Early-bird Discount
expires in
Register Now

Blog

Trust Frameworks at Scale: Building Bridges Across Borders

Blog Post

Trust Frameworks at Scale: Building Bridges Across Borders

Alejandro Leal
Feb 24, 2026

In last week's Road to EIC webinar, From Milestones to Momentum: Scaling Digital Identity and Trust Worldwide, we brought together five speakers: Eve Maler (Venn Factory), David Brossard (Axiomatics), Gerry Gebel (Strata Identity), Olaf Jonkers (itsme), and me, as moderator. While their perspectives differed, they did converge on a single takeaway: when identity systems “grow up”, the technical problems are no longer the hardest ones. The hardest ones are operational, human, and legal.  

“What once worked in limited environments…” 

In pilot deployments, identity systems operate in protected environments. Test users are known. Edge cases are limited. And security monitoring is often an afterthought because the surface area is manageable.  

At scale in production, those assumptions disappear. 

Edge cases are no longer peripheral. They become daily events. Combinations of user behaviors that were never tested begin to surface. Minor architectural shortcuts become systemic vulnerabilities. A missing metric becomes an operational blind spot. A user journey that worked flawlessly in a lab, fails in the real world. 

This is the moment when identity transitions from “feature” to “societal dependency.” At enterprise scale, identity is an enabler. It protects systems, governs access, and supports business processes. But when a single digital identity infrastructure underpins access to government portals, banking services, healthcare records, telecom subscriptions, tax filings, digital signatures, and welfare systems, it ceases to be a technical layer. It becomes foundational infrastructure. 

The panel made one point particularly clear: identity standards are no longer “the solution”; they are only the beginning of accountability. A standard is not a silver bullet; it is an agreement to collaborate at the same time across multiple parties. Standards do not guarantee correct implementation, operational maturity, or user understanding. In fact, once multiple parties adopt and interpret a standard simultaneously, complexity multiplies rather than diminishes. Interoperability is not achieved by publishing a specification. It is achieved through governance, conformance, and continuous collaboration. 

“Fraudsters will change very rapidly.” 

Another recurring theme was the arrival of fraud once systems reach critical mass. When a digital identity facilitates comprehensive access to government, banking, telecom, and insurance services, it also becomes attractive for criminals. The transition from “no fraud” to “critical loss” is not gradual. It is immediate. Fraud appears when the ecosystem becomes worth attacking. 

What matters is not a single mitigation, but the capacity for the identity system to adapt. Fraud is not a defect you patch; it is an adversary you combat. Put in one control, and the fraudsters tactics change. 

In nationwide or mass market identity systems, the stakes are asymmetric. In workforce identity, lockouts are inconvenient. In organizations there is an admin, there is a helpdesk, there is an office door you can physically knock on to fix the problem. With citizen identity, lockout is not just “annoying”; it is disabling at a citizen level. That difference should inform every wallet roadmap. 

“You might need it in the next five minutes.” 

Identity lifecycle management is one of the most neglected components of a country level digital identity management program. Devices fail. Phones are lost. PINs are forgotten. People change handsets and also have them stolen. And yet the recovery paths we design often resemble passport issuance: appointments, queues, manual checks, and other types of bureaucracy. 

That pacing is incompatible with a continuously operating digital life. A citizen cannot lose access to electricity, healthcare, or banking for extended periods just because they can’t have their identity verified.  

A robust trust framework at scale must treat recovery as a first-class control, not a back-office afterthought. Recovery must be secure, but also scalable. It cannot rely on a public official manually reactivating an identity or a wallet for thousands of people a day. The recovery process must also be online, and it must be realistic about what users actually do when stressed, tired, or frightened. 

“A collision of commercial interests versus state interests.” 

Trust frameworks do not exist in a vacuum. They interact with regulations, sovereignty, and the reality that surveillance is not a future risk. It is a present condition. If high assurance becomes synonymous with “open your kimono”, then privacy becomes collateral damage and the identity community becomes complicit. 

Digital sovereignty adds another layer of complexity; where data lives, who operates the infrastructure, which and when jurisdictions can compel production, and how far extraterritorial laws can extend their reach. In Europe, this discussion is moving from theoretical to political, with scrutiny falling not only on technology, but on ownership structures and cloud dependencies. 

Regulation, for all its potential irritations, is an instrument of trust. It draws lines. It creates enforceable expectations. It can standardize the conditions under which ecosystems interoperate. But it also introduces ongoing tension; individual interests, commercial interests, and state interests rarely converge, and when they do, they do so temporarily. More on this here.  

If trust frameworks are to scale across borders, they must operate these tensions as a given. 

“Main takeaways”  

The discussion ultimately converged on these takeaways: 

Trust frameworks at scale require systems that are designed for reuse from the outset, that externalizable interfaces, are delivered as modular components, and have the capacity to interoperate without surrendering control. They also require continuous experimentation, because standards and architectures built for a previous era cannot simply be extended into this one. They require operational agility, because fraud adapts faster than governance. They also require lifecycle realism, because devices break and people make mistakes.   

Above all, they require balance. Balance between privacy and visibility. Between sovereignty and interoperability. Between commercial incentives and the public good. Between high assurance and effective recovery. The challenge is not to eliminate the tensions, but to design frameworks resilient enough to coexist with them. 

Hope for success remains justified, but only if the designs are well considered. A world with fewer digital borders, more portable trust, and interoperable identity is technically achievable. Whether it is trustworthy will depend not on a single standard or wallet, but on the cumulative integrity of the trust bridges we build. 

EIC Berlin in May: where the conversation continues 

At EIC in Berlin in May, the same panelists will continue pulling these topic threads in the following sessions: 

Find out more by joining us at EIC 2026 taking place in Berlin and online from 19-22 of May.  

See you there!  


KuppingerCole Analysts AG
Background and Education Alejandro holds a bachelor's degree in international relations from Jagiellonian University in Poland and a master's degree in technology governance and digital transformation from Tallinn University of Technology in Estonia.  Professional Experience As a Lead Analyst at KuppingerCole Analysts, Alejandro's research focuses on Privileged Access Management (PAM), Cloud Infrastructure Entitlement Management (CIEM), Identity Threat Detection and Response (ITDR), Access Management, AI Identity, Passwordless Authentication, Customer Identity and Access Management (CIAM), Identity Fabrics, Identity Verification, Zero Trust, and related topics. Beyond his analyst work, he has collaborated with several European think tanks, where he developed expertise in digital transformation, public sector modernization, and the strategic impact of geopolitical developments on business.
Almost Ready for EIC 2026?
Reach out to our team with any remaining questions

Research Assistant

Hi, I'm Kuppi, your AI-powered research assistant. Ask me about KuppingerCole Analysts' research, events, or analysts.
As an AI assistant, I can make mistakes. Please verify important information.