The news that moves digital trust.
Every month, the regulation, fraud patterns and identity technology that matter, analysed by the team building Europe's digital-trust platform. 36 articles and counting.
Digital ID at the pub: England and Wales open alcohol sales to verified digital age checks
Regulations laid on 30 June let licensed premises accept digital verification services for alcohol age checks. Everyday identity just moved from documents to attributes.
30 June: the day every member state shows its digital identity homework
Age-verification implementation plans are due to Brussels by month-end, while the December wallet deadline looms. The second half of 2026 is where digital identity becomes infrastructure.
Five pilots, one deadline: the EU’s age-verification rollout takes shape
Denmark, France, Greece, Italy and Spain are piloting the EU’s privacy-preserving age solution, with implementation plans due end-June and rollout urged by end-2026. Platforms should read the direction, not the dates.
Ofcom’s year ahead: the Online Safety Act grows teeth, quietly
With the King’s Speech framing the digital agenda and Ofcom publishing its online-safety priorities, UK enforcement is shifting from launch drama to systematic supervision.
Spain goes live, Brussels ships an age app: April was digital identity’s proof month
Spain’s MiDNI digital ID became official on 2 April; the EU’s white-label age-verification app went feature-ready on the 15th; and on the 29th the Commission set the rollout clock. Momentum is now visible to citizens.
CIR 2026/798: Europe just standardised remote onboarding
The Commission’s implementing regulation of 7 April makes ETSI TS 119 461 the mandated standard for EUDI Wallet identity proofing. Remote onboarding now has one European bar.
FATF’s AI horizon scan: when deepfakes pass liveness, evidence chains decide
The FATF’s Horizon Scan on AI and deepfakes warns that synthetic media can beat biometric checks and surface only after funds move. The answer is layered proof, not single controls.
77% and climbing: the fraud-fighter survey that quantifies the deepfake surge
New industry research across eight regions finds deepfake social engineering rising faster than any other fraud type, and only a small minority of organisations firmly ready. The gap is architectural.
Eighteen months to AMLR: the single rulebook is closer than your roadmap thinks
July 2027 sounds distant until you subtract procurement, integration, model validation and parallel running. The institutions starting now are the ones that will be calm.
The quiet death of the SMS code: regulators start writing the obituary
The UAE central bank ordered SMS and email OTPs phased out by March 2026 in favour of biometric, risk-based authentication. Expect the pattern to travel.
DORA, one year on: the register was the easy part
A year into the Digital Operational Resilience Act, supervisors have moved from registers to evidence: show us the exit plan, the test results, the incident timeline. Vendors are being sorted.
DAC7 2026: the platforms that validated TINs are having a quiet January
Third reporting cycle, same lesson: seller tax numbers validated at onboarding turn the January deadline into an export job. The rest are re-documenting under pressure.
The 2026 compliance calendar: six dates that will shape digital trust
DAC7 in January, AI Act high-risk rules in August, EUDI wallets by December: 2026 is the densest regulatory year digital identity has seen. Plan it now.
2025 in review: the year AI attacked identity, and cryptography held
Deepfake calls, synthetic customers, GenAI document mills: 2025 was the stress test. What held, what broke, and the architecture lesson for 2026.
What the EUDI wallet pilots proved, and what they quietly buried
As the large-scale pilots wind toward conclusions, patterns are clear: reuse delights users, issuance is the bottleneck, and the trust chain is where the value concentrates.
Black Friday for fraudsters: marketplace scams hit their annual peak
Peak shopping season is peak scam season: fake sellers, mule storefronts, triangulation fraud. Marketplaces that verify sellers before the rush keep both revenue and reputation.
Cybersecurity Awareness Month: identity is the perimeter now
The 2025 breach reviews all point the same way: attackers do not break in, they log in. Phishing-resistant identity has become the control that decides everything else.
Verification of Payee is live: the euro area just verified itself
From today, every euro credit transfer gets a name-IBAN check. Day one of the largest counterparty-verification rollout in payments history.
Watermarks are not enough: content provenance needs signatures, not stamps
As election seasons and deepfake scandals collide, the industry debate over AI content labelling misses the point: labels identify the fake, signatures prove the real.
Verification of Payee, 30 days out: the readiness gaps banks are racing to close
With the 9 October deadline a month away, euro-area banks are in final VoP testing. The gaps being found are instructive for anyone who verifies counterparties.
Account takeover’s summer peak: why recovery flows are the weakest door
Vacation season is account-takeover season: out-of-office victims, urgent “locked out” pretexts, and helpdesks that reset credentials on a convincing phone call. The fix is identity, not more questions.
The AI Act’s second wave: GPAI obligations and the provenance question
From 2 August 2025, general-purpose AI model providers face transparency and copyright obligations. For everyone downstream, the question becomes: how do you prove what is authentic?
The UK switched on age checks: first lessons from launch week
On 25 July 2025 highly effective age assurance became mandatory for adult content in the UK. Traffic shifted, VPN searches spiked, and the compliant providers learned fast.
AMLA opens its doors: Europe’s AML supervisor starts work in Frankfurt
On 1 July 2025 the EU’s Anti-Money Laundering Authority began operations. Direct supervision starts in 2028, but the behavioural shift for compliance teams starts now.
Verification of Payee is coming: what the October deadline teaches every industry
From 9 October 2025, euro-area banks must check that account names match IBANs before every transfer. The principle generalises: verify the counterparty, not just the credentials.
One month to comply: the UK’s age-check deadline is 25 July
Ofcom confirmed it: from 25 July 2025, services with adult content accessible in the UK must run highly effective age assurance. A practical checklist for the final month.
Pig butchering goes industrial: inside the romance-investment scam economy
International crackdowns keep exposing the scale of “pig butchering” operations: compounds, scripts, and billions in losses. The only durable countermeasure is verified identity between strangers.
eIDAS 2.0 implementing acts: the fine print that makes wallets real
The Commission’s implementing regulations are translating eIDAS 2.0 from principle into protocol: wallet integrity, certification, relying-party registration. Here is what changes for businesses.
The AML single rulebook: what AMLR changes while you are not looking
The EU’s AML Regulation replaces directive patchwork with directly applicable rules from July 2027. The customer due diligence chapters deserve attention now, not in 2027.
Ofcom’s children’s codes land: the age-assurance countdown is real
With the Online Safety Act’s children’s safety codes finalised in spring 2025, services have a hard runway to July: highly effective age assurance or restructure the service.
Synthetic identities: the customer who never existed
Synthetic identity fraud, real data fragments assembled into fake people, keeps rising as generative AI industrialises the assembly line. Document-photo onboarding cannot stop it. Chip-level verification can.
The European Digital Identity Wallet takes shape: what the pilots are teaching us
Large-scale EUDI Wallet pilots are stress-testing payments, travel, education and health use cases across the EU. The lessons matter for every business that verifies identity today.
The deepfake conference call: when seeing your CFO is no longer believing
Multi-million euro losses from deepfake video calls keep mounting. The lesson is uncomfortable: video without cryptographic identity verification is now an attack surface.
The AI Act shows its first teeth: what 2 February changed for biometric systems
From 2 February 2025 the EU AI Act’s prohibitions apply: social scoring, emotion recognition at work, untargeted face scraping. What it means for identity verification, and what it deliberately does not mean.
DAC7 round two: why platforms failed TIN validation the first time
The 31 January 2025 DAC7 deadline is the second reporting cycle for digital platforms. The lesson from round one: invalid tax identification numbers are the number one cause of rejected reports.
DORA is live: what operational resilience means for your identity stack
The Digital Operational Resilience Act applies from 17 January 2025. Financial entities are now accountable for the resilience of every ICT vendor in their chain, including identity verification providers.
