Digital identity has reached a critical inflection point. After years of foundational work, global initiatives are moving from pilots and standards development to real-world deployment. The challenge now is no longer proving feasibility, but achieving scale, interoperability, and trust across borders, sectors, and regulatory environments.
Modern identity technologies provide the tools to address this shift. Open standards, conformance frameworks, and ecosystem accreditation enable consistent implementation while supporting innovation. When combined with strong governance models, these technologies can bridge public and private ecosystems and support high-assurance digital interactions.
Get ready for an insightful panel discussion moderated by Alejandro Leal, Senior Analyst at KuppingerCole Analysts. Alejandro will lead a thought-provoking conversation with four renowned experts: David Brossard (Axiomatics), Gerry Gebel (Strata Identity), Olaf Jonkers (itsme), and Eve Maler (Venn Factory). Together, they’ll dive into the latest trends, challenges, and opportunities shaping the future of digital identity, sharing practical strategies and visionary ideas to help organizations thrive in an increasingly connected world.
Hello everyone. My name is Alejandro Leal. I'm a Senior Analyst at KuppingerCole, and today I will be the moderator of this webinar.
So, we know that the title of the webinar is From Milestones to Momentum, Scaling Digital Identity and Trust Worldwide. As we know, over the past few years, we've seen digital identity move from carefully controlled pilots into mass market, cross-border, and large-scale deployments.
So, what once worked in limited environments is now facing an entirely different challenge. We see fraud at scale, social engineering, regulations, and the expectations of those regulations. And we also see how human behavior often does not follow the architectural assumptions.
So, in today's discussion, we want to explore what really changes when identity systems grow up, where standards help, where they fall short, and how concepts like identity assurance need to evolve, especially when trust becomes a societal dependency rather than just a technical feature. Here with me, I have a group of experts. They will be sharing their thoughts on today's topic. But the conversation is not going to end today. They will also be at EIC in Berlin in May, where we will continue to discuss more exciting things.
Now, if you guys could please introduce yourselves. Maybe we can start first with Eve, then with Olaf, then with Jerry, and then with David.
Well, thank you so much, Alejandro. It's a pleasure to be with you all. I'm Eve Mailer. I have a long history in data and identity standards, including XML and SAML and more. I was most recently CTO at ForgeRock, and I also led the identity interop strategy at Sun Microsystems. I was an analyst at Forrester.
And today, at Venn Factory, I help the tech world develop irresistible identity strategies. To that end, I'm coming out with a new book called Mastering Digital Identity, about which more, I'm sure, in the conversation. Thanks. Okay. I'll take over. Good afternoon, everybody. Good afternoon or good morning depends on which time zone you're in. My name is Olaf Junkers. I'm the head of risk and compliance at It's Me. It's Me is, to some of you, known as the Belgian electronic identification means since eight years now. Eight years?
Yeah, eight years. Time flies. And with that, we have, let's say, a role to play as a societal means of getting access to your applications, whether it is government, whether it is your banking app, insurance, telco. So our usage of It's Me is now something like 8 million users on an almost daily basis within Belgium. We are EIDAS high. So that's our reference, if you want. We are also a QTSP.
And my personal background actually comes back from 25 years in identity, starting in upsets like UTMaco at the time, a German company, but also being with Certipost, which is the company after or behind the electronic identity card in Belgium at the time. So that's me. Looking forward to the discussion. All right.
Thanks, Olaf. Jerry Gable. Spent a minute or two in identity and other areas as a practitioner, as an analyst, into the software world with David over at Axiomatics for a while. Most recently retired from Strata Identity as head of product and standards, and also recently retired as co-chair, along with David and others, of the AuthZen Group. So happy to be here with you all today.
And, David, over to you. Thanks, David, CTO at Axiomatics. Excuse me.
Wow, what a start. CTO at Axiomatics. I'm battling a cold. It's minus 10 degrees Celsius out here in Sweden. And my latest business trip was in Helsinki yesterday, and it was minus 15. So it's kind of weird when you go home to a warmer place and it's still below zero. Like Jerry said, he and I worked together. He taught me quite a few things. I still have a lot to learn from Jerry and Eve and Olaf. Just happy to be here. Spent my entire career in identity and authorization more specifically. I've suffered through standards, and I've helped design some standards, including lately AuthZen.
Awesome. Well, thank you so much. It's really an honor to share the stage with you. And maybe the first theme of today's discussion will be around the idea of going from pilots to more widespread adoption. Digital identity has clearly moved beyond experimentation. So from your perspective, and maybe we can start first with Eve, what fundamentally changes when identity solutions move from pilots into mass adoption?
Yeah, great question. I'm going to answer sort of in two parts. In one case you have in the enterprise where you're piloting a program, and what happens when you go to full production is edge cases become surprises. So if you think of the things that you thought to test as being sparse elements of a matrix, well, the whole matrix gets filled out. Every combination gets explored by people that you're not entirely in control of, by software that you didn't understand the implications of. And you find gaps.
So they could be security gaps, they could be user experience gaps, and they can run from the small, like, hey, you were reporting small amounts of data, and now you have to start paging results because there's so many of them, to the very large where you're refining your metrics over time, but oops, you forgot to instrument the telemetry to gather enough data to assess those metrics. So that's one thing I'd call out. Another thing, in different circumstances, in the implementation of a standard. This is much more subtle and difficult because we can be enthusiastic about a standard.
A standard requires multiple parties to change their behavior. It's one of the toughest things you can do. So what I find often is that multi-sided business models kind of just go missing. It's really hard to think through the implications.
In fact, that might be one of those unknown unknowns until you sort of meet the market. And I like to think in terms of product market fit, even for standards, it's very hard. So I'll stop there. I can bounce back on that, Eve. I agree. A lot of what I've seen, a lot of architects or, you know, stakeholders, when they want to implement a solution, not specific to digital identity, by the way, they think that sometimes the standard is the silver bullet. They'll pick it up.
I remember reading that Bruce Schneier wrote he regretted writing applied cryptography because people started picking up the crypto standards and thinking, oh, well, now that I encrypt with X, then I'm safe. Well, actually, no, there's a lot of process around how you use the standard to actually make good use of it. And that applies to SAML, OpenID Connect, and the digital identity standards, right? It's not just a technology issue or a standard issue. It's also a human issue of how you implement those standards to make sure you do it the right way and in an efficient way.
What comes to mind to me when you're moving from a pilot or experiment into production and scale is production support. You know, have you really designed the implementation for scale and for problem determination?
Eve, you mentioned telemetry and so on. Can I figure out what's going wrong in those edge cases and do it quickly? Because now I'm part of a business process. And so I've got to be aware of that and cognizant of that. And I think that's maybe an issue where we have to put extra focus is, you know, can I scale that out to the enterprise size that I need? Can the system perform and can I support it? Because that's a super important aspect of the solution. I'm bringing a dimension here, which is not the enterprise dimension, but which is, let's say, the nationwide dimension.
If you're focusing on a consumer to different businesses interaction where you have a public, you have an audience which is attractive, not only for your relying parties, which they find interesting, I can source into 2 million, 3 million, 4 million possible users or customers. This is also becoming a very attractive, let's say, source of victims for fraudsters. So you see a lot of those use cases, which you didn't anticipate. And then linking into what Eve said, you didn't foresee these kind of usages.
Actually, you didn't know that your system was capable of doing it this way. And you have to be prepared to address those challenges, which are very dynamic. You counter a certain mitigation or you build in a certain mitigation. You counter a certain modus operandi of a fraudster. They will change. They will change very rapidly. And they will keep doing things that you didn't expect. And you have to be prepared. You have to be agile in that sense that you can react and correspond to those fraud cases. It's a scale issue.
We didn't see, starting off with It's Me, we didn't see any fraud whatsoever. And we have banks in that system already since the beginning. But we didn't see any fraud up to a certain level where we said, okay, now we start having this critical loss. That's where it happened.
You know, David, you talked about the assumptions behind implementing standards and how as new use cases arise and new challenges emerge, then those assumptions are no longer the same. Are there any other, let's say, architectural or governance assumptions that as systems scale are no longer the same? I'm thinking of two things. First of all, we, the standards community, we realize that defining the standard alone is not enough. So I'm thinking of, say, OAuth 2.1 that includes BCP's best current practices.
Essentially saying, look, there's OAuth, but the way you use OAuth might make it secure or not so secure, right? So look at the best practices and make sure you implement. And then a more recent example is IPSE, of course. IPSE says there's a lot of identity standards. How do we combine them to deliver X, to deliver Y? And then perhaps closer to home, me as a regular citizen, I'm amazed by how digital identity for workforce is so different from digital identity for the consumer and is different from digital identity for the citizen, right?
Olaf, I would love to spend more time with you and talk about what happened in Belgium. Because, you know, if I get locked out of my work account, I could just go find the admin. I can physically go find an admin and they can reinstate me. If I get locked out of my H&M account or my movie theater account, no biggie. It's annoying, but no biggie. If I get locked out of my Belgian citizen account, like, oh, my God, what am I going to do, right?
So Alejandro, to your point, like, you have to think about all these processes that change depending on the constituent, depending on the backup, depending also on the digital literacy. Like, are you dealing with – all of us, we know how to use email. We know how to use, you know, digital authentication systems. But my grandmother, my parents, my five-year-old, how do they, you know, how do they live in a world of digital identity? How do they interact with such a system knowing very well that this will become, let's say, reality for them in their lifetime?
Just to give you an example, we did the study on that to see, okay, which are the ones that are the most literate as age groups and which ones are less literate. And to a surprise, elderly are quite literate. They are quite well-driven for doing, for example, searching their pension.
Jerry, no offense, but I guess you would be searching for that soon. Revenge of the elderly.
But also, there's a very large group of people, younger people, that actually know very well how to use their smartphone for everything, which is social networks for the kind of TikToks and Messenger and what you have there. But if you take a look at using public services like going to tax administration, et cetera, they are illiterate.
Actually, they don't know how to start using these. So, it was very interesting for us to see that we have to educate those younger people, actually, for starting using formal and official applications on their same smartphone that they have been using already for years, but in another context.
You know, social media companies measure how well they're doing by daily active users, right? So, if you're daily or maybe even monthly, you've got a facility with some service that you wouldn't have if it's only yearly or less often. And it's one of those things that we sort of forget about.
So, that's kind of like an individual viewpoint on a scale problem. There are other kind of population-level scale problems that some of them we can predict.
Like, everybody sort of knows about the retailer Black Friday kind of, you know, holiday timeframe surge or, you know, certain other things where you can predict when it's going to come. Or, like, pay-per-view where you're streaming media and everybody has to log in all at once. Then there's cases we didn't anticipate. And I found one really interesting case study when I was doing research for my book. In COVID timeframe, certain things stopped happening, not that we really, you know, planned that to stop happening, but so I was talking with a company that's in hospitality.
And they had some automated systems to check for, well, at a certain age of not having logged in, they would do some password reset notifications. Well, come to sort of the end of COVID, and apparently the system decided to send 9 million password reset notifications all at once.
So, this is the kind of thing, okay, we didn't plan for it, it happened. Ultimately, what this company discovered was all the problems were mostly from those less explored paths through all the user journeys, right?
So, they were getting exercised in a way that was unpleasant for people. They were able to correct those and benefit everybody all at once.
So, it wasn't just around password resets. Hopefully, they're rooting out the need for password resets, so that would be nice. But these are the kinds of things where you just have to experience life and take the lessons from them.
So, I've got a real life example from that happened to me back in December. My phone died, and I'm in Sweden, and everything is pretty much digital.
And so, your digital identity is issued by your bank. And for whatever reason, I was really, really worried I was going to need to prove digitally who I was for, I don't know, preschool, whatever it may be.
So, I really wanted to get my digital identity figured out again. And so, I don't have a phone, I decide to walk to a local bank branch. And I get there, and it's closed. It's closed because you can only enter if you have an appointment. To have an appointment, you need to call.
Well, I can't call. So, that's point number one is out.
So, point number two, if you have a Swedish passport, you can actually self-serve your digital identity. There's an NFC chip, you can read it.
So, I have a tablet, I'm like, I'll just put my digital identity on the tablet, I'm good to go. But it needs an NFC reader, which my tablet, my older tablet, didn't have.
So, I was out of that system. Eventually, like the next day or the day after, I got a new phone, and I was able to self-serve. But it showed that, like, within one or two days, had I had something super urgent to sign, I was sort of stuck. Two things that I want to hook into here, David. Exactly. This is one of the things that I think needs special attention going forward with anything, which is the European identity wallets and the European identity ecosystem that we're setting up currently. There's a lot of drive in there currently.
We will see a lot of things happening, which is good, which is very required, needed. But I don't think that we're following through on what is actually needed there. And I heard, not so long ago, I heard an official say, it's like you have with your ID card currently. You don't mind if you're two or three weeks out of an ID card. You have to wait for it anyway. This is not going well with digital life as we know it. You want to be served. You have to be able to get to that application that you need, not within weeks, not within days. But you might need it in the next five minutes.
And that's the kind of lifecycle management, which is often not well thought through. And I'm afraid that this also lives in the heads of some people that actually are in the steering house of what is going to be set up. It's not the life experience, which is living, I'm afraid, on that level yet. Those are the lessons we still have to go through and learn along the way.
Yeah, and I think, Olaf, what's happening is that if I had to go pick mail up from a local drop-off point 10 years ago, maybe through a bit of convincing, they would have let me pick it up. But today, if you don't have the digital ID, or in that case, you could also use your physical ID. But if you're out of luck, there is no – and it's for a good reason, right? So avoid frauds. It's for a good reason. But it can be very frustrating at times when you are really who you say you are, and you can't do what it is you need to do.
Yeah, correct. And it's life. It's life as we know it. Your mobile phone, it will die off. You will change your mobile phone at a certain moment. You will lose it. People might steal your mobile phone. So you might forget your PIN.
I mean, this is real life. Those are the life cycle stages that you have to be prepared for, that you cannot, let's say, at that moment, start making an appointment with a public official and go to the city hall and try to reactivate it on your mobile phone.
One, it's not scalable. Two, these people are not equipped to do that for you. So this has to be a process which is living completely.
One, online. Two, mobile only. So you have to have a mobile only experience. That's what we learned through the years of having this online. Switching gears a little bit, there's a question from the audience, and I'd like to maybe incentivize some of the audience members to ask questions. The question is, how long will we depend on passwords online with usernames? Big tech passkeys don't solve interoperability or really serve the account holder in the journey to self-custodial ID wallets.
Eve, you were talking earlier about passwords, and given your experience at ForgeRock, maybe you can take this. You know, I've long held this belief that static shared secrets are like cockroaches.
Like, they will survive the apocalypse. They're too useful for syncing deliberately and benevolently between people. So you're saying New York is the city of passwords? That's what I heard, Eve. I don't know about that. I will say, I think, if and when, there are cases where we're starting to actually root out passwords entirely.
And, you know, I've been a skeptic about the whole kill the password thing, because, like, I don't think killing static shared secrets is something that's possible. We'll still have pins on phones for a long time. And the second that we eliminate it from a pathway entirely, there will be lessons that we will learn painfully about the affordances of passwords. So I've been long sort of yelling about the need to solve delegation, because that's how we're letting people we know and trust impersonate us. And that's not a great solution.
It would be better if I could do the least privilege with their access versus ours. But password sharing is what is getting us by. In a preparation call, we were talking a little bit about death in the digital estate, you know, the work that the Dade Group has been doing.
You know, in times of real distress, somebody passes away, and what you've got is their phone. You're going to need access to it. And there are certain things you're going to need to do with it that are probably against the terms of service. So realistically, I think that it's going to be a backup for a long time. I still think that getting to a passwordless experience, even when there's a backup of a static shared secret, it's better than the alternative of not, you know, of still putting passwords on the wire all the time.
So I do think we're on a journey to get to this place of better control, but it is going to depend on certain things we haven't. We in the industry have been working on these things, but they haven't been thoroughly thought through in the case of real deployed systems. And even another thing at the forefront right now is agentic AI. Now we're delegating actions to agents.
You know, how do we do that in a controlled manner? But back to passwords for a moment. I think there is some beauty in passwords in that they're very transparent in a way that you know where you use them and what do you use them for. Whereas if you're using, you know, delegated sign-on or social sign-on, do you really have visibility into that whole web of what my identity is connected to?
You know, it's not as obvious to me as a user. Whereas if I have passwords for all these 10 places that I go, I know I use each password separately for each of those entities and it's transparent to me. That's what I mean. So I think there's a lot of value in that. And maybe that's what you were alluding to a little bit, Eve. There's a recent exploit. I was actually a victim of this email compromise, phishing email scam thing where it's sort of hidden behind. They're not getting your primary credentials.
What they're doing is they're tricking you into getting an access token by logging into something legitimate from a client that appears legitimate but isn't. And not only was that confusing and you lose the thread. Like if you're trying to pull on a little thread on the ground, it goes under some branches and it goes over some other things. And it's hard to know at the end of the day who's connected to whom. Loose coupling is fraught. It's a great solution for some things, but it is fraught for the user experience. And so by the way, rotating your password does not fix that problem.
MFA, which I had, does not fix that problem. It's all about the token and the session. So these are things that we're starting to unpack. And like I can ask any non-technical person now who at least has a phone, you know, do you know what pass keys are? And they're like, oh, yeah, you know, I just accepted a passkey from whatever my local retailer. But untangling all of the Federation stuff, we've got a lot of work to do.
At scale, that is causing confusion and fraud. And maybe we need to teach people how the system works, which I regret. I would regret that if we have to do that. Yeah. And I kind of agree with everything that has been said. Passwords are still there and getting fully rid of them, I'm afraid, will take still some time. But picking on one of the questions from Jim here in the conversation, it's linking to that, right? Identification, authentication is at least what we focus on. We do not focus deliberately on authorization.
In the context that you're dealing with, you might be anonymous, but an 18 year plus person, or you might be the CEO of XYZ, or you might just be a member of the public inquiring about his tax status. This authorization, this context building is the application or the service provider, the consumer of this identity. And I think with the password sharing, for example, what you're actually doing is you're authorizing somebody else to do stuff on behalf of you. And this is where, for example, enterprise identity management systems come into play.
But also where we have to see with governments, for example, also that they set out the correct authorization systems. What we often see, getting back to fraud, is that people are or might get the victim to a certain fraud scenario. At a certain moment, you can escalate this and you can block an account or you can block a transaction. But actually what you should be doing is you source this out to a relative. You ask a trust person to watch for this person. What are you actually doing? Can I help you?
And it's a very interesting concept that has been launched by a local bank here, one of the bigger banks in Belgium, to have a guardian angel. So basically you're in your mobile app, you're doing banking transactions, you're not aware that you're being phished or socially engineered, but the bank suspects you are being socially engineered. They get a lot of noise on this. So what they do is they actually reach out to your guardian angel like, this person is doing stuff and can you help him out? Because we think that he's being socially engineered.
So the crowdsourcing of this kind of information would be one of the solutions of getting this resolved. I love that so hard. I actually have a chapter in my book about relationship management and crowdsourcing being the biggest trick that we're missing through vouching, through other protections, through key sharding. There's a lot of great things that we can do that make it very tough for a deepfake, for example, to get through once you're done with all of that. One of the biggest protections we can have is not do it alone.
Yeah, and it opens up a whole lot of opportunities as well, right? One example that actually exists is that when you get Amazon Prime in the US, you can share that with your family, right? So one person pays the $10 a month or whatever it may be, and then your spouse or your kids or whoever you have in your Amazon account can actually benefit from Prime shipping and all that stuff. In some countries in Europe, it's not the case. And so what do you do then?
Well, you share your password. So now that other person is impersonating you when maybe they're going to buy a $500 item that you didn't want to buy, or maybe it's Christmas, they're going to buy something for you. It's supposed to be a surprise, and of course, you get the email that they bought the gift for you.
And then, you know, Olaf, you mentioned, so it's authorization, access, delegation, and consent, right? These are all authorization-related aspects. So if you were to say, I want to delegate to my kid the ability to spend money, say $10 a month, this is the new digital allowance, pocket money. And they could buy anything on Amazon, but it's got to be, I don't know if there's such a thing as PG-13 ratings for regular products, but let's assume it's, you know, child-friendly products, right? And maybe you don't want them to buy a product made in wherever, right?
But it would be kind of nice if you could put these guardrails. There's different sectors, there's healthcare, there's banking, there's many other aspects where we could build really cool services and actually generate business and deliver better customer-slash-citizen service if we had these ideas of, concepts of delegation, consent, and so on.
And Jared, you mentioned agents, you know, meaning AI agents. Like, the notion of delegating to an agent is, it used to not be about AI.
You know, we have agents, we have real estate agents, we have legal agents for us. The AI use case is a subset, absolutely a subset, of all the things that humans need in human-to-human interactions. So we need to solve it anyway, and maybe this is the push we need. That's right. But the discussion about the guardian angel and crowdsourcing makes me think, from a banking perspective, at least here in the U.S., the know-your-customer regulations. So now the bank has to know that they're crowdsourcing sources. So it's a bit more complexity on the provider side there as well.
And by the way, IAM systems do not really have any of this concept of relationships between identities baked in. Like, remember when Netflix struggled with the whole, they encouraged password sharing, and then they realized that it was impacting their profits, and they started doing something about it, and they got clever. They started using user-managed access because I've been doing it for so long, and we delved into those access delegation use cases for so long. We got a pile of them. So solving it in some kind of more regularized way would be really healthy, I think, for all the IAM.
And Eve, to build on that, so Netflix has this feature now where you can pay for a separate account, but it's slightly cheaper than a whole new account. If you want to pay for a separate account, meaning you're not going to see what the people are watching, and they can be anywhere in the world, it's maybe seven bucks. It's a little cheaper because it belongs to the greater family, right? So they're building proprietary features in Netflix.
Google have this thing, it's called the account inactivity feature, where if you don't log into your account, then your guardian angel, effectively, gets an email saying, oh, it's been three months. Let's go back to the work that data is doing. So maybe data could normalize that pattern and then go to Google and Yahoo and you name it, and say, this is how you could implement these recovery processes, these guardian angel processes, so on and so forth, because they are definitely needed, absolutely needed. So we've been talking a lot about trust.
You guys already mentioned this a couple of times. And it's such an abstract question. How should identity assurance evolve when trust is becoming this sort of societal dependency rather than a technical feature? David?
Yeah, I want to share a personal experience that Olaf, you reminded me of. You mentioned EUIDAS, right? I'm looking forward to a world where whatever identity I've established somewhere can be shared somewhere else. So within the EU, of course. I would love to be able to go to Belgium and suddenly get an it's me identity within minutes, because I'm saying that I've moved to Belgium and because Belgium trusts the Swedish government, they know who I am. That's point number one. But another example, I moved to the States about 15 years ago or 10 years ago.
And I had to get, of course, I was in Chicago, I had to get an electricity account set up. So they use a company called ComEd over there. And because I had no history, no credit history, I had to go to a Western Union store with my passport, with some kind of bank account statement manually. And not just any Western Union store, that particular one from that particular neighborhood that I have to go to show paper that, by the way, could be falsified. And even if they're not falsified, the teller on the other end perhaps has some sort of training.
But come on, let's face it, do they know how to recognize a fake bank statement or a fake passport? I very much doubt it. Just to say, look, I have lights in my living room. So I really want a system where you can transfer trust from one place to another.
David, it sounds like bring your own identity, which you wrote about, I don't know, 2007-ish or so? No, user-centric identity started real early, like 2000, basically 2000.
Yeah, yeah. So those concepts have been there for a long, long time. And I think there's still a lot of these boundaries, whether they're nation-state boundaries or just commerce boundaries that still exist, walled gardens and so on. So I think we're going to be talking about this for quite some time yet.
Well, there is some hope there. There's light at the end of the tunnel if you want. In that sense, the EU actually has this array in place for since, I think, first EIDAS was 2000, help me out, 2016, 2014, 2014 it was. So basically identity, electronic identity was standardized. And that's where we actually took off. It's based on national identity documents and in such a way that indeed this, to a very high level of assurance, you can rely on this identity.
You do not have to forward your main birth date in all use cases, but in some use cases, say KYC for a bank, yes, they do want to know where you live. They have to know that this is a legal obligation for banks. So basically that identity, that root of trust that you source into is the national authorities issuing, if you want, your identity reference.
So that's the hook-on that we from EIDAS have learned to let's say facilitate also in that digital realm because those physical identity cards, those passports, it's not really stuff that you can just transpose into a digital identity, but you can. So basically EIDAS now has an amendment. You get a wallet, a digital wallet. These are the kind of things that enable this kind of cross-border recognition, at least in Europe. I'm not talking about the US yet, but at least in Europe, the EIDAS amendment was intentionally set up to enable this kind of cross-border use cases.
You are a Swedish citizen. You want to consume electronic services throughout the European landscape. Whether it be public service, whether it be a private company, you should be able to use your wallet. And it's actually made mandatory for certain sectors where strong user authentication is indeed already required by contract or by law. There's an elephant in this room. So while we're talking about individually identifiable people through systems that do that for a living, over here we have surveillance, widespread surveillance.
I don't know if anybody's seen this new movie that came out, Mercy, with the L.A. cop in a near future L.A. that is just completely riotous. And in order to handle the caseloads, they have an A.I. court with an A.I.
judge, and they get access to everything. And the whole movie is done in this kind of moment-by-moment, you know, 90-minute countdown clock. I thought it was a good movie. Also terrifying. And the amount of exhaust data that we're all exuding is so great that this is readily available. So if you really want high assurance, sure, just, you know, open the kimono and let everything you do be visible and lose any sense of privacy, anything that happens behind a curtain.
No, it all happens out there for authorities to see, for others to see. We're practically there. So it's one thing that it's hard for, I think, identitarians to grapple with because we want to be the great custodians of not just security, but privacy. And we don't control all those levers. And I think it's good to keep that in mind and see what we can do to affect the way that looks. It's very interesting, Eve.
I think that, given the fact that there's a lot of talk right now, here in Europe at least, about identity, do you think there's a clash for us identity people when it comes to where the future is going in terms of standards or where the European companies are heading? Well, if you're asking me, I'll say briefly. I know everybody will want to weigh in. So last night, I finally read through the Utah state endorsed digital identity law that's coming in. And it's very interesting. I've long been a skeptic about decentralized identity fixing things because it's a new technology.
What they're doing with this SETI thing is it's kind of got like a user constitution in it. It's got a bill of rights, if you will. And they're trying very, very hard to lock down the usage of this very powerful technology, user-centric though it may be, to merely the purposes just needed.
I think, you know, the proof of the pudding will be in the eating. But it's a way to start to at least create transparency so that you can assess whether it works. I think any also any notion of digital sovereignty, Alejandro, runs across the collision of commercial interests versus individual interests versus state interests. And I think that's just going to be a continuing elastic moving area here for years to come.
I mean, we've been dealing with different, even different privacy regimes across the globe for years now. That's nothing new for identity practitioners to be managing. So I think the digital sovereignty or however that evolves, I think it's just going to be another aspect of it that we're going to have to deal with going forward.
Yeah, to build on weighing in on the discussion, I had recently, very recently, had discussions with multiple of my, let's say, could be competition even, but the colleagues in the industry. And this is a topic in Europe. And a lot of people actually are looking at, OK, this is something we have been used to be challenged on. You remember probably Max Schrems at the time contesting the EU, US data adequacy and the data exchange on personal data. Max Schrems did it twice, by the way. I was waiting for the third one to come to come by. But this is this is getting a very new dimension.
Actually, a lot of dynamics here. So we will see. And I actually spoke this morning to one of the member states supervisory authorities, and they explicitly mentioned that this will get attention in accrediting these kind of players in an identity realm. They want to have the certainty enforced upon the people. Not to mention that, for example, in Holland, you had you have the ID, which is which is their digital identity. It's being run on cloud services by Solvenity. And Solvenity was in the in the midst of being bought by a subsidiary of IBM.
This has caused part of the world to be Parliamentary questions in the politics of of Holland. And they are taking action on this now. So it is quite well a dynamics and it gets real attention on political as well as administrative. Are you going to say something, David?
Yeah, I'm sorry. I've got someone crushing the webinar here, but I was going to say, you know, part of your question was whether the standards folks were crushing. I don't know that we're crushing. I think we're trying to build all the standards.
And then, of course, we're we're trying to figure out how they can be best used. And we have to think about concerns like privacy protection, of course, side effects of using a centralized identity.
Jerry, earlier you were saying that if you use social logging or federated logging, you no longer know what website you you use it at. Another side effect is that Google knows that I'm using Airbnb, for instance. They know when I log into Airbnb. So there's lots of things that we need to fix. I do sort of think that this is going to sound bad, but I think that like the private sector is going to help us move forward because they have a much bigger incentive.
It's a commercial incentive to to move forward, whereas governments, they they do it for the right honorable reasons, hopefully of privacy preservation. Some governments, of course, do it for the wrong reason of spying on their constituents. But I think private sector will help. Dan was asking in the chat, why aren't banks working more on identity? I think that in some places like Denmark and Sweden and maybe Benelux, the banks have played a great part in enabling digital identity. They didn't do it to be nice.
They did it because it was cheaper for them to run identity verification and also avoid fraud. I'd love to see the numbers on bank fraud in the U.S. compared to the Nordics. I haven't seen them, but I would hope or guess that there's less fraud in the Nordics with the banks. And if there is, then there is in the U.S. with the username and password.
Yeah, and Alejandro, to your regulation. Oh, thanks.
You know, thinking about, you know, our standard, our standards helping. And I don't think we can say standards in the aggregate are helping or hurting. As I mentioned earlier, I think standards are a kind of a product. And so the purpose of a standard from the perspective of a business is not to do something very scary. It's to strategically commoditize some functionality so that they can build larger volumes of value on top. So that means opening that up to competitors as well. So it's kind of like an act of faith every time a standard gets done.
AuthZen is a great example of where, you know, there was a very careful assessment taken of who needs to adopt this for this to actually cross that chasm. There's a Ross Haliluk, who writes under strategy of security, has this great analysis between industry problems versus business problems. And sometimes the startup will poke at something and it's actually an industry problem, meaning it's sort of for the good of humankind when it should be.
You know, you need to figure out what the business problem is. And that's why banks, I think, are sometimes slow. They don't see identity data. They don't see identity accounts being as valuable as bank accounts yet. Maybe they haven't figured out it would basically be a new line of business for them to really go wholesale into something bigger. But they've also been very helpful in terms of, you know, working like all the payment systems that retailers have now incorporated have become less fraud filled because they're riding on the back of the card issuers and the payment methods.
And the banks and we could see that in the numbers, which is good. Well, actually, and that's where banks already use identity, but for them, this is the card. Right. With the card, they know their funds behind this. So we are risk coverage in these transactions. But what they what they start realizing is that the card itself is actually just a means of transposing that identity into the card that they issued to that to that same person. And I want to try to strike a balance with what we in Europe actually try to do a bit more, a bit more than, for example, our U.S. counterparts. We regulate.
There is there's European regulation. There are lines that we draw like, OK, you can do this, but you cannot do this. And it helps start standardization, by the way. So. So basically, if you have something like the wallet behind that, there will be standards behind that. There will be some standardization on technical implementation, but also the regulation itself gives a means to industries to say, if I use this instrument, this instrument is regulated and it's being controlled on a national level and on a European level. And why not later on on a global level?
This this follows certain rules and I can ensure certain reliance on this kind of infrastructure. It's trying to strike a balance. GDPR or cookies. We all know the cookies. We all hate them. Try to click away the cookie banner. Those are the kind of things that we earned as a consumer. It protects us to a certain extent, but we're also a bit annoyed with, let's say, the fallout of these. So trying to strike that balance in that regulation is something that helps us and I think is the way forward of protecting the consumers actually with their personal data, with their identities.
We now have only 10 minutes left. So before we talk about EIC, maybe you guys can give me your main takeaway. What would be the main thing that you would like the audience to know? Maybe we can start first with Eve, then Olaf, Jerry and David. So maybe a main takeaway for me is we need to enable. I'm going to use the word generativity, which before we started talking about Gen AI meant unanticipated reuse of our systems.
You know, we talk about identity fabrics being important, hooking up of disparate systems being important. It's especially important in the AI era.
In 2011, this guy named Steve Yegi wrote a famous rant called the Platform Rant, where he had the experience of working for Google and then for Amazon and observed the differences. And what he liked about what Amazon did was enforce this rule. All service interfaces without exception must be designed from the ground up to be externalizable. Once you do that, you can start building systems at much higher scale with much greater visibility and control. So it sounds like you're going to have to compromise on one of those things, but you need not.
So if we're looking for things that scale, if we're looking for systems that scale, and if we're looking for the kind of transparency that we need to check to see if they're scaling, that's the way that I would go. Thank you. Not sure if I can summarize everything that we talked about in just two sentences, but I think the consensus here is that scale needs another approach than just following, let's say, what we are used to do before. It's something that needs the interaction of the user itself. You have to anticipate users doing stupid stuff.
And you have to be prepared to mitigate this and to react on it. And I think in some of the systems that we're talking about, and especially the enterprise identity business has discovered already, I think they are doing a tremendous job in protecting the enterprise assets because they know their audience, they know where it comes from, and they can anticipate at least some deviant behavior. But I don't think that we are prepared already for doing that in that scale of the consumer or the government-like scale of doing this for the whole of the community of the country.
And that's the concern that I have. I will be addressing that on EIC, actually.
Yeah, I think a good takeaway to consider is that every organization needs a significant experimenting lab or testing capability. You know, we've talked about some new technologies, talked about some older ones like passwords.
You know, now we have Engentic, AI, MCP. We have all of them, right? We have new standards. So the world will continue to change. I think it's changing more rapidly now than it has in the past. So I think having the capability to do those experiments, those pilots, and really understand how the technology is going to be useful or not so useful for different use cases, for different business scenarios, you know, and just being able to understand it better as you move forward because, you know, you can't you can't just rely on past identity systems.
You know, they were built for a previous era. You know, the ways are changing now. So we need to continue experiment and test out these new capabilities, these new standards, because they are all building blocks and how you assemble them is going to be different than, you know, even peers in your own industry do that for their own use cases. So I think that's a really important takeaway in my view.
Yeah, I'm hopeful. I'm hopeful we're going to get to a place where technology and standards, of course, get us an even better world where, you know, we share data for the greater good. This might sound very naive, but for instance, if all the health data, all the analytics of every single person who's had say cancer treatment around the world were shared in a single pool, maybe research would go that much faster. Right.
So I think we need to build standards and utilize and implement standards with good intent, all the while not being overly gullible and putting guardrails so that it doesn't get abused. You know, a private sector abuse would be insurance companies using that to charge you more money, for instance, without your consent. Or it could be bad guys outright stealing your data for whatever reason it may be. But I'm hopeful. I really want to see a world where there are no borders, at least no digital borders where you are recognized as a citizen of X and you move to another country.
They acknowledge that identity. You get set up more quickly. You go to doctors in Chicago and then you go to doctors in Belgium and they know your history within with consent, of course, and you get better treatment and others get better treatment out of it.
So, yeah, I'm hopeful. On that positive note, I'd like to thank you guys for your insightful conversation. I had nine questions for this webinar. I only managed to ask you two questions. So that's a good sign. Just maybe the last thing to talk about EIC. Looking ahead to IC, I'm going to be there. I'll be doing a presentation on PAM on the current market. And I'm looking forward to meeting you in person.
Maybe, Olaf, you said that you were going to do a keynote. Wrong button. Sorry.
Yes, I was. Indeed, I'm doing a keynote. I will be addressing sorry for that, guys. I will be addressing how to do indeed fraud mitigations on scale, the kind of modus operandi that we see, what our force is trying to do and how can you indeed counter that. So a very interesting experience that we live through and I want to share this with the audience. How about you, Eva?
Yeah, well, Max Trem's got to mention earlier and I'm a big Max Trem's fangirl. So I'm excited to say that I'll get to be on a panel with Max and with Martin Kupinger, a panel called Consent's Journey from Annoying to Meaningful. So pretty sure everybody will be really interested in the outcome of that. And I'll also get to be on the main stage talking about the behind mastering digital identity from revenue. And if it is curious about the book, which is still not out, but it's going to be out real soon, just go to mastering digital identity dot com. Can't wait for EIC. Awesome.
I look forward to that one. How about you, Jerry? So this year I will not be at EIC unless Martin or somebody puts me on the agenda at the last minute, which has happened before. But I'll be missing you all. But watching from afar. We're going to lobby that, Jerry. I want to talk to Martin and say we need Jerry. All right.
Yes, I will be there. I will be speaking on behalf of OpenID about of Zen.
You know, would you have it? I'm excited to be there.
Also, Cooper and Nicole have been very supportive of OpenID and of Zen. And every year for the past two or three years, at least, we've been getting a room. So open to the public, but it could also be used by the working groups. So we can hash out new profiles, you know, do things face to face that work better than just a virtual call every week. Right. So we're really thankful for that. And if anyone wants to learn more about Zen, it really is the place to go. We've gotten rid of the old people that were, you know, co-chairs. We've got fresh faces now. So we're good.
Good luck with that, David. Well, right on time. Thank you so much and have a great day and see you in Berlin. Thank you.
See All Locations
See All Locations