Digital ID Plans Keep Failing. What Comes After?

Government digital identity plans have a pattern: they get announced, they attract criticism, and then they quietly disappear. That is not a conspiracy. It is a predictable result of two problems that keep being underestimated — public distrust and technical complexity. But the more interesting question is what happens next, because the need those plans were meant to meet does not vanish with them.

Is Digital ID Mandatory Anywhere Yet?

For most people, not yet. No major English-speaking country currently requires every adult to hold a government digital ID in order to live an ordinary life. Schemes have been proposed repeatedly and have repeatedly stalled.

But “not mandatory” is doing a lot of work in that sentence. Age verification is already compulsory on certain categories of website in the UK, and Australia has set a minimum age for social media use. HMRC already requires a digital account for self-assessment in the UK. You are not being handed a national ID card, but the number of things you cannot do without proving who you are online keeps growing.

So the honest answer is that digital ID is not mandatory as a single scheme, and is becoming mandatory in pieces.

Why Digital ID Schemes Keep Getting Killed

A government digital ID scheme, in plain terms, is a single official account that lets you prove who you are online — replacing a pile of passwords and scanned documents with one verified credential issued by the state.

The UK launched GOV.UK Verify in 2016 as exactly that. By 2023 it had been wound down, having never reached the adoption targets set for it. Australia’s digital identity programme has moved through multiple iterations and name changes, with uptake remaining low outside a narrow set of government services. These are not edge cases — they are the norm.

Two things keep sinking these efforts. First, people do not want governments holding a master key to their online life, and that reluctance is not irrational given the history of data breaches in public sector systems. Second, building a secure, interoperable identity system is genuinely hard, and the timelines politicians announce rarely survive contact with the engineering required.

The Gap a Scrapped Scheme Leaves Behind

When a digital identity plan dies, the underlying problem stays. People still need to prove their age to access certain websites. They still need to log into benefits systems, tax portals, and health records. That gap does not wait.

Age verification is the clearest example. In the UK, the Online Safety Act 2023 requires platforms hosting pornography to verify the age of users, but the specific mechanism is left to the platforms. That duty is separate from any national ID scheme, and it remains in force regardless of what happens to those schemes. With no government-run system available, each site decides what counts as proof. Some use credit card checks. Some use third-party services that scan your face or your driving licence. The law exists; the standardised way to meet it does not.

A private solution to that problem is not automatically safer than a government one. It is a different kind of risk. You are handing your date of birth, your face, or your financial data to a company whose primary interest is not your privacy.

Who Rushes In When Governments Step Back

The main private players are banks, credit reference agencies like Experian, tech giants, and a growing number of specialist ID verification startups such as Yoti or Onfido.

The tech giant route is already familiar to most people, even if they have not thought about it. The “Sign in with Google” or “Sign in with Apple” buttons that appear on dozens of sites are a form of federated identity — meaning you use one account to prove who you are across many different services. One company ends up with a detailed map of which sites you visit and when.

Millions of people use these buttons every day because they are convenient. The trade-off is that a single account suspension — for reasons that may have nothing to do with you — can cut off access to everything tied to it simultaneously.

These private systems are not regulated the way a government ID scheme would be. If something goes wrong, your legal remedies are weaker and less clear.

What Each Route Actually Means for Your Data

It helps to put three options side by side.

Government-run ID: One central record. Potentially accessible to police or intelligence agencies under warrant. Usually covered by data protection law, and in most countries subject to freedom of information requests. The risk is state surveillance and data breaches at scale.

Bank or credit agency: Your identity is tied to your financial history. Data is shared across fraud prevention networks — in the UK, organisations like CIFAS share records between member institutions. Your identity profile can affect credit decisions in ways you may not be able to see or challenge easily.

Big tech login: Tracks which services you authenticate with, feeds into advertising profiles, and the company can suspend your access without meaningful appeal. Google’s account termination policies, for instance, give users limited recourse when an account is flagged automatically.

None of these is safe. Each carries a different kind of risk. Knowing which one you are accepting is the starting point.

Laws That Are Trying to Fill the Void Right Now

The EU’s digital identity wallet, established under the revised eIDAS regulation adopted in 2024, takes a specific approach: rather than sharing a full ID scan, citizens can share only the single detail a service actually needs — your age, but not your name; your nationality, but not your address. It is designed to minimise what any one service learns about you.

In the UK, the Data (Use and Access) Act received Royal Assent in June 2025. It creates a framework for certified digital verification services, setting rules for how private identity providers must operate. Much of the practical detail sits in secondary legislation and a trust framework that are still being worked out, so what it means in daily life is not yet settled.

In the US and Australia, age verification laws aimed specifically at social media access for minors are advancing faster than broader digital identity plans, because they are politically easier to pass. Australia’s Online Safety Amendment (Social Media Minimum Age) Act 2024 set a minimum age of 16 for social media use, though the verification mechanism remains unresolved.

None of this is finished. The rules governing who can verify your identity online are being written now.

What You Can Actually Do About It

You do not need to be technical to take useful steps.

  • Check your third-party logins. Most Google and Apple accounts have a section listing every service you have authenticated through them. Review it. Remove services you no longer use.
  • Know your data rights. In the UK, EU, and Australia you can submit a Subject Access Request to any company asking what data they hold about you. They are legally required to respond.
  • Watch for public consultations. The UK government consulted publicly before the Data (Use and Access) Act, and the EU’s eIDAS process had public comment periods. Secondary legislation and trust frameworks go through the same process, so there are still open doors. Governments do read these submissions, and responses from ordinary people do shift outcomes.
  • Understand that opting out entirely is becoming harder. HMRC in the UK already requires a digital account for self-assessment. That direction is not reversing.

The goal is not to make you anxious. It is to help you make a choice rather than just click accept.

The Bigger Picture: A Decision That Will Not Wait

Someone is going to end up controlling how you prove who you are online. The question is whether that is a government, a bank, a tech company, or some combination of all three.

Every time a government digital identity plan collapses, the default shifts further toward private control. Private control is less visible and less subject to challenge than a government scheme, even if it feels less threatening. There is no public equivalent of a freedom of information request to Meta.

Digital identity is not a niche concern. It will determine who can access public services, who gets believed in online spaces, and how much of your daily movement — which sites you visit, which services you use, which communities you belong to — leaves a permanent record somewhere.

Frequently asked questions

Is digital ID mandatory?

Not as a single national scheme, in any major English-speaking country, at the time of writing. But parts of it are already compulsory: age checks on certain websites in the UK, a minimum age for social media in Australia, and digital accounts for some government services. The pattern is that digital ID is arriving in pieces rather than as one card everyone must carry.

If a government digital ID plan gets scrapped, does that mean I am safer?

Not automatically. When a government plan is scrapped, private companies fill the gap with less regulation and fewer obligations to you. You may have traded a visible risk for a less visible one.

What is wrong with just using my Google or Apple account to log in everywhere?

Nothing is immediately wrong with it. The problem is concentration. One company builds a detailed picture of your online activity across every service you authenticate through them. And if that account is suspended — for any reason — you can lose access to everything tied to it at once, with limited right of appeal.

Do I have any say in how these digital ID systems are designed?

More than most people realise. Governments in the UK, EU, US, and Australia have all run public consultations on digital identity legislation before passing it. Submitting a response to a consultation is open to any member of the public and takes less than an hour. The responses are read and they do influence the final text.

Related reading

Digital ID keeps coming back because the underlying problem is real: online systems genuinely cannot tell who anyone is. The question is who gets to hold that identity — you, a government database, or a company that sells it on.

There is a version of this where you own your identity and prove things about yourself without handing over your life. That is what we are working on.

Get Wes Kussmaul’s Escape the Plantation free, and follow where this goes.

Grab Your Free Ebook

Subscribe to our mailing list and get your free copy of Escape the Plantation.

“No problem can withstand the assault of sustained thinking.”

                                                                                                                                                 — Voltaire

🔒 YOU own the information that identifies YOU.
The operation of this website is governed by the ordinances of the City of Osmio, including its Privacy Ordinance.
View Privacy Ordinance

No Tracking Pixels or Beacons

Today's internet has become infested with hidden trackers — tiny “pixel beacons,” scripts, and device tracking tools designed to follow you without your knowledge.

As a Member Enterprise of The Authenticity Alliance, the operator of this website uses no tracking pixels, no beacons, and no covert identity-reporting mechanisms of any kind.

If we want to know something about you, we’ll ask — we won’t spy.
Learn About Spyfree

What is Authenticity™?

The word “Authenticity™” identifies a digital or physical space of “accountable anonymity” in which people enjoy both privacy for themselves and accountability from others.

Authenticity™ is the condition that exists in a space where there are

  • Digital Signatures Everywhere backed by
  • Measurably Reliable Identity Certificates that are
  • Owned by their Users and which provide
  • Privacy via Accountable Anonymity.

 

Learn about digital signatures and identity certificates in this short video →

What is The Authenticity Alliance?

We are an Authenticity Growers Cooperative

Similar to familiar agricultural cooperatives in the physical world, The Authenticity Alliance is a network of enterprises and individuals whose purpose is to “grow” Authenticity and bring it to the digital world.

Each Authenticity Enterprise—that is, each Member Enterprise of the Alliance—solves a particular inauthenticity problem in its chosen target market or audience.

What Does The Authenticity Alliance Do?

The Alliance brings together independent enterprises that share a common mission: creating spaces of accountable anonymity where digital signatures, reliable identity certificates, and privacy protection work together to solve real-world inauthenticity problems.

Who is the Authenticity Alliance?

The Authenticity Alliance is comprised of two groups working together to promote trust and transparency across digital ecosystems.

  • Enterprises: Authenticity Enterprises that provide Authenticity solutions for the inauthenticity pains in a specific market or industry.
  • Individuals: People who understand the problems of inauthenticity that plague the world’s information systems and who want to help implement and promote Authenticity™ principles.

Authenticity Enterprises

Each is an Enterprise Member of The Authenticity Alliance

Individual Enterprise in The Authenticity Alliance

Customers and members of an Authenticity Enterprise are automatically eligible to become Individual Members of The Authenticity Alliance.You may also join directly as an individual Member here.

 

© 2026 The Authenticity Alliance. All rights reserved. REAL Security | REAL Privacy | REAL Accountability