in Panel, Seminar

The standards you never see: human rights and digital identity at NetGouv26

On 27 May 2026, I spoke at NetGouv26, the third annual conference of the Working Group on Internet Governance and Regulation (CNRS Research Network 2091 on Internet, AI and Society), held at the Maison de la recherche of Sorbonne Nouvelle in Paris and online, in partnership with AFNIC, Sorbonne Nouvelle’s Irméccen, and Internet Society France, with support from the Internet Society Foundation. The conference gathers the francophone research community working on Internet governance across disciplines: STS, communication studies, law, political science, computer science, geopolitics, design, and economics.

My talk, “Human rights and technical standards: translating principles into practice,” started from a simple observation: standards shape the invisible infrastructure of the digital world, digital identity, cybersecurity, interoperability, accessibility, data protection, AI enabled services, and none of that is neutral. Standards determine how systems are designed, connected, secured, and used.

Technical standards are not neutral. They determine how systems are designed, connected, secured, and used.

I anchored the talk in digital identity, since it raises the question in its most concrete form. A digital identity wallet forces very specific choices: which data gets shared, whether the attributes transmitted can be minimized, who controls access, how exclusion gets avoided, and how security, trust, and redress get guaranteed. Legal guarantees only mean something once they are translated into technical architecture.

A recent ITU-T Recommendation illustrates the point well. X.2310, approved in March 2026 by Study Group 17, sets security requirements for decentralized identity management systems built on distributed ledger technology. It defines identity models, basic, custody and delegation, and self-issue, and assigns them assurance levels from AL1 to AL3 depending on the use case: a digital business card might sit at AL1, a vaccination certificate at AL2, a driving licence at AL3. It is a genuinely careful piece of security engineering, covering threats from credential theft to private key loss. But the Recommendation is explicit that it does not address regulatory questions. That gap, rigorous security requirements on one side, and on the other side the separate work of making sure those same systems avoid exclusion, preserve meaningful consent, and leave room for redress, is exactly the translation problem I spend most of my time on.

In practice, that translation looks like this: privacy becomes data minimization, security, and user control; accessibility becomes services usable by everyone; non-discrimination becomes testing, documentation, and risk assessment; transparency becomes information, traceability, and explainability. It sounds straightforward stated that way, but the two communities involved ask fundamentally different questions. Human rights thinking asks who could be affected, which rights are at stake, which groups risk exclusion, and what redress is possible. Standards thinking asks what the system should do, how to measure its performance, what controls are needed, and what documentation is required. Bridging those two sets of questions is most of the actual work.

I described how ITU operates on three levels here: technical standards themselves, covering accessibility, security, quality of service, data protection, digital identity, and AI based systems; capacity building and policy dialogue, through AI strategies, digital public infrastructure work, regulatory sandboxes, and the Global Symposium for Regulators; and international cooperation, through ITU-T study groups, the AI Standards Exchange, AI for Good, and joint work with ISO, IEC, OHCHR, and others. On the practical side, we are building a human rights checklist for standardization groups, arranging consultations with outside experts, piloting the approach in a handful of study groups, and developing training for delegates and secretariat staff, the point being to move from raising awareness to actually implementing something.

I closed with a direct pitch to the room, since NetGouv is exactly the kind of audience that can help close this gap. Academic researchers are well placed to identify emerging risks, document social impact, translate legal concepts into technical criteria, evaluate existing standards, and propose testing and audit methods. Standards work needs research, not just industry expertise, and I invited people in the room to get involved directly: join ITU’s standardization work, contribute to study groups, take part in workshops and consultations, share methods and use cases, help test the human rights tools we are building, and generally help connect research, policy, and technical work. Human rights need to be built into standards from the design stage, not bolted on afterward.

Write a Comment

Comment