Identity
Identity, as a legal and technical category, used to mean *a name attached to a body in a place*. It does not mean that anymore. In its current operational form, identity means the cryptographic binding of a biometric template — an iris…

Identity, as a legal and technical category, used to mean a name attached to a body in a place.
It does not mean that anymore.
In its current operational form, identity means the cryptographic binding of a biometric template — an iris scan, a facial-recognition vector, a fingerprint hash — to a permanent unique identifier, whether a Social Security number, an Aadhaar number, a national-ID number, or a wallet address, in a digital store accessible to whichever institutional party has been delegated the authority to verify. The name attached to the body in the place is still there. It is, increasingly, decorative.
The shift began with biometric-enrollment programs that promised to make life more convenient. It accelerated when those programs were tied to payment systems. It became operational when payment systems were tied to government identity, when government identity was tied to employment verification, when employment verification was tied to lease applications, when lease applications were tied to credit scores, when credit scores were tied to insurance, when insurance was tied to healthcare access, when healthcare access was tied to a database the patient could not see and could not edit and could not export.
This is the identity stack. It exists in fully-operational form in three countries — India, Estonia, the United Arab Emirates — and in nearly-operational form in approximately one hundred more, including the entire European Union and approximately thirty-eight U.S. states.
The defenders of the stack are not wrong about what it solves. The World Bank estimates that roughly 850 million people on earth have no official identification at all, down from over a billion in 2017, but still 850 million people who cannot open a bank account, enroll in a school, receive a vaccine on a record, vote, or cross a border, because on paper they do not exist. More than half are children whose births were never registered. The case for giving them a verifiable identity is not a libertarian abstraction; it is the difference between a person and a non-person in every system that distributes anything. India’s program alone brought formal identity to hundreds of millions who had never had it.
The identity stack was built to include, and at the scale of inclusion it has largely worked. The argument of this chapter is not that the stack should not exist. It is that the same property that makes inclusion possible — the instant, automated, machine-verifiable binding of a body to a record — makes exclusion possible by exactly the same mechanism, at exactly the same speed, with exactly the same finality. And the architecture provides no operational way to tell the two apart from the inside.
Walk three people through it.
The American is at an airport. She holds a mobile driver’s license in her phone’s wallet: Apple Wallet, in one of the fourteen U.S. jurisdictions that issued mDL credentials accepted in the wallet by late 2025, or the Samsung Wallet integration California added in April 2026. The credential derives from a REAL ID-compliant license; REAL ID enforcement began on 7 May 2025. At the checkpoint, one of the 250-plus that accept mDL, she taps the phone, and a camera takes her photograph, and the photograph is matched against a stored image. The match resolves in under a second. She is who she says she is. She keeps her shoes on. The line moves.
What she does not see, and cannot see, is the matching itself. Which image her live face was compared against, what confidence score the comparison returned, what threshold the system used to call it a match, and what would have happened at a score one or two points lower. The verification is a black box that opens for her and stays closed to her. On a good day this is invisible, because a good day is defined as the day the box opens.
The box does not open the same way for everyone. The National Institute of Standards and Technology’s Face Recognition Vendor Test, the most authoritative public audit of the technology, evaluated 189 algorithms from 99 developers and found, for one-to-one matching, false-positive rates ten to a hundred times higher for Asian and African American faces than for white faces, depending on the algorithm. The earlier Gender Shades study found error rates of 34.7% for darker-skinned women against under 1% for lighter-skinned men. The disparity is not a moral failing of the camera. It is a property of the training data and the optics, and it means the probability that the box stays closed when it should open is not distributed evenly across the people standing in the line.
When the box stays closed for the wrong person, the American has a name for the experience without quite having a remedy for it. The Terrorist Screening Database, the watchlist machinery built on the same logic of matching a person against a record, offers the precedent. The No-Fly List is a subset of it; the database held roughly 1.2 million names as of 2017, the No-Fly List itself something like 81,000 by 2016. Because the early list matched on names without unique identifiers, it generated false positives at industrial scale: infants flagged, an 18-month-old ordered off a plane, roughly a hundred Canadian families reporting children weeks old caught in the net. DHS’s own figures put about 98% of complaints about the list in the false-positive column.
When Americans went to court over it, they did not lose on the facts. They won. In Latif v. Holder (2014) a federal court in Oregon held that the redress process violated the Fifth Amendment’s due-process guarantee, calling it “wholly ineffective”: no notice of listing, no reasons, no meaningful way to contest it. In Elhady v. Kable (2019) a federal court in the Eastern District of Virginia found the watchlist process unconstitutional as applied to the plaintiffs, because the redress program told a listed person nothing: not whether they were on the list, not the criteria used, not the evidence relied upon, and gave them no opportunity to rebut it. Plaintiffs won the principle. The government still does not, as a general matter, tell people why they are listed. The remedy was a declaration; the machine kept running.
That is the shape of recourse in the American identity stack. The court can find the process unconstitutional and the process can continue, because the thing the court objects to — the opacity, the inability of the matched person to see what they were matched against — is not a bug in the system. It is the system’s reason for existing. You cannot litigate your way to transparency in a machine whose value proposition is that it decides faster than you can ask.
The American at the checkpoint, then, has the strongest legal position of the three people in this chapter and close to the weakest practical one. She is a citizen of a country with a Bill of Rights, a functioning federal judiciary, and a civil-liberties bar that wins these cases. And if the camera returns a false negative on her, decides she is not herself, she will miss her flight while a TSA officer pulls her aside, and she will have no document she can hold up that the camera is obligated to believe over its own score. The credential in her phone is not evidence she can submit. It is a request the machine may decline.
The second person is at a ration counter in Jharkhand.
He is enrolled in Aadhaar, the largest biometric identity system in the world: roughly 1.39 billion numbers generated by early 2024, covering more than 93% of India’s population, each one binding fingerprints, iris scans, and a facial photograph to a twelve-digit identifier. By August 2025, face-authentication transactions on Aadhaar had crossed two billion, up from 500 million the previous summer. To draw his family’s subsidized grain from the Public Distribution System, he must authenticate. He presents a fingerprint, or increasingly a face, to a point-of-sale device that checks it against the rationing record over a mobile data connection.
When the match succeeds, the system works exactly as designed. The right grain goes to the right household, and the ghost beneficiaries and duplicate cards that the program was built to eliminate cannot collect. This is the inclusion case, and in aggregate India’s defenders can point to real deduplication and real delivery.
When the match fails, the grain does not come.
A 2017 survey of 890 households across 32 villages in eight Jharkhand districts, conducted by Jean Dreze, Nazar Khalid, Reetika Khera, and Anmol Somanchi, found a 49% failure-to-match rate. Half the people who came to authenticate could not be matched to their own digital identifier. The causes are mundane and physical: fingerprints worn smooth by manual labor, rural connectivity that drops the transaction, server outages, absent operators, dead portals. The system fails most reliably on exactly the bodies it was built to serve — the farmer, the construction worker, the elderly — because those are the bodies whose fingerprints have been sanded down by the work that made them poor enough to need the ration.
In September 2017, an eleven-year-old girl named Santoshi Kumari died in Simdega district, Jharkhand. Her family’s ration card had been cancelled because it was not linked to their Aadhaar number, and the local dealer had refused them rations for months. She had gone without food for close to eight days. Her mother said she died asking for rice. Her new ration card arrived about two weeks after her death. She is one of at least nineteen deaths the Right to Food Campaign has linked to Aadhaar-based exclusion from rations. The others have names too. A sixty-year-old man, Ruplal Marandi, in Deoghar district, after biometric authentication failed for two months. Two children, Munni and Govinda, in Bihar’s Buxar district.
The Indian Supreme Court has been here. In Justice K.S. Puttaswamy v. Union of India (2018) it upheld the Aadhaar Act 4-1, while striking down the mandatory linking of Aadhaar to bank accounts and SIM cards as failing the proportionality test. Aadhaar remained mandatory for welfare. The Court could constrain the linking; it could not constrain the fingerprint. The man at the counter has a constitutional right to his ration and no working fingerprint to claim it with, and there is no clause in the judgment that grows him a new one.
His recourse, in practice, is the journalist and the campaign: the Scroll.in reporter who drives to Simdega, the Right to Food volunteers who keep the count. The system itself offers him an authentication retry. When the retry fails, it offers him another. The override exists; the override is operationally dead, because the dealer who could override it is the same dealer who profits from the cancelled card, and the machine gives him cover. The number said no.
The third person is a German woman opening a bank account.
She does it through a digital identity wallet, under the European Union’s revised eIDAS framework, the regulation that is building a continent-wide, interoperable identity layer that every member state must offer and every regulated service may demand. Her KYC check resolves against a supervised database; her wallet asserts her identity; the bank, satisfied, opens the account. This is the cleanest case of the three. No grain, no flight, no watchlist, just a credential and a service, the friction of being a person in a regulated economy reduced to a tap. The inclusion argument here is almost too obvious to state: she does not have to mail anyone a notarized photocopy of her passport.
The cost is structural and it is mostly invisible to her. eIDAS 2.0 includes a provision, Article 45, that requires web browsers to trust certificate authorities appointed by member-state governments and bars browsers from imposing security requirements on those authorities beyond a baseline set by a European standards body. The cryptographic objection was raised in November 2023 by over five hundred security researchers and NGOs in an open letter, with Mozilla co-organizing an industry statement and Google’s Chrome security team registering concerns. A government holding such a certificate authority can request a website’s certificate and, with a man-in-the-middle position, decrypt the encrypted traffic between that website and its users. And the regulation may forbid browsers from enforcing the very transparency mechanism that would let anyone notice. The same identity layer that lets her open an account in one tap is built on a trust root she is required to trust and forbidden the tools to verify.
She will likely never feel it. The German has the strongest practical position of the three: a wallet that works, a banking system that respects it, a data-protection regime, the GDPR, with genuine teeth. Those teeth are not theoretical. When Tools for Humanity’s Worldcoin project, Sam Altman’s iris-scanning identity venture, came through Europe offering cryptocurrency in exchange for letting a chrome sphere photograph the inside of your eye, the German data-protection authority concluded it had violated the GDPR and ordered the biometric data deleted. Spain banned it. Portugal banned it for three months. Hong Kong ordered it to stop and confirmed 8,302 people had already had their faces and irises scanned. And in Kenya, where people lined up in Nairobi to trade their irises for a few dollars in tokens, the High Court ruled in May 2025 that the collection was illegal — improperly induced consent, no data-protection impact assessment, no registration as a data processor — and ordered Tools for Humanity to permanently delete the biometric data of more than 300,000 Kenyans, a deletion the data-protection commissioner confirmed completed in January 2026.
Worldcoin demonstrates the regulators working. It also demonstrates what they are working against: a private company that walked into the poorest neighborhoods on earth, offered cash for the most permanent biometric a body has, and built a database faster than five jurisdictions could ban it. The crypto incentive was the tell. The consent was the legal cover. The structural argument is that there will always be another company, and the regulators are always behind it, because the database can be built in an afternoon and litigated for a decade.
The German’s recourse, then, is the best available anywhere: a regulator that will, eventually, find the violation and order the deletion. What the regulator cannot do is restore the eye to the state it was in before the sphere photographed it. A biometric is not a password. She cannot change her iris after a breach the way she changes a leaked credit-card number, and the breach precedent is not hypothetical. In 2018 The Tribune reported that unrestricted access to the Aadhaar database of over a billion people could be bought for about eight U.S. dollars. The German’s data sits behind a better regime than that. It is still a body part written to a disk.
Three people, three jurisdictions, three positions on the spectrum of legal protection. The American has the strongest rights and the bluntest practical remedy. The German has the strongest enforcement and the most irreversible exposure. The Indian has, on paper, a constitutional guarantee and, in the village, a worn fingerprint and a dealer with a reason to say no. And all three are inside the same machine, because the machine is the same machine.
In each case the identity assertion is verifiable in under a second. In each case the verification is enforced by an automated system that a human is technically permitted, and practically disinclined, to override. And in each case the person whose identity is being asserted has no operational ability to see what their body was matched against, what score the match returned, or what threshold decided their grain, their flight, their account. The verification is fast precisely because it does not stop to explain itself. The explanation is the latency the whole system was built to remove.
Which leaves the two questions the stack cannot answer from the inside.
The first: what is the recourse when the verification produces a false negative for someone who genuinely is the identity-holder? When the camera decides the American is not herself, the fingerprint decides the Indian is not himself, the wallet fails the German at the counter? The honest answer is that the recourse is to try again, and then to find a human, and then — if the human defers to the machine, which the human is trained and incentivized to do — to find a lawyer or a journalist and wait. The recourse is slow in exact proportion to how fast the rejection was. The machine says no in a second and the appeal takes a year, and in the gap is the missed flight, the empty bowl, the closed account. Latif and Elhady and Puttaswamy are the high-water marks of that recourse, and what they establish is that you can win the principle and still not get told why the number said no.
The second question is worse, because it has no plaintiff. What is the recourse when the verification produces a false positive — when the system matches someone who is not the identity-holder, and acts? The false negative at least produces a victim who knows they were wronged and can, however slowly, complain. The false positive produces a victim who often never learns they were impersonated, and a second victim, the person wrongly matched against a record that was never theirs, who learns it at the worst possible moment.
Robert Williams learned it in January 2020, in Detroit, when police arrested him at his home in front of his wife and two daughters on a felony charge, held him overnight, on the strength of a facial-recognition match against surveillance footage of a watch theft he had nothing to do with. The charge was dismissed weeks later. He was the first publicly known person wrongfully arrested in the United States on a face-recognition false positive. He is the answer to the second question, and the answer is that there was no recourse until after the cell door had already closed, because the machine did not flag a claim he made about himself. It made a claim about him, to someone else, and acted on it before he was in the room.
That is the difference between the old identity and the new one. The old identity was a name attached to a body in a place, and you carried it, and when someone disputed it you produced it and argued. The new identity is a score the machine computes about your body and asserts to a third party, and you are not a participant in the assertion. You are its subject. You find out what the machine decided about you the way Williams did, when the consequence arrives at the door.
The name attached to the body in the place is still there. It is, increasingly, decorative.