3.6 million people in Buenos Aires access their documents through an app whose credentials are anchored on an Ethereum rollup.
Almost none of that infrastructure is pointed at the AI risks it could absorb.
New LADP report, out today:
ladp.io/ai-risks
Five cases: QuarkID in Buenos Aires, Sovra, Blerify, Proyecto DIDI, World.
Three settle on Ethereum L1. Two deliberately don't. A report funded by the EF that only looked at Ethereum wouldn't be evidence about Ethereum.
Finding 1: the rails are further along than the discourse suggests.
QuarkID is the most widely deployed DID protocol we found in LATAM government infrastructure. Uruguay's AGESIC published a pilot with Blerify: a cross-border trust list where each country runs its own node.
Finding 2: the AI case is made openly by private companies and almost nowhere by the public institutions that would deploy it.
Governments issue verifiable credentials for documents and benefits. Not against deepfakes, synthetic identity or phishing at scale.
Finding 3: the one I didn't expect: what's missing is almost never technical.
The contracts work. The cryptography works. The biometric enrolment works. It's the legal instruments, the policy and the advocacy that are in their infancy.
What moves it is a decree that gets published, and someone who can explain a zero-knowledge proof to the official who has to sign it.
Therefore, most of the 13 recommendations aren't engineering.
Budget the legal framework into the deployment roadmap. Look at mid-size countries, where fewer people have to say yes. Translate cryptographic guarantees into language a regulator can act on.
Proof of non-personhood is being specified in four standards bodies.
By Claudio Cifuentes, with me. 22 interviews, Nov 2025 - Mar 2026. Funded by the
@Ethereum Foundation, whose work overlaps with it.
ladp.io/ai-risks