HomeAtlasDashboardChartsMetalsResearchPersonsBubble MapGlobeLeadershipLensesMethodologyGlossarySource ↗
Independent research & opinion. Gradings are automated / LLM-assisted and may contain errors or hallucinations; nothing here is a statement of fact, financial advice, or an accusation of wrongdoing by any party. Claims about identifiable people or organizations reflect public records + good-faith interpretation; intent is not inferred from association. Methodology & disclaimer.

Digital ID at the OS / app-store / hardware layer — the device-attestation enforcement chokepoint

Built 2026-06-14. Structured data + edges: digitalid-os-hardware-stack.json. The technical enforcement layer under digitalid-regulatory and the UK push in spec-uk-labour-tbi-influence. Companion to digitalid-orchestration-real-incentive and age-verification-abolition. (WebFetch was unavailable during research; figures are from search extracts of the cited primary sources — some exact dates graded contested.)

Digital identity and age verification are being pushed down from websites to the operating system, app store, and hardware — where enforcement is binding and anonymity is hard. The EU wallet must bind to a certified secure element; the EU age app and US app-store laws route the duty through Google Play Integrity and Apple App Attest / Declared Age Range; the Google-Apple mobile-OS duopoly becomes the de facto age authority. This is the layer that turns "optional" digital ID into something a device can make binding.

1. eIDAS 2.0 / EUDI wallet — hardware binding

2. The EU age-verification app — the Google/Apple dependency

3. Android — attestation, on-device mDL, OS age signals

4. Apple — OS-level age sharing on Secure-Enclave attestation

5. App-store mandates + the duopoly chokepoint

6. The SIM / secure-element layer (parallel hardware root)

7. The civil-liberties cost

Synthesis

The digital-ID debate is usually argued at the policy/website level, but enforcement is migrating to the device: eIDAS "high" assurance requires a certified secure element; the EU age app and US app-store laws route the duty through Google's Play Integrity and Apple's App Attest/Declared Age Range; and the Digital Credentials API lets any website demand an OS-issued credential. That makes the Google-Apple mobile-OS duopoly the de facto identity/age authority and turns "optional" digital ID (UK, spec-uk-labour-tbi-influence) into something the device can make binding — while attestation quietly excludes anonymity and alternative OSes.

What is NOT asserted


Sources: EU Digital Identity ARF (GitHub); eudi.dev high-level requirements; Regulation (EU) 2024/1183_2024/1183); EU age-verification blueprint (v2); EU age-verification policy; Android Play Integrity; Android Keystore attestation; Play Age Signals; Chrome Digital Credentials API; Apple Declared Age Range (WWDC 2025); Apple App Attest; Apple age-assurance update (Feb 2026); Utah SB 142; Ofcom age checks; GSMA eUICC; Security Explorations — eSIM; GrapheneOS attestation.

← Research index · structured data: digitalid-os-hardware-stack.json · digitalid-os-hardware-stack.md