AI & Economy

India Stack 2.0: What UPI's Success Teaches the World About Digital Public Infrastructure

Saranya Sajeev · Sep 12, 2026 · 7 min read

In January 2026 alone, UPI processed 21.7 billion transactions worth more than ₹28 lakh crore. India now accounts for roughly 49% of all real-time digital payment volume on the planet. A payment system that didn't exist a decade ago has become, by transaction count, the largest of its kind in the world — and India has spent the last two years actively exporting the architecture behind it to dozens of other countries. That's a genuine policy success story, one of the clearest examples anywhere of a government building infrastructure that actually gets used at population scale.

It's also, underneath the headline numbers, a story with real human costs that the export narrative tends to leave out. Both things are true at once, and a blog about technology and public policy that only tells the first half isn't being honest about what "digital public infrastructure" actually requires to work for everyone it's built for.

What actually got built, and why it worked

India Stack isn't one product — it's a layered set of open, interoperable digital systems: Aadhaar for identity, UPI for payments, DigiLocker for document storage, and a growing set of consent-based data-sharing frameworks sitting on top. The philosophy, championed by the volunteer think tank iSPIRT working alongside government, was to build foundational digital rails as public infrastructure — free or near-free to build on — rather than leaving something as basic as "can two strangers pay each other instantly" to be solved individually and expensively by every bank and fintech company. DigiLocker alone now has over 67 crore users and has issued more than 950 crore digital documents. That's the part of the DPI thesis that has clearly, measurably worked: build the rails once, publicly, and let a much larger ecosystem of banks, fintechs, and government schemes build on top for a fraction of what it would cost each of them to build separately.

The economic case for this is straightforward and largely proven. India's digital economy now contributes an estimated 12-14% of GDP, a share projected to approach a fifth of the economy within a decade, and a meaningful part of that growth traces directly to the reduction in friction — lower transaction costs, faster onboarding, wider financial inclusion — that this shared infrastructure layer enabled.

The export story: India as a digital infrastructure supplier, not just a user

What's newer, and genuinely notable from a global policy standpoint, is how deliberately India has turned this into an exportable model. The government has signed cooperation agreements with roughly 23 to 24 countries to share or adopt components of India Stack, spanning Africa, Southeast Asia, Latin America, and the Middle East. UPI itself is now live for cross-border transactions in eight or nine countries, including the UAE, Singapore, France, Mauritius, Nepal, Bhutan, and Sri Lanka. Perhaps more consequential in the long run is MOSIP — the Bengaluru-built, open-source identity platform derived from Aadhaar's architecture — which is now deployed in more than 15 countries, including the Philippines, Morocco, and Ethiopia, giving nations that could never afford to build a national identity system from scratch a working, battle-tested alternative to buying one from a Western vendor.

This is soft power built out of working code rather than diplomacy alone, and it's a genuinely distinctive Indian contribution to how digital governance spreads globally — most of the developing world's prior options for this kind of infrastructure came from expensive proprietary vendors or foreign aid programs with their own strings attached. India Stack Global offers something different: source code, technical assistance, and policy templates, largely free of the licensing costs that would make comparable systems from Western tech companies unaffordable for many partner governments.

What the export narrative usually leaves out

Here's where the story needs the same rigor this blog has tried to apply to every other AI and technology claim in this series, because the India Stack success narrative, told on its own, is incomplete in a way that matters.

Aadhaar-based biometric authentication — the identity layer underneath much of India's welfare delivery, banking, and increasingly its telecom system — fails at a rate that has remained stubbornly around 6.5% for over a decade, according to analysis of UIDAI's own parliamentary disclosures. That sounds small until you do the arithmetic: roughly 312 million biometric authentications are attempted each month for welfare, banking, and public services, and around 20 million of them fail — more people affected every month than the combined population of Delhi and Mumbai. Parliament's own Public Accounts Committee has heard, across party lines, that faulty fingerprint and iris scans are blocking eligible recipients from subsidised food rations and rural employment guarantee work.

The pattern in who fails isn't random. It clusters heavily among manual laborers — agricultural workers, construction workers, domestic workers — whose fingerprints degrade through years of physical work, and among elderly citizens whose iris patterns change with age. That's a genuinely structural contradiction: the people most dependent on welfare delivered through this system are also the ones most likely to be excluded by its core authentication method. Research and field reporting, including documented cases going back years, have linked authentication failures to real hardship, including instances where people were unable to access food rations for extended periods due to a single malfunctioning device at a local ration shop, with no available override and no clear path to escalate. Academic field studies, including work by economist Jean Drèze and colleagues in Jharkhand villages, have found exclusion error rates as high as 20% in areas where biometric authentication was required for every transaction. India's own Comptroller and Auditor General found in a 2021 performance audit that UIDAI had not systematically studied the causes of its own authentication failures.

None of this erases what UPI and DigiLocker have accomplished on the payments and documents side, where the technology is a genuinely good fit for the problem — moving money and storing documents don't depend on a living human body's biometric traits holding steady over decades of manual labor. But it's precisely because the payments success has been so visible and so exportable that the identity-layer problems risk getting quietly exported along with it, into countries adopting MOSIP-based systems without necessarily building in the exception-handling, appeals processes, and non-biometric fallback options that India itself still hasn't fully solved after more than a decade of trying.

The actual lesson for other countries

The honest version of "what UPI's success teaches the world" isn't simply "build shared digital rails and good things follow," even though that's the version usually told in international forums. It's closer to: shared digital public infrastructure can deliver genuine, population-scale gains in efficiency, inclusion, and cost — India's UPI numbers are real and worth studying seriously — but the parts of that infrastructure resting on biometric identity carry a specific, well-documented failure mode that hits the poorest and most vulnerable hardest, and no amount of transaction-volume success on the payments side substitutes for solving that problem on the identity side.

A country adopting India Stack's architecture today has an advantage India didn't have in 2010: the failure data already exists. The responsible way to import this model isn't to copy the payments success and hope the identity problems don't translate — it's to build the appeals mechanisms, non-biometric fallback options, and exception-handling infrastructure in from day one, treating them as core infrastructure rather than an afterthought the way India, by its own Parliament's admission, largely still hasn't.

That's a less triumphant story than the one usually told at DPI summits. It's also the more useful one, for any country actually trying to build this kind of system rather than just admire it from a distance.