Good afternoon, everybody. In a few years' time, everybody in this room will start reaching for that digital wallet. That's the intention that we have, that's the design that we gave for eIDAS, along with several hundreds of millions of other Europeans. That's the future for eIDAS too, that's the design that we make, that is the target of what we are building today. Belgium has been operating a version of that future already for nine years. We have electronic identification means for eight million users in Belgium already.
We've been running that for nine years, and we have some experience with what can happen with that. I run risk and compliance there. The thing that we see, and we have spent close to a We have learned a few lessons, and I think these are worth sharing on this forum. Most important lesson is this. I need a clicker. Most important lesson is this. The fraud problem has moved also.
So, it's not because you have technology, et cetera, in place that your fraud will disappear. That's a lot of things that I heard today in the last couple of days that technology would solve a lot of things.
Well, it solves a lot of things, but it will still stick, that fraud problem. So it's consistent with what we actually see, and the harder question is whether the way that we manage the credential and how that is being used is actual consequential or in line and consistent with what we expect that users would be doing with it.
So, before I unpack that, let's have a closer look at what that European future looks like. My name is Olaf Junkers. You heard that already. I work for It's Me since ten years. I have 25 years of background in identity and management of that. I love being in this area. I have been pioneering together with my colleagues in EIDAS already for that period. We have now become and are considered quite critical to the society in Belgium. We are an essential entity, and rightfully so. The critical infrastructure that we have is serving 8 million users. I mentioned that already.
We have up to 50 million transactions per month. We have practically all sectors in Belgium covered.
We have 3,000-plus partners that are actually, or platforms that are actually integrating with It's Me, and most of them are quite critical. Government applications, bank applications, et cetera. We are a level of assurance high. We are a qualified trust service provider. We meet NIST 2, DORA, AML, every regulatory framework that you can throw at it, we have to probably meet as a company. We are here now for the European promise, European identity wallet. We heard a lot about how far we are already getting with that.
The EIC conference here of Kupinger Coal is actually a very good reference for that. Many of us are looking at what is happening there, so that implementation of that digital decade is fortunately becoming reality. That framework is there. We have digital identity, we have assurance frameworks, and you will not have missed that we have the UD wallet that is coming to us.
Now, that UD wallet is good. It's a broader framework. We have identity that is no longer a feature attached to a certain service. That's the floor beneath. This is identity in itself. Identity will be the substrate on which services will run. The ambition behind this is very laudable, because basically, democratic access to public services, for citizens, for example, that cannot easily walk to a city hall, it's critical. You have to provide this kind of services in this day and age. You have to make it digital.
But also, access to private services, private services which have become fundamental rights, access to financial services, access to internet even, access to telco. Those services will be enabled by such infrastructure. Cross-border interoperability does not currently exist. We missed that one, but that's EI 2 for you. We will manage it with EI 2. Let me be clear, I don't want to dispute the destination itself. The legal architecture is there. We need that today in that mobile-first world.
What I do, however, want to question a bit is whether the framework in the current shape with the current regulation that we have will get us there without compounding the fraud problem that was designed actually to mitigate. So, once that identity infrastructure goes nationwide, your fraud prevention becomes a totally different ballgame. In a pilot, fraud remains an edge case. You think of it, but you're not as creative as that fraudster. Once you go beyond, in a fraud case, in a test environment, you handle it bilaterally. You can manage it. You absorb it. It does not define the system.
What we experienced actually with a nationwide deployment is that when it covers a complete population, the fraud is no longer an edge case. You live with it. It scales with that adoption.
So, what is essential infrastructure for a citizen becomes also essential infrastructure for fraudsters, for criminals. So, the same thing that makes that wallet useful, and that's what we try to achieve, is what makes it an attractive target for criminals.
So, also, that scale helps, fortunately, those people. Any system that processes a large enough volume of valuable transactions will attract that kind of fraud. They will have the fraud problem proportional to that scale.
So, basically, the European wallet will not be that exception. They will have to face that as well, and the question that we have today is within the next few years if the fraud will appear, but will we be ready to manage it with the framework that we're putting in place? To be clear, that's covered already. I'm not talking about agentic AI, I'm not talking about post-quantum crypto. These are all things I don't know too much about. Let's be honest, I'm not an expert there, but the risk I'm describing, it's not depending on those kind of implementations or technology.
It does not require breaking the cryptography. The risks that will define next phases are much more mundane. It's the user themselves that will do things which we did not anticipate.
So, basically, we cannot just engineer it away. That's a problem.
So, basically, for those structural gaps that I see, I see three gaps. So, let's walk through with the first one.
So, the reality of modern mobile life is not that, basically, I can just enable my apps and be done with it. That's theory. The users will lose their device. They will lend it out. They will give it to their kids, to their partner. They will help others or they will be asked or ask others to help them.
So, basically, the model that we have now assumes a detailed and idealized relationship between the user and his or her device. One person, one phone, one consistent context. This is not the case.
So, basically, this means that what we aim for today, the credential that is valid or invalid is a binary question, is not sufficient as we need to do for fraud mitigations. There's no device intelligence. We do not have behavioral context. We do not do risk scoring. We don't know where the credential actually comes from. Accessibility provisions as a specific one. Accessibility provisions by design create a necessary exception to strict device binding. Why is that?
Because, basically, those people that need it are also a meaningful portion of the population, and they will be included with accessing a mobile wallet. However, those same exceptions are also the most attractive for social engineering. We see this every week.
So, just to give you a short example, the victim is called over the telephone. Lists of telephones or GSM numbers are all over the place.
Also, with demographic information, so I can filter out elderly people, people that are more naïve, I can just call them. Basically, these people get a call, you are being scammed. They tell you, and that's exactly what they are doing. They're scamming you.
So, basically, these people are being scammed, and they are being told you have to necessarily update your SIM. Here's the app. You need to do it quick because otherwise you will be defrauded. It goes fast. Still provide me with your PIN, and all of a sudden, the screen goes black.
Basically, they're defrauded, and they didn't even realise what they were doing. There was no breaking of crypto. There was no device binding that was compromised. It's just an extra app which gives control to defrauders on that same very device. It's fully compliant, but yet again, fully misused.
So, second gap. The philosophy of the framework itself provides us with a problem.
So, basically, self-sovereign identity is a great idea. Privacy-wise, I couldn't think of a better thing. It's also incompatible with the way that fraud is countered in practice. Talk with any bank, and they will tell you. Fraud prevention requires real-time signals. You have to listen in on what's happening on that device. A cross-relying party, you have to know device intelligence, you have to know the velocity of what's happening, the behavioural anomalies that you see, known bad patterns.
None of that fits inside the model where the user controls each credential transaction unilaterally, and where each transaction is treated as a closed event. You're blind. Governance has to be dynamic. The rules have to change as a fraud pattern changes.
So, what looked normal as a risk, or as a normal behaviour six months ago, can all of a sudden be a cause for concern. It can be the pattern that you see as a compromise. So that framework that was certified once, it will change. Fraud evolves continuously. You will have to follow that fraud evolution with your solution. It's a different posture that you have to take. It's not certification alone. Don't get me wrong, I'm not arguing for less user control. User control must be there.
I'm arguing that the absolute version of self-sovereignty, where the user is the only party with visibility into how the wallet is used, is a model that fraud will thrive on. They will exploit it, because it has no shared layer for observability on those transactions. The framework has not solved it yet. The EIS did not solve it yet. Until it does, those relying parties will bear the brunt.
Banks, telcos, and the citizens. Third gap. The third gap is the one that worries me the most, because it's not getting proper attention. Identity-proofing today is actually mostly happening at onboarding. It's a very expensive step. You want to have a real KYC check, for example, you do a document scan, you do a liveness check, you do manual reviews.
Basically, it is expensive. You do it once, when the customer joins your company and you trust the result for years to come. Wallet verifications is orders of magnitude cheaper. What we will see as a result is that the verification will move out of the onboarding scene and out of the onboarding process. It will move into transaction-level usage. Many small checks instead of one big one.
So, basically, the fraud will follow. Lower transaction values, but much higher frequency. Different operational shape. The fraud playbook that we use today will change dramatically going forward. And there's a structural problem. The framework funds the issuance of the credentials, but it does not adequately fund the response that we need for ongoing fraud.
So, basically, public authorities, they're not resourced, they're not mandated to operate a dynamic, real-time fraud response at population scale. Regulatory framework does not require them to have this. Identity is a critical infrastructure. Critical infrastructure needs maintenance.
Roads, bridges, power grids, water systems, they all have to have continuous operational investments to sustain the trustworthiness of those infrastructures. It's the same with identity. Without a sustainable funding and an operational model for ongoing fraud response, that ecosystem will get riskier and less valuable to use and more expensive to defend.
So, I have described three gaps. I want to spend a few minutes on a fourth issue that I see. It's compounding probably the same three gaps that we heard before. It happens when you see those gaps within the context of European federated structure.
So, basically, you will see that a single legal construct like EIDAS is being implemented by different member states and we see it already in different forms and different measures. Some member states will invest heavily, red teaming, fraud testing, ongoing oversight, it will be there. They will treat certification as a beginning, while others will treat it as a checkbox. That divergence is already visible.
So, we see that already lighter certification approaches are alongside some very rigorous ones. Legal facade of equivalence is uniform, but the operational reality behind it is not.
Now, consider the relying party behind this, the bank. A bank in any member state has to accept any and all of these European identity wallets. They will be exposed, they cannot discriminate. They cannot say we trust this country's wallet and not the other one.
So, the certification rigor of the least rigorous member state will define the level of trust. That may not be the intention of the architecture, far from it, but it will actually be the product that we get out of this in the market. This is the fragmentation problem we thought we were solving, but we actually did not solve it, we just moved it up a layer. The financial sector, specifically, is inheriting this problem in a sharper form than anyone else. Once the European identity wallet is mandatory, banks must accept it.
They cannot route around it, they cannot price out the risk away by refusing those wallets. Because the regulation requires acceptance, they cannot fall back to alternative identity proving. The question of trust gets transferred to the relying party, who does not have the tools to manage it. They will not have that visibility. Banks will be expected to absorb that fraud problem on their side, so that the framework will help create, sorry, the fraud problem that the framework actually helped create.
The liability mechanisms that we currently have in place do not match that scale of the exposure that they get. This is a structural problem. They cannot be solved by the individual banks acting alone.
So, basically, this needs to get some more attention. Nine years of experience, and I want to be very careful here. It's not a product pitch.
So, basically, I just want to share the experiences that we have there. We have roughly 8 million users. We have been operating that for a long time across those banks, across insurance, telco, and we have processed billions of authentications, millions of qualified electronic signatures, and, basically, any identity system that tells you that at this scale, they are completely fraud-free, they are trying to sell you something. What we do is constantly adapting to the fraud response that we need.
So, we have a team, we have the security operations centre, we have the tooling that they need to respond to it, and we do that in real-time. We push out the attackers out of the environment when we see those patterns change. That work is beyond our official certification. It's run by an operator, by us, that owns the consequence when things go wrong. The trust is projected on our ecosystem.
So, basically, that's the layer the Wallet framework currently has no equivalent for. So, I'm not saying we have solved the problem, but, again, we have spent nine years of discovering what actually the problem is, and how to handle that at scale. Conclusion, I will name three things that I think the framework still has to find a place for in the framework. The three things are, first, a recognised role in that ecosystem for a dynamic security and fraud intelligence layer. Above any individual Wallet itself. I have one minute, so I have to speed up.
Secondly, a credible mechanism for ongoing certification. Not just a tick in the box, it has to be a credible supervision. Two-speed Europe is a policy choice, not a technical inevitability.
Thirdly, funding an operational model that pays for response. Not only the issuance. The cost of running this layer over decades should be recognised somewhere. Private operators, like us, with a population-scale experience can contribute in how this should be done.
Finally, I want to leave you with this closing thought. Europe is building a Wallet ecosystem that is cryptographically strong, politically very ambitious, but also operationally very fragile. Standards alone will not solve this. Fraud will exploit the fragmentation that we see, the human behaviour, and the uneven implementations in that implementation of the European identity Wallet. That reality has to be acknowledged before we can solve the fraud. Thank you. Thanks a lot, Olaf, for showing us that this is not only a technical thing to solve, right? It goes very beyond.
We know this from the business, but also from this. Maybe one short question, maybe you can quickly answer. When did this all-with-a-fraud start?
So, when was the point? Was it directly in the beginning when you started, or it just came into play? That's the thing. In the first years, we didn't experience any fraud at all. That was a learning curve. Once you start building up, you get critical mass, you start doing the valuable business cases with banks, that's where you saw the first instances of very creative use of that same ecosystem, but defrauding people. It immediately triggered that response, like, okay, we have to do something with this. Thanks a lot again, and see you soon. Thank you.