The internet has an identity problem

We have spent thirty years building an internet that is extraordinarily good at moving information and increasingly good at moving money, but remarkably bad at establishing who or what is on the other side of an interaction.

The result is that we compensate with passwords, usernames, security questions, one-time codes, passport scans, selfies, cookies, device fingerprints and endless databases containing copies of the same personal information.

It is a terrible architecture.

If a website needs to know that I am over eighteen, why should I give it my name, photograph, date of birth, address and passport number? It doesn't need to know who I am. It needs to know one thing about me:

I am over eighteen.

That distinction sounds trivial, but it changes the whole digital identity debate.

Identity should not be about proving who you are every time. It should increasingly be about proving what is true about you.

The UK government itself describes digital identity in these terms. Its Digital Identity and Attributes Trust Framework covers services that allow people to prove their identity, information about themselves or their eligibility to do something.

That word attributes may turn out to be far more important than the word identity.

Imagine buying a bottle of wine.

Today, somebody might ask to see your driving licence. To establish that you are eighteen, you potentially reveal your photograph, full name, exact date of birth and home address.

That's absurd when you think about it.

A digital credential could simply answer:

Over 18? YES.

Nothing else needs to be disclosed.

This is increasingly where Europe is heading. The European Commission's age-verification system is specifically designed so that someone can prove they are over eighteen without revealing their precise age, identity or other personal information. Its latest architecture even incorporates zero-knowledge proof technology.

That introduces an important idea into everyday life: selective disclosure.

Instead of identity being a document you hand over, identity becomes a collection of verifiable claims. I am over eighteen. I have a driving licence. I am authorised to represent this company. I have sufficient funds. I live in the United Kingdom. I am qualified to practise medicine. I have permission to spend up to £5,000 on behalf of my employer.

The organisation requesting the information gets the answer it needs and, ideally, nothing more.

That's why I find the term digital identity slightly misleading.

The bigger issue is digital trust.

When I walk into my local bank, there are dozens of contextual signals establishing trust. The people may recognise me. I carry documents. I have a history with the institution. There are laws governing what happens if something goes wrong.

Online, much of that disappears.

So, we have tried to recreate trust by accumulating data.

The more we know about you, the theory goes, the more confident we can be that you are you.

That has produced gigantic honeypots of personal information. Companies collect passports, dates of birth, addresses, photographs and biometric information because everybody independently needs to establish the same facts.

A better model turns this around.

Instead of:

Trust me because I know everything about you.

We move towards:

Trust this assertion because a trusted authority cryptographically attests that it is true.

That is a fundamentally different internet and here we reach the difficult part. If a credential says I am over eighteen, who issued it? If it says I am Chris Skinner, who established that? If it says I have £100,000 available to invest, who verified the funds? Government? A bank? Apple or Google? A specialist identity company? A decentralised network?

This is why governments keep talking about trust frameworks, rather than merely digital ID cards. Britain's framework establishes rules under which digital verification services can be certified as trustworthy. The Data (Use and Access) Act 2025 has subsequently provided a statutory basis for encouraging trusted digital verification services across the economy.

The UK's emerging system is therefore potentially more interesting than the simplistic argument over whether Britain should have "digital ID".

The architectural question is whether we create one enormous government identity database or an ecosystem in which trusted organisations can issue and verify credentials according to common standards.

Those are very different propositions.

Then there is the European Union and the EU is taking this further with the European Digital Identity Wallet.

Member States are required to provide wallets by the end of 2026. The idea is that individuals control a wallet containing trusted digital credentials that can be presented to governments and businesses across Europe.

Importantly, the architecture supports selective disclosure. The EU's age-verification example demonstrates what this means in practice: the service can receive confirmation that the user meets the age requirement without receiving the underlying identity information.

This makes the smartphone potentially something much more important than a digital wallet for money. It becomes a wallet for trust. Passport. Driving licence. Qualifications. Bank credentials. Employment status. Age. Health entitlements. Memberships. Authority to act.

Potentially hundreds of digitally verifiable attributes … and that is where banking enters the picture.

Banks have spent decades building Know Your Customer infrastructure. They know who you are because regulation requires them to know. That capability has traditionally been treated as a compliance cost. Digital identity potentially turns it into an asset.

Imagine that a website needs confirmation that I am over eighteen. My bank could attest to that without telling the website my date of birth.

A property platform needs confirmation that I can afford a £500,000 house. My bank doesn't need to reveal my account balance. It could provide a credential stating that I satisfy the required financial threshold. An employer needs to know that an account belongs to me. A government department needs confirmation of my address. A merchant needs to know that the person initiating a high-value transaction is genuinely authorised to do so.

Suddenly the bank is not merely storing and moving money. It is providing trusted assertions about customers.

That could become a significant role in the next generation of financial services which is where the discussion gets even more interesting.

Digital identity today is mainly framed around people.

Tomorrow it will increasingly involve machines.

Imagine telling an AI agent: Book my flights to Singapore, find a hotel near the conference, spend no more than £4,000 and use my British Airways status where possible.

The agent now needs an identity. Not necessarily your identity. It needs something more nuanced. It needs to prove: I am an authorised agent acting for Chris. Chris has authorised me to book travel. I may spend up to £4,000. This authority expires on Friday. I cannot transfer money to another person.

Now identity becomes inseparable from authority and authority becomes inseparable from trust.

The question facing a merchant is no longer simply:

Who are you?

It becomes:

Who are you acting for, what are you authorised to do, who granted that authority, how can I verify it and who is liable if something goes wrong?

That is a vastly more sophisticated trust problem.

This is why I think we may eventually stop talking about digital identity as though it were the destination. Identity is merely one component. The emerging architecture looks more like:

  • Who are you?
  • What is true about you?
  • What are you allowed to do?
  • What are you trying to do?
  • Can you execute it?
  • Who carries responsibility?
  • Can we prove afterwards what happened?

That is the infrastructure required for an agentic economy.

There is also an important paradox here.

People often assume digital identity means less privacy because governments and companies will know more about us. Poorly designed digital identity absolutely could produce that outcome. Properly designed digital identity could do the opposite.

Today I routinely disclose far more information than necessary simply because our identity technology is primitive.

A privacy-preserving credential can reveal less. Not my birthday. Just "over 18". Not my bank balance. Just "sufficient funds". Not my passport. Just "UK citizen". Not my medical record. Just "eligible".

The EU's age-verification architecture demonstrates that this is technically feasible. Its model deliberately separates proof of eligibility from disclosure of identity.

So, the privacy debate should not simply be: Should we have digital identity? It should be: What is the minimum information required to establish trust?

That is a much better question.

The issue is that we built the internet in layers. TCP/IP moved information. The web made information usable. Cloud computing made computing scalable. Smartphones made the network personal. APIs connected services. Digital payments made commerce instantaneous. AI is now making the network intelligent … but one fundamental layer remains incomplete:

TRUST.

Who are you? What can you prove? Who vouches for you? What may you do? What may your machine do? Who carries the liability?

Those questions become much more important when billions of humans, companies, devices and autonomous agents start transacting with each other.

We are beginning to build the trust infrastructure of the digital economy.

And whoever controls that infrastructure – governments, banks, Big Tech, decentralised networks or some combination of them – may end up controlling one of the most important layers of the twenty-first-century internet.

The debate isn't really about proving who you are.

It is about who gets to decide whom we trust.

 

This blog was inspired by a few articles as listed below:

[1]: https://www.gov.uk/government/publications/uk-digital-identity-and-attributes-trust-framework-04/uk-digital-identity-and-attributes-trust-framework-gamma-04-pre-release

[2]: https://digital-strategy.ec.europa.eu/en/policies/eu-age-verification

[3]: https://assets.publishing.service.gov.uk/media/6a54d8b52467584757371e0e/Annual_Report_of_Part_2_DUAA__1__A.pdf

[4]: https://digital-strategy.ec.europa.eu/en/policies/eudi-regulation

[5]: https://ec.europa.eu/digital-building-blocks/sites/spaces/EUDIGITALIDENTITYWALLET/pages/930450954/The%2BAge%2BVerification%2BManual

[6]: https://digital-strategy.ec.europa.eu/en/news/commission-urges-member-states-rollout-eu-age-verification-app

 

Chris Skinner Author Avatar

Chris M Skinner

Chris Skinner is best known as an independent commentator on the financial markets through his blog, TheFinanser.com, as author of the bestselling book Digital Bank, and Chair of the European networking forum the Financial Services Club. He has been voted one of the most influential people in banking by The Financial Brand (as well as one of the best blogs), a FinTech Titan (Next Bank), one of the Fintech Leaders you need to follow (City AM, Deluxe and Jax Finance), as well as one of the Top 40 most influential people in financial technology by the Wall Street Journal's Financial News. To learn more click here...