Digital Tribulations 23: Let’s Talk About Digital Sovereignty in Latin American Governments – Interview with Luis Papagni

The introduction of Digital Tribulations, a series of intellectual interviews on the developments of digital sovereignty in Latin America, can be read here. The entire series can be found here.
Esteban from the AGC (Asociación Gremial de Computación) — Argentina’s tech worker union — invited me to the first meeting of the informatical workers of Argentina. It was held at the UMET, Universidad Metropolitana para la Educación y el Trabajo, founded in 2013, and currently co-managed by more than 100 unions, civil society groups, and municipalities, which shape its degree programs and research agendas around the country’s productive and technological development. UMET runs a joint research center with CONICET, Argentina’s national scientific council, focused on work, technology, and social innovation. It offers subsidized tuition for union members and their families as part of a push to widen access to higher education for workers. The meeting ran from 6pm, with a light reception at the entrance: the coffee was bad, but the medialunas were good. There were associations coming from all around the country.
The room was full of people of all ages, including a couple of good-humored older and elegant men, and a small group of three tattooed videogame programmers from the “Women in Games” collective for whom the central issue wasn’t so much technical regulation as the regulation of AI-generated art. The topic of the evening was, in fact, the regulation of artificial intelligence, and the speakers who followed one another represented a range of voices: Esteban himself, speaking on behalf of the Observatorio del Trabajo Informático; someone from Calliope, a tech platform; and a representative of ADICRA, the computer science teachers’ association, who was arguing that regulation should be the ministry’s job — though, they admitted, the ministry itself is currently divided on the issue. A speaker from the foundation Sociedad Digital brought up Milei’s stance against any form of regulation, while the UMET’s own student center weighed in with the students’ perspective.
One intervention that stood out to me came from Buenos Aires’ R programming community, who made the case for free software as a way of breaking down barriers to access to knowledge — a point that ties directly back to the question of technological sovereignty: whoever controls the tools also controls access to knowledge. Also present were ARSAT, the state telecommunications company; Les Tiques, the LGBT+ tech workers’ collective; and the Observatorio de Derechos Informáticos Argentino. A recurring theme throughout the discussion was that regulation shouldn’t just impose limits — it should create conditions for industrial development in the sector. The Atlas de la Inteligencia Artificial para América Latina was cited in this regard.

Fig. 1 The meeting starts at UMET 
At its turn, Luis Papagni raised an interesting question: should the conversation start from the use of AI, or from its production? He pointed to Chile, which chose to start from production. I asked Papagni for an interview, which we did in San Telmo, Buenos Aires, one of the city’s oldest neighborhoods, known for its cobblestone streets, colonial-era buildings, and bohemian, slightly worn-down charm, with its antique shops and tango halls. We met in a café with good medialunas, sat down at wooden tables, and started discussing his recent thesis on a shared Latin American system of digital sovereignty.
***
Where did you work and how did you become interested in the topic of technological sovereignty?
I’m a systems engineer. I have a master’s degree in regulation and the digital ecosystem, which I did in Colombia, at Universidad Externado de Colombia. That’s regarding education. As for my work: I’ve been working for more than 25 years, starting in the private sector and then moving to the public sector in the Province of Buenos Aires. I began working at a provincial tax agency called ARBA (Buenos Aires Province Revenue Agency), and from there I started moving through different public management positions.
I was IT Director in Social Development, provincial Systems Director, manager at ARBA, director at the Ministry of Development and Environment. And then here at the national level as Undersecretary of Administrative Innovation. And my last public position was at the Argentine Embassy in Colombia, as Technology Advisor and coordinator of the Argentine Digital HUB. With that experience I started to see the issue of technological sovereignty: how the State often doesn’t take sovereignty principles into account, in the sense that today the digital world encompasses much more than the analog world. And at that point we have to start thinking about what sovereignty means in this digital ecosystem, which isn’t the same as at a physical border: how far does a country’s responsibility extend digitally, how should it maintain, protect, and control it. All these issues that I think today’s discussions are heading in a different direction, and sovereignty isn’t very present in them.
Maybe the big corporations do take it into account, but among countries, few have framed digital sovereignty as a real frontier, just like cyberspace. It has expanded so much that today, as citizens, we also need the State to protect its own assets, while also looking after citizens in the digital ecosystem. And today not many are raising this, nor acting on it. So that’s why I try to advocate on this issue: let’s discuss digital sovereignty. Not just discuss the use of artificial intelligence; let’s also discuss why we’re going to use foreign platforms instead of local ones, why we don’t drive local technology development, why we don’t work on transparency and algorithmic protection from the ground up—not only in Argentina, because I think this is also an issue for Latin America.
I had the opportunity to travel through several Latin American countries thanks to the role I held, and I think Latin American countries have great potential that is starting to become visible. The serious problem we have in Latin America is that we’re very fragmented. I think Europe is different, and in that fragmentation, the discussion gets a bit scattered: we’re not working in a coordinated way on sovereignty, either at the regional level or within each individual country. But I think it’s something that, above all, public regulators need to start taking into account.
Let’s consider two indicators of sovereignty: how much the topic is discussed and how much a certain country develops its own computational infrastructure. How is the Argentinian situation?
Let’s see: Argentina is one of the Latin American countries—if I’m not mistaken, it’s the only Latin American country—that has two satellites in orbit and one more under construction. In fact, with these satellites it has covered a large part of its national territory, and besides, it has satellite capabilities to sell to other countries as well. As such, Argentinian communication is safeguarded by a state-owned company. 
From this point of view, Argentina had, over the last 15 or 20 years, a vision of technological sovereignty that today I’m not seeing carried forward in the same way. I think that perhaps the regulatory mechanisms being pursued don’t have a vision of what sovereignty is and how that technological sovereignty could be maintained. Argentina, at the Latin American level, advanced enormously. Today it’s on a plateau, at least from what I know, without a clear definition on sovereignty issues.
There’s also the issue of data centers. It was very much in the news that, at the end of last year, there were announcements about establishing data centers in Argentina with a very, very large investment. I would take that with a grain of salt. It was an announcement without substance: there was no agreement, from what I know, not even from press reports, that could support that statement. They’re good intentions. Now, the topic is on the table, it’s starting to become visible. I think Argentina has a good setting to be able to establish these data centers. But in the vision of implementing data centers on national territory, there has to be a safeguard on the part of the State, in the sense of: what capabilities remain for Argentina? Is it just a short-term infrastructure investment, and then what? Because in the end Argentina is giving up natural resources, giving up technological capacity, giving up data. What’s left?
 I think that’s where you have to be extremely careful about how these kinds of contracts or agreements are made: what computing capabilities remain in Argentina. Not just human resource development capabilities, but also the capacity for companies and universities to use part of that processing capacity. I think that’s where we can add value: okay, they’re in Argentina; we’ll give benefits so these kinds of companies set up here, but we have to take into account human resource capacity development, data processing capacity development by academia, the State, SMEs; and the protection of personal data according to the rules that exist in Argentina. 
There’s a checklist of precautions before making grandiose announcements that, in the end, remained just announcements, because today there’s no effective agreement in sight, nor one framed from a clear point of view: whether it’s a financial agreement, what’s enabled, what’s required, and what remains. But it is a warning sign: certain precautions need to be taken when this kind of initiative is promoted. 
Part of digital sovereignty is the construction of digital public infrastructure (DPI). Latin America interests as a space of experimentation. For example, PIX was revolutionary in changing citizens’ lives in two or three years.
The issue of digital public infrastructures seems to me to be the evolution that countries that have achieved digital government need to make. I think Latin America—countries like Argentina, Brazil, Colombia, Chile, Uruguay—have progressed very well on digital government issues.  The thing is they reached a scaling point where they can no longer keep advancing. And I think viewing digital infrastructures as digital public infrastructures, as a public good, is the next step.
These DPIs are showing that it’s a scaling process. I think Latin America has many opportunities to make that leap. And I often compare it to a highway: it’s the highway of what’s coming, and it can be used both by the public sector and the private sector, not just the public sector. And things like digital payments, digital identity, interoperability mark the foundation of these digital public infrastructures: they need governance by the State, but public use, by both the public and private sectors.
That lets you get out of the current siloed compartments of digital government and start moving toward a much more fluid integration with the private sector. In PIX, payments can be made from both the public and private sectors, but with public sector governance to respect the rules, procedures, and protection of citizens in their accounts and so on. The State sets the rules, but the infrastructure can be used by both the public and private sectors. Also, digital public infrastructure gives you a view from the citizen’s side, from the end user’s side. Because up to now, everything built in digital government has been to solve problems for the State, without looking at the citizen. That is: an agency needed to solve some procedure, created an application, published it, and it looked great, but it solved its own problem. And the citizen was left with the burden of having to download that app, plus needing four more apps for different procedures. So you end up solving something for the State, but not for the citizens.
With digital public infrastructure, it’s about reversing that view: I have a single identity. In the analog world we have one identity; in the digital world we have infinite ones. So it’s about bringing that to the citizen’s side: that the citizen has a single identity; that they stop being a “digital errand-runner” for the State; that the State can achieve interoperability between the State and the private sector. And the safeguarding and protection—one of the main factors—is to facilitate those economic transactions for the citizen. That’s why I think these three pillars in digital public infrastructures need to move forward.
Apart from payments infrastructure, DPI is also digital identity systems. Can you tell us more about your recently written thesis?
The thesis covers a model of digital identity governance for Latin America: how to approach a digital identity model in Latin America looking at the European Union model, eIDAS 2 (the second version of the European framework/regulation for digital identity and trust services), which is currently in force. So the thesis makes a comparison of the possibilities Latin America has to implement a model similar to Europe’s, knowing that, for example, we don’t have a “supranational” body like the European Union. I ask: how should it be coordinated? What possibilities do countries have? What are the maturity levels of countries on this issue? And how could you implement a digital identity?
The thesis proposes—or leaves open— the possibility of thinking about a body: a regional digital identity council, the CRID, formed by organizations like the Organization of American States (OAS), which is the regional political forum of the Americas, and by funders such as banks, to decide what will be used and what policies should be adopted. I approach this issue starting from the history of digital signatures in Latin America. Why did I focus on digital signatures? Because in Latin America—especially in the southern countries: Argentina, Brazil, Uruguay, Paraguay, Chile, Colombia, Ecuador—the laws implementing digital signatures date from roughly the same period. And all the countries started advancing with digital signatures independently. But what happened? Many chose different standards, different infrastructure frameworks, different political integration frameworks. And each one developed on its own.
When we got to 2017–2018, discussion began on how to integrate or achieve interoperability between countries with digital signatures. And we found that, since we had different standards, different security policies, different infrastructure, it was very difficult to establish an integration method for everyone together. 
All of this happened with the first eIDAS directive too, the European regulation to unify digital identity and signatures, with all the difficulties there were in getting different countries’ systems to talk to each other.
Exactly. Today, to have a digital signature with cross-border validity, you have to make a country-by-country agreement: bilateral agreements. Because you have to look at the infrastructure, the legal side, and the standards schemes the other country has in order to validate it on your end. But you have to do it one by one. If they had made a decision to have a standard with a specific policy from the very beginning, all of this would have been easier. So my purpose in the thesis is: let’s not wait to integrate or achieve interoperability once digital identity is already deployed. The topic is already being discussed: let’s establish a standard now. Then, each country has the autonomy and sovereignty to implement digital identity whenever it wants, but with a standard decided at the regional level so this doesn’t happen to us again.
What I liked about the second European directive is the proposal of a standard definition. I think that’s the basic and fundamental thing: a standard definition. And integration with the private sector. These are two points that I think Latin America doesn’t see today. I’ll tell you why: it’s a very fragmented region. Very fragmented internally within each country, and at the regional level. So it’s very hard to move forward on common directives and common policies. There’s also fragmentation with the private sector: I think Latin America has a marked border between the public and private sectors, and that’s not as much the case in Europe; there they can work in a more coordinated way. I think these are two measures we need to start taking from the very beginning.
Within the debate on digital identification, what’s your opinion on the use of biometrics? Brazil uses it a lot with some personal data protection issues. 
I think biometrics is very useful, but it needs to be safeguarded by the public sector. You shouldn’t use biometric data for the private sector. So I think a path of sovereign digital identity, using blockchain for example, where the State is the one that can biometrically identify a person and issue their credential, and then validation by the private sector is done without biometrics, is a scheme that can work.
The private sector doesn’t need access to your biometrics to be able to validate your identity. And at the security level, it’s one of the most secure pillars. It’s a scheme similar to the digital signature one in Argentina: you validate your identity with biometrics to get your digital signature, and you revalidate it every two years. With verifiable credentials, something similar could be done: every so often you revalidate with biometrics, but the biometrics are handled by the State with safeguards and personal data protection, without opening it up to the private sector.
Did you find anything interesting about the development of this kind of system in other American countries?
Yes. I found something I wasn’t expecting. Caribbean countries didn’t advance in digital government the way Argentina, Brazil, Uruguay, and Chile did. However, they found in digital public infrastructures a leap toward a “smart government” model, without going through digital government first. They found that digital public infrastructures let them integrate many services without having first built a complete digital government, and jump straight to a smart government. And that gave them an exponential leap.
The case of El Salvador, the Dominican Republic, Costa Rica: they’re already working on digital public infrastructures and with digital identity much more advanced than countries that had progressed a lot in digital government. Why? First, because you have an important level of political decision-making: when the political decision-maker sees “I’ve already solved this,” you have to make them understand that this is about scaling. And second, because governments that advanced a lot in digital government have to integrate what they created with the private sector. Many advanced internally, but didn’t integrate with the private sector.
Caribbean countries, on the other hand, which hadn’t advanced before, had quick adaptation, quick implementation, and quick adoption by citizens. I think today they’re leading the charge on DPI implementation much faster. Among them, on the digital identity issue: the Dominican Republic is one, El Salvador is another. These are countries that today are leading in digital identity, and they owe all of this to digital public infrastructures.
 
And what about generative artificial intelligence: how can it help in this implementation in this transition?
I don’t know if it can help. I think we’re a region where we are consumers of artificial intelligence and not producers. And that’s a big problem: consuming what comes from outside instead of what we need to generate with our own identity, our own policies, our own biases—not foreign biases. But that leap toward using artificial intelligence needs data. And that data has to be provided by the State, based on data protection.
I think that if we can’t move forward on a digital government structure—leaving behind the siloed compartments and starting to work on a data infrastructure—we won’t be able to be AI producers and we’ll be consumers. I think the first step in Latin America is to aim to be AI producers and use its digital public infrastructures as the foundation. Otherwise, we’ll be eternal consumers and we’ll just do what we’re told from outside, without a vision of our own identity and our own political vision. Because, traveling and asking many people in Latin America how cooperation between countries can be strengthened, I found that everyone says “yes, we have to do it,” but no one is doing it.
Do you have an idea of what steps could be taken?
Today there’s a network, the Latin American and Caribbean e-Government Network. It’s an excellent starting framework for this kind of discussion. It brings together the top technology and innovation authorities from Latin America and the Caribbean, and it’s promoted by the Inter-American Development Bank (IDB) and the OAS. I think it’s an excellent framework for initial discussion, but it’s a very technical framework. And I think we no longer need a technical discussion: we need a political and social one.
So the discussion has to take place in bodies like the OAS, for example, where work policies can be defined for all countries. I leave it as an open question in the thesis: if it’s not the OAS, it could be Mercosur, for example, or other regional organizations that could take on that leadership. But there has to be leadership from a supranational body to drive this discourse. I think it’s time to think: you can’t think of everything from within a single country. If you really want to work on this issue, you have to think about it regionally. Geopolitics is changing, and I think it’s time for Latin America to start having more of a bloc-level vision to protect its priorities. Otherwise, we’ll be dependent on whatever decision is made elsewhere.