Good afternoon, everybody. In a few years' time, everybody in this room will start reaching for that digital wallet. That's the intention that we have, that's the design that we gave for eIDAS, along with several hundreds of millions of other Europeans. That's the future for eIDAS too, that's the design that we make, this is the target of what we are building today. Belgium has been operating a version of that future already for nine years.
We have electronic identification means for eight million users in Belgium already, we've been running that for nine years, and we have some experience with what can happen with that. I run risk and compliance there. The thing that we see, and we have spent close to a decade discovering, is what population-scale digital identity actually means. What it takes to manage this. We have learned a few lessons, and I think these are worth sharing on this forum. The most important lesson is this. I need a clicker. The most important lesson is this.
The fraud problem has moved also, so it's not because you have technology, et cetera, in place, that your fraud will disappear. That's a lot of things that I heard today in the last couple of days, that technology would solve a lot of things.
Well, it solves a lot of things, but it will still stick, that fraud problem. So it's consistent with what we actually see, and the harder question is whether the way that we manage the credential and how that is being used is actual consequential or in line and consistent with what we expect that the users would be doing with it.
So, before I unpack that, let's have a closer look at what that European future looks like. My name is Olaf Junkers. I work for It's Me already since ten years. I have 25 years of background in identity and management of that. I love being in this area. I have been pioneering together with my colleagues in EIDAS already for that period. We have now become and are considered quite critical to the society in Belgium. We are an essential entity, and rightfully so. The critical infrastructure that we have is serving 8 million users. I mentioned that already.
We have up to 50 million transactions per month. We have practically all sectors in Belgium covered.
We have 3,000-plus partners that are actually, or platforms that are actually integrating with It's Me, and most of them quite critical. Government applications, bank applications, et cetera. We are a level of assurance high. We are a qualified trust service provider. We meet NIST 2, DORA, AML, let's say regulatory framework that you can throw at it. We have to probably meet as a company. We are here now for the European Promise, European Identity Wallet. We heard a lot about how far we are already getting with that.
The EIC conference here of Copenhagen is actually a very good reference for that. Many of us are looking at what is happening there. So that implementation of that digital decade is fortunately becoming reality. So that framework is there. We have digital identity. We have assurance frameworks. And you will not have missed that we have the UD wallet that is coming to us.
Now, that UD wallet is good. It's a broader framework. We have identity that is no longer a feature attached to a certain service. That's the floor beneath. This is identity in itself. Identity will be the substrate on which services will run. The ambition behind this is very laudable because basically democratic access to public services for citizens, for example, that cannot easily walk to a city hall, it's critical. You have to provide this kind of services in this day and age. You have to make it digital.
But also access to private services, private services which have become fundamental rights, access to financial services, access to internet even, access to telco. So, basically, also those services will be enabled by such infrastructure. Cross-border interoperability does not currently exist. We missed that one.
But, okay, that's EIDES 2 for you. We will manage it with EIDES 2. Let me be clear. I don't want to dispute the destination itself. The legal architecture is there. We need that today in that mobile first world.
What I do, however, want to question a bit is whether the framework in the current shape with the current regulation that we have will get us there without compounding the fraud problem that was designed actually to mitigate. So, once that identity infrastructure goes nationwide, your fraud prevention becomes a totally different ballgame. In a pilot, fraud remains an edge case. You think of it, but you're not as creative as that fraudster. Once you go beyond, in a fraud case, in a test environment, you handle it bilaterally. You can manage it. You absorb it. It does not define the system.
What we experienced actually with a nationwide deployment is that when it covers a complete population, the fraud is no longer an edge case. You live with it. It scales with that adoption.
So, what is essential infrastructure for a citizen becomes also essential infrastructure for fraudsters, for criminals. So, the same thing that makes that wallet useful, and that's what we were trying to achieve, is what makes it an attractive target for criminals.
Also, that scale helps, fortunately, those people. Any system that processes a large enough volume of valuable transactions will attract that kind of fraud. They will have the fraud problem proportional to that scale.
So, basically, the European wallet will not be that exception. They will have to face that as well. The question that we have today is within the next few years if the fraud will appear, but will we be ready to manage it with the framework that we're putting in place? To be clear, that's covered already, yes? I'm not talking about agentic AI, I'm not talking about post-quantum crypto. These are all things I don't know too much about. Let's be honest. I'm not an expert there. But the risk I'm describing, it's not depending on those kind of implementations or technology.
It does not require breaking the cryptography. The risks that will define next phases are much more mundane. It's the user themselves that will do things which we did not anticipate.
So, basically, we cannot just engineer it away. That's a problem.
So, basically, for those structural gaps that I see, I see three gaps. So, let's walk through with the first one.
So, the reality of modern mobile life is not that basically I can just enable my apps and be done with it. That's theory. The users will lose their device. They will lend it out. They will give it to their kids, to their partner. They will help others or they will be asked or ask others to help them.
So, basically, the model that we have now assumes a detailed and idealized relationship between the user and his or her device. One person, one phone, one consistent context. This is not the case.
So, basically, this means that what we aim for today, the credential that is valid or invalid is a binary question is not sufficient as we need to do for fraud mitigations. There's no device intelligence. We do not have behavioural context. We do not do risk scoring. We don't know where the credential prevalence actually comes from. Accessibility provisions as a specific one. Accessibility provisions by design create a necessary exception to strict device binding. Why is that?
Because, basically, those people that need it are also a meaningful portion of the population, and they will be included with accessing a mobile wallet. However, those same exceptions are also the most attractive for social engineering. We see this every week.
So, just to give you a short example, victim is called over the telephone. Lists of telephones or GSM numbers are all over the place, also with demographic information, so I can filter out elderly people, people that are more naive. I can just call them.
Basically, these people get a call, you are being scammed. They tell you, and that's exactly what they are doing. They're scamming you.
So, basically, these people are being scammed, and they are being told you have to necessarily update your SIM. Here's the app. You need to do it quick because otherwise you will be defrauded. It goes fast. Still provide me with your pin, and all of a sudden, the screen goes black.
Basically, they're defrauded, and they didn't even realise what they were doing. There was no breaking of crypto. There was no device binding that was compromised. It's just an extra app which gives control to defrauders on that same very device. It's fully compliant, but, yet again, fully misused.
So, second gap. The philosophy of the framework itself provides us with a problem.
So, basically, self-sovereign identity is a great idea. Privacy-wise, I couldn't think of a better thing. It's also incompatible with the way that fraud is countered in practice. Talk with any bank, and they will tell you. Fraud prevention requires real-time signals. You have to listen in on what is happening on that device. A cross-relying party, you have to know device intelligence, you have to know the velocity of what is happening, the behavioural anomalies that you see, known bad patterns.
None of that fits inside the model where the user controls each transaction unilaterally where each transaction is treated as a closed event. You're blind. Governance has to be dynamic. The rules have to change as the fraud pattern changes.
So, what looked normal as a risk, or as a normal behaviour six months ago can all of a sudden be a cause for concern. It can be the pattern that you see as a compromise. So that framework that was certified once, it will change. Fraud evolves continuously. You will have to follow that fraud evolution with your solution. It's a different posture that you have to take. It's not certification alone.
Now, don't get me wrong, I'm not arguing for less user control. User control must be there. I'm arguing that the absolute version of self-sovereignty, where the user is the only party with visibility into how the wallet is used, is a model that fraud will thrive on. They will exploit it because it has no shared layer for observability on those transactions. Framework has not solved it yet. Until it does, those relying parties will bear the brunt.
Banks, telcos, and the citizens. The third gap is the one that worries me the most, because it's not getting the proper attention. Identity-proofing today is actually mostly happening at onboarding. It's a very expensive step. You want to have a real KYC check, for example, you do a document scan, you do a liveness check, you do manual reviews.
Basically, it is expensive. You do it once. When the customer joins your company and you trust the result for years to come. Wallet verifications is orders of magnitude cheaper. What we will see as a result is that the verification will move out of the onboarding scene and out of the onboarding process. It will move into transaction-level usage. Many small checks instead of one big one.
Basically, the fraud will follow. Lower transaction values, but much higher frequency. Different operational shape. The fraud playbook that we use today will change dramatically going forward. There's a structural problem. The framework funds the issuance of the credentials, but it does not adequately fund the response that we need for ongoing fraud.
So, basically, public authorities, they're not resourced, they're not mandated to operate a dynamic real-time fraud response at population scale. Regulatory framework does not require them to have this. Identity is a critical infrastructure. Critical infrastructure needs maintenance.
Roads, bridges, power grids, water systems, they all have to have continuous operational investments to sustain the trustworthiness of those infrastructures. It's the same with identity. Without a sustainable funding and an operational model for ongoing fraud response, that ecosystem will get riskier and less valuable to use, and more expensive to defend. So I have described three gaps. I want to spend a few minutes on a fourth issue that I see. It's compounding probably the same three gaps that we heard before.
It happens when you see those gaps within the context of European federated structure. So, basically, you will see that a single legal construct like EIDAS is being implemented by different member states, and we see it already in different forms and different measures. Some member states will invest heavily, red teaming, fraud testing, ongoing oversight, it will be there. They will treat certification as a beginning, while others will treat it as a check box. That divergence is already visible, so we see that already lighter certification approaches alongside some very rigorous ones.
Legal facade of equivalence is uniform, but the operational reality behind it is not. Now consider the relying party behind this, the bank. A bank in any member state has to accept any and all of these member states, any of all these European identity wallets. They will be exposed. They cannot discriminate. They cannot say we trust this country's wallet and not the other one. So the certification rigour of the least rigorous member state will define the level of trust.
That may not be the intention of the architecture, far from it, but it will actually be the product that we get out of this in the market. This is the fragmentation problem we thought we were solving, but we actually did not solve it, we just moved it up a layer. The financial sector specifically is inheriting this problem in a sharper form than anyone else. Once the European identity wallet is mandatory, banks must accept it. They cannot route around it, they cannot price out the risk away by refusing those wallets.
Because the regulation requires acceptance, they cannot fall back to alternative identity proving. The question of trust gets transferred to the relying party who does not have the tools to manage it. They will not have that visibility. Banks will be expected to absorb that fraud problem on their side, so that the framework will help create, sorry, the fraud problem that the framework actually helps create. The liability mechanisms that we currently have in place do not match that scale of the exposure that they get. This is a structural problem.
They cannot be solved by the individual banks acting alone. So, basically, this needs to get some more attention. Nine years of experience, and I want to be very careful here, it's not a product pitch.
So, basically, I just want to share the experiences that we have there. We have roughly 8 million users. We have been operating that for a long time across those banks, across insurance, telco, and we have processed billions of authentications, millions of qualified electronic signatures, and basically any identity system that tells you that at this scale they are completely fraud free, they are trying to sell you something. What we do is constantly adapting to the fraud response that we need.
So we have a team, we have the security operations centre, we have the tooling that they need to respond to it, and we do that in real time. We push out the attackers out of the environment when we see those patterns change. That work is beyond our official certification. It's run by an operator by us that owns the consequence when things go wrong. The trust is projected on our ecosystem.
So, basically, that's the layer that the framework currently has no equivalent for. I'm not saying we have solved the problem, but, again, we have spent nine years of discovering what actually the problem is and how to handle that at scale. Conclusion, I will name three things that I think the framework still has to find a place for in the framework. The three things are, first, a recognised role in that ecosystem for a dynamic security and fraud intelligence layer. Above any individual wallet itself. I have one minute, so I have to speed up.
Secondly, a credible mechanism for ongoing certification. Not just a tick in the box, it has to be a credible supervision. Two-speed Europe is a policy choice, not a technical inevitability.
Thirdly, funding an operational model that pays for response. Not only the issuance. The cost of running this layer over decades should be recognised somewhere. Private operators like us, with a population scale experience, can contribute in how this should be done.
Finally, I want to leave you with this closing thought. Europe is building a wallet ecosystem that is cryptographically strong, politically very ambitious, but also operationally very fragile. Standards alone will not solve this. Fraud will exploit the fragmentation that we see, the human behaviour, and the uneven implementations in that implementation of the European identity wallets. That reality has to be acknowledged before we can solve the fraud. Thank you. Thanks a lot, Olaf, for showing us that this is not only a technical thing to solve, right? It goes very beyond.
You know this from the business, but also from this. Maybe one short question, maybe you can quickly answer. When did this all with the fraud start?
So, when was the point? Was it directly in the beginning when you started, or it just came into play? That's the thing. The first years, we didn't experience any fraud at all. So that was a learning curve. Once you start building up, you get critical mass, you start doing the valuable business cases with banks, that's where you saw the first instances of very creative use of that same ecosystem, but defrauding people. And it immediately triggered that response like, okay, we have to do something with this. Thanks a lot again, and see you soon. Thank you.