<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Biometric Update</title>
	<atom:link href="https://www.biometricupdate.com/feed" rel="self" type="application/rss+xml" />
	<link>https://www.biometricupdate.com</link>
	<description>Biometrics News, Companies and Explainers</description>
	<lastBuildDate>Tue, 06 Oct 2026 16:48:57 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	
<site xmlns="com-wordpress:feed-additions:1">66434804</site>	<item>
		<title>IAD from Idemia PS blocks all biometric bypass attempts in BixeLab evaluation</title>
		<link>https://www.biometricupdate.com/202610/iad-from-idemia-ps-blocks-all-biometric-bypass-attempts-in-bixelab-evaluation</link>
					<comments>https://www.biometricupdate.com/202610/iad-from-idemia-ps-blocks-all-biometric-bypass-attempts-in-bixelab-evaluation#respond</comments>
		
		<dc:creator><![CDATA[Chris Burt]]></dc:creator>
		<pubDate>Tue, 06 Oct 2026 14:30:44 +0000</pubDate>
				<category><![CDATA[Biometric R&D]]></category>
		<category><![CDATA[Biometrics News]]></category>
		<category><![CDATA[Liveness Detection]]></category>
		<category><![CDATA[AI fraud]]></category>
		<category><![CDATA[biometric testing]]></category>
		<category><![CDATA[biometrics]]></category>
		<category><![CDATA[BixeLab]]></category>
		<category><![CDATA[CEN/TS 18099]]></category>
		<category><![CDATA[IAD certification]]></category>
		<category><![CDATA[Idemia Public Security]]></category>
		<category><![CDATA[injection attack detection]]></category>
		<guid isPermaLink="false">https://www.biometricupdate.com/?p=358381</guid>

					<description><![CDATA[
		<img width="2048" height="1366" src="https://d1sr9z1pdl3mb7.cloudfront.net/wp-content/uploads/2025/02/10141537/injection-attack-scaled.jpg" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="" decoding="async" fetchpriority="high" srcset="https://d1sr9z1pdl3mb7.cloudfront.net/wp-content/uploads/2025/02/10141537/injection-attack-scaled.jpg 2048w, https://d1sr9z1pdl3mb7.cloudfront.net/wp-content/uploads/2025/02/10141537/injection-attack-300x200.jpg 300w, https://d1sr9z1pdl3mb7.cloudfront.net/wp-content/uploads/2025/02/10141537/injection-attack-1024x683.jpg 1024w, https://d1sr9z1pdl3mb7.cloudfront.net/wp-content/uploads/2025/02/10141537/injection-attack-150x100.jpg 150w, https://d1sr9z1pdl3mb7.cloudfront.net/wp-content/uploads/2025/02/10141537/injection-attack-768x512.jpg 768w, https://d1sr9z1pdl3mb7.cloudfront.net/wp-content/uploads/2025/02/10141537/injection-attack-1536x1025.jpg 1536w" sizes="(max-width: 2048px) 100vw, 2048px" />
		A global leader in biometrics has joined the ranks of technology providers confirmed compliant with the European standard for biometric injection attack detection (IAD) to defend against deepfakes, with <a href="https://www.biometricupdate.com/companies/idemia-public-security">Idemia Public Security</a> passing an evaluation by <a href="https://www.biometricupdate.com/companies/bixelab">BixeLab</a>.

Independent validation of vendor claims about IAD effectiveness is increasingly crucial in a market where biometric bypass checks are expected to rise at a CAGR of nearly 100 percent, according to the <a href="https://www.biometricupdate.com/202606/2026-injection-attack-detection-market-report-and-buyers-guide">2026 Injection Attack Detection Market Report and Buyer’s Guide</a> from <em>Biometric Update </em>and Goode Intelligence.

Idemia PS submitted version 3.38 of its WebCapture SDK to the Australia-based lab, where it went through 900 attempts and met the requirements of Level 2 (Substantial) protection.

None of the attacks attempted during the assessment by BixeLab were successful, and Idemia’s software made only two classification errors among the 300 legitimate user transactions, for a false rejection rate (FRR) of 0.67 percent.

<a href="https://bixelab.com/wp-content/uploads/2026/10/LoC-26_BXL067-Injection.v2.0.pdf" target="_blank" rel="noopener">The evaluation</a> was carried out in alignment with CEN/TS 18099 on both Android and macOS devices, and used 10 different injection attack instrument species including deepfakes, face swaps, replay attacks, face morphs and avatar reenactments.

“As deepfakes and injection attacks become more sophisticated and accessible, independent testing is increasingly important to ensure biometric systems can withstand real-world threats,” says Ted Dunstone, CEO of BixeLab, in the company announcement. “Testing against recognized standards such as CEN/TS 18099 provides organizations with objective evidence that these protections work in practice.”

Idemia PS SVP and Global Head of Smart Biometrics Virginie Flam emphasizes the importance of delivering the simple experience for legitimate users that the assessment shows while keeping pace with evolving AI-powered fraud.

The company has consistently placed among the leaders in face biometrics accuracy in independent assessments like <a href="https://www.biometricupdate.com/202609/nist-frte-11-update-shows-shifting-leaders-persistent-demographic-disparities">NIST’s FRTE</a>.

There are still less than a dozen IAD providers in the world who have publicly announced independent assessments to the EU standard. The number is rising quickly, however, even <a href="https://www.biometricupdate.com/202606/iad-procurement-testing-and-deployment-criteria-clarified-by-expert-panel">ahead of the finalization of ISO/IEC 25456</a>.]]></description>
		
					<wfw:commentRss>https://www.biometricupdate.com/202610/iad-from-idemia-ps-blocks-all-biometric-bypass-attempts-in-bixelab-evaluation/feed</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">358381</post-id>	</item>
		<item>
		<title>Pakistan’s Super App ambition faces gaps in digital foundations</title>
		<link>https://www.biometricupdate.com/202610/pakistans-super-app-ambition-faces-gaps-in-digital-foundations</link>
					<comments>https://www.biometricupdate.com/202610/pakistans-super-app-ambition-faces-gaps-in-digital-foundations#respond</comments>
		
		<dc:creator><![CDATA[Lu-Hai Liang]]></dc:creator>
		<pubDate>Tue, 06 Oct 2026 14:07:37 +0000</pubDate>
				<category><![CDATA[Biometrics News]]></category>
		<category><![CDATA[Civil / National ID]]></category>
		<category><![CDATA[Government Services]]></category>
		<category><![CDATA[digital ID]]></category>
		<category><![CDATA[digital public infrastructure]]></category>
		<category><![CDATA[NADRA]]></category>
		<category><![CDATA[Pakistan]]></category>
		<category><![CDATA[super app]]></category>
		<category><![CDATA[World Bank]]></category>
		<guid isPermaLink="false">https://www.biometricupdate.com/?p=358371</guid>

					<description><![CDATA[
		<img width="2048" height="1365" src="https://d1sr9z1pdl3mb7.cloudfront.net/wp-content/uploads/2024/08/15172441/pakistan-digital-wallet-scaled.jpg" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="" decoding="async" srcset="https://d1sr9z1pdl3mb7.cloudfront.net/wp-content/uploads/2024/08/15172441/pakistan-digital-wallet-scaled.jpg 2048w, https://d1sr9z1pdl3mb7.cloudfront.net/wp-content/uploads/2024/08/15172441/pakistan-digital-wallet-300x200.jpg 300w, https://d1sr9z1pdl3mb7.cloudfront.net/wp-content/uploads/2024/08/15172441/pakistan-digital-wallet-1024x683.jpg 1024w, https://d1sr9z1pdl3mb7.cloudfront.net/wp-content/uploads/2024/08/15172441/pakistan-digital-wallet-150x100.jpg 150w, https://d1sr9z1pdl3mb7.cloudfront.net/wp-content/uploads/2024/08/15172441/pakistan-digital-wallet-768x512.jpg 768w, https://d1sr9z1pdl3mb7.cloudfront.net/wp-content/uploads/2024/08/15172441/pakistan-digital-wallet-1536x1024.jpg 1536w" sizes="(max-width: 2048px) 100vw, 2048px" />
		Pakistan is racing to design a unified “<a href="https://www.biometricupdate.com/202602/pakistan-super-app-for-govt-services-document-verification-advances-toward-launch">Super App</a>” that promises citizens one gateway to government and private-sector services, but the latest signs indicate the underlying digital public infrastructure is struggling to keep pace.

Pakistan’s Ministry of IT extended the deadline for proposals on the national Super App from March 31 to April 10 after limited initial interest, according to <a href="https://propakistani.pk/2026/03/31/deadline-for-govts-digital-super-app-extended-with-tech-firms-caught-sleeping/">ProPakistani</a>. The Super App sits within the Digital Economy Enhancement Project (DEEP), backed by the World Bank.

Lawmakers have also pressed for secure national messaging platforms, with BEEP already in use and a broader Super App envisioned to integrate identity, communication and third-party services like ride‑hailing.

At a recent meeting chaired by Senator Palwasha Mohammad Zai Khan, lawmakers stressed the need for sensitive government communication to be kept within national systems. The Ministry of IT told the committee that BEEP, a government communications app, is already being used in place of WhatsApp and Zoom, and that secure phones for senior officials have been approved.

Senators raised concerns over project costs, citing figures of $74 million for BEEP and $20 million for the Super App, and directed the ministry and Pakistan Telecommunication Authority (PTA) to present detailed progress reports at the next meeting, according to <a href="https://minutemirror.com.pk/pakistan-plans-national-super-app-as-senate-raises-data-security-concerns-634951/">Minute Mirror</a>.

Progress on the Digital Economy Enhancement Project (<a href="https://www.biometricupdate.com/202501/looking-into-the-deep-advancing-pakistans-dpi">DEEP</a>) remains slow. Only $8.36 million of its revised $69.16 million financing, around 12 percent, had been disbursed more than two years after the project became effective, according to <a href="https://www.brecorder.com/news/40438591?utm_source=chatgpt.com">Business Recorder’s account of a World Bank review</a>. Just six entities were integrated with the National Data Exchange Layer against a target of 40.

Approved in March 2024 and set to close in July 2028, the project is rated “Moderately Satisfactory” overall, but the World Bank highlighted gaps in implementation. Key aims include strengthening digital governance, building the Pakistan Business Portal, and expanding citizen services.

Private-sector participation remains limited, with only one private-sector entity integrated with the National Data Exchange Layer. The Pakistan Business Portal has yet to process registrations or payments. While NADRA has issued 2.3 million digital IDs, transactions through the National Data Exchange Layer stood at 650,000 in August 2026, against a closing-period target of 13.333 million. Adoption gaps remain.

Women account for only 9.2 percent of users of digitally enabled services, below the 30 percent target. The Enterprise Architecture Framework has been completed but still needs to be published with an adoption roadmap, while the Data Governance Policy and Interoperability Framework await formal adoption and operationalization. The review calls for a time-bound strategy to prioritize services and bring more agencies onto the platforms.

The potential for a super app remains. Writing in <a href="https://www.dawn.com/news/2034769">Dawn</a>, chairman of the Pakistan Fintech Network, Nadeem Hussain, argues that many foundational pieces of a digital ecosystem are already in place — with digital identity via NADRA and electronic payments through Raast, for example.

“The additional benefit of a super app is that, given the depth of individual data available, a personal credit score can be built quite easily,” Hussain claims. “Based on the data available on WeChat, Chinese financial institutions can provide a credit limit of up to 200,000 yuan on the spot. Instant credit online or offline.”

Hussain also cautions against concentrating sensitive data and services in a single platform, favoring an open public-private model.

The Super App is planned to integrate with NADRA’s digital ID system for secure authentication and feature single sign‑on, personalized dashboards and a protected digital vault. Its microservices‑based architecture is intended to allow future expansion, third‑party integration and workflow automation.

For now the Super App represents an ambitious digital front door, a tantalizing vision, but one that arguably risks opening out onto corridors where identity, exchange and governance remain under construction.]]></description>
		
					<wfw:commentRss>https://www.biometricupdate.com/202610/pakistans-super-app-ambition-faces-gaps-in-digital-foundations/feed</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">358371</post-id>	</item>
		<item>
		<title>Vietnam expands VNeID into securities sector</title>
		<link>https://www.biometricupdate.com/202610/vietnam-expands-vneid-into-securities-sector</link>
					<comments>https://www.biometricupdate.com/202610/vietnam-expands-vneid-into-securities-sector#respond</comments>
		
		<dc:creator><![CDATA[Lu-Hai Liang]]></dc:creator>
		<pubDate>Tue, 06 Oct 2026 13:32:50 +0000</pubDate>
				<category><![CDATA[Biometrics News]]></category>
		<category><![CDATA[Civil / National ID]]></category>
		<category><![CDATA[Financial Services]]></category>
		<category><![CDATA[digital ID]]></category>
		<category><![CDATA[fraud prevention]]></category>
		<category><![CDATA[identity verification]]></category>
		<category><![CDATA[Vietnam]]></category>
		<category><![CDATA[VNeID]]></category>
		<guid isPermaLink="false">https://www.biometricupdate.com/?p=358361</guid>

					<description><![CDATA[
		<img width="1009" height="655" src="https://d1sr9z1pdl3mb7.cloudfront.net/wp-content/uploads/2024/10/23152725/vneid-app.png" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="" decoding="async" srcset="https://d1sr9z1pdl3mb7.cloudfront.net/wp-content/uploads/2024/10/23152725/vneid-app.png 1009w, https://d1sr9z1pdl3mb7.cloudfront.net/wp-content/uploads/2024/10/23152725/vneid-app-300x195.png 300w, https://d1sr9z1pdl3mb7.cloudfront.net/wp-content/uploads/2024/10/23152725/vneid-app-150x97.png 150w, https://d1sr9z1pdl3mb7.cloudfront.net/wp-content/uploads/2024/10/23152725/vneid-app-768x499.png 768w" sizes="(max-width: 1009px) 100vw, 1009px" />
		VNeID is making opening a securities account in Vietnam that much simpler. Vietnamese citizens who hold level‑2 electronic identity accounts can now use verified information, which is stored in the national digital ID app, to complete account registration directly on their smartphones.

With reduced paperwork and fewer repeated identity checks, securities firms report rapid uptake, according to <a href="https://www.vietnam.vn/en/vneid-mo-rong-he-sinh-thai-dich-vu-so">Vietnam.vn</a>. The report cites one securities firm as saying more than 70 percent of its new trading accounts are now opened via VNeID. Reported benefits include stronger protection against fraud, faster verification and greater convenience for customers.

VNeID’s expansion follows Decree 320/2026/ND-CP, which came into effect on September 28. According to the report, many online accounts across banking, telecoms, e-commerce and healthcare must be linked to and authenticated through electronic identity accounts. The aim is to reduce fake accounts and improve trust in digital transactions.

Vietnam is rapidly expanding VNeID. A sweeping <a href="https://www.biometricupdate.com/202608/vietnam-extends-vneid-beyond-people-to-assets-land-and-transactions">draft Law on Electronic Identification and Authentication</a> would expand digital identity beyond people and organizations to physical objects, intangible assets and data, events and transactions, and locations. The draft law would position identity as the trust layer for much of Vietnam’s digital economy.

Vietnam is also moving to assign every land parcel a unique digital ID as it shifts from paper “red books” to data‑based management integrated with VNeID. The system has been piloted in Thanh Hoa Province as it standardizes and cleans parcel records, enabling electronic land‑use certificates and reducing paperwork.

Vietnam’s government has ambitions for VNeID that would turn it into a national “super app.” The plans <a href="https://www.biometricupdate.com/202605/vietnam-approves-sweeping-plan-to-turn-vneid-into-national-digital-super-app">set out a roadmap</a> that stretches from 2026 to 2045 and places the platform at the center of the country’s digital government ambitions. Linkages would also cross borders.

Vietnam has formalized plans to connect its VNeID digital identity system <a href="https://www.biometricupdate.com/202609/vietnam-moves-to-link-vneid-with-singapore-laos-digital-id-systems">with Singapore’s Singpass and Laos’ LAeID</a>, starting with airport pilots before potentially expanding the model across ASEAN. The move gives firmer shape to Vietnam’s push for regional digital identity interoperability as ASEAN governments work toward <a href="https://www.biometricupdate.com/202608/aseans-defa-sets-stage-for-regional-digital-identity-interoperability">deeper digital integration</a>.]]></description>
		
					<wfw:commentRss>https://www.biometricupdate.com/202610/vietnam-expands-vneid-into-securities-sector/feed</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">358361</post-id>	</item>
		<item>
		<title>Libyan officials get EU-backed biometrics training to improve border management</title>
		<link>https://www.biometricupdate.com/202610/libyan-officials-get-eu-backed-biometrics-training-to-improve-border-management</link>
					<comments>https://www.biometricupdate.com/202610/libyan-officials-get-eu-backed-biometrics-training-to-improve-border-management#respond</comments>
		
		<dc:creator><![CDATA[Ayang Macdonald]]></dc:creator>
		<pubDate>Tue, 06 Oct 2026 13:17:53 +0000</pubDate>
				<category><![CDATA[Biometrics News]]></category>
		<category><![CDATA[Border and Port Security]]></category>
		<category><![CDATA[biometrics]]></category>
		<category><![CDATA[border management]]></category>
		<category><![CDATA[document verification]]></category>
		<category><![CDATA[Europe]]></category>
		<category><![CDATA[Libya]]></category>
		<category><![CDATA[port security]]></category>
		<guid isPermaLink="false">https://www.biometricupdate.com/?p=358350</guid>

					<description><![CDATA[
		<img width="1117" height="745" src="https://d1sr9z1pdl3mb7.cloudfront.net/wp-content/uploads/2026/10/06091630/libya-training.jpg" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="" decoding="async" loading="lazy" srcset="https://d1sr9z1pdl3mb7.cloudfront.net/wp-content/uploads/2026/10/06091630/libya-training.jpg 1117w, https://d1sr9z1pdl3mb7.cloudfront.net/wp-content/uploads/2026/10/06091630/libya-training-300x200.jpg 300w, https://d1sr9z1pdl3mb7.cloudfront.net/wp-content/uploads/2026/10/06091630/libya-training-1024x683.jpg 1024w, https://d1sr9z1pdl3mb7.cloudfront.net/wp-content/uploads/2026/10/06091630/libya-training-150x100.jpg 150w, https://d1sr9z1pdl3mb7.cloudfront.net/wp-content/uploads/2026/10/06091630/libya-training-768x512.jpg 768w" sizes="auto, (max-width: 1117px) 100vw, 1117px" />
		Officials from three Libyan government ministries and the country's Customs Authority have undergone specialist training on biometrics and document security at the Italian State Police Academy (CAPS) in Cesena as part of an EU-backed initiative aimed at strengthening the country's integrated border management.

Through the initiative, the EU Border Assistance Mission in Libya (EUBAM Libya) is supporting Libyan authorities through technical advice, specialized training and the exchange of expertise on border management. EUBAM Libya is a civilian, non-executive EU mission.

Participants from the Ministries of Interior, Defense and Foreign Affairs, together with those from the Customs Authority, received training on document production and security features, electronic documents, biometrics, and the detection of fraudulent and manipulated documents, according to <a href="https://www.eeas.europa.eu/eubam-libya/european-multiagency-training-and-mentoring-strengthen-libyan-integrated-border-management-ibm_en">EUBAM Libya</a>.

The training was followed by a visit to Ancona International Port, where participants observed Italian authorities conducting live document and identity checks, using interoperable databases, and carrying out currency checks and risk-based customs inspections, including scanner use.

Libya is a major transit country for migrants from Africa seeking to reach Europe, including Italy, via the central Mediterranean. The training in Italy comes at a time when Tripoli is discussing the modernization of physical security and inspection infrastructure at its airports, seaports and land crossings.

During a recent visit to the United States, Libya's Interior Minister, Maj. Gen. Imad Trabelsi, met with representatives of <a href="https://www.rapiscansystems.com/en/markets/customs-and-border/customs-border-people-screening">Rapiscan Systems</a> and <a href="https://screeningsolution.com/customs-and-border">S2 Global</a> to discuss border and entry-point security, Libya Herald <a href="https://libyaherald.com/2026/10/rapiscan-systems-s2-global-discuss-with-tripoli-interior-minister-border-security-inspection-systems">reports</a>. Those discussions covered non-intrusive screening technologies for vehicles, containers, cargo, luggage and individuals, as well as systems for detecting explosives, narcotics, radioactive materials and contraband. They also discussed X-ray image analysis and screening data management.

The parties also discussed linking screening results with shipment information, operational data and security databases to provide a broader view of inspection operations, support risk assessment and identify cases requiring further scrutiny. The proposed approach could allow for comprehensive screening or multi-stage risk-based processes.

Libya’s efforts reflect developments in a number of countries where governments are taking measures to build <a href="https://www.biometricupdate.com/202606/why-border-security-is-moving-beyond-the-checkpoint">integrated border management systems</a>, including through biometrics, partnerships and coordination.

Salah Sakli, former central director of the Tunisian Border Guards, <a href="https://adf-magazine.com/2026/09/the-strategic-importance-of-border-management/">highlights</a> the importance of coordination and cooperation across agencies and between countries in an opinion piece published by Africa Defense Forum.

Sakli argues that stronger coordination is needed to tackle terrorism, trafficking, irregular migration and other transnational threats. He also emphasizes interoperability and information sharing, modern equipment, electronic surveillance, risk prevention, coordination with neighboring states, and the need to balance security with the legitimate movement of people and goods.

These developments point to a broader shift in border management toward technology and data, with biometrics, document verification, interoperable databases, non-intrusive screening and risk assessment increasingly working together.]]></description>
		
					<wfw:commentRss>https://www.biometricupdate.com/202610/libyan-officials-get-eu-backed-biometrics-training-to-improve-border-management/feed</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">358350</post-id>	</item>
		<item>
		<title>Where commercial value can actually be created around the EUDI Wallet</title>
		<link>https://www.biometricupdate.com/202610/where-commercial-value-can-actually-be-created-around-the-eudi-wallet</link>
					<comments>https://www.biometricupdate.com/202610/where-commercial-value-can-actually-be-created-around-the-eudi-wallet#respond</comments>
		
		<dc:creator><![CDATA[Ashok Singal]]></dc:creator>
		<pubDate>Tue, 06 Oct 2026 12:33:32 +0000</pubDate>
				<category><![CDATA[Biometrics News]]></category>
		<category><![CDATA[Civil / National ID]]></category>
		<category><![CDATA[Industry Analysis]]></category>
		<category><![CDATA[digital ID]]></category>
		<category><![CDATA[digital wallets]]></category>
		<category><![CDATA[Dock]]></category>
		<category><![CDATA[EU Digital Identity Framework]]></category>
		<category><![CDATA[EU Digital Identity Wallet]]></category>
		<category><![CDATA[Europe]]></category>
		<guid isPermaLink="false">https://www.biometricupdate.com/?p=358338</guid>

					<description><![CDATA[
		<img width="1520" height="990" src="https://d1sr9z1pdl3mb7.cloudfront.net/wp-content/uploads/2026/03/12105942/eudi-wallet-phone.jpg" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="" decoding="async" loading="lazy" srcset="https://d1sr9z1pdl3mb7.cloudfront.net/wp-content/uploads/2026/03/12105942/eudi-wallet-phone.jpg 1520w, https://d1sr9z1pdl3mb7.cloudfront.net/wp-content/uploads/2026/03/12105942/eudi-wallet-phone-300x195.jpg 300w, https://d1sr9z1pdl3mb7.cloudfront.net/wp-content/uploads/2026/03/12105942/eudi-wallet-phone-1024x667.jpg 1024w, https://d1sr9z1pdl3mb7.cloudfront.net/wp-content/uploads/2026/03/12105942/eudi-wallet-phone-150x98.jpg 150w, https://d1sr9z1pdl3mb7.cloudfront.net/wp-content/uploads/2026/03/12105942/eudi-wallet-phone-768x500.jpg 768w" sizes="auto, (max-width: 1520px) 100vw, 1520px" />
		Much of the discussion around the <a href="https://www.biometricupdate.com/tag/eu-digital-identity-wallet">European Digital Identity (EUDI) Wallet</a> has focused on its stakeholders and their roles. Once the trust infrastructure is in place, the commercial questions go further: what value does each participant create, who benefits and how does the participant get paid?

Dock Labs explored these questions in its webinar, <em>Building a Business Model Around EUDI Credentials</em>, featuring Richard Esplin and Agne Caunt. This analysis draws on that discussion to assess which models have the strongest commercial case. The examples below illustrate how those models work.

The strongest near-term opportunities involve reducing existing verification costs, incorporating credentials into established services and supplying acceptance technology. New payment flows require additional evidence of demand.
<h2><strong>The regulation settles three things before any business model does</strong></h2>
Basic identity is free. The wallet arrives with state-backed identity data, and its issuance, use and revocation must be free for natural persons. Private issuers cannot build a business on selling core identity. Their opening is in attributes the state does not supply: qualifications, income, membership and professional authorization.

Some acceptance is mandatory, on a separate timetable. Certain private relying parties must accept EUDI wallets, including covered services requiring strong user authentication and very large online platforms under specified conditions. The obligation is distinct from the end-of-2026 wallet availability deadline. Article 5f gives covered private relying parties a 36-month timetable from the relevant implementing acts, excludes micro and small enterprises from that provision, and requires acceptance upon the user’s voluntary request. Mandatory acceptance creates an implementation requirement; it does not guarantee usage or savings.

Usage tracking is heavily constrained. <a href="https://www.biometricupdate.com/202309/what-does-selective-disclosure-really-mean-a-deep-dive-into-the-latest-etsi-technical-report">Selective disclosure</a> lets users prove an attribute, such as an age threshold, without sharing a full document. The regulation also limits how wallet providers can collect and combine usage data. Business models that depend on following identifiable holders across services or linking credential presentations over time therefore face significant constraints.

These rules explain most of the assessments that follow. Models that need no new payment flow and no usage data are the easiest to build.
<h2><strong>Verifiers: the strongest near-term case</strong></h2>
Verifiers gain first because their return needs nobody else’s payment. Today a business may pay repeatedly for document checks, biometric comparison or database verification each time a new customer is onboarded.

For example, a lender accepts an income credential in place of collecting and assessing supporting evidence. The return is indirect: lower verification costs, less manual work, faster onboarding, better completion rates and lower fraud exposure.

The condition is that the credential replaces a process. A verifier that keeps every existing check and adds credential acceptance on top has added cost, with little saved.

Direct revenue is less certain. Illustrative examples include a stadium charging a small fee for fast entry or a retailer charging monthly for express checkout, with a credential proving entitlement. In both cases the customer pays for the time saved, and the credential is only one way to deliver it.

Referral models sit in between. A hotel could verify a guest’s loyalty credential and pass that guest to partner restaurants or spas for a fee. That works only if partners value the customers they receive.
<h2><strong>Issuers: value where the cost fits an existing fee or budget</strong></h2>
Issuers create value by turning information they have already established into evidence others can rely on. Whether they can charge for it depends on who benefits.

The models most likely to work attach the credential to money that already moves: A university bundles a digital diploma into an existing administrative fee; an employer funds staff credentials out of lower administrative costs; a hotel group treats loyalty credentials as a customer acquisition cost; governments can fund credentials they are already responsible for issuing, such as digital driving licences.

Charging the holder directly is plausible for narrow cases, such as a professional paying for a qualification credential that employers ask for.

Verifier-pays-issuer faces a harder question: why would a verifier pay for a credential the holder already possesses and presents? A lender compensates an income-credential issuer each time an applicant presents its credential. It faces two open questions. The holder already has the credential, so the verifier needs a reason to pay for it. And billing per use has to be done without revealing which holder presented which credential.

<a href="https://www.biometricupdate.com/202607/dock-labs-maps-where-the-eudi-wallet-market-begins">Credential type</a> adds a cost decision. Electronic Attestations of Attributes (EAAs) cover information such as membership or qualifications. Qualified attestations (QEAAs) come from qualified trust service providers and carry specific legal effects. Qualification pays for itself only where a relying party needs that assurance, such as a regulated transaction. For a loyalty program, qualified issuance needs an additional justification.

Issuers should confirm which credentials businesses will accept before investing in them. A credential nobody accepts has no commercial value.
<h2><strong>Ecosystem providers: large value, but only after both sides join</strong></h2>
Ecosystem providers establish shared credential formats, trusted issuers, participation rules and commercial terms. Their value lies in reducing separate negotiations and integrations between participants. Certification bodies, technology integrators and referral partners also contribute to these networks.

The likely value is not the wallet itself, but reducing the cost of connecting issuers, verifiers and credential types.

Revenue models include governance, certification, membership, revenue-sharing and marketplace fees. Their analogies are Visa and Mastercard scheme fees, card interchange, SWIFT’s KYC Registry and app stores.

The card analogy shows both the prize and the obstacle. Card schemes earn fees because merchants and cardholders are both already present in large numbers. A new credential network cannot assume either side is already present: issuers need a reason to join, and verifiers need useful credentials.

Sector networks with committed participants have the stronger early case. Open marketplaces face greater coordination and adoption costs.
<h2><strong>Wallet providers: the most constrained role</strong></h2>
Wallet providers have the least room to charge. Notified EUDI wallets must be free for natural persons to obtain, use and revoke, and providers are barred from observing transactions. Charging natural persons simply for obtaining, using or revoking the notified wallet is not available as a business model.

Illustrative examples include a pathology laboratory wallet whose test-result credentials patients share with hospitals and healthcare providers, reducing repeated forms and transcription when receiving systems import the results, or a bank wallet combining customer credentials and payment cards. The value depends on acceptance and workflow integration. Neither example establishes demand for a separate consumer subscription.

The speakers discuss user subscriptions, premium features, issuer fees, verifier fees and business-wallet functionality. Business offerings have the clearest case because organizations already pay for integration, management and support. The free-service requirement for natural persons does not apply in the same way, although relevant regulatory obligations remain.

Wallet providers also have no automatic claim on revenue they enable. A stadium’s fast-lane fee belongs to the stadium unless an agreement shares it.
<h2><strong>What models outside the EUDI framework show</strong></h2>
<a href="https://www.biometricupdate.com/tag/mdl">U.S. mobile driver’s licences</a> support a cautious commercial reading. California offers a free wallet and supports major phone wallets, while <a href="https://www.aamva.org/">AAMVA</a> provides free access to its issuer certificate list. These arrangements demonstrate value for verifiers and downstream services without establishing a payment to the issuer for every presentation.

Issuance alone does not create utility: acceptance varies by wallet and service. EUDI’s acceptance obligations offer an advantage, but working integrations determine the benefit. Online credentials have a clear process to replace—document-and-selfie collection—while in-person savings depend on volume, staff effort and assurance needs.

Free wallets and basic readers also raise the bar for paid offerings. The stronger opportunity is helping businesses use credentials through integration, management and specialized workflows, rather than charging consumers simply to hold them.

Bank-led schemes. Nordic BankID systems have banks issue the identity and relying parties pay per transaction. They are the clearest proof that verifier-pays can work, and they worked only after issuers covered nearly the whole population. Australia’s ConnectID follows the same design.
<h2><strong>What to watch as wallets launch</strong></h2>
Three signals matter: verifiers retiring existing checks, businesses paying for acceptance infrastructure or valuable attributes, and sector networks securing fees that participants accept.

Organizations must also choose between open and closed ecosystems. University qualifications accepted across industries gain wider reuse. Staff credentials restricted to an employer’s systems offer greater control and a clearer route to internal savings. Open networks expand reach but require broader interoperability and commercial coordination.

The practical starting point is one existing customer journey: what information it needs, which issuers and credential types meet its requirements, and what work disappears when that evidence arrives through a wallet. That provides a firmer commercial foundation than introducing a fee simply because credentials can be exchanged.]]></description>
		
					<wfw:commentRss>https://www.biometricupdate.com/202610/where-commercial-value-can-actually-be-created-around-the-eudi-wallet/feed</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">358338</post-id>	</item>
		<item>
		<title>Sarawak links state digital ID with Malaysia’s MyDigital ID for cross-government service access</title>
		<link>https://www.biometricupdate.com/202610/sarawak-links-state-digital-id-with-malaysias-mydigital-id-for-cross-government-service-access</link>
					<comments>https://www.biometricupdate.com/202610/sarawak-links-state-digital-id-with-malaysias-mydigital-id-for-cross-government-service-access#respond</comments>
		
		<dc:creator><![CDATA[Ayang Macdonald]]></dc:creator>
		<pubDate>Tue, 06 Oct 2026 12:21:30 +0000</pubDate>
				<category><![CDATA[Biometrics News]]></category>
		<category><![CDATA[Government Services]]></category>
		<category><![CDATA[ID for All]]></category>
		<category><![CDATA[cross border identity verification]]></category>
		<category><![CDATA[digital government]]></category>
		<category><![CDATA[government services]]></category>
		<category><![CDATA[Malaysia]]></category>
		<category><![CDATA[MyDigital ID]]></category>
		<category><![CDATA[QR code]]></category>
		<guid isPermaLink="false">https://www.biometricupdate.com/?p=358328</guid>

					<description><![CDATA[
		<img width="2032" height="1374" src="https://d1sr9z1pdl3mb7.cloudfront.net/wp-content/uploads/2026/10/06082019/sarawakpass.png" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="" decoding="async" loading="lazy" srcset="https://d1sr9z1pdl3mb7.cloudfront.net/wp-content/uploads/2026/10/06082019/sarawakpass.png 2032w, https://d1sr9z1pdl3mb7.cloudfront.net/wp-content/uploads/2026/10/06082019/sarawakpass-300x203.png 300w, https://d1sr9z1pdl3mb7.cloudfront.net/wp-content/uploads/2026/10/06082019/sarawakpass-1024x692.png 1024w, https://d1sr9z1pdl3mb7.cloudfront.net/wp-content/uploads/2026/10/06082019/sarawakpass-150x101.png 150w, https://d1sr9z1pdl3mb7.cloudfront.net/wp-content/uploads/2026/10/06082019/sarawakpass-768x519.png 768w, https://d1sr9z1pdl3mb7.cloudfront.net/wp-content/uploads/2026/10/06082019/sarawakpass-1536x1039.png 1536w" sizes="auto, (max-width: 2032px) 100vw, 2032px" />
		SarawakPass, a state-level digital ID in Malaysia, has been integrated with the national MyDigital ID system, allowing users to access participating state and federal services through either credential by scanning a QR code.

The integration was showcased at the International Digital Economy Conference Sarawak (IDECS) 2026 in Kuching on October 5, in the presence of Sarawak Premier Abang Johari Tun Openg, Dayak Daily <a href="https://dayakdaily.com/sarawakpass-now-links-sarawak-federal-digital-services-through-mydigital-id/">reports</a>.

The move is another example of a subnational credential operating alongside a national identity layer. Tobago ID in Tobago offers a <a href="https://www.biometricupdate.com/202609/tobago-launches-sub-national-digital-id-for-public-service-access">similar model</a> for public-service access.

According to a news release announcing the integration, SarawakPass users can now scan a MyDigital ID QR code to log into participating federal web services, while MyDigital ID users can do the reverse to access participating Sarawak services. Sarawak is a state located in East Malaysia on the island of Borneo.

SarawakPass has also expanded beyond government services, with integrations including Sarawak Energy's SEB Cares, Sarawak Water and AirBorneo. The state government plans to develop SarawakPass further as a shared digital layer for consent-based data exchange and personalized services.

The integration follows a <a href="https://www.biometricupdate.com/202512/malaysia-begins-mydigital-id-verification-integration-for-all-mobile-operators">memorandum of understanding</a> signed last year between the Sarawak government and Malaysia’s National Cyber Security Agency. At the time, authorities said the integration of the subnational and national digital IDs would make authentication across state and federal platforms seamless. SarawakPass was launched last year as an evolution of the existing Sarawak ID.

MyDigital ID CEO Nik Hisham Nik Ibrahim said the integration is a major step forward in building a national digital identity ecosystem that will facilitate access to a wide range of public services. He said the digital ID scheme has continued to expand, with about 14.1 million users now across 203 integrations and 82 million logins recorded since August last year. Nik Hisham added that the integration brings the trust of the national identity foundation closer to residents of Sarawak.

Malaysia is also advancing a federal push to build a stronger digital ecosystem. In a written parliamentary reply in July, Deputy Prime Minister Ahmad Zahid Hamidi said 19 state-level online applications had been integrated with MyDigital ID, with 28 more in development. Hamidi put the number of integrated online government services at 114 as of June, noting that a January 2025 directive from the chief secretary to the government requires ministries, statutory bodies, state secretaries and local authorities to adopt MyDigital ID single sign-on, which he said would help its use, as <a href="https://www.nst.com.my/news/nation/2026/07/1483246/mydigital-id-expands-19-state-level-platforms#google_vignette">reported</a> by New Straits Times.

Authorities have said MyDigital ID is voluntary, but its expanding integration into government and other services has raised questions about how voluntary it remains in practice.

A recent <a href="https://www.biometricupdate.com/202609/malaysia-and-mydigital-id-when-optional-starts-to-look-unavoidable">analysis</a> noted that while the credential remains formally optional, its growing use as an authentication layer for services means citizens could increasingly encounter situations where having a MyDigital ID becomes the practical route to accessing particular platforms.

MyDigital ID is increasingly being required for some services, including MyJPJ (road transport) and prepaid SIM card registration, while it has also been promoted as an age-verification option for social media users. MyDigital ID is targeting 17 million registered accounts by the end of 2026.

The SarawakPass integration therefore fits into a broader Malaysian push to make MyDigital ID interoperable across state, federal and eventually <a href="https://www.biometricupdate.com/202607/philippines-malaysia-explore-cross-border-digital-identity-verification">cross-border services</a>.]]></description>
		
					<wfw:commentRss>https://www.biometricupdate.com/202610/sarawak-links-state-digital-id-with-malaysias-mydigital-id-for-cross-government-service-access/feed</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">358328</post-id>	</item>
		<item>
		<title>Japan sets October launch for My Number Card on Android</title>
		<link>https://www.biometricupdate.com/202610/japan-sets-october-launch-for-my-number-card-on-android</link>
					<comments>https://www.biometricupdate.com/202610/japan-sets-october-launch-for-my-number-card-on-android#respond</comments>
		
		<dc:creator><![CDATA[Abhishek Jadhav]]></dc:creator>
		<pubDate>Tue, 06 Oct 2026 12:20:52 +0000</pubDate>
				<category><![CDATA[Biometrics News]]></category>
		<category><![CDATA[Civil / National ID]]></category>
		<category><![CDATA[age verification]]></category>
		<category><![CDATA[Android]]></category>
		<category><![CDATA[digital ID]]></category>
		<category><![CDATA[identity verification]]></category>
		<category><![CDATA[Japan]]></category>
		<category><![CDATA[My Number]]></category>
		<guid isPermaLink="false">https://www.biometricupdate.com/?p=358393</guid>

					<description><![CDATA[
		<img width="2000" height="1333" src="https://d1sr9z1pdl3mb7.cloudfront.net/wp-content/uploads/2020/03/02125402/android-phone.jpg" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="android phone" decoding="async" loading="lazy" srcset="https://d1sr9z1pdl3mb7.cloudfront.net/wp-content/uploads/2020/03/02125402/android-phone.jpg 2000w, https://d1sr9z1pdl3mb7.cloudfront.net/wp-content/uploads/2020/03/02125402/android-phone-150x100.jpg 150w, https://d1sr9z1pdl3mb7.cloudfront.net/wp-content/uploads/2020/03/02125402/android-phone-300x200.jpg 300w, https://d1sr9z1pdl3mb7.cloudfront.net/wp-content/uploads/2020/03/02125402/android-phone-768x512.jpg 768w, https://d1sr9z1pdl3mb7.cloudfront.net/wp-content/uploads/2020/03/02125402/android-phone-1024x683.jpg 1024w" sizes="auto, (max-width: 2000px) 100vw, 2000px" />
		Japan will <a href="https://www.digital.go.jp/en/news/482b21c3-146e-41dc-ab63-6c06c4a153bf">launch</a> My Number Card on Android on October 20, adding government-verified identity attributes to Google Wallet for in-person identity, age and residency checks.

The Digital Agency has scheduled the service for October 20. It will initially support identity, age, and residency checks during face-to-face government and commercial services.

Android phones have supported <a href="https://www.biometricupdate.com/tag/my-number">My Number</a> electronic certificates since 2023.

The certificates allow users to authenticate to My Number Portal, submit tax returns and moving applications, review medical expenses and pension information, and obtain government certificates at convenience stores.

The new attribute function provides a different capability. It stores government-verified identity information on the phone and allows the user to present selected information to a public agency or business.

The smartphone credential can contain My Number Card attributes including the holder’s name, address, date of birth, sex and facial photograph.

Businesses and public agencies must add compatible reading software before they can accept the Android credential

The <a href="https://www.digital.go.jp/policies/mynumber/mynumbercard-mdoc">Digital Agency</a> says organizations can use its free My Number Card Face-to-Face Verification App. They may also obtain software from an approved vendor.

Custom implementations can require an application to the Digital Agency, testing in its verification environment, and, depending on the software, government certification.

My Number on smartphones can use the device’s biometric authentication, such as face or fingerprint recognition, instead of requiring a PIN for some functions.

My Number Card for Android will require a phone containing a security chip that meets government specifications.

The Digital Agency has not published the criteria or a list of supported devices. It says further compatibility information will be available by October 20.

The Oct. 20 launch brings Android closer to feature parity with the <a href="https://www.biometricupdate.com/202212/japan-pushes-apple-to-support-digital-id-card-function-on-iphone">iPhone version</a> of My Number Card and extends Japan’s mobile identity system from online authentication into face-to-face credential presentation.]]></description>
		
					<wfw:commentRss>https://www.biometricupdate.com/202610/japan-sets-october-launch-for-my-number-card-on-android/feed</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">358393</post-id>	</item>
		<item>
		<title>DHS puts numbers behind RIVR-2, details new deepfake testing</title>
		<link>https://www.biometricupdate.com/202610/dhs-puts-numbers-behind-rivr-2-details-new-deepfake-testing</link>
					<comments>https://www.biometricupdate.com/202610/dhs-puts-numbers-behind-rivr-2-details-new-deepfake-testing#respond</comments>
		
		<dc:creator><![CDATA[Ashok Singal]]></dc:creator>
		<pubDate>Mon, 05 Oct 2026 22:01:03 +0000</pubDate>
				<category><![CDATA[Biometrics News]]></category>
		<category><![CDATA[Industry Analysis]]></category>
		<category><![CDATA[Liveness Detection]]></category>
		<category><![CDATA[biometric liveness detection]]></category>
		<category><![CDATA[biometric testing]]></category>
		<category><![CDATA[biometrics]]></category>
		<category><![CDATA[deepfake detection]]></category>
		<category><![CDATA[DHS S&T]]></category>
		<category><![CDATA[Remote Identity Validation Rally (RIVR)]]></category>
		<category><![CDATA[RIVR-X]]></category>
		<category><![CDATA[selfie biometrics]]></category>
		<guid isPermaLink="false">https://www.biometricupdate.com/?p=358317</guid>

					<description><![CDATA[
		<img width="2048" height="1366" src="https://d1sr9z1pdl3mb7.cloudfront.net/wp-content/uploads/2025/06/01124637/AI-identity-management-spoof-detection-scaled.jpg" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="" decoding="async" loading="lazy" srcset="https://d1sr9z1pdl3mb7.cloudfront.net/wp-content/uploads/2025/06/01124637/AI-identity-management-spoof-detection-scaled.jpg 2048w, https://d1sr9z1pdl3mb7.cloudfront.net/wp-content/uploads/2025/06/01124637/AI-identity-management-spoof-detection-300x200.jpg 300w, https://d1sr9z1pdl3mb7.cloudfront.net/wp-content/uploads/2025/06/01124637/AI-identity-management-spoof-detection-1024x683.jpg 1024w, https://d1sr9z1pdl3mb7.cloudfront.net/wp-content/uploads/2025/06/01124637/AI-identity-management-spoof-detection-150x100.jpg 150w, https://d1sr9z1pdl3mb7.cloudfront.net/wp-content/uploads/2025/06/01124637/AI-identity-management-spoof-detection-768x512.jpg 768w, https://d1sr9z1pdl3mb7.cloudfront.net/wp-content/uploads/2025/06/01124637/AI-identity-management-spoof-detection-1536x1025.jpg 1536w" sizes="auto, (max-width: 2048px) 100vw, 2048px" />
		DHS Science and Technology Directorate <a href="https://www.biometricupdate.com/202609/dhs-expands-rivr-testing-to-deepfakes-ai-generated-ids">announced RIVR-2</a> on September 21, emphasizing industry collaboration and the need for defenses to evolve faster than AI-generated documents and real-time impersonation attacks. A September 30 technical <a href="https://mdtf.org/Images/RemoteIdentity/RIVR-2%20Announcement.mp4">webinar</a> provided the next layer: quantifying gaps from RIVR-1, detailing how the next four tracks will be evaluated, and outlining a faster, recurring testing model.
<h2><strong>RIVR-1 shows different convenience and security bottlenecks</strong></h2>
DHS used the webinar to present <a href="https://mdtf.org/Images/RemoteIdentity/RIVR-2%20Announcement_final.pdf">RIVR-1 results</a> through the separate lenses of convenience for legitimate users and security against fraud.

On convenience, DHS reported that about one in four legitimate users failed to complete the full remote identity workflow. The component results show differences across the three technologies: median success was 99 percent for selfie-to-document matching (SMTD) and 96 percent for presentation attack detection (PAD), compared with 79 percent for identity document validation (IDV).

Security produced a different set of results. Selfie matching detected 99.99 percent of impostors across more than 7.8 million attempts, while the median IDV system detected 87 percent of fraudulent IDs across more than 1,900 IDs representing all 50 states. The median PAD system detected 53 percent of presentations using the attack instrument that was most successful against the tested systems.

The results put the RIVR-2 tracks in context: document validation recorded the lowest legitimate-user success rate, while PAD recorded the lowest detection rate against the attack highlighted by DHS.
<h2><strong>RIVR-X creates a track for emerging technologies</strong></h2>
IDV, SMTD and PAD remain the main <a href="https://www.biometricupdate.com/tag/remote-identity-validation-rally-rivr">RIVR</a> tracks, while biometric deepfake detection (BDD) becomes the first evaluation under RIVR-X, an experimental series for emerging technologies.

DHS also outlined plans to move toward approximately twice-yearly evaluations, creating opportunities to identify areas for improvement and test updated technologies in subsequent rounds.
<h2><strong>IDV expands the evidence and sets benchmarks</strong></h2>
<a href="https://mdtf.org/Images/RemoteIdentity/IDV%20Technical%20Documentation.pdf">RIVR-2-IDV</a> is open to commercial technologies currently in deployment, rather than systems still in pilot.

<a href="https://www.biometricupdate.com/tag/maryland-test-facility-mdtf">Maryland Test Facility (MdTF)</a> technical requirements specify a sequestered dataset, with no sample images provided, containing genuine and fraudulent U.S. driver’s licenses and state IDs from multiple issuing authorities, along with international passport face pages. Images include rotation, optical blur, perspective distortion and captures from different smartphone makes and models.

Evidence validation examines document format and completeness, expected security features, and signs of tampering or counterfeiting, including deepfakes. The technical requirements set a 10-second processing threshold and five-second goal. System error, document false reject and document false accept rates each have a 10 percent threshold for high performance and a 1 percent goal for excellent performance. Results can be disaggregated by factors including issuing authority and imaging smartphone.

RIVR-2-IDV also uses what DHS calls a “failure is suspicious” policy. A system error on a genuine document counts as a false rejection, while an error on a fraudulent document is treated as a fraudulent-document detection. A system therefore does not have to successfully process and explicitly classify a fraudulent document for that transaction to count as detected under the methodology.

Deepfake testing also intersects with IDV. Providers can opt into RIVR-X testing against digitally generated or manipulated document images, extending the evaluation to how IDV technologies respond to this type of document evidence.
<h2><strong>Selfie matching gets tougher images</strong></h2>
SMTD recorded the highest legitimate-user success and impostor-detection rates among the RIVR-1 results DHS presented. RIVR-2 adds image conditions intended to examine performance with more challenging inputs.

MdTF says the sequestered dataset includes selfies varying in pose, expression and illumination, along with rotation, optical blur, perspective distortion and images from different smartphone makes and models. New for RIVR-2 are common selfie-quality degradations, including photos taken in low light.

The addition allows matching performance to be measured when selfie illumination is less favorable than under well-lit conditions.

SMTD is measured through failure-to-extract, false non-match and false match rates, with biometric comparison evaluated at a system-provided operating threshold corresponding to a false match rate of one in 10,000.
<h2><strong>PAD gets regularly updated attack instruments</strong></h2>
RIVR-1 results presented by DHS showed the median PAD system detecting 53 percent of the most successful presentation attack.

RIVR-2 will evaluate active and passive PAD using multiple presentation attack instruments that DHS says will be updated regularly, with performance measured using BPCER and APCER.
<h2><strong>RIVR-X combines deepfake detectors, datasets and generation methods</strong></h2>
For biometric deepfake detection, DHS described an evaluation involving detectors, deepfake datasets and generation methods. The evaluation is intended to examine which generation methods are difficult to detect and whether detector performance generalizes across different methods.

Participating detector providers will be asked to contribute 1,000 deepfake images representing attacks their own technology detects successfully but that may be difficult for other detectors. DHS is also seeking contributions of deepfake attack data from other organizations.

The approach means participants can contribute both detection technologies and attack data to the evaluation. DHS said the contributed datasets will support comparisons involving different deepfake-generation methods.

DHS is also planning a Biometric and Identity Deepfake Detection Technical Exchange involving government and industry experts. The exchange will address development of an ongoing evaluation framework, including how sources of genuine and deepfake media can change over time while protecting commercial intellectual property.
<h2><strong>Testing runs into 2027</strong></h2>
Applications for IDV and SMTD are due October 16, with acceptance notifications scheduled for October 30 and systems due for testing by November 20.

PAD and BDD applications are expected to open in December, with testing extending into 2027.
<h2><strong>From aliased results to a different buyer-vendor conversation</strong></h2>
<a href="https://www.biometricupdate.com/tag/remote-identity-validation-rally-rivr">RIVR</a> results can change the traditional vendor conversation. Instead of starting with claims such as “we have the industry’s best document validation,” “our face matching is highly accurate,” or “our technology stops sophisticated attacks,” buyers can start with independent test results.

There is an important limitation in RIVR-2: results will be aliased by default, although participating companies can choose to identify themselves. Buyers will not automatically be able to associate every published result with a vendor.

Buyers can still ask whether a vendor participated and, if so, whether it will disclose its alias and results. Where vendors identify themselves, the conversation can move to measured performance: Where did the technology trail stronger-performing systems? Why? What is the roadmap for addressing those gaps, and when will improvements be delivered?

DHS expects this model to change with RIVR-3 and subsequent evaluations, when company names will be associated with results by default. If implemented as described, buyers would no longer depend on voluntary disclosure to connect performance with a provider, and participation in independent testing could become a qualification criterion for some procurements.

For vendors, recurring evaluations provide measured results that can identify areas for further development and opportunities to demonstrate improvement in subsequent rounds. For researchers and standards organizations, the evaluations provide data on unresolved gaps across document validation, presentation attacks, degraded biometric imagery and deepfake detection.

RIVR-2 expands the scope and frequency of that testing, while DHS’s planned move to named results in RIVR-3 would make vendor performance directly attributable by default.]]></description>
		
					<wfw:commentRss>https://www.biometricupdate.com/202610/dhs-puts-numbers-behind-rivr-2-details-new-deepfake-testing/feed</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		<enclosure url="https://mdtf.org/Images/RemoteIdentity/RIVR-2%20Announcement.mp4" length="183657865" type="video/mp4" />

		<post-id xmlns="com-wordpress:feed-additions:1">358317</post-id>	</item>
		<item>
		<title>Apple, Google lobby lawmakers to remove liability from draft online safety bills</title>
		<link>https://www.biometricupdate.com/202610/apple-google-lobby-lawmakers-to-remove-liability-from-draft-online-safety-bills</link>
					<comments>https://www.biometricupdate.com/202610/apple-google-lobby-lawmakers-to-remove-liability-from-draft-online-safety-bills#respond</comments>
		
		<dc:creator><![CDATA[Joel R. McConvey]]></dc:creator>
		<pubDate>Mon, 05 Oct 2026 21:44:02 +0000</pubDate>
				<category><![CDATA[Age Assurance]]></category>
		<category><![CDATA[Biometrics News]]></category>
		<category><![CDATA[age verification]]></category>
		<category><![CDATA[App Store Accountability Act (ASA)]]></category>
		<category><![CDATA[app store age verification]]></category>
		<category><![CDATA[Apple]]></category>
		<category><![CDATA[Google]]></category>
		<category><![CDATA[Meta]]></category>
		<guid isPermaLink="false">https://www.biometricupdate.com/?p=358292</guid>

					<description><![CDATA[
		<img width="2048" height="1536" src="https://d1sr9z1pdl3mb7.cloudfront.net/wp-content/uploads/2025/05/28170822/app-store-scaled.jpg" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="" decoding="async" loading="lazy" srcset="https://d1sr9z1pdl3mb7.cloudfront.net/wp-content/uploads/2025/05/28170822/app-store-scaled.jpg 2048w, https://d1sr9z1pdl3mb7.cloudfront.net/wp-content/uploads/2025/05/28170822/app-store-300x225.jpg 300w, https://d1sr9z1pdl3mb7.cloudfront.net/wp-content/uploads/2025/05/28170822/app-store-1024x768.jpg 1024w, https://d1sr9z1pdl3mb7.cloudfront.net/wp-content/uploads/2025/05/28170822/app-store-150x113.jpg 150w, https://d1sr9z1pdl3mb7.cloudfront.net/wp-content/uploads/2025/05/28170822/app-store-768x576.jpg 768w, https://d1sr9z1pdl3mb7.cloudfront.net/wp-content/uploads/2025/05/28170822/app-store-1536x1152.jpg 1536w" sizes="auto, (max-width: 2048px) 100vw, 2048px" />
		<span style="font-weight: 400;">A new expose shows Apple and Google engaged in “a massive effort to press state lawmakers to adopt kids’ online safety laws that would shield the tech giants from some lawsuits tied to age-verification requirements.” </span><span style="font-weight: 400;">The </span><a href="https://www.politico.com/news/2026/10/04/apple-googlestates-app-stores-lawsuits-01105892"><span style="font-weight: 400;">report</span></a><span style="font-weight: 400;"> from Politico offers more proof of what regulators and age assurance advocates have </span><a href="https://www.biometricupdate.com/202608/australias-esafety-boss-seeks-easier-access-to-documents-in-ongoing-battle-with-social-media"><span style="font-weight: 400;">known for some time</span></a><span style="font-weight: 400;">: when it comes to age assurance regulations, Silicon Valley's main goal is avoiding liability.</span><span style="font-weight: 400;"> </span>

<span style="font-weight: 400;">Here, draft legislation, internal emails and “interviews with seven people with knowledge of the effort” all show Apple and Google – which together control the bulk of the device and OS market – urging lawmakers to redraft versions of the App Store Accountability Act with alternative text that would remove the possibility of private lawsuits and assign enforcement entirely to state attorneys general. </span>

<span style="font-weight: 400;">The so-called Mobile Ecosystem Responsibility Act (MERA) dictates that “the Attorney General shall have exclusive authority to enforce,” and specifies that nothing in the bill “shall be interpreted to serve as the basis for a private right of action.” </span>

<span style="font-weight: 400;">This suggested law, and the lobbyists pitching it, followed versions of the <a href="https://www.congress.gov/bill/119th-congress/senate-bill/1586">App Store Accountability Ac</a>t across Georgia, Arizona and Kansas, as Apple and Google aimed to limit accountability measures in the existing draft law. </span>
<h2>Meta, Apple eye each other across the age assurance divide</h2>
<span style="font-weight: 400;">Long rumbling through industry conversations on age assurance, the faults separating two sides of the Silicon Valley power structure are increasingly exposed. </span><span style="font-weight: 400;">The world is trying to make the internet and its flagship spaces less risky, and no company wants to get caught in the regulatory web; the result is a standoff between </span><a href="https://www.biometricupdate.com/202502/meta-insists-app-stores-not-apps-are-the-best-place-for-age-assurance-measures"><span style="font-weight: 400;">social media giants</span></a><span style="font-weight: 400;"> on one side, and device titans on the other.</span><span style="font-weight: 400;"> </span>

<span style="font-weight: 400;">Meta and other social media companies have spent significant time and money arguing against age checks at the platform level, and </span><a href="https://www.biometricupdate.com/202411/should-app-stores-be-responsible-for-age-assurance-meta-says-yes-but-experts-disagree"><span style="font-weight: 400;">in favor of the ASAA</span></a><span style="font-weight: 400;">.</span><span style="font-weight: 400;"> So says Politico: “social media companies, like Meta, have been supportive of the legislation, advocates say, partly because it shifts liability around age verification to app stores rather than the platforms themselves.” Meta, </span><a href="https://www.biometricupdate.com/202608/meta-agrees-to-enhanced-age-assurance-in-18b-settlement-in-social-media-harms-case"><span style="font-weight: 400;">beset by lawsuits</span></a><span style="font-weight: 400;"> and bad press, will do what it can to make age assurance someone else’s problem. </span>

<span style="font-weight: 400;">Apple and Google, meanwhile, roll out </span><a href="https://www.biometricupdate.com/202602/apple-updates-declared-age-range-api-for-national-state-level-age-assurance-laws"><span style="font-weight: 400;">declared age range models</span></a><span style="font-weight: 400;"> and hold them up as evidence of their commitment to compliance.</span><span style="font-weight: 400;"> At the same time, they pester lawmakers to alter draft legislation to protect them from legal consequences. </span>
<h2>Age assurance models at both levels face perpetual litigation machine</h2>
<span style="font-weight: 400;">Whether intentional or not, the overall result is a legislative landscape in which complexity begins to look like a major obstacle to practical implementation, as states pass regulations and Big Tech meets them from both sides with lawsuits, lobbyists and lies. </span>

Four states have enacted App Store Accountability Acts, while California has adopted a related but distinct operating-system age-assurance framework.

<span style="font-weight: 400;">So far, five states have enacted versions of the </span><span style="font-weight: 400;">App Store Accountability Act or similar legislation</span><span style="font-weight: 400;">. Utah and Louisiana have both enacted their own spins on the law. </span><span style="font-weight: 400;">Texas passed SB 2420, but it’s currently enforceable following a Fifth Circuit Court decision – one in a growing list of rulings that have seen the law </span><a href="https://www.biometricupdate.com/202607/scotus-sides-with-texas-on-app-store-age-verification-denies-emergency-block"><span style="font-weight: 400;">knocked about</span></a><span style="font-weight: 400;"> the U.S. courts willy-nilly.</span><span style="font-weight: 400;"> Alabama’s version of the ASAA is set to take effect January 1, 2027, as is <a href="https://www.biometricupdate.com/202609/california-child-safety-laws-expand-age-checks-to-addictive-feeds-ai-chatbots">California’s AB 1043</a>, or Digital Age Assurance Act, an app store age-adaptation framework closely related to the ASAA. </span>

<span style="font-weight: 400;">Three more states – Arizona, Georgia and Kansas – have introduced versions of the law. </span>

<span style="font-weight: 400;">The legislative architecture of the U.S. means that these states all battle for themselves in the courtroom, even when a legal framework is shared. (On a federal level, the Kids Online Safety Act, or KOSA, </span><a href="https://www.biometricupdate.com/202610/kosa-stalls-in-senate-as-age-assurance-moves-into-online-safety-debate"><span style="font-weight: 400;">stalled in the Senate last week</span></a><span style="font-weight: 400;">.) </span>

<span style="font-weight: 400;">And they now face the competing interests of the world’s most powerful tech companies. In this context, the path to a consistent, clear age assurance regime in the states looks long, rocky and at constant risk of ambush by a team of relentless tech lawyers. </span>]]></description>
		
					<wfw:commentRss>https://www.biometricupdate.com/202610/apple-google-lobby-lawmakers-to-remove-liability-from-draft-online-safety-bills/feed</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">358292</post-id>	</item>
		<item>
		<title>Input wanted on draft standard update for operational biometric systems testing</title>
		<link>https://www.biometricupdate.com/202610/input-wanted-on-draft-standard-update-for-operational-biometric-systems-testing</link>
					<comments>https://www.biometricupdate.com/202610/input-wanted-on-draft-standard-update-for-operational-biometric-systems-testing#respond</comments>
		
		<dc:creator><![CDATA[Chris Burt]]></dc:creator>
		<pubDate>Mon, 05 Oct 2026 21:06:16 +0000</pubDate>
				<category><![CDATA[Biometric R&D]]></category>
		<category><![CDATA[Biometrics News]]></category>
		<category><![CDATA[biometric testing]]></category>
		<category><![CDATA[biometrics]]></category>
		<category><![CDATA[ISO standards]]></category>
		<category><![CDATA[ISO/IEC 19795-6]]></category>
		<guid isPermaLink="false">https://www.biometricupdate.com/?p=358294</guid>

					<description><![CDATA[
		<img width="2048" height="1536" src="https://d1sr9z1pdl3mb7.cloudfront.net/wp-content/uploads/2026/06/26135820/bixelab-biometric-testing2.jpg" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="Back of a person in an orange shirt watching a large monitor showing a video conference with blurred participants; a tripod camera sits on the desk nearby." decoding="async" loading="lazy" srcset="https://d1sr9z1pdl3mb7.cloudfront.net/wp-content/uploads/2026/06/26135820/bixelab-biometric-testing2.jpg 2048w, https://d1sr9z1pdl3mb7.cloudfront.net/wp-content/uploads/2026/06/26135820/bixelab-biometric-testing2-300x225.jpg 300w, https://d1sr9z1pdl3mb7.cloudfront.net/wp-content/uploads/2026/06/26135820/bixelab-biometric-testing2-1024x768.jpg 1024w, https://d1sr9z1pdl3mb7.cloudfront.net/wp-content/uploads/2026/06/26135820/bixelab-biometric-testing2-150x113.jpg 150w, https://d1sr9z1pdl3mb7.cloudfront.net/wp-content/uploads/2026/06/26135820/bixelab-biometric-testing2-768x576.jpg 768w, https://d1sr9z1pdl3mb7.cloudfront.net/wp-content/uploads/2026/06/26135820/bixelab-biometric-testing2-1536x1152.jpg 1536w" sizes="auto, (max-width: 2048px) 100vw, 2048px" />
		The functional requirements of operational biometric systems are evolving fast, but the standard that tests of those systems are based on dates from the era when convolutional neural networks were reframing what it was possible for those systems to do.

An <a href="https://www.iso.org/standard/91311.html">update</a> of the ISO/IEC 19795-6 standard is not just in order, but on the way. A new working draft of the standard for “Information technology – Biometric performance testing and reporting” has been released by JTC 1/SC 37.

SAIC Scientist Director and MdTF Researcher Yevgeniy Sirotin, who is also vice chair of the AI Subcommittee at the Intelligence and National Security Alliance, invited contributions from professionals who have experience with operational biometric systems in a <a href="https://www.linkedin.com/posts/yevgeniy-sirotin-public_iso-standards-biometrics-share-7510715534070677504-kiI_/">LinkedIn post</a>.

The standard provides guidance on operational testing for biometrics, including performance metrics, the data that can be retained for performance monitoring and requirements for test methodology, data recording and results reporting. The <a href="https://www.iso.org/standard/50873.html">current version</a> was published in 2012 and last confirmed in 2024.
<h2>A shared language for operational biometric systems testing</h2>
The new version expands the standard’s scope to include vulnerability testing, and reframes the subject as “testing of operational systems” instead of “operational testing.”

Vulnerabilities addressed include biometric presentation attack detection (PAD), morph attack detection (MAD) and deepfake attack detection.

Working draft 3, seen by <em>Biometric Update</em>, shows work progressing on clarifying the terminology around testing. The editor has replaced “System identification rate” with “system acceptance rate” and “system rejection rate,” and added new terms “biometric attack sample” and “biometric bona-fide sample.”

The WG seeks expert community feedback on whether false acceptance rate (FAR) and false reject rate (FRR) are the best performance metrics to use, and sets requirements for the metrics to use whether ground truth can be established or not, and what should go into those metrics.

The editor would like the expert community to help clarify what constitutes “business rules,” which could end up being replaced by a term like “system policy.”

The latest draft also adds guidance on data protection requirements for operational evaluations, appropriate treatment of test size and repeated transactions and introduces the term “tester biometric review,” but still needs guidance on how to perform such a review.

“We need clear language regarding how to test operational biometric systems when perfect ground truth is not known,” says Sirotin on LinkedIn.

BixeLab published a white paper earlier this year that discusses ISO/IEC 19795-6 in the context of how to understand <a href="https://www.biometricupdate.com/202606/bixelab-addresses-market-confusion-around-biometrics-testing-with-new-resources">the relation between testing and real-world results</a>.]]></description>
		
					<wfw:commentRss>https://www.biometricupdate.com/202610/input-wanted-on-draft-standard-update-for-operational-biometric-systems-testing/feed</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
		<post-id xmlns="com-wordpress:feed-additions:1">358294</post-id>	</item>
	</channel>
</rss>
