tech, humanised

Technology should make us more human, not less.

A warm, practical resource for keeping people — their dignity, attention and connection — at the centre of the tools we build and use. The good news: dehumanising technology is a choice, which means a more human one is always available.

what we mean

Tech is dehumanising when it treats a person as a number, a problem to be processed, or an attention source to be mined — instead of a human being to be served.

It rarely arrives as a villain. It shows up as the helpline with no human at the end of it. The score that decides your loan without explanation. The feed engineered to keep you scrolling past midnight. The shift app that pings you like a part in a machine.

None of that is inevitable. The same technology can be built and used to give people more time, more dignity, more agency and more genuine connection. That is the whole project here: noticing the difference, and choosing the human path on purpose.

a gentle gut-check

Signs a piece of tech might be dehumanising you.

Not a diagnosis — just a few honest prompts. If several feel familiar, that's worth listening to. You're not being dramatic, and you're not alone.

  • There is no realistic way to reach an actual person when something goes wrong.
  • A decision was made about you, and no one can explain how or why.
  • You feel watched or measured in ways you never agreed to.
  • You open an app to do one thing and leave foggy, drained, or worse about yourself.
  • The tool seems built to keep you using it, not to help you finish and leave.
  • You're treated as a "user", a "ticket" or a "case" rather than a person with a name.

Recognising it is the first humanising act. Next: find your footing →

the writing

Notes on keeping people human.

Plain-spoken pieces on what dehumanising technology looks like, how to build and adopt better, and how to look after yourself when a tool is wearing you thin.

the risks

The quiet ways technology can dehumanise us

It rarely announces itself. It arrives as convenience, efficiency and "just how things work now". Here are six patterns to recognise — and why naming them is the first step back.

Dehumanising technology almost never looks like a villain. There's no glowing red eye, no cackling. It looks like a faster checkout, a tidier spreadsheet, a chatbot that answers at 3am. The harm slips in sideways, dressed as progress — which is exactly why it's worth learning to see.

To "dehumanise" simply means to treat a person as something less than a full human being: as a number, a data point, a problem to be processed, or a source of attention to be mined. Technology doesn't have to do this. But when it's designed only for efficiency, profit or scale — with people treated as inputs rather than the point — it drifts there on its own.

Here are six of the most common patterns. None of them require bad people to occur. They mostly require no one stopping to ask, how will this feel from the other side of the screen?

1. You get reduced to a metric

The first move is always the same: a whole person is flattened into a single measurable thing. A delivery driver becomes a "drop rate". A patient becomes a bed number. A reader becomes "time on page". A child becomes a reading level.

Measurement isn't the enemy — we need numbers to run anything at scale. The danger is when the metric quietly replaces the person in everyone's mind, including their own. We start optimising the number instead of caring for the human it was meant to describe. The map eats the territory.

The moment a number stands in for a person, someone stops being seen.

2. The human exit is removed

You have a problem that doesn't fit the menu. You press 0. You type "speak to a person". You search the site for a phone number that no longer exists. The system was built so that, past a certain point, no human can be reached — because humans are expensive and "deflection" looks great on a dashboard.

This is one of the most widely felt forms of dehumanisation, because it removes the thing that makes us social animals: the ability to be heard by someone who can understand and act. Being stuck in a loop with no human at the end isn't just annoying. It quietly tells you that your particular situation doesn't matter enough to warrant a person.

3. Decisions are made about you that no one can explain

An application is declined. An account is frozen. A post is removed. A price doubles. When you ask why, the answer is some version of "the system decided" — and no one, not even the staff in front of you, can tell you how or appeal it in plain terms.

Opaque automated decisions strip away two deeply human things at once: understanding and recourse. We can usually live with a "no" if we know why and can respond to it. What corrodes dignity is a verdict from a black box, delivered as if it were the weather.

4. Your attention gets farmed

Some products are designed to help you do a thing and leave. Others are designed to keep you there — because their business depends on the hours you spend, not the value you get. Infinite scroll, autoplay, variable-reward notifications, streaks, and feeds tuned to provoke rather than inform are not accidents. They're the engineering of compulsion.

The dehumanising part isn't that these tools are fun. It's that they treat your attention as a resource to be extracted rather than a finite, precious part of your one life. You came to connect or relax; you leave foggy, agitated, and somehow worse about yourself — and the design counts that as a win.

5. You're watched, scored and sorted without consent

Surveillance has become ambient. Location trails, purchase histories, keystroke timing, productivity scores, "sentiment" read from your messages — gathered continuously, often invisibly, and used to predict and nudge what you'll do next.

Being constantly observed changes us. We perform instead of live. We self-censor. The sense that you can be yourself in private — a basic condition for being a person rather than a subject — gets thinner. And when that data is used to sort people into categories that shape what jobs, prices or opportunities they see, surveillance turns into quiet, automated discrimination.

6. The very language treats people as raw material

Listen to how technology talks about the people it serves. "Users." "Eyeballs." "Traffic." "Churn." "Engagement." "Monetising the audience." "Capturing" attention. None of these words contain a human face. Language shapes thought, and an industry that calls people "users" for long enough starts to design for use rather than for flourishing.

This one matters because it's upstream of all the others. Change how a team speaks about the people on the other side of the screen, and you change what feels normal to build.

the hopeful part

Every pattern above is a choice, not a law of nature. A metric can sit beside a name. A human exit can be one click away. A decision can come with a reason. A tool can be built to help you finish and leave. Data can be minimised by default. And a team can decide to call people people. None of this is harder than the dehumanising version — it just has to be wanted.

Why naming it is the first step

Dehumanisation thrives on seeming inevitable — "that's just how the internet works now". Once you can name the pattern, it stops being weather and becomes a design decision someone made, which means a different decision is possible. You can ask for the human exit. You can choose tools built to respect you. If you build technology, you can refuse to ship the dark pattern even when the dashboard would reward it.

That's the whole reason this resource exists. Seeing clearly is not pessimism. It's the start of building something better.

keep going

the remedy

Designing & adopting technology that respects people

A humane tool isn't a softer, slower one. It's a tool that treats the person on the other side as the point. Here are seven principles — and a checklist you can use this week.

Whether you write the code, sign the purchase order, or decide how a tool gets rolled out across a team, you have more power to keep technology human than you might think. Most dehumanising design isn't malicious — it's the result of no one being responsible for the human experience. These principles give that responsibility a home.

1. Keep a human in the loop — and a human at the door

Automate the repetitive, the predictable, the boring. But for anything that meaningfully affects a person's money, health, livelihood, reputation or access, make sure a human can step in, review and override. Just as importantly, make the human reachable: a clearly signposted way to reach a real person, without a maze, is the single most humane feature most services lack.

The test: if this goes wrong for one person in a way the system didn't anticipate, what happens to them? If the honest answer is "nothing — they're stuck", you have more design to do.

2. Make the person the customer, not the product

Be honest about who the technology actually serves. If the people using it are also the ones paying for it — directly or through their organisation — their interests and the product's interests can align. If they're "free", their attention or data is usually the thing being sold, and the design will drift toward extracting it.

You can't always change the business model, but you can refuse to let it quietly override the user's interests. When the two conflict, decide in advance whose side the product is on, and design accordingly.

3. Default to dignity

Defaults are the most powerful design decision you'll make, because most people never change them. So set them where you'd want them set for someone you love: privacy on, data collection minimal, notifications calm, the gentlest option first. Make the respectful choice the easy one and the extractive choice the deliberate one — never the reverse.

The default is your real value statement. Everything else is marketing.

4. Be explainable and appealable

If your system makes or shapes decisions about people, those people deserve to understand them and to push back. That means a reason a normal person can follow ("declined because X"), not a reference number. It means a real route to appeal that reaches a human with the power to change the outcome. And it means logging enough that you yourself could reconstruct why the system did what it did.

This is doubly true for anything using AI. A model's confidence is not the same as being right, and "the algorithm decided" is never an acceptable final answer to a person whose life it touched.

5. Design for the worst day, not the demo

Products are designed for the cheerful average case and demoed to applause. But people meet technology on their worst days too — grieving, panicking, locked out, in pain, in a second language, on an old phone with one bar of signal. Humane design asks: what happens to the most vulnerable person who will ever touch this?

If your error messages assume calm, your flows assume confidence, and your accessibility is an afterthought, you've designed only for the people who least needed your care.

6. Measure what's human, not just what's easy

We optimise what we measure, so be careful what you measure. Engagement, time-on-app and clicks are easy to count and dangerous to chase — they reward compulsion as readily as value. Sit a human metric next to every efficiency one: Did people accomplish what they came for? Did they leave better off? Would they recommend it to a friend they care about? Did we reduce, not just shift, someone's stress?

A genuinely good product is often one people use less over time because it actually solved their problem. Make sure your dashboards can tell that story without punishing it.

7. Move at the speed of trust

When adopting technology in an organisation — new software, automation, AI — the temptation is to deploy fast and explain later. That's how you get fear, quiet sabotage and tools that technically work but humanly fail. Bring the people affected in early. Tell them honestly what changes and what doesn't. Show how it makes their work better, not just cheaper. Train properly. Leave room to say "this isn't working".

Technology adopted with people lands; technology done to people gets resented, and resentment is its own kind of dehumanisation.

use it this week — the checklist

  • The human exit: Can a person reach a real human in two steps or fewer? Is the route obvious?
  • The override: For any high-stakes automated decision, can a human review and reverse it?
  • The reason: When we say "no", can we say why in plain language?
  • The default: Are privacy, data and notification defaults set the way we'd want for someone we love?
  • The worst day: Have we tested this with a stressed, distracted or vulnerable person — not just the happy path?
  • The data diet: Are we collecting only what we genuinely need, and deleting the rest?
  • The honest metric: Is there a measure of whether people are actually better off — sitting right next to the engagement numbers?
  • The language: Do we talk about "people", or have we slipped into "users", "eyeballs" and "churn"?

Questions to ask any vendor

If you're buying technology rather than building it, your leverage is in the questions you ask before you sign:

  • Where does our people's data go, who can see it, and how do we get it deleted?
  • If your system makes a decision we disagree with, how do we override it?
  • What does support actually look like for our end users on a bad day?
  • What are you optimising for, and how would we know if it started working against our people?
  • If we leave you in two years, how do we get our data and our people's work out?

A vendor who welcomes these questions is one you can work with. A vendor who can't answer them is telling you something important.

The encouraging truth

None of this asks you to be slower, poorer or less ambitious. Humane technology is usually better technology: more trusted, more loyal, less likely to blow up into a scandal, more pleasant to build and to work for. Respect for people isn't a tax on good engineering. Increasingly, it is good engineering. The teams that figure that out first won't just feel better about their work — they'll win.

keep going

for you

Finding your footing when tech feels dehumanising

If a tool, app or system has been wearing you down, you're not weak and you're not imagining it. Here are kind, doable ways to take back a little ground — starting today.

First, the most important thing: if technology has been making you feel small, anxious, invisible or exhausted, that's a reasonable response to environments often designed to produce exactly those feelings. The fault is not in you for struggling. And there's a lot you can do — none of it requiring you to throw your phone in a lake.

Pick one or two of these to try. You don't need all of them, and you don't need to do it perfectly. Small recoveries count.

Reclaim your attention

Your attention is being competed for by teams of clever people. You don't have to out-discipline them — you just have to change the defaults so willpower isn't doing all the work.

  • Turn off most notifications. Keep alerts from actual humans (messages, calls). Silence the rest — the badges, the "someone you may know", the nudges to come back. You decide when to check, not the app.
  • Make the addictive apps duller and further away. Move them off your home screen, into a folder, or log out so opening them takes a deliberate step. Greyscale mode makes a surprising difference.
  • Put a small gap between impulse and action. A two-tap login, a screen-time reminder, or simply leaving the phone in another room while you eat or sleep returns the choice to you.
  • Follow fewer things, on purpose. Curate feeds toward what leaves you informed or glad, and unfollow what leaves you agitated. You're allowed to make your inputs kinder.

Insist on reaching a human

When a service traps you in a loop, the goal is to get to a person with the power to help. A few moves that genuinely work:

  • In a phone menu, try pressing 0 repeatedly, or saying "agent" / "representative" / "complaint". Saying you want to cancel often routes you to a real, empowered human fast.
  • With a chatbot, type plainly: "I need to speak to a person." Repeat it. Don't argue with the bot — just keep asking for the handoff.
  • Write down names, times and reference numbers as you go. It steadies you and makes any follow-up far stronger.
  • If you're stuck, escalate sideways: a public message to the company, a formal complaint, or your country's relevant ombudsman or disputes scheme. Knowing the escalation path exists takes away the trapped feeling.
  • Be firm and be kind. The person who finally answers usually didn't design the maze — they're stuck in it with you.
You are allowed to take up space, ask for a human, and expect to be treated like one.

Set boundaries you can actually keep

Boundaries fail when they rely on heroic self-control. Build ones the environment helps you keep:

  • Pick tech-free zones or times — the dinner table, the first and last 30 minutes of the day, the bedroom. Charge the phone outside the bedroom and use a normal alarm clock.
  • Batch the draining stuff. Check email or messages at set times rather than continuously. The world copes; you recover hours.
  • Separate work from you. If you can, keep work apps off your personal phone, or use a focus profile that switches them off after hours. You are not a server that must always be available.
  • Let people know. "I check messages a couple of times a day" resets expectations and gives others permission to do the same.

Choose tools that treat you like a person

You have more choice than the loudest apps suggest. Where you can, vote with your feet:

  • Prefer tools you pay for over "free" ones when the free version is clearly selling your attention or data — paying is often the cheaper deal in the end.
  • Favour products that are calm by design: no endless feed, no manipulative streaks, easy to leave.
  • Do a quick privacy tidy-up: review app permissions and turn off location, microphone and contact access for anything that doesn't truly need them. Skim the privacy settings of your main accounts once and dial them down.
  • When something respects you, tell people. Recommending humane tools is how they win.

When it's your employer's system

Sometimes the dehumanising tech is one you can't simply quit — a monitoring tool, a scheduling app, a rigid workflow. You still have moves:

  • Name the specific harm, calmly and concretely. "The new system pings me on days off and I can't switch it off" is harder to dismiss than "I hate this app".
  • Find your allies. If it's grinding you down, it's likely affecting colleagues too. Raised together — or through a union or staff forum where you have one — concerns carry far more weight.
  • Know your rights. Many places have real legal limits on workplace surveillance, data use and the right to disconnect. A quick check of your local rules can be quietly empowering.
  • Protect your energy where you can't change the system. Do the parts you control well, and don't let a badly designed tool convince you that you are the problem.

if it's heavier than a tool

Sometimes what's wearing you down isn't really the app — it's everything the app is sitting on top of. If you're feeling persistently low, anxious, isolated or overwhelmed, please reach out to someone you trust, or to a doctor or a local support line. Talking to a real person is the most humanising thing of all, and you deserve that support. No website, including this one, is a substitute for it.

A gentle reminder to end on

You don't have to win against the whole machine. You just have to reclaim enough room to feel like yourself again — a quiet morning, a real conversation, an afternoon where your attention belonged to you. Each small boundary is a vote for a more human relationship with technology, and those votes add up, in your own life and in the wider culture.

Be patient with yourself. You're navigating environments built by experts to be hard to put down. Every bit of ground you take back is a real win — and it's yours to keep.

keep going

the long read · digital identity

Who vouches for you, and who gets to watch?

Digital identity can hand New Zealanders real freedom — less friction, less fraud, less of our private lives spilled across a hundred forms. The same plumbing, wired differently, becomes the most efficient instrument of control a state has ever held. The technology does not decide which one we get — the architecture does.

“A digital identity system is not good or bad in the way a bridge is not safe or unsafe — it depends entirely on how it is built and who maintains it. The same components that let you prove you’re over 18 without revealing your name can, with three design changes and one law, let a government know everywhere you’ve been and switch off your ability to buy petrol.”

01

Definitions

First, what “digital identity” actually is

The phrase covers three different things that get muddled together. Keeping them apart is the whole game, because the risks live in how they connect.

Identification is the claim — “I am Paul.” Authentication is the proof — “and here is something only Paul can present.” Identity data is everything attached to that proven claim — your age, your address, your entitlements, your record. A digital identity system is just software that does these three jobs without paper, ideally faster and more privately than the manila-folder world it replaces.

New Zealand has deliberately not built a single national ID card with one number that unlocks everything. Instead the model is federated: many accredited providers, the citizen holding their own credentials, and verifiers who check a claim without phoning a central database. The legal scaffolding for this is the Digital Identity Services Trust Framework Act 2023, in force from mid-2024, which accredits providers against rules on privacy, security and interoperability rather than herding everyone into one system. RealMe is the long-standing government login; companies like Mattr build the verifiable-credential technology underneath; the Privacy Act 2020 and its thirteen Information Privacy Principles sit over the top.

Why the model matters

The single most consequential decision in any national identity programme is whether there is one key that links everything or many keys that don’t. New Zealand has so far chosen many. Most of the dangers in this briefing begin the moment that choice is quietly reversed.

So the rest of this piece is organised around one axis — how centralised the system is — because that axis, more than the brand of the technology, determines whether digital identity is a gift to citizens or a lever over them.

THE ARCHITECTURE SPECTRUM MORE CENTRAL CONTROL MORE INDIVIDUAL CONTROL 1 Centralised register One database, one number, the state holds everything 2 Federated Many accredited providers, shared rules, no single key 3 Self-held wallet You carry your credentials; prove claims, reveal nothing else NZ TODAY ≈ HERE
New Zealand’s framework sits around federated — better than a single national register, short of fully self-held. Pressure tends to pull systems left over time, one efficiency at a time.
02

The case for

The real upside for New Zealanders

It would be a mistake to treat digital identity as something only to be feared. Done well, it returns time, dignity and safety to ordinary people — and it can reveal less about us than the paper system it replaces, not more.

Less friction, less repetition

Today you prove who you are dozens of times a year — to a bank, a landlord, a pharmacy, a government portal — and each time you hand over more than the question requires. A working digital identity lets you prove a single fact, once, and reuse that proof everywhere without re-running the whole verification each time. For someone whose nearest bank branch has closed and the next is an hour’s drive away, or for anyone forced to keep re-proving who they are — a recent migrant, a person rebuilding after losing their documents — that saving is not trivial; it is access.

Older New Zealanders show why this cuts both ways. Built with delegated authority — a family member or carer acting with proper, auditable permission rather than just being handed a password — and a staffed counter kept as the fallback, digital identity can spare a frail or remote person repeated trips and the scam exposure of mailing documents around. Built instead as slick self-service that quietly assumes a lifetime of passwords and two-factor logins, the same system locks that person out entirely. The convenience is access for one person and a wall for another — and which one you get is a design choice, not a property of the technology.

Genuine fraud reduction

Identity theft and synthetic-identity fraud thrive on photocopied driver licences and emailed passport scans. Cryptographically verifiable credentials can be checked for authenticity without the verifier ever storing the underlying document — removing exactly the loose copies that fraudsters harvest.

The counter-intuitive privacy win: selective disclosure

This is the part most people miss. A well-built credential lets you answer “are you over 18?” with a plain yes — mathematically proven, impossible to forge — while revealing nothing else. No name, no birth date, no address, no document number. The bouncer, the bottle store, the betting site each learn the one bit they’re entitled to and nothing more. Paper can’t do that. This is privacy-enhancing technology, and it is the strongest argument for getting on with it.

Inclusion, done right

Roughly a tenth of New Zealanders struggle to assemble the documents the current system demands — recent migrants, people who’ve experienced homelessness, trans people whose documents don’t match. A humane digital identity can lower that barrier. The same system, designed carelessly, can raise it into a wall. Inclusion is a design outcome, not an automatic one.

THE SAME QUESTION — “ARE YOU OVER 18?” Paper / photocopy way YOU HAND OVER EVERYTHING → Full legal name → Exact date of birth → Home address → Document / licence number → A photo of your face → verifier now holds a copy forever Selective-disclosure way YOU PROVE ONE FACT YES OVER 18 ✓ → verifier learns nothing else
Selective disclosure flips the usual privacy story: the digital version can reveal less than the laminated card. Whether a real system is built this way is the question that matters.
03

Risk · external threat

Threat tier 1 — attackers from outside

When the prize is the whole country in one place

The first danger has nothing to do with the government’s intentions. It is simply that any large store of identity data is a target, and the bigger and more connected it is, the bigger the prize and the worse the day it leaks.

The honeypot problem

Security people talk about blast radius — how much damage one breach can do. A federated system where credentials live on people’s own devices has a small blast radius: compromise one phone, harm one person. A centralised register where one breach exposes every New Zealander’s name, address, biometrics and government interactions has a blast radius the size of the nation. The same data that makes a centralised system efficient is exactly what makes it catastrophic when — not if — it is breached.

Biometrics make this worse, because they can’t be reissued. You can change a leaked password in seconds. You cannot change your face or your fingerprints. A breach of a biometric register is permanent in a way a credit-card breach never is.

Aggregation turns harmless data harmful

Individually, your pharmacy visits, your travel records and your benefit status are mundane. Joined together through a single identity key, they describe your health, your movements and your finances in a way none of them does alone. Linkage is the multiplier. An attacker who reaches one linked system reaches the citizen, not the record.

The supply-chain reality

Attackers rarely break the cryptography. They phish an administrator, compromise a contractor, or exploit a third-party vendor with a key to the system — the same pattern behind most large public-sector breaches worldwide. The more agencies plug into a shared identity backbone, the more doors there are, and a backbone is only as trustworthy as its weakest connected supplier.

ONE BREACH — TWO ARCHITECTURES Centralised honeypot ONE STORE BLAST RADIUS = EVERYONE Distributed / self-held BLAST RADIUS = ONE PERSON
Centralisation is convenient until the breach. Then it is a single event that harms everyone at once — and biometric data, unlike a password, can never be reissued.
04

Risk · power, not malice

Threat tier 2 — the slow aggregation of state power

How a convenience becomes a single view of the citizen

The second danger needs no villain. It is the cumulative effect of reasonable-sounding decisions, each justified on its own, that together hand the state a capability it never explicitly asked for.

Function creep

Every identity system begins with a narrow purpose and a promise that it will only ever be used for that. Then a second agency finds it useful. Then a third. Each extension is defended as sensible — why make people prove themselves twice? — and each is individually hard to argue against. The endpoint is a system doing far more than anyone consented to at the start, reached without a single decision that looked alarming on the day it was made. Function creep is not a hypothetical failure mode; it is the default trajectory of useful infrastructure unless something actively holds it back.

The death of practical obscurity

Most of our freedom in daily life rests on a quiet fact: our activities are technically knowable but not actually joined up. The bus you took, the clinic you visited, the march you attended, the book you borrowed — all on record somewhere, none connected. That gap is called practical obscurity, and a great deal of ordinary liberty lives inside it. A universal identity key used across government closes the gap. Nothing new is recorded; it is simply all linkable now, by whoever holds the key.

Cross-government data sharing — the hinge

Data-sharing between agencies is sold, accurately, as better service: tell us once, not ten times. But the same pipes that pre-fill your form let an analyst assemble a complete dossier on any individual in seconds. The benefit and the risk travel down the identical wire. What separates them is not the technology but the rules on the wire — purpose limits, audit logs, and hard legal walls between, say, the tax system and the police.

The chilling effect

People behave differently when they believe they’re watched, even if no one is acting on what they see. Attendance at lawful protests falls. Sensitive searches go unmade. Unpopular views go unspoken. A society that has wired up a single view of every citizen pays this cost whether or not the capability is ever abused — the knowledge that it could be is enough to bend behaviour. This is the quietest harm and often the largest.

WHAT ONE LINKING KEY CHANGES Siloed — today Health Tax Justice Welfare Travel Education SEPARATE — NO COMPLETE PICTURE One linking key ONE CITIZEN Health Tax Justice Welfare Travel Education LINKED — COMPLETE DOSSIER, INSTANTLY
Nothing new is collected. The single key simply joins what was always separate — and a complete picture of a person is a different, far more powerful thing than the scattered records that compose it.
05

Risk · the far edge

Threat tier 3 — deliberate use as an instrument of control

The authoritarian endpoint, described honestly

This is the scenario people reach for first — “social credit,” CCP-style surveillance. It deserves a clear-eyed treatment rather than a scary one, because the real mechanism is both less cartoonish and more instructive than the headline.

What China actually does — and doesn’t

The popular image of a single national score that rises and falls with your every act is largely a myth. China’s “social credit” is in reality a fragmented patchwork: corporate-compliance ratings, court blacklists of people who have ignored judgments, and assorted local pilots — not one universal number ranking every citizen. The widely shared commercial scores, like Sesame Credit, are opt-in loyalty products run by private firms, closer to a Western credit score than to dystopia.

But the parts that are real are the parts that matter for this discussion. The court blacklists genuinely restrict millions of people from buying plane and high-speed-rail tickets — an identity-keyed denial of services at national scale. And the surveillance apparatus — pervasive cameras, facial recognition, and the COVID-era health-code apps that decided who could enter a building, board a train or leave their suburb — demonstrated something important: an identity system tied to permissions becomes a movement-control system the moment a government chooses to wire it that way. The capability was built quietly for public-health and convenience reasons, then repurposed.

The lesson worth taking

The danger isn’t that New Zealand wakes up one morning and installs a social-credit score. It’s that a country can assemble all the components of one — verified identity, linked records, permission-gated services, digital payments — for entirely benign reasons, and then a future government, or an emergency, repurposes the finished machine. The hard part of building a control system is the plumbing. Benign programmes lay the plumbing.

How the components compose

An identity layer answers who. Linked records answer what about them. Permission-gating answers what they’re allowed to do. Add programmable payments and you can answer what they’re allowed to buy — and enforce all of it automatically, at population scale, without a single human in the loop. None of these layers is sinister alone. Stacked, and pointed at a person, they are a degree of control no secret police of the twentieth century could have dreamt of, achieved with a fraction of the staff.

This is not an argument that New Zealand is heading there. It is an argument that the distance between “excellent digital government” and “turnkey control system” is shorter than it looks, and is measured almost entirely in safeguards rather than in technology. Which is exactly why the safeguards are the real subject — see section 08.

06

Programmable money

What a central bank digital currency changes

Identity tells a system who you are. Money is how you act on the world. Join the two and you don’t just observe behaviour — you can permit or forbid it, transaction by transaction. This is why CBDCs belong in any honest discussion of digital identity.

Where New Zealand is

The Reserve Bank has been consulting on “Digital Cash” — a retail CBDC. Its stated design intentions matter and deserve to be reported fairly: digital cash is meant to complement physical cash rather than replace it, the Reserve Bank has said it would not see individuals’ transaction data, privacy is named as a core requirement, and offline functionality is on the table. On its own terms, this is close to a best-case design. The risks below are about what the same technology can do, and what future governments could change, not an account of current RBNZ intent.

The crucial distinction: programmable money vs programmable currency

These get conflated and they are opposites.

  • Programmable money puts the rules at the edge, under the control of the people transacting. You can tell your own money to pay rent on the first of the month, or release funds to a builder when work is signed off. This is useful and benign — it’s your rule, on your money.
  • Programmable currency puts the rules at the centre, baked into the money itself by the issuer. The unit of currency carries conditions you didn’t set and can’t remove: it expires on a date, only works inside a region, or can’t be spent on certain categories.

The first is a feature. The second is a control surface. Whether a CBDC is one or the other is a design decision made years before anyone notices the difference in daily life.

What centrally programmable currency could do

Stimulus payments that expire in 60 days to force spending. Money that can’t buy certain goods. Funds geofenced to your home region. Welfare that arrives pre-restricted. Negative interest applied automatically to balances. Each can be pitched as good policy — and each removes a choice that physical cash silently protected. China’s e-CNY has trialled expiry and other programmable features; the capability is not theoretical.

The privacy floor that cash quietly provides

Physical cash is the last fully private, fully fungible, offline-capable means of payment most people have. It works in a power cut, leaves no record, and can’t be switched off remotely. A digital currency that fully displaced cash — even a well-meaning one — would remove that floor unless it deliberately rebuilds it: genuine offline use, real anonymity for small payments, and a legal guarantee that the money can’t be made to refuse a lawful purchase. Preserving cash itself is, for now, one of the simplest safeguards available.

WHO HOLDS THE RULES? Programmable money RULES AT THE EDGE — YOURS YOU set the rule “pay rent on the 1st” benign — your choice, your money Programmable currency RULES AT THE CENTRE — THEIRS ISSUERCONTROL “expires · region-locked · category-blocked” control surface — baked into the money
Same word, opposite meanings. Programmable money hands control to you; programmable currency hands it to the issuer. A CBDC can be built either way — and the choice is largely invisible to the public until it is exercised.
07

The composite risk

When the layers stack into a single lever

No single piece in this briefing is alarming on its own. The risk is compositional: each layer is built for a good reason, by different people, in different years — and only when they sit on top of one another does the full capability appear. This is the picture worth holding in your head.

EACH LAYER IS BENIGN ALONE · STACKED, IT IS A LEVER 1 · Identity knows precisely WHO you are login, age check ✓ useful 2 · Linked records knows WHAT is true about you tell-us-once ✓ useful 3 · Permission-gating decides WHAT YOU MAY DO access control △ dual-use 4 · Programmable currency decides WHAT YOU MAY BUY spend rules ⚠ control surface 5 · Scoring / eligibility decides WHAT YOU DESERVE automated judgement ⚠ the lever THE COMPLETE MACHINE
The components are usually built separately and for good reasons. The safeguards in section 08 are precisely the walls between these layers — and the whole risk is that the walls are cheaper to remove than to build.

The asymmetry that should worry us most

Building this stack takes years and many hands. Activating it as a control system can take a single statute or a single emergency declaration. Capability and intent are separate; infrastructure outlives the government that built it. A safeguard that depends only on today’s good intentions is not a safeguard — it’s a hope.

08

What good looks like

The guardrails that keep us on the right side

Here is the optimistic core of the whole piece: every risk above has a known, practical countermeasure. None requires giving up the benefits. They are design and governance choices we can demand now, while the systems are still being shaped.

  • 1No single linking key.Keep identifiers sector-specific so health, tax and justice records can’t be silently joined. This one choice defuses most of section 04.
  • 2Data minimisation & selective disclosure by default.Systems should prove the one fact asked for and reveal nothing else — the “are you over 18?” pattern, made the norm rather than the exception.
  • 3Decentralised, self-held credentials.Keep the data on people’s own devices, not in a national honeypot. Small blast radius beats convenient catastrophe.
  • 4Hard purpose limitation in law.Each use written down, narrowly; new uses requiring fresh, public, debated authorisation — not an internal memo. This is the legal answer to function creep.
  • 5Voluntariness and real alternatives.No essential service — banking, healthcare, voting, benefits — may be available only through the digital identity. A non-digital path must always exist.
  • 6Tamper-evident, independent audit logs.Every access to a person’s data logged, reviewable by an independent watchdog with teeth, and ideally visible to the person themselves.
  • 7Cash preserved; CBDC privacy guaranteed.Keep physical cash usable, mandate genuine offline and anonymous small-value digital payments, and legally forbid centrally-imposed spending restrictions.
  • 8Sunset clauses and emergency limits.Powers granted in a crisis should expire automatically. The COVID-era apps showed how “temporary” infrastructure persists unless an expiry date is written in from day one.
  • 9Independent oversight with the power to say no.The Privacy Commissioner and equivalent bodies need the resourcing and statutory authority to halt deployments — oversight without a brake is decoration.

Where New Zealand actually stands

On the whole, comparatively well. The federated, consent-based, voluntary model in the Trust Framework Act is closer to the right side of every diagram in this piece than to the wrong one, and the Privacy Act 2020 and an active Privacy Commissioner provide real friction. New Zealand has not built the single national register that does most of the damage. The honest caution is not “we are sliding into authoritarianism” — it is that the default drift of useful infrastructure is leftward on every spectrum here, one reasonable efficiency at a time, and that the guardrails above need to be locked in before the convenience arrives, not litigated after.

Keeping the human in the loop

The thread we mustn’t let go of

Digital identity is coming, and on balance New Zealanders should want a good version of it — one that hands back time, cuts fraud, and reveals less about us than the paper forms ever did. The point of weighing the dark edges so carefully is not to refuse the technology. It is to insist that the people who build it choose the architecture that serves us, and that the rest of us understand the choice well enough to hold them to it.

A bridge can be built to carry people or to cut a town in half. The steel doesn’t decide. We do — while there’s still a draughtsman’s table and the lines aren’t yet poured in concrete.

Use this as

A briefing for boards, public submissions, or anyone weighing the Trust Framework, Digital Cash and cross-government data sharing. It argues neither for nor against digital identity — it argues for getting the architecture and the guardrails right, because that, not the technology, is what decides the kind of society we end up living in.