Global
The OpenID Foundation has completed conformance testing for two of the most widely adopted specifications underpinning digital identity wallets, giving governments and technology providers a common way to demonstrate that their implementations meet interoperability requirements.
Test suites for OpenID for Verifiable Presentations (OpenID4VP) and OpenID for Verifiable Credential Issuance (OpenID4VCI), when used with the High Assurance Interoperability Profile (HAIP), are now available. Once an implementation has successfully completed the tests, organisations can apply for OpenID Foundation self-certification.
The specifications have been selected by more than 30 jurisdictions, including the UK, Switzerland, India and EU member states through the European Digital Identity Wallet programme. Real-world interoperability testing achieved pass rates of more than 90 percent for OpenID4VP and 87 percent for OpenID4VCI.
Germany
Germany is pressing ahead with plans to launch its EU Digital Identity Wallet on 2 January 2027, despite criticism that the initial version will offer only limited functionality.
The government describes the programme as a structured, agile large-scale IT project operating within its timeframe and budget. The initial wallet is expected to focus on identification and credential presentation, with qualified electronic signatures, pseudonymous logins and payment authorisations following in 2027 and 2028.
Germany is nevertheless expected to be among the first EU countries to launch, albeit just after the 24 December 2026 deadline for member states to provide citizens with an EUDI Wallet. Fewer than half of the bloc’s 27 member states are currently expected to meet that deadline.
Global
SailPoint has launched a unified identity security offering designed to govern human users, non-human identities and AI agents through the same security architecture.
The new SailPoint Identity Security solution combines the company’s Agentic Fabric, which is now generally available, with its new Human Fabric. SailPoint said its research found 97 percent of AI agents have access to sensitive data, while only 21 percent of organisations are highly confident in their ability to manage AI agent security risks.
Agentic Fabric is designed to discover and govern AI agents, credentials and Model Context Protocol servers, with capabilities including sensitive data redaction, automated ownership rules and a centralised “kill switch” for rogue agents.
United Kingdom
The Office for Digital Identities and Attributes (OfDIA) is considering introducing dedicated rules for digital age assurance as digital verification expands into areas including alcohol sales.
Its 2026 annual report says the regulator will explore options for enabling children to prove their age online in a safe and privacy-preserving way, while supporting wider government efforts to use registered Digital Verification Services for age checks and other regulated use cases.
The UK register now includes 46 DVS providers. OfDIA estimates that the wider UK digital identity sector, including electronic signatures and other trust services, generated more than £2 billion in revenue during 2024-25, with around 275 companies operating in the market.
Global
Daon has unveiled a five-patent “Quantum Identity” architecture intended to address the authenticity of biometric and authentication evidence as organisations prepare identity systems for the quantum era.
The company argues that post-quantum cryptography can protect keys, signatures, credentials and communications against future attacks, but cannot determine whether the evidence entering an identity system is itself genuine.
Its approach therefore focuses on areas including biometric manipulation, liveness, authentication data and protection against injected, cloned or replayed evidence. Daon said its five US patents cover morphing defence, quantum-enhanced morphing detection, quantum identity verification, quantum liveness and quantum injection and replay resistance.
Global
Okta is planning to acquire identity security startup Permiso Security as it looks to extend identity threat detection beyond its own technology ecosystem.
Permiso provides more than 2,500 risk signals across over 70 identity platforms, giving Okta greater visibility into identities operating across environments including AWS, Google Cloud, Microsoft Azure, Active Directory and Entra.
The acquisition is intended to strengthen Okta’s ability to combine identity posture information with suspicious activity signals, helping organisations identify cases where vulnerabilities such as dormant privileged accounts are being actively exploited.
United States
Login.gov is strengthening its fraud prevention capabilities and cutting prices for government agency customers as the US federal digital identity service approaches its tenth anniversary.
The General Services Administration said the service is improving its detection and response to suspicious activity as threats become more sophisticated, including attacks potentially involving artificial intelligence.
Login.gov is also working with the National Design Studio to improve the identity verification user experience and reduce friction while maintaining federal privacy, security and identity standards. Lower pricing for agency partners is meanwhile intended to encourage wider adoption of the shared service across government.
United Kingdom
More than half of UK consumers are hesitant about using biometric payments because of concerns about the privacy of their data, according to research from payments orchestration company Aevi.
The survey of 3,000 adults across the UK and US found 52 percent of UK respondents said privacy and potential misuse of biometric data by private companies would make them hesitant to use biometric payments, compared with 32 percent concerned about government access or surveillance.
Attitudes also varied significantly by age. Some 80 percent of UK respondents aged 25 to 34 said they trusted companies to protect their biometric data, falling to 32 percent among 45- to 54-year-olds and 29 percent among over-65s. Half of over-65s also said they saw no clear benefit in biometric payments over existing payment methods.
If you liked this content…
Ethiopia
Ethiopia has launched Faydaverse, a state-owned commercial enterprise designed to scale and commercialise the country’s national digital identity technology.
The move takes the technology underpinning Ethiopia’s National Digital ID Program beyond its original role as government infrastructure, with Faydaverse operating under sovereign wealth fund Ethiopian Investment Holdings.
Almost 50 million people have enrolled in Ethiopia’s digital ID system and more than 160 million authentication requests have been processed. Officials also see Faydaverse as a potential vehicle for exporting Ethiopia’s identity technology to other African countries.
Czech Republic
iDenfy has integrated Czech Bank iD into its identity verification platform, allowing users to prove their identity through existing online banking credentials rather than submitting physical identity documents.
Bank iD was introduced in 2021 and is used by more than five million Czech internet banking customers. The system allows citizens to authenticate for both government and private sector services, with identity information verified directly through participating banks.
iDenfy said the integration is intended to reduce onboarding friction and document-related dropouts while providing businesses with verified identity information directly from the banking network.
Norway
iDenfy has also integrated Norway’s BankID into its identity verification platform.
The company said the integration provides businesses operating in Norway with access to the country’s established digital identity infrastructure while reducing friction during Know Your Customer checks.
The move comes amid increasing concerns around identity-related fraud in Norway, with iDenfy citing a 47 percent increase during 2025.
Global
VanishID has previewed a new AI Exploitability Management capability designed to measure how publicly available information about employees could be weaponised using AI.
The technology assesses more than 40 AI-enabled attack scenarios, including executive impersonation, real-time deepfakes, voice cloning, spear phishing and business email compromise. It generates an AI Exploitability Score for individuals to help security teams identify which publicly exposed information presents the greatest risk.
VanishID said the assessment operates externally, from the same perspective as an attacker, without requiring software installation, integrations or user credentials. The company unveiled the capability at Black Hat USA 2026.
Global
Intercede has secured approximately $2.6 million in new digital identity and credential management contracts and renewals across government, defence and other critical sectors.
The deals include deployments of its MyID credential management platform for US federal agencies, a multinational military alliance, European public sector organisations and customers in the Middle East.
The company has also identified around $1.65 million in additional renewal opportunities extending to early 2030 as it looks to grow recurring revenues from its identity and authentication technology.
Sierra Leone
Sierra Leone has brought government, businesses, financial institutions and civil society together to advance plans for a national digital identity and Digital Public Infrastructure ecosystem.
The initiative follows a June agreement between the Ministry of Communication, Technology and Innovation, Bhutan National Digital Identity and the SIGN Foundation to support development of the country’s identity infrastructure using open-source technology and verifiable credentials.
The programme is being developed around three core DPI components: trusted digital identity, digital payments and interoperable data exchange. The government said its next steps will include developing the policy, governance and technical foundations for the ecosystem.
United Kingdom
L8P8 has launched Loop8ID Age Shield in the UK as businesses adapt to age assurance requirements under the Online Safety Act.
The middleware uses biometric authentication already available on a user’s device to confirm the person requesting an age check is the genuine account holder, before requesting an age-eligibility signal from the device. The company says the system does not collect birth dates, identity documents or other personally identifiable information.
The technology is live on Apple iOS in the UK and has been integrated with Google’s Android age-signal API ahead of its wider UK rollout. L8P8 said the approach is intended to help businesses meet age assurance requirements without creating additional repositories of sensitive identity information.
South Africa
South African startup aiQ Cognitive Technologies says it has developed a digital identity technology capable of creating a persistent identifier directly from an individual rather than relying on conventional identity credentials.
The company’s QiD technology uses neuromorphic processing to generate what it describes as a unique and irreversible numerical identifier from a selfie taken through a web browser. aiQ says no biometric template is stored and the same identifier can be generated whenever the individual returns.
The system also incorporates active and passive liveness detection and age estimation, with potential applications including remote customer onboarding, authentication and digital public infrastructure.





