Publicado 16 de septiembre de 2026

Mitigating AI Privacy Risks in Latin America

Identity Infrastructure, Institutional Capacity and the Path to Adoption

Authors
Claudio Cifuentes LoboDirector de Investigación y Alianzas
Marcus AlburezCofundador
Research advisors
Said Saillant, Ph.D. Asesor sénior, Gobernanza de IA
Case studies
QuarkID / miBA, Sovra, Blerify, World, Proyecto DIDI

The report is published in English. This page’s navigation is localised; the research text is not.

The question

Artificial intelligence is producing measurable harm in Latin America, and most of it lands on privacy. Synthetic media now defeats the identity protocols and biometric checks that banks and governments rely on. Phishing runs at industrial scale. Personal data flows into systems that answer to nobody in the populations they classify.

This report asks whether decentralized identifiers, verifiable credentials and zero-knowledge proofs, part of Ethereum’s cryptographic stack, can work as practical infrastructure against those risks. It examines five cases in the region, three of them live, and what each could carry.

Read Report

Three findings

01

The rails already exist, and they are more deployed than anyone assumes

The region’s government-backed identity infrastructure is more mature and more widely deployed than public awareness suggests. Three of the five are in production, issuing credentials to people now.

  • QuarkID is the most widely deployed DID protocol in Latin American government infrastructure that this research identified, running in Buenos Aires and, through Sovra, in Nuevo León and Salta.
  • QuarkID counts 1.8 million DIDs created on-chain by July 2026, per a public Matter Labs query. The count covers every issuer on the protocol, Sovra’s programmes included, and measures DIDs rather than unique users.
  • Blerify piloted a decentralised trust list with AGESIC in Uruguay, the only primary-source government confirmation in the dataset.
02

Private companies make the AI-risk case. Public institutions do not

The AI-risk use case is stated openly by private companies and almost nowhere by the public institutions that would deploy it. Governments run verifiable credential programmes built on the same cryptographic techniques, but issue them for documents, benefits and identity, and none against AI risks. The value of infrastructure they already operate goes uncollected.

  • World positions biometric enrolment as proof of human for an internet crowded with AI.
  • Blerify sells verifiable credentials as a way to withstand deepfakes and retire KYC checks that no longer hold.
  • Sovra now advertises an identity layer for government AI agents.
  • No public deployment in Latin America uses its identity infrastructure as an instrument against the privacy risks of AI.
03

What is missing is not technology

Smart contracts, advanced cryptography and biometric enrolment are in place and working. The legal instruments, the public policy and the advocacy that would carry them are barely started.

  • Panama’s digital driving licence was built and announced for 12 May 2026 and remains unavailable, pending its legal framework.
  • El Salvador’s national ID is complete and awaiting legislative reform, though no Salvadoran source names Blerify in connection with it.
  • Regulators can take a year or more to reach a conclusion about a version of a system that no longer exists.
  • Proyecto DIDI ran into digital literacy rather than cryptography.

Five Case Studies

What each one does, what it is worth against an AI privacy risk, how far it has actually got, who issues it, which credential format and which proofs it uses, where it settles, and the standards it implements.

What it does
Government-operated decentralized digital identity protocol integrated into the miBA city app, so that residents hold and present verifiable credentials with selective disclosure.
Relevance for AI privacy-risk mitigation
No AI component in its original version; credentials are issued for documents, benefits and identity. Relevant as the reference for an interoperable standard across governments at regional scale, the shared rail on which an AI layer would be built.
Status
Live Public launch in miBA, October 2024; 60+ document types available; 1.8 million DIDs created on-chain by July 2026. The consortium that built the protocol has since dissolved; no QuarkID 2.0 specification as of August 2026.
Deployments and counterparts
City of Buenos Aires, Argentina. Counterpart: the Government of the City of Buenos Aires, which operates the system as public issuer. Sovra reuses the protocol in Nuevo León and Salta (see Sovra).
Credential format and proofs
W3C DIDs and Verifiable Credentials; selective disclosure through BBS+ signatures applied in the wallet, not independently verified by this research.
Anchoring / settlement
zkSync Era (Ethereum Layer 2); Sidetree method with Merkle proofs for state. Settles to Ethereum.
Standards implemented
W3C DID CoreW3C Verifiable Credentials Data ModelSidetreeTrust over IP alignment

Four areas

13 Recommendations

Entering government, standards and interoperability, education and institutional capacity, and pilots with institutional partners.

I Closing the integration gap and entering government

  1. 01

    In the cases studied, a government-first strategy is what unblocked the application of cryptography and AI products.

    Cryptographically-backed credential ecosystems stall on a coordination problem: issuers and holders will not invest before verifiers exist at scale, and verifiers will not invest before holders do. A government issuer resolves both sides at once, producing a large base of legitimate credential holders and, through its own administrative procedures, verification demand that no private issuer can manufacture. The regulatory work follows from that rather than preceding it: having a government-scale implementation already running is what made it possible to push for rules permitting decentralized alternatives to mandatory centralized records. Two vendors and one city are the pattern this research found; whether it holds as a general rule is a question for a larger sample.

  2. 02

    Identity programs built on cryptographic rails already exist in LATAM: consider building AI layers on top of them.

    No public deployment in Latin America uses its identity infrastructure as an instrument against the privacy risks of AI. The one actor in the region with a track record on that problem is private: World has built multiple institutional partnerships to verify that humans rather than AI agents are on the other side of an interaction. Governments run verifiable credential programs built on similar cryptographic techniques, but issue them for documents, benefits and identity, never against AI risks. The first move is to put it on the agenda of the programs already running, on Ethereum or not.

  3. 03

    Lead with the AI-threat argument, and give officials something they can defend internally.

    Government decision-makers are not procuring cryptographic infrastructure; they are accountable for citizen protection and are under political pressure from AI-driven fraud. What carries the conversation toward cryptography as a usable instrument against that fraud is precedent, international and regional, of the two being deployed together. Precedent moves the decision from evaluating an unfamiliar vendor to joining something governments comparable to them have already committed to. What the ecosystem lacks is a shared version of this argument, with the incident evidence and both levels of precedent already assembled, so that the official across the table has something to take into a budget meeting instead of each actor rebuilding it from scratch.

  4. 04

    Mid-size countries may offer fewer veto points and shorter timelines.

    Countries in the 3 to 12 million population range (Panama, El Salvador, Dominican Republic, Uruguay, Costa Rica) concentrate the decision in fewer hands than the large LATAM economies, where a credential layer has to clear a federal government, its agencies and the subnational units that will issue. That band widens the 4 to 10 million pattern Blerify reported from its own government engagements, so as to take in three countries whose digital identity procurement this research did not confirm. Sovra's confirmed deployments show the shape of that: both are a state and a province rather than national programs. For pilots under time and resource constraints it is a reasonable working hypothesis, drawn from two vendors' engagements rather than from a comparison this research ran.

  5. 05

    Budget the legal framework into the initial deployment roadmap, with as much weight as the technology, if not more.

    Throughout our case studies, teams pointed out that it's common for technical iteration to outpace regulatory oversight, where an authority reviewing a system can take a year or more to reach a conclusion about a version that no longer exists. Regulators do not have the time, incentives or capacity to close that gap themselves, so a project that treats legal work as something that follows delivery is choosing to be potentially judged on documentation it has already superseded. World is the case in point, holding the largest deployment in the region while losing jurisdictions to legal decisions rather than technical ones. Treat the enabling instrument, decree, resolution or reform, as a deliverable with an owner and a date inside the project plan.

II Standards and interoperability

  1. 06

    Build credentials on international standards.

    A credential that will be verified outside the organisation that issued it has to rest on an international standard. Government work needs both: the ISO 18013-5 mdoc format for identity documents, whose fixed namespace for driving licences is what makes a credential readable by a verifier that has never heard of the issuer, and which identity programmes are extending to other documents, and W3C verifiable credentials for everything else a government issues, where no such namespace exists. A private issuer putting out a diploma, a professional licence or a KYC result can work in W3C alone. Both travel over the same OpenID protocols, which is how Blerify and Sovra already operate.

  2. 07

    Interoperable regional protocols can integrate LATAM's ecosystem and reach government scale.

    QuarkID, built by a LATAM consortium, became the most widely deployed DID/VC protocol in the region's public infrastructure that this research identified, and what made that possible was the coordination it unlocked: a common language several organisations could implement without committing to one vendor. The arrangement has since come apart, and the momentum with it. Participants in this research described it as important to keep discussing, and ideally building, protocols of this kind: designed around the region's own characteristics, fused with the global standards the region needs to interoperate with, and with an integrated ecosystem behind them.

  3. 08

    Consider post-quantum from the start.

    Credentials issued today are signed with elliptic-curve schemes that a cryptographically relevant quantum computer would break, and the long-term risk is forgery rather than decryption: an adversary who derives an issuer's private key from its public key can mint credentials that verify as genuine. The exposure is uneven: issuer keys, trust anchors and root certificates are expected to operate for decades, which puts them well inside that timeline. Of the case studies here, only Blerify designed for it. Post-quantum certificates are an integrated feature of its issuance platform, shipped in hybrid mode so that post-quantum and classical cryptography run side by side and existing integrations keep working, and the company's founding team published the first quantum-resistant EVM blockchain implementation. Consider integrating quantum readiness into the architecture now and deploy fully once ISO 18013-5 and OpenID4VP add the NIST algorithms to their registries.

III Education and institutional capacity

  1. 09

    Translate cryptographic guarantees into policy language, and fund that translation.

    Open-source code and whitepapers do not reach the audience that determines whether this infrastructure gets adopted at scale. Regulators and legislators who cannot read ZK proof systems cannot evaluate their privacy guarantees, enforce their use, or legislate sensibly about them. The ecosystem needs sustained investment in face-to-face education with the people who set the rules: what the technology does, what it doesn't do, what its failure modes are, and what governance it requires.

  2. 10

    Design for the user you have, not the user the protocol assumes.

    Proyecto DIDI ran into digital literacy rather than cryptography. The joint report it published with the Interamerican Development Bank and LACChain is specific about where the gap sat: end users, validators and issuers alike were found to have basic or non-existent digital skills, and a single training approach across those three groups was insufficient. It also names a design consequence projects rarely accept, that some core tenets of self-sovereign identity proved counterproductive to adoption given the socioeconomic realities of the target population, which makes the trade-off between technological purity and usability a decision to take rather than defer.

  3. 11

    Make the AI-risk case to the people holding the credential, not only to the officials issuing it.

    The argument that opens government conversations in this report is the AI threat: deepfakes defeating biometric verification, phishing that reaches institutional staff, synthetic identities at scale. It works because the officials on the other side of the table already feel the exposure. The same argument is not being made to the people who will carry the credentials. A citizen who does not know that a remote identity check can be defeated has no reason to prefer a cryptographic public service over a convenient one, and a credential adopted purely for convenience never has its risk-mitigation property exercised or valued.

IV Pilots with institutional partners

  1. 12

    Pilot agent credentialing before governments cross into transactional AI.

    Government AI assistants across the region are moving from answering questions to completing procedures. That transition changes the accountability requirements: a decision starts carrying real-world consequences, and the absence of a verifiable audit trail stops being theoretical. The pilot: work with a government digital agency, ideally with a multilateral as convener so the result travels beyond one country, to design and prototype a credentialing system for the agents operating inside a public service, paired with a cryptographic audit trail for transactional decisions. The prior design question is whether the DID/VC infrastructure several countries already run can express agent delegation, which is cheaper to answer than to build from scratch.

  2. 13

    Pilot a proof-of-non-personhood layer before bot-resistant services are needed.

    Every conversation with identity infrastructure builders (World, Blerify, Sovra) surfaced the same anticipatory concern: governments will need to distinguish malicious bots from human designated AI agents on public platforms before they have the institutional confidence to deploy the necessary tooling. The tooling is arriving. World's AgentKit lets a verified holder delegate proof of unique humanity to an agent, and Okta and Vercel have both announced work in the same direction, though Okta's product remains in early-access beta and Vercel's contribution is a workflow step rather than an identity check. All of it is enterprise software, and none of it is in Latin America. The window to build institutional confidence in the region is now, ahead of the first scaled AI-fraud incident. The pilot: select one high-volume, bot-vulnerable public service (social benefit claiming, appointment booking, citizen complaints) and layer World ID's ZK proof of human, or a W3C-aligned equivalent, onto the access flow. Treat the deliverable as operational evidence that convinces the next government adopter, and judge it on that.

These are the executive summary’s thirteen. The full text carries further recommendations inside the case chapters, which belong to their cases and are surfaced there.

The report

Cite it, and read it in full

Funding and interests

This report was funded by the Ethereum Foundation, and its subject matter overlaps with the funder’s own work at several points.

Claudio Cifuentes Lobo, Marcus Alburez (2026). Mitigating AI Privacy Risks in Latin America: Identity Infrastructure, Institutional Capacity and the Path to Adoption. Latin American Dynamism Project. https://doi.org/10.5281/zenodo.22714852

Licensed CC BY 4.0. 102 works cited.

Published in English only. Unlike the deep tech report, this one has no Spanish or Portuguese edition.