> ## Content Index
> Fetch the complete content index at: https://aiaffairs.nz/llms.txt
> Use this file to discover other available public pages before exploring further.

# New Zealand’s DPI Must Identify More Than People
- URL: https://aiaffairs.nz/new-zealands-dpi-must-identify-more-than-people/
- Published: 2026-08-01T00:00:00.000Z
- Updated: 2026-09-20T23:41:46.000Z
- Author: Mehrdad Fatemi
- Tags: Editorials, Aotearoa, AI Architecture, Policy & Regulation, From the Publisher

New Zealand has built a strong, people-centred digital identity foundation. But effective digital public infrastructure must also establish what produced data, where it relates to, and which AI agent acted under whose authority. Extending trust to things, places and agents would improve automation, safety and accountability without requiring a central surveillance registry.

## New Zealand should evolve its trust framework as an identity–location–provenance fabric, not simply a digital ID system.

The Digital Identity Services Trust Framework primarily addresses personal and organisational information. W3C decentralised identifiers, by contrast, can identify devices, assets, places, datasets and software agents; Verifiable Credentials can attach trusted claims such as ownership, calibration, permissions and status.

Decentralised identifiers can give a sensor, building, dataset, vehicle or AI agent a persistent, cryptographically verifiable identity without making one central registry the universal gatekeeper. W3C’s DID standard explicitly allows identifiers for people, organisations, things and abstract entities; verifiable credentials can then attest ownership, certification, authority, software version or delegated permissions.

Location needs similar discipline. A deterministic geotag might come from surveyed coordinates, GNSS or an authoritative place identifier. An inferred location may combine IP, Wi-Fi, cellular and sensor signals, but should carry a confidence score, accuracy radius, timestamp and method. Inference improves coverage, but creates privacy and false-certainty risks; even vehicle GPS data can become personal information under New Zealand privacy law.

Finally, identity and location are not enough without provenance: who or what created the data, what changed it, under whose authority, and whether credentials remain valid. W3C PROV, GS1 EPCIS and C2PA demonstrate interoperable approaches for supply-chain events, datasets and digital media.

- Identify every participant: people, organisations, assets, places, datasets and agents.
- Treat inferred location as an assertion—not a fact.
- Bind credentials to accountable issuers, delegated authority and revocation.
- Mitigate spoofing and centralisation through signed evidence, multi-source corroboration, key rotation, selective disclosure and open governance.

---

*Originally published on* [*LinkedIn*](https://www.linkedin.com/pulse/new-zealands-dpi-must-identify-more-than-people-mehrdad-fatemi-9vlbe/?ref=aiaffairs.nz)*.*