Not knowing is no excuse. Not even genuinely not knowing.
In four months the EU makes a digital identity wallet mandatory. Cryptographers warned in 2024. Half the public has never heard of it.
By 24 December 2026, all twenty-seven EU member states must make a certified digital identity wallet available to their citizens. The clock started when the Commission’s first implementing regulations entered into force in December 2024, and it runs out on Christmas Eve.
Four months remain. As of 3 August 2026, not one country has shipped a certified wallet.
Denmark is furthest along — AltID went into production on 3 June — but with a caveat: its relying party registry is not yet an eIDAS 2.0 relying party registry. The certification infrastructure itself is still being built across Europe.
ENISA described the situation earlier this year in one sentence: “no EUDI Wallet has been deployed or certified, and the specification remains work in progress.”
Some countries have already planned to miss. Germany has spent €79.3 million and set its launch target for 2 January 2027 — nine days past the deadline. One assessment in January found that only 12 of 27 member states were on track to have a working wallet by year end.
And even where a wallet does arrive, there is a second problem. In a survey of 2,000 adults in France and Germany, 51% had never heard of the EUDI wallet. Another 27% had heard of it but did not know what it does. Twenty percent have any grasp of it at all.
A piece of infrastructure that will be legally mandatory arrives in four months, and half the people it is for do not know it exists.
So what is it
By the figures just cited, four in five people do not know what it is. So here it is.
It is an app on a phone. It holds things like an identity card, a driving licence, proof of insurance, a diploma. When somewhere needs to check something, the wallet presents only the one thing needed.
At a bar, “over eighteen” goes across. The name does not. Neither does the date of birth or the address. At a hospital, the insurance entitlement goes across and the rest stays where it is.
That is the design intent. This piece is about whether the intent is being kept.
The obvious conclusion is that this is another delay.
It is worth noticing what did not stop during the delay.
What already exists
Belgium has a national identity system with roughly 80% adoption among adults over sixteen. It passed eight million users in 2025 and now handles 594 million authentications a year. People use it to log into their bank, file taxes, open medical records, sign contracts.
The state did not build it.
It was built by the Belgian Mobile ID consortium — four banks (Belfius, BNP Paribas Fortis, KBC/CBC, ING) and three telecom operators (Orange Belgium, Proximus, Telenet). The Federal Holding and Investment Company took a 20% stake in mid-2021, the first government investment since launch, and remains a shareholder.
Read the order again.
The banks and the telecoms built it first. The state came in later, as a minority shareholder.
Meanwhile the state is building a separate app, MyGov.be, run by the federal policy and support service, which selected Zetes as its e-signature supplier in July. In the European wallet trackers Belgium is listed as “existing app: upgrade confirmed.” The private system is reported as likely to plug into the national one.
That is not replacement. That is overlap.
And it is not an identity check
Something here has gone unremarked rather than misunderstood. The explanation did not reach people, and many — including the person writing this — simply assumed.
These systems do not authenticate identity. They confirm presence.
When someone logs in, the system does not ask who is this person. It asks whether a binding registered earlier is still live and whether someone is activating it right now. The identity check happened once, at enrolment, through a bank’s know-your-customer process or a national eID card. Every use after that confirms presence, not identity.
The fair objection is that this still sits on top of a national eID. True — as a system it depends on identity verification.
What matters is where that dependency sits. It sits at the enrolment layer, and the bank is what performs it. The state has not stopped verifying identity; it has moved into the position of recognising what a bank verified.
[Premise] What if proving that you exist, without saying who you are, is already the default in ordinary life?
This is not a prediction. What follows uses that premise as a coordinate and reads the present again.
What breaks first
A state cannot build this.
Not will not — structurally cannot. Identity infrastructure stays alive only through high-frequency use. Authentication used once a year is forgotten, its password lost, its app deleted. Only what people use weekly survives.
States do not transact with citizens weekly. Banks do. Telecoms do.
| Country | System | Adoption |
|---|---|---|
| Norway | BankID | ~97% |
| Sweden | BankID | 99% of adults aged 18–65 |
| Denmark | MitID | ~93% |
| Belgium | itsme | ~80% |
All four began in the private sector. None grew because a government required it. Each became the fastest way to log into banking, insurance and e-commerce, became indispensable, and then became the de facto standard.
One country could be explained by culture. Four is a structure.
The country in that table that says the most is Sweden.
With BankID at 99%, Sweden has scheduled certification of its state wallet for 2029 — certification-ready in 2028, certified in 2029. Three years past the legal deadline. Switzerland is looking beyond 2026 as well.
It is hard to call that negligence. In a country where 99% already use something that works, a state wallet is not urgent. The better a private identity system works, the further the state wallet slides. The regulation did not price that in.
What the law asked for, and what the design answered
Everything above is a rearrangement of known facts. The actual fracture is here.
eIDAS 2.0 does not suggest privacy. It requires it.
Article 5a(16) states that after an attestation of attributes has been issued, the framework “shall not allow” the issuer or any other party to obtain data that would let transactions or user behaviour be tracked, linked or correlated — unless the user explicitly authorises it. The same paragraph requires enabling privacy-preserving techniques that ensure unlinkability where identifying the user is not necessary. Article 5a(4) requires that selective disclosure be possible.
In plain terms: if a bar verifies that someone is over eighteen and a hospital verifies the same person’s insurance, the two should not be able to compare records and discover it was the same person.
The law asked for that. Precisely stated, it asked for it where identifying the user is not required. The condition is real. So is the requirement.
In June 2024 the Commission convened cryptographers and asked them to review the design as it then stood. The answer: the design falls short of the privacy requirements the regulation sets out, because it relies on cryptographic methods never designed for those requirements. They concluded that a substantial redesign was needed and pointed to anonymous credentials — the BBS family, understood in the literature for over twenty years.
Two years later, on 15 April 2026, the Commission announced that the age verification app was technically ready. The technical documentation from the same period says:
Support for a zero-knowledge proof is upcoming.
There is a temptation here to guess at intent. Who blocked it, and why.
That is not necessary. The structure is enough.
- The party that needs the anonymity is the citizen.
- The party that must implement it is the set of banks, telecoms, healthcare providers and very large online platforms that will be obliged to accept the wallet from 2027.
The interests are not aligned.
There is a technical problem alongside it. Aggregates that supposedly identify no one — analysis by age band, for instance — feel safe, but at sufficient granularity the aggregate itself identifies. Re-identification from aggregate data is an old research subject and the findings point consistently in one direction. Anonymity is not obtained by deleting fields.
Why so few know — two readings
Return to that number: half of French and German respondents have never heard of the wallet.
It reads two ways.
One. The explanation did not land. Not that no material was ever published, but that it did not reach the people it was for.
Two. The explanation existed somewhere, but there was no room in the day to go and find it.
Before choosing, one more figure from the same survey is owed. After being told that the wallet could confirm their age without handing over a name, a date of birth or an address, 63% said they would be more likely to use it.
People are not indifferent. Told what it does, they say they want it. That number pushes toward the first reading.
Still, hearing an explanation inside a survey and having room in an ordinary day to seek one out are different things. So the choice stays open. But take the second reading and something left unexplained above becomes clear.
These systems did not win on explanation. They won by being attached to the bank.
You cannot skip the bank. You cannot skip the tax filing. A person with no slack does not read an explanation; they use what is already in their hand. So the private sector did not win on better technology or better communication. It won because people’s lives are tight.
That people have no room to examine institutions is observable. Who produced that condition is not. So the sentence stops here.
One thing must be added. Participation is not optional.
From 2027, banks, telecoms, healthcare providers and very large online platforms must accept this wallet. Accepting it means the door leads through it. Someone without a wallet is not mildly inconvenienced; they are left outside.
Not participating means falling out. Not in the sense that anyone left behind deserved it — in the structural sense that the number of doors narrows to one.
And if that is true, half the population not knowing is not a neutral condition. Leaving people uninformed in front of a door that is becoming compulsory is closer to leaving them out than to failing to explain.
So not knowing is not an excuse. Not even genuinely not knowing. But the excuse belongs to whoever built the door without announcing it, not to the person standing in front of it unaware.
[Author’s position] I feel a frustration here, and it is not a simple one.
This structure is tiresomely complete, there is froth in it, and there are lives being protected because of it. Four banks and three telecoms holding the identity checks of most adults in a country is an oligopoly. That oligopoly is also free, secure, and genuinely makes people’s days easier. Both are true, which makes simple opposition impossible.
This is not a conclusion. It is a disclosure of where I stand. The judgement remains the reader’s.
The institution already came once
Set out one more sequence.
| When | What |
|---|---|
| April 2016 | GDPR adopted |
| 2016 | itsme announced |
| 30 May 2017 | itsme goes live |
| 25 May 2018 | GDPR applies |
It was designed and born after the GDPR was adopted and before it applied — precisely the window in which every European company was redrawing its systems for the GDPR.
And the structure it describes of itself — collecting no more personal data than needed, not tracking behaviour for advertising, using separate keys per partner — is the shape of the data minimisation the GDPR asked for.
No causal claim is made here. That it was built that way because of the GDPR is not established. What is established is that the sequence and the shape coincide. The arrangement is set down; the judgement is left.
What would have to exist first
Big tech, finance and the state would have to be in one basket.
They are not. They sit in different boats, and there are stretches where each benefits from the others’ failure.
Then something appears that was not visible at the start of this piece.
The 2027 acceptance obligation is exactly the provision that builds that basket.
Compelling banks, telecoms, healthcare and large platforms to accept the wallet is the procedure for putting the interested parties in one boat. The regulation knew the order.
It is only that the first step of that order was completed by the private sector a decade ago.
Anticipated objections
“Zero certified wallets is an administrative delay. This is overreading.” The strongest objection, and the delay itself is not the argument. The argument is that presence has been proven every day throughout the delay. A working system arrived before the institution did, and the institution is coming to document it rather than to build it.
“Then what is the alternative?” One direction: store context rather than identity, treat that context as the present identity, and let it change with future behaviour. If presence is confirmed, no information about the person standing there now is used.
The direction has a cost, and there is no reason to hide it. Storing context means a context database comes into being. Identity is a few fixed attributes; context is accumulated behaviour, and it can be more sensitive. And if context changes with future behaviour, who adjudicates the change? The moment an adjudicator exists, that is a new power. Removing the authority to issue identity can create the authority to assess conduct.
This is not a solved problem. Better not to pretend it is.
So what does December begin
Not a new era of proving identity. That era began some time ago in Belgium, and around the same time in Norway, Sweden and Denmark.
Nor is the institution merely arriving late. Read that way it becomes regulation is useless and the private sector does everything, and the timeline above forbids that reading.
The institution is not late. It comes twice.
Once to set the shape — 2016, the GDPR — inside which the banks and telecoms built. And now a second time, to ratify what was built: December 2026, eIDAS 2.0.
It is more accurate to say that the private sector built first inside a shape the institution had set, than that it got there ahead of the institution.
The second visit carries a condition. The law asked for anonymity, and the design has not yet produced it. And half the public does not know that.
The app through which eight million Belgians prove their existence every day already knows who they are. The institution arriving in December — does it come to change that, or to ratify it?
The judgement is left where it belongs.
Not yet verified
This piece is not marked verified until the items below are confirmed.
- The exact date the 2027 acceptance obligation takes effect. The text says only "from 2027".
- Whether FPIM still holds exactly 20%. There have been capital raises since 2021, so the stake may have been diluted; the text gives the 2021 figure with its date.
- Article text was confirmed through a site that reproduces the regulation, not against EUR-Lex directly.
- Swedish and German timelines come from reporting on national roadmaps, not from primary government publications.
Corrections
- → version 2 — Unverifiable absolute claims were removed. "No one ever explained it" cannot be checked — explanatory material does exist, from the Commission among others. What can be checked is the survey finding that 80% of respondents do not know what it is. Four such phrases were rewritten to sit on the evidence ("the explanation did not reach people"), and the heading "Why nobody knows" became "Why so few know". The argument is unchanged; its basis is now narrower.
- → version 3 — A section, "So what is it", was added. This piece cited a survey finding that 80% of respondents do not know what a digital identity wallet is, and then never explained what the thing does. It was reproducing the very opacity it criticised. Two sections covering a single argument were merged, and two objections already conceded in the body (dependence on the national eID; Nordic exceptionalism) were removed as duplication. No fact or argument changed.
Sources
- Regulation (EU) 2024/1183, Article 5a
- Regulation (EU) 2024/1183 (EUR-Lex)
- EUDI wallet status by member state — August 2026
- EUDI wallet status by member state — July 2026
- Germany's EUDI wallet push highlights Europe's implementation gap
- ENISA assessment, as reported
- IDnow survey — only 1 in 5 Europeans are familiar with the EUDI wallet
- EUDI What? As the deadline looms, awareness remains low
- Cryptographers' feedback on the EU Digital Identity ARF (June 2024)
- Cryptographers warn about EUDI wallet privacy
- European Commission age verification manual
- itsme shareholders and figures
- itsme launch announcement (May 2017)
- itsme privacy statement
- Adoption of private-sector identity schemes compared
- Belgium launches MyGov.be
- Belgium selects Zetes for MyGov.be e-signatures (July 2026)
- National readiness for the EUDI wallet
Read in another language
How this was made
Topic selection, premise, and judgement were done by a person; source collection and drafting by AI. This is not a translation. Each language version is written separately from the same source document.