TL;DR: Digital IDs moved from pilot projects into everyday use in 2025 as regulation tightened, privacy expectations rose, and orchestration became necessary across multiple identity methods, according to Yoti. The shift shows that trust, interoperability, and selective disclosure now shape identity strategy as much as compliance does.
At a glance
What this is: This is a year-end analysis of how digital IDs, age assurance, regulation, and trust changed in 2025, with the key finding that digital identity moved closer to mainstream infrastructure.
Why it matters: It matters because IAM, identity verification, and lifecycle teams now need to design for reusable identity, selective disclosure, and cross-provider orchestration rather than isolated point checks.
By the numbers:
- In 2025, Yoti passed 1 billion age checks globally, reflecting how widely trusted age assurance is now relied on across regulated industries.
- March 2025 marked Yoti reaching its first EBITDA-profitable month, driven by continued revenue growth and wider adoption of its products.
👉 Read Yoti's 2025 year-in-review on digital IDs, regulation, and trust
Context
Digital IDs became more visible in 2025 because organisations needed ways to prove age and identity without collecting full documents every time. The underlying governance issue is not just authentication, but how much personal data is shared, retained, and reused across services.
That shift pushes identity teams to think beyond one-off verification and toward reusable, privacy-preserving identity patterns. For practitioners, the real question is how to make digital identity usable across services while still preserving assurance, accountability, and data minimisation.
Key questions
Q: How should organisations govern reusable digital identity across multiple services?
A: Treat reusable digital identity as a governed trust decision, not a convenience feature. Set assurance thresholds for the original proofing event, define which relying parties can accept reuse, and require revocation and monitoring rules that match the risk of the transaction. Without those controls, reuse spreads a weak trust decision instead of reducing friction.
Q: Why does selective disclosure matter for IAM and identity verification programmes?
A: Selective disclosure matters because it lets services verify only the claim they need, instead of collecting a full identity record. That reduces unnecessary data exposure, lowers privacy risk, and makes retention decisions easier to defend. It also forces teams to measure assurance quality, not just document volume.
Q: How can identity teams decide when orchestration is necessary?
A: Use orchestration when multiple certified identity methods, regional rules, or fallback options must be presented through one consistent policy layer. The decision point should be governed centrally, because inconsistent routing can create uneven assurance and fragmented user experience across markets.
Q: Who is accountable when digital identity data is stored or shared incorrectly?
A: Accountability should sit with both the issuer and the provider that handles the data, because each controls a different part of the trust chain. Governance teams should assign ownership for proofing, storage, disclosure, and revocation separately so failures can be traced and corrected.
Technical breakdown
Selective disclosure changes the identity model
Selective disclosure means a user proves a specific attribute, such as being over 18, without exposing the full identity document behind it. That is a material shift from traditional verification flows, which often collect more data than the decision actually requires. In identity governance terms, the control objective changes from full-data capture to claim validation. That affects storage, retention, auditability, and downstream reuse. It also reduces unnecessary exposure when a service only needs a single assertion, not a full identity record.
Practical implication: Practitioners should map each verification flow to the minimum claim required and stop defaulting to full-document collection.
Orchestration is becoming the integration layer for digital identity
An orchestration service provider sits between relying parties and multiple identity methods, abstracting the complexity of integrating each provider separately. In practice, that means one policy and integration layer can route users through different certified identities, government credentials, or cross-border options. The architectural trade-off is governance concentration: the orchestration layer becomes a control point for assurance rules, provider selection, logging, and fallback paths. If that layer is weak, the whole trust chain becomes inconsistent even when the underlying identity methods are certified.
Practical implication: Identity teams should treat orchestration as a policy-enforcement plane, not just an integration convenience.
Verified identity is being extended into real-time interactions
Verified Calls reflects a broader trend where identity assurance is no longer limited to onboarding. The challenge from deepfakes and impersonation is that a person can appear legitimate in a live interaction without actually being who they claim to be. Verified presence or liveness checks reduce that gap by adding identity assurance before or during the call. This is relevant to high-risk workflows such as hiring, onboarding, payments, and sensitive support interactions, where impersonation can create financial or operational harm.
Practical implication: Teams should extend assurance controls into live interactions where impersonation risk can affect business decisions.
NHI Mgmt Group analysis
Digital ID adoption is no longer a pilot problem, it is a governance problem. Once reusable identity moves into everyday use, the question changes from whether the technology works to whether organisations can govern reuse, retention, and assurance across contexts. That is a lifecycle issue as much as a verification issue, because the same identity proof may be consumed by multiple services with different risk profiles. Practitioners should treat digital ID adoption as an identity governance programme, not a point-solution rollout.
Selective disclosure is the right privacy model for many age-assurance use cases, but it changes what must be audited. If a service only needs one attribute, collecting the full identity document is an avoidable governance failure. The control emphasis shifts to claim provenance, proof validity, and downstream data handling. For IAM and compliance teams, that means assurance evidence matters more than document volume.
Orchestration consolidates trust decisions into one layer, which makes it a governance choke point. As more identity methods, wallet types, and regulated verification paths converge, the orchestration layer decides which proof is accepted, when fallback occurs, and how evidence is retained. That concentration can improve consistency, but it also means policy drift becomes systemic rather than local. Practitioners should manage orchestration like a privileged identity control plane.
Trust has become an operational requirement, not a brand attribute. The article’s central lesson is that users now expect identity systems to minimise data, prove assurance, and remain usable across services. That expectation will keep rising as regulation hardens and impersonation risks grow. Identity leaders should build for explainable assurance, not just technical compliance.
From our research:
- 43% of security professionals are concerned about AI systems learning and reproducing sensitive information patterns from codebases, according to The State of Secrets in AppSec.
- Only 44% of developers are reported to follow security best practices for secrets management, exposing a significant developer behaviour gap.
- The broader lesson sits alongside Ultimate Guide to NHIs , Lifecycle Processes for Managing NHIs, where identity lifecycle discipline remains the control point that prevents trust sprawl.
What this signals
Digital identity programmes are moving from isolated verification use cases toward broader lifecycle governance, which means teams will need clearer policy ownership for reuse, retention, and revocation. The governance question is no longer whether a digital ID works at the point of check, but whether it stays trustworthy as it moves across services and jurisdictions.
Selective disclosure debt: as more services adopt reusable identity, organisations that still default to full-document collection will carry unnecessary privacy, retention, and breach exposure. The practical signal is that identity architecture should be measured by how little data it needs to make a valid decision, not how much it can capture.
For identity teams, the next phase is likely to be less about adding more verification methods and more about orchestrating the methods already in play. That makes policy consistency, audit trails, and provider governance central design concerns rather than implementation details.
For practitioners
- Define minimum-claim verification policies Map each use case to the smallest attribute set needed, such as age over 18 rather than full identity document capture. Then align retention, logging, and downstream sharing to that minimum claim.
- Treat orchestration as a governed control plane Assign explicit ownership for provider routing, fallback logic, assurance thresholds, and audit logging so the orchestration layer does not become an unmanaged trust decision point.
- Extend assurance into live interactions Add identity proofing or liveness checks to high-risk calls, onboarding sessions, and sensitive transactions where impersonation could change a business decision.
- Review privacy-by-design evidence Confirm that identity flows can demonstrate selective disclosure, limited retention, and clear user control over what is shared and for how long.
Key takeaways
- Digital IDs moved from experimental identity checks to everyday infrastructure in 2025, driven by regulation, trust, and usability.
- The operational challenge is now governance, especially selective disclosure, orchestration, and assurance across reused identity proofs.
- Identity teams should design for minimum-data verification and explicit policy ownership, because that is where trust now lives.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
NIST CSF 2.0, NIST SP 800-53 Rev 5 and NIST Zero Trust (SP 800-207) set the technical controls, while GDPR define the regulatory obligations.
| Framework | Control / Reference | Relevance |
|---|---|---|
| NIST CSF 2.0 | PR.AC-1 | Digital ID access decisions depend on identity proofing and assurance. |
| NIST SP 800-53 Rev 5 | IA-2 | Identity verification and authentication are central to age-check and onboarding flows. |
| NIST Zero Trust (SP 800-207) | Orchestrated identity decisions align with continuous verification principles. | |
| GDPR | Art.5 | Selective disclosure and data minimisation are directly relevant to identity checks. |
Review identity proofing workflows against IA-2 and ensure authentication strength matches risk.
Key terms
- Selective Disclosure: Selective disclosure is the practice of sharing only the identity attributes needed for a specific decision. In credential-based systems, it reduces oversharing, lowers retention burden, and limits exposure when a verifier does not need the full record to make a trustworthy judgment.
- Identity Orchestration: Identity orchestration is the control layer that routes identity decisions across applications and environments instead of letting each system manage access independently. For agents, it is the mechanism that can centralise policy, auditing, and downscoping at runtime.
- Age Assurance: Age assurance is the set of controls used to determine whether a person can access content or services restricted by age. It can include document checks, biometrics, in-band verification and decision logging, but the governance requirement is the same: the organisation must be able to justify the outcome.
What's in the full article
Yoti's full post covers the operational detail this post intentionally leaves for the source:
- The full year-in-review narrative behind the profitability milestone and what drove wider product adoption.
- Examples of how orchestration is being used to support multiple certified identity methods across markets.
- The product and policy context behind Verified Calls and why live-interaction assurance became a focus.
- The company’s own view of how regulation changed buyer expectations for privacy-first identity checks.
Deepen your knowledge
NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an identity security programme, it is worth exploring.
Published by the NHIMG editorial team on August 2, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org