TL;DR: Digital identity has moved past proving who someone is and into orchestrating trusted interactions across issuers, sectors, borders, and delegated authority, according to Uniken, with EUDI Wallet acceptance becoming mandatory for some relying parties from December 2027. The governance problem is now evidence, policy, and trust travel, not basic credential verification.
NHIMG editorial — based on content published by Uniken: The goal was never digital identity. It was orchestrating trust
Questions worth separating out
Q: How should organisations govern credential acceptance in cross-border identity systems?
A: Treat credential acceptance as a governance decision, not an integration task.
Q: Why does delegated authority create more risk than simple authentication?
A: Authentication proves a subject presented a valid credential.
Q: What breaks when identity proofing is weak?
A: Weak proofing lets the organisation issue credentials to the wrong person or entity, which means later access controls are protecting an assumption that was never verified.
Practitioner guidance
- Map trust conditions separately from authentication Document which parts of your identity stack prove identity, which parts prove issuer trust, and which parts prove delegated authority.
- Design for evidence continuity across boundaries Make sure wallet acceptance, presentation, and transaction binding preserve enough context for audit, dispute handling, and regulatory review.
- Model delegated authority as a lifecycle problem Track when authority is granted, changed, and revoked for humans, service accounts, and AI-assisted actors.
What's in the full article
Uniken's full blog covers the operational detail this post intentionally leaves for the source:
- How the Geneva discussions map to payment authentication, device binding, and wallet attestation in practice.
- The policy questions behind cross-border acceptance and accountable change control that this post only outlines.
- Why proof of age emerged as the most scalable reusable credential and what that implies for rollout strategy.
- The article's view on cooperation across ministries, private relying parties, and standards bodies.
👉 Read Uniken's analysis of digital identity trust orchestration and EUDI acceptance →
EUDI trust orchestration: what changes for IAM teams now?
Explore further
Trust orchestration is the real identity programme now. The industry has largely solved the mechanics of proving a credential, but not the governance of deciding when that credential can be trusted across organisations, sectors, and borders. That changes identity from a single authentication event into a policy and evidence problem. Practitioners should stop treating verification as the endpoint and start treating trust conditions as the control surface.
A few things that frame the scale:
- The most developed and most widely deployed reusable credential with biometrics today is proof of age, not a national identity wallet, according to The State of Secrets in AppSec.
- Companies are dedicating an average of 32.4% of their security budgets to secrets management and code security, with US organisations leading at 40.8%, according to The State of Secrets in AppSec.
A question worth separating out:
Q: How can security teams prepare for EUDI-style wallet acceptance requirements?
A: Start by reviewing relying-party policy, evidence retention, issuer trust criteria, and exception handling. Then test whether your architecture can accept a wallet credential while preserving the proof needed for audit and dispute resolution. If those capabilities are missing, the gap is governance, not just development effort.
👉 Read our full editorial: Digital identity is shifting from verification to trust orchestration