Power down? ID gone.

Digital ID: A System Nobody Asked For, and the Risks Everybody Will Bear

Governments around the world have moved aggressively toward digital identity systems. They have done so largely without asking the men and women who will live under those systems whether they want them. The reasons for that reluctance to ask are becoming clearer by the day.


Who Decided This Was a Good Idea?

The question deserves a direct answer.

Digital ID systems have been designed, procured, and implemented by governments in partnership with technology companies. The men and women who will carry digital identities – and who will be denied services, face enforcement action, or be excluded from participation in civic and commercial life if those systems fail – were not meaningfully consulted in any jurisdiction where these systems have been introduced.

In Australia, the federal government passed the Digital ID Act 2024 (Cth). The legislation creates a framework for a national digital identity system. The parliamentary debate on the Bill recorded significant concerns from a minority of senators about privacy, coercion, and the concentration of identity verification power in a small number of approved providers. Those concerns were not resolved before the legislation passed.

In the United Kingdom, a national ID card scheme was proposed, debated for years, and ultimately abandoned in 2011 after significant public opposition. The current digital driving licence pilots have proceeded with far less public debate than the card scheme that preceded them attracted.

In the European Union, the eIDAS framework and its successor eIDAS 2.0 impose digital identity wallets on member states, with citizens in theory able to opt out – but with increasing practical pressure to participate as services migrate to digital-only channels.

In no jurisdiction of which the author is aware has a binding, properly conducted public referendum on digital ID been held. The question of whether the people consent to being digitally identified has not been put to the people.


The Hacking Problem

Digital identity systems are databases. Databases are hacked. That is not a theoretical risk. It is a documented, recurring, and accelerating reality.

The scale of identity data breaches in recent years is significant:

In 2022, the Optus breach in Australia exposed the personal details of approximately 9.8 million current and former customers, including passport and licence numbers – the exact categories of data that digital ID systems depend upon and centralise.

In the same year, the Medibank breach exposed the medical records and personal details of approximately 9.7 million Australians. Medical data is increasingly linked to identity verification systems in the health context.

The MyGov system in Australia, which serves as a gateway to government services including the Australian Taxation Office, Centrelink, and Medicare, has been subject to repeated attempts at fraudulent access. The system’s single sign-on architecture means that a compromise of MyGov credentials is a compromise of the man or woman’s entire government service relationship.

The specific danger of centralised digital ID is the aggregation problem: where identity data is held in one place, one successful breach compromises everything simultaneously. A stolen physical wallet loses one document at a time. A compromised digital identity loses the entire stack at once – and unlike a physical document, a compromised digital identity can be used remotely, instantly, at scale, before the breach is even detected.

The Australian Cyber Security Centre’s own annual threat reports have consistently identified credential theft and identity fraud as primary and growing threats. Government digital systems are specifically named as targets. These are not the observations of critics. They are the government’s own assessments of its own systems’ vulnerability.


The Power and Infrastructure Failure Problem

The VicRoads outage reported on 11 June 2026 is not an isolated event. It is an example of a structural problem that digital ID proponents have not adequately answered.

Digital systems depend on:

  • Power to the servers that hold the data
  • Network connectivity between those servers and the man or woman trying to access their identity
  • Software that functions correctly
  • Hardware that does not fail
  • Maintenance windows that do not coincide with moments when people need their documents

Every one of these dependencies is a single point of failure. Physical identity documents have none of them. A laminated card does not need Wi-Fi. It does not stop working during a system upgrade. It does not require a server in a data centre to remain functional. It works in a blackout, in a remote area, in a country with no mobile coverage, and on the day the cloud provider has an outage.

The global record of digital system failures is extensive and growing:

The 2021 Fastly outage took down large portions of the internet for approximately one hour, demonstrating that centralised cloud infrastructure can fail at scale with minimal warning.

Australia’s myGov system has experienced multiple outages, including during high-demand periods such as the early weeks of the COVID-19 pandemic when large numbers of men and women needed to access Centrelink services simultaneously.

The UK’s NHS digital systems have experienced significant outages, including the 2017 WannaCry ransomware attack that disrupted hospitals across the country – an attack on a health system that holds identity data.

In each case, the men and women who depended on the system had no alternative. They were turned away from services, unable to prove their identity, and unable to access entitlements. The system’s failure became their problem.


The Power Grid Dimension

The question of what happens to digital ID during extended power failures has not been answered by any government that has introduced such a system.

Australia’s electricity grid is under documented stress. The Australian Energy Market Operator publishes regular assessments of grid reliability. Extreme weather events produce localised and regional power outages that can last hours or days. Bushfires have severed power to entire regions. Floods have done the same.

In those circumstances, a man or woman who holds only a digital licence, and whose registration and insurance are verified only through an online database, is effectively undocumented. They cannot prove who they are. They cannot prove their vehicle is registered. They cannot access services that require identity verification. All of this happens not because they have done anything wrong, but because the infrastructure on which their identity now depends has failed.

The question of what happens to a man or woman’s legal standing when the system that mediates it goes offline is one that governments introducing digital ID have not satisfactorily answered, because there is no satisfactory answer within the current design of those systems.


The Enforcement Asymmetry

Here is the structural unfairness at the heart of digital ID in the enforcement context.

When the system works, it works against the man or woman if the records are wrong – and records are sometimes wrong. Database errors, processing delays, system glitches, and administrative failures all produce records that do not accurately reflect the actual position. A man or woman whose registration renewal payment was made but not yet processed appears in the database as unregistered. The enforcement action follows from the database record, not from the facts.

When the system fails, the man or woman bears the consequences of that failure too – they cannot demonstrate their compliance because the system that holds the evidence of compliance is down.

In both cases, the risk sits with the individual. The institution retains the power to enforce based on whatever the system says when it is working, and faces no consequence when it is not.

This asymmetry is not accidental. It is a structural feature of systems designed primarily for administrative convenience and state revenue efficiency, rather than for the protection of the rights of the men and women who must live under them.


The Coercion Trajectory

Every digital ID system introduced as voluntary has moved toward practical compulsion over time. The mechanism is consistent: services progressively migrate to digital-only channels; those who cannot or will not use digital ID find themselves excluded; exclusion from services creates pressure to participate; participation is then described as a choice.

In Australia, the Digital ID Act 2024 contains provisions stating that participation is voluntary and that existing identity verification methods will be maintained. Those assurances exist in the text of the legislation. They do not exist as constitutional protections. They can be amended or repealed by a future parliament. The infrastructure built around digital ID creates its own momentum toward universal adoption, regardless of what the founding legislation says about voluntariness.

The trajectory in every jurisdiction where this has been examined follows the same arc: voluntary introduction, service migration, practical compulsion, formal compulsion.


What Men and Women Can Do

Understand your rights before the system tells you what they are.

A digital licence is a convenience, not a legal requirement to abandon your physical documents where physical documents remain valid. Keep your physical licence. Keep copies of your registration and insurance documents in your vehicle. Do not depend exclusively on a system that has already demonstrated it will fail.

If you receive an enforcement notice during a system outage – for an apparent failure that the outage contributed to – do not simply pay. The institution must prove its case. A database record from a system experiencing a major outage is not self-proving evidence. The burden of proof lies with the institution, not with you.

Document system failures when they affect you. Date, time, nature of the failure, what you were trying to access, what error you received. That record may be directly relevant to any enforcement action that follows.

Engage with the political process on digital ID legislation. The Digital ID Act 2024 (Cth) is subject to parliamentary scrutiny. Senators and Members of Parliament representing your interests can be written to. Submissions to parliamentary inquiries can be made by any Australian. The question of whether digital ID in its current form serves the interests of the men and women who must live under it is a political question that has not been settled.


The Question That Has Not Been Answered

Who bears the cost when the system fails?

In the VicRoads outage of June 2026, thousands of men and women have been unable to access their digital licences, pay their registration, or verify their vehicle details. VicRoads will restore the system. It will not compensate the people who received infringement notices during the outage, could not access services they were entitled to, or were disadvantaged in dealings that required identity verification.

The system failed. The people will bear the consequences. Nobody who designed or procured the system will be held accountable for the failure.

That is the answer to the question of who thought digital ID was a good idea. It was a good idea for the institutions that administer it. For the men and women who must live under it, and who carry all the risk when it fails, the question has not been answered to their satisfaction – because it was never put to them.


Salus populi suprema lex esto – the welfare of the people shall be the supreme law. A system that serves the administrative convenience of the state at the expense of the security and practical liberty of the men and women it governs has inverted that principle. The people did not ask for this. They should be asking why they were not asked.*


This article represents general analysis and commentary. It does not constitute legal advice. Specific legal questions should be directed to a qualified legal adviser.

Last Updated 3 months ago

Views: 108

Posted by Jillian