Digital Identity Systems — Research Reference

1.4 billion enrollments. World's largest biometric identity database — fingerprints, iris scans, facial photographs linked to 12-digit ID.

2026-06-16 14 min read Research file
Contents

India’s Aadhaar

1.4 billion enrollments. World’s largest biometric identity database — fingerprints, iris scans, facial photographs linked to 12-digit ID.

Documented Exclusion Deaths

Right to Food Campaign documented 20+ starvation deaths where Aadhaar failures blocked PDS ration access. Economist Jean Dreze counted a dozen deaths in Jharkhand alone. Authentication failure rates: 49% in Jharkhand, 37% in Rajasthan. Laborers with worn fingerprints and elderly with changed iris patterns locked out.

Data Breach

January 3, 2018: Tribune India reporters bought database access for $8 via WhatsApp group. 1.1 billion records exposed. UIDAI responded by filing an FIR against the journalist.

Supreme Court (September 26, 2018)

4:1 majority upheld Aadhaar but struck down: mandatory bank/SIM linking, Section 33(2) national security access to biometrics, reduced data retention from 5 years to 6 months.

Rethink Aadhaar Campaign

50+ organizations, 200+ individuals. Documents exclusion testimonials.


EU eIDAS 2.0 — European Digital Identity Wallet

Regulation (EU) 2024/1183, entered into force May 20, 2024. Every Member State must offer a wallet by December 2026; all relying parties must accept by November 2027.

Article 45 Controversy

Article 45 forbids browsers from enforcing security requirements on government-issued CAs. 400+ cybersecurity experts and NGOs signed Mozilla/EFF letter warning any EU member state could issue certificates for MITM interception against any EU citizen.


Worldcoin / World ID (Sam Altman)

Iris scanning for identity verification. At least 8 countries have banned or investigated operations.

Kenya: Court ordered deletion of iris/facial data from 300,000+ Kenyans. Permanent ban on further biometric collection.

Other actions: Spain AEPD ban (GDPR violations), Portugal ban (minors’ biometric data), South Korea fine (~$829K), Hong Kong operations ceased, Brazil blanket ban, Indonesia suspension, Germany corrective measures.


UK Online Safety Act — Age Verification as De Facto Digital ID

“Highly Effective Age Assurance” methods: government-issued ID checks, biometric facial age estimation, credit card verification, digital identity wallets.

VPN sign-ups surged 1,400% the day age verification was enforced (July 25, 2025).


Vaccine Passports as Digital ID Precedent

EU Digital COVID Certificate active July 2021 to June 2023. Infrastructure transitioned to WHO Global Digital Health Certification Network (June 27, 2023).

New York’s Excelsior Pass explored retrofitting for other credentials. Privacy International: “Once biometric data are collected and filed, there is no delete button.”


No-Fly List and Watchlist Systems

TSDB contains 1.2 million names; 4,600 are US citizens/LPRs. Children under age 1 have generated false positives. 30,000 complaints by 2005.

Federal court in Portland ruled no-fly list process unconstitutional (ACLU v. Kashem). Government’s revised process still does not reveal reasons or evidence.


World Bank ID4D and WEF

World Bank claims 850 million lack official ID. ID4D on track to reach 550 million people in 60 countries. Funded by Gates Foundation, UK Government, France, NORAD, Omidyar Network.

WEF Known Traveller Digital Identity — blockchain-based biometric travel identity. Pilot stalled during COVID, never revived.


Biometric Surveillance

Clearview AI: ~30 billion scraped faceprints (CEO Hoan Ton-That, 2023; the company has stated a 100-billion goal). $51.75M settlement (equity stake). Vermont AG lawsuit (April 2025). ICE using Clearview that Illinois cops are barred from using.

China: blacklisted persons’ faces projected on billboards at intersections. SenseTime raised roughly $2.6 billion in venture funding (mixed investors, including Alibaba and SoftBank).

City bans: San Francisco, Boston, Portland (OR) banned government/law enforcement use. Illinois BIPA strongest state law.


Counter-Arguments

World Bank: 850 million without ID cannot access healthcare, education, financial services. India’s fuel subsidy programme saves ~$1 billion/year through Aadhaar-linked direct transfers.


Key Narrative Threads

  1. The ratchet effect: COVID vaccine passports → WHO global system. Infrastructure described as “extensible.” Active dismantlement required; default is persistence.
  2. Exclusion as feature: Aadhaar 49% failure rate in Jharkhand. No-fly list hits children under 1. Not edge cases — operating logic.
  3. The browser trust problem: eIDAS Article 45 = government MITM capability. 400+ experts said so.
  4. Global coordination: ID4D across 60 countries. Shared funding, architecture, personnel.
  5. The Worldcoin pattern: 8 countries banned it. Kenya ordered deletion of ~350,000 records (Judicial Review Application No. E119 of 2023, [2025] KEHC 5629). Company reported ~26 million iris hashes by early 2026 regardless.

Recent developments (late 2025–2026)

UK — the BritCard / digital ID push under Starmer

On 26 September 2025 the UK government announced a new digital ID scheme to be rolled out to all UK citizens and legal residents by the end of the Parliament (due by 2029). The government framed it as a tool to make illegal working harder and to streamline access to public services. The free digital ID would be stored on a phone and contain name, date of birth, nationality/residency status, and a photo “as the basis for biometric security,” and was to be mandatory for Right to Work checks by the end of the Parliament. PM Keir Starmer was quoted: “Digital ID is an enormous opportunity for the UK. It will make it tougher to work illegally in this country, making our borders more secure.”

Starmer unveiled the plans at the Global Progressive Action Conference in London on 25 September 2025; the scheme was widely branded “BritCard” / “Brit Card” in the press. Work and Pensions Secretary Pat McFadden pointed to Estonia’s identity card as a model. The policy impetus is traced to two Labour-linked sources: a June 2025 Labour Together report proposing a “BritCard” digital identity, and a September 2025 Tony Blair Institute report advocating a consolidated “super ID card.” In April 2025 more than 40 Labour MPs had signed an open letter urging a digital ID to tackle irregular immigration.

Public reaction was immediate. The UK Parliament petition “Do not introduce Digital ID cards” (petition 730194) passed 1 million signatures within 24 hours, crossed 2 million by 27 September 2025, and closed on 9 January 2026 with 2,984,191 signatures — one of the largest petitions in the Parliament petitions system’s history. Parliament debated it on 8 December 2025. In its formal response the Department for Science, Innovation and Technology declined to drop the scheme, stating it would “introduce a digital ID within this Parliament to help tackle illegal migration, make accessing government services easier, and enable wider efficiencies,” while asserting it would not be a criminal offence to decline one and that police could not demand it during stop-and-search.

In January 2026 the government dropped the mandatory element ahead of a public consultation: holding the government digital ID itself would not be compulsory for Right to Work checks. Employers must still conduct checks digitally from 2029, but individuals may use a third-party private digital ID provider as well as the GOV.UK app. A public consultation (“Making public services work for you with your digital identity”) ran from 10 March 2026 to 5 May 2026, supported by an advisory group convened by Chief Secretary to the Prime Minister Darren Jones and, later, a 120-member citizens’ “People’s Panel.”

The digital ID builds on existing infrastructure: the GOV.UK Wallet (announced January 2025; a smartphone repository for credentials, beginning with a mobile driving licence and expanding toward passports) and GOV.UK One Login, the single sign-on for government services. One Login had over 12 million registered users by 2025, with identity verification through it becoming compulsory for new company directors from 18 November 2025.

The UK arc fits the dossier’s existing ratchet thesis: the compulsory framing was withdrawn under a near-three-million-signature backlash, but the underlying infrastructure (One Login, GOV.UK Wallet, mandatory digital Right to Work checks even if not via the state app) advanced regardless. The retreat was on the branding and the single-provider mandate, not on building the identity layer.

EU — European Digital Identity Wallet (eIDAS 2.0) approaching the 2026 milestone

Under Regulation (EU) 2024/1183 (adopted 20 May 2024), every EU member state must make at least one compliant EU Digital Identity (EUDI) Wallet available to citizens, residents, and businesses by the end of 2026; the commonly cited hard deadline is 31 December 2026, with production launches clustering in Q4 2026. Regulated relying parties (including banks, for strong customer authentication) must accept the wallet by late 2027, and the Commission targets 80% adoption by 2030. Personal-capacity users can e-sign with legal validity free of charge. This extends the dossier’s existing eIDAS 2.0 / Article 45 section with the now-imminent rollout dates.

Large-scale pilots ran through 2025, with two additional pilots starting autumn 2025 after the original four concluded; certification activity was slated across Q1–Q3 2026 ahead of the production deadline.

Age verification as digital-ID on-ramp (UK, EU, US)

UK: Ofcom’s powers to enforce the Online Safety Act’s “highly effective age assurance” duties took effect on 25 July 2025 (the dossier’s existing OSA section notes the same date and the 1,400% VPN surge). Ofcom opened an enforcement programme and, by November 2025, had 76 sites under investigation. It issued its first fines: £50,000 against an “nudification” site and £1 million against AVS Group Limited (with a £1,000/day penalty for continued non-compliance), described in coverage as among its largest OSA fines to date.

EU: On 14 July 2025 the European Commission released an age-verification “blueprint” (the “mini-wallet”) alongside guidelines under Article 28(1) of the Digital Services Act for very large online platforms. The mini-wallet lets a user prove they are over 18 without revealing personal data to the service, with single-use, non-correlatable attestations to prevent cross-platform tracking. It is built on the same technical specifications as the forthcoming EU Digital Identity Wallet — explicitly a stepping stone toward the end-2026 EUDI rollout. Five member states pilot it in 2025–2026: France, Spain, Italy, Denmark, and Greece, integrating with national wallets (France Identité, Spain’s Cartera Digital, Italy’s IT Wallet in the IO app, Denmark’s MitID).

US: On 27 June 2025 the Supreme Court decided Free Speech Coalition, Inc. v. Paxton (6–3), upholding Texas H.B. 1181, which requires age verification on sites where more than one-third of content is “sexual material harmful to minors.” The majority applied intermediate scrutiny; Justice Kagan dissented (joined by Sotomayor and Jackson), arguing strict scrutiny should apply. By the end of 2025, roughly 25 states had enacted adult-content age-verification laws (most using a one-third threshold; Kansas at 25%), with nine states’ laws taking effect in 2025 (per EFF: South Carolina, Florida, Tennessee, Georgia, Wyoming, North Dakota, Arizona, Ohio, Missouri). EFF reported Florida saw a ~1,150% increase in VPN demand after its law took effect.

The pattern across all three jurisdictions is the same and reinforces the dossier’s existing OSA framing: age assurance is the politically palatable wedge (“protect children”) that normalizes presenting verified identity (or a wallet-issued attestation) to access ordinary online services — and in the EU case the age-verification tool is explicitly the same technical stack as the national identity wallet. Cross-reference: see AI moderation (platform compliance and content gating) and the UK OSA section above in this file.

Worldcoin / “World” (Sam Altman) — rebrand, US/UK expansion, continued bans

Worldcoin rebranded its ecosystem to “World” and unveiled a new iris-scanning Orb (reported October 2024). On 30 April 2025 World launched in the United States with flagship locations in six cities — Atlanta, Austin, Los Angeles, Miami, Nashville, and San Francisco — letting US residents verify “proof of human” via iris scan, and announced an Orb Mini (“It goes where you go”). It also announced partnerships: a “World Visa card” available only to iris-verified users, and a Match Group pilot using World ID for age/identity verification on Tinder (initially in Japan). World launched in the UK in June 2025.

Regulatory pressure continued in 2025 alongside the expansion. On 5 May 2025 the High Court of Kenya ruled World’s activities illegal, citing violations of the Data Protection Act 2019 (extending the deletion order noted in the dossier’s existing Worldcoin section). In May 2025 Indonesia’s Ministry of Communication and Digital suspended World’s operating permit, citing registration/permit violations by a local operator.

India — Aadhaar expansion into the private sector

On 2 February 2025 India’s Ministry of Electronics and IT introduced the Aadhaar Authentication for Good Governance (Social Welfare, Innovation, Knowledge) Amendment Rules, 2025, allowing private businesses (e-commerce, travel, hospitality, healthcare) to use Aadhaar authentication to verify customers — broadening access that had been restricted after the 2018 Supreme Court judgment (covered in the dossier’s existing Aadhaar section). Critics quoted by TechCrunch: Supreme Court advocate-on-record Prasanna S said the amendment “attempts to virtually re-legislate what was struck down”; Sidharth Deb (The Quantum Hub) warned it “carries the risk of exclusion”; Kamesh Shekar (The Dialogue) called for clearer evaluation criteria. Mandatory PAN–Aadhaar linking continued, with unlinked PAN cards set to become inoperative from 1 January 2026.

Cross-references and the control-grid throughline

These 2025–2026 developments tighten the identity-to-access linkage that is the dossier’s organizing thesis: the UK (digital Right to Work checks), the EU (wallet acceptance mandate for relying parties by 2027), the US (verified-age gating of lawful content), and India (private-sector Aadhaar gating of commerce) all move identity verification from an exceptional event to a precondition for ordinary participation. The age-verification wedge and the national wallet are converging on the same infrastructure (explicit in the EU blueprint). For adjacent control-surfaces see the sibling dossiers: the health-governance ratchet (the post-COVID health-credential ratchet), AI moderation (platform-side compliance and content gating), and CBDC (payment-rail identity binding and the social-credit connection).

Get updates on the Evil Robots series

Newsletter essays on AI escape, deception, and the humans who built them.