DPI-AI Framework: Vision paper on Building AI-Ready Nations through Digital Public Infrastructure
Treat AI as modular infrastructure, but make legitimacy modular too: risk-tier workflows with signed, bounded, revocable authority and built-in redress.
Review
The DPI–AI Vision Paper makes a significant architectural move. It argues that AI should not sit above digital public infrastructure as an opaque “intelligence layer”, but should be decomposed into modular AI Blocks invoked through DPI Workflows and surfaced via Public Agents. That framing is directionally correct. It treats AI as *composable capability* rather than institutional magic.
Where the paper remains aspirational is in its operational governance depth. Composability of services must be matched by composability of legitimacy. If AI Blocks are callable, then authority must also be callable, bounded, signed, and revocable. If workflows orchestrate identity, policy, and inference, then risk must be tiered explicitly. Not every workflow is equal. Informational assistance is not the same as a benefits denial. Conditional automation is not the same as a rights-affecting determination.
A risk-tiered workflow catalog and a clear governance operating model would turn this framework into a deployable blueprint. High-impact workflows must carry mandatory safeguards, binding policy gates, and built-in appeal mechanisms. Controllers, block providers, DPI operators, and ecosystem governors must have explicit accountability mapped to deployment, incident response, and certification. Without this, “interoperability” risks becoming a technical feature rather than a trust guarantee.
The core insight remains valuable: AI should plug into public infrastructure rather than replace it. But capability scales quickly. Legitimacy does not. The next step is to institutionalize assurance with the same rigor the framework applies to architecture.
Scoring reference (useful for operationalizing risk tiers): https://github.com/sankarshanmukhopadhyay/dpi-ai-governance-artifacts/blob/main/artifacts/dpi-ai-risk-scoring-matrix.md
Key Insight
Treat AI as modular infrastructure, but make legitimacy modular too: risk-tier workflows with signed, bounded, revocable authority and built-in redress.