It is tempting to think of an identity system as a piece of technology: a database, biometrics, software, authentication, and the infrastructure that connects them. While these are unquestionably important, they are only part of what makes an identity system work, and not the full answer.
An ID system eventually becomes part of how a country works. It interacts with institutions and services, with laws and policies, with the people who operate it and the people who use it. As those things change and evolve, the identity system has to change with them.
I have understood this increasingly clearly through my involvement with MOSIP, and it is particularly relevant to reflect on today, as more than 200 million IDs have been generated on MOSIP-based systems around the world.
When we began building MOSIP at IIIT-Bangalore in 2018, we were not setting out to build what would later come to be described as Digital Public Infrastructure. The language around Digital Public Goods and DPI was not yet what it is today. The small team of technologists who envisioned and founded MOSIP, did so in an endeavour to respond to a very practical problem:
Countries that wanted to build digital identity systems often had to choose their systems from technology that was proprietary, expensive in perpetuity, and difficult to adapt to changing needs. It was becoming increasingly important to countries to own their infrastructure, rather than become permanently dependent on any external factor.
The larger idea came from solving this problem well.
Looking back, I think that distinction is important. MOSIP did not become part of global DPI discourse because we set out to join a contemporary conversation. We built an important piece of digital infrastructure according to principles we believed were right: open-source, modularity, security, interoperability, vendor neutrality and, most importantly, country ownership.
The fact that these principles fit naturally into today's understanding of Digital Public Infrastructure is reassuring. It confirms that the early instincts were sound.
But perhaps the more interesting part of the story is what countries have done with the platform since.
Morocco, our first country partner, signed on before a single feature had been built. Its implementation has since grown into a national system and helped establish a path for others to follow. The Philippines has taken MOSIP to its largest deployment to date, with more than 94 million IDs generated. Ethiopia independently discovered MOSIP and has adapted it to its own context, integrating it with existing records and connecting identity to an expanding network of 90+ public services. Togo was the first country to use MOSIP's Rapid Pilot model, showing that a national identity platform could be tested and adapted within a much shorter cycle. Uganda has taken a different path again, using MOSIP in a Brownfield implementation to build on an existing identity system and extend it to meet today's needs. In fact, every one of the 30+ countries that has engaged with us has taught us something.
These are not variations of a single MOSIP blueprint. They are different national journeys, defined and led by people who understand their countries with insight that could only have come from the inside.
That matters because there is no universal recipe for identity. Population sizes differ, as do existing systems, laws, institutions, infrastructure, languages, and public expectations. A technology platform that expects every country to work in exactly the same way will eventually become a constraint rather than useful infrastructure.
At IIIT-Bangalore, we have historically believed that when we build something for a public institution, our responsibility does not end when the software is delivered. Our role was first to offer a strong foundation, and then to support countries as they made it their own, learn from what happened in practice, and remain available when they needed us.
The milestone we touched in August 2026 – reaching 200 million generated IDs on MOSIP-based systems – is significant, and worthy of celebration. It is also a reason to ask new and different questions.
Technology matures through learning, iteration, and better engineering, but people do not remain constant, and so neither can technology. The way a 20-year-old understands identity is likely to be very different from the way someone of my generation understands it. The ways in which people interact with technology will change, expectations around privacy will change, and countries will find new uses for identity that we cannot predict today.
We have to be ready for that.
For MOSIP, that means thinking beyond the issuance of an ID. If we are responsible for a foundational identity platform, we have to care about what happens to that foundation as the world around it changes. That means continuing to ask questions about authentication, privacy, credentials and the ways identity connects with other forms of digital infrastructure.
It also means listening to expert voices in an extensive and diverse ecosystem of country decision-makers, technologists, and academics, and doing the quiet, honest, and often difficult work of ensuring enough of those voices are informing the decisions we make.
Some of the most useful things we learn about identity may not come from a technical specification or a laboratory. They may come from talking to someone in a village in Ethiopia or a barangay in the Philippines and asking them what they actually do with their digital ID. They may come from an implementation team discovering that a process we designed one way works better another way. They may come from a country telling us that an assumption we made simply does not fit its reality.
This is one of the advantages of being part of an academic institution. A university is a place of inquiry, where it should be possible to question the answers we already have.
In my career, I have repeatedly found that ideas endure for a myriad of reasons: because they have been scrutinised from different directions, because the people behind them are willing to adapt, and because diverse perspectives have been welcomed into the room.
Two hundred million IDs is evidence of something that matters beyond the number itself. It is confirmation that countries can, and should, build critical digital infrastructure with greater ownership, flexibility and choice. That open technology can work at national scale. And that countries can learn from one another rather than having to start from scratch each time.
This milestone belongs to countries and the people they serve.
We were fortunate to build the foundation. The countries that use it have already taken MOSIP in directions we could not have imagined, adapting it to their own systems, contexts, and ambitions. I suspect that will continue to be the story.
Our responsibility is to keep listening, learning, and improving the foundation as needs evolve. What countries build with it and where they take it next, is theirs to decide.
That is a good place for a foundation to be.