Paper 21 · AI, Identity, Medical

The Identity Paradox

Identity sovereignty operationalises citizenship.

Europe has written the best-designed digital identity law in the world, and the architecture being built to deliver it cannot satisfy the regulation.

The European Digital Identity Regulation (EU) 2024/1183 mandates unlinkability: the property that a citizen using their wallet at a bank, a doctor and a public service generates no observable connection between those uses, even to the wallet provider. The Architecture Reference Framework v1.6, which defines the technical specification, ships baseline cryptographic primitives that demonstrably violate this property. The zero-knowledge library most member states are integrating is owned by Google. Unobservability stops at the platform layer.

Europe is closer than it has ever been to a genuinely sovereign citizen identity infrastructure. The law is written and the political fight has been won. The architectural gap between the regulation and the implementation is the work of the next twelve to eighteen months. Closing it would deliver the only verifiably sovereign citizen identity stack in the world.

“Every time an App or website asks us to create a new digital identity or to easily log on via a big platform, we have no idea what happens to our data in reality.”

— Ursula von der Leyen, State of the Union address, 16 September 2020

Six years on, the answer to that question is being built. The European Digital Identity Regulation entered into force on 20 May 2024. By the end of 2026, every member state must offer its citizens a certified digital identity wallet. By the end of 2027, banks, telecoms, healthcare providers, transport operators, social media platforms, and search engines must accept the wallet as a valid means of authentication. By 2030, the Commission targets eighty per cent of European citizens using it. The Age Verification Blueprint launched on 15 April 2026. The digital euro pilot begins in the second half of 2027, and the identity layer it depends on is the wallet. A continental-scale sovereign digital identity infrastructure is twenty months from operational reality.

This is a European achievement. The regulation that underpins it (Regulation (EU) 2024/1183) is the best-designed digital identity law in the world. Europe did not stumble into it. Thirty-nine civil society organisations, three hundred scientists, the European Parliament’s ITRE committee, Mozilla, Privacy International, epicenter.works, the Electronic Frontier Foundation, the Internet Society, and the European Data Protection Supervisor fought a two-year adversarial battle to make it what it is. The fight removed a unique persistent identifier that would have made eIDAS 2 architecturally closer to India’s Aadhaar than to what Europe claims to stand for. The fight embedded pseudonymity, unlinkability, unobservability, and selective disclosure into the regulation’s operative articles. The fight is why the law does what the law does.

And yet. The regulation mandates unlinkability as a property the wallet must deliver. The baseline technical architecture being built to deliver it cannot, as a matter of formal cryptographic argument, satisfy the regulation’s own requirement. The wallet-provider unobservability clause binds the wallet provider; it does not reach the smartphone operating system, the Secure Element firmware, the attestation chain, or the app store. Those layers Europe does not control and cannot, under current architecture, regulate into compliance. The zero-knowledge cryptographic library being integrated into the EU reference implementation is authored by Google. The certificate authorities whose signatures give the wallet’s transport security its trust anchor are concentrated in American jurisdiction.

This is the paradox. Europe has written law that refuses platform capture of citizen identity. The architecture being assembled to deliver that law sits on infrastructure Europe does not own. The more successfully the regulation lands, the more embedded the American substrate becomes in the digital layer that underwrites European sovereignty. Success at the legal layer threatens to entrench dependency at the layer beneath.

The gap is examined in what follows. Europe is closer than it has ever been to a sovereign identity infrastructure, and further than the marketing acknowledges. The technical and regulatory gaps standing between what the law promises and what the architecture will deliver are nameable. Closing them is the work of the next twelve to eighteen months. The most important fact about this gap is that it is not permanent.

I. The three models Europe was choosing between

National digital identity at scale is not new. Three models exist in the world today. Each of them was, at some point in the last decade, a live possibility for Europe. The question eIDAS 2 answers is which of the three Europe would become, and which of them Europe was refusing.

Aadhaar

India’s Aadhaar is the largest biometric identity system in human history. One and a half billion enrollees, ninety per cent of India’s population. A twelve-digit unique identifier linked to ten fingerprints, two iris scans, and a face photograph in a centralised Central Identities Data Repository. Eighty million authentications every day.

Aadhaar was designed from 2009 under Nandan Nilekani of Infosys, backed by the Bill and Melinda Gates Foundation and the World Bank, and launched in 2010. In [2]its original legal framing, participation was voluntary. In practice, within five years, Aadhaar was linked to tax returns, welfare benefits, mobile phone contracts, bank accounts, and school admissions.

The Indian Supreme Court struck down Section 57 of the Aadhaar Act in 2018 to prevent private companies from demanding the identifier. In January 2025, the Indian government reopened the infrastructure to select private companies under a regulatory sandbox.[3]

Aadhaar’s defenders point to its scale and its genuine benefits for welfare delivery.

Its critics point to 360-degree profiling that is architecturally trivial when every transaction runs against a single identifier, to the multiple documented data leaks (two hundred government websites exposed Aadhaar data in 2018), and to the structural impossibility of exit once the system is the precondition for social existence.

The model is centralised, biometric-first, persistent-identifier-based, and, increasingly, open to private commercial exploitation of public identity infrastructure.

The Chinese system

China’s digital identity infrastructure is less a single system than a patchwork of national and provincial schemes that coordinate state identity, financial behaviour, social conduct, and surveillance. Social credit scores integrate tax compliance, court judgments, social media activity, and purchasing patterns.

Low scores produce operational consequences: bans from high-speed rail and flights, restrictions on government employment, limits on children’s admission to elite schools. The architecture’s design premise is behavioural governance. The state and the platforms are not adversaries; they are integrated.

There is no meaningful distinction between public infrastructure and private surveillance because both operate under unified state direction.

The American platform model

The United States never built a national digital identity system. In its absence, identity at internet scale became a private-sector product. Sign in with Google, Sign in with Apple, Log in with Facebook, Microsoft Account. Identity-as-login, monetised through the advertising and data-aggregation businesses that surround it. Every authentication is a data point. Every data point feeds profiles.

Every profile is an input to advertising targeting, behavioural prediction, and, where law permits, subpoena response. The user gets convenience; the platform gets the data; the state gets subpoena access on American terms and under American jurisdiction.

Von der Leyen’s 2020 complaint was about this model. Every app, every website, every login via a big platform: Europeans had no idea what happened to their data. The honest answer, then and now, is that the data was being used for the purposes the platforms found commercially useful, within whatever constraints American law and European regulation could impose from outside the infrastructure.

The third way

Europe’s response, assembled under the eIDAS 2 banner, is meant to be none of the three. Not centralised like Aadhaar: the wallet stores credentials on the user’s device, there is no Central Identities Data Repository, and the regulation explicitly prohibits a unique persistent identifier.

Not behavioural like the Chinese system: the wallet’s data protection cockpit surfaces every data request to the user, pseudonymity is a legal right, and the use of the wallet is voluntary.

Not platform-captured like the American model: the wallet is issued by member states or by private providers certified under European law, its acceptance is mandatory for regulated sectors, and its architectural guarantees are enshrined in regulation rather than terms of service.

This is the third-way claim, the phrase borrowed deliberately from the political-philosophical tradition rather than from counting alternatives. It is testable. Federated rather than centralised: testable. User-controlled rather than state-controlled: testable. Selective disclosure by default: testable. No persistent identifier: testable. Unlinkability at the cryptographic layer: testable.

Unobservability at the wallet provider layer: testable. If all of these hold in practice, Europe has built something the world has not seen at scale before.

Whether they all hold is the question that follows. The answer, as we will see, is: most of them do, and the ones that don’t are the ones that matter most.

II. Why Europe is building this

What Europe is building toward

Finishing the single market. Freedom of movement has been a European legal right since 1957 and a lived practical friction ever since.

A citizen who moves from Berlin to Madrid for a job currently re-proves identity at the bank, the tax agency, the healthcare system, the landlord, the school, the utility companies:

each against separate national infrastructure, each with different document formats, each requiring some combination of in-person appearances and certified translations. eIDAS 1’s own evidence showed that only fourteen per cent of European public services accepted cross-border authentication.

A hundred and fifty million Europeans had no access to strong cross-border authentication at all. The single market for services, promised at Maastricht, never arrived at the identity layer. eIDAS 2 is the first serious attempt to finish it.

A sovereign substrate for European regulation. GDPR. The Digital Services Act. The Digital Markets Act. The AI Act. PSD3. The Anti-Money Laundering Regulation. The digital euro. Every one of these depends on reliable identity verification to operate.

Without a common substrate, each regulated entity reaches for whatever identity tooling is commercially available: today that means American platform identity or bespoke verification vendors. The result is that European law exists on paper and meets American infrastructure at the point of enforcement. eIDAS 2 is the identity floor on which all of the other regulations can finally stand.

This is a structural achievement. For the first time, Europe will have a verification layer that makes regulated digital life actually regulable at continental scale.

The democratisation of legal-grade digital action. A provision in the regulation that almost nobody talks about: Recital 20 establishes that qualified electronic signatures must be free of charge to all natural persons for non-professional purposes.

Today, a qualified electronic signature (the only digital signature with the same legal effect as a handwritten one under EU law) costs a European citizen between fifty and a hundred euros a year and typically requires a hardware token or smart card. QES is a tool for lawyers, company directors, and estate executors.

In 2027, every European will have cryptographically binding signature capability on their phone, issued through the wallet, free at the point of use. Rental agreements, employment contracts, property transactions, powers of attorney, advance healthcare directives, consent forms: any of these becomes a legally binding digital action accessible to everyone.

This is the kind of public civic infrastructure Europe has historically been good at: universal suffrage, universal healthcare, universal education. It is now being extended into digital life, almost without public notice.

What Europe is refusing

The three alternative models are not symmetric in their consequences for Europe. Each of them would mean something specific.

An Aadhaar-shaped architecture would centralise state power over citizens in ways European constitutional traditions specifically and repeatedly reject. The 1983 German Census Decision established a constitutional right to informational self-determination precisely because German constitutional jurisprudence remembered what centralised identity registers had enabled forty years earlier.

The French CNIL tradition, the 1995 Data Protection Directive, GDPR: each of these exists because Europe’s twentieth-century memory of state identity systems is that they are dangerous in exactly the way Aadhaar is dangerous. They are architecturally available for tyranny, even if not inherently tyrannical.

That the original 2021 eIDAS 2 proposal contained a unique persistent identifier (and how that identifier was removed) is the subject of Section IV.

But the American platform-captured model is the one Europe is defaulting to if the wallet fails to land. This is the one most easily mistaken for neutral because it is already here. Sign in with Google takes two seconds, works everywhere, is free at the point of use. The substrate is monetisation, profile aggregation, and cross-site behavioural inference.

Every European sign-in is a data point sold back into advertising targeting or held in reserve. The strategic consequences cascade. An identity layer captured by external platforms means every identity-dependent European regulation has its enforcement filtered through American corporate infrastructure.

The Ireland-as-GDPR-chokepoint pattern (where enforcement against Meta, Google, Apple, TikTok stalls for years in a single member state’s supervisory bottleneck) is not a bug of jurisdiction. It is a feature of the infrastructure. When the identity layer is captured, every regulation downstream inherits the capture. European law exists; European enforcement stops at the platform boundary.

The external political environment of 2025-2026 sharpened this from an abstract worry into a concrete threat model. In August 2025, a French judge serving on the International Criminal Court, Nicolas Guillou, was placed under United States sanctions along with several colleagues.

The sanctions reached beyond the judges to threaten financial institutions that processed their transactions, visa services that issued their documents, and platforms that hosted their communications. This is not a hypothetical scenario about what a hostile American administration could do with infrastructure leverage. It is documented practice.

The capacity to weaponise identity infrastructure against Europeans (to restrict sitting judges from payment systems, from authentication-gated services, from platform-hosted communications) was demonstrated on European nationals in the exercise of European judicial duties.

Greenland, earlier in 2025, illustrated the other end of the same spectrum: an American administration floating territorial acquisition of European territory through economic and political pressure. These are not the reasons Europe began building eIDAS 2, but they are why the completion of the project has stopped feeling abstract.

The point is not that any particular American administration will weaponise digital infrastructure against Europe. The point is that any American administration can, and that Europe has to decide, architecturally and not just rhetorically, whether to leave itself exposed to that possibility.

Identity is where that decision lives most sharply, because identity underwrites every downstream digital interaction.

This is the default Europe is refusing. A continent-scale regulatory architecture that depends, at the operational layer, on the goodwill of companies it cannot regulate at the infrastructure layer and on the forbearance of a government whose alignment with European interests is no longer assumable.

The EUDI wallet is Europe’s mechanism for refusing that default. Whether the mechanism works is the subject of what follows.

III. What the regulation mandates

The regulation does ten things. Five of them are named in Commission marketing and on the Digital Strategy website. Five of them are not stated publicly but follow directly from the regulation’s operative articles and from the ecosystem being assembled around them.

Read together, they form a coherent strategic architecture: an identity layer that simultaneously serves citizens, underwrites the single market, enforces European law, and claims territory back from the platforms.

User-facing control

Citizens control their identity data. The wallet implements selective disclosure: a user can prove they are over eighteen without revealing their date of birth, prove they hold a valid driver’s licence without revealing their name, prove residence in a particular member state without revealing their address.

A mandatory in-wallet data protection cockpit records every data request, every credential shared, and every relying party that received information, and lets users exercise their GDPR rights with any of those relying parties through the wallet itself. Article 5(2) establishes a freely chosen pseudonym as a right whenever no legal identification is required.

The wallet is voluntary: public and private bodies must accept it but cannot refuse service to citizens who don’t use it. Credentials are stored on the user’s device; no single compromise reveals millions of profiles. The reference wallet is open-source; anyone can inspect it.

This package is architecturally distinct from anything deployed at comparable scale anywhere else in the world. Aadhaar offers none of it. The American platform model offers the opposite of all of it. The Chinese system is actively designed to prevent all of it.

The fact that Europe’s wallet has these features as mandatory properties rather than optional goodwill gestures is the single most important design choice in the regulation.

Integration

Cross-border interoperability is the regulation’s most unambiguous win. Every certified EUDI wallet must work in every member state. A Spanish wallet presenting an Italian-issued credential to a German bank is a legally and technically defined flow.

Mandatory acceptance applies across all regulated sectors (banking, insurance, telecommunications, transport, healthcare, energy) and to all Very Large Online Platforms under the DSA.

Where eIDAS 1 produced twenty-seven incompatible national implementations (the Belgian itsme wallet does not talk to the French FranceConnect which does not talk to the German eID) eIDAS 2 mandates a single Architecture Reference Framework, common technical specifications, and Europe-wide certification.

The fragmentation that made eIDAS 1 a political success and an operational failure is structurally prevented. Four large-scale pilots plus the WE BUILD consortium have tested the architecture across every member state. The substrate is stress-tested.

Public service modernisation sits on this substrate. The Once-Only Technical System, operational since December 2023, lets one public authority request documentation directly from another on the citizen’s behalf, eliminating repeated submissions across member states. Over two hundred European Qualified Trust Service Providers are certified to issue qualified signatures, seals, and attestations.

The wallet itself functions as a Qualified Signature Creation Device: the private key for a citizen’s QES lives in the phone’s Secure Element, protected by biometric authentication. Recital 20’s free-QES provision democratises a legal instrument previously available only to professionals, putting cryptographically binding signature capability in every European’s pocket.

Strategic architecture

The regulation’s most consequential provisions are the ones that never appear in citizen-facing communications. Article 5(7) requires providers of Very Large Online Platforms under the DSA (every major US-owned consumer platform, from Google and Meta to Amazon and Apple) to accept the wallet as a means of authentication.

Baker McKenzie’s plain-English reading: since every VLOP uses user accounts, the requirement applies to all of them. Article 5f extends the same obligation to banks, telecoms, insurers, healthcare, and transport wherever Strong Customer Authentication is legally required.

This is an enforcement substrate for European digital regulation. The DSA’s Article 28 obligation to protect minors converges on age verification. The European Age Verification Blueprint announced on 15 April 2026, piloted in seven member states, uses zero-knowledge proofs to confirm age thresholds without revealing date of birth.

On 26 March 2026, the Commission announced preliminary findings under the DSA against four pornography platforms for failing to protect minors. The enforcement teeth that were missing under GDPR are being assembled through the eIDAS 2 architecture.

Strong Customer Authentication under PSD3, AML KYC under AMLR, and GDPR rights operationalised through the Data Protection Cockpit all flow through the same substrate.

Alongside enforcement: strategic autonomy. The wallet is the mechanism by which Europe attempts to displace Sign in with Apple, Sign in with Google, Log in with Facebook, and Microsoft Entra from the European digital economy. The regulation is carefully non-exclusionary.

It works by creating a legally mandated alternative that regulated entities cannot refuse, and by shifting the default behaviour of Europeans toward a European-issued credential. The Apple and Google identity layers become one option among several, rather than the load-bearing infrastructure for European login.

The Brussels Effect potential is present but modest. ISO/IEC 18013-5, the mobile driving licence standard the wallet uses, is already being adopted by twelve US state mDL programmes including Arizona, California, and Maryland. OpenID4VP and OpenID4VCI, the presentation and issuance protocols, are becoming global defaults.

Australia’s Digital ID Act 2024 tracks eIDAS 2 at several architectural levels. The UK, post-Brexit, has chosen to build separately: a quieter data point about the limits of Brussels Effect gravity in the digital identity domain.[4]

And finally: industrial anchor customer. Every EUDI wallet requires a certified Secure Element at Common Criteria EAL4+. NXP Semiconductors (Netherlands), Infineon (Germany), and STMicroelectronics (France-Italy) dominate the European Secure Element supply chain; Thales, IDEMIA, Utimaco, and Giesecke+Devrient supply the surrounding trust infrastructure.

The Chips Act’s forty-three billion euro investment toward European semiconductor sovereignty needs anchor customers of this scale. The wallet at four hundred million units plus refresh cycles is that anchor: sovereign demand creating sovereign supply, if the demand holds.[5]

Ten goals, assembled into a single regulatory instrument. Each of them is defensible in its own right. Read together, they form the most ambitious piece of digital sovereignty legislation any major economy has passed. The question is whether the architecture being built to deliver them actually delivers them.

IV. The fight that won the law

The regulation’s privacy architecture was not gifted from Brussels. It was won in a two-year political fight that could have gone the other way, and the outcome matters because it determines whether what follows reads as critique of a half-measure or completion of a real achievement.

On 3 June 2021, the Commission published its original proposal for what would become eIDAS 2. Embedded in the text was a unique persistent identifier: a single number assigned to each European citizen, used across all wallet interactions, enabling linkage of every authentication event by every relying party across the entire European digital economy.

The proposal was marketed as privacy-preserving. The architecture it specified was not. It was, structurally, closer to Aadhaar than to any recognisably European privacy tradition.[6]

In December 2022, the Council of the European Union adopted its General Approach. The unique persistent identifier survived.

Epicenter.works, a small Austrian civil liberties organisation that had been tracking the proposal since the first draft, issued a warning that month: the Council text would “allow the tracking and profiling of user behaviour across interactions with different companies and government entities.

Every user transaction is centrally observable for the member state, thereby creating a panoptical view spanning across all areas of life.” The warning was not hyperbole. It was a precise description of what the proposal would have built.[7]

What happened next is worth reading slowly. Thirty-nine civil society organisations, academics, and independent experts signed an open letter to the European Parliament in early 2023. Mozilla, the Electronic Frontier Foundation, Privacy International, European Digital Rights, the Internet Society, Access Now, and two dozen smaller organisations.

A separate open letter from more than three hundred scientists and cryptographers attacked Article 45’s provisions on website certificates that would have enabled mass interception of encrypted traffic. The European Parliament’s ITRE committee, under rapporteur Romana Jerković, took the concerns seriously.

Inside the Commission, the Directorate-General for Justice pushed back against the Directorate-General for Communications Networks. Inside member state governments, data protection authorities argued against interior ministries.[8]

On 28 June 2023, in the political trilogue between Parliament, Council, and Commission, the unique persistent identifier was removed. Epicenter.works’ response on the day was simple and unusually plain: “The strong opposition to a unique and persistent identifier has been successful: the serial number for human beings has been removed in the political trilogue on 28.06.

This is a huge win.”[9]

The final political trilogue on 8 November 2023 added the rest of the architecture. Article 5(2) established a right to freely chosen pseudonyms whenever no legal identification requirement applies. Article 5a.16 mandated unlinkability as a property the wallet must deliver.

Recital 11c bound wallet providers to unobservability: they must not collect data about user transactions or have insight into them. Recital 14 directed member states to integrate privacy-preserving technologies including zero-knowledge proofs. Article 12b.3 established the right to pseudonymity and required the separation of wallet data from all other data held by the wallet provider.

The data protection cockpit became mandatory. The EU Digital Identity Framework Board was established to coordinate enforcement across member states.[10]

Some things were lost in the trilogue. Mandatory GDPR certification of wallets did not survive. The EDIFB’s enforcement powers ended up weaker than GDPR’s European Data Protection Board.

Penalties for relying parties that ignore their obligations were capped at five million euros or one per cent of global turnover: meaningful but weaker than GDPR’s four per cent or the Digital Markets Act’s ten per cent. The Article 45 browser-certificate provisions, which would have enabled mass interception, were neutralised rather than cleanly removed. The architecture is not perfect.

It is, however, what Europe says it is: a digital identity regulation that rejects centralised tracking, rejects persistent identifiers, and treats citizen control as a structural property rather than a compliance aspiration.

The regulation is not a Commission bureaucratic exercise. It is the output of a functioning European democratic process, with civil society playing the role civil society is supposed to play, legislators taking the input seriously, and the final text embedding the values that Europe claims to stand for.

The people who did this work, at epicenter.works, at EDRi, at Mozilla, at the Internet Society, on Jerković’s committee, in Ann Cavoukian-style academic privacy engineering, deserve to be named and credited. They did something that does not often happen in European legislative processes. They made the law better than it would otherwise have been.

And that is why what comes next matters. The regulation they won mandates unlinkability, pseudonymity, unobservability, and selective disclosure as legally binding requirements. The architecture being assembled to deliver those requirements (the Architecture Reference Framework, the baseline cryptographic primitives, the platform dependencies) does not yet deliver them.

That gap is the subject of the next section. It is a report on how close the delivery has come to matching what the regulation promised, and what still has to happen for the match to hold.

V. The Gap

The regulation mandates unlinkability. The architecture being built does not deliver it. The regulation mandates unobservability at the wallet provider layer. The architecture cannot reach the operating-system layer where observation actually happens. The regulation mandates selective disclosure through privacy-preserving technologies.

The reference implementation integrates a zero-knowledge library authored by Google. These are not minor implementation gaps. They are a structural mismatch between what European law requires and what the technical system under construction can provide.

The gap is the distance between the democratically agreed legal text and the technical architecture being built to implement it. The Spanish Data Protection Agency called out “significant gaps” between the ARF and the regulation in January 2025.

Epicenter.works wrote in November 2023 that the ARF “couldn’t be further away from the democratically agreed legal text.”

A cryptographers’ open letter on the ARF GitHub discussion in June 2024 stated that the proposed architecture “fall[s] short of the privacy requirements that were explicitly defined after extensive debate in the Digital Identity regulation.”

A 2024 paper by Baum et al. argues formally that the baseline implementation violates the eIDAS regulation. The pattern is visible from multiple vantage points.[11]

The gap has three concrete instances and one meta-instance. Taken together, they describe a structural relationship: Europe is sovereign at the layer it regulates and dependent at the layer underneath. The regulation reaches as far as the wallet application. The infrastructure the wallet runs on is American.

The ARF-regulation gap

The Architecture Reference Framework is the technical specification that translates the regulation’s legal requirements into implementable form. As of early 2026, the ARF is at version 1.6 and still iterating. In multiple specific places, it does not match what it implements. The ARF treats unlinkability as achievable through batched single-use credentials.

The regulation treats unlinkability as a property that must hold against all feasible adversaries, including the issuer. These are different concepts, and the difference matters for whether the wallet’s legally mandated properties are delivered in practice. This is the meta-instance: a structural divergence between the specification document and the regulation it is meant to implement.

The failure is not in any specific cryptographic primitive.

Gap 1: Baseline cryptography formally violates the regulation

Unlinkability means something specific. If a European presents their wallet to a nightclub bouncer, then the next day to a pharmacist, then the next day to their bank, no combination of those three parties (even working together, even under legal compulsion) should be able to reconstruct that these were the same person. The regulation says this must hold. The architecture being built does not.

The wallet’s baseline credential formats are SD-JWT (Selectively Disclosable JSON Web Tokens with salted hashes) and ISO/IEC 18013-5 mobile Driver’s Licence with Mobile Security Object. Both are established, interoperable, cryptographically sound for their intended purposes. Neither delivers unlinkability in the sense the regulation requires.

They achieve a weak form of it through batched single-use credentials: the issuer produces a batch of signed credentials, each usable once, and the user presents a fresh credential for each transaction. Verifiers cannot link transactions because the credentials differ. But the issuer knows which batch went to which user.

If the issuer colludes with a verifier (or is compelled by a court to produce records) the linkage is trivial. The user is re-identified. The bouncer, the pharmacist, and the bank, working through the issuer, can reconstruct the trail.

In a 2024 paper submitted to the eIDAS Expert Group, Baum, Heilman, Mohamad, Nielsen, and Rosing argue formally that this architecture violates the eIDAS regulation’s own unlinkability requirement. The regulation’s language, they argue, does not permit issuer-colluding re-identification.

If the adversary model is “any feasible coalition of relying parties and issuers,” the baseline implementation fails. This is a formal cryptographic argument with reference to the regulation’s operative text. It has not been rebutted in the academic or policy literature.[12]

The fix is known. BBS+ signatures (and the related BBS# proposal) support issuer-unlinkable credentials: the issuer itself cannot link presentations to issued credentials. BBS+ is an established cryptographic primitive with open-source implementations, W3C and IETF standardisation tracks, and prior art going back to 2004.

A cryptographers’ open letter to the Commission in June 2024, signed by leading figures in cryptographic privacy research, recommended adopting BBS+ as the EUDI wallet’s primary credential format. The Commission’s response has been to keep SD-JWT and mDL as the baseline while noting Recital 14’s “should integrate” language for zero-knowledge proofs. The wording is “should integrate”, not “shall integrate”. The privacy architecture the regulation mandates remains optional at the cryptographic layer.[13]

Gap 2: The zero-knowledge library is Google’s

Recital 14’s nudge toward zero-knowledge proofs has been taken seriously in at least one respect: the EU reference implementation on GitHub contains a Swift library called `av-lib-ios-longfellow-zkp`. Longfellow is a zero-knowledge proof system named after the bridge outside Google’s Cambridge, Massachusetts office. It was authored at Google.

Google’s July 2025 announcement positioned Longfellow explicitly for EU adoption:

“The European Union’s eIDAS Regulation, set to take effect in 2026, encourages Member States to integrate privacy-enhancing technologies like ZKP into the European Digital Identity Wallet. With our commitment to making these ZKP tools [14]openly available, Member States can integrate this into their future EUDI Wallets, accelerating their development.”

The immediate technical problem is that Longfellow’s upstream Android implementation requires Google Play Services to operate.

The Amsterdam-based Dyne.org foundation has forked the library to produce a Google-free European build, and the TS13 technical specification under debate in early 2026 will determine whether the reference implementation mandates Google’s upstream, allows the Dyne fork, or supports a broader class of zero-knowledge systems.

The French and German delegations have pushed back against a Longfellow-exclusive approach. BBS+ and other European-rooted alternatives remain in play. The outcome is not decided.[15]

The deeper problem is more structural. The cryptographic primitive that would close Gap 1 (the primitive that would make the wallet’s unlinkability guarantee actually hold) is, in the current reference implementation, American code.

A European sovereign identity infrastructure’s most important privacy property would be delivered by a library authored in Silicon Valley and integrated through a CI/CD pipeline whose upstream Europe does not control. This is not a claim about Google’s intentions. Google has been a constructive participant in the standards process, and Longfellow is a good cryptographic system.

The claim is about the shape of the dependency. Europe’s sovereign privacy architecture depends, at the primitive layer, on what Silicon Valley chooses to make available and on the terms under which it is made available. That is a dependency by any other name.

Gap 3: Unobservability stops at the platform layer

Recital 11c of the regulation binds wallet providers: they must “ensure unobservability by not collecting data and not having insight into the transactions of the users of the Wallet.

This means that the providers should not be able to see the details of the transactions made by the user.” The wallet provider (whether a member state, a government-contracted private issuer, or a certified private wallet) cannot observe. This is a meaningful commitment that applies only to the wallet provider.

Every transaction the wallet performs passes through layers the wallet provider does not control. The operating system on the user’s phone (iOS or Android in ninety-nine per cent of cases) observes which applications are invoked, when, and in what sequence.

The Secure Element storing the wallet’s cryptographic keys is provisioned and ultimately managed by the phone’s manufacturer, which means Apple for iPhones and Google or Samsung for most Android devices. The attestation chain that proves the wallet is genuine (that it is a valid instance of a certified wallet, not a malicious impersonator) relies on root keys controlled by the phone manufacturer.

The NFC stack that handles proximity authentication is controlled by the OS. The network transport runs over TLS connections authenticated by certificate authorities, most of which are American or operate under American jurisdiction.

Think of what happens when a citizen in Madrid uses their wallet to prove their age at a pharmacy. Spanish law governs the transaction. A Spanish-certified wallet issued by the Spanish government runs on the user’s phone. The Spanish pharmacist sees only what the user consents to share. Unobservability holds, on the Spanish side.

On the other side: the iPhone’s operating system, written in Cupertino, registered the app launch. The Secure Element’s attestation, signed by Apple’s root keys, authenticated the wallet to the pharmacist’s reader. The TLS connection carrying the credential was authenticated by a certificate authority sitting in American jurisdiction. Apple does not sell this data. Apple does not need to.

The data sits on Apple’s servers, legally subject to whatever requests American authorities make of it under whatever legal framework happens to exist at the time. The wallet provider, as required, does not observe. The platform, entirely outside the regulation’s reach, does.

The cryptographic chain that binds a wallet credential to a specific certified wallet on a specific device rises through the Secure Element, the OS, the hardware attestation roots, the app store signatures, and the manufacturer’s public key infrastructure. Europe has regulated the wallet.

Europe has not regulated, and under current treaty competencies cannot straightforwardly regulate, the layers underneath. A user whose wallet provider cannot see their transactions is still observable through the phone’s telemetry, through the manufacturer’s update channels, through the app store’s install records, through the attestation chain’s verification traffic.

Europe’s strongest privacy guarantee, the one that most distinguishes the European model from the American platform model, is structurally incomplete. The sovereignty claim holds at the layer Europe regulates. It fails at the layer beneath.

The pattern

Three gaps, one meta-gap, one pattern.

The pattern is that Europe has, in each specific case, regulated what it can regulate (the wallet application, the wallet provider’s conduct, the relying party’s acceptance obligations) and relied on commercial or international cooperation for what it cannot regulate (the operating system, the Secure Element, the cryptographic primitives, the certificate authorities, the app store).

This is not a failure of European law.

European law has reached its current outer limit.

The ARF is closer to the regulation than the original June 2021 proposal was, and it will be closer still in version 1.8 than it is in 1.6. But the gap between the ARF’s best version and what the regulation requires is not closable by revising the ARF alone.

The closure requires either that Europe extend its regulatory reach into the platform layer, or that Europe build European alternatives to the platform layer, or that Europe negotiate binding cooperation from the platforms. None of these is easy.

All of them are possible.

In the five-position framework that runs through this series, eIDAS 2 has placed the identity layer at Position 2: European infrastructure operated by European providers, federated rather than centralised, with no entity in the chain subject to non-EU jurisdiction.

The infrastructure underneath that layer sits at Position 4: deployment control, operational management, and architectural choices concentrated outside European jurisdiction, with European components competing for supply contracts but not for control. The distance between the two positions is where the gap lives. Closing it is what the next two years of European digital policy have to accomplish.

VI. Why it matters now

The gap would matter if eIDAS 2 stood alone. It matters more because eIDAS 2 does not stand alone. The wallet is load-bearing for projects already in flight: the digital euro, Europe’s regulatory reach into US platforms, Europe’s claim to export sovereign digital norms, Europe’s industrial policy for silicon. Each of those projects inherits the gap and amplifies it.

The consequences compound in a specific direction: the closer eIDAS 2 comes to succeeding, the more embedded the dependency becomes in the layers built on top of it.

Platform displacement becomes re-encapsulation

The strategic goal of displacing Sign in with Apple and Sign in with Google from the European identity layer is real. The mechanism (mandatory acceptance of the wallet by VLOPs) is legally enforceable. The outcome may not be the displacement the marketing implies.

Apple, in the United States, launched digital ID in Apple Wallet in 2025, implementing ISO/IEC 18013-5 selective disclosure, passport chip reading, and face biometric verification. The system is live at two hundred and fifty TSA checkpoints. Apple’s technical implementation is, by several measures, ahead of the European reference wallet in user experience.

Google is a participant in the EU Digital Identity Wallet Consortium’s payments taskforce. The technical architectures are converging. Nothing in the eIDAS 2 regulation prevents Apple Wallet or Google Wallet from being recognised as a private wallet under Article 5a, subject to member state certification.

If they are (and there are commercial, political, and user-experience pressures that make this likely in some member states) the operational implementation of the European sovereign identity infrastructure sits inside American containers.[16]

This is not total platform capture. A credential issued by the Italian government, stored in Apple Wallet, presented to a German bank, governed by European regulation is more sovereign than Sign in with Apple under American law. But it is not the sovereignty that “European Digital Identity Wallet” suggests to a citizen who hears the phrase.

It is European regulatory logic running inside American infrastructure, which is a hybrid. The sovereignty claim becomes partial in a specific way: the legal regime is European, the operational substrate is American, and the distinction between the two is invisible to ordinary users.

Poland’s mObywatel wallet has eleven million users and counting. Sweden’s BankID has been in daily use since 2003. Belgium’s itsme has saturated its domestic market. These are proofs that European wallets can reach real scale. France’s digital ID, by contrast, had three point two million users in December 2025: a figure too low to be a credible primary channel.

The divergence between the Polish and the French cases is not technical. It is a question of state capacity and political will. Where those exist, European wallets work. Where they don’t, the platform-as-container scenario becomes the default.[17]

Brussels Effect exports the compromise

The Brussels Effect (Anu Bradford’s 2012 term for Europe’s ability to set global regulatory norms through single-market access leverage) is the mechanism by which GDPR became the world’s privacy baseline.

California’s CCPA, Brazil’s LGPD, India’s DPDP Act, Japan’s APPI, South Korea’s PIPA, and many others track GDPR’s structure because compliance with Europe was cheaper when globalised than when localised. eIDAS 2 has some of the same potential.

ISO/IEC 18013-5 is being adopted by US state mDL programmes in Arizona, California, Maryland, Colorado, Georgia, New Mexico, Hawaii, Iowa, Ohio, Puerto Rico, Utah, and Virginia. OpenID4VP and OpenID4VCI are becoming global defaults for wallet authentication and credential issuance. Australia’s Digital ID Act 2024 tracks eIDAS 2 in several specific architectural decisions.[18]

But Brussels Effect exports the architecture that exists, not the architecture Europe wishes existed. If the baseline cryptography that eIDAS 2 ships with is SD-JWT and mDL without mandatory BBS+ or ZK proofs, then the global baseline becomes the same.

If the reference ZK implementation is Google’s Longfellow, then jurisdictions copying Europe adopt Silicon Valley cryptography inside European regulatory framing. The Brussels Effect does not discriminate between strong and weak architectures. It propagates what Europe ships.

The more successful eIDAS 2 becomes internationally, the more widely the gap between its legal promises and its architectural delivery is reproduced. Countries that copy Europe’s regulation but adopt the baseline architecture will end up with legal privacy commitments that their architecture does not deliver: a global replication of the same structural problem.

The UK’s decision to build a separate Digital ID Scheme rather than join eIDAS is a small but meaningful canary. The first major European economy to exit the EU has also chosen not to track the EU’s digital identity architecture. The gravity of the Brussels Effect is less absolute for identity than it was for privacy.

This means the architectural choices Europe makes in the next eighteen months determine European outcomes and the global trajectory of what “privacy-preserving digital identity” means in practice for the next decade.

The digital euro inherits the gap

The digital euro pilot begins in the second half of 2027. The wallet is its identity layer.

Onboarding at the payment service provider, offline signing for cash-equivalent transactions, biometric authentication for cardless payments, transaction signing under PSD3 Strong Customer Authentication, revocation in case of theft: every function the digital euro requires runs through the wallet, and through the wallet inherits the gap.

Offline signing flows through the Secure Element managed by Apple or Google. Biometric authentication is mediated by the operating-system biometric system. Identity attestations rely on the attestation chain rising to the phone manufacturer’s root keys.

The digital euro, the most unambiguously sovereign European currency project since the euro itself, operates through an identity infrastructure whose bottom layer is American.

The anchor customer effect is real but incomplete

The industrial policy dimension of eIDAS 2 is the piece most easily overlooked. European Secure Element suppliers (NXP, Infineon, STMicroelectronics) will sell hundreds of millions of SEs over the wallet’s deployment cycle.

European Qualified Trust Service Providers, Hardware Security Module manufacturers (Utimaco, Thales, Atos Eviden), Common Criteria certification labs, and identity software firms (IDnow, Scytáles, Signicat, itsme) will benefit from structural demand at continental scale.

The wallet is, in industrial policy terms, the single largest guaranteed customer the European digital sovereignty agenda has created. Chips Act investment gains a demand anchor. GAIA-X sovereign cloud ambitions gain a workload. European cryptographic expertise gains a market.

The incompleteness is at the operational layer. Even when NXP supplies the Secure Element chip, the keys provisioned into that SE in a deployed smartphone are controlled by Apple or Google or Samsung, not by NXP and not by the member state.

GlobalPlatform has been developing Secondary Application Manager and Card Specification Provider frameworks since 2023 that would let member states independently manage applet loading onto eSEs. SAM/CSP-compliant deployments are not yet at scale. SAM-Ready technology exists; SAM-deployed does not.

Until the operational control gap is closed, European chip suppliers benefit from wallet demand while American platform operators retain control over what runs on the chips. The anchor customer effect is real but partial. Owning the chip supply is not the same as owning the deployed infrastructure.

The cloud backend problem is similar. Nothing in the regulation or the ARF requires wallet provider backends, QTSP infrastructure, or trust list hosting to run on European sovereign cloud. Most of it, in practice, will run on AWS, Azure, or Google Cloud because that is what is commercially available and cost-competitive. The regulation gestures at sovereign technologies in recitals.

It does not mandate them. The wallet could end up being a demand anchor for American hyperscalers as much as for European infrastructure, depending on procurement choices made in member state capitals over the next two years.

Read these four dependencies together. The digital euro pilot starts in 2027 on a wallet infrastructure whose sovereignty is incomplete. The Brussels Effect, once triggered, propagates whatever architecture Europe ships: the weakest version as easily as the strongest. The platforms the wallet was meant to displace are quietly positioning themselves to host it instead.

The industrial demand signal flows to European chip suppliers but the operational control does not. None of these is catastrophic on its own. Each of them is a vector by which the gap becomes harder to close later than it is now.

The next eighteen months are the window in which the architectural decisions being made for eIDAS 2 will be the architectural decisions inherited by the digital euro, by the age verification blueprint, by every downstream project that runs on wallet rails. Fix the gap at the wallet layer and every downstream project inherits the fix.

Leave it unfixed and every downstream project inherits the dependency, with compounding difficulty each year to extract.

VII. Finishing the job

The gap is real. It is also not permanent. Unlike many of the dependencies documented in this series, this one has an open policy window with identifiable technical interventions that would close it. The next eighteen months are when those interventions have to happen. What follows is the list, in rough order of leverage.

Make strong cryptography mandatory, not optional. Recital 14’s “should integrate” language for zero-knowledge proofs must be upgraded to “shall integrate” in the implementing acts. BBS+ or an equivalent issuer-unlinkable primitive must be specified as a required credential format, not as one option among several.

The June 2024 cryptographers’ open letter is the technical basis. The European Digital Identity Cooperation Group has the authority. The decision is a political one about whether to enforce the regulation’s own requirements at the cryptographic layer or to let the baseline implementation define what unlinkability means in practice.

Close the ARF-regulation gap through structured review. The Spanish DPA’s January 2025 note, the Cryptographers’ ARF feedback, epicenter.works’ repeated analyses, and the EDPB’s commentary have produced a detailed catalogue of where the ARF falls short of the regulation.

A formal reconciliation exercise, coordinated by the Cooperation Group with input from data protection authorities and independent academic review, could produce an ARF version 2.0 that systematically tracks the regulation’s operative articles. This is what good regulatory implementation looks like when taken seriously.

Deploy SAM and CSP. GlobalPlatform’s specifications for independent applet management on embedded Secure Elements exist. Their deployment requires commercial agreements between member states, mobile network operators, and smartphone manufacturers.

Germany, France, the Netherlands, Italy, and Spain have the market weight to negotiate SAM/CSP deployment on the terms that let them manage the Secure Elements in the phones their citizens use. This is industrial negotiation requiring coordinated political will more than new regulation.

Raise the penalty ceiling. eIDAS 2’s current penalty cap of one per cent of global turnover is materially lower than GDPR’s four per cent or the Digital Markets Act’s ten. A VLOP that wishes to avoid accepting the wallet can absorb one per cent. Four per cent is harder. Ten per cent changes the calculus.

Penalty parity with the other pieces of the European digital regulatory stack would materially increase the regulation’s enforceability against the entities most likely to resist it.

Mandate sovereign cloud for critical wallet infrastructure. Wallet provider backends, trust list hosting, revocation infrastructure, and QTSP HSM operations should run on certified European sovereign cloud.

The definition of “sovereign cloud” (which has been muddied by GAIA-X’s membership compromises) can be tightened through procurement rules and implementing acts without requiring treaty change. OVHcloud, T-Systems, Deutsche Telekom, Atos Eviden, and several smaller European providers have the capacity. Procurement preference plus regulatory requirement creates the market.

Give the EDIFB real enforcement powers. The European Digital Identity Framework Board currently has coordination and advisory functions. GDPR’s experience with the European Data Protection Board shows that a coordination body without binding powers becomes a forum for delay.

The EDIFB should be upgraded (through a future regulatory amendment or through expanded implementing-act authority) to issue binding cross-border decisions, impose corrective measures on relying parties that fail their acceptance obligations, and coordinate enforcement actions across member state supervisors. The Ireland problem will not solve itself through soft coordination.

Finance European cryptographic alternatives to Longfellow. The Dyne.org fork of Longfellow is a civil society response to a problem that should have been a Commission-funded R&D priority.

European Chips Act funding, Horizon Europe programmes, and national research agencies should coordinate on a European zero-knowledge cryptographic stack that has the production-grade engineering of Longfellow without the upstream dependency on Google Play Services. This is a question of prioritisation, neither large in money nor difficult in expertise.

Protect adoption as a political priority. The France-versus-Poland divergence on wallet adoption (three point two million users versus eleven million) shows that state capacity and political attention produce different outcomes with the same regulation.

The Commission can support this by funding adoption-focused technical assistance, by coordinating cross-member-state adoption campaigns, and by making the eighty per cent 2030 target a real political commitment rather than a rhetorical flourish. Without adoption, none of the architectural improvements above matter, because there is no deployed wallet infrastructure for them to improve.

These are eight interventions. None of them requires treaty change. None of them requires fundamental rearchitecting. Most of them require political will, technical specification work, and industrial negotiation: the ordinary instruments of European policy.

The window for doing them is now, because the wallet goes live at the end of 2026 and the architectural decisions being made in the next twelve months will be the ones that ship.

VIII. The identity paradox

Von der Leyen asked the question in 2020: every time an app or website asks us to create a new digital identity or to easily log on via a big platform, we have no idea what happens to our data in reality. The question was exactly right.

The answer, in 2020, was that Europe’s digital identity layer was captured by four American companies, monetised through advertising surveillance, available under American subpoena jurisdiction, and designed to aggregate rather than protect. Europe had no public alternative and no serious plan to build one.

The answer in 2026 is different. Europe has the best-designed digital identity regulation in the world. Thirty-nine civil society organisations, three hundred scientists, a serious parliamentary rapporteur, a network of data protection authorities, and a functioning democratic process made it what it is.

The regulation mandates pseudonymity, unlinkability, unobservability, and selective disclosure as legally binding properties. It creates a continental-scale identity infrastructure that refuses centralised tracking, refuses persistent identifiers, and refuses platform capture as a structural choice. It underwrites the single market at the identity layer for the first time.

It democratises qualified electronic signatures. It provides the substrate for the digital euro. It gives European regulators an enforcement surface against American platforms that GDPR never fully possessed. It is, as a legal achievement, the most significant piece of European digital sovereignty legislation of the decade.

And yet. The architecture being built to deliver the legal achievement does not yet match the achievement. The baseline cryptography formally violates the regulation’s unlinkability requirement. The zero-knowledge library in the reference implementation is authored by Google. The unobservability mandate stops at the operating-system layer.

The Secure Element keys are provisioned by Apple or Google. The attestation chain runs up to American root keys. The cloud backend is not required to be European. The penalty cap is lower than GDPR’s. The enforcement coordination body has no binding powers. The Apple Wallet as recognised container is a live scenario. The sovereignty claim at the legal layer is real.

The sovereignty claim at the infrastructure layer is not yet.

This is the paradox the paper began with. It is the honest report of a project eighty per cent complete and nineteen months from deployment, with the remaining twenty per cent being exactly the part that determines whether the eighty per cent holds. Europe has built something new at the legal layer.

Europe has not yet built the infrastructure to hold it up. The two halves of the achievement are separable in analysis but inseparable in operation. If the infrastructure fails to match the law, the law degrades into what law without infrastructure always degrades into: aspiration, enforcement theatre, and eventual irrelevance.

The ICC judges under American sanctions are not the reason this project exists. They are the reason its completion stopped feeling abstract.

The decisions Europe makes in the next eighteen months about cryptographic primitives, Secure Element control, cloud sovereignty, and enforcement powers are the decisions that determine whether an external political environment can weaponise against Europe the infrastructure Europe’s daily life runs on. The answer is not foreordained.

It depends on choices being made right now in implementing acts, in ARF iterations, in procurement guidelines, in industrial negotiations, and in the political weight member states put behind adoption. There is no technical reason the gap cannot be closed. There is only the question of whether it will be.

Europe came closer to the third way than it ever has before. The regulation is not Aadhaar. It is not the Chinese system. It is not Sign in with Google re-skinned for Brussels. It is an attempt to build a digital identity layer that serves citizens, underwrites democracy, respects sovereignty, and refuses capture. What remains is to finish it.

The law is done. The architecture is being written now. The outcome is still open.

[1] Regulation (EU) 2024/1183 of the European Parliament and of the Council of 11 April 2024 amending Regulation (EU) No 910/2014 as regards establishing the European Digital Identity Framework, OJ L 2024/1183, 30 April 2024. Entered into force 20 May 2024.

[2] Unique Identification Authority of India (UIDAI), Aadhaar enrolment statistics, 2025. Aadhaar covers approximately 1.4 billion residents; the system processes approximately 80 million authentications per day across welfare, banking, telecoms, tax and services.

[3] Justice K.S. Puttaswamy (Retd.) v. Union of India, Supreme Court of India, judgement of 26 September 2018. Five-judge bench struck down Section 57 of the Aadhaar Act 2016 prohibiting private entities from requiring Aadhaar authentication.

[4] European Commission, Proposal for a Regulation amending Regulation (EU) No 910/2014 as regards establishing a framework for a European Digital Identity, COM(2021) 281 final, 3 June 2021.

[5] Council of the European Union, General Approach on the Commission proposal amending Regulation (EU) No 910/2014, document 15604/22, 6 December 2022. Council text retained the unique persistent identifier subsequently removed in trilogue.

[6] Provisional political agreement on the European Digital Identity Framework reached in trilogue, 28-29 June 2023. Removal of the unique persistent identifier confirmed in the trilogue text and welcomed by epicenter.works and 24 undersigning civil society organisations.

[7] Final political trilogue agreement on Regulation (EU) 2024/1183, 8 November 2023. Article 5(2) (pseudonyms), Article 5a.16 (unlinkability), Recital 11c (unobservability), Recital 14 (privacy-preserving technologies), and Article 12b.3 (separation of wallet data) added in the final text.

[8] Agencia Espanola de Proteccion de Datos (AEPD), public statement on EUDI Wallet Architecture Reference Framework, January 2025. AEPD identified significant gaps between the ARF specification and Regulation (EU) 2024/1183 privacy requirements.

[9] BBS+ signatures, originally introduced by Boneh, Boyen and Shacham (2004); cryptographic suite standardised through W3C Credentials Community Group and IETF Crypto Forum Research Group drafts. Supports issuer-unlinkable selective-disclosure credentials suitable for digital wallets.

[10] Open letter from cryptographers and privacy researchers to the European Commission on EUDI Wallet baseline cryptography, June 2024, hosted on the EU Digital Identity Wallet ARF GitHub discussion. Recommends mandatory BBS+ adoption to satisfy unlinkability requirements.

[11] Longfellow zero-knowledge proof system, authored at Google. Open-sourced under Apache 2.0 licence. Reference Swift integration shipped in EU reference implementation as ‘av-lib-ios-longfellow-zkp’.

[12] Google Security Blog, ‘Open-sourcing Longfellow ZKP for digital identity’, July 2025. Positions Longfellow for EU eIDAS Regulation adoption: ‘Member States can integrate this into their future EUDI Wallets.’

[13] Dyne.org foundation, Google-free fork of Longfellow library, 2025-2026. Dyne.org is an Amsterdam-based digital sovereignty research foundation; the fork removes Google Play Services dependencies for European deployment.

[14] Transportation Security Administration, mobile driving licence and digital ID acceptance, 2025-2026. Approximately 250 TSA checkpoints accept digital ID via Apple Wallet, Google Wallet, and Samsung Wallet implementations.

[15] BankID, Sweden’s federated bank-issued digital identity scheme, operational since 2003. Operated by Finansiell ID-Teknik BID AB, owned by Swedish banks. Approximately 8 million active users.

[16] Agence nationale des titres securises (ANTS), Identite Numerique France usage statistics, December 2025. Approximately 3.2 million active users at year-end, low penetration relative to mass-market deployments in Poland, Sweden, Belgium and Estonia.

[17] ISO/IEC 18013-5:2021, Personal identification - ISO-compliant driving licence - Part 5: Mobile driving licence (mDL) application. Adopted by US state mDL programmes including Arizona, California, Colorado, Georgia, Hawaii, Iowa, Maryland, New Mexico, Ohio, Puerto Rico, Utah, and Virginia.

[18] Open letter from scientists and cryptographers on Article 45 of the eIDAS 2 proposal, 2023. Over 300 signatories, principally cryptographic and security researchers, raised concerns about provisions enabling government-mandated browser certificate authorities.

Sign the Manifesto. The eight demands that follow from the case made in this paper and the twenty-seven others. Sign →