A government can have a digital identity system, online services and APIs across its agencies and still struggle to make those pieces work together.
That is the problem Mifan Careem, Senior Vice President and GM of Solutions BU at WSO2, put at the centre of his WSO2Con Africa 2026 presentation, where he outlined what he described as a “Sovereign Government Operating System” for the digital government era.
Careem’s argument starts below the AI layer. Governments need a common foundation for identity, access management, data exchange and citizen services before they can safely introduce AI agents that act across institutions. His presentation brought those components together under a broader discussion of digital sovereignty, resilience, sustainability and open-source technology, with sovereign cloud and sovereign AI sitting underneath the operating model.
Why digital government needs an operating layer
The practical problem is familiar. A citizen’s information can be spread across several government agencies, each responsible for a different part of the record. A birth registry may hold a person’s name, an immigration authority may hold entry and exit information, while another agency maintains vehicle ownership or tax records. When one piece of information changes, the state needs a way to propagate that change to the systems that legitimately depend on it.
Careem used a passport application to illustrate the problem. A name recorded at birth belongs to one government institution, passport information belongs to another, immigration records sit elsewhere and vehicle ownership can involve another agency. Without a data exchange mechanism, a citizen can end up repeating the same update across multiple systems.
That makes interoperability more than a technical convenience. It determines whether digital government can operate as a connected service or remains a collection of separate digital departments. Careem’s proposed architecture places government data exchange alongside identity and citizen services as one of the three main components of the operating system.
Identity becomes the first foundation
The identity layer extends beyond issuing a digital version of a national ID card. Careem broke government identity into several functions, including foundational identity, citizen access management, workforce access and government-to-government or government-to-business access.
He also described three broad approaches to digital identity. Some countries use centralised systems, while others rely on federated models in which different national systems recognise one another. Wallet-based decentralised identity adds another model, allowing citizens to hold verifiable credentials and present selected information to a service when required.
The wallet model changes how information can be shared. Careem gave a healthcare example in which a patient could hold medical credentials in a wallet and provide a clinic with selected information, such as previous surgeries or allergies, without handing over an entire identity record. The receiving institution can verify the credential without having to connect directly to the central government system for every transaction.
That architecture also introduces an important requirement for governments operating across areas with uneven connectivity. Careem argued that digital services need fallback mechanisms for people who cannot maintain a real-time internet connection, including the ability to return to paper-based processes where necessary.
Government data needs a common exchange layer
The second foundation is the Government National Data Exchange, or NDX, presented as a way to let agencies exchange information through a governed infrastructure rather than relying on isolated point-to-point connections.
The slide architecture places several functions inside the exchange layer: a metadata registry and catalogue, an access-control and data-orchestration layer, an API gateway, a consent and authorisation registry, unified authentication and IAM, and audit and logging. The presentation describes the model as GraphQL- and API-based, with support for data custodianship, consent, asynchronous data, versioning and federation.
That matters because government data is not simply a pool of information waiting to be connected. Different agencies remain responsible for different datasets, and access can depend on legal authority, consent and the purpose for which information is being requested.
Careem returned repeatedly to that question of custodianship. If one agency provides information to another, the architecture needs to establish who controls the data, what permissions apply and whether a citizen’s consent is required. Those controls become even more important once software agents can make requests without a person manually initiating every interaction.
The presentation pointed to open-source approaches including X-Road, GovStack and an OpenNDX implementation from the Lanka Software Foundation as examples of the broader ecosystem around government data exchange. WSO2’s own proposal uses APIs and GraphQL as the mechanism through which agencies can expose and consume services.
Sovereignty goes beyond where data is stored
Careem’s definition of digital sovereignty is broader than keeping government data within national borders. He described sovereignty as a question of control over the technology and the ability to decide how that technology operates.
His simplest explanation was a light switch. If a country owns the switch, it controls whether the system operates. Resilience asks whether another switch exists when the first one fails. Sustainability asks whether the country has the people and capability to repair or operate the system when something goes wrong.
That distinction is important for governments considering cloud and AI infrastructure. Keeping a workload inside a country can address one part of the sovereignty question, but it does not automatically give a government control over the software, skills, operational processes or ability to change providers.
Careem therefore placed open source alongside sovereignty, resilience and sustainability. He argued that governments should be able to inspect the technology, modify it, maintain it and operate it without becoming permanently dependent on an external party. He also stressed that open source does not mean free software; in his framing, its value lies in transparency and freedom to control the technology.
For African governments, that question sits alongside a broader digital infrastructure challenge. Kenya, for example, is building out data-centre capacity and digital public infrastructure while also dealing with questions around interoperability, data governance and sovereign control. The broader African digital-government conversation therefore extends well beyond the AI model itself.
AI agents add a new identity and governance problem
The architecture becomes more complicated once AI agents are given permission to act.
Careem’s Sovereign AI framework puts an agent’s identity alongside citizen and workflow identity. An agent would have its own identity, scoped delegation and audit trail, while access to government APIs would be governed by policy and consent. The presentation also calls for traceable AI-assisted decisions, controlled model traffic and safeguards around sensitive information.
This builds directly on a problem already emerging across enterprise AI: an agent needs to be identifiable when it calls an API, retrieves information or performs an action. In government, the stakes are higher because the systems involved can contain identity records, tax information, health data, immigration records and other sensitive information.
Careem gave the example of an agent acting on behalf of a taxpayer. If software can eventually perform a government transaction for a person, the system needs to establish which agent acted, what authority it had and who delegated that authority. Agent identity therefore becomes part of the government’s access-control architecture rather than an optional feature of an AI application.
The same principle applies to human oversight. The Sovereign AI framework presented at WSO2Con Africa calls for agents to operate within delegated authority while keeping officers involved in high-impact decisions. That creates a boundary around agentic action: software can perform authorised work, but the government retains control over which actions require human intervention.
What the model means for African governments
The presentation’s relevance to Africa comes from the way these components fit together. Digital identity, government data exchange, APIs, citizen services, cloud infrastructure and AI governance are often discussed as separate technology projects, but Careem’s model treats them as parts of one public-sector architecture.
Uganda provides one example discussed during the presentation. Careem described work with the country’s National Information Technology Authority around a data interoperability use case involving multiple government agencies, with questions around data access, consent, privacy and custodianship.
The approach also reflects a wider African digital infrastructure conversation in which interoperability and trusted data exchange are becoming central to public services. Kenya’s digital public infrastructure agenda, for example, includes digital identity, secure data exchange and interoperability alongside AI, data protection and data governance. That creates a policy and infrastructure environment in which the architecture Careem described is directly relevant to how governments think about connected services.
WSO2 is also presenting the model as part of a broader government technology offering. Its slides describe the company as supporting a sovereign government architecture built around identity, data exchange and citizen services, with sovereign cloud and sovereign AI beneath those layers. The presentation states that 42 national governments run on WSO2, a figure that should be understood as the company’s own positioning rather than an independently verified industry measure.
The commercial context is important because Careem was presenting a technology architecture as well as a public-sector philosophy. WSO2’s government proposition includes an index-based pricing model that the company says links public-sector fees to national income classifications, alongside its emphasis on open-source technology and government control. The presentation positions that approach as a way of making digital infrastructure more accessible while reducing dependence on proprietary systems.
The central idea, however, goes beyond one vendor’s products. As governments move from digitising individual services toward systems that can coordinate work across agencies, the underlying architecture becomes part of the AI question. An agent cannot safely operate across government simply because a model is capable of reasoning; it needs identity, permissions, access to governed data, reliable interfaces and a record of what it did.
That leaves the sovereign government operating system as a useful way to describe the layer underneath agentic government. Identity establishes who can act, data exchange determines what information can move and between whom, citizen services provide the interface to the public, while infrastructure and governance determine who controls the system and how its actions can be accounted for.
For African governments preparing to use AI agents in public services, that architecture may prove just as important as the models sitting on top of it.
Real ESG impact doesn’t happen in panels alone, it happens in the rooms where financiers, operators, and policymakers actually align. Our GreenShift Forum 2026 cuts the noise, bringing together the people rewiring Africa’s sustainability and energy frameworks for one focused day in Nairobi. Secure your seat.
Go to TECHTRENDSKE.co.ke for more tech and business news from the African continent and across the world.
Follow us on WhatsApp, Telegram, Twitter, and Facebook, or subscribe to our weekly newsletter to ensure you don’t miss out on any future updates. Send tips to info@techtrendsmedia.co.ke





