Governments in the AI era
The Government AI Playbook, Part 2: Credentials Before Chatbots
Cari · 2026-09-17 · 6 min read
TL;DR: A citizen chatbot built on top of paper processes can only explain the queue faster. Governments that want AI to actually change service delivery need to fix the foundation first: verifiable credentials that make every document instantly checkable, then digital workflows that can complete end to end, and only then a conversational layer on top. Sequence matters more than model choice.
In Part 1 of this playbook we argued that government AI should start with the queue, the real backlog of applications, renewals, and approvals that citizens are actually waiting on. Part 2 is about what has to be true underneath before an AI assistant can do anything meaningful about that queue.
The chatbot rush
Right now, ministries everywhere are shipping citizen chatbots. The demos are impressive. Ask about a business licence and the bot answers in seconds, in plain language, in the citizen's own words.
Then the citizen asks the obvious follow up: can you do it for me?
And the honest answer, almost everywhere, is no. The bot can describe the form, but the form is still paper. It can explain the requirements, but the supporting documents still need to be photocopied, stamped, and carried to a counter. It can tell you the office hours, but you still have to stand in the line.
A chatbot on top of a paper process is decoration on a broken foundation. It does not shorten the queue. It explains the queue faster.
Why identity and verification come first
The reason most government workflows cannot complete digitally is not a missing chatbot. It is that nobody can trust a document without phoning someone.
Think about what actually happens when a citizen submits a permit application. An officer receives a birth certificate, a land title, a prior licence, a tax clearance. Every one of those documents was issued by some other office, and the receiving officer has no fast way to know whether any of them is genuine. So the process falls back to the oldest verification protocol there is: call the issuing ministry, wait for someone to check a ledger, wait for a letter back.
That phone call is the real queue. The counter is just where it becomes visible.
Verifiable credentials remove the phone call. A verifiable credential is a document issued as signed, structured data under the W3C standard. The citizen holds it, presents it wherever it is needed, and any receiving system can check the cryptographic signature in milliseconds. Verification does not phone the ministry. It does not even require the issuing ministry's systems to be online at that moment. The mathematics does the checking.
This is why Cari issues every permit as a W3C verifiable credential by default. Not as a premium feature or a later phase, but as the base case. A permit that cannot verify itself is a permit that will eventually put someone back in a queue.
The sequence that actually works
Once you see the phone call as the bottleneck, the right order becomes clear.
First, credentials. Make the documents themselves checkable. When a permit, licence, or registration is issued as a verifiable credential, every downstream office that touches it stops needing to confirm it manually. Fraudulent documents fail verification instantly instead of surviving for years inside paper files.
Second, workflows. Once documents verify themselves, processes can actually complete digitally. An application that needs a tax clearance and a prior licence no longer stalls waiting for two other offices to answer letters. The system checks both credentials at submission time and moves on. This is the step most digital government projects skip, which is why so many online portals end with the words print this form and bring it to the office.
Third, and only third, the assistant. When the rails underneath can actually finish things, a conversational layer becomes transformative instead of cosmetic. Now the answer to can you do it for me is yes. The assistant collects the credentials from the citizen's wallet, submits the application, and the workflow completes because every input verifies itself. The AI is no longer a narrator of a broken process. It is an operator of a working one.
The trust argument
There is a second reason to sequence this way, and it may matter more than the efficiency case.
Language models sometimes get things wrong. When a chatbot hallucinates an answer about a permit requirement and a citizen loses a day, or a fee, or a court date because of it, the damage is not limited to that one interaction. Citizens generalise. The government's digital services become something you double check in person, which defeats the entire purpose.
Cryptographic verification runs in the opposite direction. Every time a credential verifies, trust compounds. The citizen learns that the digital document is not a picture of the truth but the truth itself, checkable by anyone, forgeable by no one. That is the kind of reliability a public institution can build a reputation on.
So the sequencing rule can be stated simply: put the deterministic layer under the probabilistic one. Let cryptography handle the facts and let the AI handle the conversation. A chatbot resting on verifiable rails inherits their credibility. A chatbot resting on nothing spends credibility it never earned.
What this looks like for one ministry
None of this requires a whole of government transformation programme. The practical path for a single ministry looks like this.
Start with one registry. Pick a permit or licence type with real volume and a painful verification loop. Stand up a digital registry for it. On Cari, 13 registry types deploy in minutes, so the setup cost of this step is no longer the barrier it used to be.
Issue credentials alongside paper. Do not rip out the existing process on day one. Every new permit goes out in both forms: the paper the citizen expects and the verifiable credential the future runs on. Receiving offices can start checking signatures instead of making calls, and the paper quietly becomes the backup rather than the record.
Speak the same language as everyone else. Registries only pay off when their data connects, across ministries and across borders. This is why being standards native matters: Cari ships with 24,789 UN/LOCODE location codes and 6,939 Harmonised System codes built in, so a permit issued in one country is legible to a port, a bank, or a ministry in another without a translation project.
Then add conversational access on top. With the registry live and credentials flowing, the assistant has something real to operate. It can check status against the actual registry, submit applications that actually complete, and answer questions with the registry as its source of truth rather than its best guess.
Common questions
Should we cancel our chatbot project? Not necessarily. Reframe it. A chatbot scoped to answering questions from a verified registry, with clear limits, is useful today. The mistake is treating the chatbot as the digitisation strategy rather than the interface to one.
Do citizens need smartphones for verifiable credentials? A credential is data, not an app. It can live in a phone wallet, but it can also be printed as a QR code on the paper document itself, which means the same physical permit a citizen already carries becomes instantly checkable.
How is this different from putting documents in a database? A database record is trusted only as far as the database is. A verifiable credential carries its own proof, so it can be checked by another ministry, a bank, or a foreign port without granting them access to your systems and without them phoning your office.
The queue is the symptom. The phone call is the disease. If your ministry is ready to sequence this properly, from one registry to credentials to an assistant that can actually finish things, you can see how country onboarding works here.