R350 SeriesPath to the Abyss Part 8 / 17

Seventh Step: Turn Identity into Permission

When the question “who are you?” becomes the question “what are you allowed to do?”

Identity was once primarily an answer to a simple question: Who are you? Name. Date of birth. Citizenship. Signature. Photograph. A document proving that you really are you. But digital identity can become something substantially larger. Not only proof of who you are. It can become a key that opens doors. A bank. A phone. A prescription. Travel. A contract. A government service. A social benefit. A payment. Proof of age. Access to an online service. And this is where one of the most important boundaries on the entire path begins. A key that opens doors can also leave them closed.

Digital identity is no longer the future

The European Digital Identity Wallet is no longer a concept in a white paper. It is an adopted European legal and technical infrastructure. The regulation entered into force in 2024, while 2026 is seeing implementing acts, testing and preparation of national wallets ahead of actual rollout. The European Commission itself lists a very broad range of uses. The wallet will be able to prove identity for public services, open a bank account, register a SIM card, use a mobile driving licence, sign contracts, present an e-prescription, prove educational qualifications, access social services, travel and confirm identity for payments.[1][2][3]

It is important to understand this without hysteria and without embellishment. Today the European system is designed with strong legal safeguards. Use must be voluntary. Under the current regulation, a person who does not use the wallet may not for that reason be placed at a disadvantage in access to public or private services, on the labour market or in business. Other means of identification must also remain available. That is the law today. But law is not a law of physics. Law is a human decision that other humans may one day change. The infrastructure remains.

The key is already broad enough

This is what should make a person think. The digital wallet is not intended for just one thing. It is not merely an electronic identity card. Its value lies precisely in its ability to connect different credentials or attributes of a person. Who you are. How old you are. Whether you have a driving licence. What qualifications you hold. Whether you have a right to a particular social service. Which prescription was issued to you. Whether you are entitled to a service.

And all of this can be proven digitally, without a traditional paper document. That has enormous practical advantages. But the civilisational question is not only: Is the system convenient? The question is: What happens if the same infrastructure one day becomes necessary for participating in society?

The precedent already exists

We do not have to guess whether a digital certificate can be turned into a condition of access. It has already happened. During the COVID-19 pandemic, the European Union established an interoperable system of digital certificates for vaccination, testing and recovery. The primary purpose of the European certificate was to facilitate free movement. But under their own laws, member states could also use the same certificates for other purposes. Italy went very far.[4][5]

In autumn 2021 it introduced a mandatory Green Pass for public and private workplaces. During certain periods the certificate was also required for restaurants, sport, cultural events, hotels and other activities. Regardless of how anyone today evaluates the justification for those measures, the mechanism itself matters. Digital proof of a particular status became a condition for access to work and to part of social life. This is not theory. It happened.[6][7]

And that means the question is no longer:

Is it technically and politically possible to use a digital credential as a permission?

We already know the answer. Yes. The real question is where a future society will draw the line.

The German Democratic Republic border crossing at Bahnhof Friedrichstraße on 18 November 1989.
Bahnhof Friedrichstraße, 18 November 1989. At the former East German border crossing, documents and identity checks directly determined permission to cross the border. Today’s European digital-identity systems have different purposes, legal bases, and safeguards; the photograph illustrates the general function of identity as an access key and does not equate the two regimes. Image: Frits Wiarda / Wikimedia Commons CC BY-SA 3.0

Control does not require one central score for each person

When people hear the term “social credit”, they often imagine one enormous government number beside every person’s name. Perhaps that is even too primitive a model. A far more effective system could operate without a single overall score. One service needs proof of age. Another proof of identity. A third a licence. A fourth a health attribute. A fifth a financial credential. A sixth proof of residence. A seventh proof of entitlement to a service. Each door checks only the attribute it needs.

On paper, the system may not contain one enormous file holding your entire life. But for the individual the result can be very similar. If you do not possess the appropriate digital credential, the door does not open. That is the essence of a permission society. It does not need one central dictator. It needs standardised keys and standardised doors.

The health certificate acquired a global successor

Here too the development is concrete. After the acute phase of the pandemic ended, the European COVID-certificate infrastructure did not simply disappear into history. In 2023 the European Commission and the World Health Organization began a partnership in which WHO adopted the technical foundation of the European system and used it to build the Global Digital Health Certification Network. At launch, WHO said the infrastructure was intended to expand beyond COVID certificates to digitised International Certificates of Vaccination or Prophylaxis, routine immunisation cards and international patient summaries.[8][9]

WHO stresses that it does not itself store personal health data; it maintains a trust infrastructure, including public keys used to verify the authenticity of documents. That is an important technical distinction. But the broader picture matters too. The infrastructure for verifiable digital health credentials did not end with the pandemic. It continued to develop. Something first presented as a crisis tool became a building block of a more permanent global digital-health infrastructure. That does not by itself prove abuse. It does prove continuity.

The most dangerous word is not “mandatory”

The most dangerous word may be: practical. Something can remain formally voluntary for as long as it is possible to live without it. But what if, ten years from now, most banks, employers, government services, transport systems and digital platforms use the same identity standard? What if an alternative exists only on paper, while in practice it means long procedures, waiting and access to fewer and fewer services? What if a company does not say: “You must have a digital identity.” Instead it says: “Without it we cannot verify you securely enough.” The result can be the same. Very little modern control requires naked coercion. It is enough for one option to be fast, free and universal while the other is impractical. People choose convenience. And a few years later no one remembers why the alternative mattered in the first place.

First, proof of age

In 2026 the European Commission urged member states to accelerate rollout of the European age-verification application, which can be used on its own or integrated into the EUDI Wallet. At first glance the idea is very good. An online service can verify that a user is old enough without learning their name or exact date of birth. From a privacy perspective, that is even better than sending an identity card to every website.[10]

But again the system’s fundamental characteristic appears: identity is becoming a machine-verifiable collection of permissions and attributes. Today: “over 18”. Tomorrow the system may technically verify many other attributes. The question is not whether children should have access to adult content. The broader question is: how much of everyday life do we want to place behind automated digital gates that open only after successful verification?

“But today it is voluntary”

That is true. And it is right to say so. The current European regulation is unusually clear on this point. But a person who thinks only about today’s version of the system is not thinking far enough ahead. Large infrastructures outlive governments. They outlive crises. They outlive their original purposes. The internet did not remain what it was in 1995. The smartphone did not remain a telephone. A social network did not remain a page for photographs of friends. And digital identity is unlikely to remain merely a digital version of an identity card.[1]

Technological infrastructure acquires new functions because that is its nature. So the question for a free society is not: Do we trust today’s government? It is: Would we be willing to hand the same infrastructure to the worst government we can imagine? If the answer is no, then safeguards are not bureaucratic obstacles. They are the essence of freedom.

What if identity is only the beginning?

What if the ultimate purpose is not one digital identity card at all? What if the system’s real value lies in creating, for the first time, a universal digital language for proving attributes of a person? Identity. Age. Permission. Qualification. Health credential. Financial eligibility. Entitlement to a service. What if new attributes are later added that today seem politically unacceptable? What if the next major crisis moves the boundary again? What if people then say what they always say:

“Only temporarily.” This is not proof that it will happen. But after the pandemic we can no longer claim that a digital certificate can never become a condition of access. That boundary has already been crossed. Digital identity is therefore not merely a technical question. It is a question of power. Who defines the attributes? Who defines the conditions? Who registers the doors? Who changes the rules? Who guarantees an alternative? And what happens to the person who says: I do not want to participate?

Identity is ready. Money comes next.

Once a person is digitally identified, an action can be linked to a person with a high degree of certainty. That is useful for contracts. Banking. Fraud prevention. Government services. But if you want to build a truly powerful system of administration, identity alone is not enough. The person must still possess something with which they can act independently. Money. The ability to buy. To sell. To pay. To save. To support a person or organisation without having to ask the infrastructure for permission for every transaction.

That is why the next step on the path is inevitable. First you know who the person is. Then you connect identity to their money. And once you can control access to both, the question is no longer only who they are. The question becomes: what can they still do at all?

Sources and further reading

  1. EU Regulation 2024/1183: voluntary use and non-discrimination. Regulation (EU) 2024/1183 of the European Parliament and of the Council, European Digital Identity Framework Source
  2. European Commission: official EUDI Wallet use cases. European Commission, EU Digital Identity Wallet Pilot implementation Source
  3. EUDI implementation and testing in 2026. European Commission, Launchpad Testing 2026 Source
  4. EU Digital COVID Certificate. Regulation (EU) 2021/953, framework for issuance, verification and acceptance of interoperable COVID-19 vaccination, test and recovery certificates Source
  5. European Commission: national use of DCC outside free movement. European Commission, Health Security Committee summary report, 21 April 2021 Source
  6. Italy: Green Pass as a condition for work. Ministero della Salute, Governo vara decreto legge su green pass obbligatorio nel luoghi di lavoro pubblici e privati, 17 September 2021 Source
  7. Italy: Green Pass as a condition for services and activities. Presidenza del Consiglio dei Ministri / Protezione Civile, Decreto-Legge 24 marzo 2022, n. 24 Source
  8. WHO Global Digital Health Certification Network. World Health Organization, The European Commission and WHO launch landmark digital health initiative to strengthen global health security, 5 June 2023 Source
  9. WHO: expansion of health trust-network use cases. WHO Director-General, remarks at GDHCN signing ceremony, 5 June 2023 Source
  10. EU age-verification app 2026. European Commission, Commission urges Member States to rollout EU age verification app, 29 April 2026 Source