Governments in the AI era
Verifiable Credentials, Explained for Ministers
Cari · 2026-09-03 · 8 min read
TL;DR: A verifiable credential is a digital version of a government document that carries its own proof, so a bank, a landlord, or a border officer can confirm in one second that it is genuine, unaltered, and issued by your ministry, without ever calling your ministry. It is an open world standard, not a product, and it is the most practical defence a government has against AI-generated forgeries.
A licence, and then a year of proving it
Consider a citizen who does everything right. She registers her business, pays her fees, waits her turn, and receives her licence from the ministry. The document is real. Her problems are just beginning.
The bank will not open her business account until it confirms the licence is genuine. So the bank calls the ministry. The line is busy, the officer who signs verification letters is on leave, and the file takes three weeks. Then her landlord wants the same confirmation before signing a commercial lease. Then a supplier abroad wants it. Then a border agency wants it. Each verification is a phone call, a letter, or a stamped copy, and every one of them lands on a ministry desk that already has a queue.
Multiply her by every licence, permit, certificate, and registration your government issues, and you can see where a large share of your public service's time goes: confirming that documents you already issued are real.
The idea in one sentence
A verifiable credential is a digital document that carries its own proof, so anyone can check that it is genuine, unaltered, and issued by you, in about one second, without contacting your ministry.
The proof is a digital seal, a piece of mathematics attached to the document when you issue it. Think of it as a wax seal that cannot be copied and that shatters visibly if anyone changes a single letter of the document. Checking the seal takes software a fraction of a second, and the check answers three questions at once: did this ministry really issue it, has it been altered since, and is it still valid.
The standard behind this is published by the W3C, the same international body that maintains the standards the web itself runs on. It is public, free to use, and implemented by many vendors worldwide.
Three roles you already know
The system has three roles, and your government already performs all of them on paper today.
The issuer is the ministry. It creates the credential, applies its digital seal, and hands it over, exactly as it prints and signs a paper licence now.
The holder is the citizen. She keeps the credential in a digital wallet on her phone, the way she keeps the paper in a drawer, and she alone decides when to present it and to whom.
The verifier is whoever needs to trust the document: the bank, the border agency, the employer, the foreign supplier. The verifier checks the seal with software and gets an instant answer. No phone call, no letter, no queue at the ministry.
Notice what changed. The ministry's authority is still the source of trust. What disappears is the ministry's role as a switchboard that must be reached every time that trust needs confirming.
What it is not
Three misconceptions come up in every cabinet discussion, so it is worth settling them plainly.
It is not a central database that outsiders browse. Verification does not phone home to a government system. The citizen presents her credential, the verifier checks the seal, and the transaction happens between those two parties. There is no portal where banks rummage through your registries.
It is not surveillance. Because verification does not phone home, the ministry does not learn where the citizen used her credential. Government does not gain a log of which banks, landlords, or borders she showed it to. In fact this arrangement is more private than today's system, where every verification call tells the ministry exactly who is checking on whom.
It is not vendor lock-in. Because W3C verifiable credentials are an open world standard, a credential issued under it works with any compliant software. If your government changes technology providers in five years, citizens keep their documents and verifiers keep the ability to check them. You are adopting a standard, the way you adopted PDF or email, not marrying a supplier.
Why this matters now
Two forces make this urgent rather than merely interesting.
First, AI has made forgery cheap. A convincing fake licence, certificate, or letterhead now takes minutes to produce and costs nothing. Visual inspection, stamps, and signatures were already weak defences; against generative AI they are no defence at all. A digital seal cannot be faked without the ministry's own issuing key, so the mathematics holds even when the eye cannot. Cryptographic verification, which simply means checking that seal by machine, is the countermeasure that scales.
Second, trade is cross-border and trust is not. A bank in another country cannot call your ministry, does not know your letterheads, and will discount your citizens' documents accordingly. A verifiable credential is checkable from anywhere on earth in one second, which means your exporters, professionals, and businesses carry proof that travels as fast as they do.
What adoption looks like in practice
This is not a whole-of-government digital transformation programme. The sensible path is small and measurable.
Pick one high-friction permit, one where your officers spend real hours answering verification requests. Issue it as a verifiable credential alongside the paper, so nothing breaks and no one is forced to change. Then measure the drop in verification calls over a quarter.
When the numbers come in, expand registry by registry, in order of pain. The paper can remain for as long as you want it to; the credential simply does the verification work the paper never could.
This is how Cari approaches it: every permit issued on the Cari platform is a W3C verifiable credential by default, with the paper document alongside it, so governments get the benefit from the first permit without a system migration.
Common questions
What does it cost? Far less than a national ID scheme or a new registry system, because you are adding a digital seal to documents you already issue, not rebuilding the registry behind them. The main costs are the issuing software and a modest change to one permit workflow, and the savings begin with the first verification call that no longer happens. Starting with a single permit keeps the initial commitment small enough to evaluate like a pilot, not a programme.
Is this safe for citizens' privacy? Safer than the status quo. The citizen holds her own credential and chooses when to show it, the ministry never learns where it was used, and a credential can reveal only what is needed, for example proving a licence is valid without exposing the holder's home address.
What if the technology landscape changes? The credential outlives the vendor. Because the format is an open international standard, documents issued today remain checkable by any compliant software tomorrow, under a different supplier or a different government.
If you are weighing where a first credential pilot would relieve the most pressure in your own registries, we have laid out the practical starting path at cari.global/country-onboarding.