Hello, everyone. Thanks for getting up bright and early. Hello. Hello. Thank you for the hoots and hollers. Appreciate it. I'm Elizabeth Garber. I'm the marketing and strategy director at the OpenID Foundation, and I also lead an initiative called City Hub as the program coordinator and the secretariat. We'll get into a little bit about what that means shortly.
This talk, by the way, I should say, this is primarily the thought leadership of Gail Hodges, who was unable to be here today, so I am going to be glancing down here at my speaker's notes a little bit, so I hope you'll forgive me. As we take a bird's eye view of what's going on in not just the digital identity industry, but in many related industries, we can see trends like policies cascading from one country to another. Digital identity is just one of several waves of policies that are moving across the globe. We have 160 EID policies and regulations.
We have 130 plus data privacy laws now on the books. We have 90 plus countries moving towards open banking, open finance, open data. Sixty plus countries have digital identity laws. More than 60 have age assurance policies, and then what's coming next, AI, several others. One of the observations we see is that as countries approach the themes of digital identity, open finance, faster payments, they do it in different ways. Some countries are looking at them as one major construct, while others are implementing them separately.
We also see a mix of private sector and public sector-led approaches to all three of these domain spaces. There's not a one-size-fits-all as to how countries roll out these policies and technologies. One of the things that we like to look for in the OpenID Foundation is whether the door is being kept open to interoperability both within and between countries. Another trend around the world is digital public infrastructure. You hear this a lot at the G20, the OECD, when you work with the African Union.
I hear it, I work with the digital public infrastructure group at the UN. DPI are essentially digital tools that are built on top of the hard infrastructures put in place by a nation, and they become components that are used across government systems, things like e-signatures, things like payment processes, identity. We want to be clear that the term DPI does not refer to things that are built inside government. There is an intrinsic mix of public and private sector products, services, and ecosystems inside this term. These are complex ecosystems, and governments play a vital role.
They are digital identity acceptors, they enable government services, and it is a regulator of digital ID ecosystems. But the private sector is playing a vital role as well. The private sector is often building this infrastructure, and of course they are acting as verifiers all across the ecosystem. When building ID systems, there are of course lots of layers, and every country is building their own layers of policy and technical tools, from an operational and technical point of view, and also from a legal regulatory and legislative point of view.
What this means across the global landscape is that actually we have a bit of a mess going on here. We have different standards being selected in one part of the world, different open-source software, different laws, regulations, etc, so the layers of challenge to interoperability become pretty complex. So who is winning in this world of complexity?
We see $9.2 trillion of cybercrime which is equivalent to the third largest country by GDP volume, and it is growing faster than any country, so it is easy to see that in this world of complexity, and a lack of interoperability, the bad guys are winning. So the key challenges we are all facing, we have talked about interoperability and security of these stacks, but as we said earlier, most countries have privacy policies now, but privacy, even the wealthiest countries and businesses struggle to deliver at the protocol layer by default. Think for a moment about protecting our children online.
Despite all of our technical talents and standards, policies, we arguably have a failing grade in our ability to protect children and the vulnerable. So it is our global community and the most vulnerable among us, including the young and the elderly and disadvantaged. Last but not least, is that with this constellation of policy and tech stacks, we create an incredible compliance burden for the smallest companies around the world.
They struggle with market expansion and the cost of compliance due to the challenges of translating these cascading policies into profiles and standards that can allow for compliance with the law by default. And we can see the storm clouds rolling in. We've got all sorts of new technologies emerging, AI, agentic tech, competition versus public goods, digital public goods, data localisation, inconsistent use of standards, there is seismic change going on in development funding, tariffs, cloud-based infrastructures and limited expertise among senior leaders.
So if we really want domestic interoperability and cross-border interoperability, standards bodies around the world need to be collaborating. They need to be finding public and private funding for shared resources. And that's where CityHub comes in. CityHub stands for the sustainable interoperable digital identity, and it's basically a global collaboration for folks interested in digital identity solutions that are interoperable across border and solve local challenges.
By digital commons, we mean we're building, curating and creating a set of tools to help ecosystems implement safe interoperable digital identity. We have several core founding principles. Number one, human centricity and human rights. Number two, domestic sovereignty. Each country should be empowered and is entitled to make their own choices about the architectures that work for them. Multilateral engagement. So we can't solve this alone in a room with standards bodies. We need to be engaging with the international aid organisations.
We need to be engaging with the governments themselves, with the private sector, as well as the public sector. Our fourth principle is that we are grounded in the use cases for digital identity, especially cross-borders. We're grounded in the knowledge of how individuals will be using digital identity in their day-to-day lives as they try and use their education credentials earned in one country to obtain a job in another.
Finally, technology normalisation, as well as technology normalisation. So how do we deliver on these principles?
Well, CityHub has been going. We launched in November of 2023, and, over the course of the last year, we have led public sessions in five countries around the world, so we met in Paris, in Cape Town, in Berlin here before EIC last year, Washington, D.C., and Tokyo.
So, yes, it was five. We also work to build upon the work that was primarily led out of the Open Identity Exchange, which sadly is no longer with this community.
Thank you, Nick Mothershaw, for all your thought leadership over the years. So we're building on the work conducted at OIX to build trust frameworks and practices related to trust frameworks around the world. And we're also continuing the work of the Global Assured Identity Network, GAIN, and other similar ventures to try to identify architectural patterns that enable networks of networks around the world. We do research into champion use cases, and we try to support in-country wherever possible. CityHub is directly aligned to the OECD principles, among others.
It is a global multi-stakeholder community. It's facilitated by dozens of non-profits in the identity space, and last year, we met with this many countries. I think that number is about 35. So last year, we developed reports on three champion use cases that I would encourage you all to go and visit on our website, city-hub.community. We wrote a use case about education, refugees, and opening a bank account across borders. As I mentioned, we're building on the work done out of OIX to enable digital ID governance. We're expanding trust framework analysis.
We're working collaboratively to develop standardized rule books, a trust framework comparison tool, and policy criteria metadata exchange methods. And if we can compare trust frameworks this way, then we can code it. So that's the point of the trust framework analysis. Technical tools to enable cross-border trust. So this year, we're working on an analysis of key protocols, architectural patterns to enable cross-border interoperability, and then a technical proof of concept.
So in this multi-stakeholder community, we are working across multi-stakeholders, and we are working to build out a commons, create, curate tools that enable policy, design and delivery, as well as technology. 90 per cent of the participants in City Hub agreed that the work needed to continue, and we invite you to be a part of it. That's it from me. Thank you so much, Elizabeth. We're very grateful for you stepping in at the last minute, especially under the circumstances. So we really appreciate that.
I haven't got any questions from the audience yet, but I just wanted to ask you which jurisdictions do you think are currently leading in implementing identity and trust frameworks that balance innovation with privacy and security? Well, I think you can't question that EIDIS is a leading exemplar. I also think that Ad Har continues to be an exemplar of, as they develop their digital stack and their privacy legislation, which admittedly came after the Supreme Court case, but it continues to be a fantastic example.
Okay, and of course all the great work that you're doing. Please everyone, give it up for Elizabeth Garber. Thank you.