DIDAS warns that age verification alone cannot solve harmful content, addictive design, profiling or commercial exploitation of children online. Where verification is necessary, it should reveal only what is required, such as a simple “over/under age threshold”, without exposing identity, birth date or biometrics. DIDAS proposes six principles: privacy by design/default, unlinkability, data minimisation, open-source […]
Phocuswright sees that the EU Digital Identity Wallet is gaining ground, but adoption differs strongly between France, Germany, and the UK. Awareness is growing, France leads with 25%, while Germany shows the largest increase from 13% to 21%. Trust is decisive: 54% of Germans trust the Personalausweis, while trust in digital identity systems is clearly […]
Security researchers uncovered severe vulnerabilities in Belgium’s Connective eID signing software, used by more than 2 million citizens. The technology is deployed by 8 of Belgium’s 10 largest banks, more than 60 government agencies and over 1,000 enterprises. A fundamental weakness was that the software failed to properly verify which website was communicating with the […]
AI agents challenge traditional IAM by acting at machine speed and scale, with unpredictable access patterns that human-centric security models weren’t designed for. Prompt injection, credential exposure and multi-agent delegation create attack paths that conventional authentication and authorization controls struggle to govern. Existing behavioral monitoring can be effectively blind to autonomous agents, while ownership, accountability, […]

