Identosphere 173: The Digital Identity Moment • The California Career Passport RFP • Who Owns The Intelligence Layer (Trust Registries)
Kaliya "Identity Woman" Young's newsletter about all things digital identity, self-sovereign identity and the emerging developments in the field.
Thoughtful
A follow-up to “Technology Paternalism Expands — A Case for Self-Sovereign Identity”
A while ago I published a piece on Technology Paternalism, the anti-pattern by which a technology system is designed to shape, restrict, or pre-decide choices for people, commonly justified as safety, efficiency, or protection. What resulted were vivid discussions. A huge thank you to all the voices in the discussion. This article picks up on them.
Everything Collapses to 32 Bytes (Tim Bouma)
If I stare long enough, whatever looks complicated will eventually collapse into something much smaller, much sharper, and a bit more unsettling. Object, Controller, Event, 32 bytes (OCE-32) came out of that kind of staring... Let’s talk about the 32 bytes…
Where are we Now?
Is Digital Identity Having Its “Suddenly” Moment?
Estimates suggest the United States has lost $3 trillion to fraud and improper payments across just federal government programs over the last two decades.[⁵] The old model is failing catastrophically, and the first, second, and third-order costs are being borne by individuals, institutions, and taxpayers alike.
Utah’s Chief Privacy Officer, Christopher Bramwell, has been explicit about the strategy: embed rights-first principles into statute before systems deploy, not after. “If we fail to act,” Bramwell wrote in GovTech, “identity will be defined for us by whoever has the resources and ambition to control it.”[¹¹]
From DMV to Wallet: Understanding Verifiable Digital Credential Issuance [NIST Article]
This blog post explores what it takes to issue verifiable digital credentials, with a focus on mobile driver’s licenses (mDLs). We’ll look at how issuance works today in practice, where inconsistencies exist, and how standards bodies (FIDO, ISO and OpenID Foundation) are working to bring greater trust and interoperability.
Stepping stones from Digital Identity to Data Protection
By reframing digital identity as What You Really Need To Know? and building infostructure to secure the story behind the data, enormous opportunities would open up in bigger more urgent areas, including open data, the Internet of Things, supply chain integrity, digital safety and generative AI quality. Different credentials would be issued to respective digital Subjects, to assert and protect any qualities of interest. The Subjects of these focused VCs can be non-human; they can even be intangible, such as data itself.
Before the wallet, there is meaning!
Data is not flat, and pretending it is flat is where most systems quietly lose the plot. An address is a structured thing with parts. An employer employs an employee. A seller is related to a buyer. A department is part of an organization. These relationships are not decoration: they are the meaning.
Evolution of Identity: 1994-2025 and Beyond
Digital identity has been “the future” for over a decade, but the data tells a more nuanced story.
Verifiable Credentials
Identification does not create identity - sets of verifiable credentials do
I have been trying to stress that identification and identity are two different things - that identity is not only who you, an organisation, their AI-agents or things are - but also what you/they are - and on whose account you/they can act.
The California Career Passport RFP Is Out. And It’s a Game Changer.
Free Teir 1 C2PA Certificates from SSL.com
A C2PA Certificate lets you attach a cryptographically signed provenance record, a “content credential,” to any media file. Anyone who receives the file can verify its origin, check whether it’s been altered, and see an auditable chain of custody from creation to distribution. Built on the open C2PA standard, backed by Adobe, Google, Microsoft, BBC, Reuters, Sony, Nikon and the broader Content Authenticity Initiative.
The C2PA Free Tier (since May 2026) includes one Level 1 Claim Signing Certificate valid for 1 year, plus 10,000 trusted timestamps per year, issued via the SSL portal.
Digital Trust
Machines Don’t Need Identity. They Need a Warrant. (Paul Knowles)
Why non-human identities solve the wrong problem, and why machine governance requires single-use warrants at the execution boundary, not standing permissions.
Proofing Creep in Production: Design Patterns for Sensible Identity Verification (Andy Hindle)
If anything, proofing creep has now reached production scale. It arrives bundled into platforms, marketed as innovation, and justified through architecture diagrams with many arrows and little restraint.
Response to The Missing Layer Behind Digital Trust (Tim Bouma)
The paper speaks often of trust, governance, assurance, accreditation, and interoperability. It asks how trust can be exported across jurisdictions and how credentials issued in one country might be recognized in another.
But beneath all of these questions lies another, more fundamental one that is never explicitly articulated:
Who controls the record?
Who Owns The Intelligence Layer (Trust Registries)? (Ayra)
But making sense of that data — curating which registries to trust for which purposes, interpreting what the data means for specific compliance requirements, governing the edge cases where automated answers aren’t sufficient — that requires domain expertise, industry relationships, and governed judgment that competitors cannot replicate.
Credential Engine Joins Ayra to Advance Global Trust in Digital Credentials
Vocabulary Before Standards: Why the Legal Community Must Move First on Autonomous Systems Governance
Six standards bodies [IETF / OpenID Foundation / W3C / FIDO Alliance / The Linux Foundation / National Institute of Standards and Technology (NIST)] are hardening the vocabulary of autonomous systems governance right now. None of them can name the bearer of consequence. The American Bar Association's Autonomous Systems Governance Working Group is moving. But it needs to move faster than the ratification process. Vocabulary before standards. We only get one shot at this.
Series of essays revisiting the book Identity Reboot, published in 2020.
Privacy, Profit and Power
Profit optimisation kills privacy instrumentally: data extraction to target ads and maximise engagement left the information environment degraded. Privacy had to die so the machine could learn your preferences.
Autonomy, Agency and AGI
In 2020, I argued that a diluted information environment degrades autonomy (independence to decide), and that shrinking autonomy contracts human agency (power to do). Philosopher Isaiah Berlin offers “two liberties” to distinguish the two: negative liberty (“freedom from”) and positive liberty (“freedom to”).
Humans, Robots and Identity
In 2020, I argued that a direct line connects identity systems to political infrastructure. In the last chapter of the book I even went so far as arguing that different identity regimes would lead to different human futures, as our attitudes to identity would be a proxy for our relationship with AI. When we give the robots wallets, identity, or assigned consciousness, all of the above applies. This was rather radical at the time. Now, decidedly less so.
AI Agents & Identity
[Non-paper] Trusted Identities for AI agents: An Opportunity for Europe (We Build)
We are pleased to share this new non-paper organised by WE BUILD participants about AI agents, digital wallets and payments….It is clear to most that AI agents will manage many situations in our daily lives. Without a solid foundation that ensures a chain of trust our societies are at risk.
From Distributed Intelligence to Verifiable Responsibility
The accountability substrate: completing the AI-native Internet.
The AI-native Internet will not scale on distributed intelligence alone. It requires distributed responsibility, made enforceable through verifiable accountability. Responsibility is the social outcome of coordinated action; accountability is the technical substrate that makes responsibility enforceable at machine speed.






