• Understand the current maturity of decentralized identity ecosystems
• Learn how wallets, passkeys, and verifiable credentials work together
• Explore interoperability challenges and emerging implementation guidance
• Assess sustainable business models for digital wallet providers
• Understand how EU digital identity wallets differ from other ecosystems
• Gain practical insight into moving decentralized identity into real-world adoption
Decentralized identity has moved from theory to tangible building blocks, yet broad trust and adoption remain uneven. Wallets, passkeys, and verifiable credentials promise privacy-preserving digital interactions, but fragmentation, unclear implementation paths, and unresolved economic questions still slow real-world deployment.
Modern standards and platforms are beginning to close these gaps. Passkeys reduce phishing and password risk, verifiable credentials enable portable identity proofs, and emerging APIs and wallets provide interoperability. The challenge now is aligning security, privacy, usability, and incentives into a coherent, scalable ecosystem.
Alejandro Leal, Senior Analyst at KuppingerCole Analysts will frame the current state of decentralized identity, examining market maturity, adoption barriers, and the role of standards in building trust. He will connect technical progress with regulatory realities and enterprise readiness.
Nishant Kaushik, CTO at FIDO Alliance, together with Henk Marsman and Torsten Lodderstedt at SPRIND will share practical insights from standards development, research, and ecosystem deployment. They will discuss interoperability, wallet architectures, sustainable business models, and how decentralized identity can move from pilots to trusted everyday use.
Hello everyone. My name is Alejandro Leal, Senior Analyst at KuppingerCole. Welcome to the State of Decentralized Identity webinar, Wallets, Credentials, and Real-World Adoption.
Today, I have a group of experts joining me on stage. And before the round of introductions, I would like to remind the audience that you can enter questions at any time. We will be looking at your questions, and we'll be having a very engaging conversation. So feel free to write anything you would like to know. We have a very knowledgeable group of people here that can address those questions.
So now, maybe we can have the round of introduction. Maybe we can start first with Nishant.
Thank you, Alejandro. This is Nishant Kaushik. I'm the CTO at the FIDO Alliance, helping drive our technical initiatives and working with all our members and pushing the digital identity ecosystem forward. Thanks for having me today.
Thank you, Nishant. Maybe we can go with Henk now.
Yes, thanks, Alejandro. Happy to be here as well. My name is Henk Marsman. I'm doing PhD research at Delft University at the moment, looking at business models in data ecosystems. And I'm also a principal consultant with a boutique advisory firm on digital identity. Thank you.
Now, last but not least, Torsten. Hello, everybody. My name is Torsten Woderstedt, and I am the project lead for the introduction of the EODI wallet in Germany. And besides this, I have been involved in writing a couple of technical standards that are relevant in the wallet space. Great.
Well, thank you so much for joining me today. I would first like to maybe set the stage a little bit before we jump in into the discussion. As we know, over the past few years, decentralized identity has evolved from, let's say, a largely theoretical model into a more concrete one. We now have working components, digital wallets, passkeys, verifiable credentials, and APIs and standards that allow these elements to interact.
So, in other words, the technical building blocks increasingly exist. Yet, if we step back and look at the broader ecosystem, I think that we see a different picture. Trust across this ecosystem is uneven. Interoperability is not yet frictionless, and the economic incentives to many participants remain unclear.
So, detention is really at the heart of today's discussion, because decentralized identity is not just a technology problem, but it's also an ecosystem problem. And for such a system to work at scale, multiple actors must participate simultaneously. Wallet providers, credential issuers, relying parties, infrastructure providers, regulators, each of them must see a clear value proposition and a sustainable role in the ecosystem.
So, this raises a series of important questions. Why would organizations choose to become wallet providers? What incentives exist for relying parties to accept verifiable credentials? Or how do these systems interact with broader data exchange ecosystems? And I think this is where the European Digital Identity Wallet Initiative on their EI becomes an interesting subject. As we know, Europe is attempting something very ambitious, creating a trusted digital identity framework that can work across borders, sectors, and industries.
But whether this model succeeds will depend not only on regulations or standards, but on whether it can generate sustainable participation across the ecosystem. So, I think that's the goal of today's discussion, is to explore these interconnected dimensions. And with that framing in mind, maybe we can start with the first question. How mature is the decentralized identity ecosystem today, both from a technical dimension and institutionally? And maybe we can start first with Nishant. Sure.
So, I think the ecosystem is maturing, but I think it comes back to what you were saying, right? Like, it's not necessarily – this isn't just a technical or a technological issue, right? When we start thinking about the ecosystem, it's about legal, it's about societal, and it's about political, right? And all of those things, when you frame them together, especially when you look at what's happening with the EU digital wallet, a lot of that is regulatory-driven. You're trying to create incentives for the market, as you mentioned.
Establishing that as the driving function for essentially forcing trust into the ecosystem takes time. It takes cooperation. It takes a lot of work. And as you pointed out, a lot of the players in this ecosystem are still trying to work out what it means for them. How will they engage? What do they need in order to be able to actively participate in that market?
So, it's not just about the fact that with technology advancing, we now have both technological underpinnings with respect to things like devices, things like secure TPMs and things like that that are underpinning it. We have the standards in place, et cetera. But then driving towards actual utility requires those issues of regulatory, legal, and societal trust to be built into the ecosystem. And that is something we have to get to by demonstrating value, by demonstrating interoperability, by demonstrating utility for the individual, right?
And respect for privacy and all those sorts of constraints. When you frame it that way, there's a lot that needs to be solved. There's a lot that we need to work on.
And so, by definition, that is going to take some time and a lot of cooperation from different folks in the ecosystem. I saw you nodding there, Henk. Maybe you got something to say? I was adding to that what Nishant says, especially around if you look at it through a value lens, what value are we creating here and where is value being made? I think in this ecosystem and in these decentralized identity ecosystems, we are putting a value proposition forward saying that if we give digital identity certain safeguards and a high legal status, then that can bring value.
The question then is where does it bring value and to whom does it bring value? And I think we're now at the point where the EUDI ecosystem is getting to an initial state of maturity.
And so, we're going to see these solutions entering the market. And then the question is where and to whom do these digital walls bring value? And is it in my engagement with the government doing a tax report or is it with online retailers in what kind of scenarios? And I think the question of is that ecosystem mature is one, but whether people or actors or providers will join that ecosystem also depends on where can it be used.
And the more valuable it becomes in other data ecosystems with other value propositions, like buying a house, buying a car, doing online shopping, that will also give a pull on the original ecosystem. So, it's also a matter of seeing what value does the EIDIS ecosystem bring that is a really safe digital identity solution that you can use in a lot of other use cases and contexts. Depending on how much value we can generate there, it's also not just a matter of as a wallet provider, how valuable is the EIDIS ecosystem for me?
But also, can I look at other purposes and use cases where these solutions are deployed, where value is created, and how does that affect my business model a lot, for example? Absolutely.
Thorsten, I think I saw earlier that you were doing a presentation in Dresden on this topic. Is there anything that maybe you could share with us, anything from those conversations?
Sure, a lot. How much time do we have?
So, let me take one step back. And I would like to talk about why we are doing the EODI wallet. Because that sheds some light on how personally you see the status of the current digital identity ecosystem. Because from my perspective, it does not exist yet. And it is about digital credentials in general. Let me start with the societal perspective on it. As we digitize, we need to find ways to effectively, securely, in a privacy-preserving way, prove things about us, who we are, what we are allowed to do, and so on. And especially in the German society, what we currently do is we use pictures.
We use scans of stuff, right? We use video chats and all that. And this is not secure, it's not privacy-preserving, it's not effective, it is endangered by fraud, and so on.
So, from a societal perspective, having digital credentials allows us to fight fraud and reduce cost. From a user standpoint, it's basically what people expect today, right? They pay with their smartphone, so they also expect to present their identity from the smartphone to prove that they are entitled to drive a car, and so on.
So, it's just adopting what we do to their reality of their daily life. And it's about comfort, right? From a service provider standpoint, it's basically about reducing cost, right? It's about optimization, about building new products.
So, that's how I see the landscape of value, if you like. But in order to enable that, a lot needs to be done. First of all, we need to have a digital infrastructure that is non-discriminatory. What we have right now, and what we have today, we have wallets in the market. But those wallets work differently, and the wallet providers basically control what credentials we can do wallets use with, what technology is used to issue stuff, to present stuff, and so on. It's really, it's a patchwork in the end. And this is why we need something like an EUDI wallet.
Because the EUDI wallet gives a framework for interoperability, technical as well as regulatory. And basically, with that lays the foundation for an ecosystem wallets that are secure, highly secure, privacy preserving, interoperable, and non-discriminatory.
So, for example, in Germany, we will have multiple wallets, and every issue of a credential, every relying party must work with any wallet. And any of those wallets must work with any of the relying parties and issues. And this is a prerequisite to really build an ecosystem.
Otherwise, there is no fairness in an ecosystem. And that's why we need the EUDI wallet, and that's why we are building it. And we are in a very early stage, so we cannot talk about maturity yet, because we are heading towards step number one, right? Getting that beast alive. And then we will see how it's going to work. Just to maybe follow up on that, what would you say are the necessary conditions for this ecosystem to scale sustainably? While incorporating the non-discriminatory aspect, the interoperability, and all of these things that you mentioned. How can we scale?
First of all, we need to understand what are the needs, what are the desires, and what's the proposition for the different actors, right? And if I follow the chain, users want use cases. Use cases need data. So we need to figure out how we can bring data into the ecosystem, what motivates provider of that credentials to really issue. And this is really the hard part. And we haven't found the silver bullet yet, right? What we do is we have a low entry barrier into the ecosystem, and in Germany at least, we have a very open and transparent consultation process. We talk with different entities.
And at that conference, for example, that I have spoken in the morning, we are talking with municipalities, right? What problems we can solve for them. And then we find compelling use cases for them, why they should issue credentials into the wallet. So you need to have as many as possible participants in the ecosystem. And that means low entry barrier, a clear technical solution, clear proposition, and then just work with the organizations to get their use cases on board.
So we, for example, we started a sandbox last December with the PID functionality in order to be able to really build those use cases over the course of a year before we go live. And this year, early next year. So start early, reach out, engage with the society, with the folks, and try to build use cases as soon as possible. Start early, reach out, engage with the society, with the folks, and try to build use cases, as many as possible use cases as early as possible. So that's at least our approach. So one quick point on that.
I think it's interesting to think of this from the perspective, as Hank said, from what is the value being brought to players in the ecosystem. Now, one of the challenges with scaling this ecosystem is the hesitance of especially relying parties to jump in. Because in order for a relying party to start leveraging things like digital credentials, they need assurance. They need assurance that that is a reliable vector for them to leverage, right? And one of the challenges we find is there are still ecosystem challenges that prevent relying parties from wanting to jump in.
So articulating use cases is an excellent way of saying, essentially, what are the things that I can derive value from? The challenge we're finding is that for a relying party, they can, in some cases, articulate that use case. But what they're faced right now with is, I can use the digital credentials for this use case, but will my usage be accepted, or can I reliably leverage it? And that comes, in many ways, down to two parts, right?
One is, if I leverage, let's take the example of account opening, right, which is a common use case that is described. And I'm not even talking about things like banking. But even for things like signing up for an eSIM or something like that, oftentimes those account opening requirements for identity verification have a regulatory governance around it, right? You have to satisfy certain regulations, you have to satisfy certain audit requirements.
Right now, a lot of relying parties don't know if using a digital credential will give them the regulatory cover that they require. And that is one of the biggest challenges that, for example, the EUDI Wallet project explicitly took on. When you start going beyond EU and start seeing the explosion of digital credentials across the world, they are not tackling that challenge as head-on as the EU, perhaps, David DI does, right? And that is a significant challenge for relying parties who want to leverage this, because as Tosin mentioned, this is about reducing costs, this is about reducing fraud.
Every relying party is – and about improving user experience. Every relying party wants that. But if they have to worry about, if I use this digital credential, and then somebody later is going to audit me and say, well, this isn't according to the regulation, so it's not valid, and now you're going to get fined, that is a barrier for them to adopt. If they have to look at a fragmented ecosystem and say, I can build infrastructure to accept a mobile driving license as a way of doing identity verification, but not every – if you take the US, for example, not every state supports MDLs.
Now, I have to have two parallel infrastructures. I have to build a new infrastructure for MDLs, but I still have to maintain my old one that relies on the old-fashioned scanner photograph and do a selfie match thing. That cost of having two separate infrastructures is significant.
And so, a lot of relying parties, especially the ones that are more budget-constrained, take a wait-and-see approach, which is, we're going to wait until this whole ecosystem matures, and then we'll jump in. Well, the challenge is, if there's not enough relying parties, the ecosystem will not mature.
So, we kind of have this little bit of a chicken-and-egg situation that is evolving, and that's really one of the things that we need to tackle is, in order for this ecosystem to actually start scaling and delivering value, we need to remove some of these barriers that exist today.
Yeah, I feel that is exactly one of the things that EIDIS tries to force through regulation, break that chicken-and-egg issue by forcing that every citizen and also organizations can make use of a wallet and store their identity in it, and forcing at least a couple of industries and a couple of specific sectors with conditions like strong customer authentication to accept it.
At the same time, I also see in conversations that organizations are still struggling because, on paper, it looks nice if a Dutch citizen goes to a German bank and EIDIS covers the legal backing of the verifiable credential that is issued, but there's also the fact that it may save costs, but the investments to process a verifiable credential maybe technically are not even the biggest, but the processes in many organizations that rely on the copy of the passport that is physically or digitally stored, that needs to be adjusted.
People need to be retrained, processes need to be adjusted, and also in regulated industries, auditors need to come along, so it's also figuring out that this change will bring benefit, but there's also often a significant effort to adjust, and in those situations, I do have the feeling that some companies will say, well, we're not going to be the first one to figure this out, we'll let some others take the lead on it, and then hopefully learn from some of their mistakes, so the entry will be easier for us.
And the other thing that I know from just scientific literature, that these ecosystems design, they're being birthed, and they evolve over time, so I also expect that in the use of digital identity and digital wallets, probably the initial steps will be to replace existing processes and ways of use, but then innovation will also kick in, and if there's a citizen at the front door that has a wallet with a lot of data, and I can ask him all kinds of questions, that also opens up new possibilities for services and products that can be configured and delivered to that customer, and that again then will also spur on more establishment and growth of the ecosystem.
I think, of course, the main question is also in the area of who will be the frontrunners, and will their being first give them so much advantage that they can go in and spend the learning money and then also reap the benefits of it, or whether there will be more like an early majority that will lead the way there, and I think in that sense, I don't see a lot of organizations already figuring this out or paying a lot of attention to it.
Maybe that is different for either of you, but I have the feeling that for some of them, for organizations, also the idea of development is still a bit obscure, it's something legal, something with wallets, and not everybody has it on their innovation radar yet, while it's supposed to be there quite rapidly. Those are very good points, but I would like to maybe draw your attention to one of the questions, or maybe you want to address that, Torsten? I would like to reflect on what both Arjun and Meng said, because it's really inspiring.
So first of all, we have a scaling issue, obviously, and if you have to build 10 different solutions for doing identification for anti-money laundering, that's really expensive. And I think, at least on paper, UDI Wallet addresses that by basically providing a solution that covers the whole European Union, which is a couple of hundred million users, which is better than having a solution in the Netherlands, and a solution in Germany, and a solution in France, and so on. That's on paper.
In reality, you need to convince users to install the app, and really then also bring the identification data into the app, and this is really something that is really difficult, and that's something we are working on. Two elements. First of all, we are trying to come up with a proposition that creates enough pull for the users to really install the app and install the PID into the wallet, and the strategy we are pursuing is to really provide a wallet that can be used with the identification and the driver's license in online-offline scenarios or proximity scenarios.
So, this is something that no other solution can provide yet. And the second is we work with early adopters that also provide use cases in those proximity scenarios, like picking up your parcel in a shop, you need to prove your identity, just pull up your phone, prove your identity, you're done.
So, leave your wallet at home. This is our philosophy, basically, to really motivate people to install the app and so on. And the second element to that is a multi-wallet ecosystem, because right now we are working on the national wallet. We will go live in January with that, but we start from zero. And as we all know, an identity starting from zero is really difficult, because in the end, relying parties are interested in conversion rates, right? User coverage conversion rates. And that's why we have a multi-wallet strategy in Germany.
We would like to enable other wallet providers, already service providers in the market, to become EODI wallet providers. And if it really works, then, for example, a bank institution with, I don't know, 10, 20 million installed apps can turn their app into an EODI wallet, which will also give us reach on the user side, right? And this is the first and most important thing you need to bring up, right? And then it's going to be more interesting to the relying party. In the end, you need to find solutions for all those three parties, right?
And there is no, I would say, one-size-fits-all solution. What I can say in Germany, there is tremendous momentum. You could even say hunger to get that digitization problem solved. But I also have to admit, in Germany, we are really, really, really, really behind when I compare us to other EU member states, like the Netherlands, for example. That potentially explains why there is so much interest in getting that thing settled. I didn't mean to cut you there, Torsten, but thank you so much for sharing those insights. I was actually surprised when I moved to Germany the first time.
I was living in Estonia before, so it was a drastic change. I was getting fax and lots of letters in my email. But regardless, we have a couple of questions in the chat, and I would like to address those as well. The first question is, I agree with Torsten's view of the need for the EU wallet versus the other commercial suppliers. But is there a risk that the time and effort required to obtain a consensus on the EU wallet means that by the time it is ready, the commercial wallets have already captured users? I don't know who would like to take that question. I can have a go at it.
Perhaps it helps to make a distinction between the data and the wallet, because we're setting requirements to which this wallet needs to adhere, so it will be a safe and secure wallet. So you can use it without the fear of being tracked and traced. You will always have to click accept before you share data. And the question if people actually know what it means is another question for another time. But that's the wallet. The data is currently high quality data. For example, the excerpt from the civil registry that I'm a Dutch citizen, that my name is Henk Marsman.
That data is not going to be shared with just anything or anyone. It will only be shared with this certified wallet. If there are more apps, wallets becoming available that are allowed to obtain that data, then the question is not that much on how is this wallet being used. But for the user or me as an individual, it would be much more interesting to say who accepts this data, regardless which one of the five apps that are called wallets would store it. So perhaps this distinction will also make it a bit more clear that there may be a lot of commercial wallets.
And most people that I know are using an Apple wallet to pay for their groceries in the supermarket. But that wallet will not contain high quality data. So there will be perhaps even more of a battle between use cases where you can use both wallets because it's low quality data. So the user can select their EU wallet or their Apple wallet, so to speak, or another brand. And there will be use cases where you need that high quality data and then there's only just a couple of wallets that will be able to get that data and share it under the user's control.
And I think that will also be part of the whole evolution and how this ecosystem will develop in the future. Well, we may have a focus on wallets now, but perhaps in the end, if wallets become more infrastructure, then it's more about the data and how the user can use it. From my perspective, there's no reason why Apple should not get the PIT. The only prerequisite is they certify as an UDI wallet provider, which means they follow the rules defined by the UDI or by their regulation. Be interoperable, be non-discriminatory, follow GDPR, and so on. So there are a couple of prerequisites.
And if they are fulfilled and they are recognized by member states, all good. They can become an UDI wallet provider. That's how I believe items should work going forward. Yeah. Yeah. And as Hank mentioned, at the end of the day, it's really about the data and the expectations around the data. And the expectations are driven by the verifiers as well as by the holder, right? The identities, you know, presenter who's presenting that identity. From a user perspective, they have expectations around experience and how easy it will be, but also how much control they have, how much security.
They want to know that it's secure, right? And we oftentimes do not give enough credit to individuals to be able to make these decisions for themselves with respect to appropriately choosing which mechanism to use, when to use it, right? So a lot of times they understand the risk that they're taking, so they can make those choices themselves. And it's all about giving them choice. Choice is a very powerful tool in building trust, right?
When we talk about, I think one of the questions was around building up the trust and how, today, a lot of, as to use Torsten's example, when you go to the store to pick up your package and you're presenting these physical documents, those physical documents are based on a digital record, as was mentioned, and are often, as we know, easy to fake, forge, et cetera. But trust in those documents, from a process perspective, has been built over many, many decades, even centuries, right?
There is a trust filter convention, and we're now trying to transport that trust into an entirely new infrastructure that everybody in the ecosystem has to get used to. So providing choice is going to be a big part of enabling trust, because people will almost always trust what they have the ability to choose. And when they're choosing, they will necessarily go through a process of trying to identify what works for them.
And yes, there will naturally be some sort of bias towards things that are easier, which is easier if you're dealing with the platform-provided wallet. But wallet certification is a critical element of this, because in order to have trust, you need to know that your data is being managed properly. And that trust is going to come from the issuers telling you that they have done some work to ensure that where the data is being provided is trustworthy, right?
So again, going back to the idea of the trust fabric, there's a lot that needs to go into it. And that's where certification of wallets, certification of – and requirements even on issuers as well as verifiers is going to be a key part of that. And how the wallet plays a role in conveying that.
So there's actually a lot of responsibility on wallets in conveying that trust by showing the right data, providing the right controls to the user, making sure that they understand what's going on, things like consent, things like responsible data disclosure and selective data disclosure and things like that. The wallet plays a huge role in that. And the better wallets will win, because they will provide the user that ability to understand what's going on, make a choice and control the experience.
Maybe to add to that trust, what also gives a lot of trust is that you know what happens when things go wrong. I think that's exactly where the IDES regulation – so I'm happy with purchasing stuff using my credit card online, because I know if it goes wrong, I'll call the company and they go back. I think what we will see in this ecosystem is also that the first car didn't have an airbag yet. We had some accidents and then regulators came up with the idea that we need some safety features. I also think with these wallets, we will use them.
Some people might overshare, some wallets may be breached. And then the response of how this ecosystem takes that in and makes sure that it improves will also determine to a great extent whether people know how to deal with it and then trust the use of a wallet to share data. Because they know that it is secure by design and implemented secure, but also still when something goes wrong, you know that there's some level of protection that you can lean into when things go wrong.
Yeah, I also would like to add that communication plays a very important role in building trust, because even people that are interested to use it want to know, is it secure? How are my data being treated and so on? Can I be surveyed when using the wallet? So we right now have a discussion in Germany whether the wallet is going to be a tool for surveillance, right? A political discussion, because as the wallet really becomes a major infrastructure element, it is being discussed publicly in the parliament, for example.
So communication, sending the right messages, explaining things is very important to prepare the space and also convince people that this is going to be a trustworthy tool. When you talk about convincing people, Tristan, I would like to maybe draw attention to one of the questions in the chat.
It says, how do you think people should enroll to the wallets? And I think that's alluding to your earlier comment when you were saying that currently you're looking at ways to create incentives for people to download the app to see the value of the wallet. Are you approaching this, let's say from a generational perspective, that maybe there will be some generational gaps when it comes to adoption? First of all, I would never assume that older people, for example, are less capable of using digital tools. This is what people sometimes think.
So in my perspective and my perception, this goes across different national levels. Yes, we are looking into different sectors. So we have a consultation process, I think I mentioned that, that is basically running in parallel to our project. And we have been reaching out since 23 to the society, talked with civil society actors, talked with people that are experts for inclusion and accessibility and so on. Really figuring out what we can do to build a tool that is embraced by the whole society. It's not an easy task, but that's some element of things we are doing.
Yes, and I can echo that from the Netherlands. I know at least the Dutch government program is heavily involved in user testing. And that's across age levels, but indeed also people with disabilities. Can they use the wallet? At the same time, there's also sufficient reporting and evidence for the fact that not everybody can come along in the whole digital disruption and evolution. And so one report a year ago stated that, for example, in the Netherlands are 400,000 people who do their e-banking.
And they don't do their e-banking because it's their son, their nephew, their daughter doing it for them. So that's exactly, I think also what Nishan said. It's not an obligation or it's not mandatory to use this wallet. There will be multiple methods you can choose as a citizen. You can still go back with your paper document. It will just be a lot faster with the wallet. I think one of the inclusion aspects is there in those multiple methods. And that's not directly related to the ecosystem, but much more to the service provider.
Saying if people can come to my front desk or send me an email or fill in their form or use the digital wallet. That across those methods, the effort needed to use that service should not be too big of a difference between the individual methods. Also for wallet providers, that's one of the questions that I haven't heard a lot yet. But that is understanding that if I build a wallet and people can use it to share their data, that's not a green field. People already share data.
So they need to kind of compete in all kinds of interactions with other methods that people are now using to share their data. So part of their business model is also, and why would a user step away from the online form to my wallet to share this data? If adoption by users is my objective. And that triggers a whole lot of other questions for these organizations saying so. And if a service provider wants eight data points and I have five in my wallet, how does that work? Do they then still go to the online form and fill in the remainder of the data?
Those are all things I think that we will see happening in reality with the use of this wallet. And I think the first use cases might be very small because they want to start with the pure interaction with everything that is in the wallet and then expand to more complex cases. And then try to broaden that scope and make it widely available to people with half a wallet or a full wallet. And that's the crystal ball thinking. Yeah. And one of the things, putting on a few different hats at the same time for this point, just going beyond the EU, right?
Like there's a lot of areas where you don't necessarily have the same infrastructure you can rely on in order to bootstrap a digital wallet based ecosystem, right? So a lot of countries don't have reliable physical documentation. They don't have robust identity registries of any sort or anything like that. As folks who are working to build a digital identity ecosystem, a decentralized identity ecosystem with all these architectural piece, we have to take that into account as well.
So whether you look at work being done by companies like Vouchsafe who are looking at vouching as a way of proving and establishing a digital identity where identity documentation may be lacking. And we then go into things like how does that get recognized? Does that get the same regulatory recognition required in order for an identity bootstrap that way to be able to do things like open bank accounts and things like that?
We see oftentimes in the US, the Better Identity Coalition, for example, is doing a lot of work in trying to highlight the fact that there are a lot of people who don't have documentation because they've become homeless. They've lost the documentation in a fire. Oftentimes you don't have those kinds of proofs. How do you support those scenarios? And you want them to be onboarded. So you do have to create multiple pathways, multiple options, and that is both technological, it is standards, but it is also regulatory and you need to accommodate for that as well.
We need to look at things like not make assumptions around the fact that you have one user, one device. There are many people who share devices. You have often in many areas, you have one device per family, or you may have a device shared in a refugee camp and things like that. All of these are considerations that we need to build into this infrastructure as we're defining it in a way, as Torsten elegantly put it, so we're not discriminating against a population. It doesn't really matter whether it's age or financial or where you are in the world.
These are all important aspects that we need to define. Just to follow up on that, I'd like to ask a question. I know that there are more questions in the chat from the audience, so we will get to those. But you already briefly mentioned what I'm going to ask you, but even though you are an outsider in this discussion, since you're based in the US, and due to the geopolitics and all the buzz around the topic of digital certainty, would you say that Europe is building a model that is exportable, or is uniquely European from your perspective?
If you go back to, I think, the point I made at the very beginning, which is that this isn't just about technical architecture, but it's also about things like societal values and regulatory controls, legal controls, etc. I think there's a lot of what I see from a Fidel Alliance perspective and other areas, there's a lot of countries around the world that are looking at the EU model as a model. So they are looking at what's happening in the EU and saying that we want that, we want to adopt that. But societal norms play a huge role in how these things play out.
So if you see, for example, the explosion in digital credentials in Asia, especially in places like Japan, where there is a high degree of trust in government, you kind of see a different architecture being put in place regarding how these things are being brought to society. If you look at, for example, what India did with Aadhaar, a very different model, how they're doing that and how they're going about that, compared to MyNumberCard, but also compared to what the EU is doing. When you look at the US, there is no equivalent.
MDL is happening in 50 different ways across the country, and there's a huge effort to try and rationalize that. And because obviously, as we know, interoperability and cross-jurisdiction interoperability is a critical element to solve in order for this to mature. So I do think it is an exportable model that is happening in the EU. But what is very, very important is that anybody trying to export the model or anybody trying to import the model needs to not look at it purely from a technological perspective, but absolutely must think it through from a societal perspective.
Is that model that is being exported something that will work for our population? Will it work for our people? Because they will accept the sort of fundamental assumptions that are baked into that model.
If not, it may be the wrong thing for you. We've seen this a few times. We've seen countries try to adopt other models, and it has just failed in deployment. And you've got many millions wasted because they just couldn't make it work for the population because they ignored the human element. So I do think that it's sort of like a mixed bag. It is definitely exportable, but not to everybody. It definitely has to be fit for purpose.
Yeah, I would like to add that. I mean, observe what we're doing, learn from it, and then consider what you're going to adopt. That would be my message to other jurisdictions. And I would also like to point out that even across the member states, the implementation of the overall thing will look differently. And this is a good thing because IDAS caters for the cultural differences among the different EU member states, and they are very different culturally. So we don't even need to go across the jurisdiction European Union.
The fact that every member state has the ability to build what is appropriate for the country or the nation makes a lot of sense from my perspective. I mean, we are talking with a lot of other projects across the European Union. It's really amazing to see how much differences there are, even though we have one regulatory and technical framework. And so the differentiation between what is presented from the wallet and how things are being provided into the wallet is very important. So you made the argument of how identification works, for example, Michel. Absolutely.
It's a big difference, especially between continental Europe and I would say UK, US, or Australia, for example. And I think that's going to be, that works completely differently. And that's okay. But in the end, we can use similar technical or the same technical standards. And we can, for example, agree on a legal basis, on a regulatory basis, for example, to also mutually accept the identification credentials that are produced by those processes. I think this is something we should aim for to really achieve global interoperability. I had a question today at a conference.
I mean, the question was, it's cool that we have that thing in the European Union. But what if I would like to use my identity credential with a Japanese company? Because under the EU regulation, every relying party for an EU-DI wallet must be registered in the EU.
Well, okay, perhaps we need to find a solution that goes beyond what is right now in the European Union. We have to learn, but in the end, we need to achieve something that works interoperably across the globe. It does not mean that all the solutions need to be exactly a duplication or replication of what we're going to do here in the EU.
Yeah, and so one of the things that the FIDO Alliance did last year was launch our digital credentials initiative. And we have our digital credentials working group working to try and address what the study group we previously had identified as gaps in the model. And the key elements that came out of it, we started off with one idea, which is one key element is wallet certification. Because as Rosa mentioned, even though it's the EU, each state has its own cultural and technical requirements. They're establishing that thing.
Each state is responsible for their own certification, but it has to be subject to a EU-wide certification or meet the requirements. And then you have to go certification. As Rosa mentioned, you don't want to stay within the EU. You want to be able to take that same identity wallet and use it in other locations as you travel, as you maybe move for business, or you do work there. So you want that global interoperability. So defining wallet certification was one of the key elements we identified as a way of helping create a baseline, which is what that working group is working on.
But one of the other things that very quickly emerged as we started going into this discussion was what Rosa mentioned, the concept of verifier authentication scalability. Because in this ecosystem, you might have a few hundred wallets. You might have thousands of issuers. You're going to have millions and millions of verifiers. And there is both technical as well as regulatory requirements around who can be a verifier, what data they can request.
In order to go back to the idea of how does this ecosystem scale and thrive, you cannot create the barrier of every verifier having this really high bar that they need to cross, where they need to be registered as a legal entity in every single jurisdiction where they're going to be doing business. That is never going to work. The bookstore, the amazing bookstore in Spain where I can buy real books, I should be able to buy books from there as a citizen in Germany without having to worry about what do I have to do in order to get my package delivered.
And that bookstore has to be registered in Germany in order to be able to ship to me. We don't want those barriers in place for this ecosystem to thrive.
So, that is a new work stream that got identified very quickly and has been getting huge requests for activity there. And the DC Working Group has been focusing on that because of this exact issue. It is about unlocking value for the verifiers, the reliant parties, so that they can actually take advantage of the way decentralized identity will enable business, enable cross-border business, cross-jurisdiction business.
Thank you, Nishant. I'm aware that we have 10 minutes left and I still see some questions in the chat.
Maybe, Hank, maybe you could answer this one. The question is, how do you see the role of the new regulation proposal of EU business wallet and the possibility to identify legal person representatives and their powers of representation to accelerate ecosystem growth across the EU?
Yeah, I think actually that is economically much more interesting than the individual citizen. Because these things of being able to very quickly authenticate a business across Europe fits in so many other regulations. And there are a lot of know-your-business regulations. There is the DEC7 regulation that, at least here in the Netherlands, is translated into saying that if you're on an online marketplace and if you sell above a certain amount, then you need to be identified. Who are you? That also goes for small, medium-sized enterprises.
So this whole business wallet development, I think, will tie directly into that. Being able to identify an Italian company that I'm doing business with or a French company that is, I don't know, sending me a couple of crates of wine or cheese, also reduces fraud risk in those transactions.
Of course, it has different challenges on who oversees that wallet and what things go wrong there. But I think it's kind of the business addition to the wallet solution stack. And if you look at the economies of B2B activity, I think that's financially very much larger than individual interactions. Although if you look at the EIDAS and one of the recitals stating about why we do this is also to allow our citizens free access to digital services.
So that's the addition to the focus on the human being in Europe and how can they navigate their online life with government-issued credentials, if that makes sense. I would like to have a perspective on that. So first of all, this new regulation is very early stage. So we don't know where we're going to land. And I would like to differentiate between the ability to identify an organization and the representatives and the wallet. And I would like to see this kind of credentials already in the UDI wallet because there's a need. And I don't see why we can't put that in the UDI wallet.
So this is one of the top use cases that we have on our list. So identification of organizations, identification of people that are allowed to represent is super crucial. For the ecosystem, we already need that for the relying party authentication. So we're setting up an infrastructure for that and we can't wait for the business wallet regulation to be published. So let's see how this regulation evolves. But conceptually, I really would like to keep that separate. Identification of organizations, which is more about attestations, attestation of attributes from my perspective.
And the wallet functionality where I still need to be convinced that this is really something we need. Yeah, because that also ties into representation. So I can represent the company. I can also represent a relative that I'm taking care of. Absolutely. That's something we have in mind for stage two for next year, for example. Very important to really address the use case. Nice. Yeah. Mindful of the time. We have just six more minutes and there's still some questions. The chat is very engaged. They're even having their own conversation there.
But Nishan, there was a user asking if you could maybe share where they can find the study on the success in digital credentials in Japan. Maybe if you happen to know the name, maybe you can write it on the chat.
Otherwise, I suggest that the user reaches out to Nishan separately. Another question for Torsten. I don't know how much you can say now, but the user is asking, how will January look like next year? What will happen or could happen or not happen? I hope we will have nice weather and can start a great 2027. I can tell you from a German perspective, we will have a national wallet live and an ecosystem live. And that wallet will have a core feature set that we believe is the core feature set of the wallet. It's going to be the PID and the electronic attestation attributes.
We decided in Germany to postpone implementation of the other functions like pseudonyms, QAS and so on to a second stage. Because we believe the complexity to build all of that in the given timeframe and the given complexity is not feasible. So the current status right now is that technical standards are not yet finalized, even for core elements of the EODR wallet. So we're working on closing that gap and also finalizing the implementing it. And once we have done that, we also need to do a security assessment of the wallet. So we are pretty sure that we will go live with that wallet.
It will be secure, it will be privacy preserving, we will have use cases. And then we will incrementally work towards getting all the other functions implemented. That's our approach. So we are looking onto creation of value, which is more important to us than hitting all the regulatory requirements in the first stage. That makes sense. Thank you for sharing that perspective. I would like to remind you that we will have this conversation in Berlin in May at EIC. We will be having a lot of sessions on the topic and the speakers will be attending.
So given that we have just a few minutes, we can just share the last remarks, maybe just your main takeaways. And maybe we can start first with Nishant, then Hank, and then with Torsten.
Yeah, so as I mentioned, looking forward to continuing the conversation in Berlin at EIC. Definitely want to continue to push the idea that because trust takes time to establish, to Torsten's point, a lot of this is going to be iterative. But one key element here is making sure that we don't let perfection be the enemy of good. This is going to gradually build over time. And as we build through the process, we will see advantages accrue.
As we build out the infrastructure, as we build out the capabilities, we will start to see the cost of implementing these for everybody start to go down and that's when you'll start to see more and more adoption. So it's not that it has to be born fully formed on day one. It will grow and it will take time. And for a while, we will be continuing to deal with this tension, this push and pull between the pre versus the post, if you will. But I do think the amount of collaboration and work that is happening in this space is amazing and inspiring.
And I do think that means we are going to be able to solve many of the problems that folks have been waiting for a long time. Like anything, it's going to be a roller coaster, but it'll be fun and it'll definitely get there.
Yeah, I think I'd like to add there that identity is foundational to life. In all our interactions, we bring our identity along. Now we're building something in the digital world that is going to touch everybody's life in multiple aspects. What I take away from this conversation is that it's good to have these conversations, to not think about this from just a Dutch perspective or an academic perspective, not to think of it just from a technological perspective or just a societal. All these things are related together. So I really love these conversations.
I think we should have them more also in Berlin. To kind of unpick this and make sure that whatever we end up with is better than what we have right now. But especially that it has a certain level of robustness. Because things will get pushed over and bad things will happen. That is life. And I think the biggest part is how you deal with the mistakes and not just the happy flow. Because the happy flow is very nice. And as I said beforehand, all those weird edge cases might be central to our humanity. That's what comes up when we have these type of more broad conversations.
And then go back to our happy little projects to make this thing work. Yeah, that resonates well with me. First of all, thank you for this very inspiring conversation. I'm really looking forward to continue that in Berlin. You said some very important things, Henk. The question of that panel was what's the difference between the concept, right? Going from conceptual to really rolling it out. And that's the big difference, right? You need to really double click on all those things that people typically ignore. Like lifecycle management and all that stuff, right? So it's going to be serious.
And for us, it's going to be really tenuous this year. And I'm looking forward to continuing this discussion with you guys in Berlin. Thank you very much for your insights. It was a very fruitful conversation. So as always, if you guys have any questions for the speakers, just reach out to them. And see you all in Berlin. Thank you.
See All Locations
See All Locations