Verdict: India's Digital Public Infrastructure (DPI) model — the open-rails approach behind Aadhaar and UPI — has demonstrably solved identity and payments at billion-person scale. Now the same architect, Nandan Nilekani, has been tasked with fixing India's exam paper leak crisis. The evidence says technology can eliminate the physical paper vector and create accountability trails, but the institutional gaps (a testing agency with 38% permanent-staff vacancy, a one-shot exam model that creates massive cheating incentives) require governance fixes that no platform alone delivers. For builders, the DPI playbook offers a concrete framework for designing trust into systems — but it also carries hard-won lessons about exclusion, fraud vectors, and the limits of tech when the incentives are misaligned.
Last verified: 2026-08-04
- Nilekani's 6-member task force announced July 26, 2026 to reform NTA-conducted exams
- Aadhaar: 1.449 billion generated (UIDAI dashboard, live); 1.418 billion as of March 31, 2025 (UIDAI Annual Report 2024–25)
- UPI: record 23.66 billion transactions in July 2026 (NPCI data)
- NEET UG 2026 cancelled May 12, 2026 after paper leak allegations; ~22.79 lakh students affected
- Public Examinations Amendment Bill 2026 proposes 5–10 year jail, ₹50 lakh fine for exam fraud
- 41 paper leaks in 5 years, ~14 million job seekers affected (Indian Express investigation)
What is India's Digital Public Infrastructure (DPI), and why does it matter for builders?
India's Digital Public Infrastructure is a set of open, interoperable digital rails — identity, payments, and data exchange — built as public goods rather than proprietary platforms. The model, known collectively as the India Stack, enables public and private innovation on top of shared infrastructure. For builders — especially those building AI systems for real work — it's the clearest real-world example of how to design trust into systems at population scale.
According to a Press Information Bureau (PIB) report from March 2026, India has built digital public infrastructure for over 1.4 billion people at very low cost, positioning it as a replicable framework for countries worldwide. The approach rests on three principles: inclusion (open access), innovation (private-sector layers on public rails), and trust (verifiable, auditable systems) (PIB, March 2026).
The core building blocks:
| DPI Layer | What it does | Scale (verified) | Impact |
|---|---|---|---|
| Aadhaar (identity) | Biometric digital ID for 1.4B+ citizens | 1,448,910,429 generated (UIDAI Dashboard) | Foundation for KYC, welfare delivery, banking |
| UPI (payments) | Real-time, interbank transfers via open API | 23.66B transactions in July 2026 (NPCI/CNBCTV18) | Transformed retail payments; 705+ banks live |
| DigiLocker / Account Aggregator / ONDC | Data exchange, document storage, open commerce | Expanding | Enables consent-based data sharing and market access |
The United Nations Development Programme (UNDP) defines DPI as "foundational digital systems that form the backbone of modern societies" — enabling secure interaction between people, businesses, and governments (UNDP).
How did Aadhaar and UPI prove the DPI model at scale?
Aadhaar enrolled over a billion people by combining biometric capture (fingerprints, iris scans, photos) with a 12-digit unique number. The UIDAI Annual Report 2024–25 states that 141.80 crore (1.418 billion) Aadhaars had been issued as of March 31, 2025, with saturation above 90% in 28 states and union territories (UIDAI Annual Report 2024–25). The live dashboard shows the number has since crossed 1.449 billion.
UPI (Unified Payments Interface), launched in 2016 by the National Payments Corporation of India (NPCI), processes tens of billions of transactions per month. In July 2026, it hit a record 23.66 billion transactions worth ₹29.88 lakh crore, with volumes up 22% year-on-year (CNBCTV18, August 1, 2026). Over 705 banks are now live on UPI (NPCI Product Statistics).
These systems worked because:
- Open APIs — Any bank or fintech can build on UPI rails. PhonePe (48.4% market share) and Google Pay (36.9%) compete on top of the same public infrastructure (GrabOn/NPCI).
- Interoperability — A payment from any bank to any bank works the same way. Identity from Aadhaar plugs into banking, welfare, telecom.
- Public-good architecture — The government provides the rails; the market builds the apps. This is fundamentally different from a closed platform like PayPal or WeChat Pay.
- Incremental trust — UPI started with low transaction limits and scaled up as confidence grew. Aadhaar phased in use cases from subsidy delivery to banking to e-KYC.
Who is on the Nilekani exam reform task force, and what is its mandate?
Prime Minister Narendra Modi announced the six-member high-powered task force on July 26, 2026, following the NEET UG 2026 paper leak scandal and the resignation of Education Minister Dharmendra Pradhan (New Indian Express, July 26, 2026). The mandate: recommend technology-driven and structural reforms for examinations conducted by the National Testing Agency (NTA), with particular focus on restoring trust.
| Member | Background | Expected role |
|---|---|---|
| Nandan Nilekani (chair) | Infosys co-founder, founding chairman of UIDAI | Technology architecture, DPI approach |
| S. Somanath | Former ISRO chairman (2022–2025) | High-reliability systems, risk management |
| Tapan Deka | Former Intelligence Bureau director (2022–2026) | Threat assessment, organized crime detection |
| V. Kamakoti | Director, IIT Madras | Computer-based testing feasibility, secure software |
| Anita Karwal | Former Union Education Secretary | Education administration, policy interface |
| Amrit Lal Meena | Former Bihar Chief Secretary (logistics) | Supply chain, centre operations coordination |
(NewsDrum; Dataquest, July 27, 2026; Gulf News)
The composition is deliberate: technology (Nilekani, Kamakoti), security (Deka), operations (Somanath, Meena), and policy (Karwal). As Dataquest noted, the panel's recommendations will matter only if authorities can implement common standards across testing agencies, educational institutions, vendors, and thousands of examination centres (Dataquest).
Why has the National Testing Agency kept failing despite existing technology?
The National Testing Agency (NTA) was established in 2017 as an autonomous body under the Ministry of Education. According to The Quint's RTI investigation, NTA has conducted 270+ examinations and handled 6.6 crore (66 million) candidate registrations since inception. In 2026 alone, it conducted 12 examinations involving 65+ lakh (6.5 million) registrations (The Quint, July 28, 2026).
But the institutional capacity is startlingly thin:
| Metric | Figure | Source |
|---|---|---|
| Sanctioned permanent posts | 39 | The Quint (RTI data) |
| Permanent staff vacancy rate | 38% | The Quint |
| Director-level vacancies (13 sanctioned) | ~70% (only 4 filled) | The Quint |
| Additional staff (temporary/contract) | 124 | The Quint |
| Revenue surplus (6 years) | ₹448 crore | parliamentary committee cited by The Quint |
The NTA's governing body met only twice in 30 months. A parliamentary committee headed by Congress MP Digvijay Singh had already flagged serious concerns and recommended sweeping reforms months before the NEET UG 2026 leak — but many recommendations were not implemented (India Today, May 12, 2026).
The fundamental issue: the agency has a surplus of ₹448 crore but hasn't used it to build internal capacity or strengthen vendor oversight. Technology alone can't fix an institutional vacuum — a problem familiar to anyone watching India's broader tech and AI jobs crisis, where structurally mismatched capacity meets structurally mismatched demand.
What exactly happened in the NEET paper leak scandals?
The NEET UG (National Eligibility-cum-Entrance Test for undergraduate medical admissions) has now been compromised twice in three years.
NEET 2024: The CBI investigation revealed that a man named Pankaj Kumar entered the strongroom at Oasis School in Hazaribagh at 8:02 AM on exam morning, broke through packaging with a toolkit, photographed the question paper, and resealed it with a lighter by 9:20 AM. The photos were sent to accomplices who solved them and shared answers to 155 "beneficiaries" across Hazaribagh and Patna. Some candidates memorized answers from photocopies and burnt the papers — but not fully. Bihar police traced the serial numbers on the burnt fragments back to Hazaribagh. The Supreme Court ultimately refused to cancel the exam, ruling the leak was not "systemic" enough to vitiate its integrity, but the episode exposed how fragile the physical paper chain was (India Today, July 24, 2024; Supreme Court Observer, July 23, 2024).
NEET UG 2026: Cancelled on May 12, 2026 after the Rajasthan Special Operations Group found a handwritten "guess paper" containing approximately 410 questions, of which around 120 (90 Biology + 30 Chemistry) allegedly matched the actual exam paper. The document was reportedly circulated via WhatsApp groups 42 hours before the exam. Approximately 22.79 lakh students who appeared across 551 cities were affected. A CBI probe was ordered (Procapitas, May 2026; India Today, May 12, 2026).
An investigation by The Indian Express found 41 paper leaks in India over five years, affecting approximately 14 million job seekers (Kashmir Observer, June 28, 2024).
Can DPI lessons from Aadhaar and UPI actually fix exam integrity?
This is the core question — and the honest answer is: partially, with significant caveats. Here's a structured comparison of what transfers and what doesn't:
What transfers from the DPI playbook
| DPI Lesson | How it applies to exam reform | Confidence |
|---|---|---|
| Encrypt-at-rest + decrypt-at-start | Papers encrypted until exam start time; no human touches plaintext before the exam | Confirmed (standard CBT practice) |
| Computer-Based Testing (CBT) eliminates the physical paper chain | No printing press, no transport, no strongroom break-ins — the attack vectors from 2024 and 2026 vanish | Confirmed (IIT, CAT, GATE already use CBT successfully) |
| Biometric authentication reduces impersonation | Aadhaar-style fingerprint/iris at exam centres prevents proxy candidates | Confirmed (UIDAI has the infrastructure) |
| Real-time audit trails | Every centre, every login, every paper access logged and monitored | Confirmed (standard practice in CBT systems) |
| AI anomaly detection | Flag suspicious answer patterns, performance clusters, or access log irregularities | Vendor claim (needs independent validation) |
| Multiple exam dates instead of one-shot | Reduces single-point-of-failure risk; takes pressure off one day | Reported (proposed by multiple commentators; under task force consideration) |
What does NOT transfer
| DPI Limitation | Why exams are different |
|---|---|
| Aadhaar excluded vulnerable people who couldn't authenticate | Exams must not exclude students without reliable internet, biometric devices, or CBT centres in remote areas |
| UPI created new fraud vectors (phishing, SIM-swap scams) | CBT introduces new risks: server outages, connectivity failures, software bugs, cybersecurity attacks |
| Trust was built incrementally — UPI started small and scaled | A one-shot exam for 22.79 lakh students can't "start small" — the first attempt must work flawlessly |
| DPI works when incentives are aligned | The incentive to leak a medical entrance exam is enormous (government vs. private medical college fees differ by tens of lakhs or even crores) — technology can't neutralize that financial gravity |
The Dataquest analysis frames it precisely: "The practical objective cannot be to create an examination system described as completely unhackable. It should instead make breaches harder to execute, easier to detect, and quicker to contain" (Dataquest, July 27, 2026).
What legal framework backs the technology push?
India enacted the Public Examinations (Prevention of Unfair Means) Act, 2024 — the first legislation specifically targeting paper leaks. It came into force on June 21, 2024 (Kashmir Observer). Under the original Act:
- Individuals using unfair means: 3–5 years imprisonment, fine up to ₹10 lakh
- Service providers / organized crime: minimum 5 years, maximum 10 years, fine of ₹1 crore
The Public Examinations (Prevention of Unfair Means) Amendment Bill, 2026, approved by the Union Cabinet, significantly strengthens penalties (Firstpost; ET Now):
| Penalty | Original Act (2024) | Amendment Bill (2026) |
|---|---|---|
| Minimum imprisonment | 3 years | 5 years |
| Maximum imprisonment | 5 years | 10 years |
| Maximum fine (individuals) | ₹10 lakh | ₹50 lakh |
| Service provider directors | ₹1 crore fine | Up to ₹5 crore fine, 5-year minimum jail |
| Investigation/trial | No time limit | Time-bound, fast-track courts |
| Special investigation | Not specified | Special Task Force (STF) for serious offences |
The amendment also introduces fast-track courts for examination-related offences, addressing the reality that without swift consequences, deterrence fails.
Is India's DPI approach becoming a global export?
Yes — and this matters for builders because it validates the model's replicability. Per the PIB report:
- India has signed DPI cooperation agreements with 24 countries for India Stack adoption
- UPI is now operational in 8 countries for cross-border payments
- MOSIP (Modular Open-Source Identity Platform), India's open-source identity framework, is being adopted or explored by 25+ nations for their national identity programmes
- India contributed the highest number of solutions to the Global DPI Repository established during its G20 Presidency
(PIB, March 2026; Atlantic Council, October 2024)
The Atlantic Council notes that India's DPI success is attributed to "its large population, technological expertise, low mobile data costs, and supportive political and economic conditions" — conditions that don't automatically transfer to every context (Atlantic Council).
What this means for you: lessons for anyone building trust-critical systems
Whether you're building an AI agent platform, a fintech product, or a governance tool, the DPI playbook and the exam reform case offer concrete takeaways:
Open rails beat closed platforms for trust. UPI's open API let a thousand apps compete on the same rails. The trust is in the infrastructure, not any single vendor. If you're building a platform, consider what layer should be open and shared vs. what's your competitive moat — the same strategic question that separates viable AI businesses from OpenAI competitors.
Design for incremental trust, not day-one perfection. UPI started with low limits and scaled up. Aadhaar phased in use cases. If you're launching a trust-critical product, start with safeguards and low stakes, then expand as confidence builds. A system that needs to be flawless on day one with 22.79 lakh users is a system designed to fail.
Technology eliminates vectors; it doesn't fix incentives. CBT eliminates printing-press leaks. It doesn't eliminate the ₹30–75 lakh that parents allegedly paid for leaked papers in 2024. If the financial incentive to cheat exceeds the cost of getting caught, no technology stack will close that gap. Make breaches harder, easier to detect, and quicker to contain — but also fix the incentive structure.
Audit trails are non-negotiable. The CBI cracked the 2024 case because it traced a unique serial number on a half-burnt paper. Digital systems should make that kind of forensics trivial — every access logged, every action attributable, every anomaly flagged in real time.
Watch for exclusion. Aadhaar's biggest failure was excluding the very people it was meant to help — those whose fingerprints were worn from manual labor, those without documentation. Any trust system you build must have fallback paths for edge cases, or you'll create new forms of exclusion in the name of security.
Institutional capacity is the bottleneck, not technology. The NTA had a ₹448 crore surplus and 38% permanent staff vacancy. The technology existed; the people and processes didn't. When you build for scale, invest in the operational layer — the people, the oversight, the accountability — not just the platform.
FAQ
Q: What is Digital Public Infrastructure (DPI)? A: DPI is a set of open, interoperable digital systems — such as identity, payments, and data exchange — built as public goods. India's DPI (the "India Stack") includes Aadhaar (identity), UPI (payments), DigiLocker (documents), and Account Aggregator (consent-based data sharing). The UN defines DPI as foundational systems that form the backbone of modern societies, enabling secure interaction between people, businesses, and governments.
Q: Who is on the Nilekani exam reform task force? A: The six-member task force announced July 26, 2026 includes Nandan Nilekani (chair, Infosys co-founder/UIDAI architect), S. Somanath (former ISRO chairman), Tapan Deka (former IB director), V. Kamakoti (IIT Madras director), Anita Karwal (former education secretary), and Amrit Lal Meena (former Bihar chief secretary, logistics expert). Their mandate is to recommend technology and structural reforms for NTA-conducted examinations.
Q: How many NEET paper leaks have happened? A: NEET UG has been compromised twice in three years — the 2024 exam (where the Supreme Court found a non-systemic leak at Hazaribagh/Patna affecting 155 students) and the 2026 exam (cancelled after a "guess paper" with ~120 matching questions was circulated via WhatsApp 42 hours before the exam, affecting ~22.79 lakh students). An Indian Express investigation found 41 paper leaks across Indian exams in five years, affecting ~14 million job seekers.
Q: Can computer-based testing (CBT) eliminate paper leaks? A: CBT eliminates the physical paper chain — printing, transport, strongroom storage — which was the attack vector in both the 2024 and 2026 NEET leaks. However, CBT introduces new risks: server outages, connectivity failures in remote areas, software vulnerabilities, and cybersecurity attacks. IIT, CAT, and GATE already use CBT successfully, but scaling to 22+ lakh students across 551 cities requires infrastructure and safeguards that don't yet exist uniformly.
Q: What penalties exist for exam paper leaks in India? A: The Public Examinations (Prevention of Unfair Means) Act, 2024 (in force since June 21, 2024) imposes 3–5 years jail and ₹10 lakh fine for individuals, and 5–10 years with ₹1 crore fine for service providers/organized crime. The 2026 Amendment Bill increases this to 5–10 years jail, ₹50 lakh fine for individuals, and up to ₹5 crore for service provider directors, plus fast-track courts and a Special Task Force for serious offences.
Q: What lessons from Aadhaar and UPI apply to exam reform? A: Key transferable lessons: encrypt-at-rest with decrypt-at-start, biometric authentication, real-time audit trails, AI-based anomaly detection, and multiple exam dates (reducing single-point-of-failure risk). Key non-transferable issues: Aadhaar's exclusion of vulnerable populations must not be repeated with students lacking reliable internet; UPI's incremental trust model doesn't work for a one-shot exam; and technology can't neutralize the enormous financial incentives (₹30–75 lakh allegedly paid for leaked papers) that drive exam fraud.

Discussion
0 comments