The goal was never digital identity. It was orchestrating trust.
Reflections from the Global Digital Collaboration Conference, Geneva, 1–3 September 2026.
Sessions were held under the Chatham House Rule. What follows carries no attribution to any speaker or organisation.
I have been to a lot of identity conferences, and sat through a lot of architecture diagrams. I left Geneva more certain than ever of something that would have sounded premature a few years ago: this is no longer a technology challenge. The technology works, and it is proven.
That is not a small thing to be able to say. For a decade our industry’s hardest problems were technical ones, because the technology genuinely was the constraint. Selective disclosure was a research question. Wallets were a slide.
What that leaves is harder and considerably more interesting: not proving who someone is, but orchestrating the conditions under which a stranger’s claim can be trusted, across institutions and borders that have no particular reason to trust each other.
That distinction sounds academic until you try to build against it. It changes what you buy, what you budget for, and who needs to be in the room when you decide.
The question has changed
For years our industry has been organised around a single question. Who are you? Answer it well enough and everything downstream was assumed to follow – onboarding, authorisation, compliance, fraud prevention, all treated as consequences of identification.
That framing has quietly expired. It has been replaced by a ladder of questions, and identification is only the first rung.
Can I trust the credential you are presenting? Can I trust whoever issued it, and can I establish that in the moment? Are you authorised to act on behalf of whoever you are acting for, and can you demonstrate that at the point of the interaction? Can that trust travel – across a border, across a sector, across two technology ecosystems designed by people who have never met?
And increasingly, a question that barely existed a few years ago, can we establish something about the intent behind an interaction, whether the counterparty is a human being or an AI agent acting on someone’s behalf?
Delegated authority is the thinnest part of the current stack. We have spent enormous effort on establishing that a person is who they claim to be, and much less on establishing what they have been authorised to do, and by whom. Add software agents acting under delegation and the gap becomes harder to ignore.
None of these questions are answered by knowing who someone is. They are answered by orchestration.
Orchestration is what happens after the credential verifies
The most useful session I attended was a breakout on what happens when digital identity meets payments. I went in expecting a technical discussion and came out with a much clearer view of where the real work sits.
The technical picture is encouraging. We are close to defining verifiable credential schemes for payments. Digital payment credentials are being designed to meet both payment authentication and regulatory requirements such as eIDAS, and the component parts are increasingly well specified: device binding, dynamic linking of transaction data, wallet attestation, cross-origin authentication, combined presentation.
The policy surface underneath is where the difficulty lives. Any workable scheme has to hold across the different categories of bank account in use around the world, which is already multi-dimensional. Introduce credit cards and the dimensions multiply again. The hard part is not the cryptography; it is the number of dimensions the policy has to hold across at once.
Here is what I took from it, offered as my reading rather than as the conclusion of the session.
For a regulated institution, verifying a credential may turn out to be the straightforward part. Look again at what is being specified – device binding, dynamic linking of transaction data, wallet attestation, combined presentation – and much of it is concerned with being able to establish afterwards what was bound to what, and on whose authority.
That is not authentication. It is evidence. And it is what regulators will ask for, because it is what regulators always ask for.
Which matters more than it might sound, because the clock is already running. From December 2027, organisations already required to use strong customer authentication — banks, payment providers, telecoms and others — must accept an EUDI Wallet credential when a customer chooses to present one. Acceptance stops being a strategic choice and becomes an obligation. If that reading holds, the institutions that do well from it will be the ones that treat credential acceptance as a governance question rather than an integration project.
More trust should not require more data
There is one instinct I would ask organisations to unlearn: the assumption that more trust requires more data. It is an understandable one, built up over years in which the only way to be confident about a customer was to collect and keep whatever they could be persuaded to hand over.
Geneva offered useful evidence against it. The consensus in the room was that the most developed and most widely deployed reusable credential with biometrics anywhere in the world today is proof of age. Not a national identity wallet. Not a comprehensive KYC credential. A credential whose entire purpose is to answer one question.
I don’t think that is a coincidence, and I don’t think it is because anyone prioritised it. “Over eighteen” is close to the smallest claim it is possible to make. One answer, no identifier, almost nothing for the relying party to store, secure, or subsequently lose. The credential that reached scale is the one that asks for the least — in a domain where the stakes are high and regulatory attention is intense.
The view from LATAM was that Brazil is the strongest in the region on this, on credentials and on payments alike, and that the driver there is not commercial. It is the protection of minors, across content, commerce and technology. Whatever else that tells us, it suggests the deployments moving fastest are the ones with a duty of care behind them rather than a business case.
Europe appears to be reaching the same conclusion from the opposite direction — by design rather than by deployment. It is building several digital identity systems at once, under different legal bases, and none can deliver cross-border trust in isolation. The response taking shape is a proposed pan-European trust framework built on digital subsidiarity and mutual recognition, open standards, accountable change control, inclusion by design, and unlinkability by default, with re-linking possible only through judicial process. It is not a finished model. It needs iteration and further research.
Unlinkability by default is the principle I would prioritise, and proof of age is why. Minimal disclosure is not a constraint to be accepted reluctantly in exchange for adoption. On the evidence available, it appears to be a precondition for it.
Cooperation is the mechanism
None of this gets orchestrated by one party.
There is no single company on earth that can build everything decentralised identity requires. I say that as someone who runs one. This is a collaboration and orchestration game, and the companies that understand it as such will do better than those still trying to own the whole stack.
But the cooperation that matters runs wider than the vendor landscape. It has to work inside a country – between ministries, between public services and the private institutions that will do most of the actual relying, and between all of them and the citizens whose trust is the only thing that makes a mandate real. And it has to work beyond national frontiers, because sovereignty was never meant to mean isolation. A credential that works only within one jurisdiction, or one ministry, is not really a credential. It is a login.
It must also include the scientific community, the participant most often left off this list. The framework emerging in Europe is explicit that it needs further research. That is not a caveat to be managed; it is a work item, and it requires people whose job is enquiry rather than delivery.
Which brings me to my favourite thing about the week: governments, standards bodies, technology companies, civil society and open-source communities around the same table, being candid with each other. A convening like that matters as much as any individual standard does. The standard tells you what to build. The convening is where you find out whether anyone will use it, whether it works across the border, and what you got wrong.
We have spent years building technology to prove who someone is. That work was hard and it is largely done.
The next chapter is about proving what can be trusted about an interaction. It is a bigger challenge, it cannot be solved by any one of us alone, and the only people who will solve it are those willing to sit at that table. I found it a much more interesting problem, and I suspect I am not the only one.
Hola! I’m Gonzalo Alonso; over the last 30 years I’ve led at Google and Microsoft, as well as building and exiting my own tech startups. I’m now proud to be the Chief Executive Officer at Ditto.