacy behaviour, cyberbullying, online civility and parental help-seeking — funded by the company that wrote the curriculum, which is why the nulls are credible. Established This literature is thin and should be described as thin, not summarised as though frameworks and Delphi studies were outcome evidence.

Established And the framing itself: “portable, inclusive and more efficient” is three claims argued as one, with three different answers. Efficiency is real where the identity layer replaced the delivery channel and absent where it was added in front of one. Inclusion is measured negative at the margin in every deployment anyone has looked at, because the errors fall on the manual labourer with worn fingerprints, the ninety-year-old whose face no longer matches, and the refugee who needs the card and therefore cannot refuse it. Established Portability is the limb with no supporting evidence at all — and the body that most wanted it to be true is the body that measured its absence.