Digital Public Infrastructure (DPI) is globally understood to describe the foundations for digital government or a digital economy, but how does the framework need to be extended and evolved to support an AI nation? How can nations leapfrog legacy ideas about DPI to ensure the necessary foundations for a rapidly changing digital economy that goes beyond the basics? Taking some time to review and update the current working definition of DPI is not only necessary to ensure effective and high impact digital investment for nations trying to support responsible and safe use of AI, but to avoid creating gaps in national digital public infrastructure programs.

A second, and perhaps more urgent reason to update our global understanding of DPI is because the foundational assumptions of good security it was based upon are now undermined by agentic AI, which can effectively mimic a real person and bypass traditional authentication and validation (including biometric) systems. Later in this article is a synopsis of the security issue facing traditional DPI models.

DPI can, and should, be an effective lever in nation building, ideally designed to drive multidimensional well-being and opportunities for all, building on the promise of government as a platform.

DPI often can refer to at least three different things:

  1. A series of specific digital platforms or capabilities relied upon for a digital economy (usually narrowly defined as digital identity, payment gateways and data exchange);
  2. An architectural framework for designing digital infrastructure (eg, architectural principles and standards) that can inform capabilities for a digital economy; or
  3. A shorthand way of describing any government digital infrastructure that people rely upon or have to interact with, such as government services.

For the purpose of this article, I explore (1) and (2) through the lens of the specific types of national digital capabilities required to support social, economic and cross-sector prosperity as we move into evolved digital and AI capable nations, including the impact on architectural principles and design. I also attempt to address the current gaps in the narrow DPI approach taken in some frameworks, as a provocation and contribution to global efforts to review and reconsider traditional DPI approaches.

DPI+AI - Updating DPI capabilities for an AI Nation

While DPI means different things to different people, a narrow definition of DPI has been commonly used around the world which includes three specific capabilities: digital identity, digital payments and data exchanges. This DPIx3 model has been adopted by governments, academia and development agencies around the world (DPI Map, 2025) and informs billions in development investments, even though these three capabilities have been proven to be necessary but not sufficient for digital transformation, for effective government services or for significant, sustainable or equitable economic growth. DPI and digital transformation is now starting to converge in unexpected ways with increasing AI adoption with a growing desire to evolve DPI to meet the needs of an AI nation (ref: The African Journal of Information and Communication (AJIC) Issue 35, 2025. Understanding interrelationships between AI and digital public infrastructure in India and Brazil).

Even before the rise of mainstream AI, Governments have found a narrow definition of DPI to be lacking in core capabilities to deliver services, streamline regulation, deliver policy outcomes, or to continuously improve national economic security and prosperity.

Traditional government responsibilities like regulation and grants management need to be more digital and data-driven, proactive and impactful in a fast paced world.

Government service delivery today requires omni-channel architecture and front-end integration of cross-portfolio business systems to achieve a seamless, inclusive and high quality citizen experience online and offline, from self-service to fully assisted. Regulated organizations would prefer the efficiency and lower risk of digital regulations and policy twins they could consume as a service. Policy outcomes would be easier and faster to deliver with digital policy infrastructure, capable of measuring, monitoring, modelling and proactively managing policy settings over time. AI introduces new complexities, particularly for higher risk systems which require real time monitoring and escalation (of AI inputs, outputs, models and socio-economic impacts), full lifecycle management of data and code, and technical guardrails like “pause buttons” and feedback loops.

Extending DPI to include some of these digital capabilities could dramatically improve the impact of digital investment while stimulating broader social and economic growth, productivity and innovation.

Below is a proposed model for a modern DPI+AI approach categorised by key capabilities, with each capability relying (at least in part) on the capabilities below it.

DPI Capability: Policy infrastructure (including digital regulation).

  • Intended Outcome & Public Benefit: The ability to efficiently, collaboratively and proactively design, deliver and optimise intended policy and regulatory outcomes including to drive national SDGs.

  • Public benefit: an enabler for streamlined regulatory compliance, public engagement on policy design and participatory governance.

  • National Platform(s): Digital Policy Twin(s) (public access to machine readable legislation, regulation, etc), policy modelling tool(s) and scenario testing, next gen policy steering mechanisms, public engagement tool(s), policy and impact monitoring and escalation

DPI Capability: Advanced analytics & AI

  • Intended Outcome & Public Benefit: The DPI required to activate safe and responsible national use of AI.

  • Public benefit: domestic language and context LLMs, reusable AI guardrails, sovereign AI supply chains for high risk AI across sectors.

  • National Platform(s): High risk AI guardrails (eg, monitoring of supply chain, inputs/outputs, models), public impact patterns analysis, sovereign LLM(s),

DPI Capability: Government service delivery

  • Intended Outcome & Public Benefit: High quality, inclusive and easy to use government services across all channels, from full self-service to fully assisted.

  • Public benefit: service excellence, but also improved access to justice through publicly reusable information about services, eligibility, decision making, etc.

  • National Platform(s): Payment system(s), omni-channel architecture, public/staff feedback, service/data registers, case management, notifications, delegation of authority

DPI Capability: Identity & security

  • Intended Outcome & Public Benefit: The ability to validate the identity of a person, official or organisation for high trust engagements/transactions.

  • Public benefit: high integrity docs and gov identity framework that could be reused across the economy, mechanisms to validate critical information, reusable AI security.

  • National Platform(s): Digital identity, high integrity domain name controls, biometrics & proof of life, official document verification, monitoring & escalation, proof of source (especially for critical information), agentic AI authentication

DPI Capability: Data/information

  • Intended Outcome & Public Benefit: The ability to share, verify or access relevant information, just in time, with user consent.

  • Public benefit: access to reusable public data and APIs for private innovation, transparency/accountability and to fuel new industries and services, high integrity and high trust management of public and private resources, ability to analyse market/economy for private decision making.

  • National Platform(s): Data exchange, linked administrative data, high integrity national statistics/census, land registry, vital records (birth, death, marriage, etc), data utilities & verifiable claims (conditional/action validation), consent infrastructure

DPI Capability: Connectivity

  • Intended Outcome & Public Benefit: So people can participate in the digital economy.

  • Public benefit: Equitable access to the internet is a precondition for digital inclusion. Securely managed DNS provides a public good where people can better trust (and transact with) websites that are assurable, also providing a mechanism to validate important national information or government notifications.

  • National Platform(s): Secure and well managed domain administration (DNS), universal and meaningful internet connectivity (mobile and/or fixed), public access points that provide access to anyone without is otherwise without connectivity.

Expanding the DPI architectural approach

The DPI architectural principles and standards adopted globally provide a strong framework for infrastructure that is extendable, extremely reusable and flexible in a rapidly changing world. There are two key ways this might be expanded for an AI economy.

Firstly, the very nature of IT risk management fundamentally changes when you have systems that are continuously learning and evolving independently of traditional (and manual) change management processes such as CI/CD pipelines and test-driven software and updates deployment. Most IT systems will have continuous monitoring of networks, access management and data, but not necessarily continuous monitoring of AI models, supply chains (data/code) or user inputs/outputs. Continuous monitoring of the entire system is especially required for high risk AI systems, which also require technical guardrails such as a highly accessible “pause” button, so that human overseers of AI systems can easily pause or stop them if they start to exhibit unexpected outputs or behaviours.

Secondly, very few government systems proactively measure and monitor for the intended (or unintended) impacts to the public, so how can government investment in infrastructure best drive policy intent and public outcomes on an ongoing basis? Including the intended public/policy impact is built into the architectural system design would dramatically improve the efficacy of DPI investment, supported by continuous testing against well-defined policy/public scenarios, and realtime monitoring of impact/outcomes (with escalation of any unintended impacts) built into the operating model. This would help ensure all government systems (including AI) are designed and optimised over time to drive their intended impact, not just to meet security and other compliance requirements, and would help to ensure any unintended impacts are identified and mitigated in a timely fashion.

A final useful addition would be to incorporate “user epics” into DPI design and implementation. User epics provide a methodology to ensure DPI is built in a holistic way that actually meets an entire need, whereas the absence of “user epics” can lead to technically strong capabilities that don’t work well for users. A framework of common user epics would be a powerful addition to the DPI architectural framework to ensure design, implementation and investment of DPI (and other capabilities) is programmed to meet real needs from real people who rely upon or interact with DPI (individuals or businesses). Below are a few example user epics which could inform the design and effective delivery of DPI:

  • As a citizen, I want to easily and conveniently find and access all government services that are relevant to me, with assistance if I have any issues.

  • As a business owner, I want to register and manage my business online, so I can be confident I’m complying with regulations and operating efficiently.

  • As someone interacting with a government chatbot or automated service, I want a clear explanation provided to me and an easy way to challenge the outcome.

  • As someone living in Australia, I want to be able to validate the source and authenticity of critical information like election results or payment details to buy a house, so I can avoid being scammed at important moments in my life.

  • As a parent, I want to access and manage my child's education information online, including grades, attendance, and communication with teachers.

  • As a resident, I want to report an issue with my local environment (e.g., a pothole, a street light outage) and track its resolution, so I can see tangible improvements.

Implementing high quality single purpose platforms (like payments or digital identity) in a modular and loosely coupled architecture provides enormous flexibility into the future, but single purpose platforms without the complementary capabilities needed to deliver an actual outcome can end up gathering dust and helping no one. User epics like these can be used during the design and delivery of DPI to ensure implementation meets a range of real needs, is genuinely multi purpose, and ensures that gaps in the architecture are identified and addressed when investing in DPI platforms.

Updating DPI assumptions to mitigate agentic AI risks

The security of DPI is built on the foundational assumptions that we can authenticate and validate a person is a) real; and b) who they say they are with c) the correct permissions to do what they are trying to do. But agentic AI systems are already proving to be able to effectively bypass these assumptions by mimicking a real person. Gemini on Android can already do this in a few ways: by hijacking identify verification; monitoring and intervening in authenticated spaces, accessing all parts of multifactor authentication before the user sees them; and even agentically navigating transaction websites or payments on the user’s behalf. If we accept biometrics from an Android user, we are actually accepting Android's attestation that the user authenticated, but an AI with sufficient access could have “passed” those used biometrics itself without any real user engagement. Similarly, when analytics see a browser, we assume a user is controlling the browser, but AI agents can do that on a user's behalf. It may be possible to mitigate this by establishing agentic tool chains and pathways, or with cryptographic proofs of consent for an agent to act on a user’s behalf. However, this kind of solution is untested at scale, and doesn't resolve the issue of detecting malicious agents. Whatever the case, investigation and deployment of agentic authentication/security solutions need to be included in DPI frameworks moving forward, and should be a priority for government investment.

Next steps on DPI for an AI Nation

As nations around the world explore and shape what it means to be an "AI Nation" taking the deep and hard won lessons from several decades of digital, it is a timely opportunity to reassess what we know and think about DPI. I hope this article has provided both some ideas and provocation to stimulate an evidence and experience based approach to evolving our shared understanding of DPI, so we can help ensure government investments in digital can more effectively deliver meaningful outcomes and whole of nation enablers for a more inclusive, equitable, prosperous and safe society.

This article was kindly reviewed (and improved!) by Michael Lisser, Possum Hogkin and Alex Oprunenco, with thanks.