<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Biometric Update</title>
	<atom:link href="https://www.biometricupdate.com/feed" rel="self" type="application/rss+xml" />
	<link>https://www.biometricupdate.com</link>
	<description>Biometrics News, Companies and Explainers</description>
	<lastBuildDate>Wed, 16 Sep 2026 14:19:56 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	
<site xmlns="com-wordpress:feed-additions:1">66434804</site>	<item>
		<title>International Identity Day shifts focus beyond coverage to trust</title>
		<link>https://www.biometricupdate.com/202609/international-identity-day-shifts-focus-beyond-coverage-to-trust</link>
					<comments>https://www.biometricupdate.com/202609/international-identity-day-shifts-focus-beyond-coverage-to-trust#respond</comments>
		
		<dc:creator><![CDATA[Abhishek Jadhav]]></dc:creator>
		<pubDate>Wed, 16 Sep 2026 13:29:27 +0000</pubDate>
				<category><![CDATA[Biometrics News]]></category>
		<category><![CDATA[ID for All]]></category>
		<category><![CDATA[Dr. Joseph Atick]]></category>
		<category><![CDATA[ID4Africa]]></category>
		<category><![CDATA[International Identity Day]]></category>
		<category><![CDATA[legal identity]]></category>
		<category><![CDATA[SDG 16.9]]></category>
		<guid isPermaLink="false">https://www.biometricupdate.com/?p=355961</guid>

					<description><![CDATA[
		<img width="1024" height="768" src="https://d1sr9z1pdl3mb7.cloudfront.net/wp-content/uploads/2018/05/01162839/International-Identity-Day-buttons-%40ID4Africa.jpg" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="" decoding="async" fetchpriority="high" srcset="https://d1sr9z1pdl3mb7.cloudfront.net/wp-content/uploads/2018/05/01162839/International-Identity-Day-buttons-%40ID4Africa.jpg 1024w, https://d1sr9z1pdl3mb7.cloudfront.net/wp-content/uploads/2018/05/01162839/International-Identity-Day-buttons-%40ID4Africa-150x113.jpg 150w, https://d1sr9z1pdl3mb7.cloudfront.net/wp-content/uploads/2018/05/01162839/International-Identity-Day-buttons-%40ID4Africa-300x225.jpg 300w, https://d1sr9z1pdl3mb7.cloudfront.net/wp-content/uploads/2018/05/01162839/International-Identity-Day-buttons-%40ID4Africa-768x576.jpg 768w" sizes="(max-width: 1024px) 100vw, 1024px" />
		<span style="font-weight: 400;">The ninth annual International Identity Day is being observed today under the theme “My Identity, My Shadow. Never Apart.”</span><span style="font-weight: 400;"> </span>

<span style="font-weight: 400;">This year’s campaign emphasizes the need for identity that remains useful, secure, and trusted throughout a person’s life, beyond registration and credential issuance.</span><span style="font-weight: 400;"> </span>

<span style="font-weight: 400;">ID4Africa Executive Chairman Dr. Joseph Atick says population coverage remains important but is no longer a sufficient measure of an identity system’s success.</span>

<span style="font-weight: 400;">In a</span> <a href="https://youtu.be/kEHOnMpqphU?si=3n67ChY5XZT3ZnWc" target="_blank" rel="noopener"><span style="font-weight: 400;">message</span></a><span style="font-weight: 400;"> for the observance, he asks whether an identity works for the individual and provides practical value in daily life.</span>

<span style="font-weight: 400;">Atick says legal identity should be established from the beginning, remain useful throughout a person’s life, and be secure by design</span>

<span style="font-weight: 400;">People should also know when their identity is accessed and have control over what information they share, with whom, and for what purpose, he says.</span>

<span style="font-weight: 400;">Atick continues, “Trust is not created by technology alone. It is earned through strong institutions, effective safeguards, transparency, accountability.”</span>

<span style="font-weight: 400;">The message reflects ID4Africa’s</span><a href="https://www.biometricupdate.com/202605/id4africa-2026-shifts-focus-to-digital-identity-ecosystems-and-sustainability"> <span style="font-weight: 400;">broader shift</span></a><span style="font-weight: 400;"> from enrollment targets to sustainable identity ecosystems.</span>

<span style="font-weight: 400;">The latest</span><a href="https://documents1.worldbank.org/curated/en/099061526195037307/pdf/P505783-9210f6e7-7448-4668-92af-056e5c6ac310.pdf" target="_blank" rel="noopener"> <span style="font-weight: 400;">World Bank ID4D Global Dataset</span></a><span style="font-weight: 400;"> estimates that </span><a href="https://www.biometricupdate.com/202511/new-world-bank-data-shows-800m-people-worldwide-still-lack-legal-identity"><span style="font-weight: 400;">800 million people</span></a><span style="font-weight: 400;"> lack proof of legal identity, down from one billion in 2017.</span>

<span style="font-weight: 400;">More than 400 million of them live in Sub-Saharan Africa. Approximately 450 million are children whose births were never registered.</span>

<span style="font-weight: 400;">The World Bank estimates that 2.8 billion people lack access to a government recognized digital ID that can be used for online transactions.</span>

<span style="font-weight: 400;">Having a digital ID also does not mean that it is being used. More than 70 percent of adults in Vietnam have one, but fewer than 20 percent have used it.</span>

<span style="font-weight: 400;">The figures highlight different challenges: lacking proof of legal identity, lacking access to digital identity, and not using an available digital ID.</span><span style="font-weight: 400;"> </span>

<span style="font-weight: 400;">September 16 was selected because it corresponds to the</span><a href="https://sdg16now.org/report/target16-9/" target="_blank" rel="noopener"> <i><span style="font-weight: 400;">UN Sustainable Development Goal 16.9</span></i></a><span style="font-weight: 400;"> that seeks to provide legal identity for all, including birth registration, by 2030.</span>

<span style="font-weight: 400;">ID4Africa</span> <a href="https://www.biometricupdate.com/201804/drive-for-official-un-international-identity-day-launched-at-id4africa"><span style="font-weight: 400;">launched</span></a><span style="font-weight: 400;"> the campaign at its annual meeting in Abuja in 2018. International Identity Day has not been designated as an official UN international day.</span><span style="font-weight: 400;"> </span>

<span style="font-weight: 400;">The</span><a href="https://www.id-day.org/campaign" target="_blank" rel="noopener"> <span style="font-weight: 400;">campaign coalition</span></a><span style="font-weight: 400;"> has since grown to more than 400 partner organizations from governments, development agencies, civil society and the private sector.</span>

<span style="font-weight: 400;">Nigeria, Namibia, Niger, Liberia and Madagascar have formally adopted September 16 as a National Day of Identity. </span><span style="font-weight: 400;">Countries across Africa are </span><a href="https://www.id-day.org/2026-activities" target="_blank" rel="noopener"><span style="font-weight: 400;">commemorating Identity Day</span></a><span style="font-weight: 400;"> through national events, public outreach and community activities.</span>

<span style="font-weight: 400;">Identity technology provider </span><a href="https://www.biometricupdate.com/companies/veridos-gmbh"><span style="font-weight: 400;">Veridos</span></a><span style="font-weight: 400;"> is among the companies supporting this year’s observance. CEO Bernd Kümmerle says trusted identity enables people to participate in society while protecting them from growing physical and digital threats.</span>

<span style="font-weight: 400;">Atick’s message places that technology within a broader governance framework: identity systems must combine utility with institutional safeguards, transparency and accountability if they are to earn public trust. </span>]]></description>
		
					<wfw:commentRss>https://www.biometricupdate.com/202609/international-identity-day-shifts-focus-beyond-coverage-to-trust/feed</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">355961</post-id>	</item>
		<item>
		<title>24.4M Filipinos use national ID to open GCash accounts: PSA</title>
		<link>https://www.biometricupdate.com/202609/24-4m-filipinos-use-national-id-to-open-gcash-accounts-psa</link>
					<comments>https://www.biometricupdate.com/202609/24-4m-filipinos-use-national-id-to-open-gcash-accounts-psa#respond</comments>
		
		<dc:creator><![CDATA[Lu-Hai Liang]]></dc:creator>
		<pubDate>Wed, 16 Sep 2026 12:48:51 +0000</pubDate>
				<category><![CDATA[Biometrics News]]></category>
		<category><![CDATA[Financial Services]]></category>
		<category><![CDATA[ID for All]]></category>
		<category><![CDATA[digital ID infrastructure]]></category>
		<category><![CDATA[digital wallets]]></category>
		<category><![CDATA[financial inclusion]]></category>
		<category><![CDATA[GCash]]></category>
		<category><![CDATA[national ID]]></category>
		<category><![CDATA[PhilID]]></category>
		<category><![CDATA[Philippines]]></category>
		<guid isPermaLink="false">https://www.biometricupdate.com/?p=355965</guid>

					<description><![CDATA[
		<img width="1377" height="762" src="https://d1sr9z1pdl3mb7.cloudfront.net/wp-content/uploads/2025/05/15132157/GCash-PSA.jpg" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="" decoding="async" srcset="https://d1sr9z1pdl3mb7.cloudfront.net/wp-content/uploads/2025/05/15132157/GCash-PSA.jpg 1377w, https://d1sr9z1pdl3mb7.cloudfront.net/wp-content/uploads/2025/05/15132157/GCash-PSA-300x166.jpg 300w, https://d1sr9z1pdl3mb7.cloudfront.net/wp-content/uploads/2025/05/15132157/GCash-PSA-1024x567.jpg 1024w, https://d1sr9z1pdl3mb7.cloudfront.net/wp-content/uploads/2025/05/15132157/GCash-PSA-150x83.jpg 150w, https://d1sr9z1pdl3mb7.cloudfront.net/wp-content/uploads/2025/05/15132157/GCash-PSA-768x425.jpg 768w" sizes="(max-width: 1377px) 100vw, 1377px" />
		The Philippine Statistics Authority (PSA) says more than 24 million Filipinos have successfully verified their identities and opened e-wallet accounts through GCash, using their national ID.

As of May, 61 percent of onboarded <a href="https://www.biometricupdate.com/202505/philippines-partners-with-gcash-to-drive-national-id-and-mobile-wallet-uptake">GCash</a> users relied on their national ID in card, paper or digital ID form for account opening and verification.<span style="font-weight: 400;"> This is equivalent to 24.4 million Filipinos.</span>

PSA National Statistician Claire Dennis S. Mapa said the initiative ensures that “no Filipino gets left behind in the country’s digital transformation agenda just because they don’t have a government ID.”

The partnership between PSA and GCash extends further with GCash becoming the first e‑wallet in the Philippines to integrate the PSAHelpline service.

This allows users to request official civil registry documents like birth, marriage and death certificates, as well as CENOMAR and CENODEATH, directly through the app. These documents are issued in tamper‑proof PDF format, digitally signed by PSA and carry full legal weight.

The documents are issued as cryptographically secured PDFs with the same legal validity as physical PSA certificates, and their authenticity can be verified electronically. Birth, death and marriage certificates cost ₱290 (US$4.61) each, while CENOMAR and CENODEATH certificates cost ₱345 ($5.49). Last year 18 million certificates were issued. Demand is expected to rise further with the new digital service.

GCash users can access the PSAHelpline Mini App through the GLife section, streamlining the process from request to payment and delivery. Physical copies and door‑to‑door delivery remain available for those who prefer traditional formats, the PSA clarified.

The collaboration builds on grassroots efforts such as PSA co‑location and GCash barangay outposts, which since July 2025 have enabled more than 2,000 residents across 25 communities to register for national IDs and open verified e‑wallet accounts.

PSA registration officers noted that the popularity of GCash services has encouraged more citizens to register for IDs, bridging gaps in documentation that have historically excluded many from the formal financial system.

Financial exclusion nevertheless remains substantial. The Bangko Sentral ng Pilipinas’ 2025 Consumer Finance and Inclusion Survey found that half of Filipino adults owned a formal financial account. Lack of documentation has historically been among the barriers to account ownership, giving the national ID a potentially important role in expanding access. By integrating national ID verification into widely used platforms like GCash, officials say millions of previously unbanked citizens can now participate in the digital economy.

PSA has invited other financial institutions to partner with the national ID system to broaden its reach and strengthen the country’s digital identity infrastructure. “By making essential civil registry documents easier to access, we are helping more Filipinos participate in the digital economy and access the opportunities they deserve,” <a href="https://www.abs-cbn.com/news/business/2026/2/25/gcash-users-can-now-request-birth-marriage-certificates-through-the-app-1258">said</a> Cleo Celeste Santos, GCash’s VP for Public Sector.

The PSA will continue engaging with companies, schools and government agencies to ensure acceptance of digital certificates, Mapa added, to reinforce the legal and practical value of the national ID system in everyday transactions.]]></description>
		
					<wfw:commentRss>https://www.biometricupdate.com/202609/24-4m-filipinos-use-national-id-to-open-gcash-accounts-psa/feed</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">355965</post-id>	</item>
		<item>
		<title>Lindner brings inGo construction credentials to Germany’s d-you wallet</title>
		<link>https://www.biometricupdate.com/202609/lindner-brings-ingo-construction-credentials-to-germanys-d-you-wallet</link>
					<comments>https://www.biometricupdate.com/202609/lindner-brings-ingo-construction-credentials-to-germanys-d-you-wallet#respond</comments>
		
		<dc:creator><![CDATA[Lu-Hai Liang]]></dc:creator>
		<pubDate>Wed, 16 Sep 2026 12:44:05 +0000</pubDate>
				<category><![CDATA[Biometrics News]]></category>
		<category><![CDATA[Civil / National ID]]></category>
		<category><![CDATA[construction]]></category>
		<category><![CDATA[d‑you]]></category>
		<category><![CDATA[digital wallets]]></category>
		<category><![CDATA[EU Digital Identity Wallet]]></category>
		<category><![CDATA[Germany]]></category>
		<category><![CDATA[inGo]]></category>
		<category><![CDATA[Lindner Group]]></category>
		<category><![CDATA[reusable digital ID]]></category>
		<guid isPermaLink="false">https://www.biometricupdate.com/?p=355975</guid>

					<description><![CDATA[
		<img width="2048" height="1080" src="https://d1sr9z1pdl3mb7.cloudfront.net/wp-content/uploads/2026/09/16090824/construction-phone-scaled.jpg" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="" decoding="async" srcset="https://d1sr9z1pdl3mb7.cloudfront.net/wp-content/uploads/2026/09/16090824/construction-phone-scaled.jpg 2048w, https://d1sr9z1pdl3mb7.cloudfront.net/wp-content/uploads/2026/09/16090824/construction-phone-300x158.jpg 300w, https://d1sr9z1pdl3mb7.cloudfront.net/wp-content/uploads/2026/09/16090824/construction-phone-1024x540.jpg 1024w, https://d1sr9z1pdl3mb7.cloudfront.net/wp-content/uploads/2026/09/16090824/construction-phone-150x79.jpg 150w, https://d1sr9z1pdl3mb7.cloudfront.net/wp-content/uploads/2026/09/16090824/construction-phone-768x405.jpg 768w, https://d1sr9z1pdl3mb7.cloudfront.net/wp-content/uploads/2026/09/16090824/construction-phone-1536x810.jpg 1536w" sizes="(max-width: 2048px) 100vw, 2048px" />
		Subcontractor management platform inGo will connect with <a href="https://www.biometricupdate.com/202609/germany-unveils-national-eudi-wallet-d-you">Germany’s d-you digital identity wallet</a> as part of launch partner Lindner Group’s participation in the program. The platform is already used on hundreds of construction sites and is being prepared for d-you’s January 2, 2027 launch.

As a launch partner, <a href="https://www.ingo-id.com/">inGo</a> will integrate directly with the European Digital Identity (EUDI) Wallet framework. This will allow workers and subcontractors to provide verified digital certificates without re‑entering data, reducing paperwork and improving efficiency.

At a partner roundtable in Berlin on September 9, Lindner Managing Director Martin Weber said inGo was built from everyday construction site needs. “That’s exactly where inGo was developed,” he said. “The mobile app brings together all documents, certificates, and legal requirements in one central place.”

inGo was developed by <a href="https://www.lindner-group.com/">Lindner Group</a> subsidiary tibe.io to digitize compliance checks and subcontractor management. The app centralizes documents, certificates and legal requirements, replacing paper passes with QR codes and sending automated reminders when certificates are about to expire.

Lindner reports more than 850 subcontractors and 1,200 projects are registered. “Looking ahead, the technology behind inGo is intended to be used not only in construction but in other industries as well,” Weber added.

Branded d‑you, Germany’s digital wallet will allow citizens to store and use digital versions of IDs, driver’s licences and other documents on their smartphones. At launch, around 40 partners from business, science and public administration will provide services through the wallet. The services include age verification, legally binding contracts and online bank account opening.

The app will be voluntary, free, and compliant with EU technical standards, storing data encrypted on the user’s device rather than in the cloud. The wallet is <a href="https://eudi-wallet.gov.de/">Germany’s implementation</a> of the EU‑wide EUDI Wallet framework

For Lindner, the integration shows how a tool developed for construction site compliance can become part of a broader European digital identity ecosystem. The company says it eventually plans to take the technology behind inGo into other industries.]]></description>
		
					<wfw:commentRss>https://www.biometricupdate.com/202609/lindner-brings-ingo-construction-credentials-to-germanys-d-you-wallet/feed</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">355975</post-id>	</item>
		<item>
		<title>Proof’s VDC launch brings together banking regulation, reusable identity and AI agents</title>
		<link>https://www.biometricupdate.com/202609/proofs-vdc-launch-brings-together-banking-regulation-reusable-identity-and-ai-agents</link>
					<comments>https://www.biometricupdate.com/202609/proofs-vdc-launch-brings-together-banking-regulation-reusable-identity-and-ai-agents#respond</comments>
		
		<dc:creator><![CDATA[Ashok Singal]]></dc:creator>
		<pubDate>Tue, 15 Sep 2026 23:15:23 +0000</pubDate>
				<category><![CDATA[Biometrics News]]></category>
		<category><![CDATA[Civil / National ID]]></category>
		<category><![CDATA[Financial Services]]></category>
		<category><![CDATA[AI agents]]></category>
		<category><![CDATA[authorization]]></category>
		<category><![CDATA[digital identity]]></category>
		<category><![CDATA[IAL2]]></category>
		<category><![CDATA[identity proofing]]></category>
		<category><![CDATA[Proof]]></category>
		<category><![CDATA[reusable digital ID]]></category>
		<category><![CDATA[verifiable credentials]]></category>
		<guid isPermaLink="false">https://www.biometricupdate.com/?p=355948</guid>

					<description><![CDATA[
		<img width="2048" height="1365" src="https://d1sr9z1pdl3mb7.cloudfront.net/wp-content/uploads/2023/02/22111201/face-biometric-enrollment-scaled.jpg" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="" decoding="async" loading="lazy" srcset="https://d1sr9z1pdl3mb7.cloudfront.net/wp-content/uploads/2023/02/22111201/face-biometric-enrollment-scaled.jpg 2048w, https://d1sr9z1pdl3mb7.cloudfront.net/wp-content/uploads/2023/02/22111201/face-biometric-enrollment-300x200.jpg 300w, https://d1sr9z1pdl3mb7.cloudfront.net/wp-content/uploads/2023/02/22111201/face-biometric-enrollment-1024x683.jpg 1024w, https://d1sr9z1pdl3mb7.cloudfront.net/wp-content/uploads/2023/02/22111201/face-biometric-enrollment-150x100.jpg 150w, https://d1sr9z1pdl3mb7.cloudfront.net/wp-content/uploads/2023/02/22111201/face-biometric-enrollment-768x512.jpg 768w, https://d1sr9z1pdl3mb7.cloudfront.net/wp-content/uploads/2023/02/22111201/face-biometric-enrollment-1536x1024.jpg 1536w" sizes="auto, (max-width: 2048px) 100vw, 2048px" />
		<a href="https://www.biometricupdate.com/companies/proof">Proof</a>, the identity and transaction-security company formerly known as Notarize, has launched its Verifiable Digital Credential, a portable digital identity that allows consumers to complete identity proofing once and reuse that verified identity across financial institutions and other organizations that accept Proof credentials. The VDC became generally available through Proof’s platform and API on September 15.

The launch comes as three developments converge around reusable identity: U.S. regulators have given financial institutions clearer guidance for using verifiable digital credentials; Proof has an existing network of businesses where reusable identity could potentially gain utility; and AI agents are creating a new identity problem — proving not only who is behind an agent, but what that person authorized it to do.

Together, those developments make the launch more than the introduction of another digital credential. They point toward a model in which verified identity can move between institutions — and potentially into transactions performed by AI agents on a person’s behalf.

According to Proof, each credential is anchored to an individual X.509 certificate issued by its WebTrust-audited certificate authority following <a href="https://www.biometricupdate.com/tag/kantara">Kantara</a>-certified <a href="https://www.biometricupdate.com/202310/iso-nist-compliance-updates-for-proof-arana-yoti-authid">IAL2 identity proofing</a>. The credential is held by the consumer rather than belonging to an individual relying institution, allowing it to be presented again wherever Proof credentials are accepted.

The significance of the launch becomes clearer when each of those three developments is considered separately.
<h2><strong>Regulators give VDCs a clearer path into financial services</strong></h2>
The first development happened just seven days before Proof’s announcement.

On September 8, the Financial Crimes Enforcement Network, together with staff from the Federal Reserve, FDIC, NCUA and OCC, issued new and updated FAQs explaining how verifiable digital credentials can fit within existing Customer Identification Program requirements.

The agencies addressed VDCs through two routes.

Government-issued VDCs, such as <a href="https://www.biometricupdate.com/202609/federal-regulators-say-mdls-can-be-used-for-bank-identity-checks">mobile driver’s licenses</a> (mDLs), may qualify as government-issued identification and therefore potentially be used as a documentary verification method when applicable CIP requirements are satisfied.

Separately, regulators updated an existing FAQ covering electronic credentials to explicitly <a href="https://www.biometricupdate.com/202609/ai-fraud-accelerates-us-shift-toward-cryptographic-digital-identity">include VDCs</a> alongside digital certificates as a potential non-documentary identity verification method. That guidance can include credentials issued and maintained by non-government third parties.

That second route is particularly relevant to commercial credential issuers such as Proof.

It does not amount to a regulatory endorsement of Proof or any other provider. Financial institutions remain responsible for ensuring that a third-party credential issuer uses an appropriate level of authentication. The guidance also does not change existing Bank Secrecy Act requirements or create new supervisory expectations.

What has changed is that VDCs are now explicitly addressed within federal CIP guidance.

Roger W. Ferguson Jr., former vice chairman of the Federal Reserve Board of Governors and a member of Proof’s board of directors, framed portable identity as both a consumer-experience and trust-infrastructure issue.

“Portable digital identity has the potential to reduce friction for consumers while giving institutions stronger, independently verifiable evidence,” Ferguson said, adding that such systems require infrastructure built to standards expected of financial institutions.

The regulatory clarification gives financial institutions greater clarity for evaluating an identity model that differs significantly from how most consumers prove who they are today.
<h2><strong>From repeatedly verifying an ID to carrying an identity</strong></h2>
Consider a consumer opening a checking account.

They might upload a driver’s license, take a selfie and complete identity and fraud checks. Later, they apply for a credit card and potentially repeat the process. A mortgage can trigger another identity check. Opening an account or applying for another credit card at a different institution can start the process again.

Each institution effectively establishes the person’s identity for itself, while copies of sensitive identity information can accumulate across organizations.

“For decades, every institution has effectively rebuilt a person’s identity from scratch,” Proof founder and CEO Pat Kinsel said, describing the repeated cycle of document uploads, selfies and identity checks.

Proof’s model is designed to change that architecture.

After completing <a href="https://www.biometricupdate.com/202408/what-are-nist-ial2-and-ial3-identity-verification-standards">IAL2 identity proofing</a>, Proof says the consumer receives a VDC anchored to a unique X.509 certificate bound to the verified identity. The credential is delivered to the consumer’s device and cryptographically bound to a hardware-protected key.

The consumer can then present the credential again at an institution that accepts it rather than repeating the complete identity-proofing process.

Proof says the service supports OpenID for Verifiable Credential Issuance (OID4VCI) and OpenID for Verifiable Presentations (OID4VP), allowing consumers either to enroll just in time or, if they already hold a Proof credential, reauthenticate and present their existing identity. Organizations do not have to preregister every user before receiving a credential.

Proof says the credential can also be reused for interactions including wire authorizations, beneficiary changes and account recovery. The company supports revocation and live credential-status checks, allowing a relying institution to determine whether a credential remains valid.

Using selective disclosure based on the SD-JWT verifiable credential format, Proof says consumers can provide only the identity attributes required for a particular decision rather than transmitting an entire identity document.

The institution still determines whether it trusts and accepts the credential.

That distinction is important. Reusable identity does not eliminate the relying institution’s responsibility to decide whom and what to trust. Instead, it changes the evidence available to make that decision.
<h2><strong>Proof already has a network where reusable identity could expand</strong></h2>
The second factor is distribution.

A reusable credential has limited value if there is nowhere to reuse it.

Proof says its identity infrastructure already serves more than 8,000 businesses across mortgage, auto, wealth, insurance and enterprise, and that more than $1 trillion in transactions have been secured across its platform.

Those figures describe Proof’s broader business network. They do not mean that all 8,000 businesses currently accept Proof’s VDC.

The company says individuals can claim a credential through Proof and use it with “participating organizations” across its network, but its announcement does not specify how many organizations currently accept the credential.

Still, Proof enters the reusable-identity market with an existing base of business relationships into which the credential could potentially expand.

The company has also spent 2026 building relationships and infrastructure around that strategy.

In March, Proof <a href="https://www.biometricupdate.com/202603/idemia-public-security-proof-partner-on-single-portable-digital-credential">announced</a> a strategic partnership with IDEMIA Public Security. The companies said they planned to combine IDEMIA’s identity verification and authentication technologies with Proof’s PKI-based digital signature and authorization network to support privacy-preserving VDCs spanning physical, logical and digital environments.

In May, Proof <a href="https://www.biometricupdate.com/202605/proofs-fido-alliance-membership-to-shape-ai-agent-standards">joined</a> the FIDO Alliance, describing the move as part of its work connecting verified human identity with actions performed through AI agents.

Then, in <a href="https://www.proof.com/blog/identity-infrastructure-agentic-internet-x401">June</a>, Proof launched x401, which the company describes as an open, issuer-neutral protocol for verifying the identity and authority behind AI agents.

Taken together, the announcements show the direction of Proof’s strategy: not simply issuing a credential, but trying to establish infrastructure through which verified identity and authorization can be reused across different interactions.
<h2><strong>AI agents introduce a new identity and authorization problem</strong></h2>
The third development pushes the story beyond traditional customer onboarding.

AI agents raise a different version of a familiar identity question.

Imagine an agent receiving an instruction to open an account, move money or change a beneficiary.

The institution receiving that request needs to answer two separate questions: Who is the human behind the agent, and did that person authorize this particular action?

Proof is positioning its VDC and x401 architecture around that problem.

The company says its VDC establishes the identity of the person, while its authorization infrastructure and x401 protocol are designed to carry that identity into agentic interactions and create cryptographic evidence connecting an agent’s action to the verified person and the authority granted to it.

When Proof launched x401 in June, it described the protocol as issuer-neutral and designed to allow a website or API to request the particular evidence it requires from an agent — such as verified identity, age, membership, organizational affiliation, signing authority or proof of humanness.

The agent can then present a compatible credential and authorization for the receiving service to evaluate.

The architecture is Proof’s answer to an emerging problem, rather than evidence that the industry has settled on a particular approach to agent identity or authorization.

But it illustrates why portable identity could become more relevant as transactions move beyond direct human-to-application interactions.

A reusable credential could potentially serve two generations of digital transactions: reducing repeated identity proofing in today’s human-initiated interactions while providing one component of the trust infrastructure needed when software begins acting on a verified person’s behalf.
<h2><strong>From identity checks to identity infrastructure</strong></h2>
The convergence of these developments is what makes Proof’s launch notable.

Regulatory clarity provides a pathway. Proof’s existing business network could provide distribution. And the rise of AI agents is creating new questions around how verified human identity and delegated authority can be carried into machine-initiated transactions.

The immediate proposition is relatively straightforward.

Instead of repeatedly uploading identity documents and completing identity proofing at every participating institution, a consumer verifies their identity once, receives cryptographically verifiable evidence of that identity and presents it again where the credential is accepted.

But the longer-term implication is broader.

Digital identity verification has largely operated as a point-in-time transaction: an institution asks who someone is and performs the checks necessary to answer that question. The result generally remains inside that institution.

Reusable credentials begin to separate the verified identity from the institution that happens to need it at that moment.

If financial institutions become comfortable accepting credentials issued by trusted third parties, identity verification could gradually shift from something every institution independently reconstructs toward a portable trust layer that consumers carry between financial relationships.

And if AI agents increasingly transact on behalf of those consumers, that identity may eventually need to travel another step — from the verified human, through an authorized agent, to the institution receiving the instruction.

Proof’s launch places the company at the intersection of those two shifts: making human identity reusable today and attempting to make that identity usable when machines act on humans’ behalf tomorrow.]]></description>
		
					<wfw:commentRss>https://www.biometricupdate.com/202609/proofs-vdc-launch-brings-together-banking-regulation-reusable-identity-and-ai-agents/feed</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">355948</post-id>	</item>
		<item>
		<title>Deal for cybersecurity lab expands Fime’s digital identity assurance portfolio</title>
		<link>https://www.biometricupdate.com/202609/deal-for-cybersecurity-lab-expands-fimes-digital-identity-assurance-portfolio</link>
					<comments>https://www.biometricupdate.com/202609/deal-for-cybersecurity-lab-expands-fimes-digital-identity-assurance-portfolio#respond</comments>
		
		<dc:creator><![CDATA[Chris Burt]]></dc:creator>
		<pubDate>Tue, 15 Sep 2026 19:25:56 +0000</pubDate>
				<category><![CDATA[Biometrics News]]></category>
		<category><![CDATA[Trade Notes]]></category>
		<category><![CDATA[acquisitions]]></category>
		<category><![CDATA[biometric testing]]></category>
		<category><![CDATA[cybersecurity]]></category>
		<category><![CDATA[digital trust]]></category>
		<category><![CDATA[Fime]]></category>
		<category><![CDATA[Red Alert Labs]]></category>
		<guid isPermaLink="false">https://www.biometricupdate.com/?p=355887</guid>

					<description><![CDATA[
		<img width="2048" height="1152" src="https://d1sr9z1pdl3mb7.cloudfront.net/wp-content/uploads/2024/09/12085247/acquisition-scaled.jpg" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="" decoding="async" loading="lazy" srcset="https://d1sr9z1pdl3mb7.cloudfront.net/wp-content/uploads/2024/09/12085247/acquisition-scaled.jpg 2048w, https://d1sr9z1pdl3mb7.cloudfront.net/wp-content/uploads/2024/09/12085247/acquisition-300x169.jpg 300w, https://d1sr9z1pdl3mb7.cloudfront.net/wp-content/uploads/2024/09/12085247/acquisition-1024x576.jpg 1024w, https://d1sr9z1pdl3mb7.cloudfront.net/wp-content/uploads/2024/09/12085247/acquisition-150x84.jpg 150w, https://d1sr9z1pdl3mb7.cloudfront.net/wp-content/uploads/2024/09/12085247/acquisition-768x432.jpg 768w, https://d1sr9z1pdl3mb7.cloudfront.net/wp-content/uploads/2024/09/12085247/acquisition-1536x864.jpg 1536w" sizes="auto, (max-width: 2048px) 100vw, 2048px" />
		The market around biometrics and digital identity testing has developed to the point where accredited labs and evaluation bodies are choosing strategic directions that differentiate them from their competition.

In the latest example of this trend, <a href="https://www.biometricupdate.com/companies/fime">Fime</a> has acquired cybersecurity and compliance automation provider <a href="https://www.redalertlabs.com/">Red Alert Labs</a> to advance its position as an overall digital trust provider.

The acquisition brings cybersecurity evaluation, certification expertise and compliance automation capabilities to Fime’s established portfolio of payments, smart mobility and digital identity testing, according to the announcement. It also gives Fime access to Red Alert Labs’ Cyberpass compliance automation platform.

Red Alert Labs is lending its <a href="https://www.biometricupdate.com/202502/european-ai-compliance-project-certain-launches">expertise in AI compliance</a> to the EU’s CERTAIN initiative as a consortium partner.

Fime CEO Lionel Grosclaude notes the firms ambition to serve as a global digital trust provider. That means providing the trust infrastructure that enables digital ecosystems to scale.

“For more than three decades, we have helped build trust in payments, and we have extended that expertise into digital identity and smart mobility,” Grosclaude says. “Cybersecurity is the next natural step. These markets are converging: customers increasingly need to prove not only that a product works and interoperates, but that it is secure, compliant and remains trustworthy throughout its lifecycle.”

Red Alert Labs Founder and Managing Director Roland Atoui says the together with Fime it can offer continuous compliance readiness assessments, certification industrialization and enhance trust in digital identity, digital wallets and the ecosystems that are emerging around AI agents.

He will continue to lead the lab, which continues operating as an independent entity, keeping its accreditations and autonomy.

Fime’s steady expansion of its testing and trust assurance services includes the recent launch of a certification scheme for mDL-storing <a href="https://www.biometricupdate.com/202607/fime-launches-mdl-certification-scheme-for-wallets-readers">digital wallets and mDL readers</a>.]]></description>
		
					<wfw:commentRss>https://www.biometricupdate.com/202609/deal-for-cybersecurity-lab-expands-fimes-digital-identity-assurance-portfolio/feed</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">355887</post-id>	</item>
		<item>
		<title>OSD granted patent for biometric barcode security and authentication</title>
		<link>https://www.biometricupdate.com/202609/osd-granted-patent-for-biometric-barcode-security-and-authentication</link>
					<comments>https://www.biometricupdate.com/202609/osd-granted-patent-for-biometric-barcode-security-and-authentication#respond</comments>
		
		<dc:creator><![CDATA[Chris Burt]]></dc:creator>
		<pubDate>Tue, 15 Sep 2026 19:24:16 +0000</pubDate>
				<category><![CDATA[Biometric R&D]]></category>
		<category><![CDATA[Biometrics News]]></category>
		<category><![CDATA[Civil / National ID]]></category>
		<category><![CDATA[Austrian State Printing House (OSD)]]></category>
		<category><![CDATA[data protection]]></category>
		<category><![CDATA[identity document]]></category>
		<category><![CDATA[patents]]></category>
		<category><![CDATA[QR code]]></category>
		<category><![CDATA[research and development]]></category>
		<guid isPermaLink="false">https://www.biometricupdate.com/?p=355925</guid>

					<description><![CDATA[
		<img width="2048" height="945" src="https://d1sr9z1pdl3mb7.cloudfront.net/wp-content/uploads/2026/09/15152117/Andorra_Drivers_License.jpg" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="" decoding="async" loading="lazy" srcset="https://d1sr9z1pdl3mb7.cloudfront.net/wp-content/uploads/2026/09/15152117/Andorra_Drivers_License.jpg 2048w, https://d1sr9z1pdl3mb7.cloudfront.net/wp-content/uploads/2026/09/15152117/Andorra_Drivers_License-300x138.jpg 300w, https://d1sr9z1pdl3mb7.cloudfront.net/wp-content/uploads/2026/09/15152117/Andorra_Drivers_License-1024x473.jpg 1024w, https://d1sr9z1pdl3mb7.cloudfront.net/wp-content/uploads/2026/09/15152117/Andorra_Drivers_License-150x69.jpg 150w, https://d1sr9z1pdl3mb7.cloudfront.net/wp-content/uploads/2026/09/15152117/Andorra_Drivers_License-768x354.jpg 768w, https://d1sr9z1pdl3mb7.cloudfront.net/wp-content/uploads/2026/09/15152117/Andorra_Drivers_License-1536x709.jpg 1536w" sizes="auto, (max-width: 2048px) 100vw, 2048px" />
		A new European patent awarded to the <a href="https://www.biometricupdate.com/companies/osterreichische-staatsdruckerei-gmbh">Austrian State Printing Company</a> (OSD) provides IP protection for a technology the company says could establish a new standard for securing the data included on identity documents.

The patent granted for “<a href="https://register.epo.org/application?number=EP22185169&amp;tab=main">Securing and Authenticating of a Personal Identity Document</a>” describes a process to protect identity data with the company’s “Open Secure Document Biometric Barcode” for physical IDs. The process brings together biometrics and a QR code through open ledger technology. The publication of the patent in the European Patent Bulletin gives it international validity.

A control code is generated by applying a hash function to the payload data, which must be matched to access the identity data.

OSD points out that verification of chip-based ID documents that rely on NFC can be hampered by connection errors or physical wear-and-tear on the documents. OSD therefore suggests using a “digital security seal” either as an alternative or complement to the chip-based functionality of Machine Readable Travel Documents (MRTDs).

The biometric barcode technology can further be used to protect the foundational ID documents, or “breeder” documents like citizenship or birth certificates that are typically used in the issuance of passports and other identity documents.

OSD says its technology also protects against future risks like data harvesting and subsequent decryption by quantum computers, the company says.

“With the granting of this patent, OSD underscores its position as a global pioneer in the field of high-security technology and sets new standards for the protection of sensitive data,” explains OSD Director General Helmut Lackner. “Modern technologies ‘made in Austria’ not only protect citizens’ sensitive personal data but also ensure technological independence and sovereignty in uncertain times.”

OSD provides identity services to countries around the world, including an integration of <a href="https://www.biometricupdate.com/202609/liberia-to-link-national-id-crvs-in-planned-infrastructure-upgrade">Liberia’s national ID and civil registry</a>, and issuance of biometric ID cards in Nigeria for <a href="https://www.biometricupdate.com/202605/osd-euphoria-revealed-as-tech-suppliers-for-ecowas-biometric-id-in-nigeria">travel in the ECOWAS region</a>.]]></description>
		
					<wfw:commentRss>https://www.biometricupdate.com/202609/osd-granted-patent-for-biometric-barcode-security-and-authentication/feed</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">355925</post-id>	</item>
		<item>
		<title>UK pubs can legally accept digital ID for age assurance; now, implementation begins</title>
		<link>https://www.biometricupdate.com/202609/uk-pubs-can-legally-accept-digital-id-for-age-assurance-now-implementation-begins</link>
					<comments>https://www.biometricupdate.com/202609/uk-pubs-can-legally-accept-digital-id-for-age-assurance-now-implementation-begins#respond</comments>
		
		<dc:creator><![CDATA[Joel R. McConvey]]></dc:creator>
		<pubDate>Tue, 15 Sep 2026 18:59:11 +0000</pubDate>
				<category><![CDATA[Age Assurance]]></category>
		<category><![CDATA[Biometrics News]]></category>
		<category><![CDATA[age verification]]></category>
		<category><![CDATA[biometrics]]></category>
		<category><![CDATA[Digital Proof of Age (DPoA)]]></category>
		<category><![CDATA[digital verification service (DVS)]]></category>
		<category><![CDATA[legislation]]></category>
		<category><![CDATA[Luciditi]]></category>
		<category><![CDATA[TOTUM]]></category>
		<category><![CDATA[UK age verification]]></category>
		<category><![CDATA[UK digital ID]]></category>
		<category><![CDATA[Yoti]]></category>
		<guid isPermaLink="false">https://www.biometricupdate.com/?p=355904</guid>

					<description><![CDATA[
		<img width="2048" height="1481" src="https://d1sr9z1pdl3mb7.cloudfront.net/wp-content/uploads/2025/11/25170131/digital-id-in-pubs-scaled.jpg" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="" decoding="async" loading="lazy" srcset="https://d1sr9z1pdl3mb7.cloudfront.net/wp-content/uploads/2025/11/25170131/digital-id-in-pubs-scaled.jpg 2048w, https://d1sr9z1pdl3mb7.cloudfront.net/wp-content/uploads/2025/11/25170131/digital-id-in-pubs-300x217.jpg 300w, https://d1sr9z1pdl3mb7.cloudfront.net/wp-content/uploads/2025/11/25170131/digital-id-in-pubs-1024x741.jpg 1024w, https://d1sr9z1pdl3mb7.cloudfront.net/wp-content/uploads/2025/11/25170131/digital-id-in-pubs-150x108.jpg 150w, https://d1sr9z1pdl3mb7.cloudfront.net/wp-content/uploads/2025/11/25170131/digital-id-in-pubs-768x555.jpg 768w, https://d1sr9z1pdl3mb7.cloudfront.net/wp-content/uploads/2025/11/25170131/digital-id-in-pubs-1536x1111.jpg 1536w" sizes="auto, (max-width: 2048px) 100vw, 2048px" />
		The UK government has made it official: licensed premises across England and Wales will now have the option to accept digital proof of age for alcohol sales. The draft Licensing Act 2003 (Mandatory Licensing Conditions) (Amendment) Order 2026 has been approved by both the House of Commons and the House of Lords.

Which is to say, the amendments to the mandatory licensing conditions for alcohol sales are now in force, and certified digital ID is a valid option for age assurance in pubs, bars, restaurants, shops and other licensed premises. Finally, the government’s <a href="https://www.biometricupdate.com/202606/uk-pubs-to-accept-digital-id-for-age-assurance-by-christmas-2026">promise of Christmastime pints</a> bought using digital ID for age checks is coming to pass.

“Pubs, bars, restaurants, music venues and other licensed premises across England and Wales will have the choice to introduce digital proof of age for alcohol sales under new rules coming into force today,” says the release. It quotes Digital Government Minister Stephanie Peacock, who says the “groundbreaking” change “will mean you do not need to carry a physical ID, nor hand over sensitive personal information such as your name or address just to prove your age – allowing everyone to feel safer on a night out.”

There is one small caveat, expressed in the caution that “it will take businesses time to widely adopt and accept digital proof-of-age.” Put another way, the system is in no way actually ready for action: the law may allow digital ID for buying hooch, but for now most places don’t have the training, partners and infrastructure needed to accept them. The reality of the change will unfold as part of the larger <a href="https://www.biometricupdate.com/202609/interoperability-adoption-now-critical-questions-facing-uk-digital-identity-effort">shift to digital ID</a> and credentials, as businesses respond to legislative change, customer demand and generational shifts.
<h2>For Luciditi and other certified DVS providers, hard work begins</h2>
UK biometrics providers, however, have been preparing for some time. Only digital IDs provided by firms certified against the Digital Verification Services (DVS) trust framework are valid in the <a href="https://www.biometricupdate.com/202608/ofdia-guidance-limits-alcohol-age-checks-to-certified-uk-digital-id-providers">UK system</a>. DVSPs must operate a currently certified Orchestration Service, with which a license holder must have an agreement in place prior to accepting digital ID.

Luckily, a number of leading providers have already laid the foundations for the ecosystem. Currently, the <a href="https://www.access-dvs-register.service.gov.uk/register/all-providers?PageNum=5">UK DVS register</a> lists 46 providers.

Among those certified for orchestration, <a href="https://www.biometricupdate.com/companies/luciditi">Luciditi</a> and Yoti have worked on a <a href="https://www.biometricupdate.com/202604/yoti-luciditi-demo-interoperable-age-check-at-2026-gaass">partnership</a> to allow interoperability between their products (along with Post Office EasyID), to help drive adoption of what could be a game-changing shift in how identity functions as proof of age.

In a post on Luciditi’s website, CTO Philip Young <a href="https://luciditi.co.uk/use-of-digital-id-with-alcohol-sales-england-and-wales-whats-changing/">says</a> that “allowing individuals to use certified digital IDs for alcohol sales is a practical, modern change that will make life easier for consumers and safer for front-line staff.”

“Whichever digital ID someone chooses, they now have a secure digital option that protects their privacy. With Luciditi Verification Services already present in point of sale systems and assistive challenge 25 technologies, we’re helping all kinds of licensed premises reduce conflict, improve compliance, and deliver a smoother customer journey.”

Young notes that licensees are not obliged to accept digital ID; they can choose to require physical ID. And he expands on the government’s buried proviso on timing, acknowledging that “it will take time for a critical mass of licensed premises to get hold of the technology so that it becomes ubiquitous.” That said, he predicts that “things will likely look very different by this time next year!”
<h2>Yoti announces partnerships with four UK point of sale providers</h2>
<a href="https://www.biometricupdate.com/companies/yoti">Yoti</a>, which has been <a href="https://www.biometricupdate.com/202607/yoti-licensing-connect-prepare-uk-pubs-for-digital-proof-of-age">gearing up</a> for the change in laws for more than a decade, today announced new partnerships with Diebold Nixdorf, Flooid, StrongPoint Kestronics and Zebra Technologies, all of which provide point of sale and self-checkout technology to the UK’s leading supermarkets, retail and hospitality businesses.

Per a release from the company, “through their partnerships with Yoti, the technology partners and retailers will integrate digital ID checks into their existing point of sale and self-checkout systems, making it easier for licensed businesses already using their technology to begin accepting digital proof of age.”

Yoti also offers a free ID Checker mobile and web app and a partnership with Licensing Connect, to make it easier for small businesses to check that a customer’s digital proof of age is authentic and valid. The company says more than 15,000 businesses downloaded the ID Checker app ahead of the change in law, “meaning many premises can start accepting Yoti ID and Post Office EasyID for alcohol sales from today.”

Robin Tombs, CEO of Yoti, calls the change “a landmark moment for <a href="https://www.biometricupdate.com/202607/the-uk-national-digital-id-is-dead-long-live-the-uk-digital-id">digital identity in the UK</a>.”

“We’ve been working towards this moment since Yoti was founded in 2014 and we’re delighted to work with leading technology providers including Diebold Nixdorf, Flooid, StrongPoint, Kestronics and Zebra Technologies to make it simple for businesses to start accepting digital proof of age.”

Yoti’s group product manager, Emily Hyett, recently joined the <em>Biometric Update Podcast</em> to discuss <a href="https://www.biometricupdate.com/202609/digital-id-for-alcohol-sales-is-coming-to-the-uk-hear-what-it-means-for-the-identity-sector">how Yoti’s digital ID works</a>, what customers can expect and what providers can do to help support broad adoption.
<h2>TOTUM to launch digital proof of age product for students</h2>
More specialized companies are also making changes in the wake of the new law. A release from <a href="https://totum.com/">TOTUM</a>, a member benefits and ID platform for students, apprentices and professionals, says it is preparing the launch of its own digital proof of age solution, building on its TOTUM+ PASS card.

Simon Wild, head of marketing at TOTUM, says its PASS+ card “has already given millions of students a trusted way to verify their age,” and says the company is “excited to bring that same reliability to a digital format that fits straight into their phone.”]]></description>
		
					<wfw:commentRss>https://www.biometricupdate.com/202609/uk-pubs-can-legally-accept-digital-id-for-age-assurance-now-implementation-begins/feed</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">355904</post-id>	</item>
		<item>
		<title>From data residency to key sovereignty: Thales launches UK cloud HSM</title>
		<link>https://www.biometricupdate.com/202609/from-data-residency-to-key-sovereignty-thales-launches-uk-cloud-hsm</link>
					<comments>https://www.biometricupdate.com/202609/from-data-residency-to-key-sovereignty-thales-launches-uk-cloud-hsm#respond</comments>
		
		<dc:creator><![CDATA[Ashok Singal]]></dc:creator>
		<pubDate>Tue, 15 Sep 2026 18:55:33 +0000</pubDate>
				<category><![CDATA[Biometrics News]]></category>
		<category><![CDATA[Trade Notes]]></category>
		<category><![CDATA[cloud services]]></category>
		<category><![CDATA[data protection]]></category>
		<category><![CDATA[data sovereignty]]></category>
		<category><![CDATA[hardware security module (HSM)]]></category>
		<category><![CDATA[identity infrastructure]]></category>
		<category><![CDATA[key sovereignty]]></category>
		<category><![CDATA[Thales]]></category>
		<category><![CDATA[Thales Digital Identity and Security]]></category>
		<guid isPermaLink="false">https://www.biometricupdate.com/?p=355811</guid>

					<description><![CDATA[
		<img width="2048" height="1365" src="https://d1sr9z1pdl3mb7.cloudfront.net/wp-content/uploads/2022/09/12135754/cloud-computing-scaled.jpg" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="" decoding="async" loading="lazy" srcset="https://d1sr9z1pdl3mb7.cloudfront.net/wp-content/uploads/2022/09/12135754/cloud-computing-scaled.jpg 2048w, https://d1sr9z1pdl3mb7.cloudfront.net/wp-content/uploads/2022/09/12135754/cloud-computing-300x200.jpg 300w, https://d1sr9z1pdl3mb7.cloudfront.net/wp-content/uploads/2022/09/12135754/cloud-computing-1024x683.jpg 1024w, https://d1sr9z1pdl3mb7.cloudfront.net/wp-content/uploads/2022/09/12135754/cloud-computing-150x100.jpg 150w, https://d1sr9z1pdl3mb7.cloudfront.net/wp-content/uploads/2022/09/12135754/cloud-computing-768x512.jpg 768w, https://d1sr9z1pdl3mb7.cloudfront.net/wp-content/uploads/2022/09/12135754/cloud-computing-1536x1024.jpg 1536w" sizes="auto, (max-width: 2048px) 100vw, 2048px" />
		French technology and cybersecurity group Thales has launched a UK-hosted version of its Luna Cloud HSM, allowing organizations to consume hardware security module (HSM) capabilities as a cloud service while keeping the full lifecycle of their cryptographic keys within the UK.

<a href="https://www.thalesgroup.com/en/news-centre/press-releases/thales-launches-uk-hosted-cloud-hsm-help-customers-overcome-key-barrier">Announced</a> on September 14, the service addresses a growing consideration for organizations moving sensitive systems to the cloud: keeping data in the UK may not be enough if the cryptographic keys protecting that data are managed elsewhere.
<h2><strong>From dedicated HSMs to HSM as a service</strong></h2>
Traditionally, organizations requiring greater control over cryptographic keys could deploy and manage their own HSM hardware. That provides control, but also brings the cost and complexity of installing, maintaining and scaling specialized infrastructure.

Thales’ Luna Cloud HSM provides those capabilities as a service through its cloud marketplace for cryptographic and data-protection services. The marketplace, called <a href="https://cpl.thalesgroup.com/encryption/data-protection-on-demand">Data Protection on Demand (DPoD)</a>, allows organizations to consume cryptographic capabilities without buying and managing the underlying HSM infrastructure themselves.

For UK customers, the important part is localization. Thales says cryptographic keys will be generated, stored, used, backed up and destroyed within the UK. Two UK-based DPoD instances will also provide high availability and disaster recovery within the country.

“Cloud adoption has moved beyond questions of where services are hosted,” said Paul Hampton, Data Protection Cloud Services Owner at Thales. Organizations increasingly need to know who controls the cryptographic keys protecting their applications, identities and data, he added.
<h2><strong>Cloud HSM is not new</strong></h2>
Thales is not the only provider addressing this. Microsoft Azure, AWS and Google Cloud all offer HSM or key-management services that can operate within specific regions, including the UK.

But their native services are primarily tied to their respective cloud environments. Thales’ model, delivered independently of any single hyperscaler, allows organizations to separate their choice of cryptographic infrastructure from the cloud hosting their applications and data.

That distinction could matter most to customers concerned about dependence on a foreign-headquartered cloud provider — the same broader jurisdictional concern underlying recent European technology decisions.
<h2><strong>Data residency does not solve the entire sovereignty problem</strong></h2>
Keeping sensitive data in a UK data center addresses data residency. But organizations must also consider who controls the cryptographic keys that provide access to encrypted information.

Where are those keys stored? Who can access them? Where are backups maintained? Which jurisdiction applies to the infrastructure provider?

These questions are particularly relevant for digital identity, where cryptographic keys underpin credential signing, authentication, encryption and trusted transactions.

Thales’ proposition therefore combines two requirements: consuming cryptographic infrastructure as a cloud service while maintaining domestic control over the keys protecting sensitive systems.
<h2><strong>Sovereignty concerns are already affecting technology decisions</strong></h2>
<a href="https://www.biometricupdate.com/202609/from-data-residency-to-tech-sovereignty-europe-rethinks-control">Recent European cases</a> show that these concerns can influence major technology and investment decisions.

The Dutch government blocked U.S.-based Kyndryl’s proposed acquisition of Dutch cloud provider Solvinity earlier this year. Solvinity supports infrastructure behind DigiD, the Netherlands’ national authentication system, raising concerns about critical digital infrastructure coming under the control of a U.S. parent company.

Switzerland faced a related controversy over plans involving AWS infrastructure for its national electronic identity ecosystem, highlighting concerns about relying on foreign-controlled infrastructure for sensitive government systems.

The cases demonstrate why physical data residency is increasingly being separated from technological control. Encryption can reduce exposure when an infrastructure provider cannot decrypt customer data, but that moves the sovereignty question one level deeper: who controls the keys?
<h2><strong>Independent validation adds another layer of assurance</strong></h2>
Thales points to both FIPS 140 validation and SOC 2 compliance for its Luna HSM technology and cloud services.

Under the NIST-led <a href="https://csrc.nist.gov/projects/cryptographic-module-validation-program">Cryptographic Module Validation Program (CMVP)</a>, cryptographic modules are tested against FIPS requirements by accredited independent laboratories before their results are reviewed and validated by the program. SOC 2 provides additional independent assurance around controls governing areas such as security and availability.

For regulated and government customers, these assessments provide evidence beyond the vendor’s own claims about the infrastructure protecting their cryptographic keys.

The technology is also already being applied to digital identity infrastructure. Earlier this year, Thales and Ubiqu <a href="https://www.biometricupdate.com/202601/thales-and-ubiqu-collaborate-on-rse-for-secure-eu-digital-id-wallet-infrastructure">integrated</a> Luna HSMs into a remote secure element for the EUDI Wallet, where the HSM provides the protected environment for cryptographic keys and operations. The solution is designed to meet eIDAS High requirements and support post-quantum cryptography.
<h2><strong>Why now?</strong></h2>
More sensitive workloads are moving to the cloud, bringing government systems, financial services, telecommunications and digital identity infrastructure into the migration conversation. At the same time, sovereignty requirements are expanding beyond the location of data toward questions of ownership, jurisdiction and cryptographic control.

Another transition is approaching: <a href="https://www.biometricupdate.com/tag/post-quantum-cryptography">post-quantum cryptography</a>. Organizations are beginning to prepare cryptographic infrastructure for algorithms designed to withstand future attacks from quantum computers. Thales positions the UK-hosted service as a crypto-agile foundation for that transition, allowing organizations to adapt their cryptographic infrastructure as standards and requirements evolve.

Thales’ own <a href="https://cpl.thalesgroup.com/quantum-ai-data-threat-report#form-download">research</a>, conducted by S&amp;P Global Market Intelligence, found that 36 percent of respondents considered strong encryption and key management sufficient protection for their sovereignty objectives regardless of physical location.

That points to two approaches emerging around sovereign cloud: localize the infrastructure, or retain cryptographic control over the data even when infrastructure crosses borders. The UK-hosted Luna service combines elements of both.
<h2><strong>Broader implications for the industry</strong></h2>
Thales’ UK launch reflects two broader shifts in cloud infrastructure.

First, data sovereignty is expanding beyond where data is stored. Governments and regulated organizations increasingly have to consider who controls their cloud infrastructure, cryptographic keys, backups and other technology supporting sensitive applications.

Second, the infrastructure protecting those keys is itself moving to the cloud. HSMs have traditionally been specialized appliances organizations purchased, installed and operated. They are increasingly becoming infrastructure that can be consumed as a service.

For governments and regulated enterprises, this creates a new balance between infrastructure ownership and infrastructure control. Organizations may not need to physically own every component if they can retain sufficient control over their keys, determine where they are managed and meet domestic resilience and governance requirements.

The post-quantum transition could further accelerate that shift. Crypto-agile services may make it easier for organizations to change algorithms and security policies as cryptographic standards evolve without replacing individually managed hardware across their infrastructure.

For cloud and security providers, local HSM and key-management infrastructure could therefore become an increasingly important part of sovereign cloud offerings as more sensitive government, financial and identity workloads move to the cloud.

<a href="https://www.biometricupdate.com/tag/thales-digital-identity-and-security">Thales</a>’ UK expansion suggests the next phase of cloud sovereignty will be determined not only by where data resides, but also by who controls the cryptographic infrastructure protecting it.]]></description>
		
					<wfw:commentRss>https://www.biometricupdate.com/202609/from-data-residency-to-key-sovereignty-thales-launches-uk-cloud-hsm/feed</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">355811</post-id>	</item>
		<item>
		<title>EU to propose tiered social media age restrictions for under-15s</title>
		<link>https://www.biometricupdate.com/202609/eu-to-propose-tiered-social-media-age-restrictions-for-under-15s</link>
					<comments>https://www.biometricupdate.com/202609/eu-to-propose-tiered-social-media-age-restrictions-for-under-15s#respond</comments>
		
		<dc:creator><![CDATA[Joel R. McConvey]]></dc:creator>
		<pubDate>Tue, 15 Sep 2026 18:47:50 +0000</pubDate>
				<category><![CDATA[Age Assurance]]></category>
		<category><![CDATA[Biometrics News]]></category>
		<category><![CDATA[age verification]]></category>
		<category><![CDATA[biometrics]]></category>
		<category><![CDATA[chatbots]]></category>
		<category><![CDATA[EU age verification]]></category>
		<category><![CDATA[EU KIDS Act]]></category>
		<category><![CDATA[gaming]]></category>
		<category><![CDATA[legislation]]></category>
		<category><![CDATA[social media]]></category>
		<guid isPermaLink="false">https://www.biometricupdate.com/?p=355883</guid>

					<description><![CDATA[
		<img width="1080" height="720" src="https://d1sr9z1pdl3mb7.cloudfront.net/wp-content/uploads/2026/02/03130419/online-marketplace-for-AI-generated-content.jpg" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="" decoding="async" loading="lazy" srcset="https://d1sr9z1pdl3mb7.cloudfront.net/wp-content/uploads/2026/02/03130419/online-marketplace-for-AI-generated-content.jpg 1080w, https://d1sr9z1pdl3mb7.cloudfront.net/wp-content/uploads/2026/02/03130419/online-marketplace-for-AI-generated-content-300x200.jpg 300w, https://d1sr9z1pdl3mb7.cloudfront.net/wp-content/uploads/2026/02/03130419/online-marketplace-for-AI-generated-content-1024x683.jpg 1024w, https://d1sr9z1pdl3mb7.cloudfront.net/wp-content/uploads/2026/02/03130419/online-marketplace-for-AI-generated-content-150x100.jpg 150w, https://d1sr9z1pdl3mb7.cloudfront.net/wp-content/uploads/2026/02/03130419/online-marketplace-for-AI-generated-content-768x512.jpg 768w" sizes="auto, (max-width: 1080px) 100vw, 1080px" />
		The governing body of the European Union is moving ahead on a proposal to set a minimum legal age of 15 for using social media platforms. Politico <a href="https://www.politico.eu/article/eu-to-propose-new-legislation-on-minors-protection-on-thursday/">reports</a> that the European Commission will propose new rules to limit access to social media and video-sharing platforms for those under 15 years of age.

Expected Thursday, the EU KIDS Act will establish age restrictions, but also include requirements for safety by design. The proposal “aims to create a tiered system for accessing social media under parental supervision before age 15,” wherein content is progressively accessible at different ages, and there are limits on contact with strangers and screen times.

The accompanying new enforcement architecture follows the models of the Digital Services Act and the Artificial Intelligence Act, including supervisory fees to be paid by the highest-risk companies, intended to cover the costs of enforcement.
<h2>Proposal answers Macron’s call</h2>
European Commission President Ursula von der Leyen has been a vocal advocate for online safety laws and <a href="https://www.biometricupdate.com/202607/european-commission-calls-for-mandated-age-assurance-for-social-media">age assurance requirements</a> for social media platforms, and began facing more pressure to act on a bloc-wide solution after France’s national law covering social media was put on hold by a Constitutional Council over free speech concerns.

French President Emmanuel Macron, in particular, <a href="https://www.biometricupdate.com/202609/eu-age-assurance-debate-intensifies-as-macron-seeks-bloc-wide-social-media-law">urged von der Leyen</a> to pursue a unified position across member states on a minimum age for social media, as Austria, Denmark, France, Greece and Spain all pursue laws at the national level, creating the possibility for fragmented regulations across the bloc.

The Commission has encouraged EU member states to adopt its white-label age verification app, but the incoming EU Digital Identity Wallet (EUDI Wallet) program looks likely to reorient the sector towards a wallet-based model – <a href="https://www.biometricupdate.com/202609/for-eu-consumers-trust-in-eudi-wallet-will-need-to-be-earned-over-time-idnow">albeit slowly</a>.
<h2>Regulations also target AI chatbots, video game platforms</h2>
<a href="https://www.biometricupdate.com/202607/ofcom-launches-investigation-into-tiktok-over-age-inference-system">TikTok</a>, Instagram, <a href="https://www.biometricupdate.com/202601/ireland-hears-fast-track-calls-for-deepfake-bill-following-xs-grok-controversy">X</a> and other large social media platforms have become regulatory targets due to rising concerns from parents, educators and kids themselves about the potential mental health risks the platforms present for kids. Meta has faced <a href="https://www.biometricupdate.com/202608/meta-agrees-to-enhanced-age-assurance-in-18b-settlement-in-social-media-harms-case">major legal consequences</a> in the U.S. over how its platforms have failed to protect minors. <a href="https://psycnet.apa.org/fulltext/2026-89350-001.html">New studies</a> are emerging showing a correlation between short-form video consumption and negative cognitive changes.

However, while social platforms have become the biggest targets, they are not the only services to face the regulator’s whip. The EU’s proposal also applies to video-sharing platforms, online games (they’re looking at you, <a href="https://www.biometricupdate.com/202608/roblox-makes-enforceable-promise-to-address-remaining-online-safety-concerns">Roblox</a>), AI chatbots and AI companions.

Per the report, the text is still subject to change ahead of its formal presentation on Thursday and will have to be negotiated with European governments and members of the European Parliament afterward. Von der Leyen is expected to present more details in her State of the European Union speech to parliament members in Strasbourg on Wednesday.]]></description>
		
					<wfw:commentRss>https://www.biometricupdate.com/202609/eu-to-propose-tiered-social-media-age-restrictions-for-under-15s/feed</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">355883</post-id>	</item>
		<item>
		<title>Google rolls out age inference in Canada</title>
		<link>https://www.biometricupdate.com/202609/google-rolls-out-age-inference-in-canada</link>
					<comments>https://www.biometricupdate.com/202609/google-rolls-out-age-inference-in-canada#respond</comments>
		
		<dc:creator><![CDATA[Joel R. McConvey]]></dc:creator>
		<pubDate>Tue, 15 Sep 2026 18:45:42 +0000</pubDate>
				<category><![CDATA[Age Assurance]]></category>
		<category><![CDATA[Biometrics News]]></category>
		<category><![CDATA[age inference]]></category>
		<category><![CDATA[Google]]></category>
		<category><![CDATA[Google Play Age Signals]]></category>
		<category><![CDATA[machine learning]]></category>
		<category><![CDATA[YouTube]]></category>
		<guid isPermaLink="false">https://www.biometricupdate.com/?p=355936</guid>

					<description><![CDATA[
		<img width="2048" height="1536" src="https://d1sr9z1pdl3mb7.cloudfront.net/wp-content/uploads/2025/06/25122709/youtube-scaled.jpg" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="" decoding="async" loading="lazy" srcset="https://d1sr9z1pdl3mb7.cloudfront.net/wp-content/uploads/2025/06/25122709/youtube-scaled.jpg 2048w, https://d1sr9z1pdl3mb7.cloudfront.net/wp-content/uploads/2025/06/25122709/youtube-300x225.jpg 300w, https://d1sr9z1pdl3mb7.cloudfront.net/wp-content/uploads/2025/06/25122709/youtube-1024x768.jpg 1024w, https://d1sr9z1pdl3mb7.cloudfront.net/wp-content/uploads/2025/06/25122709/youtube-150x113.jpg 150w, https://d1sr9z1pdl3mb7.cloudfront.net/wp-content/uploads/2025/06/25122709/youtube-768x576.jpg 768w, https://d1sr9z1pdl3mb7.cloudfront.net/wp-content/uploads/2025/06/25122709/youtube-1536x1152.jpg 1536w" sizes="auto, (max-width: 2048px) 100vw, 2048px" />
		Google is trying out an age assurance strategy in Canada for its YouTube platform. However, it has opted not for <a href="https://www.biometricupdate.com/202607/2026-age-assurance-digital-age-credentials-market-report">privacy preserving age assurance technology</a> certified against international standards – but rather for its own machine learning-based age profiling system.

Google calls it “age estimation,” though it is more properly classified as age inference, and even then only tenuously; <a href="https://www.iso.org/standard/88143.html">ISO/IEC 27566-1</a>, which covers age assurance systems, specifies that true age inference must be “based on verified information.”

Google’s system uses machine learning to “interpret a variety of signals already associated with a user’s account, such as the types of information a user has searched for or the categories of videos they’ve watched on YouTube. These signals help us determine whether a user is likely over or under the age of 18.”

In a <a href="https://blog.google/intl/en-ca/company-news/technology/ensuring-safer-online-experiences-for-canadian-kids-and-teens/">post</a>, the company will automatically apply age-appropriate protections for users it determines to be under 18, including “Digital Wellbeing tools” such as “reminders to take a break and go to bed”;  disabling personalized ads and restricting age-sensitive ad categories; and blocking minors from accessing apps restricted to adults on Google Play.

However, this method does not offer a conclusion based on what most would consider “verified information.” Google’s analysis of search and watch histories does not offer the same certainty as a verified database – and in one not-so-dim light, this looks like just another opportunity for Google to collect more data about its users.

Being geared toward a Canadian audience, Google’s statement is deferential, polite and friendly. It insists its profiling tech was designed with user privacy in mind: “it minimizes the need to collect additional data and ensures we are not sharing granular user information with apps and websites unnecessarily.”

However, it cannot resist casting a little shade at regulators in general – nor spreading the liability around for everyone to share. “While some would like a system that imposes a universal arbiter of age,” it says, “we believe that liability and responsibility rest with every service owner – the developer, the publisher, the app creator – because they know their users and services best.”

Notably, users who believe they have been incorrectly identified as underage can appeal by perfoming age verifciation by uploading a photo of their government ID or a selfie.  The company does not specify if it performs this verification process in-house, or outsources it to a third party provider.

Google’s ML-based system has been implemented <a href="https://www.biometricupdate.com/202508/ai-age-assurance-not-a-hit-with-youtube-users">in the U.S.</a>, where a petition calling on YouTube to turn it off accrued 100,000 signatures. In July of 2025, the company said it had “used this approach in other markets for some time.”

The company also pointed to the would-be inference system when it was trying to argue its way out of being included in Australia’s Social Media Minimum Age Act. That <a href="https://www.biometricupdate.com/202507/youtube-plays-different-cards-in-us-australia-in-adapting-to-age-assurance-era">effort</a> also involved enlisting beloved children’s entertainers The Wiggles to shout down the age assurance law.

That said, it has been proactive in rolling out its <a href="https://www.biometricupdate.com/202608/google-rolls-out-play-age-signals-api-as-age-assurance-ecosystem-evolves">Play Age Signals API</a>, which uses an age range declared by an adult at the time of device registration to curate and limit content for age-appropriate experiences.

Canada recently <a href="https://www.biometricupdate.com/202606/canada-joins-push-for-social-media-age-assurance-with-new-digital-safety-law">tabled legislation</a> that would see it follow Australia, the UK and Europe in imposing age restrictions on social media platforms and put protections on AI chatbots.]]></description>
		
					<wfw:commentRss>https://www.biometricupdate.com/202609/google-rolls-out-age-inference-in-canada/feed</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">355936</post-id>	</item>
	</channel>
</rss>
