Biometrics, digital wallets and national identity platforms are converging into a new layer of global security infrastructure. Yet while some technologies have reached large-scale operational maturity, others remain in pilots, proofs of concept or an accelerating contest with AI-enabled fraud. For governments and security leaders, digital identity is becoming as much a question of resilience and sovereignty as of technology.
Identity used to be a remarkably tangible security concept. A passport, a signature, perhaps a PIN — and, when necessary, a person behind a counter making the final judgement.
The digital world has turned that comparatively simple relationship into a chain of technologies and institutions. Cameras capture faces, algorithms compare biometric characteristics, smartphones hold credentials, government registers provide authoritative data and private platforms decide within fractions of a second whether an individual can be trusted.
Access to a bank account, an aircraft, a public service or a sensitive industrial system can now depend on that chain working as intended.
This is changing the character of the identity-security market. Identity solutions can no longer be neatly divided into passport readers, fingerprint sensors, digital onboarding and access-control systems. Biometrics, identity verification, digital wallets, fraud intelligence, public-key infrastructure and national digital identity programmes are increasingly interconnected.
The more important change, however, concerns how these systems should be judged.
The question is no longer simply whether a technology can recognise an individual. It is whether the entire chain of trust remains dependable under real operating conditions.
That distinction matters because the technology landscape is uneven. Facial matching has reached considerable maturity in many controlled scenarios. Reliable detection of synthetic identities and deepfakes has not. Digital wallets have demonstrated technical feasibility through substantial pilot programmes, but Europe has yet to complete mass deployment. National digital identity platforms can authenticate tens of millions of citizens, yet their success can turn them into systemic points of failure. Post-quantum technologies are moving into practical demonstrations, but remain far from routine deployment across legacy identity infrastructures.
Innovation, in other words, is not the same thing as maturity.
1. Biometrics: When Accuracy Is No Longer Enough
Few security technologies have improved as dramatically as automated facial recognition. For years, progress could be described largely through increasingly impressive benchmark results: lower error rates, faster matching and new algorithms climbing the rankings.
That story is becoming more complicated.
The US National Institute of Standards and Technology continuously evaluates facial recognition technology through its Face Recognition Technology Evaluation, or FRTE. By the end of July 2026, the current 1:1 programme had evaluated 1,441 algorithms from 439 developers. NIST considers not only recognition accuracy, but also computational resources, speed and the influence of image and subject characteristics.
The emerging picture is one of technological convergence. In several conventional verification benchmarks, leading algorithms now perform very close to one another. Differences become far more pronounced when operating conditions become difficult.
That shift has practical consequences for procurement.
If several systems perform exceptionally well on controlled frontal images, an advantage measured in fractions of a percentage point may matter less than performance under poor illumination, awkward camera angles or inconsistent image quality. Latency, interoperability, scalability and demographic consistency become more significant.
NIST’s work also continues to show that image quality can influence demographic differences in facial recognition performance. That issue moves well beyond engineering when facial recognition is used in border management, law enforcement or government identity systems. A failure to unlock a smartphone is inconvenient. A systematically uneven failure rate in a state security process raises questions of fairness, due process and institutional legitimacy.
None of this means facial recognition is immature. On the contrary, biometric matching itself is highly mature in many defined operating environments. What is increasingly difficult to defend is the assumption that a strong matcher constitutes a complete identity-security system.
Deepfakes change the meaning of “live”
Liveness detection exposes the problem.
Traditional presentation attacks were comparatively straightforward. A fraudster might hold up a photograph, replay a video or present a mask. Generative AI has expanded the attack surface. Faces and voices can now be synthesised, modified in real time or injected directly into digital processes.
The security question is therefore changing from “Does this face match the reference image?” to “Is the person or media stream itself authentic?”
Regulators are beginning to respond. New Zealand’s Authentication Assurance Standard requires measures against spoofing in biometric authentication and, for relevant higher-assurance implementations, specifies liveness testing against presentation attacks. The accompanying guidance also acknowledges a more uncomfortable reality: attack methods continue to evolve, meaning compliance with today’s standard cannot guarantee resilience against tomorrow’s manipulation techniques.
Research makes that limitation particularly clear.
A 2026 Fraunhofer SIT study evaluated five current audio deepfake detectors against real-world social-media material. Performance deteriorated substantially outside more controlled testing environments. On one particularly difficult dataset, the best reported F1 score using predetermined thresholds was only 50.89 per cent. The researchers concluded that contemporary detectors cannot yet reliably identify real-world audio deepfakes.
Fraunhofer IOSB, meanwhile, is developing its RealOrRender approach for detecting AI-generated images. The work is feeding into a demonstrator intended initially to support Germany’s Federal Office for Information Security. That distinction matters: it is a technology demonstrator, not evidence that arbitrary synthetic visual media can already be detected reliably at production scale.
The realistic assessment is therefore less spectacular than some industry marketing, but far more useful for security decision-makers. Facial matching is mature. Reliable synthetic-media detection remains an arms race.
High-risk applications should consequently treat facial comparison, liveness, device integrity, manipulation detection and contextual risk signals as complementary layers rather than competing products.
Websites:
NIST Face Recognition Technology Evaluation – pages.nist.gov/frvt/
Fraunhofer SIT – sit.fraunhofer.de
Fraunhofer IOSB – iosb.fraunhofer.de
New Zealand Digital Government – digital.govt.nz
2. Digital Wallets: The Identity Document Moves to the Smartphone
At the same time as biometric systems become more sophisticated, the document they are often intended to support is changing.
The physical identity card is not disappearing, but it is losing its monopoly.
Digital wallets promise to hold identity credentials, driving licences, educational qualifications and age attributes in a form that can be presented electronically and, crucially, selectively. Instead of disclosing an entire document, a user may be able to prove only the information required for a specific transaction.
Europe’s Digital Identity Wallet programme is the largest test of that model currently under way.
Six Large Scale Pilot Projects have been established. Four have completed their programmes, while two remain active. Around 550 public and private organisations from 26 EU member states, Norway, Iceland and Ukraine have participated, testing more than eleven categories of use case.
At that scale, this is no longer a laboratory exercise. It is a serious attempt to prove that wallet-based identity can work across national borders, industries and administrative systems.
But it would still be premature to call the European wallet an established mass-market infrastructure.
Member states are required to make compliant wallets available by the end of 2026. The difficult phase therefore lies ahead. A successful controlled exchange between participating organisations is not the same as an ecosystem in which millions of citizens use different smartphones to interact with thousands of public agencies, banks and private services.
Mass deployment introduces less glamorous but critical questions. What happens when a phone is lost? How is identity recovered securely? How are revoked credentials handled? What happens offline? Can people with disabilities use the system reliably? How is a user re-enrolled if both device and recovery mechanism are compromised?
The underlying concept has passed a substantial feasibility test. Operational maturity at continental scale has not yet been demonstrated.
Interoperability becomes a sovereignty issue
That is why apparently technical standards carry significant political weight.
The OpenID Foundation has developed conformance programmes for OpenID for Verifiable Presentations, OpenID for Verifiable Credential Issuance and the High Assurance Interoperability Profile. They give issuers, wallet providers and verifiers a way to test whether implementations that claim to follow the same specifications actually behave consistently.
Without that layer, digital identity risks becoming another platform market in which formally compatible products remain locked into proprietary ecosystems.
For Europe, the issue is inseparable from digital sovereignty. A government credential should not become unusable simply because a citizen changes handset manufacturer, wallet provider or commercial platform. Nor should access to public identity depend excessively on the commercial decisions of a small number of global technology companies.
France offers an early illustration of how the infrastructure can move into daily use. Since 24 June 2026, France Identité can be used as proof of identity for baggage drop and boarding at French airports. Only the information required for that process, such as name and photograph, needs to be presented. The application has passed 4.5 million users.
There are important limits. France Identité does not yet replace identity documents for border control. That makes it a useful example of realistic technological maturity: no longer experimental, but not yet universal.
The private market is advancing in parallel. Signicat’s ReadID is listed in the UK’s official Digital Verification Services Register for both component and orchestration functions. It combines NFC-based document validation with biometric identity-verification capabilities and is already used in large volumes of transactions.
Even here, however, technology and regulation are evolving at different speeds. The UK’s Digital Verification Services Trust Framework 1.0 was finalised in June 2026 but will only take effect once the first relevant conformity assessment body has been accredited, and no earlier than September.
For security buyers, this is not a bureaucratic footnote. A technically mature product may still operate within a regulatory architecture that is itself changing.
Websites:
EU Digital Identity Wallet – digital-strategy.ec.europa.eu
OpenID Foundation – openid.net
France Identité – france-identite.gouv.fr
Signicat / ReadID – signicat.com
UK Digital Verification Services Register – digital-identity-services-register.service.gov.uk
3. National Digital Identity: When Convenience Becomes Critical Infrastructure
Europe’s discussion is centred heavily on wallets and interoperability. Elsewhere, governments are increasingly developing digital identity as a component of Digital Public Infrastructure — a shared layer through which government agencies, banks and private companies can authenticate individuals.
The Philippines illustrates both the attraction and the consequences of that model.
Its National ID Authentication Services are increasingly being integrated into government and financial-service processes. The logic is compelling. Instead of relying solely on whether a photocopy, uploaded image or physical credential appears genuine, institutions can connect identity checks to an authoritative national system.
For banks, that could reduce document fraud. For government, it can simplify access to services. For citizens without extensive conventional financial histories, it may improve access to formal banking.
But success creates dependence.
The more organisations rely on one authoritative identity infrastructure, the greater the consequences when it fails.
Nepal provides a warning. According to reports documented in the source material, growing use of the country’s National Identity Management Information System has placed significant strain on its infrastructure. Banks, telecommunications providers, transport services, passport functions and other government systems increasingly depend on central identity verification, while biometric matching capacity has struggled with load.
The problem is revealing because it has little to do with biometric accuracy.
A system can achieve extremely low false-match rates and still fail as security infrastructure if users cannot reach it.
For national digital identity, feasibility studies therefore need to examine far more than cryptography and matching performance. Capacity under peak demand, geographical redundancy, failover mechanisms, recovery time, supplier dependency and fallback procedures become security requirements in their own right.
A highly trusted central identity platform can also become a highly valuable single point of failure.
That is one reason digital identity is increasingly intertwined with national resilience and sovereignty.
Across Africa, governments are pursuing digital public infrastructure partly as a route to more efficient administration and financial inclusion, but also as a means of controlling the foundations of their digital economies.
MOSIP offers an open-source modular architecture for national identity systems and is being used or explored across a growing number of jurisdictions. Sierra Leone is developing a MOSIP-based ecosystem linking trusted identity, verifiable credentials, payments and interoperable data exchange.
The political question behind such projects is increasingly difficult to separate from their technical design. Who controls the source code? Where are biometric databases hosted? Who possesses the cryptographic keys? Which foreign suppliers remain indispensable? What happens if geopolitical relations deteriorate or a vendor withdraws support?
Identity infrastructure is therefore becoming part of the wider debate about strategic technology dependence.
Websites:
Philippine National ID / PSA – psa.gov.ph
MOSIP – mosip.io
4. Banking and Payments: Identity Becomes Continuous
Few sectors expose the limitations of traditional identity verification more clearly than financial services.
Know Your Customer has historically been built around a moment in time. A customer opens an account, provides documents, passes verification and is subsequently treated as known.
Cybercrime does not respect that boundary.
A correctly opened account can be compromised months later. A genuine mobile phone can be stolen. A customer can be manipulated through social engineering into authorising a fraudulent transfer. Session tokens can be hijacked without an attacker ever presenting a forged passport.
The relevant question therefore shifts from “Who is this customer?” to “Is the legitimate customer still in control?”
BioCatch is emblematic of that transition. Its technology combines behavioural biometrics with device, network and other digital signals to detect unusual behaviour during banking interactions. The system is not simply asking whether the person passed onboarding. It is looking for evidence that the relationship between user, device and behaviour has changed.
Visa’s planned $2.4 billion acquisition of BioCatch illustrates how strategically important this upstream layer of fraud prevention has become. Rather than identifying fraud only when a payment is executed, financial institutions increasingly want to detect indications of compromise earlier in the customer journey.
Behavioural biometrics is already deployed at substantial commercial scale. That places it firmly beyond the experimental stage. But its limitations matter.
Behaviour generates risk signals. It does not provide metaphysical certainty about who is behind a screen.
That is precisely why its strongest role is within a layered architecture: an additional source of confidence, or doubt, rather than a replacement for identity proofing.
Can KYC itself become portable?
A more experimental idea concerns the reuse of identity verification between institutions.
The US-based SOLO Network is testing whether identity work performed by one regulated bank can be reused by another. Standardised certificates are intended to record which procedures were carried out, potentially including document validation, biometric comparison and liveness checks.
The pilot is being observed by US regulatory bodies. That point requires careful interpretation. Regulatory observation is not government approval, a safe harbour or confirmation that the model will ultimately be accepted at scale.
That is exactly what makes SOLO interesting as a feasibility exercise.
The technology is relatively easy to imagine. The harder problem is institutional trust.
If Bank A verified a customer six months ago, under what conditions should Bank B accept that work? How current must the verification be? What if a biometric method considered robust at the time is later shown to be vulnerable? Which institution bears responsibility if the identity proves fraudulent?
Portable KYC is therefore not simply an identity problem. It is an experiment in whether trust itself can be standardised and transferred between regulated organisations.
Incode’s GovFaceMatch addresses a related problem from another direction. Rather than determining whether a presented identity document appears genuine, the system is designed to compare a live selfie directly against records held by the issuing motor-vehicle authority in participating US jurisdictions.
Conceptually, the shift is important. The trust anchor moves away from the artefact presented by the customer and towards the authoritative source that issued the identity.
That becomes attractive as generative AI improves the quality of synthetic documents. But procurement teams should retain an important distinction: performance claims such as verification times and conversion improvements published by a vendor are not equivalent to independent benchmark results.
In identity security, a plausible architecture, a vendor benchmark and independently validated operational performance remain three different things.
Websites:
Visa – visa.com
BioCatch – biocatch.com
SOLO – solo.one
Incode – incode.com
5. Age Assurance: Proving Enough Without Revealing Everything
Few areas show the political tension around identity more clearly than age assurance.
Governments increasingly agree that children should face stronger protections against certain online content and services. They are far less united on the technology that should enforce those protections.
The available approaches range from government-issued identity documents and national ID systems to facial age estimation, digital credentials, payment information and operating-system-level age signals.
That variety is itself evidence that the technological problem has not been conclusively solved.
The UK’s communications regulator Ofcom offered one of the more realistic assessments in its 2026 report on age assurance: no individual method eliminates the risk of circumvention completely. The regulator sees value in layered approaches and expects organisations to review the performance of third-party age-assurance providers rather than assume that initial implementation is sufficient.
This is an important distinction for the security industry.
Age estimation, for example, can be highly useful without being an identity system.
Innovative Technology’s MyCheckr uses camera-based age estimation to support staff in retail and hospitality environments. In parts of northern England, such devices are being used in cooperation with policing and licensing activity. The company says images are not retained.
Its practical value lies in decision support. It can alert an employee that an ID check is advisable. That is not necessarily the same thing as a high-assurance legal proof of age.
Europe is exploring a different direction. The European Commission has been developing an age-verification approach designed to allow a user to prove that a threshold has been met without disclosing their full identity or precise date of birth. The architecture is aligned with the technical foundations of the EUDI Wallet and reflects a broader privacy principle: systems should disclose only the attribute required for the decision.
That principle could prove highly consequential.
A nightclub does not necessarily need to know a customer’s home address. An online service may not need a legal name or birth date. It may only need reliable evidence that the individual is over 18.
Identity minimisation may therefore become a security property in its own right.
The controversy surrounding Patronscan in San Francisco shows why.
Two bars in the Castro district paused their use of the identity-scanning technology after concerns about the collection and retention of images and identity data. The vendor says it does not conduct facial recognition and retains data only for defined purposes and periods. Yet the reaction illustrates something security engineering often treats as secondary: context changes the meaning of surveillance.
A system regarded as efficient security control in one environment may be perceived as intrusive monitoring in another, particularly when the individuals affected belong to groups for whom unwanted identification can carry wider consequences.
A technically effective identity system can therefore still fail in practice if users consider its data practices disproportionate.
Social acceptance is not external to feasibility. For identity systems, it is part of it.
Websites:
Ofcom – ofcom.org.uk
EU Digital Identity / Age Verification – digital-strategy.ec.europa.eu
Innovative Technology – innovative-technology.com
Patronscan – patronscan.com
6. The Market: Between Deployment, Proof of Concept and Promise
The identity market is also beginning to consolidate.
In Sweden, Precise Biometrics and Fingerprint Cards have completed their merger, combining hardware and software capabilities across biometric security, access and identity. The transaction reflects an increasingly obvious market reality: standalone biometric components are becoming part of broader identity architectures.
That shift follows the threat model.
A highly accurate fingerprint reader solves little if identity was compromised during enrolment. A strong facial matcher provides limited protection if an attacker takes control of the authenticated session afterwards. Customers increasingly need systems capable of combining sensors, algorithms, orchestration and risk intelligence.
Yet other areas of the market remain at a much earlier stage of maturity.
Post-quantum identity is a good example.
TOPPAN Holdings, Japan’s National Institute of Information and Communications Technology and ISARA have demonstrated a proof of concept for migrating existing certificate and smart-card infrastructure towards post-quantum cryptography. Their test environment covered conventional cryptography, a hybrid transition stage and a fully post-quantum configuration, including use of algorithms based on NIST-standardised ML-DSA.
The significance is considerable. It demonstrates that migration of long-lived identity infrastructure can be engineered without simply abandoning existing systems overnight.
But this remains what the organisations themselves describe as a proof of concept.
It does not mean that public authorities or healthcare systems can replace existing cards tomorrow and consider the quantum problem solved. Legacy readers, certification authorities, backend applications, key-management processes and decades-old identity systems have to operate during a transition that may last many years.
The partners themselves envisage further limited implementations before broader real-world deployment.
This makes post-quantum identity a useful lesson in technological language.
A proof of concept answers whether something can work. A pilot examines whether it can work under constrained real-world conditions. Production deployment demonstrates whether the system can operate at scale. Only sustained operation reveals whether it is genuinely infrastructure-grade.
Security procurement frequently collapses these stages into a single word: innovation.
It should not.
A credible assessment of an identity solution needs to examine the entire lifecycle — enrolment, authentication, credential recovery, revocation, system failure, device replacement, adversarial testing, supplier exit, interoperability and incident response.
Only then does functioning technology become dependable infrastructure.
Websites:
Precise Biometrics – precisebiometrics.com
TOPPAN Holdings – holdings.toppan.com
NICT – nict.go.jp
ISARA – isara.com
Identity Is Becoming a Question of Power
The international identity market therefore presents a more nuanced picture than either technology enthusiasts or sceptics often suggest.
Many of the underlying technologies work extremely well.
Faces can be compared with remarkable accuracy under appropriate conditions. Electronic documents can be cryptographically authenticated. Smartphones can hold high-value credentials. Government platforms can perform identity checks at national scale. Digital wallets can disclose selected attributes rather than complete documents. Behavioural biometrics can identify changes that suggest an account is no longer under legitimate control.
The unresolved problems emerge when these individual capabilities become infrastructure.
Can a national identity service survive extreme transaction volumes? What happens when a central register becomes unavailable? How does an individual recover a digital identity after losing both device and credentials? Can a deepfake detector remain reliable against next year’s generation of synthetic media rather than yesterday’s? Who accepts liability for reused KYC? And how sovereign can a national identity system really be if critical elements depend on foreign technology providers?
Those questions belong in feasibility studies just as much as false-match rates and processing times.
For governments and security buyers, technical functionality should therefore be regarded as the first rung of a much longer maturity ladder. It must be followed by evidence of scalability, resilience, adversarial robustness, interoperability, privacy protection, social legitimacy and the ability to maintain the system throughout its operational life.
The present state of the market reflects that spectrum.
Conventional biometric matching is mature across many applications. Deepfake detection provides increasingly valuable signals but cannot yet offer universal reliability. Digital wallets have moved through substantial real-world feasibility programmes and are approaching mass deployment. Age assurance is developing rapidly, but no single technology addresses every requirement. Portable KYC remains an intriguing institutional experiment. Post-quantum identity has moved from theory into practical test environments, but the operational migration has barely begun.
This distinction matters more than the label attached to the latest product launch.
Because digital identity is ultimately becoming a question of power: who can establish identity, who is permitted to challenge it, who controls the underlying infrastructure and who decides what constitutes sufficient proof.
The most important identity system of the future may therefore not be the one with the most impressive algorithm.
It will be the one whose chain of trust still holds when something goes wrong.
Companies, Institutions and Initiatives Covered
This article includes developments involving NIST, Fraunhofer SIT, Fraunhofer IOSB, New Zealand Digital Government, the EU Digital Identity Wallet, the OpenID Foundation, France Identité, Signicat/ReadID, the UK Digital Verification Services Trust Framework, the Philippine National ID system and NIDAS, MOSIP, Nepal’s national identity infrastructure, Visa, BioCatch, SOLO, Incode, Ofcom, Innovative Technology/MyCheckr, the European age-verification architecture, Patronscan, Precise Biometrics, Fingerprint Cards, TOPPAN Holdings, NICT and ISARA.


