On Monday, the Waag Futurelab — a Dutch digital-rights research group — published an analysis that should rattle anyone who thought the EU’s Digital Identity Wallet was going to be a sovereign affair. Their finding, laid out in a front-page piece that has since been chewed over on Hacker News to the tune of 645 upvotes, is straightforward and damning: the wallets every EU citizen is supposed to have by December 2026 depend, at a fundamental architectural level, on the safety-net services of Google and Apple.
Not “can optionally use.” Not “interoperate with.” Depend.
The report walks through how Android’s SafetyNet and Apple’s DeviceCheck — the hardware-backed attestation APIs that tell an app whether a phone has been rooted or jailbroken — sit in the critical path of the EU’s grand identity scheme. If your phone fails that check, the wallet won’t provision. The authentication flow halts. You’re locked out. And there is no European fallback. No EU-built hardware trust mechanism. No alternative root-of-trust the consortium designed itself.
Brussels wrote a spec assuming the platforms would be there. And the platforms are Google and Apple.
The Architecture Nobody Wants to Discuss
What the Waag researchers surfaced is not technically a secret. The eIDAS 2.0 technical architecture documents, particularly the reference implementation work done by the European Commission’s working groups, have always assumed a mobile-first posture. The wallet runs as an app. The app needs a secure environment. The secure environment, on the phones people actually carry, is provided by the operating-system vendor.
Google’s SafetyNet (now Play Integrity API) and Apple’s DeviceCheck attest to the state of the device. They are not identity systems themselves, but they gate what can run and what can be trusted. Without a clean attestation, the wallet cannot guarantee it is running in an uncompromised context, and the entire chain breaks.
Europe had years to build an alternative. It built a standard. It built a reference app. It did not build a hardware root-of-trust. It did not fund a European secure enclave. It did not, crucially, require that the wallet work on devices that fail platform attestation — such as de-Googled Android phones, jailbroken iPhones, or the small but real population of devices running alternative mobile operating systems.
The result is not a regulatory capture story in the classic sense. It is simpler and more unsettling: the EU outsourced a sovereign function to two California-based corporations because nobody in Brussels wanted to have the phone-hardware conversation.
The Convenient Alliance of Privacy NGOs and Platform Power
Here is where the predictable right-of-center take would land: this is what happens when regulators mandate technology without understanding it. The EU passed a law, set a deadline, and didn’t realize it was wiring the plumbing of state-issued identity through Cupertino and Mountain View.
That take is correct as far as it goes, and it is also boring. The more interesting thing — the thing the Waag analysis gestures at but doesn’t fully name — is the quiet alliance between digital-rights advocates and the platform duopoly that makes this dependency so hard to dislodge.
The digital-rights crowd, understandably, wants wallets that cannot be silently compromised. They want cryptographic guarantees that your identity credential hasn’t been cloned. They want device integrity checks. All of which pushes the architecture toward the very hardware-attestation infrastructure that only Google and Apple provide at scale. Every NGO demand for anti-tampering, for secure provisioning, for verifiable device state — each one tightens the platforms’ grip.
“The security model everyone demanded is the security model that locks us in,” as one developer on the German sandbox project put it in a Slack DM this spring. “We wrote the requirements, and Google’s API was the only thing on the shelf that met them.”
The irony is sharp. The same civil-society groups that spent a decade warning about platform monopolies have, by insisting on privacy-maximalist technical requirements, helped produce a system where the platforms are functionally irreplaceable.
The Contingency That Should Exist but Doesn’t
None of this was inevitable. The EU could have mandated that wallets work on attested and unattested devices alike, with a graduated trust model — full credentials on secure devices, limited credentials on unverified ones. It could have funded a European hardware security module initiative, or required that the wallet specification include an open-source attestation path that any OS vendor could implement. It could have built the wallet as a physical smartcard with a contactless interface, the way Estonia did with its national ID card two decades ago, and treated the phone as a convenience layer rather than the root of the entire system.
It chose none of these. As of this week, fewer than one-third of EU member states meet the readiness benchmark for the December 2026 deadline, per the European Commission’s own monitoring. Germany’s sandbox — 115 organizations, 150 use cases — is still working through relying-party onboarding. The first public German state wallet app isn’t expected until early 2027. The deadline is slipping before it arrives.
And yet the dependency is already baked in. The reference architecture is locked. The procurement cycles have run. The consortiums that built the spec will not reopen it because a Dutch research group published a blog post.
What Sovereignty Actually Costs
The column that cheers this — “European bureaucracy humiliated by American tech, again” — misses the point by a mile. The humiliation isn’t that Google and Apple won. They didn’t have to win anything. They were simply there, providing a service that the EU’s own requirements made indispensable, while Europe declined to fund a competitor.
Sovereignty is not declared. It is built, chip by chip, standard by standard, procurement by procurement. It costs money. It requires saying no to requirements that only an American platform can meet. It means accepting that the first version will be less polished than what Google ships, and shipping it anyway.
The EU wanted the polish without the dependency. It got neither.
December 2026 is five months away. The wallets will arrive, on schedule or slightly late. They will work on iPhones and Pixels. They will pass attestation. They will be secure, in the narrow sense that the platform vendors define. And every time a European citizen opens one, a small packet of bytes will travel to a server in California to ask permission.
Sources
- Google expands Wallet with digital IDs and age credentials in EU | Biometric Update
- Waag | European digital ID wallets are a gift to Google and Apple
- Digital ID is going mainstream in 2026
- EU Sets 2026 Deadline for Digital Identity Wallet Rollout - LinkedIn
- EUDI Wallet 2026: Deadline, Rollout and Lessons