The identity layer isn’t being rebuilt. It’s being outgrown.
Consolidating yesterday’s identity tools is a retention strategy for incumbents. Continuous, privacy-first assurance is a growth strategy for the future.
There is a comfortable story going around the identity industry right now. It goes like this: the way to prepare for the next decade of digital trust is to gather up the authentication tools you already have — one-time passcodes, tokens, transaction signing, the credentials layer — and bring them together under a single platform, so you can modernise without disruption. Nothing gets ripped out. Nothing breaks. You simply add the new on top of the old, at your own pace.
It is a reassuring message. It is also, on closer inspection, a message written for a very specific audience: identity vendors with a great deal of legacy to protect. For the world’s largest banks, carrying decades of accumulated authentication infrastructure, “modernise without touching anything” is exactly what they want to hear. But that story tells you far more about the seller than about where digital identity is actually going.
Point-in-time trust is being outpaced by the threat
For most of its history, identity has worked as a series of gates. You verify a customer once at onboarding. You authenticate them at login. You sign a transaction when money moves. Each of these is a moment — a discrete check, passed or failed, and then the door closes behind you.
That model is now being outpaced by the very thing everyone claims to be worried about. AI-driven fraud does not politely present itself at the gate. Deepfakes defeat the selfie check. Injection attacks bypass the camera entirely. Synthetic identities are assembled to pass onboarding cleanly and then behave, session after session, in ways a one-time check was never designed to catch. When the adversary is continuous and adaptive, a defence built out of point-in-time gates is structurally behind — no matter how many of those gates you consolidate onto one screen.
This is the flaw in the consolidation narrative. Bringing five authentication products under one roof does not change what those products are: gates. A bigger bundle of gates is still a bundle of gates. The organisations that will define the next decade of trust are not asking how to manage more of them more effectively. They are asking a harder question — how do I know, continuously, that the entity I am dealing with is who and what it claims to be, across the whole life of the relationship, and not merely at the three or four moments I happened to check.
The organisations being built now don’t carry the legacy
Here is the part the incumbent identity vendors’ story quietly omits. Organisations with legacy identity management stacks are going to be at a disadvantage to modern firms such as the organisations shaping European financial services today — challenger banks, digital-first lenders, the retail and neobank players. They have no legacy estate to preserve. They never issued the hardware tokens. They are not maintaining an on-premises authentication stack from a previous era. For them, “adopt the new without abandoning the old” is not a benefit. There is no old. There is only the question of whether they build on trust infrastructure that assumes a continuous, adversarial, AI-shaped reality from day one, or on infrastructure designed around the constraints of an era they were fortunate enough to skip.
These companies do not want to be told they can modernise gradually. They want to be right the first time. That means three things that a consolidated legacy platform is not built to deliver: assurance that is continuous rather than momentary; privacy that is designed in rather than bolted on; and defence that is native to the AI threat surface rather than adjacent to it.
Organisations with legacy stacks, if they don’t modernise, will be at a significant disadvantage in that their systems won’t deliver the best customer experience, risk reduction, AI-native capability, and price point, due to the simple fact that, at their core, they were built for a different threat and use case landscape.
Regulation is rewarding continuous, auditable trust
The regulatory direction of travel in Europe points the same way. eIDAS 2.0 and the EU Digital Identity Wallet are moving identity toward reusable, user-held credentials, which makes it more critical, not less, to verify that a presented credential is being used by its legitimate holder in real time, and not replayed, injected or synthesised. PSD3 and the payments framework is set to tighten expectations around fraud and strong customer authentication. DORA pushes financial entities toward demonstrable, continuous operational resilience rather than point-in-time attestation. None of this rewards a static gate that was passed at some moment in the past. All of it rewards trust that is live, auditable and continuous.
Privacy is the other half of the same shift. Reusable identity only works if organisations can rely on it without hoarding data they do not need and cannot defend. A trust layer that treats data minimisation as a design principle, verifying what must be verified and no more, is not a compliance nicety. It is the key element that makes continuous assurance safe to operate at scale while meeting regulatory compliance.
Who actually rebuilds the identity layer
So it is worth being precise about language. The identity layer of the internet is not going to be rebuilt by the vendors whose commercial priority is protecting the estate they already sold. That is not a criticism of their engineering; it is an observation about incentives. When your success depends on your existing base modernising slowly and buying more of what they already own, “disruption” is not the story you tell. “Gradual, without disruption” is.
The identity layer will be built, instead, by vendors that never carried the legacy, and by the trust infrastructure built within them. Infrastructure that assumes the adversary is continuous, so assurance must be continuous. These systems treat privacy as the precondition for reuse at its core, not something bolted on. They are also designed for the AI threat surface as it is in 2026, not as it was when the tokens were first issued.
The future of digital trust does not belong to whoever consolidates the past most neatly. It belongs to whoever is building for what comes next. At Ditto, this is the whole of our thesis. We are building continuous, privacy-first assurance that focuses on the core notion of what trust on the internet is supposed to mean.
Hi I'm Matt! I've 20 years of experience in identity, mobile intelligence and fraud prevention solutions, and am working with Ditto to build the next generation of identity.