Civic / Privacy / Digital Rights
AI, Digital Identity, CBDCs, Surveillance, and the Mark of the Beast
Report summary
Digital identity systems and retail central bank digital currencies are separate policy domains, but they increasingly converge in practice. A modern digital identity stack typically includes identity proofing, credential issuance, authentication, and optional federation or portability across servic
Key topics
- Civic / Privacy / Digital Rights
- Civic
- Privacy
- Digital Rights
- AI
- Runtime
- Physics
- Research Archive
- Audit
Research provenance
For citation, use the report title and canonical URL. Archival presence does not establish authorship or promote report statements into portfolio evidence.
Source availability: 31 citation markers in the source export have no recoverable source links. Those markers are omitted from this reader; any supplied bibliography and ordinary links remain. Check the original sources before relying on the cited claims.
This page renders the archived Markdown as safe, formatted HTML. It is background research and does not become a portfolio claim without evidence review.
Full report
On this page
Executive summary
Digital identity systems and retail central bank digital currencies are separate policy domains, but they increasingly converge in practice. A modern digital identity stack typically includes identity proofing, credential issuance, authentication, and optional federation or portability across services. CBDC architectures typically vary across account-based, token-like, offline-capable, and programmable or condition-triggered designs, while many central banks now prefer hybrid or two-tier models in which private intermediaries handle wallets and onboarding while the central bank operates the core ledger or settlement layer. AI already plays a material role across this stack: document validation, liveness checks, biometric matching, fraud monitoring, anomaly detection, and transaction-network analysis. These capabilities can reduce fraud and improve usability, but they also expand the capacity for profiling, exclusion, and centralized data governance.
The central policy question is not whether these technologies are inherently totalitarian, but whether legal and technical choices make them linkable, queryable, and governable in coercive ways. Official CBDC and digital-identity publications repeatedly acknowledge this trade-off. The IMF notes that CBDC data can create a “digital trail” containing transaction histories, demographics, and behavioral patterns, while the ECB, Bank of England, and BIS all frame privacy as a core design requirement rather than a side issue. In practice, surveillance risk rises sharply when identity, payments, device metadata, and AI-based risk scoring are fused across institutions without strict purpose limitation, due process, and data minimization.
Privacy-preserving alternatives are technically real, not merely aspirational. W3C verifiable credentials and DIDs allow portable credentials with holder control; selective disclosure can reduce over-sharing; zero-knowledge proofs and multiparty computation can separate compliance proofs from raw disclosures; and BIS Project Tourbillon shows that cash-like payer anonymity is technically feasible, though often with performance and complexity costs. These tools do not eliminate governance risk, but they can materially reduce routine surveillance if combined with explicit legal firewalls, offline options, and continued access to cash.
Theological claims linking digital identity or CBDCs to the “mark of the beast” draw their force from Revelation 13:16–18, especially the linkage between the mark and the inability to “buy or sell.” Yet primary religious sources show that major traditions do not converge on a simple “new payment technology = mark” reading. Catholic and Orthodox commentary treats Revelation as apocalyptic symbolism rooted in first-century Roman imperial power and emperor worship. Jehovah’s Witnesses interpret the mark symbolically as allegiance to the political order. Seventh-day Adventist teaching is also symbolic, but distinctively ties the end-time conflict to worship and Sabbath/Sunday observance rather than a payment rail. In contemporary evangelical prophecy discourse, influential teachers often argue that cashless systems could be precursors or “infrastructure” for end-time control, but even those voices usually stop short of saying a current system is literally the mark itself.
My assessment is therefore twofold. First, the claim that current digital-ID or CBDC projects are the biblical mark of the beast is theologically weak and overconfident. Second, the fear that tightly integrated identity-payment-AI systems could enable coercive economic exclusion is technically and politically plausible. Policymakers should take the latter risk seriously even if they reject the former claim.
Technical foundations
A digital identity system is an end-to-end system for asserting and proving official identity at different assurance levels. FATF defines it in terms of identity proofing and enrolment, authentication and lifecycle management, and optional portability or federation; NIST similarly structures the field around identity proofing, authentication, and federation, expressed as IAL, AAL, and FAL assurance levels. In practice, this means a system must answer at least three questions: who a person is, whether the credential presenter is that person, and whether the credential can be trusted across services.
Architecturally, governments and platforms now use several patterns. “Foundational” systems establish general-purpose identity; “functional” systems are limited-purpose systems such as tax IDs, passports, driver’s licenses, or benefit credentials. Federated systems let an identity provider authenticate on behalf of multiple relying parties. Wallet-based systems increasingly use verifiable credentials, where issuers, holders, and verifiers exchange tamper-evident claims. The EU Digital Identity Wallet is explicitly designed to let users store, share, and sign digital documents while remaining in control of their data; W3C’s VC model defines the issuer-holder-verifier triad; and DID standards aim to reduce dependence on centralized identifier authorities.
CBDC design starts from a different question: how should public money function in digital form? BIS distinguishes account-based retail CBDCs, which are tied to identification schemes, from token-based access, which uses signature-like control and can support greater anonymity. Operationally, central banks also distinguish direct, indirect, and hybrid/two-tier models. The current policy center of gravity is the hybrid or platform model: the central bank issues the liability and operates core infrastructure, while private intermediaries handle customer-facing wallets, onboarding, and innovation layers.
Programmability needs a sharp distinction. Official central-bank documents increasingly separate programmable money from conditional or programmable payments. The ECB says a digital euro would “never be programmable money,” but it could support conditional payments such as pay-on-delivery. The Bank of England takes a similar line, stating that centrally imposed spending restrictions would be prohibited in law and designed out of the architecture, even while user-consented automated payments could be supported via APIs and external services.
Offline CBDC is also no longer theoretical. ECB work says that offline digital-euro payments are intended to offer cash-like privacy, with only payer and payee knowing personal transaction details. The Riksbank’s phase-four e-krona pilot showed that secure offline payments are feasible, but also found real challenges around secure hardware, synchronization, liquidity, and person-to-person security. The Bank of England’s technology paper likewise frames offline support as valuable for resilience and inclusion, while warning about double-spend risks and the policy implications of fully anonymous offline records.
The following table synthesizes how the major retail CBDC design choices alter privacy and surveillance exposure. Ratings are analytic judgments derived from official descriptions, not formal labels used by central banks.
| Design model | Core mechanism | Typical identity requirement | Privacy potential | Surveillance risk |
|---|---|---|---|---|
| Account-based | Ledger entries tied to named or pseudonymous accounts | Medium to high | Low to medium | High if identity and transaction data are centrally linkable |
| Token-like or e-cash | Control by keys/signatures or bearer-like units | Low to medium | High | Medium; lower for routine observation, higher for AML edge cases |
| Offline balance-based | Local or secure-element value transfer with later sync | Usually tiered or capped | Medium to high | Medium; stronger resilience, but reconciliation and anti-double-spend controls matter |
| Conditional payments | Rules trigger payment on external events | Medium | Medium | Medium to high depending on rule layer and event-data access |
| Centrally programmable money | Money itself restricted by issuer after transfer | High or medium | Low | Very high |
AI roles and surveillance pathways
AI is already embedded in digital onboarding. FATF highlights AI and machine learning for determining the validity of government-issued IDs, while NIST guidance makes liveness detection a necessary control for remote biometric identity verification. In other words, AI is not only a future risk; it is a present component of production-grade digital identity systems.
AI also changes payment surveillance from simple rule-matching to dynamic pattern recognition. FATF notes that reliable digital ID can strengthen transaction monitoring and reduce weaknesses in human controls. BIS Project Hertha goes further, exploring AI and network analytics in real-time retail payment systems to identify financial-crime patterns using a “minimum set of data points.” Those are defensible goals. But once a system is engineered to score anomalous behavior, the same architecture can be used for broader behavioral inference, segmentation, and automated intervention.
That risk intensifies because payment data are behaviorally rich. The IMF explicitly notes that CBDC data could encapsulate transaction histories, user demographics, and behavioral patterns, and warns that overcollection can create negative externalities when institutions collect, process, or share personal data beyond what users can meaningfully control. Academic work on payment-data profiling makes the same point more bluntly: all data generated by payment services can be used to create personal profiles, raising concerns about opacity, discrimination, and loss of informational self-determination.
Surveillance does not require one omniscient state database. It can emerge from the interaction of multiple lawful but linkable systems: digital identity registries, telecom metadata, PSP logs, merchant categories, geolocation, device fingerprints, and AI risk scores. GDPR’s principles of purpose limitation and data minimization are meant to constrain precisely this kind of function creep, while the EU AI Act restricts some biometric categorization, emotion recognition, social-scoring-adjacent uses, and certain remote biometric identification practices because of their fundamental-rights impact.
flowchart TD
A[Identity proofing and wallet onboarding] --> B[Identifier and credential binding]
B --> C[Payment initiation]
C --> D[Transaction data creation]
D --> E[AI verification, fraud scoring, and anomaly detection]
E --> F[Cross-system linkage]
F --> G[Behavioral profiling and segmentation]
G --> H[Automated controls]
H --> I[Reporting, freezing, throttling, or exclusion]
This flow is not inevitable, but each step is already contemplated somewhere in current identity, AML, or CBDC design literature: proofing and authentication in NIST/FATF, payment analytics in BIS, and data-governance trade-offs in the IMF. The key policy question is whether legal and technical architecture allow these steps to be combined.
Privacy-preserving designs, governance, and law
The best current literature does not treat privacy as an all-or-nothing choice between “cash-like anonymity” and “full traceability.” It treats privacy as an architectural and governance problem. The IMF argues that better outcomes come from privacy-by-design, institutional transparency, and a menu of privacy settings, ranging from mostly anonymous small-value wallets to more identified higher-value wallets. ECB and Bank of England publications make analogous commitments, including claims that their institutions should not be able to see how users spend their money.
The main privacy-enhancing tools are now reasonably well defined. W3C verifiable credentials support issuer-holder-verifier flows, and selective disclosure allows holders to present only the attributes needed for a transaction. DIDs reduce dependence on centralized identifier issuance. The IMF’s CBDC privacy note identifies ZKPs, MPC, anonymization techniques including differential privacy, and verified credentials as usable PETs. BIS Project Tourbillon adds blind signatures and mixing to the design space, showing that strong payer anonymity can be engineered, though with real complexity and throughput trade-offs.
The table below summarizes the most relevant PETs for this policy area. The important point is that these technologies are useful but not self-executing: bad governance can nullify good cryptography.
| PET or standard | Primary use | Main privacy gain | Main limitation |
|---|---|---|---|
| Verifiable credentials | Portable proofs of attributes | Reduces repeated full-data sharing | Ecosystem governance and revocation are hard |
| Selective disclosure | Reveal only needed fields | Minimizes oversharing | Verifier policy can still pressure disclosure |
| DIDs | Decentralized identifier control | Fewer centralized identifier bottlenecks | Does not by itself solve proofing or legal trust |
| ZKPs | Prove facts without exposing raw data | Strong separation of compliance and disclosure | High complexity, performance cost |
| MPC | Compute over distributed private inputs | Avoids pooling raw datasets | Operationally complex, still needs governance |
| Blind signatures or e-cash methods | Token issuance with anonymity | Cash-like payer privacy | Compatibility with AML and recovery policies |
Legally, the clearest current guardrails are data-protection rules, AI-specific restrictions, and CBDC-enabling statutes. In Europe, the GDPR centers purpose limitation, data minimization, storage limitation, and security. The EUDI framework and wallet programs are explicitly framed around user control and privacy. The AI Act adds a specific layer for biometric and high-risk AI uses. In the UK, the Bank of England repeatedly states that a digital pound would require primary legislation to guarantee privacy and prohibit state control over spending. These frameworks do not eliminate surveillance risk, but they provide the vocabulary needed to structure it: who may collect what, for which purpose, under what authority, and with what recourse.
Pilot evidence and design comparison
Real-world pilots show wide variation. China’s e-CNY is the most developed large-economy retail CBDC deployment, and official PBC material emphasizes “managed anonymity,” with lower-tier wallets and small-value anonymous transaction support. Nigeria’s eNaira is a live retail CBDC, legal tender, and wallet-based. The Bahamas’ Sand Dollar is live nationwide, regulated, and tiered by wallet class, with lower-KYC and enhanced-KYC paths. India’s retail e₹ remains in pilot, distributed through banks and non-banks via wallets. Sweden’s e-krona pilot stressed offline feasibility, but also exposed implementation complexities. Brazil’s Drex work is oriented more toward tokenized finance and smart-contract-enabled ecosystems, and official pilot reporting says privacy, security, and architecture remain active design challenges.
The most important lesson from these pilots is that “CBDC” is too broad a category for responsible debate. A low-tier wallet with capped balances and segmented data access differs radically from a fully identified, centrally queryable, AI-scored payment graph. Similarly, official European and UK design work currently resists centrally programmable money and foregrounds privacy, whereas other ecosystems prioritize integration with tokenized financial products and smart contracts more strongly. Public controversy often collapses these designs into one imagined system and thereby misses the real design levers.
Theological interpretations and the mark of the beast
The scriptural core is straightforward. Revelation 13 describes a mark on the right hand or forehead and says that no one may “buy or sell” without it; Revelation 7 and 14 contrast this with the seal or name of God on the faithful. USCCB commentary emphasizes that Revelation is apocalyptic literature full of symbolism, and its notes on chapter 13 interpret the beast primarily in relation to the Roman Empire, emperor worship, and persecution of Christians, with 666 most likely pointing to Nero Caesar. That makes the biblical text about idolatrous allegiance and coercive power before it is about technology.
That symbolic orientation is also visible in other traditions. Greek Orthodox commentary explicitly warns that Revelation’s numbers and symbols are not secret references to today’s leaders or current economic conditions. Jehovah’s Witnesses interpret the mark symbolically as giving worshipful loyalty to the political system; for them, the hand and forehead evoke actions and thoughts, not a literal implant or payment token. These are very different traditions, yet both resist a naïve “new device equals prophecy fulfilled” approach.
Seventh-day Adventism is distinctive. Adventist historical theology links the end-time conflict to worship, divine law, and Sabbath versus Sunday observance; official Adventist materials today still present the final crisis primarily in those terms, not as a particular payment technology. That means Adventists often see the mark as symbolic and covenantal, but still tied to concrete coercive social order. In effect, technology may assist enforcement, but it is not usually the essence of the mark in Adventist theology.
Contemporary evangelical prophecy discourse is more mixed. Some influential teachers, such as David Jeremiah, argue that cashless systems make it easier to imagine Revelation 13’s economic exclusion and may be “laying the groundwork” for a future global system. Others in the same broad evangelical world warn against barcode-, vaccine-, or gadget-driven speculation and urge readers to understand Revelation’s recurring symbolic patterns rather than map every new technology onto the beast. These voices matter because they shape how many lay Christians interpret digital identity and CBDCs in real time.
On plausibility, the strongest claim is also the narrowest one: digital identity and CBDCs could, under some future political regime, become instruments of economic compulsion that resemble the “buy or sell” mechanism in Revelation. The weakest claim is the strongest-sounding one: that any current digital wallet, biometric ID, or CBDC pilot is itself the biblical mark of the beast. The former is a serious policy warning; the latter is not well supported by either technical evidence or mainstream exegesis.
Risk scenarios, mitigations, and policy recommendations
The most plausible risk scenarios are mundane before they are apocalyptic. A fused identity-payment stack can enable: automated freezing or throttling after opaque risk scores; silent expansion from AML controls into commercial profiling; exclusion caused by biometric mismatch or identity-proofing failure; and cross-agency or cross-border data sharing that weakens functional separation between payments, benefits, migration control, policing, and intelligence. None of these require an explicitly authoritarian constitution. They can emerge from weak governance, emergency powers, or vendor-driven “feature creep.”
The core mitigation principle is separation. Identity proofing should be separable from routine transaction visibility. Small-value payments should have strong privacy protections, ideally including offline options. The central bank should not see retail personal transaction data absent tightly bounded legal authority. AI-based scoring should never be the sole basis for freezing, denying, or blacklisting payment access, and there should be rapid human appeal. Cash must remain available, not merely tolerated. Those design principles are already compatible with the better official work from the ECB, Bank of England, BIS, and IMF.
For policymakers, the best package is concrete. Enact statutory prohibitions on centrally programmable money and generalized social scoring. Require purpose limitation, data minimization, independent audits, open technical standards, and privacy-impact assessments for identity/payment interoperability. Mandate tiered wallets, offline functionality, non-biometric fallback channels, and PET-enabled selective disclosure wherever feasible. Define bright-line rules for law-enforcement access, with warrants or equivalent safeguards, logging, and notice where legally possible. Require public reporting on false positives, suspensions, bias, and redress outcomes.
Open questions and limitations
Some important areas remain unsettled in the public record. Large central banks continue to revise privacy, offline, and legal models; Drex and the digital pound remain design-phase projects rather than launched retail systems; and official denominational positions outside Catholic, Orthodox, Jehovah’s Witness, and Seventh-day Adventist sources are often diffuse rather than magisterial. Even so, the highest-confidence conclusion is stable: the surveillance danger is real, but it is contingent on architecture and law, while the literal identification of present systems with the biblical “mark of the beast” is not well established by either mainstream theology or the available technical evidence.