Privacy protection, for example, can be demonstrated through data minimization practices, regular third-party audits, and transparent consent mechanisms that allow individuals; especially those with low digital literacy, to meaningfully control how their data is used. Effective grievance redress systems that track and resolve privacy-related complaints also serve as critical accountability tools. Meaningful community participation can be assessed by the degree to which marginalized groups are represented in AI policy design and decisionmaking processes. Evidence that AI systems are advancing development rather than enabling surveillance can be seen in whether their outputs correlate with more equitable service delivery, improved welfare targeting, or reductions in bias across socioeconomic and demographic lines. Transparency and oversight are key: indicators such as the publication of model documentation, the frequency of fairness audits, and the existence of independent bodies empowered to review or halt deployments are essential to ensuring that AI supports development goals while respecting human rights. Mandate Privacy-by-Design in All Public Digital Infrastructure Governments must require that all digital systems, particularly those used in public service delivery, welfare targeting, or digital identification, embed privacy-by-design principles from the outset. This involves minimizing the collection of personal data, ensuring that only relevant information is gathered and retained for a limited period, and that systems are built with user consent, purpose limitation, and data security as default settings. Public digital platforms should incorporate transparent data governance policies, privacy impact assessments, and clear channels for grievance redress. By making privacy an architectural cornerstone rather than an afterthought, states can protect individuals from surveillance overreach and build long-term public trust in digital transformation initiatives. To note, this recommendation may face significant political economy challenges, particularly in contexts where state institutions may benefit from opaque data practices or where surveillance aligns with broader security or control agendas. Government compliance cannot be assumed, especially when data centralization serves political or bureaucratic interests. To shift incentives, compliance could be tied to funding or technical assistance from international development agencies, many of which now include digital safeguards in their governance frameworks. Oversight mechanisms should include independent data protection authorities with enforcement power, backed by legislation that mandates privacy impact assessments and routine audits for all new digital infrastructure projects. Civil society organizations (CSOs) can monitor implementation by engaging in technology assessments, 8

Select target paragraph3