TL;DR: Germany already has the technical building blocks for a nationwide Germany App, while the real constraint is trust in digital identities, secure communication, and transparent digital processes, according to KOBIL. For identity teams, the larger issue is not platform invention but whether governance can make citizen, workforce, and machine interactions trustworthy enough for AI-era services.
NHIMG editorial — based on content published by KOBIL: Statement on digital sovereignty, identity trust, and the Germany App debate
Questions worth separating out
Q: How should organisations govern identity trust in national digital platforms?
A: Organisations should define trust boundaries before integration begins, then apply consistent identity assurance, logging, and revocation rules across every participating service.
Q: Why do AI infrastructure programmes create new identity governance risk?
A: They create risk because machine-speed workflows can combine APIs, secrets, and delegated authority faster than conventional review cycles can observe.
Q: What do organisations get wrong about digital sovereignty programs?
A: They often treat sovereignty as a compliance checkbox tied to cloud region selection.
Practitioner guidance
- Map identity trust boundaries across the full service chain Document where identity is created, verified, delegated, and revoked across citizen services, business services, and AI-supported workflows.
- Extend governance to non-human actors Treat service accounts, API credentials, and AI-enabled automation as governed identities with ownership, policy scope, and lifecycle controls.
- Build traceability into the platform architecture Require end-to-end logging that connects identity events to transaction outcomes, including authentication, authorisation, delegation, and revocation.
What's in the full article
KOBIL's full article covers the strategic argument and product context this post intentionally leaves for the source:
- The company’s own examples of digital identity, secure communication, and platform capabilities that it says already exist.
- Its broader argument for digital sovereignty in Germany and why it sees timing as a governance issue rather than a development problem.
- The author’s perspective on public administration, SMEs, and industry participation in platform building.
- The source’s discussion of how AI changes the trust debate for public and enterprise digital services.
👉 Read KOBIL’s perspective on digital sovereignty, identity trust, and the Germany App debate →
Germany App ambitions: what does digital sovereignty mean for IAM teams?
Explore further
Digital sovereignty is now an identity governance problem, not just a technology ambition. The article is right that much of the capability already exists, but capability alone does not create trust. What matters is whether identities, sessions, and delegated access can be governed consistently across public services, suppliers, and AI-mediated workflows. The practitioner conclusion is that sovereignty without enforceable identity controls is only policy language, not operational control.
A few things that frame the scale:
- The average estimated time to remediate a leaked secret is 27 days, despite 75% of organisations expressing strong confidence in their secrets management capabilities, according to The State of Secrets in AppSec.
- Organisations maintain an average of 6 distinct secrets manager instances, creating fragmentation that undermines centralised control.
A question worth separating out:
Q: Who should be accountable when shared digital services cross organisational boundaries?
A: Accountability should sit with the organisation that owns the identity decision, not with the service layer alone. Shared services need explicit ownership for authentication, delegated access, logging, and revocation, otherwise incident response becomes a blame transfer exercise. Governance must stay attached to the control point, not the user interface.
👉 Read our full editorial: Digital sovereignty and identity trust are the real Germany App challenge