eIDAS 2.0 / EU DIGITAL IDENTITY WALLET (EUDI)
- Status
- ACTIVE — Regulation (EU) 2024/1183; in force 20 May 2024; every member state must offer a compliant EUDI Wallet by end-2026, regulated relying parties must accept by late 2027
- Hazard — Reach
- 86
- RCH / FND / ENT
- 9 / 9 / 8
- Conduct
- FRAMEWORK-INSTRUMENT — PRIVACY BY DESIGN ON PAPER, THE LINKABLE KEY BY CAPABILITY
OLYMPUS opened an institutional file on a framework. A regulation has no Big Five and no Dark Triad, and the unit does not invent them; what a framework has is a text, a deployment deadline, and a governing model. eIDAS 2.0 is catalogued here as the master credential — the statute that gives every EU resident one verifiable, cross-border identity wallet and obliges the continent’s institutions to accept it. The finding is the shape of the component, not the intent of its drafters: an identity layer with genuine convenience and genuine privacy engineering on its face, and, underneath, the two properties that make an identity layer the load-bearing piece of any control grid — everything can be hung off it, and the issuer holds the key. The numbers in the front matter are reach, entrenchment, and durability. A credential outlives every commissioner who signs it, and identity is the component you enroll into once and cannot delete.
Institutional Archetype
THE MASTER CREDENTIAL — The archetype is the single key that opens every door and, held by the issuer, can lock any of them. The EUDI Wallet does not run a bank, a border post, or a platform; it is the credential those services are obliged to check. Once a population is enrolled into one verifiable identity, every other capability on the grid — payments, benefits, age-gated content, strong customer authentication, movement — can be attached to it without any further vote. That is the structural power: not authorship of any single exclusion, but authorship of the credential inside which every future exclusion becomes a configuration change rather than a new law. The wallet is engineered for selective disclosure — prove you are over 18 without revealing your birthday — and that engineering is real. What the engineering cannot remove is the property that made identity the load-bearing component in the first place: the issuer that can turn a credential on can turn it off, and the relying party that must accept it can be required to demand it.
Mandate & Origin
eIDAS 2.0 is Regulation (EU) 2024/1183, which amended the original 2014 eIDAS regulation and entered into force on 20 May 2024. Its central instrument is the European Digital Identity Wallet (EUDI Wallet). The architecture, from the regulation and the Commission’s own pages:
- Universal provision: every member state must make at least one compliant EUDI Wallet available to citizens, residents, and businesses by the end of 2026 — the commonly cited hard deadline is 31 December 2026, with production launches clustering in Q4 2026.
- Mandatory acceptance: regulated relying parties — including banks, for strong customer authentication — must accept the wallet by late 2027, and the Commission targets 80% adoption by 2030.
- Free legal e-signature: personal-capacity users can e-sign with legal validity free of charge.
- Selective disclosure: the wallet is specified to release only the attributes a service actually needs, with attestations designed to be non-correlatable across services.
- Piloting: large-scale pilots ran through 2025 (two additional pilots began autumn 2025 after the original four concluded), with certification activity slated across Q1–Q3 2026 ahead of the production deadline.
Funding & Backers
The framework is a European Commission programme, built out through the Digital Europe Programme and the Connecting Europe Facility, with the member states delivering the national wallets that implement it — France’s France Identité, Spain’s Cartera Digital, Italy’s IT Wallet in the IO app, Denmark’s MitID, and their counterparts. The backing is therefore public and continental: the issuer is the state, in twenty-seven variants, coordinated by a supranational regulator that sets the common technical framework the national wallets must certify against.
Running ahead of the full wallet, the Commission released an age-verification “mini-wallet” in July 2025 — built on the same technical specifications as the EUDI Wallet, and explicitly described as a stepping stone to the end-2026 rollout. It is piloting in France, Spain, Italy, Denmark, and Greece, integrating with those national wallets. The mini-wallet is the on-ramp: a citizen learns to present a state-issued attestation to access ordinary online services under the “protect minors” framing, on the identical stack that will later carry the full identity credential.
Institutional Voice & Intent
The voice is the trust-and-convenience register — the grammar of “a trusted and secure European e-identity,” of interoperability, user control, and privacy by design. The statute speaks in the language of the citizen’s own benefit: one wallet, works everywhere, you choose what to share, the state cannot see where you use it. And the privacy engineering behind that grammar is not decorative — selective disclosure and non-correlatable attestations are specified in the framework, and the age-verification mini-wallet demonstrates them: prove you are over 18 without handing the service your identity. On its face this is the strongest privacy posture any state identity system has offered.
Stated intent: Give every European a single, secure, cross-border digital identity under the user’s own control; enable interoperability across twenty-seven member states; let citizens prove exactly what a service needs and nothing more; end the patchwork of incompatible national schemes.
Observed intent: Enroll the continent into one verifiable identity credential that regulated services are obliged to accept, on a fixed deadline; establish the identity layer onto which every other grid capability — payments, benefits, content access, movement — can later be attached without a new statute; and set the common technical standard other jurisdictions read against.
Gap: The stated and observed intents overlap wherever “one wallet under your control” describes the convenience it genuinely delivers. The gap opens at the two properties the privacy engineering cannot remove. First, linkability by design at the issuer: selective disclosure limits what a relying party learns, but the wallet is still a single state-issued credential, and the roster of where mandatory acceptance applies expands by regulation, not by consent — the age-verification mini-wallet already normalizes presenting a state attestation to reach ordinary services. Second, the browser-trust clause (below), where the mechanism required for cross-border interoperability is, by the cybersecurity community’s reading, the same mechanism required for mass interception. Nothing in the wallet’s rollout was imposed at gunpoint; each enrollment is offered as a service the citizen asked for. That is the point of building the identity layer as a convenience with a deadline rather than a mandate with a backlash.
Position in the Apparatus
eIDAS 2.0 is the identity component of the European wing of the apparatus this file documents, and it sits directly beside the two statutes already on file. The EU Digital Services Act is the content-control rulebook; the EU AI Act is the model-control rulebook; eIDAS 2.0 is the identity rulebook — and the age-verification mini-wallet is where they meet, because it was released alongside DSA Article 28(1) guidance for very large platforms and is built to gate content by verified attribute. Identity is upstream of both: a content regime and a model regime both become far more enforceable once every user is a verified credential rather than an anonymous session. Where the American identity apparatus is a fragmented assembly — the watchlists, Clearview’s scraped index, the state-by-state age-verification wave — the EU is building the single credential by statute, on a deadline, with mandatory acceptance. The framework is the template other jurisdictions read against; the UK’s post-BritCard retreat left the underlying identity layer building regardless, and the direction of travel is the same one.
Actions & Leadership Choices
Founding purpose, judged on evidence. eIDAS 2.0 answered real friction — twenty-seven incompatible national identity schemes, no cross-border way to prove who you are online, and a private-platform identity layer (log in with Google, log in with Facebook) that the EU had no wish to depend on. As interoperability it is genuine, and the privacy engineering is the strongest a state identity system has shipped. The deeds below are weighed against that genuine purpose, not against a bad-faith prior — and the load-bearing conduct is a single, documented technical fight.
The Article 45 controversy, where the conduct shows. The framework’s most-contested clause is Article 45, which governs the browser trust of Qualified Website Authentication Certificates (QWACs) issued under member-state trust lists. On the cybersecurity community’s reading, Article 45 constrains browsers — Chrome, Firefox, Safari, all of them — from enforcing their own security requirements against a government-designated certificate authority: if a member state issues a certificate for a site, the browser must trust it, and the padlock shows as though nothing is wrong. That is the ordinary technical description of a man-in-the-middle capability. More than 400 cybersecurity experts and NGOs signed a joint Mozilla/EFF letter warning the clause would let any member state intercept any EU citizen’s encrypted traffic; a separate scientists’ open letter reached 552 signatories from 42 countries (as of late November 2023). The EU’s position, stated at full strength, is that Article 45 is about interoperability for the digital identity wallet, not surveillance. The cybersecurity community’s answer, also at full strength: the mechanism required for the interoperability and the mechanism required for the interception are identical, and you cannot build the one without enabling the other. The litigation here is technical, not judicial, and it is not resolved — Mozilla’s November 2024 account of the negotiated safeguards is the record of a compromise, not of the objection being withdrawn.
The stepping-stone, on the record. The clearest action is the sequence. In July 2025 the Commission released the age-verification mini-wallet — the same technical stack as the full EUDI Wallet — under the child-protection framing, and put it into pilot in five states before the identity wallet itself was mandatory. The capability to present a state-issued attestation to access an ordinary service was normalized first, on the palatable ground, ahead of the deadline that makes the full credential universal. Nothing in that sequence was unlawful or hidden; the Commission described the mini-wallet as a stepping stone in its own release. The recurring lesson of this file’s drawer, in identity form: the capability is built first on the easy case, the category it serves expands later, and a framework never resigns.
CONDUCT verdict: FRAMEWORK-INSTRUMENT — PRIVACY BY DESIGN ON PAPER, THE LINKABLE KEY BY CAPABILITY. A genuine interoperability framework with the strongest privacy engineering a state identity system has offered, whose load-bearing property is nonetheless that it enrolls a continent into one issuer-held credential that regulated services are obliged to accept — and whose one documented technical fight, Article 45, is precisely the argument over whether the plumbing for cross-border trust is separable from the plumbing for interception. The privacy is real. So is the key.
Reach Assessment
Institutional: Maximum within its class. eIDAS 2.0 is the identity template of the democratic world’s digital-identity architecture — statutory, deadlined, and mandatory-acceptance where other schemes are voluntary or fragmented. It sits beneath the DSA and the AI Act as the component both grow more enforceable against.
Memetic: High. “Digital identity wallet,” “selective disclosure,” “trusted acceptance” become the vocabulary other jurisdictions conduct their own identity debates in — the same Brussels-Effect mechanism the DSA runs on, in identity form: build one wallet for the largest regulated market and the standard travels.
Civilizational: High. The framework does not build AI systems and does not write their refusals. It builds the credential that everything else on the grid can be hung off — payments, content, benefits, movement — on a continent-wide deadline, and it fought its one open technical battle over whether the trust plumbing that makes the credential portable is separable from the plumbing that makes any citizen’s traffic interceptable. Identity is the component you enroll into once. There is no delete button, and the issuer keeps the key.
Sources: European Commission — European Digital Identity (EUDI) Regulation; Regulation (EU) 2024/1183 — EUR-Lex; Establishment of the European Digital Identity Framework — EUR-Lex summary; EU Digital Identity Wallet Home — European Commission digital-building-blocks; eIDAS 2.0 Sets a Dangerous Precedent for Web Security — EFF; Mozilla, EFF and cybersecurity experts publish letter on the dangers of Article 45.2 — Mozilla; Europe prepares to break browser security with new law — The Register, 8 Nov 2023; Behind the scenes of eIDAS: a look at Article 45 and its implications — Mozilla net policy, Nov 2024; Commission makes available an age-verification blueprint (14 Jul 2025) — European Commission; EU moves forward on age verification with release of guidelines, software — Biometric Update, Jul 2025.
Get updates on the Evil Robots series
Newsletter essays on AI escape, deception, and the humans who built them.