Google Wallet and the EUDI framework have converged on almost everything technical — the same protocol, the same credential format, even the same zero-knowledge scheme. Where they fork is on who decides: who vouches for the credential, and who vouches for the verifier. And both, by different routes, ended up inventing the same intermediary tier to make the thing scale. With opposite legal characters.
Europe is solving interoperability inward — making its national wallets speak to each other. But step outside the eIDAS2 umbrella and the story changes. Switzerland runs a mature age-verification ecosystem on incompatible foundations; the EU-Japan pilot aligned the protocols and then hit a wall on trust. Formats are converging. Trust — the part that actually decides whether a verifier can accept a credential — isn't.
Nobody builds EUDI age verification from scratch: the real build route runs on a pre-built engine, open source or licensed. I costed that honest scenario — the engine we know first-hand is EUDIPLO, the base espuni runs on —: 9–14 weeks of a senior developer, 0.2–0.3 FTE of perpetual maintenance, and a break-even in the order of 40,000 verifications per month above which building wins. Below that figure, the numbers say something else.
Zero-Knowledge Proofs are the most advanced privacy piece in the EU Age Verification Blueprint: they prove you're over 18 without showing the credential. We built an independent ZK verifier, tested it against the official reference AV app with a real credential, and it accepted the proof in 317 ms. Here's how the relying-party side works — the hard part — and, just as plainly, what our verifier still doesn't do.
I had a verifier that passed every test against the EU's reference age verification wallet. Then I pointed it at AltID, Denmark's production issuer, and it was rejected before a single credential moved. Here's what reference implementations don't prepare you for — and why passing one isn't the same as being interoperable.
Yesterday the UK's new Prime Minister scrapped the national digital identity scheme. It's easy to read that as 'digital identity is dead' — but the age verification market it's often confused with is a separate thing, and it's still very much alive. Here's the distinction, and the one lesson that does carry across.
Posts warning that digital identity wallets log every time you prove who you are are spreading fast. The ARF — the EU's public technical specification — describes something close to the opposite. But there are real objections underneath, and they're better than the viral ones.
Denmark just became the first member state with an age verification issuer on the EU's production Trusted List. A close look at how AltID actually works — and what it means for platforms that need to comply with DSA Article 28.
A technical walkthrough of the EU's reference standard for age verification — and why it solves the GDPR tension that age verification usually creates.