Smart Cities - Contracts, Privacy, Data & Legal Identities

MAY 20. 2024 - DON'T READ THIS! IT'S BEEN REPLACED BY "Zero Trust On Steroids - Rethinking Security Models For Citizens And Enterprises In The Age of AI Agents And Tech"





In the not so distant future, imagine yourself walking down a street in a smart city. You'll be wearing "smart clothing", AI/AR glasses, able to be in both the physical world of the street, while at the same time in a virtual smart city world. Around you will be people wearing and using the same tech, as well as buildings, retailers et al also leveraging it. Bots, both physical and virtual, will also be on the street and in the smart city virtual world. AI agents will likely be in the millions or more, with some of them appearing in your virtual world.

Result? It rapidly creates what I call a very non-private world. People, enterprises et al will be able to instantly identify you, consume your biometric, behavioral and neurodata, leveraging this to accurately predict your behavior.

My point? Our old ideas of privacy, contracts, legal identity etc. are thrown into the dustbins of time. To give you the opportunity to live privately in this non-private world, if that's what you want to do, is what this brief article dives into.

Note: Watch this video at the 1 minutes mark to see an example as you walk down the street.

First, Let's Use A Diagram to Explain the Risk

Before leaping into a discussion about this, let's first use a diagram to explain risk to you, the citizen, in a smart city, at any point in time. So, look at this diagram. It shows six zones of trust:

  • Physical - the place you are in the city at each moment in time
  • Digital - Any digital document, file, video et al you're interacting with at each moment in time
  • Humans (physical and digital) - who you are interacting with or walking by at each moment in time
  • AI systems/bots (both physical and digital) - who you're interacting with at each moment in time
  • IoT - Any IoT device you're either interacting with or, that's able to take your biometric, behavioral, neurodata and use this to identify you and/or predict your behavior at each moment in time
  • Metaverse AI/AR/VR - any of these types of environments you're interacting with at each moment in time

My point? Each zone has different risks associated with it. So, for a given moment in time, as you walk down a street, each zone will have a different risk for you.

Let's hypothetically assume the risk levels for physical, digital and metaverse are low, while the risk levels for humans and bots walking towards you, along with IoT devices are high. What does this mean?

It means the humans, bots and IoT devices can readily identify you, and leverage your biometric, behavioral and neurodata to predict your behavior.

Managing Risk

So, you as the citizen, need to have the tech tools and legal law/regulation framework, giving you choice. Like what?

  • Let's assume you want to live privately - thus you need tools and laws/regulations allowing you to remain anonymous while walking down the street
  • Or, perhaps you only want certain types of retailers to know portions of your legal identity, behavioral and neurodata
  • Or, perhaps you don't give a damn. You want to let everyone and anyone to be able to use your data as they please

Now, I'm Not a Good Graphics Person!

If I was, here's what I would produce as the diagram for you at any moment in time. Based on your "risk appetite", for each moment in time, each trust zone would be color shaded. Low risk would be a light color, while high risk would be a dark shade of the zone color.

So, taking the above, you would have a different set of risk preferences, in different shades, which could be computed for each moment in time for you. Your overall risk would be the summation of the individual trust zone risks.

Enter PIAM

To do this, on a moment by moment basis, you require your own "Personalized Identity Access Management" (PIAM) system, that leverages AI. You could preset your PIAM before leaving the door of your home, to risk levels.

So, if you wanted to act completely anonymously, your PIAM would deny any requests by humans, AI systems/bots, IoT devices et al to identify you. Or, if you don't give a damn, you could preset your PIAM to agree to any and all requests to identify you and use your data. Or, some shade in between.

The PIAM AI can instantly create legal consent agreements on the fly, between yourself and an entity, enterprise, etc. who you agree to release portions of your legal identity data to.

It Also Requires "Smart Contracts"

As say Jane Doe walks down the street, she'll want to enable her PIAM to automatically create consent agreements on the fly. Thus, it requires AI leveraged smart contracts to do this.

It Requires a LSSI Device

What the heck is this? It's your "Legal Self-Sovereign Identity" (LSSI) device. It's four different possible types:

  • A personal legal identity smart card
  • A digital legal identity application
  • A biometrically tied to you physical wristband containing your legal identity information
  • A chip implanted into you containing your legal identity information

Here's the main point - You are in control of the LSSI devices, determining where, when and with whom you'll share portions of your legal identity et al. The LSSI devices give you the range of proving legally, anonymously if you're above or below age of consent, if you're a human, Covid vaccinations, your credentials, etc.

Smart AI Leveraged Digital Identities Also Require Legal Identification Where Risk Requires It

While governments around the planet work at creating their own digital identity standards, it's not going to work well. Why? Rapidly emerging smart AI leveraged digital identities of us.

They'll require legal identification which is tied to the underlying physical legal identity. Since these entities can interact and work anyplace on the planet, it requires a global/local framework.

To see a discussion of this skim this article:

  • Entity Management System” where it discusses doctor or nurse Jane Doe using her AI enabled smart digital identity of her to simultaneously manage several patients while she works with someone else

It Also Requires a SOLICT

What's this? It's your "Source of Legal Identity & Credential Truth" (SOLICT). This is your own personal database, which contains information sent to it by authoritative legal sources for your identity and credentials.

It also contains ALL your legal consent agreements, from cradle to grave, you've agreed to with any third party. All the consent agreements you and your PIAM have agreed to are stored here.

Thus, if you're lucky enough to live in a jurisdiction like the EU, then you can go back in time, via your SOLICT, select one consent agreement you want to revoke, and do this leveraging an act like EU GDPR Article 17 - "Right to be Forgotten".

It Requires Governments To Get Their Legal Identity Acts Together

To see my message to government and industry leaders skim these docs:

To see the architectures skim these docs:

This Isn't on Most Peoples' Radar Screens When They Talk About Smart Cities

Sadly, people are so enraptured with the tech, their city and/or jurisdiction. Yet, it requires a global/local solution, that must include not only tech changes, but also changes to laws and regulations around the planet.

  • Yes, it's very complicated
  • Yes, it's very political
  • No, there isn't an easy quick fix

Summary

If I've caught your interest by this article, then please do the following:

  • Widely distribute it amongst people you think should read it
  • Contact me - I'm looking for like-minded souls to partner with

Thanks for taking your time to read a long article!!!!! Guy

About Guy Huntington

I'm an identity trailblazing problem solver. My past clients include Boeing, Capital One and the Government of Alberta's Digital Citizen Identity & Authentication project. Many of my past projects were leading edge at the time in the identity/security space. I've spent the last eight years working my way through creating a new legal identity architecture and leveraging this to then rethink learning.

I've also done a lot in education as a volunteer over my lifetime.?This included chairing my school district's technology committee in the 90's - which resulted in wiring most of the schools with optic fiber, behind building a technology leveraged school, and past president of Skills Canada BC and Skills Canada.

I do short term consulting for Boards, C-suites and Governments, assisting them in readying themselves for the arrival of AI systems, bots and AI leveraged, smart digital identities of humans.

I've written LOTS about the change coming. Skim the?over 100 LinkedIn articles?I've written,?or my webpage?with lots of papers.

Quotes I REALLY LIKE!!!!!!:

  • We cannot solve our problems with the same thinking we used when we created them” – Albert Einstein
  • “Change is hard at first, messy in the middle and gorgeous at the end.” – Robin Sharma
  • “Change is the law of life. And those who look only to the past or present are certain to miss the future” – John F. Kennedy

Reference Links:

An Identity Day in The Life:

My Message To Government & Industry Leaders:

National Security:

Rethinking Legal Identity, Credentials & Learning:

Learning Vision:

Creativity:

AI Agents:

Architecture:

AI/Human Legal Identity/Learning Cost References

AI Leveraged, Smart Digital Identities of Humans:

CISO's:

Companies, C-Suites and Boards:

Legal Identity & TODA:

Enterprise Articles:

Rethinking Enterprise Architecture In The Age of AI:

LLC's & AI:

Challenges With AI:

New Security Model:

DAO:

Kids:

Sex:

Schools:

Biometrics:

Legal Identity:

Identity, Death, Laws & Processes:

Open Source:

Notaries:

Climate Change, Migration & Legal Identity:

"Human Migration, Physical and Digital Legal Identity - A Thought Paper

Fraud/Crime:

Behavioral Marketing:

AI Systems and Bots:

Contract Law:

Insurance:

Health:

AI/AR/VR Metaverse Type Environments:

SOLICT:

EMP/HEMP Data Centre Protection:

Climate:

A 100,000-Foot Level Summary Of Legal Human Identity

  • Each person when they’re born has their legal identity data plus their forensic biometrics (fingerprints, and later when they can keep their eyes open – their iris) entered into a new age CRVS system (Civil Registration Vital Statistics - birth, name/gender change, marriage/divorce and death registry) with data standards
  • The CRVS writes to an external database, per single person, the identity data plus their forensic biometrics called a SOLICT “Source of Legal Identity & Credential Truth).?The person now controls this
  • As well, the CRVS also writes to the SOLICT legal identity relationships e.g. child/parent, cryptographically linking the SOLICTs.?So Jane Doe and her son John will have cryptographic digitally signed links showing their parent/child.?The same methodology can be used for power of attorney/person, executor of estate/deceased, etc.
  • The SOLICT in turn then pushes out the information to four different types of LSSI Devices “Legal Self-Sovereign Identity”; physical ID card, digital legal identity app, biometrically tied physical wristband containing identity information or a chip inserted into each person
  • The person is now able, with their consent, to release legal identity information about themselves.?This ranges from being able to legally, anonymously prove they’re a human (and not a bot), above or below age of consent, Covid vaccinated, etc.?It also means they can, at their discretion, release portions of their identity like gender, first name, legal name, address, etc.
  • NOTE: All consents granted by the person are stored in their SOLICT
  • Consent management for each person will be managed by their PIAM “Personal Identity Access Management) system.?This is AI leveraged, allowing the person, at their discretion, to automatically create consent legal agreements on the fly
  • It works both locally and globally, physically and digitally anywhere on the planet
  • AI systems/bots are also registered, where risk requires it, in the new age CRVS system
  • Governance and continual threat assessment, is done by a new, global, independent, non-profit funded by a very small charge per CRVS event to a jurisdiction to a maximum yearly amount.

A 100,000-Foot Level Summary Of The Learning Vision:

  • When the learner is a toddler, with their parents’ consent, they’ll be assessed by a physical bot for their learning abilities.?This will include sight, sound, hearing and smell, as well as hand-eye coordination, how they work or don’t work with others, learning abilities, all leveraging biometric and behavioral data
  • All consents given on behalf of the learner or, later in the learner’s life by the learner themselves, are stored in the learner’s SOLICT “Source of Legal Identity & Credential Truth
  • This is fed into a DLT “Digital Learning Twin”, which is created and legally bound to the learner
  • The DLT the produces its first IEP “Individualized Education Plan”, for the learner
  • The parents take home with them a learning assistant bot to assist the learner, each day, in learning.?The bot updates the DLT, which in turn continually refines the learner’s IEP
  • All learning data from the learner is stored in their LDV “Learner Data Vault”
  • When the learner’s first day of school comes, the parents prove the learner and their identities and legal relationship with the learner, via their LSSI devices (Legal Self-Sovereign Identity)
  • With their consent, they approve how the learner’s identity information will be used not only within the school, but also in AI/AR/VR learning environments
  • As well, the parents give their consent for the learner’s DLT, IEP and learning assistant bot to be used, via their PIAM (Personal Identity Access Management) and the learner’s PIAM
  • The schools LMS “Learning Management System” instantly takes the legal consent agreements, plus the learner’s identity and learning information, and integrates this with the school’s learning systems
  • From the first day, each learner is delivered a customized learning program, continually updated by both human and AI system/bot learning specialists, as well as sensors, learning assessments, etc.
  • All learner data collected in the school, is stored in the learner’s LDV
  • If the learner enters any AI/AR/VR type learning environment, consent agreements are created instantly on the fly with the learner, school, school districts, learning specialists, etc.?
  • These specify how the learner will be identified, learning data use, storage, deletion, etc.
  • When the learner acquires learning credentials, these are digitally signed by the authoritative learning authority, and written to the learner’s SOLICT.
  • The SOLICT in turn pushes these out to the learner’s LSSI devices
  • The learner is now in control of their learning credentials
  • When the learner graduates, they’ll be able, with their consent, to offer use of their DLT, IEP and LDV to employers, post-secondary, etc.?This significantly reduces time and costs to train or help the learner learn
  • The learner continually leverages their DLT/IEP/LDV until their die i.e., it’s a lifelong learning system
  • IT’S TRANSFORMATIONAL OVER TIME, NOT OVERNIGHT

?



Ahmed Karam

Father | Leader | Digital Transformation Fighter | Smart Cities | Innovation | Sustainability | GRC | EA | Driving Positive Change for a Better World, Today and Tomorrow

3 年

Thank you Guy for sharing.

要查看或添加评论,请登录

Guy Huntington的更多文章

社区洞察

其他会员也浏览了