Digital Public Infrastructure · 2026-03-05

DPI-AI Framework: Vision paper on Building AI-Ready Nations through Digital Public Infrastructure

Centre for Digital Public Infrastructure (CDPI)Original paperMarkdown source
digital public infrastructureAI governancepublic sectorworkflowsrisk tieringassurance
Key Insight

Treat AI as modular infrastructure, but make legitimacy modular too: risk-tier workflows with signed, bounded, revocable authority and built-in redress.

Review

The DPI–AI Vision Paper makes a significant architectural move. It argues that AI should not sit above digital public infrastructure as an opaque “intelligence layer”, but should be decomposed into modular AI Blocks invoked through DPI Workflows and surfaced via Public Agents. That framing is directionally correct. It treats AI as *composable capability* rather than institutional magic.

Where the paper remains aspirational is in its operational governance depth. Composability of services must be matched by composability of legitimacy. If AI Blocks are callable, then authority must also be callable, bounded, signed, and revocable. If workflows orchestrate identity, policy, and inference, then risk must be tiered explicitly. Not every workflow is equal. Informational assistance is not the same as a benefits denial. Conditional automation is not the same as a rights-affecting determination.

A risk-tiered workflow catalog and a clear governance operating model would turn this framework into a deployable blueprint. High-impact workflows must carry mandatory safeguards, binding policy gates, and built-in appeal mechanisms. Controllers, block providers, DPI operators, and ecosystem governors must have explicit accountability mapped to deployment, incident response, and certification. Without this, “interoperability” risks becoming a technical feature rather than a trust guarantee.

The core insight remains valuable: AI should plug into public infrastructure rather than replace it. But capability scales quickly. Legitimacy does not. The next step is to institutionalize assurance with the same rigor the framework applies to architecture.

Scoring reference (useful for operationalizing risk tiers): https://github.com/sankarshanmukhopadhyay/dpi-ai-governance-artifacts/blob/main/artifacts/dpi-ai-risk-scoring-matrix.md

Key Insight

Treat AI as modular infrastructure, but make legitimacy modular too: risk-tier workflows with signed, bounded, revocable authority and built-in redress.

Appears in these collections

Continue exploring

Related reviews

More in Digital Public Infrastructure
Digital Public Infrastructure · 2026-05-04

DPI@2047 for Viksit Bharat: A Strategic Roadmap to Enable Non-linear Inclusive Socio-economic Growth

NITI Aayog / NITI Frontier Tech Hub

DPI@2047 treats digital public infrastructure as market-making state capacity, but it does not operationalize the governance layer that must decide who controls data flows, AI-mediated decisions, ecosystem access, revocation, redress, and accountability across decentralized implementation.

Digital Public Infrastructure · 2026-05-06

Building Digital Foundations in Small Island Digital States 2.0

United Nations Development Programme

The brief treats SIDS digital transformation as an institutional capability problem rather than an ICT rollout problem, but it still needs a sharper operating model for authority, assurance, revocation, redress, and supplier accountability across shared digital infrastructure.